<feed xmlns='http://www.w3.org/2005/Atom'>
<title>vyos-1x.git/src/helpers, branch fix/T8955-http-api-verify-tls</title>
<subtitle>VyOS command definitions, scripts, and utilities (mirror of https://github.com/vyos/vyos-1x.git)
</subtitle>
<id>https://git.amelek.net/vyos/vyos-1x.git/atom?h=fix%2FT8955-http-api-verify-tls</id>
<link rel='self' href='https://git.amelek.net/vyos/vyos-1x.git/atom?h=fix%2FT8955-http-api-verify-tls'/>
<link rel='alternate' type='text/html' href='https://git.amelek.net/vyos/vyos-1x.git/'/>
<updated>2026-09-24T15:26:28+00:00</updated>
<entry>
<title>wwan: T9350: move session re-dial from cron into vyos-netlinkd</title>
<updated>2026-09-24T15:26:28+00:00</updated>
<author>
<name>Christian Breunig</name>
<email>christian@breunig.cc</email>
</author>
<published>2026-09-24T15:26:28+00:00</published>
<link rel='alternate' type='text/html' href='https://git.amelek.net/vyos/vyos-1x.git/commit/?id=f148cc7c47a7fc6f81a06817de5f24e0836d0792'/>
<id>urn:sha1:f148cc7c47a7fc6f81a06817de5f24e0836d0792</id>
<content type='text'>
/etc/cron.d/vyos-wwan re-ran the conf_mode script every 5 minutes via
op-mode "connect interface wwanN" to re-establish a session lost to RF
signal loss. Re-entering conf_mode from cron is unsafe: the cron job knows
nothing about the boot commit or about a commit in flight, so when a tick
lands before the running config is populated, get_config() returns nothing
but {'ifname', 'deleted'} and apply() takes the teardown branch instead of
dialling. It then stops the DHCP clients, stops ModemManager and unlinks its
own cron file, leaving wwan0 down with no way to recover until the next
commit:

  CRON[1869]: (root) CMD (/usr/libexec/vyos/vyos-check-wwan.py)
  systemd[1]: Stopping DHCP client on wwan0...
  systemd[1]: Stopping Modem Manager...

This is timing dependent - it only bites when a */5 tick coincides with
boot - which is why it presents as an intermittently dead WWAN interface.

Move the re-dial into vyos-netlinkd, which already tracks these interfaces
for DHCP and already gates all of its work behind boot_configuration_complete()
and commit_in_progress2(). A re-dial can therefore no longer land on a
half-applied configuration. It also dials ModemManager directly rather than
re-entering conf_mode, so the teardown branch is no longer reachable from
the recovery path at all.
</content>
</entry>
<entry>
<title>Merge pull request #5399 from jeleel-muibi/t9145-wlb-health-script-env</title>
<updated>2026-08-25T12:05:15+00:00</updated>
<author>
<name>Viacheslav Hletenko</name>
<email>v.gletenko@vyos.io</email>
</author>
<published>2026-08-25T12:05:15+00:00</published>
<link rel='alternate' type='text/html' href='https://git.amelek.net/vyos/vyos-1x.git/commit/?id=d2b54b9d01aee583a80a0cd48a790843d8c85b76'/>
<id>urn:sha1:d2b54b9d01aee583a80a0cd48a790843d8c85b76</id>
<content type='text'>
wan-load-balance: T9145: add health script interface env</content>
</entry>
<entry>
<title>utils: T8868: Refactor kernel command-line arguments and memory info</title>
<updated>2026-08-20T13:35:07+00:00</updated>
<author>
<name>Oleksandr Kuchmystyi</name>
<email>o.kuchmystyi@vyos.io</email>
</author>
<published>2026-07-23T09:17:36+00:00</published>
<link rel='alternate' type='text/html' href='https://git.amelek.net/vyos/vyos-1x.git/commit/?id=b1d4de376eb79c932539c5ec2ddb5241fbce8bb7'/>
<id>urn:sha1:b1d4de376eb79c932539c5ec2ddb5241fbce8bb7</id>
<content type='text'>
- Replaced direct file reads from `/proc/cmdline` with `get_kernel_boot_arg()`
  for fetching kernel command-line arguments in multiple modules.
- Improved memory information retrieval by utilizing `get_memory_info()`.
</content>
</entry>
<entry>
<title>wan-load-balance: T9145: add health script interface env</title>
<updated>2026-08-20T11:50:05+00:00</updated>
<author>
<name>Jeleel Muibi</name>
<email>jeleel-muibi@users.noreply.github.com</email>
</author>
<published>2026-08-13T09:59:32+00:00</published>
<link rel='alternate' type='text/html' href='https://git.amelek.net/vyos/vyos-1x.git/commit/?id=cb7f10c438cfa0f8cac77988588252ca0954d564'/>
<id>urn:sha1:cb7f10c438cfa0f8cac77988588252ca0954d564</id>
<content type='text'>
</content>
</entry>
<entry>
<title>T3871: make boot-time interface naming deterministic and hw-id aware</title>
<updated>2026-08-08T16:33:38+00:00</updated>
<author>
<name>Christian Breunig</name>
<email>christian@breunig.cc</email>
</author>
<published>2026-08-06T19:59:21+00:00</published>
<link rel='alternate' type='text/html' href='https://git.amelek.net/vyos/vyos-1x.git/commit/?id=22cfee116c9935f4a33da4923eff189f2f646371'/>
<id>urn:sha1:22cfee116c9935f4a33da4923eff189f2f646371</id>
<content type='text'>
Multi-vendor PCIe NIC systems could lose or rename Ethernet/wireless
interfaces on boot, because naming was decided from a single per-device
udev event before all hardware had a chance to enumerate.

Replace that with one authoritative pass, run once configuration is
available during router startup: wait for configured hardware, apply
every hw-id binding, and name whatever has none yet by PCIe distance
from the root complex and MAC address - the same result every boot.

A node with its hw-id deleted (NIC replacement) or its whole
configuration removed is treated as an ordinary open slot, filled the
same way - recovering its original hardware whenever the interfaces
that vacated slots this boot also show up as candidates.

Boot now reports any interface still unresolved, and the pass is covered
by a new test suite in vyos-build named: make testifname

Assisted-by: Claude:claude-sonnet-5
</content>
</entry>
<entry>
<title>utils: T9008: migrate remaining cmd() callers to cmdl() and remove cmd()</title>
<updated>2026-07-17T16:10:08+00:00</updated>
<author>
<name>Christian Breunig</name>
<email>christian@breunig.cc</email>
</author>
<published>2026-07-09T20:21:52+00:00</published>
<link rel='alternate' type='text/html' href='https://git.amelek.net/vyos/vyos-1x.git/commit/?id=e0684c0c343835c7674a94424d847592511915b0'/>
<id>urn:sha1:e0684c0c343835c7674a94424d847592511915b0</id>
<content type='text'>
Complete the safer-subprocess migration started by the cmdl()/ifconfig
refactoring and convert every remaining vyos.utils.process.cmd() call site to
the list-based cmdl().

Drop the vyos.utils.process.cmd() implementation as it is no longer in use.
</content>
</entry>
<entry>
<title>T8344: Preserve symlinks when copying config to/from TPM encrypted volume</title>
<updated>2026-07-03T11:18:32+00:00</updated>
<author>
<name>Nataliia Solomko</name>
<email>natalirs1985@gmail.com</email>
</author>
<published>2026-07-03T11:18:32+00:00</published>
<link rel='alternate' type='text/html' href='https://git.amelek.net/vyos/vyos-1x.git/commit/?id=2a73f2a1bdd1c1ea6b7fd3d27ba8c2e335fa14bb'/>
<id>urn:sha1:2a73f2a1bdd1c1ea6b7fd3d27ba8c2e335fa14bb</id>
<content type='text'>
shutil.copytree() defaults to symlinks=False, so it recurses into
symlinked directories and recreates them as real directories instead
of preserving the symlink.
cloud-init creates /opt/vyatta/etc/config/cloud/instance as a symlink
to instances/i-&lt;id&gt;. Enabling/disabling config encryption copied this
tree with copytree() and silently turned that symlink into a real
directory, causing cloud-init to fail on later runs with:
    IsADirectoryError: [Errno 21] Is a directory: '.../cloud/instance'
Pass symlinks=True to preserve symlinks during the copy.
</content>
</entry>
<entry>
<title>ci: T8490: fix typos in comments, strings, and local identifiers</title>
<updated>2026-06-29T12:10:10+00:00</updated>
<author>
<name>Yuriy Andamasov</name>
<email>yuriy@vyos.io</email>
</author>
<published>2026-06-29T07:28:43+00:00</published>
<link rel='alternate' type='text/html' href='https://git.amelek.net/vyos/vyos-1x.git/commit/?id=094928ba02bbabf3807ebe8f5ae77b957435d288'/>
<id>urn:sha1:094928ba02bbabf3807ebe8f5ae77b957435d288</id>
<content type='text'>
Reaches a clean typos baseline for the T8490 ruleset pilot. Categories:
- Comments/docs: recursivly, taret, passsed, characted, arhive, AtrributeError;
  "ned" -&gt; "new" (migration comments).
- Messages/strings: writeable -&gt; writable (x5); OCaml log "Commandis" -&gt; "Command is".
- Local variables (all refs in-function): commited, formating, presistent;
  inpt_range -&gt; input_range; tz_datas -&gt; tz_data_raw (avoids the tz_data collision).
- Self-contained renames (definition + all references in-file): formated_stats,
  _get_formatted_output_conections -&gt; ..._connections, expension_failure -&gt;
  expansion_failure (ping + traceroute), snmpd_restart_reqired -&gt; ..._required.

False positives are allowlisted centrally (vyos/.github, separate PR), NOT changed
here: mke2fs, Maya-calendar "Mak", RFC 4122 "IDentifier" (hostapd), and VPP's
"U-Forwrd" bridge-domain column header (op_mode/vpp.py + the VPP smoketest assert
the real upstream `vppctl` output). Verified: typos clean, py_compile of every
edited .py, zero remaining old-identifier references.

🤖 Generated by [robots](https://vyos.io)
</content>
</entry>
<entry>
<title>geoip: T8987: Support updates via source-address/vrf</title>
<updated>2026-06-25T14:19:06+00:00</updated>
<author>
<name>sarthurdev</name>
<email>965089+sarthurdev@users.noreply.github.com</email>
</author>
<published>2026-06-17T17:21:48+00:00</published>
<link rel='alternate' type='text/html' href='https://git.amelek.net/vyos/vyos-1x.git/commit/?id=be535fd16bdf9a7978d4e2b049fdf0b45c6e9f38'/>
<id>urn:sha1:be535fd16bdf9a7978d4e2b049fdf0b45c6e9f38</id>
<content type='text'>
</content>
</entry>
<entry>
<title>T8502: add client support for config-sync excluded paths</title>
<updated>2026-05-28T13:31:26+00:00</updated>
<author>
<name>John Estabrook</name>
<email>jestabro@vyos.io</email>
</author>
<published>2026-05-04T19:35:42+00:00</published>
<link rel='alternate' type='text/html' href='https://git.amelek.net/vyos/vyos-1x.git/commit/?id=4113da576b6f934d0340cb18ae184bb25c1619c0'/>
<id>urn:sha1:4113da576b6f934d0340cb18ae184bb25c1619c0</id>
<content type='text'>
</content>
</entry>
</feed>
