Age | Commit message (Collapse) | Author |
|
(cherry picked from commit 884de8dc760b461246fe001b662946970da6f930)
|
|
(cherry picked from commit 5978fd1df855d163436e4e9108a32bc2d1157af4)
|
|
kernel: T6286: Enable Generic driver for Hyper-V VMBus (backport #579)
|
|
Generic driver for Hyper-V VMBus is required in Hyper-V environments for direct
access to network devices from userspace.
(cherry picked from commit 999ccad3f8ed35b18eff4cdf6baba6b1b3e87af0)
|
|
ixgbe: T6162: Add 1000BASE-BX support (backport #540)
|
|
(cherry picked from commit fbe43ddcc2ee4a132a135bca688c533a4e9fab15)
|
|
The ixgbe driver did not support the 1000BASE-BX standard so for example FS.com
SFP-GE-BX 1310/1490nm 10km transceiver received an unsupported module error even
with allow_unsupported_sfp enabled.
To solve this problem I created a patch that was accepted by Linux upstream
(https://github.com/torvalds/linux/commit/1b43e0d20f2d007ec4c124b0deaa848ff8d61f4a)
so starting from kernel 6.9 the ixgbe driver will have 1000BASE-BX support,
however VyOS uses the out of tree driver so it is necessary to backport the patch.
(cherry picked from commit a44647f0982f2a6b7a78af80f82e1c650ab0b11e)
|
|
(cherry picked from commit 471ac04b050b2402d5bfa0e2e8eafe5380a4f0a7)
|
|
(cherry picked from commit d9499a16a463aa3fb0d6df791232e13c68f3908a)
|
|
Docker: T6111: update commit ref for vyos1x-config
|
|
|
|
image-tools: T6154: installer prompts to confirm password (backport #569)
|
|
(cherry picked from commit 6fe57a7042e82af3a587376ab014d76dc0920e35)
|
|
(cherry picked from commit eeb1a98a776db56664a504eb4e58df47a24d70cb)
|
|
ntp: T6080: T6123: restrict config.boot.default NTP settings to RFC1918 and fe80::/10, fc00::/7 only (backport #559)
|
|
Adds ipv4/ipv6 localhost, link-local and private address as allowed-clients to NTP service.
(cherry picked from commit d2d083ac579477db4a09b8d71d55e883a488ddf1)
|
|
T6238: Check pull request title action requires the python script (backport #560)
|
|
T6173: fix TypeError: 'NoneType' object is not iterable (backport #565)
|
|
Commit 611cfc85c531 ("T6173: validate allowed characters in ISO image name")
missed the probability that version is a dict member bot empty.
(cherry picked from commit 801def2d7105acc45868c361730e5be5ab4c36ea)
|
|
T6235: Git update actions-label-merge-conflict version (backport #561)
|
|
The `check-pr-title-and-commit-messages.py` that used for the action
is not exists.
Add this script.
(cherry picked from commit 06d12a527eb6601e67c36a740c81974f64752abe)
|
|
Update `actions-label-merge-conflict` due to `Node.js 16 actions are deprecated.`
(cherry picked from commit 252f29949e6cc538d0a63f58a46c34e9447dfe8a)
|
|
(cherry picked from commit b04c480b6059960004f08812b10b38b39862e316)
|
|
T6228: Cleanup of not existing systemd units (backport #556)
|
|
T1797: Delete not exist disable vpp service (backport #555)
|
|
Delete not existing units:
```
06:12:51 Failed to disable unit, unit logd.service does not exist.
06:12:51 Failed to disable unit, unit heartbeat.service does not exist.
```
(cherry picked from commit 0622fa1ee540041715d585cb78296570b7493e30)
|
|
T6173: validate allowed characters in ISO image name (backport #553)
|
|
The builder log:
```
06:12:53 Failed to disable unit, unit vpp.service does not exist.
```
(cherry picked from commit daf8d44060a516a77b0856f5ac9286aeec32bfcb)
|
|
Building custom VyOS version: 1.5-asdf%-202404081841
I: Checking if packages required for VyOS image build are installed
Version contained illegal character(s), allowed: abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789.-+
(cherry picked from commit 611cfc85c531f6b6c55f89503d6d2cdf84213317)
|
|
image-tools: T6207: update test script for prompt for boot config (backport #551)
|
|
(cherry picked from commit 4a8bc369ef7c9ebd8e1ce0d4067fca5f474204a7)
|
|
(cherry picked from commit 0c12b79fd8d13db8e7b9789132a0eb7f5ba27a8d)
|
|
(cherry picked from commit 70ff94dc37cfa7907774c7b07981b22c75a0021b)
|
|
(cherry picked from commit 28c08a784ebdddfe56d8d33b4f28b147ad0a5265)
|
|
(cherry picked from commit 22f3569e994fe1e1f8fb96d81ddd62347d0d9df5)
|
|
(cherry picked from commit 9fed492e1235f38bfa0055911a743609d4f08aac)
|
|
dropbear: T6195: package upgrade 2022.83-1+deb12u1 (backport #547)
|
|
(cherry picked from commit 4417986365472fd9055b12309ba49d88272db04c)
|
|
Fix CVE-2023-48795: (terrapin attack)
The SSH transport protocol with certain OpenSSH extensions allows remote
attackers to bypass integrity checks such that some packets are omitted (from
the extension negotiation message), and a client and server may consequently
end up with a connection for which some security features have been downgraded
or disabled, aka a Terrapin attack.
(cherry picked from commit b17befe2e4e914f3f604bcfa1843f75519d46a4d)
|
|
No need to provide them via the package repository
(cherry picked from commit adab6badd7b1a41bae55d8ae3fa58d213f5ce13d)
|
|
T6033: bump hsflowd version v2.0.55-1 extended PCAP capabilities (backport #544)
|
|
Bump the `hsflowd` version to `v2.0.55-1`
Fixed and extended PCAP capabilities for not hardware/bridge
interfaces (like GRE tunnel interface).
It fixes crashes the daemon if you use tunnel interfaces
```
hsflowd[9160]: PCAP: tun0 has no supported datalink encapsulaton
hsflowd[9160]: Received signal 11
hsflowd[9160]: SIGSEGV, faulty address is (nil)
```
The correct commit fix in https://github.com/sflow/host-sflow/commit/62346aa67240ced0fb16b6725f16d8fa40eaea60
Updated version starts the hsflowd without issues
(cherry picked from commit eb05b77bac542dca906b25f647117c7566380cf2)
|
|
(cherry picked from commit 7fe033b20c23a74028fa088844f4bb993dea83ab)
|
|
|
|
ixgbe: T6155: always enable allow_unsupported_sfp for all NICs by default (backport #538)
|
|
is undefined
This extends an else path with the logic from commit ea7d59a4b ("ixgbe: T6155:
always enable allow_unsupported_sfp for all NICs by default")
(cherry picked from commit 70ac747b2889757e35ac2a90fd77cda9d4b97ebd)
|
|
(cherry picked from commit 311963f379925d56f678f7b173ce6f74cba3d1ce)
|
|
In-tree vs. Out-Of-Tree drivers differ in the way how unsupported transceivers
are defined (uint vs array of int) for the Kernel module parameters.
This results in:
kernel: ixgbe 0000:5e:00.0: failed to initialize because an unsupported SFP+ module type was detected.
kernel: ixgbe 0000:5e:00.0: Reload the driver after installing a supported module.
kernel: ixgbe 0000:5e:00.0: removed PHC on eth6
This patch always enables unsupported SFP+ modules as wo do anyway from
the userspace but only for the first port.
(cherry picked from commit ea7d59a4bf64a854be04ccf7566e1cf95d4e09a8)
|
|
(cherry picked from commit 7552e07320b990d87e3af589e00ec9b2b2241980)
|
|
build: T1449: add default_config field support in flavor files to allow people to easily include a custom default config
|