Page MenuHomeVyOS Platform

jjakob (Jernej Jakob)
User

Projects

User Details

User Since
Nov 6 2018, 10:08 PM (73 w, 5 d)

I'm usually on #vyos:chat.freenode.net.

Recent Activity

Sat, Apr 4

jjakob added a comment to T1586: OpenVPN add IPv6 support to tunnels.

duplicate of T149 ?

Sat, Apr 4, 2:00 PM · VyOS 1.3 Equuleus
jjakob added a comment to T149: IPv6 support in OpenVPN tunnel.

I can try to tackle this if noone else is working on it.

Sat, Apr 4, 1:59 PM · VyOS 1.3 Equuleus
jjakob added a comment to T2222: openvpn: requires "multihome" option to listen on all addresses with udp protocol.

https://github.com/vyos/vyos-1x/pull/298

Sat, Apr 4, 1:20 PM · VyOS 1.3 Equuleus
jjakob triaged T2222: openvpn: requires "multihome" option to listen on all addresses with udp protocol as Normal priority.
Sat, Apr 4, 1:10 PM · VyOS 1.3 Equuleus
jjakob triaged T2217: Comparing old and new configurations in scripts (daemon reloads and restarts) as Low priority.
Sat, Apr 4, 9:39 AM · VyOS 1.3 Equuleus
jjakob updated subscribers of T2205: "set interface ethernet" fails on Hyper-V.
Sat, Apr 4, 8:53 AM · VyOS 1.3 Equuleus
jjakob added a comment to T2205: "set interface ethernet" fails on Hyper-V.

Currently none of the offloading (gro, gso, sg, tso, ufo) settings are checked either at src/conf_mode/interfaces-ethernet.py verify() or in the module python/vyos/ifconfig/ethernet.py. Setting one of these when the driver doesn't support it will result in an unhandled exception. This may not be so disastrous when setting the options in config mode, as the commit will fail due to the exception, but will have more disastrous results when a config which has these options set is loaded into a system with NICs that don't support it - this will cause boot time commit to fail. As per T2158 and PR#272 none of these calls should result in an exception, but rather just print a warning and continue.

Sat, Apr 4, 8:48 AM · VyOS 1.3 Equuleus

Thu, Apr 2

jjakob closed T2072: Shell autocomplete of option (config node) with quoted value doesn't work as Resolved.
Thu, Apr 2, 5:10 PM · VyOS 1.3 Equuleus
jjakob reopened T2072: Shell autocomplete of option (config node) with quoted value doesn't work as "In progress".

This PR still needs to be merged: https://github.com/vyos/vyatta-cfg/pull/23

Thu, Apr 2, 4:39 PM · VyOS 1.3 Equuleus
jjakob triaged T1911: Completion helper list is not sorted as Low priority.
Thu, Apr 2, 3:08 PM · VyOS 1.3 Equuleus
jjakob added a comment to T1911: Completion helper list is not sorted.

The above patch breaks sorting for other nodes that contain text, not a number. We'd need some way to distinguish different node types (text, IP, number,...) and chose different sorts depending on that. I don't know if the new XML command definitions support a node type element, the old ones did (e.g. number could be type: u32).

Thu, Apr 2, 2:51 PM · VyOS 1.3 Equuleus
jjakob triaged T2199: Rewrite firewall in new XML/Python style as Wishlist priority.
Thu, Apr 2, 11:48 AM · VyOS 1.3 Equuleus
jjakob triaged T2198: Rewrite NAT in new XML/Python style as Wishlist priority.
Thu, Apr 2, 11:46 AM · VyOS 1.3 Equuleus
jjakob added a comment to T1579: Rewrite all interface types in new XML/Python style.

Is this only for interfaces or for other rewrites (NAT, Firewall, BGP) too? If so, I'll add all the related tasks.

Thu, Apr 2, 11:35 AM · VyOS 1.3 Equuleus

Wed, Apr 1

jjakob updated the task description for T2195: Support for encrypted DNS: dnscrypt, DoH, DoT, anonymized DNS.
Wed, Apr 1, 2:23 PM · VyOS 1.3 Equuleus
jjakob triaged T2195: Support for encrypted DNS: dnscrypt, DoH, DoT, anonymized DNS as Wishlist priority.
Wed, Apr 1, 2:21 PM · VyOS 1.3 Equuleus
jjakob added a comment to T2158: Commit fails if ethernet interface doesn't support flow control (pause).

