Bug#1070685: linux-image-6.1.0-21-amd64: Found Trace in the logs about br_netfilter and nf_conntrack
Package: src:linux Version: 6.1.90-1 Severity: normal Dear Maintainer, * What led up to the situation? Rebooting the box after kernel package upgrade * What exactly did you do (or not do) that was effective (or ineffective)? Nothing * What was the outcome of this action? Nothing * What outcome did you expect instead? Rebooting without traces in the logs -- Package-specific info: ** Version: Linux version 6.1.0-21-amd64 (debian-ker...@lists.debian.org) (gcc-12 (Debian 12.2.0-14) 12.2.0, GNU ld (GNU Binutils for Debian) 2.40) #1 SMP PREEMPT_DYNAMIC Debian 6.1.90-1 (2024-05-03) ** Command line: BOOT_IMAGE=/vmlinuz-6.1.0-21-amd64 root=UUID=a75e6ad5-37fc-4f69-9361-f94d6c0e5d2f ro net.ifnames=0 apparmor=0 selinux=0 noresume consoleblank=0 console=tty1 ** Tainted: WOE (12800) * kernel issued warning * externally-built ("out-of-tree") module was loaded * unsigned module was loaded ** Kernel log: May 7 08:10:12 cerberus kernel: [ 76.203881] [ cut here ] May 7 08:10:12 cerberus kernel: [ 76.203895] WARNING: CPU: 3 PID: 0 at net/bridge/br_netfilter_hooks.c:622 br_nf_local_in+0x1a9/0x1d0 [br_netfilter] May 7 08:10:12 cerberus kernel: [ 76.203911] Modules linked in: ctr ccm nf_tables xt_nat xt_recent xt_geoip(OE) xt_NFQUEUE xt_mark xt_CT xt_tcpudp xt_helper nf_nat_ftp nf_conntrack_ftp ip6table_raw ip6table_mangle ip6table_nat xt_MASQUERADE iptable_nat nf_nat xt_TCPMSS xt_LOG nf_log_syslog ipt_REJECT nf_reject_ipv4 iptable_raw iptable_mangle xt_multiport xt_state xt_limit xt_conntrack nf_conntrack nf_defrag_ipv6 nf_defrag_ipv4 libcrc32c ip6table_filter ip6_tables iptable_filter ip_tables x_tables ovpn_dco_v2(OE) ip6_udp_tunnel udp_tunnel tcp_bbr nct6775 nct6775_core hwmon_vid br_netfilter bridge stp llc nfnetlink_queue nfnetlink i915 ppdev intel_rapl_msr evdev intel_rapl_common x86_pkg_temp_thermal intel_powerclamp drm_buddy coretemp video rt2800usb wmi ghash_clmulni_intel drm_display_helper rt2x00usb sha512_ssse3 sha512_generic rt2800lib rt2x00lib cec sha256_ssse3 sha1_ssse3 rc_core mac80211 aesni_intel ttm crypto_simd drm_kms_helper libarc4 cryptd cfg80211 rapl intel_cstate drm intel_uncore rfkill parport_pc pcspkr May 7 08:10:12 cerberus kernel: [ 76.203999] serio_raw iTCO_wdt intel_pmc_bxt iTCO_vendor_support parport watchdog at24 button ext4 crc16 mbcache jbd2 crc32c_generic sg sd_mod t10_pi crc64_rocksoft crc64 crc_t10dif crct10dif_generic ahci libahci libata crct10dif_pclmul crct10dif_common crc32_pclmul crc32c_intel psmouse scsi_mod i2c_i801 i2c_smbus ehci_pci ehci_hcd scsi_common lpc_ich usbcore igb i2c_algo_bit usb_common dca May 7 08:10:12 cerberus kernel: [ 76.204039] CPU: 3 PID: 0 Comm: swapper/3 Tainted: G OE 6.1.0-21-amd64 #1 Debian 6.1.90-1 May 7 08:10:12 cerberus kernel: [ 76.204044] Hardware name: Sophos UTM/To be filled by O.E.M., BIOS 4.6.4 11/08/2011 May 7 08:10:12 cerberus kernel: [ 76.204046] RIP: 0010:br_nf_local_in+0x1a9/0x1d0 [br_netfilter] May 7 08:10:12 cerberus kernel: [ 76.204056] Code: df e8 4b b7 cd fa 66 83 ab b8 00 00 00 08 eb 94 be 04 00 00 00 48 89 df e8 34 b7 cd fa 66 83 ab b8 00 00 00 04 e9 7a ff ff ff <0f> 0b e9 f0 fe ff ff 0f 0b e9 dd fe ff ff 48 89 ef e8 41 67 d8 fa May 7 08:10:12 cerberus kernel: [ 76.204059] RSP: 0018:bf5600144928 EFLAGS: 00010202 May 7 08:10:12 cerberus kernel: [ 76.204062] RAX: 0002 RBX: 9ac2862ff300 RCX: May 7 08:10:12 cerberus kernel: [ 76.204065] RDX: bf5600144980 RSI: 9ac2862ff300 RDI: May 7 08:10:12 cerberus kernel: [ 76.204067] RBP: 9ac2848a8100 R08: 0001 R09: 9ac2872be980 May 7 08:10:12 cerberus kernel: [ 76.204070] R10: 9ac2872be000 R11: 0002 R12: bf5600144980 May 7 08:10:12 cerberus kernel: [ 76.204072] R13: R14: 9ac282f4bac0 R15: 9ac2d027da00 May 7 08:10:12 cerberus kernel: [ 76.204074] FS: () GS:9ac5b018() knlGS: May 7 08:10:12 cerberus kernel: [ 76.204077] CS: 0010 DS: ES: CR0: 80050033 May 7 08:10:12 cerberus kernel: [ 76.204080] CR2: 5618751eb018 CR3: 2e610006 CR4: 000606e0 May 7 08:10:12 cerberus kernel: [ 76.204083] Call Trace: May 7 08:10:12 cerberus kernel: [ 76.204087] May 7 08:10:12 cerberus kernel: [ 76.204090] ? __warn+0x7d/0xc0 May 7 08:10:12 cerberus kernel: [ 76.204097] ? br_nf_local_in+0x1a9/0x1d0 [br_netfilter] May 7 08:10:12 cerberus kernel: [ 76.204105] ? report_bug+0xe2/0x150 May 7 08:10:12 cerberus kernel: [ 76.204113] ? handle_bug+0x41/0x70 May 7 08:10:12 cerberus kernel: [ 76.204118] ? exc_invalid_op+0x13/0x60 May 7 08:10:12 cerberus kernel: [ 76.204122] ? asm_exc_invalid_op+0x16/0x20 May 7 08:10:12 cerberus kernel: [ 76.204128] ? br_nf_local_in+0x1a9/0x1d0 [br_netfilter] May 7 08:10:12 cerberus k
Bug#918227: xtables-addons-common: GeoIPCountryCSV.zip ERROR 404: Not Found
Package: xtables-addons-common Version: 2.12-0.1 Severity: important Dear Maintainer, * What led up to the situation? Running periodically a script that calls /usr/lib/xtables-addons/xt_geoip_dl to update GeoIPv6.csv.gz and GeoIPCountryCSV.zip * What exactly did you do (or not do) that was effective (or ineffective) Call /usr/lib/xtables-addons/xt_geoip_dl * What was the outcome of this action? --2019-01-04 14:26:53-- http://geolite.maxmind.com/download/geoip/database/GeoIPCountryCSV.zip Reusing existing connection to geolite.maxmind.com:80. HTTP request sent, awaiting response... 404 Not Found * What outcome did you expect instead? Download GeoIPCountryCSV.zip, but starting January 2, 2019 it was removed from the website and a switch to GeoLite2 format databases is needed which could be downloaded at https://geolite.maxmind.com/download/geoip/database/GeoLite2-Country-CSV.zip. Sadly it seems to me that the xtables packages in the stable repositories are unable to handle the GeoLite2 format databases. -- System Information: Debian Release: 9.5 APT prefers stable-updates APT policy: (500, 'stable-updates'), (500, 'stable') Architecture: amd64 (x86_64) Kernel: Linux 4.9.0-8-amd64 (SMP w/4 CPU cores) Locale: LANG=en_US.UTF-8, LC_CTYPE=en_US.UTF-8 (charmap=UTF-8), LANGUAGE=en_US:en (charmap=UTF-8) Shell: /bin/sh linked to /bin/dash Init: sysvinit (via /sbin/init) Versions of packages xtables-addons-common depends on: ii libc6 2.24-11+deb9u3 ii libxtables12 1.6.0+snapshot20161117-6 Versions of packages xtables-addons-common recommends: ii unzip6.0-21 ii wget 1.18-5+deb9u2 ii xtables-addons-dkms 2.12-0.1 Versions of packages xtables-addons-common suggests: ii libtext-csv-xs-perl 1.26-1 -- no debconf information