Age | Commit message (Collapse) | Author | |
---|---|---|---|
2024-08-14 | T6636: firewall: fix firewall template in order to write logs for ↵ | Nicolas Fort | |
default-action in order to match same structure as in rules. This way op-mode command for showing firewall log prints logs for default-actions too | |||
2024-08-14 | T6646: conntrack: in ignore rules, if protocols=all, do not append it to the ↵ | Nicolas Fort | |
rule | |||
2024-08-14 | op_mode: T6651: Add a top level op mode word "execute" | Nataliia Solomko | |
2024-08-13 | T6183: interfaces openvpn: suppport specifying IP protocol version | Lucas Christian | |
2024-08-13 | T5743: HTTPS API ability to import PKI certificates | Nataliia Solomko | |
2024-08-12 | Merge pull request #3958 from natali-rs1985/T6624-current | Christian Breunig | |
suricata: T6624: Make it possible for suricata address groups to reference each other | |||
2024-08-12 | suricata: T6624: Fix for service suricata address-groups cannot be used in ↵ | Nataliia Solomko | |
each other | |||
2024-08-12 | Merge pull request #3970 from lucasec/t6648 | Christian Breunig | |
T6648: dhcpv6-server: align stateless DHCPv6 options with stateful | |||
2024-08-12 | T6648: dhcpv6-server: align stateless DHCPv6 options with stateful | Lucas Christian | |
2024-08-12 | Merge pull request #3937 from jestabro/env-set-alternative | Christian Breunig | |
configd: T6633: inject missing env vars for configfs utility | |||
2024-08-12 | configd: T6633: inject missing env vars for configfs utility | John Estabrook | |
2024-08-12 | Merge pull request #3961 from jestabro/verify-interface-exists-config | John Estabrook | |
configverify: T6642: verify_interface_exists requires config_dict arg | |||
2024-08-12 | configverify: T6642: verify_interface_exists requires config_dict arg | John Estabrook | |
The function verify_interface_exists requires a reference to the ambient config_dict rather than creating an instance. As access is required to the 'interfaces' path, provide as attribute of class ConfigDict, so as not to confuse path searches of script-specific config_dict instances. | |||
2024-08-12 | xml: T6650: add initial op-mode cache support | John Estabrook | |
2024-08-11 | Merge pull request #3965 from kumvijaya/currentcurrent-merge-commit-handling | Christian Breunig | |
T6637: add pr commenting back in un-used import check | |||
2024-08-11 | Merge branch 'current' into current | Vijayakumar A | |
2024-08-10 | Merge pull request #3964 from nicolas-fort/T6643 | Christian Breunig | |
T6643: firewall: fix ip address range parsing on firewall rules. | |||
2024-08-10 | T6637: add pr commenting back in un-used import check | Vijayakumar A | |
2024-08-09 | T6643: firewall: fix ip address range parsing on firewall rules. | Nicolas Fort | |
2024-08-09 | Merge pull request #3960 from jestabro/verify-interface-state-exists | Daniil Baturin | |
qos: T6638: require interface state existence in verify conditional | |||
2024-08-08 | qos: T6638: require interface state existence in verify conditional | John Estabrook | |
2024-08-08 | Merge pull request #3955 from jestabro/configd-in-session-false | Daniil Baturin | |
configd: T6640: enforce in_session returns False under configd | |||
2024-08-07 | configd: T6640: enforce in_session returns False under configd | John Estabrook | |
The CStore in_session check is a false positive outside of a config session if a specific environment variable is set with an existing referent in unionfs. To allow extensions when running under configd and avoid confusion, enforce in_session returns False. | |||
2024-08-06 | Merge pull request #3949 from kumvijaya/current | Daniil Baturin | |
T6637: py files filter added for unused import check | |||
2024-08-06 | smoketest: T6614: add op-mode test for Kernel version (#3946) | Christian Breunig | |
2024-08-06 | Merge pull request #3945 from c-po/T3204-sysctl | Christian Breunig | |
sysctl: T3204: restore sysctl setttings overwritten by tuned | |||
2024-08-06 | T6637: py files filter added for unused import check | Vijayakumar A | |
2024-08-06 | T6634: README: Add image graphs of contributors (#3944) | Viacheslav Hletenko | |
2024-08-05 | sysctl: T3204: restore sysctl setttings overwritten by tuned | Christian Breunig | |
2024-08-05 | Merge pull request #3947 from c-po/openvpn-T6555 | Christian Breunig | |
smoketest: T6555: openvpn: NameError: name 'elf' is not defined | |||
2024-08-05 | smoketest: T6555: openvpn: NameError: name 'elf' is not defined | Christian Breunig | |
2024-08-05 | Merge pull request #3942 from c-po/bugfixes | Daniil Baturin | |
T6560: T4694: T6555: multiple minor bugfixes for package build | |||
2024-08-05 | smoketest: T6555: openvpn: SyntaxError: '(' was never closed | Christian Breunig | |
2024-08-05 | firewall: T4694: fix GRE key include path in XML | Christian Breunig | |
2024-08-05 | GitHub: T6560: checkout pull request HEAD commit instead of merge commit | Christian Breunig | |
2024-08-05 | Merge pull request #3637 from talmakion/feature/T4694/gre-match-fields | Christian Breunig | |
firewall: T4694: Adding GRE flags & fields matches to firewall rules | |||
2024-08-05 | Merge branch 'current' into feature/T4694/gre-match-fields | Christian Breunig | |
2024-08-05 | Merge pull request #3920 from fett0/T6555 | Christian Breunig | |
OPENVPN: T6555: add server-bridge options in mode server | |||
2024-08-05 | Merge pull request #3939 from c-po/unused-imports | Christian Breunig | |
T5873: T6619: remove unused imports | |||
2024-08-04 | firewall: T4694: Adding GRE flags & fields matches to firewall rules | Andrew Topp | |
* Only matching flags and fields used by modern RFC2890 "extended GRE" - this is backwards-compatible, but does not match all possible flags. * There are no nftables helpers for the GRE key field, which is critical to match individual tunnel sessions (more detail in the forum post) * nft expression syntax is not flexible enough for multiple field matches in a single rule and the key offset changes depending on flags. * Thus, clumsy compromise in requiring an explicit match on the "checksum" flag if a key is present, so we know where key will be. In most cases, nobody uses the checksum, but assuming it to be off or automatically adding a "not checksum" match unless told otherwise would be confusing * The automatic "flags key" check when specifying a key doesn't have similar validation, I added it first and it makes sense. I would still like to find a workaround to the "checksum" offset problem. * If we could add 2 rules from 1 config definition, we could match both cases with appropriate offsets, but this would break existing FW generation logic, logging, etc. * Added a "test_gre_match" smoketest | |||
2024-08-04 | Merge pull request #3901 from nicolas-fort/T4072-extend-bridge-fwall | Christian Breunig | |
T4072: firewall extend bridge firewall | |||
2024-08-04 | ipsec: T5873: remove unused imports | Christian Breunig | |
2024-08-04 | multicast: T6619: remove unused imports | Christian Breunig | |
2024-08-02 | Merge pull request #3933 from jestabro/add-missing-standard-func | Daniil Baturin | |
T6632: add missing standard functions to config scripts | |||
2024-08-02 | Merge pull request #3932 from jestabro/check-kmod-under-configd | Daniil Baturin | |
T6629: call check_kmod within a standard config function | |||
2024-08-02 | T6619: Remove the remaining uses of per-protocol FRR configs (#3916) | Roman Khramshin | |
2024-08-02 | T6486: generate OpenVPN use data-ciphers instead of ncp-ciphers (#3930) | Viacheslav Hletenko | |
In the PR https://github.com/vyos/vyos-1x/pull/3823 the ncp-ciphers were replaced with `data-ciphers` fix template for "generate openvpn client-config" | |||
2024-08-02 | OPENVPN: T6555: fix name to bridge | fett0 | |
2024-08-02 | T6632: add missing standard functions to config scripts | John Estabrook | |
2024-08-02 | OPENVPN: T6555: fix name to bridge | fett0 | |