Bug 827919 - iptables-restore corrupts --log-prefix settings
iptables-restore corrupts --log-prefix settings
Status: CLOSED DUPLICATE of bug 825796
Product: Fedora
Classification: Fedora
Component: iptables (Show other bugs)
i686 Linux
unspecified Severity medium
: ---
: ---
Assigned To: Thomas Woerner
Fedora Extras Quality Assurance
Depends On:
  Show dependency treegraph
Reported: 2012-06-03 14:21 EDT by rambler8
Modified: 2012-06-30 16:54 EDT (History)
7 users (show)

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Last Closed: 2012-06-30 16:54:58 EDT
Type: Bug
Regression: ---
Mount Type: ---
Documentation: ---
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---

Attachments (Terms of Use)

  None (edit)
Description rambler8 2012-06-03 14:21:32 EDT
If an iptables rule uses the --log-prefix setting, the specified log-prefix is not used after saving and restarting, i.e.:

iptables-save > /etc/sysconfig/iptables
systemctl restart iptables.service

Instead the log prefix is set to "--log-prefix" rather than the configured value. 

Version-Release number of selected component (if applicable):

How reproducible:

Steps to Reproduce:
1. iptables -I INPUT -s -j LOG --log-prefix "From Example.com:"
2. iptables-save > /etc/sysconfig/iptables
3. systemctl restart iptables.service
4. iptables -L | grep ''

Actual results:
LOG all -- anywhere LOG level warning prefix "--log-prefix"

Expected results:
LOG all -- anywhere LOG level warning prefix "From Example.com:"

Additional Information:
After running iptables-save > /etc/sysconfig/iptables, the saved rule appears to be in the correct format, i.e.: 
-A INPUT -s -j LOG --log-prefix "From Example.com:"
Comment 1 Andrew Haveland-Robinson 2012-06-13 21:19:45 EDT
I've also just encountered this problem with iptables-

More information, after running:
iptables-restore < /etc/sysconfig/iptables

and running this:
iptables -S | grep log-prefix

I get this:

-A CHAIN1 -j LOG --log-prefix --lo --log-level 6
-A CHAIN2 -j LOG --log-prefix --lo --log-level 6
-A CHAIN3 -j LOG --log-prefix --log-prefi --log-level 6
-A CHAIN4 -j LOG --log-prefix --log-pref --log-level 6

Corresponding lines in /etc/sysconfig/iptables:
-A CHAIN1 -j LOG --log-prefix "VN: " --log-level 6
-A CHAIN2 -j LOG --log-prefix "ZA: " --log-level 6
-A CHAIN3 -j LOG --log-prefix "MAIL_BLOCK:" --log-level 6
-A CHAIN4 -j LOG --log-prefix "MAIL_DROP:" --log-level 6

This shouldn't be difficult to fix - the faulty prefix name has the correct length, but seems to fetching from the wrong buffer location.

Annoying - I have too many rules to replace manually.
Would it be possible to make --line-numbers work with -S and not just with the unprocessable -L directive?
This way, one can search and replace rules more easily using grep and cut.
Comment 2 Peter Wu 2012-06-25 14:09:09 EDT
What compiler versions are you using? Using Arch Linux and gcc 4.7.1 on iptables 1.4.14, I get the same error. If I build with -O0, the bug goes away. -O1 and -O2 are both affected.
Comment 3 Peter Wu 2012-06-25 16:43:00 EDT
Patch available on http://bugzilla.netfilter.org/show_bug.cgi?id=774
Comment 4 Michael Schwendt 2012-06-30 16:54:58 EDT

*** This bug has been marked as a duplicate of bug 825796 ***

Note You need to log in before you can comment on or make changes to this bug.