Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.kernel > #58696 > unrolled thread

Bug#872560: linux-image-amd64: CONFIG_CGROUP_BPF is not set

Started byMichael Schubert <michael@kinvolk.io>
First post2017-08-18 16:30 +0200
Last post2018-01-22 13:10 +0100
Articles 6 — 6 participants

Back to article view | Back to linux.debian.kernel


Contents

  Bug#872560: linux-image-amd64: CONFIG_CGROUP_BPF is not set Michael Schubert <michael@kinvolk.io> - 2017-08-18 16:30 +0200
    Bug#872560: Related issues Yuri D'Elia <wavexx@thregr.org> - 2017-11-28 10:30 +0100
    Bug#872560: iproute2 vrf Jan Luebbe <jluebbe@lasnet.de> - 2017-12-14 17:30 +0100
    Bug#872560: flatpak --user --scope Kotik <debiarchiv@yandex.ru> - 2017-12-20 14:50 +0100
    Bug#872560: systemd[1]: Proceeding WITHOUT firewalling in effect! (This warning is only shown for the first loaded unit using IP firewalling.) Mathieu Malaterre <malat@debian.org> - 2018-01-22 13:00 +0100
    Processed: systemd[1]: Proceeding WITHOUT firewalling in effect!  (This warning is only shown for the first loaded unit using IP  firewalling.) "Debian Bug Tracking System" <owner@bugs.debian.org> - 2018-01-22 13:10 +0100

#58696 — Bug#872560: linux-image-amd64: CONFIG_CGROUP_BPF is not set

FromMichael Schubert <michael@kinvolk.io>
Date2017-08-18 16:30 +0200
SubjectBug#872560: linux-image-amd64: CONFIG_CGROUP_BPF is not set
Message-ID<ufQrF-4YI-27@gated-at.bofh.it>
Package: linux-image-amd64
Version: 4.12+84
Severity: normal

Dear Maintainer,

Please consider enabling CONFIG_CGROUP_BPF.

We use BPF for network filtering and accounting and therefore would like
to use bpf cgroup socket filtering on newer kernels.

Thank you.

-- System Information:
Debian Release: buster/sid
  APT prefers testing
  APT policy: (500, 'testing'), (50, 'unstable'), (1, 'experimental')
Architecture: amd64 (x86_64)

Kernel: Linux 4.12.0-1-amd64 (SMP w/4 CPU cores)
Locale: LANG=en_US.UTF-8, LC_CTYPE=en_US.UTF-8 (charmap=UTF-8), LANGUAGE=en_US:en (charmap=UTF-8)
Shell: /bin/sh linked to /bin/dash
Init: systemd (via /run/systemd/system)

Versions of packages linux-image-amd64 depends on:
ii  linux-image-4.12.0-1-amd64  4.12.6-1

linux-image-amd64 recommends no packages.

linux-image-amd64 suggests no packages.

-- no debconf information

[toc] | [next] | [standalone]


#59501 — Bug#872560: Related issues

FromYuri D'Elia <wavexx@thregr.org>
Date2017-11-28 10:30 +0100
SubjectBug#872560: Related issues
Message-ID<uQKnf-1e2-9@gated-at.bofh.it>
In reply to#58696
FYI, this also has implications for systemd.
See the following bug report:

  https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=878965

and the related upstream:

  https://github.com/systemd/systemd/issues/7054

[toc] | [prev] | [next] | [standalone]


#59657 — Bug#872560: iproute2 vrf

FromJan Luebbe <jluebbe@lasnet.de>
Date2017-12-14 17:30 +0100
SubjectBug#872560: iproute2 vrf
Message-ID<uWEyu-10y-9@gated-at.bofh.it>
In reply to#58696
iproute2 versions since v4.10.0 (which are not yet in Debian) have the
'ip vrf exec' subcommand, which needs CONFIG_CGROUP_BPF as well.

[toc] | [prev] | [next] | [standalone]


#59711 — Bug#872560: flatpak --user --scope

FromKotik <debiarchiv@yandex.ru>
Date2017-12-20 14:50 +0100
SubjectBug#872560: flatpak --user --scope
Message-ID<uYMUV-5xx-7@gated-at.bofh.it>
In reply to#58696

[Multipart message — attachments visible in raw view] — view raw

Flatpak needs CONFIG_CGROUP_BPFtoo.

     https://github.com/flatpak/flatpak/issues/1216
     https://github.com/systemd/systemd/issues/3388


[toc] | [prev] | [next] | [standalone]


#60043 — Bug#872560: systemd[1]: Proceeding WITHOUT firewalling in effect! (This warning is only shown for the first loaded unit using IP firewalling.)

FromMathieu Malaterre <malat@debian.org>
Date2018-01-22 13:00 +0100
SubjectBug#872560: systemd[1]: Proceeding WITHOUT firewalling in effect! (This warning is only shown for the first loaded unit using IP firewalling.)
Message-ID<vaIVz-4qb-5@gated-at.bofh.it>
In reply to#58696
Control: affects -1 src:systemd

For easier reference:

dmesg reveals:

[    8.324634] systemd[1]: File
/lib/systemd/system/systemd-journald.service:35 configures an IP
firewall (IPAddressDeny=any), but the local system does not s
upport BPF/cgroup based firewalling.
[    8.337180] systemd[1]: Proceeding WITHOUT firewalling in effect!
(This warning is only shown for the first loaded unit using IP
firewalling.)

This requires both CONFIG_CGROUP_BPF & CONFIG_BPF_SYSCALL

See:
https://github.com/systemd/systemd/issues/7188

[toc] | [prev] | [next] | [standalone]


#60044 — Processed: systemd[1]: Proceeding WITHOUT firewalling in effect! (This warning is only shown for the first loaded unit using IP firewalling.)

From"Debian Bug Tracking System" <owner@bugs.debian.org>
Date2018-01-22 13:10 +0100
SubjectProcessed: systemd[1]: Proceeding WITHOUT firewalling in effect! (This warning is only shown for the first loaded unit using IP firewalling.)
Message-ID<vaJ5f-4IM-3@gated-at.bofh.it>
In reply to#58696
Processing control commands:

> affects -1 src:systemd
Bug #872560 [src:linux] linux-image-amd64: CONFIG_CGROUP_BPF is not set
Added indication that 872560 affects src:systemd

-- 
872560: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=872560
Debian Bug Tracking System
Contact owner@bugs.debian.org with problems

[toc] | [prev] | [standalone]


Back to top | Article view | linux.debian.kernel


csiph-web