Bug 1590589 - Builds fail due to iptables lock 'iptables-restore: exit status 4'
Summary: Builds fail due to iptables lock 'iptables-restore: exit status 4'
Keywords:
Status: CLOSED DUPLICATE of bug 1734009
Alias: None
Product: OpenShift Container Platform
Classification: Red Hat
Component: Networking
Version: 3.11.0
Hardware: All
OS: Linux
urgent
urgent
Target Milestone: ---
: 3.11.z
Assignee: Casey Callendrello
QA Contact: zhaozhanqi
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2018-06-13 00:47 UTC by emahoney
Modified: 2023-10-06 17:49 UTC (History)
25 users (show)

Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Environment:
Last Closed: 2019-09-26 20:31:57 UTC
Target Upstream Version:
Embargoed:


Attachments (Terms of Use)

Description emahoney 2018-06-13 00:47:22 UTC
Description of problem: Facing issues where builds are failing due to iptables lock:

~~~
Jun 12 19:18:42 opennode-66-40.hosted.a3.vary.redhat.com atomic-openshift-node[10569]: E0612 19:18:42.463911   10569 kubelet_pods.go:1121] Failed killing the pod "dashing-33-deploy": failed to "KillPodSandbox" for "1ea67f12-6e75-11e8-9c50-0a979bbb7299" with KillPodSandboxError: "rpc error: code = Unknown desc = NetworkPlugin cni failed to teardown pod \"dashing-33-deploy_it-marketing\" network: CNI request failed with status 400: 'Failed to execute iptables-restore: exit status 4 (Another app is currently holding the xtables lock. Perhaps you want to use the -w option?\n)\n'"
~~~

This looks quite a bit like a regression of the BZ below:

    https://bugzilla.redhat.com/show_bug.cgi?id=1514627


Version-Release number of selected component (if applicable):
atomic-openshift-3.9.30-1.git.0.dec1ba7.el7.x86_64          
atomic-openshift-node-3.9.30-1.git.0.dec1ba7.el7.x86_64     
iptables-1.4.21-24.1.el7_5.x86_64
kernel-3.10.0-862.el7.x86_64

How reproducible: Have not been able to reproduce in lab. 


Steps to Reproduce:
1.n/a
2.
3.

Actual results: Builds are failing due to iptables lock. 


Expected results: Builds succeed. 


Additional info:

Comment 9 contact+rhelbugzilla 2018-07-16 14:56:48 UTC
If this is caused by running `iptables-restore --table=$TABLE` or `ip6tables-restore --table=$TABLE` it may be https://bugzilla.netfilter.org/show_bug.cgi?id=1271, which has a patch fixing the bug.

Comment 63 Eric Rich 2019-03-26 15:21:17 UTC
https://bugzilla.redhat.com/show_bug.cgi?id=1673305 may be a duplicate bug of this issue.

Comment 71 Ryan Howe 2019-09-26 20:31:57 UTC

*** This bug has been marked as a duplicate of bug 1734009 ***

Comment 72 Red Hat Bugzilla 2023-09-15 00:09:58 UTC
The needinfo request[s] on this closed bug have been removed as they have been unresolved for 500 days


Note You need to log in before you can comment on or make changes to this bug.