From c57bcf0d4352bf53edf436522918bbb3e75b43ec Mon Sep 17 00:00:00 2001 From: Romain Naour Date: Wed, 24 Jun 2026 14:51:52 +0200 Subject: [PATCH] package/iptables: improve kernel support for iptables-legacy and iptables-nft Since kernels 6.17, support for netfilter legacy tables were disabled by default [1] but iptables package needs Netfilter legacy tables support enabled in the kernel when nftables compat is not enabled. Make sure to enable CONFIG_IP_NF_IPTABLES_LEGACY and CONFIG_NETFILTER_XTABLES_LEGACY for kernels >= 6.17. Fixes: [BRTEST# iptables --flush modprobe: module ip_tables not found in modules.dep iptables v1.8.11 (legacy): can't initialize iptables table `filter': Table does not exist (do you need to insmod?) Perhaps iptables or your kernel needs to be upgraded. On the other hand, when nftables compat (iptables-nft) is used by default (BR2_PACKAGE_IPTABLES_NFTABLES_DEFAULT=y) we have to enable nft protocol support in the kernel. iptables --version iptables: Failed to initialize nft: Protocol not supported Enable CONFIG_NF_TABLES and CONFIG_NF_TABLES_INET as for NFTABLES_LINUX_CONFIG_FIXUPS and complete the list with CONFIG_NFT_SOCKET needed to pass the TestIptables with nftables compat (iptables-nft) enabled. Without CONFIG_NFT_SOCKET: iptables --policy INPUT ACCEPT iptables v1.8.11 (nf_tables): TABLE_ADD failed (Operation not supported): table filter So, enable kernel support for iptables-legacy only if nftables compat is not enabled by default. Enable iptables-nft support when nftables compat is enabled, even if not used by default. [1] https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?id=9fce66583f06c212e95e4b76dd61d8432ffa56b6 Signed-off-by: Romain Naour [Fiona: fix typo in commit message] Signed-off-by: Fiona Klute --- package/iptables/iptables.mk | 22 ++++++++++++++++++++++ 1 file changed, 22 insertions(+) diff --git a/package/iptables/iptables.mk b/package/iptables/iptables.mk index a9d912f6cc..bb01c07a43 100644 --- a/package/iptables/iptables.mk +++ b/package/iptables/iptables.mk @@ -49,11 +49,33 @@ else IPTABLES_CONF_OPTS += --disable-bpf-compiler --disable-nfsynproxy endif +# Enable kernel support for iptables-nft even if nftables compat is not +# enabled by default. +ifeq ($(BR2_PACKAGE_IPTABLES_NFTABLES),y) +define IPTABLES_LINUX_CONFIG_FIXUPS_IPTABLES_NFT + $(call KCONFIG_ENABLE_OPT,CONFIG_NF_TABLES) + $(call KCONFIG_ENABLE_OPT,CONFIG_NF_TABLES_INET) + $(call KCONFIG_ENABLE_OPT,CONFIG_NFT_SOCKET) +endef +endif + +# Enable kernel support for iptables-legacy only if nftables compat is not +# enabled by default. +ifeq ($(BR2_PACKAGE_IPTABLES_NFTABLES_DEFAULT),) +define IPTABLES_LINUX_CONFIG_FIXUPS_IPTABLES_LEGACY + # [for Linux kernel versions 6.17 and later] + $(call KCONFIG_ENABLE_OPT,CONFIG_IP_NF_IPTABLES_LEGACY) + $(call KCONFIG_ENABLE_OPT,CONFIG_NETFILTER_XTABLES_LEGACY) +endef +endif + define IPTABLES_LINUX_CONFIG_FIXUPS $(call KCONFIG_ENABLE_OPT,CONFIG_IP_NF_IPTABLES) $(call KCONFIG_ENABLE_OPT,CONFIG_IP_NF_FILTER) $(call KCONFIG_ENABLE_OPT,CONFIG_NETFILTER) $(call KCONFIG_ENABLE_OPT,CONFIG_NETFILTER_XTABLES) + $(IPTABLES_LINUX_CONFIG_FIXUPS_IPTABLES_LEGACY) + $(IPTABLES_LINUX_CONFIG_FIXUPS_IPTABLES_NFT) endef define IPTABLES_INSTALL_INIT_SYSV