Upstream: moby check-config.sh is wrong about iptables on kernels >= 6.4 #71

Open
opened 2026-08-30 11:38:49 +00:00 by tiagoagueda · 0 comments
Owner

Found while enabling Docker on this board, and it cost real time, so it is probably
worth reporting upstream.

The problem

moby/moby contrib/check-config.sh reports these as missing under Generally
Necessary
:

CONFIG_IP_NF_FILTER, CONFIG_IP_NF_MANGLE, CONFIG_IP_NF_RAW, CONFIG_IP_NF_NAT,
CONFIG_IP_NF_TARGET_MASQUERADE   (and the IP6 equivalents)

Since kernel 6.4 the legacy xtables backend was split out behind
CONFIG_NETFILTER_XTABLES_LEGACY, and every one of those symbols now carries
depends on IP_NF_IPTABLES_LEGACY, which in turn depends on
NETFILTER_XTABLES_LEGACY.

The failure mode is nasty. You set CONFIG_IP_NF_FILTER=y, run olddefconfig, and the
kernel silently drops it again because the dependency is unmet. check-config.sh
then reports exactly what it reported before, with no hint as to which symbol is
actually gating them. Here it took three rounds to find.

Meanwhile IP_NF_IPTABLES_LEGACY's own help text says:

This is not needed if you are using iptables over nftables (iptables-nft).

which is the default on Debian 13 and most current distributions. So for a large and
growing fraction of hosts the script demands options that are genuinely unnecessary,
while never naming the one symbol that would make them settable.

What a fix looks like

Either check NETFILTER_XTABLES_LEGACY first and explain the dependency, or detect the
iptables backend in use and check the nft symbols (NFT_COMPAT, NFT_NAT, NFT_MASQ,
NFT_FIB_*) instead when the host is on iptables-nft.

Local state

patches/configs/docker.config enables both paths deliberately, so this board is not
blocked on it. This issue is only about reporting it upstream.

Found while enabling Docker on this board, and it cost real time, so it is probably worth reporting upstream. ## The problem `moby/moby contrib/check-config.sh` reports these as missing under *Generally Necessary*: ``` CONFIG_IP_NF_FILTER, CONFIG_IP_NF_MANGLE, CONFIG_IP_NF_RAW, CONFIG_IP_NF_NAT, CONFIG_IP_NF_TARGET_MASQUERADE (and the IP6 equivalents) ``` Since kernel 6.4 the legacy xtables backend was split out behind `CONFIG_NETFILTER_XTABLES_LEGACY`, and every one of those symbols now carries `depends on IP_NF_IPTABLES_LEGACY`, which in turn depends on `NETFILTER_XTABLES_LEGACY`. The failure mode is nasty. You set `CONFIG_IP_NF_FILTER=y`, run `olddefconfig`, and the kernel **silently drops it again** because the dependency is unmet. `check-config.sh` then reports exactly what it reported before, with no hint as to which symbol is actually gating them. Here it took three rounds to find. Meanwhile `IP_NF_IPTABLES_LEGACY`'s own help text says: > This is not needed if you are using iptables over nftables (iptables-nft). which is the default on Debian 13 and most current distributions. So for a large and growing fraction of hosts the script demands options that are genuinely unnecessary, while never naming the one symbol that would make them settable. ## What a fix looks like Either check `NETFILTER_XTABLES_LEGACY` first and explain the dependency, or detect the iptables backend in use and check the nft symbols (`NFT_COMPAT`, `NFT_NAT`, `NFT_MASQ`, `NFT_FIB_*`) instead when the host is on iptables-nft. ## Local state `patches/configs/docker.config` enables both paths deliberately, so this board is not blocked on it. This issue is only about reporting it upstream.
Sign in to join this conversation.
No description provided.