summaryrefslogtreecommitdiffstats
path: root/meta/recipes-extended/iptables
diff options
context:
space:
mode:
authorRichard Purdie <richard.purdie@linuxfoundation.org>2025-11-07 13:31:53 +0000
committerRichard Purdie <richard.purdie@linuxfoundation.org>2025-11-07 13:31:53 +0000
commit8c22ff0d8b70d9b12f0487ef696a7e915b9e3173 (patch)
treeefdc32587159d0050a69009bdf2330a531727d95 /meta/recipes-extended/iptables
parentd412d2747595c1cc4a5e3ca975e3adc31b2f7891 (diff)
downloadpoky-8c22ff0d8b70d9b12f0487ef696a7e915b9e3173.tar.gz
The poky repository master branch is no longer being updated.
You can either: a) switch to individual clones of bitbake, openembedded-core, meta-yocto and yocto-docs b) use the new bitbake-setup You can find information about either approach in our documentation: https://docs.yoctoproject.org/ Note that "poky" the distro setting is still available in meta-yocto as before and we continue to use and maintain that. Long live Poky! Some further information on the background of this change can be found in: https://lists.openembedded.org/g/openembedded-architecture/message/2179 Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
Diffstat (limited to 'meta/recipes-extended/iptables')
-rw-r--r--meta/recipes-extended/iptables/iptables/ip6tables.rules0
-rw-r--r--meta/recipes-extended/iptables/iptables/ip6tables.service13
-rw-r--r--meta/recipes-extended/iptables/iptables/iptables.rules0
-rw-r--r--meta/recipes-extended/iptables/iptables/iptables.service13
-rw-r--r--meta/recipes-extended/iptables/iptables_1.8.11.bb124
5 files changed, 0 insertions, 150 deletions
diff --git a/meta/recipes-extended/iptables/iptables/ip6tables.rules b/meta/recipes-extended/iptables/iptables/ip6tables.rules
deleted file mode 100644
index e69de29bb2..0000000000
--- a/meta/recipes-extended/iptables/iptables/ip6tables.rules
+++ /dev/null
diff --git a/meta/recipes-extended/iptables/iptables/ip6tables.service b/meta/recipes-extended/iptables/iptables/ip6tables.service
deleted file mode 100644
index 6c059fca49..0000000000
--- a/meta/recipes-extended/iptables/iptables/ip6tables.service
+++ /dev/null
@@ -1,13 +0,0 @@
1[Unit]
2Description=IPv6 Packet Filtering Framework
3Before=network-pre.target
4Wants=network-pre.target
5
6[Service]
7Type=oneshot
8ExecStart=@SBINDIR@/ip6tables-restore -w -- @RULESDIR@/ip6tables.rules
9ExecReload=@SBINDIR@/ip6tables-restore -w -- @RULESDIR@/ip6tables.rules
10RemainAfterExit=yes
11
12[Install]
13WantedBy=multi-user.target
diff --git a/meta/recipes-extended/iptables/iptables/iptables.rules b/meta/recipes-extended/iptables/iptables/iptables.rules
deleted file mode 100644
index e69de29bb2..0000000000
--- a/meta/recipes-extended/iptables/iptables/iptables.rules
+++ /dev/null
diff --git a/meta/recipes-extended/iptables/iptables/iptables.service b/meta/recipes-extended/iptables/iptables/iptables.service
deleted file mode 100644
index 0eb3c343de..0000000000
--- a/meta/recipes-extended/iptables/iptables/iptables.service
+++ /dev/null
@@ -1,13 +0,0 @@
1[Unit]
2Description=IPv4 Packet Filtering Framework
3Before=network-pre.target
4Wants=network-pre.target
5
6[Service]
7Type=oneshot
8ExecStart=@SBINDIR@/iptables-restore -w -- @RULESDIR@/iptables.rules
9ExecReload=@SBINDIR@/iptables-restore -w -- @RULESDIR@/iptables.rules
10RemainAfterExit=yes
11
12[Install]
13WantedBy=multi-user.target
diff --git a/meta/recipes-extended/iptables/iptables_1.8.11.bb b/meta/recipes-extended/iptables/iptables_1.8.11.bb
deleted file mode 100644
index 686dc5afe5..0000000000
--- a/meta/recipes-extended/iptables/iptables_1.8.11.bb
+++ /dev/null
@@ -1,124 +0,0 @@
1SUMMARY = "Tools for managing kernel packet filtering capabilities"
2DESCRIPTION = "iptables is the userspace command line program used to configure and control network packet \
3filtering code in Linux."
4HOMEPAGE = "http://www.netfilter.org/"
5BUGTRACKER = "http://bugzilla.netfilter.org/"
6LICENSE = "GPL-2.0-or-later"
7LIC_FILES_CHKSUM = "file://COPYING;md5=b234ee4d69f5fce4486a80fdaf4a4263 \
8 file://iptables/iptables.c;beginline=13;endline=25;md5=c5cffd09974558cf27d0f763df2a12dc \
9"
10
11SRC_URI = "http://netfilter.org/projects/iptables/files/iptables-${PV}.tar.xz \
12 file://iptables.service \
13 file://iptables.rules \
14 file://ip6tables.service \
15 file://ip6tables.rules \
16 "
17SRC_URI[sha256sum] = "d87303d55ef8c92bcad4dd3f978b26d272013642b029425775f5bad1009fe7b2"
18
19SYSTEMD_SERVICE:${PN} = "\
20 iptables.service \
21 ${@bb.utils.contains('PACKAGECONFIG', 'ipv6', 'ip6tables.service', '', d)} \
22"
23
24inherit autotools pkgconfig systemd
25
26EXTRA_OECONF = "--with-kernel=${STAGING_INCDIR}"
27
28CFLAGS:append:libc-musl = " -D__UAPI_DEF_ETHHDR=0"
29
30PACKAGECONFIG ?= "${@bb.utils.filter('DISTRO_FEATURES', 'ipv6', d)}"
31PACKAGECONFIG[ipv6] = "--enable-ipv6,--disable-ipv6,"
32
33# libnfnetlink recipe is in meta-networking layer
34PACKAGECONFIG[libnfnetlink] = "--enable-libnfnetlink --enable-connlabel,--disable-libnfnetlink --disable-connlabel,libnfnetlink libnetfilter-conntrack"
35
36# libnftnl recipe is in meta-networking layer(previously known as libnftables)
37PACKAGECONFIG[libnftnl] = "--enable-nftables,--disable-nftables,libnftnl"
38
39do_configure:prepend() {
40 # Remove some libtool m4 files
41 # Keep ax_check_linker_flags.m4 which belongs to autoconf-archive.
42 rm -f libtool.m4 lt~obsolete.m4 ltoptions.m4 ltsugar.m4 ltversion.m4
43
44 # Copy a header to fix out of tree builds
45 cp -f ${S}/libiptc/linux_list.h ${S}/include/libiptc/
46}
47
48IPTABLES_RULES_DIR ?= "${sysconfdir}/${BPN}"
49
50do_install:append() {
51 install -d ${D}${IPTABLES_RULES_DIR}
52 install -m 0644 ${UNPACKDIR}/iptables.rules ${D}${IPTABLES_RULES_DIR}
53
54 install -d ${D}${systemd_system_unitdir}
55 install -m 0644 ${UNPACKDIR}/iptables.service ${D}${systemd_system_unitdir}
56
57 sed -i \
58 -e 's,@SBINDIR@,${sbindir},g' \
59 -e 's,@RULESDIR@,${IPTABLES_RULES_DIR},g' \
60 ${D}${systemd_system_unitdir}/iptables.service
61
62 if ${@bb.utils.contains('PACKAGECONFIG', 'ipv6', 'true', 'false', d)} ; then
63 install -m 0644 ${UNPACKDIR}/ip6tables.rules ${D}${IPTABLES_RULES_DIR}
64 install -m 0644 ${UNPACKDIR}/ip6tables.service ${D}${systemd_system_unitdir}
65
66 sed -i \
67 -e 's,@SBINDIR@,${sbindir},g' \
68 -e 's,@RULESDIR@,${IPTABLES_RULES_DIR},g' \
69 ${D}${systemd_system_unitdir}/ip6tables.service
70 fi
71
72 # if libnftnl is included, make the iptables symlink point to the nft-based binary by default
73 if ${@bb.utils.contains('PACKAGECONFIG', 'libnftnl', 'true', 'false', d)} ; then
74 ln -sf ${sbindir}/xtables-nft-multi ${D}${sbindir}/iptables
75 ln -sf ${sbindir}/xtables-nft-multi ${D}${sbindir}/iptables-save
76 ln -sf ${sbindir}/xtables-nft-multi ${D}${sbindir}/iptables-restore
77 # ethertypes is provided by the netbase package
78 rm -f ${D}${sysconfdir}/ethertypes
79 fi
80}
81
82PACKAGES =+ "${PN}-modules ${PN}-apply"
83PACKAGES_DYNAMIC += "^${PN}-module-.*"
84
85python populate_packages:prepend() {
86 modules = do_split_packages(d, '${libdir}/xtables', r'lib(.*)\.so$', '${PN}-module-%s', '${PN} module %s', extra_depends='')
87 if modules:
88 metapkg = d.getVar('PN') + '-modules'
89 d.appendVar('RDEPENDS:' + metapkg, ' ' + ' '.join(modules))
90}
91
92RDEPENDS:${PN} = "${PN}-module-xt-standard"
93RRECOMMENDS:${PN} = " \
94 ${PN}-modules \
95 kernel-module-x-tables \
96 kernel-module-ip-tables \
97 kernel-module-iptable-filter \
98 kernel-module-iptable-nat \
99 kernel-module-nf-defrag-ipv4 \
100 kernel-module-nf-conntrack \
101 kernel-module-nf-conntrack-ipv4 \
102 kernel-module-nf-nat \
103 kernel-module-ipt-masquerade \
104 ${@bb.utils.contains('PACKAGECONFIG', 'ipv6', '\
105 kernel-module-ip6table-filter \
106 kernel-module-ip6-tables \
107 ', '', d)} \
108"
109
110FILES:${PN} += "${datadir}/xtables"
111
112FILES:${PN}-apply = "${sbindir}/ip*-apply"
113RDEPENDS:${PN}-apply = "${PN} bash"
114
115# Include the symlinks as well in respective packages
116FILES:${PN}-module-xt-conntrack += "${libdir}/xtables/libxt_state.so"
117FILES:${PN}-module-xt-ct += "${libdir}/xtables/libxt_NOTRACK.so ${libdir}/xtables/libxt_REDIRECT.so"
118FILES:${PN}-module-xt-nat += "${libdir}/xtables/libxt_SNAT.so ${libdir}/xtables/libxt_DNAT.so ${libdir}/xtables/libxt_MASQUERADE.so"
119
120ALLOW_EMPTY:${PN}-modules = "1"
121
122INSANE_SKIP:${PN}-module-xt-conntrack = "dev-so"
123INSANE_SKIP:${PN}-module-xt-ct = "dev-so"
124INSANE_SKIP:${PN}-module-xt-nat = "dev-so"