Devuan bug report logs - #405
Iptables --tcp-option off by one

Package: iptables; Reported by: Andrey Nikitushkin <[email protected]>; Keywords: debian; Done: Mark Hindley <[email protected]>; Maintainer for iptables is (unknown).
Notification sent to Andrey Nikitushkin <[email protected]>:
bug acknowledged by developer. Full text available.
Marked bug as done Request was from Mark Hindley <[email protected]> to [email protected]. Full text available.
Changed bug title to 'Iptables --tcp-option off by one' from 'Iptables standartd issue'. Request was from Mark Hindley <[email protected]> to [email protected]. Full text available.

Message received at [email protected]:


Received: (at 405-quiet) by bugs.devuan.org; 1 Mar 2020 14:10:03 +0000
Return-Path: <[email protected]>
Delivered-To: [email protected]
Received: from tupac3.dyne.org [195.169.149.119]
	by doc.devuan.org with IMAP (fetchmail-6.4.0.beta4)
	for <debbugs@localhost> (single-drop); Sun, 01 Mar 2020 14:10:03 +0000 (UTC)
Received: from mx.hindley.org.uk (mohindley.plus.com [81.174.245.179])
	(using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits))
	(No client certificate requested)
	by vm6.ganeti.dyne.org (Postfix) with ESMTPS id 0473CF609A8
	for <[email protected]>; Sun,  1 Mar 2020 14:59:05 +0100 (CET)
Received: from apollo.hindleynet ([192.168.1.3] helo=apollo)
	by mx.hindley.org.uk with esmtps (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128)
	(Exim 4.84_2)
	(envelope-from <[email protected]>)
	id 1j8P7Y-0006nz-V1
	for [email protected]; Sun, 01 Mar 2020 13:59:05 +0000
Received: from mark by apollo with local (Exim 4.84_2)
	(envelope-from <[email protected]>)
	id 1j8P7X-00037v-SJ
	for [email protected]; Sun, 01 Mar 2020 13:59:03 +0000
Date: Sun, 1 Mar 2020 13:59:03 +0000
From: Mark Hindley <[email protected]>
To: [email protected]
Subject: Re: Iptables standartd issue
Message-ID: <[email protected]>
MIME-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
In-Reply-To: <[email protected]>
X-Debbugs-No-Ack: No Thanks
User-Agent: Mutt/1.5.23 (2014-03-12)
X-Spam-Status: No, score=0.0 required=5.0 tests=FAKE_REPLY_C,SPF_PASS
	autolearn=disabled version=3.4.2
X-Spam-Checker-Version: SpamAssassin 3.4.2 (2018-09-13) on tupac3.dyne.org

Control: retitle -1 Iptables --tcp-option off by one

Added tag(s) debian. Request was from Mark Hindley <[email protected]> to [email protected]. Full text available.

Message received at [email protected]:


Received: (at 405) by bugs.devuan.org; 1 Mar 2020 14:00:02 +0000
Return-Path: <[email protected]>
Delivered-To: [email protected]
Received: from tupac3.dyne.org [195.169.149.119]
	by doc.devuan.org with IMAP (fetchmail-6.4.0.beta4)
	for <debbugs@localhost> (single-drop); Sun, 01 Mar 2020 14:00:01 +0000 (UTC)
Received: from mx.hindley.org.uk (mohindley.plus.com [81.174.245.179])
	(using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits))
	(No client certificate requested)
	by vm6.ganeti.dyne.org (Postfix) with ESMTPS id C8108F609A8
	for <[email protected]>; Sun,  1 Mar 2020 14:54:46 +0100 (CET)
Received: from apollo.hindleynet ([192.168.1.3] helo=apollo)
	by mx.hindley.org.uk with esmtps (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128)
	(Exim 4.84_2)
	(envelope-from <[email protected]>)
	id 1j8P3N-0006ml-9O; Sun, 01 Mar 2020 13:54:45 +0000
Received: from mark by apollo with local (Exim 4.84_2)
	(envelope-from <[email protected]>)
	id 1j8P3M-00034x-IN; Sun, 01 Mar 2020 13:54:44 +0000
Date: Sun, 1 Mar 2020 13:54:44 +0000
From: Mark Hindley <[email protected]>
To: [email protected]
Cc: Andrey Nikitushkin <[email protected]>
Subject: Re: Iptables standartd issue
Message-ID: <[email protected]>
MIME-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
In-Reply-To: <[email protected]>
X-Debbugs-No-Ack: No Thanks
User-Agent: Mutt/1.5.23 (2014-03-12)
X-Spam-Status: No, score=0.0 required=5.0 tests=FAKE_REPLY_C,SPF_PASS
	autolearn=disabled version=3.4.2
X-Spam-Checker-Version: SpamAssassin 3.4.2 (2018-09-13) on tupac3.dyne.org

Control: tags -1 debian

Andrey,

Thanks for this.

However, as iptables is not forked in Devuan and we use the Debian package
directly, we have no way to fix this. You would be better reporting it directly
to Debian's BTS or even iptables upstream.

Thanks.

Mark

Information forwarded to [email protected], [email protected]:
bug#405; Package iptables. Full text available.

Message received at [email protected]:


Received: (at submit) by bugs.devuan.org; 29 Feb 2020 21:40:05 +0000
Return-Path: <[email protected]>
Delivered-To: [email protected]
Received: from tupac3.dyne.org [195.169.149.119]
	by doc.devuan.org with IMAP (fetchmail-6.4.0.beta4)
	for <debbugs@localhost> (single-drop); Sat, 29 Feb 2020 21:40:05 +0000 (UTC)
Received: from mail-wr1-f41.google.com (mail-wr1-f41.google.com [209.85.221.41])
	(using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits))
	(No client certificate requested)
	by vm6.ganeti.dyne.org (Postfix) with ESMTPS id 7793DF60AEA
	for <[email protected]>; Sat, 29 Feb 2020 22:38:23 +0100 (CET)
Authentication-Results: vm6.ganeti.dyne.org;
	dkim=pass (2048-bit key; unprotected) header.d=gmail.com [email protected] header.b="XK6/2TAX";
	dkim-atps=neutral
Received: by mail-wr1-f41.google.com with SMTP id v2so7645109wrp.12
        for <[email protected]>; Sat, 29 Feb 2020 13:38:23 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
        d=gmail.com; s=20161025;
        h=to:from:subject:message-id:date:user-agent:mime-version
         :content-language;
        bh=OEqqfdkVENy9b6sFYk0k/mHXrZCB664SB2Yp/atTeE0=;
        b=XK6/2TAXMhmBV1Xo58na6Wli37gaHUJFtUdp5oxv6+ueayurdFTL7E8NDcFygBEXUN
         O6OEJF6gW/q+/Dnui/6WREYEH2QngK6Okd9zEOvR1C1DhqVYMFZffbqzvwiff9OXhwMn
         xiaW0KkMr5q5g8Q541zY7ConLePPhkLtvtSSX/kddBrnVod5BiH83v/jg13Z7Wt2M/EW
         T8foiuLJ034IDFMG9H5G13HWltlmVG1fVloDiciGASzPzcJ05MkrcBBVsIBaWS64Nh4y
         izGdcDHA3SLz19MLGXA0apEfdw2cLONI2l84hOT7nJlZh9Zk7Y4/WvKtASg71CKLaswY
         BH/w==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
        d=1e100.net; s=20161025;
        h=x-gm-message-state:to:from:subject:message-id:date:user-agent
         :mime-version:content-language;
        bh=OEqqfdkVENy9b6sFYk0k/mHXrZCB664SB2Yp/atTeE0=;
        b=BlxDWeORrIA9GsSItB4b/maF61d54dxfzr5L4IuKyVPpBB7v2VUufG3X3JA1t1tusJ
         s2xIpxap29v/b8tmzq5HhWpGM4qinaOF8mwvBHpQGyOKXsi6T5zlHKmYWZlV/BHbP0Lu
         Wxm7iiFKApmp9kgONPK6AXSGgTT7rD68rdF8i1Z8F9d/uEmj7W2hLvMb05Ix/spGpdPz
         2FwgcHZPNwhmHYtZfWCgusNIUhYs4ClSJ/1O0F5KQ7dJUXO7x0ROQKNf13LywXQTZ3Mv
         QeRKdEdiXiDQ77VAZN6CILWAu6g4ob/NiCTgmb8t8oRqWTuSckmPVYewhIIi8X+h2qqO
         lXNQ==
X-Gm-Message-State: APjAAAXhQZwcQvDffuDISVzXxejaLldrIlbxNctt6s93DH208mHA1bHQ
	qLG1v/qxIntV8z5baK6BGEYHMNLJ
X-Google-Smtp-Source: APXvYqxAsdodSne8E1JXjWppZ99JTNPBnwlxwPFUw/kadlbZVUdUaYE4LmZDyPNCweOg0G+a//MH0A==
X-Received: by 2002:adf:b19d:: with SMTP id q29mr12036036wra.211.1583012301664;
        Sat, 29 Feb 2020 13:38:21 -0800 (PST)
Received: from [192.168.132.2] (host-93-124-43-90.dsl.sura.ru. [93.124.43.90])
        by smtp.gmail.com with ESMTPSA id w19sm7510729wmc.22.2020.02.29.13.38.20
        for <[email protected]>
        (version=TLS1_3 cipher=TLS_AES_128_GCM_SHA256 bits=128/128);
        Sat, 29 Feb 2020 13:38:20 -0800 (PST)
To: [email protected]
From: Andrey Nikitushkin <[email protected]>
Subject: Iptables standartd issue
Message-ID: <[email protected]>
Date: Sun, 1 Mar 2020 00:38:17 +0300
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:68.0) Gecko/20100101
 Thunderbird/68.5.0
MIME-Version: 1.0
Content-Type: multipart/alternative;
 boundary="------------C71D0614AC7B5AB6F0537196"
Content-Language: en-US
X-Spam-Status: No, score=-0.2 required=5.0 tests=DKIM_SIGNED,DKIM_VALID,
	DKIM_VALID_AU,DKIM_VALID_EF,FREEMAIL_FROM,HTML_MESSAGE,
	RCVD_IN_DNSWL_NONE,SPF_PASS autolearn=disabled version=3.4.2
X-Spam-Checker-Version: SpamAssassin 3.4.2 (2018-09-13) on tupac3.dyne.org

