summaryrefslogtreecommitdiff
path: root/scripts/package-build
AgeCommit message (Collapse)Author
4 daysT9147: Bump accel-ppp-ng version to 9874ea3sever-sever-patch-1Viacheslav Hletenko
This version includes a fix for T8391: Bonding interface permission errors with custom Ethernet MTU
6 dayskernel: T9138: enable support for Microsoft MANA NIC driverDaniil Baturin
10 daysiproute2: T8926: add custom build which matches Kernel 6.18Christian Breunig
2026-07-20Merge pull request #1248 from c-po/arm64-kernelDaniil Baturin
Kernel: T9103: fix arm64 syscalltbl path breaking linux-perf package build
2026-07-19Kernel: T9103: fix arm64 syscalltbl path breaking linux-perf package buildChristian Breunig
Building linux-perf-* on a native arm64 build host failed with "No rule to make target '.../unistd_64.h'" because arch/arm64/kernel/Makefile.syscalls overrides syscalltbl with a path relative to the kernel root, but tools/lib/perf/Makefile invokes the header generator from tools/lib/perf/ instead. Make the override absolute, matching the srctree-prefixed default.
2026-07-17Merge pull request #1243 from alexandr-san4ez/T8868-rollingViacheslav Hletenko
Kernel: T8868: Enable crash dump (kdump) and debug info in config
2026-07-16Merge pull request #1245 from tjjh89017/openssl-fixChristian Breunig
openssl: T9083: fix APT detected package downgrade despite identical versions
2026-07-16openssl: T9083: fix APT detected package downgrade despite identical versionsDate Huang
VyOS rolling APT repo (packages.vyos.net/repositories/rolling) publishing its own openssl/libssl3 packages, pinned at priority 600 (higher than Debian's 500) causes a "poisoning" of the APT cache policy inside the chroot: openssl: Installed: 3.0.20-1~deb12u2 Candidate: 3.0.20-1~deb12u2 Version table: * 3.0.20-1~deb12u2 500 <- debian bookworm + bookworm-security * 3.0.20-1~deb12u2 600 <- packages.vyos.net rolling (same version string, higher pin) * 3.0.17-1~deb12u2 500 <- bookworm-updates This results in APT seeing a version-string tie between Debian's build and the VyOS repo build of the same package and, because of the pin-priority swap, classifies switching to the VyOS repo copy as a "downgrade". This is fixed by appending a clear VyOS related marked to the package version, preventing any possible downgrade detection. Signed-off-by: Date Huang <tjjh89017@hotmail.com> Co-authored-by: Christian Breunig <christian@breunig.cc>
2026-07-15Merge pull request #1239 from c-po/compress-kernel-modulesViacheslav Hletenko
Kernel: T5641: enable module compression to save disk space
2026-07-10Kernel: T8868: Enable crash dump (kdump) and debug info in configOleksandr Kuchmystyi
Enabling the following options allows us to use `kdump-tools`: - `CONFIG_CRASH_DUMP` - `CONFIG_DEBUG_INFO` - `CONFIG_PROC_VMCORE`
2026-07-08Merge pull request #1238 from c-po/kernel-update-6.18.38Christian Breunig
Kernel: T9067: Update Linux Kernel to 6.18.38
2026-07-08Kernel: T5641: add --keep-kernel build option to not call "make mrproper"Christian Breunig
Option useful during development to not automatically clean the Linux Kernel source folder of all its intermediate files.
2026-07-08Kernel: T5641: enable module compression to save disk spaceChristian Breunig
After signing the Linux Kernel modules with the ephemeral key, proceed by compressing the Kernel modules with xz to reduce the final ISO image size. Initial tests have shown a size reduction by 60MiB.
2026-07-08Kernel: T5641: module signing done by common config - remove from arm64Christian Breunig
2026-07-08Kernel: T9067: Update Linux Kernel to 6.18.38Christian Breunig
2026-07-07build: T9058: add a script for building Squid from sourceDaniil Baturin
2026-07-05kernel: T8940: disable HYPERV_VTL_MODE and restore Hyper-V vPCI driverAlex Kudentsov
2026-07-03Merge pull request #1233 from sever-sever/T8508-currViacheslav Hletenko
T9040: Build FIPS-provider OpenSSL version
2026-07-03T9040: Build FIPS-compliant OpenSSL versionViacheslav Hletenko
Build FIPS-compatible OpenSSL binaries The FIPS provider does not get built and installed automatically. To enable it, you need to configure OpenSSL using the `enable-fips` option.
2026-07-01accel-ppp-ng: T9039: update the commit hashDaniil Baturin
for the fix for legacy hash algorithm loading to make MS-CHAP work correctly again
2026-07-01Merge pull request #1228 from c-po/podman-updateDaniil Baturin
podman: T9024: package upgrade from v4.9.5 to v5.8.4
2026-06-30podman: T9024: package upgrade from v4.9.5 to v5.8.4Christian Breunig
This updates the used Podman version from 4.9.5 to 5.8.4 which is a major bump. For this update to work on Vyos we also do need to switch from crun to runc, as the Debian Bookworm provided version of crun is not working with podman 5.8.4. Building crun from Debian trixie package sources does not work due to missing build time dependencies.
2026-06-26Merge pull request #1227 from c-po/bnx2-patchViacheslav Hletenko
Kernel: T8914: add support for 2.5G pluggables on BCM57810S
2026-06-26Merge pull request #1189 from c-po/l2tpv3Daniil Baturin
Kernel: T8605: net/l2tp: allow unmanaged tunnel setup without route to peer
2026-06-25Kernel: T8914: add support for 2.5G pluggables on BCM57810SChristian Breunig
Add the well-known JAMESMTL kernel module patch for bnx2x to advertise 2.5Gbit/s capabilities on Broadcom NetXtreme2-X cards with BCM57810S chipset. This is useful for ISP GPON access networks that use 2.5Gbit/s pluggables and need the NIC to negotiate beyond 1000baseT/Full, avoiding the 940Mbit/s practical cap on overprovisioned 1G services. References: * https://hack-gpon.org/broadcom-57810s/ * https://github.com/JAMESMTL/snippets/blob/dceb2fee74d80c66d/bnx2x/patches/bnx2x_warpcore_8727_2_5g_sgmii_txfault.patch
2026-06-25Kernel: T9010: update existing patches to remove "hunk off" noticesChristian Breunig
2026-06-25Merge pull request #1225 from natali-rs1985/T9013Viacheslav Hletenko
T9013: Add FRR patch to fix BMP connect source-interface deletion
2026-06-24Merge pull request #1224 from c-po/kernel-update-6.18Christian Breunig
T9010: Update Linux Kernel to 6.18.36 and re-fresh Intel OOT driver versions
2026-06-24T9013: Add FRR patch to fix BMP connect source-interface deletionNataliia Solomko
2026-06-23Merge pull request #1175 from hedrok/T8599-fail-build-on-patch-failViacheslav Hletenko
T8599: Make source packages required and fix them
2026-06-23Kernel: T9010: remove Intel NIC Debian postinstall file after buildChristian Breunig
2026-06-23Kernel: T9010: update Intel OOT module driversChristian Breunig
Update versions: * igb v5.20.28 * ixgbe v6.4.4 * ixgbevf v5.3.36 * i40e v2.30.18 * ice v2.6.6 * iavf v4.13.35
2026-06-19Merge pull request #1222 from vyos/T8099-strongswan-6.0Daniil Baturin
T8099: Update strongswan to 6.0.6
2026-06-19T8599: Use .orig suffix for 3.0 source format onlyKyrylo Yatsenko
1.0 source format version needs tarball without '.orig' suffix as described in https://www.man7.org/linux/man-pages/man1/dpkg-source.1.html. Only if debian/source/format exists and contains 3.0, use '.orig'
2026-06-18T8599: dropbear binary-only packageKyrylo Yatsenko
Patch modifies debian/control and debian/rules, there is no easy way to fix source package creation in such case. As quick solution disable source package build for this package (previously it failed silently)
2026-06-18T8599: Don't ignore other build.py failuresKyrylo Yatsenko
Exit with error for other failures: * Creating/installing dependency package should be error: e.g. debugging why strongswan cannot find systemd could be easier if build.py failed when it couldn't install systemd and not when `configure` couldn't find it. * Creating tarball * pre_hook run
2026-06-18T8599: Make source packages required and fix themKyrylo Yatsenko
A lot of packages failed to build source package. Stop ignoring source package build errors and fix it. To fix source packages: * Use <source_package>_<upstream_version>.orig.tar.gz naming for source archive. * Get `source_package` and `upstream_version` from changelog using dpkg-parsechangelog utility * Clean build-deps after usage or dpkg-source sees these files as changes relative to upstream. * Add '.github' to --diff-ignore source option
2026-06-15T861: add secure boot support. Build shim-signed packageasklymenko
2026-06-12T861: add secure boot support. Build shim-signed packageasklymenko
2026-06-10Merge pull request #1221 from c-po/salt-removalViacheslav Hletenko
salt: T8973: remove package build due to feature removal
2026-06-10T8099: Update strongswan to 6.0.6Kyrylo Yatsenko
* Upgrade to 6.0.6 * Update 30-strongswan-configs.chroot to not change /etc/strongswan.d/charon.conf as the file is part of package strongswan-charon that should not be installed * Rebase all patches * Enable ML-KEM for Post Quantum
2026-06-10T8099: Fix strongswan buildKyrylo Yatsenko
* Remove systemd-dev from dependencies * Add `set -e` to build_cmd. Strongswan depends on `systemd` and `systemd-dev`, installing both fails with: ``` The following packages have unmet dependencies: systemd-dev : Breaks: systemd (< 253-2~) but 252.39-1~deb12u2 is to be installed E: Unable to correct problems, you have held broken packages. ``` `systemd-dev` contains pkg-config files for systemd and udev, but current `systemd` package installs identical `/usr/share/pkgconfig/systemd.pc` - maybe that's why packages cannot be installed simultaneously. So remove it from dependencies. Though the package failed to build, `./build.py` returned 0 as `build_cmd` has two build commands one after another without any checks of exit value of first one that builds strongswan. Added `set -e` so that any failure in any of commands results to build failure.
2026-06-10Merge pull request #1199 from hedrok/T8426-evpn-anycast-arpChristian Breunig
T8426: FRR support for EVPN Anycast
2026-06-09salt: T8973: remove package build due to feature removalChristian Breunig
As salt has been marked deprecated via T8056 and is thus deprecated in VyOS 1.5 and VyOS 1.4 it is time to remove it from the rolling release.
2026-06-08T8969: vyos-build failing to build, missing dependencies. Modify gitignore fileasklymenko
2026-06-08T8969: vyos-build failing to build, missing dependencies. Add build scriptsasklymenko
2026-05-30T8943: scripts/package-build: migrate broken commit_id refs after 1c renameYuriy Andamasov
PR #1204 ("ci: T8943: migrate branch-name refs current->rolling (rollout 1c)") covered .github/workflows/ only and missed seven commit_id values in scripts/package-build/ that referenced the pre-1c default-branch names of vyos-owned repos. The GitHub branch-rename redirect works for the REST API and web UI, not for git refs in a fresh clone — scripts/package-build/build.py clones the upstream and `git checkout <commit_id>`, which fails after the source repo was renamed. Updated: libnss-mapuser/package.toml current -> rolling libpam-radius-auth/package.toml current -> rolling vpp/package.toml (vyos-vpp-patches) current -> rolling vyos-1x/package.toml current -> rolling tacacs/package.toml (libtacplus-map) master -> rolling tacacs/package.toml (libpam-tacplus) master -> rolling tacacs/package.toml (libnss-tacplus) master -> rolling Verified post-rename defaults via `gh api repos/vyos/<r> --jq .default_branch` for all seven; verified the failure mode via a fresh `git clone https://github.com/vyos/vyos-1x.git` + `git checkout current` which errors with "pathspec 'current' did not match any file(s) known to git". LTS branches (sagitta/circinus/equuleus) were scanned and require no changes — only third-party `evgeny-gridasov/openvpn-otp` master appears there, unaffected by 1c. 🤖 Generated by [robots](https://vyos.io)
2026-05-28Kernel: T8938: consolidate build time options for amd64 and arm64 WWANChristian Breunig
2026-05-27T8426: FRR support for EVPN AnycastKyrylo Yatsenko
Add FRR patch for better MACVLAN support in FRR code.
2026-05-23Kernel: T8919: Update Linux Kernel to 6.18.33Christian Breunig
The Kernel 6.18.33 now has an upstream fix for the fragnesia vulnerability