Re: Bugs in ebtables-restore extension presence checks and other, suggestion for /proc interface

Bart De Schuymer <[email protected]>
Newsgroups gmane.linux.network.bridge.ebtables.devel
Message-ID <[email protected]>
Op di, 11-09-2007 te 01:11 +0200, schreef Lech Perczak:
> Hi. I'm working on ebtables init script for Gentoo, and I've encountered
> 
> certain problems when trying to control it with ebtables-save and
> 
> ebtables-restore. I'm against using kernel modules on servers, routers
> and bridges, and therefore I've compiled complete ebtables inside the
> kernel. As ebtables-save was querying /proc/modules to get installed
> ebtables extensions, I've patched it to fallback to manual configuration
> when nothing is detected, and it works. But when I try to restore the
> rules and policies, ebtables-restore comes up with strange errors. For
> example, although broute table is enabled, when I try to tell
> ebtables-restore that this table is to be configured, it comes up with
> this message: "The kernel doesn't support a certain ebtables extension,
> consider recompiling your kernel or insmod the extension.". Sometimes I
> get same message not for broute, but for nat table. It was never
> encountered for filter table, like in here:
> 
> router ~ # ebtables-restore
> *filter
> :INPUT ACCEPT
> :FORWARD ACCEPT
> :OUTPUT ACCEPT
> 
> *nat
> :PREROUTING ACCEPT
> :OUTPUT ACCEPT
> :POSTROUTING ACCEPT
> 
> *broute
> The kernel doesn't support a certain ebtables extension, consider
> recompiling your kernel or insmod the extension.
> 
> 
> The next error, is when I try to restore particular rule (this one is
> connected with MAC SNAT - very common use) i get the following:
> 
> router ~ # ebtables-restore
> *filter
> :INPUT ACCEPT
> :FORWARD ACCEPT
> :OUTPUT ACCEPT
> *nat
> :PREROUTING ACCEPT
> :OUTPUT ACCEPT
> :POSTROUTING ACCEPT
> -A POSTROUTING -o wlan0 -j snat --to-src 0:50:fc:48:fb:9b --snat-target
> ACCEPT
> Ebtables: libebtc.c ebt_check_for_loops 1007 :Out of memory.
> 
> When setting this rule manually the bridge behaves as it should and the
> rule produces it's effect. But when I try to restore it it isn't
> written. I haven't any idea for more test cases, but after reading
> ebtables-restore.c I'm sure that these errors don't originate from
> ebtables-restore itself, moreover, the second error states libebtc.c. As
> I think many people don't like using any modules on bridges/routers or
> servers I came up with idea of creating /proc interface showing at least
> supported table names to get rid of manual configuration and/or grepping
> /proc/modules in either Gentoo and script supplied with your package,
> just like in iptables. Bart, What do you think about it?

Sounds good to me. I'll have a look at it after this weekend.
I'll try to reproduce your issue next week too, I can't quite grasp
it...

cheers,
Bart



-------------------------------------------------------------------------
This SF.net email is sponsored by: Microsoft
Defy all challenges. Microsoft(R) Visual Studio 2005.
http://clk.atdmt.com/MRT/go/vse0120000070mrt/direct/01/
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.