Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.kernel > #80363

Bug#1051592: linux: Regression - upgrade to 6.1.52-1 breaks nftables

From Salvatore Bonaccorso <carnil@debian.org>
Newsgroups linux.debian.bugs.dist, linux.debian.kernel
Subject Bug#1051592: linux: Regression - upgrade to 6.1.52-1 breaks nftables
Date 2023-09-10 12:30 +0200
Message-ID <HcpRv-80Py-3@gated-at.bofh.it> (permalink)
References <Hcosp-7ZJi-11@gated-at.bofh.it> <Hcosp-7ZJi-11@gated-at.bofh.it>
Organization linux.* mail to news gateway

Cross-posted to 2 groups.

Show all headers | View raw


Control: tags -1 + moreinfo

Hi

On Sun, Sep 10, 2023 at 10:38:45AM +0200, Timo Sigurdsson wrote:
> Package: linux
> Version: 6.1.52-1
> Severity: grave
> 
> Dear Maintainers,
> 
> linux-image-6.1.0-12-amd64 causes a serious regression in nftables.
> After upgrading one of my machines, nftables fails to start -
> leaving the system without an active firewall.
> 
> Doing
> `nft -cf /etc/nftables.conf'
> throws many "Operation not supported" errors on rulesets that have been in place for months wihtout issues.
> 
> Just to give two simple examples from the log when nftables fails to start:
> /etc/nftables.conf:99:4-44: Error: Could not process rule: Operation not supported
>                         tcp option maxseg size 1-500 counter drop
>                         ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
> /etc/nftables.conf:308:4-27: Error: Could not process rule: Operation not supported
>                         tcp dport sip-tls accept
>                         ^^^^^^^^^^^^^^^^^^^^^^^^
> 
> Downgrading to linux-image-6.1.0-11-amd64 resolves the issue.
> 
> Notes: I'm running a local rebuild of linux-image-amd64 with a few
> additional symbols enabled. But since these symbols are totally
> unrelated to the netfilter subsystem and there are no changes to the
> source itself, I'm certain, this affects the original Debian build
> as well. Whether it only affects certain architectures or rulesets,
> I can't say, though.
> 
> I'm cc'ing debian-security@debian.org because the update came via
> the stable-security channel.

This is defintively not 'grave' but I keep it for the time beeing at
RC level and might be adjusted later.

Would it be possible to provide a minimal set of rules triggering the
issue? Can you reproduce the issue with the official build?

Regards,
Salvatore

Back to linux.debian.kernel | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread


Thread

Bug#1051592: linux: Regression - upgrade to 6.1.52-1 breaks nftables "Timo Sigurdsson" <public_timo.s@silentcreek.de> - 2023-09-10 11:00 +0200
  Processed: Re: Bug#1051592: linux: Regression - upgrade to  6.1.52-1 breaks nftables "Debian Bug Tracking System" <owner@bugs.debian.org> - 2023-09-10 12:30 +0200
  Bug#1051592: linux: Regression - upgrade to 6.1.52-1 breaks nftables Salvatore Bonaccorso <carnil@debian.org> - 2023-09-10 12:30 +0200
  Bug#1051592: linux: Regression - upgrade to 6.1.52-1 breaks nftables Salvatore Bonaccorso <carnil@debian.org> - 2023-09-11 16:20 +0200
    Bug#1051592: linux: Regression - upgrade to 6.1.52-1 breaks nftables Salvatore Bonaccorso <carnil@debian.org> - 2023-09-11 16:30 +0200
  Processed: Re: Bug#1051592: linux: Regression - upgrade to  6.1.52-1 breaks nftables "Debian Bug Tracking System" <owner@bugs.debian.org> - 2023-09-11 16:40 +0200
  Bug#1051592: linux: Regression - upgrade to 6.1.52-1 breaks nftables Salvatore Bonaccorso <carnil@debian.org> - 2023-09-11 23:00 +0200

csiph-web