evilsocket / opensnitch

OpenSnitch is a GNU/Linux interactive application firewall inspired by Little Snitch.
GNU General Public License v3.0
10.74k stars 498 forks source link

service refuse to start, ipv6 problem #234

Closed ghost closed 3 years ago

ghost commented 5 years ago

hello,

open-snitch service is refusing to start with ipv6.disable=1 in grub

thanks

^[[2m[2018-12-28 04:33:29]^[[0m ^[[97m^[[104m IMP ^[[0m Starting opensnitch-daemon v1.0.0b
^[[2m[2018-12-28 04:33:29]^[[0m ^[[97m^[[42m INF ^[[0m Loading rules from /etc/opensnitchd/rules ...
^[[2m[2018-12-28 04:33:29]^[[0m ^[[97m^[[41m^[[1m !!! ^[[0m Error while running conntrack firewall rule: exit status 1
opensnitchd.service - OpenSnitch is a GNU/Linux port of the Little Snitch application firewall.
   Loaded: loaded (/usr/lib/systemd/system/opensnitchd.service; enabled; vendor preset: disabled)
   Active: activating (auto-restart) (Result: exit-code) since Fri 2018-12-28 05:33:08 CET; 5s ago
     Docs: https://github.com/evilsocket/opensnitch
  Process: 4010 ExecStart=/usr/bin/opensnitchd -log-file /var/log/opensnitchd.log -rules-path /etc/opensnitchd/rules -ui-sock>
  Process: 4009 ExecStartPre=/bin/mkdir -p /etc/opensnitchd/rules (code=exited, status=0/SUCCESS)
 Main PID: 4010 (code=exited, status=1/FAILURE)
28/12/2018 05:33    sudo         mi : TTY=pts/5 ; PWD=/home/mi ; USER=root ; COMMAND=/usr/bin/systemctl start opensnitchd
28/12/2018 05:33    sudo    pam_unix(sudo:session): session opened for user root by mi(uid=0)
28/12/2018 05:33    systemd Starting OpenSnitch is a GNU/Linux port of the Little Snitch application firewall....
28/12/2018 05:33    systemd Started OpenSnitch is a GNU/Linux port of the Little Snitch application firewall..
28/12/2018 05:33    audit   SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 msg='unit=opensnitchd comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success'
28/12/2018 05:33    sudo    pam_unix(sudo:session): session closed for user root
28/12/2018 05:33    kernel  audit: type=1130 audit(1545971608.945:832): pid=1 uid=0 auid=4294967295 ses=4294967295 msg='unit=opensnitchd comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success'
28/12/2018 05:33    audit   NETFILTER_CFG table=filter family=2 entries=174
28/12/2018 05:33    audit   SYSCALL arch=c000003e syscall=54 success=yes exit=0 a0=4 a1=0 a2=40 a3=55b9fbe80740 items=0 ppid=4051 pid=4059 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="iptables" exe="/usr/bin/xtables-legacy-multi" key=(null)
28/12/2018 05:33    audit   PROCTITLE proctitle=2F7573722F62696E2F69707461626C6573002D4900494E5055540031002D2D70726F746F636F6C00756470002D2D73706F7274003533002D6A004E465155455545002D2D71756575652D6E756D0030002D2D71756575652D627970617373
28/12/2018 05:33    kernel  audit: type=1325 audit(1545971609.065:833): table=filter family=2 entries=174
28/12/2018 05:33    kernel  audit: type=1300 audit(1545971609.065:833): arch=c000003e syscall=54 success=yes exit=0 a0=4 a1=0 a2=40 a3=55b9fbe80740 items=0 ppid=4051 pid=4059 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="iptables" exe="/usr/bin/xtables-legacy-multi" key=(null)
28/12/2018 05:33    kernel  audit: type=1327 audit(1545971609.065:833): proctitle=2F7573722F62696E2F69707461626C6573002D4900494E5055540031002D2D70726F746F636F6C00756470002D2D73706F7274003533002D6A004E465155455545002D2D71756575652D6E756D0030002D2D71756575652D627970617373
28/12/2018 05:33    audit   NETFILTER_CFG table=mangle family=2 entries=29
28/12/2018 05:33    audit   SYSCALL arch=c000003e syscall=54 success=yes exit=0 a0=4 a1=0 a2=40 a3=559734c8f940 items=0 ppid=4051 pid=4060 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="iptables" exe="/usr/bin/xtables-legacy-multi" key=(null)
28/12/2018 05:33    audit   PROCTITLE proctitle=2F7573722F62696E2F69707461626C6573002D41004F5554505554002D74006D616E676C65002D6D00636F6E6E747261636B002D2D63747374617465004E4557002D6A004E465155455545002D2D71756575652D6E756D0030002D2D71756575652D627970617373
28/12/2018 05:33    kernel  audit: type=1325 audit(1545971609.068:834): table=mangle family=2 entries=29
28/12/2018 05:33    kernel  audit: type=1300 audit(1545971609.068:834): arch=c000003e syscall=54 success=yes exit=0 a0=4 a1=0 a2=40 a3=559734c8f940 items=0 ppid=4051 pid=4060 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="iptables" exe="/usr/bin/xtables-legacy-multi" key=(null)
28/12/2018 05:33    kernel  audit: type=1327 audit(1545971609.068:834): proctitle=2F7573722F62696E2F69707461626C6573002D41004F5554505554002D74006D616E676C65002D6D00636F6E6E747261636B002D2D63747374617465004E4557002D6A004E465155455545002D2D71756575652D6E756D0030002D2D71756575652D627970617373
28/12/2018 05:33    opensnitchd ERROR: path=/usr/bin/ip6tables args=[-A OUTPUT -t mangle -m conntrack --ctstate NEW -j NFQUEUE --queue-num 0 --queue-bypass] err=exit status 1 out='Could not open socket to kernel: Address family not supported by protocol
28/12/2018 05:33    opensnitchd '
28/12/2018 05:33    systemd opensnitchd.service: Main process exited, code=exited, status=1/FAILURE
28/12/2018 05:33    systemd opensnitchd.service: Failed with result 'exit-code'.
28/12/2018 05:33    audit   SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 msg='unit=opensnitchd comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=failed'
28/12/2018 05:33    kernel  audit: type=1131 audit(1545971609.088:835): pid=1 uid=0 auid=4294967295 ses=4294967295 msg='unit=opensnitchd comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=failed'
ghost commented 5 years ago

qomui has about the same problem and they fixed it in those commits: https://github.com/corrad1nho/qomui/commit/486ff2e413b2901b46ef169fb892095a21efcbac https://github.com/corrad1nho/qomui/commit/2405eef179802cc24c0e51bdc85994ead5e449dd https://github.com/corrad1nho/qomui/commit/1e4045f6af4d1d3423742e81728d7c205b15de67

thanks

gustavo-iniguez-goya commented 3 years ago

Fixed in latest version.