Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.kernel > #89739 > unrolled thread

Bug#1118653: linux-image-6.17.2-amd64: Please restore CONFIG_NETFILTER_XT_TARGET_MASQUERADE

Started byBastian Blank <waldi@debian.org>
First post2025-10-23 21:40 +0200
Last post2025-10-23 23:40 +0200
Articles 5 — 2 participants

Back to article view | Back to linux.debian.kernel

This discussion starts older than the indexed window; earlier articles aren't shown. The article labeled Started by below is the oldest one visible, not the original post.


Contents

  Bug#1118653: linux-image-6.17.2-amd64: Please restore CONFIG_NETFILTER_XT_TARGET_MASQUERADE Bastian Blank <waldi@debian.org> - 2025-10-23 21:40 +0200
    Bug#1118653: linux-image-6.17.2-amd64: Please restore CONFIG_NETFILTER_XT_TARGET_MASQUERADE Bastian Blank <waldi@debian.org> - 2025-10-23 23:40 +0200
      Bug#1118653: linux-image-6.17.2-amd64: Please restore CONFIG_NETFILTER_XT_TARGET_MASQUERADE Dmytro Nezhevenko <dion@dion.org.ua> - 2025-10-23 23:50 +0200
        Bug#1118653: linux-image-6.17.2-amd64: Please restore CONFIG_NETFILTER_XT_TARGET_MASQUERADE Bastian Blank <waldi@debian.org> - 2025-10-24 00:30 +0200
    Bug#1118653: linux-image-6.17.2-amd64: Please restore CONFIG_NETFILTER_XT_TARGET_MASQUERADE Dmytro Nezhevenko <dion@dion.org.ua> - 2025-10-23 23:40 +0200

#89739 — Bug#1118653: linux-image-6.17.2-amd64: Please restore CONFIG_NETFILTER_XT_TARGET_MASQUERADE

FromBastian Blank <waldi@debian.org>
Date2025-10-23 21:40 +0200
SubjectBug#1118653: linux-image-6.17.2-amd64: Please restore CONFIG_NETFILTER_XT_TARGET_MASQUERADE
Message-ID<LJ9kd-7pD7-7@gated-at.bofh.it>
On Thu, Oct 23, 2025 at 04:26:44PM +0200, Dmytro Nezhevenko wrote:
> This prevents libvirt from bringing up virtual bridge networking with
> it's default configuration (that uses iptables)

Please verify you have iptables-nft and not iptables-legacy installed.

Bastian

-- 
Spock: We suffered 23 casualties in that attack, Captain.

[toc] | [next] | [standalone]


#89746

FromBastian Blank <waldi@debian.org>
Date2025-10-23 23:40 +0200
Message-ID<LJbcl-7qVh-11@gated-at.bofh.it>
In reply to#89739
On Thu, Oct 23, 2025 at 11:07:56PM +0200, Dmytro Nezhevenko wrote:
> On Thu, Oct 23, 2025 at 09:37:52PM +0200, Bastian Blank wrote:
> > Please verify you have iptables-nft and not iptables-legacy installed.
> % dpkg-query -W |grep iptables                                                                        
> iptables        1.8.11-2
> 
> That's all I've. I've both iptables and nftables installed (for historical
> reasons). I'm able to switch libvirt to nftables. And has no personal
> requirement to use iptables. It's just default for libvirt right now and
> that's why I created that ticket.

My bad.  This is one package with two different implementations.  So
please verify you use the -nft version.  Something like:

update-alternatives --list /usr/bin/iptables

However some tools might iverride this, so moving the legacy binary
(iptables-legacy) away can find stuff as well.

Bastian

-- 
Landru! Guide us!
		-- A Beta 3-oid, "The Return of the Archons", stardate 3157.4

[toc] | [prev] | [next] | [standalone]


#89748

FromDmytro Nezhevenko <dion@dion.org.ua>
Date2025-10-23 23:50 +0200
Message-ID<LJbm1-7qYQ-1@gated-at.bofh.it>
In reply to#89746
On Thu, Oct 23, 2025 at 11:37:49PM +0200, Bastian Blank wrote:
> My bad.  This is one package with two different implementations.  So
> please verify you use the -nft version.  Something like:
> 
> update-alternatives --list /usr/bin/iptables
> 
> However some tools might iverride this, so moving the legacy binary
> (iptables-legacy) away can find stuff as well.

I think you asked about this:

%sudo update-alternatives --list iptables                                                                         
/usr/sbin/iptables-legacy
/usr/sbin/iptables-nft

% sudo update-alternatives --display iptables               
iptables - auto mode
  link best version is /usr/sbin/iptables-nft
  link currently points to /usr/sbin/iptables-nft
  link iptables is /usr/sbin/iptables
  slave iptables-restore is /usr/sbin/iptables-restore
  slave iptables-save is /usr/sbin/iptables-save
/usr/sbin/iptables-legacy - priority 10
  slave iptables-restore: /usr/sbin/iptables-legacy-restore
  slave iptables-save: /usr/sbin/iptables-legacy-save
/usr/sbin/iptables-nft - priority 20
  slave iptables-restore: /usr/sbin/iptables-nft-restore
  slave iptables-save: /usr/sbin/iptables-nft-save

-- 
WBR, Dmitry

[toc] | [prev] | [next] | [standalone]


#89749

FromBastian Blank <waldi@debian.org>
Date2025-10-24 00:30 +0200
Message-ID<LJbYJ-7rvB-3@gated-at.bofh.it>
In reply to#89748
On Thu, Oct 23, 2025 at 11:44:23PM +0200, Dmytro Nezhevenko wrote:
> I think you asked about this:

Yeah.  Thx.  It seems I have to look for myself. 

Bastian

-- 
Where there's no emotion, there's no motive for violence.
		-- Spock, "Dagger of the Mind", stardate 2715.1

[toc] | [prev] | [next] | [standalone]


#89747

FromDmytro Nezhevenko <dion@dion.org.ua>
Date2025-10-23 23:40 +0200
Message-ID<LJbcl-7qVh-9@gated-at.bofh.it>
In reply to#89739
On Thu, Oct 23, 2025 at 09:37:52PM +0200, Bastian Blank wrote:
> On Thu, Oct 23, 2025 at 04:26:44PM +0200, Dmytro Nezhevenko wrote:
> > This prevents libvirt from bringing up virtual bridge networking with
> > it's default configuration (that uses iptables)
> 
> Please verify you have iptables-nft and not iptables-legacy installed.
> 

Hi. 

% dpkg-query -W |grep iptables                                                                        
iptables        1.8.11-2

That's all I've. I've both iptables and nftables installed (for historical
reasons). I'm able to switch libvirt to nftables. And has no personal
requirement to use iptables. It's just default for libvirt right now and
that's why I created that ticket.

-- 
WBR, Dmitry

[toc] | [prev] | [standalone]


Back to top | Article view | linux.debian.kernel


csiph-web