<feed xmlns='http://www.w3.org/2005/Atom'>
<title>vyos-1x.git/smoketest, branch rolling</title>
<subtitle>VyOS command definitions, scripts, and utilities (mirror of https://github.com/vyos/vyos-1x.git)
</subtitle>
<id>https://git.amelek.net/vyos/vyos-1x.git/atom?h=rolling</id>
<link rel='self' href='https://git.amelek.net/vyos/vyos-1x.git/atom?h=rolling'/>
<link rel='alternate' type='text/html' href='https://git.amelek.net/vyos/vyos-1x.git/'/>
<updated>2026-08-11T18:02:14+00:00</updated>
<entry>
<title>Merge pull request #5388 from c-po/remove-acme-autocert</title>
<updated>2026-08-11T18:02:14+00:00</updated>
<author>
<name>Christian Breunig</name>
<email>christian@breunig.cc</email>
</author>
<published>2026-08-11T18:02:14+00:00</published>
<link rel='alternate' type='text/html' href='https://git.amelek.net/vyos/vyos-1x.git/commit/?id=625d03bfcb12f4b2971590f6b0266c6c37d2f12b'/>
<id>urn:sha1:625d03bfcb12f4b2971590f6b0266c6c37d2f12b</id>
<content type='text'>
pki: T9135: derive ACME certificate chains from disk</content>
</entry>
<entry>
<title>Merge pull request #5365 from l0crian1/last-used</title>
<updated>2026-08-11T15:53:51+00:00</updated>
<author>
<name>John Estabrook</name>
<email>jestabro@vyos.io</email>
</author>
<published>2026-08-11T15:53:51+00:00</published>
<link rel='alternate' type='text/html' href='https://git.amelek.net/vyos/vyos-1x.git/commit/?id=7767004a4d2368dd7f9c6b3876f312944a4ce862'/>
<id>urn:sha1:7767004a4d2368dd7f9c6b3876f312944a4ce862</id>
<content type='text'>
firewall: T8221: Add last-used option to firewall rules</content>
</entry>
<entry>
<title>Merge pull request #5363 from natali-rs1985/T9134</title>
<updated>2026-08-11T07:22:11+00:00</updated>
<author>
<name>Kyrylo Yatsenko</name>
<email>hedrok@gmail.com</email>
</author>
<published>2026-08-11T07:22:11+00:00</published>
<link rel='alternate' type='text/html' href='https://git.amelek.net/vyos/vyos-1x.git/commit/?id=dadeaf21e70712ecd617ddd4850bc8e9f599a973'/>
<id>urn:sha1:dadeaf21e70712ecd617ddd4850bc8e9f599a973</id>
<content type='text'>
qos: T9134: Fix commit crash when classes match different protocols</content>
</entry>
<entry>
<title>smoketest: T9135: clear load-balancing haproxy in PKI testcase</title>
<updated>2026-08-10T19:04:07+00:00</updated>
<author>
<name>Christian Breunig</name>
<email>christian@breunig.cc</email>
</author>
<published>2026-08-09T18:12:53+00:00</published>
<link rel='alternate' type='text/html' href='https://git.amelek.net/vyos/vyos-1x.git/commit/?id=e0d7cd46336f104869fb73001f010a59f2b70b04'/>
<id>urn:sha1:e0d7cd46336f104869fb73001f010a59f2b70b04</id>
<content type='text'>
The PKI testsuite's setUpClass() already clears out pki and service https so
it can run on a live system, but left an existing load-balancing haproxy
configuration in place, which could reference certificates the tests then
delete out from under it.
</content>
</entry>
<entry>
<title>Merge pull request #5384 from c-po/container-fix</title>
<updated>2026-08-10T13:43:08+00:00</updated>
<author>
<name>John Estabrook</name>
<email>jestabro@vyos.io</email>
</author>
<published>2026-08-10T13:43:08+00:00</published>
<link rel='alternate' type='text/html' href='https://git.amelek.net/vyos/vyos-1x.git/commit/?id=b361f499edbca79703157b943201547b52f0e453'/>
<id>urn:sha1:b361f499edbca79703157b943201547b52f0e453</id>
<content type='text'>
container: T7736: fix smoketest failures caused by netavark/aardvark-dns IPv6 DAD race</content>
</entry>
<entry>
<title>Merge pull request #5347 from statio/T9122-flow-accounting-netflow-vrf</title>
<updated>2026-08-08T16:46:36+00:00</updated>
<author>
<name>Kyrylo Yatsenko</name>
<email>hedrok@gmail.com</email>
</author>
<published>2026-08-08T16:46:36+00:00</published>
<link rel='alternate' type='text/html' href='https://git.amelek.net/vyos/vyos-1x.git/commit/?id=f6a1ff94f02282bd018b9b49ae1a9812619ec7ba'/>
<id>urn:sha1:f6a1ff94f02282bd018b9b49ae1a9812619ec7ba</id>
<content type='text'>
flow-accounting: T9122: bind NetFlow export to the configured VRF</content>
</entry>
<entry>
<title>smoketest: T7736: use default route with distance 230 for container test</title>
<updated>2026-08-07T21:17:32+00:00</updated>
<author>
<name>Christian Breunig</name>
<email>christian@breunig.cc</email>
</author>
<published>2026-08-07T21:04:22+00:00</published>
<link rel='alternate' type='text/html' href='https://git.amelek.net/vyos/vyos-1x.git/commit/?id=7f9853b2a2778e79ba60a8e294c84ad4f00eb172'/>
<id>urn:sha1:7f9853b2a2778e79ba60a8e294c84ad4f00eb172</id>
<content type='text'>
On a live system, prevent that the smoketest default route overwrites
any other dynamically learned route by defining a higher distance.
</content>
</entry>
<entry>
<title>smoketest: T7736: remove saved config snapshot once a test completes</title>
<updated>2026-08-07T21:17:32+00:00</updated>
<author>
<name>Christian Breunig</name>
<email>christian@breunig.cc</email>
</author>
<published>2026-08-07T21:00:09+00:00</published>
<link rel='alternate' type='text/html' href='https://git.amelek.net/vyos/vyos-1x.git/commit/?id=ccb9703ef5c382199c823428b90a458cd6ab7027'/>
<id>urn:sha1:ccb9703ef5c382199c823428b90a458cd6ab7027</id>
<content type='text'>
VyOSUnitTestSHIM.tearDownClass() restores the pre-test configuration from
/tmp/vyos-smoketest-save but never removed the file afterwards. Since it
is a fixed, shared path, whichever user ran a smoketest last ends up
owning it with no group/other write permission - the next user to run
any smoketest on the same box gets a hard "Permission denied" writing to
that path, even though nothing else is actually wrong.
</content>
</entry>
<entry>
<title>container: T7736: disable IPv6 DAD for netavark bridges to fix aardvark-dns race</title>
<updated>2026-08-07T21:17:28+00:00</updated>
<author>
<name>Christian Breunig</name>
<email>christian@breunig.cc</email>
</author>
<published>2026-08-07T20:59:54+00:00</published>
<link rel='alternate' type='text/html' href='https://git.amelek.net/vyos/vyos-1x.git/commit/?id=dabeff277774190d047155be6566da184b2b3e8f'/>
<id>urn:sha1:dabeff277774190d047155be6566da184b2b3e8f</id>
<content type='text'>
netavark assigns the IPv6 gateway address to a container "pod-*" bridge
and immediately invokes aardvark-dns to bind its DNS listener to it. While
the address is "tentative" during Duplicate Address Detection, that bind()
fails with EADDRNOTAVAIL and container startup fails for any IPv6-enabled
network.

The kernel only skips DAD for an address if both "all" and the specific
interface's own accept_dad are disabled at the moment the interface is
created. A per-interface override is always either too late for a network's
first-ever container - as the network can only be created in-time and not
explicitly before starting the first container.
</content>
</entry>
<entry>
<title>Merge pull request #5305 from natali-rs1985/T8996</title>
<updated>2026-08-06T15:33:27+00:00</updated>
<author>
<name>Daniil Baturin</name>
<email>daniil@vyos.io</email>
</author>
<published>2026-08-06T15:33:27+00:00</published>
<link rel='alternate' type='text/html' href='https://git.amelek.net/vyos/vyos-1x.git/commit/?id=278fba204200f02bb461f786f889b40dc38a26f6'/>
<id>urn:sha1:278fba204200f02bb461f786f889b40dc38a26f6</id>
<content type='text'>
qos: T8996: Implement set-dscp packet remarking for shaper policy</content>
</entry>
</feed>
