Path: csiph.com!weretis.net!feeder8.news.weretis.net!news.samoylyk.net!gothmog.csi.it!bofh.it!news.nic.it!robomod From: Colin Watson Newsgroups: linux.debian.devel,linux.debian.kernel Subject: Re: MBF: Removal of iptables-legacy Date: Mon, 24 Nov 2025 15:20:01 +0100 Message-ID: References: X-Mailbox-Line: From debian-devel-request@lists.debian.org Mon Nov 24 14:13:48 2025 Old-Return-Path: X-Amavis-Spam-Status: No, score=-109.41 tagged_above=-10000 required=5.3 tests=[BAYES_00=-2, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FOURLA=0.1, LDO_WHITELIST=-5, RCVD_IN_DNSWL_MED=-2.3, UNPARSEABLE_RELAY=0.001, USER_IN_DKIM_WELCOMELIST=-0.01, USER_IN_DKIM_WHITELIST=-100] autolearn=ham autolearn_force=no Mail-Followup-To: debian-devel@lists.debian.org, debian-kernel@lists.debian.org MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii; format=flowed Content-Disposition: inline X-Debian-User: cjwatson X-Mailing-List: archive/latest/368515 List-ID: List-URL: List-Archive: https://lists.debian.org/msgid-search/aSRoCMFYrSFXP1JL@riva.ucam.org Approved: robomod@news.nic.it Lines: 17 Organization: linux.* mail to news gateway Sender: robomod@news.nic.it X-Original-Date: Mon, 24 Nov 2025 14:13:28 +0000 X-Original-Message-ID: X-Original-References: <20251123095739.5pojnggqt47xr5bv@shell.thinkmo.de> <20251123162509.mlyfuvv74o7qw3g2@shell.thinkmo.de> Xref: csiph.com linux.debian.devel:119701 linux.debian.kernel:90211 On Sun, Nov 23, 2025 at 05:25:09PM +0100, Bastian Blank wrote: >On Sun, Nov 23, 2025 at 03:12:27PM +0000, Colin Watson wrote: >> I wonder how many of these are conditional code in packages that also >> support nft? For example, incus caught my eye in your list: it has both >> xtables and nftables drivers, and it prefers nftables if it's available. It >> doesn't look as though anything would need to change in that package to cope >> with a kernel without iptables support. > >The source check matched this reference to the legacy stuff: > >| test/suites/container_devices_nic_bridged_filtering.sh: echo "==> SKIP: ebtables must be legacy version (try update-alternatives --set ebtables /usr/sbin/ebtables-legacy)" That code is within a [ "$firewallDriver" = "xtables" ] check, which will be false on a modern system. -- Colin Watson (he/him) [cjwatson@debian.org]