Bug#1051592: Regression: Commit "netfilter: nf_tables: disallow rule addition to bound chain via NFTA_RULE_CHAIN_ID" breaks ruleset loading in linux-stable

2023-09-29 Thread Linux regression tracking (Thorsten Leemhuis)
On 12.09.23 12:27, Florian Westphal wrote: > Linux regression tracking (Thorsten Leemhuis) > wrote: >> On 12.09.23 00:57, Pablo Neira Ayuso wrote: >>> Userspace nftables v1.0.6 generates incorrect bytecode that hits a new >>> kernel check that rejects adding rules to bound chains. The incorrect

Bug#1051592: Regression: Commit "netfilter: nf_tables: disallow rule addition to bound chain via NFTA_RULE_CHAIN_ID" breaks ruleset loading in linux-stable

2023-09-25 Thread Jeremy Sowden
On 2023-09-25, at 10:31:57 +0200, Arturo Borrero Gonzalez wrote: > On 9/24/23 13:48, Salvatore Bonaccorso wrote: > > The work for bookworm has been done, but for bullseye: would you be > > able to help here and prepare the fixes? Unfortunatlly the fixes will > > not apply cleanly. If we fear to

Bug#1051592: Regression: Commit "netfilter: nf_tables: disallow rule addition to bound chain via NFTA_RULE_CHAIN_ID" breaks ruleset loading in linux-stable

2023-09-25 Thread Arturo Borrero Gonzalez
On 9/24/23 13:48, Salvatore Bonaccorso wrote: The work for bookworm has been done, but for bullseye: would you be able to help here and prepare the fixes? Unfortunatlly the fixes will not apply cleanly. If we fear to much breakage, maybe upstream can be convinced to help? Hi Salvatore, I

Bug#1051592: Regression: Commit "netfilter: nf_tables: disallow rule addition to bound chain via NFTA_RULE_CHAIN_ID" breaks ruleset loading in linux-stable

2023-09-24 Thread Salvatore Bonaccorso
Hi Arturo, On Sat, Sep 16, 2023 at 09:02:34AM +0200, Arturo Borrero Gonzalez wrote: > On Sat, Sep 16, 2023, 08:37 Salvatore Bonaccorso wrote: > > > Hi > > > > Dropping some recipients for the Debian specific handling of this > > issue. So AFAIU upstream will not consider this on src:linux side

Bug#1051592: Regression: Commit "netfilter: nf_tables: disallow rule addition to bound chain via NFTA_RULE_CHAIN_ID" breaks ruleset loading in linux-stable

2023-09-16 Thread Salvatore Bonaccorso
Hi ARturo, On Sat, Sep 16, 2023 at 09:02:34AM +0200, Arturo Borrero Gonzalez wrote: > On Sat, Sep 16, 2023, 08:37 Salvatore Bonaccorso wrote: > > > Hi > > > > Dropping some recipients for the Debian specific handling of this > > issue. So AFAIU upstream will not consider this on src:linux side

Bug#1051592: Regression: Commit "netfilter: nf_tables: disallow rule addition to bound chain via NFTA_RULE_CHAIN_ID" breaks ruleset loading in linux-stable

2023-09-16 Thread Arturo Borrero Gonzalez
On Sat, Sep 16, 2023, 08:37 Salvatore Bonaccorso wrote: > Hi > > Dropping some recipients for the Debian specific handling of this > issue. So AFAIU upstream will not consider this on src:linux side to > be further handled and needs to be addressed in nftables. > > Arturo: With the patches

Bug#1051592: Regression: Commit "netfilter: nf_tables: disallow rule addition to bound chain via NFTA_RULE_CHAIN_ID" breaks ruleset loading in linux-stable

2023-09-16 Thread Salvatore Bonaccorso
Hi Dropping some recipients for the Debian specific handling of this issue. So AFAIU upstream will not consider this on src:linux side to be further handled and needs to be addressed in nftables. Arturo: With the patches provided I prepared (as Timo) an update targetting bookworm for the next

Bug#1051592: Regression: Commit "netfilter: nf_tables: disallow rule addition to bound chain via NFTA_RULE_CHAIN_ID" breaks ruleset loading in linux-stable

2023-09-15 Thread Timo Sigurdsson
Hi, Salvatore Bonaccorso schrieb am 12.09.2023 21:13 (GMT +02:00): > Hi Timo, > > On Tue, Sep 12, 2023 at 01:39:59PM +0200, Timo Sigurdsson wrote: >> Hi Pablo, >> >> Pablo Neira Ayuso schrieb am 12.09.2023 00:57 (GMT +02:00): >> >> > Hi Timo, >> > >> > On Mon, Sep 11, 2023 at 11:37:50PM

Bug#1051592: Regression: Commit "netfilter: nf_tables: disallow rule addition to bound chain via NFTA_RULE_CHAIN_ID" breaks ruleset loading in linux-stable

2023-09-12 Thread Salvatore Bonaccorso
Hi Timo, On Tue, Sep 12, 2023 at 01:39:59PM +0200, Timo Sigurdsson wrote: > Hi Pablo, > > Pablo Neira Ayuso schrieb am 12.09.2023 00:57 (GMT +02:00): > > > Hi Timo, > > > > On Mon, Sep 11, 2023 at 11:37:50PM +0200, Timo Sigurdsson wrote: > >> Hi, > >> > >> recently, Debian updated their

Bug#1051592: Regression: Commit "netfilter: nf_tables: disallow rule addition to bound chain via NFTA_RULE_CHAIN_ID" breaks ruleset loading in linux-stable

2023-09-12 Thread Pablo Neira Ayuso
On Tue, Sep 12, 2023 at 01:39:59PM +0200, Timo Sigurdsson wrote: > Hi Pablo, > > Pablo Neira Ayuso schrieb am 12.09.2023 00:57 (GMT +02:00): > > > Hi Timo, > > > > On Mon, Sep 11, 2023 at 11:37:50PM +0200, Timo Sigurdsson wrote: > >> Hi, > >> > >> recently, Debian updated their stable kernel

Bug#1051592: Regression: Commit "netfilter: nf_tables: disallow rule addition to bound chain via NFTA_RULE_CHAIN_ID" breaks ruleset loading in linux-stable

2023-09-12 Thread Florian Westphal
Timo Sigurdsson wrote: > > Linux regression tracking (Thorsten Leemhuis) > > wrote: > >> On 12.09.23 00:57, Pablo Neira Ayuso wrote: > >> > Userspace nftables v1.0.6 generates incorrect bytecode that hits a new > >> > kernel check that rejects adding rules to bound chains. The incorrect > >> >

Bug#1051592: Regression: Commit "netfilter: nf_tables: disallow rule addition to bound chain via NFTA_RULE_CHAIN_ID" breaks ruleset loading in linux-stable

2023-09-12 Thread Timo Sigurdsson
Hi, Florian Westphal schrieb am 12.09.2023 12:27 (GMT +02:00): > Linux regression tracking (Thorsten Leemhuis) > wrote: >> On 12.09.23 00:57, Pablo Neira Ayuso wrote: >> > Userspace nftables v1.0.6 generates incorrect bytecode that hits a new >> > kernel check that rejects adding rules to bound

Bug#1051592: Regression: Commit "netfilter: nf_tables: disallow rule addition to bound chain via NFTA_RULE_CHAIN_ID" breaks ruleset loading in linux-stable

2023-09-12 Thread Timo Sigurdsson
Hi Pablo, Pablo Neira Ayuso schrieb am 12.09.2023 00:57 (GMT +02:00): > Hi Timo, > > On Mon, Sep 11, 2023 at 11:37:50PM +0200, Timo Sigurdsson wrote: >> Hi, >> >> recently, Debian updated their stable kernel from 6.1.38 to 6.1.52 >> which broke nftables ruleset loading on one of my machines

Bug#1051592: Regression: Commit "netfilter: nf_tables: disallow rule addition to bound chain via NFTA_RULE_CHAIN_ID" breaks ruleset loading in linux-stable

2023-09-12 Thread Florian Westphal
Linux regression tracking (Thorsten Leemhuis) wrote: > On 12.09.23 00:57, Pablo Neira Ayuso wrote: > > Userspace nftables v1.0.6 generates incorrect bytecode that hits a new > > kernel check that rejects adding rules to bound chains. The incorrect > > bytecode adds the chain binding, attach it to

Bug#1051592: Regression: Commit "netfilter: nf_tables: disallow rule addition to bound chain via NFTA_RULE_CHAIN_ID" breaks ruleset loading in linux-stable

2023-09-12 Thread Linux regression tracking (Thorsten Leemhuis)
On 12.09.23 00:57, Pablo Neira Ayuso wrote: > On Mon, Sep 11, 2023 at 11:37:50PM +0200, Timo Sigurdsson wrote: >> >> recently, Debian updated their stable kernel from 6.1.38 to 6.1.52 >> which broke nftables ruleset loading on one of my machines with lots >> of "Operation not supported" errors.

Bug#1051592: Regression: Commit "netfilter: nf_tables: disallow rule addition to bound chain via NFTA_RULE_CHAIN_ID" breaks ruleset loading in linux-stable

2023-09-11 Thread Pablo Neira Ayuso
Hi Timo, On Mon, Sep 11, 2023 at 11:37:50PM +0200, Timo Sigurdsson wrote: > Hi, > > recently, Debian updated their stable kernel from 6.1.38 to 6.1.52 > which broke nftables ruleset loading on one of my machines with lots > of "Operation not supported" errors. I've reported this to the > Debian

Bug#1051592: Regression: Commit "netfilter: nf_tables: disallow rule addition to bound chain via NFTA_RULE_CHAIN_ID" breaks ruleset loading in linux-stable

2023-09-11 Thread Timo Sigurdsson
Hi, recently, Debian updated their stable kernel from 6.1.38 to 6.1.52 which broke nftables ruleset loading on one of my machines with lots of "Operation not supported" errors. I've reported this to the Debian project (see link below) and Salvatore Bonaccorso and I identified "netfilter: