Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.kernel > #50902
| From | Ben Hutchings <ben@decadent.org.uk> |
|---|---|
| Newsgroups | linux.debian.bugs.dist, linux.debian.kernel |
| Subject | Bug#800445: nf_conntrack: table full, dropping packet |
| Date | 2015-10-03 03:40 +0200 |
| Message-ID | <qfjXP-40r-3@gated-at.bofh.it> (permalink) |
| References | <qe2mm-6A8-1@gated-at.bofh.it> |
| Organization | linux.* mail to news gateway |
Cross-posted to 2 groups.
[Multipart message — attachments visible in raw view] - view raw
Control: tag -1 upstream fixed-upstream patch moreinfo On Tue, 2015-09-29 at 08:20 -0400, anomie@users.sourceforge.net wrote: > Package: linux-image-4.2.0-1-amd64 > Version: 4.2.1-2 > > After booting the kernel image provided by this package and attempting > to connect to the Internet, network access doesn't actually work. The > message "nf_conntrack: table full, dropping packet" is repeatedly > logged. > > Comparing the contents of the various /proc/sys conntrack files between > a working 4.1 kernel (from linux-image-4.1.0-2-amd64) and the broken > 4.2, the only difference I see is that nf_conntrack_count has a value > "-5". Yes, negative 5. /proc/net/stat/nf_conntrack's "entries" column > matches this with a value of fffffffb. /proc/net/nf_conntrack is empty > on the 4.2 kernel, while it has a handful of expected entries on 4.1. > > I have iptables rules set up by shorewall on this machine, including > configuration to forward/masq traffic on the interface used by vde2, in > case that helps reproduce this. Removing all the iptables rules and > removing the nf_conntrack_ipv4 module (and everything that depends on > it, of course) stops the error. Disabling shorewall at boot allows > network functionality and starting shorewall later didn't immediately > cause the problem, but in some experimentation after the system locked > up. I think I found the fix for this, but please can you test the attached patch? (Instructions for building a patched kernel package are at <https://kernel-handbook.alioth.debian.org/ch-common-tasks.html#s-common-official>.) Ben. -- Ben Hutchings compatible: Gracefully accepts erroneous data from any source
Back to linux.debian.kernel | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread
Bug#800445: nf_conntrack: table full, dropping packet anomie@users.sourceforge.net - 2015-09-29 14:40 +0200
Bug#800445: nf_conntrack: table full, dropping packet C. Dominik Bódi <dominik.bodi@gmx.de> - 2015-10-01 17:30 +0200
Bug#800445: nf_conntrack: table full, dropping packet Ben Hutchings <ben@decadent.org.uk> - 2015-10-03 03:40 +0200
Bug#800445: nf_conntrack: table full, dropping packet anomie@users.sourceforge.net - 2015-10-07 04:20 +0200
Processed: Re: Bug#800445: nf_conntrack: table full, dropping packet owner@bugs.debian.org (Debian Bug Tracking System) - 2015-10-03 03:40 +0200
csiph-web