Commit 105aee6
committed
iptables rule without an ip range applies to all interfaces
The current logic pretends it only applies to 127.0.0.1, which
means the new `guestIPMustBeZero` rule does not detect it properly.
This is a problem with nerdctl and containerd on Alpine. It works
"by accident" on Ubuntu because the port was also bound to [::],
which had an entry in /proc/net/tcp6.
Signed-off-by: Jan Dubois <jan.dubois@suse.com>1 parent 943c90b commit 105aee6
2 files changed
+4
-6
lines changed| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
75 | 75 | | |
76 | 76 | | |
77 | 77 | | |
78 | | - | |
79 | | - | |
80 | | - | |
| 78 | + | |
81 | 79 | | |
82 | 80 | | |
83 | | - | |
| 81 | + | |
84 | 82 | | |
85 | 83 | | |
86 | 84 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
84 | 84 | | |
85 | 85 | | |
86 | 86 | | |
87 | | - | |
88 | | - | |
| 87 | + | |
| 88 | + | |
89 | 89 | | |
90 | 90 | | |
91 | 91 | | |
| |||
0 commit comments