Your message dated Wed, 02 Sep 2026 09:49:56 +0000
with message-id <[email protected]>
and subject line Bug#1138454: fixed in nftables 1.1.7-1
has caused the Debian Bug report #1138454,
regarding nftables: nft -j monitor leaks memory
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)
--
1138454: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1138454
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Package: nftables
Version: 1.1.3-1
Severity: normal
Dear Maintainer,
'nft -j monitor' leaks a small amount of memory for every set element
event. The leak has been fixed upstream in commit [1]. While the leak is
small, it can add up when the monitor runs for a long time, as it does
on my router (with another long-running process parsing nft's JSON
output). I would thus greatly appreciate it if the fix made its way into
trixie in some form.
[1] d2a427c4abfadd2ce51bdab54c40fbf3d990c724
https://git.netfilter.org/nftables/commit/?id=d2a427c4abfadd2ce51bdab54c40fbf3d990c724
Cheers,
--
Anton Khirnov
--- End Message ---
--- Begin Message ---
Source: nftables
Source-Version: 1.1.7-1
Done: Jeremy Sowden <[email protected]>
We believe that the bug you reported is fixed in the latest version of
nftables, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Jeremy Sowden <[email protected]> (supplier of updated nftables package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Format: 1.8
Date: Wed, 02 Sep 2026 09:08:26 +0100
Source: nftables
Architecture: source
Version: 1.1.7-1
Distribution: unstable
Urgency: medium
Maintainer: Debian Netfilter Packaging Team
<[email protected]>
Changed-By: Jeremy Sowden <[email protected]>
Closes: 1138454
Changes:
nftables (1.1.7-1) unstable; urgency=medium
.
[ Luca Boccassi ]
* [b5cb949] nftables.service: add ConditionFileNotEmpty=/etc/nftables.conf
.
[ Jeremy Sowden ]
* [5985c60] d/gbp.conf: import-orig: set `upstream-vcs-tag`
* [7509113] New upstream version 1.1.7 (Closes: #1138454)
- Fix spurious EEXIST error when using the create element command with
large batches.
- Improve error reporting for syntax errors by printing expected
tokens.
- add/insert commands use 'handle' for positioning in JSON. The handle
specifies from what rule to add (after the specified rule) or insert
(before the specified rule). Multiple rules added at the same handle
are positioned relative to the original rule, not to previously
inserted rules.
- Sort strings datatype when listing sets.
- Sort concatenation components in big endian, so the listing is
independent of the architecture byteorder.
- Update --debug=netlink to display data in its byteorder and size,
this applies to immediate data in expressions and set elements.
- Set element support for multi-statements, eg. counter + quota.
One can also combine with ct count, last and limit rate.
- Connlimit support with maps.
- Include "count" field when listing set in JSON
- Support for using bitmask datatypes as set key, eg. tcp flags.
- Fix element deletion by numeric cgroupsv2 id.
- Fix get element with intervals including maximum datatype value,
- Use poll() not select(), otherwise libnftables breaks with
third party applications with >= 1024 open file descriptors.
- Do not reset counter if -c/--check is specified with the reset
command.
- man nft(8) documentation updates and assorted fixes.
* [48a753f] d/patches: remove upstreamed patch
* [d445013] d/control, d/t/control: run `wrap-and-sort -ast`
* [fe6c5f8] d/control: bump Standards-Version to 4.7.4
* [2a73d41] d/control: bump debhelper-compat to 14
* [6b64720] d/control: remove substvars handled by debhelper at compat 14
* [058e778] d/control: remove default `Rules-Requires-Root` field
* [121b033] d/control: bump min. version for libnftnl-dev build-dep to 1.3.2
Checksums-Sha1:
1d50816bdcf58a3208182801bbb96ddbafddac35 2832 nftables_1.1.7-1.dsc
999bae3a589cc304ab5282d85c465c31614d6b47 1062488 nftables_1.1.7.orig.tar.xz
9ce148531cce2a9cadfcd265de9637b3c181db47 833 nftables_1.1.7.orig.tar.xz.asc
5de27b3e2b339d5e2aabfb5e11b0dc823030b4eb 23964 nftables_1.1.7-1.debian.tar.xz
abd672d90cb0aacf1dbf94739574af415952e0af 9029 nftables_1.1.7-1_amd64.buildinfo
Checksums-Sha256:
067fef104b6e4ed88f1c087948fda09edaf9af91ef40ed4182f432778a06ff94 2832
nftables_1.1.7-1.dsc
a6fbf060d8d4fff001517a2b94f356bb4366bfbf0ba366366f9d27cc38caa58f 1062488
nftables_1.1.7.orig.tar.xz
b055832142b654c5e1614f0a8f6b8d12d462b630af5af92945441faf5227da35 833
nftables_1.1.7.orig.tar.xz.asc
76e41f5b10c941d4fbef26294223e22405e900a5f24999e1b0e6594edc6d5642 23964
nftables_1.1.7-1.debian.tar.xz
842f518a5af7430b280fde65466b814d538badfb67d5ac57930b352f19267663 9029
nftables_1.1.7-1_amd64.buildinfo
Files:
8f4955a92390bc4469d1cc56914e36ad 2832 net important nftables_1.1.7-1.dsc
97a41dd161157440cf19e9f848834166 1062488 net important
nftables_1.1.7.orig.tar.xz
c1a0a179a29011739a53f4ac864ed5c0 833 net important
nftables_1.1.7.orig.tar.xz.asc
e596ae8aac74adf231e6f3e9356a35f3 23964 net important
nftables_1.1.7-1.debian.tar.xz
a9a6fcc1ee3dd482a555d5ff9aa4f06f 9029 net important
nftables_1.1.7-1_amd64.buildinfo
-----BEGIN PGP SIGNATURE-----
wsG7BAEBCgBvBYJql+3yCRAphqwKvfEEDUcUAAAAAAAeACBzYWx0QG5vdGF0aW9u
cy5zZXF1b2lhLXBncC5vcmcLmtwg0+ChJSjIu+jWpj+91kll7ettJVeXGhHHrhyq
zhYhBGwdtFNj70A3vVbVFymGrAq98QQNAAC0MhAAjBOm9Pi3ZnH6ujkfY2jGUgA7
R50STBYtUuqcWLp9IFmuHcFwFFbkiNnUGYmEetXwzXP1C3pfkFecnTzc4x/TQa8L
enxyOE0a88bVxKHnFUh7KwE/ckraROvOWwGcRD4miPv6RPoKF5AqdoHoVEDBb3SU
7m/koyVNqjBQgIppRD6yY7Cm9Lcot3+IjsCPWE8Jekf5a+5yUCsjC2Soe/L+ZJ/N
ZtkfjcURLbSoJssus2Po88Sa/JqyBw8Dy543ctJ4HsIN2iKXY7CGfy7/fqqi8tXK
p8rzNTqSc1eUfClZmbr3ZsAqP63/WlRImnohcjuVOgetrYpNnvm5BDNRU63NYjO3
T0ayKzi2eNy00l04b4xWTjy+29oiaKLAt/MZ5rxg4oD0B7j5Ju4s23XX8zfVg5Vh
l4LJT6R1K9yZow0+PnAe2U2wE+fxJUAHKsVBGhjRNi17oxzHPm1/qXzkZBXbMf8x
MGORkL50rxmpEYRKLkDqrGMNT1rFPDHymE/89NlnkkdI44sz5pd44P+34WORG49s
optCjxhm+NHzV8YceULpES9GRKEW6KG71czBBoFX1rN1TYqrSwdCyKRBcCYGe3LH
Ppzh8MuenyO3Pq1fVbKmg9UUdK4nL0wN6H+JCmH0ByeGb8TO6oFJ70w3AtDqKva+
G8PoWxRAj0SjlWsJVhU=
=ZmiY
-----END PGP SIGNATURE-----
pgpf1tjXzlFoK.pgp
Description: PGP signature
--- End Message ---