Your message dated Sat, 18 Feb 2023 18:44:03 +0000
with message-id <[email protected]>
and subject line Bug#992852: fixed in shorewall 5.2.8-2
has caused the Debian Bug report #992852,
regarding /lib/systemd/system/shorewall.service: ignores the setting of SAFESTOP
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)
--
992852: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=992852
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Package: shorewall
Version: 5.2.3.2-1
Severity: normal
File: /lib/systemd/system/shorewall.service
Dear Maintainer,
when setting SAFESTOP=1 in /etc/default/shorewall and doing `service
shorewall stop`, I'd expect the firewall to be safe-stopped (`shorewall
stop`), not cleared (i.e. opened, `shorewall clear`).
With sysvinit this works as expected, but in the systemd.service file,
the ExecStop action is hard-coded to `shorewall clear`, not respecting
the value of the SAFESTOP variable.
This could lead to security issues, as the firewall opens unexpectedly.
-- System Information:
Debian Release: 10.10
APT prefers oldstable-updates
APT policy: (500, 'oldstable-updates'), (500, 'oldstable')
Architecture: amd64 (x86_64)
Kernel: Linux 4.19.0-17-amd64 (SMP w/1 CPU core)
Locale: LANG=de_DE.UTF-8, LC_CTYPE=de_DE.UTF-8 (charmap=UTF-8),
LANGUAGE=de_DE.UTF-8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/dash
Init: systemd (via /run/systemd/system)
LSM: AppArmor: enabled
Versions of packages shorewall depends on:
ii bc 1.07.1-2+b1
ii debconf [debconf-2.0] 1.5.71
ii iproute2 4.20.0-2+deb10u1
ii iptables 1.8.2-4
ii lsb-base 10.2019051400
ii perl 5.28.1-6+deb10u1
ii shorewall-core 5.2.3.2-1
Versions of packages shorewall recommends:
ii libnetfilter-cthelper0 1.0.0-1+b1
Versions of packages shorewall suggests:
ii make 4.2.1-1.2
pn shorewall-doc <none>
-- Configuration Files:
/etc/default/shorewall changed [not included]
/etc/shorewall/conntrack [Errno 13] Keine Berechtigung:
'/etc/shorewall/conntrack'
/etc/shorewall/params [Errno 13] Keine Berechtigung: '/etc/shorewall/params'
/etc/shorewall/shorewall.conf changed [not included]
-- debconf information excluded
--- End Message ---
--- Begin Message ---
Source: shorewall
Source-Version: 5.2.8-2
Done: Jeremy Sowden <[email protected]>
We believe that the bug you reported is fixed in the latest version of
shorewall, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Jeremy Sowden <[email protected]> (supplier of updated shorewall package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Format: 1.8
Date: Sat, 18 Feb 2023 12:56:48 +0000
Source: shorewall
Architecture: source
Version: 5.2.8-2
Distribution: unstable
Urgency: medium
Maintainer: Debian Shorewall Team <[email protected]>
Changed-By: Jeremy Sowden <[email protected]>
Closes: 992852 1030733
Changes:
shorewall (5.2.8-2) unstable; urgency=medium
.
* d/rules: adjust disabling of shorewall-doc rules
* d/patches: add fix for `stop` command to shorewall.8
* Support `SAFESTOP` under systemd (Closes: #992852)
* d/p/03_init_script_fix.patch: update `Forwarded:` link
* d/patches: update patches which have been applied upstream
* d/patches: add patch to fix parsing of `ip addr show` output
(Closes: 1030733)
* d/control: run wrap-and-sort
Checksums-Sha1:
1d6648c995499122c315b9a8d57afb6181a32e97 2440 shorewall_5.2.8-2.dsc
0d27875dbf32f93de1d5fdb3cbb5db1b57c031ac 28684 shorewall_5.2.8-2.debian.tar.xz
1d0c68843e928c680b7484d3035bab260f3ffcec 5884
shorewall_5.2.8-2_source.buildinfo
Checksums-Sha256:
7fbbda76577ec970a5d81fe69cb21be84f405b228a216a7fefd45a899ec5be1d 2440
shorewall_5.2.8-2.dsc
a440647752d8c1fdcc6bea89e9b9ce6e68f65d2a7fb7a995a0760a2f174dc9ef 28684
shorewall_5.2.8-2.debian.tar.xz
21e572e2fa34a7f68862f0fbf8487d76ef89ba6552d2848b5cae21196ecd2298 5884
shorewall_5.2.8-2_source.buildinfo
Files:
0ff5c301d276f4c66ea61a14d8e47517 2440 net optional shorewall_5.2.8-2.dsc
76d4c79244640ee76f7c59ef15822270 28684 net optional
shorewall_5.2.8-2.debian.tar.xz
02e236f5ec2b2428f0b252f2607c5dbf 5884 net optional
shorewall_5.2.8-2_source.buildinfo
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEvjSXQsqYfs1+d+QtrRX0NfBfli0FAmPxFAIACgkQrRX0NfBf
li3prg//ci6jOHfmXc+aUgnyq0eI/0gxcKUHwxzoTgnMIbII04Qct4F7/Hti3812
xRfECFQKWrMk9Lleywlt0xLk7IV2aOXLtgmT/bHctdQJl63/LyZQfVHpjktnz4om
BoqETe7Tq+OkhetFRjb5MpPcrQb3jZOBNJgQN2I+fHdI+GtWiB/Mt2/QuGAF/1KJ
jducxKCvI/YXj/5PnqJKjVDE5qnN7HzJFdgiWGafuLGHb0LYRZ5Cgm827fiKUWlI
i8A1GGTXZUZMymcgmnVWMYbveDaoEyCwLw+04p2xYTE0gxd/UPrrvS1Yt4IaKLOc
Hcwxe+mLvV7wN76LrQcLvoDoYxs577HiaHS/eMfC/utQqlZ9Pb5qc8/VuyBHdtIL
fkYuHbvGC+NZGRdV2op8i56KfD8BW21/cqcvbXTmrUzA7N1hYV5rqPHrak85MSB/
T1h9xaLfUGaq5W/CqX/bjUzrAAPMWuGtbD/gmy7DGOgbIV47r3unIzKV0Rx+OpEp
jCJLfq6uKWYquITyryuiEoElEmKV3eMo1nKo+aK0XpKeS1jWKC2iAzI7c2TefTAf
FqhuPM6OVpZ2hxo0BztAFpgIQaDgRmYgoRNxNom+e31iYYoNQAV0hfS0YYOSUfAl
9hjWTMVz0fsQwNwVsrPIUz3bWT1bTsO6tuNSkN68T7Gj+scxxCw=
=mICc
-----END PGP SIGNATURE-----
--- End Message ---