Re: firewall rules on builders (iptables, firewalld, libvirt...)

2014-10-30 Thread Dennis Gilmore
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On Tue, 28 Oct 2014 11:07:31 -0400 Paul W. Frields sticks...@gmail.com wrote: On Tue, Oct 28, 2014 at 08:50:29AM -0600, Stephen John Smoogen wrote: On 28 October 2014 08:04, Matthew Miller mat...@fedoraproject.org wrote: It's my

firewall rules on builders (iptables, firewalld, libvirt...)

2014-10-28 Thread Matthew Miller
It's my understanding (Dennis please correct if I'm wrong) that the problem with cloud image creation was due to libvirt iptables rules being lost when iptables was restarted. This is a fundamental known issue (see last paragraph of http://libvirt.org/firewall.html), and one of the things

Re: firewall rules on builders (iptables, firewalld, libvirt...)

2014-10-28 Thread Stephen John Smoogen
On 28 October 2014 08:04, Matthew Miller mat...@fedoraproject.org wrote: It's my understanding (Dennis please correct if I'm wrong) that the problem with cloud image creation was due to libvirt iptables rules being lost when iptables was restarted. This is a fundamental known issue (see last

Re: firewall rules on builders (iptables, firewalld, libvirt...)

2014-10-28 Thread Paul W. Frields
On Tue, Oct 28, 2014 at 08:50:29AM -0600, Stephen John Smoogen wrote: On 28 October 2014 08:04, Matthew Miller mat...@fedoraproject.org wrote: It's my understanding (Dennis please correct if I'm wrong) that the problem with cloud image creation was due to libvirt iptables rules being lost

Re: firewall rules on builders (iptables, firewalld, libvirt...)

2014-10-28 Thread Kevin Fenzi
On Tue, 28 Oct 2014 11:07:31 -0400 Paul W. Frields sticks...@gmail.com wrote: The firewalld rich language is probably also worth looking into -- if for no other reason than to determine whether it is capable of handling these use cases. If not, we should file RFEs upstream because we I'm