Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Networking issues with fedora-25, debian-9 as NetVM template in 4.0rc1 #2964

Closed
0spinboson opened this issue Aug 4, 2017 · 14 comments
Closed
Labels
C: Debian/Ubuntu C: Fedora T: bug Type: bug report. A problem or defect resulting in unintended behavior in something that exists.
Milestone

Comments

@0spinboson
Copy link

0spinboson commented Aug 4, 2017

Qubes OS version (e.g., R3.2):

4.0rc1

Affected TemplateVMs (e.g., fedora-23, if applicable):

fedora-25, debian-9

Expected behavior:

can use either or both of the templates for sys-net, sys-firewall.

Actual behavior:

(on 2 computers): fedora-25 almost never works as sys-net, but does sometimes (so I don't get it).

Debian-8 as netVM works flawlessly, but when I updated that (fresh) template to debian-9, it also stopped forwarding to sys-firewall.
Connectivity inside sys-net is fine, and/so connecting dom0 updater to the netVM directly does work.

@andrewdavidwong andrewdavidwong added T: bug Type: bug report. A problem or defect resulting in unintended behavior in something that exists. C: Debian/Ubuntu C: Fedora labels Aug 5, 2017
@andrewdavidwong andrewdavidwong added this to the Release 4.0 milestone Aug 5, 2017
@marmarek
Copy link
Member

marmarek commented Aug 6, 2017

Can you be more specific than "fedora-25 almost never works as sys-net"? What exactly happen?

@andrewdavidwong
Copy link
Member

I can confirm this on R3.2. When I try to use fedora-25 or fedora-25-minimal as the TemplateVM for sys-net, I can connect to Wi-Fi networks as normal, but AppVMs have no internet connection. Switching sys-net back to fedora-24* immediately fixes it.

@0spinboson
Copy link
Author

0spinboson commented Aug 7, 2017

no packets are forwarded to sys-firewall or beyond (though it randomly did work one time, I have no idea how/why). Compare these three logs of 'iptables -L -vn' run in sys-net, which are hopefully more informative. No rules added or changed by me, this is the out of the box configuration.

iptablesfc25.txt
iptablesd9.txt
iptablesd8.txt

@marmarek
Copy link
Member

marmarek commented Aug 7, 2017

Can you include the same with -t nat option?

@0spinboson
Copy link
Author

@marmarek
Copy link
Member

marmarek commented Aug 7, 2017

Looks ok... What is value of /proc/sys/net/ipv4/ip_forward?

@marmarek
Copy link
Member

marmarek commented Aug 7, 2017

(just one of broken cases is enough)

@0spinboson
Copy link
Author

0spinboson commented Aug 7, 2017 via email

@tlaurion
Copy link
Contributor

tlaurion commented Sep 7, 2017

Also have the bug. Any other troubleshooting paths to suggest? Other output that would help in troubleshooting this issue?

@andrewdavidwong
Copy link
Member

@tlaurion: In my case, it turned out that #3008 was the real problem. Blacklisting iwlmvm fixed it. (See the comments on that issue.)

@0spinboson
Copy link
Author

Glad your issue was resolved, but I never use sleep/standby, and I also don't use wifi.

@marmarek
Copy link
Member

Maybe you can track with tcpdump where exactly the packets are lost?

@0spinboson
Copy link
Author

I have no idea why, but for me the issue with fc25 and fc26 not being usable as the sys-net template has disappeared with rc2.

@andrewdavidwong
Copy link
Member

Closing this as "resolved" for now. If you believe the issue is not yet resolved, or if anyone is still affected by this issue, please leave a comment, and we'll be happy to reopen this. Thank you.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
C: Debian/Ubuntu C: Fedora T: bug Type: bug report. A problem or defect resulting in unintended behavior in something that exists.
Projects
None yet
Development

No branches or pull requests

4 participants