Page MenuHomePhabricator

hagbard (burkhard)
User

Projects

User Details

User Since
May 25 2018, 2:31 AM (73 w, 3 d)

Recent Activity

Sat, Oct 19

hagbard added a comment to T1743: equuleus: remove references to SSH key type "rsa1" deprecated in Debian Buster.

Thanks for your contribution.

Sat, Oct 19, 1:31 AM · VyOS 1.3 Equuleus

Fri, Oct 18

hagbard moved T1581: Add GNU Wget from Needs Triage to Finished on the VyOS 1.2 Crux (VyOS 1.2.4) board.
Fri, Oct 18, 10:19 PM · VyOS 1.2 Crux (VyOS 1.2.4), VyOS 1.3 Equuleus, vyatta-busybox
hagbard moved T1581: Add GNU Wget from Need Triage to Finished on the VyOS 1.3 Equuleus board.
Fri, Oct 18, 10:19 PM · VyOS 1.2 Crux (VyOS 1.2.4), VyOS 1.3 Equuleus, vyatta-busybox
hagbard closed T1581: Add GNU Wget as Wontfix.
Fri, Oct 18, 10:19 PM · VyOS 1.2 Crux (VyOS 1.2.4), VyOS 1.3 Equuleus, vyatta-busybox
hagbard moved T1604: equuleus: buster: vbash: tab completion breaks from Need Triage to Finished on the VyOS 1.3 Equuleus board.
Fri, Oct 18, 9:52 PM · VyOS 1.3 Equuleus
hagbard closed T1604: equuleus: buster: vbash: tab completion breaks, a subtask of T476: Start builds for Debian 10 (Buster), as Resolved.
Fri, Oct 18, 9:52 PM · VyOS 1.3 Equuleus
hagbard closed T1604: equuleus: buster: vbash: tab completion breaks as Resolved.

Perfect. Thanks a lot guys.

Fri, Oct 18, 9:52 PM · VyOS 1.3 Equuleus
hagbard changed the status of T1581: Add GNU Wget from Open to On hold.
Fri, Oct 18, 8:03 PM · VyOS 1.2 Crux (VyOS 1.2.4), VyOS 1.3 Equuleus, vyatta-busybox
hagbard added a comment to T1581: Add GNU Wget.

@Harliff Does curl work for you?

Fri, Oct 18, 8:03 PM · VyOS 1.2 Crux (VyOS 1.2.4), VyOS 1.3 Equuleus, vyatta-busybox
hagbard claimed T1581: Add GNU Wget.
Fri, Oct 18, 8:02 PM · VyOS 1.2 Crux (VyOS 1.2.4), VyOS 1.3 Equuleus, vyatta-busybox
hagbard added a comment to T1604: equuleus: buster: vbash: tab completion breaks.

Is that still and issue, sorry I lost track a little while I was busy with other stuff.

Fri, Oct 18, 8:01 PM · VyOS 1.3 Equuleus
hagbard changed the status of T1705: High CPU usage by bgpd when snmp is active from Needs testing to Backport candidate.
Fri, Oct 18, 7:59 PM · VyOS 1.2 Crux
hagbard moved T1705: High CPU usage by bgpd when snmp is active from In Progress to Backlog on the VyOS 1.2 Crux board.
Fri, Oct 18, 7:58 PM · VyOS 1.2 Crux
hagbard closed T1684: Unable to enable IPv6 autoconf on PPPoE as Resolved.
Fri, Oct 18, 7:58 PM · VyOS 1.3 Equuleus, VyOS 1.2 Crux (VyOS 1.2.3)
hagbard moved T1684: Unable to enable IPv6 autoconf on PPPoE from Backlog to Finished on the VyOS 1.2 Crux (VyOS 1.2.3) board.
Fri, Oct 18, 7:58 PM · VyOS 1.3 Equuleus, VyOS 1.2 Crux (VyOS 1.2.3)
hagbard added a comment to T1741: Add system wide proxy setting.

already added to the ocumentation: https://vyos.readthedocs.io/en/latest/system/proxy.html

Fri, Oct 18, 7:40 PM · VyOS 1.3 Equuleus
hagbard changed the status of T1741: Add system wide proxy setting from In progress to Needs testing.

https://github.com/vyos/vyos-1x/commit/df9544233fb661e830285c1a0d7755cff4b27408
https://github.com/vyos/vyatta-cfg-system/commit/3a99ea6e9b8ef9ef417d38d1d0bab8d2d2401aa8 (add system image)

Fri, Oct 18, 6:03 PM · VyOS 1.3 Equuleus
hagbard added a comment to T1741: Add system wide proxy setting.

I have an idea, I can either write it to profile.d, that is exporting http_proxy, https_proxy and ftp_proxy into the shell env, and in the install-image script if the profile files exists, I load it which exposes these variables as well and curl is working with no issue. If removed, that file won't exists and curl works like it did before. If the proxy variables shouldn't be in the user environment, I can write it to a particular file only used by scripts which which would need that information.

Fri, Oct 18, 5:13 PM · VyOS 1.3 Equuleus
hagbard added a comment to T1741: Add system wide proxy setting.

curl only accepts ~/.curlrc, so that can become a hassle with multiple home directories on a box.

Fri, Oct 18, 4:42 PM · VyOS 1.3 Equuleus
hagbard moved T1720: support for more 'show ip route' commands from In Progress to Backlog on the VyOS 1.2 Crux board.
Fri, Oct 18, 4:23 PM · VyOS 1.2 Crux
hagbard added a comment to T1741: Add system wide proxy setting.

That would work but it's only for a single programm you define it. I think it could be enough for the beginning. I still have to check if curlrc is being read when invoked from the perl script, it usually should.

Fri, Oct 18, 3:10 PM · VyOS 1.3 Equuleus

Thu, Oct 17

hagbard added a comment to T1741: Add system wide proxy setting.

The removal makes a little headache. Setting it system wide is not an issue at all, writing and execute in profile.d. Removing it would require to logout and login again to re-read the bash.profile. I may have to rethink that.

Thu, Oct 17, 10:01 PM · VyOS 1.3 Equuleus
hagbard triaged T1741: Add system wide proxy setting as Normal priority.
Thu, Oct 17, 9:49 PM · VyOS 1.3 Equuleus
hagbard changed the status of T1741: Add system wide proxy setting from Open to In progress.
Thu, Oct 17, 9:49 PM · VyOS 1.3 Equuleus
hagbard claimed T1741: Add system wide proxy setting.

I have that issue for a while here too and just helped myself locally. I'll can take care of that.

Thu, Oct 17, 3:10 PM · VyOS 1.3 Equuleus

Tue, Oct 15

hagbard added a comment to T1732: Removing vyatta-webproxy module.

Most enterprises use it still as a cheap authentication method, I'm totally in favor to drop it, not only in vyos. Breaking it off (they generate fitting ssl certs on the fly signed with a private PKI), is questionable as well, since I think https should be end to end encryption, everyone who messes with that idea, well I wouldn't trust them on other items as well.

Tue, Oct 15, 4:36 PM · VyOS 1.3 Equuleus
hagbard added a comment to T1705: High CPU usage by bgpd when snmp is active.

works with:

Version:          VyOS 1.2-rolling-201910110117
Built by:         autobuild@vyos.net
Built on:         Fri 11 Oct 2019 01:17 UTC
Build UUID:       48a11fa6-8c59-4dbb-94a3-215376c09a02
Build Commit ID:  46f9b2ab60e4fa
Tue, Oct 15, 4:22 PM · VyOS 1.2 Crux
hagbard added a comment to T1705: High CPU usage by bgpd when snmp is active.

Can't create an iso right now to test it.

Tue, Oct 15, 4:17 PM · VyOS 1.2 Crux
hagbard added a comment to T1705: High CPU usage by bgpd when snmp is active.

typo fixed: https://github.com/vyos/vyos-1x/commit/50acd442ade9a4e447269eaf94ce14d354af8d0c
http://dev.packages.vyos.net/repositories/current/vyos/pool/main/v/vyos-1x/vyos-1x_1.3.0-16_all.deb should work now

Tue, Oct 15, 3:56 PM · VyOS 1.2 Crux

Fri, Oct 11

hagbard moved T1684: Unable to enable IPv6 autoconf on PPPoE from In Progress to Finished on the VyOS 1.3 Equuleus board.
Fri, Oct 11, 9:21 PM · VyOS 1.3 Equuleus, VyOS 1.2 Crux (VyOS 1.2.3)
hagbard claimed T1604: equuleus: buster: vbash: tab completion breaks.

