-
-
Notifications
You must be signed in to change notification settings - Fork 1.2k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
netfilter-mailcow restart loop #5849
Comments
Oop, seems also related to #5798 |
Clearing all iptables rules with I did not manually touch the iptables, so I assume mailcow messed something up at some point |
Yes, there is definitely something wrong. I noticed this too! |
Yeah, I was lucky that I really use my vps just for the mailserver, |
If I clear the iptables and restart the Mailcow as mentioned here, it works for less than a day before crashing again. |
I applied the work-around mentioned here: #5735 (comment) and added this to
This workaround should fix the vulnerability and fix the netfilter restart loop. Reboot after adding this. the docker service will automatically add other necessary DOCKER* chains to nftables and keep this DOCKER-USER chain untouched. You can list all rules with |
This issue has been automatically marked as stale because it has not had recent activity. It will be closed if no further activity occurs. |
Contribution guidelines
I've found a bug and checked that ...
Description
Logs:
Steps to reproduce:
Which branch are you using?
master
Which architecture are you using?
x86
Operating System:
Linux mail.aitsys.dev 5.10.0-28-amd64 #1 SMP Debian 5.10.209-2 (2024-01-31) x86_64 GNU/Linux (bullseye)
Server/VM specifications:
8GB RAM, 4 Cores AMD EPYC 7282 16-Core Processor
Is Apparmor, SELinux or similar active?
no
Virtualization technology:
KVM
Docker version:
26.0.2
docker-compose version or docker compose version:
v2.26.1
mailcow version:
2024-04
Reverse proxy:
None (Using mailcow directly)
Logs of git diff:
Logs of iptables -L -vn:
Logs of ip6tables -L -vn:
Logs of iptables -L -vn -t nat:
Logs of ip6tables -L -vn -t nat:
DNS check:
The text was updated successfully, but these errors were encountered: