Page MenuHomeVyOS Platform
Feed All Stories

Sep 8 2023

Viacheslav added a reverting change for rVYOSONEX7a99a59b338f: Create build.yml: rVYOSONEXa0e3d29ee33e: Revert "Create build.yml".
Sep 8 2023, 10:37 AM
n.fort closed T4356: DHCP v6 client only supports single interface configuration as Resolved.

I'm closing this one. No news in the last year, and the tests I've done last month were ok.

Sep 8 2023, 10:12 AM · VyOS 1.4 Sagitta
n.fort closed T5450: Firewall interface group - Allow inverted matcher as Resolved.
Sep 8 2023, 10:04 AM · VyOS 1.4 Sagitta
n.fort closed T5460: Firewall - remove config-trap as Resolved.
Sep 8 2023, 10:04 AM · VyOS 1.4 Sagitta
n.fort closed T5502: Firewall - wrong parser for inbound and/or outbound interface as Resolved.
Sep 8 2023, 10:03 AM · VyOS 1.4 Sagitta
n.fort changed the status of T4072: Feature Request: Firewall on bridge interfaces from Open to In progress.
Sep 8 2023, 10:02 AM · VyOS 1.4 Sagitta
n.fort changed the status of T5553: Firewall - Add action continue from Confirmed to In progress.
Sep 8 2023, 10:01 AM · VyOS 1.4 Sagitta
n.fort added a comment to T5553: Firewall - Add action continue.

Feature included in: https://github.com/vyos/vyos-1x/pull/2222

Sep 8 2023, 10:01 AM · VyOS 1.4 Sagitta
unity closed T5560: VyOS version in current branch should be changed from 1.4 to 1.5 as Resolved.

The PR is merged

Sep 8 2023, 9:28 AM · VyOS 1.5 Circinus
Viacheslav added a project to T5559: Selective proxy-arp/proxy-ndp when doing SNAT/DNAT: VyOS 1.5 Circinus.
Sep 8 2023, 9:00 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
unity changed the status of T5560: VyOS version in current branch should be changed from 1.4 to 1.5 from Open to In progress.

PR is created https://github.com/vyos/vyos-build/pull/394

Sep 8 2023, 8:49 AM · VyOS 1.5 Circinus
unity created T5560: VyOS version in current branch should be changed from 1.4 to 1.5.
Sep 8 2023, 8:44 AM · VyOS 1.5 Circinus
Apachez updated the task description for T5559: Selective proxy-arp/proxy-ndp when doing SNAT/DNAT.
Sep 8 2023, 6:17 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
Apachez created T5559: Selective proxy-arp/proxy-ndp when doing SNAT/DNAT.
Sep 8 2023, 5:54 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
jestabro committed rVYOSONEX302c264ece7d: save-config: T5551: check if None before write, as is the case at boot.
Sep 8 2023, 5:33 AM
GitHub <[email protected]> committed rVYOSONEXbf287c6ef35f: Merge pull request #2207 from jestabro/T5551-sagitta (authored by c-po).
Sep 8 2023, 5:33 AM
sarthurdev committed rVYOSONEX56a6e53f78f1: smoketest: T5558: Extend configtest to allow checking of migration script….
Sep 8 2023, 5:32 AM
GitHub <[email protected]> committed rVYOSONEXc57a519ea9af: Merge pull request #2221 from sarthurdev/configtest_extend (authored by c-po).
Sep 8 2023, 5:32 AM
jestabro added a comment to T5353: config-mgmt: normalize archive updates and commit log entries.

Sagitta PR updated with fix for regression in T5556.

Sep 8 2023, 12:58 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
jestabro added a subtask for T5353: config-mgmt: normalize archive updates and commit log entries: T5556: reboot now and poweroff does not work.
Sep 8 2023, 12:57 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
jestabro added a parent task for T5556: reboot now and poweroff does not work: T5353: config-mgmt: normalize archive updates and commit log entries.
Sep 8 2023, 12:57 AM · VyOS 1.5 Circinus

Sep 7 2023

n.fort added a comment to T4072: Feature Request: Firewall on bridge interfaces.

