Join GitHub today
GitHub is home to over 28 million developers working together to host and review code, manage projects, and build software together.
Sign upqubes-firewall-user-script is only executed in sys-net and sys-firewall #4134
Comments
andrewdavidwong
added
bug
C: core
labels
Jul 24, 2018
andrewdavidwong
added this to the Release 4.0 updates milestone
Jul 24, 2018
This comment has been minimized.
Show comment
Hide comment
This comment has been minimized.
marmarek
Jul 24, 2018
Member
This is expected behavior, see https://www.qubes-os.org/doc/config-files/
Specifically, you can enable qubes-firewall service (even in template, but that wouldn't make sense). Note that qubes-firewall service is about guarding traffic from connected VMs, so it this VM doesn't provide network to any other, there is no need for qubes-firewall service (which matches default configuration).
In non-network-providing VMs you can use /rw/config/rc.local for own firewall rules, there is no dynamic firewall updates, so nothing will override them.
|
This is expected behavior, see https://www.qubes-os.org/doc/config-files/ |
marmarek
closed this
Jul 24, 2018
andrewdavidwong
added
notanissue
and removed
bug
labels
Jul 24, 2018
This comment has been minimized.
Show comment
Hide comment
This comment has been minimized.
andrewdavidwong
Jul 24, 2018
Member
Or maybe
/rw/config/qubes-firewall-user-scriptshouldn't confusingly exist in the TemplateVMs if there is a reason why we don't execute it.
I guess they have to exist in TemplateVMs so that they can exist in the ProxyVMs based on those TemplateVMs.
I guess they have to exist in TemplateVMs so that they can exist in the ProxyVMs based on those TemplateVMs. |
gasull commentedJul 24, 2018
•
edited
Edited 1 time
-
gasull
edited Jul 24, 2018 (most recent)
-
gasull
created Jul 24, 2018
Qubes OS version:
Qubes release 4.0 (R4.0)
Affected component(s):
Steps to reproduce the behavior:
/rw/config/qubes-firewall-user-scriptand add the following line:Expected behavior:
The output of
journalctl -t qubes-firewallshould be this:Or maybe
/rw/config/qubes-firewall-user-scriptshouldn't confusingly exist in the TemplateVMs if there is a reason why we don't execute it.Actual behavior:
The output of
journalctl -t qubes-firewallis this:General notes:
I tried with
iptablescommands, but I wanted to prove the commands are not ignored for some resaon, but they are not even executed.sys-netandsys-firewalldo execute/rw/config/qubes-firewall-user-script, but the other qubes do not. This is true for both Fedora and Debian templates.Related issues: