Compare commits

...
Sign in to create a new pull request.

5 commits

Author SHA1 Message Date
Phil Sutter
9b8cd53fba iptables-1.8.13-3
- Fix for missing /var/lock/subsys directory in init scripts

Related: rhbz#2525767
2026-09-02 21:13:18 +02:00
Fedora Release Engineering
268c3873ef Rebuilt for https://fedoraproject.org/wiki/Fedora_45_Mass_Rebuild 2026-07-16 04:00:53 +00:00
Phil Sutter
3cee5b875d iptables-1.8.13-1
- new version

Resolves: rhbz#2444298
2026-03-04 20:03:10 +01:00
Kevin Fenzi
b6a5b8a993 add revert to fix running in docker containers
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-02-26 16:14:48 -08:00
Kevin Fenzi
8fe5342cbe Update to 1.8.12. Fixes rhbz#2440980 2026-02-21 11:38:41 -08:00
8 changed files with 35 additions and 223 deletions

4
.gitignore vendored
View file

@ -17,3 +17,7 @@
/iptables-1.8.10.tar.xz.sig /iptables-1.8.10.tar.xz.sig
/iptables-1.8.11.tar.xz /iptables-1.8.11.tar.xz
/iptables-1.8.11.tar.xz.sig /iptables-1.8.11.tar.xz.sig
/iptables-1.8.12.tar.xz
/iptables-1.8.12.tar.xz.sig
/iptables-1.8.13.tar.xz
/iptables-1.8.13.tar.xz.sig

View file

@ -25,7 +25,7 @@ start() {
/usr/sbin/arptables-restore < $ARPTABLES_CONFIG && \ /usr/sbin/arptables-restore < $ARPTABLES_CONFIG && \
success || \ success || \
failure failure
touch /var/lock/subsys/arptables touch /var/lock/arptables
else else
failure failure
echo "Configuration file /etc/sysconfig/arptables missing" echo "Configuration file /etc/sysconfig/arptables missing"
@ -43,7 +43,7 @@ stop() {
arptables -P OUTPUT ACCEPT && \ arptables -P OUTPUT ACCEPT && \
success || \ success || \
failure failure
rm -f /var/lock/subsys/arptables rm -f /var/lock/arptables
} }
case "$1" in case "$1" in
@ -63,7 +63,7 @@ restart|reload)
;; ;;
condrestart|try-restart|force-reload) condrestart|try-restart|force-reload)
[ -e /var/lock/subsys/arptables ] && start [ -e /var/lock/arptables ] && start
;; ;;
*) *)

View file

@ -16,7 +16,7 @@ failure() {
EBTABLES_CONFIG=/etc/sysconfig/ebtables-config EBTABLES_CONFIG=/etc/sysconfig/ebtables-config
EBTABLES_DATA=/etc/sysconfig/ebtables EBTABLES_DATA=/etc/sysconfig/ebtables
EBTABLES_TABLES="broute filter nat" EBTABLES_TABLES="broute filter nat"
VAR_SUBSYS_EBTABLES=/var/lock/subsys/ebtables VAR_LOCK_EBTABLES=/var/lock/ebtables
# ebtables-config defaults # ebtables-config defaults
EBTABLES_SAVE_ON_STOP="no" EBTABLES_SAVE_ON_STOP="no"
@ -67,7 +67,7 @@ start() {
initialize initialize
fi fi
local ret=$? local ret=$?
touch $VAR_SUBSYS_EBTABLES touch $VAR_LOCK_EBTABLES
return $ret return $ret
} }
@ -79,7 +79,7 @@ save() {
case $1 in case $1 in
start) start)
[ -f "$VAR_SUBSYS_EBTABLES" ] && exit 0 [ -f "$VAR_LOCK_EBTABLES" ] && exit 0
start && success || failure start && success || failure
RETVAL=$? RETVAL=$?
;; ;;
@ -88,7 +88,7 @@ case $1 in
echo -n $"ebtables: stopping firewall: " echo -n $"ebtables: stopping firewall: "
initialize && success || failure initialize && success || failure
RETVAL=$? RETVAL=$?
rm -f $VAR_SUBSYS_EBTABLES rm -f $VAR_LOCK_EBTABLES
;; ;;
save) save)
save save

View file

@ -1,27 +0,0 @@
commit 192c3a6bc18f206895ec5e38812d648ccfe7e281
Author: Phil Sutter <phil@nwl.cc>
Date: Wed Apr 23 12:36:13 2025 +0200
xshared: Accept an option if any given command allows it
Fixed commit made option checking overly strict: Some commands may be
commbined (foremost --list and --zero), reject a given option only if it
is not allowed by any of the given commands.
Reported-by: Adam Nielsen <a.nielsen@shikadi.net>
Fixes: 9c09d28102bb4 ("xshared: Simplify generic_opt_check()")
Signed-off-by: Phil Sutter <phil@nwl.cc>
diff --git a/iptables/xshared.c b/iptables/xshared.c
index cdfd11ab..fc61e0fd 100644
--- a/iptables/xshared.c
+++ b/iptables/xshared.c
@@ -980,7 +980,7 @@ static void generic_opt_check(struct xt_cmd_parse_ops *ops,
*/
for (i = 0, optval = 1; i < NUMBER_OF_OPT; optval = (1 << ++i)) {
if ((options & optval) &&
- (options_v_commands[i] & command) != command)
+ !(options_v_commands[i] & command))
xtables_error(PARAMETER_PROBLEM,
"Illegal option `%s' with this command",
ops->option_name(optval));

