SCIENTIFIC-LINUX-DEVEL Archives

September 2017

SCIENTIFIC-LINUX-DEVEL@LISTSERV.FNAL.GOV

Options: Use Monospaced Font
Show Text Part by Default
Show All Mail Headers

Message: [<< First] [< Prev] [Next >] [Last >>]
Topic: [<< First] [< Prev] [Next >] [Last >>]
Author: [<< First] [< Prev] [Next >] [Last >>]

Print Reply
Subject:
From:
Steven Haigh <[log in to unmask]>
Reply To:
Steven Haigh <[log in to unmask]>
Date:
Fri, 15 Sep 2017 17:11:42 +1000
Content-Type:
text/plain
Parts/Attachments:
text/plain (25 lines)
On 2017-09-15 16:11, Ilari Stenroth wrote:
> CentOS did fix the iptables bug before the upstream EL distribution in
> their package release iptables-1.4.21-18.0.1.el7. It's mentioned here:
> https://wiki.centos.org/Manuals/ReleaseNotes/CentOS7 Maybe the fixed
> package can be ported to SL7.4?

I reported the initial bug to RH via bugzilla.

The problem is that the CentOS fix does not completely fix the issue - 
however works around one specific case.

The same race condition also applies for iptables rulesets that load 
kernel modules as the rules are inserted.

I don't believe this has been fixed by CentOS, or RH as yet.

This means any non-bog standard firewall could still cause a silent 
failure of firewall rules on boot.

-- 
Steven Haigh

? [log in to unmask]     ? http://www.crc.id.au
? +61 (3) 9001 6090    ? 0412 935 897

ATOM RSS1 RSS2