summaryrefslogtreecommitdiff
path: root/scripts
AgeCommit message (Collapse)Author
4 daysT9147: Bump accel-ppp-ng version to 9874ea3sever-sever-patch-1Viacheslav Hletenko
This version includes a fix for T8391: Bonding interface permission errors with custom Ethernet MTU
4 daysMerge pull request #1255 from dmbaturin/T9140-boot-menu-version-flavorAndrii Klymenko
build: T9140: include version and flavor information in the boot menu
6 daysbuild: T9140: include version and flavor information in the boot menuDaniil Baturin
6 dayskernel: T9138: enable support for Microsoft MANA NIC driverDaniil Baturin
7 daysMerge pull request #1252 from c-po/iproute2Viacheslav Hletenko
iproute2: T8926: add custom build which matches Kernel 6.18
10 daysiproute2: T8926: add custom build which matches Kernel 6.18Christian Breunig
11 daysT9124: Fix smoketest file checksarthurdev
The prior expect of 'No such file or directory' can prevent smoketests from completing if test fails with that same error
11 daysTestsuite: T9021: answer question during test for bash_history migrationChristian Breunig
2026-07-20Merge pull request #1247 from c-po/smoketest-fixesViacheslav Hletenko
T9099: improve test framework - add safeguards
2026-07-20Merge pull request #1248 from c-po/arm64-kernelDaniil Baturin
Kernel: T9103: fix arm64 syscalltbl path breaking linux-perf package build
2026-07-19Kernel: T9103: fix arm64 syscalltbl path breaking linux-perf package buildChristian Breunig
Building linux-perf-* on a native arm64 build host failed with "No rule to make target '.../unistd_64.h'" because arch/arm64/kernel/Makefile.syscalls overrides syscalltbl with a path relative to the kernel root, but tools/lib/perf/Makefile invokes the header generator from tools/lib/perf/ instead. Make the override absolute, matching the srctree-prefixed default.
2026-07-17Testsuite: T9099: harden GRUB console-select navigation with expect() checksChristian Breunig
BOOTLOADERchooseSerialConsole() sent fixed DOWN/ENTER keystrokes with blind sleeps to navigate the post-install GRUB "Boot options" and "Select console type" submenus. Under host load, a dropped keystroke could land navigation one level too deep (e.g. "Select boot mode" instead of "Select console type"). GRUB submenus never time out on their own, so the VM sat there until the unrelated 600s login wait in loginVM() expired, producing a confusing pexpect.TIMEOUT far from the real cause. Add child.expect() checks after each submenu transition to confirm the expected menu actually rendered before sending the next keypress, so a misnavigation now fails fast and points at the right step.
2026-07-17Merge pull request #1246 from c-po/sbom-fixAndrii Klymenko
sbom: T9098: syft should run un squashfs instead of unpacked chroot
2026-07-17Merge pull request #1243 from alexandr-san4ez/T8868-rollingViacheslav Hletenko
Kernel: T8868: Enable crash dump (kdump) and debug info in config
2026-07-16sbom: T9098: syft should run un squashfs instead of unpacked chrootChristian Breunig
lb (live-build) binary runs binary_rootfs first, then binary_grub-efi. binary_grub-efi temporarily installs EFI tooling and then runs: "apt remove --auto-remove --purge --allow-remove-essential" That cleanup is safe for the already-generated squashfs, but it mutates build/chroot and can remove vyos-1x, breaking subsequent work that expects chroot to remain intact for SBOM generation. But why unpacking the squashfs? In an ideal world we could call syft on the compressed squashfs file which is supported. In our world, we do use a BCJ pre-filter chained with LZMA2 for compressing the squashfs, which will increase the compression ratio without a decompression penalty. Difference: ~14.3 MB, ~2.7% smaller This is unsupported by fyft which means we do need to unpack the squashfs first before checking the files and generating the SBOM file.
2026-07-16Merge pull request #1245 from tjjh89017/openssl-fixChristian Breunig
openssl: T9083: fix APT detected package downgrade despite identical versions
2026-07-16openssl: T9083: fix APT detected package downgrade despite identical versionsDate Huang
VyOS rolling APT repo (packages.vyos.net/repositories/rolling) publishing its own openssl/libssl3 packages, pinned at priority 600 (higher than Debian's 500) causes a "poisoning" of the APT cache policy inside the chroot: openssl: Installed: 3.0.20-1~deb12u2 Candidate: 3.0.20-1~deb12u2 Version table: * 3.0.20-1~deb12u2 500 <- debian bookworm + bookworm-security * 3.0.20-1~deb12u2 600 <- packages.vyos.net rolling (same version string, higher pin) * 3.0.17-1~deb12u2 500 <- bookworm-updates This results in APT seeing a version-string tie between Debian's build and the VyOS repo build of the same package and, because of the pin-priority swap, classifies switching to the VyOS repo copy as a "downgrade". This is fixed by appending a clear VyOS related marked to the package version, preventing any possible downgrade detection. Signed-off-by: Date Huang <tjjh89017@hotmail.com> Co-authored-by: Christian Breunig <christian@breunig.cc>
2026-07-15Merge pull request #1239 from c-po/compress-kernel-modulesViacheslav Hletenko
Kernel: T5641: enable module compression to save disk space
2026-07-10Kernel: T8868: Enable crash dump (kdump) and debug info in configOleksandr Kuchmystyi
Enabling the following options allows us to use `kdump-tools`: - `CONFIG_CRASH_DUMP` - `CONFIG_DEBUG_INFO` - `CONFIG_PROC_VMCORE`
2026-07-08Merge pull request #1238 from c-po/kernel-update-6.18.38Christian Breunig
Kernel: T9067: Update Linux Kernel to 6.18.38
2026-07-08Kernel: T5641: add --keep-kernel build option to not call "make mrproper"Christian Breunig
Option useful during development to not automatically clean the Linux Kernel source folder of all its intermediate files.
2026-07-08Kernel: T5641: enable module compression to save disk spaceChristian Breunig
After signing the Linux Kernel modules with the ephemeral key, proceed by compressing the Kernel modules with xz to reduce the final ISO image size. Initial tests have shown a size reduction by 60MiB.
2026-07-08Kernel: T5641: module signing done by common config - remove from arm64Christian Breunig
2026-07-08Kernel: T9067: Update Linux Kernel to 6.18.38Christian Breunig
2026-07-07build: T9058: add a script for building Squid from sourceDaniil Baturin
2026-07-05kernel: T8940: disable HYPERV_VTL_MODE and restore Hyper-V vPCI driverAlex Kudentsov
2026-07-03Merge pull request #1233 from sever-sever/T8508-currViacheslav Hletenko
T9040: Build FIPS-provider OpenSSL version
2026-07-03T9040: Build FIPS-compliant OpenSSL versionViacheslav Hletenko
Build FIPS-compatible OpenSSL binaries The FIPS provider does not get built and installed automatically. To enable it, you need to configure OpenSSL using the `enable-fips` option.
2026-07-01accel-ppp-ng: T9039: update the commit hashDaniil Baturin
for the fix for legacy hash algorithm loading to make MS-CHAP work correctly again
2026-07-01Merge pull request #1228 from c-po/podman-updateDaniil Baturin
podman: T9024: package upgrade from v4.9.5 to v5.8.4
2026-06-30podman: T9024: package upgrade from v4.9.5 to v5.8.4Christian Breunig
This updates the used Podman version from 4.9.5 to 5.8.4 which is a major bump. For this update to work on Vyos we also do need to switch from crun to runc, as the Debian Bookworm provided version of crun is not working with podman 5.8.4. Building crun from Debian trixie package sources does not work due to missing build time dependencies.
2026-06-26Merge pull request #1227 from c-po/bnx2-patchViacheslav Hletenko
Kernel: T8914: add support for 2.5G pluggables on BCM57810S
2026-06-26Merge pull request #1189 from c-po/l2tpv3Daniil Baturin
Kernel: T8605: net/l2tp: allow unmanaged tunnel setup without route to peer
2026-06-25Kernel: T8914: add support for 2.5G pluggables on BCM57810SChristian Breunig
Add the well-known JAMESMTL kernel module patch for bnx2x to advertise 2.5Gbit/s capabilities on Broadcom NetXtreme2-X cards with BCM57810S chipset. This is useful for ISP GPON access networks that use 2.5Gbit/s pluggables and need the NIC to negotiate beyond 1000baseT/Full, avoiding the 940Mbit/s practical cap on overprovisioned 1G services. References: * https://hack-gpon.org/broadcom-57810s/ * https://github.com/JAMESMTL/snippets/blob/dceb2fee74d80c66d/bnx2x/patches/bnx2x_warpcore_8727_2_5g_sgmii_txfault.patch
2026-06-25Kernel: T9010: update existing patches to remove "hunk off" noticesChristian Breunig
2026-06-25Merge pull request #1225 from natali-rs1985/T9013Viacheslav Hletenko
T9013: Add FRR patch to fix BMP connect source-interface deletion
2026-06-24Merge pull request #1224 from c-po/kernel-update-6.18Christian Breunig
T9010: Update Linux Kernel to 6.18.36 and re-fresh Intel OOT driver versions
2026-06-24T9013: Add FRR patch to fix BMP connect source-interface deletionNataliia Solomko
2026-06-23Merge pull request #1175 from hedrok/T8599-fail-build-on-patch-failViacheslav Hletenko
T8599: Make source packages required and fix them
2026-06-23Kernel: T9010: remove Intel NIC Debian postinstall file after buildChristian Breunig
2026-06-23Kernel: T9010: update Intel OOT module driversChristian Breunig
Update versions: * igb v5.20.28 * ixgbe v6.4.4 * ixgbevf v5.3.36 * i40e v2.30.18 * ice v2.6.6 * iavf v4.13.35
2026-06-19Merge pull request #1222 from vyos/T8099-strongswan-6.0Daniil Baturin
T8099: Update strongswan to 6.0.6
2026-06-19T8599: Use .orig suffix for 3.0 source format onlyKyrylo Yatsenko
1.0 source format version needs tarball without '.orig' suffix as described in https://www.man7.org/linux/man-pages/man1/dpkg-source.1.html. Only if debian/source/format exists and contains 3.0, use '.orig'
2026-06-18T8599: dropbear binary-only packageKyrylo Yatsenko
Patch modifies debian/control and debian/rules, there is no easy way to fix source package creation in such case. As quick solution disable source package build for this package (previously it failed silently)
2026-06-18T8599: Don't ignore other build.py failuresKyrylo Yatsenko
Exit with error for other failures: * Creating/installing dependency package should be error: e.g. debugging why strongswan cannot find systemd could be easier if build.py failed when it couldn't install systemd and not when `configure` couldn't find it. * Creating tarball * pre_hook run
2026-06-18T8599: Make source packages required and fix themKyrylo Yatsenko
A lot of packages failed to build source package. Stop ignoring source package build errors and fix it. To fix source packages: * Use <source_package>_<upstream_version>.orig.tar.gz naming for source archive. * Get `source_package` and `upstream_version` from changelog using dpkg-parsechangelog utility * Clean build-deps after usage or dpkg-source sees these files as changes relative to upstream. * Add '.github' to --diff-ignore source option
2026-06-15T861: add secure boot support. Build shim-signed packageasklymenko
2026-06-12T861: add secure boot support. Build shim-signed packageasklymenko
2026-06-10Merge pull request #1221 from c-po/salt-removalViacheslav Hletenko
salt: T8973: remove package build due to feature removal
2026-06-10T8099: Update strongswan to 6.0.6Kyrylo Yatsenko
* Upgrade to 6.0.6 * Update 30-strongswan-configs.chroot to not change /etc/strongswan.d/charon.conf as the file is part of package strongswan-charon that should not be installed * Rebase all patches * Enable ML-KEM for Post Quantum