Overview

Request 1216681 review

Add patch for CVE-2024-9676 (bsc#1231698) (forwarded request 1216334 from danishprakash)

Loading...

Marcus Rueckert's avatar

that ipv6 change seems wrong.

shouldnt this change be in the netavark package and not in podman? podman can be run with other CNIs too no?


Dan Čermák's avatar
author source maintainer

No, CNI support has been deprecated & disabled with podman 5.0


Marcus Rueckert's avatar

well even then ... it is not podman which needs this module but netavark.


Danish Prakash's avatar

Podman and netavark both need this module to be loaded, for rootless and rootfull networking respectively. Adding it to netavark, even though technically correct, would be redundant because netavark is only consumed by podman.


Marcus Rueckert's avatar

actually a further discussion brought up a few more interesting points

  1. firewalld which is our default firewall solution is using nftables now by default
  2. the module you try to load there isnt actually used by nftables but by iptables.
  3. based on https://github.com/containers/netavark/pull/883 it looks like netavark could natively support nftables?

i just had the "fun" of debugging a machine where the main firewall was nftables, but docker in that case was still using iptables. for proper distro integration it would be better if we ensured that podman and netavark are using nftables as well. or at least us the iptables nft backend.


Request History
Dan Čermák's avatar

dancermak created request

Add patch for CVE-2024-9676 (bsc#1231698) (forwarded request 1216334 from danishprakash)


Saul Goodman's avatar

licensedigger accepted review

ok


Ana Guerrero's avatar

anag+factory set openSUSE:Factory:Staging:H as a staging project

Being evaluated by staging project "openSUSE:Factory:Staging:H"


Ana Guerrero's avatar

anag+factory staged request

Picked "openSUSE:Factory:Staging:H"


Factory Auto's avatar

factory-auto added opensuse-review-team as a reviewer

Please review sources


Factory Auto's avatar

factory-auto accepted review

Check script succeeded


Marcus Rueckert's avatar

darix accepted review

Accepted review for by_group opensuse-review-team request 1216681 from user factory-auto

openSUSE Build Service is sponsored by