| Summary: | [PATCH] etc/rc.d/netwait breaks on releng/10.3 if ipfw configured | ||||||
|---|---|---|---|---|---|---|---|
| Product: | Base System | Reporter: | John Marshall <john> | ||||
| Component: | bin | Assignee: | Ian Lepore <ian> | ||||
| Status: | Closed FIXED | ||||||
| Severity: | Affects Some People | CC: | 000.fbsd, re | ||||
| Priority: | --- | Keywords: | patch | ||||
| Version: | 10.3-BETA2 | ||||||
| Hardware: | Any | ||||||
| OS: | Any | ||||||
| Attachments: |
|
||||||
|
Description
John Marshall
2016-03-12 03:47:47 UTC
A commit references this bug: Author: ian Date: Sun Mar 13 19:42:59 UTC 2016 New revision: 296807 URL: https://svnweb.freebsd.org/changeset/base/296807 Log: Require firewall setup before running rc.d/netwait, otherwise the ping packets sent by netwait may not get through. PR: 207916 Submitted by: John.Marshall@riverwillow.com.au (ipfw), ian@ (pf, ipfilter) Changes: head/etc/rc.d/netwait I think a better fix would be to split this into two scripts, one that waits for network interfaces to appear and another that waits for IP connectivity. The interface wait would happen before NETWORKING and the IP wait afterwards like it used to. When I started to pursue that I ran into an existing circular dependency between devd and mountcritremote which becomes much worse when inserting the new interface-wait before NETWORKING (one dependency conflict turns into a couple dozen). That's going to be hard to resolve, so I've committed the provided fix (and added the pf and ipfilter firewalls as well) for now. If ipwf is hardcoded dependency of netwait now, what if I am using PF as firewall of my choice? Will netwait fail? (In reply to Miroslav Lachman from comment #3) No, the "requirements" don't really mean the named script has to complete successfully, it only directs rcorder(8) to sort them so that they run in requirement order. So the change just ensures that all 3 flavors of firewall-setup script will have a chance to run before the netwait script runs. Thank you. I was not sure because I played with rc and rcorder long time ago. A commit references this bug: Author: ian Date: Wed Mar 16 16:21:30 UTC 2016 New revision: 296940 URL: https://svnweb.freebsd.org/changeset/base/296940 Log: MFC r296807: Require firewall setup before running rc.d/netwait, otherwise the ping packets sent by netwait may not get through. PR: 207916 Changes: _U stable/10/ stable/10/contrib/llvm/tools/clang/lib/Driver/Tools.cpp stable/10/etc/rc.d/netwait A commit references this bug: Author: ian Date: Wed Mar 16 16:52:31 UTC 2016 New revision: 296943 URL: https://svnweb.freebsd.org/changeset/base/296943 Log: MFC r296807: (this time with 100% fewer unintended changes mixed in)... Require firewall setup before running rc.d/netwait, otherwise the ping packets sent by netwait may not get through. PR: 207916 Changes: _U stable/10/ stable/10/etc/rc.d/netwait A commit references this bug: Author: ian Date: Wed Mar 16 17:35:55 UTC 2016 New revision: 296946 URL: https://svnweb.freebsd.org/changeset/base/296946 Log: MFC 296943: Require firewall setup before running rc.d/netwait, otherwise the ping packets sent by netwait may not get through. PR: 207916 Approved by: re (marius) Changes: _U releng/10.3/ releng/10.3/etc/rc.d/netwait |