Page MenuHomeVyOS Platform
Feed All Stories

May 10 2024

n.fort added a comment to T5794: Flowtable with Bond Race.

Maybe we should change firewall priority, and make sure all interfaces are defined in the system before loading firewall?

May 10 2024, 1:58 PM · VyOS 1.5 Circinus
Viacheslav edited projects for T6038: Losing default route after first reboot (cloud-init & DHCP), added: VyOS 1.4 Sagitta (1.4.0-epa3); removed VyOS 1.4 Sagitta (1.4.0-epa1).
May 10 2024, 1:49 PM · VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus
n.fort added a comment to T6329: Firewall - Error while printing groups.

PR: https://github.com/vyos/vyos-1x/pull/3442

May 10 2024, 1:39 PM · VyOS 1.4 Sagitta (1.4.0-epa3), VyOS 1.5 Circinus
Mergify <37929162+mergify[bot]@users.noreply.github.com> committed rVYOSONEXbced1b4ef04f: bond: T6303: must reset system-mac to 00:00:00:00:00:00 on deletion (authored by c-po).
May 10 2024, 1:22 PM
Mergify <37929162+mergify[bot]@users.noreply.github.com> committed rVYOSONEX82552e2abc77: bond: T6303: system-mac is not allowed to be a multicast MAC address (authored by c-po).
May 10 2024, 1:22 PM
Mergify <37929162+mergify[bot]@users.noreply.github.com> committed rVYOSONEX05099eab245c: bond: T6303: add system mac address on bond (authored by fett0 <[email protected]>).
May 10 2024, 1:22 PM
c-po moved T6303: Allow configuring system MAC address on bonding interfaces with LACP from Open to Finished on the VyOS 1.5 Circinus board.
May 10 2024, 1:21 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
c-po changed the status of T6303: Allow configuring system MAC address on bonding interfaces with LACP from In progress to Needs testing.
May 10 2024, 1:21 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
c-po committed rVYOSONEX234f35d8bae7: bond: T6303: add system mac address on bond (authored by fett0 <[email protected]>).
May 10 2024, 1:20 PM
c-po committed rVYOSONEXd8ddd7191d30: bond: T6303: system-mac is not allowed to be a multicast MAC address.
May 10 2024, 1:20 PM
c-po committed rVYOSONEX314901e7b457: bond: T6303: must reset system-mac to 00:00:00:00:00:00 on deletion.
May 10 2024, 1:20 PM
GitHub <[email protected]> committed rVYOSONEXdef74a8fa4e0: Merge pull request #3410 from fett0/T6303 (authored by c-po).
May 10 2024, 1:20 PM
Mergify <37929162+mergify[bot]@users.noreply.github.com> committed rVYOSONEXf47c2e5b800b: bridge: T6317: add dependency call for wireless interfaces (authored by c-po).
May 10 2024, 1:14 PM
Mergify <37929162+mergify[bot]@users.noreply.github.com> committed rVYOSONEX5f968fe51937: bridge: T6317: call dependency when deleting bridge member (authored by c-po).
May 10 2024, 1:14 PM
c-po changed the status of T6317: VLAN doesn't work on a bridge with a wireless interface member from In progress to Needs testing.
May 10 2024, 1:13 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
c-po committed rVYOSONEX31fc53729615: bridge: T6317: call dependency when deleting bridge member.
May 10 2024, 1:13 PM
c-po committed rVYOSONEX431443ab3f66: bridge: T6317: add dependency call for wireless interfaces.
May 10 2024, 1:13 PM
GitHub <[email protected]> committed rVYOSONEX8fa1cb497f8f: Merge pull request #3430 from c-po/bridge-T6317 (authored by c-po).
May 10 2024, 1:13 PM
n.fort committed rVYOSONEX78fa1ec77a22: T6329: firewall: add a patch for op-mode command <show firewall group>.
May 10 2024, 1:10 PM
Apachez reopened T5593: Further shrink VyOS imagesize as "Open".

I dont think this is resolved.