PR: https://github.com/vyos/vyos-1x/pull/2222

Sep 7 2023, 8:47 PM · VyOS 1.4 Sagitta
jestabro closed T5412: Add support for extending config-mode dependencies in supplemental package, a subtask of T4820: Support for inter-config-mode script dependencies, as Unknown Status.
Sep 7 2023, 8:21 PM · VyOS 1.4 Sagitta
jestabro closed T5412: Add support for extending config-mode dependencies in supplemental package, a subtask of T5403: Add support for extending xml cache , as Unknown Status.
Sep 7 2023, 8:21 PM · VyOS 1.4 Sagitta
jestabro closed T5412: Add support for extending config-mode dependencies in supplemental package as Unknown Status.
Sep 7 2023, 8:21 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
jestabro closed T5556: reboot now and poweroff does not work as Resolved.

The logic error is fixed in commit above: updates work as expected, and all smoketests (but for unrelated test) pass.

Sep 7 2023, 8:10 PM · VyOS 1.5 Circinus
sarthurdev changed the status of T5558: Update config test to check resulting migrations from In progress to Needs testing.

PR: https://github.com/vyos/vyos-1x/pull/2221

Sep 7 2023, 7:36 PM · VyOS 1.5 Circinus
jestabro committed rVYOSONEXfd5517b38191: config-mgmt: T5556: fix bug in revision to archive update.
Sep 7 2023, 6:34 PM
Apachez closed T5489: Change to BBR as TCP congestion control, or at least make it an config option as Resolved.

Using VyOS 1.4-rolling-202309070021.

Sep 7 2023, 6:30 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
jestabro added a comment to T5556: reboot now and poweroff does not work.

Not as such: this is a logic error in T5353, which will be fixed momentarily. Nonetheless, T5514 is worthwhile to consider.

Sep 7 2023, 5:53 PM · VyOS 1.5 Circinus
sarthurdev moved T5558: Update config test to check resulting migrations from Open to In Progress on the VyOS 1.5 Circinus board.
Sep 7 2023, 5:53 PM · VyOS 1.5 Circinus
sarthurdev changed the status of T5558: Update config test to check resulting migrations from Open to In progress.
Sep 7 2023, 5:53 PM · VyOS 1.5 Circinus
Apachez added a comment to T5556: reboot now and poweroff does not work.

Related to https://vyos.dev/T5514 ?

Sep 7 2023, 5:49 PM · VyOS 1.5 Circinus
Viacheslav added a comment to T5554: Disable sudo for PAM RADIUS.

For 1.4 add session [default=ignore success=2] pam_succeed_if.so service = sudo to /etc/pam.d/common-session-noninteractive fixes the issue

# here are the per-package modules (the "Primary" block)
session [default=1]                     pam_permit.so
# here's the fallback if no module succeeds
session requisite                       pam_deny.so
# prime the stack with a positive return value if there isn't one already;
# this avoids us returning an error just because nothing sets a success code
# since the modules above will each just jump around
session required                        pam_permit.so
# and here are more per-package modules (the "Additional" block)
session required        pam_mkhomedir.so umask=0022 skel=/etc/skel
session [default=ignore success=2] pam_succeed_if.so service = sudo
session [default=ignore success=ignore] pam_succeed_if.so user ingroup aaa quiet
session [authinfo_unavail=ignore success=ok default=ignore] pam_radius_auth.so
session required        pam_unix.so
# end of pam-auth-update config
Sep 7 2023, 4:02 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
Viacheslav edited projects for T5555: Fix timezone migrator (system 13-to-14), added: VyOS 1.3 Equuleus (1.3.4); removed VyOS 1.3 Equuleus (1.3.5).
Sep 7 2023, 3:13 PM · VyOS 1.3 Equuleus (1.3.4), VyOS 1.5 Circinus, VyOS 1.4 Sagitta
jestabro committed rVYOSONEX0869b91c0b15: conf-mode: T5412: add script for add-on package check of dependencies.
Sep 7 2023, 3:07 PM
jestabro committed rVYOSONEXd9ad551816e3: conf-mode: T5412: add support for supplemental dependency definitions.
Sep 7 2023, 3:07 PM
jestabro committed rVYOSONEX12440ea1af8e: conf-mode: T5412: move dependency check from smoketest to nosetest.
Sep 7 2023, 3:06 PM
GitHub <[email protected]> committed rVYOSONEX73ee99fac6c6: Merge pull request #2216 from jestabro/ext-dependency (authored by c-po).
Sep 7 2023, 3:06 PM
sarthurdev committed rVYOSONEXb357b70647c9: system: T5555: Fix time-zone migrator changing valid time-zones to UTC.
Sep 7 2023, 3:06 PM
GitHub <[email protected]> committed rVYOSONEX8d11722f1829: Merge pull request #2219 from sarthurdev/T5555_equuleus (authored by c-po).
Sep 7 2023, 3:06 PM
sarthurdev committed rVYOSONEXd1edbfd18e71: system: T5555: Fix time-zone migrator changing valid time-zones to UTC.
Sep 7 2023, 2:17 PM
GitHub <[email protected]> committed rVYOSONEX0fcf2cbcfcab: Merge pull request #2218 from sarthurdev/T5555_sagitta (authored by c-po).
Sep 7 2023, 2:17 PM
sarthurdev committed rVYOSONEXc85095572c0a: system: T5555: Fix time-zone migrator changing valid time-zones to UTC.
Sep 7 2023, 2:16 PM
GitHub <[email protected]> committed rVYOSONEX05dd8edcae53: Merge pull request #2217 from sarthurdev/T5555 (authored by c-po).
Sep 7 2023, 2:16 PM
c-po added a comment to T5557: bgp: Use treat-as-withdraw for tunnel encapsulation attribute CVE-2023-38802.

1.4 running FRR9 is already mitigated

Sep 7 2023, 2:14 PM · VyOS 1.3 Equuleus (1.3.4)
c-po claimed T5557: bgp: Use treat-as-withdraw for tunnel encapsulation attribute CVE-2023-38802.
Sep 7 2023, 2:13 PM · VyOS 1.3 Equuleus (1.3.4)
c-po created T5557: bgp: Use treat-as-withdraw for tunnel encapsulation attribute CVE-2023-38802.
Sep 7 2023, 2:13 PM · VyOS 1.3 Equuleus (1.3.4)
jestabro triaged T5556: reboot now and poweroff does not work as Urgent! priority.

Logic error in recent bug fix; correction is being checked ...

Sep 7 2023, 1:37 PM · VyOS 1.5 Circinus
sarthurdev moved T5555: Fix timezone migrator (system 13-to-14) from Need Triage to In Progress on the VyOS 1.3 Equuleus (1.3.5) board.
Sep 7 2023, 1:13 PM · VyOS 1.3 Equuleus (1.3.4), VyOS 1.5 Circinus, VyOS 1.4 Sagitta
sarthurdev moved T5555: Fix timezone migrator (system 13-to-14) from Open to In Progress on the VyOS 1.5 Circinus board.
Sep 7 2023, 1:13 PM · VyOS 1.3 Equuleus (1.3.4), VyOS 1.5 Circinus, VyOS 1.4 Sagitta
sarthurdev moved T5555: Fix timezone migrator (system 13-to-14) from Open to In Progress on the VyOS 1.4 Sagitta board.
Sep 7 2023, 1:13 PM · VyOS 1.3 Equuleus (1.3.4), VyOS 1.5 Circinus, VyOS 1.4 Sagitta
sarthurdev changed the status of T5555: Fix timezone migrator (system 13-to-14) from In progress to Needs testing.

current PR: https://github.com/vyos/vyos-1x/pull/2217
1.4 PR: https://github.com/vyos/vyos-1x/pull/2218
1.3 PR: https://github.com/vyos/vyos-1x/pull/2219

Sep 7 2023, 12:54 PM · VyOS 1.3 Equuleus (1.3.4), VyOS 1.5 Circinus, VyOS 1.4 Sagitta
jestabro claimed T5556: reboot now and poweroff does not work.
Sep 7 2023, 12:43 PM · VyOS 1.5 Circinus
Viacheslav renamed T5556: reboot now and poweroff does not work from reboot now does not work to reboot now and poweroff does not work.
Sep 7 2023, 12:39 PM · VyOS 1.5 Circinus
Viacheslav created T5556: reboot now and poweroff does not work.
Sep 7 2023, 12:38 PM · VyOS 1.5 Circinus
sarthurdev changed the status of T5555: Fix timezone migrator (system 13-to-14) from Open to In progress.
Sep 7 2023, 12:29 PM · VyOS 1.3 Equuleus (1.3.4), VyOS 1.5 Circinus, VyOS 1.4 Sagitta
sarthurdev created T5555: Fix timezone migrator (system 13-to-14).
Sep 7 2023, 12:29 PM · VyOS 1.3 Equuleus (1.3.4), VyOS 1.5 Circinus, VyOS 1.4 Sagitta
Viacheslav updated the task description for T5554: Disable sudo for PAM RADIUS.
Sep 7 2023, 11:50 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
Viacheslav created T5554: Disable sudo for PAM RADIUS.
Sep 7 2023, 11:43 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
ildar added a comment to T5232: Flow-accounting uacctd.service cannot restart correctly.

I see this in 20230329 rolling, but don't see on the latest one.

Sep 7 2023, 11:01 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
Apachez added a comment to T4928: Upgrade Linux Kernel to 6.1.y (2022 LTS edition).

Could please the vyos_debconfig files be updated aswell?

Sep 7 2023, 5:19 AM · VyOS 1.4 Sagitta
Apachez closed T5510: Shrink imagesize and improve read performance by changing mksquashfs syntax as Resolved.
Sep 7 2023, 5:15 AM · VyOS 1.4 Sagitta
Apachez added a comment to T5510: Shrink imagesize and improve read performance by changing mksquashfs syntax.

PR392 was merged in VyOS 1.4-rolling-202309070021.

Sep 7 2023, 5:14 AM · VyOS 1.4 Sagitta
jestabro changed Difficulty level from easy to normal on T5353: config-mgmt: normalize archive updates and commit log entries.
Sep 7 2023, 2:20 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
jestabro added a comment to T5412: Add support for extending config-mode dependencies in supplemental package.

PR:
https://github.com/vyos/vyos-1x/pull/2216

Sep 7 2023, 2:19 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
jestabro added a comment to T5353: config-mgmt: normalize archive updates and commit log entries.

PR for Sagitta (draft until dependency PR 2207 is merged to Sagitta):
https://github.com/vyos/vyos-1x/pull/2215

Sep 7 2023, 2:09 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta

Sep 6 2023

anthr76 added a comment to T5546: Failed upgrade from 1.4-rolling-202212310809 to 1.4-rolling-202309030023.

Sounds great @jestabro I'm happy to assist in any way possible

Sep 6 2023, 11:09 PM · VyOS 1.4 Sagitta (1.4.1)
jestabro closed T5353: config-mgmt: normalize archive updates and commit log entries, a subtask of T5347: Compare commit revision bug, as Unknown Status.
Sep 6 2023, 6:28 PM · VyOS 1.4 Sagitta
jestabro closed T5353: config-mgmt: normalize archive updates and commit log entries, a subtask of T5551: Missing check for boot_configuration_complete raises error in vyos-save-config.py, as Unknown Status.
Sep 6 2023, 6:28 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
jestabro closed T5353: config-mgmt: normalize archive updates and commit log entries as Unknown Status.
Sep 6 2023, 6:28 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
Viacheslav changed the status of T5489: Change to BBR as TCP congestion control, or at least make it an config option from In progress to Needs testing.
Sep 6 2023, 6:26 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
sarthurdev committed rVYOSONEX5a8e3089b35e: conntrack: T4309: T4903: Refactor `system conntrack ignore` rule generation….
Sep 6 2023, 6:26 PM
sarthurdev committed rVYOSONEX02d1cf37ef1a: conntrack: T4309: Add `conntrack ignore` smoketest.
Sep 6 2023, 6:26 PM
sarthurdev committed rVYOSONEX2c88d01697ee: nat: T1877: Fix typo in nat ConfigError.
Sep 6 2023, 6:26 PM
GitHub <[email protected]> committed rVYOSONEX50f3e9f66abf: Merge pull request #2199 from sarthurdev/T4309 (authored by c-po).
Sep 6 2023, 6:26 PM
Viacheslav committed rVYOSONEXb99ed37dd1cf: T5489: Add sysctl TCP congestion control by default to BBR.
Sep 6 2023, 6:25 PM
Viacheslav committed rVYOSONEX97326920e290: T5423: Fix for op-mode show vpn ike secrets.
Sep 6 2023, 6:25 PM
GitHub <[email protected]> committed rVYOSONEXc37f78087ba9: Merge pull request #2205 from sever-sever/T5489 (authored by c-po).
Sep 6 2023, 6:25 PM
GitHub <[email protected]> committed rVYOSONEX1cad06b6db63: Merge pull request #2206 from sever-sever/T5423 (authored by c-po).
Sep 6 2023, 6:25 PM
sarthurdev committed rVYOSONEX0de3de1e0a78: interface: T5550: Interface source-validation priority over global value.
Sep 6 2023, 6:25 PM
GitHub <[email protected]> committed rVYOSONEXe0825b52df4a: Merge pull request #2208 from sarthurdev/T5550 (authored by c-po).
Sep 6 2023, 6:25 PM
sarthurdev committed rVYOSONEXbe3d2f9f6623: firewall: T3509: Split IPv4 and IPv6 reverse path filtering like on interfaces.
Sep 6 2023, 6:25 PM
jestabro committed rVYOSONEX73e317bee57c: config-mgmt: T5353: only add log entry if archiving.
Sep 6 2023, 6:25 PM
jestabro committed rVYOSONEX730e744931e4: config-mgmt: T5353: correct update check during boot.
Sep 6 2023, 6:25 PM
jestabro committed rVYOSONEX52e4b4431ef4: config-mgmt: T5353: after updated save-config, one can include init rev.
Sep 6 2023, 6:25 PM
GitHub <[email protected]> committed rVYOSONEXe208d75edd79: Merge pull request #2211 from jestabro/bug-config-mgmt (authored by c-po).
Sep 6 2023, 6:25 PM
Apachez added a comment to T5553: Firewall - Add action continue.

