Page MenuHomeVyOS Platform
Feed All Stories

Feb 6 2024

jestabro moved T6017: Update vyos-http-api-tools for security advisory from Open to Finished on the VyOS 1.4 Sagitta board.
Feb 6 2024, 4:49 AM · VyOS 1.3 Equuleus (1.3.6), VyOS 1.4 Sagitta, VyOS 1.5 Circinus
jestabro moved T6017: Update vyos-http-api-tools for security advisory from Open to Finished on the VyOS 1.5 Circinus board.
Feb 6 2024, 4:49 AM · VyOS 1.3 Equuleus (1.3.6), VyOS 1.4 Sagitta, VyOS 1.5 Circinus
GitHub <[email protected]> committed rVYOSONEXc1be1713ae1e: Merge pull request #2939 from vyos/mergify/bp/sagitta/pr-2936 (authored by c-po).
Feb 6 2024, 4:25 AM
Mergify <37929162+mergify[bot]@users.noreply.github.com> committed rVYOSONEX1d8414c9dabd: init: T2044: always start/stop rpki during system boot (authored by c-po).
Feb 6 2024, 4:25 AM
Mergify <37929162+mergify[bot]@users.noreply.github.com> committed rVYOSONEXa32b2a9e8649: rpki: T6011: known-hosts-file is no longer supported by FRR (authored by c-po).
Feb 6 2024, 3:11 AM
c-po committed rVYOSONEX586863bf3a9c: rpki: T6011: known-hosts-file is no longer supported by FRR.
Feb 6 2024, 3:10 AM
GitHub <[email protected]> committed rVYOSONEXc1d0a778f9b2: Merge pull request #2936 from c-po/rpki-T6011 (authored by dmbaturin).
Feb 6 2024, 3:10 AM
c-po committed rVYOSONEX9199c87cf984: init: T2044: always start/stop rpki during system boot.
Feb 6 2024, 3:09 AM
GitHub <[email protected]> committed rVYOSONEXf2cefce3714c: Merge pull request #2935 from c-po/rpki (authored by dmbaturin).
Feb 6 2024, 3:09 AM

Feb 5 2024

GitHub <[email protected]> committed rVYOSONEX48be2429b831: Merge pull request #2938 from vyos/mergify/bp/sagitta/pr-2937 (authored by jestabro).
Feb 5 2024, 9:56 PM
n.fort added a comment to T445: iptables error with policy routing.

What version? Can you upgrade to 1.4?

Feb 5 2024, 9:37 PM · VyOS 1.3 Equuleus (1.3.8), test
Harliff added a comment to T445: iptables error with policy routing.

One of my router heavily affected by this issue, so if you will wrote a fix - you may ask me to test the fix.

Feb 5 2024, 9:36 PM · VyOS 1.3 Equuleus (1.3.8), test
Mergify <37929162+mergify[bot]@users.noreply.github.com> committed rVYOSONEX217b6b8894d8: T6018: adjust smoketest for update to FastAPI web framework (authored by jestabro).
Feb 5 2024, 9:34 PM
jestabro committed rVYOSONEXe1b63b9b1704: T6018: adjust smoketest for update to FastAPI web framework.
Feb 5 2024, 9:31 PM
GitHub <[email protected]> committed rVYOSONEXcf1a7ee4599c: Merge pull request #2937 from jestabro/overhead-advisory-update (authored by jestabro).
Feb 5 2024, 9:31 PM
jestabro added a project to T6018: smoketest: updating http-api framework requires a pause before test: VyOS 1.5 Circinus.
Feb 5 2024, 9:26 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
jestabro triaged T6018: smoketest: updating http-api framework requires a pause before test as Normal priority.
Feb 5 2024, 9:11 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
jestabro triaged T6017: Update vyos-http-api-tools for security advisory as High priority.
Feb 5 2024, 9:09 PM · VyOS 1.3 Equuleus (1.3.6), VyOS 1.4 Sagitta, VyOS 1.5 Circinus
c-po claimed T6010: Support setting multiple values in BGP path-attribute.
Feb 5 2024, 4:33 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
a.apostoliuk closed T5865: Rewrite ipv6 pool section to ipv6 named pools in Accel-ppp services as Resolved.
Feb 5 2024, 4:17 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
jestabro triaged T6016: Resolve intermittent failures in cleanup function after failed image install as High priority.
Feb 5 2024, 3:05 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
Viacheslav added a comment to T6012: Ability to have IPv6 nexthops for IPv4 static routes.

It seems FRR (9.0.2-36-g31dec1951) does not support this.
The route can be added, but no route is in the routing table.

vyos@r4:~$ vtysh -c "conf t" -c "ip route 192.0.2.0/24 2001:db8::1"
vyos@r4:~$ 
vyos@r4:~$ vtysh -c "show run" | match 192.0.2.0
ip route 192.0.2.0/24 2001:db8::1
vyos@r4:~$ 
vyos@r4:~$ 
vyos@r4:~$ show ip route 192.0.2.0/24
% Network not in table
vyos@r4:~$
Feb 5 2024, 2:37 PM · VyOS 1.5 Circinus
SrividyaA created T6015: "journalctl_charon" file does not contain data in the generated "ipsec debug-archive" file.
Feb 5 2024, 11:21 AM · VyOS 1.4 Sagitta (1.4.0-epa1)
n.fort changed the status of T6009: Firewall - Time not working properly when not using UTC from Confirmed to In progress.
Feb 5 2024, 10:17 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
Viacheslav changed the status of T6014: Bump keepalived version from Open to In progress.

PR for 1.5 https://github.com/vyos/vyos-build/pull/493
PR for 1.3 https://github.com/vyos/vyos-build/pull/494

Feb 5 2024, 9:32 AM · VyOS 1.3 Equuleus (1.3.6), VyOS 1.4 Sagitta, VyOS 1.5 Circinus
a.apostoliuk updated the task description for T5960: Rewriting authentication section in accel-ppp services.
Feb 5 2024, 9:28 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
Viacheslav moved T5974: QoS policy shaper is currently miscalculating bandwidth and ceil values for the default class from Open to Finished on the VyOS 1.4 Sagitta board.
Feb 5 2024, 8:47 AM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
Viacheslav closed T5974: QoS policy shaper is currently miscalculating bandwidth and ceil values for the default class as Resolved.
Feb 5 2024, 8:47 AM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
Viacheslav triaged T6014: Bump keepalived version as Normal priority.
Feb 5 2024, 8:43 AM · VyOS 1.3 Equuleus (1.3.6), VyOS 1.4 Sagitta, VyOS 1.5 Circinus
Viacheslav created T6014: Bump keepalived version.
Feb 5 2024, 8:43 AM · VyOS 1.3 Equuleus (1.3.6), VyOS 1.4 Sagitta, VyOS 1.5 Circinus
Viacheslav added a comment to T6010: Support setting multiple values in BGP path-attribute.

Update supports via whitespace

r4(config-router)#  neighbor foo path-attribute discard 23 24
Feb 5 2024, 8:36 AM · VyOS 1.4 Sagitta (1.4.0-epa3)
Viacheslav triaged T6010: Support setting multiple values in BGP path-attribute as Wishlist priority.

FRR does not support it

r4# conf t
r4(config)# router bgp 65001
r4(config-router)#  no bgp ebgp-requires-policy
r4(config-router)#  no bgp default ipv4-unicast
r4(config-router)#  no bgp network import-check
r4(config-router)#  neighbor foo peer-group
r4(config-router)#  neighbor foo path-attribute discard 24
r4(config-router)#  neighbor foo path-attribute discard 23,24
% Unknown command:  neighbor foo path-attribute discard 23,24
r4(config-router)#
Feb 5 2024, 8:34 AM · VyOS 1.4 Sagitta (1.4.0-epa3)
Viacheslav triaged T6011: rpki: known-hosts-file is no longer supported by FRR CLI - remove VyOS CLI node as Normal priority.
Feb 5 2024, 8:11 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
Viacheslav triaged T6013: SSH Certificate configuration as Wishlist priority.
Feb 5 2024, 8:10 AM · VyOS 1.5 Circinus
Viacheslav triaged T6012: Ability to have IPv6 nexthops for IPv4 static routes as Normal priority.
Feb 5 2024, 8:09 AM · VyOS 1.5 Circinus
nepeat created T6013: SSH Certificate configuration.
Feb 5 2024, 5:52 AM · VyOS 1.5 Circinus

Feb 4 2024

eureka added a comment to T6012: Ability to have IPv6 nexthops for IPv4 static routes.

This type of configuration works perfectly fine with VyOS 1.5 when receiving routes from a BGP peer (v4 routes with v6 nexthop), so it would be very nice to be able to manually install routes in the same way.

Feb 4 2024, 11:16 PM · VyOS 1.5 Circinus
nepeat created T6012: Ability to have IPv6 nexthops for IPv4 static routes.
Feb 4 2024, 10:59 PM · VyOS 1.5 Circinus

Feb 3 2024

GitHub <[email protected]> committed rVYOSONEX22a15d828e1d: Merge pull request #2934 from vyos/mergify/bp/sagitta/pr-2932 (authored by c-po).
Feb 3 2024, 9:07 PM
c-po renamed T6011: rpki: known-hosts-file is no longer supported by FRR CLI - remove VyOS CLI node from rpki: known-hosts-file is no longer supported bxy FRR CLI - remove VyOS CLI node to rpki: known-hosts-file is no longer supported by FRR CLI - remove VyOS CLI node.
Feb 3 2024, 8:44 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
c-po changed the status of T6011: rpki: known-hosts-file is no longer supported by FRR CLI - remove VyOS CLI node from Open to In progress.
Feb 3 2024, 8:14 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
c-po created T6011: rpki: known-hosts-file is no longer supported by FRR CLI - remove VyOS CLI node.
Feb 3 2024, 8:13 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
c-po added a comment to T6004: Missing RPKI boot priority prevents it from loading.

https://github.com/vyos/vyos-1x/pull/2935

Feb 3 2024, 8:08 PM · VyOS 1.3 Equuleus (1.3.7), VyOS 1.4 Sagitta (1.4.0-epa2)
c-po added a comment to T2044: RPKI doesn't boot properly.

https://github.com/vyos/vyos-1x/pull/2935

Feb 3 2024, 8:08 PM · VyOS 1.3 Equuleus (1.3.7), VyOS 1.5 Circinus, VyOS 1.4 Sagitta
Mergify <37929162+mergify[bot]@users.noreply.github.com> committed rVYOSONEX4edc0611ec0a: ipsec: T5998: add replay-windows setting (authored by c-po).
Feb 3 2024, 8:05 PM
Apachez added a comment to T5424: Routes vanishes when using FRR with ECMP and one of the ECMP paths is no longer available.

Its not clear if its fixed or not:

Feb 3 2024, 4:26 PM · Restricted Project, VyOS 1.4 Sagitta (1.4.1)
c-po committed rVYOSONEX4d943d8fbf12: ipsec: T5998: add replay-windows setting.
Feb 3 2024, 4:22 PM
GitHub <[email protected]> committed rVYOSONEX630a242cecae: Merge pull request #2932 from c-po/ipsec-T5998 (authored by c-po).
Feb 3 2024, 4:22 PM
c-po added a parent task for T2044: RPKI doesn't boot properly: T6004: Missing RPKI boot priority prevents it from loading.
Feb 3 2024, 11:51 AM · VyOS 1.3 Equuleus (1.3.7), VyOS 1.5 Circinus, VyOS 1.4 Sagitta
c-po added a subtask for T6004: Missing RPKI boot priority prevents it from loading: T2044: RPKI doesn't boot properly.
Feb 3 2024, 11:51 AM · VyOS 1.3 Equuleus (1.3.7), VyOS 1.4 Sagitta (1.4.0-epa2)
GitHub <[email protected]> committed rVYOSONEX088dcfd35af2: Merge pull request #2933 from vyos/mergify/bp/sagitta/pr-2931 (authored by c-po).
Feb 3 2024, 8:03 AM
Mergify <37929162+mergify[bot]@users.noreply.github.com> committed rVYOSONEXc224be5a55f6: configdict: T5894: preserve old behavior when dealing with PKI (authored by c-po).
Feb 3 2024, 5:03 AM
c-po committed rVYOSONEX9b56a86def67: configdict: T5894: preserve old behavior when dealing with PKI.
Feb 3 2024, 5:02 AM
GitHub <[email protected]> committed rVYOSONEX1d23d921deb0: Merge pull request #2931 from c-po/configdict-bugfix (authored by Viacheslav).
Feb 3 2024, 5:02 AM
dmbaturin created 1.3.6.
Feb 3 2024, 1:59 AM

Feb 2 2024

roedie created T6010: Support setting multiple values in BGP path-attribute.
Feb 2 2024, 7:52 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
c-po closed T6003: Add 'show rpki as-number' and 'show rpki prefix' as Resolved.
Feb 2 2024, 7:49 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
c-po moved T6003: Add 'show rpki as-number' and 'show rpki prefix' from Open to Finished on the VyOS 1.4 Sagitta board.
Feb 2 2024, 7:49 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
c-po moved T6003: Add 'show rpki as-number' and 'show rpki prefix' from Open to Finished on the VyOS 1.5 Circinus board.
Feb 2 2024, 7:49 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
c-po moved T5998: replay_window setting under vpn in config from Open to Finished on the VyOS 1.5 Circinus board.
Feb 2 2024, 7:49 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
c-po added a comment to T5998: replay_window setting under vpn in config.

PR https://github.com/vyos/vyos-1x/pull/2932

Feb 2 2024, 7:47 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
Viacheslav edited projects for T973: Create Prometheus Exporter for VyOS , added: VyOS 1.5 Circinus; removed VyOS 1.3 Equuleus (1.3.6).
Feb 2 2024, 4:45 PM · VyOS Rolling, VyOS 1.5 Circinus
Viacheslav closed T2459: Migrate vyatta-show-nat-rules.pl to Python, a subtask of T2198: Rewrite NAT in new XML/Python style, as Not Applicable.
Feb 2 2024, 4:42 PM · VyOS 1.3 Equuleus (1.3.0)
Viacheslav closed T2459: Migrate vyatta-show-nat-rules.pl to Python, a subtask of T3355: Remove all remaining legacy Vyatta code, as Not Applicable.
Feb 2 2024, 4:42 PM · VyOS 1.5 Circinus
Viacheslav closed T2459: Migrate vyatta-show-nat-rules.pl to Python as Not Applicable.

It won't be implemented for 1.3.x
Have this for 1.4/1.5

Feb 2 2024, 4:42 PM
GitHub <[email protected]> committed rVYOSONEX2d8a7bda382f: Merge pull request #2930 from vyos/mergify/bp/sagitta/pr-2748 (authored by c-po).
Feb 2 2024, 4:35 PM
Viacheslav changed the status of T4816: IPv4-mapped and IPv4-compatible IPv6 addresses not valid anymore from Open to Confirmed.
Feb 2 2024, 4:33 PM · Restricted Project, VyOS 1.4 Sagitta (1.4.1)
Viacheslav edited projects for T5153: OpenConnect route restriction via iptables is ignored, added: VyOS 1.5 Circinus; removed VyOS 1.3 Equuleus (1.3.6).
Feb 2 2024, 4:29 PM · Restricted Project, VyOS Rolling, VyOS 1.5 Circinus
Viacheslav moved T5739: Password recovery does not work if public keys are configured from Need Triage to Finished on the VyOS 1.3 Equuleus (1.3.6) board.
Feb 2 2024, 4:24 PM · VyOS 1.3 Equuleus (1.3.6), VyOS 1.5 Circinus, VyOS 1.4 Sagitta
Viacheslav moved T5739: Password recovery does not work if public keys are configured from Open to Finished on the VyOS 1.4 Sagitta board.
Feb 2 2024, 4:24 PM · VyOS 1.3 Equuleus (1.3.6), VyOS 1.5 Circinus, VyOS 1.4 Sagitta
Viacheslav closed T5739: Password recovery does not work if public keys are configured as Resolved.

merged

Feb 2 2024, 4:24 PM · VyOS 1.3 Equuleus (1.3.6), VyOS 1.5 Circinus, VyOS 1.4 Sagitta
Viacheslav closed T5848: Add triple-isolate flow isolation option to CAKE QoS policy as Resolved.
Feb 2 2024, 4:13 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
Viacheslav added a comment to T5914: CVE-2023-48795 - Terrapin vulnerability.
wget https://github.com/RUB-NDS/Terrapin-Scanner/releases/download/v1.1.0/Terrapin_Scanner_Linux_amd64
chmod +x Terrapin_Scanner_Linux_amd64
Feb 2 2024, 3:45 PM · VyOS 1.3 Equuleus (1.3.6)
Viacheslav closed T5941: [1.3.5 -> 1.4.0-RC1 Migration] Orphaned Configuration Nodes Cause Issues, a subtask of T5938: Migration fail root task for 1.4-rc, as Resolved.
Feb 2 2024, 3:36 PM · Restricted Project, VyOS 1.4 Sagitta (1.4.1)
Viacheslav closed T5941: [1.3.5 -> 1.4.0-RC1 Migration] Orphaned Configuration Nodes Cause Issues as Resolved.
Feb 2 2024, 3:36 PM · VyOS 1.4 Sagitta
Viacheslav closed T5914: CVE-2023-48795 - Terrapin vulnerability as Resolved.

Fixed https://packages.debian.org/buster/openssh-server

vyos@r15:~$ show version all | match ssh
ii  libssh-4:amd64                       0.8.7-1+deb10u2                amd64        tiny C SSH library (OpenSSL flavor)
ii  libssh2-1:amd64                      1.8.0-2.1+deb10u1              amd64        SSH2 client-side library
ii  openssh-client                       1:7.9p1-10+deb10u4             amd64        secure shell (SSH) client, for secure access to remote machines
ii  openssh-server                       1:7.9p1-10+deb10u4             amd64        secure shell (SSH) server, for secure access from remote machines
ii  openssh-sftp-server                  1:7.9p1-10+deb10u4             amd64        secure shell (SSH) sftp server module, for SFTP access from remote machines
ii  python3-paramiko                     2.4.2-0.1+deb10u1              all          Make ssh v2 connections (Python 3)
ii  sshguard                             2.3.1-1                        amd64        Protects from brute force attacks against ssh
vyos@r15:~$ 
vyos@r15:~$ show version
Feb 2 2024, 3:26 PM · VyOS 1.3 Equuleus (1.3.6)
syncer assigned T5928: Configuration fails to load on boot if offloading has VLAN interfaces defined to dmbaturin.
Feb 2 2024, 1:31 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
syncer closed T5909: Container registry with authentication prevents config load (section container) after reboot as Unknown Status.
Feb 2 2024, 1:26 PM · VyOS 1.4 Sagitta (1.4.0-epa2), VyOS 1.5 Circinus
syncer assigned T5914: CVE-2023-48795 - Terrapin vulnerability to Viacheslav.
Feb 2 2024, 1:22 PM · VyOS 1.3 Equuleus (1.3.6)
Mergify <37929162+mergify[bot]@users.noreply.github.com> committed rVYOSONEXd9cc48fe8c6b: qos: T5848: improve flow-isolation help strings (authored by c-po).
Feb 2 2024, 12:12 PM
Mergify <37929162+mergify[bot]@users.noreply.github.com> committed rVYOSONEX628877a46a04: qos: T5848: Add triple-isolate option to CAKE policy config (authored by MattK).
Feb 2 2024, 12:12 PM
c-po added a comment to T5848: Add triple-isolate flow isolation option to CAKE QoS policy.

PR https://github.com/vyos/vyos-1x/pull/2748

Feb 2 2024, 12:11 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
c-po moved T5848: Add triple-isolate flow isolation option to CAKE QoS policy from Open to Finished on the VyOS 1.4 Sagitta board.
Feb 2 2024, 12:10 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
c-po moved T5848: Add triple-isolate flow isolation option to CAKE QoS policy from Open to Finished on the VyOS 1.5 Circinus board.
Feb 2 2024, 12:10 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
MattK committed rVYOSONEX61342083d7db: qos: T5848: Add triple-isolate option to CAKE policy config.
Feb 2 2024, 12:10 PM
c-po committed rVYOSONEX762be96f45bb: qos: T5848: improve flow-isolation help strings.
Feb 2 2024, 12:10 PM
GitHub <[email protected]> committed rVYOSONEX84b17f0e666b: Merge pull request #2748 from MattKobayashi/t5848 (authored by c-po).
Feb 2 2024, 12:10 PM
n.fort changed the status of T6009: Firewall - Time not working properly when not using UTC from Open to Confirmed.
Feb 2 2024, 11:08 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
n.fort updated the task description for T6009: Firewall - Time not working properly when not using UTC.
Feb 2 2024, 11:05 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
n.fort created T6009: Firewall - Time not working properly when not using UTC.
Feb 2 2024, 11:03 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
mark22k awarded T766: Implement support for the Tinc VPN daemon a Like token.
Feb 2 2024, 10:19 AM
anonuser35hww45 added a comment to T5955: Rootless containers/set uid/gid for container.

Documentation PR: https://github.com/vyos/vyos-documentation/pull/1261

Feb 2 2024, 9:43 AM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
Viacheslav moved T5955: Rootless containers/set uid/gid for container from Open to Finished on the VyOS 1.4 Sagitta board.
Feb 2 2024, 9:20 AM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
Viacheslav closed T5955: Rootless containers/set uid/gid for container as Resolved.
Feb 2 2024, 9:20 AM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
GitHub <[email protected]> committed rVYOSONEX38a46e1bffd2: Merge pull request #2929 from vyos/mergify/bp/sagitta/pr-2927 (authored by Viacheslav).
Feb 2 2024, 9:20 AM
sarthurdev committed rVYOSONEX8e2112261c68: dhcpv6: T3771: Allow installation of routes for delegated prefixes.
Feb 2 2024, 9:07 AM
sarthurdev committed rVYOSONEX7253c8a3d464: dhcpv6: T3316: Add support for excluded-prefix in prefix delegation.
Feb 2 2024, 9:07 AM
sarthurdev committed rVYOSONEXecfc3495e759: dhcp: T3316: Change help text on `listen-interface` to be generic.
Feb 2 2024, 9:07 AM
sarthurdev committed rVYOSONEX9ba7093563d4: dhcp: T3316: Fix header on script.
Feb 2 2024, 9:07 AM
GitHub <[email protected]> committed rVYOSONEXdca220d515e6: Updates to Kea DHCPv6 PD route hook (#6) (authored by cbuechler).
Feb 2 2024, 9:07 AM