Bug 2310158 - Needs rebuild against iptables-libs-1.8.10-4
Summary: Needs rebuild against iptables-libs-1.8.10-4
Keywords:
Status: CLOSED ERRATA
Alias: None
Product: Fedora EPEL
Classification: Fedora
Component: iptables-epel
Version: epel9
Hardware: All
OS: Linux
unspecified
medium
Target Milestone: ---
Assignee: Michel Lind
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2024-09-05 08:49 UTC by Richard Fritsch
Modified: 2024-10-11 02:02 UTC (History)
14 users (show)

Fixed In Version: iptables-epel-1.8.10-5.1.el9.next iptables-epel-1.8.10-4.1.el9
Clone Of:
Environment:
Last Closed: 2024-10-11 01:41:35 UTC
Type: Bug
Embargoed:


Attachments (Terms of Use)
DNF log (904 bytes, text/plain)
2024-09-05 08:49 UTC, Richard Fritsch
no flags Details

Description Richard Fritsch 2024-09-05 08:49:07 UTC
Created attachment 2045491 [details]
DNF log

Description of problem:
The server update is blocked by the iptables-legacy requiring iptables-libs-1.8.10-2 and the iptables-libs itself being updatable to 1.8.10-4.

Version-Release number of selected component (if applicable):
1.8.10-2.2.el9

How reproducible:
Have iptables-libs 1.8.10-2.el9 installed along with iptables-legacy 1.8.10-2.2.el9. Update is then blocked.

Comment 1 jason.corley 2024-09-24 14:51:37 UTC
is there any way to raise this in priority? it should be a pretty simple rebuild against the latest version and the number of watchers on this bug indicate a fair amount of interest

Comment 2 Richard Fritsch 2024-09-25 11:36:29 UTC
Bug seems to be fixed at this point. Seems to be fixed by letting iptables-libs provide a lower version:

dnf repoquery --provides iptables-libs
Last metadata expiration check: 0:05:43 ago on Wed 25 Sep 2024 01:29:28 PM CEST.                                      
iptables-libs = 1.8.10-2.el9                 
iptables-libs = 1.8.10-4.el9_4                                                                                        
iptables-libs(x86-32) = 1.8.10-2.el9
iptables-libs(x86-32) = 1.8.10-4.el9_4                                                                                
iptables-libs(x86-64) = 1.8.10-2.el9                                                                                  
iptables-libs(x86-64) = 1.8.10-4.el9_4                   
[...]

Comment 3 jason.corley 2024-09-25 14:59:16 UTC
sadly as of this morning I'm not seeing the same updated provides in the UBI9 version of iptables-libs:

[root@f33af735ab8d /]# dnf repoquery --provides iptables-libs
Extra Packages for Enterprise Linux 9 - x86_64                                                                                                                           12 MB/s |  23 MB     00:01    
Red Hat Universal Base Image 9 (RPMs) - BaseOS                                                                                                                          1.3 MB/s | 524 kB     00:00    
Red Hat Universal Base Image 9 (RPMs) - AppStream                                                                                                                       8.3 MB/s | 2.1 MB     00:00    
Red Hat Universal Base Image 9 (RPMs) - CodeReady Builder                                                                                                               1.2 MB/s | 278 kB     00:00    
iptables-libs = 1.8.10-4.el9_4
iptables-libs(x86-32) = 1.8.10-4.el9_4
iptables-libs(x86-64) = 1.8.10-4.el9_4
... snipped ...

so I still think the proper solution would be a rebuild of the iptables-legacy package against the newer iptables-libs package(s)

Comment 4 Greg Bailey 2024-09-25 16:21:27 UTC
Not sure if this would help other users or not, but I had a legacy setup with /etc/sysconfig/iptables, and the "iptables-services" RPM that loads and saves these rules, and was also waiting for a fix to this bug.

I discovered that replacing:

* iptables-services
* iptables-legacy
* iptables-legacy-libs

with:

* iptables-nft-services
* iptables-nft

was sufficient to move to supported baseos and appstream RPMs and accomplish the same thing as the legacy iptables-services RPM, with no other configuration changes besides re-enabling the iptables service with "systemctl enable iptables".

Comment 5 Javier Salmeron 2024-10-01 10:05:43 UTC
Any chance this can be prioritized? It is blocking several upgrades.

Comment 6 Michel Lind 2024-10-01 14:31:02 UTC
PR welcome. It's been a busy month with conference travel, and since I manage a Stream fleet at work, not RHEL UBI, it is hard to otherwise prioritize issues like this

Comment 7 Matteo Brancaleoni 2024-10-01 15:05:24 UTC
(In reply to Michel Lind from comment #6)
> PR welcome. It's been a busy month with conference travel, and since I
> manage a Stream fleet at work, not RHEL UBI, it is hard to otherwise
> prioritize issues like this

I've sent a PR here: https://src.fedoraproject.org/rpms/iptables-epel/pull-request/3

Built locally with mock, tested ok.

Comment 8 Michel Lind 2024-10-01 16:18:20 UTC
Taking time off from PTO to do this

Comment 9 Fedora Update System 2024-10-02 02:37:36 UTC
FEDORA-EPEL-NEXT-2024-6734f8a3cf (iptables-epel-1.8.10-5.1.el9.next) has been submitted as an update to Fedora EPEL 9 Next.
https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-NEXT-2024-6734f8a3cf

Comment 10 Fedora Update System 2024-10-02 02:37:36 UTC
FEDORA-EPEL-2024-f377ada79a (iptables-epel-1.8.10-4.1.el9) has been submitted as an update to Fedora EPEL 9.
https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2024-f377ada79a

Comment 11 Fedora Update System 2024-10-03 03:48:32 UTC
FEDORA-EPEL-NEXT-2024-6734f8a3cf has been pushed to the Fedora EPEL 9 Next testing repository.

You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-NEXT-2024-6734f8a3cf

See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates.

Comment 12 Fedora Update System 2024-10-03 03:59:17 UTC
FEDORA-EPEL-2024-f377ada79a has been pushed to the Fedora EPEL 9 testing repository.

You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2024-f377ada79a

See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates.

Comment 13 Fedora Update System 2024-10-11 01:41:35 UTC
FEDORA-EPEL-NEXT-2024-6734f8a3cf (iptables-epel-1.8.10-5.1.el9.next) has been pushed to the Fedora EPEL 9 Next stable repository.
If problem still persists, please make note of it in this bug report.

Comment 14 Fedora Update System 2024-10-11 02:02:14 UTC
FEDORA-EPEL-2024-f377ada79a (iptables-epel-1.8.10-4.1.el9) has been pushed to the Fedora EPEL 9 stable repository.
If problem still persists, please make note of it in this bug report.


Note You need to log in before you can comment on or make changes to this bug.