Page MenuHomePhabricator

c-po (Christian Poessinger)
User

Projects

User Details

User Since
Aug 3 2017, 1:55 PM (70 w, 5 d)

Recent Activity

Yesterday

c-po edited projects for T1056: Console is slugish, added: VyOS 1.2.x ( VyOS 1.2.0-rc12); removed VyOS 1.2.x ( VyOS 1.2.0-rc11).
Mon, Dec 10, 8:02 AM · VyOS 1.2.x ( VyOS 1.2.0-rc12)
c-po added a comment to T1056: Console is slugish.

My changes will make it into rc12 as earliest, sorry

Mon, Dec 10, 8:02 AM · VyOS 1.2.x ( VyOS 1.2.0-rc12)
c-po added a comment to T1056: Console is slugish.

Disabling the complete Framebuffer subsystem works with my UEFI Testboard, too. I will drop it entirely

Mon, Dec 10, 6:47 AM · VyOS 1.2.x ( VyOS 1.2.0-rc12)

Sun, Dec 9

c-po closed T1091: Incomplete autocompletion and description at "set service dns forwarding dnssec" as Resolved.
Sun, Dec 9, 8:47 PM · VyOS 1.2.x ( VyOS 1.2.0-rc11)
c-po claimed T1091: Incomplete autocompletion and description at "set service dns forwarding dnssec".
Sun, Dec 9, 8:39 PM · VyOS 1.2.x ( VyOS 1.2.0-rc11)
c-po added a comment to T1092: Display full version in SNMP "OS String".

Not directly but it as added here: https://github.com/librenms/librenms/pull/351

Sun, Dec 9, 8:04 AM · VyOS 1.2.x

Sat, Dec 8

c-po added a comment to T1092: Display full version in SNMP "OS String".

I see OS version in libreNMS.

Sat, Dec 8, 10:36 PM · VyOS 1.2.x

Fri, Dec 7

c-po added a comment to T1028: Suspending and resuming VyOS in VMware will result in loss of static ip addresses.

Netplugd seems to be the thing we want

Fri, Dec 7, 7:31 PM · VyOS 1.2.x ( VyOS 1.2.0-rc11)
c-po added a comment to T1075: Unable to build the ISO for VyOS 1.2.0.

In vyatta-cfg-firewall please do git checkout current prior to building it, as the submodule pointer is definately not up2date.

Fri, Dec 7, 4:52 PM · VyOS 1.2.x
c-po added a comment to T1075: Unable to build the ISO for VyOS 1.2.0.

According to CI service build works as expected. Can you please retry?

Fri, Dec 7, 4:21 PM · VyOS 1.2.x

Thu, Dec 6

c-po merged task T419: Support setting dstport for VXLAN interfaces into T1067: VXLAN support improvements.
Thu, Dec 6, 7:05 AM · VyOS 1.2.x (VyOS 1.2.0-rc10)
c-po merged T419: Support setting dstport for VXLAN interfaces into T1067: VXLAN support improvements.
Thu, Dec 6, 7:05 AM · VyOS 1.3.x

Tue, Dec 4

c-po added a comment to T1067: VXLAN support improvements.

Will set interface vxlan vxlan0 destination-port 12345 be appropriate?

Tue, Dec 4, 5:30 PM · VyOS 1.3.x
c-po assigned T1081: GitHub Phabricator connection is broken to syncer.
Tue, Dec 4, 6:11 AM · VyOS-1.2.0-LTS, VyOS 1.2.x (VyOS 1.2.0-rc10)
c-po created T1081: GitHub Phabricator connection is broken.
Tue, Dec 4, 6:11 AM · VyOS-1.2.0-LTS, VyOS 1.2.x (VyOS 1.2.0-rc10)

Mon, Dec 3

c-po added a comment to T419: Support setting dstport for VXLAN interfaces.

Setting destination port per VXLAN interface sound much more reasonable

Mon, Dec 3, 6:39 AM · VyOS 1.2.x (VyOS 1.2.0-rc10)
c-po merged task T419: Support setting dstport for VXLAN interfaces into T1067: VXLAN support improvements.
Mon, Dec 3, 6:39 AM · VyOS 1.2.x (VyOS 1.2.0-rc10)
c-po merged T419: Support setting dstport for VXLAN interfaces into T1067: VXLAN support improvements.
Mon, Dec 3, 6:39 AM · VyOS 1.3.x

Sun, Dec 2

c-po added a comment to T1070: SWANCTL: DMVPN: ALL peers are deleted in swan when opennhrp tries to delete ONE peer.

What about Dockerfile in vyos-build?

Sun, Dec 2, 6:52 PM · VyOS 1.3.x
c-po created T1074: Update lldp to version 1.0.2.
Sun, Dec 2, 1:20 AM · VyOS 1.2.x ( VyOS 1.2.0-rc11)

Sat, Dec 1

c-po added a comment to T1066: Missing NICs.

I will provide a VyOS testing ISO somewhen next week, would be much appreciated if you can test.

Sat, Dec 1, 10:38 AM · VyOS 1.2.x ( VyOS 1.2.0-rc11)
c-po added a comment to T1060: Possibility to bypass the webproxy based on source IP address.

Or drop by our slack channel for help

Sat, Dec 1, 7:44 AM · VyOS 1.3.x, vyatta-webproxy
c-po added a comment to T1060: Possibility to bypass the webproxy based on source IP address.

First you need to specify a new version of your subtree,
https://github.com/vyos/vyatta-cfg-system/commit/f68dda9d619ea74bed266122ac86604284e1a9e4

Sat, Dec 1, 7:42 AM · VyOS 1.3.x, vyatta-webproxy
c-po added a comment to T1066: Missing NICs.

Correct

Sat, Dec 1, 7:36 AM · VyOS 1.2.x ( VyOS 1.2.0-rc11)
c-po added a comment to T1060: Possibility to bypass the webproxy based on source IP address.

@dsteinkopf I think almos every command is good when there is a discussion ongoing and we can agree on somehing. VyOS has so called migration scripts which are executed once we do CLI changes and thus migrate old configuration nodes to new ones. We already make use of this feature alot and it is transparent to the user.

Sat, Dec 1, 4:34 AM · VyOS 1.3.x, vyatta-webproxy
c-po added a comment to T1060: Possibility to bypass the webproxy based on source IP address.

I really like the idea and thank you for the contribution.

Sat, Dec 1, 2:56 AM · VyOS 1.3.x, vyatta-webproxy
c-po added a comment to T1066: Missing NICs.

@SteveP do you have time booting a Debian Buster (testing) ISO on your device and see if your NICs do appear?

Sat, Dec 1, 2:22 AM · VyOS 1.2.x ( VyOS 1.2.0-rc11)

Thu, Nov 29

c-po added a comment to T1056: Console is slugish.

@dmbaturin maybe can, need to verify this behavior together with the EFI stuff when I'm back in germany. If =n works for all szenarios I'm happy with it.

Thu, Nov 29, 4:36 AM · VyOS 1.2.x ( VyOS 1.2.0-rc12)

Wed, Nov 28

c-po added a comment to T1056: Console is slugish.

Can you please double-check with latest rolling release: vyos-1.2.0-rolling+201811281529-amd64.iso?

Wed, Nov 28, 2:51 PM · VyOS 1.2.x ( VyOS 1.2.0-rc12)
c-po changed the status of T1056: Console is slugish from Open to In progress.
Wed, Nov 28, 1:45 PM · VyOS 1.2.x ( VyOS 1.2.0-rc12)
c-po added a comment to T1056: Console is slugish.

System bootup time is something we should not care, as a router is not rebootet that often. Infact the startup time depends on the amount of configured services or firewall rules. We recently increased the timeout for starting of VyOS to also make it work on slower Intel Atom D525 platforms where a huge firewall config was loaded.

Wed, Nov 28, 8:17 AM · VyOS 1.2.x ( VyOS 1.2.0-rc12)
c-po added a comment to T874: Support for Two Factor Authentication for CLI access via Google Authenticator.

What do you propose as CLI syntax?

Wed, Nov 28, 7:17 AM · VyOS 1.3.x

Tue, Nov 27

c-po added a comment to T1051: Update openvpn to support TLS 1.2.

I never liked verbatim passed options, this will be a perfect candidate for a first controbution to VyOS as it will be rather easy! You want to give it a try?

Tue, Nov 27, 11:51 PM · VyOS 1.2.x ( VyOS 1.2.0-rc11)
c-po added a comment to T1052: ISO compilation error.

There hve recently been changes in regards to EFI. Please check the Dockerfile for all required packages or switch to Completely!

Tue, Nov 27, 11:47 PM · build-iso
c-po closed T1045: static route dhcp-interface failes on bootup as Resolved.
Tue, Nov 27, 2:47 PM · VyOS 1.2.x (VyOS 1.2.0-rc10)
c-po reassigned T1045: static route dhcp-interface failes on bootup from c-po to runar.
Tue, Nov 27, 2:45 PM · VyOS 1.2.x (VyOS 1.2.0-rc10)
c-po changed the status of T1045: static route dhcp-interface failes on bootup from Open to In progress.
Tue, Nov 27, 2:45 PM · VyOS 1.2.x (VyOS 1.2.0-rc10)

Mon, Nov 26

c-po added a comment to T1047: Configuration saved on a livecd cannot be carried over to the installed image.

Have you tried specifying /config/config.boot instead?

Mon, Nov 26, 11:59 AM · VyOS 1.2.x ( VyOS 1.2.0-rc11)
c-po updated the task description for T1046: Maximum CPU limit should be increased to 256 to accomodate high end servers.
Mon, Nov 26, 8:49 AM · VyOS 1.2.x (VyOS 1.2.0-rc10)
c-po added a project to T1046: Maximum CPU limit should be increased to 256 to accomodate high end servers: VyOS 1.2.x (VyOS 1.2.0-rc10).
Mon, Nov 26, 5:32 AM · VyOS 1.2.x (VyOS 1.2.0-rc10)
c-po claimed T1046: Maximum CPU limit should be increased to 256 to accomodate high end servers.
Mon, Nov 26, 5:31 AM · VyOS 1.2.x (VyOS 1.2.0-rc10)
c-po added a comment to T1046: Maximum CPU limit should be increased to 256 to accomodate high end servers.

I always thought 64 cpus should be sufficient for VyOS :)

Mon, Nov 26, 5:31 AM · VyOS 1.2.x (VyOS 1.2.0-rc10)
c-po added a comment to T1041: DNS forwarding always requires an upstream recursor - but not needed with PowerDNS Recursor.

Another idea (if having no name-server entries is disliked) would be

Mon, Nov 26, 12:14 AM · VyOS 1.2.x ( VyOS 1.2.0-rc11)

Sun, Nov 25

c-po added a comment to T1041: DNS forwarding always requires an upstream recursor - but not needed with PowerDNS Recursor.

Eoot hints could be speciefied, if none is specified, buildin one is used.

Sun, Nov 25, 10:30 PM · VyOS 1.2.x ( VyOS 1.2.0-rc11)
c-po closed T1042: Update Linux Kernel from 4.19 to 4.19.4 as Resolved.
Sun, Nov 25, 12:32 PM · VyOS 1.2.x (VyOS 1.2.0-rc9)
c-po renamed T1042: Update Linux Kernel from 4.19 to 4.19.4 from Upgrade Kernel from 4.19.0 to 4.19.4 to Update Linux Kernel from 4.19 to 4.19.4.
Sun, Nov 25, 12:27 PM · VyOS 1.2.x (VyOS 1.2.0-rc9)
c-po created T1042: Update Linux Kernel from 4.19 to 4.19.4.
Sun, Nov 25, 12:27 PM · VyOS 1.2.x (VyOS 1.2.0-rc9)
c-po added a comment to T1041: DNS forwarding always requires an upstream recursor - but not needed with PowerDNS Recursor.

Could be done by Help text and documentation

Sun, Nov 25, 10:05 AM · VyOS 1.2.x ( VyOS 1.2.0-rc11)
c-po added a comment to T1041: DNS forwarding always requires an upstream recursor - but not needed with PowerDNS Recursor.

Or, if no name-server is set, use the root servers

Sun, Nov 25, 3:39 AM · VyOS 1.2.x ( VyOS 1.2.0-rc11)
c-po created T1041: DNS forwarding always requires an upstream recursor - but not needed with PowerDNS Recursor.
Sun, Nov 25, 3:10 AM · VyOS 1.2.x ( VyOS 1.2.0-rc11)
c-po added a comment to T880: What do you think about softether VPN server?.

