)]}'
{"/COMMIT_MSG":[{"author":{"_account_id":15197,"name":"Pierre Riteau","email":"pierre@stackhpc.com","username":"priteau","status":"StackHPC"},"change_message_id":"883e29b2daba0534eab7fccee2ec1ae523e4c9ec","unresolved":true,"context_lines":[{"line_number":7,"context_line":"Install iptables-nft explicitly"},{"line_number":8,"context_line":""},{"line_number":9,"context_line":"We installed this package in previous releases, so to prevent a mixture"},{"line_number":10,"context_line":"of legacy and nftables firewall rules, we should explitly install the"},{"line_number":11,"context_line":"iptables-nft package."},{"line_number":12,"context_line":""},{"line_number":13,"context_line":"Closes-Bug: #2144562"}],"source_content_type":"text/x-gerrit-commit-message","patch_set":3,"id":"83a43ce3_745c71fa","line":10,"range":{"start_line":10,"start_character":49,"end_line":10,"end_character":57},"updated":"2026-03-16 14:34:56.000000000","message":"explicitly","commit_id":"993a299cad21608b8d96250ca24400b4f58d1e58"}],"/PATCHSET_LEVEL":[{"author":{"_account_id":28048,"name":"Will Szumski","email":"will@stackhpc.com","username":"jovial"},"change_message_id":"eff8bae3c9237f150359d032010d08a4c573d275","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":7,"id":"028ad0ba_e1b8941d","updated":"2026-03-17 10:54:48.000000000","message":"I did find that this doesn\u0027t install iptables-legacy, so the environment variable: KOLLA_LEGACY_IPTABLES breaks. I will try and install that package too.","commit_id":"c2e77bf0f8d1f5426a9246e2554728189169144b"},{"author":{"_account_id":28048,"name":"Will Szumski","email":"will@stackhpc.com","username":"jovial"},"change_message_id":"7f3fdf6736ebdfd9792a1b896e403bfd669b2e50","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":7,"id":"069ac570_3de7dfa3","updated":"2026-03-17 09:44:43.000000000","message":"recheck: tarballs.opendev.org having issues","commit_id":"c2e77bf0f8d1f5426a9246e2554728189169144b"},{"author":{"_account_id":28048,"name":"Will Szumski","email":"will@stackhpc.com","username":"jovial"},"change_message_id":"740e26119e06e69c6e76b4b17a159af897c4ab36","unresolved":true,"context_lines":[],"source_content_type":"","patch_set":9,"id":"5837acfe_a2b94352","updated":"2026-03-17 11:47:04.000000000","message":"Arghh, not in EPEL for rhel10. I did some digging and nft is the default in the rocky 10 images: 2025.2 onwards. Perhaps we just drop support for KOLLA_LEGACY_IPTABLES in rocky 10.","commit_id":"992a8079d7bd914bc4d82d0d8f884cacefd9da77"},{"author":{"_account_id":28048,"name":"Will Szumski","email":"will@stackhpc.com","username":"jovial"},"change_message_id":"3de666043a1d0f3012f11515a62f64c5d010c85a","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":9,"id":"e0249474_72a15599","updated":"2026-03-17 11:18:16.000000000","message":"Worth noting that ubuntu ships both of these in the iptables package\n\n\twill@will-XPS-9315:~/code/kolla$ dpkg -S iptables-nft\n\tiptables: /usr/sbin/iptables-nft\n\tiptables: /usr/sbin/iptables-nft-restore\n\tiptables: /usr/share/man/man8/iptables-nft-restore.8.gz\n\tiptables: /usr/share/man/man8/iptables-nft.8.gz\n\tiptables: /usr/sbin/iptables-nft-save\n\tiptables: /usr/share/man/man8/iptables-nft-save.8.gz\n\n\twill@will-XPS-9315:~/code/kolla$ dpkg -S iptables-legacy\n\tiptables: /usr/share/man/man8/iptables-legacy.8.gz\n\tiptables: /usr/share/man/man8/iptables-legacy-restore.8.gz\n\tiptables: /usr/share/man/man8/iptables-legacy-save.8.gz\n\tiptables: /usr/sbin/iptables-legacy-save\n\tiptables: /usr/sbin/iptables-legacy\n\tiptables: /usr/sbin/iptables-legacy-restore","commit_id":"992a8079d7bd914bc4d82d0d8f884cacefd9da77"},{"author":{"_account_id":28048,"name":"Will Szumski","email":"will@stackhpc.com","username":"jovial"},"change_message_id":"c6e135c300a25c3667a8800d56c5e3f6472dc750","unresolved":true,"context_lines":[],"source_content_type":"","patch_set":9,"id":"424f6408_e38b1320","in_reply_to":"5837acfe_a2b94352","updated":"2026-03-17 11:54:46.000000000","message":"Also should retarget 2025.1 since rocky10 images use iptables-nft by default.\n\nKOLLA_LEGACY_IPTABLES is broken on rocky10, but that is a different bug and I think we dropped the kolla-ansible variable to set that.","commit_id":"992a8079d7bd914bc4d82d0d8f884cacefd9da77"}]}
