package/iptables: improve kernel support for iptables-legacy and iptables-nft

Since kernels 6.17, support for netfilter legacy tables were disabled
by default [1] but iptables package needs Netfilter legacy tables
support enabled in the kernel when nftables compat is not enabled.

Make sure to enable CONFIG_IP_NF_IPTABLES_LEGACY and
CONFIG_NETFILTER_XTABLES_LEGACY for kernels >= 6.17.

Fixes:

  [BRTEST# iptables --flush
  modprobe: module ip_tables not found in modules.dep
  iptables v1.8.11 (legacy): can't initialize iptables table `filter': Table does not exist (do you need to insmod?)
  Perhaps iptables or your kernel needs to be upgraded.

On the other hand, when nftables compat (iptables-nft) is used by
default (BR2_PACKAGE_IPTABLES_NFTABLES_DEFAULT=y) we have to enable
nft protocol support in the kernel.

  iptables --version
  iptables: Failed to initialize nft: Protocol not supported

Enable CONFIG_NF_TABLES and CONFIG_NF_TABLES_INET as for
NFTABLES_LINUX_CONFIG_FIXUPS and complete the list with
CONFIG_NFT_SOCKET needed to pass the TestIptables with
nftables compat (iptables-nft) enabled.

Without CONFIG_NFT_SOCKET:

  iptables --policy INPUT ACCEPT
  iptables v1.8.11 (nf_tables):  TABLE_ADD failed (Operation not supported): table filter

So, enable kernel support for iptables-legacy only if nftables compat
is not enabled by default. Enable iptables-nft support when nftables
compat is enabled, even if not used by default.

[1] https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?id=9fce66583f06c212e95e4b76dd61d8432ffa56b6

Signed-off-by: Romain Naour <romain.naour@smile.fr>
[Fiona: fix typo in commit message]
Signed-off-by: Fiona Klute <fiona.klute@gmx.de>
This commit is contained in:
Romain Naour
2026-06-24 14:51:52 +02:00
committed by Fiona Klute
parent c384895981
commit c57bcf0d43

View File

@@ -49,11 +49,33 @@ else
IPTABLES_CONF_OPTS += --disable-bpf-compiler --disable-nfsynproxy
endif
# Enable kernel support for iptables-nft even if nftables compat is not
# enabled by default.
ifeq ($(BR2_PACKAGE_IPTABLES_NFTABLES),y)
define IPTABLES_LINUX_CONFIG_FIXUPS_IPTABLES_NFT
$(call KCONFIG_ENABLE_OPT,CONFIG_NF_TABLES)
$(call KCONFIG_ENABLE_OPT,CONFIG_NF_TABLES_INET)
$(call KCONFIG_ENABLE_OPT,CONFIG_NFT_SOCKET)
endef
endif
# Enable kernel support for iptables-legacy only if nftables compat is not
# enabled by default.
ifeq ($(BR2_PACKAGE_IPTABLES_NFTABLES_DEFAULT),)
define IPTABLES_LINUX_CONFIG_FIXUPS_IPTABLES_LEGACY
# [for Linux kernel versions 6.17 and later]
$(call KCONFIG_ENABLE_OPT,CONFIG_IP_NF_IPTABLES_LEGACY)
$(call KCONFIG_ENABLE_OPT,CONFIG_NETFILTER_XTABLES_LEGACY)
endef
endif
define IPTABLES_LINUX_CONFIG_FIXUPS
$(call KCONFIG_ENABLE_OPT,CONFIG_IP_NF_IPTABLES)
$(call KCONFIG_ENABLE_OPT,CONFIG_IP_NF_FILTER)
$(call KCONFIG_ENABLE_OPT,CONFIG_NETFILTER)
$(call KCONFIG_ENABLE_OPT,CONFIG_NETFILTER_XTABLES)
$(IPTABLES_LINUX_CONFIG_FIXUPS_IPTABLES_LEGACY)
$(IPTABLES_LINUX_CONFIG_FIXUPS_IPTABLES_NFT)
endef
define IPTABLES_INSTALL_INIT_SYSV