| Age | Commit message (Collapse) | Author |
|
This version includes a fix for
T8391: Bonding interface permission errors with custom Ethernet MTU
|
|
|
|
|
|
Kernel: T9103: fix arm64 syscalltbl path breaking linux-perf package build
|
|
Building linux-perf-* on a native arm64 build host failed with "No rule to
make target '.../unistd_64.h'" because arch/arm64/kernel/Makefile.syscalls
overrides syscalltbl with a path relative to the kernel root, but
tools/lib/perf/Makefile invokes the header generator from tools/lib/perf/
instead. Make the override absolute, matching the srctree-prefixed default.
|
|
Kernel: T8868: Enable crash dump (kdump) and debug info in config
|
|
openssl: T9083: fix APT detected package downgrade despite identical versions
|
|
VyOS rolling APT repo (packages.vyos.net/repositories/rolling) publishing its
own openssl/libssl3 packages, pinned at priority 600 (higher than Debian's 500)
causes a "poisoning" of the APT cache policy inside the chroot:
openssl:
Installed: 3.0.20-1~deb12u2
Candidate: 3.0.20-1~deb12u2
Version table:
* 3.0.20-1~deb12u2 500 <- debian bookworm + bookworm-security
* 3.0.20-1~deb12u2 600 <- packages.vyos.net rolling (same version string, higher pin)
* 3.0.17-1~deb12u2 500 <- bookworm-updates
This results in APT seeing a version-string tie between Debian's build and the
VyOS repo build of the same package and, because of the pin-priority swap,
classifies switching to the VyOS repo copy as a "downgrade".
This is fixed by appending a clear VyOS related marked to the package version,
preventing any possible downgrade detection.
Signed-off-by: Date Huang <tjjh89017@hotmail.com>
Co-authored-by: Christian Breunig <christian@breunig.cc>
|
|
Kernel: T5641: enable module compression to save disk space
|
|
Enabling the following options allows us to use `kdump-tools`:
- `CONFIG_CRASH_DUMP`
- `CONFIG_DEBUG_INFO`
- `CONFIG_PROC_VMCORE`
|
|
Kernel: T9067: Update Linux Kernel to 6.18.38
|
|
Option useful during development to not automatically clean the Linux Kernel
source folder of all its intermediate files.
|
|
After signing the Linux Kernel modules with the ephemeral key, proceed
by compressing the Kernel modules with xz to reduce the final ISO image
size.
Initial tests have shown a size reduction by 60MiB.
|
|
|
|
|
|
|
|
|
|
T9040: Build FIPS-provider OpenSSL version
|
|
Build FIPS-compatible OpenSSL binaries
The FIPS provider does not get built and installed automatically.
To enable it, you need to configure OpenSSL using the `enable-fips` option.
|
|
for the fix for legacy hash algorithm loading
to make MS-CHAP work correctly again
|
|
podman: T9024: package upgrade from v4.9.5 to v5.8.4
|
|
This updates the used Podman version from 4.9.5 to 5.8.4 which is a major bump.
For this update to work on Vyos we also do need to switch from crun to runc, as
the Debian Bookworm provided version of crun is not working with podman 5.8.4.
Building crun from Debian trixie package sources does not work due to missing
build time dependencies.
|
|
Kernel: T8914: add support for 2.5G pluggables on BCM57810S
|
|
Kernel: T8605: net/l2tp: allow unmanaged tunnel setup without route to peer
|
|
Add the well-known JAMESMTL kernel module patch for bnx2x to advertise 2.5Gbit/s
capabilities on Broadcom NetXtreme2-X cards with BCM57810S chipset.
This is useful for ISP GPON access networks that use 2.5Gbit/s pluggables and
need the NIC to negotiate beyond 1000baseT/Full, avoiding the 940Mbit/s
practical cap on overprovisioned 1G services.
References:
* https://hack-gpon.org/broadcom-57810s/
* https://github.com/JAMESMTL/snippets/blob/dceb2fee74d80c66d/bnx2x/patches/bnx2x_warpcore_8727_2_5g_sgmii_txfault.patch
|
|
|
|
T9013: Add FRR patch to fix BMP connect source-interface deletion
|
|
T9010: Update Linux Kernel to 6.18.36 and re-fresh Intel OOT driver versions
|
|
|
|
T8599: Make source packages required and fix them
|
|
|
|
Update versions:
* igb v5.20.28
* ixgbe v6.4.4
* ixgbevf v5.3.36
* i40e v2.30.18
* ice v2.6.6
* iavf v4.13.35
|
|
T8099: Update strongswan to 6.0.6
|
|
1.0 source format version needs tarball without '.orig' suffix as described in https://www.man7.org/linux/man-pages/man1/dpkg-source.1.html.
Only if debian/source/format exists and contains 3.0, use '.orig'
|
|
Patch modifies debian/control and debian/rules, there is no easy way to
fix source package creation in such case. As quick solution disable
source package build for this package (previously it failed silently)
|
|
Exit with error for other failures:
* Creating/installing dependency package should be error: e.g. debugging
why strongswan cannot find systemd could be easier if build.py failed
when it couldn't install systemd and not when `configure` couldn't
find it.
* Creating tarball
* pre_hook run
|
|
A lot of packages failed to build source package.
Stop ignoring source package build errors and fix it.
To fix source packages:
* Use <source_package>_<upstream_version>.orig.tar.gz naming for source
archive.
* Get `source_package` and `upstream_version` from changelog using
dpkg-parsechangelog utility
* Clean build-deps after usage or dpkg-source sees these files as
changes relative to upstream.
* Add '.github' to --diff-ignore source option
|
|
|
|
|
|
salt: T8973: remove package build due to feature removal
|
|
* Upgrade to 6.0.6
* Update 30-strongswan-configs.chroot to not change
/etc/strongswan.d/charon.conf as the file is part of package
strongswan-charon that should not be installed
* Rebase all patches
* Enable ML-KEM for Post Quantum
|
|
* Remove systemd-dev from dependencies
* Add `set -e` to build_cmd.
Strongswan depends on `systemd` and `systemd-dev`, installing both fails with:
```
The following packages have unmet dependencies:
systemd-dev : Breaks: systemd (< 253-2~) but 252.39-1~deb12u2 is to be installed
E: Unable to correct problems, you have held broken packages.
```
`systemd-dev` contains pkg-config files for systemd and udev, but
current `systemd` package installs identical
`/usr/share/pkgconfig/systemd.pc` - maybe that's why packages cannot be
installed simultaneously.
So remove it from dependencies.
Though the package failed to build, `./build.py` returned 0 as
`build_cmd` has two build commands one after another without any checks
of exit value of first one that builds strongswan. Added `set -e` so
that any failure in any of commands results to build failure.
|
|
T8426: FRR support for EVPN Anycast
|
|
As salt has been marked deprecated via T8056 and is thus deprecated in VyOS 1.5
and VyOS 1.4 it is time to remove it from the rolling release.
|
|
|
|
|
|
PR #1204 ("ci: T8943: migrate branch-name refs current->rolling (rollout
1c)") covered .github/workflows/ only and missed seven commit_id values
in scripts/package-build/ that referenced the pre-1c default-branch
names of vyos-owned repos.
The GitHub branch-rename redirect works for the REST API and web UI,
not for git refs in a fresh clone — scripts/package-build/build.py
clones the upstream and `git checkout <commit_id>`, which fails after
the source repo was renamed.
Updated:
libnss-mapuser/package.toml current -> rolling
libpam-radius-auth/package.toml current -> rolling
vpp/package.toml (vyos-vpp-patches) current -> rolling
vyos-1x/package.toml current -> rolling
tacacs/package.toml (libtacplus-map) master -> rolling
tacacs/package.toml (libpam-tacplus) master -> rolling
tacacs/package.toml (libnss-tacplus) master -> rolling
Verified post-rename defaults via `gh api repos/vyos/<r> --jq
.default_branch` for all seven; verified the failure mode via a fresh
`git clone https://github.com/vyos/vyos-1x.git` + `git checkout current`
which errors with "pathspec 'current' did not match any file(s) known
to git".
LTS branches (sagitta/circinus/equuleus) were scanned and require no
changes — only third-party `evgeny-gridasov/openvpn-otp` master appears
there, unaffected by 1c.
🤖 Generated by [robots](https://vyos.io)
|
|
|
|
Add FRR patch for better MACVLAN support in FRR code.
|
|
The Kernel 6.18.33 now has an upstream fix for the fragnesia vulnerability
|