iptables v1.6.0: can't initialize iptables table `filter': Permission denied (you must be root) Perhaps iptables or your kernel needs to be upgraded.

whonix 14, testing repos , standealoneVM, after last pushed upgrades this message appeared:

  • Issue Specific log
Processing triggers for qubes-whonix (1:9.8-1) ...
OK: Loading Whonix firewall...
OK: Skipping firewall mode detection since already set to 'full'.
OK: (Full torified network access allowed.)
iptables v1.6.0: can't initialize iptables table `filter': Permission denied (you must be root)
Perhaps iptables or your kernel needs to be upgraded.
iptables v1.6.0: can't initialize iptables table `filter': Permission denied (you must be root)
Perhaps iptables or your kernel needs to be upgraded.
iptables v1.6.0: can't initialize iptables table `filter': Permission denied (you must be root)
Perhaps iptables or your kernel needs to be upgraded.
iptables v1.6.0: can't initialize iptables table `filter': Permission denied (you must be root)
Perhaps iptables or your kernel needs to be upgraded.
iptables v1.6.0: can't initialize iptables table `filter': Permission denied (you must be root)
Perhaps iptables or your kernel needs to be upgraded.
iptables v1.6.0: can't initialize iptables table `filter': Permission denied (you must be root)
Perhaps iptables or your kernel needs to be upgraded.
iptables v1.6.0: can't initialize iptables table `nat': Permission denied (you must be root)
Perhaps iptables or your kernel needs to be upgraded.
iptables v1.6.0: can't initialize iptables table `nat': Permission denied (you must be root)
Perhaps iptables or your kernel needs to be upgraded.
iptables v1.6.0: can't initialize iptables table `mangle': Permission denied (you must be root)
Perhaps iptables or your kernel needs to be upgraded.
iptables v1.6.0: can't initialize iptables table `mangle': Permission denied (you must be root)
Perhaps iptables or your kernel needs to be upgraded.
iptables v1.6.0: can't initialize iptables table `raw': Permission denied (you must be root)
Perhaps iptables or your kernel needs to be upgraded.
iptables v1.6.0: can't initialize iptables table `raw': Permission denied (you must be root)
Perhaps iptables or your kernel needs to be upgraded.
ip6tables v1.6.0: can't initialize ip6tables table `filter': Permission denied (you must be root)
Perhaps ip6tables or your kernel needs to be upgraded.
ip6tables v1.6.0: can't initialize ip6tables table `filter': Permission denied (you must be root)
Perhaps ip6tables or your kernel needs to be upgraded.
ip6tables v1.6.0: can't initialize ip6tables table `filter': Permission denied (you must be root)
Perhaps ip6tables or your kernel needs to be upgraded.
ip6tables v1.6.0: can't initialize ip6tables table `filter': Permission denied (you must be root)
Perhaps ip6tables or your kernel needs to be upgraded.
ip6tables v1.6.0: can't initialize ip6tables table `filter': Permission denied (you must be root)
Perhaps ip6tables or your kernel needs to be upgraded.
ip6tables v1.6.0: can't initialize ip6tables table `mangle': Permission denied (you must be root)
Perhaps ip6tables or your kernel needs to be upgraded.
ip6tables v1.6.0: can't initialize ip6tables table `mangle': Permission denied (you must be root)
Perhaps ip6tables or your kernel needs to be upgraded.
ip6tables v1.6.0: can't initialize ip6tables table `raw': Permission denied (you must be root)
Perhaps ip6tables or your kernel needs to be upgraded.
ip6tables v1.6.0: can't initialize ip6tables table `raw': Permission denied (you must be root)
Perhaps ip6tables or your kernel needs to be upgraded.
  • Full Logs
user@host:~$ sudo apt update && sudo apt dist-upgrade && sudo apt autoremove --purge
Hit:1 tor+http://deb.dds6qkxpwdeubwucdiaord2xgbbeyds25rbsgr73tbfpqpt4a6vjwsyd.onion stretch-testers InRelease
Hit:3 https://deb.qubes-os.org/r4.0/vm stretch InRelease
Hit:2 https://cdn-aws.deb.debian.org/debian-security stretch/updates InRelease
Ign:4 https://cdn-aws.deb.debian.org/debian stretch InRelease
Hit:5 https://cdn-aws.deb.debian.org/debian stretch Release
Reading package lists... Done
Building dependency tree       
Reading state information... Done
21 packages can be upgraded. Run 'apt list --upgradable' to see them.
Reading package lists... Done
Building dependency tree       
Reading state information... Done
Calculating upgrade... Done
The following packages were automatically installed and are no longer required:
  whonix-workstation-default-applications-gui whonix-ws-desktop-shortcuts
Use 'sudo apt autoremove' to remove them.
The following packages will be upgraded:
  anon-shared-helper-scripts apparmor-profiles-hardened-debian
  hardened-desktop-applications-kde hardened-packages-dependencies-cli
  hardened-packages-recommended-cli open-link-confirmation qubes-whonix-workstation
  tb-starter usability-misc whonix-firewall whonix-repository
  whonix-shared-default-applications-gui whonix-shared-packages-dependencies-cli
  whonix-shared-packages-recommended-cli whonix-workstation-default-applications-gui
  whonix-workstation-packages-dependencies-cli
  whonix-workstation-packages-dependencies-pre
  whonix-workstation-packages-recommended-cli
  whonix-workstation-packages-recommended-gui
  whonix-workstation-shared-packages-shared-meta whonixcheck
21 upgraded, 0 newly installed, 0 to remove and 0 not upgraded.
Need to get 753 kB of archives.
After this operation, 32.8 kB of additional disk space will be used.
Do you want to continue? [Y/n] y
Get:1 tor+http://deb.dds6qkxpwdeubwucdiaord2xgbbeyds25rbsgr73tbfpqpt4a6vjwsyd.onion stretch-testers/main amd64 whonix-workstation-packages-dependencies-pre all 3:8.6-1 [28.4 kB]
Get:2 tor+http://deb.dds6qkxpwdeubwucdiaord2xgbbeyds25rbsgr73tbfpqpt4a6vjwsyd.onion stretch-testers/main amd64 whonix-workstation-packages-dependencies-cli all 3:8.6-1 [28.4 kB]
Get:3 tor+http://deb.dds6qkxpwdeubwucdiaord2xgbbeyds25rbsgr73tbfpqpt4a6vjwsyd.onion stretch-testers/main amd64 whonix-shared-default-applications-gui all 3:8.6-1 [28.5 kB]
Get:4 tor+http://deb.dds6qkxpwdeubwucdiaord2xgbbeyds25rbsgr73tbfpqpt4a6vjwsyd.onion stretch-testers/main amd64 anon-shared-helper-scripts all 3:4.3-1 [23.9 kB]
Get:5 tor+http://deb.dds6qkxpwdeubwucdiaord2xgbbeyds25rbsgr73tbfpqpt4a6vjwsyd.onion stretch-testers/main amd64 whonix-firewall all 3:4.6-1 [37.2 kB]
Get:6 tor+http://deb.dds6qkxpwdeubwucdiaord2xgbbeyds25rbsgr73tbfpqpt4a6vjwsyd.onion stretch-testers/main amd64 whonix-shared-packages-dependencies-cli all 3:8.6-1 [28.4 kB]
Get:7 tor+http://deb.dds6qkxpwdeubwucdiaord2xgbbeyds25rbsgr73tbfpqpt4a6vjwsyd.onion stretch-testers/main amd64 hardened-packages-dependencies-cli all 3:8.6-1 [28.5 kB]
Get:8 tor+http://deb.dds6qkxpwdeubwucdiaord2xgbbeyds25rbsgr73tbfpqpt4a6vjwsyd.onion stretch-testers/main amd64 whonix-repository all 3:4.3-1 [60.7 kB]
Get:9 tor+http://deb.dds6qkxpwdeubwucdiaord2xgbbeyds25rbsgr73tbfpqpt4a6vjwsyd.onion stretch-testers/main amd64 usability-misc all 3:3.5-1 [64.0 kB]
Get:10 tor+http://deb.dds6qkxpwdeubwucdiaord2xgbbeyds25rbsgr73tbfpqpt4a6vjwsyd.onion stretch-testers/main amd64 open-link-confirmation all 3:2.4-1 [13.7 kB]
Get:11 tor+http://deb.dds6qkxpwdeubwucdiaord2xgbbeyds25rbsgr73tbfpqpt4a6vjwsyd.onion stretch-testers/main amd64 hardened-packages-recommended-cli all 3:8.6-1 [28.6 kB]
Get:12 tor+http://deb.dds6qkxpwdeubwucdiaord2xgbbeyds25rbsgr73tbfpqpt4a6vjwsyd.onion stretch-testers/main amd64 hardened-desktop-applications-kde all 3:8.6-1 [28.6 kB]
Get:13 tor+http://deb.dds6qkxpwdeubwucdiaord2xgbbeyds25rbsgr73tbfpqpt4a6vjwsyd.onion stretch-testers/main amd64 whonixcheck all 3:9.2-1 [128 kB]
Get:14 tor+http://deb.dds6qkxpwdeubwucdiaord2xgbbeyds25rbsgr73tbfpqpt4a6vjwsyd.onion stretch-testers/main amd64 whonix-shared-packages-recommended-cli all 3:8.6-1 [28.5 kB]
Get:15 tor+http://deb.dds6qkxpwdeubwucdiaord2xgbbeyds25rbsgr73tbfpqpt4a6vjwsyd.onion stretch-testers/main amd64 whonix-workstation-packages-recommended-cli all 3:8.6-1 [28.5 kB]
Get:16 tor+http://deb.dds6qkxpwdeubwucdiaord2xgbbeyds25rbsgr73tbfpqpt4a6vjwsyd.onion stretch-testers/main amd64 tb-starter all 3:4.0-1 [28.2 kB]
Get:17 tor+http://deb.dds6qkxpwdeubwucdiaord2xgbbeyds25rbsgr73tbfpqpt4a6vjwsyd.onion stretch-testers/main amd64 whonix-workstation-packages-recommended-gui all 3:8.6-1 [28.7 kB]
Get:18 tor+http://deb.dds6qkxpwdeubwucdiaord2xgbbeyds25rbsgr73tbfpqpt4a6vjwsyd.onion stretch-testers/main amd64 whonix-workstation-shared-packages-shared-meta all 3:8.6-1 [28.5 kB]
Get:19 tor+http://deb.dds6qkxpwdeubwucdiaord2xgbbeyds25rbsgr73tbfpqpt4a6vjwsyd.onion stretch-testers/main amd64 qubes-whonix-workstation all 3:8.6-1 [28.5 kB]
Get:20 tor+http://deb.dds6qkxpwdeubwucdiaord2xgbbeyds25rbsgr73tbfpqpt4a6vjwsyd.onion stretch-testers/main amd64 apparmor-profiles-hardened-debian all 3:8.6-1 [28.4 kB]
Get:21 tor+http://deb.dds6qkxpwdeubwucdiaord2xgbbeyds25rbsgr73tbfpqpt4a6vjwsyd.onion stretch-testers/main amd64 whonix-workstation-default-applications-gui all 3:8.3-1 [27.4 kB]
Fetched 753 kB in 7s (105 kB/s)                                                         
(Reading database ... 94516 files and directories currently installed.)
Preparing to unpack .../00-whonix-workstation-packages-dependencies-pre_3%3a8.6-1_all.deb ...
Unpacking whonix-workstation-packages-dependencies-pre (3:8.6-1) over (3:8.1-1) ...
Preparing to unpack .../01-whonix-workstation-packages-dependencies-cli_3%3a8.6-1_all.deb ...
Unpacking whonix-workstation-packages-dependencies-cli (3:8.6-1) over (3:8.1-1) ...
Preparing to unpack .../02-whonix-shared-default-applications-gui_3%3a8.6-1_all.deb ...
Unpacking whonix-shared-default-applications-gui (3:8.6-1) over (3:8.1-1) ...
Preparing to unpack .../03-anon-shared-helper-scripts_3%3a4.3-1_all.deb ...
Unpacking anon-shared-helper-scripts (3:4.3-1) over (3:4.2-1) ...
Preparing to unpack .../04-whonix-firewall_3%3a4.6-1_all.deb ...
Unpacking whonix-firewall (3:4.6-1) over (3:4.5-1) ...
Preparing to unpack .../05-whonix-shared-packages-dependencies-cli_3%3a8.6-1_all.deb ...
Unpacking whonix-shared-packages-dependencies-cli (3:8.6-1) over (3:8.1-1) ...
Preparing to unpack .../06-hardened-packages-dependencies-cli_3%3a8.6-1_all.deb ...
Unpacking hardened-packages-dependencies-cli (3:8.6-1) over (3:8.1-1) ...
Preparing to unpack .../07-whonix-repository_3%3a4.3-1_all.deb ...
Unpacking whonix-repository (3:4.3-1) over (3:4.2-1) ...
Preparing to unpack .../08-usability-misc_3%3a3.5-1_all.deb ...
Unpacking usability-misc (3:3.5-1) over (3:3.4-1) ...
Preparing to unpack .../09-open-link-confirmation_3%3a2.4-1_all.deb ...
Unpacking open-link-confirmation (3:2.4-1) over (3:2.3-1) ...
Preparing to unpack .../10-hardened-packages-recommended-cli_3%3a8.6-1_all.deb ...
Unpacking hardened-packages-recommended-cli (3:8.6-1) over (3:8.1-1) ...
Preparing to unpack .../11-hardened-desktop-applications-kde_3%3a8.6-1_all.deb ...
Unpacking hardened-desktop-applications-kde (3:8.6-1) over (3:8.1-1) ...
Preparing to unpack .../12-whonixcheck_3%3a9.2-1_all.deb ...
Unpacking whonixcheck (3:9.2-1) over (3:9.1-1) ...
Preparing to unpack .../13-whonix-shared-packages-recommended-cli_3%3a8.6-1_all.deb ...
Unpacking whonix-shared-packages-recommended-cli (3:8.6-1) over (3:8.1-1) ...
Preparing to unpack .../14-whonix-workstation-packages-recommended-cli_3%3a8.6-1_all.deb ...
Unpacking whonix-workstation-packages-recommended-cli (3:8.6-1) over (3:8.1-1) ...
Preparing to unpack .../15-tb-starter_3%3a4.0-1_all.deb ...
Unpacking tb-starter (3:4.0-1) over (3:3.9-1) ...
Preparing to unpack .../16-whonix-workstation-packages-recommended-gui_3%3a8.6-1_all.deb ...
Unpacking whonix-workstation-packages-recommended-gui (3:8.6-1) over (3:8.1-1) ...
Preparing to unpack .../17-whonix-workstation-shared-packages-shared-meta_3%3a8.6-1_all.deb ...
Unpacking whonix-workstation-shared-packages-shared-meta (3:8.6-1) over (3:8.1-1) ...
Preparing to unpack .../18-qubes-whonix-workstation_3%3a8.6-1_all.deb ...
Unpacking qubes-whonix-workstation (3:8.6-1) over (3:8.1-1) ...
Preparing to unpack .../19-apparmor-profiles-hardened-debian_3%3a8.6-1_all.deb ...
Unpacking apparmor-profiles-hardened-debian (3:8.6-1) over (3:8.1-1) ...
Preparing to unpack .../20-whonix-workstation-default-applications-gui_3%3a8.3-1_all.deb ...
Unpacking whonix-workstation-default-applications-gui (3:8.3-1) over (3:8.1-1) ...
Processing triggers for qubes-core-agent (4.0.38-1+deb9u1) ...
Processing triggers for mime-support (3.60) ...
Processing triggers for desktop-file-utils (0.23-1) ...
Setting up whonix-repository (3:4.3-1) ...
whonix-repository postinst Running: whonix_repository --refresh-keys
INFO /usr/bin/whonix_repository: Running 'apt-key --keyring /etc/apt/trusted.gpg.d/whonix.gpg add /usr/share/whonix-repository/whonix.asc'...
Warning: apt-key should not be used in scripts (called from postinst maintainerscript of the package whonix-repository)
key 8D66066A2EEACCDA:
70 signatures not checked due to missing keys
OK
INFO /usr/bin/whonix_repository: Done.
Setting up tb-starter (3:4.0-1) ...
Setting up whonix-workstation-packages-dependencies-pre (3:8.6-1) ...
Setting up usability-misc (3:3.5-1) ...
Setting up hardened-desktop-applications-kde (3:8.6-1) ...
Setting up hardened-packages-dependencies-cli (3:8.6-1) ...
Setting up whonix-workstation-packages-recommended-cli (3:8.6-1) ...
Setting up anon-shared-helper-scripts (3:4.3-1) ...
Processing triggers for man-db (2.7.6.1-2) ...
Setting up whonix-workstation-packages-recommended-gui (3:8.6-1) ...
Setting up whonix-shared-default-applications-gui (3:8.6-1) ...
Setting up whonix-workstation-default-applications-gui (3:8.3-1) ...
Setting up open-link-confirmation (3:2.4-1) ...
Setting up apparmor-profiles-hardened-debian (3:8.6-1) ...
Setting up whonix-firewall (3:4.6-1) ...
Setting up whonix-workstation-packages-dependencies-cli (3:8.6-1) ...
Setting up hardened-packages-recommended-cli (3:8.6-1) ...
Processing triggers for qubes-whonix (1:9.8-1) ...
OK: Loading Whonix firewall...
OK: Skipping firewall mode detection since already set to 'full'.
OK: (Full torified network access allowed.)
iptables v1.6.0: can't initialize iptables table `filter': Permission denied (you must be root)
Perhaps iptables or your kernel needs to be upgraded.
iptables v1.6.0: can't initialize iptables table `filter': Permission denied (you must be root)
Perhaps iptables or your kernel needs to be upgraded.
iptables v1.6.0: can't initialize iptables table `filter': Permission denied (you must be root)
Perhaps iptables or your kernel needs to be upgraded.
iptables v1.6.0: can't initialize iptables table `filter': Permission denied (you must be root)
Perhaps iptables or your kernel needs to be upgraded.
iptables v1.6.0: can't initialize iptables table `filter': Permission denied (you must be root)
Perhaps iptables or your kernel needs to be upgraded.
iptables v1.6.0: can't initialize iptables table `filter': Permission denied (you must be root)
Perhaps iptables or your kernel needs to be upgraded.
iptables v1.6.0: can't initialize iptables table `nat': Permission denied (you must be root)
Perhaps iptables or your kernel needs to be upgraded.
iptables v1.6.0: can't initialize iptables table `nat': Permission denied (you must be root)
Perhaps iptables or your kernel needs to be upgraded.
iptables v1.6.0: can't initialize iptables table `mangle': Permission denied (you must be root)
Perhaps iptables or your kernel needs to be upgraded.
iptables v1.6.0: can't initialize iptables table `mangle': Permission denied (you must be root)
Perhaps iptables or your kernel needs to be upgraded.
iptables v1.6.0: can't initialize iptables table `raw': Permission denied (you must be root)
Perhaps iptables or your kernel needs to be upgraded.
iptables v1.6.0: can't initialize iptables table `raw': Permission denied (you must be root)
Perhaps iptables or your kernel needs to be upgraded.
ip6tables v1.6.0: can't initialize ip6tables table `filter': Permission denied (you must be root)
Perhaps ip6tables or your kernel needs to be upgraded.
ip6tables v1.6.0: can't initialize ip6tables table `filter': Permission denied (you must be root)
Perhaps ip6tables or your kernel needs to be upgraded.
ip6tables v1.6.0: can't initialize ip6tables table `filter': Permission denied (you must be root)
Perhaps ip6tables or your kernel needs to be upgraded.
ip6tables v1.6.0: can't initialize ip6tables table `filter': Permission denied (you must be root)
Perhaps ip6tables or your kernel needs to be upgraded.
ip6tables v1.6.0: can't initialize ip6tables table `filter': Permission denied (you must be root)
Perhaps ip6tables or your kernel needs to be upgraded.
ip6tables v1.6.0: can't initialize ip6tables table `mangle': Permission denied (you must be root)
Perhaps ip6tables or your kernel needs to be upgraded.
ip6tables v1.6.0: can't initialize ip6tables table `mangle': Permission denied (you must be root)
Perhaps ip6tables or your kernel needs to be upgraded.
ip6tables v1.6.0: can't initialize ip6tables table `raw': Permission denied (you must be root)
Perhaps ip6tables or your kernel needs to be upgraded.
ip6tables v1.6.0: can't initialize ip6tables table `raw': Permission denied (you must be root)
Perhaps ip6tables or your kernel needs to be upgraded.
Setting up whonix-shared-packages-dependencies-cli (3:8.6-1) ...
Setting up whonixcheck (3:9.2-1) ...
Setting up whonix-shared-packages-recommended-cli (3:8.6-1) ...
Setting up whonix-workstation-shared-packages-shared-meta (3:8.6-1) ...
Setting up qubes-whonix-workstation (3:8.6-1) ...
Reading package lists... Done
Building dependency tree       
Reading state information... Done
The following packages will be REMOVED:
  whonix-workstation-default-applications-gui* whonix-ws-desktop-shortcuts*
0 upgraded, 0 newly installed, 2 to remove and 0 not upgraded.
After this operation, 57.3 kB disk space will be freed.
Do you want to continue? [Y/n] y
(Reading database ... 94518 files and directories currently installed.)
Removing whonix-workstation-default-applications-gui (3:8.3-1) ...
Removing whonix-ws-desktop-shortcuts (3:2.4-1) ...
(Reading database ... 94508 files and directories currently installed.)
Purging configuration files for whonix-ws-desktop-shortcuts (3:2.4-1) ...
user@host:~$ 
1 Like

Confirmed. Saw this on myself before. apt-get is somehow sandboxed since Debian stretch. iptables rules can no longer be changed during apt-get upgrades. In result, if Whonix firewall iptables rules were to change, which they did not, reboot would be required.

So for now it can be safely ignored.

1 Like

Did this happen during apt-get dist-upgrade inside sys-whonix?

didnt show up in the templates upgrades , but only inside a standaloneVM based on whonix.

if you mean standaloneVM as GW , yes it happened in both GW & WS.

1 Like