samba install flushes iptables and sets all chains to policy accept
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
samba (Ubuntu) |
Invalid
|
Undecided
|
Unassigned |
Bug Description
I have been tracking down why my iptables have been getting flushed in a VM.
This is what it lead me to...
sudo iptables -L -n
sudo apt-get install -yq samba
sudo iptables -L -n
The iptables listing before the samba install is long.
The iptables listing after the samba install have been flushed and all
chains are set to policy ACCEPT!
Ubuntu 20.04.2
samba --verision
Version 4.11.6-Ubuntu
ProblemType: Bug
DistroRelease: Ubuntu 20.04
Package: samba 2:4.11.
ProcVersionSign
Uname: Linux 5.4.0-70-generic x86_64
ApportVersion: 2.20.11-
Architecture: amd64
CIFSMounts:
/mnt/v //192.168.
/mnt/pshare //192.168.
CasperMD5CheckR
Date: Tue Mar 30 14:18:30 2021
InstallationDate: Installed on 2021-03-30 (0 days ago)
InstallationMedia:
SambaClientRegr
SourcePackage: samba
UpgradeStatus: No upgrade log present (probably fresh install)
information type: | Private Security → Public Security |
Hello, sorry you are having this issue.
Unfortunately I am unable to reporduce this, with samba 2:4.11. 6+dfsg- 0ubuntu1. 6 from focal, either by applying iptables rules manually or enabling firewall rules with ufw:
$ sudo iptables -D INPUT -i lo -j LOG
$ sudo iptables -L INPUT -n
Chain INPUT (policy ACCEPT)
target prot opt source destination
LOG all -- 0.0.0.0/0 0.0.0.0/0 LOG flags 0 level 4
$ sudo apt install samba
[ELIDED]
$ sudo iptables -L INPUT -n
Chain INPUT (policy ACCEPT)
target prot opt source destination
LOG all -- 0.0.0.0/0 0.0.0.0/0 LOG flags 0 level 4
What are you using to apply firewall rules? None of the samba packages directly manipulate iptables in their postinstall scripts or in their service startup files that I can see. The samba package does drop an application file for ufw in /etc/ufw/ applications. d/samba, but if ufw is not enabled, this should not be applied, nor should the ufw trigger that runs at the end of the installation touch iptables settings.