Bug 1820365

Summary: nftables documentation improvements for 'monitor' and 'describe'
Product: Red Hat Enterprise Linux 8 Reporter: Tomas Dolezal <todoleza>
Component: nftablesAssignee: Phil Sutter <psutter>
Status: CLOSED ERRATA QA Contact: Jiri Peska <jpeska>
Severity: low Docs Contact:
Priority: low    
Version: 8.2CC: jpeska, todoleza
Target Milestone: rcKeywords: ManPageChange, Triaged, Upstream
Target Release: 8.3   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard:
Fixed In Version: nftables-0.9.3-21.el8 Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of:
: 2003707 2020853 (view as bug list) Environment:
Last Closed: 2021-11-09 19:53:44 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On:    
Bug Blocks: 2020853    

Description Tomas Dolezal 2020-04-02 21:06:11 UTC
Description of problem:
There are missing descriptions and examples of what can be done using by following nft subcommands:
 * monitor: trace and possibly other so-called events
 * describe - general usage

Version-Release number of selected component (if applicable):
nftables-0.9.3-12.el8

How reproducible:
always

Steps to Reproduce:
--examples for describe command from CLI--
difference between tcp and udp in output
nft describe udp
Error: syntax error, unexpected newline, expecting length or checksum or sport or dport
describe udp
            ^
nft describe tcp
Error: syntax error, unexpected newline
describe tcp
            ^

it is not clear what kind of expressions can this command be used to describe.

Actual results:
secretive nft describe
nft monitor not fully described

Expected results:
manpage improvements, possibly also CLI error messages fixes

Additional info:
the whole CLI interface could use a revamp for help messages when there's something wrong/clearly missing in the arguments. that's out of scope for this bugreport
bugreport base on bug 1782526#c2

Comment 2 Phil Sutter 2021-05-19 11:32:42 UTC
Patch to describe 'nft monitor trace' sent upstream:
https://lore.kernel.org/netfilter-devel/20210519112913.9238-1-phil@nwl.cc/

'nft describe' command is already there in nft.8, albeit a bit hidden: Search
for 'DESCRIBE COMMAND'. You have to pass either an expression or a data type.
'tcp' or 'udp' are neither. The different error messages stem from yacc trying
to parse the input and falling into different cases.

Comment 3 Phil Sutter 2021-05-19 16:05:45 UTC
Upstream commit to backport:

commit 2acf8b2caea19d8abd46d475a908f8d6afb33aa0
Author: Phil Sutter <phil>
Date:   Wed May 19 13:12:48 2021 +0200

    doc: nft.8: Extend monitor description by trace
    
    Briefly describe 'nft monitor trace' command functionality.
    
    Signed-off-by: Phil Sutter <phil>

Comment 12 errata-xmlrpc 2021-11-09 19:53:44 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory (nftables bug fix and enhancement update), and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://access.redhat.com/errata/RHBA-2021:4465