summaryrefslogtreecommitdiff
path: root/src/migration-scripts
diff options
context:
space:
mode:
Diffstat (limited to 'src/migration-scripts')
-rw-r--r--src/migration-scripts/bgp/0-to-12
-rw-r--r--src/migration-scripts/bgp/1-to-22
-rw-r--r--src/migration-scripts/bgp/2-to-32
-rw-r--r--src/migration-scripts/bgp/3-to-42
-rw-r--r--src/migration-scripts/bgp/4-to-52
-rw-r--r--src/migration-scripts/bgp/5-to-64
-rw-r--r--src/migration-scripts/cluster/1-to-22
-rw-r--r--src/migration-scripts/config-management/0-to-12
-rw-r--r--src/migration-scripts/conntrack-sync/1-to-22
-rw-r--r--src/migration-scripts/conntrack/1-to-22
-rw-r--r--src/migration-scripts/conntrack/2-to-32
-rw-r--r--src/migration-scripts/conntrack/3-to-42
-rw-r--r--src/migration-scripts/conntrack/4-to-52
-rw-r--r--src/migration-scripts/conntrack/5-to-630
-rw-r--r--src/migration-scripts/container/0-to-16
-rw-r--r--src/migration-scripts/container/1-to-22
-rw-r--r--src/migration-scripts/container/2-to-331
-rw-r--r--src/migration-scripts/dhcp-relay/1-to-22
-rw-r--r--src/migration-scripts/dhcp-server/10-to-112
-rw-r--r--src/migration-scripts/dhcp-server/4-to-52
-rw-r--r--src/migration-scripts/dhcp-server/5-to-62
-rw-r--r--src/migration-scripts/dhcp-server/6-to-72
-rw-r--r--src/migration-scripts/dhcp-server/7-to-88
-rw-r--r--src/migration-scripts/dhcp-server/8-to-92
-rw-r--r--src/migration-scripts/dhcp-server/9-to-102
-rw-r--r--src/migration-scripts/dhcpv6-server/0-to-12
-rw-r--r--src/migration-scripts/dhcpv6-server/1-to-22
-rw-r--r--src/migration-scripts/dhcpv6-server/2-to-32
-rw-r--r--src/migration-scripts/dhcpv6-server/3-to-42
-rw-r--r--src/migration-scripts/dhcpv6-server/4-to-52
-rw-r--r--src/migration-scripts/dhcpv6-server/5-to-62
-rw-r--r--src/migration-scripts/dns-dynamic/0-to-12
-rw-r--r--src/migration-scripts/dns-dynamic/1-to-214
-rw-r--r--src/migration-scripts/dns-dynamic/2-to-34
-rw-r--r--src/migration-scripts/dns-dynamic/3-to-42
-rw-r--r--src/migration-scripts/dns-forwarding/0-to-12
-rw-r--r--src/migration-scripts/dns-forwarding/1-to-22
-rw-r--r--src/migration-scripts/dns-forwarding/2-to-32
-rw-r--r--src/migration-scripts/dns-forwarding/3-to-42
-rw-r--r--src/migration-scripts/firewall/10-to-1171
-rw-r--r--src/migration-scripts/firewall/11-to-124
-rw-r--r--src/migration-scripts/firewall/12-to-132
-rw-r--r--src/migration-scripts/firewall/13-to-142
-rw-r--r--src/migration-scripts/firewall/14-to-154
-rw-r--r--src/migration-scripts/firewall/15-to-162
-rw-r--r--src/migration-scripts/firewall/16-to-172
-rwxr-xr-xsrc/migration-scripts/firewall/17-to-182
-rw-r--r--src/migration-scripts/firewall/18-to-1935
-rw-r--r--src/migration-scripts/firewall/19-to-20100
-rw-r--r--src/migration-scripts/firewall/5-to-62
-rw-r--r--src/migration-scripts/firewall/6-to-769
-rw-r--r--src/migration-scripts/firewall/7-to-82
-rw-r--r--src/migration-scripts/firewall/8-to-92
-rw-r--r--src/migration-scripts/firewall/9-to-102
-rw-r--r--src/migration-scripts/flow-accounting/0-to-12
-rw-r--r--src/migration-scripts/flow-accounting/1-to-22
-rw-r--r--src/migration-scripts/flow-accounting/2-to-365
-rw-r--r--src/migration-scripts/https/0-to-12
-rw-r--r--src/migration-scripts/https/1-to-22
-rw-r--r--src/migration-scripts/https/2-to-32
-rw-r--r--src/migration-scripts/https/3-to-42
-rw-r--r--src/migration-scripts/https/4-to-52
-rw-r--r--src/migration-scripts/https/5-to-62
-rw-r--r--src/migration-scripts/https/6-to-72
-rw-r--r--src/migration-scripts/ids/0-to-12
-rw-r--r--src/migration-scripts/ids/1-to-230
-rw-r--r--src/migration-scripts/interfaces/0-to-16
-rw-r--r--src/migration-scripts/interfaces/1-to-26
-rw-r--r--src/migration-scripts/interfaces/10-to-112
-rw-r--r--src/migration-scripts/interfaces/11-to-122
-rw-r--r--src/migration-scripts/interfaces/12-to-132
-rw-r--r--src/migration-scripts/interfaces/13-to-142
-rw-r--r--src/migration-scripts/interfaces/14-to-152
-rw-r--r--src/migration-scripts/interfaces/15-to-162
-rw-r--r--src/migration-scripts/interfaces/16-to-172
-rw-r--r--src/migration-scripts/interfaces/17-to-182
-rw-r--r--src/migration-scripts/interfaces/18-to-192
-rw-r--r--src/migration-scripts/interfaces/19-to-202
-rw-r--r--src/migration-scripts/interfaces/2-to-32
-rw-r--r--src/migration-scripts/interfaces/20-to-212
-rw-r--r--src/migration-scripts/interfaces/21-to-222
-rw-r--r--src/migration-scripts/interfaces/22-to-232
-rw-r--r--src/migration-scripts/interfaces/23-to-242
-rw-r--r--src/migration-scripts/interfaces/24-to-252
-rw-r--r--src/migration-scripts/interfaces/25-to-26329
-rw-r--r--src/migration-scripts/interfaces/26-to-272
-rw-r--r--src/migration-scripts/interfaces/27-to-282
-rw-r--r--src/migration-scripts/interfaces/28-to-292
-rw-r--r--src/migration-scripts/interfaces/29-to-302
-rw-r--r--src/migration-scripts/interfaces/3-to-42
-rw-r--r--src/migration-scripts/interfaces/30-to-312
-rw-r--r--src/migration-scripts/interfaces/31-to-322
-rw-r--r--src/migration-scripts/interfaces/32-to-3358
-rw-r--r--src/migration-scripts/interfaces/33-to-3440
-rw-r--r--src/migration-scripts/interfaces/4-to-52
-rw-r--r--src/migration-scripts/interfaces/5-to-68
-rw-r--r--src/migration-scripts/interfaces/6-to-72
-rw-r--r--src/migration-scripts/interfaces/7-to-84
-rw-r--r--src/migration-scripts/interfaces/8-to-94
-rw-r--r--src/migration-scripts/interfaces/9-to-106
-rw-r--r--src/migration-scripts/ipoe-server/1-to-24
-rw-r--r--src/migration-scripts/ipoe-server/2-to-32
-rw-r--r--src/migration-scripts/ipoe-server/3-to-42
-rw-r--r--src/migration-scripts/ipsec/10-to-112
-rw-r--r--src/migration-scripts/ipsec/11-to-122
-rw-r--r--src/migration-scripts/ipsec/12-to-132
-rw-r--r--src/migration-scripts/ipsec/13-to-1433
-rw-r--r--src/migration-scripts/ipsec/4-to-52
-rw-r--r--src/migration-scripts/ipsec/5-to-62
-rw-r--r--src/migration-scripts/ipsec/6-to-72
-rw-r--r--src/migration-scripts/ipsec/7-to-82
-rw-r--r--src/migration-scripts/ipsec/8-to-92
-rw-r--r--src/migration-scripts/ipsec/9-to-102
-rw-r--r--src/migration-scripts/isis/0-to-122
-rw-r--r--src/migration-scripts/isis/1-to-22
-rw-r--r--src/migration-scripts/isis/2-to-32
-rw-r--r--src/migration-scripts/l2tp/0-to-12
-rw-r--r--src/migration-scripts/l2tp/1-to-22
-rw-r--r--src/migration-scripts/l2tp/2-to-32
-rw-r--r--src/migration-scripts/l2tp/3-to-42
-rw-r--r--src/migration-scripts/l2tp/4-to-52
-rw-r--r--src/migration-scripts/l2tp/5-to-64
-rw-r--r--src/migration-scripts/l2tp/6-to-72
-rw-r--r--src/migration-scripts/l2tp/7-to-82
-rw-r--r--src/migration-scripts/l2tp/8-to-92
-rw-r--r--src/migration-scripts/lldp/0-to-12
-rw-r--r--src/migration-scripts/lldp/1-to-22
-rw-r--r--src/migration-scripts/lldp/2-to-32
-rw-r--r--src/migration-scripts/monitoring/0-to-14
-rw-r--r--src/migration-scripts/monitoring/1-to-22
-rw-r--r--src/migration-scripts/nat/4-to-52
-rw-r--r--src/migration-scripts/nat/5-to-62
-rw-r--r--src/migration-scripts/nat/6-to-74
-rw-r--r--src/migration-scripts/nat/7-to-82
-rw-r--r--src/migration-scripts/nat66/0-to-12
-rw-r--r--src/migration-scripts/nat66/1-to-26
-rw-r--r--src/migration-scripts/nat66/2-to-32
-rw-r--r--src/migration-scripts/nhrp/0-to-16
-rw-r--r--src/migration-scripts/ntp/0-to-12
-rw-r--r--src/migration-scripts/ntp/1-to-22
-rw-r--r--src/migration-scripts/ntp/2-to-32
-rw-r--r--src/migration-scripts/openconnect/0-to-12
-rw-r--r--src/migration-scripts/openconnect/1-to-24
-rw-r--r--src/migration-scripts/openconnect/2-to-32
-rw-r--r--src/migration-scripts/openvpn/0-to-113
-rw-r--r--src/migration-scripts/openvpn/1-to-28
-rw-r--r--src/migration-scripts/openvpn/2-to-32
-rw-r--r--src/migration-scripts/openvpn/3-to-42
-rw-r--r--src/migration-scripts/openvpn/4-to-538
-rw-r--r--src/migration-scripts/ospf/0-to-12
-rw-r--r--src/migration-scripts/ospf/1-to-22
-rw-r--r--src/migration-scripts/pim/0-to-12
-rw-r--r--src/migration-scripts/policy/0-to-12
-rw-r--r--src/migration-scripts/policy/1-to-22
-rw-r--r--src/migration-scripts/policy/2-to-32
-rw-r--r--src/migration-scripts/policy/3-to-44
-rw-r--r--src/migration-scripts/policy/4-to-52
-rw-r--r--src/migration-scripts/policy/5-to-62
-rw-r--r--src/migration-scripts/policy/6-to-72
-rw-r--r--src/migration-scripts/policy/7-to-82
-rw-r--r--src/migration-scripts/policy/8-to-92
-rw-r--r--src/migration-scripts/pppoe-server/0-to-12
-rw-r--r--src/migration-scripts/pppoe-server/1-to-22
-rw-r--r--src/migration-scripts/pppoe-server/10-to-112
-rw-r--r--src/migration-scripts/pppoe-server/11-to-1231
-rw-r--r--src/migration-scripts/pppoe-server/2-to-32
-rw-r--r--src/migration-scripts/pppoe-server/3-to-42
-rw-r--r--src/migration-scripts/pppoe-server/4-to-52
-rw-r--r--src/migration-scripts/pppoe-server/5-to-62
-rw-r--r--src/migration-scripts/pppoe-server/6-to-72
-rw-r--r--src/migration-scripts/pppoe-server/7-to-82
-rw-r--r--src/migration-scripts/pppoe-server/8-to-92
-rw-r--r--src/migration-scripts/pppoe-server/9-to-102
-rw-r--r--src/migration-scripts/pptp/0-to-12
-rw-r--r--src/migration-scripts/pptp/1-to-22
-rw-r--r--src/migration-scripts/pptp/2-to-32
-rw-r--r--src/migration-scripts/pptp/3-to-42
-rw-r--r--src/migration-scripts/pptp/4-to-52
-rw-r--r--src/migration-scripts/qos/1-to-22
-rw-r--r--src/migration-scripts/qos/2-to-32
-rw-r--r--src/migration-scripts/quagga/10-to-112
-rw-r--r--src/migration-scripts/quagga/11-to-126
-rw-r--r--src/migration-scripts/quagga/2-to-37
-rw-r--r--src/migration-scripts/quagga/3-to-42
-rw-r--r--src/migration-scripts/quagga/4-to-52
-rw-r--r--src/migration-scripts/quagga/5-to-62
-rw-r--r--src/migration-scripts/quagga/6-to-72
-rw-r--r--src/migration-scripts/quagga/7-to-82
-rw-r--r--src/migration-scripts/quagga/8-to-930
-rw-r--r--src/migration-scripts/quagga/9-to-102
-rw-r--r--src/migration-scripts/reverse-proxy/0-to-12
-rwxr-xr-xsrc/migration-scripts/reverse-proxy/1-to-22
-rwxr-xr-xsrc/migration-scripts/reverse-proxy/2-to-366
-rw-r--r--src/migration-scripts/rip/0-to-12
-rw-r--r--src/migration-scripts/rpki/0-to-12
-rw-r--r--src/migration-scripts/rpki/1-to-22
-rw-r--r--src/migration-scripts/salt/0-to-12
-rw-r--r--src/migration-scripts/snmp/0-to-12
-rw-r--r--src/migration-scripts/snmp/1-to-24
-rw-r--r--src/migration-scripts/snmp/2-to-34
-rw-r--r--src/migration-scripts/ssh/0-to-12
-rw-r--r--src/migration-scripts/ssh/1-to-22
-rw-r--r--src/migration-scripts/ssh/2-to-343
-rw-r--r--src/migration-scripts/sstp/0-to-14
-rw-r--r--src/migration-scripts/sstp/1-to-22
-rw-r--r--src/migration-scripts/sstp/2-to-32
-rw-r--r--src/migration-scripts/sstp/3-to-42
-rw-r--r--src/migration-scripts/sstp/4-to-52
-rw-r--r--src/migration-scripts/sstp/5-to-62
-rw-r--r--src/migration-scripts/system/10-to-112
-rw-r--r--src/migration-scripts/system/11-to-122
-rw-r--r--src/migration-scripts/system/12-to-132
-rw-r--r--src/migration-scripts/system/13-to-142
-rw-r--r--src/migration-scripts/system/14-to-152
-rw-r--r--src/migration-scripts/system/15-to-162
-rw-r--r--src/migration-scripts/system/16-to-172
-rw-r--r--src/migration-scripts/system/17-to-182
-rw-r--r--src/migration-scripts/system/18-to-192
-rw-r--r--src/migration-scripts/system/19-to-202
-rw-r--r--src/migration-scripts/system/20-to-212
-rw-r--r--src/migration-scripts/system/21-to-222
-rw-r--r--src/migration-scripts/system/22-to-234
-rw-r--r--src/migration-scripts/system/23-to-244
-rw-r--r--src/migration-scripts/system/24-to-252
-rw-r--r--src/migration-scripts/system/25-to-262
-rw-r--r--src/migration-scripts/system/26-to-272
-rw-r--r--src/migration-scripts/system/27-to-282
-rw-r--r--src/migration-scripts/system/28-to-2947
-rw-r--r--src/migration-scripts/system/29-to-3052
-rw-r--r--src/migration-scripts/system/30-to-3142
-rw-r--r--src/migration-scripts/system/31-to-3238
-rw-r--r--src/migration-scripts/system/6-to-72
-rw-r--r--src/migration-scripts/system/7-to-82
-rw-r--r--src/migration-scripts/system/8-to-92
-rw-r--r--src/migration-scripts/vpp/1-to-234
-rw-r--r--src/migration-scripts/vpp/2-to-330
-rw-r--r--src/migration-scripts/vpp/3-to-430
-rw-r--r--src/migration-scripts/vpp/4-to-535
-rw-r--r--src/migration-scripts/vpp/5-to-6593
-rw-r--r--src/migration-scripts/vrf/0-to-12
-rw-r--r--src/migration-scripts/vrf/1-to-27
-rw-r--r--src/migration-scripts/vrf/2-to-35
-rw-r--r--src/migration-scripts/vrf/3-to-450
-rw-r--r--src/migration-scripts/vrrp/1-to-214
-rw-r--r--src/migration-scripts/vrrp/2-to-32
-rw-r--r--src/migration-scripts/vrrp/3-to-42
-rw-r--r--src/migration-scripts/wanloadbalance/3-to-42
-rw-r--r--src/migration-scripts/webproxy/1-to-22
248 files changed, 2182 insertions, 458 deletions
diff --git a/src/migration-scripts/bgp/0-to-1 b/src/migration-scripts/bgp/0-to-1
index a2f3343d8..a072286ea 100644
--- a/src/migration-scripts/bgp/0-to-1
+++ b/src/migration-scripts/bgp/0-to-1
@@ -1,4 +1,4 @@
-# Copyright 2021-2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/bgp/1-to-2 b/src/migration-scripts/bgp/1-to-2
index c0fc3b05a..64732ac72 100644
--- a/src/migration-scripts/bgp/1-to-2
+++ b/src/migration-scripts/bgp/1-to-2
@@ -1,4 +1,4 @@
-# Copyright 2021-2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/bgp/2-to-3 b/src/migration-scripts/bgp/2-to-3
index d8bc34db6..9d3ab3ecf 100644
--- a/src/migration-scripts/bgp/2-to-3
+++ b/src/migration-scripts/bgp/2-to-3
@@ -1,4 +1,4 @@
-# Copyright 2022-2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/bgp/3-to-4 b/src/migration-scripts/bgp/3-to-4
index 842aef0ce..9e45bd4d6 100644
--- a/src/migration-scripts/bgp/3-to-4
+++ b/src/migration-scripts/bgp/3-to-4
@@ -1,4 +1,4 @@
-# Copyright 2023-2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/bgp/4-to-5 b/src/migration-scripts/bgp/4-to-5
index d779eb11e..42b2fd0b6 100644
--- a/src/migration-scripts/bgp/4-to-5
+++ b/src/migration-scripts/bgp/4-to-5
@@ -1,4 +1,4 @@
-# Copyright 2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/bgp/5-to-6 b/src/migration-scripts/bgp/5-to-6
index e6fea6574..3443e8000 100644
--- a/src/migration-scripts/bgp/5-to-6
+++ b/src/migration-scripts/bgp/5-to-6
@@ -1,4 +1,4 @@
-# Copyright 2025 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
@@ -25,7 +25,7 @@ def migrate(config: ConfigTree) -> None:
return
for address_family in ['ipv4-unicast', 'ipv6-unicast']:
- # there is no non-main routing table beeing redistributed under this addres family
+ # there is no non-main routing table being redistributed under this address family
# bail out early and continue with next AFI
table_path = bgp_base + ['address-family', address_family, 'redistribute', 'table']
if not config.exists(table_path):
diff --git a/src/migration-scripts/cluster/1-to-2 b/src/migration-scripts/cluster/1-to-2
index 5ca4531ea..5e5136a64 100644
--- a/src/migration-scripts/cluster/1-to-2
+++ b/src/migration-scripts/cluster/1-to-2
@@ -1,4 +1,4 @@
-# Copyright 2023-2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/config-management/0-to-1 b/src/migration-scripts/config-management/0-to-1
index 44c685630..9c1b96a4b 100644
--- a/src/migration-scripts/config-management/0-to-1
+++ b/src/migration-scripts/config-management/0-to-1
@@ -1,4 +1,4 @@
-# Copyright 2018-2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/conntrack-sync/1-to-2 b/src/migration-scripts/conntrack-sync/1-to-2
index 3e10e98c3..793bf01d8 100644
--- a/src/migration-scripts/conntrack-sync/1-to-2
+++ b/src/migration-scripts/conntrack-sync/1-to-2
@@ -1,4 +1,4 @@
-# Copyright 2021-2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/conntrack/1-to-2 b/src/migration-scripts/conntrack/1-to-2
index 0a4fb3de9..5b126c8ab 100644
--- a/src/migration-scripts/conntrack/1-to-2
+++ b/src/migration-scripts/conntrack/1-to-2
@@ -1,4 +1,4 @@
-# Copyright 2021-2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/conntrack/2-to-3 b/src/migration-scripts/conntrack/2-to-3
index 5ad4e6350..e74fe3105 100644
--- a/src/migration-scripts/conntrack/2-to-3
+++ b/src/migration-scripts/conntrack/2-to-3
@@ -1,4 +1,4 @@
-# Copyright 2021-2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/conntrack/3-to-4 b/src/migration-scripts/conntrack/3-to-4
index 679a260d5..709f97310 100644
--- a/src/migration-scripts/conntrack/3-to-4
+++ b/src/migration-scripts/conntrack/3-to-4
@@ -1,4 +1,4 @@
-# Copyright 2023-2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/conntrack/4-to-5 b/src/migration-scripts/conntrack/4-to-5
index 775fe7480..b5d2a79bc 100644
--- a/src/migration-scripts/conntrack/4-to-5
+++ b/src/migration-scripts/conntrack/4-to-5
@@ -1,4 +1,4 @@
-# Copyright 2023-2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/conntrack/5-to-6 b/src/migration-scripts/conntrack/5-to-6
new file mode 100644
index 000000000..330849243
--- /dev/null
+++ b/src/migration-scripts/conntrack/5-to-6
@@ -0,0 +1,30 @@
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
+#
+# This library is free software; you can redistribute it and/or
+# modify it under the terms of the GNU Lesser General Public
+# License as published by the Free Software Foundation; either
+# version 2.1 of the License, or (at your option) any later version.
+#
+# This library is distributed in the hope that it will be useful,
+# but WITHOUT ANY WARRANTY; without even the implied warranty of
+# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
+# Lesser General Public License for more details.
+#
+# You should have received a copy of the GNU Lesser General Public License
+# along with this library. If not, see <http://www.gnu.org/licenses/>.
+
+# T7202: fix lower limit of supported conntrack hash-size to match Kernel
+# lower limit.
+
+from vyos.configtree import ConfigTree
+
+base = ['system', 'conntrack']
+def migrate(config: ConfigTree) -> None:
+ if not config.exists(base):
+ # Nothing to do
+ return
+
+ if config.exists(base + ['hash-size']):
+ tmp = config.return_value(base + ['hash-size'])
+ if int(tmp) < 1024:
+ config.set(base + ['hash-size'], value=1024)
diff --git a/src/migration-scripts/container/0-to-1 b/src/migration-scripts/container/0-to-1
index 99102a5e6..6f11bdbac 100644
--- a/src/migration-scripts/container/0-to-1
+++ b/src/migration-scripts/container/0-to-1
@@ -1,4 +1,4 @@
-# Copyright 2022-2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
@@ -13,7 +13,7 @@
# You should have received a copy of the GNU Lesser General Public License
# along with this library. If not, see <http://www.gnu.org/licenses/>.
-# T4870: change underlaying container filesystem from vfs to overlay
+# T4870: change underlying container filesystem from vfs to overlay
import os
import shutil
@@ -35,7 +35,7 @@ def migrate(config: ConfigTree) -> None:
image_name = config.return_value(base + [container, 'image'])
call(f'sudo podman image save --quiet --output /root/{container}.tar --format oci-archive {image_name}')
- # No need to adjust the strage driver online (this is only used for testing and
+ # No need to adjust the storage driver online (this is only used for testing and
# debugging on a live system) - it is already overlay2 when the migration script
# is run during system update. But the specified driver in the image is actually
# overwritten by the still present VFS filesystem on disk. Thus podman still
diff --git a/src/migration-scripts/container/1-to-2 b/src/migration-scripts/container/1-to-2
index c12dd8ebb..8664cfac9 100644
--- a/src/migration-scripts/container/1-to-2
+++ b/src/migration-scripts/container/1-to-2
@@ -1,4 +1,4 @@
-# Copyright 2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/container/2-to-3 b/src/migration-scripts/container/2-to-3
new file mode 100644
index 000000000..0b43ecdb2
--- /dev/null
+++ b/src/migration-scripts/container/2-to-3
@@ -0,0 +1,31 @@
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
+#
+# This library is free software; you can redistribute it and/or
+# modify it under the terms of the GNU Lesser General Public
+# License as published by the Free Software Foundation; either
+# version 2.1 of the License, or (at your option) any later version.
+#
+# This library is distributed in the hope that it will be useful,
+# but WITHOUT ANY WARRANTY; without even the implied warranty of
+# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
+# Lesser General Public License for more details.
+#
+# You should have received a copy of the GNU Lesser General Public License
+# along with this library. If not, see <http://www.gnu.org/licenses/>.
