I seem to have a clue at what's wrong with AI help.

I use Debops which preserves a set of previous RULES (for one FORWARD rules) but this preserves the jump to FORWARD-early even though FORWARD-early itself is not defined in my ferm rules set.

This preserves is mainly there to keep docker rules on restart and such.

Debian default /etc/ferm/ferm.conf is not affected because it empties the FORWARD rule. But thus it purges docker rules on restart I believe.


I managed to workaround this with

"

cat /etc/ferm/rules.d/000_rule_reset_ferm_early.conf
domain (ip ip6) {
    table filter {
        chain INPUT-early {}
        chain OUTPUT-early {}
        chain FORWARD-early {}
    }
}

" and "

cat /etc/ferm/rules.d/000_rule_purge_ferm_early_hooks.conf
@hook post "iptables -D INPUT -j INPUT-early 2>/dev/null || true";
@hook post "iptables -D OUPUT -j OUTPUT-early 2>/dev/null || true";
@hook post "iptables -D FORWARD -j FORWARD-early 2>/dev/null || true";
@hook post "iptables -X INPUT-early 2>/dev/null || true";
@hook post "iptables -X OUTPUT-early 2>/dev/null || true";
@hook post "iptables -X FORWARD-early 2>/dev/null || true";

@hook post "ip6tables -D INPUT -j INPUT-early 2>/dev/null || true";
@hook post "ip6tables -D OUPUT -j OUTPUT-early 2>/dev/null || true";
@hook post "ip6tables -D FORWARD -j FORWARD-early 2>/dev/null || true";
@hook post "ip6tables -X INPUT-early 2>/dev/null || true";
@hook post "ip6tables -X OUTPUT-early 2>/dev/null || true";
@hook post "ip6tables -X FORWARD-early 2>/dev/null || true";
"


but this looks like porcelain. Everytime /etc/ferm/ferm-early.conf is modified this will requires changes.

But I cannot flush the FORWARD ruleset either because I cannot expect a predefined set of docker rules to add to it afterwards either (not to account that this script should account for when docker is not use too).


Regards

Alban

"

 sudo /usr/libexec/ferm/ferm-systemd activate
Activating firewall rules: /usr/sbin/ferm  /etc/ferm/ferm.conf
iptables-restore v1.8.13 (legacy): Couldn't load target `FORWARD-early':No such file or directory

Error occurred at line: 38
Try `iptables-restore -h' or 'iptables-restore --help' for more information.
Failed to run /usr/sbin/iptables-restore

Firewall rules rolled back.
"


"

sudo iptables -L -n -v
Chain INPUT (policy DROP 22 packets, 8224 bytes)
 pkts bytes target     prot opt in     out     source  destination
   58 14649 INPUT-early  all  --  *      *       0.0.0.0/0     0.0.0.0/0

Chain FORWARD (policy DROP 0 packets, 0 bytes)
 pkts bytes target     prot opt in     out     source  destination
    0     0 DOCKER-USER  all  --  *      *       0.0.0.0/0     0.0.0.0/0
    0     0 DOCKER-FORWARD  all  --  *      *       0.0.0.0/0       0.0.0.0/0     0     0 FORWARD-early  all  --  *      *       0.0.0.0/0       0.0.0.0/0

Chain OUTPUT (policy ACCEPT 13 packets, 16647 bytes)
 pkts bytes target     prot opt in     out     source  destination
   50 22762 OUTPUT-early  all  --  *      *       0.0.0.0/0     0.0.0.0/0

Chain DOCKER (2 references)
 pkts bytes target     prot opt in     out     source  destination
    0     0 ACCEPT     tcp  --  !br-27afa3a73960 br-27afa3a73960 0.0.0.0/0            172.18.0.2           tcp dpt:9443     0     0 ACCEPT     tcp  --  !br-27afa3a73960 br-27afa3a73960 0.0.0.0/0            172.18.0.2           tcp dpt:9000     0     0 ACCEPT     tcp  --  !br-27afa3a73960 br-27afa3a73960 0.0.0.0/0            172.18.0.2           tcp dpt:8000     0     0 DROP       all  --  !br-27afa3a73960 br-27afa3a73960 0.0.0.0/0            0.0.0.0/0
    0     0 DROP       all  --  !docker0 docker0  0.0.0.0/0     0.0.0.0/0

Chain DOCKER-BRIDGE (1 references)
 pkts bytes target     prot opt in     out     source  destination
    0     0 DOCKER     all  --  *      br-27afa3a73960  0.0.0.0/0           0.0.0.0/0
    0     0 DOCKER     all  --  *      docker0  0.0.0.0/0   0.0.0.0/0

