Page MenuHomeVyOS Platform
Feed All Stories

Aug 9 2026

nvollmar created T9184: Support configuring chown capability for containers.
Aug 9 2026, 12:13 PM · VyOS Rolling
arogers created T9183: Every log message is recorded twice: rsyslog loads imuxsock and imjournal while journald forwards to syslog.
Aug 9 2026, 8:52 AM · VyOS Rolling
drixter added a comment to T9178: ipv6 ospfv3 redistribute.

Ad.1/2 It's there

Aug 9 2026, 6:57 AM · VyOS Rolling
jestabro added a comment to T9182: Simplify vyos1x-config lexical-numeric compare function and fix corner case.

PR:
https://github.com/vyos/vyos1x-config/pull/91

Aug 9 2026, 3:24 AM · VyOS Rolling
jestabro created T9182: Simplify vyos1x-config lexical-numeric compare function and fix corner case.
Aug 9 2026, 2:50 AM · VyOS Rolling

Aug 8 2026

rherold added a comment to T9178: ipv6 ospfv3 redistribute.

Hi, thanks for the detailed report.

Aug 8 2026, 11:09 PM · VyOS Rolling
c-po added a comment to T9181: Kernel: modernize packaging and remove redundant work.

https://github.com/vyos/vyos-build/pull/1262

Aug 8 2026, 8:42 PM · VyOS Rolling
catalyys added a comment to T9180: default_action return is missing in vyos_firewall_rules.

I have added a Pull Request under https://github.com/vyos/vyos.vyos/pull/494

Aug 8 2026, 8:33 PM · VyOS Rolling
c-po created T9181: Kernel: modernize packaging and remove redundant work.
Aug 8 2026, 8:32 PM · VyOS Rolling
catalyys created T9180: default_action return is missing in vyos_firewall_rules.
Aug 8 2026, 7:56 PM · VyOS Rolling
hedrok closed T9036: ipt-NETFLOW: support VRF as Resolved.

Closed in https://vyos.dev/T9122

Aug 8 2026, 5:12 PM · VyOS Rolling
hedrok created T9179: Completion and validation don't match for source interface name.
Aug 8 2026, 5:02 PM · VyOS Rolling
Restricted Repository Identity closed T9107: Fix integration workflow after recent GitHub security updates as Resolved by committing Restricted Diffusion Commit.
Aug 8 2026, 4:37 PM · VyOS Rolling
drixter created T9178: ipv6 ospfv3 redistribute.
Aug 8 2026, 3:15 PM · VyOS Rolling
asklymenko closed T9125: Add new exception to the workflow that checks for typos as Resolved.
Aug 8 2026, 3:00 PM · VyOS Rolling
hybridops added a comment to T6941: cloud-init cannot clean up previously downloaded instance data.

I checked the current public vyos-cloud-init branches and the issue still appears to be present: cloudinit/stages.py calls util.del_file(self.paths.instance_link), while util.del_file() uses os.unlink(), so a stale real directory at that path still raises IsADirectoryError.

Aug 8 2026, 2:41 PM · VyOS 1.5 Circinus, VyOS Rolling
hybridops added a comment to T8999: openvpn: misleading "no openvpn shared-secrets in PKI" error for a dangling auth-key/crypt-key reference.

I would like to work on this task.

Aug 8 2026, 1:58 PM · VyOS Rolling
hybridops added a comment to T9172: cloud-init: add regression coverage for vyos_config_commands.

PR submitted and ready for review:
https://github.com/vyos/vyos-cloud-init/pull/116

Aug 8 2026, 11:24 AM · VyOS Rolling
hybridops added a comment to T9145: WAN Load Balancing: User-defined health-check scripts do not receive interface context (WLB_INTERFACE_NAME).

I would like to work on this task.

Aug 8 2026, 11:20 AM · VyOS Rolling
evgmol claimed T6837: Add replace configuration for module vyos_config.
Aug 8 2026, 10:58 AM · VyOS Ansible Collection
evgmol claimed T6890: Consider using true/false for all booleans in docs.
Aug 8 2026, 10:57 AM · VyOS Ansible Collection
evgmol renamed T6830: add support for file upload, management and templating from add support for file upload, management and templating to add support for file upload, management and templating.
Aug 8 2026, 10:57 AM · VyOS Ansible Collection
evgmol closed T8920: map-based connection marking and policy routing to reduce repeated DNAT/PBR rules as Not Applicable.
Aug 8 2026, 10:55 AM · VyOS Ansible Collection
evgmol added a comment to T6837: Add replace configuration for module vyos_config.

https://github.com/vyos/vyos.vyos/pull/493 - yet another attempt

Aug 8 2026, 10:53 AM · VyOS Ansible Collection

Aug 7 2026

L0crian added a comment to T9176: firewall: Implement nftables concatenation support for firewall groups.

PR: https://github.com/vyos/vyos-1x/pull/5385

Aug 7 2026, 11:08 PM · VyOS Rolling
rherold added a comment to T9177: are_same_ip() in python/vyos/utils/network.py uses wrong address family for second argument.

PR: https://github.com/vyos/vyos-1x/pull/5383

Aug 7 2026, 9:01 PM · VyOS Rolling
rherold created T9177: are_same_ip() in python/vyos/utils/network.py uses wrong address family for second argument.
Aug 7 2026, 8:48 PM · VyOS Rolling
L0crian created T9176: firewall: Implement nftables concatenation support for firewall groups.
Aug 7 2026, 6:01 PM · VyOS Rolling
itspngu created T9175: PowerDNS periodically queries security-status.secpoll.powerdns.com and discards the result.
Aug 7 2026, 5:53 PM · VyOS Rolling
jesper.beltman added a comment to T9174: WWAN modem not up, counter 100 not long enough.

Running Commit again after the modem 0 is exist does work.

Aug 7 2026, 3:13 PM · VyOS Rolling
jesper.beltman created T9174: WWAN modem not up, counter 100 not long enough.
Aug 7 2026, 3:13 PM · VyOS Rolling
Viacheslav changed the status of T9172: cloud-init: add regression coverage for vyos_config_commands from Open to In progress.
Aug 7 2026, 11:21 AM · VyOS Rolling
Viacheslav triaged T9173: Feature Request: Automate RFC 8195 Large-Community tagging from existing BGP config (Role, neighbor ASN) as Normal priority.
Aug 7 2026, 11:08 AM · VyOS Rolling
rherold added a comment to T9160: Config-path-derived group/prefix-list membership (analogous to Junos `apply-path`).

Update: the "Low fit" verdict above for policy as-path-list/community-list/extcommunity-list/large-community-list ("no natural derivation source") needs a caveat.

Aug 7 2026, 11:02 AM · VyOS Rolling
rherold created T9173: Feature Request: Automate RFC 8195 Large-Community tagging from existing BGP config (Role, neighbor ASN).
Aug 7 2026, 10:58 AM · VyOS Rolling
rherold updated subscribers of T9159: # Feature Request: Expose a client-side source-address option for `service ntp`.

@Viacheslav thx for cleanup the task,. Did you see that I ask for an decision from the team about the implementation?

Aug 7 2026, 10:38 AM · VyOS Rolling
hybridops added a comment to T9172: cloud-init: add regression coverage for vyos_config_commands.

@hybridops Would you like to claim this task?

Aug 7 2026, 10:19 AM · VyOS Rolling
Viacheslav changed the status of T9159: # Feature Request: Expose a client-side source-address option for `service ntp` from Open to In progress.
Aug 7 2026, 10:03 AM · VyOS Rolling
Viacheslav changed the status of T9160: Config-path-derived group/prefix-list membership (analogous to Junos `apply-path`) from Open to In progress.
Aug 7 2026, 9:11 AM · VyOS Rolling
Viacheslav triaged T9166: Enable IPv6 listening/peer address for conntrack-sync and DHCP high availability settings and templates as Normal priority.
Aug 7 2026, 9:04 AM · VyOS Ansible Collection
Viacheslav reassigned T8329: Accelerated Networking on Azure is not working Properly on VyOS VM when its deployed with terraform from RC to a.kudientsov.
Aug 7 2026, 9:02 AM · VyOS 1.4 Sagitta
Viacheslav changed the status of T8329: Accelerated Networking on Azure is not working Properly on VyOS VM when its deployed with terraform from Open to Needs testing.

PR https://github.com/vyos/vyos-build/pull/1249

Aug 7 2026, 8:58 AM · VyOS 1.4 Sagitta
Viacheslav closed T9163: Typos in the completion help for the service conntrack-sync interface as Resolved.
Aug 7 2026, 8:55 AM · VyOS Rolling
Viacheslav closed T9073: Add CLI support for frr_exporter optional collectors and collector options as Resolved.
Aug 7 2026, 8:53 AM · VyOS Rolling
Viacheslav closed T8921: QoS/CAKE / FQ_CODEL IFB redirect fails at boot when WireGuard interface has fixed local port as Resolved.
Aug 7 2026, 8:51 AM · VyOS Rolling
Viacheslav closed T9018: VPP VLAN does not work as Resolved.
Aug 7 2026, 8:49 AM · VyOS Rolling
Viacheslav closed T9133: fstrim systemd timer/unit does effectively nothing as Resolved.
Aug 7 2026, 8:35 AM · VyOS Rolling
Viacheslav changed the status of T9167: dhcp: Kea HA max-response-delay equals heartbeat-delay (disagrees with Kea defaults) from Open to In progress.

PR https://github.com/vyos/vyos-1x/pull/5382

Aug 7 2026, 6:19 AM · VyOS Rolling
Viacheslav triaged T9167: dhcp: Kea HA max-response-delay equals heartbeat-delay (disagrees with Kea defaults) as Normal priority.
Aug 7 2026, 6:18 AM · VyOS Rolling
Viacheslav added a comment to T9167: dhcp: Kea HA max-response-delay equals heartbeat-delay (disagrees with Kea defaults).

@bradkollmyer Would you like to claim this task?
At first glance all related changes here https://github.com/vyos/vyos-1x/blob/278fba204200f02bb461f786f889b40dc38a26f6/python/vyos/template.py#L907

Aug 7 2026, 6:18 AM · VyOS Rolling
Viacheslav closed T9065: VPP sflow not work when enable-egress is disabled as Resolved.
Aug 7 2026, 6:05 AM · VyOS Rolling
Viacheslav closed T8996: QoS: set-dscp option has no effect as Resolved.
Aug 7 2026, 6:01 AM · VyOS Rolling
Viacheslav assigned T9171: IPv6 BFD sessions never reach `Up` on unnumbered VLAN sub-interfaces sharing a parent's MAC (upstream FRR bug, tracked as FRRouting/frr#22921) to hedrok.
Aug 7 2026, 4:23 AM · VyOS Rolling
Viacheslav added a comment to T9172: cloud-init: add regression coverage for vyos_config_commands.

@hybridops Would you like to claim this task?

Aug 7 2026, 4:22 AM · VyOS Rolling

Aug 6 2026

c-po closed T8128: RTL8723AE WiFi Card Firmware Missing as Resolved.
Aug 6 2026, 8:59 PM · VyOS 1.5 Circinus (Circinus-Next), VyOS Rolling
c-po added a comment to T8128: RTL8723AE WiFi Card Firmware Missing.

File is present int rolling release. Please use any rolling release published AFTER this post.

Aug 6 2026, 8:59 PM · VyOS 1.5 Circinus (Circinus-Next), VyOS Rolling
c-po closed T9170: Kernel: missing firmware files after enabling module compression as Resolved.
Aug 6 2026, 8:40 PM · VyOS Rolling
hybridops created T9172: cloud-init: add regression coverage for vyos_config_commands.
Aug 6 2026, 5:46 PM · VyOS Rolling
rherold created T9171: IPv6 BFD sessions never reach `Up` on unnumbered VLAN sub-interfaces sharing a parent's MAC (upstream FRR bug, tracked as FRRouting/frr#22921).
Aug 6 2026, 3:07 PM · VyOS Rolling
Viacheslav closed T5526: Clarify the error message when trying to set an interface as a BGP peer group using the wrong syntax as Resolved.
Aug 6 2026, 2:05 PM · Bugs, VyOS 1.3 Equuleus (1.3.8)
c-po added a comment to T9170: Kernel: missing firmware files after enabling module compression.

https://github.com/vyos/vyos-build/pull/1261

Aug 6 2026, 5:26 AM · VyOS Rolling
c-po changed the status of T9170: Kernel: missing firmware files after enabling module compression from Open to In progress.
Aug 6 2026, 5:16 AM · VyOS Rolling
c-po created T9170: Kernel: missing firmware files after enabling module compression.
Aug 6 2026, 5:16 AM · VyOS Rolling
c-po closed T5641: Enable compression of kernel modules as Resolved.
Aug 6 2026, 5:15 AM
c-po claimed T8128: RTL8723AE WiFi Card Firmware Missing.
Aug 6 2026, 5:13 AM · VyOS 1.5 Circinus (Circinus-Next), VyOS Rolling
jestabro added a comment to T9169: Refactor vyos1x-config diff functions in functorial style.

PR:
https://github.com/vyos/vyos1x-config/pull/90

Aug 6 2026, 2:21 AM · VyOS Rolling
jestabro created T9169: Refactor vyos1x-config diff functions in functorial style.
Aug 6 2026, 1:51 AM · VyOS Rolling
jestabro added a parent task for T9168: Fix vyconf build by use of correct ocaml-protoc / pbrt version: T9044: vyconf: add CI build + test workflow (dune build + runtest on PR).
Aug 6 2026, 1:36 AM · VyOS Rolling
jestabro added a subtask for T9044: vyconf: add CI build + test workflow (dune build + runtest on PR): T9168: Fix vyconf build by use of correct ocaml-protoc / pbrt version.
Aug 6 2026, 1:36 AM · VyConf
jestabro created T9168: Fix vyconf build by use of correct ocaml-protoc / pbrt version.
Aug 6 2026, 1:36 AM · VyOS Rolling

Aug 5 2026

bradkollmyer created T9167: dhcp: Kea HA max-response-delay equals heartbeat-delay (disagrees with Kea defaults).
Aug 5 2026, 11:22 PM · VyOS Rolling
rherold added a comment to T9157: Support `fib daddr type` / `fib saddr type` matching in firewall rules (especially `prerouting raw`).
Thanks for reproducing this independently — matches what we found on our own multi-device-unnumbered topology (loopback address duplicated across lo + 3 P2P bond
interfaces per router, full-mesh OSPF core). We proved the same underlying inconsistency with a logging-only rule (no notrack, just log+counter, run in parallel with live
traffic, zero production impact):
Aug 5 2026, 3:27 PM · VyOS Rolling
chariri created T9166: Enable IPv6 listening/peer address for conntrack-sync and DHCP high availability settings and templates.
Aug 5 2026, 3:26 PM · VyOS Ansible Collection
L0crian added a comment to T9157: Support `fib daddr type` / `fib saddr type` matching in firewall rules (especially `prerouting raw`).

I tested with 2 interfaces when testing BGP over OSPF, but with 8 for BGP only ip unnumbered:

Aug 5 2026, 3:17 PM · VyOS Rolling
rherold added a comment to T9159: # Feature Request: Expose a client-side source-address option for `service ntp`.

You're right that device binding implicitly selects the VRF — bindacqdevice/binddevice on an interface that belongs to a VRF scopes that socket to it, no separate VRF
option needed for that to work at the chrony level.

Aug 5 2026, 3:13 PM · VyOS Rolling
Apachez added a comment to T9159: # Feature Request: Expose a client-side source-address option for `service ntp`.

Again, VRF is selected through both bindacqdevice and binddevice so having "asymmetric incoming/outgoing VRF binding" works perfectly fine.

Aug 5 2026, 2:39 PM · VyOS Rolling
rherold added a comment to T9159: # Feature Request: Expose a client-side source-address option for `service ntp`.

binddevice/bindacqdevice are already separately configurable — binddevice maps to the existing interface option (incoming/listen), bindacqdevice to this PR's new
ource-interface (outgoing/client). So incoming vs. outgoing device binding is already independent.

Aug 5 2026, 1:51 PM · VyOS Rolling
rherold added a comment to T9157: Support `fib daddr type` / `fib saddr type` matching in firewall rules (especially `prerouting raw`).

Thanks for testing this — appreciate the data. To reconcile with what we saw: our issue wasn't IP-unnumbered per se, but specifically that our own address appears on
multiple devices simultaneously in the local route table (ip route show table local showed our loopback duplicated across lo + 3 P2P bond interfaces used for OSPF, since
our full-mesh core reuses the loopback address on each P2P link). We proved with a logging-only rule (fib daddr . iif type unicast log) that real traffic to our own
address was classified unicast, never local, even though ip route get reported local for the same case.

Aug 5 2026, 1:49 PM · VyOS Rolling
L0crian added a comment to T9157: Support `fib daddr type` / `fib saddr type` matching in firewall rules (especially `prerouting raw`).

OSPF and BGP is for input, so they should be there.

Aug 5 2026, 1:27 PM · VyOS Rolling
Apachez added a comment to T9157: Support `fib daddr type` / `fib saddr type` matching in firewall rules (especially `prerouting raw`).

@L0crian: When you did that test did you try to reboot in between?

Aug 5 2026, 1:25 PM · VyOS Rolling
Apachez added a comment to T9159: # Feature Request: Expose a client-side source-address option for `service ntp`.

Its worsen the situation since selecting source-address wont work if thats in a different vrf so that smoketest will fail where it shouldnt.

Aug 5 2026, 1:17 PM · VyOS Rolling
L0crian added a comment to T9157: Support `fib daddr type` / `fib saddr type` matching in firewall rules (especially `prerouting raw`).

Can you provide your config you tested with. I just tested and it works as expected even with using ip unnumbered. This is with forwarding traffic going across the router:

Using ip unnumbered BGP over OSPF:
vyos@vyos# run show conntrack table ipv4
Original src    Original dst    Original packets    Original bytes    Reply src     Reply dst       Reply packets    Reply bytes    Protocol    State        Timeout    Mark    Zone
--------------  --------------  ------------------  ----------------  ------------  --------------  ---------------  -------------  ----------  -----------  ---------  ------  ------
10.0.0.1        224.0.0.5       0                   0                 224.0.0.5     10.0.0.1        0                0              unknown                  596        0
10.0.0.2        224.0.0.5       0                   0                 224.0.0.5     10.0.0.2        0                0              unknown                  598        0
10.0.0.1:43585  10.0.0.2:179    0                   0                 10.0.0.2:179  10.0.0.1:43585  0                0              tcp         ESTABLISHED  431985     0

And if I then delete the disable-conntrack, you can see forward traffic now enters conntrack:

vyos@vyos# delete firewall ipv4 forward filter disable-conntrack 
vyos@vyos# commit
vyos@vyos# run show conntrack table ipv4
Original src    Original dst    Original packets    Original bytes    Reply src     Reply dst       Reply packets    Reply bytes    Protocol    State        Timeout    Mark    Zone
--------------  --------------  ------------------  ----------------  ------------  --------------  ---------------  -------------  ----------  -----------  ---------  ------  ------
10.0.10.10      10.0.11.10      0                   0                 10.0.11.10    10.0.10.10      0                0              icmp                     27         0
10.0.0.1        224.0.0.5       0                   0                 224.0.0.5     10.0.0.1        0                0              unknown                  596        0
10.0.0.2        224.0.0.5       0                   0                 224.0.0.5     10.0.0.2        0                0              unknown                  597        0
10.0.0.1:43585  10.0.0.2:179    0                   0                 10.0.0.2:179  10.0.0.1:43585  0                0              tcp         ESTABLISHED  431979     0
Using ip unnumbered only BGP:
vyos@vyos# run show conntrack table ipv4
Entries not found
vyos@vyos# run show conntrack table ipv6
Original src               Original dst                 Original packets    Original bytes    Reply src                    Reply dst                  Reply packets    Reply bytes    Protocol    State        Timeout    Mark    Zone
-------------------------  ---------------------------  ------------------  ----------------  ---------------------------  -------------------------  ---------------  -------------  ----------  -----------  ---------  ------  ------
fe80::ecd:a4ff:fec2:0:179  fe80::eda:29ff:fe4e:0:39492  0                   0                 fe80::eda:29ff:fe4e:0:39492  fe80::ecd:a4ff:fec2:0:179  0                0              tcp         ESTABLISHED  431999     0
fe80::ecd:a4ff:fec2:0:179  fe80::eda:29ff:fe4e:0:39496  0                   0                 fe80::eda:29ff:fe4e:0:39496  fe80::ecd:a4ff:fec2:0:179  0                0              tcp         ESTABLISHED  431999     0
Aug 5 2026, 11:38 AM · VyOS Rolling
rherold added a comment to T9157: Support `fib daddr type` / `fib saddr type` matching in firewall rules (especially `prerouting raw`).
Thanks both for the input.
Aug 5 2026, 6:48 AM · VyOS Rolling
rherold added a comment to T9159: # Feature Request: Expose a client-side source-address option for `service ntp`.

@Apachez: Thanks for the feedback — you're right that a source IP alone doesn't fully solve this for multi-VRF setups with overlapping address ranges.

Aug 5 2026, 6:41 AM · VyOS Rolling
Viacheslav changed the status of T9162: show nat source rules` crashes with `KeyError: 0` for rules without `inbound-interface` from Open to In progress.
Aug 5 2026, 4:59 AM · VyOS Rolling
Apachez added a comment to T9157: Support `fib daddr type` / `fib saddr type` matching in firewall rules (especially `prerouting raw`).

Is this the same (exists in Stream 2026.03)?

Aug 5 2026, 3:45 AM · VyOS Rolling
Apachez added a comment to T9157: Support `fib daddr type` / `fib saddr type` matching in firewall rules (especially `prerouting raw`).

Also currently missing in Stream 2026.03:

Aug 5 2026, 3:43 AM · VyOS Rolling
Apachez added a comment to T9146: support no-multi-seg in DPDK VPP.

It seems that this change occurs behind the scenes as in not a configurable option. Being dealt with by adjusting buffers so jumboframes are still properly supported (even if DPDK documentation claims this is NOT compatible with jumbo frames!?).

Aug 5 2026, 3:39 AM · VyOS Rolling
Apachez added a comment to T9159: # Feature Request: Expose a client-side source-address option for `service ntp`.

How will it work if I got 2 different VRFs?

Aug 5 2026, 3:23 AM · VyOS Rolling

Aug 4 2026

rherold created T9165: BGP EVPN control-plane integration for the VPP dataplane.
Aug 4 2026, 7:50 PM · VyOS Rolling
c-po added a comment to T7736: Container: virtual-ethernet exception when attempting to modify container network created veth.

https://github.com/vyos/vyos-build/pull/1259

Aug 4 2026, 7:28 PM · VyOS Rolling
Viacheslav changed the status of T7522: Firewall commit errors should identify which rule caused the failure from Open to In progress.
Aug 4 2026, 6:36 PM · VyOS 1.4 Sagitta
Viacheslav triaged T9163: Typos in the completion help for the service conntrack-sync interface as Normal priority.
Aug 4 2026, 5:12 PM · VyOS Rolling
Viacheslav created T9163: Typos in the completion help for the service conntrack-sync interface.
Aug 4 2026, 5:08 PM · VyOS Rolling
L0crian added a comment to T7522: Firewall commit errors should identify which rule caused the failure.

PR: https://github.com/vyos/vyos-1x/pull/5377

Aug 4 2026, 4:52 PM · VyOS 1.4 Sagitta
Viacheslav triaged T9153: interface: source-validation is not removed when a logical interface is removed as Normal priority.
Aug 4 2026, 3:42 PM · VyOS Rolling
Viacheslav changed the status of T9153: interface: source-validation is not removed when a logical interface is removed from Open to In progress.
Aug 4 2026, 3:42 PM · VyOS Rolling
natali-rs1985 added a comment to T9146: support no-multi-seg in DPDK VPP.
Aug 4 2026, 3:01 PM · VyOS Rolling
Viacheslav added a comment to T9154: IPsec vti-up-down: DB keyed only by connection name causes admin-down of a VTI still carried by a live IKE_SA.

PR https://github.com/vyos/vyos-1x/pull/5370

Aug 4 2026, 11:40 AM · VyOS Rolling
rherold added a comment to T9162: show nat source rules` crashes with `KeyError: 0` for rules without `inbound-interface`.

https://github.com/vyos/vyos-1x/pull/5375

Aug 4 2026, 11:21 AM · VyOS Rolling