View file

@ -1,172 +0,0 @@
From 40406dbfaefbc204134452b2747bae4f6a122848 Mon Sep 17 00:00:00 2001
From: Jeremy Sowden <jeremy@azazel.net>
Date: Mon, 18 Nov 2024 13:56:50 +0000
Subject: nft: fix interface comparisons in `-C` commands
Commit 9ccae6397475 ("nft: Leave interface masks alone when parsing from
kernel") removed code which explicitly set interface masks to all ones. The
result of this is that they are zero. However, they are used to mask interfaces
in `is_same_interfaces`. Consequently, the masked values are alway zero, the
comparisons are always true, and check commands which ought to fail succeed:
# iptables -N test
# iptables -A test -i lo \! -o lo -j REJECT
# iptables -v -L test
Chain test (0 references)
pkts bytes target prot opt in out source destination
0 0 REJECT all -- lo !lo anywhere anywhere reject-with icmp-port-unreachable
# iptables -v -C test -i abcdefgh \! -o abcdefgh -j REJECT
REJECT all opt -- in lo out !lo 0.0.0.0/0 -> 0.0.0.0/0 reject-with icmp-port-unreachable
Remove the mask parameters from `is_same_interfaces`. Add a test-case.
Fixes: 9ccae6397475 ("nft: Leave interface masks alone when parsing from kernel")
Signed-off-by: Jeremy Sowden <jeremy@azazel.net>
Signed-off-by: Phil Sutter <phil@nwl.cc>
---
iptables/nft-arp.c | 10 ++----
iptables/nft-ipv4.c | 4 +--
iptables/nft-ipv6.c | 6 +---
iptables/nft-shared.c | 36 +++++-----------------
iptables/nft-shared.h | 6 +---
.../testcases/nft-only/0020-compare-interfaces_0 | 9 ++++++
6 files changed, 22 insertions(+), 49 deletions(-)
create mode 100755 iptables/tests/shell/testcases/nft-only/0020-compare-interfaces_0
diff --git a/iptables/nft-arp.c b/iptables/nft-arp.c
index 264864c3..c11d64c3 100644
--- a/iptables/nft-arp.c
+++ b/iptables/nft-arp.c
@@ -385,14 +385,8 @@ static bool nft_arp_is_same(const struct iptables_command_state *cs_a,
return false;
}
- return is_same_interfaces(a->arp.iniface,
- a->arp.outiface,
- (unsigned char *)a->arp.iniface_mask,
- (unsigned char *)a->arp.outiface_mask,
- b->arp.iniface,
- b->arp.outiface,
- (unsigned char *)b->arp.iniface_mask,
- (unsigned char *)b->arp.outiface_mask);
+ return is_same_interfaces(a->arp.iniface, a->arp.outiface,
+ b->arp.iniface, b->arp.outiface);
}
static void nft_arp_save_chain(const struct nftnl_chain *c, const char *policy)
diff --git a/iptables/nft-ipv4.c b/iptables/nft-ipv4.c
index 74092875..0c8bd291 100644
--- a/iptables/nft-ipv4.c
+++ b/iptables/nft-ipv4.c
@@ -113,9 +113,7 @@ static bool nft_ipv4_is_same(const struct iptables_command_state *a,
}
return is_same_interfaces(a->fw.ip.iniface, a->fw.ip.outiface,
- a->fw.ip.iniface_mask, a->fw.ip.outiface_mask,
- b->fw.ip.iniface, b->fw.ip.outiface,
- b->fw.ip.iniface_mask, b->fw.ip.outiface_mask);
+ b->fw.ip.iniface, b->fw.ip.outiface);
}
static void nft_ipv4_set_goto_flag(struct iptables_command_state *cs)
diff --git a/iptables/nft-ipv6.c b/iptables/nft-ipv6.c
index b184f8af..4dbb2af2 100644
--- a/iptables/nft-ipv6.c
+++ b/iptables/nft-ipv6.c
@@ -99,11 +99,7 @@ static bool nft_ipv6_is_same(const struct iptables_command_state *a,
}
return is_same_interfaces(a->fw6.ipv6.iniface, a->fw6.ipv6.outiface,
- a->fw6.ipv6.iniface_mask,
- a->fw6.ipv6.outiface_mask,
- b->fw6.ipv6.iniface, b->fw6.ipv6.outiface,
- b->fw6.ipv6.iniface_mask,
- b->fw6.ipv6.outiface_mask);
+ b->fw6.ipv6.iniface, b->fw6.ipv6.outiface);
}
static void nft_ipv6_set_goto_flag(struct iptables_command_state *cs)
diff --git a/iptables/nft-shared.c b/iptables/nft-shared.c
index 6775578b..2c29e68f 100644
--- a/iptables/nft-shared.c
+++ b/iptables/nft-shared.c
@@ -220,36 +220,16 @@ void add_l4proto(struct nft_handle *h, struct nftnl_rule *r,
}
bool is_same_interfaces(const char *a_iniface, const char *a_outiface,
- unsigned const char *a_iniface_mask,
- unsigned const char *a_outiface_mask,
- const char *b_iniface, const char *b_outiface,
- unsigned const char *b_iniface_mask,
- unsigned const char *b_outiface_mask)
+ const char *b_iniface, const char *b_outiface)
{
- int i;
-
- for (i = 0; i < IFNAMSIZ; i++) {
- if (a_iniface_mask[i] != b_iniface_mask[i]) {
- DEBUGP("different iniface mask %x, %x (%d)\n",
- a_iniface_mask[i] & 0xff, b_iniface_mask[i] & 0xff, i);
- return false;
- }
- if ((a_iniface[i] & a_iniface_mask[i])
- != (b_iniface[i] & b_iniface_mask[i])) {
- DEBUGP("different iniface\n");
- return false;
- }
- if (a_outiface_mask[i] != b_outiface_mask[i]) {
- DEBUGP("different outiface mask\n");
- return false;
- }
- if ((a_outiface[i] & a_outiface_mask[i])
- != (b_outiface[i] & b_outiface_mask[i])) {
- DEBUGP("different outiface\n");
- return false;
- }
+ if (strncmp(a_iniface, b_iniface, IFNAMSIZ)) {
+ DEBUGP("different iniface\n");
+ return false;
+ }
+ if (strncmp(a_outiface, b_outiface, IFNAMSIZ)) {
+ DEBUGP("different outiface\n");
+ return false;
}
-
return true;
}
diff --git a/iptables/nft-shared.h b/iptables/nft-shared.h
index 51d1e460..b57aee1f 100644
--- a/iptables/nft-shared.h
+++ b/iptables/nft-shared.h
@@ -105,11 +105,7 @@ void add_l4proto(struct nft_handle *h, struct nftnl_rule *r, uint8_t proto, uint
void add_compat(struct nftnl_rule *r, uint32_t proto, bool inv);
bool is_same_interfaces(const char *a_iniface, const char *a_outiface,
- unsigned const char *a_iniface_mask,
- unsigned const char *a_outiface_mask,
- const char *b_iniface, const char *b_outiface,
- unsigned const char *b_iniface_mask,
- unsigned const char *b_outiface_mask);
+ const char *b_iniface, const char *b_outiface);
void __get_cmp_data(struct nftnl_expr *e, void *data, size_t dlen, uint8_t *op);
void get_cmp_data(struct nftnl_expr *e, void *data, size_t dlen, bool *inv);
diff --git a/iptables/tests/shell/testcases/nft-only/0020-compare-interfaces_0 b/iptables/tests/shell/testcases/nft-only/0020-compare-interfaces_0
new file mode 100755
index 00000000..278cd648
--- /dev/null
+++ b/iptables/tests/shell/testcases/nft-only/0020-compare-interfaces_0
@@ -0,0 +1,9 @@
+#!/bin/bash
+
+[[ $XT_MULTI == *xtables-nft-multi ]] || { echo "skip $XT_MULTI"; exit 0; }
+
+$XT_MULTI iptables -N test
+$XT_MULTI iptables -A test -i lo \! -o lo -j REJECT
+$XT_MULTI iptables -C test -i abcdefgh \! -o abcdefgh -j REJECT 2>/dev/null && exit 1
+
+exit 0
--
cgit v1.2.3

