New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

fix Qubes firewall dependencies / Qubes firewall may be load too late during boot #2209

Open
adrelanos opened this Issue Jul 29, 2016 · 2 comments

Comments

Projects
None yet
2 participants
@adrelanos
Member

adrelanos commented Jul 29, 2016

Post R3.2 suggested fix since this is probably too big a change for R3.2. It is not perfectly clear yet to me how to fix this issue, however I tried to get some good input on this.

Reference, and systemd question: How to securely load a firewall before networking gets up?


  • Should use After=network-pre.target and Wants=network-pre.target. (reference)
  • Usage of network-pre.target results in systemd ordering cycle if not used right (DefaultDependencies=no [...]) (reference)

  • qubes-iptables.service is broken because it uses WantedBy=basic.target but not DefaultDependencies=no.
  • This is not a complete list.

(Follow up task of #2198.)

@andrewdavidwong

This comment has been minimized.

Show comment
Hide comment
@andrewdavidwong

andrewdavidwong Jul 29, 2016

Member

@adrelanos: Is this primarily a template issue?

Member

andrewdavidwong commented Jul 29, 2016

@adrelanos: Is this primarily a template issue?

@adrelanos

This comment has been minimized.

Show comment
Hide comment
@adrelanos

adrelanos Jul 29, 2016

Member
Member

adrelanos commented Jul 29, 2016

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment