summaryrefslogtreecommitdiff
path: root/src
AgeCommit message (Collapse)Author
2025-12-12isis: T8094: bugfix config migration from 1.3.0-rc1 -> 1.4Christian Breunig
While producing all configtest assert files for VyOS 1.4 it was noted that the the isis-small testcase from fails. This config fragment is not properly migrated when updating from VyOS 1.3.0-rc1 -> 1.4 and using IS-IS. protocols { isis FOO { interface eth1 { bfd } net 49.0001.1921.6800.1002.00 redistribute { ipv4 { connected { level-2 { route-map EXPORT-ISIS } } } } } } and results in loosing IS-IS connectivity. This is due the fact that config.rename() does not work when only using the base tagNode.
2025-12-11Merge pull request #4880 from natali-rs1985/T7972Viacheslav Hletenko
vpp: T7972: Make `nat44 no-forwarding` feature automatically configurable
2025-12-11Merge pull request #4889 from cpcowart/cc/fix-dhcpv6-renew-gateViacheslav Hletenko
T8078: dhcpv6: allow lease renew for pd & parameters
2025-12-10T7819: VPP do not override driver if it is already doneViacheslav Hletenko
The upstream VPP code already writes the ena device ID to new_id So we can remove `ena` from `override_driver()` The kernel does not provide a reliable way to check whether an ID has already been registered, so we simply attempt the write and ignore the FileExistsError. Any other failure is treated as a warning. Fixes this case: Traceback (most recent call last): File "/usr/libexec/vyos/services/vyos-configd", line 156, in run_script script.apply(c) File "/usr/libexec/vyos/conf_mode/vpp.py", line 613, in apply control_host.override_driver( File "/usr/lib/python3/dist-packages/vyos/vpp/control_host.py", line 138, in override_driver Path('/sys/module/vfio_pci/drivers/pci:vfio-pci/new_id').write_text( File "/usr/lib/python3.11/pathlib.py", line 1079, in write_text with self.open(mode='w', encoding=encoding, errors=errors, newline=newline) as f: FileExistsError: [Errno 17] File exists
2025-12-09T8078: dhcpv6: allow lease renew for pd & parametersChris Cowart
The renew command will refuse to restart the dhcp6c process for an interface unless it is configured to request an address, but the client may also be running to manage parameters and/or prefix delegations.
2025-12-08tech-support: T7134: add topology snapshot generation using `hwloc` packageOleksandr Kuchmystyi
This enhances diagnostic capabilities by providing hardware topology visuals within support archives.
2025-12-07Merge pull request #4885 from dmbaturin/T8056-deprecate-salt-minionChristian Breunig
salt: T8056: add a deprecation warning
2025-12-05Merge pull request #4888 from dmbaturin/T7810-fix-pppoe-resetViacheslav Hletenko
op-mode: T7810: fix broken 'reset connection' command
2025-12-05Merge pull request #4826 from nvollmar/T7982Viacheslav Hletenko
T7982: container: generate run arguments once
2025-12-04Merge pull request #4878 from alexandr-san4ez/T8001-currentDaniil Baturin
ipsec: T8001: Commit fails removing VTI interface in IPsec config
2025-12-04Merge pull request #4881 from alexandr-san4ez/T7594-currentDaniil Baturin
ipsec: T7594: Rename `respond` connection-type in IPSec peer settings to `trap`
2025-12-04Merge pull request #4886 from dmbaturin/T8059-migrate-syslog-portsDaniil Baturin
syslog: T8059: migrate host:port node names to the new syntax with a dedicated port option
2025-12-04ipsec: T7594: Rename `respond` connection-type in IPSec peer settings to `trap`Oleksandr Kuchmystyi
The previous 'connection-type respond' option in IPsec site-to-site peers was misleading - instead of passively waiting for peer initiation, it would initiate negotiation when matching traffic appeared, potentially causing SA duplication and renegotiation loops.
2025-12-04vpp: T7972: Make `nat44 no-forwarding` feature automatically configurableNataliia Solomko
If any dynamic rule is configured forwarding should be disabled because each packet must be processed through the NAT session table to apply proper translations
2025-12-04vyos-op-run: T7901: skip permission checks if the user is rootDaniil Baturin
2025-12-04op-mode: T7810: fix broken 'reset connection' commandDaniil Baturin
2025-12-04Merge pull request #4884 from c-po/openvpn-t7738-migrationDaniil Baturin
openvpn: T7738: avoid duplicate certs during 1.3 -> 1.4 migration
2025-12-04salt: T8056: add a deprecation warningDaniil Baturin
2025-12-04syslog: T8059: migrate host:port node names to the new syntaxDaniil Baturin
with a dedicated port option
2025-12-02Merge pull request #4866 from natali-rs1985/T8030Nataliia S.
T8030: VPP: Check support for changed driver too
2025-12-02openvpn: T7738: avoid duplicate certs during 1.3 -> 1.4 migrationChristian Breunig
When migrating from VyOS 1.3 to 1.4, OpenVPN interfaces sharing the same certificate (chain) end up getting duplicated certificate entries, one per interface — instead of reusing a single cert if applicable. This change makes the migration logic detect shared certificates and reuse a single CA and server certificate objects, preventing redundant certificate entries in the config.
2025-12-01interfaces: T8054: use --is-valid-intf-address for validating interface ↵Daniil Baturin
addresses
2025-12-01T8030: VPP: Check support for changed driver tooNataliia Solomko
2025-11-28ipsec: T8001: Commit fails removing VTI interface in IPsec configOleksandr Kuchmystyi
Fix cases where commit or IPsec up/down hooks fail if the VTI interface has already been deleted or the `/tmp/ipsec_vti_interfaces` file does not exist. Changes: - Return empty dict from `get_interface_config()` if it returns None to avoid TypeError when accessing 'operstate' (vti_updown_db.py). - Use `open_vti_updown_db_for_create_or_update()` in `vti‑up‑down` script so the temporary interface tracking file is created automatically when missing.
2025-11-28Merge pull request #4824 from alexandr-san4ez/T4251-currentViacheslav Hletenko
syslog: T4251: Rename "permitted-peers" to "permitted-peer" and improve TLS checks
2025-11-27Merge pull request #4868 from natali-rs1985/T8036Daniil Baturin
vpp: T8036: Commit fails removing nat44 static rule
2025-11-26Merge pull request #4869 from c-po/T8034Christian Breunig
frr: T8034: use dict_search() for routing protocols to check if VRF is used
2025-11-26Merge pull request #4865 from jestabro/check-unsaved-on-upgradeDaniil Baturin
T7319: check for unsaved commits before proceeding with 'add system image'
2025-11-25T7319: check unsaved_commits before upgradeJohn Estabrook
2025-11-25frr: T8034: use dict_search() for routing protocols to check if VRF is usedChristian Breunig
dict_search() is save when passing in keys that do not exist in the dict we are working on.
2025-11-25Merge pull request #4860 from sarthurdev/ping-checkJohn Estabrook
kea: T7913: Fixes for ping-check handling
2025-11-25vpp: T8036: Commit fails removing nat44 static ruleNataliia Solomko
2025-11-24Merge pull request #4672 from apschultz/zone_default_firewall_rulesetSimon
firewall: T7739: Default ruleset for firewall zones
2025-11-24Merge pull request #4861 from c-po/bond-member-mtuChristian Breunig
bond: T8023: validate member interface min/max MTU
2025-11-21bond: T8023: validate member interface min/max MTUChristian Breunig
It is impossible to set the bond interface MTU to be larger or lower then the limits of the underlaying interface MTU. Add proper commit validation and smoketest.
2025-11-20kea: T7913: Fixes for ping-check handlingsarthurdev
- Kea docs state multi-threaded mode is required for ping checking. - Parent scope needs enabling if shared-network/subnet has ping-check enabled.
2025-11-19login: T8024: show user warning for unconfigured TACACS source-addressChristian Breunig
Add a commit-time check and warning to the user if the TACACS source-address is not configured on the system or the given VRF.
2025-11-19login: T8024: show user warning for unconfigured RADIUS source-addressChristian Breunig
Add a commit-time check and warning to the user if the RADIUS source-address (IPv4 or IPv6) is not configured on the system or the given VRF.
2025-11-19login: T8024: fix typo in TACACS error message if all servers are disabledChristian Breunig
2025-11-19Merge pull request #4854 from c-po/veth-fixViacheslav Hletenko
veth: T8017: bugfix KeyError: 'peer_name'
2025-11-19Merge pull request #4850 from sever-sever/T8012Christian Breunig
T8012: Add user vpp to user groups
2025-11-19T8012: Add user vpp to user groupsViacheslav Hletenko
To allow call VPP api without sudo - Get op-mode commands without sudo - Use API call in smoke-tests
2025-11-18Merge pull request #4845 from vyos/T7556Daniil Baturin
T7556: VPP add IPFIX collector configuration
2025-11-18veth: T8017: bugfix KeyError: 'peer_name'Christian Breunig
Use safe dict_search() function to locate veth peer interface name. If no peer is defined an error will be displayed.
2025-11-17T7992: remove unneeded references to OPAM in skel/.bashrcJohn Estabrook
2025-11-14T7556: VPP add IPFIX collector configurationViacheslav Hletenko
Add VPP IPFIX configuration commands: ``` set vpp ipfix active-timeout '8' set vpp ipfix collector 192.0.2.2 port '2055' set vpp ipfix collector 192.0.2.2 source-address '192.0.2.1' set vpp ipfix flowprobe-record 'l2' set vpp ipfix flowprobe-record 'l3' set vpp ipfix flowprobe-record 'l4' set vpp ipfix inactive-timeout '32' set vpp ipfix interface eth0 set vpp ipfix interface eth1 direction 'both' set vpp ipfix interface eth1 flow-variant 'ipv4' ```
2025-11-14T7994: fix regression in check for previous installations on installJohn Estabrook
After T7836: move bind mount of /config to vyos-1x, the bind mount is configured at boot, not within the initrd. On image install, one needs to check for previous installations in the resident directory /opt/vyatta/etc/config of the mounted disk.
2025-11-13T7950: VPP: Unexpected None interface in CGNAT when ethernet subinterface is ↵Nataliia Solomko
removed from vif Do not allow to delete subinterface if it is in use in VPP features
2025-11-13Merge pull request #4835 from natali-rs1985/T7731Nataliia S.
T7731: Static ARP entries are missing after an interface status change
2025-11-12misc: T8008: remove the last remnants of pmacctDaniil Baturin