Re: [ANNOUNCE] FireHOL 2.0.0-rc.1 released

Chris Francy <[email protected]>
Newsgroups gmane.comp.security.firewalls.firehol.user
Message-ID <CABjsu1AfcQkVThpnVOs2i6PxCGyLpp0oS_jkbwGCeXz=V+QPeg@mail.gmail.com>
I am looking at the
[changelog](http://metadata.ftp-master.debian.org/changelogs//main/f/firehol/firehol_2.0.0~rc.1+ds-1_changelog)
for the the version in [experimental
repository](https://packages.debian.org/experimental/firehol) today
and I saw this note.

  * Debianization:
and fireqos-doc;
     - firehol has been moved from /sbin to /usr/sbin for consistency

This particular entry concerns me.  I believe the firehol binary was
in `/sbin` because network comes up before `/usr` is mounted, this is
to accommodate systems where /usr is nfs mounted, which is permitted
per the FHS.  Souldn't I be able to expect the firewall should be able
to function even if `/usr` cannot be mounted?

Seeing this also encouraged me to go look at the /etc/init.d/firehol
and I see it has `# Default-Start: 2 3 4 5`.  I had expected to see `#
Default-Start: S`.

Another common firewall package shorewall leaves the main binaries in
/sbin, and starts in the single user runlevel.

Chris Francy

P.S.  I believe Jerome Benoit, the Debian maintainer, is subscribed
here, but should I also add a bug to the Debian bugtracker for this?
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.