]> xenbits.xensource.com Git - libvirt.git/commitdiff
rpm: Don't default to nftables on existing distros
authorAndrea Bolognani <abologna@redhat.com>
Mon, 3 Jun 2024 10:35:49 +0000 (12:35 +0200)
committerAndrea Bolognani <abologna@redhat.com>
Mon, 3 Jun 2024 11:09:00 +0000 (13:09 +0200)
Signed-off-by: Andrea Bolognani <abologna@redhat.com>
Reviewed-by: Daniel P. Berrangé <berrange@redhat.com>
libvirt.spec.in

index 4381dbe30c7791eeceb66358000f4aba58cfd020..5ca7b95e6cde1dbadda4718b3a463e63bb2e8be9 100644 (file)
     %define with_modular_daemons 1
 %endif
 
+# Prefer nftables for future OS releases but keep using iptables
+# for existing ones
+%if 0%{?rhel} >= 10 || 0%{?fedora} >= 41
+    %define prefer_nftables 1
+    %define firewall_backend_priority nftables,iptables
+%else
+    %define prefer_nftables 0
+    %define firewall_backend_priority iptables,nftables
+%endif
+
+
+
 # Force QEMU to run as non-root
 %define qemu_user  qemu
 %define qemu_group  qemu
@@ -592,7 +604,7 @@ Summary: Network driver plugin for the libvirtd daemon
 Requires: libvirt-daemon-common = %{version}-%{release}
 Requires: libvirt-libs = %{version}-%{release}
 Requires: dnsmasq >= 2.41
-    %if 0%{?rhel} >= 10 || 0%{?fedora} >= 41
+    %if %{prefer_nftables}
 Requires: nftables
     %else
 Requires: iptables
@@ -1387,7 +1399,7 @@ export SOURCE_DATE_EPOCH=$(stat --printf='%Y' %{_specdir}/libvirt.spec)
            %{?enable_werror} \
            -Dexpensive_tests=enabled \
            -Dinit_script=systemd \
-           -Dfirewall_backend_priority=nftables,iptables \
+           -Dfirewall_backend_priority=%{firewall_backend_priority} \
            -Ddocs=enabled \
            -Dtests=enabled \
            -Drpath=disabled \