From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from lists.gentoo.org (pigeon.gentoo.org [208.92.234.80]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by finch.gentoo.org (Postfix) with ESMTPS id 4CB6B1396D9 for ; Sat, 28 Oct 2017 18:45:23 +0000 (UTC) Received: from pigeon.gentoo.org (localhost [127.0.0.1]) by pigeon.gentoo.org (Postfix) with SMTP id 067D7E0DF3; Sat, 28 Oct 2017 18:45:14 +0000 (UTC) Received: from blaine.gmane.org (unknown [195.159.176.226]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by pigeon.gentoo.org (Postfix) with ESMTPS id 98D83E0DD3 for ; Sat, 28 Oct 2017 18:45:13 +0000 (UTC) Received: from list by blaine.gmane.org with local (Exim 4.84_2) (envelope-from ) id 1e8W6J-0000lD-P0 for gentoo-user@lists.gentoo.org; Sat, 28 Oct 2017 20:44:55 +0200 X-Injected-Via-Gmane: http://gmane.org/ To: gentoo-user@lists.gentoo.org From: Nikos Chantziaras Subject: [gentoo-user] Re: systemd: "local system does not support BPF/cgroup based firewalling" Date: Sat, 28 Oct 2017 21:44:58 +0300 Message-ID: References: Precedence: bulk List-Post: List-Help: List-Unsubscribe: List-Subscribe: List-Id: Gentoo Linux mail X-BeenThere: gentoo-user@lists.gentoo.org Reply-to: gentoo-user@lists.gentoo.org Mime-Version: 1.0 Content-Type: text/plain; charset=utf-8; format=flowed Content-Transfer-Encoding: 8bit X-Complaints-To: usenet@blaine.gmane.org User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:52.0) Gecko/20100101 Thunderbird/52.4.0 In-Reply-To: Content-Language: en-US X-Archives-Salt: af1d5947-ca8b-4cad-a4e1-bd858e4d8324 X-Archives-Hash: bbff2afc2a5edda0557aee426d05aaa6 There is no such kernel option. On 28/10/17 21:21, Canek Peláez Valdés wrote: > Do you have CONFIG_CGROUP_BPF enabled? > > Regards. > > On Sat, Oct 28, 2017 at 1:03 PM, Nikos Chantziaras > wrote: > > I'm getting these at startup: > > systemd[1]: File /lib/systemd/system/systemd-journald.service:33 > configures an IP firewall (IPAddressDeny=any), but the local system > does not support BPF/cgroup based firewalling. > systemd[1]: Proceeding WITHOUT firewalling in effect! > systemd[1]: File /lib/systemd/system/systemd-udevd.service:32 > configures an IP firewall (IPAddressDeny=any), but the local system > does not support BPF/cgroup based firewalling. > systemd[1]: Proceeding WITHOUT firewalling in effect! > systemd[1]: File /lib/systemd/system/systemd-logind.service:34 > configures an IP firewall (IPAddressDeny=any), but the local system > does not support BPF/cgroup based firewalling. > systemd[1]: Proceeding WITHOUT firewalling in effect! > > What do I need to make this work? I found this: > > https://github.com/systemd/systemd/issues/7188 > > > But CONFIG_BPF_SYSCALL is enabled and I still get that message. > > This is on kernel 4.9.59 with systemd 235.