Page MenuHomeVyOS Platform
Feed All Stories

Feb 2 2024

Viacheslav closed T5848: Add triple-isolate flow isolation option to CAKE QoS policy as Resolved.
Feb 2 2024, 4:13 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
Viacheslav added a comment to T5914: CVE-2023-48795 - Terrapin vulnerability.
wget https://github.com/RUB-NDS/Terrapin-Scanner/releases/download/v1.1.0/Terrapin_Scanner_Linux_amd64
chmod +x Terrapin_Scanner_Linux_amd64
Feb 2 2024, 3:45 PM · VyOS 1.3 Equuleus (1.3.6)
Viacheslav closed T5941: [1.3.5 -> 1.4.0-RC1 Migration] Orphaned Configuration Nodes Cause Issues, a subtask of T5938: Migration fail root task for 1.4-rc, as Resolved.
Feb 2 2024, 3:36 PM · VyOS Rolling, Restricted Project
Viacheslav closed T5941: [1.3.5 -> 1.4.0-RC1 Migration] Orphaned Configuration Nodes Cause Issues as Resolved.
Feb 2 2024, 3:36 PM · VyOS 1.4 Sagitta
Viacheslav closed T5914: CVE-2023-48795 - Terrapin vulnerability as Resolved.

Fixed https://packages.debian.org/buster/openssh-server

vyos@r15:~$ show version all | match ssh
ii  libssh-4:amd64                       0.8.7-1+deb10u2                amd64        tiny C SSH library (OpenSSL flavor)
ii  libssh2-1:amd64                      1.8.0-2.1+deb10u1              amd64        SSH2 client-side library
ii  openssh-client                       1:7.9p1-10+deb10u4             amd64        secure shell (SSH) client, for secure access to remote machines
ii  openssh-server                       1:7.9p1-10+deb10u4             amd64        secure shell (SSH) server, for secure access from remote machines
ii  openssh-sftp-server                  1:7.9p1-10+deb10u4             amd64        secure shell (SSH) sftp server module, for SFTP access from remote machines
ii  python3-paramiko                     2.4.2-0.1+deb10u1              all          Make ssh v2 connections (Python 3)
ii  sshguard                             2.3.1-1                        amd64        Protects from brute force attacks against ssh
vyos@r15:~$ 
vyos@r15:~$ show version
Feb 2 2024, 3:26 PM · VyOS 1.3 Equuleus (1.3.6)
syncer assigned T5928: Configuration fails to load on boot if offloading has VLAN interfaces defined to dmbaturin.
Feb 2 2024, 1:31 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
syncer closed T5909: Container registry with authentication prevents config load (section container) after reboot as Unknown Status.
Feb 2 2024, 1:26 PM · VyOS 1.4 Sagitta (1.4.0-epa2), VyOS 1.5 Circinus
syncer assigned T5914: CVE-2023-48795 - Terrapin vulnerability to Viacheslav.
Feb 2 2024, 1:22 PM · VyOS 1.3 Equuleus (1.3.6)
Mergify <37929162+mergify[bot]@users.noreply.github.com> committed rVYOSONEXd9cc48fe8c6b: qos: T5848: improve flow-isolation help strings (authored by c-po).
Feb 2 2024, 12:12 PM
Mergify <37929162+mergify[bot]@users.noreply.github.com> committed rVYOSONEX628877a46a04: qos: T5848: Add triple-isolate option to CAKE policy config (authored by MattK).
Feb 2 2024, 12:12 PM
c-po added a comment to T5848: Add triple-isolate flow isolation option to CAKE QoS policy.

PR https://github.com/vyos/vyos-1x/pull/2748

Feb 2 2024, 12:11 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
c-po moved T5848: Add triple-isolate flow isolation option to CAKE QoS policy from Open to Finished on the VyOS 1.4 Sagitta board.
Feb 2 2024, 12:10 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
c-po moved T5848: Add triple-isolate flow isolation option to CAKE QoS policy from Open to Finished on the VyOS 1.5 Circinus board.
Feb 2 2024, 12:10 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
MattK committed rVYOSONEX61342083d7db: qos: T5848: Add triple-isolate option to CAKE policy config.
Feb 2 2024, 12:10 PM
c-po committed rVYOSONEX762be96f45bb: qos: T5848: improve flow-isolation help strings.
Feb 2 2024, 12:10 PM
GitHub <[email protected]> committed rVYOSONEX84b17f0e666b: Merge pull request #2748 from MattKobayashi/t5848 (authored by c-po).
Feb 2 2024, 12:10 PM
n.fort changed the status of T6009: Firewall - Time not working properly when not using UTC from Open to Confirmed.
Feb 2 2024, 11:08 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
n.fort updated the task description for T6009: Firewall - Time not working properly when not using UTC.
Feb 2 2024, 11:05 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
n.fort created T6009: Firewall - Time not working properly when not using UTC.
Feb 2 2024, 11:03 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
mark22k awarded T766: Implement support for the Tinc VPN daemon a Like token.
Feb 2 2024, 10:19 AM
anonuser35hww45 added a comment to T5955: Rootless containers/set uid/gid for container.

Documentation PR: https://github.com/vyos/vyos-documentation/pull/1261

Feb 2 2024, 9:43 AM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
Viacheslav moved T5955: Rootless containers/set uid/gid for container from Open to Finished on the VyOS 1.4 Sagitta board.
Feb 2 2024, 9:20 AM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
Viacheslav closed T5955: Rootless containers/set uid/gid for container as Resolved.
Feb 2 2024, 9:20 AM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
GitHub <[email protected]> committed rVYOSONEX38a46e1bffd2: Merge pull request #2929 from vyos/mergify/bp/sagitta/pr-2927 (authored by Viacheslav).
Feb 2 2024, 9:20 AM
sarthurdev committed rVYOSONEX8e2112261c68: dhcpv6: T3771: Allow installation of routes for delegated prefixes.
Feb 2 2024, 9:07 AM
sarthurdev committed rVYOSONEX7253c8a3d464: dhcpv6: T3316: Add support for excluded-prefix in prefix delegation.
Feb 2 2024, 9:07 AM
sarthurdev committed rVYOSONEXecfc3495e759: dhcp: T3316: Change help text on `listen-interface` to be generic.
Feb 2 2024, 9:07 AM
sarthurdev committed rVYOSONEX9ba7093563d4: dhcp: T3316: Fix header on script.
Feb 2 2024, 9:07 AM
GitHub <[email protected]> committed rVYOSONEXdca220d515e6: Updates to Kea DHCPv6 PD route hook (#6) (authored by cbuechler).
Feb 2 2024, 9:07 AM
GitHub <[email protected]> committed rVYOSONEXeb41a9a96f52: Merge pull request #2889 from sarthurdev/kea-hooks (authored by c-po).
Feb 2 2024, 9:07 AM
Mergify <37929162+mergify[bot]@users.noreply.github.com> committed rVYOSONEX33dfd49c385e: smoketest: T5955: verify container uid/gid setting (authored by c-po).
Feb 2 2024, 9:06 AM
Mergify <37929162+mergify[bot]@users.noreply.github.com> committed rVYOSONEXf95738c0dd62: container: T5955: allow setting uid/gid (authored by Piotr Maksymiuk <[email protected]>).
Feb 2 2024, 9:06 AM
Piotr Maksymiuk <[email protected]> committed rVYOSONEX52e9707a4329: container: T5955: allow setting uid/gid.
Feb 2 2024, 9:05 AM
c-po committed rVYOSONEXfaa4c87d93c7: smoketest: T5955: verify container uid/gid setting.
Feb 2 2024, 9:05 AM
GitHub <[email protected]> committed rVYOSONEX4b0a78b0d2e4: Merge pull request #2927 from ishioni/T5955 (authored by c-po).
Feb 2 2024, 9:05 AM
Viacheslav triaged T6008: HS20 / Hotspot 2.0 / Passpoint 2.0 Support as Wishlist priority.
Feb 2 2024, 8:52 AM · VyOS Rolling
Viacheslav raised the priority of T5971: Create the same view of ppp section for all accel-ppp services from Low to Normal.
Feb 2 2024, 8:51 AM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
Viacheslav changed the status of T5971: Create the same view of ppp section for all accel-ppp services from In progress to Needs testing.
Feb 2 2024, 8:51 AM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
GitHub <[email protected]> committed rVYOSONEXcb702bbe6143: Merge pull request #2928 from vyos/mergify/bp/sagitta/pr-2891 (authored by Viacheslav).
Feb 2 2024, 8:51 AM
GitHub <[email protected]> committed rVYOSONEXa092d507aefc: Merge pull request #2921 from vyos/mergify/bp/sagitta/pr-2903 (authored by Viacheslav).
Feb 2 2024, 8:50 AM
indrajitr committed rVYOSONEX29a43735334d: ddclient: T5966: Adjust dynamic dns config address subpath.
Feb 2 2024, 8:39 AM
indrajitr committed rVYOSONEXf03490f03781: T2719: Add 'update' in standard op-mode function list.
Feb 2 2024, 8:39 AM
indrajitr committed rVYOSONEXfb93b2d0da67: ddclient: T5966: Update smoketest for dynamic dns config subpath change.
Feb 2 2024, 8:39 AM
indrajitr committed rVYOSONEX42e39d21a66e: ddclient: T5966: Migration script for dynamic dns config subpath change.
Feb 2 2024, 8:39 AM
indrajitr committed rVYOSONEXfd3b3f3b9fff: ddclient: T5966: Streamline dynamic dns op-mode configuration.
Feb 2 2024, 8:39 AM
indrajitr committed rVYOSONEXd9ed904b72fd: op-mode: T5966: Ensure top level property to avoid empty node.
Feb 2 2024, 8:39 AM
Mergify <37929162+mergify[bot]@users.noreply.github.com> committed rVYOSONEX52e868e1abfe: T5971: Rewritten ppp options in accel-ppp services (authored by a.apostoliuk).
Feb 2 2024, 8:39 AM
GitHub <[email protected]> committed rVYOSONEX5a9a4d5d34ac: Merge pull request #2926 from indrajitr/sagitta-ddclient-T5966 (authored by c-po).
Feb 2 2024, 8:39 AM
simeonsecurity created T6008: HS20 / Hotspot 2.0 / Passpoint 2.0 Support.
Feb 2 2024, 8:39 AM · VyOS Rolling
simeonsecurity added a comment to T28: Add auto provisioning.

Would love to see more on this.

Feb 2 2024, 8:27 AM · Restricted Project, VyOS Rolling
simeonsecurity updated simeonsecurity.
Feb 2 2024, 8:25 AM
Viacheslav changed the status of T5966: Adjust dynamic dns configuration address subpath to be more intuitive and other op-mode adjustments, a subtask of T5791: Update dynamic dns configuration path to be consistent with other areas of VyOS, from Open to Needs testing.
Feb 2 2024, 8:19 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
Viacheslav changed the status of T5966: Adjust dynamic dns configuration address subpath to be more intuitive and other op-mode adjustments from Open to Needs testing.
Feb 2 2024, 8:19 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
a.apostoliuk committed rVYOSONEXd9e57fe65dd5: T5971: Rewritten ppp options in accel-ppp services.
Feb 2 2024, 8:14 AM
GitHub <[email protected]> committed rVYOSONEXf2de4378b504: Merge pull request #2891 from aapostoliuk/T5971-circinus (authored by Viacheslav).
Feb 2 2024, 8:14 AM
bweeks added a comment to T5881: IPv6 addresses jumbled in flow accounting.

I can reproduce this on VyOS 1.4.0-rc3. It also appears that IPv6 addresses are only garbled on subinterfaces.

Feb 2 2024, 7:08 AM · VyOS Rolling, Restricted Project

Feb 1 2024

anonuser35hww45 added a comment to T5955: Rootless containers/set uid/gid for container.

PR: https://github.com/vyos/vyos-1x/pull/2927

Feb 1 2024, 10:09 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
c-po changed the status of T5967: Multi-hop BFD connections can't be established; please add minimum-ttl option. from Unknown Status to Resolved.
Feb 1 2024, 9:08 PM · VyOS 1.3 Equuleus (1.3.6), VyOS 1.5 Circinus, VyOS 1.4 Sagitta
c-po committed rVYOSONEXe559ff4e552a: bfd: T5967: add minimum-ttl option.
Feb 1 2024, 9:02 PM
GitHub <[email protected]> committed rVYOSONEXa685e55f3a1b: Merge pull request #2920 from c-po/bfd-equuleus-T5967 (authored by dmbaturin).
Feb 1 2024, 9:02 PM
roedie added a comment to T6004: Missing RPKI boot priority prevents it from loading.

I've upgraden from a self built 1.4-202312040739 to 1.4rc3

Feb 1 2024, 8:50 PM · VyOS 1.3 Equuleus (1.3.7), VyOS 1.4 Sagitta (1.4.0-epa2)
GitHub <[email protected]> committed rVYOSONEXb5a907135ef1: Merge pull request #2925 from vyos/mergify/bp/sagitta/pr-2897 (authored by c-po).
Feb 1 2024, 8:41 PM
GitHub <[email protected]> committed rVYOSONEXb24e2cbef7fc: Merge pull request #2924 from vyos/mergify/bp/sagitta/pr-2756 (authored by c-po).
Feb 1 2024, 8:41 PM
c-po committed rVYOSONEX5802d14e08f8: smoketest: T5687: simplify "dns forwarding" test setup.
Feb 1 2024, 8:40 PM
c-po committed rVYOSONEX7134ab4b9f03: dns forwarding: T5687: add missing constraints on ecs-add-for CLI node.
Feb 1 2024, 8:40 PM
c-po committed rVYOSONEX97c04c16303a: dns forwarding: T5687: Implement ECS settings for PowerDNS recursor (authored by khramshinr <[email protected]>).
Feb 1 2024, 8:40 PM
c-po committed rVYOSONEX9ac2a115a228: dns forwarding: T5687: Implement ECS settings for PowerDNS recursor (authored by khramshinr <[email protected]>).
Feb 1 2024, 8:40 PM
GitHub <[email protected]> committed rVYOSONEXcd4b03898e99: Merge pull request #2922 from vyos/mergify/bp/sagitta/pr-2854 (authored by c-po).
Feb 1 2024, 8:33 PM
Mergify <37929162+mergify[bot]@users.noreply.github.com> committed rVYOSONEX2c7fd3903726: upnp: T5989: add ipv4-prefix as a valid option for UPnP ACLs (authored by cbuechler).
Feb 1 2024, 8:25 PM
GitHub <[email protected]> committed rVYOSONEX0307801b8928: upnp: T5989: add ipv4-prefix as a valid option for UPnP ACLs (authored by cbuechler).
Feb 1 2024, 8:24 PM
Mergify <37929162+mergify[bot]@users.noreply.github.com> committed rVYOSONEX264161017b94: op-mode: T5966: Ensure top level property to avoid empty node (authored by indrajitr).
Feb 1 2024, 8:22 PM
Mergify <37929162+mergify[bot]@users.noreply.github.com> committed rVYOSONEX711de2bbb60f: ddclient: T5966: Streamline dynamic dns op-mode configuration (authored by indrajitr).
Feb 1 2024, 8:22 PM
Mergify <37929162+mergify[bot]@users.noreply.github.com> committed rVYOSONEX20149076ebe1: T2719: Add 'update' in standard op-mode function list (authored by indrajitr).
Feb 1 2024, 8:22 PM
Mergify <37929162+mergify[bot]@users.noreply.github.com> committed rVYOSONEX413c4f4bf2c1: ddclient: T5966: Update smoketest for dynamic dns config subpath change (authored by indrajitr).
Feb 1 2024, 8:22 PM
Mergify <37929162+mergify[bot]@users.noreply.github.com> committed rVYOSONEXf642a3d3b2fd: ddclient: T5966: Migration script for dynamic dns config subpath change (authored by indrajitr).
Feb 1 2024, 8:22 PM
Mergify <37929162+mergify[bot]@users.noreply.github.com> committed rVYOSONEX600446af4378: ddclient: T5966: Adjust dynamic dns config address subpath (authored by indrajitr).
Feb 1 2024, 8:22 PM
Mergify <37929162+mergify[bot]@users.noreply.github.com> committed rVYOSONEX3ce9583b9420: T4839: firewall: Add dynamic address group in firewall configuration, and… (authored by n.fort).
Feb 1 2024, 8:22 PM
n.fort committed rVYOSONEX6ce5fedb602c: T4839: firewall: Add dynamic address group in firewall configuration, and….
Feb 1 2024, 8:22 PM
GitHub <[email protected]> committed rVYOSONEX8a4017d91d50: Merge pull request #2756 from nicolas-fort/T4839 (authored by c-po).
Feb 1 2024, 8:22 PM
indrajitr committed rVYOSONEX7aa116fc7a2a: ddclient: T5966: Update smoketest for dynamic dns config subpath change.
Feb 1 2024, 8:21 PM
indrajitr committed rVYOSONEX38e7e5679497: ddclient: T5966: Migration script for dynamic dns config subpath change.
Feb 1 2024, 8:21 PM
indrajitr committed rVYOSONEX4476e30007b5: ddclient: T5966: Adjust dynamic dns config address subpath.
Feb 1 2024, 8:21 PM
indrajitr committed rVYOSONEX2080f8edd69c: ddclient: T5966: Streamline dynamic dns op-mode configuration.
Feb 1 2024, 8:21 PM
indrajitr committed rVYOSONEX54dfb77a3035: T2719: Add 'update' in standard op-mode function list.
Feb 1 2024, 8:21 PM
indrajitr committed rVYOSONEX323994ed0fc4: op-mode: T5966: Ensure top level property to avoid empty node.
Feb 1 2024, 8:21 PM
GitHub <[email protected]> committed rVYOSONEX176a79420c5b: Merge pull request #2860 from indrajitr/ddclient-update-20240119 (authored by c-po).
Feb 1 2024, 8:21 PM
jestabro added a subtask for T6007: Improvements to migration system: T6006: Configure system-specific capabilities independently of migration scripts.
Feb 1 2024, 8:20 PM · VyOS 1.5 Circinus
jestabro added a parent task for T6006: Configure system-specific capabilities independently of migration scripts: T6007: Improvements to migration system.
Feb 1 2024, 8:20 PM · VyOS 1.5 Circinus
jestabro triaged T6007: Improvements to migration system as Normal priority.
Feb 1 2024, 8:19 PM · VyOS 1.5 Circinus
c-po added a comment to T6004: Missing RPKI boot priority prevents it from loading.

I can not reproduce the issue while upgrading from VyOS 1.3.5 -> 1.4.0-rc3

Feb 1 2024, 8:11 PM · VyOS 1.3 Equuleus (1.3.7), VyOS 1.4 Sagitta (1.4.0-epa2)
jestabro updated the task description for T6006: Configure system-specific capabilities independently of migration scripts.
Feb 1 2024, 8:07 PM · VyOS 1.5 Circinus
jestabro added a subtask for T3821: Add latest versions to default config files: T6006: Configure system-specific capabilities independently of migration scripts.
Feb 1 2024, 8:06 PM · VyOS 1.5 Circinus
jestabro added a parent task for T6006: Configure system-specific capabilities independently of migration scripts: T3821: Add latest versions to default config files.
Feb 1 2024, 8:06 PM · VyOS 1.5 Circinus
jestabro triaged T6006: Configure system-specific capabilities independently of migration scripts as Normal priority.
Feb 1 2024, 8:05 PM · VyOS 1.5 Circinus
GitHub <[email protected]> committed rVYOSONEX9109a5603963: Merge pull request #2916 from vyos/mergify/bp/sagitta/pr-2832 (authored by c-po).
Feb 1 2024, 7:57 PM
Mergify <37929162+mergify[bot]@users.noreply.github.com> committed rVYOSONEX7255115be80e: dns: T5959: Avoid using reserved ports for testing (authored by indrajitr).
Feb 1 2024, 7:52 PM
Mergify <37929162+mergify[bot]@users.noreply.github.com> committed rVYOSONEX3e713e5c9608: dns: T5959: Streamline dns forwarding service (authored by indrajitr).
Feb 1 2024, 7:52 PM
Mergify <37929162+mergify[bot]@users.noreply.github.com> committed rVYOSONEX8996552e61af: dns: T4578: Remove unnecessary dns forwarding statistics script (authored by indrajitr).
Feb 1 2024, 7:52 PM
Mergify <37929162+mergify[bot]@users.noreply.github.com> committed rVYOSONEX6557e0bab41a: smoketest: T5687: simplify "dns forwarding" test setup (authored by c-po).
Feb 1 2024, 7:46 PM
Mergify <37929162+mergify[bot]@users.noreply.github.com> committed rVYOSONEXb5f35c2d0f29: dns forwarding: T5687: add missing constraints on ecs-add-for CLI node (authored by c-po).
Feb 1 2024, 7:46 PM