Uploaded image for project: 'RHEL'
  1. RHEL
  2. RHEL-83068

Tweak iptables dependency on kernel-modules-extra

Linking RHIVOS CVEs to...Migration: Automation ...SWIFT: POC ConversionSync from "Extern...XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Done-Errata
    • Icon: Critical Critical
    • rhel-10.0
    • rhel-10.0
    • iptables
    • None
    • iptables-1.8.11-8.el10_0
    • No
    • Moderate
    • rhel-net-firewall
    • ssg_networking
    • 32
    • 5
    • QE ack, Dev ack
    • False
    • False
    • Hide

      None

      Show
      None
    • No
    • None
    • Approved Blocker
    • Unspecified Release Note Type - Unknown
    • Unspecified
    • Unspecified
    • Unspecified
    • All
    • None

      While testing Image Mode on aarch64, it was discovered that making kernel-modules-extra a dependency of iptables (see RHEL-65224) causes some unforeseen consequences.

      The details are in BIFROST-666, but essentially libvirt (specifically its nwfilter driver) depend on iptables, which in turn depends on kernel-modules-extra. However we have an additional kernel build available on aarch64, kernel-64k, and due to this dependency switching between the two results in libvirt getting uninstalled.

      More generally, depending on the kernel is not great when containers are involved.

      My suggestion is to turn the Requires into a Recommends, making it possible to avoid the installation of the additional package or at least to remove it after the fact; additionally, kernel-64k-modules-extra should explicitly be allowed to satisfy the dependency.

              egarver Eric Garver
              rhn-engineering-abologna Andrea Bolognani
              Eric Garver Eric Garver
              Tomas Dolezal Tomas Dolezal
              Votes:
              0 Vote for this issue
              Watchers:
              11 Start watching this issue

                Created:
                Updated:
                Resolved: