Bug#1070685: linux-image-6.1.0-21-amd64: Found Trace in the logs about br_netfilter and nf_conntrack

2024-05-07 Thread Tito Ragusa
Package: src:linux
Version: 6.1.90-1
Severity: normal

Dear Maintainer,

   * What led up to the situation?

   Rebooting the box after kernel package upgrade

   * What exactly did you do (or not do) that was effective (or
 ineffective)?
   
   Nothing

   * What was the outcome of this action?
 
   Nothing 

   * What outcome did you expect instead?

   Rebooting without traces in the logs
 
-- Package-specific info:
** Version:
Linux version 6.1.0-21-amd64 (debian-ker...@lists.debian.org) (gcc-12 (Debian 
12.2.0-14) 12.2.0, GNU ld (GNU Binutils for Debian) 2.40) #1 SMP 
PREEMPT_DYNAMIC Debian 6.1.90-1 (2024-05-03)

** Command line:
BOOT_IMAGE=/vmlinuz-6.1.0-21-amd64 
root=UUID=a75e6ad5-37fc-4f69-9361-f94d6c0e5d2f ro net.ifnames=0 apparmor=0 
selinux=0 noresume consoleblank=0 console=tty1

** Tainted: WOE (12800)
 * kernel issued warning
 * externally-built ("out-of-tree") module was loaded
 * unsigned module was loaded

** Kernel log:
  May  7 08:10:12 cerberus kernel: [   76.203881] [ cut here 
]
May  7 08:10:12 cerberus kernel: [   76.203895] WARNING: CPU: 3 PID: 0 at 
net/bridge/br_netfilter_hooks.c:622 br_nf_local_in+0x1a9/0x1d0 [br_netfilter]
May  7 08:10:12 cerberus kernel: [   76.203911] Modules linked in: ctr ccm 
nf_tables xt_nat xt_recent xt_geoip(OE) xt_NFQUEUE xt_mark xt_CT xt_tcpudp 
xt_helper nf_nat_ftp nf_conntrack_ftp ip6table_raw ip6table_mangle ip6table_nat 
xt_MASQUERADE iptable_nat nf_nat xt_TCPMSS xt_LOG nf_log_syslog ipt_REJECT 
nf_reject_ipv4 iptable_raw iptable_mangle xt_multiport xt_state xt_limit 
xt_conntrack nf_conntrack nf_defrag_ipv6 nf_defrag_ipv4 libcrc32c 
ip6table_filter ip6_tables iptable_filter ip_tables x_tables ovpn_dco_v2(OE) 
ip6_udp_tunnel udp_tunnel tcp_bbr nct6775 nct6775_core hwmon_vid br_netfilter 
bridge stp llc nfnetlink_queue nfnetlink i915 ppdev intel_rapl_msr evdev 
intel_rapl_common x86_pkg_temp_thermal intel_powerclamp drm_buddy coretemp 
video rt2800usb wmi ghash_clmulni_intel drm_display_helper rt2x00usb 
sha512_ssse3 sha512_generic rt2800lib rt2x00lib cec sha256_ssse3 sha1_ssse3 
rc_core mac80211 aesni_intel ttm crypto_simd drm_kms_helper libarc4 cryptd 
cfg80211 rapl intel_cstate drm intel_uncore rfkill parport_pc pcspkr
May  7 08:10:12 cerberus kernel: [   76.203999]  serio_raw iTCO_wdt 
intel_pmc_bxt iTCO_vendor_support parport watchdog at24 button ext4 crc16 
mbcache jbd2 crc32c_generic sg sd_mod t10_pi crc64_rocksoft crc64 crc_t10dif 
crct10dif_generic ahci libahci libata crct10dif_pclmul crct10dif_common 
crc32_pclmul crc32c_intel psmouse scsi_mod i2c_i801 i2c_smbus ehci_pci ehci_hcd 
scsi_common lpc_ich usbcore igb i2c_algo_bit usb_common dca
May  7 08:10:12 cerberus kernel: [   76.204039] CPU: 3 PID: 0 Comm: swapper/3 
Tainted: G   OE  6.1.0-21-amd64 #1  Debian 6.1.90-1
May  7 08:10:12 cerberus kernel: [   76.204044] Hardware name: Sophos UTM/To be 
filled by O.E.M., BIOS 4.6.4 11/08/2011
May  7 08:10:12 cerberus kernel: [   76.204046] RIP: 
0010:br_nf_local_in+0x1a9/0x1d0 [br_netfilter]
May  7 08:10:12 cerberus kernel: [   76.204056] Code: df e8 4b b7 cd fa 66 83 
ab b8 00 00 00 08 eb 94 be 04 00 00 00 48 89 df e8 34 b7 cd fa 66 83 ab b8 00 
00 00 04 e9 7a ff ff ff <0f> 0b e9 f0 fe ff ff 0f 0b e9 dd fe ff ff 48 89 ef e8 
41 67 d8 fa
May  7 08:10:12 cerberus kernel: [   76.204059] RSP: 0018:bf5600144928 
EFLAGS: 00010202
May  7 08:10:12 cerberus kernel: [   76.204062] RAX: 0002 RBX: 
9ac2862ff300 RCX: 
May  7 08:10:12 cerberus kernel: [   76.204065] RDX: bf5600144980 RSI: 
9ac2862ff300 RDI: 
May  7 08:10:12 cerberus kernel: [   76.204067] RBP: 9ac2848a8100 R08: 
0001 R09: 9ac2872be980
May  7 08:10:12 cerberus kernel: [   76.204070] R10: 9ac2872be000 R11: 
0002 R12: bf5600144980
May  7 08:10:12 cerberus kernel: [   76.204072] R13:  R14: 
9ac282f4bac0 R15: 9ac2d027da00
May  7 08:10:12 cerberus kernel: [   76.204074] FS:  () 
GS:9ac5b018() knlGS:
May  7 08:10:12 cerberus kernel: [   76.204077] CS:  0010 DS:  ES:  
CR0: 80050033
May  7 08:10:12 cerberus kernel: [   76.204080] CR2: 5618751eb018 CR3: 
2e610006 CR4: 000606e0
May  7 08:10:12 cerberus kernel: [   76.204083] Call Trace:
May  7 08:10:12 cerberus kernel: [   76.204087]  
May  7 08:10:12 cerberus kernel: [   76.204090]  ? __warn+0x7d/0xc0
May  7 08:10:12 cerberus kernel: [   76.204097]  ? br_nf_local_in+0x1a9/0x1d0 
[br_netfilter]
May  7 08:10:12 cerberus kernel: [   76.204105]  ? report_bug+0xe2/0x150
May  7 08:10:12 cerberus kernel: [   76.204113]  ? handle_bug+0x41/0x70
May  7 08:10:12 cerberus kernel: [   76.204118]  ? exc_invalid_op+0x13/0x60
May  7 08:10:12 cerberus kernel: [   76.204122]  ? asm_exc_invalid_op+0x16/0x20
May  7 08:10:12 cerberus kernel: [   76.204128]  ? br_nf_local_in+0x1a9/0x1d0 
[br_netfilter]
May  7 08:10:12 cerberus k

Bug#918227: xtables-addons-common: GeoIPCountryCSV.zip ERROR 404: Not Found

2019-01-04 Thread Tito Ragusa
Package: xtables-addons-common
Version: 2.12-0.1
Severity: important

Dear Maintainer,

   * What led up to the situation?
 Running periodically a script that calls 
/usr/lib/xtables-addons/xt_geoip_dl
 to update GeoIPv6.csv.gz and GeoIPCountryCSV.zip
   * What exactly did you do (or not do) that was effective (or
 ineffective)
 Call  /usr/lib/xtables-addons/xt_geoip_dl
   * What was the outcome of this action?
 --2019-01-04 14:26:53--  
http://geolite.maxmind.com/download/geoip/database/GeoIPCountryCSV.zip
 Reusing existing connection to geolite.maxmind.com:80.
 HTTP request sent, awaiting response... 404 Not Found
   * What outcome did you expect instead?
 Download GeoIPCountryCSV.zip, but starting January 2, 2019 it was removed
 from the website and a switch to GeoLite2 format databases is needed
 which could be downloaded at 
https://geolite.maxmind.com/download/geoip/database/GeoLite2-Country-CSV.zip.
 Sadly it seems to me that the xtables packages in the stable repositories
 are unable to handle the GeoLite2 format databases. 
 

-- System Information:
Debian Release: 9.5
  APT prefers stable-updates
  APT policy: (500, 'stable-updates'), (500, 'stable')
Architecture: amd64 (x86_64)

Kernel: Linux 4.9.0-8-amd64 (SMP w/4 CPU cores)
Locale: LANG=en_US.UTF-8, LC_CTYPE=en_US.UTF-8 (charmap=UTF-8), 
LANGUAGE=en_US:en (charmap=UTF-8)
Shell: /bin/sh linked to /bin/dash
Init: sysvinit (via /sbin/init)

Versions of packages xtables-addons-common depends on:
ii  libc6 2.24-11+deb9u3
ii  libxtables12  1.6.0+snapshot20161117-6

Versions of packages xtables-addons-common recommends:
ii  unzip6.0-21
ii  wget 1.18-5+deb9u2
ii  xtables-addons-dkms  2.12-0.1

Versions of packages xtables-addons-common suggests:
ii  libtext-csv-xs-perl  1.26-1

-- no debconf information