summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authoromnom62 <75066712+omnom62@users.noreply.github.com>2026-10-07 08:00:25 +1000
committerGitHub <noreply@github.com>2026-10-07 08:00:25 +1000
commit1b31896216f44526129a8338fcbd08611761e418 (patch)
treed8e80b4b7528b38f9504511bbb21d5c37b00c391
parent413a35326209e0fc830a8e332ccf5da421ef1e80 (diff)
downloadvyos.vyos-6.1.0.tar.gz
vyos.vyos-6.1.0.zip
Release 6.1.0 commit (#502)HEAD6.1.0main
-rw-r--r--CHANGELOG.rst62
-rw-r--r--changelogs/changelog.yaml142
-rw-r--r--changelogs/fragments/T6890_all_boolean.yml2
-rw-r--r--changelogs/fragments/T7260_edgecase_commands.yml2
-rw-r--r--changelogs/fragments/T7496_firewall_global_fix_disabling_src_route.yml2
-rw-r--r--changelogs/fragments/T7943-fix-sanity.yml2
-rw-r--r--changelogs/fragments/T8205_vyos_user_aggregate_fix.yml3
-rw-r--r--changelogs/fragments/T8321_vpn_ipsec.yml4
-rw-r--r--changelogs/fragments/T8511-black-formatting.yml3
-rw-r--r--changelogs/fragments/T8512-isort-fix.yml3
-rw-r--r--changelogs/fragments/T8516_unit_tests_l3_interface.yml5
-rw-r--r--changelogs/fragments/T8517_unit_tests_lldp_interfaces.yml3
-rw-r--r--changelogs/fragments/T8518-vlan-unit-tests.yml3
-rw-r--r--changelogs/fragments/T8595_add_agents_md.yml2
-rw-r--r--changelogs/fragments/T8609_rm_templates_regex_backtracking.yml12
-rw-r--r--changelogs/fragments/T9082-codeql-workflow.yml2
-rw-r--r--changelogs/fragments/T9251_vyos_user_sk_key_types.yml5
-rw-r--r--changelogs/fragments/add_cla_workflow.yml3
-rw-r--r--changelogs/fragments/ades-fix.yml3
-rw-r--r--changelogs/fragments/coderabbit-config.yml3
-rw-r--r--changelogs/fragments/config_confirm.yml3
-rw-r--r--changelogs/fragments/copilot-instructions.yml4
-rw-r--r--changelogs/fragments/deprecated-cleanup.yml3
-rw-r--r--changelogs/fragments/fix-icmp-parse-attr.yml5
-rw-r--r--changelogs/fragments/fix-snmp-server-redirect.yml3
-rw-r--r--changelogs/fragments/fix-vlan-purge.yml3
-rw-r--r--changelogs/fragments/formatting-compliance.yml3
-rw-r--r--changelogs/fragments/fw_rules_sit.yml3
-rw-r--r--changelogs/fragments/ignore-2.22.yml3
-rw-r--r--changelogs/fragments/missing-unit-tests.yml3
-rw-r--r--changelogs/fragments/sanity-devel-fix.yml3
-rw-r--r--changelogs/fragments/sanity_upstream_fixes.yml5
-rw-r--r--changelogs/fragments/t6721-vyos_fw_global.yml3
-rw-r--r--changelogs/fragments/t6818_password_filtering.yml2
-rw-r--r--changelogs/fragments/t6820_vrrp.yml3
-rw-r--r--changelogs/fragments/t6823_ipv6_autoconf.yml3
-rw-r--r--changelogs/fragments/t6828-vyos_config-enforce.yml3
-rw-r--r--changelogs/fragments/t6830_vyos_file.yml3
-rw-r--r--changelogs/fragments/t6837-vyos_config-replace.yml19
-rw-r--r--changelogs/fragments/t6838_vrf.yml3
-rw-r--r--changelogs/fragments/t7701_greedy_starwith_fix.yml3
-rw-r--r--changelogs/fragments/t7856_firewall_group_zone.yml3
-rw-r--r--changelogs/fragments/t7933_fw_rules_offload.yml3
-rw-r--r--changelogs/fragments/t8104-vyos_static_routes.yaml3
-rw-r--r--changelogs/fragments/t8220-fpz.yaml3
-rw-r--r--changelogs/fragments/t8323-vyos_nat.yml3
-rw-r--r--changelogs/fragments/t8349_vyos_interfaces_vrf.yml3
-rw-r--r--changelogs/fragments/t8851-coderabbit-centralized.yml6
-rw-r--r--changelogs/fragments/t8983_logging_global_15.yml3
-rw-r--r--changelogs/fragments/t9053_vyos_module_bugfix.yml3
-rw-r--r--changelogs/fragments/t9180_fw_rules_return_action.yml2
-rw-r--r--changelogs/fragments/typing_extensions_fix.yml3
-rw-r--r--changelogs/fragments/vyos-user-quote-plaintext-password.yml3
-rw-r--r--changelogs/fragments/vyos-user-update-password-no-log.yml3
-rw-r--r--galaxy.yml2
55 files changed, 205 insertions, 187 deletions
diff --git a/CHANGELOG.rst b/CHANGELOG.rst
index 4eac017f..ead87739 100644
--- a/CHANGELOG.rst
+++ b/CHANGELOG.rst
@@ -4,6 +4,68 @@ Vyos Collection Release Notes
.. contents:: Topics
+v6.1.0
+======
+
+Release Summary
+---------------
+
+This is the 6.1.0 release vyos.vyos collection. This release adds new VyOS resource module capabilities across configuration management, networking, security, high availability, NAT, VPN, VRF, and file management. It also introduces enhanced vyos_config workflows including enforce mode, commit-confirm, configurable password filtering, and full configuration replacement.