What's the reason for enabling flow control by default? I'd have assumed disabled is more common and causes less problems. The node naming is not the best IMO as it has "disable-" in it, more reasonable would be to have a node called "flow-control" that enabled it if set, the default being disabled, and it could have sub-nodes to tweak the exact flow control settings.

Wed, Apr 1, 1:26 PM · VyOS 1.3 Equuleus
jjakob triaged T2194: "show firewall" garbled output as Low priority.
Wed, Apr 1, 12:53 PM · VyOS 1.3 Equuleus
jjakob added a comment to T2184: OpenVPN op_mode tools broken.

I would check in main, before get_status, if a interface is disabled in config, then I'd just print "vtunX is disabled" and skip all other processing for that interface. If a interface is enabled but its status file isn't readable, print "Error: status file for vtunX is not readable" (I'd use try/except around the open in get_status, and return a exception so that main can print the error).

Wed, Apr 1, 12:12 PM · VyOS 1.3 Equuleus
jjakob triaged T2192: Create common crypto library for creation/verification/management of RSA/EC/SSH keys, certificates, requests, etc. as Low priority.
Wed, Apr 1, 11:30 AM · VyOS 1.3 Equuleus

Tue, Mar 31

jjakob added a comment to T2158: Commit fails if ethernet interface doesn't support flow control (pause).

I can confirm the above commit fixes booting with interfaces that don't support flow control. I have no way of checking that it properly applies if the interface does support it.

Tue, Mar 31, 8:55 PM · VyOS 1.3 Equuleus
jjakob closed T2144: vyos-build: docker: selection of text in the terminal still selects it in vim (mouse isn't completely disabled) as Resolved.
Tue, Mar 31, 8:43 PM · vyos-build, VyOS 1.3 Equuleus
jjakob closed T2137: vyos-build: set debian mirror for building docker image from ./configure as Wontfix.

After discussion on the PR it was determined this functionality wasn't needed.

Tue, Mar 31, 8:42 PM · vyos-build
jjakob changed the status of T2118: Failure to boot after power outage due to dirty filesystem and no fsck in initramfs from Needs testing to Confirmed.
Tue, Mar 31, 7:50 PM · VyOS 1.3 Equuleus
jjakob added a comment to T2118: Failure to boot after power outage due to dirty filesystem and no fsck in initramfs.

I tested it today and it doesn't work yet.

Tue, Mar 31, 7:48 PM · VyOS 1.3 Equuleus
jjakob updated the task description for T2188: NTP op-mode commands don't work.
Tue, Mar 31, 11:26 AM · VyOS 1.3 Equuleus
jjakob triaged T2188: NTP op-mode commands don't work as Low priority.
Tue, Mar 31, 11:23 AM · VyOS 1.3 Equuleus
jjakob added a comment to T2186: Provide more information to the user when a traceback is reported to the user.

+1, I'd also like if all failed commits were stored in a permanent log somewhere to make debugging easier, I can't find one right now.

Tue, Mar 31, 11:15 AM · VyOS 1.3 Equuleus
jjakob added a comment to T2184: OpenVPN op_mode tools broken.

The file exists on my system (1.3-rolling-202003291001):

-rw------- 1 root root 377 Mar 31 11:44 /opt/vyatta/etc/openvpn/status/vtun0.status

and show openvpn server works:

vyos@rt-home:~$ show openvpn server
Tue, Mar 31, 9:50 AM · VyOS 1.3 Equuleus
jjakob added a comment to T1999: support for ip groups in nat.

I vote for this as well. I have a lot of addresses I need to add to a nat source address so I need to create one rule per IP. Because I have a specific rule numbering scheme, I'm running out of space in it so I had to break the scheme. The ability to use groups in nat source and destination addresses would greatly help.

Tue, Mar 31, 9:37 AM · VyOS 1.3 Equuleus
jjakob added a comment to T2184: OpenVPN op_mode tools broken.

While you're looking at it, can you try to move it to a systemd service? I opened a task for discussion: T2185

Tue, Mar 31, 4:48 AM · VyOS 1.3 Equuleus
jjakob triaged T2185: Start daemons with systemd units instead of with start-stop-daemon as Normal priority.
Tue, Mar 31, 4:37 AM · VyOS 1.3 Equuleus

Sun, Mar 29

jjakob triaged T2177: Commit fails on adding disabled interface to bridge as Unbreak Now! priority.
Sun, Mar 29, 2:49 PM · VyOS 1.3 Equuleus
jjakob triaged T2176: 'WiFiIf' object has no attribute 'set_state' as Unbreak Now! priority.
Sun, Mar 29, 2:43 PM · VyOS 1.3 Equuleus

Sat, Mar 28

jjakob added a comment to T2133: ipv6 disable not working.

It's useful when the user is sure he doesn't want IPv6, as it lessens the attack surface, especially if the user doesn't know he needs to configure a IPv6 firewall separately to the IPv4 firewall. Even link-local addresses can be used to launch attacks in the absence of a firewall config.
IMO the configured interface addresses and v6 nodes should become no-ops, possibly print a warning on commit.
On the other hand, leaving IPv6 enabled, would be better to move in the direction of v6 adoption. Personally, I'd prefer this, and leave v6 enabled by default.

Sat, Mar 28, 1:58 PM · vyatta-cfg-system, vyatta-ipv6-rtradv, VyOS 1.3 Equuleus

Thu, Mar 26

jjakob added a comment to T2158: Commit fails if ethernet interface doesn't support flow control (pause).

also I would remove L107-L109 and move the debug message to the exception handler of L114

Thu, Mar 26, 10:53 AM · VyOS 1.3 Equuleus
jjakob added a comment to T2158: Commit fails if ethernet interface doesn't support flow control (pause).

I think this throws a exception that isn't caught: https://github.com/vyos/vyos-1x/blob/583e9d907236a4a98fe40e97a378c1fb655f8a95/python/vyos/ifconfig/ethernet.py#L114

root@vyos:~# /sbin/ethtool --show-pause eth0
Pause parameters for eth0:
Cannot get device pause settings: Operation not supported
root@vyos:~# echo $?
76
Thu, Mar 26, 10:51 AM · VyOS 1.3 Equuleus
jjakob updated jjakob.
Thu, Mar 26, 10:33 AM
jjakob added a comment to T2158: Commit fails if ethernet interface doesn't support flow control (pause).

@thomas-mangin Which commit do you mean, https://github.com/vyos/vyos-1x/commit/60d35d1d4d3a5acec6e39cccb166fd33490b6c27 ?
I can definitely say that did not fix the issue for r8169, the router failed boot after upgrading to 1.3-rolling-202003250217. If there were any patches after that, I can't see them.

Thu, Mar 26, 10:26 AM · VyOS 1.3 Equuleus
jjakob renamed T2158: Commit fails if ethernet interface doesn't support flow control (pause) from Need to add xen_netfront to interfaces that don't support pause to Commit fails if ethernet interface doesn't support flow control (pause).
Thu, Mar 26, 8:49 AM · VyOS 1.3 Equuleus

Wed, Mar 25

jjakob added a comment to T2105: wireless: not possible to disabled wlan0.

I'm still getting the same behavior on 1.3-rolling-202003250217:

vyos@vyos:~$ show interfaces wireless
Codes: S - State, L - Link, u - Up, D - Down, A - Admin Down
Interface        IP Address                        S/L  Description
---------        ----------                        ---  -----------
wlan0            -                                 u/u  
vyos@vyos:~$ configure
[edit]
vyos@vyos# set interfaces wireless wlan0 disable
Wed, Mar 25, 8:42 PM · VyOS 1.3 Equuleus
jjakob added a comment to T2162: migration script for router-advert sets link-mtu 0 on bridge interfaces.

Actually I had link-mtu 0 on br0 for a long time now and it worked without problem previously, maybe 0 was a special meaning for radvd?
br0 is the only interface that had ipv6 router-advert, I included one of the eth's for completeness:

interfaces {
    bridge br0 {
        address 192.0.2.1/24
        address 2001:db8::1/64
        aging 300
        description LAN
        firewall {
            local {
                name lan-local
            }
        }
        hello-time 2
        ipv6 {
            dup-addr-detect-transmits 2
            router-advert {
                cur-hop-limit 64
                link-mtu 0
                managed-flag true
                max-interval 600
                other-config-flag false
                prefix 2001:db8::/64 {
                    autonomous-flag true
                    on-link-flag true
                    valid-lifetime 2592000
                }
                reachable-time 0
                retrans-timer 0
                send-advert true
            }
        }
        max-age 20
        member {
            interface eth0 {
            }
            interface eth1 {
            }
            interface eth2 {
            }
            interface eth4 {
            }
            interface wlan0 {
            }
        }
        priority 20480
        stp
    }
    ethernet eth0 {
        duplex auto
        hw-id xx:xx:xx:xx:xx:xx
        smp-affinity auto
        speed auto
    }
}
Wed, Mar 25, 8:22 PM · VyOS 1.3 Equuleus
jjakob added a comment to T2158: Commit fails if ethernet interface doesn't support flow control (pause).

I already hotfixed the issue on mine by adding r8169 into the unsupported list - but as said, that's not the real solution.

Wed, Mar 25, 7:23 PM · VyOS 1.3 Equuleus
jjakob added a comment to T2158: Commit fails if ethernet interface doesn't support flow control (pause).

Maybe check the physical interface support via ethtool in the ethernet validate() function and raise a configerror if it doesn't? Or should the default be disabled and should a config command be enable-flow-control? The script that actually sets the flow control should definitely just print a warning to the syslog and not fail.

Wed, Mar 25, 7:15 PM · VyOS 1.3 Equuleus
jjakob added a comment to T2158: Commit fails if ethernet interface doesn't support flow control (pause).

I'll open a new task for it.

Wed, Mar 25, 6:55 PM · VyOS 1.3 Equuleus
jjakob closed T2148: openvpn: setting "server client" config without "server client ip" results in ValueError: '' does not appear to be an IPv4 or IPv6 address as Resolved.
Wed, Mar 25, 5:48 PM · VyOS 1.3 Equuleus
jjakob added a comment to T2158: Commit fails if ethernet interface doesn't support flow control (pause).

I suspect the driver blacklist won't be enough for a lot of users. A lot of very common ethernet cards don't support setting pause frames.

Wed, Mar 25, 5:31 PM · VyOS 1.3 Equuleus
jjakob triaged T2162: migration script for router-advert sets link-mtu 0 on bridge interfaces as Unbreak Now! priority.
Wed, Mar 25, 5:18 PM · VyOS 1.3 Equuleus
jjakob added a comment to T2158: Commit fails if ethernet interface doesn't support flow control (pause).

Please add r8169 as well. The script should check if the interface supports pause and silently continue if it doesn't, otherwise maintaining a list of all pause-unsupported interfaces is going to be next to impossible. I suspect a lot more of them don't.

Wed, Mar 25, 5:04 PM · VyOS 1.3 Equuleus
jjakob closed T1383: Cannot use quotes for openvpn-option --route-up as Invalid.
Wed, Mar 25, 4:23 PM · VyOS 1.3 Equuleus
jjakob added a comment to T1383: Cannot use quotes for openvpn-option --route-up.

Closing, 1.3 has rewritten the perl code from scratch in python, but the functionality should be the same.

Wed, Mar 25, 4:22 PM · VyOS 1.3 Equuleus
jjakob added a comment to T2113: OpenVPN Options error: you cannot use --verify-x509-name with --compat-names or --no-name-remapping.

We could make compat-names a configurable option that defaults to disabled, e.g. "set interfaces openvpn vtunX tls compat-names {no-remapping}"

Wed, Mar 25, 4:18 PM · VyOS 1.3 Equuleus
jjakob closed T2146: openvpn: "delete server client" doesn't delete the corresponding ccd configs as Resolved.
Wed, Mar 25, 4:11 PM · VyOS 1.3 Equuleus
jjakob claimed T2148: openvpn: setting "server client" config without "server client ip" results in ValueError: '' does not appear to be an IPv4 or IPv6 address.
Wed, Mar 25, 4:10 PM · VyOS 1.3 Equuleus
jjakob added a comment to T2139: openvpn: allow "dh-file none" to disable DH for ECDH keys.

The implementation mostly works, but still behaves unexpectedly when keys don't have a BEGIN EC PRIVATE KEY or BEGIN RSA PRIVATE KEY, but have just a plain BEGIN PRIVATE KEY, which is valid for both EC and RSA (and is the default output format for openssl ec -out, for example when removing a passphrase from the key). We need to switch to checking the key type by actually trying to read it with openssl and checking its error status.

Wed, Mar 25, 4:04 PM · VyOS 1.3 Equuleus

Tue, Mar 24

jjakob claimed T2146: openvpn: "delete server client" doesn't delete the corresponding ccd configs.
Tue, Mar 24, 7:26 PM · VyOS 1.3 Equuleus

Sun, Mar 22

jjakob created T2151: wireless: can't delete interface present in config but not present in system.
Sun, Mar 22, 12:29 PM · VyOS 1.3 Equuleus
jjakob added a comment to T1192: Wlan regression between 1.2.0-rc11 and rolling.

Couldn't reproduce in 1.3-rolling-20200319

Sun, Mar 22, 12:10 PM · VyOS 1.3 Equuleus

Sat, Mar 21

jjakob added a comment to T2147: "save" resets the edit level in config mode.

Sorry, the task name was wrong, "save" resets it, "commit" doesn't. Personally I prefer if it'd stay the same, but I don't care if it resets it either.

Sat, Mar 21, 6:28 PM · VyOS 1.3 Equuleus
jjakob renamed T2147: "save" resets the edit level in config mode from commit resets the edit level to "save" resets the edit level in config mode.
Sat, Mar 21, 6:27 PM · VyOS 1.3 Equuleus
jjakob created T2148: openvpn: setting "server client" config without "server client ip" results in ValueError: '' does not appear to be an IPv4 or IPv6 address.
Sat, Mar 21, 6:18 PM · VyOS 1.3 Equuleus
jjakob created T2147: "save" resets the edit level in config mode.
Sat, Mar 21, 6:16 PM · VyOS 1.3 Equuleus
jjakob created T2146: openvpn: "delete server client" doesn't delete the corresponding ccd configs.
Sat, Mar 21, 6:13 PM · VyOS 1.3 Equuleus
jjakob updated the task description for T2145: openvpn: server default topology net30 is incompatible with static client IPs for Windows clients.
Sat, Mar 21, 6:08 PM · VyOS 1.3 Equuleus
jjakob created T2145: openvpn: server default topology net30 is incompatible with static client IPs for Windows clients.
Sat, Mar 21, 6:07 PM · VyOS 1.3 Equuleus

Fri, Mar 20

jjakob added a comment to T2142: vyos-build: Add required packages and step to build-GCE-image script.

The discussion says the container should be started with --privileged, as is documented in the vyos-build readme. Did you test it with --privileged?

Fri, Mar 20, 9:55 AM · VyOS 1.3 Equuleus
jjakob changed the status of T2144: vyos-build: docker: selection of text in the terminal still selects it in vim (mouse isn't completely disabled) from Open to In progress.
Fri, Mar 20, 9:50 AM · vyos-build, VyOS 1.3 Equuleus
jjakob closed T2143: Hope to support DHCPv6 PD as Invalid.

Duplicate of T421

Fri, Mar 20, 9:38 AM · VyOS 2.0.x, VyOS 1.3 Equuleus
jjakob added a comment to T2054: Changing "system name-server" doesn't update dns forwarding config, neither does "restart dns forwarding".

Still present in 1.3-20200319

Fri, Mar 20, 9:35 AM · VyOS 1.3 Equuleus
jjakob added a comment to T2072: Shell autocomplete of option (config node) with quoted value doesn't work.

The above commit fixes value help on tab (it displays correct quoted values, the script doesn't error any more) but the completion itself is still broken.

Fri, Mar 20, 9:32 AM · VyOS 1.3 Equuleus
jjakob changed the status of T2072: Shell autocomplete of option (config node) with quoted value doesn't work from In progress to On hold.
Fri, Mar 20, 9:29 AM · VyOS 1.3 Equuleus
jjakob closed T2140: openvpn: tls file check function checkCertHeader returns True even when no match is found as Resolved.
Fri, Mar 20, 9:22 AM · VyOS 1.3 Equuleus

Thu, Mar 19

jjakob changed the status of T2140: openvpn: tls file check function checkCertHeader returns True even when no match is found from Open to In progress.
Thu, Mar 19, 7:30 PM · VyOS 1.3 Equuleus
jjakob changed the status of T2139: openvpn: allow "dh-file none" to disable DH for ECDH keys from Open to In progress.
Thu, Mar 19, 5:13 PM · VyOS 1.3 Equuleus
jjakob added a comment to T1538: conntrack-sync no longer works with VRRP/high-availability.

I opened the PR for our custom build of the package in vyos-build as well: https://github.com/vyos/vyos-build/pulls. I was waiting on testing results from anyone, but I went and tested it myself. The basic functionality works, I couldn't test the above bug. If it's merged and the new package build is added to CI, the above debian PR isn't needed (or our custom build isn't).

Thu, Mar 19, 4:34 PM · vyatta-vrrp, conntrack-tools
jjakob created T2138: Can't load archived configs as they are gzipped.
Thu, Mar 19, 4:21 PM · VyOS 1.3 Equuleus
jjakob closed T1744: Config load fails in ConfigTree with ValueError: Failed to parse config: lexing: empty token, a subtask of T1801: Unescaped backslashes in config values cause configuration failure, as Resolved.
Thu, Mar 19, 4:12 PM · VyOS 1.3 Equuleus
jjakob closed T1744: Config load fails in ConfigTree with ValueError: Failed to parse config: lexing: empty token as Resolved.
Thu, Mar 19, 4:12 PM · VyOS 1.3 Equuleus
jjakob added a comment to T577: Unconfigured Ethernet interface discovery partial failure on boot.

I ran into this today after upgrading to latest 1.3 rolling image. All interfaces were added and appeared to have the correct macs (the output of ip link matched what was in the config), but the physical interfaces to which they corresponded weren't right. I found this by looking at the link state of each interface and saw that two if them were swapped. The interface that should be eth2 was physically eth4 and vice versa, but the macs it was showing in ip link was wrong for that physical card, as if it were set to the other interface's mac erroneously.
I got the cards to detect properly after 2 reboots.

Thu, Mar 19, 3:51 PM · VyOS 1.3 Equuleus
jjakob claimed T2137: vyos-build: set debian mirror for building docker image from ./configure.
Thu, Mar 19, 2:25 PM · vyos-build
jjakob changed the status of T2137: vyos-build: set debian mirror for building docker image from ./configure from Open to In progress.
Thu, Mar 19, 2:25 PM · vyos-build

Wed, Mar 11

jjakob closed T2084: conntrack-tools package build error for current/equuleus, a subtask of T2085: Building some packages with vyos-build no longer works for Equuleus/current, as Resolved.
Wed, Mar 11, 12:07 AM · vyos-build, VyOS 1.3 Equuleus
jjakob closed T2084: conntrack-tools package build error for current/equuleus as Resolved.
Wed, Mar 11, 12:07 AM · conntrack-tools, vyos-build, VyOS 1.3 Equuleus

Tue, Mar 10

jjakob added a comment to T1331: DNS stops working.

I haven't encountered this since, but the single 1.2 router is still on rc11, which has updated pdns-recursor 4.2, before being reverted: https://phabricator.vyos.net/R3:8c22ceead487b745d6b7c058c4d1c0a0eaa051c8 so it may still possibly be an issue in 1.2.
I've never encountered it on 1.3 rolling.

Tue, Mar 10, 7:29 PM · VyOS 1.3 Equuleus
jjakob triaged T2118: Failure to boot after power outage due to dirty filesystem and no fsck in initramfs as High priority.
Tue, Mar 10, 6:15 PM · VyOS 1.3 Equuleus
jjakob added a comment to T2085: Building some packages with vyos-build no longer works for Equuleus/current.

I'm not in the VyOS core team so I'm not able to make direct decisions on the resolution, but as I see it, there are several possible ways to approach this.

Tue, Mar 10, 5:29 PM · vyos-build, VyOS 1.3 Equuleus

Mar 1 2020

jjakob added a comment to T1538: conntrack-sync no longer works with VRRP/high-availability.

https://github.com/jjakob/vyos-build/tree/conntrack-tools-wip builds conntrack-tools from upstream git snapshot 20200301.

Mar 1 2020, 4:51 PM · vyatta-vrrp, conntrack-tools

Feb 29 2020

jjakob added a parent task for T2084: conntrack-tools package build error for current/equuleus: T2085: Building some packages with vyos-build no longer works for Equuleus/current.
Feb 29 2020, 2:51 PM · conntrack-tools, vyos-build, VyOS 1.3 Equuleus
jjakob added a subtask for T2085: Building some packages with vyos-build no longer works for Equuleus/current: T2084: conntrack-tools package build error for current/equuleus.
Feb 29 2020, 2:51 PM · vyos-build, VyOS 1.3 Equuleus
jjakob triaged T2084: conntrack-tools package build error for current/equuleus as Normal priority.
Feb 29 2020, 2:49 PM · conntrack-tools, vyos-build, VyOS 1.3 Equuleus
jjakob triaged T2072: Shell autocomplete of option (config node) with quoted value doesn't work as Normal priority.
Feb 29 2020, 2:48 PM · VyOS 1.3 Equuleus
jjakob changed the status of T2072: Shell autocomplete of option (config node) with quoted value doesn't work from Open to In progress.
Feb 29 2020, 2:47 PM · VyOS 1.3 Equuleus
jjakob added projects to T2084: conntrack-tools package build error for current/equuleus: vyos-build, conntrack-tools.
Feb 29 2020, 2:47 PM · conntrack-tools, vyos-build, VyOS 1.3 Equuleus
jjakob changed the status of T2084: conntrack-tools package build error for current/equuleus from Open to On hold.

Fixed temporarily for now in https://phabricator.vyos.net/R3:1c4414dd363bdb268038ae238686be3e0b7f988b
We should re-add building it from upstream to fix T1538.

Feb 29 2020, 2:45 PM · conntrack-tools, vyos-build, VyOS 1.3 Equuleus
jjakob added a comment to T2085: Building some packages with vyos-build no longer works for Equuleus/current.

https://github.com/vyos/vyos-build/pull/84

Feb 29 2020, 2:12 AM · vyos-build, VyOS 1.3 Equuleus
jjakob created T2085: Building some packages with vyos-build no longer works for Equuleus/current.
Feb 29 2020, 1:25 AM · vyos-build, VyOS 1.3 Equuleus

Feb 28 2020

jjakob added a comment to T1538: conntrack-sync no longer works with VRRP/high-availability.

@cpo I think you need to add it to CI in addition to vyos-build

Feb 28 2020, 10:55 PM · vyatta-vrrp, conntrack-tools
jjakob added a comment to T1538: conntrack-sync no longer works with VRRP/high-availability.

Upstream still hasn't made a release with this patch: https://git.netfilter.org/conntrack-tools/commit/?id=c12fa8df76752b0a011430f069677b52e4dad164
So we could wait on upstream to release it and debian to package it, or build our own as we used to in 1.2.
It would be better to ask upstream to make a release as there's less work for us.

Feb 28 2020, 10:34 PM · vyatta-vrrp, conntrack-tools
jjakob claimed T2084: conntrack-tools package build error for current/equuleus.
Feb 28 2020, 10:03 PM · conntrack-tools, vyos-build, VyOS 1.3 Equuleus
jjakob added a comment to T1538: conntrack-sync no longer works with VRRP/high-availability.

We don't build conntrack-tools in 1.3 (current/equuleus) any more, upstream Debian Buster conntrack and conntrackd packages are used. So as upstream gets patched, we'll pull in those patches automatically.
If I see things correctly, there are references to conntrack-tools in the build scripts that still need to be removed.

Feb 28 2020, 9:57 PM · vyatta-vrrp, conntrack-tools