From: Adolf Belka Date: Wed, 20 Mar 2024 14:43:27 +0000 (+0100) Subject: CU185-update.sh: Add drop hostile in & out logging entries if not already present X-Git-Tag: v2.29-core185~32 X-Git-Url: http://git.ipfire.org/?a=commitdiff_plain;h=08b7500b267a54aa634fb34b67b4dfc0934ae2be;p=ipfire-2.x.git CU185-update.sh: Add drop hostile in & out logging entries if not already present - This patch ensures that those people who updated to CU184 before the CU184-update.sh patch fix to add the logging entries was added will get their optionsfw settings file correctly updated with CU185 - This only adds the LOGDROPHOSTILEIN & LOGDROPHOSTILEOUT entries if they do noit already exist in the optionsfw settings file. Tested-by: Adolf Belka Signed-off-by: Adolf Belka Signed-off-by: Michael Tremer --- diff --git a/config/rootfiles/core/185/update.sh b/config/rootfiles/core/185/update.sh index 2c95c41028..ec4d8ab82b 100644 --- a/config/rootfiles/core/185/update.sh +++ b/config/rootfiles/core/185/update.sh @@ -115,6 +115,15 @@ mv /var/ipfire/ovpn/ovpnconfig.new /var/ipfire/ovpn/ovpnconfig # Set correct ownership chown nobody:nobody /var/ipfire/ovpn/ovpnconfig +# Check if the drop hostile in and out logging options need to be added +# into the optionsfw settings file and apply to firewall +if ! [ $(grep "LOGDROPHOSTILEIN=on" /var/ipfire/optionsfw/settings) ] && \ + ! [ $(grep "LOGDROPHOSTILEOUT=on" /var/ipfire/optionsfw/settings) ]; then + sed -i '$ a\LOGDROPHOSTILEIN=on' /var/ipfire/optionsfw/settings + sed -i '$ a\LOGDROPHOSTILEOUT=on' /var/ipfire/optionsfw/settings + /usr/local/bin/firewallctrl +fi + # Rebuild initial ramdisks dracut --regenerate-all --force KVER="xxxKVERxxx"