Page MenuHomeVyOS Platform
Feed All Stories

Jan 12 2023

Viacheslav added a comment to T4930: Allow WireGuard peers via DNS hostname.

See tasks T1700 T2943

Jan 12 2023, 6:11 AM · VyOS 1.5 Circinus
tkmr_akhs created T4931: Failed to build firmware for arm64.
Jan 12 2023, 5:38 AM · VyOS 1.5 Circinus, vyos-build

Jan 11 2023

b- created T4930: Allow WireGuard peers via DNS hostname.
Jan 11 2023, 9:01 PM · VyOS 1.5 Circinus
roedie added a comment to T4918: Odd show interface behavior.

@jestabro I've created the backport PR just now.

Jan 11 2023, 7:08 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
jestabro added a comment to T4918: Odd show interface behavior.

@roedie , thanks.

Jan 11 2023, 6:37 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
roedie added a comment to T4918: Odd show interface behavior.

Will push the backport for 1.3 as well.

Jan 11 2023, 6:26 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
c-po claimed T4929: Update Intel QAT drivers to 4.20.0-00001.
Jan 11 2023, 5:50 PM · VyOS 1.4 Sagitta
c-po updated the task description for T4929: Update Intel QAT drivers to 4.20.0-00001.
Jan 11 2023, 5:50 PM · VyOS 1.4 Sagitta
c-po created T4929: Update Intel QAT drivers to 4.20.0-00001.
Jan 11 2023, 5:49 PM · VyOS 1.4 Sagitta
c-po changed the status of T4928: Upgrade Linux Kernel to 6.1.y (2022 LTS edition) from Open to In progress.
Jan 11 2023, 5:47 PM · VyOS 1.4 Sagitta
c-po created T4928: Upgrade Linux Kernel to 6.1.y (2022 LTS edition).
Jan 11 2023, 5:47 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T4924: Systemctl strongswan.service for some reason is not disabled.

So there are 2 options

  1. Live it as it is, it works as before (but maybe it is a legacy way)
  2. Return the strongswan.service and use it in all required places (conf-mode, op-mode, dmvpn scripts, etc). So old ipsec/starter must not be overlapped with strongswan.service restarts
Jan 11 2023, 4:04 PM · VyOS 1.4 Sagitta
Viacheslav added a project to T3008: Migrate from ntpd to chronyd: VyOS 1.4 Sagitta.
Jan 11 2023, 9:12 AM · VyOS 1.4 Sagitta
Viacheslav placed T3008: Migrate from ntpd to chronyd up for grabs.
Jan 11 2023, 9:11 AM · VyOS 1.4 Sagitta
a.apostoliuk changed the status of T4927: Need to change restart to reload-or-restart in Webproxy module from Open to In progress.
Jan 11 2023, 6:48 AM · VyOS 1.3 Equuleus, VyOS 1.4 Sagitta
jack9603301 awarded T3008: Migrate from ntpd to chronyd a Like token.
Jan 11 2023, 3:07 AM · VyOS 1.4 Sagitta

Jan 10 2023

jestabro closed T4880: Expose 'add/delete container image' in HTTP-API, a subtask of T578: Support Linux Container, as Resolved.
Jan 10 2023, 4:26 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
jestabro closed T4880: Expose 'add/delete container image' in HTTP-API as Resolved.
Jan 10 2023, 4:26 PM · VyOS 1.4 Sagitta
a.apostoliuk added a comment to T4551: IPsec rekeying collisions bug.

I found that if IPSEC lifetime is large(28800) then this problem occurs.
If lifetime eq 1800 sec, everything works.

Jan 10 2023, 3:46 PM · VyOS 1.4 Sagitta
Viacheslav changed the status of T4906: ipsec connections shows only one connection as up from In progress to Needs testing.
Jan 10 2023, 3:37 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
Viacheslav added a comment to T4924: Systemctl strongswan.service for some reason is not disabled.

After return strongswan.starer https://github.com/vyos/vyos-1x/commit/f5f43c6639957f95177bb77d2b569e16d4dab9dc
all looks good now, service can be restored without issues

Jan 10 2023, 1:11 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T4906: ipsec connections shows only one connection as up.

PR https://github.com/vyos/vyos-1x/pull/1745

Jan 10 2023, 12:48 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
a.apostoliuk claimed T4927: Need to change restart to reload-or-restart in Webproxy module.
Jan 10 2023, 9:42 AM · VyOS 1.3 Equuleus, VyOS 1.4 Sagitta
a.apostoliuk created T4927: Need to change restart to reload-or-restart in Webproxy module.
Jan 10 2023, 9:42 AM · VyOS 1.3 Equuleus, VyOS 1.4 Sagitta
c-po merged T4926: using chronyd service to replace ntpd into T3008: Migrate from ntpd to chronyd.
Jan 10 2023, 8:28 AM · VyOS 1.4 Sagitta
c-po merged task T4926: using chronyd service to replace ntpd into T3008: Migrate from ntpd to chronyd.
Jan 10 2023, 8:28 AM · VyOS 1.4 Sagitta
Viacheslav added a comment to T4926: using chronyd service to replace ntpd .

The similar task T3008

Jan 10 2023, 5:51 AM · VyOS 1.4 Sagitta
jack9603301 updated the task description for T4926: using chronyd service to replace ntpd .
Jan 10 2023, 5:42 AM · VyOS 1.4 Sagitta
jack9603301 renamed T4926: using chronyd service to replace ntpd from Replace ntp with clock to using chronyd service to replace ntpd .
Jan 10 2023, 5:41 AM · VyOS 1.4 Sagitta
jack9603301 created T4926: using chronyd service to replace ntpd .
Jan 10 2023, 4:38 AM · VyOS 1.4 Sagitta

Jan 9 2023

jestabro changed the status of T4880: Expose 'add/delete container image' in HTTP-API, a subtask of T578: Support Linux Container, from Open to In progress.
Jan 9 2023, 9:48 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
jestabro changed the status of T4880: Expose 'add/delete container image' in HTTP-API from Open to In progress.

PR: https://github.com/vyos/vyos-1x/pull/1744

Jan 9 2023, 9:48 PM · VyOS 1.4 Sagitta
a.apostoliuk added a comment to T4924: Systemctl strongswan.service for some reason is not disabled.

I have tested this bug.
After boot everything woks fine without any problems.
But after restart vpn command all these issues began.

  1. Error message
vyos charon[2079]: 04[NET] no socket implementation registered, sending failed
  1. Swanctl shows unnormal info. IPSEC phase is down.
  2. Traffic passes through the tunnel.
  3. New process appears
Jan 9 2023, 4:21 PM · VyOS 1.4 Sagitta
a.apostoliuk added a comment to T4924: Systemctl strongswan.service for some reason is not disabled.
Jan 9 2023, 3:39 PM · VyOS 1.4 Sagitta
Viacheslav closed T4303: BGP neighbor interface v6only fails to commit as Resolved N/A.
Jan 9 2023, 1:34 PM · VyOS 1.4 Sagitta
Viacheslav changed the status of T4844: Incorrect permissions of the safeguard DB directory, a subtask of T3810: webproxy squidguard rules don't work properly after rewriting to python. , from In progress to Needs testing.
Jan 9 2023, 1:26 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
Viacheslav changed the status of T4844: Incorrect permissions of the safeguard DB directory from In progress to Needs testing.
Jan 9 2023, 1:26 PM · VyOS 1.3 Equuleus, VyOS 1.4 Sagitta
Viacheslav closed T4524: Squid webproxy not working properly as Resolved.

