- Package:
- src:arno-iptables-firewall
- Source:
- src:arno-iptables-firewall
- Submitter:
- Antonio Terceiro
- Date:
- 2026-08-23 15:11:01 UTC
- Severity:
- normal
- Tags:
Hi, Debian CI is switching away from lxc containers in favor of incus Containers. This is motivated by security concerns from us; incus is based on lxc, but orchestrates containers substantially different: containers are not privileged (so root in the container is not uid 0 outside of it, and incus imposes a stricter isolation from the host system. arno-iptables-firewall passes its tests under lxc, but fails under incus. The relevant part of the failure is (hopefully): The full autokpgtest logs are available at: https://ci.debian.net/experiments/8/regressions/ (please beware of pagination) Common types of failure and suggested fixes are being documented at: https://wiki.debian.org/ContinuousIntegration/LxcToIncus Note that for the time being, arno-iptables-firewall is still being tested under lxc to avoid disturbing its testing migration test results. If you decide to add the `isolation-machine` restriction to get this package tested under qemu, please mention that explicitly when closing this bug (it's fine to do that only in the package changelog entry that closes the bug) so that we can configure your package for qemu on ci.debian.net.
We believe that the bug you reported is fixed in the latest version of
arno-iptables-firewall, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to 1144768@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Sven Geuer <sge@debian.org> (supplier of updated arno-iptables-firewall package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Sat, 22 Aug 2026 17:40:20 +0200
Source: arno-iptables-firewall
Architecture: source
Version: 2.1.2a-5
Distribution: unstable
Urgency: medium
Maintainer: Debian Security Tools <team+pkg-security@tracker.debian.org>
Changed-By: Sven Geuer <sge@debian.org>
Closes: 1144768
Changes:
arno-iptables-firewall (2.1.2a-5) unstable; urgency=medium
.
* d/t/*:
- Drop meanwhile unneeded test 'implicit-directories'.
- Switch remaining test to 'isolation-machine' (Closes: #1144768).
arno-iptables-firewall configures netfilter modules, so accesses the
kernel in a way not available under incus-lxc.
Checksums-Sha1:
ba53100299d10383e49d83799223bee12783c1c1 2395 arno-iptables-firewall_2.1.2a-5.dsc
f71defe8612b4343123f4142a640ee9477468b08 60504 arno-iptables-firewall_2.1.2a-5.debian.tar.xz
2e918d24bf276971785a9c83242889e7598ec3ea 405636 arno-iptables-firewall_2.1.2a-5.git.tar.xz
aac454b972332496e39a3edf52e31b55dd38ecb7 17724 arno-iptables-firewall_2.1.2a-5_source.buildinfo
Checksums-Sha256:
5fbff7b3595eb35802cbf3d910751696eaa6fba12cc80bae256fa2140b41ca66 2395 arno-iptables-firewall_2.1.2a-5.dsc
c3668c8e3781262117cd0fb7982fb91a07760a9137299b6d0dcb1c7fc14ada9a 60504 arno-iptables-firewall_2.1.2a-5.debian.tar.xz
f173b0ff81d7f570fd7abb9c4d9586e663748229638c2c5609cccfab3852bb6c 405636 arno-iptables-firewall_2.1.2a-5.git.tar.xz
21e583671ab02d749673e9d8a065b544279c4889085a322e486a3351cb5e3784 17724 arno-iptables-firewall_2.1.2a-5_source.buildinfo
Files:
9120cd754db34ebcca26a43a94f3add5 2395 net optional arno-iptables-firewall_2.1.2a-5.dsc
dfea46acc85a4684ec1a9d74120e8c8a 60504 net optional arno-iptables-firewall_2.1.2a-5.debian.tar.xz
2f3715b8187128de794635e274a5e7b0 405636 net None arno-iptables-firewall_2.1.2a-5.git.tar.xz
3f1a0f59661c9b3fba456f6d76b4b512 17724 net optional arno-iptables-firewall_2.1.2a-5_source.buildinfo
Git-Tag-Info: tag=00f5689afb53f9596b6cf686a228783d8f996cf3 fp=3df5e8aa43fc9fdfd086f195adf50edaf8add585
Git-Tag-Tagger: Sven Geuer <sge@debian.org>
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEN02M5NuW6cvUwJcqYG0ITkaDwHkFAmqJxdEACgkQYG0ITkaD
wHkYpQ//XKeny0BLLq5JzUuA52I4fYGKy2mV5NZv1ftHJthO5B0a6dxknQ11PNTD
ngA8Aj4BV0VZQUdmRitFsq1DoMmrdosN+RanKtBsYpdrLII13t4A0KkrI83jOXi5
hd1Dvw54RqP0qEB02NH3Q2ElCXYLTL230cuCG0hpWC1AeFtG6UbSl2Ho/iMrNMp5
NWGp7uLd0yCxbQkA77FqxLCMR3dypfCmhLsBoEb6Fq7T1VOO4HvQR7R8DFrnn+Lm
iKisIyUMRpH0EKv0menIjRL3NwhZtT9bzn51NVjq8mhLYhIm/P2L70UWWgzAnj74
rJsV/GAsXaA78H0oCaMWvvLsABbSInNr65PoadWMbHdws7s3vpHxuEjJzM5LMeoi
zcozR2EjJ07/UYlk9RpXQrPqUOCyJZS5Wcjjz+RLeW815l9yKIOX4jv/Q3qxyO89
kzbyliqR4IaPnzsFgnzeCuzcEnIJ/BYoWfKm6X9rcTDkvb3GAoiJtcTwN9pK6X7F
mCGEv7I91fo/7gWxGxIvXiCWtqCGV9tnvs+7vNhBvNwQao154Ov+f2G4jmz8cFnH
o/LGlZlRov/KHcKvikyjG/iylC3Ol6sjcIJghHh200cLAJzJiXYQTtHE+X5n0bCD
L4xyHSEThCBVsFLHxSVQdxmImnswIy7fTbPfVeXOCmD+77kvFHw=
=ZApL
-----END PGP SIGNATURE-----
Hi Antonio,
Your statement above, let me assume, that tests will run automatically
under qemu, with this changelog entry
* d/t/*:
- Drop meanwhile unneeded test 'implicit-directories'.
- Switch remaining test to 'isolation-machine' (Closes: #1144768).
arno-iptables-firewall configures netfilter modules, so accesses the
kernel in a way not available under incus-lxc.
also visible in the message closing the bug [1].
Alas, tests for arno-iptables-firewall/2.1.2a-5 still has been run
under lxc [2].
Do you still need an explicit request on the debian-ci list to get
tests executed under qemu? Or are there tighter requirements on how to
phrase the need of applying qemu in a changelog entry?
Sven
[1] https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1144768#10
[2] https://ci.debian.net/packages/a/arno-iptables-firewall/testing/amd64/
Hi Sven,, It needs manual intervention. What I'm pretty sure of is that as Antonio is the submitter of the bug, he intends to read the changelog messages from bugs that are closed to spot the need for the intervention. So, I very much suspect this is a matter of ETOOSOON. I've done the work. Paul
Thanks a lot, Paul.