Chain DOCKER-CT (1 references)
 pkts bytes target     prot opt in     out     source  destination
    0     0 ACCEPT     all  --  *      br-27afa3a73960  0.0.0.0/0           0.0.0.0/0            ctstate RELATED,ESTABLISHED     0     0 ACCEPT     all  --  *      docker0  0.0.0.0/0   0.0.0.0/0            ctstate RELATED,ESTABLISHED

Chain DOCKER-FORWARD (1 references)
 pkts bytes target     prot opt in     out     source  destination
    0     0 DOCKER-CT  all  --  *      *       0.0.0.0/0   0.0.0.0/0
    0     0 DOCKER-ISOLATION-STAGE-1  all  --  *      *  0.0.0.0/0            0.0.0.0/0     0     0 DOCKER-BRIDGE  all  --  *      *       0.0.0.0/0       0.0.0.0/0     0     0 ACCEPT     all  --  br-27afa3a73960 *       0.0.0.0/0           0.0.0.0/0
    0     0 ACCEPT     all  --  docker0 *       0.0.0.0/0   0.0.0.0/0

Chain DOCKER-ISOLATION-STAGE-1 (1 references)
 pkts bytes target     prot opt in     out     source  destination
    0     0 DOCKER-ISOLATION-STAGE-2  all  --  br-27afa3a73960 !br-27afa3a73960  0.0.0.0/0            0.0.0.0/0     0     0 DOCKER-ISOLATION-STAGE-2  all  --  docker0 !docker0 0.0.0.0/0            0.0.0.0/0

Chain DOCKER-ISOLATION-STAGE-2 (2 references)
 pkts bytes target     prot opt in     out     source  destination
    0     0 DROP       all  --  *      docker0  0.0.0.0/0   0.0.0.0/0
    0     0 DROP       all  --  *      br-27afa3a73960  0.0.0.0/0           0.0.0.0/0

Chain DOCKER-USER (1 references)
 pkts bytes target     prot opt in     out     source  destination

Chain FORWARD-early (1 references)
 pkts bytes target     prot opt in     out     source  destination
    0     0 DROP       all  --  *      *       0.0.0.0/0   0.0.0.0/0            state INVALID     0     0 ACCEPT     all  --  *      *       0.0.0.0/0   0.0.0.0/0            state RELATED,ESTABLISHED

Chain INPUT-early (1 references)
 pkts bytes target     prot opt in     out     source  destination
    0     0 ACCEPT     udp  --  lo     *       0.0.0.0/0   0.0.0.0/0            udp spt:54321     0     0 DROP       all  --  *      *       0.0.0.0/0   0.0.0.0/0            state INVALID    36  6425 ACCEPT     all  --  *      *       0.0.0.0/0   0.0.0.0/0            state RELATED,ESTABLISHED
    0     0 ACCEPT     all  --  lo     *       0.0.0.0/0   0.0.0.0/0
    0     0 ACCEPT     icmp --  *      *       0.0.0.0/0   0.0.0.0/0
    0     0 ACCEPT     udp  --  *      *       0.0.0.0/0   0.0.0.0/0            udp dpt:500
    0     0 ACCEPT     esp  --  *      *       0.0.0.0/0   0.0.0.0/0
    0     0 ACCEPT     ah   --  *      *       0.0.0.0/0   0.0.0.0/0
    0     0 ACCEPT     tcp  --  *      *       0.0.0.0/0   0.0.0.0/0            tcp dpt:22

Chain OUTPUT-early (1 references)
 pkts bytes target     prot opt in     out     source  destination
   37  6115 ACCEPT     all  --  *      *       0.0.0.0/0   0.0.0.0/0            state RELATED,ESTABLISHED

"


"

cat /etc/ferm/ferm.conf
# Ansible managed

# Load configuration from parts
@include 'rules.d/';
"


"

for i in  /etc/ferm/rules.d/* ; do echo $i; cat $i; echo "";done
/etc/ferm/rules.d/000_rule_docker_preserve.conf
# Ansible managed

# # Docker support.
# # cf https://github.com/MaxKellermann/ferm/issues/58#issuecomment-588600252
table nat chain (PREROUTING OUTPUT POSTROUTING DOCKER) @preserve;
table filter chain (FORWARD DOCKER DOCKER-ISOLATION-STAGE-1 DOCKER-ISOLATION-STAGE-2 DOCKER-FORWARD DOCKER-CT DOCKER-BRIDGE) @preserve;
table filter chain (DOCKER-USER) { RETURN; }

/etc/ferm/rules.d/000_rule_firewall_hooks.conf
# Ansible managed

# Run custom hooks at various firewall stages
@hook pre   "run-parts /etc/ferm/hooks/pre.d";
@hook post  "run-parts /etc/ferm/hooks/post.d";
@hook flush "run-parts /etc/ferm/hooks/flush.d";

/etc/ferm/rules.d/000_rule_firewall_log.conf
# Ansible managed

# Custom log function used by other rules
@def &log($msg) = {
    mod limit limit 2/min
              limit-burst 5
        LOG log-ip-options log-prefix "$msg";
}

/etc/ferm/rules.d/000_rule_firewall_variables.conf
# Ansible managed

# Define custom variables available in the firewall
@def $domains      = (ip ip6);
@def $ipv4_enabled = 1;
@def $ipv6_enabled = 1;

/etc/ferm/rules.d/001_rule_accept_loopback.conf
# Ansible managed

domain (ip ip6) table filter chain INPUT {
    interface lo {
        ACCEPT;
    }
}

/etc/ferm/rules.d/005_rule_accept_ansible_controller.conf
# Ansible managed

# Accept SSH connections from Ansible Controllers
domain (ip ip6) table filter chain INPUT {
    protocol tcp dport ssh {
        # Connections from any IP address not allowed
    }
}

/etc/ferm/rules.d/005_rule_policy_filter_forward.conf
# Ansible managed

domain (ip ip6) table filter chain FORWARD {
    policy DROP;
}

/etc/ferm/rules.d/005_rule_policy_filter_input.conf
# Ansible managed

domain (ip ip6) table filter chain INPUT {
    policy DROP;
}

/etc/ferm/rules.d/005_rule_policy_filter_output.conf
# Ansible managed

domain (ip ip6) table filter chain OUTPUT {
    policy ACCEPT;
}

(...)

"






On Sat, 29 Aug 2026 15:29:23 +0200 Marc Haber <[email protected]> wrote:

> Hi Alban,
>
> I have uploaded a new version of ferm to unstable that allows the
> ferm-systemd script to save more debug information. Can you try this
> please, and if it still fails (which is likely), set DEBUGLOG_DIR to a
> directory that is read-write available early and survives the system
> startup (like /var/cache/ferm, for example). Then feel free to send me a
> tarball.
>
> Greetings
> Marc
>
> On Sat, Aug 15, 2026 at 01:45:52PM +0200, Marc Haber wrote:
> >From: Marc Haber <[email protected]>
> >Subject: Bug#1144431: ferm: seems ferm early prevents ferm from starting
> >To: Alban Browaeys <[email protected]>
> >Cc: Alban Browaeys <[email protected]>, [email protected]
> >Reply-To: Marc Haber <[email protected]>,
> > [email protected]
> >Date: Sat, 15 Aug 2026 13:45:52 +0200
> >X-Debian-PR-Package: ferm
> >User-Agent: Mutt/2.2.13 (2024-03-09)
> >List-Id: <ferm.tracker.debian.org>
> >X-PTS-Package: ferm
> >X-Spam-Score: (----) -4.5
> >X-Spam-Report: torres.zugschlus.de Content analysis details: (-4.5
> > points, 5.0 required) pts rule name description ----
> > ---------------------- ------------------------------------------- -2.3
> > RCVD_IN_DNSWL_MED RBL: Sender listed at https://www.dnswl.org/,
> > medium trust
> > [2001:648:2ffc:deb:216:61ff:fe9d:958d listed
> > in] [list.dnswl.org] -0.0 SPF_PASS
> > SPF: sender matches SPF record -0.0 SPF_HELO_PASS
> > SPF: HELO matches SPF record -1.9 BAYES_00 BODY:
> > Bayes spam probability is 0 to 1% [score:
> > 0.0000] 0.2 HEADER_FROM_DIFFERENT_DOMAINS From and EnvelopeFrom 2nd level
> > mail domains are different -0.5
> > MAILING_LIST_MULTI Multiple indicators imply a widely-seen list
> > manager
> >
> >Hi Alban,
> >
> >thanks for giving this helpful information. I won't have time to look
> >into this until somewhen next week though. Do you have a workaround in
> >place that still allows you to work or do you need something quicker?
> >
> >Greetings
> >Marc
> >
> >On Sat, Aug 15, 2026 at 12:10:20PM +0200, Alban Browaeys wrote:
> >>From: Alban Browaeys <[email protected]>
> >>Subject: Re: Bug#1144431: ferm: seems ferm early prevents ferm from starting
> >>To: Marc Haber <[email protected]>, Alban Browaeys
> >><[email protected]>, [email protected]
> >>Date: Sat, 15 Aug 2026 12:10:20 +0200
> >>User-Agent: Mozilla Thunderbird
> >>X-Spam-Score: (--) -2.1
> >>X-Spam-Report: torres.zugschlus.de Content analysis details: (-2.1
> >>points, 5.0 required) pts rule name description ----
> >>---------------------- ------------------------------------------- 0.0

Reply via email to