Rocky 8 - firewalld with large ipsets

Hi everyone,

(sorry for censored links, looks like I’m not authorized to post them (?))

this post is related to this firewalld bug:

That cause a large reload time issue with large ipsets (>10-20k networks).

The fix was published in test on March 2026 on Almalinux (I was not able to find a similar test package for Rocky) AlmaLinux OS - Forever-Free Enterprise-Grade Operating System

Today I noticed that an update for firewalld was released for Rocky 8 too:

firewalld 0.9.11-11.el8_10

But it doesn’t appear to address this bug: Rocky Linux 8 x86_64 BaseOS

Someone has infos about this bugfix or where it is tracked?

I searched everywhere but I wasn’t able to locate anything related for Rocky 8 (maybe the large use of Anubis to contain of AI bots flooding degraded the google search too…)

Thanks

Due to spammers, new users can post links to rockylinux domains only. I fixed the links in your post. Once your reputation level increases after you have posted a bit, then you will be able to do more.

BTW, the fix was pushed in Almalinux testing repo, so it’s not an official fix from RHEL Rocky aims to be 1:1 with RHEL so if RHEL haven’t applied that fix, then that will be why Rocky doesn’t have it. Almalinux is ABI-compatible, so they are not 100% the same as RHEL. Once you’ve understood that difference, then you will know why Rocky doesn’t have it. So, if Red Hat add it to RHEL, then Rocky will have it.