From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from mail02.haj.ipfire.org (localhost [IPv6:::1]) by mail02.haj.ipfire.org (Postfix) with ESMTP id 4hdtQj5jtPz36WJ for ; Mon, 07 Sep 2026 16:52:13 +0000 (UTC) Received: from mail01.ipfire.org (mail01.haj.ipfire.org [IPv6:2001:678:b28::25]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature ECDSA (secp384r1 raw public key) server-digest SHA384 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "mail01.haj.ipfire.org", Issuer "YR2" (not verified)) by mail02.haj.ipfire.org (Postfix) with ESMTPS id 4hdtQf2clKz2xLt for ; Mon, 07 Sep 2026 16:52:10 +0000 (UTC) Received: from out.smtpout.orange.fr (out-74.smtpout.orange.fr [193.252.22.74]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature RSA-PSS (4096 bits) server-digest SHA256 client-signature RSA-PSS (2048 bits) client-digest SHA256) (Client CN "*.smtpout.orange.fr", Issuer "DigiCert Global G2 TLS RSA SHA256 2020 CA1" (verified OK)) by mail01.ipfire.org (Postfix) with ESMTPS id 4hdtQT1yzpz9D for ; Mon, 07 Sep 2026 16:52:01 +0000 (UTC) Authentication-Results: mail01.ipfire.org; dkim=pass header.d=orange.fr header.s=t20230301 header.b=nFWtHFNM; dmarc=pass (policy=quarantine) header.from=orange.fr; spf=pass (mail01.ipfire.org: domain of p27m@orange.fr designates 193.252.22.74 as permitted sender) smtp.mailfrom=p27m@orange.fr ARC-Seal: i=1; a=rsa-sha256; d=lists.ipfire.org; s=202003rsa; cv=none; t=1788799921; b=dUtruvTGZR71AXUzDOKazDfe3g2ln/1Gy6yiH8PMfH6GoOl3UG82JrpJxL+urmOpeIyS57 SocqlG2aEO3ON+7rB/qmqDAaZxEpd19evgbqa3DEB1G9ViCEBMH0riKBcn/rNRrxhogiWz TFMT1gMMj+MFBeRCdBGc+XxqxmE8oGvzQL7Sa7ce6Q8furCDTSVVqVadjQewCwEsq7YRYx 1vxUlOsiaV2k+AWaCUDR/9GWncLEXgFd/8N6RiGrRrsLTXE68VkCsGHY1WrbhSHk+IvCkq TxdULFzo1VyFjgg+V/dhS/h5+baPzP26U+5k1DtW5ztm5dN6reveg3TsBSCuMA== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=lists.ipfire.org; s=202003rsa; t=1788799921; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references:dkim-signature; bh=rF+keTyoSO08mXaO9Ik6kGUt8dEH7vqSl3XusFO6WIo=; b=AHwXi3Bt51APYI3pvHqPr7q1czeis2A+7JUmGHhs7pOqEM7Ru+6WXkuUoOgrIYs2GMLoVo KXipWQ1tnsu94U1GJA3hFo3Lck0V8cYTE7mXf1W2H/Hqmpmm0/HdRmAdmTDvP7iAhMpBni ocHcLl7n6dlbUQNmCoF9sWcihO0W261bZbo9KfThyeeSQ1hqLgmZxVmLvZ1r+Y3B3ZSxkJ hiPaiYBgs2WlY8jvVydZu5q9JuDZhpiPZDfSZhiWcXmOrQJGEscK62CXuHRa94ZF6HmMaV 5jsjs3VA3W0ohOZtCLJDONTzX94nqeP3CmWhJMFs/N3gWQLZvww4zSNIR7gfGA== ARC-Authentication-Results: i=1; mail01.ipfire.org; dkim=pass header.d=orange.fr header.s=t20230301 header.b=nFWtHFNM; dmarc=pass (policy=quarantine) header.from=orange.fr; spf=pass (mail01.ipfire.org: domain of p27m@orange.fr designates 193.252.22.74 as permitted sender) smtp.mailfrom=p27m@orange.fr Received: from [192.168.20.32] ([176.146.212.228]) by smtp.orange.fr with ESMTPSA id 3cZbxDP68cH183cZcxUwSg; Mon, 07 Sep 2026 18:52:00 +0200 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=orange.fr; s=t20230301; t=1788799920; bh=rF+keTyoSO08mXaO9Ik6kGUt8dEH7vqSl3XusFO6WIo=; h=Message-ID:Date:MIME-Version:Subject:To:From; b=nFWtHFNMYZDlW40cgd3ux/6/KPLboj5yEVvSrdS2HGd7O9wPQLzAbL6lOooTWOxCr ayxdyBS8/P8vjnwaXMo4FXAieWVe64EPReApmbT0tlyRedO+8+GG42dw1OuHOiV4Hn J6ZYMqpQ97iR6LXBq73iJ8Fgss7RuUvU0wIxaMGoonQ39Ol48hbsFDJ5sj/KDyjZyu PCMi3FZFjzWYZt8/3d/uhKQNWw2R1JtAeK6t3hWsW30I453bFG329M4kToPGGyQruB 56hVCBJobMsKFoHAP4xbTX8TjAWmnf9vNFqvwvCIb6Fd4xLI8WVk+waTgYEFqLZB7i 0GLhFGk49gcqQ== X-ME-Helo: [192.168.20.32] X-ME-Auth: cDI3bUBvcmFuZ2UuZnI= X-ME-Date: Mon, 07 Sep 2026 18:52:00 +0200 X-ME-IP: 176.146.212.228 Message-ID: Date: Mon, 7 Sep 2026 18:51:59 +0200 Precedence: list List-Id: List-Subscribe: , List-Unsubscribe: , List-Post: List-Help: Sender: Mail-Followup-To: MIME-Version: 1.0 User-Agent: Mozilla Thunderbird Subject: Re: [PATCH] urlfilter: Remove bundled Toulouse blacklist To: development@lists.ipfire.org References: <20260827091639.4064898-1-p27m@orange.fr> <217EBED3-D400-4695-A345-816C7DD47207@ipfire.org> <6C039B7E-2BAF-45B7-9C87-A7D008EF3443@ipfire.org> Content-Language: fr, en-US From: p27m In-Reply-To: <6C039B7E-2BAF-45B7-9C87-A7D008EF3443@ipfire.org> Content-Type: text/plain; charset=UTF-8; format=flowed Content-Transfer-Encoding: 8bit X-Rspamd-Action: no action X-Spamd-Result: default: False [-5.90 / 11.00]; BAYES_HAM(-3.00)[100.00%]; NEURAL_HAM(-3.00)[-1.000]; HFILTER_HELO_IP_A(1.00)[out.smtpout.orange.fr]; DMARC_POLICY_ALLOW(-0.50)[orange.fr,quarantine]; R_SPF_ALLOW(-0.20)[+ip4:193.252.22.0/25]; R_DKIM_ALLOW(-0.20)[orange.fr:s=t20230301]; ONCE_RECEIVED(0.20)[]; MIME_GOOD(-0.10)[text/plain]; MX_GOOD(-0.10)[smtp-in2.orange.fr]; TO_MATCH_ENVRCPT_ALL(0.00)[]; RCPT_COUNT_ONE(0.00)[1]; MIME_TRACE(0.00)[0:+]; ARC_NA(0.00)[]; FREEMAIL_ENVFROM(0.00)[orange.fr]; FREEMAIL_FROM(0.00)[orange.fr]; RCVD_TLS_ALL(0.00)[]; FROM_HAS_DN(0.00)[]; RCVD_IN_DNSWL_NONE(0.00)[193.252.22.74:from]; DWL_DNSWL_NONE(0.00)[orange.fr:dkim]; RECEIVED_SPAMHAUS_PBL(0.00)[176.146.212.228:received]; TO_DN_NONE(0.00)[]; FROM_EQ_ENVFROM(0.00)[]; DKIM_TRACE(0.00)[orange.fr:+]; MID_RHS_MATCH_FROM(0.00)[]; ASN(0.00)[asn:3215, ipnet:193.252.20.0/22, country:FR]; RCVD_VIA_SMTP_AUTH(0.00)[]; DKIM_REPUTATION(0.00)[0]; RCVD_COUNT_ONE(0.00)[1]; ARC_SIGNED(0.00)[lists.ipfire.org:s=202003rsa:i=1] X-Rspamd-Server: mail01.haj.ipfire.org X-Rspamd-Queue-Id: 4hdtQT1yzpz9D Hello Michael, Yes, I Build it and install master ISO (CU204) on my test virtual machine. SquidGuard starts without errors when the blacklist directory is empty (the patch preserves the custom list). Naturally, no category-based filtering takes place until a blacklist has been downloaded. I also ran a test using only a custom blacklist. In this case, SquidGuard starts normally, and the custom domain is correctly blocked. This point was documented in comment #13 of bug 13969: https://bugzilla.ipfire.org/show_bug.cgi?id=13969#c13 Thus, removing the default blacklist does not prevent URLFilter/SquidGuard from starting or functioning. The user can simply download or restore a blacklist later, or use only the custom blacklist. Best regards, Philippe Le 07/09/2026 à 17:22, Michael Tremer a écrit : > Hello Phil, > > Yes, this makes sense so far. But what actually happens when squidGuard is being started with nothing? I remember that this list has been treated as a dummy. Did you test this case too? > > -Michael > >> On 29 Aug 2026, at 16:56, p27m wrote: >> >> Hi Michael, >> >> Thank you for your reply. >> >> The problem described in the bug report is actually quite simple. >> >> Currently, the blacklist included in the IPFire repository and installed with IPFire dates from June 15, 2005, so it is now obsolete. >> Since March 2026, the University of Toulouse has changed some directories in its blacklist into symbolic links. >> Therefore, when restoring a backup containing a blacklist downloaded after this change, `tar` can fail because symbolic links cannot replace existing directories. As a result, the backup restoration fails. >> >> @adolf previously added a fix to `backup.pl` which removes the existing contents of `/var/ipfire/urlfilter/blacklists/` before extracting the backup. >> >> However, I recently discovered that the problem could still occur when restoring a backup from a backup ISO. >> >> For this reason, I thought that the simplest solution, and the best way to avoid similar problems in the future, would be to remove the obsolete blacklist archive from the installation. >> >> This patch does not prevent URLFilter from working without an installed blacklist. It also ensures that the old blacklist shipped with IPFire cannot interfere with restoring a newer blacklist from a backup. >> >> I have tested the patch with upgrades, fresh ISO installations, and restoration of backups containing both the Toulouse blacklist and the IPFire DBL blacklist. >> >> Best regards, >> >> Philippe >> >> Le 29/08/2026 à 17:31, Michael Tremer a écrit : >>> Thank you very much for this patch. >>> >>> I could not quite figure out what you want to achieve with this change. Is this data being shipped causing some problems? The bug report did not give me the information I was looking for either. >>> >>> All the best, >>> -Michael >