I seem to have a clue at what's wrong with AI help.
I use Debops which preserves a set of previous RULES (for one FORWARD
rules) but this preserves the jump to FORWARD-early even though
FORWARD-early itself is not defined in my ferm rules set.
This preserves is mainly there to keep docker rules on restart and such.
Debian default /etc/ferm/ferm.conf is not affected because it empties
the FORWARD rule. But thus it purges docker rules on restart I believe.
I managed to workaround this with
"
cat /etc/ferm/rules.d/000_rule_reset_ferm_early.conf
domain (ip ip6) {
table filter {
chain INPUT-early {}
chain OUTPUT-early {}
chain FORWARD-early {}
}
}
" and "
cat /etc/ferm/rules.d/000_rule_purge_ferm_early_hooks.conf
@hook post "iptables -D INPUT -j INPUT-early 2>/dev/null || true";
@hook post "iptables -D OUPUT -j OUTPUT-early 2>/dev/null || true";
@hook post "iptables -D FORWARD -j FORWARD-early 2>/dev/null || true";
@hook post "iptables -X INPUT-early 2>/dev/null || true";
@hook post "iptables -X OUTPUT-early 2>/dev/null || true";
@hook post "iptables -X FORWARD-early 2>/dev/null || true";
@hook post "ip6tables -D INPUT -j INPUT-early 2>/dev/null || true";
@hook post "ip6tables -D OUPUT -j OUTPUT-early 2>/dev/null || true";
@hook post "ip6tables -D FORWARD -j FORWARD-early 2>/dev/null || true";
@hook post "ip6tables -X INPUT-early 2>/dev/null || true";
@hook post "ip6tables -X OUTPUT-early 2>/dev/null || true";
@hook post "ip6tables -X FORWARD-early 2>/dev/null || true";
"
but this looks like porcelain. Everytime /etc/ferm/ferm-early.conf is
modified this will requires changes.
But I cannot flush the FORWARD ruleset either because I cannot expect a
predefined set of docker rules to add to it afterwards either (not to
account that this script should account for when docker is not use too).
Regards
Alban
"
sudo /usr/libexec/ferm/ferm-systemd activate
Activating firewall rules: /usr/sbin/ferm /etc/ferm/ferm.conf
iptables-restore v1.8.13 (legacy): Couldn't load target
`FORWARD-early':No such file or directory
Error occurred at line: 38
Try `iptables-restore -h' or 'iptables-restore --help' for more information.
Failed to run /usr/sbin/iptables-restore
Firewall rules rolled back.
"
"
sudo iptables -L -n -v
Chain INPUT (policy DROP 22 packets, 8224 bytes)
pkts bytes target prot opt in out source destination
58 14649 INPUT-early all -- * * 0.0.0.0/0 0.0.0.0/0
Chain FORWARD (policy DROP 0 packets, 0 bytes)
pkts bytes target prot opt in out source destination
0 0 DOCKER-USER all -- * * 0.0.0.0/0 0.0.0.0/0
0 0 DOCKER-FORWARD all -- * * 0.0.0.0/0
0.0.0.0/0
0 0 FORWARD-early all -- * * 0.0.0.0/0
0.0.0.0/0
Chain OUTPUT (policy ACCEPT 13 packets, 16647 bytes)
pkts bytes target prot opt in out source destination
50 22762 OUTPUT-early all -- * * 0.0.0.0/0 0.0.0.0/0
Chain DOCKER (2 references)
pkts bytes target prot opt in out source destination
0 0 ACCEPT tcp -- !br-27afa3a73960 br-27afa3a73960
0.0.0.0/0 172.18.0.2 tcp dpt:9443
0 0 ACCEPT tcp -- !br-27afa3a73960 br-27afa3a73960
0.0.0.0/0 172.18.0.2 tcp dpt:9000
0 0 ACCEPT tcp -- !br-27afa3a73960 br-27afa3a73960
0.0.0.0/0 172.18.0.2 tcp dpt:8000
0 0 DROP all -- !br-27afa3a73960 br-27afa3a73960
0.0.0.0/0 0.0.0.0/0
0 0 DROP all -- !docker0 docker0 0.0.0.0/0 0.0.0.0/0
Chain DOCKER-BRIDGE (1 references)
pkts bytes target prot opt in out source destination
0 0 DOCKER all -- * br-27afa3a73960 0.0.0.0/0
0.0.0.0/0
0 0 DOCKER all -- * docker0 0.0.0.0/0 0.0.0.0/0
Chain DOCKER-CT (1 references)
pkts bytes target prot opt in out source destination
0 0 ACCEPT all -- * br-27afa3a73960 0.0.0.0/0
0.0.0.0/0 ctstate RELATED,ESTABLISHED
0 0 ACCEPT all -- * docker0 0.0.0.0/0 0.0.0.0/0
ctstate RELATED,ESTABLISHED
Chain DOCKER-FORWARD (1 references)
pkts bytes target prot opt in out source destination
0 0 DOCKER-CT all -- * * 0.0.0.0/0 0.0.0.0/0
0 0 DOCKER-ISOLATION-STAGE-1 all -- * * 0.0.0.0/0
0.0.0.0/0
0 0 DOCKER-BRIDGE all -- * * 0.0.0.0/0
0.0.0.0/0
0 0 ACCEPT all -- br-27afa3a73960 * 0.0.0.0/0
0.0.0.0/0
0 0 ACCEPT all -- docker0 * 0.0.0.0/0 0.0.0.0/0
Chain DOCKER-ISOLATION-STAGE-1 (1 references)
pkts bytes target prot opt in out source destination
0 0 DOCKER-ISOLATION-STAGE-2 all -- br-27afa3a73960
!br-27afa3a73960 0.0.0.0/0 0.0.0.0/0
0 0 DOCKER-ISOLATION-STAGE-2 all -- docker0 !docker0
0.0.0.0/0 0.0.0.0/0
Chain DOCKER-ISOLATION-STAGE-2 (2 references)
pkts bytes target prot opt in out source destination
0 0 DROP all -- * docker0 0.0.0.0/0 0.0.0.0/0
0 0 DROP all -- * br-27afa3a73960 0.0.0.0/0
0.0.0.0/0
Chain DOCKER-USER (1 references)
pkts bytes target prot opt in out source destination
Chain FORWARD-early (1 references)
pkts bytes target prot opt in out source destination
0 0 DROP all -- * * 0.0.0.0/0 0.0.0.0/0
state INVALID
0 0 ACCEPT all -- * * 0.0.0.0/0 0.0.0.0/0
state RELATED,ESTABLISHED
Chain INPUT-early (1 references)
pkts bytes target prot opt in out source destination
0 0 ACCEPT udp -- lo * 0.0.0.0/0 0.0.0.0/0
udp spt:54321
0 0 DROP all -- * * 0.0.0.0/0 0.0.0.0/0
state INVALID
36 6425 ACCEPT all -- * * 0.0.0.0/0 0.0.0.0/0
state RELATED,ESTABLISHED
0 0 ACCEPT all -- lo * 0.0.0.0/0 0.0.0.0/0
0 0 ACCEPT icmp -- * * 0.0.0.0/0 0.0.0.0/0
0 0 ACCEPT udp -- * * 0.0.0.0/0 0.0.0.0/0
udp dpt:500
0 0 ACCEPT esp -- * * 0.0.0.0/0 0.0.0.0/0
0 0 ACCEPT ah -- * * 0.0.0.0/0 0.0.0.0/0
0 0 ACCEPT tcp -- * * 0.0.0.0/0 0.0.0.0/0
tcp dpt:22
Chain OUTPUT-early (1 references)
pkts bytes target prot opt in out source destination
37 6115 ACCEPT all -- * * 0.0.0.0/0 0.0.0.0/0
state RELATED,ESTABLISHED
"
"
cat /etc/ferm/ferm.conf
# Ansible managed
# Load configuration from parts
@include 'rules.d/';
"
"
for i in /etc/ferm/rules.d/* ; do echo $i; cat $i; echo "";done
/etc/ferm/rules.d/000_rule_docker_preserve.conf
# Ansible managed
# # Docker support.
# # cf
https://github.com/MaxKellermann/ferm/issues/58#issuecomment-588600252
table nat chain (PREROUTING OUTPUT POSTROUTING DOCKER) @preserve;
table filter chain (FORWARD DOCKER DOCKER-ISOLATION-STAGE-1
DOCKER-ISOLATION-STAGE-2 DOCKER-FORWARD DOCKER-CT DOCKER-BRIDGE) @preserve;
table filter chain (DOCKER-USER) { RETURN; }
/etc/ferm/rules.d/000_rule_firewall_hooks.conf
# Ansible managed
# Run custom hooks at various firewall stages
@hook pre "run-parts /etc/ferm/hooks/pre.d";
@hook post "run-parts /etc/ferm/hooks/post.d";
@hook flush "run-parts /etc/ferm/hooks/flush.d";
/etc/ferm/rules.d/000_rule_firewall_log.conf
# Ansible managed
# Custom log function used by other rules
@def &log($msg) = {
mod limit limit 2/min
limit-burst 5
LOG log-ip-options log-prefix "$msg";
}
/etc/ferm/rules.d/000_rule_firewall_variables.conf
# Ansible managed
# Define custom variables available in the firewall
@def $domains = (ip ip6);
@def $ipv4_enabled = 1;
@def $ipv6_enabled = 1;
/etc/ferm/rules.d/001_rule_accept_loopback.conf
# Ansible managed
domain (ip ip6) table filter chain INPUT {
interface lo {
ACCEPT;
}
}
/etc/ferm/rules.d/005_rule_accept_ansible_controller.conf
# Ansible managed
# Accept SSH connections from Ansible Controllers
domain (ip ip6) table filter chain INPUT {
protocol tcp dport ssh {
# Connections from any IP address not allowed
}
}
/etc/ferm/rules.d/005_rule_policy_filter_forward.conf
# Ansible managed
domain (ip ip6) table filter chain FORWARD {
policy DROP;
}
/etc/ferm/rules.d/005_rule_policy_filter_input.conf
# Ansible managed
domain (ip ip6) table filter chain INPUT {
policy DROP;
}
/etc/ferm/rules.d/005_rule_policy_filter_output.conf
# Ansible managed
domain (ip ip6) table filter chain OUTPUT {
policy ACCEPT;
}
(...)
"
On Sat, 29 Aug 2026 15:29:23 +0200 Marc Haber
<[email protected]> wrote:
> Hi Alban,
>
> I have uploaded a new version of ferm to unstable that allows the
> ferm-systemd script to save more debug information. Can you try this
> please, and if it still fails (which is likely), set DEBUGLOG_DIR to a
> directory that is read-write available early and survives the system
> startup (like /var/cache/ferm, for example). Then feel free to send me a
> tarball.
>
> Greetings
> Marc
>
> On Sat, Aug 15, 2026 at 01:45:52PM +0200, Marc Haber wrote:
> >From: Marc Haber <[email protected]>
> >Subject: Bug#1144431: ferm: seems ferm early prevents ferm from starting
> >To: Alban Browaeys <[email protected]>
> >Cc: Alban Browaeys <[email protected]>, [email protected]
> >Reply-To: Marc Haber <[email protected]>,
> > [email protected]
> >Date: Sat, 15 Aug 2026 13:45:52 +0200
> >X-Debian-PR-Package: ferm
> >User-Agent: Mutt/2.2.13 (2024-03-09)
> >List-Id: <ferm.tracker.debian.org>
> >X-PTS-Package: ferm
> >X-Spam-Score: (----) -4.5
> >X-Spam-Report: torres.zugschlus.de Content analysis details: (-4.5
> > points, 5.0 required) pts rule name description ----
> > ---------------------- ------------------------------------------- -2.3
> > RCVD_IN_DNSWL_MED RBL: Sender listed at https://www.dnswl.org/,
> > medium trust
> > [2001:648:2ffc:deb:216:61ff:fe9d:958d listed
> > in] [list.dnswl.org] -0.0 SPF_PASS
> > SPF: sender matches SPF record -0.0 SPF_HELO_PASS
> > SPF: HELO matches SPF record -1.9 BAYES_00 BODY:
> > Bayes spam probability is 0 to 1% [score:
> > 0.0000] 0.2 HEADER_FROM_DIFFERENT_DOMAINS From and EnvelopeFrom 2nd
level
> > mail domains are different -0.5
> > MAILING_LIST_MULTI Multiple indicators imply a widely-seen list
> > manager
> >
> >Hi Alban,
> >
> >thanks for giving this helpful information. I won't have time to look
> >into this until somewhen next week though. Do you have a workaround in
> >place that still allows you to work or do you need something quicker?
> >
> >Greetings
> >Marc
> >
> >On Sat, Aug 15, 2026 at 12:10:20PM +0200, Alban Browaeys wrote:
> >>From: Alban Browaeys <[email protected]>
> >>Subject: Re: Bug#1144431: ferm: seems ferm early prevents ferm from
starting
> >>To: Marc Haber <[email protected]>, Alban Browaeys
> >><[email protected]>, [email protected]
> >>Date: Sat, 15 Aug 2026 12:10:20 +0200
> >>User-Agent: Mozilla Thunderbird
> >>X-Spam-Score: (--) -2.1
> >>X-Spam-Report: torres.zugschlus.de Content analysis details: (-2.1
> >>points, 5.0 required) pts rule name description ----
> >>---------------------- ------------------------------------------- 0.0