Skip to content

Avoid noisy procfs errors in iptables detection - #589

Open
penguineer wants to merge 1 commit into
docker-library:masterfrom
penguineer:524-fix-cat-lookup-error-msg
Open

penguineer wants to merge 1 commit into
docker-library:masterfrom
penguineer:524-fix-cat-lookup-error-msg

Conversation

@penguineer

Copy link
Copy Markdown

This PR avoids misleading stderr output during normal DinD startup when optional /proc/net/*_tables_names files are absent.

On systems using the nftables backend, files such as:

/proc/net/ip6_tables_names
/proc/net/arp_tables_names

may not exist. The current probe calls cat unconditionally, which produces messages like:

cat: can't open '/proc/net/arp_tables_names': No such file or directory
cat: can't open '/proc/net/ip6_tables_names': No such file or directory

DinD then continues and starts normally.

The change adds a readability check to the existing conditional so cat is only called when the procfs entry is present/readable.

This keeps the current detection logic intact while avoiding expected probe failures being emitted on stderr and subsequently classified as application errors by logging systems that use stdout/stderr as a severity signal.

Related: #524

@penguineer

Copy link
Copy Markdown
Author

I believe this is the right change: it keeps the existing detection logic intact and only avoids calling cat when the procfs entry is not readable.

I cannot fully test this in a Docker upstream development environment, though. I have only verified the original behavior on the affected DinD setup and reviewed the shell change itself.

@tianon tianon left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Simple, unobtrusive, and I've tested that it works correctly (originally this code used -s which is exactly what the cat + -n is emulating, but it turns out this simulated kernel filesystem doesn't report the filesize because it'd have to generate on-the-fly contents to do that, so -s/"is the filesize non-zero" doesn't work, but -r works correctly 👍)

Some optional /proc/net/*_tables_names files are absent when using the
nftables backend. Check readability before calling cat so the expected
absence does not produce misleading stderr output during normal DinD
startup.
@tianon
tianon force-pushed the 524-fix-cat-lookup-error-msg branch from 8983881 to 0ec19f6 Compare October 5, 2026 20:27
@tianon

tianon commented Oct 5, 2026

Copy link
Copy Markdown
Member

(force-pushed to update the templated copies too, not just the template)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants