Re: [Security-Discuss] MDK Update And Shorewall

Thomas Herlea <Thomas.Herlea-8ZVx2yYfyutX2QMWbMbClIble9XqW/[email protected]>
Newsgroups gmane.linux.mandrake.security.general
Message-ID <[email protected]>
On Wednesday 22 September 2004 20:05, FACORAT Fabrice wrote:
> How this could be done technically ? scripts from a rpm package are
> launched when the package is installed/removed.

I am not sure of what the scripts currently do during upgrade, but the 
two methods described below seem to let the upgrade happen safely.

Method 1

If the scripts called "/sbin/service shorewall" with the action 
"rstopped" (not with "stop"), then /sbin/shorewall would be called 
with the "stop" argument (not with "clear") and the effect would be a 
safe stop as described in the shorewall documentation:

"The shorewall stop command does not remove all netfilter rules and 
open your firewall for all traffic to pass. It rather places your 
firewall in a safe state defined by the contents of 
your /etc/shorewall/routestopped file and the setting of 
ADMINISABSENTMINDED in /etc/shorewall/shorewall.conf."
(http://www.shorewall.net/starting_and_stopping_shorewall.htm#id2485982)

Then the safety of the stopped state would depend on the sysadmin or 
on the default configuration.

An issue to consider with this solution is whether a total traffic 
block would interfere with the upgrade of other packages when 
shorewall is upgraded at the same time with others.

Method 2

IMHO "/sbin/service shorewall" does not need to be (r)stopped and then 
(re)started when the package is upgraded because there is no running 
program that needs to be upgraded, as explained in the documentation:

"Shorewall is not a daemon. Once Shorewall has configured Netfilter, 
it's job is complete and there is no “Shorewall process” left running 
in your system."
(http://www.shorewall.net/Introduction.html#id2439106)

It seems to me that it should be possible to leave the netfilter rules 
untouched during the upgrade, leaving it up to the sysadmin to tune 
the shorewall config files in /etc/shorewall/ and reapply them later 
with "/sbin/service shorewall restart".

If the netfilter rules must be updated during package upgrade for some 
reason, I think it's enough to call "/sbin/service shorewall restart" 
from the rpm scripts. Still, the packager should avoid doing this if 
there is the possibility that the new version of shorewall has a 
problem with the existing format of the configuration files.

I am inexperienced with packaging, so I might have overseen something 
and the two methods might be useless, therefore it would be helpful 
if any of you pointed out problems with them.Thanks in advance for 
any criticism.

Hope this helps,
Thomas.
-- 
[Random fortune cookie]:
79. What's this "any" key I'm supposed to press?

	--Top 100 things you don't want the sysadmin to say
message.footer (text/plain, 239 B)
____________________________________________________
Want to buy your Pack or Services from MandrakeSoft? 
Go to http://www.mandrakestore.com
Join the Club : http://www.mandrakeclub.com
____________________________________________________
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.