[Bug 690922] New: ipset error Cannot open session to kernel
https://bugzilla.novell.com/show_bug.cgi?id=690922 https://bugzilla.novell.com/show_bug.cgi?id=690922#c0 Summary: ipset error Cannot open session to kernel Classification: openSUSE Product: openSUSE 11.2 Version: Final Platform: x86-64 OS/Version: openSUSE 11.4 Status: NEW Severity: Major Priority: P5 - None Component: Other AssignedTo: bnc-team-screening@forge.provo.novell.com ReportedBy: support@microtechniques.com QAContact: qa@suse.de Found By: --- Blocker: --- User-Agent: Mozilla/5.0 (Windows NT 5.1; rv:2.0) Gecko/20100101 Firefox/4.0 After upgrading to Xtables-addons I get the following message whenever I call ipset: Xtables-addons v1.35: Cannot open session to kernel. Was working at version 1.30 with kernel 2.6.37.6-19 Reproducible: Always Steps to Reproduce: 1.ipset -N okfile iptreemap 2.ipset -A okfile <someaddress> 3. Actual Results: Cannot open session to kernel Expected Results: add address to table -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
https://bugzilla.novell.com/show_bug.cgi?id=690922 https://bugzilla.novell.com/show_bug.cgi?id=690922#c zj jia <zjjia@novell.com> changed: What |Removed |Added ---------------------------------------------------------------------------- CC| |zjjia@novell.com AssignedTo|bnc-team-screening@forge.pr |jengelh@medozas.de |ovo.novell.com | -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
https://bugzilla.novell.com/show_bug.cgi?id=690922 https://bugzilla.novell.com/show_bug.cgi?id=690922#c Jan Engelhardt <jengelh@medozas.de> changed: What |Removed |Added ---------------------------------------------------------------------------- Status|NEW |ASSIGNED Component|Other |Network Product|openSUSE 11.2 |openSUSE 11.4 OS/Version|openSUSE 11.4 |Linux -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
https://bugzilla.novell.com/show_bug.cgi?id=690922 https://bugzilla.novell.com/show_bug.cgi?id=690922#c1 Jan Engelhardt <jengelh@medozas.de> changed: What |Removed |Added ---------------------------------------------------------------------------- Status|ASSIGNED |NEEDINFO InfoProvider| |support@microtechniques.com --- Comment #1 from Jan Engelhardt <jengelh@medozas.de> 2011-06-24 17:37:35 UTC --- What does `ipset --version` say? -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
https://bugzilla.novell.com/show_bug.cgi?id=690922 https://bugzilla.novell.com/show_bug.cgi?id=690922#c2 Jan Engelhardt <jengelh@medozas.de> changed: What |Removed |Added ---------------------------------------------------------------------------- Status|NEEDINFO |RESOLVED InfoProvider|support@microtechniques.com | Resolution| |WORKSFORME --- Comment #2 from Jan Engelhardt <jengelh@medozas.de> 2011-06-24 17:40:14 UTC --- I cannot reproduce with xtables-addons 1.36. Also note ipset's README: - The iptree, iptreemap types are not implemented in ipset 6.x. The types are automatically substituted with the hash:ip type. (Except that they are not automatically substituted.) -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
https://bugzilla.novell.com/show_bug.cgi?id=690922 https://bugzilla.novell.com/show_bug.cgi?id=690922#c3 --- Comment #3 from Don Hughes <support@microtechniques.com> 2011-06-24 21:07:38 UTC --- I was also able to resolve the issue by moving to 1.36. I would suggest that the update and tumbleweed repositories be updated to this version. I also had a number of scripts fail because of the dropping of the iptree type, and had to scramble to repair them in order to get the machines back online. You might forward to the xtables group the comment that this type of behavior that might be OK in a hobbyist environment, but not in a business environment. -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
You might forward to the xtables group the comment that this type of behavior
https://bugzilla.novell.com/show_bug.cgi?id=690922 https://bugzilla.novell.com/show_bug.cgi?id=690922#c4 --- Comment #4 from Jan Engelhardt <jengelh@medozas.de> 2011-06-24 21:31:53 UTC --- that might be OK in a hobbyist environment, but not in a business environment. If you would like a support contract, feel free to contact me. :) (I am the xtables-addons developer, just FTR.) -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
https://bugzilla.novell.com/show_bug.cgi?id=690922 https://bugzilla.novell.com/show_bug.cgi?id=690922#c5 Jan Engelhardt <jengelh@medozas.de> changed: What |Removed |Added ---------------------------------------------------------------------------- Status|RESOLVED |REOPENED Resolution|WORKSFORME | --- Comment #5 from Jan Engelhardt <jengelh@medozas.de> 2011-06-24 21:32:27 UTC --- Desiring update. -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
https://bugzilla.novell.com/show_bug.cgi?id=690922 https://bugzilla.novell.com/show_bug.cgi?id=690922#c6 Jan Engelhardt <jengelh@medozas.de> changed: What |Removed |Added ---------------------------------------------------------------------------- Status|REOPENED |NEEDINFO InfoProvider| |maintenance@opensuse.org --- Comment #6 from Jan Engelhardt <jengelh@medozas.de> 2011-06-24 21:37:02 UTC --- Maintenance team, I would like to have 11.4's xtables-addons-1.33 updated due to nonfunctionality of the ipset program (known protocol mismatch between kernel and userland subparts). Could you please do the SWAMP favors. -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
https://bugzilla.novell.com/show_bug.cgi?id=690922 https://bugzilla.novell.com/show_bug.cgi?id=690922#c7 --- Comment #7 from Don Hughes <support@microtechniques.com> 2011-06-24 23:58:31 UTC --- Let me expand on the previous. I use iptables and a number of the addons to build internet facing firewalls for a number of my systems. I find that the volume and sophistication of the attacks directed at my networks just continues to increase, and, for this reason, I am aggressive in applying patches to these systems. However, the interaction between the kernel, iproute, iptables, and the addons seems to be fairly fragile. Whereas security updates to my other servers seldom causes any breakage (the VMware server being a glaring exception), updates to my firewalls almost always breaks something to the point where I tend to delay applying patches until I can set aside 1/2 a day for debugging. Thus, the server that I would like to update the most is actually the one that is updated the least. When something like the HISTORYTIMEFORMAT breaks, it is annoying, but I can delay debugging it until I have the time. When the iptables scripts stop working they have to be debugged and fixed on the spot. I would like to suggest that perhaps the provides/requires in the RPMS could be expanded/tuned so I do not end up with protocol mismatch surprises. Also changes to these applications should be approached very conservatively - something like removing a feature like iptreemap needs more than a comment in a readme - perhaps warning messages in the logs that the feature will be removed in a future release like is done with a number of other packages. Let me say that I do appreciate having the addons bundled together as this is much less time consuming than patch-o-matic and separate compiles, but because of the importance of the packages, any hiccups are attention grabbing. -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
https://bugzilla.novell.com/show_bug.cgi?id=690922 https://bugzilla.novell.com/show_bug.cgi?id=690922#c8 Marcus Meissner <meissner@novell.com> changed: What |Removed |Added ---------------------------------------------------------------------------- CC| |meissner@novell.com --- Comment #8 from Marcus Meissner <meissner@novell.com> 2011-06-25 08:44:37 UTC --- lets do it +1 -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
https://bugzilla.novell.com/show_bug.cgi?id=690922 https://bugzilla.novell.com/show_bug.cgi?id=690922#c9 Swamp Workflow Management <swamp@suse.com> changed: What |Removed |Added ---------------------------------------------------------------------------- Status Whiteboard| |maint:running:41831:low --- Comment #9 from Swamp Workflow Management <swamp@suse.com> 2011-06-25 10:07:36 UTC --- The SWAMPID for this issue is 41831. This issue was rated as low. Please submit fixed packages until 2011-07-25. Also create a patchinfo file using this link: https://swamp.suse.de/webswamp/wf/41831 -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
https://bugzilla.novell.com/show_bug.cgi?id=690922 https://bugzilla.novell.com/show_bug.cgi?id=690922#c Dirk Mueller <dmueller@novell.com> changed: What |Removed |Added ---------------------------------------------------------------------------- Status|NEEDINFO |REOPENED InfoProvider|maintenance@opensuse.org | -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
https://bugzilla.novell.com/show_bug.cgi?id=690922 https://bugzilla.novell.com/show_bug.cgi?id=690922#c10 --- Comment #10 from Jan Engelhardt <jengelh@medozas.de> 2011-06-25 16:53:04 UTC --- sr 74506 -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
https://bugzilla.novell.com/show_bug.cgi?id=690922 https://bugzilla.novell.com/show_bug.cgi?id=690922#c11 Christian Dengler <cdengler@novell.com> changed: What |Removed |Added ---------------------------------------------------------------------------- Status|REOPENED |CLOSED CC| |cdengler@novell.com Resolution| |FIXED --- Comment #11 from Christian Dengler <cdengler@novell.com> 2011-07-04 11:34:57 UTC --- update released. -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
https://bugzilla.novell.com/show_bug.cgi?id=690922 https://bugzilla.novell.com/show_bug.cgi?id=690922#c12 Swamp Workflow Management <swamp@suse.de> changed: What |Removed |Added ---------------------------------------------------------------------------- Status Whiteboard|maint:running:41831:low |maint:running:41831:low | |maint:released:11.4:41832 --- Comment #12 from Swamp Workflow Management <swamp@suse.de> 2011-07-04 11:35:41 UTC --- Update released for: xtables-addons, xtables-addons-debuginfo, xtables-addons-debugsource, xtables-addons-kmp-default, xtables-addons-kmp-default-debuginfo, xtables-addons-kmp-desktop, xtables-addons-kmp-desktop-debuginfo, xtables-addons-kmp-pae, xtables-addons-kmp-pae-debuginfo, xtables-addons-kmp-xen, xtables-addons-kmp-xen-debuginfo Products: openSUSE 11.4 (debug, i586, x86_64) -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
https://bugzilla.novell.com/show_bug.cgi?id=690922 https://bugzilla.novell.com/show_bug.cgi?id=690922#c Swamp Workflow Management <swamp@suse.de> changed: What |Removed |Added ---------------------------------------------------------------------------- Status Whiteboard|maint:running:41831:low |maint:released:11.4:41832 |maint:released:11.4:41832 | -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
participants (1)
-
bugzilla_noreply@novell.com