Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.kernel > #89735 > unrolled thread

Bug#1118653: linux-image-6.17.2-amd64: Please restore CONFIG_NETFILTER_XT_TARGET_MASQUERADE

Started byBen Hutchings <ben@decadent.org.uk>
First post2025-10-23 20:30 +0200
Last post2025-11-02 10:30 +0100
Articles 4 — 3 participants

Back to article view | Back to linux.debian.kernel

This discussion starts older than the indexed window; earlier articles aren't shown. The article labeled Started by below is the oldest one visible, not the original post.


Contents

  Bug#1118653: linux-image-6.17.2-amd64: Please restore CONFIG_NETFILTER_XT_TARGET_MASQUERADE Ben Hutchings <ben@decadent.org.uk> - 2025-10-23 20:30 +0200
    Bug#1118653: linux-image-6.17.2-amd64: Please restore CONFIG_NETFILTER_XT_TARGET_MASQUERADE Bastian Blank <waldi@debian.org> - 2025-10-23 20:40 +0200
    Bug#1118653: linux-image-6.17.2-amd64: Please restore CONFIG_NETFILTER_XT_TARGET_MASQUERADE Bastian Blank <waldi@debian.org> - 2025-10-29 16:30 +0100
      Bug#1118653: linux-image-6.17.2-amd64: Please restore CONFIG_NETFILTER_XT_TARGET_MASQUERADE Salvatore Bonaccorso <carnil@debian.org> - 2025-11-02 10:30 +0100

#89735 — Bug#1118653: linux-image-6.17.2-amd64: Please restore CONFIG_NETFILTER_XT_TARGET_MASQUERADE

FromBen Hutchings <ben@decadent.org.uk>
Date2025-10-23 20:30 +0200
SubjectBug#1118653: linux-image-6.17.2-amd64: Please restore CONFIG_NETFILTER_XT_TARGET_MASQUERADE
Message-ID<LJ8et-7oXm-5@gated-at.bofh.it>

[Multipart message — attachments visible in raw view] — view raw

On Thu, 2025-10-23 at 16:26 +0200, Dmytro Nezhevenko wrote:
> Package: src:linux
> Version: 6.17.2-1~exp1
> Severity: normal
> X-Debbugs-Cc: debian-amd64@lists.debian.org
> User: debian-amd64@lists.debian.org
> Usertags: amd64
> 
> Dear Maintainer,
> 
> It looks like kernel 6.17.2 from experimental has no support for 
> CONFIG_NETFILTER_XT_TARGET_MASQUERADE
> 
> This prevents libvirt from bringing up virtual bridge networking with
> it's default configuration (that uses iptables)
> 
> Current sid kernel (6.16) is OK.
> 
> PS. Sorry if it's intentional change for transition from iptables
[...]

There was an intentional change upstream: there is a new symbol
CONFIG_NETFILTER_XTABLES_LEGACY that iptables etc. depend on, and it is
off by default.  But we certainly shouldn't break libvirt, so I think we
need to turn that back on for now.

Ben.

-- 
Ben Hutchings
Never put off till tomorrow what you can avoid all together.

[toc] | [next] | [standalone]


#89737

FromBastian Blank <waldi@debian.org>
Date2025-10-23 20:40 +0200
Message-ID<LJ8o9-7p0V-5@gated-at.bofh.it>
In reply to#89735
On Thu, Oct 23, 2025 at 08:21:43PM +0200, Ben Hutchings wrote:
> There was an intentional change upstream: there is a new symbol
> CONFIG_NETFILTER_XTABLES_LEGACY that iptables etc. depend on, and it is
> off by default.  But we certainly shouldn't break libvirt, so I think we
> need to turn that back on for now.

So libvirt uses iptables-legacy, not iptables?  At least that's how I
understand the documentation for this.

Bastian

-- 
There is a multi-legged creature crawling on your shoulder.
		-- Spock, "A Taste of Armageddon", stardate 3193.9

[toc] | [prev] | [next] | [standalone]


#89825

FromBastian Blank <waldi@debian.org>
Date2025-10-29 16:30 +0100
Message-ID<LLghz-8V0h-3@gated-at.bofh.it>
In reply to#89735
Control: reopen -1

On Thu, Oct 23, 2025 at 08:21:43PM +0200, Ben Hutchings wrote:
> There was an intentional change upstream: there is a new symbol
> CONFIG_NETFILTER_XTABLES_LEGACY that iptables etc. depend on, and it is
> off by default.  But we certainly shouldn't break libvirt, so I think we
> need to turn that back on for now.

And this problem is actually unrelated.  We don't actually set
NETFILTER_XT_TARGET_MASQUERADE in our config.  So it ends up disabled as
we also override the default selection with NETFILTER_ADVANCED=y.

| % git grep -E 'NETFILTER_ADVANCED|NETFILTER_XT_TARGET_MASQUERADE'
| debian/config/config:CONFIG_NETFILTER_ADVANCED=y
| %

Bastian

-- 
Mind your own business, Spock.  I'm sick of your halfbreed interference.

[toc] | [prev] | [next] | [standalone]


#89888

FromSalvatore Bonaccorso <carnil@debian.org>
Date2025-11-02 10:30 +0100
Message-ID<LMCzo-9RWE-5@gated-at.bofh.it>
In reply to#89825
Hi,

On Wed, Oct 29, 2025 at 04:19:41PM +0100, Bastian Blank wrote:
> Control: reopen -1
> 
> On Thu, Oct 23, 2025 at 08:21:43PM +0200, Ben Hutchings wrote:
> > There was an intentional change upstream: there is a new symbol
> > CONFIG_NETFILTER_XTABLES_LEGACY that iptables etc. depend on, and it is
> > off by default.  But we certainly shouldn't break libvirt, so I think we
> > need to turn that back on for now.
> 
> And this problem is actually unrelated.  We don't actually set
> NETFILTER_XT_TARGET_MASQUERADE in our config.  So it ends up disabled as
> we also override the default selection with NETFILTER_ADVANCED=y.
> 
> | % git grep -E 'NETFILTER_ADVANCED|NETFILTER_XT_TARGET_MASQUERADE'
> | debian/config/config:CONFIG_NETFILTER_ADVANCED=y
> | %

maybe i get thinkgs wrong right now,but it still get enabled now,
because

/boot/config-6.17.6+deb14-amd64:CONFIG_NETFILTER_ADVANCED=y
/boot/config-6.17.6+deb14-amd64:CONFIG_NETFILTER_XT_TARGET_MASQUERADE=m
/boot/config-6.17.6+deb14-amd64:CONFIG_IP_NF_TARGET_MASQUERADE=m

and

config IP_NF_TARGET_MASQUERADE
        tristate "MASQUERADE target support"
        select NETFILTER_XT_TARGET_MASQUERADE
        help
          This is a backwards-compat option for the user's convenience
          (e.g. when running oldconfig). It selects NETFILTER_XT_TARGET_MASQUERADE.

Is this correct?

Regards,
Salvatore

[toc] | [prev] | [standalone]


Back to top | Article view | linux.debian.kernel


csiph-web