View file

@ -42,7 +42,7 @@ IPTABLES_CONFIG=/etc/sysconfig/${IPTABLES}-config
IPV=${IPTABLES%tables} # ip for ipv4 | ip6 for ipv6 IPV=${IPTABLES%tables} # ip for ipv4 | ip6 for ipv6
[ "$IPV" = "ip" ] && _IPV="ipv4" || _IPV="ipv6" [ "$IPV" = "ip" ] && _IPV="ipv4" || _IPV="ipv6"
PROC_IPTABLES_NAMES=/proc/net/${IPV}_tables_names PROC_IPTABLES_NAMES=/proc/net/${IPV}_tables_names
VAR_SUBSYS_IPTABLES=/var/lock/subsys/$IPTABLES VAR_LOCK_IPTABLES=/var/lock/$IPTABLES
# only usable for root # only usable for root
if [ $EUID != 0 ]; then if [ $EUID != 0 ]; then
@ -249,7 +249,7 @@ start() {
# Load sysctl settings # Load sysctl settings
load_sysctl load_sysctl
touch $VAR_SUBSYS_IPTABLES touch $VAR_LOCK_IPTABLES
return $ret return $ret
} }
@ -264,7 +264,7 @@ stop() {
# And then, flush the rules and delete chains # And then, flush the rules and delete chains
flush_n_delete flush_n_delete
rm -f $VAR_SUBSYS_IPTABLES rm -f $VAR_LOCK_IPTABLES
return $ret return $ret
} }
@ -313,7 +313,7 @@ save() {
} }
status() { status() {
if [ ! -f "$VAR_SUBSYS_IPTABLES" ]; then if [ ! -f "$VAR_LOCK_IPTABLES" ]; then
echo $"${IPTABLES}: Firewall is not running." echo $"${IPTABLES}: Firewall is not running."
return 3 return 3
fi fi
@ -407,7 +407,7 @@ restart() {
case "$1" in case "$1" in
start) start)
[ -f "$VAR_SUBSYS_IPTABLES" ] && exit 0 [ -f "$VAR_LOCK_IPTABLES" ] && exit 0
start start
RETVAL=$? RETVAL=$?
;; ;;
@ -421,11 +421,11 @@ case "$1" in
RETVAL=$? RETVAL=$?
;; ;;
reload) reload)
[ -e "$VAR_SUBSYS_IPTABLES" ] && reload [ -e "$VAR_LOCK_IPTABLES" ] && reload
RETVAL=$? RETVAL=$?
;; ;;
condrestart|try-restart) condrestart|try-restart)
[ ! -e "$VAR_SUBSYS_IPTABLES" ] && exit 0 [ ! -e "$VAR_LOCK_IPTABLES" ] && exit 0
restart restart
RETVAL=$? RETVAL=$?
;; ;;

View file

@ -10,8 +10,8 @@
Name: iptables Name: iptables
Summary: Tools for managing Linux kernel packet filtering capabilities Summary: Tools for managing Linux kernel packet filtering capabilities
URL: https://www.netfilter.org/projects/iptables URL: https://www.netfilter.org/projects/iptables
Version: 1.8.11 Version: 1.8.13
Release: 13%{?dist} Release: 3%{?dist}
Source0: %{url}/files/%{name}-%{version}.tar.xz Source0: %{url}/files/%{name}-%{version}.tar.xz
source1: %{url}/files/%{name}-%{version}.tar.xz.sig source1: %{url}/files/%{name}-%{version}.tar.xz.sig
Source2: coreteam-gpg-key-0xD70D1A666ACF2B21.txt Source2: coreteam-gpg-key-0xD70D1A666ACF2B21.txt
@ -25,12 +25,6 @@ Source9: arptables.service
Source10: ebtables.service Source10: ebtables.service
Source11: ebtables-helper Source11: ebtables-helper
Source12: ebtables-config Source12: ebtables-config
# Patch to fix -C handling, already upstream
# https://git.netfilter.org/iptables/patch/?id=40406dbfaefbc204134452b2747bae4f6a122848
Patch1: iptables-1.8.11-fix-interface-comparisons.patch
# Patch to fix overly strict command option checking
# https://git.netfilter.org/iptables/patch/?id=192c3a6bc18f206895ec5e38812d648ccfe7e281
Patch2: iptables-1.8.11-command-options-fix.patch
# pf.os: ISC license # pf.os: ISC license
# iptables-apply: Artistic Licence 2.0 # iptables-apply: Artistic Licence 2.0
@ -476,6 +470,19 @@ fi
%changelog %changelog
* Wed Sep 02 2026 Phil Sutter <psutter@redhat.com> - 1.8.13-3
- Fix for missing /var/lock/subsys directory in init scripts
* Thu Jul 16 2026 Fedora Release Engineering <releng@fedoraproject.org> - 1.8.13-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_45_Mass_Rebuild
* Wed Mar 04 2026 Phil Sutter <psutter@redhat.com> - 1.8.13-1
- new version
* Sat Feb 21 2026 Kevin Fenzi <kevin@scrye.com> - 1.8.12-1
- Update to 1.8.12. Fixes rhbz#2440980
- Add patch to revert refuse to run under file capabilities and fix docker.
* Fri Jan 16 2026 Fedora Release Engineering <releng@fedoraproject.org> - 1.8.11-13 * Fri Jan 16 2026 Fedora Release Engineering <releng@fedoraproject.org> - 1.8.11-13
- Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild - Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild

View file

@ -1,2 +1,2 @@
SHA512 (iptables-1.8.11.tar.xz) = 4937020bf52d57a45b76e1eba125214a2f4531de52ff1d15185faeef8bea0cd90eb77f99f81baa573944aa122f350a7198cef41d70594e1b65514784addbcc40 SHA512 (iptables-1.8.13.tar.xz) = 3aefd76ca60d00f46ba4d6f39cbcfdc60517d03b6714da25dcd67542f6f4eea8d82c4855bdd9124efe18b769f41951772b8340a6eda75b85f8dd52b2289b145b
SHA512 (iptables-1.8.11.tar.xz.sig) = 8bde9436b6c6c9d97d9b1cadc417035c209e39b49111ea08fe35b714bbf94721ad0b8b2870791d3bf98154f64912109c6bdeb0ee33f954d0d3a8c3582a97f3f2 SHA512 (iptables-1.8.13.tar.xz.sig) = 9b8ef597e1f73c2697f29b07ac010313696f52f478f10c65ec4c4e2dc933be50c74c5c236512e4d756220c4d2fd511fded88dc46f2376fc5d7e2bea71fd267ca