Re: [Security-Discuss] MDK Update And Shorewall
Thomas Herlea <Thomas.Herlea-8ZVx2yYfyutX2QMWbMbClIble9XqW/[email protected]>
| Newsgroups | gmane.linux.mandrake.security.general |
|---|---|
| Message-ID | <[email protected]> |
On Wednesday 22 September 2004 20:05, FACORAT Fabrice wrote: > How this could be done technically ? scripts from a rpm package are > launched when the package is installed/removed. I am not sure of what the scripts currently do during upgrade, but the two methods described below seem to let the upgrade happen safely. Method 1 If the scripts called "/sbin/service shorewall" with the action "rstopped" (not with "stop"), then /sbin/shorewall would be called with the "stop" argument (not with "clear") and the effect would be a safe stop as described in the shorewall documentation: "The shorewall stop command does not remove all netfilter rules and open your firewall for all traffic to pass. It rather places your firewall in a safe state defined by the contents of your /etc/shorewall/routestopped file and the setting of ADMINISABSENTMINDED in /etc/shorewall/shorewall.conf." (http://www.shorewall.net/starting_and_stopping_shorewall.htm#id2485982) Then the safety of the stopped state would depend on the sysadmin or on the default configuration. An issue to consider with this solution is whether a total traffic block would interfere with the upgrade of other packages when shorewall is upgraded at the same time with others. Method 2 IMHO "/sbin/service shorewall" does not need to be (r)stopped and then (re)started when the package is upgraded because there is no running program that needs to be upgraded, as explained in the documentation: "Shorewall is not a daemon. Once Shorewall has configured Netfilter, it's job is complete and there is no “Shorewall process” left running in your system." (http://www.shorewall.net/Introduction.html#id2439106) It seems to me that it should be possible to leave the netfilter rules untouched during the upgrade, leaving it up to the sysadmin to tune the shorewall config files in /etc/shorewall/ and reapply them later with "/sbin/service shorewall restart". If the netfilter rules must be updated during package upgrade for some reason, I think it's enough to call "/sbin/service shorewall restart" from the rpm scripts. Still, the packager should avoid doing this if there is the possibility that the new version of shorewall has a problem with the existing format of the configuration files. I am inexperienced with packaging, so I might have overseen something and the two methods might be useless, therefore it would be helpful if any of you pointed out problems with them.Thanks in advance for any criticism. Hope this helps, Thomas. -- [Random fortune cookie]: 79. What's this "any" key I'm supposed to press? --Top 100 things you don't want the sysadmin to say
message.footer
(text/plain, 239 B)
____________________________________________________ Want to buy your Pack or Services from MandrakeSoft? Go to http://www.mandrakestore.com Join the Club : http://www.mandrakeclub.com ____________________________________________________