Menu

Show posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

Show posts Menu

Messages - Timeraider

#1
26.7 Series / Re: Services widget
July 23, 2026, 08:59:25 AM
Tbh, not sure if anyone asked for this change and why this wasnt pushed back against during the RC versions (if it was already implemented there)
The old list was easy on the eyes and has distinct separate parts (aka.. name | controls). And depending on the dashboard space, the list is mostly to long anyway so you need to scroll meaning it has your attention regardless without needing a lot of color.

This is basically someone saying: Ow no, I cant figure out if my hardware isnt running as its only a red light blinking. Lets make it so that when my hardware doesnt work it changes the color of my entire wall. And hides the power button somewhere on that wall as well.
#2
Quote from: muchacha_grande on July 21, 2026, 02:26:08 PMHi Timeraider, I've reported this issue on github https://github.com/opnsense/core/issues/10546.
Another issue reported earlier that can be related is https://github.com/opnsense/core/issues/10535. This has been already addressed but Franco reopened it because there is a chance that it is also related to this problem.

Ah, I missed that issue. Guess ill wait it out and keep an eye on that one :P
I can luckily sort of work around it now as I did have a security header profile with everything allowed so if actions get blocked I can still switch my site to that before executing the action but I prefer to be able to edit the existing ones ofc. ;D
#3
No errors in the logs of opnsense btw.
There is an HTML page error however im not sure if that causes anything or is related in any way.
Blocked aria-hidden on an element because its descendant retained focus. The focus must not be hidden from assistive technology users. Avoid using aria-hidden on a focused element or its ancestor. Consider using the inert attribute instead, which will also prevent focus. For more details, see the aria-hidden section of the WAI-ARIA specification at https://w3c.github.io/aria/#aria-hidden.
Element with focus: <div.modal fade modal_draggable in#security_headersdlg>
Ancestor with aria-hidden: <div.modal fade modal_draggable in#security_headersdlg>
#4
nginx plugin -> security header UI not working since 26.7
So under the Nginx plugin -> configuration -> http(s), you have an option for Security headers.
Once I try editing any of them, the UI acts weird and while it shows the tabs it refuses to show any content.
Makes it impossible to update it.
This kinda blocks me from fixing one of my sites XD

#5
Quote from: franco on July 16, 2026, 11:57:10 AM# opnsense-patch https://github.com/opnsense/core/commit/14710e775
O, perfect.
Can confirm that patch fixes the issue.
#6
nginx itself works and the other pages also work, but specifically the configuration page (arguably the most important) crashes.
Errors:
[16-Jul-2026 11:51:36 Europe/Amsterdam] TypeError: count(): Argument #1 ($value) must be of type Countable|array, null given in /var/lib/php/cache/_usr_local_opnsense_mvc_app_views_layout_partials_base_form.volt.php:9
Stack trace:
#0 [internal function]: Phalcon\Mvc\View\Engine\Volt->render('/usr/local/opns...', Array, false)
#1 [internal function]: Phalcon\Mvc\View->engineRender(Array, 'layout_partials...', false, false)
#2 [internal function]: Phalcon\Mvc\View->partial('layout_partials...', Array)
#3 /var/lib/php/cache/_usr_local_opnsense_mvc_app_views_layout_partials_base_tabs_content.volt.php(8): Phalcon\Mvc\View\Engine\AbstractEngine->partial('layout_partials...', Array)
#4 [internal function]: Phalcon\Mvc\View\Engine\Volt->render('/usr/local/opns...', Array, false)
#5 [internal function]: Phalcon\Mvc\View->engineRender(Array, 'layout_partials...', false, false)
#6 [internal function]: Phalcon\Mvc\View->partial('layout_partials...', Array)
#7 /var/lib/php/cache/_usr_local_opnsense_mvc_app_views_opnsense_nginx_index.volt.php(267): Phalcon\Mvc\View\Engine\AbstractEngine->partial('layout_partials...', Array)
#8 [internal function]: Phalcon\Mvc\View\Engine\Volt->render('/usr/local/opns...', Array, true)
#9 [internal function]: Phalcon\Mvc\View->engineRender(Array, 'OPNsense/Nginx/...', true)
#10 /usr/local/opnsense/mvc/app/controllers/OPNsense/Base/ControllerBase.php(151): Phalcon\Mvc\View->processRender('', '')
#11 /usr/local/opnsense/mvc/app/library/OPNsense/Mvc/Dispatcher.php(168): OPNsense\Base\ControllerBase->afterExecuteRoute(NULL)
#12 /usr/local/opnsense/mvc/app/library/OPNsense/Mvc/Router.php(156): OPNsense\Mvc\Dispatcher->dispatch(Object(OPNsense\Mvc\Request), Object(OPNsense\Mvc\Response), Object(OPNsense\Mvc\Session))
#13 /usr/local/opnsense/mvc/app/library/OPNsense/Mvc/Router.php(139): OPNsense\Mvc\Router->performRequest(Object(OPNsense\Mvc\Dispatcher))
#14 /usr/local/opnsense/www/index.php(66): OPNsense\Mvc\Router->routeRequest('/ui/nginx', Array)
#15 {main}


Already did the obvious like reinstalling nginx plugin, restarting etc.
#7
At one hand any extra options are always good so being able to hide specific things would always be appreciated ofcourse.
At the other hand its Zenarmor registering the service so Zenarmor should fix their packages to not set up the Cloud agent service as long as the agent package isnt installed.
#8
Yup, not just you sadly -_-

Always hope they test patches before pushing them out but well...
#9
Hmm.. wasnt this last big update as well that Zenarmor was looking for php 8.1 when OPNSense updated to php 8.2.
Maybe doublechecking dependency versions would be a good one for their checklist ;D
#10
Quote from: sy on December 19, 2024, 01:46:33 PMHi,

This is not the expected behavior, but Zenarmor excludes the firewall itself from any blocking rules. Even if your PC is blocked by a policy, you can still access the OPNsense UI or manage your policies through the Zenconsole (Cloud Management Portal) if Zenarmor is registered there.



Ah, thank you for the confirmation.
Can't hurt to be sure even if nothing will ever happen so its simply good to hear that I can't fully lock myself out :D
#11
Quote"Apologies for taking so long. I was hoping some of the other maintainers would step in while I was away, looks like that didn't happen. :("
Hehe, welcome to open-source. Whereby the creators better never go on a holiday, because the moment the creator is unavailable for a while the entire idea of "being maintained by a community" only goes as far as "Does it affect any of the contributors? Nope.. ok.. guess none of them will mind the issue for now then", none of the creators fault ofcourse but funny how it always ends up somewhere along those lines :D

Though I will be fully honest that I dont really have any credentials to be able to judge anyone ofcourse. Everyone has their expertise and mine certainly is not contributing to Perl script XD
Did make a bash script for myself to have dynamicdns with an directadmin portal (didnt want to have an third-party like noip or some of the other options in between) as that doesnt seem to be built into the ddclient, but thats about the extend of my possibilities XD
#12
Not gonna say I dont trust Zenarmor updates.. but if I have my network and selected the correct devices as trusted and afterwards ill turn on block connection for all untrusted devices.
What is best practise to make sure that if Zenarmor somehow clears the Trusted list, I still have a way into my router outside of physically connecting a screen to it :P
#13
EDIT:

Ok.. so "parameters" going to %s only means 1 word goes to %s, not all of it. And if your %s's in the configd is lower than the amount of words filled it, it simply doesnt work. You can have more %s's than parameters and it will still work though.

So all I had to do was adjust the configd and change it to
[test.dyndns]
command:/scripts/test.sh
parameters:%s %s %s %s %s %s %s %s %s %s %s %s %s %s %s %s %s %s %s %s %s %s %s %s %s %s %s %s %s %s %s %s %s %s %s %s %s %s %s %s %s
type:script_output
message: Running dynamic DNS check on domain
description: Run dynamic DNS check on domain


ORIGINAL:

So.. basically to facilitate some dynamic dns for me which cant get through the plugin .. I made myself a bash script that doesn exactly as I want.
Now I am incorporating it into the cron job interface in OPMSense, but its not exactly working as planned.
Basically.. (some of these will be templates and not my actual setup, but its the same idea.
/scripts holds an script (lets say test.sh) that checks IPs and then changing my DNS names through Directadmin .. this script works as I can run it manually as well as through cron and it works like that.
However, I want to make it so that I can edit my cron job so I can always change which subdomains it updates through the UI and not have it hardcoded in the script
If I run the command "test.sh test test2" in the CLI .. it works, updating those 2 subdomains.. meaning the parameters do work.



However... if I set it up as shown above and then have this as configd .. it doesnt work

[test.dyndns]
command:/scripts/test.sh
parameters:%s
type:script_output
message: Running dynamic DNS check on domain
description: Run dynamic DNS check on domain


So basically.. If I hardcode the subdomains, it works manually and through the webui Cron
If I parameter the subdomains it works manually, doesnt work through webui Cron (and only thing I change in the configd is at parameters I add %s
Anyone has any idea?
#14
Edit: Solved.. sorta. Issue found!
After doing more testing I found out my issue was that the opnsense had issues retrieving geo ip for a geolocation block rule. This started happening after last update.
Somehow this made it so that it blocked all countries instead of the ones I set up in the settings.
Disabling that rule allows my reverse proxies to work untill I fix or find the cause of the geo ip issue

Issue:
Using the nginx plugin in which ive made a good few http servers -> Location and then the 2 upstream parts.. default reverse proxies
My reverse proxies are not able to be reached anymore by domain URLs. Neither form the outside nor the inside.
The only way it does work from the INSIDE is to put domains in Unbound DNS Overrides and refer them to any of my LAN interface gateways.
Firewall does not show any blocks, neither does Zenarmor.
Everything worked fine (domains were reachable from outside as well as inside my network simply with  the nginx plugin) at 24.7_9 .. only after 24.7.1 it stopped working.
There is nothing in front of my OPNsense.

Any ideas?
#15
Can confirm this. While I never used it myself I can at least say that this seems to not work as intended atm.