Bug#1051592: Regression: Commit "netfilter: nf_tables: disallow rule addition to bound chain via NFTA_RULE_CHAIN_ID" breaks ruleset loading in linux-stable

2023-09-15 Thread Timo Sigurdsson
Hi, Salvatore Bonaccorso schrieb am 12.09.2023 21:13 (GMT +02:00): > Hi Timo, > > On Tue, Sep 12, 2023 at 01:39:59PM +0200, Timo Sigurdsson wrote: >> Hi Pablo, >> >> Pablo Neira Ayuso schrieb am 12.09.2023 00:57 (GMT +02:00): >> >> > Hi Timo, >

Bug#1051592: Regression: Commit "netfilter: nf_tables: disallow rule addition to bound chain via NFTA_RULE_CHAIN_ID" breaks ruleset loading in linux-stable

2023-09-12 Thread Timo Sigurdsson
Hi, Florian Westphal schrieb am 12.09.2023 12:27 (GMT +02:00): > Linux regression tracking (Thorsten Leemhuis) > wrote: >> On 12.09.23 00:57, Pablo Neira Ayuso wrote: >> > Userspace nftables v1.0.6 generates incorrect bytecode that hits a new >> > kernel check that rejects adding rules to bound

Bug#1051592: Regression: Commit "netfilter: nf_tables: disallow rule addition to bound chain via NFTA_RULE_CHAIN_ID" breaks ruleset loading in linux-stable

2023-09-12 Thread Timo Sigurdsson
Hi Pablo, Pablo Neira Ayuso schrieb am 12.09.2023 00:57 (GMT +02:00): > Hi Timo, > > On Mon, Sep 11, 2023 at 11:37:50PM +0200, Timo Sigurdsson wrote: >> Hi, >> >> recently, Debian updated their stable kernel from 6.1.38 to 6.1.52 >> which broke nftables rule

Bug#1051592: Regression: Commit "netfilter: nf_tables: disallow rule addition to bound chain via NFTA_RULE_CHAIN_ID" breaks ruleset loading in linux-stable

2023-09-11 Thread Timo Sigurdsson
Hi, recently, Debian updated their stable kernel from 6.1.38 to 6.1.52 which broke nftables ruleset loading on one of my machines with lots of "Operation not supported" errors. I've reported this to the Debian project (see link below) and Salvatore Bonaccorso and I identified "netfilter: nf_tab

Bug#1051592: linux: Regression - upgrade to 6.1.52-1 breaks nftables

2023-09-11 Thread Timo Sigurdsson
Hi Salvatore, Salvatore Bonaccorso schrieb am 11.09.2023 22:20 (GMT +02:00): > Bisected the issue: > > $ git bisect log > git bisect start > # status: waiting for both good and bad commits > # good: [61fd484b2cf6bc8022e8e5ea6f693a9991740ac2] Linux 6.1.38 > git bisect good 61fd484b2cf6bc8022e8e5e

Bug#1051592: linux: Regression - upgrade to 6.1.52-1 breaks nftables

2023-09-10 Thread Timo Sigurdsson
Hi, Salvatore Bonaccorso schrieb am 10.09.2023 12:21 (GMT +02:00): > Would it be possible to provide a minimal set of rules triggering the > issue? Can you reproduce the issue with the official build? So, I did some more testing on a different machine running the official build. My findings so

Bug#1051592: linux: Regression - upgrade to 6.1.52-1 breaks nftables

2023-09-10 Thread Timo Sigurdsson
Package: linux Version: 6.1.52-1 Severity: grave Dear Maintainers, linux-image-6.1.0-12-amd64 causes a serious regression in nftables. After upgrading one of my machines, nftables fails to start - leaving the system without an active firewall. Doing `nft -cf /etc/nftables.conf' throws many "Op

Bug#986709: rsnapshot: not suitable for stable release

2021-08-26 Thread Timo Sigurdsson
Hi, I was also unpleasently surprised that rsnapshot is not in Bullseye and there's no mention of it in the release notes either. I don't how the process or rules in Debian are for such a case, but please find a way to either reintroduce rsnapshot into the stable distribution or at least provid

Bug#928440: dhcpcd5: DHCPv6: Potential read overflow with D6_OPTION_PD_EXCLUDE

2019-05-04 Thread Timo Sigurdsson
Package: dhcpcd5 Version: 7.1.0-1 Severity: serious Tags: security upstream fixed-upstream Dear Maintainer, another week - another bug ;) Upstream released version 7.2.2 of dhcpcd5 fixing another potential security issue in DHCPv6. All versions currently supported in Debian (jessie, stretch, bu

Bug#928056: dhcpcd5: Open security issues in dhcpcd5 prior to 7.2.1 affecting all versions found in Debian

2019-04-26 Thread Timo Sigurdsson
Package: dhcpcd5 Version: any Severity: serious Dear Maintainer, upstream released a new version of dhcpcd5 fixing three security issues. All versions currently found in Debian (jessie, stretch, buster, sid) are vulnerable to at least two of these issues, according to the announcement on upstr

Bug#922478: have yet to find an armhf board that works with 4.9.144-3

2019-02-18 Thread Timo Sigurdsson
Hi Cyril, Cyril Brulebois schrieb am 18.02.2019 17:09: > Based on this suggestion and Julien's suggested patch on IRC a couple > hours ago, I've tested the attached patch successfully (as in: from a > busy loop in qemu-system-arm to the “expected” kernel panic, as > discussed in another subthread

Bug#922478: upgrade linux-image-4.9.0-8-armmp-lpae:armhf from 4.9.130-2 to 4.9.144-3 renders Bananapi and Lamobo R1 unbootable

2019-02-18 Thread Timo Sigurdsson
Hi, On Mon, 18 Feb 2019 11:28:10 +, Neil Williams wrote: > Is it feasible to have a script in devscripts or similar which maps the > version of the kernel *Candidate* to KernelCI URLs for the same > version? > > Can we correlate Debian kernel versions to something like > https://kernelci.org

Bug#922478: upgrade linux-image-4.9.0-8-armmp-lpae:armhf from 4.9.130-2 to 4.9.144-3 renders Bananapi and Lamobo R1 unbootable

2019-02-17 Thread Timo Sigurdsson
Hi, Cyril Brulebois schrieb am 17.02.2019 19:38: > Hi folks, > > Jürgen Löb (2019-02-16): >> Package: linux-image-4.9.0-8-armmp-lpae >> Version: 4.9.144-3 >> Severity: serious >> >> Updated my Lamobo R1 board with apt update;apt upgrade >> >> After the update uboot is struck at "Starting kern

Bug#922478: upgrade linux-image-4.9.0-8-armmp-lpae:armhf from 4.9.130-2 to 4.9.144-3 renders Bananapi and Lamobo R1 unbootable

2019-02-17 Thread Timo Sigurdsson
Hi, I've also been hit by this bug on two systems (both are Lemaker Bananapi). The first system upgraded the kernel via unattended-upgrades and failed to come up after reboot. I don't have a serial cable, but I did hook up the board to a HDMI display. U-Boot loads the kernel, dtb and initramfs