OCP 4.3 (based on RHEL 8.1) pulled in a RHEL 8.2 iptables package a few months ago, but did not continue following updates to the 8.2 stream and pick up the fix for Bug #1845725. We ran into a customer environment that exhibited iptables-restore hangs due to the old iptables package in 4.3/8.1, which updating the package fixed. This updated package should be tagged into OCP 4.3 to fix the issue.
We should tag iptables-1.8.4-10.el8_2.1 into OCP 4.3 repos.
This is fixed everywhere after 4.3 because they are based on RHEL 8.2.
(In reply to Ben Bennett from comment #3) > This is fixed everywhere after 4.3 because they are based on RHEL 8.2. RHCOS 4.3 is also using RHEL 8.2. And the latest 4.3 build has `iptables-1.8.4-10.el8_2.1` included ``` $ curl -sL https://releases-rhcos-art.cloud.privileged.psi.redhat.com/storage/releases/rhcos-4.3/43.82.202010030253.0/x86_64/commitmeta.json | jq '.["rpmostree.rpmdb.pkglist"][] | select(.[0] | contains("iptables"))' [ "iptables", "0", "1.8.4", "10.el8_2.1", "x86_64" ] [ "iptables-libs", "0", "1.8.4", "10.el8_2.1", "x86_64" ] ```
Verified on 4.6.0-0.nightly-2020-10-01-155541 PRETTY_NAME="Red Hat Enterprise Linux CoreOS 46.82.202010010040-0 (Ootpa)" OSTREE_VERSION='46.82.202010010040-0' iptables-libs-1.8.4-10.el8_2.1.x86_64 iptables-1.8.4-10.el8_2.1.x86_64
Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory (OpenShift Container Platform 4.6 GA Images), and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. https://access.redhat.com/errata/RHBA-2020:4196