This is a multi-part message in MIME format.
--------------C71D0614AC7B5AB6F0537196
Content-Type: text/plain; charset=utf-8; format=flowed
Content-Transfer-Encoding: 8bit

Package: iptables
Version: 1.8.2

Hello, friends!

In Devuan 1, Devuan 2, Devuan 3 (and Debian, and Ubuntu) have next 
standard issue with *iptables*!

The current range of values for the *--tcp-option* /iptables/ flag is 
1-255 - this is not correct. The correct range of values should be 
0-254. Please read the following information: 
https://www.iana.org/assignments/tcp-parameters/tcp-parameters.xhtml#tcp-parameters-1 
This negative change in /iptables/ was made approximately 2 years ago 
without making this change public. Please report this issue to the 
/iptables/ developers so that they can set the range of --tcp-option 
values in accordance with the accepted standards for the TCP Protocol.

Please see: https://dev1galaxy.org/viewtopic.php?id=3347

-- 
============================================
С наилучшими пожеланиями, Никитушкин Андрей!
Тел.(сот.): +79063975544
============================================


--------------C71D0614AC7B5AB6F0537196
Content-Type: text/html; charset=utf-8
Content-Transfer-Encoding: 8bit

<html>
  <head>

    <meta http-equiv="content-type" content="text/html; charset=UTF-8">
  </head>
  <body>
    <pre>Package: iptables
Version: 1.8.2

</pre>
    <p>Hello, friends!</p>
    <p>In Devuan 1, Devuan 2, Devuan 3 (and Debian, and Ubuntu) have
      next standard issue with <strong>iptables</strong>!</p>
    <p>The current range of values for the <strong>--tcp-option</strong>
      <em>iptables</em> flag is 1-255 - this is not correct. The correct
      range of values should be 0-254. Please read the following
      information: <a
href="https://www.iana.org/assignments/tcp-parameters/tcp-parameters.xhtml#tcp-parameters-1"
        rel="nofollow">https://www.iana.org/assignments/tcp-parameters/tcp-parameters.xhtml#tcp-parameters-1</a>
      This negative change in <em>iptables</em> was made approximately
      2 years ago without making this change public. Please report this
      issue to the <em>iptables</em> developers so that they can set
      the range of --tcp-option values in accordance with the accepted
      standards for the TCP Protocol.</p>
    <p>Please see: <a class="moz-txt-link-freetext" href="https://dev1galaxy.org/viewtopic.php?id=3347">https://dev1galaxy.org/viewtopic.php?id=3347</a><br>
    </p>
    <pre class="moz-signature" cols="72">-- 
============================================
С наилучшими пожеланиями, Никитушкин Андрей!
Тел.(сот.): +79063975544
============================================</pre>
  </body>
</html>

--------------C71D0614AC7B5AB6F0537196--

Acknowledgement sent to Andrey Nikitushkin <[email protected]>:
New bug report received and forwarded. Copy sent to [email protected]. Full text available.
Report forwarded to [email protected], [email protected]:
bug#405; Package iptables. Full text available.

Devuan BTS -- Powered by Debian bug tracking system
Copyright (C) 1999 Darren O. Benham,
1997 nCipher Corporation Ltd, 1994-97 Ian Jackson.

Devuan Bugs Owner <[email protected]>.
Last modified: Sat, 18 Jan 2025 04:39:02 UTC