This bug was fixed in the package ufw - 0.36-6
---
ufw (0.36-6) unstable; urgency=medium
* 0009-empty-non-functioning-ipt-modules.patch: empty out IPT_MODULES and
update documentation regarding modern use of connection tracking modules.
ufw historically used IPT_MODULES in
The linux task can be marked as Fix Released since
net/netfilter/nf_conntrack_helper has defaulted to 0 since 4.7.
** Changed in: ufw (Ubuntu)
Status: Triaged => In Progress
** Changed in: linux (Ubuntu)
Status: Confirmed => Fix Released
--
You received this bug notification
Users seeing this issue should modify IPT_MODULES in /etc/defaults/ufw
to be empty. Ubuntu 20.04 will do this be default and future releases of
ufw will introduce rule syntax for working with helper rules.
--
You received this bug notification because you are a member of Ubuntu
Touch seeded
** Changed in: ufw (Ubuntu)
Status: New => Triaged
** Changed in: ufw (Ubuntu)
Importance: Undecided => Medium
** Changed in: ufw (Ubuntu)
Assignee: (unassigned) => Jamie Strandboge (jdstrand)
--
You received this bug notification because you are a member of Ubuntu
Touch seeded
Shows up in dmesg on Ubuntu 18.04 with UFW.
** Also affects: ufw (Ubuntu)
Importance: Undecided
Status: New
--
You received this bug notification because you are a member of Ubuntu
Touch seeded packages, which is subscribed to iptables in Ubuntu.
Hello, I just started seeing this on Ubuntu 17.10.
** Tags added: artful
--
You received this bug notification because you are a member of Ubuntu
Touch seeded packages, which is subscribed to iptables in Ubuntu.
https://bugs.launchpad.net/bugs/1556419
Title:
nf_conntrack: automatic helper
nf_conntrack: default automatic helper assignment has been turned off
for security reasons and CT-based firewall rule not found. Use the
iptables CT target to attach helpers instead.
--
You received this bug notification because you are a member of Ubuntu
Touch seeded packages, which is
Hi. The same problem here. Release 16.04.2 LTS, iptables 1.6.0-2ubuntu3
etc. I noticed this one in dmesg entry:
$ sudo dmesg |grep iptables
[ 1168.282586] nf_conntrack: automatic helper assignment is deprecated and it
will be removed soon. Use the iptables CT target to attach helpers instead.
** Changed in: iptables (Ubuntu)
Importance: Undecided => High
** Changed in: iptables (Ubuntu)
Importance: High => Medium
--
You received this bug notification because you are a member of Ubuntu
Touch seeded packages, which is subscribed to iptables in Ubuntu.
** Tags added: yakkety
--
You received this bug notification because you are a member of Ubuntu
Touch seeded packages, which is subscribed to iptables in Ubuntu.
https://bugs.launchpad.net/bugs/1556419
Title:
nf_conntrack: automatic helper assignment is deprecated
Status in iptables package
Status changed to 'Confirmed' because the bug affects multiple users.
** Changed in: iptables (Ubuntu)
Status: New => Confirmed
--
You received this bug notification because you are a member of Ubuntu
Touch seeded packages, which is subscribed to iptables in Ubuntu.
Feedback:
i've checked the log again with a 4.5 kernel boot, and the error still
exist; so #7 is not fully exact: maybe some race or some other reason.
** Tags removed: kernel-fixed-upstream
--
You received this bug notification because you are a member of Ubuntu
Touch seeded packages, which
Tested the final 4.5 kernel; and the error is not shown:
***
kernel: ip_tables: (C) 2000-2006 Netfilter Core Team
kernel: nf_conntrack version 0.5.0 (16384 buckets, 65536 max)
ureadahead[281]: ureadahead: Error while tracing: No such file or directory
**
(note: the "ureadahead" error
FYI, this is not a new issue.
--
You received this bug notification because you are a member of Ubuntu
Touch seeded packages, which is subscribed to iptables in Ubuntu.
https://bugs.launchpad.net/bugs/1556419
Title:
nf_conntrack: automatic helper assignment is deprecated
Status in iptables
Did this issue start happening after an update/upgrade? Was there a
prior kernel version where you were not having this particular problem?
Would it be possible for you to test the latest upstream kernel? Refer
to https://wiki.ubuntu.com/KernelMainlineBuilds . Please test the latest
v4.5
Kernel build settings & iptables entries:
http://www.odi.ch/weblog/posting.php?posting=663
** Also affects: iptables (Ubuntu)
Importance: Undecided
Status: New
--
You received this bug notification because you are a member of Ubuntu
Touch seeded packages, which is subscribed to
16 matches
Mail list logo