Page MenuHomeVyOS Platform

sarthurdev (Simon)
User

Projects

User Details

User Since
May 6 2021, 3:27 PM (191 w, 6 d)

Recent Activity

Nov 29 2024

sarthurdev committed rVYOSONEX961eab48de35: pki: T3642: Minimize `node_changed` code.
Nov 29 2024, 2:48 PM
sarthurdev committed rVYOSONEX0358f6c660e6: pki: T6809: Support system install of CA certificates.
Nov 29 2024, 2:48 PM

Nov 26 2024

sarthurdev added a comment to T6040: Implement a firewall blacklisting solution.

I think it being called and centered around blacklisting is too specific. I'd be more inclined to see it as a firewall group, perhaps like the functionality of domain groups:

Nov 26 2024, 7:22 PM · VyOS Rolling

Nov 25 2024

sarthurdev committed rVYOSONEX4e49794fcf55: dhcp: T6692: Fix range options not present when `exclude` is used.
Nov 25 2024, 3:56 PM

Nov 22 2024

sarthurdev changed the status of T6809: System CA Not Updated with Configuration from Open to Needs testing.

PR: https://github.com/vyos/vyos-1x/pull/4204

Nov 22 2024, 12:15 AM · VyOS Rolling, Bugs

Nov 21 2024

sarthurdev changed the status of T6692: DHCP Exclude IP - Error Config from Open to Needs testing.

PR: https://github.com/vyos/vyos-1x/pull/4203

Nov 21 2024, 8:43 PM · VyOS 1.5 Circinus, VyOS Rolling, Bugs
sarthurdev added a comment to T6907: [op-commands] encrypted/hidden sensible information in 'show configuration'.

Could nodes be flagged as sensitive in XML properties and that flag exposed to op-mode show scripts?

Nov 21 2024, 7:08 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
sarthurdev added a comment to T6534: TPM config encryption is broken.

@syncer The fix is present in rolling and circinus branches

Nov 21 2024, 3:00 PM · VyOS 1.5 Circinus, VyOS Rolling, Bugs
sarthurdev closed T6534: TPM config encryption is broken as Resolved.

Can be closed as resolved by above PR.

Nov 21 2024, 2:10 PM · VyOS 1.5 Circinus, VyOS Rolling, Bugs

Nov 20 2024

sarthurdev committed rVYOSONEXf6ee516ca440: serial: T3397: Remove `--keep-baud` which could result in unexpected baud rate.
Nov 20 2024, 9:06 PM
sarthurdev added a comment to T3397: getty forces --keep-baud in 1.2.x.

Issue present in 1.4.0 tested with Supermicro SOL on ttyS1.

Nov 20 2024, 4:15 PM · VyOS Rolling, VyOS 1.4 Sagitta (1.4.1), VyOS 1.3 Equuleus (1.3.9)

Oct 28 2024

sarthurdev added a comment to T375: WAN failover, not to balance the load.

Most likely, if not addressed already with initial implementation.

Oct 28 2024, 8:26 AM · Restricted Project, VyOS Rolling

Oct 22 2024

sarthurdev closed T6766: Add support ECDSA keys in PKI as Resolved.
Oct 22 2024, 9:02 PM · VyOS 1.5 Circinus

Oct 10 2024

sarthurdev committed rVYOSONEXbb28e001b112: pki: T6766: Add support for ECDSA private keys.
Oct 10 2024, 3:15 PM
sarthurdev committed rVYOSONEX7765e037b9fc: haproxy: T6745: Add haproxy migration to config test.
Oct 10 2024, 3:13 PM
sarthurdev committed rVYOSONEX90a4827284ac: haproxy: T6745: Rename `reverse-proxy` to `haproxy`.
Oct 10 2024, 3:13 PM

Oct 9 2024

sarthurdev changed the status of T6745: rename reverse-proxy to haproxy from In progress to Needs testing.

