Page MenuHomeVyOS Platform
Feed All Stories

Nov 9 2022

TheSin- updated the task description for T4797: External address/network lists for firewall (Local and remote).
Nov 9 2022, 9:48 PM · VyOS 1.5 Circinus
GitHub <[email protected]> closed T4800: undefined var includes_chroot_dir in build-vyos-image as Resolved by committing Restricted Diffusion Commit.
Nov 9 2022, 7:46 PM · VyOS 1.4 Sagitta
TheSin- renamed T4797: External address/network lists for firewall (Local and remote) from Blocklists (Local and remote) to External address/network lists for firewall (Local and remote).
Nov 9 2022, 5:56 PM · VyOS 1.5 Circinus
TheSin- added a comment to T4797: External address/network lists for firewall (Local and remote).

task-scheduler logic was moved into vyos.task_scheduler so it can be imported properly and used by other modules

Nov 9 2022, 3:36 PM · VyOS 1.5 Circinus
initramfs added a comment to T4799: PowerDNS >= 4.7 does not get reloaded by vyos-hostsd.

@c-po I noticed you've reverted the commit, may I ask how you're able to reproduce the process name of 'pdns-r/worker'? Just doing the testing again with the latest build as of writing (vyos-1.4-rolling-202211060813-amd64.iso), I get:

Nov 9 2022, 8:49 AM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.3)

Nov 8 2022

TheSin- added a comment to T4797: External address/network lists for firewall (Local and remote).

In the PR it was requested to change the group category from lists to external-list which I'm fine with, but before I do the work to rename files and fields, does everyone agree with this change?

Nov 8 2022, 10:09 PM · VyOS 1.5 Circinus
TheSin- changed the status of T4797: External address/network lists for firewall (Local and remote) from Open to In progress.
Nov 8 2022, 9:01 PM · VyOS 1.5 Circinus
roedie changed the status of T4809: radvd: Allow use of AdvRASrcAddress from Open to In progress.
Nov 8 2022, 8:58 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
roedie added a comment to T4809: radvd: Allow use of AdvRASrcAddress.

I've added PR https://github.com/vyos/vyos-1x/pull/1649 for review. Not tested yet, I want to know if I'm on the right path.

Nov 8 2022, 8:57 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
roedie created T4809: radvd: Allow use of AdvRASrcAddress.
Nov 8 2022, 8:47 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
TheSin- added a comment to T4797: External address/network lists for firewall (Local and remote).

PR was added, I'm just trying to learn the documentation system now. Though to be frank documentation has never been my strong suit.

Nov 8 2022, 7:29 PM · VyOS 1.5 Circinus
c-po closed T4806: Update FRR to 8.4 in 1.4 version as Resolved.
Nov 8 2022, 7:12 PM · VyOS 1.4 Sagitta
c-po moved T4806: Update FRR to 8.4 in 1.4 version from Need Triage to Finished on the VyOS 1.4 Sagitta board.
Nov 8 2022, 7:05 PM · VyOS 1.4 Sagitta
jestabro added a comment to T4808: Add details of configtree operations to migration log.

To be a PR, after discussion with @sdev :
https://github.com/vyos/vyos-1x/compare/current...jestabro:trace-migration

Nov 8 2022, 4:59 PM · VyOS 1.4 Sagitta
jestabro triaged T4808: Add details of configtree operations to migration log as Normal priority.
Nov 8 2022, 4:40 PM · VyOS 1.4 Sagitta
pasik added a comment to T4737: FRRouting/zebra 7.5.1 does not redistribute routes to other protocols.

@v.huti Thanks for investigating and testing! How about you create a PR with the patch against 1.3 / equuleus ?

Nov 8 2022, 12:25 PM · VyOS 1.3 Equuleus (1.3.3)
marc_s added a comment to T4776: NVME storage is not detected properly during installation.

TLDR; confirmed fixed for 1.3, please backport.

Nov 8 2022, 11:15 AM · VyOS 1.3 Equuleus (1.3.5), VyOS 1.4 Sagitta
Viacheslav closed T4771: Rewrite protocol BGP op-mode to vyos.opmode format, a subtask of T4564: Root task for rewriting [op-mode] to vyos.opmode format, as Resolved.
Nov 8 2022, 9:46 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
Viacheslav closed T4771: Rewrite protocol BGP op-mode to vyos.opmode format as Resolved.
Nov 8 2022, 9:46 AM · VyOS 1.4 Sagitta
a.apostoliuk added a subtask for T4496: ping vrf help does not list VRFs: T4807: Need to fix traceroute help completion.
Nov 8 2022, 9:24 AM · VyOS 1.4 Sagitta
a.apostoliuk added a parent task for T4807: Need to fix traceroute help completion: T4496: ping vrf help does not list VRFs.
Nov 8 2022, 9:24 AM · VyOS 1.4 Sagitta
a.apostoliuk changed the status of T4807: Need to fix traceroute help completion from Open to In progress.
Nov 8 2022, 9:23 AM · VyOS 1.4 Sagitta
a.apostoliuk claimed T4807: Need to fix traceroute help completion.
Nov 8 2022, 9:23 AM · VyOS 1.4 Sagitta
a.apostoliuk created T4807: Need to fix traceroute help completion.
Nov 8 2022, 9:23 AM · VyOS 1.4 Sagitta
a.apostoliuk moved T4496: ping vrf help does not list VRFs from Need Triage to Finished on the VyOS 1.4 Sagitta board.
Nov 8 2022, 8:54 AM · VyOS 1.4 Sagitta
a.apostoliuk changed the status of T4496: ping vrf help does not list VRFs from In progress to Needs testing.
Nov 8 2022, 8:50 AM · VyOS 1.4 Sagitta
c-po added a comment to T4806: Update FRR to 8.4 in 1.4 version.

FRRouting Release 8.4 Available for Download
November 7, 2022

Nov 8 2022, 6:34 AM · VyOS 1.4 Sagitta
c-po changed the status of T4806: Update FRR to 8.4 in 1.4 version from Open to In progress.
Nov 8 2022, 6:29 AM · VyOS 1.4 Sagitta
Cheeze_It added a comment to T4806: Update FRR to 8.4 in 1.4 version.

One miracle at a time :)

Nov 8 2022, 1:16 AM · VyOS 1.4 Sagitta

Nov 7 2022

aalmenar added a project to T4806: Update FRR to 8.4 in 1.4 version: VyOS 1.4 Sagitta.
Nov 7 2022, 10:57 PM · VyOS 1.4 Sagitta
aalmenar created T4806: Update FRR to 8.4 in 1.4 version.
Nov 7 2022, 10:56 PM · VyOS 1.4 Sagitta
Viacheslav changed the status of T4799: PowerDNS >= 4.7 does not get reloaded by vyos-hostsd from Open to Needs testing.
Nov 7 2022, 7:41 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.3)
Viacheslav changed the status of T4789: Ability to get L2TP/PPTP/SSTP sessions info in a machine readable format, a subtask of T4564: Root task for rewriting [op-mode] to vyos.opmode format, from Open to In progress.
Nov 7 2022, 5:53 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
Viacheslav changed the status of T4789: Ability to get L2TP/PPTP/SSTP sessions info in a machine readable format from Open to In progress.

PR https://github.com/vyos/vyos-1x/pull/1643

Nov 7 2022, 5:53 PM · VyOS 1.4 Sagitta
Viacheslav created T4805: PPPoE server does not restart service if pool was changed.
Nov 7 2022, 5:25 PM · VyOS 1.4 Sagitta
Viacheslav created T4804: PPPoE server incorrect unconfigured check.
Nov 7 2022, 4:28 PM · VyOS 1.4 Sagitta
a.apostoliuk added a project to T4790: RADIUS login does not work if sum of timeouts more than 50s : VyOS 1.4 Sagitta.
Nov 7 2022, 1:33 PM · VyOS 1.3 Equuleus (1.3.4), VyOS 1.4 Sagitta
a.apostoliuk renamed T4790: RADIUS login does not work if sum of timeouts more than 50s from SSH login timeout if RADIUS timeout more than 60s to RADIUS login does not work if sum of timeouts more than 50s .
Nov 7 2022, 1:31 PM · VyOS 1.3 Equuleus (1.3.4), VyOS 1.4 Sagitta
v.huti added a comment to T4737: FRRouting/zebra 7.5.1 does not redistribute routes to other protocols.

Hi @zsdc! This seems to be related to T4028. The relevant commits are:

━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓
commit 92980561382fc04380414a6e2f6ca6746c2fe5e9 ┃
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┻━━━━━━━━━━━━━━━━━━━━━━━━━
Author: Donald Sharp <[email protected]>
Date:   Mon Apr 19 19:23:45 2021 -0400
Nov 7 2022, 1:17 PM · VyOS 1.3 Equuleus (1.3.3)
ssasso added a comment to T4801: Support for building AWS-ready ISO.

https://github.com/vyos/vyos-build/pull/277

Nov 7 2022, 12:29 PM · VyOS 1.4 Sagitta
hard added a comment to T4502: Consider implementing (NAT/other) flow table offload.

i see it like that

Nov 7 2022, 9:51 AM · VyOS 1.4 Sagitta
Viacheslav changed the status of T4801: Support for building AWS-ready ISO from Open to In progress.
Nov 7 2022, 8:45 AM · VyOS 1.4 Sagitta

Nov 6 2022

c-po closed T2913: Failure to install fpm while building builder docker image as Resolved.
Nov 6 2022, 8:08 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.2 Crux (VyOS 1.2.8)
c-po added a comment to T2913: Failure to install fpm while building builder docker image.

re-signed crux repo

Nov 6 2022, 8:08 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.2 Crux (VyOS 1.2.8)
jestabro closed T4803: The header 'Authorization' needs to be explictly allowed in http-api CORS middleware as Resolved.
Nov 6 2022, 3:33 PM · VyOS 1.4 Sagitta
jestabro triaged T4803: The header 'Authorization' needs to be explictly allowed in http-api CORS middleware as Normal priority.
Nov 6 2022, 3:29 PM · VyOS 1.4 Sagitta
Rain added a comment to T4612: Support arbitrary netmasks in firewall rules.

I'm not sure if wildcard-address fits. The address and the mask together combine to create the wildcard.

Nov 6 2022, 4:34 AM · VyOS 1.4 Sagitta

Nov 5 2022

c-po closed T4802: Ability to define per container shared-memory size as Resolved.
Nov 5 2022, 6:54 PM · VyOS 1.4 Sagitta
c-po closed T4802: Ability to define per container shared-memory size, a subtask of T578: Support Linux Container, as Resolved.
Nov 5 2022, 6:54 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
c-po moved T4802: Ability to define per container shared-memory size from Need Triage to Finished on the VyOS 1.4 Sagitta board.
Nov 5 2022, 6:53 PM · VyOS 1.4 Sagitta
c-po changed the status of T4802: Ability to define per container shared-memory size, a subtask of T578: Support Linux Container, from Open to In progress.
Nov 5 2022, 6:47 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
c-po changed the status of T4802: Ability to define per container shared-memory size from Open to In progress.
Nov 5 2022, 6:47 PM · VyOS 1.4 Sagitta
c-po created T4802: Ability to define per container shared-memory size.
Nov 5 2022, 6:47 PM · VyOS 1.4 Sagitta
ssasso updated the task description for T4801: Support for building AWS-ready ISO.
Nov 5 2022, 1:24 PM · VyOS 1.4 Sagitta
ssasso added a comment to T4801: Support for building AWS-ready ISO.

Note: this requires https://phabricator.vyos.net/T4800 to be completed.

Nov 5 2022, 1:22 PM · VyOS 1.4 Sagitta
ssasso added a comment to T4801: Support for building AWS-ready ISO.

https://github.com/vyos/vyos-build/pull/277

Nov 5 2022, 1:21 PM · VyOS 1.4 Sagitta
ssasso created T4801: Support for building AWS-ready ISO.
Nov 5 2022, 1:13 PM · VyOS 1.4 Sagitta
ssasso added a comment to T4800: undefined var includes_chroot_dir in build-vyos-image .

See https://github.com/vyos/vyos-build/pull/276

Nov 5 2022, 1:10 PM · VyOS 1.4 Sagitta
ssasso added a comment to T4800: undefined var includes_chroot_dir in build-vyos-image .

Well, after a better code reading, the var should be named chroot_includes_dir instead of includes_chroot_dir.

Nov 5 2022, 1:07 PM · VyOS 1.4 Sagitta
ssasso created T4800: undefined var includes_chroot_dir in build-vyos-image .
Nov 5 2022, 1:01 PM · VyOS 1.4 Sagitta
c-po added a comment to T4799: PowerDNS >= 4.7 does not get reloaded by vyos-hostsd.

Thanks for catching this

Nov 5 2022, 11:53 AM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.3)
initramfs added a comment to T4799: PowerDNS >= 4.7 does not get reloaded by vyos-hostsd.

Relevant PRs:

Nov 5 2022, 1:39 AM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.3)
initramfs updated the task description for T4799: PowerDNS >= 4.7 does not get reloaded by vyos-hostsd.
Nov 5 2022, 1:28 AM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.3)
initramfs created T4799: PowerDNS >= 4.7 does not get reloaded by vyos-hostsd.
Nov 5 2022, 1:19 AM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.3)

Nov 4 2022

jestabro added a subtask for T4795: Cleanup custom python validators: T4798: Migrate the file-exists validator away from Python.
Nov 4 2022, 3:54 PM · VyOS 1.4 Sagitta (1.4.0-epa1)
jestabro added a parent task for T4798: Migrate the file-exists validator away from Python: T4795: Cleanup custom python validators.
Nov 4 2022, 3:54 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
dmbaturin added a project to T4798: Migrate the file-exists validator away from Python: VyOS 1.3 Equuleus (1.3.3).
Nov 4 2022, 3:27 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
dmbaturin created T4798: Migrate the file-exists validator away from Python.
Nov 4 2022, 3:26 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
dmbaturin closed T2417: Python validator cleanup as Resolved.
Nov 4 2022, 3:26 PM · VyOS 1.3 Equuleus (1.3.0)
dmbaturin claimed T4770: Rewrite OpenVPN op-mode to vyos.opmode format.
Nov 4 2022, 1:18 PM · VyOS 1.4 Sagitta

Nov 3 2022

TheSin- updated the task description for T4797: External address/network lists for firewall (Local and remote).
Nov 3 2022, 9:15 PM · VyOS 1.5 Circinus
TheSin- updated the task description for T4797: External address/network lists for firewall (Local and remote).
Nov 3 2022, 8:59 PM · VyOS 1.5 Circinus
TheSin- added a comment to T4797: External address/network lists for firewall (Local and remote).

After a few hours of digging I do think this request would be very similar to geoip, only ipv4, and ipv6 groups would be required per list.

Nov 3 2022, 8:06 PM · VyOS 1.5 Circinus
sarthurdev triaged T4797: External address/network lists for firewall (Local and remote) as Wishlist priority.
Nov 3 2022, 7:44 PM · VyOS 1.5 Circinus
Viacheslav changed the status of T4758: Rewrite show dhcp server to vyos.opmode format, a subtask of T4564: Root task for rewriting [op-mode] to vyos.opmode format, from In progress to Needs testing.
Nov 3 2022, 7:42 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
Viacheslav changed the status of T4758: Rewrite show dhcp server to vyos.opmode format from In progress to Needs testing.
Nov 3 2022, 7:42 PM · VyOS 1.4 Sagitta
sarthurdev changed the status of T1097: Make firewall groups work everywhere that's appropropriate from Open to In progress.

PR adds groups to NAT: https://github.com/vyos/vyos-1x/pull/1633

Nov 3 2022, 7:41 PM · VyOS 1.4 Sagitta
sarthurdev changed the status of T1097: Make firewall groups work everywhere that's appropropriate, a subtask of T2199: Rewrite firewall in new XML/Python style, from Open to In progress.
Nov 3 2022, 7:41 PM · VyOS 1.4 Sagitta
jestabro reopened T3574: Add constraintGroup for combining validators with logical AND as "Open".

Reopened, as this was never backported to 1.3; set for 1.3.3.

Nov 3 2022, 6:14 PM · VyOS 1.4 Sagitta (1.4.0-epa1)
TheSin- added a comment to T4797: External address/network lists for firewall (Local and remote).

I didn't look deep into the nft groups, so I wasn't sure if we could mix ipv4/6 and addresses and networks, if we can then I agree one group would be best, though I'm sure ipv4/6 would still need to separate but checking each line for : makes that task super easy and fast.

Nov 3 2022, 5:38 PM · VyOS 1.5 Circinus
n.fort added a comment to T4797: External address/network lists for firewall (Local and remote).

From my point of fiew, looks interesting.
The proposed structure and behaviour doesn't look that different than what is currently in geoip filtering: external URLs with data, and sync from time to time.

Nov 3 2022, 5:29 PM · VyOS 1.5 Circinus
TheSin- created T4797: External address/network lists for firewall (Local and remote).
Nov 3 2022, 5:00 PM · VyOS 1.5 Circinus
dmbaturin created T4796: build-vyos-image ignores multiple options.
Nov 3 2022, 4:42 PM · VyOS 1.4 Sagitta (1.4.0-epa1)
c-po changed the status of T4795: Cleanup custom python validators from Open to In progress.
Nov 3 2022, 4:17 PM · VyOS 1.4 Sagitta (1.4.0-epa1)
c-po created T4795: Cleanup custom python validators.
Nov 3 2022, 4:15 PM · VyOS 1.4 Sagitta (1.4.0-epa1)
TheSin- renamed T4794: show firewall name <name> - Can't use .items() on a list from Can't use .items() on a list to show firewall name <name> - Can't use .items() on a list.
Nov 3 2022, 2:33 PM · VyOS 1.4 Sagitta
TheSin- created T4794: show firewall name <name> - Can't use .items() on a list.
Nov 3 2022, 2:14 PM · VyOS 1.4 Sagitta
a.apostoliuk added a subtask for T3953: IPSec with vti interfaces by default add default route to table 220: T4793: Create warning message about disable-route-autoinstall when ipsec vti is used.
Nov 3 2022, 12:37 PM · VyOS 1.3 Equuleus (1.3.7)
a.apostoliuk added a parent task for T4793: Create warning message about disable-route-autoinstall when ipsec vti is used: T3953: IPSec with vti interfaces by default add default route to table 220.
Nov 3 2022, 12:37 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus
a.apostoliuk changed the status of T4793: Create warning message about disable-route-autoinstall when ipsec vti is used from Open to In progress.
Nov 3 2022, 12:32 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus
a.apostoliuk triaged T4793: Create warning message about disable-route-autoinstall when ipsec vti is used as Normal priority.
Nov 3 2022, 12:31 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus
jack9603301 added a comment to T1797: Implement DPDK Fast-Path using FRR's Alternate Forwarding Planes and VPP.
Nov 3 2022, 10:02 AM · VyOS 1.5 Circinus
giezi added a comment to T1797: Implement DPDK Fast-Path using FRR's Alternate Forwarding Planes and VPP.

The enhanced linux-cp plugin (from IPng) is since 21.06 an official part of VPP, so the integration should be simple:
https://vpp.flirble.org/master/aboutvpp/releasenotes/v21.06.html#linux-control-plane-plugin-linux-cp

Nov 3 2022, 9:49 AM · VyOS 1.5 Circinus
Viacheslav placed T3953: IPSec with vti interfaces by default add default route to table 220 up for grabs.
Nov 3 2022, 7:43 AM · VyOS 1.3 Equuleus (1.3.7)
initramfs added a comment to T4760: VyOS does not support running multiple instances of DHCPv6 clients.

A patch to the WIDE DHCPv6 client seems to be sufficient to resolve this issue with respect to the way VyOS currently uses the daemon (one daemon per configured interface), PRs below:

Nov 3 2022, 1:59 AM · VyOS 1.3 Equuleus (1.3.6), VyOS 1.4 Sagitta
Viacheslav renamed T4789: Ability to get L2TP/PPTP/SSTP sessions info in a machine readable format from Ability to get L2TP/PPTP sessions info in a machine readable format to Ability to get L2TP/PPTP/SSTP sessions info in a machine readable format.
Nov 3 2022, 12:17 AM · VyOS 1.4 Sagitta

Nov 2 2022

c-po moved T4177: Strip-private doesn't work for service monitoring from Need Triage to Finished on the VyOS 1.3 Equuleus (1.3.3) board.
Nov 2 2022, 6:52 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
zsdc changed the status of T4776: NVME storage is not detected properly during installation from In progress to Needs testing.

Sure, it is fully compatible with 1.3. If no problems are found after the changes in 1.4 it must be backported.

Nov 2 2022, 4:10 PM · VyOS 1.3 Equuleus (1.3.5), VyOS 1.4 Sagitta
Viacheslav created T4792: Add SSTP VPN client.
Nov 2 2022, 3:29 PM · VyOS 1.4 Sagitta
Viacheslav changed the status of T4771: Rewrite protocol BGP op-mode to vyos.opmode format, a subtask of T4564: Root task for rewriting [op-mode] to vyos.opmode format, from In progress to Needs testing.
Nov 2 2022, 2:40 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta