FS#49597 - [nftables] core dumps if "ip protocol gre accept" is used

Attached to Project: Arch Linux
Opened by Deon Spengler (deons) - Tuesday, 07 June 2016, 06:21 GMT
Last edited by Sébastien Luttringer (seblu) - Saturday, 18 June 2016, 01:21 GMT
Task Type Bug Report
Category Upstream Bugs
Status Closed
Assigned To Sébastien Luttringer (seblu)
Architecture x86_64
Severity Medium
Priority Normal
Reported Version
Due in Version Undecided
Due Date Undecided
Percent Complete 100%
Votes 1
Private No

Details

Since update to nftables 1:0.6-1 nft core dumps. I have managed to track down the line in my config that seems to be causing the issue, if I remove the following then all works fine. "ip protocol gre accept"

I have attached my config for nftables. Reverting back to version nftables-1:0.5-2 solves the problem for now.

Jun 07 08:00:28 shadowblade systemd-coredump[11950]: Process 11947 (nft) of user 0 dumped core.
Stack trace of thread 11947:
#0 0x0000000000412235 n/a (nft)
#1 0x000000000040fb57 n/a (nft)
#2 0x000000000040e0fc n/a (nft)
#3 0x0000000000411497 n/a (nft)
#4 0x0000000000411657 n/a (nft)
#5 0x0000000000411e1f n/a (nft)
#6 0x000000000042b0fd n/a (nft)
#7 0x0000000000406bfa n/a (nft)
#8 0x00000000004067db n/a (nft)
#9 0x00007f1892413741 __libc_start_main (libc.so.6)
#10 0x0000000000406af9 n/a (nft)
-- Subject: Process 11947 (nft) dumped core

This task depends upon

Closed by  Sébastien Luttringer (seblu)
Saturday, 18 June 2016, 01:21 GMT
Reason for closing:  Fixed
Additional comments about closing:  1:0.6-2
Comment by Deon Spengler (deons) - Tuesday, 07 June 2016, 06:25 GMT
Here is the config
Comment by Deon Spengler (deons) - Tuesday, 07 June 2016, 06:34 GMT
I saw now that it was filed as a bug upstream https://bugzilla.netfilter.org/show_bug.cgi?id=1072
There is also a patch available that fixes the issue. http://git.netfilter.org/nftables/commit/?id=3503738f77cdbe521da1054a37f59ac2e442b4cf
Comment by Deon Spengler (deons) - Tuesday, 07 June 2016, 06:55 GMT
Can confirm using the patch from upstream solves the problem
Comment by Deon Spengler (deons) - Tuesday, 07 June 2016, 16:49 GMT
Can confirm using the patch from upstream solves the problem
Comment by Deon Spengler (deons) - Tuesday, 07 June 2016, 16:51 GMT

Loading...