May 10 2024, 1:07 PM · VyOS 2.0.x
n.fort changed the status of T6329: Firewall - Error while printing groups from Open to In progress.
May 10 2024, 1:05 PM · VyOS 1.4 Sagitta (1.4.0-epa3), VyOS 1.5 Circinus
n.fort created T6329: Firewall - Error while printing groups.
May 10 2024, 1:05 PM · VyOS 1.4 Sagitta (1.4.0-epa3), VyOS 1.5 Circinus
natali-rs1985 committed rVYOSONEX679980a43c8b: webproxy: T6328: Add a warning message about deprecation of web proxy URL….
May 10 2024, 1:02 PM
GitHub <[email protected]> committed rVYOSONEX4960a67e12c1: Merge pull request #3439 from natali-rs1985/T6328-sagitta (authored by c-po).
May 10 2024, 1:02 PM
natali-rs1985 added a comment to T6328: Add a warning message about deprecation of web proxy URL filtering.

PR: https://github.com/vyos/vyos-1x/pull/3439

May 10 2024, 12:54 PM · VyOS 1.4 Sagitta (1.4.0-GA)
natali-rs1985 changed the status of T6328: Add a warning message about deprecation of web proxy URL filtering from Open to In progress.
May 10 2024, 12:51 PM · VyOS 1.4 Sagitta (1.4.0-GA)
c-po added a comment to T4811: Webproxy bypassing CLI whitelist command is missing.

Sorry for the noise - see workaround

May 10 2024, 11:53 AM · VyOS 1.4 Sagitta (1.4.0-epa3), VyOS 1.5 Circinus
c-po closed T4811: Webproxy bypassing CLI whitelist command is missing as Wontfix.
May 10 2024, 11:53 AM · VyOS 1.4 Sagitta (1.4.0-epa3), VyOS 1.5 Circinus
Apachez added a comment to T6328: Add a warning message about deprecation of web proxy URL filtering.

When/If doing so it would be great if the docs would suggest for alternative methods to achieve the same thing.

May 10 2024, 10:51 AM · VyOS 1.4 Sagitta (1.4.0-GA)
dmbaturin renamed T6328: Add a warning message about deprecation of web proxy URL filtering from Add a warning message about deprecation of webroxy service to Add a warning message about deprecation of web proxy URL filtering.
May 10 2024, 9:47 AM · VyOS 1.4 Sagitta (1.4.0-GA)
dmbaturin added a comment to T6328: Add a warning message about deprecation of web proxy URL filtering.

We should make it clear that we are deprecating URL filtering with SquidGuard, not the whole web proxy service.

May 10 2024, 9:47 AM · VyOS 1.4 Sagitta (1.4.0-GA)
natali-rs1985 updated the task description for T6328: Add a warning message about deprecation of web proxy URL filtering.
May 10 2024, 9:45 AM · VyOS 1.4 Sagitta (1.4.0-GA)
natali-rs1985 updated the task description for T6328: Add a warning message about deprecation of web proxy URL filtering.
May 10 2024, 9:08 AM · VyOS 1.4 Sagitta (1.4.0-GA)
natali-rs1985 raised the priority of T6328: Add a warning message about deprecation of web proxy URL filtering from Low to Requires assessment.
May 10 2024, 9:08 AM · VyOS 1.4 Sagitta (1.4.0-GA)
natali-rs1985 created T6328: Add a warning message about deprecation of web proxy URL filtering.
May 10 2024, 9:01 AM · VyOS 1.4 Sagitta (1.4.0-GA)

May 9 2024

Viacheslav reopened T6292: Unable to update webproxy blacklist as they use captcha as "Open".
May 9 2024, 6:44 PM · Restricted Project, VyOS 1.5 Circinus
Viacheslav added a comment to T6292: Unable to update webproxy blacklist as they use captcha.

