Page MenuHomePhabricator

VyOS 1.2 Crux ( VyOS 1.2.0-EPA)Milestone
ArchivedPublic

Members

  • This project does not have any members.

Watchers

  • This project does not have any watchers.

Details

Description

Early Production Access

Recent Activity

Jun 16 2019

c-po closed T1189: [Security Advisory] PowerDNS Recursor 4.1.9 Released as Resolved.
Jun 16 2019, 6:39 PM · VyOS 1.2 Crux ( VyOS 1.2.0-EPA)
c-po added a comment to T1189: [Security Advisory] PowerDNS Recursor 4.1.9 Released.

VyOS 1.2.1 ships PowerDNS 4.1.12

Jun 16 2019, 6:38 PM · VyOS 1.2 Crux ( VyOS 1.2.0-EPA)
c-po moved T1189: [Security Advisory] PowerDNS Recursor 4.1.9 Released from Needs Triage to Finished on the VyOS 1.2 Crux ( VyOS 1.2.0-EPA) board.
Jun 16 2019, 6:38 PM · VyOS 1.2 Crux ( VyOS 1.2.0-EPA)
c-po added a comment to T1189: [Security Advisory] PowerDNS Recursor 4.1.9 Released.

@jjakob yes. Each ISO always ships the latest available PowerDNS version that is released and available via https://repo.powerdns.com/

Jun 16 2019, 6:38 PM · VyOS 1.2 Crux ( VyOS 1.2.0-EPA)
jjakob added a comment to T1189: [Security Advisory] PowerDNS Recursor 4.1.9 Released.

vyos 1.2.0-rolling+201906161308 has pdns_recursor 4.1.14, should this be marked as fixed?

Jun 16 2019, 5:33 PM · VyOS 1.2 Crux ( VyOS 1.2.0-EPA)

Mar 3 2019

rherold closed T1278: Can't configure soft-reconfiguration inbound in bgp as Resolved.

Sorry found it.

Mar 3 2019, 9:46 PM · VyOS 1.2 Crux ( VyOS 1.2.0-EPA)
rherold created T1278: Can't configure soft-reconfiguration inbound in bgp in the S1 VyOS Public space.
Mar 3 2019, 9:40 PM · VyOS 1.2 Crux ( VyOS 1.2.0-EPA)

Feb 26 2019

rherold added a comment to T1266: Put management traffic in separate routing table .

Would it be possible to add an option to bind an specific interface to an routing table?
I have tested the scenario above and create only the routing table via protocol static.
After this I manual add:

Feb 26 2019, 2:48 PM · VyOS 1.2 Crux ( VyOS 1.2.0-EPA)
rherold changed Version from 1.2 to 1.2.0 on T1266: Put management traffic in separate routing table .
Feb 26 2019, 2:27 PM · VyOS 1.2 Crux ( VyOS 1.2.0-EPA)

Feb 24 2019

rherold added a comment to T1266: Put management traffic in separate routing table .

I added a log rule to:

Feb 24 2019, 12:41 PM · VyOS 1.2 Crux ( VyOS 1.2.0-EPA)
rherold added a comment to T1266: Put management traffic in separate routing table .

why do we use fwmark in this case? As far as I can see ip rule give us all needed selectors:

Feb 24 2019, 10:11 AM · VyOS 1.2 Crux ( VyOS 1.2.0-EPA)
rherold updated the task description for T1266: Put management traffic in separate routing table .
Feb 24 2019, 9:57 AM · VyOS 1.2 Crux ( VyOS 1.2.0-EPA)
rherold created T1266: Put management traffic in separate routing table in the S1 VyOS Public space.
Feb 24 2019, 9:44 AM · VyOS 1.2 Crux ( VyOS 1.2.0-EPA)

Jan 21 2019

rherold created T1189: [Security Advisory] PowerDNS Recursor 4.1.9 Released.
Jan 21 2019, 2:01 PM · VyOS 1.2 Crux ( VyOS 1.2.0-EPA)

Jan 12 2019

syncer archived VyOS 1.2 Crux ( VyOS 1.2.0-EPA).
Jan 12 2019, 6:30 PM

Jan 11 2019

rherold added a comment to T1170: Frr Bgp DOS.

@syncer thats not true:

Jan 11 2019, 5:40 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-EPA3)
syncer added a comment to T1170: Frr Bgp DOS.

it can be some other issue though
will appreciate if it's possible to get procedure how to reproduce and we happy to work with frr devs to address that

Jan 11 2019, 3:59 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-EPA3)
danhusan added a comment to T1170: Frr Bgp DOS.

That seems odd, my global peerings all reset at the time of the test. @mariusno and @rherold did you experience something similar?

Jan 11 2019, 3:46 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-EPA3)
syncer closed T1170: Frr Bgp DOS as Resolved.

VyOS is not affected by this issue
https://vulmon.com/vulnerabilitydetails?qid=CVE-2019-5892
as it requires FRR build with certain options which we not use

Jan 11 2019, 3:19 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-EPA3)
danhusan added a comment to T1170: Frr Bgp DOS.
The FRR devs have released binary packages including the fix and
announced it on the FRR mailing lists.  After considering the feedback
on the list and discussing with FRR devs, we will postpone the
experiments until Jan. 23rd, and have updated the schedule to reflect
the delayed start and shorter timeline [A].  We will follow up with
FRR devs and mailing lists/users.
Jan 11 2019, 2:55 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-EPA3)

Jan 10 2019

dt-iland edited projects for T1172: vyatta_update_sysctl.pl does not support options that have multiple values, added: vyatta-cfg-system, VyOS 1.2 Crux ( VyOS 1.2.0-EPA), Community; removed VyOS 1.2 Crux.
Jan 10 2019, 8:21 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-GA)

Jan 8 2019

rherold triaged T1170: Frr Bgp DOS as Unbreak Now! priority.

Please unbreak now. The next test date was announced!!

Jan 8 2019, 8:57 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-EPA3)
danhusan added a comment to T1170: Frr Bgp DOS.
We plan to resume the experiments January 16th (next Wednesday), and
have updated the experiment schedule [A] accordingly.  As always, we
welcome your feedback.
Jan 8 2019, 7:58 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-EPA3)
danhusan added a comment to T1170: Frr Bgp DOS.

Wow, this explains why all my sessions dropped yesterday.

Jan 8 2019, 7:54 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-EPA3)
rherold created T1170: Frr Bgp DOS in the S1 VyOS Public space.
Jan 8 2019, 7:47 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-EPA3)

Jan 6 2019

rherold created T1164: show configuration files Permission denied in the S1 VyOS Public space.
Jan 6 2019, 9:56 PM · Rejected
rherold created T1163: Powerdns Recursor out of date and CVE-2018-10851 in the S1 VyOS Public space.
Jan 6 2019, 9:13 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-EPA3)

Jan 5 2019

hagbard closed T1152: VyOS inside virtualbox for testing as Invalid.
Jan 5 2019, 12:19 AM · Rejected

Jan 4 2019

rherold created T1155: VyOS don't install on USB Stick in the S1 VyOS Public space.
Jan 4 2019, 6:32 PM · VyOS 1.3 Equuleus
rherold added a comment to T1152: VyOS inside virtualbox for testing .

Thx for the feedback indeed it runs much better with the virtio-net driver. Bit the e1000 is the default if you choose Debian as OS in Virtualbox.
VyOS is not available in Virtualbox as OS Template. I think we should try to get an own template with nice defaults into Virtualbox. Should I open a case
in Virtualbox for it? Do we have a list of settings that would be optimal for an VyOS vm?

Jan 4 2019, 10:06 AM · Rejected

Jan 3 2019

hagbard claimed T1152: VyOS inside virtualbox for testing .

Hi @rherold , these messages are verbose debug messages, change to virtio-net or to a different emulated driver to have them disappear. In general I recommend to use the virtio one which has a better performance too compared to emulated ones, plus less complex code. (https://github.com/MorteNoir1/virtualbox_e1000_0day)

Jan 3 2019, 5:52 PM · Rejected
rherold created T1152: VyOS inside virtualbox for testing .
Jan 3 2019, 4:15 PM · Rejected

Jan 1 2019

syncer moved T875: Kernel config cleanup from Needs Triage to Finished on the VyOS 1.2 Crux ( VyOS 1.2.0-EPA) board.
Jan 1 2019, 6:12 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux ( VyOS 1.2.0-EPA)

Dec 31 2018

c-po added a comment to T1120: rc11 raid-1 array wont come up on boot.

I propose to proceed with a global change. Special case handling is always harder to test and the impact is only 5 seconds max in startup time - who cares on a 24/7 active device which is rarely rebootet?

Dec 31 2018, 5:24 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-EPA3)
danhusan added a comment to T1120: rc11 raid-1 array wont come up on boot.
In T1120#29573, @c-po wrote:

instead of differentiating between raid and non raid installations - why not always wait 5 seconds for the discs to settle? As this is only done once on startup this is IMHO better then a special case.

Dec 31 2018, 2:06 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-EPA3)
c-po added a comment to T1120: rc11 raid-1 array wont come up on boot.

instead of differentiating between raid and non raid installations - why not always wait 5 seconds for the discs to settle? As this is only done once on startup this is IMHO better then a special case.

Dec 31 2018, 1:51 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-EPA3)
dmbaturin added a comment to T1128: SNMP hostname not changed after commit.

I've added SNMP restart on hostname change, it will be in the next nightly build.

Dec 31 2018, 12:42 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-EPA2)
dmbaturin added a comment to T1112: BGP redistribute static not migrated on upgrade.

Hey @Merijn, sorry for late reply and thanks for the patch! I've merged it in and it will be in the next nightly build.

Dec 31 2018, 11:42 AM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-EPA3)
danhusan added a comment to T1120: rc11 raid-1 array wont come up on boot.

https://github.com/vyos/vyatta-cfg-system/pull/97

Dec 31 2018, 10:58 AM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-EPA3)
dmbaturin renamed T1108: "show vpn ipsec sa" fails with exception when there are no established SAs from show vpn ipsec sa - corrupted output in 1.2.0-rc10 to "show vpn ipsec sa" fails with exception when there are no established SAs.
Dec 31 2018, 10:55 AM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-EPA2)
dmbaturin closed T1108: "show vpn ipsec sa" fails with exception when there are no established SAs as Resolved.

I've changed it to handle the situation gracefully. Actual display of connecting SAs is another story of course... The fix will be in the next nightly build.

Dec 31 2018, 10:54 AM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-EPA2)

Dec 30 2018

Barrysdca added a comment to T1026: Removing tunnel deletes all tunnels?.

tested with most recent rolling version. problem still persists but it's not throwing errors.

Dec 30 2018, 5:03 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-EPA3)

Dec 29 2018

hagbard changed the status of T1131: open-vm-tools causing 100% CPU load from Open to In progress.
Dec 29 2018, 7:09 PM · VyOS 1.2 Crux (VyOS 1.2.2), VyOS 1.3 Equuleus
hagbard added a comment to T1131: open-vm-tools causing 100% CPU load.

Thanks for testing that guys.

Dec 29 2018, 6:25 PM · VyOS 1.2 Crux (VyOS 1.2.2), VyOS 1.3 Equuleus

Dec 28 2018

danhusan added a comment to T1131: open-vm-tools causing 100% CPU load.

And FYI max-ipv6-routes=10 and max-ipv4-routes=10 doesn't seem to help either.

Dec 28 2018, 7:27 PM · VyOS 1.2 Crux (VyOS 1.2.2), VyOS 1.3 Equuleus
danhusan added a comment to T1131: open-vm-tools causing 100% CPU load.

Hi @danhusan, did you ever try another poll value, like 3 secs or 5 or anything like that? If set to 0, the host system won't show you any updated meta data, like if you change the ip address etc.
(https://github.com/vmware/open-vm-tools/blob/master/open-vm-tools/services/plugins/guestInfo/guestInfoServer.c#L1662)
I'm therefore not entirely sure if that should be treated as a special case scenario (we could publish a kb if you run into that condition), or if it is a general issue since you 2 were the only ones experience that issue as far as I know.
I'm also not sure it only is triggered by your situation (full bgp table) or if it can happen on other occasions as well, if you came across more issues regarding that value, please let me know.

Dec 28 2018, 7:19 PM · VyOS 1.2 Crux (VyOS 1.2.2), VyOS 1.3 Equuleus
hagbard added a comment to T1131: open-vm-tools causing 100% CPU load.

@MrXermon , yes that sounds reasonable. I found in the code that they limit it to 100 routes, can you please try the following:
(https://github.com/vmware/open-vm-tools/blob/master/open-vm-tools/lib/include/conf.h#L138)

Dec 28 2018, 7:00 PM · VyOS 1.2 Crux (VyOS 1.2.2), VyOS 1.3 Equuleus
MrXermon added a comment to T1131: open-vm-tools causing 100% CPU load.

Hi @hagbard,
i played with different values and in my case (full table IPv6 router) the error continues during the following values:
3s, 5s, 10s, 20s, 30s
At 60s the CPU load starts to cycle between >30s full load, than it drops for a few seconds and raises again.

Dec 28 2018, 6:24 PM · VyOS 1.2 Crux (VyOS 1.2.2), VyOS 1.3 Equuleus
hagbard added a comment to T1026: Removing tunnel deletes all tunnels?.

Hi @Barrysdca did you have a chance to test again?

Dec 28 2018, 6:08 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-EPA3)
hagbard added a comment to T1131: open-vm-tools causing 100% CPU load.

Hi @danhusan, did you ever try another poll value, like 3 secs or 5 or anything like that? If set to 0, the host system won't show you any updated meta data, like if you change the ip address etc.
(https://github.com/vmware/open-vm-tools/blob/master/open-vm-tools/services/plugins/guestInfo/guestInfoServer.c#L1662)
I'm therefore not entirely sure if that should be treated as a special case scenario (we could publish a kb if you run into that condition), or if it is a general issue since you 2 were the only ones experience that issue as far as I know.
I'm also not sure it only is triggered by your situation (full bgp table) or if it can happen on other occasions as well, if you came across more issues regarding that value, please let me know.

Dec 28 2018, 6:07 PM · VyOS 1.2 Crux (VyOS 1.2.2), VyOS 1.3 Equuleus