SL5 kernel issue with iptables and bridged interfaces

2011-11-18 Thread Jon Peatfield
Having just suffered this when we upgraded one firewall to 
2.6.18-274.7.1.el5 I did some searching in TUV's bugzilla and found a 
report which seems strikingly similar - the kernel panics when iptables -j 
REJECT sends an icmp back over a bridged interface...


  https://bugzilla.redhat.com/show_bug.cgi?id=749813

From that report it seems to affect all the 2.6.18-274* series of kernels 
so we have backed off to 2.6.18-238.19.1.el5 for now - which appears to be 
stable.


I'm posting this here not because I expect any of the SL people to fix it 
(I don't expect there to be a fix until TUV releases one), but in case 
anyone else is suffering the same crashes and hasn't yet found the 
combination of things which trigger it.


--
/\
| "Computers are different from telephones.  Computers do not ring." |
|   -- A. Tanenbaum, "Computer Networks", p. 32  |
-|
| Jon Peatfield, _Computer_ Officer, DAMTP,  University of Cambridge |
| Mail:  jp...@damtp.cam.ac.uk Web:  http://www.damtp.cam.ac.uk/ |
\/


Re: SL5 kernel issue with iptables and bridged interfaces

2011-11-18 Thread Steven Timm

Thanks for posting and alerting, John.. there are some systems
at Fermilab which could be affected by this bug.

Steve Timm


On Fri, 18 Nov 2011, Jon Peatfield wrote:

Having just suffered this when we upgraded one firewall to 2.6.18-274.7.1.el5 
I did some searching in TUV's bugzilla and found a report which seems 
strikingly similar - the kernel panics when iptables -j REJECT sends an icmp 
back over a bridged interface...


 https://bugzilla.redhat.com/show_bug.cgi?id=749813

From that report it seems to affect all the 2.6.18-274* series of kernels so 
we have backed off to 2.6.18-238.19.1.el5 for now - which appears to be 
stable.


I'm posting this here not because I expect any of the SL people to fix it (I 
don't expect there to be a fix until TUV releases one), but in case anyone 
else is suffering the same crashes and hasn't yet found the combination of 
things which trigger it.





--
--
Steven C. Timm, Ph.D  (630) 840-8525
t...@fnal.gov  http://home.fnal.gov/~timm/
Fermilab Computing Division, Scientific Computing Facilities,
Grid Facilities Department, FermiGrid Services Group, Group Leader.
Lead of FermiCloud project.