+Numerous bug fixes improve configuration parsing and performance, firewall and interface handling, user management, VLAN cleanup, logging compatibility, and BGP/OSPF/route-map processing. Additional unit test coverage has been added for LLDP interfaces, VLANs, and resource module template performance.
+
+Minor Changes
+-------------
+
+- Add unit tests for vyos_lldp_interfaces module.
+- Add unit tests for vyos_vlan module.
+- plugins/modules/vyos_config.py - Added an argument to control password filtering in vyos_config. Current filtering behavior is still the default.
+- vyos_bgp_global - remove commented-out pre-1.3 deprecated parameter documentation artifacts.
+- vyos_config - Add `enforce` match mode, which enforces the supplied configuration as the desired end-state.
+- vyos_config - add support for commit-confirm workflows (automatic/manual) including configurable timeout
+- vyos_config - added a new ``replace`` option value, ``config`` (in addition to the existing default, ``line``). When set to ``replace=config``, the module uploads the complete candidate configuration supplied via ``src`` to the device and issues VyOS's native ``load`` command in configuration mode, letting VyOS's own configuration engine perform the replacement, rather than the module computing a set/delete command diff. This mirrors the mechanism offered by ``cisco.iosxr.iosxr_config``'s ``replace=config`` (https://vyos.dev/T6837).
+- vyos_file - Add support for file upload, management and templating.
+- vyos_firewall_global - Added 'diff' support
+- vyos_firewall_global - Added Firewall Zone Policy support.
+- vyos_firewall_rules - Added 'return' and 'continue' to default action.
+- vyos_ha - Add VRRP (High Availability) support.
+- vyos_interfaces - Added VRF support.
+- vyos_nat - Add new module to support NAT configuration.
+- vyos_static_routes - Fixed interface handling in next-hop parsing
+- vyos_vpn_ipsec - Add global VPN IPsec resource module support.
+- vyos_vpn_ipsec_s2s - Add IPsec site-to-site peer resource module support.
+- vyos_vrf - Add VRF support
+
+Bugfixes
+--------
+
+- Fix edgecase with empty `commands` array.
+- Fix meta/runtime.yml redirect for snmp_server pointing to non-existent vyos_snmp_servers module.
+- Safeguard interface L2 configuration by deleting only L3 address attributes in vyos_l3_interfaces; update unit and integration tests accordingly.
+- bgp_address_family.py - Fix slow parse() to stop regex backtracking on prefix-sharing inputs.
+- bgp_address_family_14.py - Fix slow parse() to stop regex backtracking on prefix-sharing inputs.
+- bgp_global.py - Fix slow parse() to stop regex backtracking on prefix-sharing inputs.
+- bgp_global_14.py - Fix slow parse() to stop regex backtracking on prefix-sharing inputs.
+- cliconf/vyos.py - Fixed greedy matching in configuration parsing
+- facts/firewall_global.py - Fix confusion between firewall zone names and group names.
+- firewall_rules - fix parse_icmp_attr() using wrong split delimiter ('.' instead of '/') and referencing undefined variable type_no in the numeric-only branch, which caused ValueError or UnboundLocalError when gathering firewall rules with ICMP type conditions.
+- ospf_interfaces.py - Fix slow parse() to stop regex backtracking on prefix-sharing inputs.
+- ospf_interfaces_14.py - Fix slow parse() to stop regex backtracking on prefix-sharing inputs.
+- plugins/modules/vyos_user.py - Fix aggregate option when extra user properties are defined
+- route_maps.py - Fix slow parse() to stop regex backtracking on prefix-sharing inputs.
+- route_maps_14.py - Fix slow parse() to stop regex backtracking on prefix-sharing inputs.
+- snmp_server.py - Fix slow parse() to stop regex backtracking on prefix-sharing inputs.
+- test_rm_templates_perf.py - Add unit test for the bugfixes
+- vyos_config - the ``allow_password_change`` filter used a regular expression that only matched ``set`` lines (``set system login user ... authentication (encrypted|plaintext)-password``), so a ``delete`` line for the same path was never filtered regardless of the ``allow_password_change`` value. This meant an account omitted from a full-config candidate could have its password deleted without the existing safety filter ever inspecting the line. The regular expression now matches both ``set`` and ``delete`` lines.
+- vyos_config.py - Fixing test case
+- vyos_firewall_global - Fix disabling src route
+- vyos_firewall_rules - add 'offload' action
+- vyos_l3_interfaces - ipv6 auto-config option incorrectly set
+- vyos_logging_global - Add support for 1.5.0+ CLI changes.
+- vyos_user - Accept OpenSSH security key types ``sk-ecdsa-sha2-nistp256@openssh.com`` and ``sk-ssh-ed25519@openssh.com`` for ``public_keys.type``, which were previously rejected.
+- vyos_user - Quote and escape plaintext-password values in set commands so VyOS accepts special characters and embedded single quotes.
+- vyos_user - Set explicit ``no_log=False`` on ``update_password`` so Ansible does not treat it as sensitive and hide it from task output.
+- vyos_vlan - fix purge generating invalid ``delete ... vif None`` commands for bare interfaces without VLAN sub-interfaces.
+
v6.0.0
======
diff --git a/changelogs/changelog.yaml b/changelogs/changelog.yaml
index f92f47be..2bf0cfd2 100644
--- a/changelogs/changelog.yaml
+++ b/changelogs/changelog.yaml
@@ -622,3 +622,145 @@ releases:
- test_module_patch.yml
- tests.yml
release_date: "2025-06-25"
+ 6.1.0:
+ changes:
+ bugfixes:
+ - Fix edgecase with empty `commands` array.
+ - Fix meta/runtime.yml redirect for snmp_server pointing to non-existent vyos_snmp_servers
+ module.
+ - Safeguard interface L2 configuration by deleting only L3 address attributes
+ in vyos_l3_interfaces; update unit and integration tests accordingly.
+ - bgp_address_family.py - Fix slow parse() to stop regex backtracking on prefix-sharing
+ inputs.
+ - bgp_address_family_14.py - Fix slow parse() to stop regex backtracking on
+ prefix-sharing inputs.
+ - bgp_global.py - Fix slow parse() to stop regex backtracking on prefix-sharing
+ inputs.
+ - bgp_global_14.py - Fix slow parse() to stop regex backtracking on prefix-sharing
+ inputs.
+ - cliconf/vyos.py - Fixed greedy matching in configuration parsing
+ - facts/firewall_global.py - Fix confusion between firewall zone names and group
+ names.
+ - firewall_rules - fix parse_icmp_attr() using wrong split delimiter ('.' instead
+ of '/') and referencing undefined variable type_no in the numeric-only branch,
+ which caused ValueError or UnboundLocalError when gathering firewall rules
+ with ICMP type conditions.
+ - ospf_interfaces.py - Fix slow parse() to stop regex backtracking on prefix-sharing
+ inputs.
+ - ospf_interfaces_14.py - Fix slow parse() to stop regex backtracking on prefix-sharing
+ inputs.
+ - plugins/modules/vyos_user.py - Fix aggregate option when extra user properties
+ are defined
+ - route_maps.py - Fix slow parse() to stop regex backtracking on prefix-sharing
+ inputs.
+ - route_maps_14.py - Fix slow parse() to stop regex backtracking on prefix-sharing
+ inputs.
+ - snmp_server.py - Fix slow parse() to stop regex backtracking on prefix-sharing
+ inputs.
+ - test_rm_templates_perf.py - Add unit test for the bugfixes
+ - vyos_config - the ``allow_password_change`` filter used a regular expression
+ that only matched ``set`` lines (``set system login user ... authentication
+ (encrypted|plaintext)-password``), so a ``delete`` line for the same path
+ was never filtered regardless of the ``allow_password_change`` value. This
+ meant an account omitted from a full-config candidate could have its password
+ deleted without the existing safety filter ever inspecting the line. The regular
+ expression now matches both ``set`` and ``delete`` lines.
+ - vyos_config.py - Fixing test case
+ - vyos_firewall_global - Fix disabling src route
+ - vyos_firewall_rules - add 'offload' action
+ - vyos_l3_interfaces - ipv6 auto-config option incorrectly set
+ - vyos_logging_global - Add support for 1.5.0+ CLI changes.
+ - vyos_user - Accept OpenSSH security key types ``sk-ecdsa-sha2-nistp256@openssh.com``
+ and ``sk-ssh-ed25519@openssh.com`` for ``public_keys.type``, which were previously
+ rejected.
+ - vyos_user - Quote and escape plaintext-password values in set commands so
+ VyOS accepts special characters and embedded single quotes.
+ - vyos_user - Set explicit ``no_log=False`` on ``update_password`` so Ansible
+ does not treat it as sensitive and hide it from task output.
+ - vyos_vlan - fix purge generating invalid ``delete ... vif None`` commands
+ for bare interfaces without VLAN sub-interfaces.
+ minor_changes:
+ - Add unit tests for vyos_lldp_interfaces module.
+ - Add unit tests for vyos_vlan module.
+ - plugins/modules/vyos_config.py - Added an argument to control password filtering
+ in vyos_config. Current filtering behavior is still the default.
+ - vyos_bgp_global - remove commented-out pre-1.3 deprecated parameter documentation
+ artifacts.
+ - vyos_config - Add `enforce` match mode, which enforces the supplied configuration
+ as the desired end-state.
+ - vyos_config - add support for commit-confirm workflows (automatic/manual)
+ including configurable timeout
+ - vyos_config - added a new ``replace`` option value, ``config`` (in addition
+ to the existing default, ``line``). When set to ``replace=config``, the module
+ uploads the complete candidate configuration supplied via ``src`` to the device
+ and issues VyOS's native ``load`` command in configuration mode, letting VyOS's
+ own configuration engine perform the replacement, rather than the module computing
+ a set/delete command diff. This mirrors the mechanism offered by ``cisco.iosxr.iosxr_config``'s
+ ``replace=config`` (https://vyos.dev/T6837).
+ - vyos_file - Add support for file upload, management and templating.
+ - vyos_firewall_global - Added 'diff' support
+ - vyos_firewall_global - Added Firewall Zone Policy support.
+ - vyos_firewall_rules - Added 'return' and 'continue' to default action.
+ - vyos_ha - Add VRRP (High Availability) support.
+ - vyos_interfaces - Added VRF support.
+ - vyos_nat - Add new module to support NAT configuration.
+ - vyos_static_routes - Fixed interface handling in next-hop parsing
+ - vyos_vpn_ipsec - Add global VPN IPsec resource module support.
+ - vyos_vpn_ipsec_s2s - Add IPsec site-to-site peer resource module support.
+ - vyos_vrf - Add VRF support
+ release_summary: This is the 6.1.0 release vyos.vyos collection.
+ fragments:
+ - 6.1.0.yml
+ - T6890_all_boolean.yml
+ - T7260_edgecase_commands.yml
+ - T7496_firewall_global_fix_disabling_src_route.yml
+ - T7943-fix-sanity.yml
+ - T8205_vyos_user_aggregate_fix.yml
+ - T8321_vpn_ipsec.yml
+ - T8511-black-formatting.yml
+ - T8512-isort-fix.yml
+ - T8516_unit_tests_l3_interface.yml
+ - T8517_unit_tests_lldp_interfaces.yml
+ - T8518-vlan-unit-tests.yml
+ - T8595_add_agents_md.yml
+ - T8609_rm_templates_regex_backtracking.yml
+ - T9082-codeql-workflow.yml
+ - T9251_vyos_user_sk_key_types.yml
+ - add_cla_workflow.yml
+ - ades-fix.yml
+ - coderabbit-config.yml
+ - config_confirm.yml
+ - copilot-instructions.yml
+ - deprecated-cleanup.yml
+ - fix-icmp-parse-attr.yml
+ - fix-snmp-server-redirect.yml
+ - fix-vlan-purge.yml
+ - formatting-compliance.yml
+ - fw_rules_sit.yml
+ - ignore-2.22.yml
+ - missing-unit-tests.yml
+ - sanity-devel-fix.yml
+ - sanity_upstream_fixes.yml
+ - t6721-vyos_fw_global.yml
+ - t6818_password_filtering.yml
+ - t6820_vrrp.yml
+ - t6823_ipv6_autoconf.yml
+ - t6828-vyos_config-enforce.yml
+ - t6830_vyos_file.yml
+ - t6837-vyos_config-replace.yml
+ - t6838_vrf.yml
+ - t7701_greedy_starwith_fix.yml
+ - t7856_firewall_group_zone.yml
+ - t7933_fw_rules_offload.yml
+ - t8104-vyos_static_routes.yaml
+ - t8220-fpz.yaml
+ - t8323-vyos_nat.yml
+ - t8349_vyos_interfaces_vrf.yml
+ - t8851-coderabbit-centralized.yml
+ - t8983_logging_global_15.yml
+ - t9053_vyos_module_bugfix.yml
+ - t9180_fw_rules_return_action.yml
+ - typing_extensions_fix.yml
+ - vyos-user-quote-plaintext-password.yml
+ - vyos-user-update-password-no-log.yml
+ release_date: "2026-09-17"
diff --git a/changelogs/fragments/T6890_all_boolean.yml b/changelogs/fragments/T6890_all_boolean.yml
deleted file mode 100644
index 2adec1d9..00000000
--- a/changelogs/fragments/T6890_all_boolean.yml
+++ /dev/null
@@ -1,2 +0,0 @@
-trivial:
- - Change string 'yes/now' to recommended 'true/false' in the collection's documentation, where practical.
diff --git a/changelogs/fragments/T7260_edgecase_commands.yml b/changelogs/fragments/T7260_edgecase_commands.yml
deleted file mode 100644
index deb24b1c..00000000
--- a/changelogs/fragments/T7260_edgecase_commands.yml
+++ /dev/null
@@ -1,2 +0,0 @@
-bugfixes:
- - Fix edgecase with empty `commands` array.
diff --git a/changelogs/fragments/T7496_firewall_global_fix_disabling_src_route.yml b/changelogs/fragments/T7496_firewall_global_fix_disabling_src_route.yml
deleted file mode 100644
index aaaf772e..00000000
--- a/changelogs/fragments/T7496_firewall_global_fix_disabling_src_route.yml
+++ /dev/null
@@ -1,2 +0,0 @@
-bugfixes:
- - vyos_firewall_global - Fix disabling src route
diff --git a/changelogs/fragments/T7943-fix-sanity.yml b/changelogs/fragments/T7943-fix-sanity.yml
deleted file mode 100644
index e5929ae4..00000000
--- a/changelogs/fragments/T7943-fix-sanity.yml
+++ /dev/null
@@ -1,2 +0,0 @@
-trivial:
- - change sanity test ignore file for 2.21
diff --git a/changelogs/fragments/T8205_vyos_user_aggregate_fix.yml b/changelogs/fragments/T8205_vyos_user_aggregate_fix.yml
deleted file mode 100644
index b9f5dead..00000000
--- a/changelogs/fragments/T8205_vyos_user_aggregate_fix.yml
+++ /dev/null
@@ -1,3 +0,0 @@
----
-bugfixes:
- - plugins/modules/vyos_user.py - Fix aggregate option when extra user properties are defined
diff --git a/changelogs/fragments/T8321_vpn_ipsec.yml b/changelogs/fragments/T8321_vpn_ipsec.yml
deleted file mode 100644
index cc33671f..00000000
--- a/changelogs/fragments/T8321_vpn_ipsec.yml
+++ /dev/null
@@ -1,4 +0,0 @@
----
-minor_changes:
- - vyos_vpn_ipsec - Add global VPN IPsec resource module support.
