#5260 HIGH Never A: iptables or netfilter is missing critical features

Zarro Boogs per Child bugtracker at laptop.org
Sat Dec 1 23:25:00 EST 2007


#5260: iptables or netfilter is missing critical features
---------------------------+------------------------------------------------
 Reporter:  AlbertCahalan  |       Owner:  jg            
     Type:  defect         |      Status:  new           
 Priority:  high           |   Milestone:  Never Assigned
Component:  distro         |     Version:                
 Keywords:                 |    Verified:  0             
---------------------------+------------------------------------------------
 This is needed to implement the Bitfrost P_NETWORK feature.

 Most likely the kernel is missing some of the netfilter modules. IMHO it
 is very bad to skimp on netfilter modules; you never know what you may
 need. In any case, it looks like the "owner" and "reject" modules are
 missing. Probably they ought to be compiled into the kernel, as they are
 likely to be in use.

 Alternately, the userspace component has been pared down.

 Currently, the following command can not work:

 iptables -A OUTPUT -m owner --uid-owner 666 -m REJECT --reject-with icmp-
 admin-prohibited

-- 
Ticket URL: <http://dev.laptop.org/ticket/5260>
One Laptop Per Child <http://dev.laptop.org>
OLPC bug tracking system



More information about the Bugs mailing list