Stretch to Buster migration : xtable to nftables fail

My YunoHost server

Hardware: lxc unprivileged container on odroid HC1 sbc 2Gb mem 250 ssd drive
YunoHost version: 4.0.4
I have access to my server : Through SSH | through the webadmin
Are you in a special context or did you perform some particular tweaking on your YunoHost instance ? : no

Description of my issue

After running migration from stretch to buster 1 pending migration left with error on firewall : https://paste.yunohost.org/raw/iyisumalus

first firewall didn’t restart, then i restart but " 18. Migrate old network traffic rules to the new nftable system" fail

it seems that generate errors on
synapse, mastodon-web, mastodon-sidekik

i fall back to 3.8 and note that modifying some port in ipv6 an error occur :“You cannot play with ip6tables here. You are either in a container or your kernel does not support it”

do someone know how to deal with ip6table inside a container ?

It’s not really clear to me …

You can try maybe to run sudo modprobe ip6table_filter, but I’m not sure it’ll work in an unpriviledged container

:confused: fail, modprob is not accessible inside the unprivileged container :frowning:

More information, its like an lxc problem
CONFIG_NF_NAT_IPV4, CONFIG_NF_NAT_IPV6 does not exist since kernel 5.1 and replace wit a combined ipv4 ipv6 CONFIG_NF_NAT module,
lxc 3.0.3 which is the packaged lxc, with systemd seems to not support CONFIG_NF_NAT (https://bbs.archlinux.org/viewtopic.php?id=257102)
I’m a bit lost and don’t know what to do. I will stay on yunhost 3.8 a bit more time.

This topic was automatically closed 15 days after the last reply. New replies are no longer allowed.