Package: opensnitch
Version: 1.5.8.1-1+b2
Severity: wishlist
Tags: upstream
Dear Maintainer,
OpenSnitch in Debian is currently incompatible with (some?) kernel space
network tools such as wireguard and NFS. These are entirely unusable so
long as the opensnitchd service is running. An eBPF module is required
when the user does not wish to completely block such traffic, but until
recently the upstream build process could not be included in Debian. [0]
The following information may be helpful for determining whether this
change is small enough to include in a bookworm point release.
I have confirmed this works with the package version mentioned above.
Any new files are from the tree at commit 11baad0. [1]
- Replace "ebpf_prog/Makefile" with the newer file and delete unknown
targets (" opensnitch-procs.o opensnitch-dns.o") on line 30.
- Remove "ebpf_prog/file.patch" since it is no longer needed.
- Add directory "ebpf_prog/bpf_headers" containing 4 upstream files.
- Rename "ebpf_prog/bpf_headers" to "ebpf_prog/bpf" for compatibility.
With the appropriate linux-headers package installed, it should now be
possible to run 'make' in the "ebpf_prog" directory and copy the
resulting "opensnitch.o" file to "/etc/opensnitchd/". (The non-standard
location is fixed upstream and will be deprecated in a future release.)
[0]
https://people.skolelinux.org/pere/blog/tags/opensnitch/
[1]
https://github.com/evilsocket/opensnitch/tree/
11baad083d5396f4d30af5ce5b1ae6ad80bb5478
-- System Information:
Debian Release: 12.0
APT prefers testing-security
APT policy: (500, 'testing-security'), (500, 'testing')
Architecture: amd64 (x86_64)
Kernel: Linux 6.1.0-9-amd64 (SMP w/4 CPU threads; PREEMPT)
Locale: LANG=en_US.UTF-8, LC_CTYPE=en_US.UTF-8 (charmap=UTF-8), LANGUAGE
not set
Shell: /bin/sh linked to /usr/bin/dash
Init: systemd (via /run/systemd/system)
LSM: AppArmor: enabled
Versions of packages opensnitch depends on:
ii libc6 2.36-9
ii libnetfilter-queue1 1.0.5-3
ii libnfnetlink0 1.0.2-2
Versions of packages opensnitch recommends:
ii python3-opensnitch-ui 1.5.8.1-1