Page MenuHomePhabricator

VyOS 1.2 Crux (VyOS 1.2.0-rc5)Milestone
ArchivedPublic

Members

  • This project does not have any members.

Watchers

  • This project does not have any watchers.

Recent Activity

Nov 13 2018

syncer archived VyOS 1.2 Crux (VyOS 1.2.0-rc5).
Nov 13 2018, 3:54 AM

Nov 7 2018

thinkl33t added a comment to T976: /etc/hosts is not updated when using hostfile-update on dhcp server in rc5.

It looks like this change was made in https://phabricator.vyos.net/T726 before the python rewrite.

Nov 7 2018, 12:02 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc7)
thinkl33t created T976: /etc/hosts is not updated when using hostfile-update on dhcp server in rc5.
Nov 7 2018, 12:00 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc7)

Nov 2 2018

hagbard closed T949: config issue when creating multiple wg interfaces at the same time. as Resolved.

https://github.com/vyos/vyos-1x/commit/2ad8fa385cefa1acbe75b8ca22a4183b00edf7de

Nov 2 2018, 7:19 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc6)

Oct 30 2018

runar added a comment to T949: config issue when creating multiple wg interfaces at the same time..

This is exactly the same issue i reported in T786, for every interface thats created the script runs its full processing.. when 10 interfaces are created it tries to execute it 10 times and so on. I have purposed a fix for this behaveor in T786 and there is a PR (https://github.com/vyos/vyos-1x/pull/33) on this. Another thing that could be done to fix this is to fix the underlaying vbash code that makes this happen, but i think that is a larger task.

Oct 30 2018, 5:15 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc6)
hagbard updated subscribers of T949: config issue when creating multiple wg interfaces at the same time..

All right, node.tag gets called twice. In the first round both interfaces are being configured correctly, then the parser calls it again (node.tag) and of course the IP already exists, so the error is valid from a script perspective.
Related to the issue @runar reported: https://phabricator.vyos.net/T786.

Oct 30 2018, 4:24 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc6)
syncer triaged T949: config issue when creating multiple wg interfaces at the same time. as Normal priority.
Oct 30 2018, 4:10 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc6)

Oct 29 2018

syncer moved T934: commit-archive from Needs Triage to Finished on the VyOS 1.2 Crux (VyOS 1.2.0-rc5) board.
Oct 29 2018, 6:19 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc5)
syncer moved T720: PPTP authentication username and password need to be restricted from Needs Triage to Finished on the VyOS 1.2 Crux (VyOS 1.2.0-rc5) board.
Oct 29 2018, 6:19 PM · VyOS 1.2 Crux (VyOS 1.2.0-rc5), VyOS-1.2.0-GA
hagbard closed T240: system integrity check as Resolved.

Currently only the check for additionally installed packages is implemented, but the script can be extended. Didn't push it to crux to have it properly tested first.

Oct 29 2018, 6:14 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc6)
hagbard closed T240: system integrity check, a subtask of T936: re-implementaion for 'show tech-support', as Resolved.
Oct 29 2018, 6:14 PM · VyOS 1.3 Equuleus
MrXermon added a comment to T943: Wireguard interfaces gone after reboot.

Listing the specific ip addresses was my legacy configuration. I removed it in the current configuration. I played a little with the interface routes and the seem to work properly on the technical side of things as i am able to ping the opposit device. But somehow the routing daemon lists routes to the peers as 'inactive' which makes the configuration unusable for me.

Oct 29 2018, 6:00 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc6)
hagbard added a comment to T943: Wireguard interfaces gone after reboot.

Since I don't know your listen ports I can't verify, if the ports you've set are correct or not. What I see in the logs, looks all ok, please keep in mind that your tunnel shows onl;y active if at least one packet passed the wg interface, otherwise you won't see anything.
So as far as i see from the above your wg interfaces are being created (you can bind multiple different peers to one interface by the way) and active.

Oct 29 2018, 5:35 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc6)
syncer added a project to T253: Config nodes containing spaces which have sub-nodes don't work: VyOS-1.2.0-GA.
Oct 29 2018, 5:26 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc5)
MrXermon added a comment to T943: Wireguard interfaces gone after reboot.

I rebased the router with the rc-4 image. After importing the configuration and rebooting the router a similar error occurs. The boot screen shows the error message "vyos-config[1708]: Configuration error". Looking into the configuration using 'show configuration' only shows the configuration of the wg2 interface but 'cat /config/config.boot' shows all three interfaces with correct configurations. The wireguard tool shows threee interfaces similar to the output before without any configuration.

Oct 29 2018, 5:25 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc6)
dmbaturin closed T253: Config nodes containing spaces which have sub-nodes don't work as Resolved.
Oct 29 2018, 5:25 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc5)
MrXermon added a comment to T943: Wireguard interfaces gone after reboot.

That's intresting. I rebooted the system a few seconds ago and the tunnels dom't become active.

Oct 29 2018, 5:04 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc6)
syncer added a comment to T816: ipaddrcheck / libcidr but on IPv6 network validation.

@c-po can we mark this as resolved?

Oct 29 2018, 9:59 AM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc10)
syncer moved T859: boot from UEFI from Backlog to In Progress on the VyOS 1.2 Crux (VyOS 1.2.0-rc5) board.
Oct 29 2018, 9:52 AM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc7)
syncer changed the status of T859: boot from UEFI from Open to In progress.
Oct 29 2018, 9:52 AM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc7)

Oct 28 2018

hagbard added a comment to T943: Wireguard interfaces gone after reboot.

I've tested your setup and can't find any issue with the interfaces in -rc4. However your routes won't survive a reboot, please use 'set protocols static interface-route <destination-net> next-hop-interface wg0'.
If that doesn't solve your issue, please check 'show interfaces' and check if the wg interfaces is setup after reboot there.
Also please provide the output of the following:
'grep wireguard /var/log/messages'

Oct 28 2018, 6:34 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc6)
dmbaturin claimed T944: BGP config script removes neighbor policies before deactivating the neighbor, which may cause routing table leaks.
Oct 28 2018, 6:04 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc6)
MrXermon added a comment to T943: Wireguard interfaces gone after reboot.

this is the configuration which i need to set again after each reboot (and i remove the ip address from the interface and set it again as ip + peer address as there is no configuration option at the moment). I removed some unimportant information.

Oct 28 2018, 4:48 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc6)
hagbard changed the status of T943: Wireguard interfaces gone after reboot from Open to In progress.

Hi @MrXermon ,
can you please share your configuration? At least the set interface wireguard ... ones would be interesting, so I can test it.

Oct 28 2018, 4:40 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc6)
hagbard updated subscribers of T253: Config nodes containing spaces which have sub-nodes don't work.

@dmbaturin Awesome, I didn't have the time to look into that further. I'm going to test it for sure.

Oct 28 2018, 4:38 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc5)
dmbaturin added a comment to T478: Firewall address group (multi and nesting).

Groups need a big overhaul, but its probably out of the 1.2.0 scope.

Oct 28 2018, 4:01 PM · VyOS 1.3 Equuleus
dmbaturin added a comment to T253: Config nodes containing spaces which have sub-nodes don't work.

I've finally located the place where tag node output is handled and added quoting analogous to what was always done to leaf node values. Now saved configs should be correct.

Oct 28 2018, 3:52 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc5)
dmbaturin edited projects for T720: PPTP authentication username and password need to be restricted, added: VyOS 1.2 Crux (VyOS 1.2.0-rc5); removed VyOS 1.2 Crux (VyOS 1.2.0-rc1).
Oct 28 2018, 3:52 PM · VyOS 1.2 Crux (VyOS 1.2.0-rc5), VyOS-1.2.0-GA
dmbaturin closed T906: APT sources present as Invalid.

In rc3 and rc4, it's empty for me.

Oct 28 2018, 3:06 PM · Invalid
syncer edited projects for T570: When edit level is not at the top, commit-archive only backups configuration for the current level and not the entire config, added: VyOS-1.2.0-GA; removed vyatta-config-mgmt.
Oct 28 2018, 2:35 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc5)
syncer merged T934: commit-archive into T570: When edit level is not at the top, commit-archive only backups configuration for the current level and not the entire config.
Oct 28 2018, 2:35 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc5)
syncer merged task T934: commit-archive into T570: When edit level is not at the top, commit-archive only backups configuration for the current level and not the entire config.
Oct 28 2018, 2:34 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc5)
dmbaturin closed T570: When edit level is not at the top, commit-archive only backups configuration for the current level and not the entire config as Resolved.
Oct 28 2018, 2:31 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc5)
dmbaturin renamed T570: When edit level is not at the top, commit-archive only backups configuration for the current level and not the entire config from configuration backup on commit: only current level backing up to When edit level is not at the top, commit-archive only backups configuration for the current level and not the entire config.
Oct 28 2018, 2:30 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc5)
dmbaturin added a comment to T570: When edit level is not at the top, commit-archive only backups configuration for the current level and not the entire config.

By default cli-shell-api showCfg is level-aware, and the script indeed did not use the option for supressing it.

Oct 28 2018, 2:29 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc5)
syncer triaged T944: BGP config script removes neighbor policies before deactivating the neighbor, which may cause routing table leaks as Normal priority.
Oct 28 2018, 2:14 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc6)
syncer changed the status of T944: BGP config script removes neighbor policies before deactivating the neighbor, which may cause routing table leaks from Open to In progress.
Oct 28 2018, 2:14 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc6)
syncer added a project to T931: Syntax error in "monitor traffic interface filter": VyOS-1.2.0-GA.
Oct 28 2018, 1:32 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc5)
dmbaturin closed T931: Syntax error in "monitor traffic interface filter" as Resolved.

Indeed, the original script only took the first word, rather than all words after "filter".

Oct 28 2018, 1:31 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc5)
dmbaturin created T944: BGP config script removes neighbor policies before deactivating the neighbor, which may cause routing table leaks.
Oct 28 2018, 12:59 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc6)
syncer assigned T458: Disabling the in-memory table plugin has no effect to hagbard.
Oct 28 2018, 8:46 AM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc8)
syncer assigned T943: Wireguard interfaces gone after reboot to hagbard.
Oct 28 2018, 8:45 AM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc6)

Oct 27 2018

cohn added a comment to T458: Disabling the in-memory table plugin has no effect.

Tested on the latest 1.2.0-rc4 and it appears that the memory plugin is still enabled.

Oct 27 2018, 11:57 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc8)
tmartinson closed T203: Protocol Template Issues as Resolved.

Verified on VyOS 1.2.0-rc4 as working correctly.

Oct 27 2018, 11:17 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc4)
hagbard added a comment to T240: system integrity check.

So that's what I have right now for checking the packages, if they are newer than the image build time, it would spit out the below:

Oct 27 2018, 8:08 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc6)
syncer added a comment to T936: re-implementaion for 'show tech-support'.

@hagbardI like the idea to have it modular,
we also need to add profiling option (collecting system metrics over some period of time)
and maybe some more stuff (specific to functionality like ipsec, bgp, firewall, etc)

Oct 27 2018, 3:22 PM · VyOS 1.3 Equuleus
syncer added a subtask for T936: re-implementaion for 'show tech-support': T240: system integrity check.
Oct 27 2018, 3:20 PM · VyOS 1.3 Equuleus
syncer added a parent task for T240: system integrity check: T936: re-implementaion for 'show tech-support'.
Oct 27 2018, 3:20 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc6)
syncer removed a parent task for T936: re-implementaion for 'show tech-support': T240: system integrity check.
Oct 27 2018, 3:20 PM · VyOS 1.3 Equuleus
syncer removed a subtask for T240: system integrity check: T936: re-implementaion for 'show tech-support'.
Oct 27 2018, 3:20 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc6)