Page MenuHomeVyOS Platform
Feed All Stories

Apr 29 2024

Viacheslav changed the status of T4921: Miniupnpd only allows for IGDv2 while IGDv1 is mostly common used and supported from Open to Needs reporter action.

@yarokifor The current version is updated, add steps to reproduce (set of commands) or close the task

vyos@r4# run show ver all | match upnp
ii  miniupnpd-nftables                   2.3.1-1                          amd64        UPnP and NAT-PMP daemon for gateway routers - nftables backend
[edit]
vyos@r4#
Apr 29 2024, 9:36 AM · Restricted Project, VyOS 1.5 Circinus
Viacheslav added a subtask for T3664: Build flavor system redesign: T4932: Some entries are missing or wrong in toml for builds for the arm64 architecture.
Apr 29 2024, 9:32 AM · VyOS 1.4 Sagitta (1.4.0-epa3)
Viacheslav added a parent task for T4932: Some entries are missing or wrong in toml for builds for the arm64 architecture: T3664: Build flavor system redesign.
Apr 29 2024, 9:32 AM · Restricted Project, VyOS Rolling, VyOS 1.5 Circinus, vyos-build
Viacheslav assigned T6082: BGP doesn't allow the same local AS and remote AS in peer groups to HollyGurza.
Apr 29 2024, 9:30 AM · VyOS 1.4 Sagitta (1.4.0-epa3)
Viacheslav changed the status of T6267: Improve commit failure messages for wireless interface configuration from Open to In progress.
Apr 29 2024, 9:27 AM · VyOS 1.4 Sagitta (1.4.0-epa3)
a.apostoliuk changed the status of T6272: PPPoE configuration does not load after deleting a PPPoE interface from the system from Open to In progress.
Apr 29 2024, 8:35 AM · VyOS 1.4 Sagitta (1.4.0-epa3)
a.apostoliuk changed the status of T6273: Hyphens and underscores are considered invalid in PPPoE access-concentrator names from Open to In progress.
Apr 29 2024, 8:34 AM · VyOS 1.4 Sagitta (1.4.0-epa3)
Viacheslav closed T2279: Router resolves as 127.0.1.1 when using Router's Recursive DNS, a subtask of T2464: DNS bugs (parent task), as Resolved.
Apr 29 2024, 8:29 AM · VyOS Rolling
Viacheslav closed T2279: Router resolves as 127.0.1.1 when using Router's Recursive DNS as Resolved.

Fixed in the commit https://github.com/vyos/vyos-1x/commit/b75e0ba0a297fd64307960f98f30c27a689deab7

Apr 29 2024, 8:29 AM · VyOS 1.4 Sagitta (1.4.0-epa3), VyOS 1.5 Circinus, VyOS 1.3 Equuleus (1.3.7)
dmbaturin triaged T6275: Carry over SSH keys between images on upgrades as Normal priority.
Apr 29 2024, 7:58 AM · VyOS Rolling
jestabro committed rVYOSONEXc5e6f9aef770: configdep: T5836: add boolean check whether script called as dependency.
Apr 29 2024, 7:48 AM
jestabro committed rVYOSONEX0239ee33ec06: configdep: T5839: remove trivially redundant config dependency calls.
Apr 29 2024, 7:48 AM
jestabro committed rVYOSONEXd2ba96d8af03: configdep: T5660: remove global redundancies under vyos-configd.
Apr 29 2024, 7:48 AM
jestabro committed rVYOSONEX2479ed1a6a71: configdep: T6276: do not call dependencies on script error.
Apr 29 2024, 7:48 AM
GitHub <[email protected]> committed rVYOSONEXc1507d684cc9: Merge pull request #3373 from jestabro/sagitta-configdep-redundancy (authored by dmbaturin).
Apr 29 2024, 7:48 AM
Viacheslav triaged T6280: OpenVPN add oauth2 plugin as Wishlist priority.
Apr 29 2024, 7:02 AM · VyOS Rolling
Viacheslav created T6280: OpenVPN add oauth2 plugin.
Apr 29 2024, 7:02 AM · VyOS Rolling
kmadaras added a comment to T6275: Carry over SSH keys between images on upgrades.

It seems like if there's an option to use remote backup in the config, yet the keys get erased every time it's upgraded that would be a bug. However , I am new to dev on VYOS, so classify it as makes sense for the team and I'll hope it get implemented at some point. 👍

Apr 29 2024, 6:38 AM · VyOS Rolling
Viacheslav added a comment to T6275: Carry over SSH keys between images on upgrades.

The bug means the feature is implemented but works with issues, but this functionality has never been implemented :)
I created a root task T6279, and several similar/related subtasks.

Apr 29 2024, 6:29 AM · VyOS Rolling
Viacheslav triaged T6279: The root task for copying SSH keys and files from the home directory to use between updates as Normal priority.
Apr 29 2024, 6:25 AM · VyOS Rolling
Viacheslav added a subtask for T6279: The root task for copying SSH keys and files from the home directory to use between updates: T741: move user home to persistent storage.
Apr 29 2024, 6:24 AM · VyOS Rolling
Viacheslav added a parent task for T741: move user home to persistent storage: T6279: The root task for copying SSH keys and files from the home directory to use between updates.
Apr 29 2024, 6:24 AM · VyOS Rolling
Viacheslav added a subtask for T6279: The root task for copying SSH keys and files from the home directory to use between updates: T5455: SSH fingerprints aren't migrated to the new image on upgrade.
Apr 29 2024, 6:24 AM · VyOS Rolling
Viacheslav added a parent task for T5455: SSH fingerprints aren't migrated to the new image on upgrade: T6279: The root task for copying SSH keys and files from the home directory to use between updates.
Apr 29 2024, 6:24 AM · VyOS Rolling
Viacheslav added a subtask for T6279: The root task for copying SSH keys and files from the home directory to use between updates: T110: Ability to store SSH keys out of the config.
Apr 29 2024, 6:23 AM · VyOS Rolling
Viacheslav added a parent task for T110: Ability to store SSH keys out of the config: T6279: The root task for copying SSH keys and files from the home directory to use between updates.
Apr 29 2024, 6:23 AM · VyOS Rolling
Viacheslav added a subtask for T6279: The root task for copying SSH keys and files from the home directory to use between updates: T6275: Carry over SSH keys between images on upgrades.
Apr 29 2024, 6:22 AM · VyOS Rolling
Viacheslav added a parent task for T6275: Carry over SSH keys between images on upgrades: T6279: The root task for copying SSH keys and files from the home directory to use between updates.
Apr 29 2024, 6:22 AM · VyOS Rolling
Viacheslav created T6279: The root task for copying SSH keys and files from the home directory to use between updates.
Apr 29 2024, 6:22 AM · VyOS Rolling
kmadaras added a comment to T6275: Carry over SSH keys between images on upgrades.

I disagree, being that there's a command and associated config entry to backup config to a remote ssh server. This config option requires key based authentication. It would seem that the backup function puts this in- scope as a bug. Everyone who uses the remote configuration backup to an external ssh box is affected.

Apr 29 2024, 6:17 AM · VyOS Rolling
Viacheslav added a comment to T6275: Carry over SSH keys between images on upgrades.

It is not a bug but a feature request.
Only keys in /etc/ssh are copied. The keys in the home user directory were never copied.

Apr 29 2024, 6:12 AM · VyOS Rolling
jestabro committed rVYOSONEX9438f1f8394b: configdep: T6276: do not call dependencies on script error.
Apr 29 2024, 4:07 AM
GitHub <[email protected]> committed rVYOSONEX0c0799aa08a7: Merge pull request #3372 from jestabro/no-configdep-on-err (authored by c-po).
Apr 29 2024, 4:07 AM
jestabro added a subtask for T6176: image-tools: rationalize setting of console type: T6278: Attempt hint for console type during image install.
Apr 29 2024, 3:18 AM · VyOS 1.4 Sagitta (1.4.0-epa3)
jestabro added a parent task for T6278: Attempt hint for console type during image install: T6176: image-tools: rationalize setting of console type.
Apr 29 2024, 3:17 AM · VyOS 1.4 Sagitta (1.4.0-epa3), VyOS 1.5 Circinus
jestabro triaged T6278: Attempt hint for console type during image install as Normal priority.
Apr 29 2024, 3:17 AM · VyOS 1.4 Sagitta (1.4.0-epa3), VyOS 1.5 Circinus

Apr 28 2024

jestabro added a comment to T6276: Do not call config dependencies on script error.

PR for 1.5:
https://github.com/vyos/vyos-1x/pull/3372
Combined PRs for backport to 1.4 of T5839, T5660, T6276 pending.

Apr 28 2024, 11:59 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
syncer edited projects for T6277: 'protocols ospf interface ... passive disable' should be renamed, added: VyOS 1.5 Circinus; removed VyOS 1.4 Sagitta.
Apr 28 2024, 11:39 PM · VyOS 1.5 Circinus
syncer updated subscribers of T6275: Carry over SSH keys between images on upgrades.

@Viacheslav can you create root task maybe and we consolidate related tasks under it

Apr 28 2024, 10:54 PM · VyOS Rolling
Harliff updated the task description for T6277: 'protocols ospf interface ... passive disable' should be renamed.
Apr 28 2024, 10:03 PM · VyOS 1.5 Circinus
syncer assigned T4982: OpenConnect should have TLS 1.0 and TLS 1.1 disabled by default to Embezzle.

@Viacheslav @c-po can you guys review this PR

Apr 28 2024, 9:25 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
Harliff updated the task description for T6277: 'protocols ospf interface ... passive disable' should be renamed.
Apr 28 2024, 9:11 PM · VyOS 1.5 Circinus
Harliff created T6277: 'protocols ospf interface ... passive disable' should be renamed.
Apr 28 2024, 9:10 PM · VyOS 1.5 Circinus
Embezzle added a comment to T4982: OpenConnect should have TLS 1.0 and TLS 1.1 disabled by default.

PR: https://github.com/vyos/vyos-1x/pull/3371

Apr 28 2024, 8:05 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
jestabro added a parent task for T6276: Do not call config dependencies on script error: T5660: Remove redundant calls to config dependency scripts.
Apr 28 2024, 7:43 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
jestabro added a subtask for T5660: Remove redundant calls to config dependency scripts: T6276: Do not call config dependencies on script error.
Apr 28 2024, 7:43 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
jestabro triaged T6276: Do not call config dependencies on script error as High priority.
Apr 28 2024, 7:43 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
kmadaras added a comment to T6275: Carry over SSH keys between images on upgrades.

This would be the key's themselves and known_hosts, stored in the non-root user folder. The prompt during upgrade seems to indicate it'll copy them over. However, whenever I upgrade, I have to manually perform ssh-keygen and ssh-copy-id again for my backup server to allow my config backup to work.

Apr 28 2024, 5:45 PM · VyOS Rolling
syncer added a comment to T6275: Carry over SSH keys between images on upgrades.

we talking about athorized_keys or known_hosts?

Apr 28 2024, 3:39 PM · VyOS Rolling
Apachez created T6275: Carry over SSH keys between images on upgrades.
Apr 28 2024, 3:30 PM · VyOS Rolling
GurliGebis added a comment to T6002: When using git as config-management commit-archive, comment is not used as commit message.

You are right - I wonder why it didn't work when I tested it back then. (Most likely I forgot to write "comment")

Apr 28 2024, 8:27 AM · Invalid

Apr 27 2024

Embezzle added a comment to T6002: When using git as config-management commit-archive, comment is not used as commit message.

I explored implementing this feature, turns out it is already available.
Correct syntax for commit messages is commit comment "example message".

Apr 27 2024, 9:24 PM · Invalid
Apachez added a comment to T6209: Improve Configuration Load/Commit Speed by moving away from deep-tree flat-file backend.

Probably related: https://vyos.dev/T5388

Apr 27 2024, 11:04 AM · VyOS Rolling
syncer assigned T6209: Improve Configuration Load/Commit Speed by moving away from deep-tree flat-file backend to dmbaturin.
Apr 27 2024, 10:10 AM · VyOS Rolling
syncer closed T6268: Please delete my account as Resolved.

Your account had associated activities so as per GDPR, it was anonymized instead

Apr 27 2024, 9:42 AM
syncer closed T6271: Please delete my account as Resolved.

Your account had associated activities so as per GDPR, it was anonymized instead

Apr 27 2024, 9:42 AM
syncer updated the task description for T6271: Please delete my account.
Apr 27 2024, 9:42 AM
anon3fe35 updated anon3fe35.
Apr 27 2024, 9:39 AM
anonuser445y6 updated anonuser445y6.
Apr 27 2024, 9:38 AM
anonuser35hww45 updated anonuser35hww45.
Apr 27 2024, 9:36 AM
syncer reassigned T2192: Create common crypto library for creation/verification/management of RSA/EC/SSH keys, certificates, requests, etc. from syncer to sarthurdev.
Apr 27 2024, 5:26 AM

Apr 26 2024

GitHub <[email protected]> committed rVYOSONEXbc5e7ba65b85: Merge pull request #3370 from vyos/mergify/bp/equuleus/pr-3066 (authored by c-po).
Apr 26 2024, 6:54 PM
GitHub <[email protected]> committed rVYOSONEXf980f8b8010a: Merge pull request #3365 from vyos/mergify/bp/sagitta/pr-3316 (authored by c-po).
Apr 26 2024, 6:34 PM
c-po committed rVYOSONEXb75e0ba0a297: vyos-hostsd: T4270: resolve only hostname without domain name to 127.0.1.1.
Apr 26 2024, 6:33 PM
Mergify <37929162+mergify[bot]@users.noreply.github.com> committed rVYOSONEX1b985d2c82ec: vyos-hostsd: T4270: resolve only hostname without domain name to 127.0.1.1 (authored by c-po).
Apr 26 2024, 6:27 PM
Embezzle closed T6259: PKI: Support RFC822 (email) names in SAN as Resolved.

Tested as working in: VyOS 1.5-rolling-202404250020

Apr 26 2024, 6:03 PM · VyOS 1.5 Circinus
sarthurdev changed the status of T6257: Add op mode commands for dynamic firewall address groups from Open to Needs testing.

PR: https://github.com/vyos/vyos-1x/pull/3369

Apr 26 2024, 5:42 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
Viacheslav added a comment to T6267: Improve commit failure messages for wireless interface configuration.

PR https://github.com/vyos/vyos-1x/pull/3368

vyos@r4# compare 
[interfaces]
+ wireless wlan0 {
+     address "192.0.2.5/32"
+ }
Apr 26 2024, 3:02 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
n.fort added a comment to T6269: Polixy route "set table" option is not working correctly.

PR: https://github.com/vyos/vyos-1x/pull/3367

Apr 26 2024, 2:21 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
a.apostoliuk created T6273: Hyphens and underscores are considered invalid in PPPoE access-concentrator names.
Apr 26 2024, 1:44 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
Viacheslav assigned T2279: Router resolves as 127.0.1.1 when using Router's Recursive DNS to c-po.
Apr 26 2024, 1:44 PM · VyOS 1.4 Sagitta (1.4.0-epa3), VyOS 1.5 Circinus, VyOS 1.3 Equuleus (1.3.7)
a.apostoliuk triaged T6272: PPPoE configuration does not load after deleting a PPPoE interface from the system as High priority.
Apr 26 2024, 1:42 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
Viacheslav assigned T6271: Please delete my account to syncer.
Apr 26 2024, 1:38 PM
Viacheslav closed T6270: L2TP - Outside address as Wontfix.

It is impossible to set several addresses, but it is possible 0.0.0.0
Limits of the accel-ppp

Apr 26 2024, 1:37 PM · VyOS 1.5 Circinus
a.apostoliuk created T6272: PPPoE configuration does not load after deleting a PPPoE interface from the system.
Apr 26 2024, 1:34 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
anon3fe35 created T6271: Please delete my account.
Apr 26 2024, 1:32 PM
joseph.oshaughnessy created T6270: L2TP - Outside address .
Apr 26 2024, 1:26 PM · VyOS 1.5 Circinus
aga updated aga.
Apr 26 2024, 1:13 PM
Viacheslav triaged T6269: Polixy route "set table" option is not working correctly as Normal priority.
Apr 26 2024, 12:47 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
Viacheslav closed T4529: Backtrace for config-archive when netwofrk is not configured as Not Applicable.

looks good for VyOS 1.5-rolling-202404260019 and VyOS 1.4-stable-202404120309

vyos@r4# set system config-management commit-archive location scp://vyos:[email protected]/tmp/
vyos@r4# 
[edit]
vyos@r4# commit
Archiving config...
  scp://192.168.255.11/tmp/ Unable to upload "scp://vyos:[email protected]/tmp//config.boot-r4.vyos.local.20240426_153518": [Errno 101] Network is unreachable
run-parts: /etc/commit/post-hooks.d/02vyos-commit-archive exited with return code 1
[edit]
vyos@r4#
Apr 26 2024, 12:46 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
n.fort changed the status of T6269: Polixy route "set table" option is not working correctly from Open to In progress.
Apr 26 2024, 12:43 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
n.fort created T6269: Polixy route "set table" option is not working correctly.
Apr 26 2024, 12:43 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
Viacheslav moved T2279: Router resolves as 127.0.1.1 when using Router's Recursive DNS from Need Triage to Finished on the VyOS 1.4 Sagitta (1.4.0-epa3) board.
Apr 26 2024, 12:06 PM · VyOS 1.4 Sagitta (1.4.0-epa3), VyOS 1.5 Circinus, VyOS 1.3 Equuleus (1.3.7)
Viacheslav edited projects for T2279: Router resolves as 127.0.1.1 when using Router's Recursive DNS, added: VyOS 1.4 Sagitta (1.4.0-epa3); removed VyOS 1.4 Sagitta.
Apr 26 2024, 12:06 PM · VyOS 1.4 Sagitta (1.4.0-epa3), VyOS 1.5 Circinus, VyOS 1.3 Equuleus (1.3.7)
Viacheslav added a comment to T2279: Router resolves as 127.0.1.1 when using Router's Recursive DNS.

It looks working on VyOS 1.5-rolling-202404260019

set system domain-name 'vyos.local'
set system host-name 'r4'
set system static-host-mapping host-name r4.vyos.local inet '100.64.0.14'
Apr 26 2024, 12:05 PM · VyOS 1.4 Sagitta (1.4.0-epa3), VyOS 1.5 Circinus, VyOS 1.3 Equuleus (1.3.7)
syncer claimed T6268: Please delete my account.
Apr 26 2024, 10:46 AM
anonuser35hww45 created T6268: Please delete my account.
Apr 26 2024, 9:22 AM
Unknown Object (User) added a comment to T6264: ISO builder fails to build 1.4 because of sagitta-packages repo 403 error.

So if all packages needed are in fact the vyos-build/packages then this should be fairly simple to build and make your own APT repo off of.

Apr 26 2024, 8:49 AM · VyOS 1.4 Sagitta
Apachez added a comment to T6258: Add IPv6 base-reachable-time option to interfaces.

Perhaps those changes should be within the firewall context?

Apr 26 2024, 8:09 AM · VyOS 1.4 Sagitta (1.4.0-epa3)
adestis added a comment to T6040: Implement a firewall blacklisting solution.

Hi Giggum,
our previous solution was IPv4 only and not so nice integrated in VyOS,
therefore there are several reasons why a rework is a good idea.

Apr 26 2024, 7:28 AM · VyOS Rolling
Viacheslav added a comment to T6258: Add IPv6 base-reachable-time option to interfaces.

Im thinking since sysctl can be changed after the system have completed its boot shouldnt the "system sysctl" be runned among the last tasks according to "/usr/libexec/vyos/priority.py", which would also fix this issue ?

Apr 26 2024, 6:45 AM · VyOS 1.4 Sagitta (1.4.0-epa3)
Giggum added a comment to T6040: Implement a firewall blacklisting solution.

@adestis did your previous solution account for non-IP address characters in a given blocklist? For example the https://www.spamhaus.org/drop/dropv6.txt list has a bunch of stuff that would need to be ignored.

Apr 26 2024, 2:06 AM · VyOS Rolling

Apr 25 2024

Apachez added a comment to T6258: Add IPv6 base-reachable-time option to interfaces.

Im thinking since sysctl can be changed after the system have completed its boot shouldnt the "system sysctl" be runned among the last tasks according to "/usr/libexec/vyos/priority.py", which would also fix this issue ?

Apr 25 2024, 10:22 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
marekm added a comment to T6264: ISO builder fails to build 1.4 because of sagitta-packages repo 403 error.

If all of this would be done by the build script (download sources, apply patches, build binary packages and copy them to a local filesystem) there would be no problem.
I can't even see the list of packages in that 403 Forbidden repo - all of it blocked completely, not just access to binary packages.

Apr 25 2024, 6:45 PM · VyOS 1.4 Sagitta
syncer added a comment to T6264: ISO builder fails to build 1.4 because of sagitta-packages repo 403 error.

Good.
So, all code is in github.
you need to spend bit of time and learn how to build packages and make them into repo
after you point vyos-build to that repo and good to go
it's time consuming, but once you have set it up, after it will not require that much time

Apr 25 2024, 5:53 PM · VyOS 1.4 Sagitta
Viacheslav moved T6263: Commit failures when trying to set an IGMP group with source address on an interface from Need Triage to Finished on the VyOS 1.4 Sagitta (1.4.0-epa3) board.
Apr 25 2024, 5:46 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
Viacheslav closed T6263: Commit failures when trying to set an IGMP group with source address on an interface as Resolved.
Apr 25 2024, 5:46 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
GitHub <[email protected]> committed rVYOSONEX854864f0dffe: Merge pull request #3366 from vyos/mergify/bp/sagitta/pr-3363 (authored by c-po).
Apr 25 2024, 5:45 PM
GitHub <[email protected]> committed rVYOSONEX9291c34a301c: Merge pull request #3362 from vyos/mergify/bp/sagitta/pr-3361 (authored by c-po).
Apr 25 2024, 5:37 PM
Mergify <37929162+mergify[bot]@users.noreply.github.com> committed rVYOSONEX7824097396ca: T6263: Groups 224.0.0.0/24 are reserved and cannot be joined (authored by Viacheslav).
Apr 25 2024, 5:37 PM