Repository navigation
Conversation
Wescoeur
added a commit
that referenced
this pull request
Sep 30, 2026
We must verify specific iptables code to ensure we don't ignore a problem somewhere. Note: this change is important for XCP-ng 9, for previous releases we don't use a recent iptables version which have error code 4 (busy lock) for example. Signed-off-by: Ronan Abhamon <ronan.abhamon@vates.tech>
Wescoeur
added a commit
that referenced
this pull request
Sep 30, 2026
Without this fix, we have a risk that the default firewall input chain is partially created in case of crash, or temporary issue. With this change, the rule is always checked when ports need to be opened. Signed-off-by: Ronan Abhamon <ronan.abhamon@vates.tech>
Wescoeur
force-pushed
the
ran-robustify-iptables
branch
from
September 30, 2026 18:26
1a5de84 to
2c6872d
Compare
Merged
Kuruyia
reviewed
Oct 1, 2026
Wescoeur
added a commit
that referenced
this pull request
Oct 1, 2026
We must verify specific iptables code to ensure we don't ignore a problem somewhere. Note: this change is important for XCP-ng 9, for previous releases we don't use a recent iptables version which have error code 4 (busy lock) for example. Signed-off-by: Ronan Abhamon <ronan.abhamon@vates.tech>
Wescoeur
added a commit
that referenced
this pull request
Oct 1, 2026
Without this fix, we have a risk that the default firewall input chain is partially created in case of crash, or temporary issue. With this change, the rule is always checked when ports need to be opened. Signed-off-by: Ronan Abhamon <ronan.abhamon@vates.tech>
Wescoeur
added a commit
that referenced
this pull request
Oct 1, 2026
Signed-off-by: Ronan Abhamon <ronan.abhamon@vates.tech>
Wescoeur
force-pushed
the
ran-robustify-iptables
branch
from
October 1, 2026 19:50
2c6872d to
13b7f7f
Compare
Wescoeur
added a commit
that referenced
this pull request
Oct 1, 2026
Signed-off-by: Ronan Abhamon <ronan.abhamon@vates.tech>
Wescoeur
force-pushed
the
ran-robustify-iptables
branch
from
October 1, 2026 19:55
13b7f7f to
ece82e8
Compare
Wescoeur
added a commit
that referenced
this pull request
Oct 1, 2026
Signed-off-by: Ronan Abhamon <ronan.abhamon@vates.tech>
Wescoeur
force-pushed
the
ran-robustify-iptables
branch
from
October 1, 2026 19:59
ece82e8 to
5a28510
Compare
Kuruyia
approved these changes
Oct 2, 2026
Wescoeur
added a commit
that referenced
this pull request
Oct 2, 2026
Signed-off-by: Ronan Abhamon <ronan.abhamon@vates.tech>
Wescoeur
added a commit
that referenced
this pull request
Oct 2, 2026
Signed-off-by: Ronan Abhamon <ronan.abhamon@vates.tech>
Wescoeur
force-pushed
the
ran-robustify-iptables
branch
from
October 2, 2026 10:18
b463ce3 to
16c6e30
Compare
Wescoeur
added a commit
that referenced
this pull request
Oct 2, 2026
Signed-off-by: Ronan Abhamon <ronan.abhamon@vates.tech>
Wescoeur
force-pushed
the
ran-robustify-iptables
branch
from
October 2, 2026 10:19
16c6e30 to
aac27b1
Compare
Member
Author
|
I added a new commit to test |
We must verify specific iptables code to ensure we don't ignore a problem somewhere. Note: this change is important for XCP-ng 9, for previous releases we don't use a recent iptables version which have error code 4 (busy lock) for example. Signed-off-by: Ronan Abhamon <ronan.abhamon@vates.tech>
Without this fix, we have a risk that the default firewall input chain is partially created in case of crash, or temporary issue. With this change, the rule is always checked when ports need to be opened. Signed-off-by: Ronan Abhamon <ronan.abhamon@vates.tech>
Wescoeur
added a commit
that referenced
this pull request
Oct 2, 2026
Signed-off-by: Ronan Abhamon <ronan.abhamon@vates.tech>
Wescoeur
added a commit
that referenced
this pull request
Oct 2, 2026
Signed-off-by: Ronan Abhamon <ronan.abhamon@vates.tech>
Wescoeur
force-pushed
the
ran-robustify-iptables
branch
from
October 2, 2026 16:36
aac27b1 to
c397411
Compare
Wescoeur
added a commit
that referenced
this pull request
Oct 7, 2026
Signed-off-by: Ronan Abhamon <ronan.abhamon@vates.tech>
Wescoeur
added a commit
that referenced
this pull request
Oct 7, 2026
Executables were run through hardcoded absolute paths, it only works on some distributions. `ss` is in `/usr/bin` on the GitHub Ubuntu runners, instead of in `/usr/sbin` on XCP-ng so the LINSTOR controller tests are marked as failed. Now "/etc/os-release" is used to find alternate OS specific paths instead. Signed-off-by: Ronan Abhamon <ronan.abhamon@vates.tech>
Signed-off-by: Ronan Abhamon <ronan.abhamon@vates.tech>
Signed-off-by: Ronan Abhamon <ronan.abhamon@vates.tech>
Wescoeur
force-pushed
the
ran-robustify-iptables
branch
from
October 7, 2026 23:26
c397411 to
3555e43
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Add 4 commits:
Note: this change is important for XCP-ng 9, for previous releases we don't use a recent iptables version which have error code 4 (busy lock) for example.
update_iptables_tcp_port_range!