Age | Commit message (Collapse) | Author | |
---|---|---|---|
2024-09-14 | T861: add UEFI Secure Boot support | Christian Breunig | |
This adds support for UEFI Secure Boot. It adds the missing pieces to the Linux Kernel and enforces module signing. This results in an additional security layer where untrusted (unsigned) Kernel modules can no longer be loaded into the live system. NOTE: This commit will not work unless signing keys are present. Arbitrary keys can be generated using instructions found in: data/live-build-config/includes.chroot/var/lib/shim-signed/mok/README.md | |||
2024-07-23 | podman: T6598: add custom podman build for version 4.9.5 | Christian Breunig | |
2024-05-16 | hooks: T6346: set default boot target to multi-user.target | Christian Breunig | |
2024-05-14 | Merge pull request #582 from 0xThiebaut/suricata | Christian Breunig | |
suricata: T751: Disable suricata.service by default | |||
2024-05-14 | T3420: Remove service upnp | Viacheslav Hletenko | |
2024-05-03 | suricata: T751: Disable suricata.service by default | Maxime THIEBAUT | |
2024-04-11 | Merge pull request #556 from sever-sever/T6228 | Christian Breunig | |
T6228: Cleanup of not existing systemd units | |||
2024-04-11 | T6228: Cleanup of not existing systemd units | Viacheslav Hletenko | |
Delete not existing units: ``` 06:12:51 Failed to disable unit, unit logd.service does not exist. 06:12:51 Failed to disable unit, unit heartbeat.service does not exist. ``` | |||
2024-04-11 | T1797: Delete not exist disable vpp service | Viacheslav Hletenko | |
The builder log: ``` 06:12:53 Failed to disable unit, unit vpp.service does not exist. ``` | |||
2023-12-20 | ssh: T5841: Remove ssh-session-cleanup.service | Indrajit Raychaudhuri | |
With libpam-systemd >= 230-2, ssh-session-cleanup.service is no longer necessary because when `UsePAM yes` in `/etc/ssh/sshd_config` (which is the default), SSH sessions are cleaned up automatically when ssh-server is shutdown or the system is rebooted. | |||
2023-12-09 | Merge pull request #336 from sarthurdev/kea | Christian Breunig | |
dhcp: T3316: Disable Kea services | |||
2023-12-03 | T4426: disable arpwatch.service by default | Christian Breunig | |
2023-11-15 | image: T4516: enable vyos-grub-update service | John Estabrook | |
2023-10-05 | dhcp: T3316: Disable Kea services | sarthurdev | |
2023-10-04 | T5589: Nonstripped binaries exists in VyOS | Apachez | |
2023-09-26 | T5589: Nonstripped binaries exists in VyOS | Apachez | |
2023-09-26 | T5589: Nonstripped binaries exists in VyOS | Apachez | |
2023-09-16 | T5511: drop empty hooks | Christian Breunig | |
This is a roundup commit to 0be277647 ("T5511: Cleanup of unused directories (and files) in order to shrink image-size") that dropy empty/commented out live-build hook scripts. | |||
2023-09-16 | T5511: Cleanup of unused directories (and files) in order to shrink image-size | Apachez | |
2023-09-14 | live: T5568: Add serial boot option to live ISO | sarthurdev | |
2023-09-11 | frr: T5239: remove daemons.conf generated by chroot hook | Christian Breunig | |
Daemon configuration is now generated during boot via vyos-1x repo. See https://github.com/vyos/vyos-1x/pull/2245 | |||
2023-09-01 | frr: T5518: enable pim6d | Christian Breunig | |
2023-08-30 | T5524: Add config directory for livecd | Viacheslav Hletenko | |
Add the '/config' directory for live image boot One of the reasons the DHCP-server uses lease from this directory T2958 | |||
2023-08-27 | T5511: Cleanup of unused directories (and files) in order to shrink image-size | Apachez | |
2023-08-24 | T5468: Remove unused manpages to free up space | Apachez | |
2023-08-08 | T5448: Disable zabbix-agent service by default | Viacheslav Hletenko | |
2023-08-06 | systemd: T5003: sendmail.service no longer exists | Christian Breunig | |
2023-08-05 | systemd: T5003: cleanup timers | Christian Breunig | |
2023-08-04 | frr: T5415: make mgmtd only listen on localhost | Christian Breunig | |
2023-07-15 | T3355: enable vyos-router.service | Christian Breunig | |
2023-06-27 | T1797: Disable vpp.service | Viacheslav Hletenko | |
2023-06-08 | T5003: disable non required GPG user services | Christian Breunig | |
2023-06-08 | T5239: disable FRR service - will by started in order by VyOS startup | Christian Breunig | |
2023-05-21 | T5003: disable sendmail service | Christian Breunig | |
2023-05-17 | T5208: disable nvmf-autoconnect.service | Christian Breunig | |
2023-05-05 | T5203: Disable by default vyos-wan-load-balance.service | Viacheslav Hletenko | |
2023-04-11 | Revert "systemd: services: remove autostart of sendmail and rsyslogd" | Christian Breunig | |
This reverts commit 0b91d71b9cd7e9641287433ea0d0fed3982edb23. Somehow FRR does not like it to be started with no logging daemon present and Smoketests fail. | |||
2023-04-08 | systemd: services: remove autostart of sendmail and rsyslogd | Christian Breunig | |
2023-04-04 | T5142: systemd-journald-audit must not show logs from auditd | Viacheslav Hletenko | |
auditd logs must no be displayed for journalctl mask it | |||
2023-03-14 | T5086: Disable by default hsflowd service | Viacheslav Hletenko | |
2023-03-11 | systemd: services: T5003: disable podman services | Christian Breunig | |
2023-03-07 | T4977: Enable Babeld | Yuxiang Zhu | |
Babeld support has been merged https://github.com/vyos/vyos-1x/pull/1800 however I just noticed `/etc/frr/daemons` came from this file. | |||
2023-02-15 | Merge pull request #306 from sarthurdev/bookworm | Christian Breunig | |
debian: T5003: Upgrade base system to Debian 12 "Bookworm" | |||
2023-02-14 | strongSwan: T4593: move to charon-systemd | Christian Breunig | |
2023-02-13 | debian: T5003: Disable `strongswan.service` provided by charon_systemd | sarthurdev | |
2023-01-31 | Revert "Resolve resource deadlock for udev iface shuffle" | Christian Poessinger | |
This reverts commit 8e6d765be123be9d937970ee96b7d6d0b5053ed5. This breaks existing configurations: https://forum.vyos.io/t/yesterday-and-todays-build-causes-network-interface-getting-corrupted-vyos-1-4-rolling-202301280924-amd64-iso | |||
2023-01-29 | Resolve resource deadlock for udev iface shuffle | RageLtMan | |
UDEV contains a default rule triggered early-on which renames all NICs by their index to eX, systemd-udevd subsequently renames the eX interface to ethX. Systemd-udevd can fail to rename the iface if it still has resource locks from the prior renaming which then fails to apply all manner of configurations resulting in a booted zombie which cannot handle L3 traffic. Fix the concern by removing 62-temporary-interface-rename.rules from /etc/udev/rules.d during the cleanup hook executed in data/live-build-config/hooks/live/82-cleanup-udev-rules.chroot. Testing: Boot-tested in OpenStack under identical infrastructure-as-code states. Verified DHCP-assigned routes, execution of cloud-init, and configuration stanzas injected through cloud-init applied to the FW and system. | |||
2023-01-14 | ntp: T3008: move from ntpd to chrony | Christian Breunig | |
2023-01-09 | Revert "systemd: T4593: disable strongswan service by default" | Christian Poessinger | |
This reverts commit 0351b37359517dab1a18379d180a01fd5271802e. | |||
2022-12-27 | systemd: T4593: disable strongswan service by default | Christian Poessinger | |