- - vyos_vpn_ipsec_s2s - Add IPsec site-to-site peer resource module support.
diff --git a/changelogs/fragments/T8511-black-formatting.yml b/changelogs/fragments/T8511-black-formatting.yml
deleted file mode 100644
index 68a0db8d..00000000
--- a/changelogs/fragments/T8511-black-formatting.yml
+++ /dev/null
@@ -1,3 +0,0 @@
----
-trivial:
- - Apply black formatting across the entire codebase to enforce consistent code style.
diff --git a/changelogs/fragments/T8512-isort-fix.yml b/changelogs/fragments/T8512-isort-fix.yml
deleted file mode 100644
index 5209017c..00000000
--- a/changelogs/fragments/T8512-isort-fix.yml
+++ /dev/null
@@ -1,3 +0,0 @@
----
-trivial:
- - Fix isort import ordering violations across module_utils to satisfy pre-commit checks.
diff --git a/changelogs/fragments/T8516_unit_tests_l3_interface.yml b/changelogs/fragments/T8516_unit_tests_l3_interface.yml
deleted file mode 100644
index 41b3218e..00000000
--- a/changelogs/fragments/T8516_unit_tests_l3_interface.yml
+++ /dev/null
@@ -1,5 +0,0 @@
----
-trivial:
- - Add unit tests for vyos_l3_interfaces module.
-bugfixes:
- - Safeguard interface L2 configuration by deleting only L3 address attributes in vyos_l3_interfaces; update unit and integration tests accordingly.
diff --git a/changelogs/fragments/T8517_unit_tests_lldp_interfaces.yml b/changelogs/fragments/T8517_unit_tests_lldp_interfaces.yml
deleted file mode 100644
index c1190d6e..00000000
--- a/changelogs/fragments/T8517_unit_tests_lldp_interfaces.yml
+++ /dev/null
@@ -1,3 +0,0 @@
----
-minor_changes:
- - Add unit tests for vyos_lldp_interfaces module.
diff --git a/changelogs/fragments/T8518-vlan-unit-tests.yml b/changelogs/fragments/T8518-vlan-unit-tests.yml
deleted file mode 100644
index 65fcdfd5..00000000
--- a/changelogs/fragments/T8518-vlan-unit-tests.yml
+++ /dev/null
@@ -1,3 +0,0 @@
----
-trivial:
- - Add unit tests for the vyos_vlan module covering present, absent, aggregate, purge, and address scenarios.
diff --git a/changelogs/fragments/T8595_add_agents_md.yml b/changelogs/fragments/T8595_add_agents_md.yml
deleted file mode 100644
index 5d7fb0a4..00000000
--- a/changelogs/fragments/T8595_add_agents_md.yml
+++ /dev/null
@@ -1,2 +0,0 @@
-trivial:
- - Add AGENTS.md tool-neutral contributor documentation, with .github/copilot-instructions.md symlink for Copilot code review compatibility.
diff --git a/changelogs/fragments/T8609_rm_templates_regex_backtracking.yml b/changelogs/fragments/T8609_rm_templates_regex_backtracking.yml
deleted file mode 100644
index b02dbf19..00000000
--- a/changelogs/fragments/T8609_rm_templates_regex_backtracking.yml
+++ /dev/null
@@ -1,12 +0,0 @@
----
-bugfixes:
- - bgp_address_family.py - Fix slow parse() to stop regex backtracking on prefix-sharing inputs.
- - bgp_address_family_14.py - Fix slow parse() to stop regex backtracking on prefix-sharing inputs.
- - bgp_global.py - Fix slow parse() to stop regex backtracking on prefix-sharing inputs.
- - bgp_global_14.py - Fix slow parse() to stop regex backtracking on prefix-sharing inputs.
- - ospf_interfaces.py - Fix slow parse() to stop regex backtracking on prefix-sharing inputs.
- - ospf_interfaces_14.py - Fix slow parse() to stop regex backtracking on prefix-sharing inputs.
- - route_maps.py - Fix slow parse() to stop regex backtracking on prefix-sharing inputs.
- - route_maps_14.py - Fix slow parse() to stop regex backtracking on prefix-sharing inputs.
- - snmp_server.py - Fix slow parse() to stop regex backtracking on prefix-sharing inputs.
- - test_rm_templates_perf.py - Add unit test for the bugfixes
diff --git a/changelogs/fragments/T9082-codeql-workflow.yml b/changelogs/fragments/T9082-codeql-workflow.yml
deleted file mode 100644
index 5d09acd7..00000000
--- a/changelogs/fragments/T9082-codeql-workflow.yml
+++ /dev/null
@@ -1,2 +0,0 @@
-trivial:
- - Add CodeQL analysis workflow calling the VyOS org-wide central reusable (T9082).
diff --git a/changelogs/fragments/T9251_vyos_user_sk_key_types.yml b/changelogs/fragments/T9251_vyos_user_sk_key_types.yml
deleted file mode 100644
index 47806abb..00000000
--- a/changelogs/fragments/T9251_vyos_user_sk_key_types.yml
+++ /dev/null
@@ -1,5 +0,0 @@
----
-bugfixes:
- - >-
- vyos_user - Accept OpenSSH security key types ``sk-ecdsa-sha2-nistp256@openssh.com`` and
- ``sk-ssh-ed25519@openssh.com`` for ``public_keys.type``, which were previously rejected.
diff --git a/changelogs/fragments/add_cla_workflow.yml b/changelogs/fragments/add_cla_workflow.yml
deleted file mode 100644
index 6e952c02..00000000
--- a/changelogs/fragments/add_cla_workflow.yml
+++ /dev/null
@@ -1,3 +0,0 @@
----
-trivial:
- - cla-check.yml - Add a workflow for the checking and signing of Contributor License Agreement (CLA)
diff --git a/changelogs/fragments/ades-fix.yml b/changelogs/fragments/ades-fix.yml
deleted file mode 100644
index bf6d7159..00000000
--- a/changelogs/fragments/ades-fix.yml
+++ /dev/null
@@ -1,3 +0,0 @@
----
-trivial:
- - tox-ansible.ini - Attempt to fallback to the previous test environment setup (without failing ADE)
diff --git a/changelogs/fragments/coderabbit-config.yml b/changelogs/fragments/coderabbit-config.yml
deleted file mode 100644
index 9442337f..00000000
--- a/changelogs/fragments/coderabbit-config.yml
+++ /dev/null
@@ -1,3 +0,0 @@
-trivial:
- - Add CodeRabbit review configuration with path-specific guidelines for review,
- docstring generation, and unit test generation.
diff --git a/changelogs/fragments/config_confirm.yml b/changelogs/fragments/config_confirm.yml
deleted file mode 100644
index 7c0565af..00000000
--- a/changelogs/fragments/config_confirm.yml
+++ /dev/null
@@ -1,3 +0,0 @@
----
-minor_changes:
- - vyos_config - add support for commit-confirm workflows (automatic/manual) including configurable timeout
diff --git a/changelogs/fragments/copilot-instructions.yml b/changelogs/fragments/copilot-instructions.yml
deleted file mode 100644
index c7af5c74..00000000
--- a/changelogs/fragments/copilot-instructions.yml
+++ /dev/null
@@ -1,4 +0,0 @@
----
-trivial:
- - Add Copilot custom review instructions to guide automated code review with
- project-specific conventions for tests, changelog fragments, and module patterns.
diff --git a/changelogs/fragments/deprecated-cleanup.yml b/changelogs/fragments/deprecated-cleanup.yml
deleted file mode 100644
index cf361adc..00000000
--- a/changelogs/fragments/deprecated-cleanup.yml
+++ /dev/null
@@ -1,3 +0,0 @@
----
-minor_changes:
- - vyos_bgp_global - remove commented-out pre-1.3 deprecated parameter documentation artifacts.
diff --git a/changelogs/fragments/fix-icmp-parse-attr.yml b/changelogs/fragments/fix-icmp-parse-attr.yml
deleted file mode 100644
index 5cf0e199..00000000
--- a/changelogs/fragments/fix-icmp-parse-attr.yml
+++ /dev/null
@@ -1,5 +0,0 @@
----
-bugfixes:
- - firewall_rules - fix parse_icmp_attr() using wrong split delimiter ('.' instead of '/')
- and referencing undefined variable type_no in the numeric-only branch, which caused
- ValueError or UnboundLocalError when gathering firewall rules with ICMP type conditions.
diff --git a/changelogs/fragments/fix-snmp-server-redirect.yml b/changelogs/fragments/fix-snmp-server-redirect.yml
deleted file mode 100644
index 59147f4a..00000000
--- a/changelogs/fragments/fix-snmp-server-redirect.yml
+++ /dev/null
@@ -1,3 +0,0 @@
----
-bugfixes:
- - Fix meta/runtime.yml redirect for snmp_server pointing to non-existent vyos_snmp_servers module.
diff --git a/changelogs/fragments/fix-vlan-purge.yml b/changelogs/fragments/fix-vlan-purge.yml
deleted file mode 100644
index bbc1d08a..00000000
--- a/changelogs/fragments/fix-vlan-purge.yml
+++ /dev/null
@@ -1,3 +0,0 @@
----
-bugfixes:
- - vyos_vlan - fix purge generating invalid ``delete ... vif None`` commands for bare interfaces without VLAN sub-interfaces.
diff --git a/changelogs/fragments/formatting-compliance.yml b/changelogs/fragments/formatting-compliance.yml
deleted file mode 100644
index d48896a9..00000000
--- a/changelogs/fragments/formatting-compliance.yml
+++ /dev/null
@@ -1,3 +0,0 @@
----
-trivial:
- - Add .git-blame-ignore-revs to exclude bulk formatting commits from git blame output.
diff --git a/changelogs/fragments/fw_rules_sit.yml b/changelogs/fragments/fw_rules_sit.yml
deleted file mode 100644
index 52e23de2..00000000
--- a/changelogs/fragments/fw_rules_sit.yml
+++ /dev/null
@@ -1,3 +0,0 @@
----
-trivial:
- - vyos_firewall_rules - Fix SIT for firewall_rules diff feature
diff --git a/changelogs/fragments/ignore-2.22.yml b/changelogs/fragments/ignore-2.22.yml
deleted file mode 100644
index 5e4a59f5..00000000
--- a/changelogs/fragments/ignore-2.22.yml
+++ /dev/null
@@ -1,3 +0,0 @@
----
-trivial:
- - ignore-2.22.yml - Update to sanity test ignore files for the new Python release
diff --git a/changelogs/fragments/missing-unit-tests.yml b/changelogs/fragments/missing-unit-tests.yml
deleted file mode 100644
index a83b336c..00000000
--- a/changelogs/fragments/missing-unit-tests.yml
+++ /dev/null
@@ -1,3 +0,0 @@
----
-minor_changes:
- - Add unit tests for vyos_vlan module.
diff --git a/changelogs/fragments/sanity-devel-fix.yml b/changelogs/fragments/sanity-devel-fix.yml
deleted file mode 100644
index 04731bc0..00000000
--- a/changelogs/fragments/sanity-devel-fix.yml
+++ /dev/null
@@ -1,3 +0,0 @@
----
-trivial:
- - vyos action plugin - Added ignore file to sanity check
diff --git a/changelogs/fragments/sanity_upstream_fixes.yml b/changelogs/fragments/sanity_upstream_fixes.yml
deleted file mode 100644
index 756d36ca..00000000
--- a/changelogs/fragments/sanity_upstream_fixes.yml
+++ /dev/null
@@ -1,5 +0,0 @@
----
-trivial:
- - procenv.py - ansible-bad-import-from Import PY3 fixed
- - yaml_helper.py - ansible-bad-import-from Import PY3 fixed
- - conftest.py - ansible-bad-import-from Import string_types fixed
diff --git a/changelogs/fragments/t6721-vyos_fw_global.yml b/changelogs/fragments/t6721-vyos_fw_global.yml
deleted file mode 100644
index bbd86f60..00000000
--- a/changelogs/fragments/t6721-vyos_fw_global.yml
+++ /dev/null
@@ -1,3 +0,0 @@
----
-minor_changes:
- - vyos_firewall_global - Added 'diff' support
diff --git a/changelogs/fragments/t6818_password_filtering.yml b/changelogs/fragments/t6818_password_filtering.yml
deleted file mode 100644
index d52283b9..00000000
--- a/changelogs/fragments/t6818_password_filtering.yml
+++ /dev/null
@@ -1,2 +0,0 @@
-minor_changes:
- - plugins/modules/vyos_config.py - Added an argument to control password filtering in vyos_config. Current filtering behavior is still the default.
diff --git a/changelogs/fragments/t6820_vrrp.yml b/changelogs/fragments/t6820_vrrp.yml
deleted file mode 100644
index 94145121..00000000
--- a/changelogs/fragments/t6820_vrrp.yml
+++ /dev/null
@@ -1,3 +0,0 @@
----
-minor_changes:
- - vyos_ha - Add VRRP (High Availability) support.
diff --git a/changelogs/fragments/t6823_ipv6_autoconf.yml b/changelogs/fragments/t6823_ipv6_autoconf.yml
deleted file mode 100644
index 8dfa04ee..00000000
--- a/changelogs/fragments/t6823_ipv6_autoconf.yml
+++ /dev/null
@@ -1,3 +0,0 @@
----
-bugfixes:
- - vyos_l3_interfaces - ipv6 auto-config option incorrectly set
diff --git a/changelogs/fragments/t6828-vyos_config-enforce.yml b/changelogs/fragments/t6828-vyos_config-enforce.yml
deleted file mode 100644
index f1f63603..00000000
--- a/changelogs/fragments/t6828-vyos_config-enforce.yml
+++ /dev/null
@@ -1,3 +0,0 @@
----
-minor_changes:
- - vyos_config - Add `enforce` match mode, which enforces the supplied configuration as the desired end-state.
diff --git a/changelogs/fragments/t6830_vyos_file.yml b/changelogs/fragments/t6830_vyos_file.yml
deleted file mode 100644
index fb50f2d9..00000000
--- a/changelogs/fragments/t6830_vyos_file.yml
+++ /dev/null
@@ -1,3 +0,0 @@
----
-minor_changes:
- - vyos_file - Add support for file upload, management and templating.
diff --git a/changelogs/fragments/t6837-vyos_config-replace.yml b/changelogs/fragments/t6837-vyos_config-replace.yml
deleted file mode 100644
index 9a0ff2b8..00000000
--- a/changelogs/fragments/t6837-vyos_config-replace.yml
+++ /dev/null
@@ -1,19 +0,0 @@
----
-minor_changes:
- - vyos_config - added a new ``replace`` option value, ``config`` (in addition
- to the existing default, ``line``). When set to ``replace=config``, the
- module uploads the complete candidate configuration supplied via ``src``
- to the device and issues VyOS's native ``load`` command in configuration
- mode, letting VyOS's own configuration engine perform the replacement,
- rather than the module computing a set/delete command diff. This mirrors
- the mechanism offered by ``cisco.iosxr.iosxr_config``'s ``replace=config``
- (https://vyos.dev/T6837).
-bugfixes:
- - vyos_config - the ``allow_password_change`` filter used a regular
- expression that only matched ``set`` lines
- (``set system login user ... authentication (encrypted|plaintext)-password``),
- so a ``delete`` line for the same path was never filtered regardless of
- the ``allow_password_change`` value. This meant an account omitted from a
- full-config candidate could have its password deleted without the
- existing safety filter ever inspecting the line. The regular expression
- now matches both ``set`` and ``delete`` lines.
diff --git a/changelogs/fragments/t6838_vrf.yml b/changelogs/fragments/t6838_vrf.yml
deleted file mode 100644
index 9483e466..00000000
--- a/changelogs/fragments/t6838_vrf.yml
+++ /dev/null
@@ -1,3 +0,0 @@
----
-minor_changes:
- - vyos_vrf - Add VRF support
diff --git a/changelogs/fragments/t7701_greedy_starwith_fix.yml b/changelogs/fragments/t7701_greedy_starwith_fix.yml
deleted file mode 100644
index 1e6bdf59..00000000
--- a/changelogs/fragments/t7701_greedy_starwith_fix.yml
+++ /dev/null
@@ -1,3 +0,0 @@
----
-bugfixes:
- - cliconf/vyos.py - Fixed greedy matching in configuration parsing
diff --git a/changelogs/fragments/t7856_firewall_group_zone.yml b/changelogs/fragments/t7856_firewall_group_zone.yml
deleted file mode 100644
index bc405976..00000000
--- a/changelogs/fragments/t7856_firewall_group_zone.yml
+++ /dev/null
@@ -1,3 +0,0 @@
----
-bugfixes:
- - facts/firewall_global.py - Fix confusion between firewall zone names and group names.
diff --git a/changelogs/fragments/t7933_fw_rules_offload.yml b/changelogs/fragments/t7933_fw_rules_offload.yml
deleted file mode 100644
index 4f44c497..00000000
--- a/changelogs/fragments/t7933_fw_rules_offload.yml
+++ /dev/null
@@ -1,3 +0,0 @@
----
-bugfixes:
- - vyos_firewall_rules - add 'offload' action
diff --git a/changelogs/fragments/t8104-vyos_static_routes.yaml b/changelogs/fragments/t8104-vyos_static_routes.yaml
deleted file mode 100644
index 2928b324..00000000
--- a/changelogs/fragments/t8104-vyos_static_routes.yaml
+++ /dev/null
@@ -1,3 +0,0 @@
----
-minor_changes:
- - vyos_static_routes - Fixed interface handling in next-hop parsing
diff --git a/changelogs/fragments/t8220-fpz.yaml b/changelogs/fragments/t8220-fpz.yaml
deleted file mode 100644
index 5c256046..00000000
--- a/changelogs/fragments/t8220-fpz.yaml
+++ /dev/null
@@ -1,3 +0,0 @@
----
-minor_changes:
- - vyos_firewall_global - Added Firewall Zone Policy support.
diff --git a/changelogs/fragments/t8323-vyos_nat.yml b/changelogs/fragments/t8323-vyos_nat.yml
deleted file mode 100644
index ae71d4a9..00000000
--- a/changelogs/fragments/t8323-vyos_nat.yml
+++ /dev/null
@@ -1,3 +0,0 @@
----
-minor_changes:
- - vyos_nat - Add new module to support NAT configuration.
diff --git a/changelogs/fragments/t8349_vyos_interfaces_vrf.yml b/changelogs/fragments/t8349_vyos_interfaces_vrf.yml
deleted file mode 100644
index 7ce0d98a..00000000
--- a/changelogs/fragments/t8349_vyos_interfaces_vrf.yml
+++ /dev/null
@@ -1,3 +0,0 @@
----
-minor_changes:
- - vyos_interfaces - Added VRF support.
diff --git a/changelogs/fragments/t8851-coderabbit-centralized.yml b/changelogs/fragments/t8851-coderabbit-centralized.yml
deleted file mode 100644
index b9be774e..00000000
--- a/changelogs/fragments/t8851-coderabbit-centralized.yml
+++ /dev/null
@@ -1,6 +0,0 @@
-trivial:
- - Migrate ``.coderabbit.yaml`` from standalone configuration to centralized
- inheritance under the org-level baseline at ``vyos/coderabbit``. No effect
- on consumers; the file shrinks from 591 lines to 205 while preserving all
- Ansible-collection-specific ``path_instructions`` and adding a
- ``knowledge_base.jira`` block scoped to ``VD`` (T8851).
diff --git a/changelogs/fragments/t8983_logging_global_15.yml b/changelogs/fragments/t8983_logging_global_15.yml
deleted file mode 100644
index 66b24bc1..00000000
--- a/changelogs/fragments/t8983_logging_global_15.yml
+++ /dev/null
@@ -1,3 +0,0 @@
----
-bugfixes:
- - vyos_logging_global - Add support for 1.5.0+ CLI changes.
diff --git a/changelogs/fragments/t9053_vyos_module_bugfix.yml b/changelogs/fragments/t9053_vyos_module_bugfix.yml
deleted file mode 100644
index b8d0a3d9..00000000
--- a/changelogs/fragments/t9053_vyos_module_bugfix.yml
+++ /dev/null
@@ -1,3 +0,0 @@
----
-bugfixes:
- - vyos_config.py - Fixing test case
diff --git a/changelogs/fragments/t9180_fw_rules_return_action.yml b/changelogs/fragments/t9180_fw_rules_return_action.yml
deleted file mode 100644
index aba64c34..00000000
--- a/changelogs/fragments/t9180_fw_rules_return_action.yml
+++ /dev/null
@@ -1,2 +0,0 @@
-minor_changes:
- - vyos_firewall_rules - Added 'return' and 'continue' to default action.
diff --git a/changelogs/fragments/typing_extensions_fix.yml b/changelogs/fragments/typing_extensions_fix.yml
deleted file mode 100644
index 951d0877..00000000
--- a/changelogs/fragments/typing_extensions_fix.yml
+++ /dev/null
@@ -1,3 +0,0 @@
----
-trivial:
- - test_requirements.txt - Add missing Py3.13 typing_extenstions lib
diff --git a/changelogs/fragments/vyos-user-quote-plaintext-password.yml b/changelogs/fragments/vyos-user-quote-plaintext-password.yml
deleted file mode 100644
index 487b592a..00000000
--- a/changelogs/fragments/vyos-user-quote-plaintext-password.yml
+++ /dev/null
@@ -1,3 +0,0 @@
----
-bugfixes:
- - vyos_user - Quote and escape plaintext-password values in set commands so VyOS accepts special characters and embedded single quotes.
diff --git a/changelogs/fragments/vyos-user-update-password-no-log.yml b/changelogs/fragments/vyos-user-update-password-no-log.yml
deleted file mode 100644
index 27b18a35..00000000
--- a/changelogs/fragments/vyos-user-update-password-no-log.yml
+++ /dev/null
@@ -1,3 +0,0 @@
----
-bugfixes:
- - vyos_user - Set explicit ``no_log=False`` on ``update_password`` so Ansible does not treat it as sensitive and hide it from task output.
diff --git a/galaxy.yml b/galaxy.yml
index 652ba5a1..3d253d6c 100644
--- a/galaxy.yml
+++ b/galaxy.yml
@@ -11,4 +11,4 @@ readme: README.md
repository: https://github.com/vyos/vyos.vyos
issues: https://vyos.dev
tags: [vyos, networking]
-version: 6.0.0
+version: 6.1.0