Fixed in T3810

Jan 9 2023, 1:24 PM · VyOS 1.4 Sagitta
Viacheslav changed the status of T3810: webproxy squidguard rules don't work properly after rewriting to python. from Backport candidate to Needs testing.
Jan 9 2023, 1:23 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
a.apostoliuk changed the status of T4877: Need verification in using import vrf and import vpn, export vpn commands from In progress to Needs testing.
Jan 9 2023, 10:54 AM · VyOS 1.4 Sagitta
Viacheslav changed the status of T4906: ipsec connections shows only one connection as up from Open to In progress.
Jan 9 2023, 10:19 AM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
c-po closed T4922: Add ssh-client source-interface CLI option as Resolved.
Jan 9 2023, 9:19 AM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.3)
c-po closed T4922: Add ssh-client source-interface CLI option, a subtask of T2651: Generate CLI abstraction for options passed to CURL and SSH client, as Resolved.
Jan 9 2023, 9:19 AM · VyOS 1.3 Equuleus (1.3.0)
c-po moved T4922: Add ssh-client source-interface CLI option from In Progress to Finished on the VyOS 1.3 Equuleus (1.3.3) board.
Jan 9 2023, 9:19 AM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.3)
Viacheslav changed the status of T1311: WAN load-balancing can't flush connections when conntrack-sync is enabled from On hold to Needs testing.
Jan 9 2023, 8:32 AM · VyOS 1.4 Sagitta (1.4.0-epa1), Restricted Project, VyOS 1.3 Equuleus (1.3.7), test
a.apostoliuk claimed T4925: Need to add the possibility to configure Pseudo-Random Functions (PRF) in IKEv2.
Jan 9 2023, 8:26 AM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
a.apostoliuk created T4925: Need to add the possibility to configure Pseudo-Random Functions (PRF) in IKEv2.
Jan 9 2023, 8:25 AM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta

Jan 8 2023

DerEnderKeks added a comment to T4923: Zebra sends router advertisements even though it's not supposed to.

I don't think this is a bug in FRR, but rather a configuration issue. I'm not really familiar with FRR, but as far as I can tell, sending RAs is an intended feature of it that can be disabled per interface: https://docs.frrouting.org/en/latest/ipv6.html#clicmd-ipv6-nd-suppress-ra
Not sure why it's enabled by default, since I couldn't find anything in the generated /etc/frr/frr.conf that would enable it.

Jan 8 2023, 6:40 PM · VyOS 1.4 Sagitta (1.4.0-epa1), Restricted Project
Viacheslav updated the task description for T4924: Systemctl strongswan.service for some reason is not disabled.
Jan 8 2023, 2:01 PM · VyOS 1.4 Sagitta
Viacheslav updated the task description for T4924: Systemctl strongswan.service for some reason is not disabled.
Jan 8 2023, 1:58 PM · VyOS 1.4 Sagitta
Viacheslav created T4924: Systemctl strongswan.service for some reason is not disabled.
Jan 8 2023, 1:46 PM · VyOS 1.4 Sagitta
Viacheslav added a project to T4921: Miniupnpd only allows for IGDv2 while IGDv1 is mostly common used and supported: VyOS 1.4 Sagitta.
Jan 8 2023, 12:35 PM · VyOS 1.5 Circinus
Viacheslav added a comment to T4923: Zebra sends router advertisements even though it's not supposed to.

Could you open an issue for FRR?
https://github.com/FRRouting/frr/issues

Jan 8 2023, 12:33 PM · VyOS 1.4 Sagitta (1.4.0-epa1), Restricted Project
DerEnderKeks created T4923: Zebra sends router advertisements even though it's not supposed to.
Jan 8 2023, 11:52 AM · VyOS 1.4 Sagitta (1.4.0-epa1), Restricted Project
c-po moved T4922: Add ssh-client source-interface CLI option from Need Triage to In Progress on the VyOS 1.3 Equuleus (1.3.3) board.
Jan 8 2023, 8:11 AM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.3)
c-po moved T4922: Add ssh-client source-interface CLI option from Need Triage to Finished on the VyOS 1.4 Sagitta board.
Jan 8 2023, 8:11 AM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.3)
c-po changed the status of T4922: Add ssh-client source-interface CLI option, a subtask of T2651: Generate CLI abstraction for options passed to CURL and SSH client, from Open to In progress.
Jan 8 2023, 8:11 AM · VyOS 1.3 Equuleus (1.3.0)
c-po changed the status of T4922: Add ssh-client source-interface CLI option from Open to In progress.
Jan 8 2023, 8:11 AM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.3)
c-po created T4922: Add ssh-client source-interface CLI option.
Jan 8 2023, 7:55 AM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.3)
Viacheslav closed T4920: ospf: Fix `passive-interface default` option as Resolved.
Jan 8 2023, 7:52 AM · VyOS 1.4 Sagitta

Jan 7 2023

yarokifor created T4921: Miniupnpd only allows for IGDv2 while IGDv1 is mostly common used and supported.
Jan 7 2023, 6:22 PM · VyOS 1.5 Circinus
Viacheslav changed the status of T4916: Rewrite IPsec authentication from Open to In progress.
Jan 7 2023, 12:37 PM · VyOS 1.4 Sagitta
sarthurdev added a comment to T4919: TPM-backed config encryption.

Draft PR: https://github.com/vyos/vyos-1x/pull/1740

Jan 7 2023, 12:03 PM · VyOS 1.5 Circinus
Viacheslav added a comment to T4917: Commit hooks .
In T4917#140239, @b- wrote:

Thanks! That’ll help me with what I’m working on :)From where does this limitation originate, anyway? Is there a way to at least add . to the acceptable characters list, so as to allow for foo.sh?  Would that break something that expects to skip over filenames with dots and other characters?

Jan 7 2023, 10:27 AM
vfreex added a comment to T4920: ospf: Fix `passive-interface default` option.

PR https://github.com/vyos/vyos-1x/pull/1741

Jan 7 2023, 9:35 AM · VyOS 1.4 Sagitta
vfreex created T4920: ospf: Fix `passive-interface default` option.
Jan 7 2023, 9:18 AM · VyOS 1.4 Sagitta
roedie closed T4884: Missing a community6 in snmpd config as Resolved.
Jan 7 2023, 8:57 AM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
c-po awarded T4919: TPM-backed config encryption a 100 token.
Jan 7 2023, 8:36 AM · VyOS 1.5 Circinus

Jan 6 2023

syncer changed the status of T4919: TPM-backed config encryption from Open to In progress.
Jan 6 2023, 10:04 PM · VyOS 1.5 Circinus
jestabro reassigned T4918: Odd show interface behavior from jestabro to roedie.
Jan 6 2023, 8:07 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
sarthurdev claimed T4919: TPM-backed config encryption.
Jan 6 2023, 7:48 PM · VyOS 1.5 Circinus
jestabro changed Difficulty level from unknown to easy on T4918: Odd show interface behavior.
Jan 6 2023, 7:45 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
jestabro claimed T4918: Odd show interface behavior.

The error is in the respective XML op-mode-definitions; arg '--intf-type' should be passed to 'show_interfaces.py' (1.3); 'interfaces.py' (1.4) so that tag node is correctly filtered.

Jan 6 2023, 7:45 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
sarthurdev created T4919: TPM-backed config encryption.
Jan 6 2023, 7:44 PM · VyOS 1.5 Circinus
roedie created T4918: Odd show interface behavior.
Jan 6 2023, 7:40 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
a.apostoliuk added a comment to T4551: IPsec rekeying collisions bug.

I have checked this config on VyOS 1.4-rolling-202212310809 (Strongswan 5.9.8). The problem is the same.

Jan 6 2023, 1:43 PM · VyOS 1.4 Sagitta
b- added a comment to T4917: Commit hooks .

Thanks! That’ll help me with what I’m working on :)From where does this limitation originate, anyway? Is there a way to at least add . to the acceptable characters list, so as to allow for foo.sh?  Would that break something that expects to skip over filenames with dots and other characters?

Jan 6 2023, 1:38 PM
Viacheslav added a comment to T4917: Commit hooks .

Scripts are run in alphabetical order. Their names must consist entirely of ASCII upper- and lower-case letters,ASCII digits, ASCII underscores, and ASCII minus-hyphens.No other characters are allowed.

Jan 6 2023, 1:18 PM

Jan 5 2023

b- added a comment to T4917: Commit hooks .

huh, is it possible that we just don't run commit hooks upon changing only comments?

Jan 5 2023, 11:00 PM
b- added a watcher for Hyper-V/Azure Support: b-.
Jan 5 2023, 9:41 PM
b- created T4917: Commit hooks .
Jan 5 2023, 9:37 PM
b- added a comment to T4915: Minisign verification failure == pass??.

I just edited the file /opt/vyatta/sbin/install-image in a running system to try testing this, and it works as expected at least for the primary minisign key. I didn't test GPG or 2nd minisign key, but I see no reason why there would be an issue there. I did touch those parts, though, so it's probably worth at least having another set of eyes look at it all.

Jan 5 2023, 8:53 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
b- added a comment to T4915: Minisign verification failure == pass??.

er wait hold up i made a mistake saving/pushing my changes
edit: fixed

Jan 5 2023, 8:19 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
b- changed Why the issue appeared? from none to implementation-mistake on T4915: Minisign verification failure == pass??.
Jan 5 2023, 8:05 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
b- changed the status of T4915: Minisign verification failure == pass?? from Open to Needs testing.

I created a PR, but I'm not certain how to compile this part of VyOS to test this, and I'm hoping someone could help me do so -- a quick glance makes it look to me like this is compiled into a .deb that's then installed by https://github.com/vyos/vyos-build/blob/current/scripts/build-vyos-image ?

Jan 5 2023, 8:01 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
dienac added a comment to T1237: Static Route Path Monitoring, failover.

will be fixed in the next rolling release

Jan 5 2023, 5:34 PM · VyOS 1.4 Sagitta
b- claimed T4915: Minisign verification failure == pass??.

The error handling on this line is basically nonexistent, but also the coding style is a little hard to follow.

Jan 5 2023, 5:09 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
Viacheslav updated the task description for T4916: Rewrite IPsec authentication.
Jan 5 2023, 4:29 PM · VyOS 1.4 Sagitta
Viacheslav created T4916: Rewrite IPsec authentication.
Jan 5 2023, 4:29 PM · VyOS 1.4 Sagitta
evgbondarenko empowered jlopez as an administrator.
Jan 5 2023, 4:26 PM
Viacheslav changed the status of T4895: Tag nodes are overwritten when configured by Cloud-Init from User-Data from Backport pending to Needs testing.
Jan 5 2023, 3:44 PM · VyOS 1.3 Equuleus (1.3.4), VyOS 1.4 Sagitta
b- created T4915: Minisign verification failure == pass??.
Jan 5 2023, 2:30 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
dmbaturin renamed T4867: "show bgp neighbors ... advertised-routes" and some other commands fail for IPv4 neighbors from Show ipv4 neighbor details fails to "show bgp neighbors ... advertised-routes" and some other commands fail for IPv4 neighbors.
Jan 5 2023, 2:22 PM · VyOS 1.4 Sagitta
dmbaturin assigned T4583: Rewrite VRRP op-mode to vyos.opmode format to erkin.
Jan 5 2023, 2:10 PM · VyOS 1.4 Sagitta
dmbaturin closed T3937: Rewrite "show system memory" in Python to make it usable as a library function, a subtask of T4564: Root task for rewriting [op-mode] to vyos.opmode format, as Resolved.
Jan 5 2023, 2:06 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
dmbaturin closed T3937: Rewrite "show system memory" in Python to make it usable as a library function as Resolved.
Jan 5 2023, 2:06 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
jestabro merged task T4892: Rewrite op-mode pki to standardized form into T4914: Rewrite the PKI op mode in the new style.
Jan 5 2023, 2:04 PM · VyOS 1.4 Sagitta
jestabro merged T4892: Rewrite op-mode pki to standardized form into T4914: Rewrite the PKI op mode in the new style.
Jan 5 2023, 2:04 PM · VyOS 1.5 Circinus
dmbaturin reassigned T4914: Rewrite the PKI op mode in the new style from dmbaturin to jestabro.
Jan 5 2023, 1:26 PM · VyOS 1.5 Circinus
dmbaturin added a subtask for T4564: Root task for rewriting [op-mode] to vyos.opmode format: T4914: Rewrite the PKI op mode in the new style.
Jan 5 2023, 1:26 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta