Page MenuHomeVyOS Platform
Feed All Stories

Feb 6 2024

GitHub <[email protected]> committed rVYOSONEX9d74ae52092e: Merge pull request #2941 from jestabro/cleanup-wait (authored by jestabro).
Feb 6 2024, 4:59 PM
Mergify <37929162+mergify[bot]@users.noreply.github.com> committed rVYOSONEXea8f374a37ec: T5921: Fix OpenConnect verify for local users (authored by Viacheslav).
Feb 6 2024, 4:49 PM
Viacheslav committed rVYOSONEX71644dfed63f: T5921: Fix OpenConnect verify for local users.
Feb 6 2024, 4:48 PM
GitHub <[email protected]> committed rVYOSONEX341fe08465cc: Merge pull request #2946 from sever-sever/T5921 (authored by c-po).
Feb 6 2024, 4:48 PM
dmbaturin triaged T6005: Error on adding a wireguard interface to OSPFv3 as High priority.
Feb 6 2024, 4:41 PM · VyOS 1.4 Sagitta (1.4.0-epa1), VyOS 1.5 Circinus
dmbaturin triaged T6009: Firewall - Time not working properly when not using UTC as High priority.
Feb 6 2024, 4:41 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
dmbaturin added a comment to T6019: Bump nftables and libnftnl version.

Just a note: with such tasks, we should always add context — why is the upgrade done. Is it for vulnerabilites? If yes, which CVEs? Is it for bug fixes? If yes, which bug report number? Is it to unblock a path to implementing new features and which ones?

Feb 6 2024, 4:40 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
dmbaturin triaged T6019: Bump nftables and libnftnl version as Normal priority.
Feb 6 2024, 4:39 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
dmbaturin created an object: Task creation policy.
Feb 6 2024, 4:31 PM
Viacheslav moved T5687: Implement ECS settings for PowerDNS recursor from Open to Finished on the VyOS 1.5 Circinus board.
Feb 6 2024, 2:55 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
Viacheslav closed T5687: Implement ECS settings for PowerDNS recursor as Resolved.
Feb 6 2024, 2:55 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
Viacheslav changed the status of T5921: Trying to commit an OpenConnect configuration without any local users results in an exception from Open to In progress.

PR https://github.com/vyos/vyos-1x/pull/2946

Feb 6 2024, 2:46 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
Viacheslav claimed T5133: Add comments for items in address-group and network-group in firewall.
Feb 6 2024, 2:08 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
Viacheslav added a project to T5926: IPSEC does not apply after l2tp configuration was changed: VyOS 1.4 Sagitta.
Feb 6 2024, 1:55 PM · VyOS 1.3 Equuleus (1.3.9), VyOS 1.4 Sagitta (1.4.0-epa1), VyOS 1.5 Circinus
Viacheslav changed the status of T5926: IPSEC does not apply after l2tp configuration was changed from Open to In progress.
Feb 6 2024, 1:55 PM · VyOS 1.3 Equuleus (1.3.9), VyOS 1.4 Sagitta (1.4.0-epa1), VyOS 1.5 Circinus
Viacheslav changed the status of T6014: Bump keepalived version from In progress to Needs testing.
Feb 6 2024, 1:44 PM · VyOS 1.3 Equuleus (1.3.6), VyOS 1.4 Sagitta, VyOS 1.5 Circinus
Viacheslav changed the status of T5133: Add comments for items in address-group and network-group in firewall from Open to In progress.
Feb 6 2024, 1:03 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
Viacheslav added a comment to T5133: Add comments for items in address-group and network-group in firewall.

PR https://github.com/vyos/vyos-1x/pull/2945

set firewall group address-group ONE address 192.0.2.1 description 'First'
set firewall group address-group ONE address 192.0.2.2 description 'Second'
Feb 6 2024, 1:02 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
n.fort changed the status of T6019: Bump nftables and libnftnl version from Open to In progress.
Feb 6 2024, 11:58 AM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
n.fort created T6019: Bump nftables and libnftnl version.
Feb 6 2024, 11:57 AM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
HollyGurza added a comment to T5926: IPSEC does not apply after l2tp configuration was changed.

https://github.com/vyos/vyos-1x/pull/2944

Feb 6 2024, 10:51 AM · VyOS 1.3 Equuleus (1.3.9), VyOS 1.4 Sagitta (1.4.0-epa1), VyOS 1.5 Circinus
HollyGurza added a comment to T3843: l2tp configuration not cleared after delete.

https://github.com/vyos/vyos-1x/pull/2944

Feb 6 2024, 10:51 AM · VyOS 1.4 Sagitta (1.4.0-epa3), VyOS 1.5 Circinus
GitHub <[email protected]> committed rVYOSONEXda465d26b524: Merge pull request #2943 from vyos/mergify/bp/current/pr-2942 (authored by dmbaturin).
Feb 6 2024, 10:24 AM
Mergify <37929162+mergify[bot]@users.noreply.github.com> committed rVYOSONEXb7cedf359f09: op-mode:T6015:Fix the charon file generated by ipsec debug script (authored by SrividyaA).
Feb 6 2024, 7:37 AM
SrividyaA committed rVYOSONEX0c9c496961dc: op-mode:T6015:Fix the charon file generated by ipsec debug script.
Feb 6 2024, 7:35 AM
GitHub <[email protected]> committed rVYOSONEXb10d1c0bd60d: Merge pull request #2942 from srividya0208/debug-ipsec (authored by Viacheslav).
Feb 6 2024, 7:35 AM
jestabro added a comment to T6016: Resolve intermittent failures in cleanup function after failed image install.

PR:
https://github.com/vyos/vyos-1x/pull/2941

Feb 6 2024, 4:59 AM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
jestabro moved T6018: smoketest: updating http-api framework requires a pause before test from Open to Finished on the VyOS 1.4 Sagitta board.
Feb 6 2024, 4:50 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
jestabro closed T6018: smoketest: updating http-api framework requires a pause before test as Resolved.
Feb 6 2024, 4:50 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
jestabro moved T6017: Update vyos-http-api-tools for security advisory from Open to Finished on the VyOS 1.4 Sagitta board.
Feb 6 2024, 4:49 AM · VyOS 1.3 Equuleus (1.3.6), VyOS 1.4 Sagitta, VyOS 1.5 Circinus
jestabro moved T6017: Update vyos-http-api-tools for security advisory from Open to Finished on the VyOS 1.5 Circinus board.
Feb 6 2024, 4:49 AM · VyOS 1.3 Equuleus (1.3.6), VyOS 1.4 Sagitta, VyOS 1.5 Circinus
GitHub <[email protected]> committed rVYOSONEXc1be1713ae1e: Merge pull request #2939 from vyos/mergify/bp/sagitta/pr-2936 (authored by c-po).
Feb 6 2024, 4:25 AM
Mergify <37929162+mergify[bot]@users.noreply.github.com> committed rVYOSONEX1d8414c9dabd: init: T2044: always start/stop rpki during system boot (authored by c-po).
Feb 6 2024, 4:25 AM
Mergify <37929162+mergify[bot]@users.noreply.github.com> committed rVYOSONEXa32b2a9e8649: rpki: T6011: known-hosts-file is no longer supported by FRR (authored by c-po).
Feb 6 2024, 3:11 AM
c-po committed rVYOSONEX586863bf3a9c: rpki: T6011: known-hosts-file is no longer supported by FRR.
Feb 6 2024, 3:10 AM
GitHub <[email protected]> committed rVYOSONEXc1d0a778f9b2: Merge pull request #2936 from c-po/rpki-T6011 (authored by dmbaturin).
Feb 6 2024, 3:10 AM
c-po committed rVYOSONEX9199c87cf984: init: T2044: always start/stop rpki during system boot.
Feb 6 2024, 3:09 AM
GitHub <[email protected]> committed rVYOSONEXf2cefce3714c: Merge pull request #2935 from c-po/rpki (authored by dmbaturin).
Feb 6 2024, 3:09 AM

Feb 5 2024

GitHub <[email protected]> committed rVYOSONEX48be2429b831: Merge pull request #2938 from vyos/mergify/bp/sagitta/pr-2937 (authored by jestabro).
Feb 5 2024, 9:56 PM
n.fort added a comment to T445: iptables error with policy routing.

What version? Can you upgrade to 1.4?

Feb 5 2024, 9:37 PM · VyOS 1.3 Equuleus (1.3.8), test
Harliff added a comment to T445: iptables error with policy routing.

One of my router heavily affected by this issue, so if you will wrote a fix - you may ask me to test the fix.

Feb 5 2024, 9:36 PM · VyOS 1.3 Equuleus (1.3.8), test
Mergify <37929162+mergify[bot]@users.noreply.github.com> committed rVYOSONEX217b6b8894d8: T6018: adjust smoketest for update to FastAPI web framework (authored by jestabro).
Feb 5 2024, 9:34 PM
jestabro committed rVYOSONEXe1b63b9b1704: T6018: adjust smoketest for update to FastAPI web framework.
Feb 5 2024, 9:31 PM
GitHub <[email protected]> committed rVYOSONEXcf1a7ee4599c: Merge pull request #2937 from jestabro/overhead-advisory-update (authored by jestabro).
Feb 5 2024, 9:31 PM
jestabro added a project to T6018: smoketest: updating http-api framework requires a pause before test: VyOS 1.5 Circinus.
Feb 5 2024, 9:26 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
jestabro triaged T6018: smoketest: updating http-api framework requires a pause before test as Normal priority.
Feb 5 2024, 9:11 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
jestabro triaged T6017: Update vyos-http-api-tools for security advisory as High priority.
Feb 5 2024, 9:09 PM · VyOS 1.3 Equuleus (1.3.6), VyOS 1.4 Sagitta, VyOS 1.5 Circinus
c-po claimed T6010: Support setting multiple values in BGP path-attribute.
Feb 5 2024, 4:33 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
a.apostoliuk closed T5865: Rewrite ipv6 pool section to ipv6 named pools in Accel-ppp services as Resolved.
Feb 5 2024, 4:17 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
jestabro triaged T6016: Resolve intermittent failures in cleanup function after failed image install as High priority.
Feb 5 2024, 3:05 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
Viacheslav added a comment to T6012: Ability to have IPv6 nexthops for IPv4 static routes.

It seems FRR (9.0.2-36-g31dec1951) does not support this.
The route can be added, but no route is in the routing table.

vyos@r4:~$ vtysh -c "conf t" -c "ip route 192.0.2.0/24 2001:db8::1"
vyos@r4:~$ 
vyos@r4:~$ vtysh -c "show run" | match 192.0.2.0
ip route 192.0.2.0/24 2001:db8::1
vyos@r4:~$ 
vyos@r4:~$ 
vyos@r4:~$ show ip route 192.0.2.0/24
% Network not in table
vyos@r4:~$
Feb 5 2024, 2:37 PM
SrividyaA created T6015: "journalctl_charon" file does not contain data in the generated "ipsec debug-archive" file.
Feb 5 2024, 11:21 AM · VyOS 1.4 Sagitta (1.4.0-epa1)
n.fort changed the status of T6009: Firewall - Time not working properly when not using UTC from Confirmed to In progress.
Feb 5 2024, 10:17 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
Viacheslav changed the status of T6014: Bump keepalived version from Open to In progress.

PR for 1.5 https://github.com/vyos/vyos-build/pull/493
PR for 1.3 https://github.com/vyos/vyos-build/pull/494

Feb 5 2024, 9:32 AM · VyOS 1.3 Equuleus (1.3.6), VyOS 1.4 Sagitta, VyOS 1.5 Circinus
a.apostoliuk updated the task description for T5960: Rewriting authentication section in accel-ppp services.
Feb 5 2024, 9:28 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
Viacheslav moved T5974: QoS policy shaper is currently miscalculating bandwidth and ceil values for the default class from Open to Finished on the VyOS 1.4 Sagitta board.
Feb 5 2024, 8:47 AM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
Viacheslav closed T5974: QoS policy shaper is currently miscalculating bandwidth and ceil values for the default class as Resolved.
Feb 5 2024, 8:47 AM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
Viacheslav triaged T6014: Bump keepalived version as Normal priority.
Feb 5 2024, 8:43 AM · VyOS 1.3 Equuleus (1.3.6), VyOS 1.4 Sagitta, VyOS 1.5 Circinus
Viacheslav created T6014: Bump keepalived version.
Feb 5 2024, 8:43 AM · VyOS 1.3 Equuleus (1.3.6), VyOS 1.4 Sagitta, VyOS 1.5 Circinus
Viacheslav added a comment to T6010: Support setting multiple values in BGP path-attribute.

Update supports via whitespace

r4(config-router)#  neighbor foo path-attribute discard 23 24
Feb 5 2024, 8:36 AM · VyOS 1.4 Sagitta (1.4.0-epa3)
Viacheslav triaged T6010: Support setting multiple values in BGP path-attribute as Wishlist priority.

