I couldn't get iptables-apply to fail with unresolvable DNS while using multiple tables. I had to insert DNS names manually because iptables resovles domain names at rule insertion and iptables-save doesn't display any DNS names.
I haven't managed to get iptables-apply to fail. I also haven't found any reports of failures. Do you have any more information or an actual test case rules file that will cause a rollback failure? The new lines in the patch you posted are exactly what is already in iptables-apply. -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org