PR: https://github.com/vyos/vyos-1x/pull/4147

Oct 9 2024, 5:56 PM · VyOS Rolling, VyOS 1.5 Circinus
sarthurdev changed the status of T6745: rename reverse-proxy to haproxy from Open to In progress.
Oct 9 2024, 1:06 PM · VyOS Rolling, VyOS 1.5 Circinus
sarthurdev changed the status of T4470: Rewrite load-balancing wan to XML/Python from In progress to Needs testing.

PR: https://github.com/vyos/vyos-1x/pull/4108

Oct 9 2024, 9:27 AM · VyOS Rolling, VyOS 1.5 Circinus
sarthurdev changed the status of T6766: Add support ECDSA keys in PKI from Open to Needs testing.

PR: https://github.com/vyos/vyos-1x/pull/4146

Oct 9 2024, 9:25 AM · VyOS 1.5 Circinus
sarthurdev added a comment to T6768: GeoIP database update does not work.

Can't reproduce on my end:

Oct 9 2024, 8:46 AM · VyOS Rolling

Oct 7 2024

sarthurdev created T6766: Add support ECDSA keys in PKI.
Oct 7 2024, 6:41 PM · VyOS 1.5 Circinus

Sep 29 2024

sarthurdev moved T4470: Rewrite load-balancing wan to XML/Python from Open to In Progress on the VyOS 1.5 Circinus board.
Sep 29 2024, 11:33 AM · VyOS Rolling, VyOS 1.5 Circinus
sarthurdev edited projects for T4470: Rewrite load-balancing wan to XML/Python, added: VyOS 1.5 Circinus; removed VyOS 1.4 Sagitta.
Sep 29 2024, 11:33 AM · VyOS Rolling, VyOS 1.5 Circinus
sarthurdev reopened T4470: Rewrite load-balancing wan to XML/Python as "In progress".

Draft PR: https://github.com/vyos/vyos-1x/pull/4108 (WIP)

Sep 29 2024, 11:33 AM · VyOS Rolling, VyOS 1.5 Circinus

Sep 2 2024

sarthurdev added a comment to T6692: DHCP Exclude IP - Error Config.

Can you please include the VyOS config?

Sep 2 2024, 2:49 PM · VyOS 1.5 Circinus, VyOS Rolling, Bugs
sarthurdev claimed T6692: DHCP Exclude IP - Error Config.
Sep 2 2024, 2:48 PM · VyOS 1.5 Circinus, VyOS Rolling, Bugs

Jun 27 2024

sarthurdev closed T4919: TPM-backed config encryption as Resolved.
Jun 27 2024, 2:15 PM · VyOS 1.5 Circinus

May 1 2024

sarthurdev committed rVYOSONEX456419c79304: firewall: T6257: Show member information for dynamic groups in op-mode.
May 1 2024, 8:13 AM

Apr 26 2024

sarthurdev changed the status of T6257: Add op mode commands for dynamic firewall address groups from Open to Needs testing.

PR: https://github.com/vyos/vyos-1x/pull/3369

Apr 26 2024, 5:42 PM · VyOS 1.4 Sagitta (1.4.0-epa3)

Apr 25 2024

sarthurdev moved T6241: Updating CRL in "pki" config does not update OpenVPN from Open to In Progress on the VyOS 1.5 Circinus board.
Apr 25 2024, 2:46 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
sarthurdev moved T6241: Updating CRL in "pki" config does not update OpenVPN from Need Triage to In Progress on the VyOS 1.4 Sagitta (1.4.0-epa3) board.
Apr 25 2024, 2:46 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
sarthurdev added a comment to T6266: Firewall flowtable ability to set timeout for TCP and UDP flow.

Possibly would make sense for CLI to fall under firewall global-options?

Apr 25 2024, 2:03 PM · VyOS Rolling
sarthurdev claimed T6257: Add op mode commands for dynamic firewall address groups.
Apr 25 2024, 1:59 PM · VyOS 1.4 Sagitta (1.4.0-epa3)

Apr 18 2024

sarthurdev committed rVYOSONEXa88b3bd344cc: pki: T6241: do not call dependency before its initialization (authored by jestabro).
Apr 18 2024, 12:42 PM

Apr 15 2024

sarthurdev committed rVYOSONEX9f9891a20995: pki: T6241: Fix dependency updates on PKI changes.
Apr 15 2024, 6:12 PM
sarthurdev closed T6174: can't view dhcp server leases if logged in as a tacacs account as Resolved.
Apr 15 2024, 2:48 PM · VyOS 1.5 Circinus
sarthurdev closed T6163: kea-dhcp4-server crashes due to incorrect lease file permissions after 1.5-rolling-202403120022 -> 1.5-rolling-202403230018 upgrade as Resolved.
Apr 15 2024, 2:48 PM · VyOS 1.5 Circinus
sarthurdev changed the status of T6241: Updating CRL in "pki" config does not update OpenVPN from Open to Needs testing.

PR: https://github.com/vyos/vyos-1x/pull/3311

Apr 15 2024, 2:43 PM · VyOS 1.4 Sagitta (1.4.0-epa3)

Apr 7 2024

sarthurdev committed rVYOSONEX7d339d18e14d: kea: T3316: Ensure correct permissions on lease files.
Apr 7 2024, 8:22 PM
sarthurdev changed the status of T6163: kea-dhcp4-server crashes due to incorrect lease file permissions after 1.5-rolling-202403120022 -> 1.5-rolling-202403230018 upgrade from Confirmed to Needs testing.

PR: https://github.com/vyos/vyos-1x/pull/3277

Apr 7 2024, 8:14 PM · VyOS 1.5 Circinus
sarthurdev merged T6137: dhcp files and directory permission not correct after image uprgading into T6163: kea-dhcp4-server crashes due to incorrect lease file permissions after 1.5-rolling-202403120022 -> 1.5-rolling-202403230018 upgrade.
Apr 7 2024, 6:17 PM · VyOS 1.5 Circinus
sarthurdev merged task T6137: dhcp files and directory permission not correct after image uprgading into T6163: kea-dhcp4-server crashes due to incorrect lease file permissions after 1.5-rolling-202403120022 -> 1.5-rolling-202403230018 upgrade.
Apr 7 2024, 6:17 PM · VyOS 1.5 Circinus
sarthurdev changed the status of T6163: kea-dhcp4-server crashes due to incorrect lease file permissions after 1.5-rolling-202403120022 -> 1.5-rolling-202403230018 upgrade from Open to Confirmed.
Apr 7 2024, 6:11 PM · VyOS 1.5 Circinus

Mar 28 2024

sarthurdev committed rVYOSONEXa39f8c73ba60: dhcp: T6174: Add TACACS/Radius users to _kea group.
Mar 28 2024, 8:31 PM
sarthurdev changed the status of T6174: can't view dhcp server leases if logged in as a tacacs account from In progress to Needs testing.

PR: https://github.com/vyos/vyos-1x/pull/3210

Mar 28 2024, 8:24 PM · VyOS 1.5 Circinus
sarthurdev committed rVYOSONEX952b1656f516: ipsec: T5606: T5871: Use multi node for CA certificates.
Mar 28 2024, 4:11 PM
sarthurdev changed the status of T6174: can't view dhcp server leases if logged in as a tacacs account from Open to In progress.
Mar 28 2024, 3:03 PM · VyOS 1.5 Circinus
sarthurdev closed T6102: Clear dhcp-server lease throws python exception on 1.5-rolling as Resolved.
Mar 28 2024, 3:02 PM · VyOS 1.5 Circinus
sarthurdev moved T6147: Conntrack not working as expected with global state-policy from In Progress to Finished on the VyOS 1.5 Circinus board.
Mar 28 2024, 3:01 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
sarthurdev closed T6147: Conntrack not working as expected with global state-policy as Resolved.
Mar 28 2024, 3:01 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
sarthurdev moved T5606: IPSec VPN: Allow multiple CAs certificates from In Progress to Finished on the VyOS 1.5 Circinus board.

Updated PR to use multi nodes: https://github.com/vyos/vyos-1x/pull/3202

Mar 28 2024, 2:21 PM · VyOS 1.4 Sagitta (1.4.0-epa3)

Mar 21 2024

sarthurdev committed rVYOSONEX62bda3b082a7: conntrack: T6147: Enable conntrack when firewall state-policy is defined.
Mar 21 2024, 12:03 AM

Mar 20 2024

sarthurdev changed the status of T6147: Conntrack not working as expected with global state-policy from In progress to Needs testing.

PR: https://github.com/vyos/vyos-1x/pull/3159

Mar 20 2024, 10:10 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
sarthurdev changed the status of T6147: Conntrack not working as expected with global state-policy from Confirmed to In progress.
Mar 20 2024, 9:47 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
sarthurdev renamed T6147: Conntrack not working as expected with global state-policy from Conntrack not working as expected to Conntrack not working as expected with global state-policy.
Mar 20 2024, 9:47 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
sarthurdev claimed T6147: Conntrack not working as expected with global state-policy.

This likely because the global state policy being reintroduced was not accounted for in the firewall check in conf script. I'll check this week.

Mar 20 2024, 8:14 PM · VyOS 1.4 Sagitta (1.4.0-epa3)

Mar 12 2024

sarthurdev updated subscribers of T6116: VyOS can't work as expected at k8s platform.

Interfaces aren't added on boot because mac address is locally administered: https://github.com/vyos/vyos-1x/blob/current/src/helpers/vyos-interface-rescan.py#L60

Mar 12 2024, 9:11 PM · VyOS Rolling, Bugs
sarthurdev committed rVYOSONEX1fbda3162305: conntrack: T5080: Fix rule order for applied conntrack modules.
Mar 12 2024, 3:14 PM

Mar 11 2024

sarthurdev updated subscribers of T6089: [1.3.6->1.4.0-epa1 Migration] "ospf passive-interface default" incorrectly added.

Pretty sure this is the offending migrator. I briefly discussed this with @c-po

Mar 11 2024, 9:45 AM · VyOS 1.4 Sagitta (1.4.0-epa3)

Mar 9 2024

sarthurdev committed rVYOSONEXc55140f8bbd8: dhcp: T6102: Fix clear DHCP lease op-mode.
Mar 9 2024, 7:09 PM
sarthurdev committed rVYOSONEX0920121eed97: dhcp: T3316: De-duplicate Kea control socket variable.
Mar 9 2024, 7:09 PM

Mar 7 2024

sarthurdev moved T6073: Conntrack/NAT not being disabled when VRFs are defined from In Progress to Finished on the VyOS 1.5 Circinus board.
Mar 7 2024, 3:45 PM · VyOS 1.4 Sagitta (1.4.0-epa2), VyOS 1.5 Circinus
sarthurdev closed T6073: Conntrack/NAT not being disabled when VRFs are defined as Resolved.
Mar 7 2024, 3:45 PM · VyOS 1.4 Sagitta (1.4.0-epa2), VyOS 1.5 Circinus
sarthurdev committed rVYOSONEX4249473dbaf5: config: T4919: Add support for encrypted config file with TPM.
Mar 7 2024, 3:37 PM
sarthurdev committed rVYOSONEX94b2a3a26827: config: T4919: mount/unmount encrypted config on VyOS start/stop.
Mar 7 2024, 3:37 PM
sarthurdev committed rVYOSONEX4a882d3f8dfc: config: T4919: Support copying encrypted volumes during install.
Mar 7 2024, 3:37 PM
sarthurdev changed the status of T6102: Clear dhcp-server lease throws python exception on 1.5-rolling from In progress to Needs testing.

PR: https://github.com/vyos/vyos-1x/pull/3106

Mar 7 2024, 3:17 PM · VyOS 1.5 Circinus

Mar 6 2024

sarthurdev changed the status of T6102: Clear dhcp-server lease throws python exception on 1.5-rolling from Open to In progress.
Mar 6 2024, 9:30 PM · VyOS 1.5 Circinus
sarthurdev claimed T6102: Clear dhcp-server lease throws python exception on 1.5-rolling.
Mar 6 2024, 7:11 PM · VyOS 1.5 Circinus
sarthurdev closed T5992: DHCP: show dhcp server leases not showing all leases as Resolved.
Mar 6 2024, 7:06 PM · VyOS 1.5 Circinus
sarthurdev closed T6063: Kea DHCP: Expose match-client-id setting as Resolved.
Mar 6 2024, 7:06 PM · VyOS 1.5 Circinus
sarthurdev moved T6079: dhcp: migration fails for duplicate static-mapping from In Progress to Finished on the VyOS 1.5 Circinus board.
Mar 6 2024, 7:05 PM · VyOS 1.4 Sagitta (1.4.0-epa2), VyOS 1.5 Circinus
sarthurdev closed T6079: dhcp: migration fails for duplicate static-mapping, a subtask of T5787: dhcp-server allows duplicate static-mapping for the same IP address, as Resolved.
Mar 6 2024, 7:05 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
sarthurdev closed T6079: dhcp: migration fails for duplicate static-mapping as Resolved.
Mar 6 2024, 7:05 PM · VyOS 1.4 Sagitta (1.4.0-epa2), VyOS 1.5 Circinus

Mar 2 2024

sarthurdev committed rVYOSONEX863e67beeff6: dhcp-server: T6079: Disable duplicate static-mappings on migration.
Mar 2 2024, 3:52 PM

Mar 1 2024

sarthurdev committed rVYOSONEX4f311675217f: dhcp-server: T6079: Increment Kea migrator versions.
Mar 1 2024, 12:23 PM
sarthurdev committed rVYOSONEX49a147e27dfa: dhcp-server: T6079: Disable duplicate static-mappings on migration.
Mar 1 2024, 12:23 PM

Feb 28 2024

sarthurdev moved T6079: dhcp: migration fails for duplicate static-mapping from Open to In Progress on the VyOS 1.5 Circinus board.
Feb 28 2024, 11:48 PM · VyOS 1.4 Sagitta (1.4.0-epa2), VyOS 1.5 Circinus
sarthurdev changed the status of T6079: dhcp: migration fails for duplicate static-mapping, a subtask of T5787: dhcp-server allows duplicate static-mapping for the same IP address, from Open to Needs testing.
Feb 28 2024, 11:48 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
sarthurdev changed the status of T6079: dhcp: migration fails for duplicate static-mapping from Open to Needs testing.

1.4 https://github.com/vyos/vyos-1x/pull/3062
1.5 https://github.com/vyos/vyos-1x/pull/3061

Feb 28 2024, 11:48 PM · VyOS 1.4 Sagitta (1.4.0-epa2), VyOS 1.5 Circinus
sarthurdev added a comment to T6076: [1.3.3->1.4.0-epa1 Migration] Most of config missing.

Firewall failed migration due to incorrect subnet, 1.3 firewall did not correctly validate those fields. Correcting source address on rule 30 on TO-ROUTER chain should migrate the firewall properly.

Feb 28 2024, 8:32 PM · Bugs, VyOS 1.4 Sagitta (1.4.1), VyOS 1.5 Circinus
sarthurdev committed rVYOSONEXbc9ccaeda542: smoketest: T5160: Deduplicate nftables verify functions to testcase class….
Feb 28 2024, 7:35 PM
sarthurdev committed rVYOSONEX6f7d1e156656: vrf: conntrack: T6073: Populate VRF zoning chains only while conntrack is….
Feb 28 2024, 7:35 PM

Feb 27 2024

sarthurdev moved T6073: Conntrack/NAT not being disabled when VRFs are defined from Open to In Progress on the VyOS 1.4 Sagitta board.
Feb 27 2024, 10:09 PM · VyOS 1.4 Sagitta (1.4.0-epa2), VyOS 1.5 Circinus
sarthurdev changed the status of T6073: Conntrack/NAT not being disabled when VRFs are defined from In progress to Needs testing.