Even better! Thanks for the hint!

Sun, Nov 25, 2:47 AM · VyOS 1.3.x

Sat, Nov 24

c-po changed the status of T1019: Enable Google BBR support at kernel compile time from Open to In progress.
Sat, Nov 24, 3:10 PM · VyOS 1.2.x (VyOS 1.2.0-rc10)
c-po added a comment to T1019: Enable Google BBR support at kernel compile time.

BBR was enabled in the latest commit to vyos-kernel

Sat, Nov 24, 3:09 PM · VyOS 1.2.x (VyOS 1.2.0-rc10)
c-po added a comment to T880: What do you think about softether VPN server?.

@syncer seems this is the only available SSTP Linux implementation

Sat, Nov 24, 1:10 PM · VyOS 1.3.x
c-po added a comment to T1012: vyos-build configure script should check /etc/issue to avoid confusion.

man strace(1) indicates that it opens several system files until it gets a match for any known distro.

Sat, Nov 24, 10:15 AM · VyOS 1.3.x, vyos-build
c-po closed T1039: Serial Getty repeating errors as Invalid.
Sat, Nov 24, 3:17 AM · VyOS 1.2.x
c-po added a comment to T1039: Serial Getty repeating errors.

VyOS ships a serial port interface in the default configuration upon installation.

Sat, Nov 24, 3:16 AM · VyOS 1.2.x
c-po added a comment to T1036: NHRP starts before IPSEC is set up..

Merged from current into crux branch.

Sat, Nov 24, 2:35 AM · VyOS 1.2.x (VyOS 1.2.0-rc9)
c-po closed T1036: NHRP starts before IPSEC is set up. as Resolved.
Sat, Nov 24, 2:35 AM · VyOS 1.2.x (VyOS 1.2.0-rc9)
c-po added a comment to T1039: Serial Getty repeating errors.

May it be you are running on a virtualized environment and have not added a serial port to your VM?

Sat, Nov 24, 2:27 AM · VyOS 1.2.x

Sat, Nov 17

c-po closed T1018: Incorrect (obsoleted) option "dynamic" for NTP server as Resolved.
Sat, Nov 17, 2:33 PM · VyOS-1.2.0-LTS, VyOS 1.2.x (VyOS 1.2.0-rc8)
c-po closed T1016: Unable to restart dhcp relay agent as Resolved.
Sat, Nov 17, 10:07 AM · VyOS-1.2.0-LTS, VyOS 1.2.x (VyOS 1.2.0-rc8)

Thu, Nov 15

c-po claimed T1018: Incorrect (obsoleted) option "dynamic" for NTP server.
Thu, Nov 15, 10:10 PM · VyOS-1.2.0-LTS, VyOS 1.2.x (VyOS 1.2.0-rc8)
c-po added a comment to T458: Disabling the in-memory table plugin has no effect.

Your commit enables memory plugin when disable is configured?

Thu, Nov 15, 6:38 PM · VyOS 1.2.x (VyOS 1.2.0-rc8)
c-po claimed T1016: Unable to restart dhcp relay agent.
Thu, Nov 15, 6:05 PM · VyOS-1.2.0-LTS, VyOS 1.2.x (VyOS 1.2.0-rc8)
c-po merged T1015: SNMP Support for IPv6 Routing Protocols (BGP/OSPFv3) into T366: SNMP Query for BGP Tunnels Returns IPv4 Tunnels Only.
Thu, Nov 15, 4:38 PM · VyOS 1.3.x
c-po merged task T1015: SNMP Support for IPv6 Routing Protocols (BGP/OSPFv3) into T366: SNMP Query for BGP Tunnels Returns IPv4 Tunnels Only.
Thu, Nov 15, 4:38 PM · VyOS 1.2.x
c-po added a comment to T1012: vyos-build configure script should check /etc/issue to avoid confusion.

@LiquidLight there is a Dockerfile, too to build VyOS

Thu, Nov 15, 9:20 AM · VyOS 1.3.x, vyos-build
c-po added a comment to T1012: vyos-build configure script should check /etc/issue to avoid confusion.

