Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.kernel > #90202 > unrolled thread

Re: MBF: Removal of iptables-legacy

Started byColin Watson <cjwatson@debian.org>
First post2025-11-23 16:20 +0100
Last post2025-11-24 15:20 +0100
Articles 3 — 2 participants

Back to article view | Back to linux.debian.kernel

This discussion starts older than the indexed window; earlier articles aren't shown. The article labeled Started by below is the oldest one visible, not the original post.


Contents

  Re: MBF: Removal of iptables-legacy Colin Watson <cjwatson@debian.org> - 2025-11-23 16:20 +0100
    Re: MBF: Removal of iptables-legacy Bastian Blank <waldi@debian.org> - 2025-11-23 17:50 +0100
      Re: MBF: Removal of iptables-legacy Colin Watson <cjwatson@debian.org> - 2025-11-24 15:20 +0100

#90202 — Re: MBF: Removal of iptables-legacy

FromColin Watson <cjwatson@debian.org>
Date2025-11-23 16:20 +0100
SubjectRe: MBF: Removal of iptables-legacy
Message-ID<LUk2C-faTf-27@gated-at.bofh.it>
[fixed typo in debian-kernel@ address]

On Sun, Nov 23, 2025 at 10:57:39AM +0100, Bastian Blank wrote:
>The Debian Kernel team decided to deprecate and remove support for the
>legacy interfaces used by iptables, arptables and ebtables from the
>kernel.  The replacement nftables compatibility layer was introduced
>around 2016.  It is finally time to try and get rid of the legacy
>interfaces, which are now disabled by default in the kernel.
>
>Our plan is to drop usage in all packages and the binaries for forky.
>We will then go and remove the kernel support itself after the release
>of forky.  So in forky, using legacy iptables will still work, but
>Debian will not provide any support and consider it deprecated.
>
>There are some packages that hardcode the use of iptables-legacy.  In
>those cases just using the non-legacy counterparts should work.  It just
>needs a reboot to get rid of the old incompatible rules loaded into the
>kernel.

I wonder how many of these are conditional code in packages that also 
support nft?  For example, incus caught my eye in your list: it has both 
xtables and nftables drivers, and it prefers nftables if it's available.  
It doesn't look as though anything would need to change in that package 
to cope with a kernel without iptables support.

I'd expect many userspace programs to take similar strategies if they've 
been around for long enough to have needed to support pre-nftables 
kernels at some point, so this MBF will likely need a fair amount of 
filtering.

-- 
Colin Watson (he/him)                              [cjwatson@debian.org]

[toc] | [next] | [standalone]


#90205

FromBastian Blank <waldi@debian.org>
Date2025-11-23 17:50 +0100
Message-ID<LUlrH-fbKK-1@gated-at.bofh.it>
In reply to#90202
On Sun, Nov 23, 2025 at 03:12:27PM +0000, Colin Watson wrote:
> I wonder how many of these are conditional code in packages that also
> support nft?  For example, incus caught my eye in your list: it has both
> xtables and nftables drivers, and it prefers nftables if it's available.  It
> doesn't look as though anything would need to change in that package to cope
> with a kernel without iptables support.

The source check matched this reference to the legacy stuff:

| test/suites/container_devices_nic_bridged_filtering.sh:            echo "==> SKIP: ebtables must be legacy version (try update-alternatives --set ebtables /usr/sbin/ebtables-legacy)"

Bastian

-- 
Extreme feminine beauty is always disturbing.
		-- Spock, "The Cloud Minders", stardate 5818.4

[toc] | [prev] | [next] | [standalone]


#90211

FromColin Watson <cjwatson@debian.org>
Date2025-11-24 15:20 +0100
Message-ID<LUFA5-fpwe-1@gated-at.bofh.it>
In reply to#90205
On Sun, Nov 23, 2025 at 05:25:09PM +0100, Bastian Blank wrote:
>On Sun, Nov 23, 2025 at 03:12:27PM +0000, Colin Watson wrote:
>> I wonder how many of these are conditional code in packages that also
>> support nft?  For example, incus caught my eye in your list: it has both
>> xtables and nftables drivers, and it prefers nftables if it's available.  It
>> doesn't look as though anything would need to change in that package to cope
>> with a kernel without iptables support.
>
>The source check matched this reference to the legacy stuff:
>
>| test/suites/container_devices_nic_bridged_filtering.sh:            echo "==> SKIP: ebtables must be legacy version (try update-alternatives --set ebtables /usr/sbin/ebtables-legacy)"

That code is within a [ "$firewallDriver" = "xtables" ] check, which 
will be false on a modern system.

-- 
Colin Watson (he/him)                              [cjwatson@debian.org]

[toc] | [prev] | [standalone]


Back to top | Article view | linux.debian.kernel


csiph-web