@jjakob Is that still an issue? I have the lastest 1.3 rolling form today and can't reproduce the issue.

Fri, Oct 11, 8:35 PM · VyOS 1.3 Equuleus
hagbard added a comment to T1725: VyOS 1.2 Rolling 201910110117 DHCP Server Configuration Fails.

running from the live-cd I think.

Fri, Oct 11, 7:59 PM · VyOS 1.2 Crux
hagbard lowered the priority of T1725: VyOS 1.2 Rolling 201910110117 DHCP Server Configuration Fails from High to Normal.

@brian.ward Please show the output of df-h at your earliest convenience.

Fri, Oct 11, 5:53 PM · VyOS 1.2 Crux
hagbard closed T1722: Add ability to debug Wireguard connections as Wontfix.
Fri, Oct 11, 5:49 PM · VyOS 1.2 Crux, VyOS 1.3 Equuleus
hagbard added a comment to T1722: Add ability to debug Wireguard connections.

@bertleywjh any other input, or can I close the ticket?

Fri, Oct 11, 5:44 PM · VyOS 1.2 Crux, VyOS 1.3 Equuleus
hagbard added a project to T1725: VyOS 1.2 Rolling 201910110117 DHCP Server Configuration Fails: VyOS 1.2 Crux.
Fri, Oct 11, 5:27 PM · VyOS 1.2 Crux
hagbard added a comment to T1725: VyOS 1.2 Rolling 201910110117 DHCP Server Configuration Fails.

@brian.ward Can you please check that /config is mounted?

Fri, Oct 11, 5:25 PM · VyOS 1.2 Crux
hagbard added a comment to T1725: VyOS 1.2 Rolling 201910110117 DHCP Server Configuration Fails.

Can't reproduce it, it does work without any issues. I copied and executed your config and did a commit.

Fri, Oct 11, 5:23 PM · VyOS 1.2 Crux
hagbard claimed T1725: VyOS 1.2 Rolling 201910110117 DHCP Server Configuration Fails.
Fri, Oct 11, 5:20 PM · VyOS 1.2 Crux
hagbard moved T1723: wireguard - Interface wg01 could not be brought up in time from Need Triage to Finished on the VyOS 1.3 Equuleus board.
Fri, Oct 11, 4:51 PM · VyOS 1.3 Equuleus
hagbard removed a project from T1723: wireguard - Interface wg01 could not be brought up in time : VyOS 1.2 Crux.
Fri, Oct 11, 4:51 PM · VyOS 1.3 Equuleus
hagbard closed T1723: wireguard - Interface wg01 could not be brought up in time as Resolved.

Looks like it has changed already in ifconfig.py. Tested it successfully as well.
https://github.com/vyos/vyos-1x/commit/f5c04661e6c031baedb6092ecafee501cca7bc28#diff-def38e05f2ac1eb35139b37ec8d47338R1375

Fri, Oct 11, 4:51 PM · VyOS 1.3 Equuleus
hagbard moved T1720: support for more 'show ip route' commands from Need Triage to In Progress on the VyOS 1.2 Crux board.
Fri, Oct 11, 4:41 PM · VyOS 1.2 Crux
hagbard moved T1724: wireguard - add endpoint check in verify() from In Progress to Finished on the VyOS 1.3 Equuleus board.
Fri, Oct 11, 4:10 PM · VyOS 1.3 Equuleus, VyOS 1.2 Crux
hagbard closed T1724: wireguard - add endpoint check in verify() as Resolved.
Fri, Oct 11, 4:10 PM · VyOS 1.3 Equuleus, VyOS 1.2 Crux
hagbard changed the status of T1724: wireguard - add endpoint check in verify() from Open to In progress.
Fri, Oct 11, 3:43 PM · VyOS 1.3 Equuleus, VyOS 1.2 Crux

Thu, Oct 10

hagbard triaged T1724: wireguard - add endpoint check in verify() as Normal priority.
Thu, Oct 10, 10:42 PM · VyOS 1.3 Equuleus, VyOS 1.2 Crux
hagbard claimed T1724: wireguard - add endpoint check in verify().
Thu, Oct 10, 10:42 PM · VyOS 1.3 Equuleus, VyOS 1.2 Crux
hagbard created T1724: wireguard - add endpoint check in verify().
Thu, Oct 10, 10:42 PM · VyOS 1.3 Equuleus, VyOS 1.2 Crux
hagbard triaged T1723: wireguard - Interface wg01 could not be brought up in time as Normal priority.
Thu, Oct 10, 10:40 PM · VyOS 1.3 Equuleus
hagbard added a comment to T1723: wireguard - Interface wg01 could not be brought up in time .

@cpo operstate will be unknown for wg interfaces, I think it's the only interface type having unknown. Anything else should be up or down, I think. I can re-implement with the wg class if that's better.
Let me know what you think, wg is working with no issues, so functionality isn't an issue here.

Thu, Oct 10, 10:40 PM · VyOS 1.3 Equuleus
hagbard updated the task description for T1723: wireguard - Interface wg01 could not be brought up in time .
Thu, Oct 10, 10:32 PM · VyOS 1.3 Equuleus
hagbard updated the task description for T1723: wireguard - Interface wg01 could not be brought up in time .
Thu, Oct 10, 10:29 PM · VyOS 1.3 Equuleus
hagbard claimed T1723: wireguard - Interface wg01 could not be brought up in time .
Thu, Oct 10, 10:26 PM · VyOS 1.3 Equuleus
hagbard created T1723: wireguard - Interface wg01 could not be brought up in time .
Thu, Oct 10, 10:25 PM · VyOS 1.3 Equuleus
hagbard added a comment to T1722: Add ability to debug Wireguard connections.

@bertleywjh wg state and link state is all is unfortunately all you will be able to see, plus like when was the last handshake and how many bytes were transfered. AFAIK there is no other way to see states of the handshake etc.

Thu, Oct 10, 9:58 PM · VyOS 1.2 Crux, VyOS 1.3 Equuleus
hagbard added a comment to T1705: High CPU usage by bgpd when snmp is active.

@fvbrasileiro here you go: https://downloads.vyos.io/rolling/current/amd64/vyos-1.2-rolling-201910102056-amd64.iso

Thu, Oct 10, 9:27 PM · VyOS 1.2 Crux
hagbard added a comment to T1705: High CPU usage by bgpd when snmp is active.

@fvbrasileiro Yeah, we found that out too today, we are working on a solution already. Please be patient.

Thu, Oct 10, 8:54 PM · VyOS 1.2 Crux
hagbard moved T1722: Add ability to debug Wireguard connections from Need Triage to In Progress on the VyOS 1.3 Equuleus board.
Thu, Oct 10, 8:38 PM · VyOS 1.2 Crux, VyOS 1.3 Equuleus
hagbard moved T1722: Add ability to debug Wireguard connections from Need Triage to In Progress on the VyOS 1.2 Crux board.
Thu, Oct 10, 8:38 PM · VyOS 1.2 Crux, VyOS 1.3 Equuleus
hagbard triaged T1722: Add ability to debug Wireguard connections as Normal priority.
Thu, Oct 10, 8:38 PM · VyOS 1.2 Crux, VyOS 1.3 Equuleus
hagbard added a comment to T1722: Add ability to debug Wireguard connections.

@bertleywjh What issue are your trying to debug?

Thu, Oct 10, 8:37 PM · VyOS 1.2 Crux, VyOS 1.3 Equuleus
hagbard claimed T1722: Add ability to debug Wireguard connections.
Thu, Oct 10, 8:35 PM · VyOS 1.2 Crux, VyOS 1.3 Equuleus
hagbard changed the status of T1720: support for more 'show ip route' commands from Open to In progress.

Next rolling will have it: https://github.com/vyos/vyatta-op-quagga/commit/219265ae4c8886bb6997ffc79f34610d6e2ea2d0 or you can manually install from the source below, if it is an urgent matter.

Thu, Oct 10, 8:35 PM · VyOS 1.2 Crux
hagbard added a comment to T1720: support for more 'show ip route' commands .

The cli part for the routing suite is up for rewrite, json is only working because it's supported by frr and the cli doesn't filter it. I think getting show ip route tag 20 working shouldn't be a big deal, but I try to avoid to add too much to the cli, will make just the rewrite way harder.

Thu, Oct 10, 6:13 PM · VyOS 1.2 Crux
hagbard added a comment to T1705: High CPU usage by bgpd when snmp is active.

There were multiple complains about bgpd crashes, memory issues inthe forum. They used the workaround removing the tables from snmpd successfully.

Thu, Oct 10, 4:17 PM · VyOS 1.2 Crux
hagbard added a comment to T1720: support for more 'show ip route' commands .

@olofl How do you set the tag? via CLI?

Thu, Oct 10, 4:13 PM · VyOS 1.2 Crux
hagbard claimed T1720: support for more 'show ip route' commands .
Thu, Oct 10, 3:49 PM · VyOS 1.2 Crux
hagbard added a comment to T1705: High CPU usage by bgpd when snmp is active.

@fvbrasileiro Please test at your earliest convenience.

Thu, Oct 10, 3:10 PM · VyOS 1.2 Crux
hagbard moved T1705: High CPU usage by bgpd when snmp is active from Need Triage to In Progress on the VyOS 1.2 Crux board.
Thu, Oct 10, 3:07 PM · VyOS 1.2 Crux
hagbard changed the status of T1705: High CPU usage by bgpd when snmp is active from Open to Needs testing.
Thu, Oct 10, 3:07 PM · VyOS 1.2 Crux
hagbard claimed T1705: High CPU usage by bgpd when snmp is active.
Thu, Oct 10, 2:50 PM · VyOS 1.2 Crux

Wed, Oct 9

hagbard closed T1718: ISO check in /opt/vyatta/sbin/install-image faulty as Resolved.

https://github.com/vyos/vyatta-cfg-system/commit/4b3434f8fab3201e7483bff95af71b7a1f51a13c

Wed, Oct 9, 8:25 PM · VyOS 1.3 Equuleus
hagbard closed T1719: ssh deprecated options as Resolved.

1.2 is not affected which runs OpenSSH_6.7p1 Debian-5+deb8u8, OpenSSL 1.0.1t 3 May 2016

Wed, Oct 9, 4:19 PM · VyOS 1.3 Equuleus
hagbard closed T1663: T1656 equuleus: buster: arm64/aarch64: ipaddrcheck does not complete testing, a subtask of T476: Start builds for Debian 10 (Buster), as Resolved.
Wed, Oct 9, 3:19 PM · VyOS 1.3 Equuleus
hagbard closed T1663: T1656 equuleus: buster: arm64/aarch64: ipaddrcheck does not complete testing as Resolved.
Wed, Oct 9, 3:19 PM · VyOS 1.3 Equuleus
hagbard moved T1718: ISO check in /opt/vyatta/sbin/install-image faulty from Need Triage to In Progress on the VyOS 1.3 Equuleus board.
Wed, Oct 9, 3:18 PM · VyOS 1.3 Equuleus
hagbard moved T1719: ssh deprecated options from Need Triage to In Progress on the VyOS 1.3 Equuleus board.
Wed, Oct 9, 3:18 PM · VyOS 1.3 Equuleus
hagbard renamed T1719: ssh deprecated options from ssh depricated options to ssh deprecated options.
Wed, Oct 9, 3:15 PM · VyOS 1.3 Equuleus

Tue, Oct 8

hagbard added a comment to T1719: ssh deprecated options.

Can we just remove the deprecated options from being generated? They only leave a few lines in syslog, but these options are deprecated already in stretch.
(https://www.openssh.com/txt/release-7.9)

Tue, Oct 8, 10:05 PM · VyOS 1.3 Equuleus
hagbard claimed T1719: ssh deprecated options.
Tue, Oct 8, 9:58 PM · VyOS 1.3 Equuleus
hagbard created T1719: ssh deprecated options.
Tue, Oct 8, 9:58 PM · VyOS 1.3 Equuleus
hagbard closed T1717: disable multiple daemons to autostart at boot as Resolved.

https://github.com/vyos/vyos-build/commit/1ff1b22726f1f4678dca8295860623d728e20521

Tue, Oct 8, 8:43 PM · VyOS 1.3 Equuleus
hagbard claimed T1718: ISO check in /opt/vyatta/sbin/install-image faulty.
Tue, Oct 8, 8:28 PM · VyOS 1.3 Equuleus
hagbard created T1718: ISO check in /opt/vyatta/sbin/install-image faulty.
Tue, Oct 8, 8:26 PM · VyOS 1.3 Equuleus
hagbard changed the status of T1717: disable multiple daemons to autostart at boot from Open to In progress.
Tue, Oct 8, 4:16 PM · VyOS 1.3 Equuleus
hagbard claimed T1717: disable multiple daemons to autostart at boot.
  • systemctl disable pacemaker
  • systemctl disable corosync
  • systemctl disable wpa_supplicant
Tue, Oct 8, 4:11 PM · VyOS 1.3 Equuleus
hagbard renamed T1717: disable multiple daemons to autostart at boot from disable pacemaker, squid autostart at boot to disable multiple daemons to autostart at boot.
Tue, Oct 8, 3:55 PM · VyOS 1.3 Equuleus
hagbard triaged T1717: disable multiple daemons to autostart at boot as Normal priority.
Tue, Oct 8, 3:51 PM · VyOS 1.3 Equuleus
hagbard created T1717: disable multiple daemons to autostart at boot.
Tue, Oct 8, 3:51 PM · VyOS 1.3 Equuleus

Thu, Oct 3

hagbard moved T1700: Wireguard FQDN endpoint doesn't work after reboot from In Progress to Finished on the VyOS 1.3 Equuleus board.
Thu, Oct 3, 5:39 PM · VyOS 1.3 Equuleus, VyOS 1.2 Crux
hagbard moved T1700: Wireguard FQDN endpoint doesn't work after reboot from Backlog to Finished on the VyOS 1.2 Crux board.
Thu, Oct 3, 5:39 PM · VyOS 1.3 Equuleus, VyOS 1.2 Crux
hagbard closed T1700: Wireguard FQDN endpoint doesn't work after reboot as Wontfix.
Thu, Oct 3, 5:38 PM · VyOS 1.3 Equuleus, VyOS 1.2 Crux

Wed, Oct 2

hagbard added a comment to T1700: Wireguard FQDN endpoint doesn't work after reboot.

I'll close as won't fix, given the fact that it is an upstream issue. Anything build around it, is in my opinion just a kludge, unless we would go with a separate daemon which can check and re-establish connections if they fail. The danger is that vyos becomes then more a server than a router. As workaround, a cronjob could do that as well, either setting an option via cli (wg-heartbeat or so since keepalive is a wg option already), which drops a cronjob onto the box and checks the wg endpoint periodically, if it fails it just calls diable/enable and checks again for X times, before it sleeps for let's say 24hs or so. @kroy would something like acronjob help you? Could be also set as a @reboot job and once the traffic flows it kicks itself out. Just wanna throw out ideas here.

Wed, Oct 2, 7:18 PM · VyOS 1.3 Equuleus, VyOS 1.2 Crux

Tue, Oct 1

hagbard closed T1706: wireguard broken in latest rolling as Resolved.
Tue, Oct 1, 7:53 PM · VyOS 1.3 Equuleus
hagbard added a comment to T1706: wireguard broken in latest rolling.

https://github.com/vyos/vyos-1x/commit/cf499f958423919264884e9f1c5c1b593fd9de0e next rolling will have it fixed.

Tue, Oct 1, 7:53 PM · VyOS 1.3 Equuleus
hagbard moved T1706: wireguard broken in latest rolling from Need Triage to In Progress on the VyOS 1.3 Equuleus board.
Tue, Oct 1, 7:42 PM · VyOS 1.3 Equuleus
hagbard added a comment to T1706: wireguard broken in latest rolling.

They have been committed at the same time, while I was using the current version if ifconfig.py and new one was published.
https://github.com/vyos/vyos-1x/commit/c24eb48c54b562fe7f78cdda82f2e245e9ab8506

Tue, Oct 1, 7:39 PM · VyOS 1.3 Equuleus
hagbard renamed T1706: wireguard broken in latest rolling from wigreuard broken in latest rolling to wireguard broken in latest rolling.
Tue, Oct 1, 7:05 PM · VyOS 1.3 Equuleus
hagbard claimed T1706: wireguard broken in latest rolling.
Tue, Oct 1, 6:55 PM · VyOS 1.3 Equuleus