aarch64 - netlink: Error: Could not process rule: No buffer space available
Steven Haigh <[email protected]> Wed, 4 Mar 2026 10:36:20 +1100
| Newsgroups | gmane.comp.security.firewalls.netfilter.general |
|---|---|
| Message-ID | <[email protected]> |
Hi all,
Firstly, please CC me in replies as I'm not subscribed to the list.
I am currently loading some named sets into nftables using the following
configuration:
set au-ipv4 {
type ipv4_addr
flags interval
auto-merge
elements = { $AU.ipv4 }
}
set au-ipv6 {
type ipv6_addr
flags interval
auto-merge
elements = { $AU.ipv6 }
}
These sets are loaded in the config via:
include "/etc/nftables/firewall/geo-nft/countrysets/AU.ipv4";
include "/etc/nftables/firewall/geo-nft/countrysets/AU.ipv6";
The files are created using the geo-nft.sh script here:
https://raw.githubusercontent.com/wirefalls/geo-nft/main/geo-nft.sh
When loading these, I get the following fatal error:
netlink: Error: Could not process rule: No buffer space available
This only seems to happen on the aarch64 installs. The same kernel
version + tools version on x86_64 architecture seems to load just fine.
$ cat /proc/version
Linux version 6.18.15-200.fc43.aarch64
(mockbuild@835a9c7eeabc46d3b99996c22f20c9cf) (gcc (GCC) 15.2.1 20260123
(Red Hat 15.2.1-7), GNU ld version 2.45.1-4.fc43) #1 SMP PREEMPT_DYNAMIC
Fri Feb 27 22:55:30 UTC 2026
$ nft --version
nftables v1.1.3 (Commodore Bullmoose #4)
I've had no success in hunting for why this would be the case.
I've found that I can batch-load the sets in ~500 rules at a time, and
the entire set will load - but including them at the nftables service
level always fails.
How should I fix this?
--
Steven Haigh
📧 [email protected]
💻 https://crc.id.au