I'm re-opening until we make a final decision

May 9 2024, 6:44 PM · Restricted Project, VyOS 1.5 Circinus
jestabro moved T5458: USB Console options is missing for a new image after "add system image" upgrade from Open to Finished on the VyOS 1.5 Circinus board.
May 9 2024, 5:51 PM · VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus
jestabro moved T5458: USB Console options is missing for a new image after "add system image" upgrade from Need Triage to Finished on the VyOS 1.4 Sagitta (1.4.0-GA) board.
May 9 2024, 5:50 PM · VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus
jestabro closed T5458: USB Console options is missing for a new image after "add system image" upgrade as Wontfix.

See details and explanation in subtask T6327; notably, one can configure as system console, but setting at boot has limited use.

May 9 2024, 5:49 PM · VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus
jestabro added projects to T6278: Attempt hint for console type during image install: VyOS 1.5 Circinus, VyOS 1.4 Sagitta (1.4.0-epa3).
May 9 2024, 5:44 PM · VyOS 1.4 Sagitta (1.4.0-epa3), VyOS 1.5 Circinus
jestabro added a subtask for T6176: image-tools: rationalize setting of console type: T6327: Drop boot console type ttyUSB (USB serial).
May 9 2024, 5:44 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
jestabro added a parent task for T6327: Drop boot console type ttyUSB (USB serial): T6176: image-tools: rationalize setting of console type.
May 9 2024, 5:44 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
jestabro added a subtask for T5458: USB Console options is missing for a new image after "add system image" upgrade: T6327: Drop boot console type ttyUSB (USB serial).
May 9 2024, 5:43 PM · VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus
jestabro added a parent task for T6327: Drop boot console type ttyUSB (USB serial): T5458: USB Console options is missing for a new image after "add system image" upgrade.
May 9 2024, 5:43 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
jestabro triaged T6327: Drop boot console type ttyUSB (USB serial) as Normal priority.
May 9 2024, 5:43 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
Viacheslav edited projects for T6313: Add "NAT" to "generate" command for rule resequence, added: VyOS 1.5 Circinus; removed VyOS 1.4 Sagitta.
May 9 2024, 4:12 PM · VyOS 1.4 Sagitta (1.4.1), VyOS 1.5 Circinus
GitHub <[email protected]> committed rVYOSONEX0999a75da918: Merge pull request #3438 from vyos/mergify/bp/sagitta/pr-3436 (authored by c-po).
May 9 2024, 3:29 PM
Viacheslav closed T6292: Unable to update webproxy blacklist as they use captcha as Wontfix.

The service webproxy is deprecated and will be removed in 1.5

May 9 2024, 3:21 PM · Restricted Project, VyOS 1.5 Circinus
c-po reopened T4811: Webproxy bypassing CLI whitelist command is missing as "In progress".
May 9 2024, 3:19 PM · VyOS 1.4 Sagitta (1.4.0-epa3), VyOS 1.5 Circinus
Mergify <37929162+mergify[bot]@users.noreply.github.com> committed rVYOSONEXfaf450705d46: sstp: T4393: Add support to configure host-name (SNI) (authored by natali-rs1985).
May 9 2024, 3:13 PM
natali-rs1985 committed rVYOSONEX92b468b9a0d5: sstp: T4393: Add support to configure host-name (SNI).
May 9 2024, 3:12 PM
GitHub <[email protected]> committed rVYOSONEX7925402b487b: Merge pull request #3436 from natali-rs1985/T4393-current (authored by c-po).
May 9 2024, 3:12 PM
GitHub <[email protected]> committed rVYOSONEXc38795e317cd: Merge pull request #3434 from vyos/mergify/bp/sagitta/pr-3433 (authored by c-po).
May 9 2024, 2:58 PM
GitHub <[email protected]> committed rVYOSONEXc30c8cf63f59: Merge pull request #3437 from vyos/mergify/bp/sagitta/pr-3435 (authored by c-po).
May 9 2024, 2:57 PM
Viacheslav moved T6325: Update pipfile python3 version or delete pip file for vyos-1x from Open to Finished on the VyOS 1.4 Sagitta board.
May 9 2024, 2:40 PM · VyOS 1.4 Sagitta
Viacheslav closed T6325: Update pipfile python3 version or delete pip file for vyos-1x as Resolved.

Removed in https://github.com/vyos/vyos-1x/pull/3435

May 9 2024, 2:40 PM · VyOS 1.4 Sagitta
Mergify <37929162+mergify[bot]@users.noreply.github.com> committed rVYOSONEXc028c02330ce: T6199: remove unused Python pip files (authored by c-po).
May 9 2024, 2:39 PM
c-po committed rVYOSONEXa1aa0a8a663e: T6199: remove unused Python pip files.
May 9 2024, 2:38 PM
GitHub <[email protected]> committed rVYOSONEX7d035fe85624: Merge pull request #3435 from c-po/cleanup-pipfile (authored by dmbaturin).
May 9 2024, 2:38 PM
Mergify <37929162+mergify[bot]@users.noreply.github.com> committed rVYOSONEX46fc66ab2298: T6323: openvpn: Correction of auto-completion description of "mfa totp digits" (authored by SrividyaA).
May 9 2024, 2:06 PM
c-po committed rVYOSONEX7dab763df070: T6323: openvpn: Correction of auto-completion description of "mfa totp digits" (authored by SrividyaA).
May 9 2024, 2:06 PM
GitHub <[email protected]> committed rVYOSONEX05b893d8d965: Merge pull request #3433 from srividya0208/T6323 (authored by c-po).
May 9 2024, 2:06 PM
GitHub <[email protected]> committed rVYOSONEX3d0dcb5e57c3: Merge pull request #3432 from vyos/feature/T6315-remove-reviewers-assignment (authored by c-po).
May 9 2024, 2:02 PM
Viacheslav triaged T6315: Add Codeql reusable action workflow as Normal priority.
May 9 2024, 1:56 PM · GitHub Infrastructure
Viacheslav triaged T6318: vyos-1x: WiFi Regulatory Domain should be set system-wide instead of per-device as Normal priority.
May 9 2024, 1:54 PM · VyOS 1.5 Circinus
jestabro claimed T6326: Specific error is not returned via the HTTP API during a configuration failure..
May 9 2024, 1:38 PM · VyOS Rolling, Restricted Project, VyOS 1.5 Circinus
penetal created T6326: Specific error is not returned via the HTTP API during a configuration failure..
May 9 2024, 1:30 PM · VyOS Rolling, Restricted Project, VyOS 1.5 Circinus
jestabro claimed T5458: USB Console options is missing for a new image after "add system image" upgrade.
May 9 2024, 1:18 PM · VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus
Viacheslav renamed T6325: Update pipfile python3 version or delete pip file for vyos-1x from Update pip file python3 version or delete pip file for vyos-1x to Update pipfile python3 version or delete pip file for vyos-1x.
May 9 2024, 12:46 PM · VyOS 1.4 Sagitta
Viacheslav triaged T6325: Update pipfile python3 version or delete pip file for vyos-1x as Normal priority.
May 9 2024, 12:46 PM · VyOS 1.4 Sagitta
Vijayakumar added a comment to T6316: need to add automatic assignment of reviewers from reviewers team.

@syncer Any idea why conflict check fails for this PR https://github.com/vyos/vyos-1x/actions/runs/9015620312 ?

May 9 2024, 12:02 PM · GitHub Infrastructure
Apachez added a comment to T6322: Include microcode update packages for both intel and amd64 cpus.

It can be handy to have the option to have it disabled (or you can just in bash-mode do "apt-get remove intel-microcode --purge" if you dont want it after install) but it should be enabled by default due to security reasons.

May 9 2024, 10:03 AM · Restricted Project, VyOS 1.5 Circinus
Vijayakumar committed rVYOSONEX890391885d66: T6316: remove reviewers assignment in workflow as it will done by codeowners… (authored by Vijayakumar A <[email protected]>).
May 9 2024, 10:02 AM
Vijayakumar added a comment to T6315: Add Codeql reusable action workflow.

Ok,
Reviewers' assignment from the workflow can be removed (as it will be handled globally using codeowner file)
Raised PR,. Please check
https://github.com/vyos/vyos-1x/pull/3432

May 9 2024, 9:55 AM · GitHub Infrastructure
marekm added a comment to T6322: Include microcode update packages for both intel and amd64 cpus.

Please consider making the microcode updates optional, and possible to load a specified file downloaded separately from the CPU vendor, independent of VyOS updates.
Some possible edge cases:

  • running VyOS in a VM (microcode update has no effect in the guest anyway, needs to be done in the hypervisor)
  • microcode update released in a hurry breaks something, need to revert to an older one
  • microcode update reduces performance, doesn't improve security of VyOS (because it's not a typical multi-user system with untrusted users who can run any programs)
  • microcode update has important fixes, but it will take time before a new LTS is released, or VyOS can't be updated because the subscription has expired
May 9 2024, 9:52 AM · Restricted Project, VyOS 1.5 Circinus
GitHub <[email protected]> committed rVYOSONEX7fbccb71cee6: T6316: remove reviewers yml as it is controlled in global level (authored by Vijayakumar A <[email protected]>).
May 9 2024, 9:49 AM
GitHub <[email protected]> committed rVYOSONEX5d38c0a60f41: T6315: remove reviewers assignment in workflow as it will done by codeowners… (authored by Vijayakumar A <[email protected]>).
May 9 2024, 9:40 AM
trae32566 added a comment to T1641: VRRP conntrack-sync dropping packets passing through the router.

I think this was resolved at some point, but I ended up removing it (the accept-protocol stuff) from my config since it didn't appear necessary and was causing issues, so I'm not certain.

May 9 2024, 8:50 AM · Restricted Project, VyOS 1.4 Sagitta (1.4.1)
GitHub <[email protected]> committed rVYOSONEXa45ba57e0ed8: Merge pull request #3431 from vyos/feature/T6315-update-codeql-branch (authored by dmbaturin).
May 9 2024, 8:40 AM
Viacheslav closed T6324: CVE-2024-2961 as Resolved.
May 9 2024, 8:34 AM · VyOS 1.3 Equuleus (1.3.7), VyOS 1.4 Sagitta (1.4.0-epa3)
Viacheslav added a comment to T6324: CVE-2024-2961.

For 1.4 also fixed

vyos@r1-right:~$ show version all | match "GNU C L"
ii  libc-bin                             2.36-9+deb12u7                   amd64        GNU C Library: Binaries
ii  libc-l10n                            2.36-9+deb12u7                   all          GNU C Library: localization files
ii  libc6:amd64                          2.36-9+deb12u7                   amd64        GNU C Library: Shared libraries
ii  locales                              2.36-9+deb12u7                   all          GNU C Library: National Language (locale) data [support]
vyos@r1-right:~$ 
vyos@r1-right:~$ show ver
Version:          VyOS 1.4-stable-202405090309
Release train:    sagitta
May 9 2024, 8:22 AM · VyOS 1.3 Equuleus (1.3.7), VyOS 1.4 Sagitta (1.4.0-epa3)
natali-rs1985 changed the status of T4393: sstp: add support for configuring host-name (SNI) from Open to In progress.
May 9 2024, 8:20 AM · VyOS 1.4 Sagitta (1.4.0-GA)
syncer assigned T6140: After running a while the default routing failed on vyos 1.4 epa1&epa2 with pppoe0 enabled to Viacheslav.
May 9 2024, 8:18 AM · Restricted Project, VyOS 1.4 Sagitta (1.4.1)
Viacheslav moved T6324: CVE-2024-2961 from Backlog to Finished on the VyOS 1.4 Sagitta (1.4.0-epa3) board.
May 9 2024, 8:16 AM · VyOS 1.3 Equuleus (1.3.7), VyOS 1.4 Sagitta (1.4.0-epa3)
syncer moved T6324: CVE-2024-2961 from Backlog to Finished on the VyOS 1.3 Equuleus (1.3.7) board.
May 9 2024, 8:15 AM · VyOS 1.3 Equuleus (1.3.7), VyOS 1.4 Sagitta (1.4.0-epa3)
Viacheslav added a comment to T6324: CVE-2024-2961.

Fixed

vyos@r1-right:~$ show version all | match "GNU C L"
ii  libc-bin                             2.28-10+deb10u3                amd64        GNU C Library: Binaries
ii  libc-l10n                            2.28-10+deb10u3                all          GNU C Library: localization files
ii  libc6:amd64                          2.28-10+deb10u3                amd64        GNU C Library: Shared libraries
ii  locales                              2.28-10+deb10u3                all          GNU C Library: National Language (locale) data [support]
vyos@r1-right:~$ 
vyos@r1-right:~$ show version
May 9 2024, 8:08 AM · VyOS 1.3 Equuleus (1.3.7), VyOS 1.4 Sagitta (1.4.0-epa3)
syncer moved T6324: CVE-2024-2961 from Need Triage to Backlog on the VyOS 1.4 Sagitta (1.4.0-epa3) board.
May 9 2024, 8:03 AM · VyOS 1.3 Equuleus (1.3.7), VyOS 1.4 Sagitta (1.4.0-epa3)
syncer changed the status of T6324: CVE-2024-2961 from Open to In progress.
May 9 2024, 8:03 AM · VyOS 1.3 Equuleus (1.3.7), VyOS 1.4 Sagitta (1.4.0-epa3)
syncer added a comment to T6315: Add Codeql reusable action workflow.

there is some issue https://github.com/vyos/vyos-1x/actions/runs/9013844673/job/24765384018?pr=3431

May 9 2024, 8:02 AM · GitHub Infrastructure
a.apostoliuk triaged T6324: CVE-2024-2961 as Normal priority.
May 9 2024, 7:55 AM · VyOS 1.3 Equuleus (1.3.7), VyOS 1.4 Sagitta (1.4.0-epa3)
Vijayakumar added a comment to T6315: Add Codeql reusable action workflow.

Please approve https://github.com/vyos/vyos-1x/pull/3431

May 9 2024, 7:19 AM · GitHub Infrastructure
GitHub <[email protected]> committed rVYOSONEXd8a0bb52c396: T6315: updated codeql branch name (authored by Vijayakumar A <[email protected]>).
May 9 2024, 7:15 AM
Vijayakumar added a comment to T6316: need to add automatic assignment of reviewers from reviewers team.

Added codeowner file and basis pr templates and checks
https://github.com/vyos/.github/pull/1
Please review the PR

May 9 2024, 7:09 AM · GitHub Infrastructure
SrividyaA claimed T6323: Correction of auto-completion description of "mfa totp digits".
May 9 2024, 6:46 AM · VyOS 1.4 Sagitta (1.4.0-epa3)
SrividyaA created T6323: Correction of auto-completion description of "mfa totp digits".
May 9 2024, 6:44 AM · VyOS 1.4 Sagitta (1.4.0-epa3)

May 8 2024

e.pc.yuan added a comment to T5636: Need geoip option for policy route.

set policy local-route doesn't make sense to me to have a geoip network group, however geoip in set policy route allows for greater flexibility while performing routing to ensure traffic traverse through specific destination for compliance and regulatory purposes.

May 8 2024, 9:42 PM · Restricted Project, VyOS 1.5 Circinus
syncer triaged T6322: Include microcode update packages for both intel and amd64 cpus as Normal priority.
May 8 2024, 9:41 PM · Restricted Project, VyOS 1.5 Circinus
syncer merged task T6321: intel-microcode package should be included into T6322: Include microcode update packages for both intel and amd64 cpus.
May 8 2024, 9:03 PM · VyOS 1.5 Circinus
syncer merged T6321: intel-microcode package should be included into T6322: Include microcode update packages for both intel and amd64 cpus.
May 8 2024, 9:03 PM · Restricted Project, VyOS 1.5 Circinus