From mboxrd@z Thu Jan 1 00:00:00 1970 From: Adolf Belka To: development@lists.ipfire.org Subject: [PATCH] CU185-update.sh: Add drop hostile in & out logging entries if not already present Date: Wed, 20 Mar 2024 15:43:27 +0100 Message-ID: <20240320144327.6050-1-adolf.belka@ipfire.org> MIME-Version: 1.0 Content-Type: multipart/mixed; boundary="===============2184148351006623010==" List-Id: --===============2184148351006623010== Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable - This patch ensures that those people who updated to CU184 before the CU184-= update.sh patch fix to add the logging entries was added will get their optionsfw se= ttings file correctly updated with CU185 - This only adds the LOGDROPHOSTILEIN & LOGDROPHOSTILEOUT entries if they do = noit already exist in the optionsfw settings file. Tested-by: Adolf Belka Signed-off-by: Adolf Belka --- config/rootfiles/core/185/update.sh | 9 +++++++++ 1 file changed, 9 insertions(+) diff --git a/config/rootfiles/core/185/update.sh b/config/rootfiles/core/185/= update.sh index 2c95c4102..ec4d8ab82 100644 --- a/config/rootfiles/core/185/update.sh +++ b/config/rootfiles/core/185/update.sh @@ -115,6 +115,15 @@ mv /var/ipfire/ovpn/ovpnconfig.new /var/ipfire/ovpn/ovpn= config # Set correct ownership chown nobody:nobody /var/ipfire/ovpn/ovpnconfig =20 +# Check if the drop hostile in and out logging options need to be added +# into the optionsfw settings file and apply to firewall +if ! [ $(grep "LOGDROPHOSTILEIN=3Don" /var/ipfire/optionsfw/settings) ] && \ + ! [ $(grep "LOGDROPHOSTILEOUT=3Don" /var/ipfire/optionsfw/settings) ]; th= en + sed -i '$ a\LOGDROPHOSTILEIN=3Don' /var/ipfire/optionsfw/settings + sed -i '$ a\LOGDROPHOSTILEOUT=3Don' /var/ipfire/optionsfw/settings + /usr/local/bin/firewallctrl +fi + # Rebuild initial ramdisks dracut --regenerate-all --force KVER=3D"xxxKVERxxx" --=20 2.44.0 --===============2184148351006623010==--