Issue file con be overwritten. lsb_release -d would be a better way, as it gives you Description: Debian GNU/Linux 8.11 (jessie)

Thu, Nov 15, 6:08 AM · VyOS 1.3.x, vyos-build

Mon, Nov 12

c-po closed T993: Unclutter PPTP RADIUS configuration nodes as Resolved.
Mon, Nov 12, 7:32 PM · VyOS-1.2.0-LTS, VyOS 1.2.x (VyOS 1.2.0-rc8)

Sun, Nov 11

c-po merged task T998: "service dns dynamic" does now honor the "use-web" statement into T983: 'set service dns dynamic interface eth0 use-web url' has no effect.
Sun, Nov 11, 8:21 PM · VyOS-1.2.0-LTS, VyOS 1.2.x (VyOS 1.2.0-rc7)
c-po merged T998: "service dns dynamic" does now honor the "use-web" statement into T983: 'set service dns dynamic interface eth0 use-web url' has no effect.
Sun, Nov 11, 8:21 PM · VyOS 1.2.x (VyOS 1.2.0-rc8)
c-po edited projects for T999: "strip-private" doesn't strip pre-shared-secret, added: VyOS 1.2.x (VyOS 1.2.0-rc7); removed VyOS 1.2.x.
Sun, Nov 11, 7:49 PM · VyOS-1.2.0-LTS, VyOS 1.2.x (VyOS 1.2.0-rc7)
c-po closed T999: "strip-private" doesn't strip pre-shared-secret as Resolved.
Sun, Nov 11, 7:46 PM · VyOS-1.2.0-LTS, VyOS 1.2.x (VyOS 1.2.0-rc7)
c-po closed T998: "service dns dynamic" does now honor the "use-web" statement as Resolved.
Sun, Nov 11, 7:26 PM · VyOS-1.2.0-LTS, VyOS 1.2.x (VyOS 1.2.0-rc7)
c-po added a comment to T998: "service dns dynamic" does now honor the "use-web" statement.

Looks like this was always a bug. In the old Perl implementation the if clause was the same:
https://github.com/vyos/vyatta-cfg-system/blob/9b469f3c5734c086fc30b097405ea46ec2cee725/scripts/dynamic-dns/vyatta-dynamic-dns.pl#L223-L230

Sun, Nov 11, 7:16 PM · VyOS-1.2.0-LTS, VyOS 1.2.x (VyOS 1.2.0-rc7)
c-po updated the task description for T998: "service dns dynamic" does now honor the "use-web" statement.
Sun, Nov 11, 7:10 PM · VyOS-1.2.0-LTS, VyOS 1.2.x (VyOS 1.2.0-rc7)
c-po changed the status of T998: "service dns dynamic" does now honor the "use-web" statement from Open to In progress.
Sun, Nov 11, 7:09 PM · VyOS-1.2.0-LTS, VyOS 1.2.x (VyOS 1.2.0-rc7)
c-po created T998: "service dns dynamic" does now honor the "use-web" statement.
Sun, Nov 11, 7:09 PM · VyOS-1.2.0-LTS, VyOS 1.2.x (VyOS 1.2.0-rc7)
c-po added a comment to T977: Permission denied error when performing config rollback on a machine upgraded from VyOS 1.1.x.

@dmbaturin This is what I did:

Sun, Nov 11, 6:59 PM · VyOS 1.2.x ( VyOS 1.2.0-rc11), VyOS-1.2.0-LTS

Nov 11 2018

c-po changed the status of T993: Unclutter PPTP RADIUS configuration nodes from Open to In progress.
Nov 11 2018, 4:43 PM · VyOS-1.2.0-LTS, VyOS 1.2.x (VyOS 1.2.0-rc8)
c-po created T993: Unclutter PPTP RADIUS configuration nodes.
Nov 11 2018, 4:43 PM · VyOS-1.2.0-LTS, VyOS 1.2.x (VyOS 1.2.0-rc8)
c-po closed T987: Unclutter L2TP/IPSec RADIUS configuration nodes as Resolved.
Nov 11 2018, 4:38 PM · VyOS-1.2.0-LTS, VyOS 1.2.x (VyOS 1.2.0-rc7)

Nov 10 2018

c-po added a comment to T786: new style xml and conf-mode scripts: posibillity to add tagNode value as parameter to conf-script.

This looks like an ultimate hackaround. Maybe we should check if we can change the C implementation

Nov 10 2018, 8:49 AM · VyOS 1.3.x

Nov 9 2018

c-po closed T371: Add command alias configuration node as Invalid.
Nov 9 2018, 4:35 PM · Invalid
c-po added a comment to T371: Add command alias configuration node.

Actually I only wanted to use it got configuration backup.

Nov 9 2018, 4:35 PM · Invalid
c-po claimed T987: Unclutter L2TP/IPSec RADIUS configuration nodes.
Nov 9 2018, 3:51 PM · VyOS-1.2.0-LTS, VyOS 1.2.x (VyOS 1.2.0-rc7)
c-po created T987: Unclutter L2TP/IPSec RADIUS configuration nodes.
Nov 9 2018, 3:51 PM · VyOS-1.2.0-LTS, VyOS 1.2.x (VyOS 1.2.0-rc7)
c-po closed T828: Specify RADIUS source ip as Resolved.
Nov 9 2018, 3:09 PM · VyOS 1.2.x (VyOS 1.2.0-rc7)
c-po closed T946: enable denverton SoC in kernel config as Resolved.
Nov 9 2018, 9:34 AM · VyOS-1.2.0-LTS, VyOS 1.2.x (VyOS 1.2.0-rc7)
c-po added a comment to T946: enable denverton SoC in kernel config.

Please note: Kernel Intel driver version is kot always related to Intel out of tree modules. Denverton C3000 NICs work fine with 4.18 atleast so as we run 4.19 we‘re off the hook.

Nov 9 2018, 9:34 AM · VyOS-1.2.0-LTS, VyOS 1.2.x (VyOS 1.2.0-rc7)
c-po closed T978: PowerDNS config for upstream IPv6 nameservers is broken as Resolved.
Nov 9 2018, 6:51 AM · VyOS-1.2.0-LTS, VyOS 1.2.x (VyOS 1.2.0-rc7)

Nov 8 2018

c-po changed the status of T978: PowerDNS config for upstream IPv6 nameservers is broken from Open to In progress.
Nov 8 2018, 8:20 PM · VyOS-1.2.0-LTS, VyOS 1.2.x (VyOS 1.2.0-rc7)
c-po closed T974: PowerDNS config can't handle listening on IPv6 addresses as Resolved.
Nov 8 2018, 3:08 PM · VyOS 1.2.x (VyOS 1.2.0-rc8)
c-po added a comment to T974: PowerDNS config can't handle listening on IPv6 addresses.

Can you search for the following file on your device and edit it to test your proposed changes:

Nov 8 2018, 11:06 AM · VyOS 1.2.x (VyOS 1.2.0-rc8)

Nov 7 2018

c-po added a comment to T962: Intel 520 card requires modprobe option when using non-Intel SFP.

T123 addressed exactly this issue but we not yet have agreed on a CLI yet. I do not know if it's safe to enable it in generall.

Nov 7 2018, 3:45 PM · VyOS 1.2.x (VyOS 1.2.0-rc8)
c-po closed T959: Rewrite "protocol igmp-proxy" in XML/Python as Resolved.
Nov 7 2018, 1:48 PM · VyOS-1.2.0-LTS, VyOS 1.2.x (VyOS 1.2.0-rc7)
c-po added a project to T959: Rewrite "protocol igmp-proxy" in XML/Python: VyOS-1.2.0-LTS.
Nov 7 2018, 1:48 PM · VyOS-1.2.0-LTS, VyOS 1.2.x (VyOS 1.2.0-rc7)
c-po closed T975: `Show ip multicast mfc/interface` prints adresses the wrong way around as Resolved.
Nov 7 2018, 1:47 PM · VyOS 1.2.x (VyOS 1.2.0-rc7), VyOS-1.2.0-LTS
c-po closed T975: `Show ip multicast mfc/interface` prints adresses the wrong way around, a subtask of T959: Rewrite "protocol igmp-proxy" in XML/Python, as Resolved.
Nov 7 2018, 1:47 PM · VyOS-1.2.0-LTS, VyOS 1.2.x (VyOS 1.2.0-rc7)