Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.devel > #120110

Re: MBF: Removal of iptables-legacy

From Jeremy Sowden <azazel@debian.org>
Newsgroups linux.debian.devel, linux.debian.kernel
Subject Re: MBF: Removal of iptables-legacy
Date 2026-01-07 09:20 +0100
Message-ID <MawVP-8HpB-7@gated-at.bofh.it> (permalink)
References <LUfmh-f7PC-7@gated-at.bofh.it> <MaqQp-8D57-1@gated-at.bofh.it>
Organization linux.* mail to news gateway

Cross-posted to 2 groups.

Show all headers | View raw


[Multipart message — attachments visible in raw view] - view raw

On 2026-01-07, at 02:40:37 +0100, Andrea Bolognani wrote:
> On Sun, Nov 23, 2025 at 10:57:39AM +0100, Bastian Blank wrote:
> > The Debian Kernel team decided to deprecate and remove support for the
> > legacy interfaces used by iptables, arptables and ebtables from the
> > kernel.  The replacement nftables compatibility layer was introduced
> > around 2016.  It is finally time to try and get rid of the legacy
> > interfaces, which are now disabled by default in the kernel.
> >
> > Our plan is to drop usage in all packages and the binaries for forky.
> > We will then go and remove the kernel support itself after the release
> > of forky.  So in forky, using legacy iptables will still work, but
> > Debian will not provide any support and consider it deprecated.
> >
> > There are some packages that hardcode the use of iptables-legacy.  In
> > those cases just using the non-legacy counterparts should work.  It just
> > needs a reboot to get rid of the old incompatible rules loaded into the
> > kernel.
> 
> Bit late to the party, sorry.
> 
> Can you please confirm that it's only iptables-legacy (and the
> underlying kernel code) going away, and that iptables-nft will keep
> working going forward?

Correct.

> libvirt tried to switch to nft a year ago but unfortunately that
> turned out to be unfeasible at the time, so we are currently relying
> on the compatibility interface provided by iptables-nft. Additional
> details in #1090355.

J.

Back to linux.debian.devel | Previous | Next — Previous in thread | Find similar | Unroll thread


Thread

MBF: Removal of iptables-legacy Bastian Blank <waldi@debian.org> - 2025-11-23 11:20 +0100
  Re: MBF: Removal of iptables-legacy Colin Watson <cjwatson@debian.org> - 2025-11-23 16:20 +0100
    Re: MBF: Removal of iptables-legacy Vincent Danjean <vdanjean.ml@free.fr> - 2025-11-23 17:00 +0100
      Re: MBF: Removal of iptables-legacy Lucas Castro <lucas@gnuabordo.com.br> - 2025-11-24 17:20 +0100
        Re: MBF: Removal of iptables-legacy Marc Haber <mh+debian-devel@zugschlus.de> - 2025-11-24 17:50 +0100
          Re: MBF: Removal of iptables-legacy Lucas Castro <lucas@gnuabordo.com.br> - 2025-11-24 18:00 +0100
    nft gripe (was: MBF: Removal of iptables-legacy) Marc Haber <mh+debian-devel@zugschlus.de> - 2025-11-23 17:30 +0100
    Re: MBF: Removal of iptables-legacy Bastian Blank <waldi@debian.org> - 2025-11-23 17:50 +0100
      Re: MBF: Removal of iptables-legacy Colin Watson <cjwatson@debian.org> - 2025-11-24 15:20 +0100
  Re: MBF: Removal of iptables-legacy Tianon Gravi <tianon@debian.org> - 2025-11-25 02:10 +0100
  Re: MBF: Removal of iptables-legacy Andrea Bolognani <eof@kiyuko.org> - 2026-01-07 02:50 +0100
    Re: MBF: Removal of iptables-legacy Jeremy Sowden <azazel@debian.org> - 2026-01-07 09:20 +0100

csiph-web