<feed xmlns='http://www.w3.org/2005/Atom'>
<title>vyos-1x.git/src/etc/dhcp, branch fix/T8955-http-api-verify-tls</title>
<subtitle>VyOS command definitions, scripts, and utilities (mirror of https://github.com/vyos/vyos-1x.git)
</subtitle>
<id>https://git.amelek.net/vyos/vyos-1x.git/atom?h=fix%2FT8955-http-api-verify-tls</id>
<link rel='self' href='https://git.amelek.net/vyos/vyos-1x.git/atom?h=fix%2FT8955-http-api-verify-tls'/>
<link rel='alternate' type='text/html' href='https://git.amelek.net/vyos/vyos-1x.git/'/>
<updated>2026-09-06T14:16:37+00:00</updated>
<entry>
<title>dhcp: T9278: do not append the VRF option twice to ip route commands</title>
<updated>2026-09-06T14:16:37+00:00</updated>
<author>
<name>Christian Breunig</name>
<email>christian@breunig.cc</email>
</author>
<published>2026-09-06T14:16:37+00:00</published>
<link rel='alternate' type='text/html' href='https://git.amelek.net/vyos/vyos-1x.git/commit/?id=599ebc0e23ec8f4415a6192d34d562cb663e4174'/>
<id>urn:sha1:599ebc0e23ec8f4415a6192d34d562cb663e4174</id>
<content type='text'>
01-vyos-cleanup builds its route deletion with an explicit "vrf &lt;name&gt;". The ip()
wrapper caught that command and delroute() appended $VRF_OPTION again, so both
"ip route show" and "ip route del" ran with "vrf red vrf red". The FRR-down
kernel fallback had the same flaw.

Add vrf_option(), yielding $VRF_OPTION only when the arguments carry no "vrf"
token, and use it in both places. The append cannot simply be dropped, as
delroute() is also reached without a VRF. iptovtysh() parses single fields and
was never affected.
</content>
</entry>
<entry>
<title>dhcp: T9278: move DHCP client hook tracing to a gated debug level</title>
<updated>2026-09-06T14:16:37+00:00</updated>
<author>
<name>Christian Breunig</name>
<email>christian@breunig.cc</email>
</author>
<published>2026-09-06T14:16:37+00:00</published>
<link rel='alternate' type='text/html' href='https://git.amelek.net/vyos/vyos-1x.git/commit/?id=3fc7b6e052402dba9bf13bbff54ff6d99a87fd8e'/>
<id>urn:sha1:3fc7b6e052402dba9bf13bbff54ff6d99a87fd8e</id>
<content type='text'>
Each lease event emitted some fifteen daemon.info lines tracing internal steps
rather than recording a change. Add a "debug" level to logmsg(), silenced unless
/tmp/vyos.dhclient.debug exists, following the flag file convention used for FRR
and ifconfig. Demoting alone would not help, as journald shows all priorities by
default. Fifteen tracing messages move to debug; the sixteen recording an actual
change stay at info.

Also fix logmsg(): "warn" had no case arm although it is used, and the global
LOG_PRIO leaked the preceding call's priority. It is now local.
</content>
</entry>
<entry>
<title>static: T9278: reconcile FRR config after every DHCP lease event</title>
<updated>2026-09-04T20:14:45+00:00</updated>
<author>
<name>Christian Breunig</name>
<email>christian@breunig.cc</email>
</author>
<published>2026-09-04T20:14:45+00:00</published>
<link rel='alternate' type='text/html' href='https://git.amelek.net/vyos/vyos-1x.git/commit/?id=9a7d5b27cd908473b7cd9e16fc0d1bbe7e983d2e'/>
<id>urn:sha1:9a7d5b27cd908473b7cd9e16fc0d1bbe7e983d2e</id>
<content type='text'>
The default route derived from "interfaces &lt;type&gt; &lt;ifname&gt; address dhcp" is
rendered from the DHCP lease file, so it is only known at lease time. Until now
the sole runtime path into staticd was the one-shot vtysh injection in
dhclient-enter-hooks.d/03-vyos-ipwrapper. That injection races the FRR reload of
the very commit which started the DHCP client: dhclient runs with "-nw", thus the
commit does not wait for a lease, and when BOUND arrives mid-reload frr_alive()
can report FRR as down. The route is then installed into the kernel only and FRR
never learns about it. Nothing recovers afterwards, as FRRender.generate()
short-circuits on an unchanged configuration dict.

The self-healing re-render used by "protocols static route &lt;prefix&gt;
dhcp-interface" was gated on /tmp/static_dhcp_interfaces, which never lists plain
"address dhcp" interfaces - protocols_static.py does not even run on an
interface-only commit, as no config-mode dependency points to it.

Derive the DHCP dependent interface list from the configuration dict itself, both
for the default VRF and for every named VRF, and use it for FRR change
detection. Drop the interface list gate in the dhclient exit hook so any lease
event requests a re-render.

Also poll for the lease and for the rendered route in the affected smoketests
instead of relying on a fixed sleep.
</content>
</entry>
<entry>
<title>T8410: Fix typos and mistakes for comments and messages</title>
<updated>2026-03-27T15:00:17+00:00</updated>
<author>
<name>Viacheslav Hletenko</name>
<email>v.gletenko@vyos.io</email>
</author>
<published>2026-03-27T14:43:47+00:00</published>
<link rel='alternate' type='text/html' href='https://git.amelek.net/vyos/vyos-1x.git/commit/?id=139b0841f8242a5c6ebdafb37380c1fb78342aae'/>
<id>urn:sha1:139b0841f8242a5c6ebdafb37380c1fb78342aae</id>
<content type='text'>
Fix typos and mistakes
No functional changes
</content>
</entry>
<entry>
<title>T8188: Preserve static IPv4 addresses flushed by dhclient</title>
<updated>2026-03-19T16:07:08+00:00</updated>
<author>
<name>Nataliia Solomko</name>
<email>natalirs1985@gmail.com</email>
</author>
<published>2026-02-04T12:55:34+00:00</published>
<link rel='alternate' type='text/html' href='https://git.amelek.net/vyos/vyos-1x.git/commit/?id=2a6a63391173e8cef9354a696e188e90f43def74'/>
<id>urn:sha1:2a6a63391173e8cef9354a696e188e90f43def74</id>
<content type='text'>
When dhclient renews/rebinds a lease, it calls "ip -4 addr flush dev
&lt;interface&gt;". This removes ALL IPv4 addresses, including static
addresses configured via VyOS (e.g., "set interfaces ethernet eth0
address 192.168.1.1/24").
The updated hook logic now intercepts the "ip -4 addr flush" command and replaces
it with a selective flush that only removes addresses marked as
"dynamic" by the kernel. DHCP-assigned addresses have the "dynamic" flag
set automatically.
</content>
</entry>
<entry>
<title>T5811: Make static dhcp-interface routes robust</title>
<updated>2025-10-21T16:57:40+00:00</updated>
<author>
<name>Kyrylo Yatsenko</name>
<email>hedrok@gmail.com</email>
</author>
<published>2025-10-17T10:58:01+00:00</published>
<link rel='alternate' type='text/html' href='https://git.amelek.net/vyos/vyos-1x.git/commit/?id=c4632bb6ad6c055fb7fe5a5c055354c6895ba8e5'/>
<id>urn:sha1:c4632bb6ad6c055fb7fe5a5c055354c6895ba8e5</id>
<content type='text'>
Solves the problem that vyos-configs in FRRender caches configuation and
DHCP changes are ignored.

* Add src/helpers/vyos-request-configd-update.py that requests vyos-configd
  to update FRR configuration.
* Make dhclient hooks use it instead of calling protocols_static.py
* Make FRRender cache not only configuration but also DHCP gateways so
  that is any of them changes, FRR configuration is updated
</content>
</entry>
<entry>
<title>T3680: protocols: add dhclient hooks for dhcp-interface static routes</title>
<updated>2025-10-21T16:57:40+00:00</updated>
<author>
<name>Matthew Kobayashi</name>
<email>matthew@kobayashi.au</email>
</author>
<published>2025-10-02T03:15:03+00:00</published>
<link rel='alternate' type='text/html' href='https://git.amelek.net/vyos/vyos-1x.git/commit/?id=70b7818f75f55de14214b85a12b8ec13d98ff89b'/>
<id>urn:sha1:70b7818f75f55de14214b85a12b8ec13d98ff89b</id>
<content type='text'>
</content>
</entry>
<entry>
<title>T7941: fix DHCP client running in VRF with non-word characters</title>
<updated>2025-10-18T11:19:10+00:00</updated>
<author>
<name>Christian Breunig</name>
<email>christian@breunig.cc</email>
</author>
<published>2025-10-18T11:14:54+00:00</published>
<link rel='alternate' type='text/html' href='https://git.amelek.net/vyos/vyos-1x.git/commit/?id=6a5cd3b87b2dee397ddb4a72dffd25e4e24122f1'/>
<id>urn:sha1:6a5cd3b87b2dee397ddb4a72dffd25e4e24122f1</id>
<content type='text'>
The previous implementation used awk with a regex to extract the VRF name from
JSON data, relying on "(\w+)" to match the value. This broke for valid VRF
names containing hyphens or other non-word characters.

This update replaces the regex-based extraction with a jq query that reliably
parses the JSON structure, ensuring correct behavior regardless of VRF name
format. This also reduces parsing fragility by using a tool purpose-built for
JSON processing.
</content>
</entry>
<entry>
<title>T7591: remove copyright years from source files</title>
<updated>2025-06-28T21:16:52+00:00</updated>
<author>
<name>Christian Breunig</name>
<email>christian@breunig.cc</email>
</author>
<published>2025-06-28T18:51:21+00:00</published>
<link rel='alternate' type='text/html' href='https://git.amelek.net/vyos/vyos-1x.git/commit/?id=1478516ae437f19ebeb7d6ff9b83dd74f8e76758'/>
<id>urn:sha1:1478516ae437f19ebeb7d6ff9b83dd74f8e76758</id>
<content type='text'>
The legal team says years are not necessary so we can go ahead with it, since
it will simplify backporting.

Automatically removed using: git ls-files | grep -v libvyosconfig | xargs sed -i -E \
's/^# Copyright (19|20)[0-9]{2}(-[0-9]{4})? VyOS maintainers.*/# Copyright VyOS maintainers and contributors &lt;maintainers@vyos.io&gt;/g'

In addition we will error-out during "make" if someone re-adds a legacy
copyright notice
</content>
</entry>
<entry>
<title>dhclient: T6253: Respect `no-default-route`</title>
<updated>2025-04-22T02:20:30+00:00</updated>
<author>
<name>Matthew Kobayashi</name>
<email>matthew@kobayashi.au</email>
</author>
<published>2025-04-22T02:06:04+00:00</published>
<link rel='alternate' type='text/html' href='https://git.amelek.net/vyos/vyos-1x.git/commit/?id=2ff0981bfe1231fc430507b4b5f8031c05005db1'/>
<id>urn:sha1:2ff0981bfe1231fc430507b4b5f8031c05005db1</id>
<content type='text'>
</content>
</entry>
</feed>