In case there are other just like me who didnt know about "action continue":

Sep 6 2023, 5:55 PM · VyOS 1.4 Sagitta
n.fort changed the status of T5553: Firewall - Add action continue from Open to Confirmed.
Sep 6 2023, 5:39 PM · VyOS 1.4 Sagitta
n.fort created T5553: Firewall - Add action continue.
Sep 6 2023, 5:39 PM · VyOS 1.4 Sagitta
Apachez added a comment to T5388: Something is fishy with commit and boot times when more than a few hundred static routes are being used.

Something else to consider is to increase the readcache of squashfs by changing this:

Sep 6 2023, 4:35 PM · Restricted Project, VyOS 1.5 Circinus
Apachez added a comment to T5388: Something is fishy with commit and boot times when more than a few hundred static routes are being used.

Looking at the kernel configs from both arm and x86 arch:

Sep 6 2023, 4:24 PM · Restricted Project, VyOS 1.5 Circinus
Apachez added a comment to T5455: SSH fingerprints aren't migrated to the new image on upgrade.

So what needs to be done is to copy that block and make a separate question regarding:

Sep 6 2023, 3:26 PM · VyOS Rolling
Apachez added a comment to T5440: Restore pre/postconfig scripts if user deleted them.

According to https://github.com/vyos/vyos-1x/blob/current/src/init/vyos-router it should be named:

Sep 6 2023, 2:39 PM · VyOS 1.4 Sagitta
jestabro added a comment to T5546: Failed upgrade from 1.4-rolling-202212310809 to 1.4-rolling-202309030023.

@anthr76 T5520 would be unrelated to an upgrade from 1.4-rolling-202212310809, as the change to using Bookworm did not occur until 2023. We can take a look at the specific errors that you encountered.

Sep 6 2023, 2:37 PM · VyOS 1.4 Sagitta (1.4.1)
Apachez added a comment to T5546: Failed upgrade from 1.4-rolling-202212310809 to 1.4-rolling-202309030023.

There is a similar case going on at the forum with different workarounds which might help?

Sep 6 2023, 2:31 PM · VyOS 1.4 Sagitta (1.4.1)
fernando updated subscribers of T4919: TPM-backed config encryption.

@sdev take a look over these repository :

Sep 6 2023, 1:28 PM · VyOS 1.5 Circinus
anthr76 added a comment to T5546: Failed upgrade from 1.4-rolling-202212310809 to 1.4-rolling-202309030023.

The steps above i can try as a last ditch effort but that means I need to be on site with the device and will require lots of time (and downtime)

Sep 6 2023, 12:53 PM · VyOS 1.4 Sagitta (1.4.1)
Viacheslav moved T5542: ipoe-server: external-dhcp(dhcp-relay) not woking / not implemented from Open to Finished on the VyOS 1.4 Sagitta board.
Sep 6 2023, 12:08 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T5440: Restore pre/postconfig scripts if user deleted them.

I have two scripts
Is it ok?

vyos@r14:~$ sudo ls -la /config/scripts/vyos-postconfig-boot*
-rwxrwxr-x 1 root vyattacfg 413 Sep  6 15:04 /config/scripts/vyos-postconfig-boot.script
-rwxrwxr-x 1 root vyattacfg 230 Jun 27 06:17 /config/scripts/vyos-postconfig-bootup.script
vyos@r14:~$
Sep 6 2023, 12:07 PM · VyOS 1.4 Sagitta