Repository navigation
Conversation
The kernel has nf_tables and conntrack but no NAT: NF_NAT, NFT_NAT and NFT_REJECT are not set, and NFT_MASQ is not available without NF_NAT. On a comma four with this config, NetworkManager's shared mode gave a hotspot client a DHCP lease, but no nm-shared table was created. Enable NF_NAT, NFT_NAT, NFT_MASQ and NFT_REJECT. NFT_REJECT is included because the nm-shared-wlan0 table that NetworkManager created on the device has reject rules next to the masquerade rule. This also turns on NF_NAT_MASQUERADE, NFT_REJECT_INET/IPV4/IPV6 and NF_REJECT_IPV4/IPV6.
vamOS System ProfileChanges vs master
Added packages: cmake-4.2.2_3, dhcpcd-10.3.2_2, expat-2.8.4_1, expat-devel-2.8.4_1, jsoncpp-1.9.8_1, libharfbuzz-14.4.0_1, python3-3.14.7_1, python3-Mako-1.4.1_1, python3-Pygments-2.21.0_1, texinfo-7.3_2, vim-9.2.1031_1, vim-common-9.2.1031_1, xxd-9.2.1031_1 Removed packages: cmake-4.2.2_2, dhcpcd-10.3.2_1, expat-2.8.3_1, expat-devel-2.8.3_1, jsoncpp-1.9.6_1, libharfbuzz-14.3.1_1, python3-3.14.6_1, python3-Mako-1.3.2_3, python3-Pygments-2.20.0_1, texinfo-7.3_1, vim-9.2.0506_1, vim-common-9.2.0506_1, xxd-9.2.0506_1 Directory size changes (>1MB)
Top 10 Directories
Category Breakdown
Top 10 Packages by Size
|
| File | Size |
|---|---|
| /usr/lib/llvm/21/lib/libLLVM.so.21.1 | 124.3MB |
| /usr/lib/llvm/21/lib/libMLIR.so.21.1 | 89.7MB |
| /usr/lib/llvm/21/bin/mlir-transform-opt | 82.9MB |
| /usr/lib/llvm/21/lib/libclang-cpp.so.21.1 | 56MB |
| /usr/lib/llvm/21/bin/mlir-translate | 53.2MB |
| /usr/lib/llvm/21/bin/llvm-exegesis | 52MB |
| /usr/lib/llvm/21/bin/llvm-bolt-binary-analysis | 50.6MB |
| /usr/bin/uv | 41.6MB |
| /usr/lib/gcc/aarch64-linux-gnu/14.2/gnat1 | 40.1MB |
| /usr/bin/gdb | 39.1MB |
| /usr/lib/libgallium-26.1.8.so | 37.7MB |
| /usr/lib/gcc/aarch64-linux-gnu/14.2/cc1plus | 37.3MB |
| /usr/lib/libllvm-qcom.so | 35.2MB |
| /usr/lib/gcc/aarch64-linux-gnu/14.2/cc1 | 35.2MB |
| /usr/lib/libRusticlOpenCL.so.1.0.0 | 34.4MB |
| /usr/lib/gcc/aarch64-linux-gnu/14.2/lto1 | 33.9MB |
| /usr/bin/lto-dump | 33.9MB |
| /usr/local/venv/bin/ruff | 31.8MB |
| /usr/share/icu/78.3/icudt78l.dat | 31.5MB |
| /usr/lib/llvm/21/lib/libclang.so.21.1.7 | 30.2MB |
| /usr/lib/libz3.so | 28.8MB |
| /usr/lib/llvm/21/bin/c-index-test | 28.6MB |
| /usr/local/venv/lib/python3.12/site-packages/gcc_arm_none_eabi/toolchain/libexec/gcc/arm-none-eabi/13.2.1/cc1 | 28.2MB |
| /usr/bin/run | 26.7MB |
| /usr/local/venv/lib/python3.12/site-packages/numpy.libs/libscipy_openblas64_-71e1b124.so | 23.6MB |
| /usr/comma/updater | 23.5MB |
| /usr/comma/setup | 23.5MB |
| /usr/comma/reset | 23.5MB |
| /usr/local/uv/python/cpython-3.12.14-linux-aarch64-gnu/bin/python3.12 | 22.1MB |
| /usr/local/uv/python/cpython-3.12.14-linux-aarch64-gnu/lib/libpython3.12.so.1.0 | 22MB |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Enable
CONFIG_NF_NAT,CONFIG_NFT_NAT,CONFIG_NFT_MASQandCONFIG_NFT_REJECT, so the Wi-Fi hotspot can NAT its clients with nftables.Why
NF_NAT,NFT_NATandNFT_REJECTare not set, andNFT_MASQneedsNF_NAT. So NetworkManager's shared mode (ipv4.method=shared) gives hotspot clients an address but no NAT (see Testing).rejectrules next tomasquerade, so I enabledNFT_REJECTtoo. I did not test a build with NAT but withoutNFT_REJECT.NF_NAT_MASQUERADE,NFT_REJECT_INET/IPV4/IPV6andNF_REJECT_IPV4/IPV6. Nothing else in the netfilter config changes.iptables-legacyis installed, but theip_tablesmodule is not in the image, soiptables-legacy -t nat -Lfails with "Table does not exist".Testing
comma four, liberation-day-7.2 kernel (
7.2.0-vamos-7626c37) with local ath10k-only debug patches (different versions in Before and After; neither touches netfilter). "Before" is the released config. "After" adds these four options (andATH10K_DEBUG);/proc/config.gzon the device showsNF_NAT=y,NFT_MASQ=yandNFT_REJECT=y. The netfilter lines ofvamos.configand the kernel source commit are the same on master.nm-shared-*table.masqueraderule foroifname "usb0", andip_forward=1. An iPhone (mobile data off) on the AP loaded a page from a test HTTP server on my Mac, which is connected over USB (usb0). The Mac saw the request coming from the device's usb0 address, 192.168.42.2.wpa-pskprofile set up like openpilot's hotspot): NM creatednm-shared-wlan0with the masquerade and reject rules. Traffic passed only after I also enabled forwarding on usb0 (see below).Not covered: forwarding on the upstream interface
This PR only adds the kernel options. Even with them, the hotspot also needs forwarding on the upstream interface, and NM didn't turn it on for an upstream it doesn't manage:
net.ipv4.conf.wlan0.forwardingwas 1.net.ipv4.ip_forwardandnet.ipv4.conf.usb0.forwardingstayed 0, andnmclishows usb0 as unmanaged. Replies coming back in on usb0 were dropped (InAddrErrorswent from 77 to 132 during one page reload) until I setnet.ipv4.conf.usb0.forwarding=1by hand.Note: I worked through this together with Claude (AI). English is hard for me, so the English was written with AI help, but I ran the device tests myself on my comma four, and the results above come from those runs.