Page MenuHomePhabricator
Feed Advanced Search

Today

c-po closed T1525: OpenVPN server clients disconnected after 60 mins as Invalid.
Tue, Sep 17, 3:41 AM · VyOS 1.3 Equuleus

Yesterday

c-po claimed T1666: Deleting a bond will place member interfaces into A/D state.
Mon, Sep 16, 5:55 PM · VyOS 1.3 Equuleus
c-po added a comment to T628: StrongSwan requires configuration change for proper routing over VTI..

@LBegnaud if I read the source correct the command set vpn ipsec options disable-route-autoinstall is what you are looking for, it was implemented in T71

Mon, Sep 16, 5:27 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
c-po created T1666: Deleting a bond will place member interfaces into A/D state.
Mon, Sep 16, 4:28 PM · VyOS 1.3 Equuleus

Sun, Sep 15

c-po added a comment to T1637: Rewrite ethernet interface in new style XML syntax.

This could be used as base for testing:

Sun, Sep 15, 3:00 PM · VyOS 1.3 Equuleus
c-po closed T1630: OpenVPN after changing it from root to nobody (unprivileged user) cant add routes, a subtask of T1548: Rewrite OpenVPN interface/op-commands in new style XML/Python, as Resolved.
Sun, Sep 15, 11:56 AM · VyOS 1.3 Equuleus
c-po closed T1630: OpenVPN after changing it from root to nobody (unprivileged user) cant add routes as Resolved.
Sun, Sep 15, 11:56 AM · VyOS 1.3 Equuleus
c-po added a comment to T1630: OpenVPN after changing it from root to nobody (unprivileged user) cant add routes.

No feedback received, considering this as resolved. please reopen if issue reappears.

Sun, Sep 15, 11:56 AM · VyOS 1.3 Equuleus
c-po closed T1662: openvpn: 'show openvpn client' error as Resolved.
Sun, Sep 15, 8:52 AM · VyOS 1.3 Equuleus
c-po closed T1661: openvpn: wrong checking for existence cert files as Resolved.
Sun, Sep 15, 8:51 AM · VyOS 1.3 Equuleus

Fri, Sep 13

c-po added a comment to T1660: Bonding dont’t work on VyOS 1.2-rolling-201909120338.

Please test again with the rolling release from 2019-09-14. Thanks for reporting the issue.

Fri, Sep 13, 6:44 PM · VyOS 1.2 Crux
c-po added a subtask for T1614: Rewrite bonding interface in new style XML syntax: T1660: Bonding dont’t work on VyOS 1.2-rolling-201909120338.
Fri, Sep 13, 6:41 PM · VyOS 1.3 Equuleus
c-po added a parent task for T1660: Bonding dont’t work on VyOS 1.2-rolling-201909120338: T1614: Rewrite bonding interface in new style XML syntax.
Fri, Sep 13, 6:41 PM · VyOS 1.2 Crux
c-po closed T1660: Bonding dont’t work on VyOS 1.2-rolling-201909120338 as Resolved.
Fri, Sep 13, 6:40 PM · VyOS 1.2 Crux

Thu, Sep 12

c-po added a parent task for T1466: Add EAPOL login support: T1637: Rewrite ethernet interface in new style XML syntax.
Thu, Sep 12, 6:44 AM · VyOS 1.3 Equuleus
c-po added a subtask for T1637: Rewrite ethernet interface in new style XML syntax: T1466: Add EAPOL login support.
Thu, Sep 12, 6:44 AM · VyOS 1.3 Equuleus

Tue, Sep 10

c-po added a comment to T1648: add cli command 'delete wireguard named-key <key>'.

Why can I not delete the default key? If I wan‘t to drop WireGuard on a device I also wan’t to remove that key.

Tue, Sep 10, 5:30 PM · VyOS 1.3 Equuleus

Sat, Sep 7

c-po updated the task description for T1640: Update Linux Kernel to v4.19.70.
Sat, Sep 7, 10:21 PM · VyOS 1.3 Equuleus
c-po closed T1640: Update Linux Kernel to v4.19.70 as Resolved.
Sat, Sep 7, 10:19 PM · VyOS 1.3 Equuleus
c-po created T1640: Update Linux Kernel to v4.19.70.
Sat, Sep 7, 10:17 PM · VyOS 1.3 Equuleus

Fri, Sep 6

c-po changed the status of T1637: Rewrite ethernet interface in new style XML syntax from Open to In progress.
Fri, Sep 6, 1:26 PM · VyOS 1.3 Equuleus
c-po changed the status of T1637: Rewrite ethernet interface in new style XML syntax, a subtask of T1579: Rewrite all interface types in new XML/Python style, from Open to In progress.
Fri, Sep 6, 1:26 PM · VyOS 1.3 Equuleus
c-po created T1637: Rewrite ethernet interface in new style XML syntax.
Fri, Sep 6, 1:26 PM · VyOS 1.3 Equuleus
c-po changed the status of T1630: OpenVPN after changing it from root to nobody (unprivileged user) cant add routes from Open to Needs testing.
Fri, Sep 6, 1:20 PM · VyOS 1.3 Equuleus
c-po changed the status of T1630: OpenVPN after changing it from root to nobody (unprivileged user) cant add routes, a subtask of T1548: Rewrite OpenVPN interface/op-commands in new style XML/Python, from Open to Needs testing.
Fri, Sep 6, 1:20 PM · VyOS 1.3 Equuleus
c-po added a comment to T1630: OpenVPN after changing it from root to nobody (unprivileged user) cant add routes.

OpenVPN now runs as user openvpn with the above helper script. Please also test this new implementation, it will be in the rolling ISO which is building right now.

Fri, Sep 6, 1:19 PM · VyOS 1.3 Equuleus
c-po added a comment to T1630: OpenVPN after changing it from root to nobody (unprivileged user) cant add routes.

Persistent tunnel is a configuration option set interfaces openvpn vtun10 persistent-tunnel

Fri, Sep 6, 11:07 AM · VyOS 1.3 Equuleus
c-po closed T1636: Rewrite VXLAN in new style XML/Python, a subtask of T1579: Rewrite all interface types in new XML/Python style, as Resolved.
Fri, Sep 6, 11:03 AM · VyOS 1.3 Equuleus
c-po closed T1636: Rewrite VXLAN in new style XML/Python as Resolved.
Fri, Sep 6, 11:03 AM · VyOS 1.3 Equuleus
c-po updated the task description for T1636: Rewrite VXLAN in new style XML/Python.
Fri, Sep 6, 11:03 AM · VyOS 1.3 Equuleus

Thu, Sep 5

c-po added a comment to T770: Bonded interfaces get updated with incorrect hw-id in config..

Huh? Which perl script?

Thu, Sep 5, 5:43 PM · VyOS 1.2 Crux, VyOS 1.3 Equuleus
c-po added a comment to T770: Bonded interfaces get updated with incorrect hw-id in config..

As the bonding interface has been completely rewritten this should not be an issue as I do not touch underlaying interface MAC addresses

Thu, Sep 5, 4:19 PM · VyOS 1.2 Crux, VyOS 1.3 Equuleus
c-po added a comment to T1572: Wireguard keyPair per interface.

Why not specify the keys or the key file location via CLI like other VPN implementations do it?

Thu, Sep 5, 3:51 AM · VyOS 1.3 Equuleus
c-po changed the status of T1636: Rewrite VXLAN in new style XML/Python, a subtask of T1579: Rewrite all interface types in new XML/Python style, from Open to In progress.
Thu, Sep 5, 3:49 AM · VyOS 1.3 Equuleus
c-po changed the status of T1636: Rewrite VXLAN in new style XML/Python from Open to In progress.
Thu, Sep 5, 3:49 AM · VyOS 1.3 Equuleus
c-po created T1636: Rewrite VXLAN in new style XML/Python.
Thu, Sep 5, 3:49 AM · VyOS 1.3 Equuleus

Wed, Sep 4

c-po closed T1439: DHCPv6 static-mappings not working due to excess quotes around dhcp6.client-id as Resolved.
Wed, Sep 4, 7:28 PM · VyOS 1.2 Crux (VyOS 1.2.3), VyOS 1.3 Equuleus
c-po moved T1439: DHCPv6 static-mappings not working due to excess quotes around dhcp6.client-id from Needs Triage to Finished on the VyOS 1.2 Crux (VyOS 1.2.3) board.
Wed, Sep 4, 7:28 PM · VyOS 1.2 Crux (VyOS 1.2.3), VyOS 1.3 Equuleus
c-po moved T1439: DHCPv6 static-mappings not working due to excess quotes around dhcp6.client-id from VyOS 1.2.4 to VyOS 1.2.3 on the VyOS 1.2 Crux board.
Wed, Sep 4, 7:28 PM · VyOS 1.2 Crux (VyOS 1.2.3), VyOS 1.3 Equuleus
c-po moved T1439: DHCPv6 static-mappings not working due to excess quotes around dhcp6.client-id from Need Triage to Finished on the VyOS 1.3 Equuleus board.
Wed, Sep 4, 7:27 PM · VyOS 1.2 Crux (VyOS 1.2.3), VyOS 1.3 Equuleus
c-po closed T1632: OpenVPN 'push' options with quotes as Resolved.
Wed, Sep 4, 6:35 PM · VyOS 1.3 Equuleus
c-po added a comment to T1632: OpenVPN 'push' options with quotes.

You could use quoting like mentioned in T1129.

Wed, Sep 4, 6:31 PM · VyOS 1.3 Equuleus
c-po added a comment to T1614: Rewrite bonding interface in new style XML syntax.

Rewrite was tested using:

Wed, Sep 4, 2:43 PM · VyOS 1.3 Equuleus
c-po closed T1557: Create generic abstraction for configuring interfaces e.g. IP address as Resolved.
Wed, Sep 4, 2:39 PM · VyOS 1.3 Equuleus
c-po closed T1557: Create generic abstraction for configuring interfaces e.g. IP address, a subtask of T1579: Rewrite all interface types in new XML/Python style, as Resolved.
Wed, Sep 4, 2:39 PM · VyOS 1.3 Equuleus
c-po closed T1631: Multiple push-route options cause error generating openvpn configuration, a subtask of T1548: Rewrite OpenVPN interface/op-commands in new style XML/Python, as Resolved.
Wed, Sep 4, 2:39 PM · VyOS 1.3 Equuleus
c-po closed T1631: Multiple push-route options cause error generating openvpn configuration as Resolved.
Wed, Sep 4, 2:39 PM · VyOS 1.3 Equuleus
c-po closed T1614: Rewrite bonding interface in new style XML syntax, a subtask of T1579: Rewrite all interface types in new XML/Python style, as Resolved.
Wed, Sep 4, 2:38 PM · VyOS 1.3 Equuleus
c-po closed T1614: Rewrite bonding interface in new style XML syntax as Resolved.
Wed, Sep 4, 2:38 PM · VyOS 1.3 Equuleus
c-po updated the task description for T1614: Rewrite bonding interface in new style XML syntax.
Wed, Sep 4, 2:38 PM · VyOS 1.3 Equuleus
c-po added a comment to T1630: OpenVPN after changing it from root to nobody (unprivileged user) cant add routes.

I like the openvpn:openvpn ownership idea

Wed, Sep 4, 2:15 PM · VyOS 1.3 Equuleus
c-po added a comment to T1633: Cannot bridge interfaces.

The documentation is also correct. Please not that there are two git branches for the documentation, current and equuleus. You send me the VyOS 1.2.2 crux link. I gave you the upcoming VyOS 1.2 equuleus link.

Wed, Sep 4, 1:57 PM · VyOS 1.2 Crux
c-po added a comment to T1631: Multiple push-route options cause error generating openvpn configuration.

This is actually a duplicate of T1617.

Wed, Sep 4, 12:58 PM · VyOS 1.3 Equuleus
c-po closed T1633: Cannot bridge interfaces as Invalid.
Wed, Sep 4, 12:37 PM · VyOS 1.2 Crux
c-po added a comment to T1633: Cannot bridge interfaces.

The bahavior has changed, see https://vyos.readthedocs.io/en/equuleus/interfaces/bridging.html

Wed, Sep 4, 12:36 PM · VyOS 1.2 Crux
c-po added a comment to T1631: Multiple push-route options cause error generating openvpn configuration.

1.3 rolling is not recommended for users - its pre-alpha.

Wed, Sep 4, 12:35 PM · VyOS 1.3 Equuleus
c-po added a comment to T1631: Multiple push-route options cause error generating openvpn configuration.

@jdevincentis is this a custom build? Using VyOS 1.2-rolling-201909040337 I can not reproduce the issue with:

Wed, Sep 4, 12:10 PM · VyOS 1.3 Equuleus
c-po claimed T1632: OpenVPN 'push' options with quotes.
Wed, Sep 4, 7:22 AM · VyOS 1.3 Equuleus
c-po added a subtask for T1548: Rewrite OpenVPN interface/op-commands in new style XML/Python: T1631: Multiple push-route options cause error generating openvpn configuration.
Wed, Sep 4, 7:20 AM · VyOS 1.3 Equuleus
c-po added a parent task for T1631: Multiple push-route options cause error generating openvpn configuration: T1548: Rewrite OpenVPN interface/op-commands in new style XML/Python.
Wed, Sep 4, 7:20 AM · VyOS 1.3 Equuleus
c-po changed the status of T1631: Multiple push-route options cause error generating openvpn configuration from Open to In progress.
Wed, Sep 4, 7:20 AM · VyOS 1.3 Equuleus

Tue, Sep 3

c-po added a comment to T1630: OpenVPN after changing it from root to nobody (unprivileged user) cant add routes.

The config generator would need to be adopted https://github.com/vyos/vyos-1x/blob/current/src/conf_mode/interface-openvpn.py and the wrapper script added. I have no time before tomorrow, sorry

Tue, Sep 3, 5:30 PM · VyOS 1.3 Equuleus
c-po added a comment to T1448: Permissions after image update .

Please test with latest rolling and not a custom build.

Tue, Sep 3, 4:18 PM · Rejected
c-po added a parent task for T1630: OpenVPN after changing it from root to nobody (unprivileged user) cant add routes: T1548: Rewrite OpenVPN interface/op-commands in new style XML/Python.
Tue, Sep 3, 4:17 PM · VyOS 1.3 Equuleus
c-po added a subtask for T1548: Rewrite OpenVPN interface/op-commands in new style XML/Python: T1630: OpenVPN after changing it from root to nobody (unprivileged user) cant add routes.
Tue, Sep 3, 4:17 PM · VyOS 1.3 Equuleus
c-po claimed T1630: OpenVPN after changing it from root to nobody (unprivileged user) cant add routes.
Tue, Sep 3, 4:17 PM · VyOS 1.3 Equuleus
c-po added a comment to T1630: OpenVPN after changing it from root to nobody (unprivileged user) cant add routes.

When the site looses connection and thus a SIGUSR21 is sent to OpenVPN to restart internally the priviledges have dropped and yes, /sbin/ip can't be called again.

Tue, Sep 3, 4:16 PM · VyOS 1.3 Equuleus
c-po moved T1629: IP addresses configured on vif-s interfaces are not added to the system from Need Triage to VyOS 1.2.4 on the VyOS 1.2 Crux board.
Tue, Sep 3, 2:59 PM · VyOS 1.2 Crux (VyOS 1.2.4)
c-po assigned T1629: IP addresses configured on vif-s interfaces are not added to the system to dmbaturin.
Tue, Sep 3, 2:59 PM · VyOS 1.2 Crux (VyOS 1.2.4)
c-po created T1629: IP addresses configured on vif-s interfaces are not added to the system.
Tue, Sep 3, 2:58 PM · VyOS 1.2 Crux (VyOS 1.2.4)
c-po assigned T1628: Adopt WireGuard configuration script to new vyos.ifconfig class to hagbard.
Tue, Sep 3, 12:01 PM · VyOS 1.3 Equuleus
c-po created T1628: Adopt WireGuard configuration script to new vyos.ifconfig class.
Tue, Sep 3, 12:01 PM · VyOS 1.3 Equuleus
c-po updated the task description for T1627: Rewrite wireless interface in new style XML syntax.
Tue, Sep 3, 10:21 AM · VyOS 1.3 Equuleus
c-po created T1627: Rewrite wireless interface in new style XML syntax.
Tue, Sep 3, 10:21 AM · VyOS 1.3 Equuleus
c-po updated the task description for T1564: BGP IPv6 only peer-group not supported.
Tue, Sep 3, 9:02 AM · VyOS 1.3 Equuleus
c-po updated the task description for T1564: BGP IPv6 only peer-group not supported.
Tue, Sep 3, 9:01 AM · VyOS 1.3 Equuleus
c-po updated the task description for T1626: BGP exchanges prefixes withou specified address-family.
Tue, Sep 3, 8:49 AM · VyOS 1.2 Crux
c-po created T1626: BGP exchanges prefixes withou specified address-family.
Tue, Sep 3, 8:49 AM · VyOS 1.2 Crux

Mon, Sep 2

c-po added a comment to T1624: Failed to set up config session.

Reverted https://github.com/vyos/vyatta-cfg/commit/710728ee8eb6def82f9a142468960f6985dcf4e8

Mon, Sep 2, 6:43 PM · VyOS 1.3 Equuleus

Sun, Sep 1

c-po triaged T1624: Failed to set up config session as Unbreak Now! priority.
Sun, Sep 1, 4:36 PM · VyOS 1.3 Equuleus
c-po created T1624: Failed to set up config session.
Sun, Sep 1, 4:36 PM · VyOS 1.3 Equuleus
c-po added a comment to T1557: Create generic abstraction for configuring interfaces e.g. IP address.

@hagbard not a problem. Looks like we now go the "our own lib" way as pyroute2 has some flaws. DHCP is already fix and I continue improve the script and remove redundant code before it will be extended to support VLAN/bonding.

Sun, Sep 1, 8:03 AM · VyOS 1.3 Equuleus

Sat, Aug 31

c-po claimed T1557: Create generic abstraction for configuring interfaces e.g. IP address.
Sat, Aug 31, 11:14 AM · VyOS 1.3 Equuleus
c-po added a comment to T1557: Create generic abstraction for configuring interfaces e.g. IP address.

DHCP + DHCPv6 working now in bridge interface.

Sat, Aug 31, 11:14 AM · VyOS 1.3 Equuleus

Thu, Aug 29

c-po closed T1618: ping wont accept arguments as Invalid.
Thu, Aug 29, 10:12 AM · Rejected
c-po added a comment to T1618: ping wont accept arguments.

This is "as intended" b/c ping is an op-mode command.

Thu, Aug 29, 10:12 AM · Rejected

Wed, Aug 28

c-po added a comment to T1615: After migration to pyroute2 the address DHCP statement is no longer covered.

https://github.com/vyos/vyos-1x/commit/71f7a947539963112c61fef2a5f278d524d71198

Wed, Aug 28, 9:01 AM · VyOS 1.3 Equuleus
c-po added a comment to T1557: Create generic abstraction for configuring interfaces e.g. IP address.

@hagbard during some tests with the bridge interface (https://github.com/vyos/vyos-1x/commit/71f7a947539963112c61fef2a5f278d524d71198) I noticed the following:

Wed, Aug 28, 9:00 AM · VyOS 1.3 Equuleus
c-po closed T1615: After migration to pyroute2 the address DHCP statement is no longer covered, a subtask of T1556: Rewrite Bridge in new style XML syntax, as Resolved.
Wed, Aug 28, 8:58 AM · VyOS 1.3 Equuleus
c-po closed T1615: After migration to pyroute2 the address DHCP statement is no longer covered as Resolved.
Wed, Aug 28, 8:58 AM · VyOS 1.3 Equuleus
c-po added a comment to T1557: Create generic abstraction for configuring interfaces e.g. IP address.

Pyroute2 states:

One of the major issues with IPDB is its memory footprint. It proved not to be suitable for environments with thousands of routes or neighbours. Being a design issue, it could not be fixed, so a new module was started, NDB, that aims to replace IPDB. IPDB is still more feature rich, but NDB is already more fast and stable.

Wed, Aug 28, 8:53 AM · VyOS 1.3 Equuleus

Tue, Aug 27

c-po closed T1613: IPv6 traffic is not captured by NetFlow sensor (pmacct/NFLOG) as Resolved.
Tue, Aug 27, 8:24 PM · VyOS 1.2 Crux (VyOS 1.2.3), VyOS 1.3 Equuleus
c-po moved T1613: IPv6 traffic is not captured by NetFlow sensor (pmacct/NFLOG) from Need Triage to Finished on the VyOS 1.3 Equuleus board.
Tue, Aug 27, 8:24 PM · VyOS 1.2 Crux (VyOS 1.2.3), VyOS 1.3 Equuleus
c-po moved T1613: IPv6 traffic is not captured by NetFlow sensor (pmacct/NFLOG) from Needs Triage to Finished on the VyOS 1.2 Crux (VyOS 1.2.3) board.
Tue, Aug 27, 8:24 PM · VyOS 1.2 Crux (VyOS 1.2.3), VyOS 1.3 Equuleus
c-po edited projects for T1613: IPv6 traffic is not captured by NetFlow sensor (pmacct/NFLOG), added: VyOS 1.2 Crux (VyOS 1.2.3); removed VyOS 1.2 Crux.
Tue, Aug 27, 8:24 PM · VyOS 1.2 Crux (VyOS 1.2.3), VyOS 1.3 Equuleus
c-po added a project to T1613: IPv6 traffic is not captured by NetFlow sensor (pmacct/NFLOG): VyOS 1.3 Equuleus.
Tue, Aug 27, 8:23 PM · VyOS 1.2 Crux (VyOS 1.2.3), VyOS 1.3 Equuleus
c-po added a comment to T1613: IPv6 traffic is not captured by NetFlow sensor (pmacct/NFLOG).

backported to crux

Tue, Aug 27, 8:23 PM · VyOS 1.2 Crux (VyOS 1.2.3), VyOS 1.3 Equuleus
c-po closed T1617: OpenVPN push route failure as Resolved.
Tue, Aug 27, 8:19 PM · VyOS 1.3 Equuleus
c-po closed T1617: OpenVPN push route failure, a subtask of T1548: Rewrite OpenVPN interface/op-commands in new style XML/Python, as Resolved.
Tue, Aug 27, 8:19 PM · VyOS 1.3 Equuleus
c-po added a subtask for T1548: Rewrite OpenVPN interface/op-commands in new style XML/Python: T1617: OpenVPN push route failure.
Tue, Aug 27, 8:19 PM · VyOS 1.3 Equuleus