IPv6 Firewall Options Visibility in YaST on OpenSUSE Leap 15.6
0 reputation · 13 Mar 2025, 06:47 UTC
0 reputation · 13 Mar 2025, 06:47 UTC
In OpenSUSE Leap 15.6 the YaST firewall module (YaST 3.3.1) presents an IPv6 checkbox that must be enabled manually. The module does not automatically detect whether the running kernel has IPv6 support, so the checkbox remains visible even when the kernel is compiled without IPv6. Enabling the checkbox in such a scenario has no effect and YaST logs a generic failure message, providing no clear indication of the underlying issue.
The core question is whether YaST should automatically hide or disable the IPv6 firewall options when the kernel lacks IPv6 capability, thereby preventing users from enabling non‑functional rules. If this behavior is not implemented, what diagnostic feedback should YaST provide to help administrators identify the missing kernel support?
1. Should YaST automatically detect kernel IPv6 support and hide or disable the IPv6 firewall options when unavailable?
2. If not, what specific diagnostic message or UI indicator should YaST present when an IPv6 rule fails due to missing kernel support?
29275 reputation · 13 Mar 2025, 14:41 UTC
Yes – YaST should automatically detect whether the running kernel has IPv6 support and hide or disable the IPv6 firewall checkbox when IPv6 is unavailable. If this detection is not implemented, YaST must present a clear diagnostic message and a UI indicator (e.g., a disabled checkbox with a tooltip) when an attempt to enable IPv6 rules fails due to missing kernel support.
YaST can determine IPv6 availability by checking for the ipv6 kernel module or the presence of the IPv6 proc interface:
# Check if the ipv6 module is loaded
lsmod | grep ipv6
# Or verify the proc file exists
[ -f /proc/net/if_inet6 ] && echo "IPv6 present" || echo "IPv6 absent"
If either test indicates IPv6 is absent, the YaST UI should hide the IPv6 checkbox or disable it and show a tooltip explaining the reason.
When a user tries to enable IPv6 firewall rules on a system without kernel IPv6 support, YaST should display a message such as:
"IPv6 support not available in the kernel; IPv6 firewall rules cannot be applied. Load the
ipv6module or use a kernel with CONFIG_IPV6 enabled."
Accompany this with a UI indicator: the IPv6 checkbox rendered disabled (grayed out) and a tooltip that repeats the same message on hover.
lsmod | grep ipv6 or [ -f /proc/net/if_inet6 ] && echo IPv6 present.Use comments to ask for clarification. Post a solution as an answer.
No question comments on this page.