+
+# T7473: container: allow log-driver to be set per container
+
+from vyos.configtree import ConfigTree
+
+def migrate(config: ConfigTree) -> None:
+ log_base = ['container', 'log-driver']
+ container_base = ['container', 'name']
+
+ if not config.exists(log_base):
+ return
+ else:
+ log_driver = config.return_value(log_base)
+ for container in config.list_nodes(container_base):
+ # Set the log-driver for each container
+ config.set(container_base + [container, 'log-driver'], value=log_driver)
+ config.delete(log_base)
diff --git a/src/migration-scripts/dhcp-relay/1-to-2 b/src/migration-scripts/dhcp-relay/1-to-2
index 54cd8d6c0..50ac29df1 100644
--- a/src/migration-scripts/dhcp-relay/1-to-2
+++ b/src/migration-scripts/dhcp-relay/1-to-2
@@ -1,4 +1,4 @@
-# Copyright 2018-2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/dhcp-server/10-to-11 b/src/migration-scripts/dhcp-server/10-to-11
index f54a4c7b7..82f303868 100644
--- a/src/migration-scripts/dhcp-server/10-to-11
+++ b/src/migration-scripts/dhcp-server/10-to-11
@@ -1,4 +1,4 @@
-# Copyright 2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/dhcp-server/4-to-5 b/src/migration-scripts/dhcp-server/4-to-5
index a655515dc..9b121d23f 100644
--- a/src/migration-scripts/dhcp-server/4-to-5
+++ b/src/migration-scripts/dhcp-server/4-to-5
@@ -1,6 +1,6 @@
#!/usr/bin/env python3
-# Copyright 2018-2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/dhcp-server/5-to-6 b/src/migration-scripts/dhcp-server/5-to-6
index 9404cd038..fd2ed9e34 100644
--- a/src/migration-scripts/dhcp-server/5-to-6
+++ b/src/migration-scripts/dhcp-server/5-to-6
@@ -1,4 +1,4 @@
-# Copyright 2021-2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/dhcp-server/6-to-7 b/src/migration-scripts/dhcp-server/6-to-7
index 4e6583a31..fbb8c06f9 100644
--- a/src/migration-scripts/dhcp-server/6-to-7
+++ b/src/migration-scripts/dhcp-server/6-to-7
@@ -1,4 +1,4 @@
-# Copyright 2022-2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/dhcp-server/7-to-8 b/src/migration-scripts/dhcp-server/7-to-8
index 7fcb62e86..fb939e020 100644
--- a/src/migration-scripts/dhcp-server/7-to-8
+++ b/src/migration-scripts/dhcp-server/7-to-8
@@ -1,4 +1,4 @@
-# Copyright 2023-2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
@@ -41,9 +41,6 @@ def migrate(config: ConfigTree) -> None:
for network in config.list_nodes(base + ['shared-network-name']):
base_network = base + ['shared-network-name', network]
- if config.exists(base_network + ['ping-check']):
- config.delete(base_network + ['ping-check'])
-
if config.exists(base_network + ['shared-network-parameters']):
config.delete(base_network +['shared-network-parameters'])
@@ -57,9 +54,6 @@ def migrate(config: ConfigTree) -> None:
if config.exists(base_subnet + ['enable-failover']):
config.delete(base_subnet + ['enable-failover'])
- if config.exists(base_subnet + ['ping-check']):
- config.delete(base_subnet + ['ping-check'])
-
if config.exists(base_subnet + ['subnet-parameters']):
config.delete(base_subnet + ['subnet-parameters'])
diff --git a/src/migration-scripts/dhcp-server/8-to-9 b/src/migration-scripts/dhcp-server/8-to-9
index 5843e9fda..34c80cb22 100644
--- a/src/migration-scripts/dhcp-server/8-to-9
+++ b/src/migration-scripts/dhcp-server/8-to-9
@@ -1,4 +1,4 @@
-# Copyright 2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/dhcp-server/9-to-10 b/src/migration-scripts/dhcp-server/9-to-10
index eda97550d..0d3d53d5e 100644
--- a/src/migration-scripts/dhcp-server/9-to-10
+++ b/src/migration-scripts/dhcp-server/9-to-10
@@ -1,4 +1,4 @@
-# Copyright 2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/dhcpv6-server/0-to-1 b/src/migration-scripts/dhcpv6-server/0-to-1
index fd9b2d739..e46063a26 100644
--- a/src/migration-scripts/dhcpv6-server/0-to-1
+++ b/src/migration-scripts/dhcpv6-server/0-to-1
@@ -1,4 +1,4 @@
-# Copyright 202-2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/dhcpv6-server/1-to-2 b/src/migration-scripts/dhcpv6-server/1-to-2
index ad307495c..cd7b06673 100644
--- a/src/migration-scripts/dhcpv6-server/1-to-2
+++ b/src/migration-scripts/dhcpv6-server/1-to-2
@@ -1,4 +1,4 @@
-# Copyright 2023-2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/dhcpv6-server/2-to-3 b/src/migration-scripts/dhcpv6-server/2-to-3
index b44798d18..728720ecb 100644
--- a/src/migration-scripts/dhcpv6-server/2-to-3
+++ b/src/migration-scripts/dhcpv6-server/2-to-3
@@ -1,4 +1,4 @@
-# Copyright 2023-2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/dhcpv6-server/3-to-4 b/src/migration-scripts/dhcpv6-server/3-to-4
index e38e36505..db10fcb6c 100644
--- a/src/migration-scripts/dhcpv6-server/3-to-4
+++ b/src/migration-scripts/dhcpv6-server/3-to-4
@@ -1,4 +1,4 @@
-# Copyright 2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/dhcpv6-server/4-to-5 b/src/migration-scripts/dhcpv6-server/4-to-5
index ad18e1a84..fd8c63644 100644
--- a/src/migration-scripts/dhcpv6-server/4-to-5
+++ b/src/migration-scripts/dhcpv6-server/4-to-5
@@ -1,4 +1,4 @@
-# Copyright 2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/dhcpv6-server/5-to-6 b/src/migration-scripts/dhcpv6-server/5-to-6
index cad0a3538..e12020597 100644
--- a/src/migration-scripts/dhcpv6-server/5-to-6
+++ b/src/migration-scripts/dhcpv6-server/5-to-6
@@ -1,4 +1,4 @@
-# Copyright 2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/dns-dynamic/0-to-1 b/src/migration-scripts/dns-dynamic/0-to-1
index 6a91b36af..a75fedcad 100644
--- a/src/migration-scripts/dns-dynamic/0-to-1
+++ b/src/migration-scripts/dns-dynamic/0-to-1
@@ -1,4 +1,4 @@
-# Copyright 2023-2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/dns-dynamic/1-to-2 b/src/migration-scripts/dns-dynamic/1-to-2
index 7f4938147..424d4fa85 100644
--- a/src/migration-scripts/dns-dynamic/1-to-2
+++ b/src/migration-scripts/dns-dynamic/1-to-2
@@ -1,4 +1,4 @@
-# Copyright 2023-2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
@@ -51,8 +51,10 @@ def migrate(config: ConfigTree) -> None:
# Migrate "service dns dynamic address <interface> service <service> protocol dnsexit"
# to "service dns dynamic address <interface> service <service> protocol dnsexit2"
for address in config.list_nodes(address_path):
- for svc_cfg in config.list_nodes(address_path + [address, 'service']):
- if config.exists(address_path + [address, 'service', svc_cfg, 'protocol']):
- protocol = config.return_value(address_path + [address, 'service', svc_cfg, 'protocol'])
- if protocol == 'dnsexit':
- config.set(address_path + [address, 'service', svc_cfg, 'protocol'], 'dnsexit2')
+ service_path = address_path + [address, 'service']
+ if config.exists(service_path):
+ for svc_cfg in config.list_nodes(service_path):
+ if config.exists(service_path + [svc_cfg, 'protocol']):
+ protocol = config.return_value(service_path + [svc_cfg, 'protocol'])
+ if protocol == 'dnsexit':
+ config.set(service_path + [svc_cfg, 'protocol'], 'dnsexit2')
diff --git a/src/migration-scripts/dns-dynamic/2-to-3 b/src/migration-scripts/dns-dynamic/2-to-3
index 9aafc41a4..9e79078fa 100644
--- a/src/migration-scripts/dns-dynamic/2-to-3
+++ b/src/migration-scripts/dns-dynamic/2-to-3
@@ -1,4 +1,4 @@
-# Copyright 2023-2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
@@ -33,7 +33,7 @@ def normalize_name(name):
the old name format.
"""
# Normalize unicode characters to ASCII (NFKD)
- # Replace all separators with hypens, strip leading and trailing hyphens
+ # Replace all separators with hyphens, strip leading and trailing hyphens
name = normalize('NFKD', name).encode('ascii', 'ignore').decode()
name = re.sub(r'(\s|_|\W)+', '-', name).strip('-')
diff --git a/src/migration-scripts/dns-dynamic/3-to-4 b/src/migration-scripts/dns-dynamic/3-to-4
index c8e1ffeee..ff640f7ef 100644
--- a/src/migration-scripts/dns-dynamic/3-to-4
+++ b/src/migration-scripts/dns-dynamic/3-to-4
@@ -1,4 +1,4 @@
-# Copyright 2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/dns-forwarding/0-to-1 b/src/migration-scripts/dns-forwarding/0-to-1
index 264ffb40d..fe1669e84 100644
--- a/src/migration-scripts/dns-forwarding/0-to-1
+++ b/src/migration-scripts/dns-forwarding/0-to-1
@@ -1,4 +1,4 @@
-# Copyright 2019-2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/dns-forwarding/1-to-2 b/src/migration-scripts/dns-forwarding/1-to-2
index 15ed1e136..2d90078ec 100644
--- a/src/migration-scripts/dns-forwarding/1-to-2
+++ b/src/migration-scripts/dns-forwarding/1-to-2
@@ -1,4 +1,4 @@
-# Copyright 2019-2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/dns-forwarding/2-to-3 b/src/migration-scripts/dns-forwarding/2-to-3
index 729c1f00a..0fdfd8447 100644
--- a/src/migration-scripts/dns-forwarding/2-to-3
+++ b/src/migration-scripts/dns-forwarding/2-to-3
@@ -1,4 +1,4 @@
-# Copyright 2020-2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/dns-forwarding/3-to-4 b/src/migration-scripts/dns-forwarding/3-to-4
index b02c0b7ca..f22cfea81 100644
--- a/src/migration-scripts/dns-forwarding/3-to-4
+++ b/src/migration-scripts/dns-forwarding/3-to-4
@@ -1,4 +1,4 @@
-# Copyright 2023-2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/firewall/10-to-11 b/src/migration-scripts/firewall/10-to-11
index 70a170940..f608c200d 100644
--- a/src/migration-scripts/firewall/10-to-11
+++ b/src/migration-scripts/firewall/10-to-11
@@ -1,4 +1,4 @@
-# Copyright 2023-2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
@@ -36,10 +36,57 @@
# set firewall [ipv4 | ipv6] input filter rule <5,10,15,...> action jump
# set firewall [ipv4 | ipv6] input filter rule <5,10,15,...> jump-target <name>
+# T8281: Normalize firewall rule network prefixes for source and destination address
+#
+# Fixes invalid/non-canonical prefixes like:
+# 10.10.10.1/30 -> 10.10.10.0/30
+# 2001:db8::1/64 -> 2001:db8::/64
+#
+# Only "source address" and "destination address" are rewritten.
+
+from ipaddress import ip_network
from vyos.configtree import ConfigTree
base = ['firewall']
+
+def normalize_address(config: ConfigTree, path: list[str]):
+ if not config.exists(path):
+ return
+
+ def normalize(value: str) -> str | None:
+ if '/' not in value:
+ return None
+
+ is_except = value.startswith('!')
+ if is_except:
+ value = value.lstrip('!')
+
+ try:
+ new_value = str(ip_network(value, strict=False))
+ except ValueError:
+ return None
+
+ return f'!{new_value}' if is_except else new_value
+
+ value = config.return_value(path)
+ if value:
+ normalized = normalize(value)
+ if normalized and normalized != value:
+ config.set(path, value=normalized)
+
+
+def migrate_ruleset(config: ConfigTree, ruleset_base: list[str]):
+ if not config.exists(ruleset_base + ['rule']):
+ return
+
+ for rule_id in config.list_nodes(ruleset_base + ['rule']):
+ rule_base = ruleset_base + ['rule', rule_id]
+
+ for direction in ['source', 'destination']:
+ normalize_address(config, rule_base + [direction, 'address'])
+
+
def migrate(config: ConfigTree) -> None:
if not config.exists(base):
# Nothing to do
@@ -185,3 +232,25 @@ def migrate(config: ConfigTree) -> None:
inp_ipv6_rule = inp_ipv6_rule + 5
config.delete(base + ['interface'])
+
+ ### Normalize/fix firewall rule network prefixes for source and destination address (T8281)
+ for family in ['ipv4', 'ipv6', 'bridge']:
+ # 1) Named rulesets:
+ # set firewall ipv4|ipv6|bridge name <ruleset> rule <id> ...
+ ruleset_base = base + [family, 'name']
+ if config.exists(ruleset_base):
+ for ruleset in config.list_nodes(ruleset_base):
+ migrate_ruleset(config, ruleset_base + [ruleset])
+
+ # 2) Hook-based rulesets:
+ # set firewall ipv4|ipv6|bridge input|output|forward filter|raw rule <id> ...
+ # set firewall ipv4|ipv6 prerouting raw rule <id> ...
+ hook_rulesets = {
+ 'input': ['filter', 'raw'],
+ 'output': ['filter', 'raw'],
+ 'forward': ['filter', 'raw'],
+ 'prerouting': ['raw'],
+ }
+ for hook, rulesets in hook_rulesets.items():
+ for ruleset in rulesets:
+ migrate_ruleset(config, base + [family, hook, ruleset])
diff --git a/src/migration-scripts/firewall/11-to-12 b/src/migration-scripts/firewall/11-to-12
index 80a74cca9..5e9e9de32 100644
--- a/src/migration-scripts/firewall/11-to-12
+++ b/src/migration-scripts/firewall/11-to-12
@@ -1,4 +1,4 @@
-# Copyright 2023-2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
@@ -13,7 +13,7 @@
# You should have received a copy of the GNU Lesser General Public License
# along with this library. If not, see <http://www.gnu.org/licenses/>.
-# T5681: Firewall re-writing. Simplify cli when mathcing interface
+# T5681: Firewall re-writing. Simplify cli when matching interface
# From
# set firewall ... rule <rule> [inbound-interface | outboubd-interface] interface-name <iface>
# set firewall ... rule <rule> [inbound-interface | outboubd-interface] interface-group <iface_group>
diff --git a/src/migration-scripts/firewall/12-to-13 b/src/migration-scripts/firewall/12-to-13
index d7b801cd3..58c4e864a 100644
--- a/src/migration-scripts/firewall/12-to-13
+++ b/src/migration-scripts/firewall/12-to-13
@@ -1,4 +1,4 @@
-# Copyright 2023-2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/firewall/13-to-14 b/src/migration-scripts/firewall/13-to-14
index 723b0aea2..dbd585584 100644
--- a/src/migration-scripts/firewall/13-to-14
+++ b/src/migration-scripts/firewall/13-to-14
@@ -1,4 +1,4 @@
-# Copyright 2023-2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/firewall/14-to-15 b/src/migration-scripts/firewall/14-to-15
index e4a2aaee4..692b4d949 100644
--- a/src/migration-scripts/firewall/14-to-15
+++ b/src/migration-scripts/firewall/14-to-15
@@ -1,4 +1,4 @@
-# Copyright 2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
@@ -13,7 +13,7 @@
# You should have received a copy of the GNU Lesser General Public License
# along with this library. If not, see <http://www.gnu.org/licenses/>.
-# T5535: Migrate <set system ip disable-directed-broadcast> to <set firewall global-options directed-broadcas [enable|disable]
+# T5535: Migrate <set system ip disable-directed-broadcast> to <set firewall global-options directed-broadcast [enable|disable]
from vyos.configtree import ConfigTree
diff --git a/src/migration-scripts/firewall/15-to-16 b/src/migration-scripts/firewall/15-to-16
index 8e28bba6f..1eac943ba 100644
--- a/src/migration-scripts/firewall/15-to-16
+++ b/src/migration-scripts/firewall/15-to-16
@@ -1,6 +1,6 @@
#!/usr/bin/env python3
#
-# Copyright (C) 2022-2024 VyOS maintainers and contributors
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This program is free software; you can redistribute it and/or modify
# it under the terms of the GNU General Public License version 2 or later as
diff --git a/src/migration-scripts/firewall/16-to-17 b/src/migration-scripts/firewall/16-to-17
index ad0706f04..e0582aeab 100644
--- a/src/migration-scripts/firewall/16-to-17
+++ b/src/migration-scripts/firewall/16-to-17
@@ -1,4 +1,4 @@
-# Copyright (C) 2024 VyOS maintainers and contributors
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This program is free software; you can redistribute it and/or modify
# it under the terms of the GNU General Public License version 2 or later as
diff --git a/src/migration-scripts/firewall/17-to-18 b/src/migration-scripts/firewall/17-to-18
index 34ce6aa07..6cde20870 100755
--- a/src/migration-scripts/firewall/17-to-18
+++ b/src/migration-scripts/firewall/17-to-18
@@ -1,4 +1,4 @@
-# Copyright (C) 2024-2025 VyOS maintainers and contributors
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/firewall/18-to-19 b/src/migration-scripts/firewall/18-to-19
new file mode 100644
index 000000000..bcc4a482b
--- /dev/null
+++ b/src/migration-scripts/firewall/18-to-19
@@ -0,0 +1,35 @@
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
+#
+# This library is free software; you can redistribute it and/or
+# modify it under the terms of the GNU Lesser General Public
+# License as published by the Free Software Foundation; either
+# version 2.1 of the License, or (at your option) any later version.
+#
+# This library is distributed in the hope that it will be useful,
+# but WITHOUT ANY WARRANTY; without even the implied warranty of
+# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
+# Lesser General Public License for more details.
+#
+# You should have received a copy of the GNU Lesser General Public License
+# along with this library. If not, see <http://www.gnu.org/licenses/>.
+
+# From
+# set firewall global-options apply-to-bridged-traffic invalid-connections
+# To
+# set firewall global-options apply-to-bridged-traffic accept-invalid ethernet-type <ethertype>
+
+from vyos.configtree import ConfigTree
+
+base = ['firewall', 'global-options', 'apply-to-bridged-traffic']
+
+def migrate(config: ConfigTree) -> None:
+ if not config.exists(base + ['invalid-connections']):
+ # Nothing to do
+ return
+
+ ether_types = ['dhcp', 'arp', 'pppoe-discovery', 'pppoe', '802.1q', '802.1ad', 'wol']
+
+ for ether_type in ether_types:
+ config.set(base + ['accept-invalid', 'ethernet-type'], value=ether_type, replace=False)
+
+ config.delete(base + ['invalid-connections'])
diff --git a/src/migration-scripts/firewall/19-to-20 b/src/migration-scripts/firewall/19-to-20
new file mode 100644
index 000000000..c0ef5e127
--- /dev/null
+++ b/src/migration-scripts/firewall/19-to-20
@@ -0,0 +1,100 @@
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
+#
+# This library is free software; you can redistribute it and/or
+# modify it under the terms of the GNU Lesser General Public
+# License as published by the Free Software Foundation; either
+# version 2.1 of the License, or (at your option) any later version.
+#
+# This library is distributed in the hope that it will be useful,
+# but WITHOUT ANY WARRANTY; without even the implied warranty of
+# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
+# Lesser General Public License for more details.
+#
+# You should have received a copy of the GNU Lesser General Public License
+# along with this library. If not, see <http://www.gnu.org/licenses/>.
+
+# T7366: Firewall rules allow empty nodes
+# When configuring the firewall, many nodes are accepted with empty values,
+# which are not parsed into rules.
+
+# Very few of these have subsequent error handling. Some should be obvious
+# to the user that a value is required, like 'inbound-interface' (though
+# an error should still be thrown if they're configured without children).
+
+# But some could be misunderstood and lead to an outage or wide open firewall.
+# For instance, let's say someone wanted to block all icmp. They may incorrectly
+# configure:
+
+# set firewall ipv4 input filter rule 10 action drop
+# set firewall ipv4 input filter rule 10 icmp
+
+# And this would create this rule in nftables, dropping all traffic in subsequent rules:
+
+# counter packets 0 bytes 0 drop comment "ipv4-INP-filter-10"
+
+# They could also unintentionally allow all traffic by attempting to only allow icmp in a rule.
+
+import json
+
+from vyos.configtree import ConfigTree
+from vyos.utils.dict import dict_search_args
+
+firewall_base = ['firewall']
+
+def migrate(config: ConfigTree) -> None:
+ if not config.exists(firewall_base):
+ # Nothing to do
+ return
+
+ firewall_dict = json.loads(config.to_json()).get('firewall')
+
+ is_empty_list = []
+ is_empty_list.append([
+ ['add-address-to-group'],
+ ['connection-status'],
+ ['destination', 'group'],
+ ['destination', 'geoip'],
+ ['destination'],
+ ['fragment'],
+ ['gre', 'flags'],
+ ['gre'],
+ ['hop-limit'],
+ ['icmp'],
+ ['icmpv6'],
+ ['inbound-interface'],
+ ['ipsec'],
+ ['limit'],
+ ['log-options'],
+ ['outbound-interface'],
+ ['set'],
+ ['source', 'group'],
+ ['source', 'geoip'],
+ ['source'],
+ ['tcp', 'flags'],
+ ['tcp'],
+ ['time'],
+ ['ttl'],
+ ['vlan']
+ ])
+
+ for family in ['ipv4', 'ipv6', 'bridge']:
+ if family in firewall_dict:
+ for chain in ['name','forward','input','output', 'prerouting']:
+ if chain in firewall_dict[family]:
+ for priority, priority_conf in firewall_dict[family][chain].items():
+ if 'rule' in priority_conf:
+ for rule_id, rule_conf in priority_conf['rule'].items():
+ node_deleted_list = []
+ for node in is_empty_list[0]:
+ if dict_search_args(rule_conf, *node) == {}:
+ if len(node) == 1:
+ if node not in node_deleted_list:
+ config.delete(firewall_base + [family, chain, priority, 'rule', rule_id, node[0]])
+ else:
+ del firewall_dict[family][chain][priority]['rule'][rule_id][node[0]][node[1]]
+
+ if dict_search_args(rule_conf, node[0]) == {}:
+ config.delete(firewall_base + [family, chain, priority, 'rule', rule_id, node[0]])
+ node_deleted_list.append([node[0]])
+ else:
+ config.delete(firewall_base + [family, chain, priority, 'rule', rule_id, node[0], node[1]])
diff --git a/src/migration-scripts/firewall/5-to-6 b/src/migration-scripts/firewall/5-to-6
index d01684787..49348a620 100644
--- a/src/migration-scripts/firewall/5-to-6
+++ b/src/migration-scripts/firewall/5-to-6
@@ -1,4 +1,4 @@
-# Copyright 2021-2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/firewall/6-to-7 b/src/migration-scripts/firewall/6-to-7
index 1afbc780b..db83497cd 100644
--- a/src/migration-scripts/firewall/6-to-7
+++ b/src/migration-scripts/firewall/6-to-7
@@ -1,4 +1,4 @@
-# Copyright 2021-2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
@@ -92,6 +92,24 @@ icmpv6_translations = {
v4_groups = ["address-group", "network-group", "port-group"]
v6_groups = ["ipv6-address-group", "ipv6-network-group", "port-group"]
+valid_group_name_pattern = re.compile(r'^[A-Za-z0-9_.-]+$')
+invalid_group_name_pattern = re.compile(r'[^A-Za-z0-9_.-]')
+
+def is_valid_group_name(name: str) -> bool:
+ return bool(valid_group_name_pattern.match(name))
+
+def sanitize_group_name(name: str) -> str:
+ """Function to sanitize group name by replacing invalid characters"""
+ return invalid_group_name_pattern.sub('_', name)
+
+def get_unique_group_name(config: ConfigTree, path: list[str], name: str) -> str:
+ """Function to generate a unique group name if the proposed name already exists"""
+
+ new_name = sanitize_group_name(name)
+ while config.exists(path + [new_name]):
+ new_name = f'{new_name}_'
+ return new_name
+
def migrate(config: ConfigTree) -> None:
if not config.exists(base):
# Nothing to do
@@ -108,16 +126,13 @@ def migrate(config: ConfigTree) -> None:
if config.exists(name_description):
tmp = config.return_value(name_description)
config.set(name_description, value=tmp[:max_len_description])
- if '+' in group_name:
- replacement_string = "_"
+
+ if not is_valid_group_name(group_name):
if group_type in v4_groups and not v4_found:
v4_found = True
if group_type in v6_groups and not v6_found:
v6_found = True
- new_group_name = group_name.replace('+', replacement_string)
- while config.exists(base + ['group', group_type, new_group_name]):
- replacement_string = replacement_string + "_"
- new_group_name = group_name.replace('+', replacement_string)
+ new_group_name = get_unique_group_name(config, base + ['group', group_type], group_name)
translated_dict[group_name] = new_group_name
config.copy(base + ['group', group_type, group_name], base + ['group', group_type, new_group_name])
config.delete(base + ['group', group_type, group_name])
@@ -185,17 +200,25 @@ def migrate(config: ConfigTree) -> None:
if config.exists(base + ['name', name, 'rule', rule, direction, 'group']) and v4_found:
for group_type in config.list_nodes(base + ['name', name, 'rule', rule, direction, 'group']):
group_name = config.return_value(base + ['name', name, 'rule', rule, direction, 'group', group_type])
- if '+' in group_name:
- if group_name[0] == "!":
- new_group_name = "!" + translated_dict[group_name[1:]]
+
+ translated_group_name = group_name[1:] if group_name.startswith('!') else group_name
+ if translated_group_name in translated_dict:
+ if group_name.startswith('!'):
+ new_group_name = '!' + translated_dict[translated_group_name]
else:
- new_group_name = translated_dict[group_name]
+ new_group_name = translated_dict[translated_group_name]
config.set(base + ['name', name, 'rule', rule, direction, 'group', group_type], value=new_group_name)
pg_base = base + ['name', name, 'rule', rule, direction, 'group', 'port-group']
proto_base = base + ['name', name, 'rule', rule, 'protocol']
- if config.exists(pg_base) and not config.exists(proto_base):
- config.set(proto_base, value='tcp_udp')
+ if config.exists(pg_base):
+ if config.exists(proto_base):
+ proto_name = config.return_value(proto_base)
+ set_as_tcp_udp = proto_name == 'all'
+ else:
+ set_as_tcp_udp = False
+ if set_as_tcp_udp:
+ config.set(proto_base, value='tcp_udp')
if '+' in name:
replacement_string = "_"
@@ -282,17 +305,25 @@ def migrate(config: ConfigTree) -> None:
if config.exists(base + ['ipv6-name', name, 'rule', rule, direction, 'group']) and v6_found:
for group_type in config.list_nodes(base + ['ipv6-name', name, 'rule', rule, direction, 'group']):
group_name = config.return_value(base + ['ipv6-name', name, 'rule', rule, direction, 'group', group_type])
- if '+' in group_name:
- if group_name[0] == "!":
- new_group_name = "!" + translated_dict[group_name[1:]]
+
+ translated_group_name = group_name[1:] if group_name.startswith('!') else group_name
+ if translated_group_name in translated_dict:
+ if group_name.startswith('!'):
+ new_group_name = '!' + translated_dict[translated_group_name]
else:
- new_group_name = translated_dict[group_name]
+ new_group_name = translated_dict[translated_group_name]
config.set(base + ['ipv6-name', name, 'rule', rule, direction, 'group', group_type], value=new_group_name)
pg_base = base + ['ipv6-name', name, 'rule', rule, direction, 'group', 'port-group']
proto_base = base + ['ipv6-name', name, 'rule', rule, 'protocol']
- if config.exists(pg_base) and not config.exists(proto_base):
- config.set(proto_base, value='tcp_udp')
+ if config.exists(pg_base):
+ if config.exists(proto_base):
+ proto_name = config.return_value(proto_base)
+ set_as_tcp_udp = proto_name == 'all'
+ else:
+ set_as_tcp_udp = False
+ if set_as_tcp_udp:
+ config.set(proto_base, value='tcp_udp')
if '+' in name:
replacement_string = "_"
diff --git a/src/migration-scripts/firewall/7-to-8 b/src/migration-scripts/firewall/7-to-8
index b8bcc52cc..80303849e 100644
--- a/src/migration-scripts/firewall/7-to-8
+++ b/src/migration-scripts/firewall/7-to-8
@@ -1,4 +1,4 @@
-# Copyright 2022-2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/firewall/8-to-9 b/src/migration-scripts/firewall/8-to-9
index 3c9e84662..916000387 100644
--- a/src/migration-scripts/firewall/8-to-9
+++ b/src/migration-scripts/firewall/8-to-9
@@ -1,4 +1,4 @@
-# Copyright 2022-2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/firewall/9-to-10 b/src/migration-scripts/firewall/9-to-10
index 306a53a86..57970e8ab 100644
--- a/src/migration-scripts/firewall/9-to-10
+++ b/src/migration-scripts/firewall/9-to-10
@@ -1,4 +1,4 @@
-# Copyright 2023-2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/flow-accounting/0-to-1 b/src/migration-scripts/flow-accounting/0-to-1
index 77670e3ef..af4c6cbe6 100644
--- a/src/migration-scripts/flow-accounting/0-to-1
+++ b/src/migration-scripts/flow-accounting/0-to-1
@@ -1,4 +1,4 @@
-# Copyright 2021-2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/flow-accounting/1-to-2 b/src/migration-scripts/flow-accounting/1-to-2
index 5ffb1eec8..c1a48274e 100644
--- a/src/migration-scripts/flow-accounting/1-to-2
+++ b/src/migration-scripts/flow-accounting/1-to-2
@@ -1,4 +1,4 @@
-# Copyright 2021-2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/flow-accounting/2-to-3 b/src/migration-scripts/flow-accounting/2-to-3
new file mode 100644
index 000000000..48292fc1d
--- /dev/null
+++ b/src/migration-scripts/flow-accounting/2-to-3
@@ -0,0 +1,65 @@
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
+#
+# This library is free software; you can redistribute it and/or
+# modify it under the terms of the GNU Lesser General Public
+# License as published by the Free Software Foundation; either
+# version 2.1 of the License, or (at your option) any later version.
+#
+# This library is distributed in the hope that it will be useful,
+# but WITHOUT ANY WARRANTY; without even the implied warranty of
+# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
+# Lesser General Public License for more details.
+#
+# You should have received a copy of the GNU Lesser General Public License
+# along with this library. If not, see <http://www.gnu.org/licenses/>.
+
+# migrate from pmacct to ipt-NETFLOW:
+# Remove 'timeout' subtree, 'buffer-size', 'disable-imt', 'packet-length' and
+# 'syslog-facility' from 'system flow-accounting'
+#
+# Move "system flow-accounting interface" to "system flow-accounting netflow interface"
+#
+# Remove "system flow-accounting source" and add it to each server
+# under "system flow-accounting netflow server SERVER source-address"
+
+
+from vyos.configtree import ConfigTree
+
+base = ['system', 'flow-accounting']
+remove_keys = [
+ ['buffer-size'],
+ ['disable-imt'],
+ ['netflow', 'timeout'],
+ ['packet-length'],
+ ['syslog-facility'],
+]
+
+def migrate(config: ConfigTree) -> None:
+ if not config.exists(base):
+ # Nothing to do
+ return
+
+ # Remove not needed pmacct fields
+ for k in remove_keys:
+ p = base + k
+ if config.exists(p):
+ config.delete(p)
+
+ # Move "system flow-accounting interface" -> "system flow-accounting netflow interface"
+ if config.exists(base + ['interface']):
+ config.copy(base + ['interface'], base + ['netflow', 'interface'])
+ config.delete(base + ['interface'])
+
+ # Remove old "source-address", add it to each server as "source-address"
+ source_prev_path = base + ['netflow', 'source-address']
+ if config.exists(source_prev_path):
+ source_value = config.return_value(source_prev_path)
+ config.delete(source_prev_path)
+
+ # So we loose 'source-address' value if there are no servers
+ # configured, but it is not valid configuration if there
+ # is no server, so it shouldn't be a problem
+ if config.exists(base + ['netflow', 'server']):
+ path = base + ['netflow', 'server']
+ for server in config.list_nodes(path):
+ config.set(path + [server, 'source-address'], source_value)
diff --git a/src/migration-scripts/https/0-to-1 b/src/migration-scripts/https/0-to-1
index 52fe3f2ad..c39f5d15b 100644
--- a/src/migration-scripts/https/0-to-1
+++ b/src/migration-scripts/https/0-to-1
@@ -1,4 +1,4 @@
-# Copyright 202-2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/https/1-to-2 b/src/migration-scripts/https/1-to-2
index dad7ac1f0..708b7c919 100644
--- a/src/migration-scripts/https/1-to-2
+++ b/src/migration-scripts/https/1-to-2
@@ -1,4 +1,4 @@
-# Copyright 2020-2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/https/2-to-3 b/src/migration-scripts/https/2-to-3
index 1125caebf..9efaf840a 100644
--- a/src/migration-scripts/https/2-to-3
+++ b/src/migration-scripts/https/2-to-3
@@ -1,4 +1,4 @@
-# Copyright 2021-2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/https/3-to-4 b/src/migration-scripts/https/3-to-4
index c01236cc6..be9bb17ff 100644
--- a/src/migration-scripts/https/3-to-4
+++ b/src/migration-scripts/https/3-to-4
@@ -1,4 +1,4 @@
-# Copyright 2022-2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/https/4-to-5 b/src/migration-scripts/https/4-to-5
index 0f1c7901f..a99e8d8a5 100644
--- a/src/migration-scripts/https/4-to-5
+++ b/src/migration-scripts/https/4-to-5
@@ -1,4 +1,4 @@
-# Copyright 2023-2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/https/5-to-6 b/src/migration-scripts/https/5-to-6
index 6ef6976b6..f51b35972 100644
--- a/src/migration-scripts/https/5-to-6
+++ b/src/migration-scripts/https/5-to-6
@@ -1,4 +1,4 @@
-# Copyright 2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/https/6-to-7 b/src/migration-scripts/https/6-to-7
index 571f3b6ae..36ac3d1d9 100644
--- a/src/migration-scripts/https/6-to-7
+++ b/src/migration-scripts/https/6-to-7
@@ -1,4 +1,4 @@
-# Copyright 2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/ids/0-to-1 b/src/migration-scripts/ids/0-to-1
index 1b963e839..108f68399 100644
--- a/src/migration-scripts/ids/0-to-1
+++ b/src/migration-scripts/ids/0-to-1
@@ -1,4 +1,4 @@
-# Copyright 2022-2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/ids/1-to-2 b/src/migration-scripts/ids/1-to-2
new file mode 100644
index 000000000..6f93f8b45
--- /dev/null
+++ b/src/migration-scripts/ids/1-to-2
@@ -0,0 +1,30 @@
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
+#
+# This library is free software; you can redistribute it and/or
+# modify it under the terms of the GNU Lesser General Public
+# License as published by the Free Software Foundation; either
+# version 2.1 of the License, or (at your option) any later version.
+#
+# This library is distributed in the hope that it will be useful,
+# but WITHOUT ANY WARRANTY; without even the implied warranty of
+# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
+# Lesser General Public License for more details.
+#
+# You should have received a copy of the GNU Lesser General Public License
+# along with this library. If not, see <http://www.gnu.org/licenses/>.
+
+# T: Migrate threshold and add new threshold types
+
+from vyos.configtree import ConfigTree
+
+# The old 'service ids' path was only used for FastNetMon
+# Suricata is in 'service suricata',
+# so this isn't an overreach
+base = ['service', 'ids']
+
+def migrate(config: ConfigTree) -> None:
+ if not config.exists(base):
+ # Nothing to do
+ return
+ else:
+ config.delete(base)
diff --git a/src/migration-scripts/interfaces/0-to-1 b/src/migration-scripts/interfaces/0-to-1
index 7c135e76e..c4417c4ca 100644
--- a/src/migration-scripts/interfaces/0-to-1
+++ b/src/migration-scripts/interfaces/0-to-1
@@ -1,4 +1,4 @@
-# Copyright 2019-2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
@@ -20,6 +20,8 @@
from vyos.configtree import ConfigTree
+base = ['interfaces', 'bridge']
+
def migrate_bridge(config, tree, intf):
# check if bridge-group exists
tree_bridge = tree + ['bridge-group']
@@ -49,8 +51,6 @@ def migrate_bridge(config, tree, intf):
def migrate(config: ConfigTree) -> None:
- base = ['interfaces', 'bridge']
-
if not config.exists(base):
# Nothing to do
return
diff --git a/src/migration-scripts/interfaces/1-to-2 b/src/migration-scripts/interfaces/1-to-2
index ebf02b028..d0abb4466 100644
--- a/src/migration-scripts/interfaces/1-to-2
+++ b/src/migration-scripts/interfaces/1-to-2
@@ -1,4 +1,4 @@
-# Copyright 2019-2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
@@ -34,7 +34,7 @@ def migrate(config: ConfigTree) -> None:
if config.exists(['interfaces', 'ethernet', intf, 'bond-group']):
# get configured bond interface
bond = config.return_value(['interfaces', 'ethernet', intf, 'bond-group'])
- # delete old interface asigned (nested) bond group
+ # delete old interface assigned (nested) bond group
config.delete(['interfaces', 'ethernet', intf, 'bond-group'])
# create new bond member interface
config.set(base + [bond, 'member', 'interface'], value=intf, replace=False)
@@ -42,7 +42,7 @@ def migrate(config: ConfigTree) -> None:
#
# some combinations were allowed in the past from a CLI perspective
# but the kernel overwrote them - remove from CLI to not confuse the users.
- # In addition new consitency checks are in place so users can't repeat the
+ # In addition new consistency checks are in place so users can't repeat the
# mistake. One of those nice issues is https://vyos.dev/T532
for bond in config.list_nodes(base):
if config.exists(base + [bond, 'arp-monitor', 'interval']) and config.exists(base + [bond, 'mode']):
diff --git a/src/migration-scripts/interfaces/10-to-11 b/src/migration-scripts/interfaces/10-to-11
index 8a562f2d0..2e8d2d099 100644
--- a/src/migration-scripts/interfaces/10-to-11
+++ b/src/migration-scripts/interfaces/10-to-11
@@ -1,4 +1,4 @@
-# Copyright 2020-2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/interfaces/11-to-12 b/src/migration-scripts/interfaces/11-to-12
index 132cecbb7..e1bd496c9 100644
--- a/src/migration-scripts/interfaces/11-to-12
+++ b/src/migration-scripts/interfaces/11-to-12
@@ -1,4 +1,4 @@
-# Copyright 2020-2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/interfaces/12-to-13 b/src/migration-scripts/interfaces/12-to-13
index 585deb898..abd01ceb8 100644
--- a/src/migration-scripts/interfaces/12-to-13
+++ b/src/migration-scripts/interfaces/12-to-13
@@ -1,4 +1,4 @@
-# Copyright 2020-2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/interfaces/13-to-14 b/src/migration-scripts/interfaces/13-to-14
index 45d8e3b5f..c8b686ee9 100644
--- a/src/migration-scripts/interfaces/13-to-14
+++ b/src/migration-scripts/interfaces/13-to-14
@@ -1,4 +1,4 @@
-# Copyright 2020-2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/interfaces/14-to-15 b/src/migration-scripts/interfaces/14-to-15
index d45d59bba..e48371539 100644
--- a/src/migration-scripts/interfaces/14-to-15
+++ b/src/migration-scripts/interfaces/14-to-15
@@ -1,4 +1,4 @@
-# Copyright 2020-2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/interfaces/15-to-16 b/src/migration-scripts/interfaces/15-to-16
index c9abdb5f8..44768356c 100644
--- a/src/migration-scripts/interfaces/15-to-16
+++ b/src/migration-scripts/interfaces/15-to-16
@@ -1,4 +1,4 @@
-# Copyright 2020-2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/interfaces/16-to-17 b/src/migration-scripts/interfaces/16-to-17
index 7d241ac68..e3161f178 100644
--- a/src/migration-scripts/interfaces/16-to-17
+++ b/src/migration-scripts/interfaces/16-to-17
@@ -1,4 +1,4 @@
-# Copyright 2020-2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/interfaces/17-to-18 b/src/migration-scripts/interfaces/17-to-18
index f45695a88..a9bf8174c 100644
--- a/src/migration-scripts/interfaces/17-to-18
+++ b/src/migration-scripts/interfaces/17-to-18
@@ -1,4 +1,4 @@
-# Copyright 2020-2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/interfaces/18-to-19 b/src/migration-scripts/interfaces/18-to-19
index ae1a07adb..2b54d5cdc 100644
--- a/src/migration-scripts/interfaces/18-to-19
+++ b/src/migration-scripts/interfaces/18-to-19
@@ -1,4 +1,4 @@
-# Copyright 2021-2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/interfaces/19-to-20 b/src/migration-scripts/interfaces/19-to-20
index 7ee6302e2..7262bdad8 100644
--- a/src/migration-scripts/interfaces/19-to-20
+++ b/src/migration-scripts/interfaces/19-to-20
@@ -1,4 +1,4 @@
-# Copyright 2021-2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/interfaces/2-to-3 b/src/migration-scripts/interfaces/2-to-3
index 695dcbf7a..bb59eb3ce 100644
--- a/src/migration-scripts/interfaces/2-to-3
+++ b/src/migration-scripts/interfaces/2-to-3
@@ -1,4 +1,4 @@
-# Copyright 2019-2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/interfaces/20-to-21 b/src/migration-scripts/interfaces/20-to-21
index 0b6895177..73c98957c 100644
--- a/src/migration-scripts/interfaces/20-to-21
+++ b/src/migration-scripts/interfaces/20-to-21
@@ -1,4 +1,4 @@
-# Copyright 2021-2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/interfaces/21-to-22 b/src/migration-scripts/interfaces/21-to-22
index 046eb10c6..a5feffce3 100644
--- a/src/migration-scripts/interfaces/21-to-22
+++ b/src/migration-scripts/interfaces/21-to-22
@@ -1,4 +1,4 @@
-# Copyright 2021-2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/interfaces/22-to-23 b/src/migration-scripts/interfaces/22-to-23
index 31f7fa2ff..401d5db0e 100644
--- a/src/migration-scripts/interfaces/22-to-23
+++ b/src/migration-scripts/interfaces/22-to-23
@@ -1,4 +1,4 @@
-# Copyright 2021-2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/interfaces/23-to-24 b/src/migration-scripts/interfaces/23-to-24
index b72ceee49..c534628ce 100644
--- a/src/migration-scripts/interfaces/23-to-24
+++ b/src/migration-scripts/interfaces/23-to-24
@@ -1,4 +1,4 @@
-# Copyright 2021-2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/interfaces/24-to-25 b/src/migration-scripts/interfaces/24-to-25
index 9f8cc80ec..7386507f9 100644
--- a/src/migration-scripts/interfaces/24-to-25
+++ b/src/migration-scripts/interfaces/24-to-25
@@ -1,4 +1,4 @@
-# Copyright 2021-2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/interfaces/25-to-26 b/src/migration-scripts/interfaces/25-to-26
index 7a4032d10..1f10e3dca 100644
--- a/src/migration-scripts/interfaces/25-to-26
+++ b/src/migration-scripts/interfaces/25-to-26
@@ -1,4 +1,4 @@
-# Copyright 2021-2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
@@ -29,6 +29,7 @@ from vyos.pki import encode_dh_parameters
from vyos.pki import encode_private_key
from vyos.pki import verify_crl
from vyos.utils.process import run
+from vyos.utils.file import read_file
def wrapped_pem_to_config_value(pem):
out = []
@@ -38,20 +39,28 @@ def wrapped_pem_to_config_value(pem):
out.append(line)
return "".join(out)
-def read_file_for_pki(config_auth_path):
- full_path = os.path.join(AUTH_DIR, config_auth_path)
- output = None
+def read_auth_file(config_auth_path):
+ full_path = os.path.normpath(os.path.join(AUTH_DIR, config_auth_path))
+
+ # If the file is not found under `/config/auth`, it may be because the `/config`
+ # partition has not been bind-mounted yet during early boot migration execution.
+ # Fall back to the equivalent path under `/opt/vyatta/etc/config/auth` which
+ # is accessible at all boot stages.
+ if not os.path.isfile(full_path) and full_path.startswith(f'{AUTH_DIR}/'):
+ full_path = AUTH_DIR_FALLBACK + full_path[len(AUTH_DIR): ]
if os.path.isfile(full_path):
if not os.access(full_path, os.R_OK):
- run(f'sudo chmod 644 {full_path}')
+ run(['sudo', 'chmod', '644', full_path])
+
+ return read_file(full_path)
- with open(full_path, 'r') as f:
- output = f.read()
+ return None
- return output
AUTH_DIR = '/config/auth'
+AUTH_DIR_FALLBACK = '/opt/vyatta/etc/config/auth'
+
pki_base = ['pki']
def migrate(config: ConfigTree) -> None:
@@ -69,13 +78,30 @@ def migrate(config: ConfigTree) -> None:
config.set_tag(pki_base + ['openvpn', 'shared-secret'])
key_file = config.return_value(base + [interface, 'shared-secret-key-file'])
- key = read_file_for_pki(key_file)
+ key = read_auth_file(key_file)
key_pki_name = f'{pki_name}_shared'
if key:
- config.set(pki_base + ['openvpn', 'shared-secret', key_pki_name, 'key'], value=wrapped_pem_to_config_value(key))
- config.set(pki_base + ['openvpn', 'shared-secret', key_pki_name, 'version'], value='1')
- config.set(base + [interface, 'shared-secret-key'], value=key_pki_name)
+ # Check if OpenVPN shared-secret already exists - no need to check node
+ # existence as it is always created above when entering this context
+ secret_exists = None
+ for secret_name in config.list_nodes(pki_base + ['openvpn', 'shared-secret']):
+ secret_path = pki_base + ['openvpn', 'shared-secret', secret_name, 'key']
+ if not config.exists(secret_path):
+ continue
+
+ secret = config.return_value(secret_path)
+ # Check for duplicate cert/key - and re-use if possible
+ if secret == wrapped_pem_to_config_value(key):
+ secret_exists = secret_name
+ break
+
+ if secret_exists:
+ config.set(base + [interface, 'shared-secret-key'], value=secret_exists)
+ else:
+ config.set(pki_base + ['openvpn', 'shared-secret', key_pki_name, 'key'], value=wrapped_pem_to_config_value(key))
+ config.set(pki_base + ['openvpn', 'shared-secret', key_pki_name, 'version'], value='1')
+ config.set(base + [interface, 'shared-secret-key'], value=key_pki_name)
else:
print(f'Failed to migrate shared-secret-key on openvpn interface {interface}')
@@ -90,13 +116,30 @@ def migrate(config: ConfigTree) -> None:
config.set_tag(pki_base + ['openvpn', 'shared-secret'])
key_file = config.return_value(base + [interface, 'tls', 'auth-file'])
- key = read_file_for_pki(key_file)
+ key = read_auth_file(key_file)
key_pki_name = f'{pki_name}_auth'
if key:
- config.set(pki_base + ['openvpn', 'shared-secret', key_pki_name, 'key'], value=wrapped_pem_to_config_value(key))
- config.set(pki_base + ['openvpn', 'shared-secret', key_pki_name, 'version'], value='1')
- config.set(base + [interface, 'tls', 'auth-key'], value=key_pki_name)
+ # Check if OpenVPN auth key already exists - no need to check node
+ # existence as it is always created above when entering this context
+ secret_exists = None
+ for secret_name in config.list_nodes(pki_base + ['openvpn', 'shared-secret']):
+ secret_path = pki_base + ['openvpn', 'shared-secret', secret_name, 'key']
+ if not config.exists(secret_path):
+ continue
+
+ secret = config.return_value(secret_path)
+ # Check for duplicate cert/key - and re-use if possible
+ if secret == wrapped_pem_to_config_value(key):
+ secret_exists = secret_name
+ break
+
+ if secret_exists:
+ config.set(base + [interface, 'tls', 'auth-key'], value=secret_exists)
+ else:
+ config.set(pki_base + ['openvpn', 'shared-secret', key_pki_name, 'key'], value=wrapped_pem_to_config_value(key))
+ config.set(pki_base + ['openvpn', 'shared-secret', key_pki_name, 'version'], value='1')
+ config.set(base + [interface, 'tls', 'auth-key'], value=key_pki_name)
else:
print(f'Failed to migrate auth-key on openvpn interface {interface}')
@@ -108,13 +151,30 @@ def migrate(config: ConfigTree) -> None:
config.set_tag(pki_base + ['openvpn', 'shared-secret'])
key_file = config.return_value(base + [interface, 'tls', 'crypt-file'])
- key = read_file_for_pki(key_file)
+ key = read_auth_file(key_file)
key_pki_name = f'{pki_name}_crypt'
if key:
- config.set(pki_base + ['openvpn', 'shared-secret', key_pki_name, 'key'], value=wrapped_pem_to_config_value(key))
- config.set(pki_base + ['openvpn', 'shared-secret', key_pki_name, 'version'], value='1')
- config.set(base + [interface, 'tls', 'crypt-key'], value=key_pki_name)
+ # Check if OpenVPN auth key already exists - no need to check node
+ # existence as it is always created above when entering this context
+ secret_exists = None
+ for secret_name in config.list_nodes(pki_base + ['openvpn', 'shared-secret']):
+ secret_path = pki_base + ['openvpn', 'shared-secret', secret_name, 'key']
+ if not config.exists(secret_path):
+ continue
+
+ secret = config.return_value(secret_path)
+ # Check for duplicate cert/key - and re-use if possible
+ if secret == wrapped_pem_to_config_value(key):
+ secret_exists = secret_name
+ break
+
+ if secret_exists:
+ config.set(base + [interface, 'tls', 'crypt-key'], value=secret_exists)
+ else:
+ config.set(pki_base + ['openvpn', 'shared-secret', key_pki_name, 'key'], value=wrapped_pem_to_config_value(key))
+ config.set(pki_base + ['openvpn', 'shared-secret', key_pki_name, 'version'], value='1')
+ config.set(base + [interface, 'tls', 'crypt-key'], value=key_pki_name)
else:
print(f'Failed to migrate crypt-key on openvpn interface {interface}')
@@ -128,28 +188,41 @@ def migrate(config: ConfigTree) -> None:
config.set_tag(pki_base + ['ca'])
cert_file = config.return_value(x509_base + ['ca-cert-file'])
- cert_path = os.path.join(AUTH_DIR, cert_file)
-
- if os.path.isfile(cert_path):
- if not os.access(cert_path, os.R_OK):
- run(f'sudo chmod 644 {cert_path}')
-
- with open(cert_path, 'r') as f:
- certs_str = f.read()
- certs_data = certs_str.split(CERT_BEGIN)
- index = 1
- for cert_data in certs_data[1:]:
- cert = load_certificate(CERT_BEGIN + cert_data, wrap_tags=False)
-
- if cert:
- ca_certs[f'{pki_name}_{index}'] = cert
- cert_pem = encode_certificate(cert)
+ certs_str = read_auth_file(cert_file)
+
+ if certs_str:
+ certs_data = certs_str.split(CERT_BEGIN)
+ index = 1
+ for cert_data in certs_data[1:]:
+ cert = load_certificate(CERT_BEGIN + cert_data, wrap_tags=False)
+
+ if cert:
+ ca_certs[f'{pki_name}_{index}'] = cert
+ cert_pem = encode_certificate(cert)
+
+ # Check if CA already exists - no need to check node existence as
+ # it is always created above when entering this context
+ ca_exists = None
+ for ca_name in config.list_nodes(pki_base + ['ca']):
+ ca_cert_path = pki_base + ['ca', ca_name, 'certificate']
+ if not config.exists(ca_cert_path):
+ continue
+
+ ca_base64 = config.return_value(ca_cert_path)
+ # Check for duplicate cert/key - and re-use if possible
+ if ca_base64 == wrapped_pem_to_config_value(cert_pem):
+ ca_exists = ca_name
+ break
+
+ if ca_exists:
+ config.set(x509_base + ['ca-certificate'], value=ca_exists, replace=False)
+ else:
config.set(pki_base + ['ca', f'{pki_name}_{index}', 'certificate'], value=wrapped_pem_to_config_value(cert_pem))
config.set(x509_base + ['ca-certificate'], value=f'{pki_name}_{index}', replace=False)
- else:
- print(f'Failed to migrate CA certificate on openvpn interface {interface}')
+ else:
+ print(f'Failed to migrate CA certificate on openvpn interface {interface}')
- index += 1
+ index += 1
else:
print(f'Failed to migrate CA certificate on openvpn interface {interface}')
@@ -161,26 +234,36 @@ def migrate(config: ConfigTree) -> None:
config.set_tag(pki_base + ['ca'])
crl_file = config.return_value(x509_base + ['crl-file'])
- crl_path = os.path.join(AUTH_DIR, crl_file)
- crl = None
- crl_ca_name = None
-
- if os.path.isfile(crl_path):
- if not os.access(crl_path, os.R_OK):
- run(f'sudo chmod 644 {crl_path}')
+ crl_data = read_auth_file(crl_file)
- with open(crl_path, 'r') as f:
- crl_data = f.read()
- crl = load_crl(crl_data, wrap_tags=False)
+ crl = load_crl(crl_data, wrap_tags=False) if crl_data else None
+ crl_ca_name = None
- for ca_name, ca_cert in ca_certs.items():
- if verify_crl(crl, ca_cert):
- crl_ca_name = ca_name
- break
+ if crl:
+ for ca_name, ca_cert in ca_certs.items():
+ if verify_crl(crl, ca_cert):
+ crl_ca_name = ca_name
+ break
- if crl and crl_ca_name:
+ if crl_ca_name:
crl_pem = encode_certificate(crl)
- config.set(pki_base + ['ca', crl_ca_name, 'crl'], value=wrapped_pem_to_config_value(crl_pem))
+
+ # Check if CRL already exists - no need to check node
+ # existence as it is always created above when entering this context
+ crl_exists = None
+ for ca_name in config.list_nodes(pki_base + ['ca']):
+ crl_path = pki_base + ['ca', ca_name, 'crl']
+ if not config.exists(crl_path):
+ continue
