From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org X-Spam-Level: ** X-Spam-Status: No, score=2.5 required=3.0 tests=DKIM_INVALID,DKIM_SIGNED, HEADER_FROM_DIFFERENT_DOMAINS,HTML_MESSAGE,MAILING_LIST_MULTI, NUMERIC_HTTP_ADDR,SPF_HELO_NONE,SPF_PASS autolearn=no autolearn_force=no version=3.4.0 Received: from mail.kernel.org (mail.kernel.org [198.145.29.99]) by smtp.lore.kernel.org (Postfix) with ESMTP id 0F624C35DEE for ; Tue, 25 Feb 2020 00:47:19 +0000 (UTC) Received: from krantz.zx2c4.com (krantz.zx2c4.com [192.95.5.69]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by mail.kernel.org (Postfix) with ESMTPS id A3D182072D for ; Tue, 25 Feb 2020 00:47:18 +0000 (UTC) Authentication-Results: mail.kernel.org; dkim=fail reason="signature verification failed" (2048-bit key) header.d=panagiotou.net header.i=@panagiotou.net header.b="Z0HGc+KG" DMARC-Filter: OpenDMARC Filter v1.3.2 mail.kernel.org A3D182072D Authentication-Results: mail.kernel.org; dmarc=none (p=none dis=none) header.from=panagiotou.net Authentication-Results: mail.kernel.org; spf=pass smtp.mailfrom=wireguard-bounces@lists.zx2c4.com Received: from krantz.zx2c4.com (localhost [IPv6:::1]) by krantz.zx2c4.com (ZX2C4 Mail Server) with ESMTP id c59aca29; Tue, 25 Feb 2020 00:43:48 +0000 (UTC) Received: from krantz.zx2c4.com (localhost [127.0.0.1]) by krantz.zx2c4.com (ZX2C4 Mail Server) with ESMTP id 5beb617b for ; Sun, 23 Feb 2020 16:46:22 +0000 (UTC) Received: from mail-lj1-x22f.google.com (mail-lj1-x22f.google.com [IPv6:2a00:1450:4864:20::22f]) by krantz.zx2c4.com (ZX2C4 Mail Server) with ESMTP id 0cae0c3f for ; Sun, 23 Feb 2020 16:46:21 +0000 (UTC) Received: by mail-lj1-x22f.google.com with SMTP id o15so7393844ljg.6 for ; Sun, 23 Feb 2020 08:49:38 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=panagiotou.net; s=google; h=mime-version:references:in-reply-to:from:date:message-id:subject:to :cc; bh=7zXu98uAszyshVoLHPpl4UVLbidpbbSKtIKvE36eNUc=; b=Z0HGc+KG124HtJUMxBH9HeejQZ9PnKtlST6HcEZBvD10WZ6T1BCq/lkwbe5NDl3TFB naI5p2gJUz+GTIyR41JB/cRsYT0YclB6b94v7cAk/xHsJVJJE2d9md6oonn/0OMRmawR BEcQMKRlSj7SAhv9h7OXk0GuoVVgezw5mBpgprnyQZEYbH3Zm/FG6XMFMDKF4BTYtFiF ZBSgoo8gqAL59WnKy9qM1f+seuKQSKhyVa+JPJn/4dcsX6ynWoyRdalRzRizcP8FGwQH +oVjh0PEQ8/dE0TDqsbd+tUET6pd65npNtKBFKd/wCqmA7Ex87zsLfuuQLpOsoyOZDUw dg6g== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc; bh=7zXu98uAszyshVoLHPpl4UVLbidpbbSKtIKvE36eNUc=; b=KfAmxKU6hLHCalfwE4R5tg3ufI36gK/XVJtTED8Fxg+rrlgD31iFTlO0ZZlh3WKlfZ QgKlqo8EfzxwwBYtx31rX6E4TdbgxqU2Ph8GLfwUnXoQs3UcvIVVipgnjh1xZfwHf9HW ptrweV9zfh7cDjX3PrbkbDC/a2FNyV7qlB/xlSuZniNzVLDO6wBmZ+Skx5jAqFWLgNKB xvz0CS4W3KDBzFlkNNki+YRN9f1Od1wYbm/5/pKCP57XaLsxEbJxX06kmUT/PtPK7aOg vZUn63TaF5a+3dgcxh30Q/VxUNFdaVCzxV5suDA+ThgFgSTxx2uofoJnh0WtzeOe96TJ 0m1Q== X-Gm-Message-State: APjAAAVY3SeUGuO04vXtOb3WpvztgFyUpk+WiDh9A5IQH1IRUc5vq0L9 Q1wZyDZqrlCunVP8vweG+KSMQaVADtk0RHV5THXfBPftr4g= X-Google-Smtp-Source: APXvYqy/Q7ZaijUXWi9GTXycSiZYuBhShouhGqZc3+1HP/J68stvY1TmJIulLNPK/GkvuQOi3zXdEC9/03NBs4APsEU= X-Received: by 2002:a2e:98ca:: with SMTP id s10mr5125992ljj.160.1582476577066; Sun, 23 Feb 2020 08:49:37 -0800 (PST) MIME-Version: 1.0 References: In-Reply-To: From: "Dimitri J. Panagiotou" Date: Sun, 23 Feb 2020 08:49:25 -0800 Message-ID: Subject: Re: xtables lock at startup? To: "Jason A. Donenfeld" X-Mailman-Approved-At: Tue, 25 Feb 2020 01:43:43 +0100 Cc: WireGuard mailing list X-BeenThere: wireguard@lists.zx2c4.com X-Mailman-Version: 2.1.15 Precedence: list List-Id: Development discussion of WireGuard List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Content-Type: multipart/mixed; boundary="===============7386313506830649731==" Errors-To: wireguard-bounces@lists.zx2c4.com Sender: "WireGuard" --===============7386313506830649731== Content-Type: multipart/alternative; boundary="0000000000003de459059f410ae2" --0000000000003de459059f410ae2 Content-Type: text/plain; charset="UTF-8" OK, thanks. On Sun, Feb 23, 2020 at 2:58 AM Jason A. Donenfeld wrote: > Do what it says; pass the -w option to iptables. > > On Sun, Feb 23, 2020, 11:36 Dimitri J. Panagiotou > wrote: > >> Hi, >> >> Since upgrading to Fedora 31 (5.5), wireguard (latest) does not start >> after rebooting. >> It does start with no problem at all after rebooting, by manually running >> wg-quick. >> >> This is what I get: >> -- Reboot -- >> Feb 22 01:19:48 myservername systemd[1]: Starting WireGuard via >> wg-quick(8) for wg0... >> Feb 22 01:19:49 myservername wg-quick[1173]: [#] ip link add wg0 type >> wireguard >> Feb 22 01:19:49 myservername wg-quick[1173]: [#] wg setconf wg0 /dev/fd/63 >> Feb 22 01:19:50 myservername wg-quick[1173]: [#] ip -4 address add >> 10.12.182.1/24 dev wg0 >> Feb 22 01:19:50 myservername wg-quick[1173]: [#] ip link set mtu 1420 up >> dev wg0 >> Feb 22 01:19:50 myservername wg-quick[1173]: [#] mount `10.12.197.1' >> /etc/resolv.conf >> Feb 22 01:19:51 myservername wg-quick[1173]: [#] iptables -A FORWARD -i >> wg0 -j ACCEPT; iptables -t nat -A POSTROUTING -o enp2s0 -j MASQUERADE >> Feb 22 01:19:51 myservername wg-quick[1173]: Another app is currently >> holding the xtables lock. Perhaps you want to use the -w option? >> Feb 22 01:19:51 myservername wg-quick[1173]: [#] umount /etc/resolv.conf >> Feb 22 01:19:51 myservername wg-quick[1173]: [#] ip link delete dev wg0 >> Feb 22 01:19:51 myservername systemd[1]: wg-quick@wg0.service: Main >> process exited, code=exited, status=4/NOPERMISSION >> Feb 22 01:19:51 myservername systemd[1]: wg-quick@wg0.service: Failed >> with result 'exit-code'. >> Feb 22 01:19:51 myservername systemd[1]: Failed to start WireGuard via >> wg-quick(8) for wg0. >> >> Running >> wireguard-dkms.noarch 1:0.0.20200215-2.fc31 >> @jdoss-wireguard >> wireguard-tools.x86_64 1:1.0.20200102-1.fc31 >> @jdoss-wireguard >> >> Any idea what's causing this? >> >> Thanks, >> -dimitri >> >> >> _______________________________________________ >> WireGuard mailing list >> WireGuard@lists.zx2c4.com >> https://lists.zx2c4.com/mailman/listinfo/wireguard >> > --0000000000003de459059f410ae2 Content-Type: text/html; charset="UTF-8" Content-Transfer-Encoding: quoted-printable
OK, thanks.



On Sun, Feb 23, 2020 at 2:58 AM Jason A. Done= nfeld <Jason@zx2c4.= com> wrote:
Do what it says; pass the -w option to iptables.
=
On Sun, Feb 23, 2020, 11:36 Dimitri J. Panagioto= u <dimitri@p= anagiotou.net> wrote:
Hi,

Since up= grading to Fedora 31 (5.5), wireguard (latest) does not start after rebooti= ng.
It does start with no problem at all after rebooting,= by manually running wg-quick.

Thi= s is what I get:
-- Reboot --
Feb 22 01:19:48 myservername systemd[1]: Starting WireGuard vi= a wg-quick(8) for wg0...
Feb 22 01:19:49 = myservername wg-quick[1173]: [#] ip link add wg0 type wireguard
<= font color=3D"#330033">Feb 22 01:19:49 myservername wg-quick[1173]: [#] wg = setconf wg0 /dev/fd/63
Feb 22 01:19:50 my= servername wg-quick[1173]: [#] ip -4 address add 10.12.182.1/24 dev wg0
Feb 22 01:19:50 myservername wg-quick[1173]:= [#] ip link set mtu 1420 up dev wg0
Feb = 22 01:19:50 myservername wg-quick[1173]: [#] mount `10.12.197.1' /etc/r= esolv.conf
Feb 22 01:19:51 myservername w= g-quick[1173]: [#] iptables -A FORWARD -i wg0 -j ACCEPT; iptables -t nat -A= POSTROUTING -o enp2s0 -j MASQUERADE
Feb = 22 01:19:51 myservername wg-quick[1173]: Another app is currently holding t= he xtables lock. Perhaps you want to use the -w option?
Feb 22 01:19:51 myservername wg-quick[1173]: [#] umount /etc= /resolv.conf
Feb 22 01:19:51 myservername= wg-quick[1173]: [#] ip link delete dev wg0
Feb 22 01:19:51 myservername systemd[1]: wg-quick@wg0.service: Main proc= ess exited, code=3Dexited, status=3D4/NOPERMISSION
Feb 22 01:19:51 myservername systemd[1]: wg-quick@wg0.service: Fa= iled with result 'exit-code'.
Feb= 22 01:19:51 myservername systemd[1]: Failed to start WireGuard via wg-quic= k(8) for wg0.

Running= =C2=A0
wireguard-dkms.noarch =C2=A0 =C2=A0 =C2=A0 =C2=A0 = =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 1:0.0.20200215-2.fc= 31 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0@jdoss-wir= eguard
wireguard-tools.x86_64 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 = =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A01:1.0.20200102-1.fc31 =C2=A0 =C2= =A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0@jdoss-wireguard

Any idea what's causing this?=C2= =A0=C2=A0

Thanks,
-dimitri


_______________________________________________
WireGuard mailing list
WireGuard@lists.zx2c4.com
https://lists.zx2c4.com/mailman/listinf= o/wireguard
--0000000000003de459059f410ae2-- --===============7386313506830649731== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline _______________________________________________ WireGuard mailing list WireGuard@lists.zx2c4.com https://lists.zx2c4.com/mailman/listinfo/wireguard --===============7386313506830649731==--