PR: https://github.com/vyos/vyos-1x/pull/3055

Feb 27 2024, 10:09 PM · VyOS 1.4 Sagitta (1.4.0-epa2), VyOS 1.5 Circinus
sarthurdev renamed T6073: Conntrack/NAT not being disabled when VRFs are defined from Conntrack/NAT not being disabled to Conntrack/NAT not being disabled when VRFs are defined.
Feb 27 2024, 7:07 PM · VyOS 1.4 Sagitta (1.4.0-epa2), VyOS 1.5 Circinus
sarthurdev closed T5080: Disable conntrack by default, a subtask of T5160: Firewall refactor, as Resolved.
Feb 27 2024, 7:06 PM · VyOS 1.4 Sagitta
sarthurdev closed T5080: Disable conntrack by default as Resolved.

Not a regression as far as this task is concerned. Will update T6073

Feb 27 2024, 7:06 PM · VyOS 1.4 Sagitta (1.4.0-epa3)

Feb 26 2024

sarthurdev committed rVYOSONEX83b435ffe1a6: dhcp-server: T6063: Add `ignore-client-id` to relax client identifier checks….
Feb 26 2024, 2:26 PM
sarthurdev triaged T6068: Support active-active and active-passive high availability modes in DHCP server as Wishlist priority.
Feb 26 2024, 11:32 AM · VyOS 1.4 Sagitta (1.4.0-epa3)

Feb 25 2024

sarthurdev changed the status of T6063: Kea DHCP: Expose match-client-id setting from Open to Needs testing.

PR: https://github.com/vyos/vyos-1x/pull/3049

Feb 25 2024, 10:43 PM · VyOS 1.5 Circinus

Feb 24 2024

sarthurdev claimed T6063: Kea DHCP: Expose match-client-id setting.
Feb 24 2024, 10:44 PM · VyOS 1.5 Circinus

Feb 23 2024

sarthurdev committed rVYOSONEX1f22ac1bb0a3: pki: T6055: Cleanup unnecessary sudo, preserve env when sudo is needed.
Feb 23 2024, 1:01 PM
sarthurdev committed rVYOSONEXe2adfdef9e79: pki: T3642: Fix typo in PKI includes.
Feb 23 2024, 1:01 PM
sarthurdev moved T6055: PKI error: "failed to install x value" when executed the command from conf mode from Need Triage to In Progress on the VyOS 1.4 Sagitta (1.4.0-epa1) board.
Feb 23 2024, 12:43 PM · VyOS 1.4 Sagitta (1.4.0-epa2)
sarthurdev changed the status of T6055: PKI error: "failed to install x value" when executed the command from conf mode from Open to Needs testing.

PR: https://github.com/vyos/vyos-1x/pull/3040

Feb 23 2024, 12:40 PM · VyOS 1.4 Sagitta (1.4.0-epa2)
sarthurdev moved T5376: Conntrack FTP helper does not work properly from In Progress to Finished on the VyOS 1.5 Circinus board.
Feb 23 2024, 12:23 PM · VyOS 1.4 Sagitta (1.4.0-epa1), VyOS 1.5 Circinus
sarthurdev closed T5376: Conntrack FTP helper does not work properly as Resolved.

Glad to hear it @svd135 @swanduron

Feb 23 2024, 12:23 PM · VyOS 1.4 Sagitta (1.4.0-epa1), VyOS 1.5 Circinus
sarthurdev claimed T6055: PKI error: "failed to install x value" when executed the command from conf mode.
Feb 23 2024, 10:20 AM · VyOS 1.4 Sagitta (1.4.0-epa2)