Bug#918497: RFS: arptables/0.0.4+snapshot20181021-1 - ARP table administration

2019-01-08 Thread Arturo Borrero Gonzalez
On Mon, 7 Jan 2019 17:59:57 +0100 Adam Borowski wrote: > On Sun, Jan 06, 2019 at 06:31:01PM +0100, Alberto Molina Coballes wrote: > > * Package name: arptables > >Version : 0.0.4+snapshot20181021-1 > > > * [2c7c7c6] New upstream version 0.0.4+snapshot20181021 > > * [c6b2324]

Bug#918551: [pkg-netfilter-team] Bug#918551: ebtables-nft does not know -t broute

2019-01-08 Thread Arturo Borrero Gonzalez
Control: forwarded -1 https://bugzilla.netfilter.org/show_bug.cgi?id=1316 On 1/7/19 12:43 PM, Wolfgang Walter wrote: > Package: iptables > Version: 1.8.2-3 > Severity: important > > After upgrading the ebtables packet our routers broke. Reason is that the > ebtables command now defaults to

Bug#918469: [pkg-netfilter-team] Bug#918469: Please Provides ebtables and arptables

2019-01-08 Thread Arturo Borrero Gonzalez
On 1/6/19 12:56 PM, Laurent Bigonville wrote: > Package: iptables > Version: 1.8.2-3 > Severity: normal > > Hi, > > Shouldn't the iptables packages Provides ebtables and arptables now that > it ships these executables as well? > > AFAICS, the implementation shipped in iptables are providing the

Bug#918046: RFS: ebtables/2.0.10.4+snapshot20181205-1 - Ethernet bridge frame table administration

2019-01-03 Thread Arturo Borrero Gonzalez
On Wed, 02 Jan 2019 20:06:47 +0100 Alberto Molina Coballes wrote: > Package: sponsorship-requests > Severity: normal > > I am looking for a sponsor for my package "ebtables" > Done! :-)

Bug#918046: RFS: ebtables/2.0.10.4+snapshot20181205-1 - Ethernet bridge frame table administration

2019-01-03 Thread Arturo Borrero Gonzalez
On Wed, 02 Jan 2019 20:06:47 +0100 Alberto Molina Coballes wrote: > Package: sponsorship-requests > Severity: normal > > I am looking for a sponsor for my package "ebtables" > Done! :-)

Bug#916392: please provide a column marker mechanism

2019-01-02 Thread Arturo Borrero Gonzalez
On 1/1/19 4:58 PM, Benno Schulenberg wrote: > Attached is a version with a working --edge option, > plus some other buglets ironed out. > > Benno LGTM! thanks.

Bug#833325: iptables: bin-or-sbin-binary-requires-usr-lib-library /sbin/xtables-multi

2018-12-28 Thread Arturo Borrero Gonzalez
Control: fixed -1 1.8.1-2 On Wed, 03 Aug 2016 08:56:00 +0200 Antonio Ospite wrote: > Package: iptables > Version: 1.6.0-3 > Severity: normal > > Dear Maintainer, > > the "adequate" QA tool reports these for the /sbin/xtables-multi > executable: > > iptables:

Bug#892951: iptables rules loaded via iptables-restore ....rules.v4 are dropped every few minutes.

2018-12-28 Thread Arturo Borrero Gonzalez
On Wed, 14 Mar 2018 12:39:38 -0700 "g.smyli" wrote: > Package: iptables > Version: 1.6.0+snapshot20161117-6 > Severity: normal > > Dear Maintainer, > > *** Reporter, please consider answering these questions, where appropriate *** > >* What led up to the situation? > I believe the problem

Bug#905284: iptables-save should exit 1 instead of lying to the unprivileged user

2018-12-28 Thread Arturo Borrero Gonzalez
Control: forwarded -1 https://bugzilla.netfilter.org/show_bug.cgi?id=1313 signature.asc Description: OpenPGP digital signature

Bug#913883: usrmerge: can't merge with iptables and ebtables installed

2018-12-28 Thread Arturo Borrero Gonzalez
On Sat, 8 Dec 2018 00:29:38 +0100 Marco d'Itri wrote:> I would really appreciate if the iptables maintainer could comment about > this bug. > We are working on both arptables & ebtables and will upload a fixed version soon. I'm closing this bug now, since it has nothing to do with the iptables

Bug#915627: icmpv6 error in ufw

2018-12-28 Thread Arturo Borrero Gonzalez
Control: reassing -1 ufw This is probably a bug in ufw. I can do this here: $ sudo ip6tables-nft -A FORWARD -i eth0 -p icmpv6 -m icmpv6 --icmpv6-type no-route $ sudo ip6tables-legacy -A FORWARD -i eth0 -p icmpv6 -m icmpv6 --icmpv6-type no-route and both work.

Bug#888154: iptables: ip4/6 handling ambiguous and f2b no longer starts

2018-12-28 Thread Arturo Borrero Gonzalez
Control: reassign -1 fail2ban On Tue, 23 Jan 2018 18:22:14 +0100 Christoph Anton Mitterer wrote: > Package: iptables > Version: 1.6.1-2+b1 > Severity: important > > > > Hi. > > Seems with the new version no chains/rules get added to netfilter for me. > > What I do is, I have

Bug#916596: iptables.postinst failure on link creation

2018-12-28 Thread Arturo Borrero Gonzalez
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Control: tag -1 moreinfo On Sun, 16 Dec 2018 13:14:19 +0100 Olivier wrote: > Package: iptables Version: 1.8.2-2+b1 Severity: important > > Dear Maintainer, > > Issue occure during iptables:i386 1.8.2-2 -> 1.8.2-2+b1 upgrade. > >

Accepted iptables 1.8.2-3 (source) into unstable

2018-12-28 Thread Arturo Borrero Gonzalez
: unstable Urgency: medium Maintainer: Debian Netfilter Packaging Team Changed-By: Arturo Borrero Gonzalez Description: iptables - administration tools for packet filtering and NAT iptables-dev - transitional dummy package libip4tc-dev - Development files for libip4tc libip4tc0 - netfilter

Re: [Cloud-announce] CloudVPS network maintenance tomorrow 2018-12-20 @ 17:00 UTC

2018-12-20 Thread Arturo Borrero Gonzalez
On 12/19/18 6:16 PM, Arturo Borrero Gonzalez wrote: > Hi! > > Tomorrow 2018-12-20 @ 17:00 UTC (~24h from now) we will be conducting > some network maintenance in Cloud VPS (openstack). > > We will be doing some works on the transport network that connects the > Neutr

Re: [Cloud] [Cloud-announce] CloudVPS network maintenance tomorrow 2018-12-20 @ 17:00 UTC

2018-12-20 Thread Arturo Borrero Gonzalez
On 12/19/18 6:16 PM, Arturo Borrero Gonzalez wrote: > Hi! > > Tomorrow 2018-12-20 @ 17:00 UTC (~24h from now) we will be conducting > some network maintenance in Cloud VPS (openstack). > > We will be doing some works on the transport network that connects the > Neutr

Bug#916863: [pkg-netfilter-team] Bug#916863: [nftables] tproxy action not parsed correctly

2018-12-19 Thread Arturo Borrero Gonzalez
Control: forwarded -1 https://bugzilla.netfilter.org/show_bug.cgi?id=1310

[Cloud] [Cloud-announce] CloudVPS network maintenance tomorrow 2018-12-20 @ 17:00 UTC

2018-12-19 Thread Arturo Borrero Gonzalez
Hi! Tomorrow 2018-12-20 @ 17:00 UTC (~24h from now) we will be conducting some network maintenance in Cloud VPS (openstack). We will be doing some works on the transport network that connects the Neutron server to the rest of the internet. Running CloudVPS instances will see a brief connection

Bug#916863: [pkg-netfilter-team] Bug#916863: [nftables] tproxy action not parsed correctly

2018-12-19 Thread Arturo Borrero Gonzalez
On 12/19/18 5:57 PM, Michał Mirosław wrote: > Package: nftables > Version: 0.9.0-2 > Severity: normal > > --- Please enter the report below this line. --- > > # nft add rule inet filter divert 'ip6 daddr ::/0 meta l4proto tcp tproxy to > :2000 meta mark set 1 accept' > Error: syntax error,

Bug#916392: please provide a column marker mechanism

2018-12-17 Thread Arturo Borrero Gonzalez
On 12/17/18 7:55 PM, Benno Schulenberg wrote: > > Hi Arturo, > > Interesting request. But... a vertical bar across the screen is > hard to make -- it would mean having to extend shorter lines with > whitespace to reach the desired column. What is easier to make > is to color any text that

Bug#916392: please provide a column marker mechanism

2018-12-13 Thread Arturo Borrero Gonzalez
Package: nano Version: 3.2-1 Severity: wishlist Tags: upstream I use the nano editor daily :-) Thanks for your work, it's really appreciated. A handly option to have while writting code (and other files as well actually) is to get a column marker. Let's say you want to do write more than 80

Bug#912046: [pkg-netfilter-team] Bug#912046: debsums: Error: symlink loop detected in path 'sbin/ebtables'.

2018-12-10 Thread Arturo Borrero Gonzalez
On 12/10/18 9:30 AM, Laurent Bigonville wrote: > On Sat, 1 Dec 2018 13:36:11 +0100 gregor herrmann > wrote: > >> On Sat, 27 Oct 2018 17:39:50 +0200, Laurent Bigonville wrote: >> >> > When running debsums -ac, it complains that: >> > >> > debsums: Error: symlink loop detected in path

Bug#912046: [pkg-netfilter-team] Bug#912046: debsums: Error: symlink loop detected in path 'sbin/ebtables'.

2018-12-10 Thread Arturo Borrero Gonzalez
On 12/10/18 9:30 AM, Laurent Bigonville wrote: > On Sat, 1 Dec 2018 13:36:11 +0100 gregor herrmann > wrote: > >> On Sat, 27 Oct 2018 17:39:50 +0200, Laurent Bigonville wrote: >> >> > When running debsums -ac, it complains that: >> > >> > debsums: Error: symlink loop detected in path

Bug#912610: [pkg-netfilter-team] Bug#912610: with iptables 1.8.2-2 is still the same error

2018-12-05 Thread Arturo Borrero Gonzalez
On 12/5/18 1:08 PM, PatrikX3 wrote: > *iptables/testing,now 1.8.2-2 amd64 [installed]* > * > * > *root@server:~# ufw enable* > *Command may disrupt existing ssh connections. Proceed with operation > (y|n)? y* > *ERROR: problem running ufw-init* > *ip6tables-restore v1.8.2 (nf_tables): unknown

Re: Proposal: rename of arptables.git and ebtables.git

2018-12-05 Thread Arturo Borrero Gonzalez
On 12/4/18 11:57 AM, Pablo Neira Ayuso wrote: > On Tue, Dec 04, 2018 at 11:50:46AM +0100, Arturo Borrero Gonzalez wrote: >> On 11/28/18 2:10 PM, Arturo Borrero Gonzalez wrote: >>> On 11/28/18 1:44 PM, Arturo Borrero Gonzalez wrote: >>>> Hi, >>>> >>&g

Re: Proposal: rename of arptables.git and ebtables.git

2018-12-04 Thread Arturo Borrero Gonzalez
On 11/28/18 2:10 PM, Arturo Borrero Gonzalez wrote: > On 11/28/18 1:44 PM, Arturo Borrero Gonzalez wrote: >> Hi, >> >> Now that the iptables.git repo offers arptables-nft and ebtables-nft, >> arptables.git holds arptables-legacy, etc, why we don't just rename

Accepted nftables 0.9.0-2 (source) into unstable

2018-12-03 Thread Arturo Borrero Gonzalez
-By: Arturo Borrero Gonzalez Description: libnftables-dev - Development files for libnftables libnftables0 - Netfilter nftables high level userspace API library nftables - Program to control packet filtering rules by Netfilter project Closes: 903083 Changes: nftables (0.9.0-2) unstable; urgency

Accepted libnftnl 1.1.2-2 (source) into unstable

2018-12-03 Thread Arturo Borrero Gonzalez
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Format: 1.8 Date: Mon, 03 Dec 2018 12:20:58 +0100 Source: libnftnl Binary: libnftnl11 libnftnl-dev Architecture: source Version: 1.1.2-2 Distribution: unstable Urgency: medium Maintainer: Debian Netfilter Packaging Team Changed-By: Arturo Borrero

Bug#821884: [nano] please provide a shortcut to delete previous/next word

2018-12-03 Thread Arturo Borrero Gonzalez
Control: fixed -1 3.2-1 On 12/2/18 8:34 PM, Benno Schulenberg wrote: > > Since nano-3.0, deletes the word to the right of the cursor, > and deletes the word to the left. > > If you never use ^H, on some terminals you can also make > delete the word to the left of the cursor when you add in

Accepted libnftnl 1.1.2-1 (source) into unstable

2018-11-30 Thread Arturo Borrero Gonzalez
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Format: 1.8 Date: Fri, 30 Nov 2018 12:24:50 +0100 Source: libnftnl Binary: libnftnl11 libnftnl-dev Architecture: source Version: 1.1.2-1 Distribution: unstable Urgency: medium Maintainer: Debian Netfilter Packaging Team Changed-By: Arturo Borrero

Bug#888695: nftables: Enabled systemd service blocks boot sequence

2018-11-29 Thread Arturo Borrero Gonzalez
On 11/28/18 8:26 PM, Pablo Pasquín Rosillo wrote: > Just checked and it works fine with DefaultDependencies=no :) > I'm interested in the kernel oops, that should be fixed independently of the systemd configuration.

[PATCH nft] tests: fix return codes

2018-11-28 Thread Arturo Borrero Gonzalez
Please, consider merging the attached patch. thanks. commit 3497067ca187047c61d89ccad6eab4ebf5df9219 Author: Arturo Borrero Gonzalez Date: Wed Nov 28 14:31:57 2018 +0100 tests: fix return codes Try to return != 0 if a testsuite fails. Signed-off-by: Arturo Borrero

Re: Proposal: rename of arptables.git and ebtables.git

2018-11-28 Thread Arturo Borrero Gonzalez
On 11/28/18 1:44 PM, Arturo Borrero Gonzalez wrote: > Hi, > > Now that the iptables.git repo offers arptables-nft and ebtables-nft, > arptables.git holds arptables-legacy, etc, why we don't just rename the > repos? > > * from arptables.git to arptables-legacy.git

Proposal: rename of arptables.git and ebtables.git

2018-11-28 Thread Arturo Borrero Gonzalez
Hi, Now that the iptables.git repo offers arptables-nft and ebtables-nft, arptables.git holds arptables-legacy, etc, why we don't just rename the repos? * from arptables.git to arptables-legacy.git * from ebtables.git to ebtables-legacy.git This rename should help distros understand the

Bug#914706: [pkg-netfilter-team] Bug#914706: Add 1 more element to a set and you can delete the 1st element

2018-11-28 Thread Arturo Borrero Gonzalez
Control: forwarded -1 https://bugzilla.netfilter.org/show_bug.cgi?id=1304

Bug#888695: nftables: Enabled systemd service blocks boot sequence

2018-11-28 Thread Arturo Borrero Gonzalez
Control: tags -1 moreinfo On Thu, 1 Feb 2018 09:50:31 +0100 Paolo Rosquin wrote: > No idea why it only happens to me. Anyway, I have narrowed down the > problem to one line in nftables.service: > > DefaultDependencies=no > > Without this everything works fine. > Could you please check if

