From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from mail02.haj.ipfire.org (localhost [IPv6:::1]) by mail02.haj.ipfire.org (Postfix) with ESMTP id 4hXKcX11bvz36WZ for ; Sat, 29 Aug 2026 15:56:28 +0000 (UTC) Received: from mail01.ipfire.org (mail01.haj.ipfire.org [172.28.1.202]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519) (Client CN "mail01.haj.ipfire.org", Issuer "YR2" (not verified)) by mail02.haj.ipfire.org (Postfix) with ESMTPS id 4hXKcS5N1gz2xVL for ; Sat, 29 Aug 2026 15:56:24 +0000 (UTC) Received: from smtp.smtpout.orange.fr (smtp-71.smtpout.orange.fr [80.12.242.71]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature RSA-PSS (4096 bits) server-digest SHA256 client-signature RSA-PSS (2048 bits) client-digest SHA256) (Client CN "*.smtpout.orange.fr", Issuer "DigiCert Global G2 TLS RSA SHA256 2020 CA1" (verified OK)) by mail01.ipfire.org (Postfix) with ESMTPS id 4hXKcJ3GfJz1mh for ; Sat, 29 Aug 2026 15:56:16 +0000 (UTC) Authentication-Results: mail01.ipfire.org; dkim=pass header.d=orange.fr header.s=t20230301 header.b=RvvelKJl; spf=pass (mail01.ipfire.org: domain of p27m@orange.fr designates 80.12.242.71 as permitted sender) smtp.mailfrom=p27m@orange.fr; dmarc=pass (policy=quarantine) header.from=orange.fr ARC-Seal: i=1; a=rsa-sha256; d=lists.ipfire.org; s=202003rsa; cv=none; t=1788018976; b=hWxpY/+w/VsmT8cWYTgmxOBZJ+0BKzgfEes8Gp3M+0ZS3TKsL3nJqrxU5XXurlxudL6aNf PPe6ow4VjSjZKO+l5VbA9ovRV4IFRPpMKCceR08PV4YkgM0w3CxDlfDH4Ui2bQwLkulhZ2 J13Vh1dxO/QIZvQVfEqu579sjGXwtTBwZk5E0fMkMKVY+lddp8whaIhfMDok2opgMVuc0Q Ao7qwT7z+NePnDFFbNlT2PRv28rPf+Piu6Hdh6bsP2sAy4cTbqlBz00HHJF0GeAXCJ9vkh jxDI+p/dgyc2pgdrPE7133DUe/qmDog/abN4LH5Cl9sQEVsdUkXzfr9JcZVjtA== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=lists.ipfire.org; s=202003rsa; t=1788018976; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: in-reply-to:in-reply-to:references:references:dkim-signature; bh=iwEyErN/+Qkkx/IYJ+zxnXsIqIVyxe4O+CvngzzSUjQ=; b=RxZae4OEtxlSDwAK7TcZa5wZ0zvzJZbEMEX9OAA0GTxDhSUA5C2AkioK85EIAjg/04VdHE L+Uftj1P7ZXBdyGwlBMZt0QdU0lmxgaUR/kX5vsEXJ+IHGtnMPVxb33Kjdx1r/ousfmG5V V4UCdPEiJaA66f0WkMm3EBd2m0TS+QQllX61J1uFZV0WpNWcP+yweKjo+gtR4X+w1CUv0U J9VYKE7FtLiPUZtxX63YufNFKmiOMEqkx5kgrZ/GhG1KdfNqa/AI+ppqr+aIOIfUhFznx/ J3QCiXPaiv7/+Xgkv1TYWN9+MOqrVpHFuxTgxjZV2On4eXg08D6ugzrA2vjFDw== ARC-Authentication-Results: i=1; mail01.ipfire.org; dkim=pass header.d=orange.fr header.s=t20230301 header.b=RvvelKJl; spf=pass (mail01.ipfire.org: domain of p27m@orange.fr designates 80.12.242.71 as permitted sender) smtp.mailfrom=p27m@orange.fr; dmarc=pass (policy=quarantine) header.from=orange.fr Received: from [192.168.20.32] ([176.146.212.228]) by smtp.orange.fr with ESMTPSA id 0LPjxboyRQZqZ0LPjxdXdc; Sat, 29 Aug 2026 17:56:15 +0200 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=orange.fr; s=t20230301; t=1788018975; bh=iwEyErN/+Qkkx/IYJ+zxnXsIqIVyxe4O+CvngzzSUjQ=; h=Message-ID:Date:MIME-Version:Subject:To:From; b=RvvelKJldYqWgw0iAS4fEsX84EpvlNq9ox9XNwUeXhcnXmFv7E7kH2tF+wl72v+Xa rLwt0jPusLK4QKcoLsHU2/M6+CPKCUQKHPIGAzDHZza/+ns6F9C/GPAo4BuuTOUYPA YFnAZq+rT8/kl5K03iEJhjiUWCp1A6w22yI/ZWTK1wsmr2HYVXX4wAseYJ5Rt58cnX LT2n/ollc3Fdw977nT0oOQydtiTFvfLfwOxY6Efr1592zR+Eyxe20y0BjjMvmdmfim 6KVYnLPAZmdNS5hfCG4vnrqh6hoc4eCnV/kRifhNz62sPeruMZiUiEva57hHg9uI1A pX0doDLv3/frw== X-ME-Helo: [192.168.20.32] X-ME-Auth: cDI3bUBvcmFuZ2UuZnI= X-ME-Date: Sat, 29 Aug 2026 17:56:15 +0200 X-ME-IP: 176.146.212.228 Content-Type: multipart/alternative; boundary="------------zvX7C120rJDiNp9nc4zEHjHC" Message-ID: Date: Sat, 29 Aug 2026 17:56:15 +0200 Precedence: list List-Id: List-Subscribe: , List-Unsubscribe: , List-Post: List-Help: Sender: Mail-Followup-To: MIME-Version: 1.0 User-Agent: Mozilla Thunderbird Subject: Re: [PATCH] urlfilter: Remove bundled Toulouse blacklist To: development@lists.ipfire.org References: <20260827091639.4064898-1-p27m@orange.fr> <217EBED3-D400-4695-A345-816C7DD47207@ipfire.org> Content-Language: fr From: p27m In-Reply-To: <217EBED3-D400-4695-A345-816C7DD47207@ipfire.org> X-Rspamd-Action: no action X-Spamd-Result: default: False [-6.10 / 11.00]; BAYES_HAM(-3.00)[100.00%]; NEURAL_HAM(-3.00)[-0.999]; HFILTER_HELO_IP_A(1.00)[smtp.smtpout.orange.fr]; DMARC_POLICY_ALLOW(-0.50)[orange.fr,quarantine]; ONCE_RECEIVED(0.20)[]; R_DKIM_ALLOW(-0.20)[orange.fr:s=t20230301]; R_SPF_ALLOW(-0.20)[+ip4:80.12.242.0/25]; RWL_MAILSPIKE_VERYGOOD(-0.20)[80.12.242.71:from]; MIME_GOOD(-0.10)[multipart/alternative,text/plain]; MX_GOOD(-0.10)[smtp-in2.orange.fr]; IP_REPUTATION_HAM(0.00)[asn: 3215(0.00), country: FR(-0.00), ip: 80.12.242.71(0.00)]; FREEMAIL_FROM(0.00)[orange.fr]; FREEMAIL_ENVFROM(0.00)[orange.fr]; ARC_NA(0.00)[]; TO_MATCH_ENVRCPT_ALL(0.00)[]; MIME_TRACE(0.00)[0:+,1:+,2:~]; RCPT_COUNT_ONE(0.00)[1]; RCVD_TLS_ALL(0.00)[]; FROM_HAS_DN(0.00)[]; RCVD_IN_DNSWL_NONE(0.00)[80.12.242.71:from]; DWL_DNSWL_NONE(0.00)[orange.fr:dkim]; RECEIVED_SPAMHAUS_PBL(0.00)[176.146.212.228:received]; TO_DN_NONE(0.00)[]; FROM_EQ_ENVFROM(0.00)[]; DKIM_TRACE(0.00)[orange.fr:+]; MID_RHS_MATCH_FROM(0.00)[]; ASN(0.00)[asn:3215, ipnet:80.12.240.0/20, country:FR]; RCVD_VIA_SMTP_AUTH(0.00)[]; DKIM_REPUTATION(0.00)[0]; RCVD_COUNT_ONE(0.00)[1]; ARC_SIGNED(0.00)[lists.ipfire.org:s=202003rsa:i=1] X-Rspamd-Server: mail01.haj.ipfire.org X-Rspamd-Queue-Id: 4hXKcJ3GfJz1mh This is a multi-part message in MIME format. --------------zvX7C120rJDiNp9nc4zEHjHC Content-Type: text/plain; charset=UTF-8; format=flowed Content-Transfer-Encoding: 8bit Hi Michael, Thank you for your reply. The problem described in the bug report is actually quite simple. Currently, the blacklist included in the IPFire repository and installed with IPFire dates from June 15, 2005, so it is now obsolete. Since March 2026, the University of Toulouse has changed some directories in its blacklist into symbolic links. Therefore, when restoring a backup containing a blacklist downloaded after this change, `tar` can fail because symbolic links cannot replace existing directories. As a result, the backup restoration fails. @adolf previously added a fix to `backup.pl` which removes the existing contents of `/var/ipfire/urlfilter/blacklists/` before extracting the backup. However, I recently discovered that the problem could still occur when restoring a backup from a backup ISO. For this reason, I thought that the simplest solution, and the best way to avoid similar problems in the future, would be to remove the obsolete blacklist archive from the installation. This patch does not prevent URLFilter from working without an installed blacklist. It also ensures that the old blacklist shipped with IPFire cannot interfere with restoring a newer blacklist from a backup. I have tested the patch with upgrades, fresh ISO installations, and restoration of backups containing both the Toulouse blacklist and the IPFire DBL blacklist. Best regards, Philippe Le 29/08/2026 à 17:31, Michael Tremer a écrit : > Thank you very much for this patch. > > I could not quite figure out what you want to achieve with this change. Is this data being shipped causing some problems? The bug report did not give me the information I was looking for either. > > All the best, > -Michael --------------zvX7C120rJDiNp9nc4zEHjHC Content-Type: text/html; charset=UTF-8 Content-Transfer-Encoding: 8bit

Hi Michael,

Thank you for your reply.

The problem described in the bug report is actually quite simple.

Currently, the blacklist included in the IPFire repository and installed with IPFire dates from June 15, 2005, so it is now obsolete.
Since March 2026, the University of Toulouse has changed some directories in its blacklist into symbolic links.
Therefore, when restoring a backup containing a blacklist downloaded after this change, `tar` can fail because symbolic links cannot replace existing directories. As a result, the backup restoration fails.

@adolf previously added a fix to `backup.pl` which removes the existing contents of `/var/ipfire/urlfilter/blacklists/` before extracting the backup.

However, I recently discovered that the problem could still occur when restoring a backup from a backup ISO.

For this reason, I thought that the simplest solution, and the best way to avoid similar problems in the future, would be to remove the obsolete blacklist archive from the installation.

This patch does not prevent URLFilter from working without an installed blacklist. It also ensures that the old blacklist shipped with IPFire cannot interfere with restoring a newer blacklist from a backup.

I have tested the patch with upgrades, fresh ISO installations, and restoration of backups containing both the Toulouse blacklist and the IPFire DBL blacklist.

Best regards,

Philippe

Le 29/08/2026 à 17:31, Michael Tremer a écrit :
Thank you very much for this patch.

I could not quite figure out what you want to achieve with this change. Is this data being shipped causing some problems? The bug report did not give me the information I was looking for either.

All the best,
-Michael
--------------zvX7C120rJDiNp9nc4zEHjHC--