[Pkg-utopia-maintainers] Bug#916791: firewalld: nftables backend not happy with --set-log-denied={unicast, broadcast, multicast}

Sam Morris sam at robots.org.uk
Tue Dec 18 16:08:11 GMT 2018


Package: firewalld
Version: 0.6.3-4
Severity: normal

firewalld doesn't seem to be happy with any log setting other than 'all'
and 'off'.

# firewall-cmd --set-log-denied=unicast
# journalctl -u firewalld -e
...
Dec 18 16:06:46 firewalld[576]: ERROR: Failed to apply rules. A firewall reload might solve the issue if the firewall has been modified using ip*tables or ebtables.
Dec 18 16:06:46 firewalld[576]: ERROR: 'nftables' object has no attribute '_log_denied'
Dec 18 16:06:47 firewalld[576]: ERROR: Failed to apply rules. A firewall reload might solve the issue if the firewall has been modified using ip*tables or ebtables.
Dec 18 16:06:47 firewalld[576]: ERROR: '/usr/sbin/nft add rule inet firewalld raw_PREROUTING_ZONES goto raw_PRE_public' failed: Error: Could not process rule: No such file or directory
                                add rule inet firewalld raw_PREROUTING_ZONES goto raw_PRE_public
                                ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
Dec 18 16:06:47 firewalld[576]: ERROR: Failed to apply rules. A firewall reload might solve the issue if the firewall has been modified using ip*tables or ebtables.
Dec 18 16:06:47 firewalld[576]: ERROR: '/usr/sbin/nft insert rule inet firewalld raw_PREROUTING_ZONES iifname wlp2s0 goto raw_PRE_public' failed: Error: Could not process rule: No such file or directory
                                insert rule inet firewalld raw_PREROUTING_ZONES iifname wlp2s0 goto raw_PRE_public
                                ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^

-- System Information:
Debian Release: buster/sid
  APT prefers testing-debug
  APT policy: (570, 'testing-debug'), (570, 'testing'), (540, 'unstable-debug'), (540, 'unstable'), (1, 'experimental')
Architecture: amd64 (x86_64)

Kernel: Linux 4.18.0-3-amd64 (SMP w/4 CPU cores)
Locale: LANG=en_GB.UTF-8, LC_CTYPE=en_GB.UTF-8 (charmap=UTF-8), LANGUAGE=en_GB.UTF-8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/dash
Init: systemd (via /run/systemd/system)
LSM: AppArmor: enabled

Versions of packages firewalld depends on:
ii  dbus                 1.12.12-1
ii  gir1.2-glib-2.0      1.58.2-1
ii  init-system-helpers  1.56
ii  iptables             1.8.2-2+b1
ii  policykit-1          0.105-23
ii  python3              3.6.7-1
ii  python3-dbus         1.2.8-2+b1
ii  python3-gi           3.30.4-1
ii  python3-slip-dbus    0.6.5-2

Versions of packages firewalld recommends:
ii  ebtables  2.0.10.4-5
ii  ipset     6.38-1

firewalld suggests no packages.

-- Configuration Files:
/etc/firewalld/firewalld.conf [Errno 13] Permission denied: '/etc/firewalld/firewalld.conf'
/etc/firewalld/lockdown-whitelist.xml [Errno 13] Permission denied: '/etc/firewalld/lockdown-whitelist.xml'

-- no debconf information



More information about the Pkg-utopia-maintainers mailing list