Page MenuHomePhabricator

VyOS 1.2 CruxProject
ActivePublic

Milestones

Members

  • This project does not have any members.

Details

Description

Jessie based VyOS - Crux

Recent Activity

Yesterday

syncer assigned T1876: IPSec VTI tunnels are deleted after rekey and dangling around as A/D to Dmitry.
Sat, Dec 14, 6:30 PM · VyOS 1.3 Equuleus
c-po triaged T1876: IPSec VTI tunnels are deleted after rekey and dangling around as A/D as Unbreak Now! priority.
Sat, Dec 14, 1:55 PM · VyOS 1.3 Equuleus
c-po updated the task description for T1876: IPSec VTI tunnels are deleted after rekey and dangling around as A/D.
Sat, Dec 14, 1:55 PM · VyOS 1.3 Equuleus
c-po created T1876: IPSec VTI tunnels are deleted after rekey and dangling around as A/D.
Sat, Dec 14, 1:53 PM · VyOS 1.3 Equuleus

Fri, Dec 13

c-po added a comment to T1832: radvd adding feature DNSSL branch.example.com example.com to existing package.

tagNode has been renamed to dnssl

Fri, Dec 13, 5:02 PM · VyOS 1.2 Crux, VyOS 1.3 Equuleus
zsdc created T1875: Add the ability to use network address as BGP neighbor (bgp listen range).
Fri, Dec 13, 11:19 AM · VyOS 1.2 Crux

Thu, Dec 12

hagbard renamed T1872: Removing serial console port from ESXi VM causes flooded syslog from Removing serial console port from ESXi VM causes flodded syslog to Removing serial console port from ESXi VM causes flooded syslog.
Thu, Dec 12, 7:11 PM · VyOS 1.2 Crux
jjakob added a comment to T1872: Removing serial console port from ESXi VM causes flooded syslog.

I'm experiencing the same issue of the service failing to start on 1.3.
The installation was first started with the default config in a VM that had a serial port. Then the installation was transferred to a physical machine without a serial port, and the whole /config directory was manually copied from the old installation on that machine. The result were the same errors in syslog/journal.
I believe the issue is that if the config.boot is manually replaced or edited on disk, the script that would normally be triggered on commit when deleting system console is never triggered, thus the service remains enabled, but there is no system console in the config to delete any more.

Thu, Dec 12, 7:10 PM · VyOS 1.2 Crux
c-po updated the task description for T1872: Removing serial console port from ESXi VM causes flooded syslog.
Thu, Dec 12, 6:34 PM · VyOS 1.2 Crux
c-po created T1872: Removing serial console port from ESXi VM causes flooded syslog.
Thu, Dec 12, 6:31 PM · VyOS 1.2 Crux
c-po closed T1865: IPSec (IKEv2) connections to AZURE are dying as Invalid.
Thu, Dec 12, 11:33 AM · VyOS 1.2 Crux
c-po added a comment to T1865: IPSec (IKEv2) connections to AZURE are dying.

Problem was in the wrong IKEv2 definition, set vpn ipsec ike-group IKE-AZURE ikev2-reauth must be yes

Thu, Dec 12, 11:33 AM · VyOS 1.2 Crux

Wed, Dec 11

hagbard moved T1832: radvd adding feature DNSSL branch.example.com example.com to existing package from In Progress to Finished on the VyOS 1.3 Equuleus board.
Wed, Dec 11, 4:10 PM · VyOS 1.2 Crux, VyOS 1.3 Equuleus
hagbard changed the status of T1832: radvd adding feature DNSSL branch.example.com example.com to existing package from Needs testing to Backport candidate.
Wed, Dec 11, 4:10 PM · VyOS 1.2 Crux, VyOS 1.3 Equuleus
hagbard added a project to T1832: radvd adding feature DNSSL branch.example.com example.com to existing package: VyOS 1.2 Crux.
Wed, Dec 11, 4:09 PM · VyOS 1.2 Crux, VyOS 1.3 Equuleus
hagbard closed T1851: wireguard - changing the pubkey on an existing peer seems to destroy the running config. as Resolved.
Wed, Dec 11, 3:55 PM · VyOS 1.2 Crux
hagbard changed the status of T1851: wireguard - changing the pubkey on an existing peer seems to destroy the running config. from Needs testing to Backport pending.
Wed, Dec 11, 3:55 PM · VyOS 1.2 Crux
kroy updated subscribers of T1851: wireguard - changing the pubkey on an existing peer seems to destroy the running config..

T1846 fixes this

Wed, Dec 11, 5:30 AM · VyOS 1.2 Crux

Tue, Dec 10

hagbard added a comment to T1867: ISO 1.2.4-epa1 not having the latest changes.

Looks like the vyos-1x images was not rebuilt from the crux branch before the new image was built. I manually checked out the crux branch and the commit ins backported in there, rebuilt the packages manually and everything needed is in there and working.

Tue, Dec 10, 7:12 PM · VyOS 1.2 Crux
Raeven added a comment to T1867: ISO 1.2.4-epa1 not having the latest changes.

Link to the changelog https://phabricator.vyos.net/maniphest/query/Vx2T4niywHe4/#R

Tue, Dec 10, 6:54 PM · VyOS 1.2 Crux
Raeven created T1867: ISO 1.2.4-epa1 not having the latest changes.
Tue, Dec 10, 6:47 PM · VyOS 1.2 Crux
hagbard changed the status of T1853: wireguard - disable peer doesn't work , a subtask of T1851: wireguard - changing the pubkey on an existing peer seems to destroy the running config., from Needs testing to Backport candidate.
Tue, Dec 10, 5:57 PM · VyOS 1.2 Crux
hagbard changed the status of T1853: wireguard - disable peer doesn't work from Needs testing to Backport candidate.

tested with today rolling release. (https://downloads.vyos.io/rolling/current/amd64/vyos-1.2-rolling-201912100217-amd64.iso)

Tue, Dec 10, 5:57 PM · VyOS 1.3 Equuleus, VyOS 1.2 Crux
hagbard changed the status of T1851: wireguard - changing the pubkey on an existing peer seems to destroy the running config. from Open to Needs testing.

@kroy please test with the latest rolling if https://phabricator.vyos.net/T1846 solves your issue.

Tue, Dec 10, 5:38 PM · VyOS 1.2 Crux
elbuit changed Difficulty level from unknown to normal on T1836: import-conf-mode-commands in vyos-1x/scripts fails to create an xml.
Tue, Dec 10, 2:22 PM · VyOS 1.2 Crux (VyOS 1.2.4)
elbuit changed the status of T1836: import-conf-mode-commands in vyos-1x/scripts fails to create an xml from Open to In progress.
Tue, Dec 10, 2:21 PM · VyOS 1.2 Crux (VyOS 1.2.4)

Mon, Dec 9

jestabro added a parent task for T1851: wireguard - changing the pubkey on an existing peer seems to destroy the running config.: T1846: Make session_config not depend on the current edit level.
Mon, Dec 9, 7:55 PM · VyOS 1.2 Crux
kroy added a comment to T1851: wireguard - changing the pubkey on an existing peer seems to destroy the running config..

Related to T1844, which should correct the original problem in this ticket

Mon, Dec 9, 7:17 PM · VyOS 1.2 Crux
kroy added a comment to T1853: wireguard - disable peer doesn't work .
Mon, Dec 9, 6:57 PM · VyOS 1.3 Equuleus, VyOS 1.2 Crux

Sun, Dec 8

c-po updated the task description for T1865: IPSec (IKEv2) connections to AZURE are dying.
Sun, Dec 8, 12:17 PM · VyOS 1.2 Crux
c-po updated the task description for T1865: IPSec (IKEv2) connections to AZURE are dying.
Sun, Dec 8, 12:17 PM · VyOS 1.2 Crux
c-po created T1865: IPSec (IKEv2) connections to AZURE are dying.
Sun, Dec 8, 12:14 PM · VyOS 1.2 Crux
c-po changed the status of T1864: Lower IPSec DPD timeout lower limit from 10s -> 2s from Open to In progress.
Sun, Dec 8, 11:58 AM · VyOS 1.2 Crux (VyOS 1.2.5), VyOS 1.3 Equuleus
c-po created T1864: Lower IPSec DPD timeout lower limit from 10s -> 2s.
Sun, Dec 8, 11:58 AM · VyOS 1.2 Crux (VyOS 1.2.5), VyOS 1.3 Equuleus

Fri, Dec 6

c-po created T1857: strip-private pipe option does not handle IPv6 addresses on interfaces.
Fri, Dec 6, 4:39 PM · VyOS 1.2 Crux (VyOS 1.2.4)
Viacheslav added a comment to T1854: Dynamic DNS configuration cannot be deleted.

@zsdc Maybe Incorrect file location. "ddclient.pid"

Fri, Dec 6, 8:29 AM · VyOS 1.3 Equuleus
c-po changed Difficulty level from unknown to easy on T1856: Support configuring IPSec SA bytes.
Fri, Dec 6, 7:34 AM · VyOS 1.3 Equuleus
c-po created T1856: Support configuring IPSec SA bytes.
Fri, Dec 6, 7:34 AM · VyOS 1.3 Equuleus
kroy added a comment to T1851: wireguard - changing the pubkey on an existing peer seems to destroy the running config..

Okay, so this problem just got a LOT more bizarre.

Fri, Dec 6, 1:31 AM · VyOS 1.2 Crux

Thu, Dec 5

dmbaturin added a comment to T1826: Misleading message on "reboot at" command.

The runtime errors are fixed by the above commit.

Thu, Dec 5, 11:15 PM · VyOS 1.2 Crux
dmbaturin added a parent task for T1826: Misleading message on "reboot at" command: T1855: Clean up the reboot/poweroff CLI and script.
Thu, Dec 5, 11:09 PM · VyOS 1.2 Crux
dmbaturin renamed T1826: Misleading message on "reboot at" command from Missleading message on "reboot at" command to Misleading message on "reboot at" command.
Thu, Dec 5, 10:43 PM · VyOS 1.2 Crux
hagbard added a comment to T1851: wireguard - changing the pubkey on an existing peer seems to destroy the running config..

@kroy I can't really reproduce it if I disable the peer first when multiple peers are defined on the same wg interface.
Can you please do a touch /tmp/vyos.ifconfig.debug and then run your commands and post it here?
It will show you the commands execute for each step like:

vyos@wg01# set  interfaces wireguard wg0 peer wg02 disable 
[edit]
vyos@wg01# commit
[ interfaces wireguard wg0 ]
DEBUG/wg0    write '1420' > '/sys/class/net/wg0/mtu'
DEBUG/wg0    write 'wg0' > '/sys/class/net/wg0/ifalias'
DEBUG/wg0    cmd 'wg set wg0 peer G1aA2KkyFyC8xsCUeENvuIW8HC5yDxwi902nR20592Y= remove'
DEBUG/wg0    cmd 'wg set wg0 listen-port 12345 fwmark 0 private-key /config/auth/wireguard/default/private.key peer hbwJSCu6SGUKIReNhWxlDIFRNCl5L7PaUSYOo2BF+Rg=  preshared-key /dev/null  allowed-ips 10.100.100.3/32 endpoint 10.1.1.203:12345 persistent-keepalive 0'
DEBUG/wg0    cmd 'ip link set dev wg0 up'
Thu, Dec 5, 10:21 PM · VyOS 1.2 Crux
hagbard moved T1853: wireguard - disable peer doesn't work from Need Triage to Finished on the VyOS 1.3 Equuleus board.
Thu, Dec 5, 9:59 PM · VyOS 1.3 Equuleus, VyOS 1.2 Crux
hagbard changed the status of T1853: wireguard - disable peer doesn't work , a subtask of T1851: wireguard - changing the pubkey on an existing peer seems to destroy the running config., from In progress to Needs testing.
Thu, Dec 5, 9:59 PM · VyOS 1.2 Crux
hagbard changed the status of T1853: wireguard - disable peer doesn't work from In progress to Needs testing.

https://github.com/vyos/vyos-1x/commit/fde531d3791a3d71aa27f99244d7cbb3b3625bf0

Thu, Dec 5, 9:59 PM · VyOS 1.3 Equuleus, VyOS 1.2 Crux
hagbard triaged T1853: wireguard - disable peer doesn't work as Normal priority.
Thu, Dec 5, 9:04 PM · VyOS 1.3 Equuleus, VyOS 1.2 Crux
zsdc changed the status of T1854: Dynamic DNS configuration cannot be deleted from Open to Confirmed.
Thu, Dec 5, 7:41 PM · VyOS 1.3 Equuleus
zsdc created T1854: Dynamic DNS configuration cannot be deleted.
Thu, Dec 5, 7:41 PM · VyOS 1.3 Equuleus
hagbard changed the status of T1853: wireguard - disable peer doesn't work , a subtask of T1851: wireguard - changing the pubkey on an existing peer seems to destroy the running config., from Open to In progress.
Thu, Dec 5, 7:05 PM · VyOS 1.2 Crux