FRR does not support it

r4# conf t
r4(config)# router bgp 65001
r4(config-router)#  no bgp ebgp-requires-policy
r4(config-router)#  no bgp default ipv4-unicast
r4(config-router)#  no bgp network import-check
r4(config-router)#  neighbor foo peer-group
r4(config-router)#  neighbor foo path-attribute discard 24
r4(config-router)#  neighbor foo path-attribute discard 23,24
% Unknown command:  neighbor foo path-attribute discard 23,24
r4(config-router)#
Feb 5 2024, 8:34 AM · VyOS 1.4 Sagitta (1.4.0-epa3)
Viacheslav triaged T6011: rpki: known-hosts-file is no longer supported by FRR CLI - remove VyOS CLI node as Normal priority.
Feb 5 2024, 8:11 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
Viacheslav triaged T6013: SSH Certificate configuration as Wishlist priority.
Feb 5 2024, 8:10 AM · VyOS Rolling
Viacheslav triaged T6012: Ability to have IPv6 nexthops for IPv4 static routes as Normal priority.
Feb 5 2024, 8:09 AM
nepeat created T6013: SSH Certificate configuration.
Feb 5 2024, 5:52 AM · VyOS Rolling

Feb 4 2024

eureka added a comment to T6012: Ability to have IPv6 nexthops for IPv4 static routes.

This type of configuration works perfectly fine with VyOS 1.5 when receiving routes from a BGP peer (v4 routes with v6 nexthop), so it would be very nice to be able to manually install routes in the same way.

Feb 4 2024, 11:16 PM
nepeat created T6012: Ability to have IPv6 nexthops for IPv4 static routes.
Feb 4 2024, 10:59 PM

Feb 3 2024

GitHub <[email protected]> committed rVYOSONEX22a15d828e1d: Merge pull request #2934 from vyos/mergify/bp/sagitta/pr-2932 (authored by c-po).
Feb 3 2024, 9:07 PM
c-po renamed T6011: rpki: known-hosts-file is no longer supported by FRR CLI - remove VyOS CLI node from rpki: known-hosts-file is no longer supported bxy FRR CLI - remove VyOS CLI node to rpki: known-hosts-file is no longer supported by FRR CLI - remove VyOS CLI node.
Feb 3 2024, 8:44 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
c-po changed the status of T6011: rpki: known-hosts-file is no longer supported by FRR CLI - remove VyOS CLI node from Open to In progress.
Feb 3 2024, 8:14 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
c-po created T6011: rpki: known-hosts-file is no longer supported by FRR CLI - remove VyOS CLI node.
Feb 3 2024, 8:13 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
c-po added a comment to T6004: Missing RPKI boot priority prevents it from loading.

https://github.com/vyos/vyos-1x/pull/2935

Feb 3 2024, 8:08 PM · VyOS 1.3 Equuleus (1.3.7), VyOS 1.4 Sagitta (1.4.0-epa2)
c-po added a comment to T2044: RPKI doesn't boot properly.

https://github.com/vyos/vyos-1x/pull/2935

Feb 3 2024, 8:08 PM · VyOS 1.3 Equuleus (1.3.7), VyOS 1.5 Circinus, VyOS 1.4 Sagitta
Mergify <37929162+mergify[bot]@users.noreply.github.com> committed rVYOSONEX4edc0611ec0a: ipsec: T5998: add replay-windows setting (authored by c-po).
Feb 3 2024, 8:05 PM
Apachez added a comment to T5424: Routes vanishes when using FRR with ECMP and one of the ECMP paths is no longer available.

Its not clear if its fixed or not:

Feb 3 2024, 4:26 PM · VyOS Rolling, Restricted Project
c-po committed rVYOSONEX4d943d8fbf12: ipsec: T5998: add replay-windows setting.
Feb 3 2024, 4:22 PM
GitHub <[email protected]> committed rVYOSONEX630a242cecae: Merge pull request #2932 from c-po/ipsec-T5998 (authored by c-po).
Feb 3 2024, 4:22 PM
c-po added a parent task for T2044: RPKI doesn't boot properly: T6004: Missing RPKI boot priority prevents it from loading.
Feb 3 2024, 11:51 AM · VyOS 1.3 Equuleus (1.3.7), VyOS 1.5 Circinus, VyOS 1.4 Sagitta
c-po added a subtask for T6004: Missing RPKI boot priority prevents it from loading: T2044: RPKI doesn't boot properly.
Feb 3 2024, 11:51 AM · VyOS 1.3 Equuleus (1.3.7), VyOS 1.4 Sagitta (1.4.0-epa2)
GitHub <[email protected]> committed rVYOSONEX088dcfd35af2: Merge pull request #2933 from vyos/mergify/bp/sagitta/pr-2931 (authored by c-po).
Feb 3 2024, 8:03 AM
Mergify <37929162+mergify[bot]@users.noreply.github.com> committed rVYOSONEXc224be5a55f6: configdict: T5894: preserve old behavior when dealing with PKI (authored by c-po).
Feb 3 2024, 5:03 AM
c-po committed rVYOSONEX9b56a86def67: configdict: T5894: preserve old behavior when dealing with PKI.
Feb 3 2024, 5:02 AM
GitHub <[email protected]> committed rVYOSONEX1d23d921deb0: Merge pull request #2931 from c-po/configdict-bugfix (authored by Viacheslav).
Feb 3 2024, 5:02 AM
dmbaturin created 1.3.6.
Feb 3 2024, 1:59 AM

Feb 2 2024

roedie created T6010: Support setting multiple values in BGP path-attribute.
Feb 2 2024, 7:52 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
c-po closed T6003: Add 'show rpki as-number' and 'show rpki prefix' as Resolved.
Feb 2 2024, 7:49 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
c-po moved T6003: Add 'show rpki as-number' and 'show rpki prefix' from Open to Finished on the VyOS 1.4 Sagitta board.
Feb 2 2024, 7:49 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
c-po moved T6003: Add 'show rpki as-number' and 'show rpki prefix' from Open to Finished on the VyOS 1.5 Circinus board.
Feb 2 2024, 7:49 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
c-po moved T5998: replay_window setting under vpn in config from Open to Finished on the VyOS 1.5 Circinus board.
Feb 2 2024, 7:49 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
c-po added a comment to T5998: replay_window setting under vpn in config.

PR https://github.com/vyos/vyos-1x/pull/2932

Feb 2 2024, 7:47 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
Viacheslav edited projects for T973: Create Prometheus Exporter for VyOS , added: VyOS 1.5 Circinus; removed VyOS 1.3 Equuleus (1.3.6).
Feb 2 2024, 4:45 PM · VyOS Rolling, VyOS 1.5 Circinus
Viacheslav closed T2459: Migrate vyatta-show-nat-rules.pl to Python, a subtask of T2198: Rewrite NAT in new XML/Python style, as Not Applicable.
Feb 2 2024, 4:42 PM · VyOS 1.3 Equuleus (1.3.0)
Viacheslav closed T2459: Migrate vyatta-show-nat-rules.pl to Python, a subtask of T3355: Remove all remaining legacy Vyatta code, as Not Applicable.
Feb 2 2024, 4:42 PM · VyOS Rolling
Viacheslav closed T2459: Migrate vyatta-show-nat-rules.pl to Python as Not Applicable.

It won't be implemented for 1.3.x
Have this for 1.4/1.5

Feb 2 2024, 4:42 PM
GitHub <[email protected]> committed rVYOSONEX2d8a7bda382f: Merge pull request #2930 from vyos/mergify/bp/sagitta/pr-2748 (authored by c-po).
Feb 2 2024, 4:35 PM
Viacheslav changed the status of T4816: IPv4-mapped and IPv4-compatible IPv6 addresses not valid anymore from Open to Confirmed.
Feb 2 2024, 4:33 PM · Restricted Project, VyOS 1.4 Sagitta (1.4.1)
Viacheslav edited projects for T5153: OpenConnect route restriction via iptables is ignored, added: VyOS 1.5 Circinus; removed VyOS 1.3 Equuleus (1.3.6).
Feb 2 2024, 4:29 PM
Viacheslav moved T5739: Password recovery does not work if public keys are configured from Need Triage to Finished on the VyOS 1.3 Equuleus (1.3.6) board.
Feb 2 2024, 4:24 PM · VyOS 1.3 Equuleus (1.3.6), VyOS 1.5 Circinus, VyOS 1.4 Sagitta
Viacheslav moved T5739: Password recovery does not work if public keys are configured from Open to Finished on the VyOS 1.4 Sagitta board.
Feb 2 2024, 4:24 PM · VyOS 1.3 Equuleus (1.3.6), VyOS 1.5 Circinus, VyOS 1.4 Sagitta
Viacheslav closed T5739: Password recovery does not work if public keys are configured as Resolved.

merged

Feb 2 2024, 4:24 PM · VyOS 1.3 Equuleus (1.3.6), VyOS 1.5 Circinus, VyOS 1.4 Sagitta