canonical / lxd

Powerful system container and virtual machine manager
https://canonical.com/lxd
GNU Affero General Public License v3.0
4.32k stars 926 forks source link

Host and container internet connection lost when lxd container is up and back when it is stopped. #12584

Closed zcatav closed 9 months ago

zcatav commented 9 months ago

Hello, I have a problem with the use of LXD. I have listed the relevant information below. I can provide additional information if needed. Thank you in advance for your suggestions on how to solve my problem.

Sincerely regards

Required information

Issue description

I installed Lxd as described in the Debian wiki. I created a Debian11 container with Lxc launch. Once inside the container I had internet access for the first few minutes, then the host unreachable warning and communication was lost. At the same time internet access was lost on the host. When I exited the container and closed it, internet connection was restored for the host. It was possible to access the host from inside the container.

Steps to reproduce

  1. Install antiX linux 23
  2. Install Lxd and launch a container
  3. Wait a few minutes and try to connect internet

Information to attach

Resources: Processes: 9 CPU usage: CPU usage (in seconds): 4 Memory usage: Memory (current): 19.39MiB Network usage: eth0: Type: broadcast State: UP Host interface: veth03d2eeea MAC address: 00:16:3e:88:2b:a4 MTU: 1500 Bytes received: 10.17kB Bytes sent: 3.79kB Packets received: 47 Packets sent: 33 IP addresses: inet: 10.17.247.16/24 (global) inet6: fd42:6e83:9e3d:1e00:216:3eff:fe88:2ba4/64 (global) inet6: fe80::216:3eff:fe88:2ba4/64 (link) lo: Type: loopback State: UP MTU: 65536 Bytes received: 0B Bytes sent: 0B Packets received: 0 Packets sent: 0 IP addresses: inet: 127.0.0.1/8 (local) inet6: ::1/128 (local)

Log:

host ~ $ ping 8.8.8.8
PING 8.8.8.8 (8.8.8.8): 56 data bytes 92 bytes from medantix.local (169.254.216.23): Destination Host Unreachable 92 bytes from medantix.local (169.254.216.23): Destination Host Unreachable 92 bytes from medantix.local (169.254.216.23): Destination Host Unreachable 92 bytes from medantix.local (169.254.216.23): Destination Host Unreachable 92 bytes from medantix.local (169.254.216.23): Destination Host Unreachable 92 bytes from medantix.local (169.254.216.23): Destination Host Unreachable 92 bytes from medantix.local (169.254.216.23): Destination Host Unreachable 92 bytes from medantix.local (169.254.216.23): Destination Host Unreachable ^C--- 8.8.8.8 ping statistics --- 9 packets transmitted, 0 packets received, 100% packet loss

lxc monitor lxc monitor
location: none metadata: context: id: 7e5f6737-ec98-476a-bfc6-acac184d089d local: /var/lib/lxd/unix.socket remote: '@' level: debug message: Event listener server handler started timestamp: "2023-12-01T12:40:15.653770058+03:00" type: logging

location: none metadata: context: ip: '@' method: GET protocol: unix url: /1.0 username: catav level: debug message: Handling API request timestamp: "2023-12-01T12:40:35.517322824+03:00" type: logging

location: none metadata: context: ip: '@' method: GET protocol: unix url: /1.0/events username: catav level: debug message: Handling API request timestamp: "2023-12-01T12:40:35.52567153+03:00" type: logging

location: none metadata: context: ip: '@' method: POST protocol: unix url: /1.0/instances/tedis/exec username: catav level: debug message: Handling API request timestamp: "2023-12-01T12:40:35.53024608+03:00" type: logging

location: none metadata: context: id: 5f2cb093-738f-431b-9ee9-2fd7595f1421 local: /var/lib/lxd/unix.socket remote: '@' level: debug message: Event listener server handler started timestamp: "2023-12-01T12:40:35.531805176+03:00" type: logging

location: none metadata: context: {} level: debug message: Waiting for exec websockets to connect timestamp: "2023-12-01T12:40:35.563200071+03:00" type: logging

location: none metadata: class: websocket created_at: "2023-12-01T12:40:35.544243459+03:00" description: Executing command err: "" id: ce8bc6a3-457b-445e-b261-f55c62e6dc67 location: none may_cancel: false metadata: command:

location: none metadata: context: class: websocket description: Executing command operation: ce8bc6a3-457b-445e-b261-f55c62e6dc67 project: default level: debug message: New operation timestamp: "2023-12-01T12:40:35.561515005+03:00" type: logging

location: none metadata: context: class: websocket description: Executing command operation: ce8bc6a3-457b-445e-b261-f55c62e6dc67 project: default level: debug message: Started operation timestamp: "2023-12-01T12:40:35.562088419+03:00" type: logging

location: none metadata: class: websocket created_at: "2023-12-01T12:40:35.544243459+03:00" description: Executing command err: "" id: ce8bc6a3-457b-445e-b261-f55c62e6dc67 location: none may_cancel: false metadata: command:

location: none metadata: context: class: websocket description: Executing command operation: ce8bc6a3-457b-445e-b261-f55c62e6dc67 project: default level: debug message: Connecting to operation timestamp: "2023-12-01T12:40:35.568443296+03:00" type: logging

location: none metadata: context: ip: '@' method: GET protocol: unix url: /1.0/operations/ce8bc6a3-457b-445e-b261-f55c62e6dc67/websocket?secret=b816aa7a907b76ad03f1d76140e181461157884b8830d428decf748ceab880ec username: catav level: debug message: Handling API request timestamp: "2023-12-01T12:40:35.568252005+03:00" type: logging

location: none metadata: context: class: websocket description: Executing command operation: ce8bc6a3-457b-445e-b261-f55c62e6dc67 project: default level: debug message: Connecting to operation timestamp: "2023-12-01T12:40:35.57266131+03:00" type: logging

location: none metadata: context: ip: '@' method: GET protocol: unix url: /1.0/operations/ce8bc6a3-457b-445e-b261-f55c62e6dc67/websocket?secret=4855ae2305bef3ff0e00454bf5c602dd94ee239b88b5e1423d945a6087dd7083 username: catav level: debug message: Handling API request timestamp: "2023-12-01T12:40:35.571583712+03:00" type: logging

location: none metadata: context: class: websocket description: Executing command operation: ce8bc6a3-457b-445e-b261-f55c62e6dc67 project: default level: debug message: Connected to operation timestamp: "2023-12-01T12:40:35.56901874+03:00" type: logging

location: none metadata: context: class: websocket description: Executing command operation: ce8bc6a3-457b-445e-b261-f55c62e6dc67 project: default level: debug message: Connected to operation timestamp: "2023-12-01T12:40:35.573227598+03:00" type: logging

location: none metadata: context: ip: '@' method: GET protocol: unix url: /1.0/operations/ce8bc6a3-457b-445e-b261-f55c62e6dc67 username: catav level: debug message: Handling API request timestamp: "2023-12-01T12:40:35.576669956+03:00" type: logging

location: none metadata: action: instance-exec context: command:

location: none metadata: context: attachedPid: "7201" instance: tedis instanceType: container project: default level: debug message: Retrieved PID of executing child process timestamp: "2023-12-01T12:40:35.614388069+03:00" type: logging

location: none metadata: context: PID: "7201" instance: tedis interactive: "true" project: default level: debug message: Instance process started timestamp: "2023-12-01T12:40:35.615616722+03:00" type: logging

location: none metadata: context: PID: "7201" instance: tedis interactive: "true" project: default level: debug message: Exec control handler started timestamp: "2023-12-01T12:40:35.616960096+03:00" type: logging

location: none metadata: context: PID: "7201" instance: tedis interactive: "true" number: "0" project: default level: debug message: Exec mirror websocket started timestamp: "2023-12-01T12:40:35.616370102+03:00" type: logging

zcatav commented 9 months ago

ip a 1: lo: <LOOPBACK,UP,LOWER_UP> mtu 65536 qdisc noqueue state UNKNOWN group default qlen 1000 link/loopback 00:00:00:00:00:00 brd 00:00:00:00:00:00 inet 127.0.0.1/8 scope host lo valid_lft forever preferred_lft forever inet6 ::1/128 scope host valid_lft forever preferred_lft forever 2: eth0: <NO-CARRIER,BROADCAST,MULTICAST,DYNAMIC,UP> mtu 1500 qdisc pfifo_fast state DOWN group default qlen 1000 link/ether f4:6d:04:bb:ea:8d brd ff:ff:ff:ff:ff:ff 3: wlan0: <BROADCAST,MULTICAST,DYNAMIC,UP,LOWER_UP> mtu 1500 qdisc pfifo_fast state UP group default qlen 1000 link/ether e0:b9:a5:30:43:c4 brd ff:ff:ff:ff:ff:ff inet 192.168.214.117/24 brd 192.168.214.255 scope global wlan0 valid_lft forever preferred_lft forever inet6 fe80::e2b9:a5ff:fe30:43c4/64 scope link valid_lft forever preferred_lft forever 4: lxdbr0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue state UP group default qlen 1000 link/ether 00:16:3e:2b:d3:20 brd ff:ff:ff:ff:ff:ff inet 10.17.247.1/24 scope global lxdbr0 valid_lft forever preferred_lft forever inet6 fd42:6e83:9e3d:1e00::1/64 scope global valid_lft forever preferred_lft forever inet6 fe80::216:3eff:fe2b:d320/64 scope link valid_lft forever preferred_lft forever 6: vethd422414a@if5: <BROADCAST,MULTICAST,DYNAMIC,UP,LOWER_UP> mtu 1500 qdisc noqueue master lxdbr0 state UP group default qlen 1000 link/ether 52:33:2c:e3:3c:cc brd ff:ff:ff:ff:ff:ff link-netnsid 0 inet 169.254.228.155/16 brd 169.254.255.255 scope global vethd422414a valid_lft forever preferred_lft forever inet6 fe80::5033:2cff:fee3:3ccc/64 scope link valid_lft forever preferred_lft forever

ip r 0.0.0.0 dev vethd422414a scope link default dev vethd422414a scope link 10.17.247.0/24 dev lxdbr0 proto kernel scope link src 10.17.247.1 169.254.0.0/16 dev vethd422414a proto kernel scope link src 169.254.228.155 192.168.214.0/24 dev wlan0 proto kernel scope link src 192.168.214.117 192.168.214.114 dev wlan0 scope link

iptables Chain INPUT (policy ACCEPT 0 packets, 0 bytes) pkts bytes target prot opt in out source destination

Chain FORWARD (policy ACCEPT 0 packets, 0 bytes) pkts bytes target prot opt in out source destination

Chain OUTPUT (policy ACCEPT 0 packets, 0 bytes) pkts bytes target prot opt in out source destination

ufw Status: inactive

pss fauxww USER PID %CPU %MEM VSZ RSS TTY STAT START TIME COMMAND root 2 0.0 0.0 0 0 ? S 12:23 0:00 [kthreadd] root 3 0.0 0.0 0 0 ? I< 12:23 0:00 _ [rcugp] root 4 0.0 0.0 0 0 ? I< 12:23 0:00 \ [rcu_pargp] root 5 0.0 0.0 0 0 ? I< 12:23 0:00 \ [slubflushwq] root 6 0.0 0.0 0 0 ? I< 12:23 0:00 _ [netns] root 7 0.0 0.0 0 0 ? I 12:23 0:00 _ [kworker/0:0-events] root 8 0.0 0.0 0 0 ? I< 12:23 0:00 \ [kworker/0:0H-eventshighpri] root 9 0.0 0.0 0 0 ? I 12:23 0:00 _ [kworker/u8:0-btrfs-endio-write] root 10 0.0 0.0 0 0 ? I< 12:23 0:00 \ [mm_percpuwq] root 11 0.0 0.0 0 0 ? I 12:23 0:00 \ [rcu_taskskthread] root 12 0.0 0.0 0 0 ? I 12:23 0:00 \ [rcu_tasks_tracekthread] root 13 0.0 0.0 0 0 ? S 12:23 0:00 _ [ksoftirqd/0] root 14 0.1 0.0 0 0 ? I 12:23 0:00 \ [rcupreempt] root 15 0.0 0.0 0 0 ? S 12:23 0:00 _ [migration/0] root 16 0.0 0.0 0 0 ? S 12:23 0:00 _ [cpuhp/0] root 17 0.0 0.0 0 0 ? S 12:23 0:00 _ [cpuhp/1] root 18 0.0 0.0 0 0 ? S 12:23 0:00 _ [migration/1] root 19 0.4 0.0 0 0 ? S 12:23 0:00 _ [ksoftirqd/1] root 20 0.0 0.0 0 0 ? I 12:23 0:00 _ [kworker/1:0-events] root 21 0.0 0.0 0 0 ? I< 12:23 0:00 \ [kworker/1:0H-eventshighpri] root 22 0.0 0.0 0 0 ? S 12:23 0:00 _ [cpuhp/2] root 23 0.0 0.0 0 0 ? S 12:23 0:00 _ [migration/2] root 24 2.2 0.0 0 0 ? S 12:23 0:04 _ [ksoftirqd/2] root 25 0.0 0.0 0 0 ? I 12:23 0:00 \ [kworker/2:0-rcugp] root 26 0.0 0.0 0 0 ? I< 12:23 0:00 _ [kworker/2:0H-kblockd] root 27 0.0 0.0 0 0 ? S 12:23 0:00 _ [cpuhp/3] root 28 0.0 0.0 0 0 ? S 12:23 0:00 _ [migration/3] root 29 0.3 0.0 0 0 ? S 12:23 0:00 _ [ksoftirqd/3] root 30 0.0 0.0 0 0 ? I 12:23 0:00 \ [kworker/3:0-mm_percpuwq] root 31 0.0 0.0 0 0 ? I< 12:23 0:00 \ [kworker/3:0H-eventshighpri] root 33 0.0 0.0 0 0 ? I 12:23 0:00 _ [kworker/u8:1-btrfs-endio-write] root 34 0.7 0.0 0 0 ? I 12:23 0:01 \ [kworker/u8:2-eventsunbound] root 35 0.0 0.0 0 0 ? I 12:23 0:00 _ [kworker/u8:3-btrfs-endio-write] root 36 0.0 0.0 0 0 ? S 12:23 0:00 _ [kdevtmpfs] root 37 0.0 0.0 0 0 ? I< 12:23 0:00 \ [inet_fragwq] root 38 0.0 0.0 0 0 ? S 12:23 0:00 _ [kauditd] root 39 0.0 0.0 0 0 ? I 12:23 0:00 _ [kworker/2:1-events] root 40 0.0 0.0 0 0 ? I 12:23 0:00 _ [kworker/0:1-events] root 41 0.0 0.0 0 0 ? S 12:23 0:00 \ [oomreaper] root 42 0.0 0.0 0 0 ? I< 12:23 0:00 _ [writeback] root 43 0.0 0.0 0 0 ? S 12:23 0:00 _ [kcompactd0] root 44 0.0 0.0 0 0 ? SN 12:23 0:00 _ [ksmd] root 45 0.0 0.0 0 0 ? SN 12:23 0:00 _ [khugepaged] root 46 0.0 0.0 0 0 ? I< 12:23 0:00 _ [kintegrityd] root 47 0.0 0.0 0 0 ? I< 12:23 0:00 _ [kblockd] root 48 0.0 0.0 0 0 ? I< 12:23 0:00 \ [blkcg_puntbio] root 49 0.0 0.0 0 0 ? I< 12:23 0:00 \ [atasff] root 50 0.0 0.0 0 0 ? I< 12:23 0:00 _ [md] root 51 0.0 0.0 0 0 ? I< 12:23 0:00 _ [edac-poller] root 52 0.0 0.0 0 0 ? I< 12:23 0:00 \ [devfreqwq] root 53 0.0 0.0 0 0 ? S 12:23 0:00 _ [watchdogd] root 54 0.0 0.0 0 0 ? I< 12:23 0:00 _ [kworker/0:1H-kblockd] root 55 0.0 0.0 0 0 ? S 12:23 0:00 _ [kswapd0] root 56 0.0 0.0 0 0 ? I 12:23 0:00 _ [kworker/1:1-pm] root 58 0.1 0.0 0 0 ? I 12:23 0:00 _ [kworker/3:1-events] root 63 0.0 0.0 0 0 ? I< 12:23 0:00 _ [kthrotld] root 66 0.0 0.0 0 0 ? I 12:23 0:00 _ [kworker/0:2] root 68 0.0 0.0 0 0 ? I 12:23 0:00 _ [kworker/2:2-events] root 69 0.0 0.0 0 0 ? I< 12:23 0:00 _ [nvme-wq] root 70 0.0 0.0 0 0 ? I< 12:23 0:00 _ [nvme-reset-wq] root 71 0.0 0.0 0 0 ? I< 12:23 0:00 _ [nvme-delete-wq] root 72 0.0 0.0 0 0 ? S 12:23 0:00 \ [scsi_eh0] root 73 0.0 0.0 0 0 ? I< 12:23 0:00 \ [scsi_tmf0] root 74 0.0 0.0 0 0 ? S 12:23 0:00 \ [scsi_eh1] root 75 0.0 0.0 0 0 ? I< 12:23 0:00 \ [scsi_tmf1] root 76 0.0 0.0 0 0 ? S 12:23 0:00 \ [scsi_eh2] root 77 0.0 0.0 0 0 ? I< 12:23 0:00 \ [scsi_tmf2] root 78 0.0 0.0 0 0 ? S 12:23 0:00 \ [scsi_eh3] root 79 0.0 0.0 0 0 ? I< 12:23 0:00 \ [scsi_tmf3] root 80 0.0 0.0 0 0 ? I 12:23 0:00 _ [kworker/u8:4-btrfs-endio-write] root 83 0.0 0.0 0 0 ? I 12:23 0:00 _ [kworker/u8:5-btrfs-endio-write] root 84 0.0 0.0 0 0 ? I 12:23 0:00 _ [kworker/u8:6-btrfs-endio-write] root 87 0.0 0.0 0 0 ? I< 12:23 0:00 \ [dm_bufiocache] root 88 0.0 0.0 0 0 ? I< 12:23 0:00 _ [tls-strp] root 89 0.0 0.0 0 0 ? I< 12:23 0:00 _ [mld] root 90 0.0 0.0 0 0 ? I< 12:23 0:00 _ [kworker/2:1H-kblockd] root 91 0.0 0.0 0 0 ? I< 12:23 0:00 \ [ipv6addrconf] root 97 0.0 0.0 0 0 ? I< 12:23 0:00 _ [kstrp] root 99 0.0 0.0 0 0 ? I< 12:23 0:00 _ [zswap-shrink] root 100 0.0 0.0 0 0 ? I< 12:23 0:00 _ [kworker/u9:0-hci0] root 145 0.0 0.0 0 0 ? I< 12:23 0:00 \ [chargermanager] root 175 0.0 0.0 0 0 ? I< 12:23 0:00 _ [kworker/1:1H-kblockd] root 180 0.0 0.0 0 0 ? I< 12:23 0:00 _ [kworker/3:1H-kblockd] root 194 0.0 0.0 0 0 ? I< 12:23 0:00 \ [acpi_thermalpm] root 195 0.0 0.0 0 0 ? S 12:23 0:00 _ [napi/eth%d-8193] root 196 0.0 0.0 0 0 ? S 12:23 0:00 _ [napi/eth%d-0] root 200 0.0 0.0 0 0 ? I 12:23 0:00 _ [kworker/3:2-pm] root 201 0.0 0.0 0 0 ? I 12:23 0:00 \ [kworker/3:3-mm_percpuwq] root 202 0.0 0.0 0 0 ? I 12:23 0:00 \ [kworker/1:2-mm_percpuwq] root 203 0.0 0.0 0 0 ? I 12:23 0:00 \ [kworker/1:3-inet_fragwq] root 204 0.0 0.0 0 0 ? I 12:23 0:00 \ [kworker/2:3-mm_percpuwq] root 216 0.0 0.0 0 0 ? I< 12:23 0:00 \ [tpm_devwq] root 296 0.0 0.0 0 0 ? I< 12:23 0:00 _ [kdmflush/253:0] root 301 0.0 0.0 0 0 ? I< 12:23 0:00 _ [cryptd] root 311 0.0 0.0 0 0 ? I< 12:23 0:00 \ [kcryptdio/253:] root 312 0.0 0.0 0 0 ? I< 12:23 0:00 _ [kcryptd/253:0] root 313 0.0 0.0 0 0 ? S 12:23 0:00 \ [dmcryptwrite/253:0] root 350 0.0 0.0 0 0 ? S 12:23 0:00 _ [jbd2/dm-0-8] root 351 0.0 0.0 0 0 ? I< 12:23 0:00 _ [ext4-rsv-conver] root 613 0.0 0.0 0 0 ? I< 12:23 0:00 _ [cfg80211] root 638 0.0 0.0 0 0 ? S 12:23 0:00 \ [wl_eventhandler] root 651 0.0 0.0 0 0 ? S 12:23 0:00 _ [card0-crtc0] root 652 0.0 0.0 0 0 ? S 12:23 0:00 _ [card0-crtc1] root 1051 0.0 0.0 0 0 ? I< 12:23 0:00 _ [kworker/u9:1-hci0] root 1052 0.0 0.0 0 0 ? I< 12:23 0:00 _ [kworker/u9:2-hci0] root 1248 0.0 0.0 0 0 ? I 12:23 0:00 _ [kworker/3:4-pm] root 1250 0.0 0.0 0 0 ? I 12:23 0:00 _ [kworker/3:5-events] root 1253 0.0 0.0 0 0 ? I 12:23 0:00 _ [kworker/3:6] root 1463 0.0 0.0 0 0 ? S 12:23 0:00 _ [jbd2/sda2-8] root 1464 0.0 0.0 0 0 ? I< 12:23 0:00 _ [ext4-rsv-conver] root 1687 0.0 0.0 0 0 ? I< 12:23 0:00 _ [rpciod] root 1688 0.0 0.0 0 0 ? I< 12:23 0:00 _ [xprtiod] root 1690 0.0 0.0 0 0 ? I< 12:23 0:00 _ [nfsiod] root 2279 0.0 0.0 0 0 ? I< 12:23 0:00 _ [kworker/2:2H] root 2345 0.0 0.0 0 0 ? I< 12:23 0:00 _ [dio/dm-0] root 2360 0.0 0.0 0 0 ? I< 12:23 0:00 _ [btrfs-worker] root 2361 0.0 0.0 0 0 ? I< 12:23 0:00 _ [btrfs-worker-hi] root 2363 0.0 0.0 0 0 ? I< 12:23 0:00 _ [btrfs-delalloc] root 2364 0.0 0.0 0 0 ? I< 12:23 0:00 \ [btrfs-flushdel] root 2365 0.0 0.0 0 0 ? I< 12:23 0:00 _ [btrfs-cache] root 2366 0.0 0.0 0 0 ? I< 12:23 0:00 _ [btrfs-fixup] root 2367 0.0 0.0 0 0 ? I< 12:23 0:00 _ [btrfs-endio] root 2368 0.0 0.0 0 0 ? I< 12:23 0:00 _ [btrfs-endio-met] root 2369 0.0 0.0 0 0 ? I< 12:23 0:00 _ [btrfs-endio-rai] root 2370 0.0 0.0 0 0 ? I< 12:23 0:00 _ [btrfs-rmw] root 2371 0.0 0.0 0 0 ? I< 12:23 0:00 _ [btrfs-endio-wri] root 2372 0.0 0.0 0 0 ? I< 12:23 0:00 _ [btrfs-compresse] root 2373 0.0 0.0 0 0 ? I< 12:23 0:00 _ [btrfs-freespace] root 2374 0.0 0.0 0 0 ? I< 12:23 0:00 _ [btrfs-delayed-m] root 2375 0.0 0.0 0 0 ? I< 12:23 0:00 _ [btrfs-qgroup-re] root 2376 0.0 0.0 0 0 ? S 12:23 0:00 _ [btrfs-cleaner] root 2377 0.0 0.0 0 0 ? S 12:23 0:00 _ [btrfs-transaction] root 2661 0.0 0.0 0 0 ? I 12:23 0:00 \ [kworker/u8:7-eventsunbound] root 2813 0.0 0.0 0 0 ? I 12:24 0:00 _ [kworker/u8:8] root 2919 0.0 0.0 0 0 ? I 12:24 0:00 \ [kworker/1:4] root 1 0.2 0.0 3296 1892 ? Ss 12:23 0:00 init [5] root 549 0.8 0.1 23480 6064 ? S 12:23 0:01 /sbin/udevd rpc 1673 0.0 0.0 4420 2076 ? Ss 12:23 0:00 /sbin/rpcbind -w statd 1682 0.0 0.0 4532 1760 ? Ss 12:23 0:00 /sbin/rpc.statd root 1697 0.0 0.0 2832 1964 ? Ss 12:23 0:00 /usr/sbin/rpc.idmapd root 1988 0.0 0.0 2632 1724 ? Ss 12:23 0:00 /usr/sbin/acpid root 2055 0.0 0.0 2492 916 ? S 12:23 0:00 /usr/sbin/seatd -g video root 2074 0.0 0.0 152752 1800 ? Sl 12:23 0:00 /usr/bin/lxcfs /var/lib/lxcfs root 2089 0.5 0.1 8264 4184 ? Ss 12:23 0:00 @usr/sbin/haveged root 2096 0.0 0.0 2576 104 ? Ss 12:23 0:00 /usr/sbin/gpm -m /dev/input/mice -t exps2 message+ 2113 0.1 0.0 4560 1976 ? Ss 12:23 0:00 /usr/bin/dbus-daemon --system root 2120 0.0 0.0 11952 2980 ? Ss 12:23 0:00 sshd: /usr/sbin/sshd [listener] 0 of 10-100 startups root 2135 1.4 0.3 23876 15380 ? Ss 12:23 0:02 /usr/bin/slimski -d root 2143 3.0 1.8 351548 75332 tty7 Rsl+ 12:23 0:04 _ /usr/lib/xorg/Xorg -nolisten tcp -auth /var/run/slimski.auth vt07 catav 2677 0.4 0.0 77476 3832 ? Ss 12:24 0:00 _ /bin/bash /usr/local/bin/desktop-session zzz-icewm catav 2739 0.0 0.0 9420 2380 ? S 12:24 0:00 _ /usr/bin/icewm-session catav 2745 1.8 0.4 147840 18616 ? Ss 12:24 0:02 _ /usr/bin/icewm --notify avahi 2146 0.0 0.0 3660 2340 ? S 12:23 0:00 avahi-daemon: running [medantix.local] avahi 2147 0.0 0.0 3480 192 ? S 12:23 0:00 _ avahi-daemon: chroot helper root 2149 0.0 0.0 76624 2128 ? Ss 12:23 0:00 /usr/sbin/cron root 2150 0.0 0.0 8240 1356 ? S 12:23 0:00 /usr/sbin/smartd --pidfile /var/run/smartd.pid root 2153 0.0 0.1 9708 5488 ? S 12:23 0:00 /usr/sbin/bluetoothd root 2164 3.5 2.3 1841604 96000 ? Sl 12:23 0:05 /usr/bin/lxd --group lxd --logfile=/var/log/lxd/lxd.log nobody 2409 1.3 0.4 20644 17160 ? Ss 12:23 0:02 \ dnsmasq --keep-in-foreground --strict-order --bind-interfaces --except-interface=lo --pid-file= --no-ping --interface=lxdbr0 --dhcp-rapid-commit --quiet-dhcp --quiet-dhcp6 --quiet-ra --listen-address=10.17.247.1 --dhcp-no-override --dhcp-authoritative --dhcp-leasefile=/var/lib/lxd/networks/lxdbr0/dnsmasq.leases --dhcp-hostsfile=/var/lib/lxd/networks/lxdbr0/dnsmasq.hosts --dhcp-range 10.17.247.2,10.17.247.254,1h --listen-address=fd42:6e83:9e3d:1e00::1 --enable-ra --dhcp-range ::,constructor:lxdbr0,ra-stateless,ra-names -s lxd --interface-name _gateway.lxd,lxdbr0 -S /lxd/ --conf-file=/var/lib/lxd/networks/lxdbr0/dnsmasq.raw -u nobody -g lxd root 2173 0.1 0.1 13684 4652 ? Ss 12:23 0:00 /usr/sbin/connmand --nodnsproxy root 2213 0.2 0.2 13840 10256 ? S 12:23 0:00 /sbin/wpa_supplicant -u -s -O /run/wpasupplicant root 2216 0.0 0.1 12524 6244 ? Ss 12:23 0:00 /usr/sbin/cupsd -C /etc/cups/cupsd.conf -s /etc/cups/cups-files.conf root 2261 0.0 0.0 42016 480 ? Ss 12:23 0:00 /usr/sbin/saned -a saned root 2269 0.0 0.0 42016 480 ? S 12:23 0:00 \ /usr/sbin/saned -a saned postgres 2329 0.1 0.7 288276 29584 ? Ss 12:23 0:00 /usr/lib/postgresql/15/bin/postgres -D /var/lib/postgresql/15/main -c configfile=/etc/postgresql/15/main/postgresql.conf postgres 2330 0.0 0.1 288408 5860 ? Ss 12:23 0:00 _ postgres: 15/main: checkpointer postgres 2331 0.0 0.1 288428 5812 ? Ss 12:23 0:00 _ postgres: 15/main: background writer postgres 2333 0.0 0.2 288276 10276 ? Ss 12:23 0:00 _ postgres: 15/main: walwriter postgres 2334 0.0 0.2 289876 8532 ? Ss 12:23 0:00 _ postgres: 15/main: autovacuum launcher postgres 2335 0.0 0.1 289856 6812 ? Ss 12:23 0:00 _ postgres: 15/main: logical replication launcher root 2478 0.0 0.4 1281536 19848 ? Ss 12:23 0:00 [lxc monitor] /var/lib/lxd/containers tedis 165536 2486 0.4 0.2 165312 9976 ? Ss 12:23 0:00 _ /sbin/init 165536 2645 0.3 0.2 31996 11928 ? Ss 12:23 0:00 _ /lib/systemd/systemd-journald 165536 2654 0.0 0.1 20612 4744 ? Ss 12:23 0:00 _ /lib/systemd/systemd-udevd 165637 2658 0.2 0.1 16048 6008 ? Ss 12:23 0:00 _ /lib/systemd/systemd-networkd 165639 2664 0.0 0.1 8228 4232 ? Ss 12:23 0:00 _ /usr/bin/dbus-daemon --system --address=systemd: --nofork --nopidfile --systemd-activation --syslog-only 165536 2666 0.2 0.1 13400 5616 ? Ss 12:23 0:00 _ /lib/systemd/systemd-logind 165638 2667 0.2 0.2 21204 8304 ? Ss 12:23 0:00 _ /lib/systemd/systemd-resolved 165536 2673 0.0 0.0 5476 2280 pts/0 Ss+ 12:23 0:00 _ /sbin/agetty -o -p -- \u --noclear --keep-baud console 115200,38400,9600 linux root 2536 0.0 0.0 75888 1048 tty1 Ss+ 12:23 0:00 /sbin/getty --noclear 38400 tty1 root 2537 0.0 0.0 75888 1036 tty2 Ss+ 12:23 0:00 /sbin/getty 38400 tty2 root 2538 0.0 0.0 75888 1020 tty3 Ss+ 12:23 0:00 /sbin/getty 38400 tty3 root 2539 0.0 0.0 75888 1076 tty4 Ss+ 12:23 0:00 /sbin/getty 38400 tty4 root 2540 0.0 0.0 75888 1060 tty5 Ss+ 12:23 0:00 /sbin/getty 38400 tty5 root 2541 0.0 0.0 75888 1028 tty6 Ss+ 12:23 0:00 /sbin/getty 38400 tty6 catav 2755 1.3 0.9 299088 36316 ? S 12:24 0:01 zzzfm --desktop catav 2795 0.0 0.0 76948 1736 ? S 12:24 0:00 /bin/bash /home/catav/.desktop-session/startup catav 2991 0.1 0.6 417656 24312 ? Sl 12:24 0:00 _ volumeicon catav 2802 0.0 0.0 76948 1648 ? S 12:24 0:00 /bin/bash /usr/local/bin/pipewire-start catav 2827 0.1 0.2 177748 11732 ? Sl 12:24 0:00 _ pipewire catav 2806 1.5 0.2 465044 9692 ? Sl 12:24 0:02 conky catav 2828 0.1 0.3 99796 14520 ? S 12:24 0:00 fbxkb catav 2841 0.0 0.0 6512 1992 ? S 12:24 0:00 dbus-launch --autolaunch 8fbc0c8a96ae65ad515322c06564890d --binary-syntax --close-stderr catav 2847 0.0 0.0 4440 2096 ? Ss 12:24 0:00 /usr/bin/dbus-daemon --syslog-only --fork --print-pid 5 --print-address 7 --session catav 2874 0.0 0.0 77472 3772 ? S 12:24 0:00 /bin/bash /usr/bin/devmon --exec-on-drive desktop-defaults-run -fm "%d" --exec-on-disc desktop-defaults-run -fm "%d" catav 2979 0.0 0.0 78924 3832 ? S 12:24 0:00 _ /usr/bin/udevil --monitor catav 2885 0.5 0.5 398056 21928 ? Sl 12:24 0:00 wireplumber catav 2888 0.0 0.1 166956 7688 ? Sl 12:24 0:00 pipewire-pulse catav 3278 4.8 2.7 659188 110384 ? Sl 12:24 0:05 cmst catav 3379 0.9 0.8 302632 33220 ? S 12:25 0:00 roxterm catav 3401 2.6 0.1 80732 7016 pts/0 Ss 12:25 0:01 _ /usr/bin/zsh catav 3623 600 0.0 77776 3968 pts/0 R+ 12:26 0:00 \ ps fauxww

zcatav commented 9 months ago

And finally nft -a list ruleset table inet lxd { # handle 5 chain pstrt.lxdbr0 { # handle 1 type nat hook postrouting priority srcnat; policy accept; ip saddr 10.17.247.0/24 ip daddr != 10.17.247.0/24 masquerade # handle 2 ip6 saddr fd42:6e83:9e3d:1e00::/64 ip6 daddr != fd42:6e83:9e3d:1e00::/64 masquerade # handle 3 }

chain fwd.lxdbr0 { # handle 4
    type filter hook forward priority filter; policy accept;
    ip version 4 oifname "lxdbr0" accept # handle 5
    ip version 4 iifname "lxdbr0" accept # handle 6
    ip6 version 6 oifname "lxdbr0" accept # handle 7
    ip6 version 6 iifname "lxdbr0" accept # handle 8
}

chain in.lxdbr0 { # handle 9
    type filter hook input priority filter; policy accept;
    iifname "lxdbr0" tcp dport 53 accept # handle 11
    iifname "lxdbr0" udp dport 53 accept # handle 12
    iifname "lxdbr0" icmp type { destination-unreachable, time-exceeded, parameter-problem } accept # handle 14
    iifname "lxdbr0" udp dport 67 accept # handle 15
    iifname "lxdbr0" icmpv6 type { destination-unreachable, packet-too-big, time-exceeded, parameter-problem, nd-router-solicit, nd-neighbor-solicit, nd-neighbor-advert, mld2-listener-report } accept # handle 17
    iifname "lxdbr0" udp dport 547 accept # handle 18
}

chain out.lxdbr0 { # handle 10
    type filter hook output priority filter; policy accept;
    oifname "lxdbr0" tcp sport 53 accept # handle 19
    oifname "lxdbr0" udp sport 53 accept # handle 20
    oifname "lxdbr0" icmp type { destination-unreachable, time-exceeded, parameter-problem } accept # handle 22
    oifname "lxdbr0" udp sport 67 accept # handle 23
    oifname "lxdbr0" icmpv6 type { destination-unreachable, packet-too-big, time-exceeded, parameter-problem, echo-request, nd-router-advert, nd-neighbor-solicit, nd-neighbor-advert, mld2-listener-report } accept # handle 25
    oifname "lxdbr0" udp sport 547 accept # handle 26
}

}

zcatav commented 9 months ago

Hello, When I saw both iptables and nftables in the system, I wondered why there were both. I uninstalled the old iptables. Connman and ufw were also deleted from the system. I set cni instead of connman, ufw was already closed. The system now appears to be working as it should.