Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.kernel > #90211

Re: MBF: Removal of iptables-legacy

From Colin Watson <cjwatson@debian.org>
Newsgroups linux.debian.devel, linux.debian.kernel
Subject Re: MBF: Removal of iptables-legacy
Date 2025-11-24 15:20 +0100
Message-ID <LUFA5-fpwe-1@gated-at.bofh.it> (permalink)
References <LUfmh-f7PC-7@gated-at.bofh.it> <LUk2C-faTf-27@gated-at.bofh.it> <LUlrH-fbKK-1@gated-at.bofh.it>
Organization linux.* mail to news gateway

Cross-posted to 2 groups.

Show all headers | View raw


On Sun, Nov 23, 2025 at 05:25:09PM +0100, Bastian Blank wrote:
>On Sun, Nov 23, 2025 at 03:12:27PM +0000, Colin Watson wrote:
>> I wonder how many of these are conditional code in packages that also
>> support nft?  For example, incus caught my eye in your list: it has both
>> xtables and nftables drivers, and it prefers nftables if it's available.  It
>> doesn't look as though anything would need to change in that package to cope
>> with a kernel without iptables support.
>
>The source check matched this reference to the legacy stuff:
>
>| test/suites/container_devices_nic_bridged_filtering.sh:            echo "==> SKIP: ebtables must be legacy version (try update-alternatives --set ebtables /usr/sbin/ebtables-legacy)"

That code is within a [ "$firewallDriver" = "xtables" ] check, which 
will be false on a modern system.

-- 
Colin Watson (he/him)                              [cjwatson@debian.org]

Back to linux.debian.kernel | Previous | Next — Previous in thread | Find similar | Unroll thread


Thread

Re: MBF: Removal of iptables-legacy Colin Watson <cjwatson@debian.org> - 2025-11-23 16:20 +0100
  Re: MBF: Removal of iptables-legacy Bastian Blank <waldi@debian.org> - 2025-11-23 17:50 +0100
    Re: MBF: Removal of iptables-legacy Colin Watson <cjwatson@debian.org> - 2025-11-24 15:20 +0100

csiph-web