Re: [Cloud] [Cloud-announce] CloudVPS network maintenance 2018-11-27 @ 17:30 UTC

2018-11-27 Thread Arturo Borrero Gonzalez
On 11/21/18 10:54 AM, Arturo Borrero Gonzalez wrote: > Hi, > > next Tuesday, 2018-11-27 @ 17:30UTC we will reboot the > labnet1001.eqiad.wmnet server for maintenance and security updates. > > This server provides virtual networking services for CloudVPS in the > main de

Re: [Cloud-announce] CloudVPS network maintenance 2018-11-27 @ 17:30 UTC

2018-11-27 Thread Arturo Borrero Gonzalez
On 11/21/18 10:54 AM, Arturo Borrero Gonzalez wrote: > Hi, > > next Tuesday, 2018-11-27 @ 17:30UTC we will reboot the > labnet1001.eqiad.wmnet server for maintenance and security updates. > > This server provides virtual networking services for CloudVPS in the > main de

Bug#914439: nftables: Unexpected behavior with 'Sets'

2018-11-23 Thread Arturo Borrero Gonzalez
On 11/23/18 2:59 PM, Aiko Barz wrote: > > Kernel: Stable vmlinuz-4.9.0-8-amd64 Please, use a newer kernel, for example: stable-bpo: 4.18.6-1~bpo9+1 > Maybe there are some known(?) nftables sets limit for this kernel? > The number of elements a set can hold is pretty big. You would see an

Bug#914439: nftables: Unexpected behavior with 'Sets'

2018-11-23 Thread Arturo Borrero Gonzalez
Control: tag -1 moreinfo On 11/23/18 2:28 PM, Aiko Barz wrote: > > I have written a nftables script, which extensively uses Sets¹. > > Unexpected: It does block an IPv6-network, which is part of the set. The > network has been loaded into the "named set". I checked it with: > $ sudo nft list

Bug#914429: nftables: Delete and Flush lead to device or resource busy with segmentation fault

2018-11-23 Thread Arturo Borrero Gonzalez
On 11/23/18 1:08 PM, Eike Lohmann wrote: > > Hi Arturo, > > thanks for your quick reply. > > Like described in my example, there is no reference to C_TestChain. > I reproduced your steps, and I had multiple issues because your steps try to delete stuff with external references. If you don't

Bug#914429: nftables: Delete and Flush lead to device or resource busy with segmentation fault

2018-11-23 Thread Arturo Borrero Gonzalez
On 11/23/18 1:08 PM, Eike Lohmann wrote: > > Hi Arturo, > > thanks for your quick reply. > > Like described in my example, there is no reference to C_TestChain. > I reproduced your steps, and I had multiple issues because your steps try to delete stuff with external references. If you don't

Bug#914397: nftables: after Stretch->Buster upgrade, named set needs "auto-merge"

2018-11-23 Thread Arturo Borrero Gonzalez
Control: fixed -1 0.9.0-1 On Fri, 23 Nov 2018 08:52:01 +0100 Gert wrote: > After analyzing my config, I can now give a full example. > The subnet came from a geoblock list, the separate host came from an > abusers list. > That causes the conflict in Buster (which can be fixed with auto-merge).

Bug#914429: nftables: Delete and Flush lead to device or resource busy with segmentation fault

2018-11-23 Thread Arturo Borrero Gonzalez
Control: severity -1 normal Control: reassign -1 linux Control: fixed -1 4.18.20-1 On 11/23/18 11:32 AM, Eike Lohmann wrote: > # nft delete chain filter C_TestChain > Error: Could not process rule: Device or resource busy > delete chain filter C_TestChain > This is not a bug. This means that

Bug#914423: document iptables/nftables situation

2018-11-23 Thread Arturo Borrero Gonzalez
Package: release-notes Severity: normal Tags: buster Hi, I think the iptables/nftables situation for Buster worth mentioning in the release notes. We got some important changes that I will describe below: === 8< === Debian Buster uses now the nftables framework by default. Starting with

Bug#914423: document iptables/nftables situation

2018-11-23 Thread Arturo Borrero Gonzalez
Package: release-notes Severity: normal Tags: buster Hi, I think the iptables/nftables situation for Buster worth mentioning in the release notes. We got some important changes that I will describe below: === 8< === Debian Buster uses now the nftables framework by default. Starting with

Bug#914416: transition: libnftnl

2018-11-23 Thread Arturo Borrero Gonzalez
Package: release.debian.org Severity: normal User: release.debian@packages.debian.org Usertags: transition Hi, upstream bumped SONAME of libnftnl, so the binary package got rename from libnftnl7 to libnftnl11. https://release.debian.org/transitions/html/auto-libnftnl.html Reverse depends

Bug#914416: transition: libnftnl

2018-11-23 Thread Arturo Borrero Gonzalez
Package: release.debian.org Severity: normal User: release.debian@packages.debian.org Usertags: transition Hi, upstream bumped SONAME of libnftnl, so the binary package got rename from libnftnl7 to libnftnl11. https://release.debian.org/transitions/html/auto-libnftnl.html Reverse depends

Bug#914129: Docker issue with iptables 1.8.2

2018-11-22 Thread Arturo Borrero Gonzalez
Control: severity -1 normal Control: unmerge -1 Control: retitle -1 possible issue with docker Let's retitle this to something more meaningfull. Downgrading severity until we see further details on this issue. Also, unmerge this bug report from the unrelated #914129.

Bug#914129: Docker issue with iptables 1.8.2

2018-11-22 Thread Arturo Borrero Gonzalez
Control: severity -1 normal Control: unmerge -1 Control: retitle -1 possible issue with docker Let's retitle this to something more meaningfull. Downgrading severity until we see further details on this issue. Also, unmerge this bug report from the unrelated #914129.

Bug#914074: Bug fixed

2018-11-22 Thread Arturo Borrero Gonzalez
Control: unmerge -1 Control: fixed -1 1.8.2-2 This bug is different from #914129, unmerging now. Also, this bug is fixed by iptables 1.8.2-2, so closing it now as well.

Bug#914074: Bug fixed

2018-11-22 Thread Arturo Borrero Gonzalez
Control: unmerge -1 Control: fixed -1 1.8.2-2 This bug is different from #914129, unmerging now. Also, this bug is fixed by iptables 1.8.2-2, so closing it now as well.

Accepted libnftnl 1.1.2-1~exp1 (source amd64) into experimental, experimental

2018-11-21 Thread Arturo Borrero Gonzalez
-By: Arturo Borrero Gonzalez Description: libnftnl-dev - Development files for libnftnl libnftnl11 - Netfilter nftables userspace API library Changes: libnftnl (1.1.2-1~exp1) experimental; urgency=medium . * [f3e2c03] d/control: mark libnftnl-dev as Multi-Arch: same * [e79eda4] New upstream

Accepted libnftnl 1.1.2-1~exp1 (source amd64) into experimental, experimental

2018-11-21 Thread Arturo Borrero Gonzalez
-By: Arturo Borrero Gonzalez Description: libnftnl-dev - Development files for libnftnl libnftnl11 - Netfilter nftables userspace API library Changes: libnftnl (1.1.2-1~exp1) experimental; urgency=medium . * [f3e2c03] d/control: mark libnftnl-dev as Multi-Arch: same * [e79eda4] New upstream

[Cloud] [Cloud-announce] CloudVPS network maintenance 2018-11-27 @ 17:30 UTC

2018-11-21 Thread Arturo Borrero Gonzalez
Hi, next Tuesday, 2018-11-27 @ 17:30UTC we will reboot the labnet1001.eqiad.wmnet server for maintenance and security updates. This server provides virtual networking services for CloudVPS in the main deployment (the old one, different from the eqiad1 deployment). We won't be doing any failover

[Cloud-announce] CloudVPS network maintenance 2018-11-27 @ 17:30 UTC

2018-11-21 Thread Arturo Borrero Gonzalez
Hi, next Tuesday, 2018-11-27 @ 17:30UTC we will reboot the labnet1001.eqiad.wmnet server for maintenance and security updates. This server provides virtual networking services for CloudVPS in the main deployment (the old one, different from the eqiad1 deployment). We won't be doing any failover

Re: [Cloud] [Cloud-announce] OSM database reboot next Tuesday 2018-11-20 at 17:30 UTC

2018-11-20 Thread Arturo Borrero Gonzalez
On 11/20/18 6:19 PM, Arturo Borrero Gonzalez wrote: > On 11/15/18 5:58 PM, Arturo Borrero Gonzalez wrote: >> Hi, >> >> next Tuesday 2018-11-20 at 17:30 UTC we will be rebooting the OSM >> database (part of our data services) for maintenance and security updates. >>

Re: [Cloud-announce] OSM database reboot next Tuesday 2018-11-20 at 17:30 UTC

2018-11-20 Thread Arturo Borrero Gonzalez
On 11/20/18 6:19 PM, Arturo Borrero Gonzalez wrote: > On 11/15/18 5:58 PM, Arturo Borrero Gonzalez wrote: >> Hi, >> >> next Tuesday 2018-11-20 at 17:30 UTC we will be rebooting the OSM >> database (part of our data services) for maintenance and security updates. >>

Re: [Cloud] [Cloud-announce] OSM database reboot next Tuesday 2018-11-20 at 17:30 UTC

2018-11-20 Thread Arturo Borrero Gonzalez
On 11/15/18 5:58 PM, Arturo Borrero Gonzalez wrote: > Hi, > > next Tuesday 2018-11-20 at 17:30 UTC we will be rebooting the OSM > database (part of our data services) for maintenance and security updates. > > In concrete the labstore1006.eqiad.wmnet (osmdb.eqiad.wmnet) server

Re: [Cloud-announce] OSM database reboot next Tuesday 2018-11-20 at 17:30 UTC

2018-11-20 Thread Arturo Borrero Gonzalez
On 11/15/18 5:58 PM, Arturo Borrero Gonzalez wrote: > Hi, > > next Tuesday 2018-11-20 at 17:30 UTC we will be rebooting the OSM > database (part of our data services) for maintenance and security updates. > > In concrete the labstore1006.eqiad.wmnet (osmdb.eqiad.wmnet) server

Accepted nftlb 0.3-1 (source) into unstable

2018-11-20 Thread Arturo Borrero Gonzalez
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Format: 1.8 Date: Tue, 20 Nov 2018 11:09:33 +0100 Source: nftlb Binary: nftlb Architecture: source Version: 0.3-1 Distribution: unstable Urgency: medium Maintainer: Arturo Borrero Gonzalez Changed-By: Arturo Borrero Gonzalez Description: nftlb

Accepted iptables 1.8.2-2 (source) into unstable

2018-11-20 Thread Arturo Borrero Gonzalez
: unstable Urgency: medium Maintainer: Debian Netfilter Packaging Team Changed-By: Arturo Borrero Gonzalez Description: iptables - administration tools for packet filtering and NAT iptables-dev - transitional dummy package libip4tc-dev - Development files for libip4tc libip4tc0 - netfilter

Bug#914129: Report bug: Iptables on Sid

2018-11-19 Thread Arturo Borrero Gonzalez
On 11/19/18 6:30 PM, Daniel Pimentel wrote: >   > > Package: iptables > Version: v1.8.2 (legacy) > > After upgrade my Debian Sid I had problem with some packages like Docker that > use it as dependency. For example when I tried start docker: > > $ sudo systemctl start docker > It would be

Re: [Cloud-announce] Brief service interruption next Monday 2018-11-19 at 13:00 UTC

2018-11-19 Thread Arturo Borrero Gonzalez
On 11/15/18 2:03 PM, Arturo Borrero Gonzalez wrote: > Next monday 2018-11-19 we will be rebooting several Cloud VPS > infrastructure servers [0] for maintenance and security updates. > > This is just a simple reboot of servers and we don't expect any outage > or major interrup

Bug#913877: [pkg-netfilter-team] Bug#913877: iptables 1.8.2: ERROR when adding REJECT target to custom chains

2018-11-16 Thread Arturo Borrero Gonzalez
On 11/16/18 1:18 PM, Amos Jeffries wrote: > My kernel version is 3.16.0-4-amd64. > This kernel is very very old. First thing to do is to upgrade your kernel to something modern. Is not related to the hardware. Both x_tables and nf_tables kernel subsystem received severe updates since 3.16. By

Bug#913877: [pkg-netfilter-team] Bug#913877: iptables 1.8.2: ERROR when adding REJECT target to custom chains

2018-11-16 Thread Arturo Borrero Gonzalez
On 11/16/18 1:18 PM, Amos Jeffries wrote: > My kernel version is 3.16.0-4-amd64. > This kernel is very very old. First thing to do is to upgrade your kernel to something modern. Is not related to the hardware. Both x_tables and nf_tables kernel subsystem received severe updates since 3.16. By

Bug#913877: iptables 1.8.2: ERROR when adding REJECT target to custom chains

2018-11-16 Thread Arturo Borrero Gonzalez
Control: tag -1 unreproducible On Fri, 16 Nov 2018 23:20:02 +1300 Amos Jeffries wrote: > Followup experiments isolating the custom sub-chain are showing even > worse behaviour from the new iptables (-nft flavour). > > These commands > > iptables -N test-foo > iptables -I test-foo 1 -s

Bug#913877: iptables 1.8.2: ERROR when adding REJECT target to custom chains

2018-11-16 Thread Arturo Borrero Gonzalez
Control: tag -1 unreproducible On Fri, 16 Nov 2018 23:20:02 +1300 Amos Jeffries wrote: > Followup experiments isolating the custom sub-chain are showing even > worse behaviour from the new iptables (-nft flavour). > > These commands > > iptables -N test-foo > iptables -I test-foo 1 -s

Bug#913877: [pkg-netfilter-team] Bug#913877: (no subject)

2018-11-16 Thread Arturo Borrero Gonzalez
Control: forwarded -1 https://bugzilla.netfilter.org/show_bug.cgi?id=1298

Bug#913877: [pkg-netfilter-team] Bug#913877: (no subject)

2018-11-16 Thread Arturo Borrero Gonzalez
Control: forwarded -1 https://bugzilla.netfilter.org/show_bug.cgi?id=1298

Bug#913877: (no subject)

2018-11-16 Thread Arturo Borrero Gonzalez
Control: forwarded -1 https://bugzilla.netfilter.org/show_bug.cgi?id=1298

Bug#913877: (no subject)

2018-11-16 Thread Arturo Borrero Gonzalez
Control: forwarded -1 https://bugzilla.netfilter.org/show_bug.cgi?id=1298

Bug#913877: [pkg-netfilter-team] Bug#913877: iptables 1.8.2: ERROR when adding REJECT target to custom chains

2018-11-16 Thread Arturo Borrero Gonzalez
Control: forward -1 https://bugzilla.netfilter.org/show_bug.cgi?id=1298 Your bug report has been forwarded upstream.

Bug#913877: [pkg-netfilter-team] Bug#913877: iptables 1.8.2: ERROR when adding REJECT target to custom chains

2018-11-16 Thread Arturo Borrero Gonzalez
Control: forward -1 https://bugzilla.netfilter.org/show_bug.cgi?id=1298 Your bug report has been forwarded upstream.

[Cloud] [Cloud-announce] OSM database reboot next Tuesday 2018-11-20 at 17:30 UTC

2018-11-15 Thread Arturo Borrero Gonzalez
Hi, next Tuesday 2018-11-20 at 17:30 UTC we will be rebooting the OSM database (part of our data services) for maintenance and security updates. In concrete the labstore1006.eqiad.wmnet (osmdb.eqiad.wmnet) server will be rebooted. The other server in the cluster, labstore1007.eqiad.wmnet has

[Cloud-announce] OSM database reboot next Tuesday 2018-11-20 at 17:30 UTC

2018-11-15 Thread Arturo Borrero Gonzalez
Hi, next Tuesday 2018-11-20 at 17:30 UTC we will be rebooting the OSM database (part of our data services) for maintenance and security updates. In concrete the labstore1006.eqiad.wmnet (osmdb.eqiad.wmnet) server will be rebooted. The other server in the cluster, labstore1007.eqiad.wmnet has

[Cloud] [Cloud-announce] Brief service interruption next Monday 2018-11-19 at 13:00 UTC

2018-11-15 Thread Arturo Borrero Gonzalez
Next monday 2018-11-19 we will be rebooting several Cloud VPS infrastructure servers [0] for maintenance and security updates. This is just a simple reboot of servers and we don't expect any outage or major interruptions, but some services may be down briefly: * Horizon and Wikitech may

[Cloud-announce] Brief service interruption next Monday 2018-11-19 at 13:00 UTC

2018-11-15 Thread Arturo Borrero Gonzalez
Next monday 2018-11-19 we will be rebooting several Cloud VPS infrastructure servers [0] for maintenance and security updates. This is just a simple reboot of servers and we don't expect any outage or major interruptions, but some services may be down briefly: * Horizon and Wikitech may

Accepted iptables 1.8.2-1 (source) into unstable

2018-11-15 Thread Arturo Borrero Gonzalez
: unstable Urgency: medium Maintainer: Debian Netfilter Packaging Team Changed-By: Arturo Borrero Gonzalez Description: iptables - administration tools for packet filtering and NAT iptables-dev - transitional dummy package libip4tc-dev - Development files for libip4tc libip4tc0 - netfilter

Bug#913088: Bug forwarded upstream

2018-11-11 Thread Arturo Borrero Gonzalez
Control: forwarded -1 https://bugzilla.netfilter.org/show_bug.cgi?id=1292

Bug#913088: Bug forwarded upstream

2018-11-11 Thread Arturo Borrero Gonzalez
Control: forwarded -1 https://bugzilla.netfilter.org/show_bug.cgi?id=1292

Bug#770885: lightdm suspend issue with buster

2018-11-06 Thread Arturo Borrero Gonzalez
I just installed 2 different laptops with the Debian Buster installer (testing). Both are using XFCE+ligthdm+NVIDIA gforce (with driver from the nvidia-driver package). In both laptops, if I suspend the session and try to get it back (for example, by closing the laptop lid) all I will get is a

Bug#770885: lightdm suspend issue with buster

2018-11-06 Thread Arturo Borrero Gonzalez
I just installed 2 different laptops with the Debian Buster installer (testing). Both are using XFCE+ligthdm+NVIDIA gforce (with driver from the nvidia-driver package). In both laptops, if I suspend the session and try to get it back (for example, by closing the laptop lid) all I will get is a

Re: Bug#912977: iptables: nftables layer breaks ipsec/policy keyword

2018-11-06 Thread Arturo Borrero Gonzalez
Control: forwarded -1 https://bugzilla.netfilter.org/show_bug.cgi?id=1290 Hopefully next upstream release will contain a fix.

Bug#912977: iptables: nftables layer breaks ipsec/policy keyword

2018-11-06 Thread Arturo Borrero Gonzalez
Control: forwarded -1 https://bugzilla.netfilter.org/show_bug.cgi?id=1290 Hopefully next upstream release will contain a fix.

Bug#912977: iptables: nftables layer breaks ipsec/policy keyword

2018-11-06 Thread Arturo Borrero Gonzalez
Control: forwarded -1 https://bugzilla.netfilter.org/show_bug.cgi?id=1290 Hopefully next upstream release will contain a fix.

Bug#912607: rule for 0.0.0.0/8 is added as 0.0.0.0/0

2018-11-02 Thread Arturo Borrero Gonzalez
Control: forwarded -1 https://bugzilla.netfilter.org/show_bug.cgi?id=1287 On Thu, 1 Nov 2018 at 20:15, Thijs Kinkhorst wrote: > > Package: iptables > Version: 1.8.1-2 > Severity: important > > Hi, > > With iptables in sid, When specifying a rule for "0.0.0.0/8", it gets > added to the ruleset as

Bug#912610: [pkg-netfilter-team] Bug#912610: iptables/ip6tables -Z doesn't work with nf_tables variety of iptables

2018-11-02 Thread Arturo Borrero Gonzalez
Control: forwarded -1 https://bugzilla.netfilter.org/show_bug.cgi?id=1286 On Thu, 1 Nov 2018 at 21:51, Jamie Strandboge wrote: > > Can you advise if this is indeed a regression in 1.8 or is it intended > behavior? If intended behavior, I'll need to update ufw accordingly > (preliminary testing

Bug#912424: nouveau driver timeout with NVIDIA geforce MX150

2018-10-31 Thread Arturo Borrero Gonzalez
Source: linux Version: 4.18.10-2 Severity: normal Tags: upstream I just installed Debian Buster (testing) in a brand new Lenovo IdeaPad 520 laptop which includes a NVIDIA GeForce MX150 graphic card, using the nouveau driver, and there are some issues with it. First symptom is that f you close

Bug#912424: nouveau driver timeout with NVIDIA geforce MX150

2018-10-31 Thread Arturo Borrero Gonzalez
Source: linux Version: 4.18.10-2 Severity: normal Tags: upstream I just installed Debian Buster (testing) in a brand new Lenovo IdeaPad 520 laptop which includes a NVIDIA GeForce MX150 graphic card, using the nouveau driver, and there are some issues with it. First symptom is that f you close

Bug#911849: Try 1.8.1-2

2018-10-25 Thread Arturo Borrero Gonzalez
Control: fixed -1 1.8.1-2 Hi, please try with iptables 1.8.1-2 which I just uploaded. It includes some symlinks to handle this. Please close bug if solved with 1.8.1-2. thanks for the report! :-)

Bug#911849: Try 1.8.1-2

2018-10-25 Thread Arturo Borrero Gonzalez
Control: fixed -1 1.8.1-2 Hi, please try with iptables 1.8.1-2 which I just uploaded. It includes some symlinks to handle this. Please close bug if solved with 1.8.1-2. thanks for the report! :-)

Accepted iptables 1.8.1-2 (source amd64) into unstable

2018-10-25 Thread Arturo Borrero Gonzalez
: unstable Urgency: medium Maintainer: Debian Netfilter Packaging Team Changed-By: Arturo Borrero Gonzalez Description: iptables - administration tools for packet filtering and NAT iptables-dev - transitional dummy package libip4tc-dev - Development files for libip4tc libip4tc0 - netfilter

Bug#911777: [pkg-netfilter-team] Bug#911777: Bug#911777: iptables: ferm broken by changed path of iptables-restore

2018-10-25 Thread Arturo Borrero Gonzalez
On Thu, 25 Oct 2018 at 11:39, Chris Boot wrote: > > So, in this case, perhaps the proper fix is for ferm to don't hardcode > > binary paths. > > Perhaps, but in that case a list of broken packages is going to need to > be compiled, bugs filed against them, and (versioned) Breaks added to >

Bug#911777: [pkg-netfilter-team] Bug#911777: iptables: ferm broken by changed path of iptables-restore

2018-10-25 Thread Arturo Borrero Gonzalez
On Thu, 25 Oct 2018 at 01:18, Cesare Leonardi wrote: > > In the ferm case, it suffice to create the following two symlinks, to > make it start again: Thanks for reporting! I would really like to don't introduce such symlinks. iptables should really stop living in /sbin. So, in this case,

Bug#911777: [pkg-netfilter-team] Bug#911777: iptables: iptables-persistent broken by changed path of iptables-restore

2018-10-25 Thread Arturo Borrero Gonzalez
On Thu, 25 Oct 2018 at 02:30, Jon DeVree wrote: > > The iptables-persistent package was also broken by this change. > Thanks for reporting. Same as for ferm. I would really like stop seing iptables-related stuff on /sbin. Perhaps iptables-persistent should avoid harcoding binary paths.

Accepted iptables 1.8.1-1 (source amd64) into unstable

2018-10-24 Thread Arturo Borrero Gonzalez
: unstable Urgency: medium Maintainer: Debian Netfilter Packaging Team Changed-By: Arturo Borrero Gonzalez Description: iptables - administration tools for packet filtering and NAT iptables-dev - transitional dummy package libip4tc-dev - Development files for libip4tc libip4tc0 - netfilter

[PATCH iptables] old patch from Debian for iptables-apply

2018-10-24 Thread Arturo Borrero Gonzalez
and the other writes the sucessful rules file. I modified the script to use mktemp instead of tempfile. I also fixed a couple of hyphens in the man page addition. Signed-off-by: Laurence J. Lane Signed-off-by: Arturo Borrero Gonzalez --- iptables-apply | 310

[Cloud] [Cloud-announce] Ubuntu deprecation plans

2018-09-28 Thread Arturo Borrero Gonzalez
Hi! We would like to share some information regarding Wikimedia Cloud Services plans for deprecating Ubuntu, specially Trusty. Ubuntu Trusty's end-of-life is April 2019 and the WMF decided to consolidate in a single operating system, which is Debian. In Cloud VPS, projects containing Ubuntu

[Cloud-announce] Ubuntu deprecation plans

2018-09-28 Thread Arturo Borrero Gonzalez
Hi! We would like to share some information regarding Wikimedia Cloud Services plans for deprecating Ubuntu, specially Trusty. Ubuntu Trusty's end-of-life is April 2019 and the WMF decided to consolidate in a single operating system, which is Debian. In Cloud VPS, projects containing Ubuntu

<    1   2   3   4   5   6   7   8   9   10   >