vyos-1x
- T6349: Fix typo in file name
- firewall: T4694: incomplete node checks in migration script
- vyos.configtree: T6620: allow list_nodes() to work on non-existent paths
- T6572: trigger remote pr only for circinus pr merge
- GitHub: T6560: action must be run on forked repo
- ipsec: T6148: Removed unused imports
- T5657: Add VRF support for zabbix-agent
- T6617: T6618: vpn ipsec remote-access: fix profile generators
- console: T3334: remove unused directories imported from vyos.defaults
- nat64: T6627: call check_kmod within standard config function
- T6486: use data-ciphers instead of ncp-ciphers in "run generate openvpn client-config"
- T6619: Remove the remaining uses of per-protocol FRR configs
- T6629: call check_kmod within a standard config function
- T6632: add missing standard functions to config scripts
- T4072: firewall extend bridge firewall
- T5873: T6619: remove unused imports
- OPENVPN: T6555: add server-bridge options in mode server
- T6560: T4694: T6555: multiple minor bugfixes for package build
- smoketest: T6555: openvpn: NameError: name 'elf' is not defined
- T6634: README: Add image graphs of contributors
- sysctl: T3204: restore sysctl settings overwritten by tuned
- smoketest: T6614: add op-mode test for Kernel version
- T6637: py files filter added for unused import check
- configd: T6640: enforce in_session returns False under configd
- qos: T6638: require interface state existence in verify conditional
- T6643: firewall: fix ip address range parsing on firewall rules.
- T6637: add pr commenting back in un-used import check
- configverify: T6642: verify_interface_exists requires config_dict arg
- configd: T6633: inject missing env vars for configfs utility
- T6648: dhcpv6-server: align stateless DHCPv6 options with stateful
- suricata: T6624: Make it possible for suricata address groups to reference each other
- xml: T6650: add initial op-mode cache support
- T6646: conntrack: in ignore rules, if protocols=all, do not append it to the rule
- op_mode: T6651: Add a top level op mode word "execute"
- T6636: firewall: fix firewall template in order print logs for default-action
- T5794: firewall: change firewall priority in oder to be loaded after all interfaces
- utils: T6658: fix write_file check in case of empty directory path
- ipoe_server: T6649: Accel-ppp separate vlan-mon from listen interfaces
- T6659: suricata: use unique cluster_id per interface
- op_mode: T3961: Generate PKI expect 2 character country code
- T5743: HTTPS API ability to import PKI certificates
- T6183: interfaces openvpn: suppport specifying IP protocol version
- T6672: Fix system option ssh-client source-interface
- op_mode: T6668: Add detailed statistics infomartion about MACsec
- T6561: Add vrf aware for show ntp
- dhclient: T6667: Added workaround for communication with FRR
- T6671: defer config dependency if scheduled in priority queue
- T6678: added darker ruff linting workflow
- T6681: Add option for SLAAC to support suppress Interval Advertisement in RA Packets
- T6647: firewall. Introduce patch for accepting invalid ARP and DHCP
- T4974: add proper dependency on openvpn-dco
- opmode: T6694: move wake-on-lan to "execute wake-on-lan"
- T6674: workflow: Add trigger to rebuild repo package
- container: T6702: re-add missing UNIX API socket
- T6698: firewall: add matcher for vlan type.
- T6678: ruff lint workflow added (removed darker)
- op_mode: T6181: A feature for checking ports
- T6693: wireless: Enable WiFi-6 (802.11ax) for 2.4GHz AccessPoints
- T6679: add group option for nat66
- T6294: Service dns forwarding add the ability to configure ZonetoCache
- T6701: Added ability to disable the container DNS plugin
- op-mode: T6694: Move some op-mode commands to the "execute" family
- T6674: Use reusable workflow for trigger package build
- pppoe-server: T6685: Add options to accept any and blank service names
- T6711: Fix restart vrrp missed comma between services
- openfabric: T6652: Add support for OpenFabric protocol
- T6703: Adds option to configure AMD pstate driver
- op-mode: T6694: Add op-mode command "execute ssh"
- policy: T6676: Invalid route-map caused bgpd to crash
- T6674: Rebuild package action use secrets inherit
- T6674: Actions use pull_request_target to trigger build package
- T6674: Actions fix variable for trigger build reuse repo
- GitHub: T6494: add TPM tests to ISO integration workflow
- op-mode: T6682: Fix for show vpn ike sa peer that always shows all SAs
- op-mode: T6715: manually changing time/date is not synced into hardware clock
- bond: T6709: add EAPoL support
- T861: op-mode: initial parts for UEFI secure boot CLI
- T6716: don't automatically set ethernet offload
- T6723: firewall: extend op-mode commands
- syslog: T5367: add format option to include timezone in message
- wireless: T6709: fix missing wpa_supplicant configuration
- http-api: T6326: return full warning/error output through api
- op-mode: T4833: Include wireguard peer name in interface summary report
- lldp: T6727: add missing input validation for interface names
- ethtool: T6729: drop text based feature parsing in favour of JSON
- T6630: ntp: support hardware timestamp offload and other mechanisms to improve accuracy
- bridge: T6675: VXLAN Interface configuration lost due to improper bridge detachment
- syslog: T6719: fix the behavior of "syslog global preserve-fqdn"
- validators: T6739: fix ipaddrcheck argument quoting
- validators: T6738: Revert "validators: T6739: fix ipaddrcheck argument quoting"
- validators: T6739: correctly quote ipaddrcheck arguments to avoid ipaddrcheck syntax errors when values include whitespace
- T6749: fix PR commenting permission issue with integration test workflow
- T6687: add fqdn support to nat rules.
- policy: T6751: add missing completion helpers for community-list
- validators: T6743: use native ipaddrcheck validator options for ranges
- T6757: Openconnect: fix template for correct config parsing while configuring source address for radius authentication.
- vyos.configtree: T6742: add bindings for create_node and is_leaf/set_leaf
- cli: T6752: add a wrapper for the show command
- T6761: Add timeout for OSPF smoketest fail
- T6763: Delete Jenkins file
- T6760: firewall: add packet modifications existing in policy route to regular firewall ruleset.
- T973: add basic node_exporter implementation
- T6755: Change vyos mirror URL for smoketest
- ipsec: T6101: Add validation for proposal option used in IKE group
- http-api: T6736: move REST API to a node distinct from GraphQL API
- Debian: T973: add missing dependency on node-exporter package
- op-mode: T6753: Fix json output for mtr / monitor traceroute
- static: T4283: fix missing f'ormat string
- T6759: add support for italian keymap
- GitHub: T6494: add parallel step to run interface based smoketests
- pki: T6481: auto import ACME certificate chain into CLI
- pbr: T6430: Local IP rules targeting VRFs by name as well as route table IDs
- cli: T6740: add a converter from set commands to config
- smoketest: T4576: add guard timeout for systemd in log level tests
- vyos.configtree: T4318: Allow set tag flag to true or false
- config-mgmt: T5976: add option for commit-confirm to use 'soft' rollback
- haproxy: T6745: Rename reverse-proxy to haproxy
- pki: T6766: Add support for ECDSA private keys
- T6712: Add nonproduction banner (backport #4148)
- T973: add basic frr_exporter implementation
- pki: T4914: Rewrite the PKI op mode in the new style
- T6784: enabled repo-sync wokrflow only for current and equuleus
- T6791: Extend fair-queue hash-interval
- T4583: Rewrite VRRP op-mode to vyos.opmode format
- T6812: Fix smoketest iproute2 check
- login: T6712: honor 80x25 terminal size for nonproduction banner message
- op_mode: T6808: Console server op mode commands throw errors when console server is not configured
- system_login: T6807: allow a trailing slash character in system login
- T6764: Fix unhandled exception on ethtool output parsing for Xen NICs
- dhcp_server: T6852: Add op mode command "show dhcpv6 server statistics"
- T6695: Machine-readable operational mode support for traceroute
- dhcp_server: T6031: fix daemon load error when static-route options are present
- T6802: Fix QoS Policy Round-Robin with Default Configuration
- T3501: Allow using more than one tuned profile
- syslog: T6858: bugfix remote syslog using TCP
- T6861: op-mode: ignore error code 255 if this UEFI doesn't support secure boot
- T6861: op-mode: add 0 into errno expect list
- babel: T6866: IPv6 distribute-lists in access-list6 format have names not numbers
- conntrack: T6878: stop the conntrack logger daemon correctly
- dhcp-server: T6876: increase retries that Kea makes to open a socket
- T6801: QoS: Policy rate-control is broken by default
- T6795: QoS: Fix duplicate entries in class match filters
- T6884: adds mtu option for container networks
- T6490: Allow creation of wireguard interfaces without requiring peers
- T6790: QoS: Improve CAKE Policy
- configd: T6899: use multipart message instead of extra exchange
- serial: T3397: Remove which could result in unexpected baud rate
- T6796: QoS: match filter by interface(iif)
- T6806: Rework QoS Policy for HFSC Shaper
- op-mode: T6900: remove uninformative 'show configuration files'
vyos-build
- no changes