|
From: Friedrich L. <fl...@fl...> - 2004-04-06 23:51:14
|
Hi! I just fixed the patch-o-matic in the 1.0.x series. If you are now having troubles in the kernel compile stage, what you will hopefully not have, then please back out this patch and contact me. Here the log message: linux:~/devil-linux/lfssystem/data/build/scripts # cvs log -r1.8.2.1 patch-o-matic RCS file: /cvsroot/devil-linux/build/scripts/patch-o-matic,v Working file: patch-o-matic [...] description: ---------------------------- revision 1.8.2.1 date: 2004/04/06 23:33:59; author: friedl; state: Exp; lines: +23 -11 While searching why the pptp netfilter connection tracking modul disappeared somewhere in the 1.0.x series, I discovered that the netfilter patch-o-matic patches fail already pretty soon in their patch process. This is now corrected. Hopefully we are not introducing some problems because certain netfilter modules that should have been there, are now really there. In case there are troubles mail fl...@fl... ============================================================================= -- MfG / Regards Friedrich Lobenstock ____________________________________________________________________ Friedrich Lobenstock Linux Services Lobenstock URL: http://www.lsl.at/ Email: fl...@fl... ____________________________________________________________________ |
|
From: Friedrich L. <fl...@fl...> - 2004-04-09 15:04:11
|
Friedrich Lobenstock wrote on 07.04.2004 01:51 MET: > > I just fixed the patch-o-matic in the 1.0.x series. If you are now > having troubles in the kernel compile stage, what you will hopefully not > have, then please back out this patch and contact me. > After testing with a freshly compiled 1.0.6beta it all looks good but the PPTP NAT- and connection-tracking modules do kill the machine when the PPTP session is closed down normally by the originating host behind the firewall. In contrast the H.323 NAT- and connection-tracking modules seem to work fine. -- MfG / Regards Friedrich Lobenstock ____________________________________________________________________ Friedrich Lobenstock Linux Services Lobenstock URL: http://www.lsl.at/ Email: fl...@fl... ____________________________________________________________________ |
|
From: Heiko Z. <he...@zu...> - 2004-04-09 15:26:20
|
> Friedrich Lobenstock wrote on 07.04.2004 01:51 MET: >> >> I just fixed the patch-o-matic in the 1.0.x series. If you are now >> having troubles in the kernel compile stage, what you will hopefully not >> have, then please back out this patch and contact me. >> > > After testing with a freshly compiled 1.0.6beta it all looks good but the > PPTP NAT- and connection-tracking modules do kill the machine when the > PPTP > session is closed down normally by the originating host behind the > firewall. > > In contrast the H.323 NAT- and connection-tracking modules seem to work > fine. Try using the latest POM snapshot. My test compile with it for 1.1.x is still running... -- Regards Heiko Zuerker http://www.devil-linux.org |
|
From: Friedrich L. <fl...@fl...> - 2004-04-09 15:34:04
|
Heiko Zuerker wrote on 09.04.2004 17:21 MET: >>Friedrich Lobenstock wrote on 07.04.2004 01:51 MET: >> >>>I just fixed the patch-o-matic in the 1.0.x series. If you are now >>>having troubles in the kernel compile stage, what you will hopefully not >>>have, then please back out this patch and contact me. >>> >> >>After testing with a freshly compiled 1.0.6beta it all looks good but the >>PPTP NAT- and connection-tracking modules do kill the machine when the >>PPTP >>session is closed down normally by the originating host behind the >>firewall. >> >>In contrast the H.323 NAT- and connection-tracking modules seem to work >>fine. > > > Try using the latest POM snapshot. Ok, I will do that. > My test compile with it for 1.1.x is still running... BTW the module dependencies were not correct on my 1.0.6beta. I had to load the extra modules with insmod and absolute path as modprobe would not find them. Do you know right away what could be the problem here? Where should I look for that? -- MfG / Regards Friedrich Lobenstock ____________________________________________________________________ Friedrich Lobenstock Linux Services Lobenstock URL: http://www.lsl.at/ Email: fl...@fl... ____________________________________________________________________ |
|
From: Heiko Z. <he...@zu...> - 2004-04-09 15:51:17
|
> Heiko Zuerker wrote on 09.04.2004 17:21 MET: >>>Friedrich Lobenstock wrote on 07.04.2004 01:51 MET: >>> >>>>I just fixed the patch-o-matic in the 1.0.x series. If you are now >>>>having troubles in the kernel compile stage, what you will hopefully >>>> not >>>>have, then please back out this patch and contact me. >>>> >>> >>>After testing with a freshly compiled 1.0.6beta it all looks good but >>> the >>>PPTP NAT- and connection-tracking modules do kill the machine when the >>>PPTP >>>session is closed down normally by the originating host behind the >>>firewall. >>> >>>In contrast the H.323 NAT- and connection-tracking modules seem to work >>>fine. >> >> >> Try using the latest POM snapshot. > > Ok, I will do that. > >> My test compile with it for 1.1.x is still running... > > BTW the module dependencies were not correct on my 1.0.6beta. I had to > load > the extra modules with insmod and absolute path as modprobe would not find > them. Do you know right away what could be the problem here? Where should > I > look for that? The only file I can imagine is the modules.conf -- Regards Heiko Zuerker http://www.devil-linux.org |
|
From: Friedrich L. <fl...@fl...> - 2004-04-09 16:09:15
|
Heiko Zuerker wrote on 09.04.2004 17:47 MET:
>>Heiko Zuerker wrote on 09.04.2004 17:21 MET:
>>
>>>>Friedrich Lobenstock wrote on 07.04.2004 01:51 MET:
>>>>
>>>>
>>>>>I just fixed the patch-o-matic in the 1.0.x series. If you are now
>>>>>having troubles in the kernel compile stage, what you will hopefully
>>>>>not
>>>>>have, then please back out this patch and contact me.
>>>>>
>>>>
>>>>After testing with a freshly compiled 1.0.6beta it all looks good but
>>>>the
>>>>PPTP NAT- and connection-tracking modules do kill the machine when the
>>>>PPTP
>>>>session is closed down normally by the originating host behind the
>>>>firewall.
>>>>
>>>>In contrast the H.323 NAT- and connection-tracking modules seem to work
>>>>fine.
>>>
>>>
>>>Try using the latest POM snapshot.
>>
>>Ok, I will do that.
>>
>>
>>>My test compile with it for 1.1.x is still running...
>>
>>BTW the module dependencies were not correct on my 1.0.6beta. I had to
>>load
>>the extra modules with insmod and absolute path as modprobe would not find
>>them. Do you know right away what could be the problem here? Where should
>>I
>>look for that?
>
>
> The only file I can imagine is the modules.conf
The following modules
ip_nat_h323
ip_conntrack_h323
ip_nat_pptp
ip_nat_proto_gre
ip_conntrack_pptp
ip_conntrack_proto_gre
which reside in the same directory as the ip_nat_ftp module, which btw can
be loaded fine with modprobe, are the modules I am talking about.
I think the problem might be lying here:
# grep ip_nat /etc/modules/modules.dep
/lib/modules/2.4.22-grsec/kernel/net/ipv4/netfilter/ip_nat_amanda.o:
/lib/modules/2.4.22-grsec/kernel/net/ipv4/netfilter/iptable_nat.o \
/lib/modules/2.4.22-grsec/kernel/net/ipv4/netfilter/ip_nat_ftp.o:
/lib/modules/2.4.22-grsec/kernel/net/ipv4/netfilter/iptable_nat.o \
/lib/modules/2.4.22-grsec/kernel/net/ipv4/netfilter/ip_nat_irc.o:
/lib/modules/2.4.22-grsec/kernel/net/ipv4/netfilter/iptable_nat.o \
/lib/modules/2.4.22-grsec/kernel/net/ipv4/netfilter/ip_nat_snmp_basic.o:
/lib/modules/2.4.22-grsec/kernel/net/ipv4/netfilter/iptable_nat.o
/lib/modules/2.4.22-grsec/kernel/net/ipv4/netfilter/ip_nat_tftp.o:
/lib/modules/2.4.22-grsec/kernel/net/ipv4/netfilter/iptable_nat.o \
Should there be an entry for 3 of the modules listed above? Running depmod
does not help, as that command does not seem to finish at all, that's why I
aborted it.
Hmmm....this time I did a "strace depmod" which showed me that it was
really doing something and that run seems to have fixed it. I guess I was
just to unpatient - as I used a config disk from 1.0.4 to boot into
1.0.6beta without updating the config.
--
MfG / Regards
Friedrich Lobenstock
____________________________________________________________________
Friedrich Lobenstock Linux Services Lobenstock
URL: http://www.lsl.at/ Email: fl...@fl...
____________________________________________________________________
|
|
From: Heiko Z. <he...@zu...> - 2004-04-09 18:11:18
|
> >> Friedrich Lobenstock wrote on 07.04.2004 01:51 MET: >>> >>> I just fixed the patch-o-matic in the 1.0.x series. If you are now >>> having troubles in the kernel compile stage, what you will hopefully >>> not >>> have, then please back out this patch and contact me. >>> >> >> After testing with a freshly compiled 1.0.6beta it all looks good but >> the >> PPTP NAT- and connection-tracking modules do kill the machine when the >> PPTP >> session is closed down normally by the originating host behind the >> firewall. >> >> In contrast the H.323 NAT- and connection-tracking modules seem to work >> fine. > > Try using the latest POM snapshot. > My test compile with it for 1.1.x is still running... It fails again, same place.... Heiko gcc -D__KERNEL__ -I/data/build/tmp/linux-2.4.25/include -Wall -Wstrict-prototypes -Wno-trigraphs -O2 -fno-strict-aliasing -fno-common -fomit -frame-pointer -pipe -mpreferred-stack-boundary=2 -march=i586 -DMODULE -DMODVERSIONS -include /data/build/tmp/linux-2.4.25/include/linux/mo dversions.h -nostdinc -iwithprefix include -DKBUILD_BASENAME=ipt_connmark -c -o ipt_connmark.o ipt_connmark.c gcc -D__KERNEL__ -I/data/build/tmp/linux-2.4.25/include -Wall -Wstrict-prototypes -Wno-trigraphs -O2 -fno-strict-aliasing -fno-common -fomit -frame-pointer -pipe -mpreferred-stack-boundary=2 -march=i586 -DMODULE -DMODVERSIONS -include /data/build/tmp/linux-2.4.25/include/linux/mo dversions.h -nostdinc -iwithprefix include -DKBUILD_BASENAME=ipt_connlimit -c -o ipt_connlimit.o ipt_connlimit.c ipt_connlimit.c: In function `init': ipt_connlimit.c:219: error: `ip_conntrack_module' undeclared (first use in this function) ipt_connlimit.c:219: error: (Each undeclared identifier is reported only once ipt_connlimit.c:219: error: for each function it appears in.) ipt_connlimit.c:220: warning: value computed is not used ipt_connlimit.c: In function `fini': ipt_connlimit.c:227: error: `ip_conntrack_module' undeclared (first use in this function) ipt_connlimit.c:228: warning: value computed is not used make[3]: *** [ipt_connlimit.o] Error 1 make[3]: Leaving directory `/data/build/tmp/linux-2.4.25/net/ipv4/netfilter' make[2]: *** [_modsubdir_ipv4/netfilter] Error 2 make[2]: Leaving directory `/data/build/tmp/linux-2.4.25/net' make[1]: *** [_mod_net] Error 2 make[1]: Leaving directory `/data/build/tmp/linux-2.4.25' |