Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 112942 - Shorewall 3.0 series
Summary: Shorewall 3.0 series
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Linux
Classification: Unclassified
Component: New packages (show other bugs)
Hardware: All Linux
: High enhancement (vote)
Assignee: Gentoo Netmon project
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2005-11-18 11:33 UTC by Vieri
Modified: 2006-10-08 13:01 UTC (History)
8 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments
Shorewall 3.0.1 ebuild (shorewall-3.0.1.ebuild,1.58 KB, text/plain)
2005-11-18 11:34 UTC, Vieri
Details
Shorewall 3.0.2 (shorewall-3.0.2.ebuild,1.75 KB, text/plain)
2005-11-25 11:42 UTC, Vieri
Details
Shorewall 3.0.2 ebuild - fixes and enhancements (shorewall-3.0.2.ebuild,2.13 KB, text/plain)
2005-12-03 17:11 UTC, Vieri
Details
Shorewall-3.0.2 portage subdir (shorewall-3.0.2.tar.gz,1.86 KB, application/octet-stream)
2005-12-03 17:12 UTC, Vieri
Details
Shorewall 3.0.2 ebuild (shorewall-3.0.2.ebuild,2.07 KB, text/plain)
2005-12-04 08:15 UTC, Vieri
Details
Shorewall 3.0.2 portage subdir (shorewall-3.0.2.tar.gz,1.86 KB, application/octet-stream)
2005-12-04 08:17 UTC, Vieri
Details
Shorewall 3.0.2 ebuild patch (shorewall-3.0.2.patch,468 bytes, patch)
2005-12-05 10:03 UTC, Vieri
Details | Diff
Shorewall 3.0.4 ebuild (shorewall-3.0.4.ebuild,1.92 KB, text/plain)
2006-01-18 06:04 UTC, Vieri
Details
Shorewall 3.0.5 modified with Andrej's suggestions (shorewall-3.0.5.ebuild,2.53 KB, text/plain)
2006-02-11 06:22 UTC, Vieri
Details

Note You need to log in before you can comment on or make changes to this bug.
Description Vieri 2005-11-18 11:33:27 UTC
Shorewall 3.0.1

Reproducible: Always
Steps to Reproduce:
1.
2.
3.
Comment 1 Vieri 2005-11-18 11:34:25 UTC
Created attachment 73144 [details]
Shorewall 3.0.1 ebuild
Comment 2 Jakub Moc (RETIRED) gentoo-dev 2005-11-18 11:45:18 UTC
Why are you filing duplicate bugs instead of continuing in the pending one?
Comment 3 Vieri 2005-11-18 12:01:42 UTC
I considered that 3.0.0 should be dropped/deleted. I thought I was doing ok, I 
guess not...
sorry.
What should I do then? Drop this report and go back to the old one?
Comment 4 Ray Booysen 2005-11-23 07:37:12 UTC
Vieri, reopen the 3.0.0 bug, mark this bug a duplicate and then post your ebuild
there.
Comment 5 Daniel Black (RETIRED) gentoo-dev 2005-11-23 10:53:02 UTC
Vieri, ignore Ray. This is fine now. Next time just append to an existing open  
bug report. Reopening and reattaching stuff now is just silly - its mucking 
around with no real gain.  
Comment 6 Vieri 2005-11-24 13:58:49 UTC
If it's ok with Ray and Jakub, I'll follow your suggestion Daniel. Will be 
careful next time.
Comment 7 Vieri 2005-11-25 11:42:01 UTC
Created attachment 73607 [details]
Shorewall 3.0.2

Shorewall 3.0.2 released.
Comment 8 Joshua Schmidlkofer 2005-12-02 16:50:12 UTC
Thanks for putting these up =) I really needed this today, and it was already
here!!!
Comment 9 Vieri 2005-12-03 17:11:11 UTC
Created attachment 74022 [details]
Shorewall 3.0.2 ebuild - fixes and enhancements

Shorewall 3.0.2 ebuild: Makefile fix and Samples.
Comment 10 Vieri 2005-12-03 17:12:39 UTC
Created attachment 74023 [details]
Shorewall-3.0.2 portage subdir

Shorewall-3.0.2 portage subdir
Comment 11 Vieri 2005-12-04 08:15:53 UTC
Created attachment 74046 [details]
Shorewall 3.0.2 ebuild

Changed the way Samples should be stored.
Comment 12 Vieri 2005-12-04 08:17:20 UTC
Created attachment 74047 [details]
Shorewall 3.0.2 portage subdir
Comment 13 Vieri 2005-12-05 10:03:11 UTC
Created attachment 74107 [details, diff]
Shorewall 3.0.2 ebuild patch

Just added an ewarn as suggested by Joshua Schmidlkofer.
Comment 14 Marcelo Goes (RETIRED) gentoo-dev 2005-12-07 10:10:06 UTC
Okies, I committed 3.0.2 to cvs with some modifications.

Please keep the following in mind for the next bug you file:
http://dev.gentoo.org/~ciaranm/docs/mw-faq/attachments.txt
http://dev.gentoo.org/~ciaranm/docs/mw-faq/keywords.txt

Thanks for reporting!
Comment 15 Vieri 2006-01-18 06:04:47 UTC
Created attachment 77418 [details]
Shorewall 3.0.4 ebuild

Identical ebuild. Version bump.
Comment 16 Vieri 2006-01-18 06:05:46 UTC
New package version.
Comment 17 Marcelo Goes (RETIRED) gentoo-dev 2006-01-18 07:04:22 UTC
In cvs, thanks. No need to attach an ebuild if you just renamed it.
Cheers!
Comment 18 Vieri 2006-02-10 09:25:55 UTC
Shorewall 3.0.5: Identical ebuild. Version bump.
Comment 19 Marcelo Goes (RETIRED) gentoo-dev 2006-02-10 12:01:50 UTC
Thanks, bumped in cvs.

x86: 3.0.4 may stabilized if you deem appropriate, so that we have a stable shorewall-3 release.
Comment 20 Andrej Kacian (RETIRED) gentoo-dev 2006-02-11 03:27:37 UTC
I've been using 3.0.4 on an ~x86 for quite some time. Yesterday, I upgraded to 3.0.4 on my stable x86 box, which is using quite non-trivial shorewall setup, what with multiple openvpn tunnels, local network and two zones for external interface. I'll mark stable if all goes ok for next few days.

This said, merging shorewall config files is a PITA, all those commented examples really need their own *.example file to live in.
Comment 21 Vieri 2006-02-11 06:22:27 UTC
Created attachment 79495 [details]
Shorewall 3.0.5 modified with Andrej's suggestions

I agree with Andrej, although partially. Most config file merges are related to changes in comments and at first this may seem a PITA. However, this isn't too bad because it forces the user to read the comments (and thus avoid strange Shorewall behaviors). Personally I would leave it like this OR maybe we could change the ebuild so it leaves the /etc/shorewall dir blank and the user must copy the config files over from /usr/share/doc. Anyway I'm attaching a proposal. I know 3.0.5 is already out so this new attachment may be taken into consideration for the next release only.
Comment 22 Marcelo Goes (RETIRED) gentoo-dev 2006-02-11 08:37:03 UTC
My vote is for leaving it the way it is. The ebuild already gives a fair amount of warning that shorewall-3 differs a lot from shorewall-2.

Having the ebuild behave differently if it finds /etc/shorewall isn't really good behavior and might be even more confusing.

My 2 cents.
Comment 23 Vieri 2006-02-11 11:12:09 UTC
I'm running two "production" firewalls/gateways/routers on x86 with Shorewall 3.0.2 since it was released. Several openvpn and PPTP tunnels among other things. Looks stable to me although I leave it entirely to the x86 team.
3.0.4 and 3.0.5 are only on test systems so I haven't really "used" them for day to day work.
Comment 24 Andrej Kacian (RETIRED) gentoo-dev 2006-02-14 02:49:22 UTC
After bit more succssful playing with shorewall configuration, I think 3.0.4 is ok to go stable. Marked x86.
Comment 25 Marcelo Goes (RETIRED) gentoo-dev 2006-02-14 08:12:52 UTC
Marking bug as fixed.
Comment 26 Vieri 2006-03-29 08:31:40 UTC
Shorewall 3.0.6: version bump.
Includes the "inet" fix mentioned previously.
Comment 27 Vieri 2006-04-05 01:05:38 UTC
Maybe the following einfo:
 * If you intend to use the 2.6 IPSEC Support, you must retrieve the
 * kernel patches from http://shorewall.net/pub/shorewall/contrib/IPSEC/
should be changed to:
 * If you intend to use the 2.6 IPSEC Support, you must retrieve the
 * kernel patches from http://shorewall.net/pub/shorewall/contrib/IPSEC/
 * or install the latest kernel and make sure it supports policy match.
Comment 28 Vieri 2006-04-12 07:49:24 UTC
(In reply to comment #27)
> Maybe the following einfo:
>  * If you intend to use the 2.6 IPSEC Support, you must retrieve the
>  * kernel patches from http://shorewall.net/pub/shorewall/contrib/IPSEC/
> should be changed to:
>  * If you intend to use the 2.6 IPSEC Support, you must retrieve the
>  * kernel patches from http://shorewall.net/pub/shorewall/contrib/IPSEC/
>  * or install the latest kernel and make sure it supports policy match.

Actually I would rather change it to:
  * If you intend to use the 2.6 IPSEC Support, you must retrieve the
  * kernel patches from http://shorewall.net/pub/shorewall/contrib/IPSEC/
  * or install kernel 2.6.16+ and compile it with support for policy match.

http://gentoo-wiki.com/HOWTO_Shorewall_Firewall_IPsec_VPN_and_2.6_kernel

Can anyone please put the 3.0.6 version up in CVS?
Comment 29 Matthias Dahl 2006-04-18 13:46:58 UTC
I second Vieri's request: putting 3.0.6 in portage (bumping is enough) would be great as it contains some important fixes. Just spent hours on a server with OpenVPN and Shorewall, just to realize that the routeback option in the hosts file was silently ignored because of a bug. *argh* Made an overlay for 3.0.6 and things work just fine now.
Comment 30 Marcelo Goes (RETIRED) gentoo-dev 2006-04-18 15:46:23 UTC
Hi,

Sorry, I have been busy.
3.0.6 is now in CVS, I added Vieri's new einfo line to the ebuild.

Thanks!
Comment 31 Vieri 2006-05-09 05:30:50 UTC
Shorewall 3.0.7: version bump.

Maybe the following einfo should be added:
 * Whether upgrading or installing you should run "shorewall check", correct any errors found and run "shorewall restart|start".
Comment 32 Vieri 2006-05-22 00:28:29 UTC
I suggest marking 3.0.6 as stable on x86 and amd64 and putting 3.0.7 up as unstable.
Comment 33 Marcelo Goes (RETIRED) gentoo-dev 2006-05-23 19:32:18 UTC
Thanks, bumped to 3.0.7 in cvs.
x86, amd64: stable keywording up to you.
Comment 34 Andrej Kacian (RETIRED) gentoo-dev 2006-05-24 13:26:36 UTC
I've been using 3.0.6 since it got released on my stable box, and it works. Marked stable on x86.
Comment 35 Vieri 2006-06-22 00:54:54 UTC
Version bump request for Shorewall 3.0.8.

Same ebuild tested on x86 and amd64.
Comment 36 Vieri 2006-07-11 08:48:45 UTC
Shorewall 3.2 ebuild proposals at:
http://bugs.gentoo.org/show_bug.cgi?id=140001

This 3.0 bug should still be kept open due to future releases in this branch.

I think Marcelo Goes has been very busy lately (devaway). Can someone else have a look at the 3.2 ebuilds?
Comment 37 Andrej Kacian (RETIRED) gentoo-dev 2006-07-11 09:16:52 UTC
(In reply to comment #36)
> Shorewall 3.2 ebuild proposals at:
> http://bugs.gentoo.org/show_bug.cgi?id=140001
> 
> This 3.0 bug should still be kept open due to future releases in this branch.
> 
> I think Marcelo Goes has been very busy lately (devaway). Can someone else have
> a look at the 3.2 ebuilds?
> 

I'll have a look at 3.2, as well as on 3.0.8 bump as time permits, sometimes this week.
Comment 38 Andrej Kacian (RETIRED) gentoo-dev 2006-07-11 09:49:15 UTC
There, 3.0.8 added to Portage, and perhaps 3.0.7 is ripe for getting marked stable, and it indeed works nicely on my two stable boxes.

I'll leave that for Marcelo for decide, though.
Comment 39 Marcelo Goes (RETIRED) gentoo-dev 2006-07-11 17:46:33 UTC
Andrej, feel free to stabilize it :-).
Comment 40 Vieri 2006-07-12 00:27:51 UTC
Thank you both.
I am reopening this bug because 3.0.9 will come out surely.
3.2.0 is another branch thus it's ok to have 3.2 out before 3.0.9 (http://bugs.gentoo.org/show_bug.cgi?id=140001).
Comment 41 Vieri 2006-08-13 14:53:57 UTC
Requesting 3.0.8 to go stable on x86 and amd64.
Comment 42 Vieri 2006-08-18 10:36:32 UTC
Maybe setting up an overlay for shorewall (or net-firewall as a whole) could be interesting?
http://overlays.gentoo.org
Comment 43 Richard Freeman gentoo-dev 2006-09-08 20:01:11 UTC
(In reply to comment #41)
> Requesting 3.0.8 to go stable on x86 and amd64.
> 

3.0.8 appears to work fine on my stable amd64 box (I am an amd64 AT).  If maintainer is willing it should be OK to keyword stable on amd64 (out 30+ days, no open bugs).

As 3.0.8 is not stable on any arch I will refrain from logging a bug with the amd64 arch team until a dev chimes in that this is OK from netmon's standpoint.
Comment 44 Benjamin Smee (strerror) (RETIRED) gentoo-dev 2006-09-18 05:30:24 UTC
feel free to stabilize it, though I just added 3.2.3 to the tree...
Comment 45 Andrej Kacian (RETIRED) gentoo-dev 2006-09-18 06:28:43 UTC
I'm using 3.0.8 since it got into the tree, and it works. Marked x86.
Comment 46 Vieri 2006-09-19 10:20:18 UTC
(In reply to comment #44)
> feel free to stabilize it, though I just added 3.2.3 to the tree...

Thanks.
3.0 is the "older" shorewall series and it really is safe to mark it stable (currently 3.0.8).
3.2 is the "newer" shorewall series and personally I think it should still be kept unstable for a while.
Comment 47 Vieri 2006-10-06 09:32:59 UTC
shorewall 3.0.9 version bump.

Andrej or someone else, please?

(It should finally close this bug.)
Comment 48 Markus Ullmann (RETIRED) gentoo-dev 2006-10-08 13:01:19 UTC
Bumped both to latest versions