Note: This is a beta release of Red Hat Bugzilla 5.0. The data contained within is a snapshot of the live data so any changes you make will not be reflected in the production Bugzilla. Also email is disabled so feel free to test any aspect of the site that you want. File any problems you find or give feedback here.
Bug 1520534 - iptables-services: restarting services unloads unrelated kernel modules
Summary: iptables-services: restarting services unloads unrelated kernel modules
Status: ON_QA
Alias: None
Product: Red Hat Enterprise Linux 7
Classification: Red Hat
Component: iptables
Version: 7.4
Hardware: Unspecified
OS: Unspecified
Target Milestone: rc
: ---
Assignee: Phil Sutter
QA Contact: Tomas Dolezal
Depends On:
TreeView+ depends on / blocked
Reported: 2017-12-04 16:25 UTC by Eric Garver
Modified: 2019-04-03 14:42 UTC (History)
6 users (show)

Fixed In Version: iptables-1.4.21-29.el7
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Last Closed:
Target Upstream Version:

Attachments (Terms of Use)

Description Eric Garver 2017-12-04 16:25:59 UTC
As reported in bug 1512575 when the iptables-services package is upgraded it will do a full restart and recursively unload kernel modules. This causes a problem for other packages that may be using those modules or modules that depend upon them.

  nf_conntrack.ko used by openvswitch.ko
  vport-geneve.ko used by openvswitch.ko
  geneve.ko used by vport-geneve.ko

iptables-services restart will attempt to recursively unload nf_conntrack and therefore also openvswitch, vport-geneve, geneve. This will cause openvswitch tunnels to go down.

iptables-services stop/restart should _not_ be unloading nf_conntrack and related kernel modules.

Comment 2 Phil Sutter 2017-12-12 16:12:14 UTC
The whole concept of unloading netfilter modules upon service restart seems futile to me. So far I heard two reasons for it being done:

1) Reset kernel state (esp. regarding conntrack).
2) Get conntrack out of fast path for increased performance.

Both aspects could be dealt with by either manually unloading modules (for users who know what they do) or a simple reload after disabling iptables (or configuring it into a stateless firewall).

Getting rid of module unloading altogether would also allow to drop previous workarounds for problems this caused (e.g. bug 1486803).

Comment 4 Phil Sutter 2018-05-07 10:36:05 UTC
Targeting at RHEL7.6 for now, including RHEL7.5 z-stream.

Comment 9 Phil Sutter 2019-03-15 18:29:12 UTC
Removing z-stream requests at least for now to prevent automatic ticket cloning.

Note You need to log in before you can comment on or make changes to this bug.