* [ANNOUNCE] call for testing of patch-o-matic-ng
@ 2004-02-25 18:28 Harald Welte
2004-02-25 19:31 ` rruegner
2004-02-29 10:11 ` [ANNOUNCE] call for testing of patch-o-matic-ng Willy TARREAU
0 siblings, 2 replies; 10+ messages in thread
From: Harald Welte @ 2004-02-25 18:28 UTC (permalink / raw)
To: Netfilter Development Mailinglist; +Cc: Netfilter Mailinglist
[-- Attachment #1: Type: text/plain, Size: 1498 bytes --]
Hi!
I've been trying to finish patch-o-matic-ng during the last week. At
least for 2.6.x kernels (specifically: 2.6.3) it seems to work just
fine. It doesn't offer you any patches that are incompatible with 2.6
or have not yet been ported.
However, more testing is definitely needed before an official release.
This is where you come in :) If you want to help, please grab the
latest patch-o-matic-ng, either from CVS or as snapshot. Do some
testing, especially with 2.4.x kernels.
If you end up in any strange behaviour (like .rej rejects in the kernel
tree, patches that apply cleanly but don't compile, patches that apply
and compile cleanly but crash the machine, ...) - please report it back
to the netfilter-devel mailinglist.
btw: It might be advisable to use ftp/www mirrors like
ftp.hu.netfilter.org / www.hu.netfilter.org , since tomorrow is a
scheduled downtime of the main netfilter site.
Thanks,
Harald.
p.s.: Yes, the nf_log patch does currently not apply against 2.6.x.
This is know, and not really a bug since it fails gracefully. Somebody
just needs to updat it.
--
- Harald Welte <laforge@netfilter.org> http://www.netfilter.org/
============================================================================
"Fragmentation is like classful addressing -- an interesting early
architectural error that shows how much experimentation was going
on while IP was being designed." -- Paul Vixie
[-- Attachment #2: Digital signature --]
[-- Type: application/pgp-signature, Size: 189 bytes --]
^ permalink raw reply [flat|nested] 10+ messages in thread
* Re: [ANNOUNCE] call for testing of patch-o-matic-ng
2004-02-25 18:28 [ANNOUNCE] call for testing of patch-o-matic-ng Harald Welte
@ 2004-02-25 19:31 ` rruegner
2004-02-25 20:28 ` Harald Welte
2004-02-29 10:11 ` [ANNOUNCE] call for testing of patch-o-matic-ng Willy TARREAU
1 sibling, 1 reply; 10+ messages in thread
From: rruegner @ 2004-02-25 19:31 UTC (permalink / raw)
To: Harald Welte, Netfilter Development Mailinglist; +Cc: Netfilter Mailinglist
Hi Harald,
do you mean something like this ?
fresh 2.6.3 kernel with patch-o-matic-ng-20040224
Welcome to Patch-o-matic (1.13)!
Kernel: /usr/src/linux
Iptables: /usr/src/iptables
Each patch is a new feature: many have minimal impact, some do not.
Almost every one has bugs, so don't apply what you don't need!
-------------------------------------------------------
Already applied:
Not all requirements fulfilled for quake3-conntrack-nat, skipping:
requirement 'linux < 2.6.0' not fulfilled
Excellent! Source trees are ready for compilation.
your rewrite seems to work , but the h323 which i could compile in the past
was rejected too
is this current state of art ?
Regards Robert
----- Original Message -----
From: "Harald Welte" <laforge@netfilter.org>
To: "Netfilter Development Mailinglist"
<netfilter-devel@lists.netfilter.org>
Cc: "Netfilter Mailinglist" <netfilter@lists.netfilter.org>
Sent: Wednesday, February 25, 2004 7:28 PM
Subject: [ANNOUNCE] call for testing of patch-o-matic-ng
^ permalink raw reply [flat|nested] 10+ messages in thread
* Re: [ANNOUNCE] call for testing of patch-o-matic-ng
2004-02-25 19:31 ` rruegner
@ 2004-02-25 20:28 ` Harald Welte
2004-02-26 16:00 ` RRuegner
0 siblings, 1 reply; 10+ messages in thread
From: Harald Welte @ 2004-02-25 20:28 UTC (permalink / raw)
To: rruegner; +Cc: Netfilter Development Mailinglist, Netfilter Mailinglist
[-- Attachment #1: Type: text/plain, Size: 869 bytes --]
On Wed, Feb 25, 2004 at 08:31:47PM +0100, rruegner wrote:
> Hi Harald,
>
> do you mean something like this ?
no.
> fresh 2.6.3 kernel with patch-o-matic-ng-20040224
as i stated in my original email, you will not be prompted for patches
that have not yet been ported.
> requirement 'linux < 2.6.0' not fulfilled
this clearly indicates that the quake3 patch is only available for
kernel 2.4.x
my main question was: Does pom-ng still work with 2.4.x kernels as
expected.
--
- Harald Welte <laforge@netfilter.org> http://www.netfilter.org/
============================================================================
"Fragmentation is like classful addressing -- an interesting early
architectural error that shows how much experimentation was going
on while IP was being designed." -- Paul Vixie
[-- Attachment #2: Digital signature --]
[-- Type: application/pgp-signature, Size: 189 bytes --]
^ permalink raw reply [flat|nested] 10+ messages in thread
* Re: [ANNOUNCE] call for testing of patch-o-matic-ng
2004-02-25 20:28 ` Harald Welte
@ 2004-02-26 16:00 ` RRuegner
2004-02-26 20:24 ` Henrik Nordstrom
2004-02-26 20:28 ` call for testing of patch-o-matic-ng tested with kernel 2.4.25 failed for h323 RRuegner
0 siblings, 2 replies; 10+ messages in thread
From: RRuegner @ 2004-02-26 16:00 UTC (permalink / raw)
To: Harald Welte, rruegner
Cc: Netfilter Development Mailinglist, Netfilter Mailinglist
Hi Harald,
i know your question, but where is the list which modules will fit to kernel
2.6.3, i have to setup a firewall machine and i wanna use 2.6.3 and want to
know which newnat will compile clean at now.
It would be nice to see a small info at the netfilter page
about that.
Alltough i understood pom ng as a special redesign
for the new kernel now i understand that this is only
a redesign of pom.
I know youre heavy buisy but do have the info i need?.
If there arent any nat mods compile clean to
2.6.3 i will switch back to 2.4 latest, and i will see what ng does to it.
Best Regards
----- Original Message -----
From: "Harald Welte" <laforge@netfilter.org>
To: "rruegner" <robowarp@gmx.de>
Cc: "Netfilter Development Mailinglist"
<netfilter-devel@lists.netfilter.org>; "Netfilter Mailinglist"
<netfilter@lists.netfilter.org>
Sent: Wednesday, February 25, 2004 9:28 PM
Subject: Re: [ANNOUNCE] call for testing of patch-o-matic-ng
^ permalink raw reply [flat|nested] 10+ messages in thread
* Re: [ANNOUNCE] call for testing of patch-o-matic-ng
2004-02-26 16:00 ` RRuegner
@ 2004-02-26 20:24 ` Henrik Nordstrom
2004-02-26 20:31 ` RRuegner
2004-02-26 20:28 ` call for testing of patch-o-matic-ng tested with kernel 2.4.25 failed for h323 RRuegner
1 sibling, 1 reply; 10+ messages in thread
From: Henrik Nordstrom @ 2004-02-26 20:24 UTC (permalink / raw)
To: RRuegner
Cc: Harald Welte, rruegner, Netfilter Development Mailinglist,
Netfilter Mailinglist
On Thu, 26 Feb 2004, RRuegner wrote:
> i know your question, but where is the list which modules will fit to kernel
> 2.6.3, i have to setup a firewall machine and i wanna use 2.6.3 and want to
> know which newnat will compile clean at now.
The goal is to have most modules ported to 2.6 when pom-ng is released I
think. The current state is not yet ready for public consumtion on 2.6 as
a lot porting efforts of the various extensions still remains.
> It would be nice to see a small info at the netfilter page about that.
Until it is ready for public consumtion there is little point in having
such page I think.
And with pom-ng properly including dependency and kernel revision checks I
am not realy convinced such page is required. If you ask it will apply
what can be applied to your kernel and tell what could not.
> Alltough i understood pom ng as a special redesign for the new kernel
> now i understand that this is only a redesign of pom.
Correct.
pom-ng is not a redesign for the new kernel, it is primary a redesign for
easier model of development and version management and at the same time
throwing in the ability to support multiple versions of the same extension
for different kernel versions.
The primary goal right now is to get pom-ng up to at least the same level
as pom is to make sure there is a stable foundation to work from allowing
the developers to forget about pom.
Secondary goal is to port as many extensions as possible to also support
2.6 but this is actually a separate project, only made practically
possible by the introduction of pom-ng. So for the 2.6 porting activity to
get up to speed the pom-ng framework must first be verified.
Regards
Henrik
^ permalink raw reply [flat|nested] 10+ messages in thread
* Re: [ANNOUNCE] call for testing of patch-o-matic-ng
2004-02-26 20:24 ` Henrik Nordstrom
@ 2004-02-26 20:31 ` RRuegner
0 siblings, 0 replies; 10+ messages in thread
From: RRuegner @ 2004-02-26 20:31 UTC (permalink / raw)
To: Henrik Nordstrom
Cc: Harald Welte, Netfilter Development Mailinglist,
Netfilter Mailinglist
Hi Henrik thx for statement
i looking more clear now.
Best Regards
----- Original Message -----
From: "Henrik Nordstrom" <hno@marasystems.com>
To: "RRuegner" <robert@ruegner.org>
Cc: "Harald Welte" <laforge@netfilter.org>; "rruegner" <robowarp@gmx.de>;
"Netfilter Development Mailinglist" <netfilter-devel@lists.netfilter.org>;
"Netfilter Mailinglist" <netfilter@lists.netfilter.org>
Sent: Thursday, February 26, 2004 9:24 PM
Subject: Re: [ANNOUNCE] call for testing of patch-o-matic-ng
> On Thu, 26 Feb 2004, RRuegner wrote:
>
> > i know your question, but where is the list which modules will fit to
kernel
> > 2.6.3, i have to setup a firewall machine and i wanna use 2.6.3 and want
to
> > know which newnat will compile clean at now.
>
> The goal is to have most modules ported to 2.6 when pom-ng is released I
> think. The current state is not yet ready for public consumtion on 2.6 as
> a lot porting efforts of the various extensions still remains.
>
> > It would be nice to see a small info at the netfilter page about that.
>
> Until it is ready for public consumtion there is little point in having
> such page I think.
>
> And with pom-ng properly including dependency and kernel revision checks I
> am not realy convinced such page is required. If you ask it will apply
> what can be applied to your kernel and tell what could not.
>
> > Alltough i understood pom ng as a special redesign for the new kernel
> > now i understand that this is only a redesign of pom.
>
> Correct.
>
> pom-ng is not a redesign for the new kernel, it is primary a redesign for
> easier model of development and version management and at the same time
> throwing in the ability to support multiple versions of the same extension
> for different kernel versions.
>
> The primary goal right now is to get pom-ng up to at least the same level
> as pom is to make sure there is a stable foundation to work from allowing
> the developers to forget about pom.
>
> Secondary goal is to port as many extensions as possible to also support
> 2.6 but this is actually a separate project, only made practically
> possible by the introduction of pom-ng. So for the 2.6 porting activity to
> get up to speed the pom-ng framework must first be verified.
>
> Regards
> Henrik
>
^ permalink raw reply [flat|nested] 10+ messages in thread
* call for testing of patch-o-matic-ng tested with kernel 2.4.25 failed for h323
2004-02-26 16:00 ` RRuegner
2004-02-26 20:24 ` Henrik Nordstrom
@ 2004-02-26 20:28 ` RRuegner
1 sibling, 0 replies; 10+ messages in thread
From: RRuegner @ 2004-02-26 20:28 UTC (permalink / raw)
To: Harald Welte; +Cc: Netfilter Development Mailinglist, Netfilter Mailinglist
Hi Harald,
the h323 pom ng patch failed for kernel 2.4.25 with same
failure message as to the 2.6.3 kernel in my machine
Regards
----- Original Message -----
From: "RRuegner" <robert@ruegner.org>
To: "Harald Welte" <laforge@netfilter.org>; "rruegner" <robowarp@gmx.de>
Cc: "Netfilter Development Mailinglist"
<netfilter-devel@lists.netfilter.org>; "Netfilter Mailinglist"
<netfilter@lists.netfilter.org>
Sent: Thursday, February 26, 2004 5:00 PM
Subject: Re: [ANNOUNCE] call for testing of patch-o-matic-ng
> Hi Harald,
> i know your question, but where is the list which modules will fit to
kernel
> 2.6.3, i have to setup a firewall machine and i wanna use 2.6.3 and want
to
> know which newnat will compile clean at now.
> It would be nice to see a small info at the netfilter page
> about that.
> Alltough i understood pom ng as a special redesign
> for the new kernel now i understand that this is only
> a redesign of pom.
> I know youre heavy buisy but do have the info i need?.
> If there arent any nat mods compile clean to
> 2.6.3 i will switch back to 2.4 latest, and i will see what ng does to
it.
> Best Regards
> ----- Original Message -----
> From: "Harald Welte" <laforge@netfilter.org>
> To: "rruegner" <robowarp@gmx.de>
> Cc: "Netfilter Development Mailinglist"
> <netfilter-devel@lists.netfilter.org>; "Netfilter Mailinglist"
> <netfilter@lists.netfilter.org>
> Sent: Wednesday, February 25, 2004 9:28 PM
> Subject: Re: [ANNOUNCE] call for testing of patch-o-matic-ng
>
>
>
^ permalink raw reply [flat|nested] 10+ messages in thread
* Re: [ANNOUNCE] call for testing of patch-o-matic-ng
2004-02-25 18:28 [ANNOUNCE] call for testing of patch-o-matic-ng Harald Welte
2004-02-25 19:31 ` rruegner
@ 2004-02-29 10:11 ` Willy TARREAU
2004-02-29 10:25 ` Henrik Nordstrom
2004-02-29 13:33 ` Harald Welte
1 sibling, 2 replies; 10+ messages in thread
From: Willy TARREAU @ 2004-02-29 10:11 UTC (permalink / raw)
To: Harald Welte, Netfilter Development Mailinglist,
Netfilter Mailinglist
Hi Harald,
Just tested it on top of 2.4.25, like this :
KERNEL_DIR=/usr/src/linux-2.4.25-pomng ./runme --batch extra
and I got a few problems :
- first, I didn't find how to specify where my iptables sources is
installed, so I had to enter it by hand each time I restarted it.
I did not find any env variable in the perl code, and I must say
that my understanding of perl is, hmmm.. very limited.
- ROUTE and TRACE told me :
"unable to find ladd slot in src /usr/src/linux-2.4.25-pomng/./net/ipv6/Makefile"
I think they wanted to add a line in the Makefile but didn't find
the right place to do so. BTW, is there a way to install a patch
only for ipv4 or for ipv6 like before ?
- I observed usual conflicts :
present 'CONNMARK' conflicts with to-be-installed 'connbytes'
present 'raw' conflicts with to-be-installed 'conntrack-seqfile'
present 'CONNMARK' conflicts with to-be-installed 'conntrack_arefcount'
- and finally, trying to apply conntrack_locking litterally killed my
box in out of memory within a few tens of seconds (I could not even
run ps) :
Out of Memory: Killed process 9841 (runme).
Out of Memory: Killed process 9970 (ps).
Out of Memory: Killed process 159 (bash).
Out of Memory: Killed process 158 (bash).
Since conntrack_locking needs conntrack_arefcount which could not
be applied, I wonder if there's some problem resolving dependancies.
I've not gone further yet.
Do you need more info ? There may be some things I did wrong, do not hesitate
to tell me ;-)
Cheers,
Willy
^ permalink raw reply [flat|nested] 10+ messages in thread* Re: [ANNOUNCE] call for testing of patch-o-matic-ng
2004-02-29 10:11 ` [ANNOUNCE] call for testing of patch-o-matic-ng Willy TARREAU
@ 2004-02-29 10:25 ` Henrik Nordstrom
2004-02-29 13:33 ` Harald Welte
1 sibling, 0 replies; 10+ messages in thread
From: Henrik Nordstrom @ 2004-02-29 10:25 UTC (permalink / raw)
To: Willy TARREAU
Cc: Harald Welte, Netfilter Development Mailinglist,
Netfilter Mailinglist
On Sun, 29 Feb 2004, Willy TARREAU wrote:
> - first, I didn't find how to specify where my iptables sources is
> installed, so I had to enter it by hand each time I restarted it.
> I did not find any env variable in the perl code, and I must say
> that my understanding of perl is, hmmm.. very limited.
There is a --path= option which can specify the path to both iptables and
the kernl.
> - ROUTE and TRACE told me :
> "unable to find ladd slot in src /usr/src/linux-2.4.25-pomng/./net/ipv6/Makefile"
> I think they wanted to add a line in the Makefile but didn't find
> the right place to do so. BTW, is there a way to install a patch
> only for ipv4 or for ipv6 like before ?
Please try with the large patch of .ladd files I posted on netfilter-devel
yesterday.
> - I observed usual conflicts :
> present 'CONNMARK' conflicts with to-be-installed 'connbytes'
> present 'raw' conflicts with to-be-installed 'conntrack-seqfile'
> present 'CONNMARK' conflicts with to-be-installed 'conntrack_arefcount'
Yes.
> - and finally, trying to apply conntrack_locking litterally killed my
> box in out of memory within a few tens of seconds (I could not even
> run ps) :
> Out of Memory: Killed process 9841 (runme).
> Out of Memory: Killed process 9970 (ps).
> Out of Memory: Killed process 159 (bash).
> Out of Memory: Killed process 158 (bash).
>
> Since conntrack_locking needs conntrack_arefcount which could not
> be applied, I wonder if there's some problem resolving dependancies.
Not unlikely.
Applying "extra" blindly is not recommended. There is reasons to why a
patch is in "extra", and many of these extensions conflict with each
other.
If you want patches from extra you better name the patches you want
explicily, after applying the base set.
Regards
Henrik
^ permalink raw reply [flat|nested] 10+ messages in thread
* Re: [ANNOUNCE] call for testing of patch-o-matic-ng
2004-02-29 10:11 ` [ANNOUNCE] call for testing of patch-o-matic-ng Willy TARREAU
2004-02-29 10:25 ` Henrik Nordstrom
@ 2004-02-29 13:33 ` Harald Welte
1 sibling, 0 replies; 10+ messages in thread
From: Harald Welte @ 2004-02-29 13:33 UTC (permalink / raw)
To: Willy TARREAU; +Cc: Netfilter Development Mailinglist, Netfilter Mailinglist
[-- Attachment #1: Type: text/plain, Size: 1968 bytes --]
On Sun, Feb 29, 2004 at 11:11:16AM +0100, Willy TARREAU wrote:
> Hi Harald,
>
> Just tested it on top of 2.4.25, like this :
>
> KERNEL_DIR=/usr/src/linux-2.4.25-pomng ./runme --batch extra
>
> and I got a few problems :
>
> - first, I didn't find how to specify where my iptables sources is
> installed, so I had to enter it by hand each time I restarted it.
> I did not find any env variable in the perl code, and I must say
> that my understanding of perl is, hmmm.. very limited.
I've now introduced the IPTABLES_DIR environment variable (or the
--iptables-path option)
> - ROUTE and TRACE told me :
> "unable to find ladd slot in src /usr/src/linux-2.4.25-pomng/./net/ipv6/Makefile"
> I think they wanted to add a line in the Makefile but didn't find
> the right place to do so.
Yes, indeed. They were in the wrong directory, should be fixed now.
> BTW, is there a way to install a patch only for ipv4 or for ipv6 like before ?
no.
> - I observed usual conflicts :
> present 'CONNMARK' conflicts with to-be-installed 'connbytes'
> present 'raw' conflicts with to-be-installed 'conntrack-seqfile'
> present 'CONNMARK' conflicts with to-be-installed 'conntrack_arefcount'
yes, that is normal and perfectly ok.
> - and finally, trying to apply conntrack_locking litterally killed my
> box in out of memory within a few tens of seconds (I could not even
> run ps) :
ouch. That needs to be fixed. I'll try to reproduce that.
> Cheers,
> Willy
Thanks for your testing so far.
--
- Harald Welte <laforge@netfilter.org> http://www.netfilter.org/
============================================================================
"Fragmentation is like classful addressing -- an interesting early
architectural error that shows how much experimentation was going
on while IP was being designed." -- Paul Vixie
[-- Attachment #2: Digital signature --]
[-- Type: application/pgp-signature, Size: 189 bytes --]
^ permalink raw reply [flat|nested] 10+ messages in thread
end of thread, other threads:[~2004-02-29 13:33 UTC | newest]
Thread overview: 10+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2004-02-25 18:28 [ANNOUNCE] call for testing of patch-o-matic-ng Harald Welte
2004-02-25 19:31 ` rruegner
2004-02-25 20:28 ` Harald Welte
2004-02-26 16:00 ` RRuegner
2004-02-26 20:24 ` Henrik Nordstrom
2004-02-26 20:31 ` RRuegner
2004-02-26 20:28 ` call for testing of patch-o-matic-ng tested with kernel 2.4.25 failed for h323 RRuegner
2004-02-29 10:11 ` [ANNOUNCE] call for testing of patch-o-matic-ng Willy TARREAU
2004-02-29 10:25 ` Henrik Nordstrom
2004-02-29 13:33 ` Harald Welte
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox