Page MenuHomeVyOS Platform
Feed All Stories

Today

cv0759 created T9384: `show pppoe-server sessions` uptime format is ambiguous (`1.06:16:20` vs `15:42:11`).
Thu, Oct 1, 2:35 PM · VyOS Rolling
cv0759 created T9383: Default `/var/log/messages` rotation keeps only ~24h, making intermittent faults undiagnosable.
Thu, Oct 1, 2:34 PM · VyOS Rolling
cv0759 created T9382: PPPoE server default LCP echo settings (10s interval x 3 failures = 30s) cause spurious session teardown.
Thu, Oct 1, 2:34 PM · VyOS Rolling
cv0759 created T9381: Suricata on pre-SSE4.2 CPUs dies with SIGILL and enters a restart loop.
Thu, Oct 1, 2:33 PM · VyOS Rolling
cv0759 created T9380: `qos policy cake` without `bandwidth` is silently applied as `unlimited` and causes packet loss.
Thu, Oct 1, 2:33 PM · VyOS Rolling
a.kudientsov created T9379: policy: prefix-list duplicate check is quadratic.
Thu, Oct 1, 2:33 PM · VyOS Rolling
cv0759 created T9378: `load` silently drops unknown/invalid configuration nodes (no error, service keeps running).
Thu, Oct 1, 2:32 PM · VyOS Rolling
a.kudientsov created T9377: frr: policy commits wait for bgpd's route-map walk on large FRR configs.
Thu, Oct 1, 2:30 PM · VyOS Rolling
ordex added a comment to T9370: openvpn: add support for cipher 'chacha-poly' in the CLI.

PR: https://github.com/vyos/vyos-1x/pull/5523
doc PR: https://github.com/vyos/vyos-documentation/pull/2324

Thu, Oct 1, 2:25 PM · VyOS Rolling
a.kudientsov created T9376: vyatta-cfg: boot and load are quadratic in the number of values of a tag node.
Thu, Oct 1, 2:22 PM · VyOS Rolling
a.kudientsov created T9375: vyos1x-config: duplicate-children check re-sorts the list on every step.
Thu, Oct 1, 2:19 PM · VyOS Rolling
jestabro claimed T9374: vyos1x-config: config parsing is cubic in the number of entries in one list.
Thu, Oct 1, 2:16 PM · VyOS Rolling
a.kudientsov created T9374: vyos1x-config: config parsing is cubic in the number of entries in one list.
Thu, Oct 1, 2:15 PM · VyOS Rolling
evgmol created T9373: Ansible repositories maintenance, October, 2026.
Thu, Oct 1, 12:03 PM · VyOS Ansible Collection
rherold created T9372: webproxy: several url-filtering options are accepted by the CLI but never used.
Thu, Oct 1, 9:31 AM · VyOS Rolling
rherold claimed T9371: webproxy: typo "!ocal-block-url-" in squidGuard.conf.j2.

PR https://github.com/vyos/vyos-1x/pull/5522

Thu, Oct 1, 9:30 AM · VyOS Rolling
rherold created T9371: webproxy: typo "!ocal-block-url-" in squidGuard.conf.j2.
Thu, Oct 1, 9:19 AM · VyOS Rolling
ordex created T9370: openvpn: add support for cipher 'chacha-poly' in the CLI.
Thu, Oct 1, 12:35 AM · VyOS Rolling

Yesterday

ordex added a comment to T8264: Upgrade OpenVPN to version 2.7 along with new 'ovpn' kernel module.

@mrpops2ko FYI the MTU problem I described was addressed in https://vyos.dev/T9364 . Can you give the latest rolling another try, if have a chance to?
In any case, please report any faulty findings in a new task, so we can take it from there.

Wed, Sep 30, 11:56 PM · VyOS Rolling
eli-sterling added a comment to T7337: Documentation for as-path-list regular expressions.

We reviewed this issue and are planning to submit a documentation pull request for it this afternoon.

Wed, Sep 30, 6:16 PM · VyOS 1.5 Circinus
eli-sterling added a comment to T7371: VyOS DHCP Server shared-network concept and behaviour is not properly documented.

We reviewed this issue and are planning to submit a documentation pull request for it this afternoon.

Wed, Sep 30, 6:16 PM · VyOS Rolling
c-po closed T9364: openvpn: set MTU to a reasonable default when enabling DCO as Resolved.
Wed, Sep 30, 6:13 PM · VyOS Rolling
c-po closed T9337: OpenVPN site-to-site: "keep-alive interval 0" leaves ping-restart armed and flaps an idle tunnel as Resolved.
Wed, Sep 30, 6:01 PM · VyOS Rolling
eli-sterling added a comment to T9089: vyos-api docs: document /retrieve showConfig behavior on empty or missing subtrees (HTTP 400).

Verification update: the current rolling API guide documents that showConfig returns HTTP 400 when a schema-valid path has no configuration, gives the "Configuration under specified path is empty" response, and recommends checking exists first or treating that exact error as empty configuration: https://github.com/vyos/vyos-documentation/blob/rolling/docs/automation/vyos-api.md#retrieve. This guidance appears in commit https://github.com/vyos/vyos-documentation/commit/3a952350bf5b5b38a7db1208ed3c910ded7b4b24. This appears to address T9089. Suggested status: Resolved if the task author or a maintainer confirms the documentation meets scope.

Wed, Sep 30, 5:48 PM · VyOS Rolling
eli-sterling added a comment to T9088: vyos-api docs: document /show with path ["configuration","commands"] (set-command export).

Verification update: the current rolling API guide documents /show with path ["configuration", "commands"] as exporting the running configuration to flat set commands, and includes an example response: https://github.com/vyos/vyos-documentation/blob/rolling/docs/automation/vyos-api.md#show. This guidance appears in commit https://github.com/vyos/vyos-documentation/commit/ca902d4eebd49697f476d538eadfcaeb8ebb2232. This appears to address T9088. Suggested status: Resolved if the task author or a maintainer confirms the documentation meets scope.

Wed, Sep 30, 5:48 PM · VyOS Rolling
eli-sterling added a comment to T9087: vyos-api docs: document commit atomicity — multi-field nodes must be set in one /configure request.

Verification update: the current rolling API guide states that each /configure request is committed immediately and that fields of a single configuration node must be included in the same request. It gives task-scheduler, NAT, and firewall examples plus related validation errors: https://github.com/vyos/vyos-documentation/blob/rolling/docs/automation/vyos-api.md#configure. This guidance appears in commit https://github.com/vyos/vyos-documentation/commit/0b88b491d043e5f281d8e3ae499c4d045da28f28. This appears to address T9087. Suggested status: Resolved if the task author or a maintainer confirms the documentation meets scope.

Wed, Sep 30, 5:48 PM · VyOS Rolling
eli-sterling added a comment to T9092: vyos-api docs: add operational guidance for large configuration applies (batch sizes, geoip cost, body-size limit).

Review update: T9092 appears partially completed in the current rolling API guide. Its Bulk configuration section covers moderate-sized batches, reconciling state after request timeouts, applying geoip/remote-group operations one per request, the default 1 MB request-body limit, and commit-confirm as a safeguard: https://github.com/vyos/vyos-documentation/blob/rolling/docs/automation/vyos-api.md#bulk-configuration. This guidance was added in commit https://github.com/vyos/vyos-documentation/commit/af04731c74b0383bc36c66addd6cc22ba41c55e0. The task also asks to direct bulk-apply users to the REST API background configure operations; I could not find that guidance in the current API guide. Suggest keeping T9092 open until that point is documented or the reporter confirms it is unnecessary.

Wed, Sep 30, 5:43 PM · VyOS Rolling
eli-sterling added a comment to T9091: vyos-api docs: document error semantics of batched /configure arrays (failing op not identified).

Verification update: the current rolling API guide documents the batched /configure failure semantics: failed operations do not commit changes for that component, cross-component partial commits are possible, and errors identify the component and missing information or conflict. See https://github.com/vyos/vyos-documentation/blob/rolling/docs/automation/vyos-api.md#configure. The documentation was added in https://github.com/vyos/vyos-documentation/commit/f002549a5fe3ae782be8fe02160fa2796e7e0471 and its atomicity/error wording was refined in https://github.com/vyos/vyos-documentation/commit/4631db6a1578550dd4c1410a8416575899f36936. This appears to address the task's core documentation gap. The current guide does not promise an exact failing-operation index/path or recommend bisecting a failed batch; if that remains part of the requested scope, T9091 may need to stay open or that API behavior could be tracked separately. Suggested status: Resolved if the reporter/maintainer agrees the documentation meets scope; otherwise keep open for the remaining error-location guidance.

Wed, Sep 30, 5:39 PM · VyOS Rolling
eli-sterling added a comment to T9090: vyos-api docs: clarify that save works on /config-file, not /configure.

Verification update: the current rolling API guide now warns in the /configure section that this endpoint does not accept {"op":"save"} and directs users to /config-file: https://github.com/vyos/vyos-documentation/blob/rolling/docs/automation/vyos-api.md#configure. This guidance is present in commit f002549a5fe3ae782be8fe02160fa2796e7e0471 (https://github.com/vyos/vyos-documentation/commit/f002549a5fe3ae782be8fe02160fa2796e7e0471), dated July 14, 2026, titled "vyos-api: T9090: T9091: batched /configure semantics; save via /config-file". This appears to address T9090. Suggested status: move from Open / Need Triage to Resolved, if the reporter or maintainer confirms.

Wed, Sep 30, 5:35 PM · VyOS Rolling
Apachez created T9369: Add timezone as variable for containers (podman).
Wed, Sep 30, 9:24 AM · VyOS Rolling
c-po added a comment to T9368: frr: commit silently skips the FRR reload when a DHCP lease event collides with it.

https://github.com/vyos/vyos-1x/pull/5520

Wed, Sep 30, 4:56 AM · VyOS Rolling
c-po claimed T9368: frr: commit silently skips the FRR reload when a DHCP lease event collides with it.
Wed, Sep 30, 4:52 AM · VyOS Rolling
c-po created T9368: frr: commit silently skips the FRR reload when a DHCP lease event collides with it.
Wed, Sep 30, 4:52 AM · VyOS Rolling

Tue, Sep 29

c-po added a comment to T9367: smoketest: vrf: only assert on the leaked flows in the VRF conntrack zone.

https://github.com/vyos/vyos-1x/pull/5518

Tue, Sep 29, 6:46 PM · VyOS Rolling
c-po added a subtask for T6097: vrf_zones blocking ipv6 traffic: T9367: smoketest: vrf: only assert on the leaked flows in the VRF conntrack zone.
Tue, Sep 29, 6:15 PM · VyOS Rolling, VyOS 1.5 Circinus
c-po added a parent task for T9367: smoketest: vrf: only assert on the leaked flows in the VRF conntrack zone: T6097: vrf_zones blocking ipv6 traffic.
Tue, Sep 29, 6:15 PM · VyOS Rolling
c-po changed the status of T9367: smoketest: vrf: only assert on the leaked flows in the VRF conntrack zone from Open to In progress.
Tue, Sep 29, 6:15 PM · VyOS Rolling
c-po created T9367: smoketest: vrf: only assert on the leaked flows in the VRF conntrack zone.
Tue, Sep 29, 6:15 PM · VyOS Rolling
RC added a comment to T9351: Accel-PPP: RADIUS: Add Message-Authenticator attribute support for Access packets (Blast-RADIUS mitigation).

Accel-ppp-ng : https://github.com/accel-ppp/accel-ppp-ng/pull/39
vyos-1x CLI: https://github.com/vyos/vyos-1x/pull/5442

Tue, Sep 29, 5:07 PM · VyOS Rolling
ordex added a comment to T9364: openvpn: set MTU to a reasonable default when enabling DCO.

documentation PR: https://github.com/vyos/vyos-documentation/pull/2260

Tue, Sep 29, 11:38 AM · VyOS Rolling
xTITUS_MAXIMUSx added a comment to T9284: dhcp6c integer overflow / garbage value in pltime causes vyos-netlinkd loop and loss of connectivity.

I tried to reproduce this on 2026.09.23-0027-rolling (wide-dhcpv6-client 20080615-23). On a test link, Kea handed out an IA_NA address and a /48 IA_PD with pltime 3000 / vltime 4000 and T1=20, and radvd sent RAs on the same link.

Tue, Sep 29, 12:50 AM · VyOS Rolling

Mon, Sep 28

xTITUS_MAXIMUSx added a comment to T8461: kea: DHCPv4 ip allocation issue on vlan interfaces.

Reproduced this on rolling with Kea 3.0.3-vyos.

Mon, Sep 28, 11:04 PM · VyOS 1.5 Circinus (Circinus-Next), VyOS Rolling
xTITUS_MAXIMUSx added a comment to T9299: FRR stale route issue following Accel-PPP L2TP session reconnection.

https://github.com/vyos/vyos-1x/pull/5510

Mon, Sep 28, 10:21 PM · VyOS Rolling
ordex added a comment to T9364: openvpn: set MTU to a reasonable default when enabling DCO.

PR: https://github.com/vyos/vyos-1x/pull/5515

Mon, Sep 28, 7:54 PM · VyOS Rolling
c-po added a comment to T5388: Something is fishy with commit and boot times when more than a few hundred static routes are being used.

There is a POC migrationg to overlayfs https://github.com/vyos/vyos-build/pull/1311 and see linked PRs

Mon, Sep 28, 7:08 PM · VyOS Rolling, Bugs
graybeard5x created T9366: FRR routes get out of sync with PPPoE server.
Mon, Sep 28, 6:49 PM · VyOS Rolling
c-po closed T6528: Move from fuse-overlayfs to native rootless overlay storage as Resolved.
Mon, Sep 28, 6:30 PM · VyOS Rolling
c-po added a comment to T6528: Move from fuse-overlayfs to native rootless overlay storage.

This has been implemented for quit some time

Mon, Sep 28, 6:30 PM · VyOS Rolling
jestabro created T9365: Expose path utils to get reference tree paths from config or partial path.
Mon, Sep 28, 2:35 PM · VyOS Rolling
ordex created T9364: openvpn: set MTU to a reasonable default when enabling DCO.
Mon, Sep 28, 1:51 PM · VyOS Rolling
ordex added a comment to T9363: openvpn: site2site failure-count is not rendered properly.

PR: https://github.com/vyos/vyos-1x/pull/5512

Mon, Sep 28, 12:38 PM · VyOS Rolling
ordex created T9363: openvpn: site2site failure-count is not rendered properly.
Mon, Sep 28, 11:45 AM · VyOS Rolling
ordex added a comment to T9337: OpenVPN site-to-site: "keep-alive interval 0" leaves ping-restart armed and flaps an idle tunnel.

PR: https://github.com/vyos/vyos-1x/pull/5511

Mon, Sep 28, 9:35 AM · VyOS Rolling
MSonger added a comment to T9274: Add more telegraf configuration.

This PR has been merged

Mon, Sep 28, 9:00 AM · VyOS Rolling

Sun, Sep 27

c-po added a comment to T9361: Remove debug noise when running config load tests.

https://github.com/vyos/vyos-1x/pull/5508

Sun, Sep 27, 7:20 PM · VyOS Rolling
c-po added a comment to T9362: pim: prevent killing an already dead/non-existing PID.

https://github.com/vyos/vyos-1x/pull/5509

Sun, Sep 27, 7:20 PM · VyOS Rolling
c-po triaged T9362: pim: prevent killing an already dead/non-existing PID as Low priority.
Sun, Sep 27, 7:14 PM · VyOS Rolling
c-po claimed T9362: pim: prevent killing an already dead/non-existing PID.
Sun, Sep 27, 7:14 PM · VyOS Rolling
c-po created T9362: pim: prevent killing an already dead/non-existing PID.
Sun, Sep 27, 7:14 PM · VyOS Rolling
c-po changed the status of T9361: Remove debug noise when running config load tests from Open to In progress.
Sun, Sep 27, 7:08 PM · VyOS Rolling
c-po created T9361: Remove debug noise when running config load tests.
Sun, Sep 27, 7:08 PM · VyOS Rolling
c-po changed the status of T9360: BGP: ORF send + receive causes unnecessary session resets on unrelated policy commits from Open to In progress.
Sun, Sep 27, 6:03 PM · VyOS Rolling
t.shiroma added a comment to T9360: BGP: ORF send + receive causes unnecessary session resets on unrelated policy commits.

I made a pull-req on https://github.com/vyos/vyos-1x/pull/5507 .

Sun, Sep 27, 9:45 AM · VyOS Rolling
t.shiroma created T9360: BGP: ORF send + receive causes unnecessary session resets on unrelated policy commits.
Sun, Sep 27, 8:13 AM · VyOS Rolling
t.shiroma added a comment to T9345: BGP: Unsupported address families in named VRFs bypass configuration validation.

I've confirmed that the pull request has been merged, so I'll mark this ticket as Resolved. Thank you!

Sun, Sep 27, 6:31 AM · VyOS Rolling
xTITUS_MAXIMUSx added a comment to T9303: VPP IPsec algorithm-compatibility check ignored.

This has been fixed with this PR https://github.com/vyos/vyos-1x/pull/5495

Sun, Sep 27, 12:16 AM · VyOS Rolling

Sat, Sep 26

c-po added a comment to T8859: `verify_diffie_hellman_length()` does not protect `int(min_keysize)` and has unused `keysize` variable.

Coder merged and removed as there are no real world callers anymore.

Sat, Sep 26, 7:12 PM
c-po closed T8859: `verify_diffie_hellman_length()` does not protect `int(min_keysize)` and has unused `keysize` variable as Not Applicable.
Sat, Sep 26, 7:11 PM
rockenbah created T9359: VTI (xfrm) interfaces always report operstate UNKNOWN — Prometheus `node_network_up` is 0 for every VTI even when the tunnel is up.
Sat, Sep 26, 5:51 PM · VyOS Rolling
rockenbah created T9358: IPsec site-to-site (connection-type initiate): tunnel stays down after peer answers NO_PROPOSAL_CHOSEN — no automatic retry despite keyingtries = 0.
Sat, Sep 26, 5:45 PM · VyOS Rolling
c-po assigned T8859: `verify_diffie_hellman_length()` does not protect `int(min_keysize)` and has unused `keysize` variable to syncer.
Sat, Sep 26, 5:10 PM
c-po closed T9326: WWAN dual-stack (ipv4v6) connect fails with ip-version-mismatch on networks requiring a single combined PDN context as Resolved.
Sat, Sep 26, 7:42 AM · VyOS Rolling
c-po added a comment to T9356: PPPoE: traceback if IPv6 is unavailable on BRAS.

https://github.com/vyos/vyos-1x/pull/5504

Sat, Sep 26, 6:34 AM · VyOS Rolling
c-po added a comment to T9357: pppoe-server requires local username to be set even when any-login is in use.

https://github.com/vyos/vyos-1x/pull/5505

Sat, Sep 26, 6:33 AM · VyOS Rolling
c-po changed Is it a breaking change? from none to compatible on T9356: PPPoE: traceback if IPv6 is unavailable on BRAS.
Sat, Sep 26, 6:20 AM · VyOS Rolling
c-po claimed T9357: pppoe-server requires local username to be set even when any-login is in use.
Sat, Sep 26, 6:20 AM · VyOS Rolling
c-po created T9357: pppoe-server requires local username to be set even when any-login is in use.
Sat, Sep 26, 6:20 AM · VyOS Rolling
c-po changed Version from 2026.09.25-1909-integration to 2026.09.25-1909-integration, 1.5.1, 1.4.5 on T9356: PPPoE: traceback if IPv6 is unavailable on BRAS.
Sat, Sep 26, 6:11 AM · VyOS Rolling
c-po changed the status of T9356: PPPoE: traceback if IPv6 is unavailable on BRAS from Open to In progress.
Sat, Sep 26, 6:00 AM · VyOS Rolling
c-po created T9356: PPPoE: traceback if IPv6 is unavailable on BRAS.
Sat, Sep 26, 6:00 AM · VyOS Rolling
rockenbah created T9355: blackbox-exporter: ICMP probes always fail ("socket: operation not permitted") — service runs unprivileged without CAP_NET_RAW.
Sat, Sep 26, 2:17 AM · VyOS Rolling

Fri, Sep 25

c-po triaged T9327: Add native support for NAT64 session synchronization (joold) as Wishlist priority.
Fri, Sep 25, 7:19 PM · VyOS Rolling
c-po triaged T9352: HAproxy: Enable transparent proxing as Wishlist priority.
Fri, Sep 25, 7:19 PM · VyOS Rolling
c-po changed the status of T9354: op-mode: replace "reset connection" with "reconnect interface" from Open to In progress.
Fri, Sep 25, 7:19 PM · VyOS Rolling
c-po added a comment to T9354: op-mode: replace "reset connection" with "reconnect interface".

https://github.com/vyos/vyos-1x/pull/5503

Fri, Sep 25, 7:04 PM · VyOS Rolling
c-po created T9354: op-mode: replace "reset connection" with "reconnect interface".
Fri, Sep 25, 7:01 PM · VyOS Rolling
c-po triaged T9347: telegraf: add vyos_system_image metric for monitor image version as Wishlist priority.
Fri, Sep 25, 5:52 PM · VyOS Rolling
c-po triaged T9336: Remote syslog server defined by FQDN fails to work when configured in a non-default VRF as Normal priority.
Fri, Sep 25, 5:51 PM · VyOS Rolling
c-po changed the status of T9338: mpls inter-as - l3vpn-multi-domain-switching from Open to In progress.
Fri, Sep 25, 5:51 PM · VyOS Rolling
c-po changed the status of T9332: GeoIP source/destination nftables set collision from Open to In progress.
Fri, Sep 25, 5:50 PM · VyOS Rolling
c-po changed the status of T9345: BGP: Unsupported address families in named VRFs bypass configuration validation from Open to In progress.
Fri, Sep 25, 5:50 PM · VyOS Rolling
c-po closed T9344: frr: remove code path when vyos-configd is not running as Resolved.
Fri, Sep 25, 5:49 PM · VyOS Rolling
Apachez added a comment to T9353: Interface speed & duplex modes are hardcoded to anything BaseT.

Shouldnt the comment with examples at line 219 be updated aswell?

Fri, Sep 25, 5:14 PM · VyOS Rolling
c-po added a comment to T9060: pppoe: spurious synthetic EUI64 /64 link-local address breaks DHCPv6-PD.

Interface nicely shows the one only link local address

Fri, Sep 25, 4:35 PM · VyOS Rolling
c-po closed T9060: pppoe: spurious synthetic EUI64 /64 link-local address breaks DHCPv6-PD as Resolved.
Fri, Sep 25, 4:34 PM · VyOS Rolling
c-po closed T9349: dhcpv6-client: do not start dhcp6c in debug mode as Resolved.
Fri, Sep 25, 4:32 PM · VyOS Rolling
natali-rs1985 added a comment to T6304: Rewrite commit-archive to more structured CLI format.

https://github.com/vyos/vyos-1x/pull/5502

Fri, Sep 25, 2:00 PM · VyOS Rolling
_mrplow added a comment to T9353: Interface speed & duplex modes are hardcoded to anything BaseT.

PR 5501 created.

Fri, Sep 25, 12:34 PM · VyOS Rolling
_mrplow created T9353: Interface speed & duplex modes are hardcoded to anything BaseT.
Fri, Sep 25, 10:47 AM · VyOS Rolling
haakon.nore changed the status of T9319: VXLAN: expose the Group Policy extension through a gbp CLI node from Open to In progress.

VXLAN-GBP support has been merged into rolling via https://github.com/vyos/vyos-1x/pull/5484.
Documentation remains open and awaiting review: https://github.com/vyos/vyos-documentation/pull/2248. It covers configuration, limitations, and a firewall example.

Fri, Sep 25, 6:51 AM · VyOS Rolling