+
+ crl_base64 = config.return_value(crl_path)
+ # Check if CRL is a duplicate and we have already imported it
+ if crl_base64 == wrapped_pem_to_config_value(crl_pem):
+ crl_exists = ca_name
+ break
+
+ if not crl_exists:
+ config.set(pki_base + ['ca', crl_ca_name, 'crl'], value=wrapped_pem_to_config_value(crl_pem))
else:
print(f'Failed to migrate CRL on openvpn interface {interface}')
@@ -192,21 +275,31 @@ def migrate(config: ConfigTree) -> None:
config.set_tag(pki_base + ['certificate'])
cert_file = config.return_value(x509_base + ['cert-file'])
- cert_path = os.path.join(AUTH_DIR, cert_file)
- cert = None
-
- if os.path.isfile(cert_path):
- if not os.access(cert_path, os.R_OK):
- run(f'sudo chmod 644 {cert_path}')
+ cert_data = read_auth_file(cert_file)
- with open(cert_path, 'r') as f:
- cert_data = f.read()
- cert = load_certificate(cert_data, wrap_tags=False)
+ cert = load_certificate(cert_data, wrap_tags=False) if cert_data else None
if cert:
cert_pem = encode_certificate(cert)
- config.set(pki_base + ['certificate', pki_name, 'certificate'], value=wrapped_pem_to_config_value(cert_pem))
- config.set(x509_base + ['certificate'], value=pki_name)
+ # Check if certificate public key already exists - no need to check node
+ # existence as it is always created above when entering this context
+ cert_exists = None
+ for cert_name in config.list_nodes(pki_base + ['certificate']):
+ cert_path = pki_base + ['certificate', cert_name, 'certificate']
+ if not config.exists(cert_path):
+ continue
+
+ cert_base64 = config.return_value(cert_path)
+ # Check for duplicate cert/key - and re-use if possible
+ if cert_base64 == wrapped_pem_to_config_value(cert_pem):
+ cert_exists = cert_name
+ break
+
+ if cert_exists:
+ config.set(x509_base + ['certificate'], value=cert_exists)
+ else:
+ config.set(pki_base + ['certificate', pki_name, 'certificate'], value=wrapped_pem_to_config_value(cert_pem))
+ config.set(x509_base + ['certificate'], value=pki_name)
else:
print(f'Failed to migrate certificate on openvpn interface {interface}')
@@ -214,20 +307,28 @@ def migrate(config: ConfigTree) -> None:
if config.exists(x509_base + ['key-file']):
key_file = config.return_value(x509_base + ['key-file'])
- key_path = os.path.join(AUTH_DIR, key_file)
- key = None
-
- if os.path.isfile(key_path):
- if not os.access(key_path, os.R_OK):
- run(f'sudo chmod 644 {key_path}')
+ key_data = read_auth_file(key_file)
- with open(key_path, 'r') as f:
- key_data = f.read()
- key = load_private_key(key_data, passphrase=None, wrap_tags=False)
+ key = load_private_key(key_data, passphrase=None, wrap_tags=False) if key_data else None
if key:
key_pem = encode_private_key(key, passphrase=None)
- config.set(pki_base + ['certificate', pki_name, 'private', 'key'], value=wrapped_pem_to_config_value(key_pem))
+ # Check if certificate public key already exists - no need to check node
+ # existence as it is always created above when entering this context
+ key_exists = None
+ for key_name in config.list_nodes(pki_base + ['certificate']):
+ key_path = pki_base + ['certificate', key_name, 'private', 'key']
+ if not config.exists(key_path):
+ continue
+
+ key_base64 = config.return_value(key_path)
+ # Check for duplicate cert/key - and re-use if possible
+ if key_base64 == wrapped_pem_to_config_value(key_pem):
+ key_exists = key_name
+ break
+
+ if not key_exists:
+ config.set(pki_base + ['certificate', pki_name, 'private', 'key'], value=wrapped_pem_to_config_value(key_pem))
else:
print(f'Failed to migrate private key on openvpn interface {interface}')
@@ -239,21 +340,32 @@ def migrate(config: ConfigTree) -> None:
config.set_tag(pki_base + ['dh'])
dh_file = config.return_value(x509_base + ['dh-file'])
- dh_path = os.path.join(AUTH_DIR, dh_file)
- dh = None
-
- if os.path.isfile(dh_path):
- if not os.access(dh_path, os.R_OK):
- run(f'sudo chmod 644 {dh_path}')
+ dh_data = read_auth_file(dh_file)
- with open(dh_path, 'r') as f:
- dh_data = f.read()
- dh = load_dh_parameters(dh_data, wrap_tags=False)
+ dh = load_dh_parameters(dh_data, wrap_tags=False) if dh_data else None
if dh:
dh_pem = encode_dh_parameters(dh)
- config.set(pki_base + ['dh', pki_name, 'parameters'], value=wrapped_pem_to_config_value(dh_pem))
- config.set(x509_base + ['dh-params'], value=pki_name)
+
+ # Check if DH parameters already exists - no need to check node existence
+ # as it is always created above when entering this context
+ dh_exists = None
+ for dh_name in config.list_nodes(pki_base + ['dh']):
+ dh_param_path = pki_base + ['dh', dh_name, 'parameters']
+ if not config.exists(dh_param_path):
+ continue
+
+ dh_base64 = config.return_value(dh_param_path)
+ # Check for duplicate cert/key - and re-use if possible
+ if dh_base64 == wrapped_pem_to_config_value(dh_pem):
+ dh_exists = dh_name
+ break
+
+ if dh_exists:
+ config.set(x509_base + ['dh-params'], value=dh_exists)
+ else:
+ config.set(pki_base + ['dh', pki_name, 'parameters'], value=wrapped_pem_to_config_value(dh_pem))
+ config.set(x509_base + ['dh-params'], value=pki_name)
else:
print(f'Failed to migrate DH parameters on openvpn interface {interface}')
@@ -270,15 +382,15 @@ def migrate(config: ConfigTree) -> None:
if config.exists(private_key_path):
key_file = config.return_value(private_key_path)
- full_key_path = f'/config/auth/wireguard/{key_file}/private.key'
+ full_key_path = f'{AUTH_DIR}/wireguard/{key_file}/private.key'
+ key_data = read_auth_file(full_key_path)
- if not os.path.exists(full_key_path):
+ if not key_data:
print(f'Could not find wireguard private key for migration on interface "{interface}"')
continue
- with open(full_key_path, 'r') as f:
- key_data = f.read().strip()
- config.set(private_key_path, value=key_data)
+ key_data = key_data.strip()
+ config.set(private_key_path, value=key_data)
for peer in config.list_nodes(base + [interface, 'peer']):
config.rename(base + [interface, 'peer', peer, 'pubkey'], 'public-key')
@@ -300,16 +412,9 @@ def migrate(config: ConfigTree) -> None:
config.set_tag(pki_base + ['ca'])
cert_file = config.return_value(x509_base + ['ca-cert-file'])
- cert_path = os.path.join(AUTH_DIR, cert_file)
- cert = None
-
- if os.path.isfile(cert_path):
- if not os.access(cert_path, os.R_OK):
- run(f'sudo chmod 644 {cert_path}')
+ cert_data = read_auth_file(cert_file)
- with open(cert_path, 'r') as f:
- cert_data = f.read()
- cert = load_certificate(cert_data, wrap_tags=False)
+ cert = load_certificate(cert_data, wrap_tags=False) if cert_data else None
if cert:
cert_pem = encode_certificate(cert)
@@ -326,16 +431,9 @@ def migrate(config: ConfigTree) -> None:
config.set_tag(pki_base + ['certificate'])
cert_file = config.return_value(x509_base + ['cert-file'])
- cert_path = os.path.join(AUTH_DIR, cert_file)
- cert = None
+ cert_data = read_auth_file(cert_file)
- if os.path.isfile(cert_path):
- if not os.access(cert_path, os.R_OK):
- run(f'sudo chmod 644 {cert_path}')
-
- with open(cert_path, 'r') as f:
- cert_data = f.read()
- cert = load_certificate(cert_data, wrap_tags=False)
+ cert = load_certificate(cert_data, wrap_tags=False) if cert_data else None
if cert:
cert_pem = encode_certificate(cert)
@@ -348,16 +446,9 @@ def migrate(config: ConfigTree) -> None:
if config.exists(x509_base + ['key-file']):
key_file = config.return_value(x509_base + ['key-file'])
- key_path = os.path.join(AUTH_DIR, key_file)
- key = None
-
- if os.path.isfile(key_path):
- if not os.access(key_path, os.R_OK):
- run(f'sudo chmod 644 {key_path}')
+ key_data = read_auth_file(key_file)
- with open(key_path, 'r') as f:
- key_data = f.read()
- key = load_private_key(key_data, passphrase=None, wrap_tags=False)
+ key = load_private_key(key_data, passphrase=None, wrap_tags=False) if key_data else None
if key:
key_pem = encode_private_key(key, passphrase=None)
diff --git a/src/migration-scripts/interfaces/26-to-27 b/src/migration-scripts/interfaces/26-to-27
index 3f58de02c..c04655da0 100644
--- a/src/migration-scripts/interfaces/26-to-27
+++ b/src/migration-scripts/interfaces/26-to-27
@@ -1,4 +1,4 @@
-# Copyright 2022-2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/interfaces/27-to-28 b/src/migration-scripts/interfaces/27-to-28
index eb9363e39..fb156a899 100644
--- a/src/migration-scripts/interfaces/27-to-28
+++ b/src/migration-scripts/interfaces/27-to-28
@@ -1,4 +1,4 @@
-# Copyright 2023-2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/interfaces/28-to-29 b/src/migration-scripts/interfaces/28-to-29
index 886d49e2c..9a2ba5757 100644
--- a/src/migration-scripts/interfaces/28-to-29
+++ b/src/migration-scripts/interfaces/28-to-29
@@ -1,4 +1,4 @@
-# Copyright 2023-2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/interfaces/29-to-30 b/src/migration-scripts/interfaces/29-to-30
index 7b32d871e..c9664e83a 100644
--- a/src/migration-scripts/interfaces/29-to-30
+++ b/src/migration-scripts/interfaces/29-to-30
@@ -1,4 +1,4 @@
-# Copyright 2023-2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/interfaces/3-to-4 b/src/migration-scripts/interfaces/3-to-4
index 4e56200e1..ed27a917b 100644
--- a/src/migration-scripts/interfaces/3-to-4
+++ b/src/migration-scripts/interfaces/3-to-4
@@ -1,4 +1,4 @@
-# Copyright 2019-2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/interfaces/30-to-31 b/src/migration-scripts/interfaces/30-to-31
index 7e509dd86..48ca063e2 100644
--- a/src/migration-scripts/interfaces/30-to-31
+++ b/src/migration-scripts/interfaces/30-to-31
@@ -1,5 +1,5 @@
#!/usr/bin/env python3
-# Copyright 2023-2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/interfaces/31-to-32 b/src/migration-scripts/interfaces/31-to-32
index 24077ed24..1c5147e6a 100644
--- a/src/migration-scripts/interfaces/31-to-32
+++ b/src/migration-scripts/interfaces/31-to-32
@@ -1,4 +1,4 @@
-# Copyright 2023-2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/interfaces/32-to-33 b/src/migration-scripts/interfaces/32-to-33
index c7b1c5b36..11b7aa58b 100644
--- a/src/migration-scripts/interfaces/32-to-33
+++ b/src/migration-scripts/interfaces/32-to-33
@@ -1,6 +1,6 @@
#!/usr/bin/env python3
#
-# Copyright (C) 2024 VyOS maintainers and contributors
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This program is free software; you can redistribute it and/or modify
# it under the terms of the GNU General Public License version 2 or later as
@@ -13,28 +13,46 @@
#
# You should have received a copy of the GNU General Public License
# along with this program. If not, see <http://www.gnu.org/licenses/>.
-#
-# T6318: WiFi country-code should be set system-wide instead of per-device
-from vyos.configtree import ConfigTree
+# T7646: restore behavior of IPv6 default route if only dhcpv6 was defined but
+# not "ipv6 address autoconf"
-base = ['interfaces', 'wireless']
+from vyos.configtree import ConfigTree
def migrate(config: ConfigTree) -> None:
- if not config.exists(base):
- # Nothing to do
- return
+ for type in config.list_nodes(['interfaces']):
+ for interface in config.list_nodes(['interfaces', type]):
+ iface_base_path = ['interfaces', type, interface]
+ dhcpv6_addr_path = iface_base_path + ['address']
+
+ if config.exists(dhcpv6_addr_path) and 'dhcpv6' in config.return_values(dhcpv6_addr_path):
+ autoconf_path = iface_base_path + ['ipv6', 'address', 'autoconf']
+ if not config.exists(autoconf_path):
+ config.set(autoconf_path)
+
+ vif_path = iface_base_path + ['vif']
+ if config.exists(vif_path):
+ for vif in config.list_nodes(vif_path):
+ vif_dhcpv6_addr_path = vif_path + [vif, 'address']
+ if config.exists(vif_dhcpv6_addr_path) and 'dhcpv6' in config.return_values(vif_dhcpv6_addr_path):
+ vif_autoconf_path = vif_path + [vif, 'ipv6', 'address', 'autoconf']
+ if not config.exists(vif_autoconf_path):
+ config.set(vif_autoconf_path)
- installed = False
- for interface in config.list_nodes(base):
- cc_path = base + [interface, 'country-code']
- if config.exists(cc_path):
- tmp = config.return_value(cc_path)
- config.delete(cc_path)
+ vif_s_path = iface_base_path + ['vif-s']
+ if config.exists(vif_s_path):
+ for vif_s in config.list_nodes(vif_s_path):
+ vif_s_dhcpv6_addr_path = vif_s_path + [vif_s, 'address']
+ if config.exists(vif_s_dhcpv6_addr_path) and 'dhcpv6' in config.return_values(vif_s_dhcpv6_addr_path):
+ vif_s_autoconf_path = vif_s_path + [vif_s, 'ipv6', 'address', 'autoconf']
+ if not config.exists(vif_s_autoconf_path):
+ config.set(vif_s_autoconf_path)
- # There can be only ONE wireless country-code per device, everything
- # else makes no sense as a WIFI router can not operate in two
- # different countries
- if not installed:
- config.set(['system', 'wireless', 'country-code'], value=tmp)
- installed = True
+ vif_c_path = iface_base_path + ['vif-s', vif_s, 'vif-c']
+ if config.exists(vif_c_path):
+ for vif_c in config.list_nodes(vif_c_path):
+ vif_c_dhcpv6_addr_path = vif_c_path + [vif_c, 'address']
+ if config.exists(vif_c_dhcpv6_addr_path) and 'dhcpv6' in config.return_values(vif_c_dhcpv6_addr_path):
+ vif_c_autoconf_path = vif_c_path + [vif_c, 'ipv6', 'address', 'autoconf']
+ if not config.exists(vif_c_autoconf_path):
+ config.set(vif_c_autoconf_path)
diff --git a/src/migration-scripts/interfaces/33-to-34 b/src/migration-scripts/interfaces/33-to-34
new file mode 100644
index 000000000..ccda04d0c
--- /dev/null
+++ b/src/migration-scripts/interfaces/33-to-34
@@ -0,0 +1,40 @@
+#!/usr/bin/env python3
+#
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
+#
+# This program is free software; you can redistribute it and/or modify
+# it under the terms of the GNU General Public License version 2 or later as
+# published by the Free Software Foundation.
+#
+# This program is distributed in the hope that it will be useful,
+# but WITHOUT ANY WARRANTY; without even the implied warranty of
+# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
+# GNU General Public License for more details.
+#
+# You should have received a copy of the GNU General Public License
+# along with this program. If not, see <http://www.gnu.org/licenses/>.
+#
+# T6318: WiFi country-code should be set system-wide instead of per-device
+
+from vyos.configtree import ConfigTree
+
+base = ['interfaces', 'wireless']
+
+def migrate(config: ConfigTree) -> None:
+ if not config.exists(base):
+ # Nothing to do
+ return
+
+ installed = False
+ for interface in config.list_nodes(base):
+ cc_path = base + [interface, 'country-code']
+ if config.exists(cc_path):
+ tmp = config.return_value(cc_path)
+ config.delete(cc_path)
+
+ # There can be only ONE wireless country-code per device, everything
+ # else makes no sense as a WIFI router can not operate in two
+ # different countries
+ if not installed:
+ config.set(['system', 'wireless', 'country-code'], value=tmp)
+ installed = True
diff --git a/src/migration-scripts/interfaces/4-to-5 b/src/migration-scripts/interfaces/4-to-5
index 93fa7c393..839e23d77 100644
--- a/src/migration-scripts/interfaces/4-to-5
+++ b/src/migration-scripts/interfaces/4-to-5
@@ -1,4 +1,4 @@
-# Copyright 2019-2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/interfaces/5-to-6 b/src/migration-scripts/interfaces/5-to-6
index 44c32ba63..e172d9c80 100644
--- a/src/migration-scripts/interfaces/5-to-6
+++ b/src/migration-scripts/interfaces/5-to-6
@@ -1,4 +1,4 @@
-# Copyright 202-2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
@@ -13,7 +13,7 @@
# You should have received a copy of the GNU Lesser General Public License
# along with this library. If not, see <http://www.gnu.org/licenses/>.
-# Migrate IPv6 router advertisments from a nested interface configuration to
+# Migrate IPv6 router advertisements from a nested interface configuration to
# a denested "service router-advert"
from vyos.configtree import ConfigTree
@@ -56,7 +56,7 @@ def copy_rtradv(c, old_base, interface):
# cleanup boolean nodes in individual route
route_base = new_base + ['route']
if c.exists(route_base):
- for route in config.list_nodes(route_base):
+ for route in c.list_nodes(route_base):
if c.exists(route_base + [route, 'remove-route']):
tmp = c.return_value(route_base + [route, 'remove-route'])
c.delete(route_base + [route, 'remove-route'])
@@ -66,7 +66,7 @@ def copy_rtradv(c, old_base, interface):
# cleanup boolean nodes in individual prefix
prefix_base = new_base + ['prefix']
if c.exists(prefix_base):
- for prefix in config.list_nodes(prefix_base):
+ for prefix in c.list_nodes(prefix_base):
if c.exists(prefix_base + [prefix, 'autonomous-flag']):
tmp = c.return_value(prefix_base + [prefix, 'autonomous-flag'])
c.delete(prefix_base + [prefix, 'autonomous-flag'])
diff --git a/src/migration-scripts/interfaces/6-to-7 b/src/migration-scripts/interfaces/6-to-7
index e60121eec..0131b419c 100644
--- a/src/migration-scripts/interfaces/6-to-7
+++ b/src/migration-scripts/interfaces/6-to-7
@@ -1,4 +1,4 @@
-# Copyright 2020-2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/interfaces/7-to-8 b/src/migration-scripts/interfaces/7-to-8
index 43ae320ab..e670deb37 100644
--- a/src/migration-scripts/interfaces/7-to-8
+++ b/src/migration-scripts/interfaces/7-to-8
@@ -1,4 +1,4 @@
-# Copyright 2020-2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
@@ -43,7 +43,7 @@ def migrate(config: ConfigTree) -> None:
# Nothing to do
return
- # list all individual wireguard interface isntance
+ # list all individual wireguard interface instance
for i in config.list_nodes(base):
iface = base + [i]
for peer in config.list_nodes(iface + ['peer']):
diff --git a/src/migration-scripts/interfaces/8-to-9 b/src/migration-scripts/interfaces/8-to-9
index bae1b34fa..baabce8bc 100644
--- a/src/migration-scripts/interfaces/8-to-9
+++ b/src/migration-scripts/interfaces/8-to-9
@@ -1,4 +1,4 @@
-# Copyright 2020-2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
@@ -26,7 +26,7 @@ def migrate(config: ConfigTree) -> None:
# Nothing to do
continue
- # list all individual interface isntance
+ # list all individual interface instance
for i in config.list_nodes(base):
iface = base + [i]
if config.exists(iface + ['link']):
diff --git a/src/migration-scripts/interfaces/9-to-10 b/src/migration-scripts/interfaces/9-to-10
index cdfd7d432..354416975 100644
--- a/src/migration-scripts/interfaces/9-to-10
+++ b/src/migration-scripts/interfaces/9-to-10
@@ -1,4 +1,4 @@
-# Copyright 2020-2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
@@ -13,7 +13,7 @@
# You should have received a copy of the GNU Lesser General Public License
# along with this library. If not, see <http://www.gnu.org/licenses/>.
-# - rename CLI node 'dhcpv6-options delgate' to 'dhcpv6-options prefix-delegation
+# - rename CLI node 'dhcpv6-options delegate' to 'dhcpv6-options prefix-delegation
# interface'
# - rename CLI node 'interface-id' for prefix-delegation to 'address' as it
# represents the local interface IPv6 address assigned by DHCPv6-PD
@@ -41,5 +41,5 @@ def migrate(config: ConfigTree) -> None:
for interface in config.list_nodes(new_path + ['interface']):
config.rename(new_path + ['interface', interface, 'interface-id'], 'address')
- # delete old noe
+ # delete old node
config.delete(base_path)
diff --git a/src/migration-scripts/ipoe-server/1-to-2 b/src/migration-scripts/ipoe-server/1-to-2
index 034eacb10..6db4a7167 100644
--- a/src/migration-scripts/ipoe-server/1-to-2
+++ b/src/migration-scripts/ipoe-server/1-to-2
@@ -1,4 +1,4 @@
-# Copyright 2023-2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
@@ -21,7 +21,7 @@
# - changed cli of all named pools
# - moved gateway-address from pool to global configuration with / netmask
# gateway can exist without pool if radius is used
-# and Framed-ip-address is transmited
+# and Framed-ip-address is transmitted
# - There are several gateway-addresses in ipoe
# - default-pool by migration.
# 1. The first pool that contains next-poll.
diff --git a/src/migration-scripts/ipoe-server/2-to-3 b/src/migration-scripts/ipoe-server/2-to-3
index dcd15e595..fb4262e1d 100644
--- a/src/migration-scripts/ipoe-server/2-to-3
+++ b/src/migration-scripts/ipoe-server/2-to-3
@@ -1,4 +1,4 @@
-# Copyright 2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/ipoe-server/3-to-4 b/src/migration-scripts/ipoe-server/3-to-4
index 3bad9756d..cce1927f3 100644
--- a/src/migration-scripts/ipoe-server/3-to-4
+++ b/src/migration-scripts/ipoe-server/3-to-4
@@ -1,4 +1,4 @@
-# Copyright 2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/ipsec/10-to-11 b/src/migration-scripts/ipsec/10-to-11
index 6c4ccb553..f88250ac1 100644
--- a/src/migration-scripts/ipsec/10-to-11
+++ b/src/migration-scripts/ipsec/10-to-11
@@ -1,4 +1,4 @@
-# Copyright 2023-2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/ipsec/11-to-12 b/src/migration-scripts/ipsec/11-to-12
index fc65f1825..f6f34bd59 100644
--- a/src/migration-scripts/ipsec/11-to-12
+++ b/src/migration-scripts/ipsec/11-to-12
@@ -1,4 +1,4 @@
-# Copyright 2023-2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/ipsec/12-to-13 b/src/migration-scripts/ipsec/12-to-13
index ffe766eb2..184ba0274 100644
--- a/src/migration-scripts/ipsec/12-to-13
+++ b/src/migration-scripts/ipsec/12-to-13
@@ -1,4 +1,4 @@
-# Copyright 2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/ipsec/13-to-14 b/src/migration-scripts/ipsec/13-to-14
new file mode 100644
index 000000000..f676a09be
--- /dev/null
+++ b/src/migration-scripts/ipsec/13-to-14
@@ -0,0 +1,33 @@
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
+#
+# This library is free software; you can redistribute it and/or
+# modify it under the terms of the GNU Lesser General Public
+# License as published by the Free Software Foundation; either
+# version 2.1 of the License, or (at your option) any later version.
+#
+# This library is distributed in the hope that it will be useful,
+# but WITHOUT ANY WARRANTY; without even the implied warranty of
+# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
+# Lesser General Public License for more details.
+#
+# You should have received a copy of the GNU Lesser General Public License
+# along with this library. If not, see <http://www.gnu.org/licenses/>.
+
+# Rename connection-type 'respond' to 'trap' (T7594):
+# vpn ipsec site-to-site peer <name> connection-type respond -> trap
+
+from vyos.configtree import ConfigTree
+
+base = ['vpn', 'ipsec', 'site-to-site']
+
+def migrate(config: ConfigTree) -> None:
+ # If IPsec config does not exist, nothing to do
+ if not config.exists(base):
+ return
+
+ # Iterate through defined peers
+ for peer in config.list_nodes(base + ['peer']):
+ path = base + ['peer', peer, 'connection-type']
+ if config.value_exists(path, 'respond'):
+ # Replace old behavior with explicit passive type
+ config.set(path, 'trap', replace=True)
diff --git a/src/migration-scripts/ipsec/4-to-5 b/src/migration-scripts/ipsec/4-to-5
index a88a543d3..62653f32d 100644
--- a/src/migration-scripts/ipsec/4-to-5
+++ b/src/migration-scripts/ipsec/4-to-5
@@ -1,4 +1,4 @@
-# Copyright 2019-2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/ipsec/5-to-6 b/src/migration-scripts/ipsec/5-to-6
index 373428d61..6c1d9c0d4 100644
--- a/src/migration-scripts/ipsec/5-to-6
+++ b/src/migration-scripts/ipsec/5-to-6
@@ -1,4 +1,4 @@
-# Copyright 2021-2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/ipsec/6-to-7 b/src/migration-scripts/ipsec/6-to-7
index 5679477c0..35d2ad6c6 100644
--- a/src/migration-scripts/ipsec/6-to-7
+++ b/src/migration-scripts/ipsec/6-to-7
@@ -1,4 +1,4 @@
-# Copyright 2021-2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/ipsec/7-to-8 b/src/migration-scripts/ipsec/7-to-8
index 481f00d29..b10230431 100644
--- a/src/migration-scripts/ipsec/7-to-8
+++ b/src/migration-scripts/ipsec/7-to-8
@@ -1,4 +1,4 @@
-# Copyright 2021-2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/ipsec/8-to-9 b/src/migration-scripts/ipsec/8-to-9
index 7f325139f..3a97c01c0 100644
--- a/src/migration-scripts/ipsec/8-to-9
+++ b/src/migration-scripts/ipsec/8-to-9
@@ -1,4 +1,4 @@
-# Copyright 2022-2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/ipsec/9-to-10 b/src/migration-scripts/ipsec/9-to-10
index 321a75973..ccb1a5e02 100644
--- a/src/migration-scripts/ipsec/9-to-10
+++ b/src/migration-scripts/ipsec/9-to-10
@@ -1,4 +1,4 @@
-# Copyright 2022-2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/isis/0-to-1 b/src/migration-scripts/isis/0-to-1
index e24288558..3a9735d29 100644
--- a/src/migration-scripts/isis/0-to-1
+++ b/src/migration-scripts/isis/0-to-1
@@ -1,4 +1,4 @@
-# Copyright 2021-2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
@@ -24,13 +24,21 @@ def migrate(config: ConfigTree) -> None:
# Nothing to do
return
- # We need a temporary copy of the config
- tmp_base = ['protocols', 'isis2']
- config.copy(base, tmp_base)
+ if not config.is_tag(base):
+ # Nothing to do
+ exit(0)
+
+ # Get IS-IS domain ID
+ domain_id = config.list_nodes(base)
+ if domain_id:
+ # We need a temporary copy of the config
+ tmp_base = ['protocols', 'isis2']
+ config.copy(base + domain_id, tmp_base)
# Now it's save to delete the old configuration
config.delete(base)
- # Rename temporary copy to new final config (IS-IS domain key is static and no
- # longer required to be set via CLI)
- config.rename(tmp_base, 'isis')
+ # Rename temporary node to new final config (IS-IS domain key is static and
+ # no longer required to be set via CLI)
+ if config.exists(tmp_base):
+ config.rename(tmp_base, 'isis')
diff --git a/src/migration-scripts/isis/1-to-2 b/src/migration-scripts/isis/1-to-2
index 0fc92a6de..e87d91516 100644
--- a/src/migration-scripts/isis/1-to-2
+++ b/src/migration-scripts/isis/1-to-2
@@ -1,4 +1,4 @@
-# Copyright 2022-2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/isis/2-to-3 b/src/migration-scripts/isis/2-to-3
index afb9f2340..9cdc84ac3 100644
--- a/src/migration-scripts/isis/2-to-3
+++ b/src/migration-scripts/isis/2-to-3
@@ -1,4 +1,4 @@
-# Copyright 2023-2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/l2tp/0-to-1 b/src/migration-scripts/l2tp/0-to-1
index f0cb6af96..03fb7e236 100644
--- a/src/migration-scripts/l2tp/0-to-1
+++ b/src/migration-scripts/l2tp/0-to-1
@@ -1,4 +1,4 @@
-# Copyright 2018-2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/l2tp/1-to-2 b/src/migration-scripts/l2tp/1-to-2
index 468d564ac..dd38edfbc 100644
--- a/src/migration-scripts/l2tp/1-to-2
+++ b/src/migration-scripts/l2tp/1-to-2
@@ -1,4 +1,4 @@
-# Copyright 2019-2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/l2tp/2-to-3 b/src/migration-scripts/l2tp/2-to-3
index 00fabb6b6..748d9544e 100644
--- a/src/migration-scripts/l2tp/2-to-3
+++ b/src/migration-scripts/l2tp/2-to-3
@@ -1,4 +1,4 @@
-# Copyright 2020-2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/l2tp/3-to-4 b/src/migration-scripts/l2tp/3-to-4
index 01c3fa844..434b3a72e 100644
--- a/src/migration-scripts/l2tp/3-to-4
+++ b/src/migration-scripts/l2tp/3-to-4
@@ -1,4 +1,4 @@
-# Copyright 2021-2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/l2tp/4-to-5 b/src/migration-scripts/l2tp/4-to-5
index 56d451b8d..c3cc8451e 100644
--- a/src/migration-scripts/l2tp/4-to-5
+++ b/src/migration-scripts/l2tp/4-to-5
@@ -1,4 +1,4 @@
-# Copyright 2023-2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/l2tp/5-to-6 b/src/migration-scripts/l2tp/5-to-6
index cc9f948a6..d57819d2a 100644
--- a/src/migration-scripts/l2tp/5-to-6
+++ b/src/migration-scripts/l2tp/5-to-6
@@ -1,4 +1,4 @@
-# Copyright 2023-2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
@@ -28,7 +28,7 @@ def migrate(config: ConfigTree) -> None:
value=config.return_value(idle_path))
config.delete(idle_path)
- #migrate mppe from authentication to ppp-otion
+ #migrate mppe from authentication to ppp-options
mppe_path = base + ['authentication', 'mppe']
if config.exists(mppe_path):
config.set(base + ['ppp-options', 'mppe'],
diff --git a/src/migration-scripts/l2tp/6-to-7 b/src/migration-scripts/l2tp/6-to-7
index 4dba5974e..f4e561382 100644
--- a/src/migration-scripts/l2tp/6-to-7
+++ b/src/migration-scripts/l2tp/6-to-7
@@ -1,4 +1,4 @@
-# Copyright 2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/l2tp/7-to-8 b/src/migration-scripts/l2tp/7-to-8
index 527906fc8..b11a28af0 100644
--- a/src/migration-scripts/l2tp/7-to-8
+++ b/src/migration-scripts/l2tp/7-to-8
@@ -1,4 +1,4 @@
-# Copyright 2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/l2tp/8-to-9 b/src/migration-scripts/l2tp/8-to-9
index e6b689e80..e5577da3e 100644
--- a/src/migration-scripts/l2tp/8-to-9
+++ b/src/migration-scripts/l2tp/8-to-9
@@ -1,4 +1,4 @@
-# Copyright 2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/lldp/0-to-1 b/src/migration-scripts/lldp/0-to-1
index c16e7e84b..052fe65c2 100644
--- a/src/migration-scripts/lldp/0-to-1
+++ b/src/migration-scripts/lldp/0-to-1
@@ -1,4 +1,4 @@
-# Copyright 2020-2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/lldp/1-to-2 b/src/migration-scripts/lldp/1-to-2
index 7f233a725..e2d936a9e 100644
--- a/src/migration-scripts/lldp/1-to-2
+++ b/src/migration-scripts/lldp/1-to-2
@@ -1,4 +1,4 @@
-# Copyright 2023-2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/lldp/2-to-3 b/src/migration-scripts/lldp/2-to-3
index 93090756c..653029550 100644
--- a/src/migration-scripts/lldp/2-to-3
+++ b/src/migration-scripts/lldp/2-to-3
@@ -1,4 +1,4 @@
-# Copyright 2025 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/monitoring/0-to-1 b/src/migration-scripts/monitoring/0-to-1
index 92f824325..7f7d9df60 100644
--- a/src/migration-scripts/monitoring/0-to-1
+++ b/src/migration-scripts/monitoring/0-to-1
@@ -1,6 +1,6 @@
#!/usr/bin/env python3
#
-# Copyright (C) 2022 VyOS maintainers and contributors
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This program is free software; you can redistribute it and/or modify
# it under the terms of the GNU General Public License version 2 or later as
@@ -14,7 +14,7 @@
# You should have received a copy of the GNU General Public License
# along with this program. If not, see <http://www.gnu.org/licenses/>.
-# Copyright 2022-2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/monitoring/1-to-2 b/src/migration-scripts/monitoring/1-to-2
index 8bdaebae9..013e8ff3a 100644
--- a/src/migration-scripts/monitoring/1-to-2
+++ b/src/migration-scripts/monitoring/1-to-2
@@ -1,4 +1,4 @@
-# Copyright 2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/nat/4-to-5 b/src/migration-scripts/nat/4-to-5
index e1919da50..f4a48bbf3 100644
--- a/src/migration-scripts/nat/4-to-5
+++ b/src/migration-scripts/nat/4-to-5
@@ -1,4 +1,4 @@
-# Copyright 2020-2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/nat/5-to-6 b/src/migration-scripts/nat/5-to-6
index a583d4eb6..e40ccebb0 100644
--- a/src/migration-scripts/nat/5-to-6
+++ b/src/migration-scripts/nat/5-to-6
@@ -1,4 +1,4 @@
-# Copyright 2023-2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/nat/6-to-7 b/src/migration-scripts/nat/6-to-7
index e9b90fc98..2e8929b1c 100644
--- a/src/migration-scripts/nat/6-to-7
+++ b/src/migration-scripts/nat/6-to-7
@@ -1,4 +1,4 @@
-# Copyright 2023-2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
@@ -13,7 +13,7 @@
# You should have received a copy of the GNU Lesser General Public License
# along with this library. If not, see <http://www.gnu.org/licenses/>.
-# T5681: Firewall re-writing. Simplify cli when mathcing interface
+# T5681: Firewall re-writing. Simplify cli when matching interface
# From
# 'set nat [source|destination] rule X [inbound-interface|outbound interface] interface-name <iface>'
# 'set nat [source|destination] rule X [inbound-interface|outbound interface] interface-group <iface_group>'
diff --git a/src/migration-scripts/nat/7-to-8 b/src/migration-scripts/nat/7-to-8
index 9ae389ef1..4af8c935c 100644
--- a/src/migration-scripts/nat/7-to-8
+++ b/src/migration-scripts/nat/7-to-8
@@ -1,4 +1,4 @@
-# Copyright 2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/nat66/0-to-1 b/src/migration-scripts/nat66/0-to-1
index b3c6bf4cc..08348379f 100644
--- a/src/migration-scripts/nat66/0-to-1
+++ b/src/migration-scripts/nat66/0-to-1
@@ -1,4 +1,4 @@
-# Copyright 2020-2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/nat66/1-to-2 b/src/migration-scripts/nat66/1-to-2
index f49940ae0..eef55e878 100644
--- a/src/migration-scripts/nat66/1-to-2
+++ b/src/migration-scripts/nat66/1-to-2
@@ -1,6 +1,6 @@
#!/usr/bin/env python3
#
-# Copyright (C) 2023 VyOS maintainers and contributors
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This program is free software; you can redistribute it and/or modify
# it under the terms of the GNU General Public License version 2 or later as
@@ -14,7 +14,7 @@
# You should have received a copy of the GNU General Public License
# along with this program. If not, see <http://www.gnu.org/licenses/>.
-# Copyright 2023-2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
@@ -29,7 +29,7 @@
# You should have received a copy of the GNU Lesser General Public License
# along with this library. If not, see <http://www.gnu.org/licenses/>.
-# T5681: Firewall re-writing. Simplify cli when mathcing interface
+# T5681: Firewall re-writing. Simplify cli when matching interface
# From
# 'set nat66 [source|destination] rule X [inbound-interface|outbound interface] <iface>'
# to
diff --git a/src/migration-scripts/nat66/2-to-3 b/src/migration-scripts/nat66/2-to-3
index 55d5f4b2b..1e76819d4 100644
--- a/src/migration-scripts/nat66/2-to-3
+++ b/src/migration-scripts/nat66/2-to-3
@@ -1,4 +1,4 @@
-# Copyright 2023-2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/nhrp/0-to-1 b/src/migration-scripts/nhrp/0-to-1
index badd88e04..1923f9283 100644
--- a/src/migration-scripts/nhrp/0-to-1
+++ b/src/migration-scripts/nhrp/0-to-1
@@ -1,4 +1,4 @@
-# Copyright 2025 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
@@ -112,7 +112,7 @@ def migrate(config: ConfigTree) -> None:
config.set(base + [tunnel_name, 'multicast'], value=nbma,
replace=False)
- ## Delete non-cahching
+ ## Delete non-caching
if config.exists(base + [tunnel_name, 'non-caching']):
config.delete(base + [tunnel_name, 'non-caching'])
## Delete shortcut-destination
@@ -126,4 +126,4 @@ def migrate(config: ConfigTree) -> None:
config.set(base + [tunnel_name, 'shortcut'])
config.delete(base + [tunnel_name, 'shortcut-target'])
## Set registration-no-unique
- config.set(base + [tunnel_name, 'registration-no-unique']) \ No newline at end of file
+ config.set(base + [tunnel_name, 'registration-no-unique'])
diff --git a/src/migration-scripts/ntp/0-to-1 b/src/migration-scripts/ntp/0-to-1
index 01f5a460a..895308b75 100644
--- a/src/migration-scripts/ntp/0-to-1
+++ b/src/migration-scripts/ntp/0-to-1
@@ -1,6 +1,6 @@
#!/usr/bin/env python3
-# Copyright 2018-2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/ntp/1-to-2 b/src/migration-scripts/ntp/1-to-2
index d5f800922..d3039041c 100644
--- a/src/migration-scripts/ntp/1-to-2
+++ b/src/migration-scripts/ntp/1-to-2
@@ -1,4 +1,4 @@
-# Copyright 2023-2025 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/ntp/2-to-3 b/src/migration-scripts/ntp/2-to-3
index bbda90351..701cffdfb 100644
--- a/src/migration-scripts/ntp/2-to-3
+++ b/src/migration-scripts/ntp/2-to-3
@@ -1,4 +1,4 @@
-# Copyright 2023-2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/openconnect/0-to-1 b/src/migration-scripts/openconnect/0-to-1
index aa5a97eee..90f7ee64a 100644
--- a/src/migration-scripts/openconnect/0-to-1
+++ b/src/migration-scripts/openconnect/0-to-1
@@ -1,4 +1,4 @@
-# Copyright 2021-2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/openconnect/1-to-2 b/src/migration-scripts/openconnect/1-to-2
index 4f74b44df..b145ccb0f 100644
--- a/src/migration-scripts/openconnect/1-to-2
+++ b/src/migration-scripts/openconnect/1-to-2
@@ -1,4 +1,4 @@
-# Copyright 2022-2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
@@ -13,7 +13,7 @@
# You should have received a copy of the GNU Lesser General Public License
# along with this library. If not, see <http://www.gnu.org/licenses/>.
-# Delete depricated outside-nexthop address
+# Delete deprecated outside-nexthop address
from vyos.configtree import ConfigTree
diff --git a/src/migration-scripts/openconnect/2-to-3 b/src/migration-scripts/openconnect/2-to-3
index 00e13ecb0..74cb6f2d8 100644
--- a/src/migration-scripts/openconnect/2-to-3
+++ b/src/migration-scripts/openconnect/2-to-3
@@ -1,4 +1,4 @@
-# Copyright 2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/openvpn/0-to-1 b/src/migration-scripts/openvpn/0-to-1
index e5db731ed..26f41d2ce 100644
--- a/src/migration-scripts/openvpn/0-to-1
+++ b/src/migration-scripts/openvpn/0-to-1
@@ -1,4 +1,4 @@
-# Copyright 2023-2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
@@ -17,6 +17,8 @@
from vyos.configtree import ConfigTree
+updated_cipher='3des'
+
def migrate(config: ConfigTree) -> None:
if not config.exists(['interfaces', 'openvpn']):
# Nothing to do
@@ -25,6 +27,7 @@ def migrate(config: ConfigTree) -> None:
ovpn_intfs = config.list_nodes(['interfaces', 'openvpn'])
for i in ovpn_intfs:
# Remove DES and Blowfish from 'encryption cipher'
+ # Support for these insecure ciphers will be removed in OpenVPN 2.6.
cipher_path = ['interfaces', 'openvpn', i, 'encryption', 'cipher']
if config.exists(cipher_path):
cipher = config.return_value(cipher_path)
@@ -41,3 +44,11 @@ def migrate(config: ConfigTree) -> None:
if config.exists(['interfaces', 'openvpn', i, 'encryption']) and \
(config.list_nodes(['interfaces', 'openvpn', i, 'encryption']) == []):
config.delete(['interfaces', 'openvpn', i, 'encryption'])
+
+ # We need to take care about site-to-site tunnels which had an implicit
+ # OpenVPN default cipher (BF-CBC) with block size less than 128 bit (64 bit).
+ mode_path = ['interfaces', 'openvpn', i, 'mode']
+ if config.exists(mode_path) and config.return_value(mode_path) == 'site-to-site':
+ # if no explicit cipher is defined, we will "upgrade" to 3DES at least
+ if not config.exists(cipher_path):
+ config.set(cipher_path, value=updated_cipher)
diff --git a/src/migration-scripts/openvpn/1-to-2 b/src/migration-scripts/openvpn/1-to-2
index 2baa7302c..75360446c 100644
--- a/src/migration-scripts/openvpn/1-to-2
+++ b/src/migration-scripts/openvpn/1-to-2
@@ -1,6 +1,6 @@
#!/usr/bin/env python3
#
-# Copyright (C) 2024 VyOS maintainers and contributors
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This program is free software; you can redistribute it and/or modify
# it under the terms of the GNU General Public License version 2 or later as
@@ -25,11 +25,17 @@ def migrate(config: ConfigTree) -> None:
# Remove 'encryption cipher' and add this value to 'encryption ncp-ciphers'
# for server and client mode.
# Site-to-site mode still can use --cipher option
+ mode_path = ['interfaces', 'openvpn', i, 'mode']
cipher_path = ['interfaces', 'openvpn', i, 'encryption', 'cipher']
ncp_cipher_path = ['interfaces', 'openvpn', i, 'encryption', 'ncp-ciphers']
+
if config.exists(cipher_path):
if config.exists(['interfaces', 'openvpn', i, 'shared-secret-key']):
continue
+ # Only migrate if mode is not 'site-to-site'
+ if config.value_exists(mode_path, 'site-to-site'):
+ continue
+
cipher = config.return_value(cipher_path)
config.delete(cipher_path)
if cipher == 'none':
diff --git a/src/migration-scripts/openvpn/2-to-3 b/src/migration-scripts/openvpn/2-to-3
index 4e6b3c8b7..f2a7d1d69 100644
--- a/src/migration-scripts/openvpn/2-to-3
+++ b/src/migration-scripts/openvpn/2-to-3
@@ -1,6 +1,6 @@
#!/usr/bin/env python3
#
-# Copyright (C) 2024 VyOS maintainers and contributors
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This program is free software; you can redistribute it and/or modify
# it under the terms of the GNU General Public License version 2 or later as
diff --git a/src/migration-scripts/openvpn/3-to-4 b/src/migration-scripts/openvpn/3-to-4
index 0529491c1..86b287102 100644
--- a/src/migration-scripts/openvpn/3-to-4
+++ b/src/migration-scripts/openvpn/3-to-4
@@ -1,5 +1,5 @@
#!/usr/bin/env python3
-# Copyright 2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/openvpn/4-to-5 b/src/migration-scripts/openvpn/4-to-5
new file mode 100644
index 000000000..5c7ee833c
--- /dev/null
+++ b/src/migration-scripts/openvpn/4-to-5
@@ -0,0 +1,38 @@
+#!/usr/bin/env python3
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
+#
+# This library is free software; you can redistribute it and/or
+# modify it under the terms of the GNU Lesser General Public
+# License as published by the Free Software Foundation; either
+# version 2.1 of the License, or (at your option) any later version.
+#
+# This library is distributed in the hope that it will be useful,
+# but WITHOUT ANY WARRANTY; without even the implied warranty of
+# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
+# Lesser General Public License for more details.
+#
+# You should have received a copy of the GNU Lesser General Public License
+# along with this library. If not, see <http://www.gnu.org/licenses/>.
+#
+# T7633: This migration converts legacy 'encryption cipher' directives into
+# 'encryption data-ciphers-fallback' for site-to-site mode tunnels.
+#
+# In modern OpenVPN (v2.6+), 'cipher' and 'data-ciphers' are not valid
+# in site-to-site mode.
+# The appropriate directive is now '--data-ciphers-fallback alg'.
+
+from vyos.configtree import ConfigTree
+
+def migrate(config: ConfigTree) -> None:
+ ovpn_intfs = config.list_nodes(['interfaces', 'openvpn'], path_must_exist=False)
+ for i in ovpn_intfs:
+ base_path = ['interfaces', 'openvpn', i]
+ mode_path = base_path + ['mode']
+ cipher_path = base_path + ['encryption', 'cipher']
+
+ # Only migrate if mode is explicitly 'site-to-site'
+ if config.value_exists(mode_path, 'site-to-site'):
+
+ # Rename 'encryption cipher' with 'encryption data-ciphers-fallback'
+ if config.exists(cipher_path):
+ config.rename(cipher_path, 'data-ciphers-fallback')
diff --git a/src/migration-scripts/ospf/0-to-1 b/src/migration-scripts/ospf/0-to-1
index a1f810960..2f20184b4 100644
--- a/src/migration-scripts/ospf/0-to-1
+++ b/src/migration-scripts/ospf/0-to-1
@@ -1,4 +1,4 @@
-# Copyright 2021-2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/ospf/1-to-2 b/src/migration-scripts/ospf/1-to-2
index 5368d8dd7..5b7862ee7 100644
--- a/src/migration-scripts/ospf/1-to-2
+++ b/src/migration-scripts/ospf/1-to-2
@@ -1,4 +1,4 @@
-# Copyright 2023-2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/pim/0-to-1 b/src/migration-scripts/pim/0-to-1
index ce24b23ba..c0b48ae67 100644
--- a/src/migration-scripts/pim/0-to-1
+++ b/src/migration-scripts/pim/0-to-1
@@ -1,4 +1,4 @@
-# Copyright 2023-2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/policy/0-to-1 b/src/migration-scripts/policy/0-to-1
index 837946c37..aea43560b 100644
--- a/src/migration-scripts/policy/0-to-1
+++ b/src/migration-scripts/policy/0-to-1
@@ -1,4 +1,4 @@
-# Copyright 2021-2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/policy/1-to-2 b/src/migration-scripts/policy/1-to-2
index ba3e48db0..5990c4a8e 100644
--- a/src/migration-scripts/policy/1-to-2
+++ b/src/migration-scripts/policy/1-to-2
@@ -1,4 +1,4 @@
-# Copyright 2022-2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/policy/2-to-3 b/src/migration-scripts/policy/2-to-3
index 399a55387..74c15885e 100644
--- a/src/migration-scripts/policy/2-to-3
+++ b/src/migration-scripts/policy/2-to-3
@@ -1,4 +1,4 @@
-# Copyright 2022-2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/policy/3-to-4 b/src/migration-scripts/policy/3-to-4
index 5d4959def..b34411c39 100644
--- a/src/migration-scripts/policy/3-to-4
+++ b/src/migration-scripts/policy/3-to-4
@@ -1,4 +1,4 @@
-# Copyright 2022-2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
@@ -105,7 +105,7 @@ def migrate(config: ConfigTree) -> None:
for rule in config.list_nodes(base + [route_map, 'rule']):
base_rule: list[str] = base + [route_map, 'rule', rule, 'set']
- # IF additive presents in coummunity then comm-list is redundant
+ # IF additive presents in community then comm-list is redundant
isAdditive: bool = True
#### Change Set community ########
if config.exists(base_rule + ['community']):
diff --git a/src/migration-scripts/policy/4-to-5 b/src/migration-scripts/policy/4-to-5
index 0ecfdfd5e..01f019d39 100644
--- a/src/migration-scripts/policy/4-to-5
+++ b/src/migration-scripts/policy/4-to-5
@@ -1,4 +1,4 @@
-# Copyright 2022-2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/policy/5-to-6 b/src/migration-scripts/policy/5-to-6
index acba0b4be..d1c818827 100644
--- a/src/migration-scripts/policy/5-to-6
+++ b/src/migration-scripts/policy/5-to-6
@@ -1,4 +1,4 @@
-# Copyright 2023-2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/policy/6-to-7 b/src/migration-scripts/policy/6-to-7
index 69aa703c5..b4e7ebcea 100644
--- a/src/migration-scripts/policy/6-to-7
+++ b/src/migration-scripts/policy/6-to-7
@@ -1,4 +1,4 @@
-# Copyright 2023-2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/policy/7-to-8 b/src/migration-scripts/policy/7-to-8
index a887f37fe..4fa45b879 100644
--- a/src/migration-scripts/policy/7-to-8
+++ b/src/migration-scripts/policy/7-to-8
@@ -1,4 +1,4 @@
-# Copyright 2023-2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/policy/8-to-9 b/src/migration-scripts/policy/8-to-9
index 355e48e00..b8cc1f471 100644
--- a/src/migration-scripts/policy/8-to-9
+++ b/src/migration-scripts/policy/8-to-9
@@ -1,4 +1,4 @@
-# Copyright (C) 2025 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/pppoe-server/0-to-1 b/src/migration-scripts/pppoe-server/0-to-1
index 8c9a24fbe..c2b25c45f 100644
--- a/src/migration-scripts/pppoe-server/0-to-1
+++ b/src/migration-scripts/pppoe-server/0-to-1
@@ -1,4 +1,4 @@
-# Copyright 2020-2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/pppoe-server/1-to-2 b/src/migration-scripts/pppoe-server/1-to-2
index c9c968bff..31132565e 100644
--- a/src/migration-scripts/pppoe-server/1-to-2
+++ b/src/migration-scripts/pppoe-server/1-to-2
@@ -1,4 +1,4 @@
-# Copyright 2020-2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/pppoe-server/10-to-11 b/src/migration-scripts/pppoe-server/10-to-11
index 6bc138b5c..9d0477172 100644
--- a/src/migration-scripts/pppoe-server/10-to-11
+++ b/src/migration-scripts/pppoe-server/10-to-11
@@ -1,4 +1,4 @@
-# Copyright 2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/pppoe-server/11-to-12 b/src/migration-scripts/pppoe-server/11-to-12
new file mode 100644
index 000000000..d38ba0367
--- /dev/null
+++ b/src/migration-scripts/pppoe-server/11-to-12
@@ -0,0 +1,31 @@
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
+#
+# This library is free software; you can redistribute it and/or
+# modify it under the terms of the GNU Lesser General Public
+# License as published by the Free Software Foundation; either
+# version 2.1 of the License, or (at your option) any later version.
+#
+# This library is distributed in the hope that it will be useful,
+# but WITHOUT ANY WARRANTY; without even the implied warranty of
+# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
+# Lesser General Public License for more details.
+#
+# You should have received a copy of the GNU Lesser General Public License
+# along with this library. If not, see <http://www.gnu.org/licenses/>.
+
+# Delete 'vpp-cp' option from interface settings
+# because it will be set automatically (T8143)
+
+from vyos.configtree import ConfigTree
+
+base = ['service', 'pppoe-server']
+
+def migrate(config: ConfigTree) -> None:
+ if not config.exists(base):
+ return
+
+ for interface in config.list_nodes(base + ['interface']):
+ base_path = base + ['interface', interface]
+ # Delete vpp-cp option from PPPoE interface settings
+ if config.exists(base_path + ['vpp-cp']):
+ config.delete(base_path + ['vpp-cp'])
diff --git a/src/migration-scripts/pppoe-server/2-to-3 b/src/migration-scripts/pppoe-server/2-to-3
index 160cffdf8..56dc032aa 100644
--- a/src/migration-scripts/pppoe-server/2-to-3
+++ b/src/migration-scripts/pppoe-server/2-to-3
@@ -1,4 +1,4 @@
-# Copyright 2020-2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/pppoe-server/3-to-4 b/src/migration-scripts/pppoe-server/3-to-4
index 29dd62201..b0eb6f2b9 100644
--- a/src/migration-scripts/pppoe-server/3-to-4
+++ b/src/migration-scripts/pppoe-server/3-to-4
@@ -1,4 +1,4 @@
-# Copyright 2020-2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/pppoe-server/4-to-5 b/src/migration-scripts/pppoe-server/4-to-5
index 03fbfb247..bb75b7e1f 100644
--- a/src/migration-scripts/pppoe-server/4-to-5
+++ b/src/migration-scripts/pppoe-server/4-to-5
@@ -1,4 +1,4 @@
-# Copyright 2020-2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/pppoe-server/5-to-6 b/src/migration-scripts/pppoe-server/5-to-6
index 13de8f8d2..4616f6021 100644
--- a/src/migration-scripts/pppoe-server/5-to-6
+++ b/src/migration-scripts/pppoe-server/5-to-6
@@ -1,4 +1,4 @@
-# Copyright 2022-2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/pppoe-server/6-to-7 b/src/migration-scripts/pppoe-server/6-to-7
index 79745a0c6..e764284da 100644
--- a/src/migration-scripts/pppoe-server/6-to-7
+++ b/src/migration-scripts/pppoe-server/6-to-7
@@ -1,4 +1,4 @@
-# Copyright 2023-2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/pppoe-server/7-to-8 b/src/migration-scripts/pppoe-server/7-to-8
index 90e4fa053..9a26da9e6 100644
--- a/src/migration-scripts/pppoe-server/7-to-8
+++ b/src/migration-scripts/pppoe-server/7-to-8
@@ -1,4 +1,4 @@
-# Copyright 2023-2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/pppoe-server/8-to-9 b/src/migration-scripts/pppoe-server/8-to-9
index e7e0aaa2c..0f10dafec 100644
--- a/src/migration-scripts/pppoe-server/8-to-9
+++ b/src/migration-scripts/pppoe-server/8-to-9
@@ -1,4 +1,4 @@
-# Copyright 2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/pppoe-server/9-to-10 b/src/migration-scripts/pppoe-server/9-to-10
index d3475e8ff..0a1931d81 100644
--- a/src/migration-scripts/pppoe-server/9-to-10
+++ b/src/migration-scripts/pppoe-server/9-to-10
@@ -1,4 +1,4 @@
-# Copyright 2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/pptp/0-to-1 b/src/migration-scripts/pptp/0-to-1
index dd0b6f57e..b0e4c3b65 100644
--- a/src/migration-scripts/pptp/0-to-1
+++ b/src/migration-scripts/pptp/0-to-1
@@ -1,4 +1,4 @@
-# Copyright 2018-2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/pptp/1-to-2 b/src/migration-scripts/pptp/1-to-2
index 1e7601193..afeb6e3bb 100644
--- a/src/migration-scripts/pptp/1-to-2
+++ b/src/migration-scripts/pptp/1-to-2
@@ -1,4 +1,4 @@
-# Copyright 2020-2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/pptp/2-to-3 b/src/migration-scripts/pptp/2-to-3
index 8b0d6d865..9f06aa1a7 100644
--- a/src/migration-scripts/pptp/2-to-3
+++ b/src/migration-scripts/pptp/2-to-3
@@ -1,4 +1,4 @@
-# Copyright 2023-2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/pptp/3-to-4 b/src/migration-scripts/pptp/3-to-4
index 2dabd8475..3fe579aa9 100644
--- a/src/migration-scripts/pptp/3-to-4
+++ b/src/migration-scripts/pptp/3-to-4
@@ -1,4 +1,4 @@
-# Copyright 2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/pptp/4-to-5 b/src/migration-scripts/pptp/4-to-5
index c906f58c4..d8390cc66 100644
--- a/src/migration-scripts/pptp/4-to-5
+++ b/src/migration-scripts/pptp/4-to-5
@@ -1,4 +1,4 @@
-# Copyright 2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/qos/1-to-2 b/src/migration-scripts/qos/1-to-2
index c43d8fa47..dea1a77eb 100644
--- a/src/migration-scripts/qos/1-to-2
+++ b/src/migration-scripts/qos/1-to-2
@@ -1,4 +1,4 @@
-# Copyright 2022-2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/qos/2-to-3 b/src/migration-scripts/qos/2-to-3
index 284fe828e..40fc7637f 100644
--- a/src/migration-scripts/qos/2-to-3
+++ b/src/migration-scripts/qos/2-to-3
@@ -1,4 +1,4 @@
-# Copyright 2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/quagga/10-to-11 b/src/migration-scripts/quagga/10-to-11
index 15dbbb193..08ea1a00e 100644
--- a/src/migration-scripts/quagga/10-to-11
+++ b/src/migration-scripts/quagga/10-to-11
@@ -1,4 +1,4 @@
-# Copyright 2023-2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/quagga/11-to-12 b/src/migration-scripts/quagga/11-to-12
index 8ae2023a1..ae8cabc63 100644
--- a/src/migration-scripts/quagga/11-to-12
+++ b/src/migration-scripts/quagga/11-to-12
@@ -1,4 +1,4 @@
-# Copyright 2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
@@ -14,7 +14,7 @@
# along with this library. If not, see <http://www.gnu.org/licenses/>.
# T6747:
-# - Migrate static BFD configuration to match FRR possibillities
+# - Migrate static BFD configuration to match FRR possibilities
# - Consolidate static multicast routing configuration under a new node
from vyos.configtree import ConfigTree
@@ -23,7 +23,7 @@ static_base = ['protocols', 'static']
def migrate(config: ConfigTree) -> None:
# Check for static route/route6 configuration
- # Migrate static BFD configuration to match FRR possibillities
+ # Migrate static BFD configuration to match FRR possibilities
for route_route6 in ['route', 'route6']:
route_route6_base = static_base + [route_route6]
if not config.exists(route_route6_base):
diff --git a/src/migration-scripts/quagga/2-to-3 b/src/migration-scripts/quagga/2-to-3
index d62c387ba..2494abdae 100644
--- a/src/migration-scripts/quagga/2-to-3
+++ b/src/migration-scripts/quagga/2-to-3
@@ -1,4 +1,4 @@
-# Copyright 2018-2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
@@ -15,6 +15,8 @@
from vyos.configtree import ConfigTree
+# Just to avoid writing it so many times
+af_path = ['address-family', 'ipv4-unicast']
def migrate_neighbor(config, neighbor_path, neighbor):
if config.exists(neighbor_path):
@@ -106,9 +108,6 @@ def migrate(config: ConfigTree) -> None:
# Nothing to do
return
- # Just to avoid writing it so many times
- af_path = ['address-family', 'ipv4-unicast']
-
# Check if BGP is actually configured and obtain the ASN
asn_list = config.list_nodes(['protocols', 'bgp'])
if asn_list:
diff --git a/src/migration-scripts/quagga/3-to-4 b/src/migration-scripts/quagga/3-to-4
index 81cf139f6..f801dcff1 100644
--- a/src/migration-scripts/quagga/3-to-4
+++ b/src/migration-scripts/quagga/3-to-4
@@ -1,4 +1,4 @@
-# Copyright 2019-2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/quagga/4-to-5 b/src/migration-scripts/quagga/4-to-5
index 27b995431..a7bb23d14 100644
--- a/src/migration-scripts/quagga/4-to-5
+++ b/src/migration-scripts/quagga/4-to-5
@@ -1,4 +1,4 @@
-# Copyright 2020-2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/quagga/5-to-6 b/src/migration-scripts/quagga/5-to-6
index 08fd070de..5dcfa3cfb 100644
--- a/src/migration-scripts/quagga/5-to-6
+++ b/src/migration-scripts/quagga/5-to-6
@@ -1,4 +1,4 @@
-# Copyright 2020-2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/quagga/6-to-7 b/src/migration-scripts/quagga/6-to-7
index 095baac03..4a28a47e7 100644
--- a/src/migration-scripts/quagga/6-to-7
+++ b/src/migration-scripts/quagga/6-to-7
@@ -1,4 +1,4 @@
-# Copyright 2021-2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/quagga/7-to-8 b/src/migration-scripts/quagga/7-to-8
index d9de26d15..60afb87cf 100644
--- a/src/migration-scripts/quagga/7-to-8
+++ b/src/migration-scripts/quagga/7-to-8
@@ -1,4 +1,4 @@
-# Copyright 2021-2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/quagga/8-to-9 b/src/migration-scripts/quagga/8-to-9
index eece6c15d..7eed424eb 100644
--- a/src/migration-scripts/quagga/8-to-9
+++ b/src/migration-scripts/quagga/8-to-9
@@ -1,4 +1,4 @@
-# Copyright 2021-2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
@@ -16,13 +16,14 @@
# - T2450: drop interface-route and interface-route6 from "protocols static"
from vyos.configtree import ConfigTree
+from vyos.template import is_ip
def migrate_interface_route(config, base, path, route_route6):
""" Generic migration function which can be called on every instance of
- interface-route, beeing it ipv4, ipv6 or nested under the "static table" nodes.
+ interface-route, being it ipv4, ipv6 or nested under the "static table" nodes.
What we do?
- - Drop 'interface-route' or 'interface-route6' and migrate the route unter the
+ - Drop 'interface-route' or 'interface-route6' and migrate the route under the
'route' or 'route6' tag node.
"""
if config.exists(base + path):
@@ -31,17 +32,24 @@ def migrate_interface_route(config, base, path, route_route6):
tmp = base + path + [route, 'next-hop-interface']
for interface in config.list_nodes(tmp):
- new_base = base + [route_route6, route, 'interface']
- config.set(new_base)
- config.set_tag(base + [route_route6])
- config.set_tag(new_base)
- config.copy(tmp + [interface], new_base + [interface])
+ if is_ip(interface): # not prohibited in 1.3.x, hence allowed
+ new_base = base + [route_route6, route, 'next-hop']
+ config.set(new_base)
+ config.set_tag(base + [route_route6])
+ config.set_tag(new_base)
+ config.copy(tmp + [interface], new_base + [interface])
+ else:
+ new_base = base + [route_route6, route, 'interface']
+ config.set(new_base)
+ config.set_tag(base + [route_route6])
+ config.set_tag(new_base)
+ config.copy(tmp + [interface], new_base + [interface])
config.delete(base + path)
def migrate_route(config, base, path, route_route6):
""" Generic migration function which can be called on every instance of
- route, beeing it ipv4, ipv6 or even nested under the static table nodes.
+ route, being it ipv4, ipv6 or even nested under the static table nodes.
What we do?
- for consistency reasons rename next-hop-interface to interface
@@ -53,7 +61,7 @@ def migrate_route(config, base, path, route_route6):
if config.exists(next_hop):
for gateway in config.list_nodes(next_hop):
# IPv4 routes calls it next-hop-interface, rename this to
- # interface instead so it's consitent with IPv6
+ # interface instead so it's consistent with IPv6
interface_path = next_hop + [gateway, 'next-hop-interface']
if config.exists(interface_path):
config.rename(interface_path, 'interface')
@@ -68,7 +76,7 @@ def migrate_route(config, base, path, route_route6):
if config.exists(next_hop):
for interface in config.list_nodes(next_hop):
# IPv4 routes calls it next-hop-interface, rename this to
- # interface instead so it's consitent with IPv6
+ # interface instead so it's consistent with IPv6
interface_path = next_hop + [interface, 'next-hop-interface']
if config.exists(interface_path):
config.rename(interface_path, 'interface')
diff --git a/src/migration-scripts/quagga/9-to-10 b/src/migration-scripts/quagga/9-to-10
index 4ac1f0b7d..a2002bf88 100644
--- a/src/migration-scripts/quagga/9-to-10
+++ b/src/migration-scripts/quagga/9-to-10
@@ -1,4 +1,4 @@
-# Copyright 2022-2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/reverse-proxy/0-to-1 b/src/migration-scripts/reverse-proxy/0-to-1
index b495474a6..b8c98ae99 100644
--- a/src/migration-scripts/reverse-proxy/0-to-1
+++ b/src/migration-scripts/reverse-proxy/0-to-1
@@ -1,4 +1,4 @@
-# Copyright 2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/reverse-proxy/1-to-2 b/src/migration-scripts/reverse-proxy/1-to-2
index 61612bc36..4b72107b1 100755
--- a/src/migration-scripts/reverse-proxy/1-to-2
+++ b/src/migration-scripts/reverse-proxy/1-to-2
@@ -1,4 +1,4 @@
-# Copyright 2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/reverse-proxy/2-to-3 b/src/migration-scripts/reverse-proxy/2-to-3
new file mode 100755
index 000000000..bf3403d11
--- /dev/null
+++ b/src/migration-scripts/reverse-proxy/2-to-3
@@ -0,0 +1,66 @@
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
+#
+# This library is free software; you can redistribute it and/or
+# modify it under the terms of the GNU Lesser General Public
+# License as published by the Free Software Foundation; either
+# version 2.1 of the License, or (at your option) any later version.
+#
+# This library is distributed in the hope that it will be useful,
+# but WITHOUT ANY WARRANTY; without even the implied warranty of
+# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
+# Lesser General Public License for more details.
+#
+# You should have received a copy of the GNU Lesser General Public License
+# along with this library. If not, see <http://www.gnu.org/licenses/>.
+
+# T7429: logging facility "all" unavailable in code
+
+from vyos.configtree import ConfigTree
+
+base = ['load-balancing', 'haproxy']
+unsupported_facilities = ['all', 'authpriv', 'mark']
+
+def config_migrator(config, config_path: list) -> None:
+ if not config.exists(config_path):
+ return
+ # Remove unsupported backend HAProxy syslog facilities form CLI
+ # Works for both backend and service CLI nodes
+ for service_backend in config.list_nodes(config_path):
+ log_path = config_path + [service_backend, 'logging', 'facility']
+ if not config.exists(log_path):
+ continue
+ # Remove unsupported syslog facilities form CLI
+ for facility in config.list_nodes(log_path):
+ if facility in unsupported_facilities:
+ config.delete(log_path + [facility])
+ continue
+ # Remove unsupported facility log level form CLI. VyOS will fallback
+ # to default log level if not set
+ if config.exists(log_path + [facility, 'level']):
+ tmp = config.return_value(log_path + [facility, 'level'])
+ if tmp == 'all':
+ config.delete(log_path + [facility, 'level'])
+
+def migrate(config: ConfigTree) -> None:
+ if not config.exists(base):
+ # Nothing to do
+ return
+
+ # Remove unsupported syslog facilities form CLI
+ global_path = base + ['global-parameters', 'logging', 'facility']
+ if config.exists(global_path):
+ for facility in config.list_nodes(global_path):
+ if facility in unsupported_facilities:
+ config.delete(global_path + [facility])
+ continue
+ # Remove unsupported facility log level form CLI. VyOS will fallback
+ # to default log level if not set
+ if config.exists(global_path + [facility, 'level']):
+ tmp = config.return_value(global_path + [facility, 'level'])
+ if tmp == 'all':
+ config.delete(global_path + [facility, 'level'])
+
+ # Remove unsupported backend HAProxy syslog facilities from CLI
+ config_migrator(config, base + ['backend'])
+ # Remove unsupported service HAProxy syslog facilities from CLI
+ config_migrator(config, base + ['service'])
diff --git a/src/migration-scripts/rip/0-to-1 b/src/migration-scripts/rip/0-to-1
index 6d41bcf58..4fbd88cfe 100644
--- a/src/migration-scripts/rip/0-to-1
+++ b/src/migration-scripts/rip/0-to-1
@@ -1,4 +1,4 @@
-# Copyright 2023-2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/rpki/0-to-1 b/src/migration-scripts/rpki/0-to-1
index b6e781fa9..2263489a0 100644
--- a/src/migration-scripts/rpki/0-to-1
+++ b/src/migration-scripts/rpki/0-to-1
@@ -1,4 +1,4 @@
-# Copyright 2021-2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/rpki/1-to-2 b/src/migration-scripts/rpki/1-to-2
index 855236d6c..42447de66 100644
--- a/src/migration-scripts/rpki/1-to-2
+++ b/src/migration-scripts/rpki/1-to-2
@@ -1,4 +1,4 @@
-# Copyright 2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/salt/0-to-1 b/src/migration-scripts/salt/0-to-1
index 3990a88dc..05f6476ce 100644
--- a/src/migration-scripts/salt/0-to-1
+++ b/src/migration-scripts/salt/0-to-1
@@ -1,4 +1,4 @@
-# Copyright 2020-2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/snmp/0-to-1 b/src/migration-scripts/snmp/0-to-1
index 03b190cb7..ee334cdc7 100644
--- a/src/migration-scripts/snmp/0-to-1
+++ b/src/migration-scripts/snmp/0-to-1
@@ -1,4 +1,4 @@
-# Copyright 2019-2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/snmp/1-to-2 b/src/migration-scripts/snmp/1-to-2
index 0120f8acb..0d1b0aa21 100644
--- a/src/migration-scripts/snmp/1-to-2
+++ b/src/migration-scripts/snmp/1-to-2
@@ -1,4 +1,4 @@
-# Copyright 2020-2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
@@ -16,7 +16,7 @@
from vyos.configtree import ConfigTree
# We no longer support hashed values prefixed with '0x' to unclutter
-# CLI and also calculate the hases in advance instead of retrieving
+# CLI and also calculate the hashes in advance instead of retrieving
# them after service startup - which was always a bad idea
prefix = '0x'
diff --git a/src/migration-scripts/snmp/2-to-3 b/src/migration-scripts/snmp/2-to-3
index 6d828b619..2cacea007 100644
--- a/src/migration-scripts/snmp/2-to-3
+++ b/src/migration-scripts/snmp/2-to-3
@@ -1,4 +1,4 @@
-# Copyright 2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
@@ -13,7 +13,7 @@
# You should have received a copy of the GNU Lesser General Public License
# along with this library. If not, see <http://www.gnu.org/licenses/>.
-# T4857: Implement FRR SNMP recomendations
+# T4857: Implement FRR SNMP recommendations
# cli changes from:
# set service snmp oid-enable route-table
# To
diff --git a/src/migration-scripts/ssh/0-to-1 b/src/migration-scripts/ssh/0-to-1
index 65b68f509..4acdd4ec3 100644
--- a/src/migration-scripts/ssh/0-to-1
+++ b/src/migration-scripts/ssh/0-to-1
@@ -1,4 +1,4 @@
-# Copyright 2020-2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/ssh/1-to-2 b/src/migration-scripts/ssh/1-to-2
index b601db3b4..7dec65e58 100644
--- a/src/migration-scripts/ssh/1-to-2
+++ b/src/migration-scripts/ssh/1-to-2
@@ -1,4 +1,4 @@
-# Copyright 2020-2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/ssh/2-to-3 b/src/migration-scripts/ssh/2-to-3
new file mode 100644
index 000000000..a3665af1e
--- /dev/null
+++ b/src/migration-scripts/ssh/2-to-3
@@ -0,0 +1,43 @@
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
+#
+# This library is free software; you can redistribute it and/or
+# modify it under the terms of the GNU Lesser General Public
+# License as published by the Free Software Foundation; either
+# version 2.1 of the License, or (at your option) any later version.
+#
+# This library is distributed in the hope that it will be useful,
+# but WITHOUT ANY WARRANTY; without even the implied warranty of
+# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
+# Lesser General Public License for more details.
+#
+# You should have received a copy of the GNU Lesser General Public License
+# along with this library. If not, see <http://www.gnu.org/licenses/>.
+
+# T8098: rijndael-cbc@lysator.liu.se was removed in OpenSSH 6.7 which is used
+# starting with VyOS 1.4 - It is an alias for aes256-cbc which was
+# standardized in RFC4253, adjust CLI accordingly.
+# https://github.com/openssh/openssh-portable/commit/03e93c753d7c223063a
+# Also rename "ciphers" -> "cipher" to follow our CLI guidelines to use
+# singular when possible
+
+from vyos.configtree import ConfigTree
+
+base = ['service', 'ssh']
+
+old_path = base + ['ciphers']
+new_path = base + ['cipher']
+
+def migrate(config: ConfigTree) -> None:
+ if not config.exists(base):
+ # Nothing to do
+ return
+
+ if config.exists(old_path):
+ config.rename(old_path, new_path[-1])
+
+ if config.exists(new_path):
+ deprecated_cipher = 'rijndael-cbc@lysator.liu.se'
+ for cipher in config.return_values(new_path):
+ if cipher == deprecated_cipher:
+ config.delete_value(new_path, value=deprecated_cipher)
+ config.set(new_path, value='aes256-cbc', replace=False)
diff --git a/src/migration-scripts/sstp/0-to-1 b/src/migration-scripts/sstp/0-to-1
index 1bd7d6c6b..f5d5c4715 100644
--- a/src/migration-scripts/sstp/0-to-1
+++ b/src/migration-scripts/sstp/0-to-1
@@ -1,4 +1,4 @@
-# Copyright 2020-2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
@@ -15,7 +15,7 @@
# - migrate from "service sstp-server" to "vpn sstp"
# - remove primary/secondary identifier from nameserver
-# - migrate RADIUS configuration to a more uniform syntax accross the system
+# - migrate RADIUS configuration to a more uniform syntax across the system
# - authentication radius-server x.x.x.x to authentication radius server x.x.x.x
# - authentication radius-settings to authentication radius
# - do not migrate radius server req-limit, use default of unlimited
diff --git a/src/migration-scripts/sstp/1-to-2 b/src/migration-scripts/sstp/1-to-2
index 2349e3c9f..7c127cc93 100644
--- a/src/migration-scripts/sstp/1-to-2
+++ b/src/migration-scripts/sstp/1-to-2
@@ -1,4 +1,4 @@
-# Copyright 2020-2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/sstp/2-to-3 b/src/migration-scripts/sstp/2-to-3
index 4255a896e..db752ad32 100644
--- a/src/migration-scripts/sstp/2-to-3
+++ b/src/migration-scripts/sstp/2-to-3
@@ -1,4 +1,4 @@
-# Copyright 2020-2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/sstp/3-to-4 b/src/migration-scripts/sstp/3-to-4
index fd10985de..dede5e87a 100644
--- a/src/migration-scripts/sstp/3-to-4
+++ b/src/migration-scripts/sstp/3-to-4
@@ -1,4 +1,4 @@
-# Copyright 2021-2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/sstp/4-to-5 b/src/migration-scripts/sstp/4-to-5
index 254e828af..74410006b 100644
--- a/src/migration-scripts/sstp/4-to-5
+++ b/src/migration-scripts/sstp/4-to-5
@@ -1,4 +1,4 @@
-# Copyright 2023-2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/sstp/5-to-6 b/src/migration-scripts/sstp/5-to-6
index fc3cc29b2..9e3ad609d 100644
--- a/src/migration-scripts/sstp/5-to-6
+++ b/src/migration-scripts/sstp/5-to-6
@@ -1,4 +1,4 @@
-# Copyright 2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/system/10-to-11 b/src/migration-scripts/system/10-to-11
index 76d7f23cb..68ff6869c 100644
--- a/src/migration-scripts/system/10-to-11
+++ b/src/migration-scripts/system/10-to-11
@@ -1,4 +1,4 @@
-# Copyright 2019-2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/system/11-to-12 b/src/migration-scripts/system/11-to-12
index 71c359b7e..c71d6eb7e 100644
--- a/src/migration-scripts/system/11-to-12
+++ b/src/migration-scripts/system/11-to-12
@@ -1,4 +1,4 @@
-# Copyright 2019-2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/system/12-to-13 b/src/migration-scripts/system/12-to-13
index 014edba91..b0c1fd8ea 100644
--- a/src/migration-scripts/system/12-to-13
+++ b/src/migration-scripts/system/12-to-13
@@ -1,4 +1,4 @@
-# Copyright 2019-2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/system/13-to-14 b/src/migration-scripts/system/13-to-14
index fbbecbcd3..0c2480bdb 100644
--- a/src/migration-scripts/system/13-to-14
+++ b/src/migration-scripts/system/13-to-14
@@ -1,4 +1,4 @@
-# Copyright 2019-2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/system/14-to-15 b/src/migration-scripts/system/14-to-15
index 281809460..ea1370365 100644
--- a/src/migration-scripts/system/14-to-15
+++ b/src/migration-scripts/system/14-to-15
@@ -1,4 +1,4 @@
-# Copyright 2019-2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/system/15-to-16 b/src/migration-scripts/system/15-to-16
index 7db042930..55642d5d1 100644
--- a/src/migration-scripts/system/15-to-16
+++ b/src/migration-scripts/system/15-to-16
@@ -1,4 +1,4 @@
-# Copyright 2019-2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/system/16-to-17 b/src/migration-scripts/system/16-to-17
index 9fb86af88..5b0c195a1 100644
--- a/src/migration-scripts/system/16-to-17
+++ b/src/migration-scripts/system/16-to-17
@@ -1,4 +1,4 @@
-# Copyright 2020-2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/system/17-to-18 b/src/migration-scripts/system/17-to-18
index 323ef4e65..e0dae4b3b 100644
--- a/src/migration-scripts/system/17-to-18
+++ b/src/migration-scripts/system/17-to-18
@@ -1,4 +1,4 @@
-# Copyright 2020-2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/system/18-to-19 b/src/migration-scripts/system/18-to-19
index 5d9788d70..121706fe5 100644
--- a/src/migration-scripts/system/18-to-19
+++ b/src/migration-scripts/system/18-to-19
@@ -1,4 +1,4 @@
-# Copyright 2020-2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/system/19-to-20 b/src/migration-scripts/system/19-to-20
index cb84e11fc..dd0d2cad1 100644
--- a/src/migration-scripts/system/19-to-20
+++ b/src/migration-scripts/system/19-to-20
@@ -1,4 +1,4 @@
-# Copyright 2020-2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/system/20-to-21 b/src/migration-scripts/system/20-to-21
index 71c283da6..96863290a 100644
--- a/src/migration-scripts/system/20-to-21
+++ b/src/migration-scripts/system/20-to-21
@@ -1,4 +1,4 @@
-# Copyright 2021-2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/system/21-to-22 b/src/migration-scripts/system/21-to-22
index 0e68a6856..fc414c70b 100644
--- a/src/migration-scripts/system/21-to-22
+++ b/src/migration-scripts/system/21-to-22
@@ -1,4 +1,4 @@
-# Copyright 2021-2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/system/22-to-23 b/src/migration-scripts/system/22-to-23
index e49094e4a..177a206e4 100644
--- a/src/migration-scripts/system/22-to-23
+++ b/src/migration-scripts/system/22-to-23
@@ -1,4 +1,4 @@
-# Copyright 2022-2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
@@ -22,7 +22,7 @@ def migrate(config: ConfigTree) -> None:
# Nothing to do
return
- # T4346: drop support to disbale IPv6 address family within the OS Kernel
+ # T4346: drop support to disable IPv6 address family within the OS Kernel
if config.exists(base + ['disable']):
config.delete(base + ['disable'])
# IPv6 address family disable was the only CLI option set - we can cleanup
diff --git a/src/migration-scripts/system/23-to-24 b/src/migration-scripts/system/23-to-24
index feb62bc32..0efd54de7 100644
--- a/src/migration-scripts/system/23-to-24
+++ b/src/migration-scripts/system/23-to-24
@@ -1,4 +1,4 @@
-# Copyright 2022-2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
@@ -43,7 +43,7 @@ def migrate(config: ConfigTree) -> None:
return
# We need a temporary copy of the config tree as the original one needs to be
- # deleted first due to a change iun thge tagNode structure.
+ # deleted first due to a change in the tagNode structure.
config.copy(base, tmp_base)
config.delete(base)
diff --git a/src/migration-scripts/system/24-to-25 b/src/migration-scripts/system/24-to-25
index bdb89902e..d0386f0a7 100644
--- a/src/migration-scripts/system/24-to-25
+++ b/src/migration-scripts/system/24-to-25
@@ -1,4 +1,4 @@
-# Copyright 2022-2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/system/25-to-26 b/src/migration-scripts/system/25-to-26
index 8832f48e5..ae70b174c 100644
--- a/src/migration-scripts/system/25-to-26
+++ b/src/migration-scripts/system/25-to-26
@@ -1,4 +1,4 @@
-# Copyright 2023-2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/system/26-to-27 b/src/migration-scripts/system/26-to-27
index 499e16e08..dc2bcd55e 100644
--- a/src/migration-scripts/system/26-to-27
+++ b/src/migration-scripts/system/26-to-27
@@ -1,4 +1,4 @@
-# Copyright 2023-2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/system/27-to-28 b/src/migration-scripts/system/27-to-28
index 0a5be48ab..896165af4 100644
--- a/src/migration-scripts/system/27-to-28
+++ b/src/migration-scripts/system/27-to-28
@@ -1,4 +1,4 @@
-# Copyright 2023-2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/system/28-to-29 b/src/migration-scripts/system/28-to-29
index ccf7056c4..7d912b612 100644
--- a/src/migration-scripts/system/28-to-29
+++ b/src/migration-scripts/system/28-to-29
@@ -1,4 +1,4 @@
-# Copyright 2025 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
@@ -18,6 +18,16 @@
# - remove syslog user console logging
# - move "global preserve-fqdn" one CLI level up
# - rename "host" to "remote"
+#
+# T8059:
+# - if a syslog remote contains a port (like 192.0.2.1:9000),
+# migrate the port part to the new dedicated "port" option
+#
+# XXX: this script leads to data loss when a config
+# has multiple remotes with the same host address but different ports.
+# That issue needs to be addressed separately (T8058)
+
+import re
from vyos.configtree import ConfigTree
@@ -64,8 +74,35 @@ def migrate(config: ConfigTree) -> None:
config.set(base + ['remote'])
config.set_tag(base + ['remote'])
for remote in config.list_nodes(base + ['host']):
- config.copy(base + ['host', remote], base + ['remote', remote])
- config.set_tag(base + ['remote'])
- if vrf:
- config.set(base + ['remote', remote, 'vrf'], value=vrf)
+ # Check if the host address has a port
+ # to migrate the port part to the new dedicated "port" option
+ res = re.match(r'(?P<host>[^:]+):(?P<port>.*)', remote)
+ if res:
+ remote_host = res.group('host')
+ remote_port = res.group('port')
+ else:
+ remote_host = remote
+ remote_port = None
+
+ # XXX: the fact that it was possible to use node names like "192.0.2.1:9000"
+ # made it possible to create configurations that would send different messages
+ # to different ports on the same server.
+ # At the moment, such configurations are unsupported
+ # so the script only keeps one of such remotes.
+ if config.exists(base + ['remote', remote_host]):
+ # Skip the remote if it already exists
+ # XXX: This tacitly implies that if multiple remotes
+ # with the same address but different ports are used,
+ # only the first one of those makes it into the migrated config.
+ continue
+ else:
+ config.copy(base + ['host', remote], base + ['remote', remote_host])
+
+ if remote_port:
+ config.set(base + ['remote', remote_host, 'port'], value=remote_port)
+
+ config.set_tag(base + ['remote'])
+ if vrf:
+ config.set(base + ['remote', remote_host, 'vrf'], value=vrf)
+
config.delete(base + ['host'])
diff --git a/src/migration-scripts/system/29-to-30 b/src/migration-scripts/system/29-to-30
new file mode 100644
index 000000000..7babde3f3
--- /dev/null
+++ b/src/migration-scripts/system/29-to-30
@@ -0,0 +1,52 @@
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
+#
+# This library is free software; you can redistribute it and/or
+# modify it under the terms of the GNU Lesser General Public
+# License as published by the Free Software Foundation; either
+# version 2.1 of the License, or (at your option) any later version.
+#
+# This library is distributed in the hope that it will be useful,
+# but WITHOUT ANY WARRANTY; without even the implied warranty of
+# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
+# Lesser General Public License for more details.
+#
+# You should have received a copy of the GNU Lesser General Public License
+# along with this library. If not, see <http://www.gnu.org/licenses/>.
+
+# T4251:
+# - drop "tls enable" node (make "tls" a standalone key)
+# - split "tls permitted-peers" list by commas into multiple "tls permitted-peer" entries
+
+from vyos.configtree import ConfigTree
+
+base = ['system', 'syslog', 'remote']
+
+
+def migrate(config: ConfigTree) -> None:
+ if not config.exists(base):
+ return
+
+ # Iterate over all remote syslog server entries (like 172.18.0.5)
+ for remote_addr in config.list_nodes(base):
+ remote_base = base + [remote_addr]
+ tls_base = remote_base + ['tls']
+
+ # (1) Remove "tls enable" -> migrate to simple "tls"
+ enable_path = tls_base + ['enable']
+ if config.exists(enable_path):
+ # Remove obsolete "enable" node
+ config.delete(enable_path)
+
+ # (2) Split "tls permitted-peers" (comma-separated string)
+ permitted_peers_path = tls_base + ['permitted-peers']
+ if config.exists(permitted_peers_path):
+ peers_str = config.return_value(permitted_peers_path)
+ # Split CSV values and normalize whitespace
+ peers = [p.strip() for p in peers_str.split(',') if p.strip()]
+
+ # Create a new "permitted-peer" entry per item
+ for peer in peers:
+ config.set(tls_base + ['permitted-peer'], value=peer, replace=False)
+
+ # Remove the old combined node
+ config.delete(permitted_peers_path)
diff --git a/src/migration-scripts/system/30-to-31 b/src/migration-scripts/system/30-to-31
new file mode 100644
index 000000000..3e57b3db6
--- /dev/null
+++ b/src/migration-scripts/system/30-to-31
@@ -0,0 +1,42 @@
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
+#
+# This library is free software; you can redistribute it and/or
+# modify it under the terms of the GNU Lesser General Public
+# License as published by the Free Software Foundation; either
+# version 2.1 of the License, or (at your option) any later version.
+#
+# This library is distributed in the hope that it will be useful,
+# but WITHOUT ANY WARRANTY; without even the implied warranty of
+# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
+# Lesser General Public License for more details.
+#
+# You should have received a copy of the GNU Lesser General Public License
+# along with this library. If not, see <http://www.gnu.org/licenses/>.
+
+# T7644:
+# FRR 10.5 doesn't have ip protocols:
+# - connected
+# - kernel
+# - table
+#
+# Remove them from
+# - system ip protocol
+# - system ipv6 protocol
+
+from vyos.configtree import ConfigTree
+
+bases = [
+ ['system', 'ip', 'protocol'],
+ ['system', 'ipv6', 'protocol'],
+]
+remove_ip_protocols = ['connected', 'kernel', 'table']
+
+def migrate(config: ConfigTree) -> None:
+ for base in bases:
+ if not config.exists(base):
+ continue
+
+ # Iterate over all ip protocols to remove
+ for protocol in remove_ip_protocols:
+ if config.exists(base + [protocol]):
+ config.delete(base + [protocol])
diff --git a/src/migration-scripts/system/31-to-32 b/src/migration-scripts/system/31-to-32
new file mode 100644
index 000000000..1688b44ed
--- /dev/null
+++ b/src/migration-scripts/system/31-to-32
@@ -0,0 +1,38 @@
+# Copyright (C) VyOS Inc.
+#
+# This library is free software; you can redistribute it and/or
+# modify it under the terms of the GNU Lesser General Public
+# License as published by the Free Software Foundation; either
+# version 2.1 of the License, or (at your option) any later version.
+#
+# This library is distributed in the hope that it will be useful,
+# but WITHOUT ANY WARRANTY; without even the implied warranty of
+# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
+# Lesser General Public License for more details.
+#
+# You should have received a copy of the GNU Lesser General Public License
+# along with this library. If not, see <http://www.gnu.org/licenses/>.
+
+# Serial
+
+from vyos.configtree import ConfigTree
+from vyos.system import disk
+from vyos.system.grub import CFG_VYOS_VARS
+from vyos.system.grub import vars_read
+
+serial_console = 'ttyS0'
+base = ['system', 'console']
+
+def migrate(config: ConfigTree) -> None:
+ if not base:
+ return
+
+ root_dir = disk.find_persistence()
+ vars_file: str = f'{root_dir}/{CFG_VYOS_VARS}'
+ vars_current: dict[str, str] = vars_read(vars_file)
+ # Check if VyOS installation uses serial boot console
+ if vars_current['console_type'] == 'ttyS':
+ # In the past we only supported ttyS0 as boot console, that's why we
+ # can hardcode it ...
+ if config.exists(base + ['device', serial_console]):
+ config.set(base + ['device', serial_console, 'kernel'])
diff --git a/src/migration-scripts/system/6-to-7 b/src/migration-scripts/system/6-to-7
index e91ccc4e9..01d214986 100644
--- a/src/migration-scripts/system/6-to-7
+++ b/src/migration-scripts/system/6-to-7
@@ -1,4 +1,4 @@
-# Copyright 2019-2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/system/7-to-8 b/src/migration-scripts/system/7-to-8
index 64dd4dc93..4e7f8c0e6 100644
--- a/src/migration-scripts/system/7-to-8
+++ b/src/migration-scripts/system/7-to-8
@@ -1,4 +1,4 @@
-# Copyright 2018-2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/system/8-to-9 b/src/migration-scripts/system/8-to-9
index ea5f7af81..f1be35126 100644
--- a/src/migration-scripts/system/8-to-9
+++ b/src/migration-scripts/system/8-to-9
@@ -1,4 +1,4 @@
-# Copyright 2018-2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/vpp/1-to-2 b/src/migration-scripts/vpp/1-to-2
new file mode 100644
index 000000000..822799cc6
--- /dev/null
+++ b/src/migration-scripts/vpp/1-to-2
@@ -0,0 +1,34 @@
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
+#
+# This library is free software; you can redistribute it and/or
+# modify it under the terms of the GNU Lesser General Public
+# License as published by the Free Software Foundation; either
+# version 2.1 of the License, or (at your option) any later version.
+#
+# This library is distributed in the hope that it will be useful,
+# but WITHOUT ANY WARRANTY; without even the implied warranty of
+# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
+# Lesser General Public License for more details.
+#
+# You should have received a copy of the GNU Lesser General Public License
+# along with this library. If not, see <http://www.gnu.org/licenses/>.
+
+# Delete 'vpp settings interface ethX xdp-options no-syscall-lock'
+# since it is set automatically
+
+from vyos.configtree import ConfigTree
+
+base = ['vpp', 'settings', 'interface']
+
+def migrate(config: ConfigTree) -> None:
+ if not config.exists(base):
+ # Nothing to do
+ return
+
+ for iface_name in config.list_nodes(base):
+ xdp_options_base = base + [iface_name, 'xdp-options']
+ if config.exists(xdp_options_base + ['no-syscall-lock']):
+ # Delete no-syscall-lock option from configuration
+ config.delete(xdp_options_base + ['no-syscall-lock'])
+ if config.exists(xdp_options_base) and len(config.list_nodes(xdp_options_base)) == 0:
+ config.delete(xdp_options_base)
diff --git a/src/migration-scripts/vpp/2-to-3 b/src/migration-scripts/vpp/2-to-3
new file mode 100644
index 000000000..655862546
--- /dev/null
+++ b/src/migration-scripts/vpp/2-to-3
@@ -0,0 +1,30 @@
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
+#
+# This library is free software; you can redistribute it and/or
+# modify it under the terms of the GNU Lesser General Public
+# License as published by the Free Software Foundation; either
+# version 2.1 of the License, or (at your option) any later version.
+#
+# This library is distributed in the hope that it will be useful,
+# but WITHOUT ANY WARRANTY; without even the implied warranty of
+# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
+# Lesser General Public License for more details.
+#
+# You should have received a copy of the GNU Lesser General Public License
+# along with this library. If not, see <http://www.gnu.org/licenses/>.
+
+# Remove "vpp sflow sample-rate" since it should be automatically inherited
+# from "system sflow" to prevent conflicts
+
+from vyos.configtree import ConfigTree
+
+base = ['vpp', 'sflow']
+
+def migrate(config: ConfigTree) -> None:
+ if not config.exists(base):
+ # Nothing to do
+ return
+
+ if config.exists(base + ['sample-rate']):
+ # Delete sample-rate option from sFlow configuration
+ config.delete(base + ['sample-rate'])
diff --git a/src/migration-scripts/vpp/3-to-4 b/src/migration-scripts/vpp/3-to-4
new file mode 100644
index 000000000..8c79299f5
--- /dev/null
+++ b/src/migration-scripts/vpp/3-to-4
@@ -0,0 +1,30 @@
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
+#
+# This library is free software; you can redistribute it and/or
+# modify it under the terms of the GNU Lesser General Public
+# License as published by the Free Software Foundation; either
+# version 2.1 of the License, or (at your option) any later version.
+#
+# This library is distributed in the hope that it will be useful,
+# but WITHOUT ANY WARRANTY; without even the implied warranty of
+# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
+# Lesser General Public License for more details.
+#
+# You should have received a copy of the GNU Lesser General Public License
+# along with this library. If not, see <http://www.gnu.org/licenses/>.
+
+# Delete 'vpp settings nat44 no-forwarding'
+# because it will be set automatically (T7972)
+
+
+from vyos.configtree import ConfigTree
+
+base = ['vpp', 'settings', 'nat44']
+
+def migrate(config: ConfigTree) -> None:
+
+ if config.exists(base + ['no-forwarding']):
+ # Delete no-forwarding option from NAT44 settings
+ config.delete(base + ['no-forwarding'])
+ if config.exists(base) and len(config.list_nodes(base)) == 0:
+ config.delete(base)
diff --git a/src/migration-scripts/vpp/4-to-5 b/src/migration-scripts/vpp/4-to-5
new file mode 100644
index 000000000..4eaedc9a1
--- /dev/null
+++ b/src/migration-scripts/vpp/4-to-5
@@ -0,0 +1,35 @@
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
+#
+# This library is free software; you can redistribute it and/or
+# modify it under the terms of the GNU Lesser General Public
+# License as published by the Free Software Foundation; either
+# version 2.1 of the License, or (at your option) any later version.
+#
+# This library is distributed in the hope that it will be useful,
+# but WITHOUT ANY WARRANTY; without even the implied warranty of
+# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
+# Lesser General Public License for more details.
+#
+# You should have received a copy of the GNU Lesser General Public License
+# along with this library. If not, see <http://www.gnu.org/licenses/>.
+
+# Delete node 'driver' and 'xdp-options' from CLI (T8202)
+
+
+from vyos.configtree import ConfigTree
+
+base = ['vpp', 'settings', 'interface']
+
+def migrate(config: ConfigTree) -> None:
+ if not config.exists(base):
+ # Nothing to do
+ return
+
+ for iface_name in config.list_nodes(base):
+ base_driver = base + [iface_name, 'driver']
+ base_xdp_options = base + [iface_name, 'xdp-options']
+ if config.exists(base_driver):
+ # Delete 'driver' node
+ config.delete(base_driver)
+ if config.exists(base_xdp_options):
+ config.delete(base_xdp_options)
diff --git a/src/migration-scripts/vpp/5-to-6 b/src/migration-scripts/vpp/5-to-6
new file mode 100644
index 000000000..cf6812446
--- /dev/null
+++ b/src/migration-scripts/vpp/5-to-6
@@ -0,0 +1,593 @@
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
+#
+# This library is free software; you can redistribute it and/or
+# modify it under the terms of the GNU Lesser General Public
+# License as published by the Free Software Foundation; either
+# version 2.1 of the License, or (at your option) any later version.
+#
+# This library is distributed in the hope that it will be useful,
+# but WITHOUT ANY WARRANTY; without even the implied warranty of
+# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
+# Lesser General Public License for more details.
+#
+# You should have received a copy of the GNU Lesser General Public License
+# along with this library. If not, see <http://www.gnu.org/licenses/>.
+#
+# Migrate 'tcp-flags' to 'tcp-flags is-set' and 'tcp-flags is-not-set' multi-value nodes (T8250)
+#
+# Rename acl 'macip' node to 'mac' (T8252)
+#
+# Rename `vpp settings logging default-log-level` to
+# `vpp settings logging default-level` (T8255)
+#
+# Move 'vpp nat44' and 'vpp settings nat44' to 'vpp nat nat44'.
+# Drop settings for nat workers (T8254)
+#
+# Delete 'ipsec' node and all settings and replace it with single 'ipsec-acceleration' flag (T8262)
+#
+# Unify CPU settings into a single 'cpu-cores' node under 'resource-allocation' (T8268)
+#
+# Convert `vpp settings interface <name> rx-mode` and `vpp kernel-interfaces <name> rx-mode`
+# to `vpp settings interfaces-rx-mode` by choose the worst value from all nodes (T8266)
+#
+# Get rid of 'dpdk-options' section for 'num-*' parameters:
+# - `vpp settings interface <ethN> dpdk-options num-*`
+# - `vpp settings interface <ethN> num-*`
+# and delete `vpp settings interface <ethN> dpdk-options promisc` (T8274)
+#
+# Migrate all resource settings into 'resource-allocation' section (T8261)
+#
+# Move bonding interface from vpp section to 'interfaces vpp bonding' (T8283)
+#
+# Move vxlan interface from vpp section to 'interfaces vpp vxlan' (T8296)
+#
+# Move ipip interface from vpp section to 'interfaces vpp ipip' (T8314)
+#
+# Migrate loopback interface from vpp section to 'interfaces vpp loopback' (T8324)
+#
+# Migrate gre interface to 'interfaces vpp gre', remove interfaces with mode "point-to-multipoint" (T8325)
+#
+# Migrate bridge interface from vpp section to 'interfaces vpp bridge' (T8327)
+#
+# Migrate xconnect interface from vpp section to 'interfaces vpp xconnect' (T8328)
+#
+# Remove vif option from vxlan interface (T8340)
+
+from vyos.configtree import ConfigTree
+
+def _migrate_vpp_acl_tcp_flags(config: ConfigTree) -> None:
+ base = ['vpp', 'acl', 'ip', 'tag-name']
+
+ if not config.exists(base):
+ # Nothing to do
+ return
+
+ for tag_name in config.list_nodes(base):
+ base_tag = base + [tag_name, 'rule']
+ for rule in config.list_nodes(base_tag):
+ base_tcp_flags = base_tag + [rule, 'tcp-flags']
+
+ if not config.exists(base_tcp_flags):
+ return
+
+ flags = config.list_nodes(base_tcp_flags)
+ set_flags = [flag for flag in flags if flag != 'not']
+ not_set_flags = config.list_nodes(base_tcp_flags + ['not'])
+
+ config.delete(base_tcp_flags)
+
+ if set_flags:
+ for flag in set_flags:
+ config.set(base_tcp_flags + ['is-set'], value=flag, replace=False)
+
+ if not_set_flags:
+ for flag in not_set_flags:
+ config.set(base_tcp_flags + ['is-not-set'], value=flag, replace=False)
+
+
+def _migrate_vpp_macip(config: ConfigTree) -> None:
+ base = ['vpp', 'acl']
+ if config.exists(base + ['macip']):
+ config.rename(base + ['macip'], 'mac')
+
+
+def _migrate_vpp_unix_settings(config: ConfigTree) -> None:
+ base_path = ['vpp', 'settings']
+ old_base_path = base_path + ['unix']
+ old_path = old_base_path + ['poll-sleep-usec']
+ new_path = base_path + ['poll-sleep-usec']
+
+ if config.exists(old_path):
+ poll_sleep_usec = config.return_value(old_path)
+ config.set(new_path, value=poll_sleep_usec)
+ config.delete(old_base_path)
+
+
+def _migrate_vpp_log(config: ConfigTree) -> None:
+ base = ['vpp', 'settings', 'logging']
+ if config.exists(base + ['default-log-level']):
+ config.rename(base + ['default-log-level'], 'default-level')
+
+
+def _migrate_vpp_nat44(config: ConfigTree) -> None:
+ base_path = ['vpp', 'nat44']
+ new_base_path = ['vpp', 'nat', 'nat44']
+ settings_path = ['vpp', 'settings', 'nat44']
+
+ if not config.exists(base_path):
+ # Nothing to do
+ return
+
+ if not config.exists(['vpp', 'nat']):
+ config.set(['vpp', 'nat'])
+
+ # copy "vpp nat44" to "vpp nat nat44"
+ config.copy(base_path, new_base_path)
+ config.delete(base_path)
+
+ # move 'vpp settings nat44' to 'vpp nat nat44'
+ if config.exists(settings_path):
+ if config.exists(settings_path + ['session-limit']):
+ session_limit = config.return_value(settings_path + ['session-limit'])
+ config.set(new_base_path + ['session-limit'], value=session_limit)
+ if config.exists(settings_path + ['timeout']):
+ config.copy(settings_path + ['timeout'], new_base_path + ['timeout'])
+ config.delete(settings_path)
+
+
+def _migrate_vpp_ipsec(config: ConfigTree) -> None:
+ base = ['vpp', 'settings']
+
+ if config.exists(base + ['ipsec']):
+ config.set(base + ['ipsec-acceleration'])
+ config.delete(base + ['ipsec'])
+
+
+def _migrate_vpp_cpu(config: ConfigTree) -> None:
+ settings_path = ['vpp', 'settings']
+ cpu_path = settings_path + ['cpu']
+
+ if not config.exists(cpu_path):
+ # Nothing to do
+ return
+
+ # get number of configured workers
+ workers = 0
+
+ if config.exists(cpu_path + ['workers']):
+ workers += int(config.return_value(cpu_path + ['workers']))
+ # add main-core to total workers
+ workers += 1
+
+ if config.exists(cpu_path + ['corelist-workers']):
+ def _count_range(item: str) -> int:
+ if '-' in item:
+ start, end = map(int, item.split('-'))
+ return end - start + 1
+ return 1
+
+ tmp = config.return_values(cpu_path + ['corelist-workers'])
+ workers = sum(_count_range(item) for item in tmp) + 1 # + main core
+
+ # set 'resource-allocation cpu-cores'
+ if workers:
+ config.set(settings_path + ['resource-allocation', 'cpu-cores'], value=str(workers))
+
+ config.delete(cpu_path)
+
+
+def _migrate_vpp_interface_rx_mode(config: ConfigTree) -> None:
+ # Per-interface rx-mode commands
+ external_interface_path = ['vpp', 'settings', 'interface']
+ kernel_interface_path = ['vpp', 'kernel-interfaces']
+
+ # New global interface rx-mode command
+ new_rx_mode_path = ['vpp', 'settings', 'interface-rx-mode']
+
+ def _iter_by_rx_modes(base_path: list):
+ if config.exists(base_path):
+ for iface_name in config.list_nodes(base_path):
+ rx_mode_path = base_path + [iface_name, 'rx-mode']
+ if config.exists(rx_mode_path):
+ rx_mode = config.return_value(rx_mode_path)
+ yield rx_mode, rx_mode_path
+
+ rx_modes = set()
+
+ def _collect_rx_modes(base_path: list):
+ for rx_mode, _ in _iter_by_rx_modes(base_path):
+ rx_modes.add(rx_mode)
+
+ _collect_rx_modes(external_interface_path)
+ _collect_rx_modes(kernel_interface_path)
+
+ if not rx_modes:
+ return
+
+ if 'interrupt' in rx_modes:
+ rx_mode = 'interrupt'
+ elif 'adaptive' in rx_modes:
+ rx_mode = 'adaptive'
+ else:
+ rx_mode = 'polling'
+
+ config.set(new_rx_mode_path, value=rx_mode)
+
+ def _delete_rx_modes(base_path: list):
+ for _, rx_mode_path in _iter_by_rx_modes(base_path):
+ config.delete(rx_mode_path)
+
+ _delete_rx_modes(external_interface_path)
+ _delete_rx_modes(kernel_interface_path)
+
+
+def _migrate_vpp_dpdk_options(config: ConfigTree) -> None:
+ base_path = ['vpp', 'settings', 'interface']
+ params = ['num-rx-desc', 'num-rx-queues', 'num-tx-desc', 'num-tx-queues']
+
+ if not config.exists(base_path):
+ return
+
+ for iface_name in config.list_nodes(base_path):
+ iface_path = base_path + [iface_name]
+ dpdk_path = iface_path + ['dpdk-options']
+
+ if config.exists(dpdk_path):
+ for param in params:
+ param_path = dpdk_path + [param]
+ new_param_path = iface_path + [param]
+
+ if config.exists(param_path):
+ # Move `vpp settings interface <iface_name> dpdk-options num-*`
+ # to `vpp settings interface <iface_name> num-*`
+ config.copy(param_path, new_param_path)
+ config.delete(param_path)
+
+ # Delete `vpp settings interface <iface_name> dpdk-options promisc`
+ promisc_path = dpdk_path + ['promisc']
+ if config.exists(promisc_path):
+ config.delete(promisc_path)
+
+
+def _migrate_vpp_resources(config: ConfigTree) -> None:
+ base = ['vpp', 'settings']
+ new_base = ['vpp', 'settings', 'resource-allocation']
+
+ if not config.exists(new_base):
+ config.set(new_base)
+
+ if config.exists(base + ['buffers']):
+ # copy "settings buffers" to "settings resource-allocation buffers"
+ config.copy(base + ['buffers'], new_base + ['buffers'])
+ config.delete(base + ['buffers'])
+
+ if config.exists(base + ['memory']):
+ # copy "settings memory" to "settings resource-allocation memory"
+ config.copy(base + ['memory'], new_base + ['memory'])
+ config.delete(base + ['memory'])
+
+ if config.exists(base + ['statseg']):
+ # copy "settings statseg" to "settings resource-allocation memory stats"
+ if not config.exists(new_base + ['memory']):
+ config.set(new_base + ['memory'])
+ config.copy(base + ['statseg'], new_base + ['memory', 'stats'])
+ config.delete(base + ['statseg'])
+
+ if config.exists(base + ['ipv6']):
+ # copy "settings ipv6" to "settings resource-allocation ipv6"
+ config.copy(base + ['ipv6'], new_base + ['ipv6'])
+ config.delete(base + ['ipv6'])
+
+ if config.exists(base + ['lcp']):
+ # move "settings lcp ignore-kernel-routes" to "settings resource-allocation ignore-kernel-routes"
+ # and remove "settings lcp netlink" node
+ if config.exists(base + ['lcp', 'ignore-kernel-routes']):
+ config.set(new_base + ['ignore-kernel-routes'])
+ config.delete(base + ['lcp'])
+
+ if config.exists(base + ['l2learn']):
+ # move "settings l2learn limit" to "settings resource-allocation mac-limit"
+ if config.exists(base + ['l2learn', 'limit']):
+ tmp = config.return_value(base + ['l2learn', 'limit'])
+ config.set(new_base + ['mac-limit'], value=tmp)
+ config.delete(base + ['l2learn'])
+
+ if config.exists(base + ['physmem']):
+ # move "settings physmem max-size" to "settings resource-allocation memory physmem-max-size"
+ if config.exists(base + ['physmem', 'max-size']):
+ tmp = config.return_value(base + ['physmem', 'max-size'])
+ config.set(new_base + ['memory', 'physmem-max-size'], value=tmp)
+ config.delete(base + ['physmem'])
+
+ if len(config.list_nodes(new_base)) == 0:
+ config.delete(new_base)
+
+
+def _migrate_interface(config, type, ifname):
+ base = ['vpp', 'interfaces', type]
+ new_base = ['interfaces', 'vpp', type]
+ kernel_interface_base = ['vpp', 'kernel-interfaces']
+
+ kernel_interface_path = base + [ifname, 'kernel-interface']
+ kernel_iface = None
+ if config.exists(kernel_interface_path):
+ kernel_iface = config.return_value(kernel_interface_path)
+ config.delete(kernel_interface_path)
+ new_ifname = f'vpp{ifname}'
+ iface_base = new_base + [new_ifname]
+ config.copy(base + [ifname], iface_base)
+ config.set_tag(new_base)
+
+ if kernel_iface and config.exists(kernel_interface_base + [kernel_iface]):
+ if config.exists(kernel_interface_base + [kernel_iface, 'vif']):
+ config.copy(kernel_interface_base + [kernel_iface, 'vif'], iface_base + ['vif'])
+ if config.exists(kernel_interface_base + [kernel_iface, 'mtu']):
+ config.copy(kernel_interface_base + [kernel_iface, 'mtu'], iface_base + ['mtu'])
+ if config.exists(kernel_interface_base + [kernel_iface, 'address']):
+ config.copy(kernel_interface_base + [kernel_iface, 'address'], iface_base + ['address'])
+ config.delete(kernel_interface_base + [kernel_iface])
+
+
+def _migrate_members_bridge(config, ifname):
+ bridge_path = ['vpp', 'interfaces', 'bridge']
+ if config.exists(bridge_path):
+ for iface in config.list_nodes(bridge_path):
+ tmp = bridge_path + [iface, 'member', 'interface']
+ if config.exists(tmp):
+ for name in config.list_nodes(tmp):
+ if name == ifname:
+ new_name = f'vpp{name}'
+ config.rename(tmp + [name], new_name)
+
+
+def _migrate_members_xconnect(config, ifname):
+ xconnect_path = ['vpp', 'interfaces', 'xconnect']
+ if config.exists(xconnect_path):
+ for iface in config.list_nodes(xconnect_path):
+ tmp = xconnect_path + [iface, 'member', 'interface']
+ if config.exists(tmp):
+ for name in config.return_values(tmp):
+ if name == ifname:
+ new_name = f'vpp{name}'
+ config.delete_value(tmp, name)
+ config.set(tmp, value=new_name, replace=False)
+
+def _migrate_vpp_bonding_interface(config: ConfigTree) -> None:
+ base = ['vpp', 'interfaces', 'bonding']
+ new_base = ['interfaces', 'vpp', 'bonding']
+ kernel_interface_base = ['vpp', 'kernel-interfaces']
+
+ if not config.exists(base):
+ return
+
+ config.set(new_base)
+
+ for ifname in config.list_nodes(base):
+ _migrate_interface(config, 'bonding', ifname)
+
+ for feature in ['nat44', 'cgnat']:
+ for direction in ['inside', 'outside']:
+ tmp_path = ['vpp', 'nat', feature, 'interface', direction]
+
+ if not config.exists(tmp_path):
+ continue
+
+ names = config.return_values(tmp_path)
+ for name in names:
+ if name.split('.')[0] == ifname:
+ new_name = f'vpp{name}'
+ config.delete_value(tmp_path, name)
+ config.set(tmp_path, value=new_name, replace=False)
+
+ ipfix_path = ['vpp', 'ipfix', 'interface']
+ if config.exists(ipfix_path):
+ for name in config.list_nodes(ipfix_path):
+ if name.split('.')[0] == ifname:
+ new_name = f'vpp{name}'
+ config.rename(ipfix_path + [name], new_name)
+
+ _migrate_members_bridge(config, ifname)
+
+ config.delete(base)
+
+ if config.exists(kernel_interface_base) and len(config.list_nodes(kernel_interface_base)) == 0:
+ config.delete(['vpp', 'kernel-interfaces'])
+
+ if len(config.list_nodes(['vpp', 'interfaces'])) == 0:
+ config.delete(['vpp', 'interfaces'])
+
+
+def _migrate_vpp_vxlan_interface(config: ConfigTree) -> None:
+ base = ['vpp', 'interfaces', 'vxlan']
+ new_base = ['interfaces', 'vpp', 'vxlan']
+ kernel_interface_base = ['vpp', 'kernel-interfaces']
+
+ if not config.exists(base):
+ return
+
+ config.set(new_base)
+
+ for ifname in config.list_nodes(base):
+ _migrate_interface(config, 'vxlan', ifname)
+
+ _migrate_members_bridge(config, ifname)
+ _migrate_members_xconnect(config, ifname)
+
+ config.delete(base)
+
+ if config.exists(kernel_interface_base) and len(config.list_nodes(kernel_interface_base)) == 0:
+ config.delete(['vpp', 'kernel-interfaces'])
+
+ if len(config.list_nodes(['vpp', 'interfaces'])) == 0:
+ config.delete(['vpp', 'interfaces'])
+
+
+def _migrate_vpp_ipip_interface(config: ConfigTree) -> None:
+ base = ['vpp', 'interfaces', 'ipip']
+ new_base = ['interfaces', 'vpp', 'ipip']
+ kernel_interface_base = ['vpp', 'kernel-interfaces']
+
+ if not config.exists(base):
+ return
+
+ config.set(new_base)
+
+ for ifname in config.list_nodes(base):
+ _migrate_interface(config, 'ipip', ifname)
+
+ _migrate_members_xconnect(config, ifname)
+
+ config.delete(base)
+
+ if config.exists(kernel_interface_base) and len(config.list_nodes(kernel_interface_base)) == 0:
+ config.delete(['vpp', 'kernel-interfaces'])
+
+ if len(config.list_nodes(['vpp', 'interfaces'])) == 0:
+ config.delete(['vpp', 'interfaces'])
+
+
+def _migrate_vpp_loopback_interface(config: ConfigTree) -> None:
+ base = ['vpp', 'interfaces', 'loopback']
+ new_base = ['interfaces', 'vpp', 'loopback']
+ kernel_interface_base = ['vpp', 'kernel-interfaces']
+
+ if not config.exists(base):
+ return
+
+ config.set(new_base)
+
+ for ifname in config.list_nodes(base):
+ _migrate_interface(config, 'loopback', ifname)
+
+ _migrate_members_bridge(config, ifname)
+
+ config.delete(base)
+
+ if config.exists(kernel_interface_base) and len(config.list_nodes(kernel_interface_base)) == 0:
+ config.delete(['vpp', 'kernel-interfaces'])
+
+ if len(config.list_nodes(['vpp', 'interfaces'])) == 0:
+ config.delete(['vpp', 'interfaces'])
+
+
+def _migrate_vpp_gre_interface(config: ConfigTree) -> None:
+ base = ['vpp', 'interfaces', 'gre']
+ new_base = ['interfaces', 'vpp', 'gre']
+ kernel_interface_base = ['vpp', 'kernel-interfaces']
+
+ if not config.exists(base):
+ return
+
+ config.set(new_base)
+
+ for ifname in config.list_nodes(base):
+ if config.exists(base + [ifname, 'mode']):
+ if config.return_value(base + [ifname, 'mode']) == 'point-to-multipoint':
+ config.delete(base + [ifname])
+ continue
+ config.delete(base + [ifname, 'mode'])
+
+ _migrate_interface(config, 'gre', ifname)
+
+ _migrate_members_bridge(config, ifname)
+ _migrate_members_xconnect(config, ifname)
+
+ config.delete(base)
+
+ if config.exists(kernel_interface_base) and len(config.list_nodes(kernel_interface_base)) == 0:
+ config.delete(['vpp', 'kernel-interfaces'])
+
+ if len(config.list_nodes(['vpp', 'interfaces'])) == 0:
+ config.delete(['vpp', 'interfaces'])
+
+
+def _migrate_vpp_bridge_interface(config: ConfigTree) -> None:
+ base = ['vpp', 'interfaces', 'bridge']
+ new_base = ['interfaces', 'vpp', 'bridge']
+
+ if not config.exists(base):
+ return
+
+ config.set(new_base)
+
+ for ifname in config.list_nodes(base):
+ _migrate_interface(config, 'bridge', ifname)
+
+ config.delete(base)
+
+ if len(config.list_nodes(['vpp', 'interfaces'])) == 0:
+ config.delete(['vpp', 'interfaces'])
+
+
+def _migrate_vpp_xconnect_interface(config: ConfigTree) -> None:
+ base = ['vpp', 'interfaces', 'xconnect']
+ new_base = ['interfaces', 'vpp', 'xconnect']
+
+ if not config.exists(base):
+ return
+
+ config.set(new_base)
+
+ for ifname in config.list_nodes(base):
+ tmp = base + [ifname, 'member', 'interface']
+ bond_found = any(name.startswith('bond') for name in config.return_values(tmp))
+ if bond_found:
+ config.delete(base + [ifname])
+ continue
+
+ _migrate_interface(config, 'xconnect', ifname)
+
+ config.delete(base)
+
+ if len(config.list_nodes(['vpp', 'interfaces'])) == 0:
+ config.delete(['vpp', 'interfaces'])
+
+
+def _migrate_vpp_vxlan_remove_vif(config: ConfigTree) -> None:
+ base = ['interfaces', 'vpp', 'vxlan']
+
+ if not config.exists(base):
+ return
+
+ for ifname in config.list_nodes(base):
+ if config.exists(base + [ifname, 'vif']):
+ config.delete(base + [ifname, 'vif'])
+
+
+def _migrate_vpp_ignore_kernel_routes(config: ConfigTree) -> None:
+ base = ['vpp', 'settings']
+ old_base = base + ['resource-allocation', 'ignore-kernel-routes']
+
+ if config.exists(old_base):
+ config.delete(old_base)
+
+ config.set(base + ['ignore-kernel-routes'])
+
+ if len(config.list_nodes(base + ['resource-allocation'])) == 0:
+ config.delete(base + ['resource-allocation'])
+
+
+def migrate(config: ConfigTree) -> None:
+ if not config.exists(['vpp']):
+ # Nothing to do
+ return
+
+ _migrate_vpp_acl_tcp_flags(config)
+ _migrate_vpp_macip(config)
+ _migrate_vpp_unix_settings(config)
+ _migrate_vpp_log(config)
+ _migrate_vpp_nat44(config)
+ _migrate_vpp_ipsec(config)
+ _migrate_vpp_cpu(config)
+ _migrate_vpp_interface_rx_mode(config)
+ _migrate_vpp_dpdk_options(config)
+ _migrate_vpp_resources(config)
+ _migrate_vpp_bonding_interface(config)
+ _migrate_vpp_vxlan_interface(config)
+ _migrate_vpp_ipip_interface(config)
+ _migrate_vpp_loopback_interface(config)
+ _migrate_vpp_gre_interface(config)
+ _migrate_vpp_bridge_interface(config)
+ _migrate_vpp_xconnect_interface(config)
+ _migrate_vpp_vxlan_remove_vif(config)
+ _migrate_vpp_ignore_kernel_routes(config)
diff --git a/src/migration-scripts/vrf/0-to-1 b/src/migration-scripts/vrf/0-to-1
index 70abae2a8..3a9567ab9 100644
--- a/src/migration-scripts/vrf/0-to-1
+++ b/src/migration-scripts/vrf/0-to-1
@@ -1,4 +1,4 @@
-# Copyright 2021-2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/vrf/1-to-2 b/src/migration-scripts/vrf/1-to-2
index 557a9ec58..2b7dd556c 100644
--- a/src/migration-scripts/vrf/1-to-2
+++ b/src/migration-scripts/vrf/1-to-2
@@ -1,4 +1,4 @@
-# Copyright 2021-2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
@@ -37,7 +37,10 @@ def migrate(config: ConfigTree) -> None:
new_static_base = vrf_base + [vrf, 'protocols']
config.set(new_static_base)
config.copy(static_base, new_static_base + ['static'])
- config.set_tag(new_static_base + ['static', 'route'])
+ if config.exists(new_static_base + ['static', 'route']):
+ config.set_tag(new_static_base + ['static', 'route'])
+ if config.exists(new_static_base + ['static', 'route6']):
+ config.set_tag(new_static_base + ['static', 'route6'])
# Now delete the old configuration
config.delete(base)
diff --git a/src/migration-scripts/vrf/2-to-3 b/src/migration-scripts/vrf/2-to-3
index acacffb41..b43067031 100644
--- a/src/migration-scripts/vrf/2-to-3
+++ b/src/migration-scripts/vrf/2-to-3
@@ -1,4 +1,4 @@
-# Copyright 2021-2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
@@ -76,7 +76,8 @@ def migrate(config: ConfigTree) -> None:
# Get a list of all currently used VRFs and tables
vrfs_current = {}
for vrf in config.list_nodes(base):
- vrfs_current[vrf] = int(config.return_value(base + [vrf, 'table']))
+ if config.exists(base + [vrf, 'table']):
+ vrfs_current[vrf] = int(config.return_value(base + [vrf, 'table']))
# Check VRF names and table numbers
name_regex = re.compile(r'^\d.*$')
diff --git a/src/migration-scripts/vrf/3-to-4 b/src/migration-scripts/vrf/3-to-4
new file mode 100644
index 000000000..959b736e5
--- /dev/null
+++ b/src/migration-scripts/vrf/3-to-4
@@ -0,0 +1,50 @@
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
+#
+# This library is free software; you can redistribute it and/or
+# modify it under the terms of the GNU Lesser General Public
+# License as published by the Free Software Foundation; either
+# version 2.1 of the License, or (at your option) any later version.
+#
+# This library is distributed in the hope that it will be useful,
+# but WITHOUT ANY WARRANTY; without even the implied warranty of
+# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
+# Lesser General Public License for more details.
+#
+# You should have received a copy of the GNU Lesser General Public License
+# along with this library. If not, see <http://www.gnu.org/licenses/>.
+
+# T7664:
+# FRR 10.5 doesn't have ip protocols:
+# - connected
+# - kernel
+# - table
+#
+# Remove them from
+# - vrf name VRF ip protocol
+# - vrf name VRF ipv6 protocol
+
+from vyos.configtree import ConfigTree
+
+subbases = [
+ ['ip', 'protocol'],
+ ['ipv6', 'protocol'],
+]
+remove_ip_protocols = ['connected', 'kernel', 'table']
+
+base = ['vrf', 'name']
+
+def migrate(config: ConfigTree) -> None:
+ if not config.exists(base):
+ # Nothing to do
+ return
+
+ for vrf in config.list_nodes(base):
+ for subbase in subbases:
+ protocol_base = base + [vrf] + subbase
+
+ if not config.exists(protocol_base):
+ continue
+
+ for protocol in remove_ip_protocols:
+ if config.exists(protocol_base + [protocol]):
+ config.delete(protocol_base + [protocol])
diff --git a/src/migration-scripts/vrrp/1-to-2 b/src/migration-scripts/vrrp/1-to-2
index 8639a7553..706537813 100644
--- a/src/migration-scripts/vrrp/1-to-2
+++ b/src/migration-scripts/vrrp/1-to-2
@@ -1,4 +1,4 @@
-# Copyright 2018-2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
@@ -25,7 +25,7 @@ from vyos.configtree import ConfigTree
# It was supported only under ethernet and bonding and their
# respective vif, vif-s, and vif-c subinterfaces
-def get_vrrp_group(path):
+def get_vrrp_group(config, path):
group = {"preempt": True, "rfc_compatibility": False, "disable": False}
if config.exists(path + ["advertise-interval"]):
@@ -115,7 +115,7 @@ def migrate(config: ConfigTree) -> None:
if config.exists(parent_path + vg_path):
pgroups = config.list_nodes(parent_path + vg_path)
for pg in pgroups:
- g = get_vrrp_group(parent_path + vg_path + [pg])
+ g = get_vrrp_group(config, parent_path + vg_path + [pg])
g["interface"] = pi
g["vrid"] = pg
groups.append(g)
@@ -132,7 +132,7 @@ def migrate(config: ConfigTree) -> None:
if config.exists(parent_path + vif_vg_path):
vifgroups = config.list_nodes(parent_path + vif_vg_path)
for vif_group in vifgroups:
- g = get_vrrp_group(parent_path + vif_vg_path + [vif_group])
+ g = get_vrrp_group(config, parent_path + vif_vg_path + [vif_group])
g["interface"] = "{0}.{1}".format(pi, vif)
g["vrid"] = vif_group
groups.append(g)
@@ -147,7 +147,7 @@ def migrate(config: ConfigTree) -> None:
if config.exists(parent_path + vifs_vg_path):
vifsgroups = config.list_nodes(parent_path + vifs_vg_path)
for vifs_group in vifsgroups:
- g = get_vrrp_group(parent_path + vifs_vg_path + [vifs_group])
+ g = get_vrrp_group(config, parent_path + vifs_vg_path + [vifs_group])
g["interface"] = "{0}.{1}".format(pi, vif_s)
g["vrid"] = vifs_group
groups.append(g)
@@ -161,7 +161,7 @@ def migrate(config: ConfigTree) -> None:
vifc_vg_path = [pi, "vif-s", vif_s, "vif-c", vif_c, "vrrp", "vrrp-group"]
vifcgroups = config.list_nodes(parent_path + vifc_vg_path)
for vifc_group in vifcgroups:
- g = get_vrrp_group(parent_path + vifc_vg_path + [vifc_group])
+ g = get_vrrp_group(config, parent_path + vifc_vg_path + [vifc_group])
g["interface"] = "{0}.{1}.{2}".format(pi, vif_s, vif_c)
g["vrid"] = vifc_group
groups.append(g)
@@ -173,7 +173,7 @@ def migrate(config: ConfigTree) -> None:
return
# Otherwise, there is VRRP to convert
-
+
# Now convert the collected groups to the new syntax
base_group_path = ["high-availability", "vrrp", "group"]
sync_path = ["high-availability", "vrrp", "sync-group"]
diff --git a/src/migration-scripts/vrrp/2-to-3 b/src/migration-scripts/vrrp/2-to-3
index 468918f91..f9158de1d 100644
--- a/src/migration-scripts/vrrp/2-to-3
+++ b/src/migration-scripts/vrrp/2-to-3
@@ -1,4 +1,4 @@
-# Copyright 2021-2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/vrrp/3-to-4 b/src/migration-scripts/vrrp/3-to-4
index 9f05cf7a1..bb20979c9 100644
--- a/src/migration-scripts/vrrp/3-to-4
+++ b/src/migration-scripts/vrrp/3-to-4
@@ -1,4 +1,4 @@
-# Copyright 2023-2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/wanloadbalance/3-to-4 b/src/migration-scripts/wanloadbalance/3-to-4
index e49f46a5b..fb3975385 100644
--- a/src/migration-scripts/wanloadbalance/3-to-4
+++ b/src/migration-scripts/wanloadbalance/3-to-4
@@ -1,4 +1,4 @@
-# Copyright 2025 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
diff --git a/src/migration-scripts/webproxy/1-to-2 b/src/migration-scripts/webproxy/1-to-2
index 5a4847474..70b54b1cd 100644
--- a/src/migration-scripts/webproxy/1-to-2
+++ b/src/migration-scripts/webproxy/1-to-2
@@ -1,4 +1,4 @@
-# Copyright 2018-2024 VyOS maintainers and contributors <maintainers@vyos.io>
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public