Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.kernel > #90202 > unrolled thread
| Started by | Colin Watson <cjwatson@debian.org> |
|---|---|
| First post | 2025-11-23 16:20 +0100 |
| Last post | 2025-11-24 15:20 +0100 |
| Articles | 3 — 2 participants |
Back to article view | Back to linux.debian.kernel
This discussion starts older than the indexed window; earlier articles aren't shown. The article labeled Started by
below is the oldest one visible, not the original post.
Re: MBF: Removal of iptables-legacy Colin Watson <cjwatson@debian.org> - 2025-11-23 16:20 +0100
Re: MBF: Removal of iptables-legacy Bastian Blank <waldi@debian.org> - 2025-11-23 17:50 +0100
Re: MBF: Removal of iptables-legacy Colin Watson <cjwatson@debian.org> - 2025-11-24 15:20 +0100
| From | Colin Watson <cjwatson@debian.org> |
|---|---|
| Date | 2025-11-23 16:20 +0100 |
| Subject | Re: MBF: Removal of iptables-legacy |
| Message-ID | <LUk2C-faTf-27@gated-at.bofh.it> |
[fixed typo in debian-kernel@ address] On Sun, Nov 23, 2025 at 10:57:39AM +0100, Bastian Blank wrote: >The Debian Kernel team decided to deprecate and remove support for the >legacy interfaces used by iptables, arptables and ebtables from the >kernel. The replacement nftables compatibility layer was introduced >around 2016. It is finally time to try and get rid of the legacy >interfaces, which are now disabled by default in the kernel. > >Our plan is to drop usage in all packages and the binaries for forky. >We will then go and remove the kernel support itself after the release >of forky. So in forky, using legacy iptables will still work, but >Debian will not provide any support and consider it deprecated. > >There are some packages that hardcode the use of iptables-legacy. In >those cases just using the non-legacy counterparts should work. It just >needs a reboot to get rid of the old incompatible rules loaded into the >kernel. I wonder how many of these are conditional code in packages that also support nft? For example, incus caught my eye in your list: it has both xtables and nftables drivers, and it prefers nftables if it's available. It doesn't look as though anything would need to change in that package to cope with a kernel without iptables support. I'd expect many userspace programs to take similar strategies if they've been around for long enough to have needed to support pre-nftables kernels at some point, so this MBF will likely need a fair amount of filtering. -- Colin Watson (he/him) [cjwatson@debian.org]
[toc] | [next] | [standalone]
| From | Bastian Blank <waldi@debian.org> |
|---|---|
| Date | 2025-11-23 17:50 +0100 |
| Message-ID | <LUlrH-fbKK-1@gated-at.bofh.it> |
| In reply to | #90202 |
On Sun, Nov 23, 2025 at 03:12:27PM +0000, Colin Watson wrote: > I wonder how many of these are conditional code in packages that also > support nft? For example, incus caught my eye in your list: it has both > xtables and nftables drivers, and it prefers nftables if it's available. It > doesn't look as though anything would need to change in that package to cope > with a kernel without iptables support. The source check matched this reference to the legacy stuff: | test/suites/container_devices_nic_bridged_filtering.sh: echo "==> SKIP: ebtables must be legacy version (try update-alternatives --set ebtables /usr/sbin/ebtables-legacy)" Bastian -- Extreme feminine beauty is always disturbing. -- Spock, "The Cloud Minders", stardate 5818.4
[toc] | [prev] | [next] | [standalone]
| From | Colin Watson <cjwatson@debian.org> |
|---|---|
| Date | 2025-11-24 15:20 +0100 |
| Message-ID | <LUFA5-fpwe-1@gated-at.bofh.it> |
| In reply to | #90205 |
On Sun, Nov 23, 2025 at 05:25:09PM +0100, Bastian Blank wrote: >On Sun, Nov 23, 2025 at 03:12:27PM +0000, Colin Watson wrote: >> I wonder how many of these are conditional code in packages that also >> support nft? For example, incus caught my eye in your list: it has both >> xtables and nftables drivers, and it prefers nftables if it's available. It >> doesn't look as though anything would need to change in that package to cope >> with a kernel without iptables support. > >The source check matched this reference to the legacy stuff: > >| test/suites/container_devices_nic_bridged_filtering.sh: echo "==> SKIP: ebtables must be legacy version (try update-alternatives --set ebtables /usr/sbin/ebtables-legacy)" That code is within a [ "$firewallDriver" = "xtables" ] check, which will be false on a modern system. -- Colin Watson (he/him) [cjwatson@debian.org]
[toc] | [prev] | [standalone]
Back to top | Article view | linux.debian.kernel
csiph-web