Commit Graph

163 Commits

Author SHA256 Message Date
Dominique Leuenberger
467626e703 Accepting request 986626 from security:netfilter
OBS-URL: https://build.opensuse.org/request/show/986626
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/firewalld?expand=0&rev=68
2022-07-05 10:27:32 +00:00
Callum Farmer
949bf0320d Accepting request 986625 from home:gmbr3:Active
- Update to 1.2.0:
  * feat(firewalld): add new --log-target parameter
  * feat(service): add snmptls, snmptls-trap services
  * feat(service): add IPFS service
  * feat(fw): startup failsafe
  * feat(service): Add kubelet-readonly
  * feat(service): Add secure version of k8s controller-plane components
  * feat(bash): completion of policy-related commands
  * feat(service): add prometheus node-exporter
  * feat(service): add Kodi JSON-RPC and EventServer services

OBS-URL: https://build.opensuse.org/request/show/986625
OBS-URL: https://build.opensuse.org/package/show/security:netfilter/firewalld?expand=0&rev=125
2022-07-04 11:07:28 +00:00
Dominique Leuenberger
559714d645 Accepting request 984239 from security:netfilter
OBS-URL: https://build.opensuse.org/request/show/984239
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/firewalld?expand=0&rev=67
2022-06-24 06:45:08 +00:00
Callum Farmer
d3f927f0c8 Accepting request 984147 from home:schubi2
- Moved logrotate files from user specific directory /etc/logrotate.d
  to vendor specific directory /usr/etc/logrotate.d.

OBS-URL: https://build.opensuse.org/request/show/984147
OBS-URL: https://build.opensuse.org/package/show/security:netfilter/firewalld?expand=0&rev=124
2022-06-21 18:20:51 +00:00
Dominique Leuenberger
ea2c2ccba9 Accepting request 966068 from security:netfilter
OBS-URL: https://build.opensuse.org/request/show/966068
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/firewalld?expand=0&rev=66
2022-04-02 16:20:03 +00:00
Callum Farmer
09d5965ce8 Accepting request 966067 from home:gmbr3:Active
- Update to 1.1.1:
  * fix(build): oci: use centos:stream8 instead of ubi:8
  * fix(functions): --check-config fails if direct.xml exists
  * fix(build): oci: use dbus inside the container
  * docs(README): add note about container host integration
  * docs: typo fixes

OBS-URL: https://build.opensuse.org/request/show/966067
OBS-URL: https://build.opensuse.org/package/show/security:netfilter/firewalld?expand=0&rev=123
2022-03-30 17:10:59 +00:00
Dominique Leuenberger
3b54277ca5 Accepting request 964017 from security:netfilter
OBS-URL: https://build.opensuse.org/request/show/964017
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/firewalld?expand=0&rev=65
2022-03-24 21:56:57 +00:00
Michał Rostecki
de4b94d2a0 Accepting request 962711 from home:witekbedyk:branches:security:netfilter
- Provide dummy firewalld-prometheus-config package (bsc#1197042)

This is to prevent file conflicts between Firewalld and Prometheus packages in case Prometheus package is built on a different system than the target one (as it is the case for SUSE Manager).

OBS-URL: https://build.opensuse.org/request/show/962711
OBS-URL: https://build.opensuse.org/package/show/security:netfilter/firewalld?expand=0&rev=122
2022-03-22 16:26:21 +00:00
Dominique Leuenberger
d5bae943bc Accepting request 960423 from security:netfilter
OBS-URL: https://build.opensuse.org/request/show/960423
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/firewalld?expand=0&rev=64
2022-03-11 20:40:55 +00:00
Callum Farmer
ceb14b7b7e Accepting request 960050 from home:mwilck:modprobe.d
- Add code for safe modprobe.d migration
  (https://en.opensuse.org/openSUSE:Packaging_UsrEtc)
- Always own %_modprobedir (bsc#1196275, jsc#SLE-20639)

OBS-URL: https://build.opensuse.org/request/show/960050
OBS-URL: https://build.opensuse.org/package/show/security:netfilter/firewalld?expand=0&rev=121
2022-03-09 09:11:22 +00:00
Dominique Leuenberger
2629c8fc50 Accepting request 959443 from security:netfilter
OBS-URL: https://build.opensuse.org/request/show/959443
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/firewalld?expand=0&rev=63
2022-03-05 13:43:08 +00:00
Callum Farmer
b31285ff7d Accepting request 959442 from home:kukuk:container
- Fix modprobe.d directory for SLE15 SP3
- Cleanup dependencies:
  - ipset, ebtables and iptables are purely optional and deprecated, 
    so don't require them
  - sysconfig is not needed at all
  - Don't hard require systemd, we don't have and need that in containers

OBS-URL: https://build.opensuse.org/request/show/959442
OBS-URL: https://build.opensuse.org/package/show/security:netfilter/firewalld?expand=0&rev=120
2022-03-04 13:25:06 +00:00
Dominique Leuenberger
e306261337 Accepting request 957780 from security:netfilter
1.1.0

OBS-URL: https://build.opensuse.org/request/show/957780
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/firewalld?expand=0&rev=62
2022-02-27 21:42:48 +00:00
Callum Farmer
098c192bd5 Accepting request 957778 from home:gmbr3:Active
- Update to 1.1.0:
  * feat(service): Add jellyfin service
  * feat(policy): support OUTPUT forward ports
  * feat: config check improvements
  * feat(service): add http3
  * feat(service): add service definition for WS-Discovery Client
  * feat(service): add service definition for WS-Discovery
  * feat(service): add service definition for AFP
  * feat(rich): Support nflog target and add log attribute
    errors/checks
  * feat(service): add ZeroTier service

OBS-URL: https://build.opensuse.org/request/show/957778
OBS-URL: https://build.opensuse.org/package/show/security:netfilter/firewalld?expand=0&rev=119
2022-02-26 14:37:46 +00:00
Dominique Leuenberger
ace763cab4 Accepting request 946416 from security:netfilter
1.0.3

OBS-URL: https://build.opensuse.org/request/show/946416
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/firewalld?expand=0&rev=61
2022-01-15 20:45:08 +00:00
Callum Farmer
f92eed8643 Accepting request 946415 from home:gmbr3:Active
- Update to 1.0.3:
  * fix(io): _check_config() expects a dict
  * feat(build): distribute an OCI container image
  * fix(ipset): reduce cost of entry overlap detection

OBS-URL: https://build.opensuse.org/request/show/946415
OBS-URL: https://build.opensuse.org/package/show/security:netfilter/firewalld?expand=0&rev=118
2022-01-14 13:02:36 +00:00
Dominique Leuenberger
5200262b33 Accepting request 932170 from security:netfilter
- Update to 1.0.2:
  * fix(firewalld): check capng_apply() return code
  * fix(nftables): do not log icmp block if inversion
  * fix(nftables): rich: source address with netmask
  * fix(fw_config): zone: on rename remove then add
  * fix(io/functions): check_config against on disk conf
  * fix(zone): detect same source/interface in zones
  * docs(policy): fix typos
  * docs(policies): fix typos (forwarded request 932169 from mrostecki)

OBS-URL: https://build.opensuse.org/request/show/932170
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/firewalld?expand=0&rev=60
2021-11-20 21:47:48 +00:00
Michał Rostecki
e6ddad9a48 Accepting request 932169 from home:mrostecki:branches:security:netfilter
- Update to 1.0.2:
  * fix(firewalld): check capng_apply() return code
  * fix(nftables): do not log icmp block if inversion
  * fix(nftables): rich: source address with netmask
  * fix(fw_config): zone: on rename remove then add
  * fix(io/functions): check_config against on disk conf
  * fix(zone): detect same source/interface in zones
  * docs(policy): fix typos
  * docs(policies): fix typos

OBS-URL: https://build.opensuse.org/request/show/932169
OBS-URL: https://build.opensuse.org/package/show/security:netfilter/firewalld?expand=0&rev=117
2021-11-18 10:10:37 +00:00
Dominique Leuenberger
e5d2d63627 Accepting request 924225 from security:netfilter
OBS-URL: https://build.opensuse.org/request/show/924225
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/firewalld?expand=0&rev=59
2021-10-11 14:48:44 +00:00
Michał Rostecki
6c5a600340 Accepting request 921449 from home:gmbr3:Active
- Update to 1.0.1:
  * keep linux capability CAP_SYS_MODULE
  * UPnP Client: actually allow SSDP traffic
  * Fix RPM macros to test if firewall-cmd is executable

OBS-URL: https://build.opensuse.org/request/show/921449
OBS-URL: https://build.opensuse.org/package/show/security:netfilter/firewalld?expand=0&rev=116
2021-10-08 13:20:47 +00:00
Richard Brown
4a1aeb23a7 Accepting request 911378 from security:netfilter
OBS-URL: https://build.opensuse.org/request/show/911378
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/firewalld?expand=0&rev=58
2021-08-16 08:08:46 +00:00
Michał Rostecki
aa08f2b535 Accepting request 910605 from home:gmbr3:Active
- Update to 1.0.0:
  * Reduced dependencies
  * Intra-zone forwarding by default
  * NAT rules moved to inet family (reduced rule set)
  * Default target is now similar to reject
  * ICMP blocks and block inversion only apply to input,
    not forward
  * tftp-client service has been removed
  * iptables backend is deprecated
  * Direct interface is deprecated
  * CleanupModulesOnExit defaults to no
    (kernel modules not unloaded)
- Add new firewalld-test package
- Move bash and zsh completions to more useful separate packages
- Clean spec file
- Move modprobe.d and autostart files out of /etc

OBS-URL: https://build.opensuse.org/request/show/910605
OBS-URL: https://build.opensuse.org/package/show/security:netfilter/firewalld?expand=0&rev=115
2021-08-11 07:56:26 +00:00
Richard Brown
d17e057975 Accepting request 883555 from security:netfilter
- Remove dependency on firewalld from firewall-macros (bsc#1183404) (forwarded request 883554 from mrostecki)

OBS-URL: https://build.opensuse.org/request/show/883555
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/firewalld?expand=0&rev=57
2021-04-10 13:26:30 +00:00
Michał Rostecki
491b7af7c8 Accepting request 883554 from home:mrostecki:branches:security:netfilter
- Remove dependency on firewalld from firewall-macros (bsc#1183404)

OBS-URL: https://build.opensuse.org/request/show/883554
OBS-URL: https://build.opensuse.org/package/show/security:netfilter/firewalld?expand=0&rev=114
2021-04-07 09:26:19 +00:00
Dominique Leuenberger
97d4bd875a Accepting request 873150 from security:netfilter
Preserve the reference to jsc#SLE-12281 in the old update to 0.7.5 (forwarded request 873148 from mrostecki)

OBS-URL: https://build.opensuse.org/request/show/873150
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/firewalld?expand=0&rev=56
2021-02-17 17:09:37 +00:00
Michał Rostecki
86a24bbf7f Accepting request 873148 from home:mrostecki:branches:security:netfilter
Preserve the reference to jsc#SLE-12281 in the old update to 0.7.5

OBS-URL: https://build.opensuse.org/request/show/873148
OBS-URL: https://build.opensuse.org/package/show/security:netfilter/firewalld?expand=0&rev=113
2021-02-17 14:03:36 +00:00
Dominique Leuenberger
9d471d09b3 Accepting request 866985 from security:netfilter
- Update to 0.9.3 (jsc#SLE-17336):
  nftables (jsc#SLE-16300):
  (rhbz#1817022, jsc#SLE-16300) (forwarded request 866984 from mrostecki)

OBS-URL: https://build.opensuse.org/request/show/866985
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/firewalld?expand=0&rev=55
2021-02-01 12:25:19 +00:00
Michał Rostecki
a50f2805cc Accepting request 866984 from home:mrostecki:branches:security:netfilter
- Update to 0.9.3 (jsc#SLE-17336):
  nftables (jsc#SLE-16300):
  (rhbz#1817022, jsc#SLE-16300)

OBS-URL: https://build.opensuse.org/request/show/866984
OBS-URL: https://build.opensuse.org/package/show/security:netfilter/firewalld?expand=0&rev=112
2021-01-26 17:59:52 +00:00
Michał Rostecki
7dc08b4e6b Accepting request 866974 from home:mrostecki:branches:security:netfilter
- Update to 0.9.3 (SLE-17336):
  nftables (SLE-16300):
  (rhbz#1817022, SLE-16300)

OBS-URL: https://build.opensuse.org/request/show/866974
OBS-URL: https://build.opensuse.org/package/show/security:netfilter/firewalld?expand=0&rev=111
2021-01-26 17:13:46 +00:00
Michał Rostecki
93ac3ead82 Accepting request 866966 from home:mrostecki:branches:security:netfilter
- Disable FlushAllOnReload option to not retain interface to zone
  assignments and direct rules when using --reload option.
  * 0002-Disable-FlushAllOnReload-option.patch

OBS-URL: https://build.opensuse.org/request/show/866966
OBS-URL: https://build.opensuse.org/package/show/security:netfilter/firewalld?expand=0&rev=110
2021-01-26 16:36:13 +00:00
Michał Rostecki
3c89112cb1 Accepting request 866564 from home:mrostecki:branches:security:netfilter
- Update to 0.9.3:
  * docs(dbus): fix invalid method names
  * fix(forward): iptables: ipset used as zone source
  * fix(rich): non-printable characters removed from rich rules
  * docs(firewall-cmd): small description grammar fix
  * fix(rich): limit table to strip non-printables to C0 and C1
  * fix(zone): add source with mac address

OBS-URL: https://build.opensuse.org/request/show/866564
OBS-URL: https://build.opensuse.org/package/show/security:netfilter/firewalld?expand=0&rev=109
2021-01-25 11:43:27 +00:00
Dominique Leuenberger
0a323e9ee8 Accepting request 863088 from security:netfilter
OBS-URL: https://build.opensuse.org/request/show/863088
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/firewalld?expand=0&rev=54
2021-01-18 10:27:30 +00:00
Michał Rostecki
6108127596 Accepting request 863051 from home:rfrohl:branches:security:netfilter
add missing dependency for firewall-offline-cmd

OBS-URL: https://build.opensuse.org/request/show/863051
OBS-URL: https://build.opensuse.org/package/show/security:netfilter/firewalld?expand=0&rev=108
2021-01-14 13:23:51 +00:00
Dominique Leuenberger
fda4feede4 Accepting request 853450 from security:netfilter
- Remove the patch which enforces usage of iptables instead of
  nftables:
  * 0001-firewall-backend-Switch-default-backend-to-iptables.patch
- Add firewalld zone for the docker0 interface. This is the
  workaround for lack of nftables support in docker. Without that
  additional zone, containers have no Internet connectivity.
  (rhbz#1817022)
- Update to 0.9.1:
  * Bugfixes:
    * docs(firewall-cmd): clarify lockdown whitelist command paths
    * fix(dbus): getActivePolicies shouldn't return a policy if a zone is not active
    * fix(policy): zone interface/source changes should affect all using zone

OBS-URL: https://build.opensuse.org/request/show/853450
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/firewalld?expand=0&rev=53
2020-12-09 21:11:01 +00:00
Dominique Leuenberger
20c8db02de https://bugzilla.opensuse.org/show_bug.cgi?id=1178801
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/firewalld?expand=0&rev=52
2020-11-14 17:22:52 +00:00
Dominique Leuenberger
1c671ba1b4 Accepting request 847328 from security:netfilter
- Remove the patch which enforces usage of iptables instead of
  nftables:
  * 0001-firewall-backend-Switch-default-backend-to-iptables.patch
- Add firewalld zone for the docker0 interface. This is the
  workaround for lack of nftables support in docker. Without that
  additional zone, containers have no Internet connectivity.
  (rhbz#1817022)
- Update to 0.9.1:
  * Bugfixes:
    * docs(firewall-cmd): clarify lockdown whitelist command paths
    * fix(dbus): getActivePolicies shouldn't return a policy if a zone is not active
    * fix(policy): zone interface/source changes should affect all using zone (forwarded request 847325 from mrostecki)

OBS-URL: https://build.opensuse.org/request/show/847328
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/firewalld?expand=0&rev=51
2020-11-13 17:53:00 +00:00
Michał Rostecki
e87c42cb75 Accepting request 847325 from home:mrostecki:branches:security:netfilter
- Remove the patch which enforces usage of iptables instead of
  nftables:
  * 0001-firewall-backend-Switch-default-backend-to-iptables.patch
- Add firewalld zone for the docker0 interface. This is the
  workaround for lack of nftables support in docker. Without that
  additional zone, containers have no Internet connectivity.
  (rhbz#1817022)
- Update to 0.9.1:
  * Bugfixes:
    * docs(firewall-cmd): clarify lockdown whitelist command paths
    * fix(dbus): getActivePolicies shouldn't return a policy if a zone is not active
    * fix(policy): zone interface/source changes should affect all using zone

OBS-URL: https://build.opensuse.org/request/show/847325
OBS-URL: https://build.opensuse.org/package/show/security:netfilter/firewalld?expand=0&rev=107
2020-11-09 17:48:32 +00:00
Dominique Leuenberger
1e3872aa2b Accepting request 836462 from security:netfilter
OBS-URL: https://build.opensuse.org/request/show/836462
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/firewalld?expand=0&rev=50
2020-10-03 16:55:28 +00:00
Robert Frohl
0dea11c5eb Accepting request 835127 from home:fbui:branches:security:netfilter
- Make use of %service_del_postun_without_restart
  And stop using DISABLE_RESTART_ON_UPDATE as this interface is
  obsolete.

OBS-URL: https://build.opensuse.org/request/show/835127
OBS-URL: https://build.opensuse.org/package/show/security:netfilter/firewalld?expand=0&rev=106
2020-09-24 08:08:44 +00:00
Dominique Leuenberger
af98866ead Accepting request 833252 from security:netfilter
- Add python3-nftables as a requirement. (forwarded request 833251 from mrostecki)

OBS-URL: https://build.opensuse.org/request/show/833252
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/firewalld?expand=0&rev=49
2020-09-21 15:07:15 +00:00
Michał Rostecki
dda7c66e07 Accepting request 833251 from home:mrostecki:branches:security:netfilter
- Add python3-nftables as a requirement.

OBS-URL: https://build.opensuse.org/request/show/833251
OBS-URL: https://build.opensuse.org/package/show/security:netfilter/firewalld?expand=0&rev=105
2020-09-09 14:50:16 +00:00
Michał Rostecki
469df4f998 Accepting request 832520 from home:gmbr3:Active
- update to 0.9.0:
  * New major features
    * prevention of Zone Drifting
    * Intra Zone Forwarding
    * Policy Objects
  * For a full list of changes, see
    https://github.com/firewalld/firewalld/compare/v0.8.0...v0.9.0

OBS-URL: https://build.opensuse.org/request/show/832520
OBS-URL: https://build.opensuse.org/package/show/security:netfilter/firewalld?expand=0&rev=104
2020-09-07 12:44:19 +00:00
Michał Rostecki
d6d990908d Accepting request 827072 from home:dirkmueller:branches:security:netfilter
- update to 0.8.3:
  * nftables: convert to libnftables JSON interface
  * service: new “helper” element to replace “module” More accurately represents the conntrack helper. Deprecates “module”.
  * allow custom helpers using standard helper modules (rhbz 1733066)
  * testsuite is now shipped in the dist tarball
  * Typo in firewall-config(1)
  * Fix typo in TFTP service description
  * doc: README: add note about language translations
  * fix: rich: source/dest only matching with mark action
  * feat: AllowZoneDrifting config option
  * feat: nftables: support AllowZoneDrifting=yes
  * feat: ipXtables: support AllowZoneDrifting=yes
  * fix: firewall-offline-cmd: Don’t print warning about AllowZoneDrifting
  * fix: add logrotate policy
  * doc: direct: add CAVEATS section
  * fix: checkIP6: strip leading/trailing square brackets
  * fix: nftables: remove square brackets from IPv6 addresses
  * fix: ipXtables: remove square brackets from IPv6 addresses
  * fix: nftables: ipset types using “port”
  * fix: nftables: zone dispatch with multidimensional ipsets
  * fix: ipset: destroy runtime sets on reload/stop
  * fix: port: support querying sub ranges
  * fix: source_port: support querying sub ranges
  * doc: specify accepted characters for object names
  * fix: doc: address copy/paste mistakes in short/description
  * fix: configure: atlocal: quote variable values
  * fix: nftables: allow set intervals with concatenations
  * doc: clarify –set-target values “default” vs “reject”
  * fix: update dynamic DCE RPC ports in freeipa-trust service
  * fix: nftables: ipset: port ranges for non-default protocols

OBS-URL: https://build.opensuse.org/request/show/827072
OBS-URL: https://build.opensuse.org/package/show/security:netfilter/firewalld?expand=0&rev=103
2020-08-17 07:45:59 +00:00
Dominique Leuenberger
1d3f684259 Accepting request 826047 from security:netfilter
- Update to version 0.7.5:
  * release: v0.7.5
  * chore(translation): merge from master
  * fix(cli): add ipset type hash:mac is incompatible with the family parameter Fixes: rhbz1541077
  * test(rhbz1483921): better test name
  * fix(cli): add --zone is an invalid option with --direct
  * fix: core: rich: Catch ValueError on non-numeric priority values
  * fix: update dynamic DCE RPC ports in freeipa-trust service
  * docs: replace occurrences of the term blacklist with denylist
  * docs(README): add libxslt for doc generation
  * test(rich): source mac with nftables backend
  * fix(firewall-offline-cmd): remove instances of "[P]" in help text
  * test(check-container): add support for centos8 stream
  * test(functions): use IndividualCalls if host doesn't support nft rule index
  * test(functions): add macro IF_HOST_SUPPORTS_NFT_RULE_INDEX
  * test(dbus): better way to check IPv6_rpfilter expected value
  * fix(ipset): flush the set if IndividiualCalls=yes
  * test(ipv6): skip square bracket address tests if ipv6 not available
  * test(gh509): only run test for nftables backend
  * fix(dbus): service: don't cleanup config for old set APIs
  * fix(config): bool values in dict based import/export
  * fix(doc): dbus: signatures for zone tuple based APIs
  * test(dbus): zone: fix zone runtime functional test title
  * test(dbus): zone: fix false failure due to list order
  * fix(client): addService needs to reduce tuple size
  * test(direct): rule in a zone chain
  * fix(direct): rule in a zone chain
  * test(dbus): zone: verify runtime config APIs
  * test(dbus): zone: verify permanent config APIs
  * fix(systemd): Conflict with nftables.service (forwarded request 826046 from mrostecki)

OBS-URL: https://build.opensuse.org/request/show/826047
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/firewalld?expand=0&rev=48
2020-08-14 07:32:13 +00:00
Michał Rostecki
20a544565d Accepting request 826046 from home:mrostecki:branches:security:netfilter
- Update to version 0.7.5:
  * release: v0.7.5
  * chore(translation): merge from master
  * fix(cli): add ipset type hash:mac is incompatible with the family parameter Fixes: rhbz1541077
  * test(rhbz1483921): better test name
  * fix(cli): add --zone is an invalid option with --direct
  * fix: core: rich: Catch ValueError on non-numeric priority values
  * fix: update dynamic DCE RPC ports in freeipa-trust service
  * docs: replace occurrences of the term blacklist with denylist
  * docs(README): add libxslt for doc generation
  * test(rich): source mac with nftables backend
  * fix(firewall-offline-cmd): remove instances of "[P]" in help text
  * test(check-container): add support for centos8 stream
  * test(functions): use IndividualCalls if host doesn't support nft rule index
  * test(functions): add macro IF_HOST_SUPPORTS_NFT_RULE_INDEX
  * test(dbus): better way to check IPv6_rpfilter expected value
  * fix(ipset): flush the set if IndividiualCalls=yes
  * test(ipv6): skip square bracket address tests if ipv6 not available
  * test(gh509): only run test for nftables backend
  * fix(dbus): service: don't cleanup config for old set APIs
  * fix(config): bool values in dict based import/export
  * fix(doc): dbus: signatures for zone tuple based APIs
  * test(dbus): zone: fix zone runtime functional test title
  * test(dbus): zone: fix false failure due to list order
  * fix(client): addService needs to reduce tuple size
  * test(direct): rule in a zone chain
  * fix(direct): rule in a zone chain
  * test(dbus): zone: verify runtime config APIs
  * test(dbus): zone: verify permanent config APIs
  * fix(systemd): Conflict with nftables.service

OBS-URL: https://build.opensuse.org/request/show/826046
OBS-URL: https://build.opensuse.org/package/show/security:netfilter/firewalld?expand=0&rev=102
2020-08-12 14:05:48 +00:00
Dominique Leuenberger
81b0a1089e Accepting request 791192 from security:netfilter
OBS-URL: https://build.opensuse.org/request/show/791192
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/firewalld?expand=0&rev=47
2020-04-05 18:49:51 +00:00
Michał Rostecki
ac3eadc775 Accepting request 791189 from home:lemmy04:branches:security:netfilter
- Update to 0.7.4
This is a bug fix only release.
However, it does reintroduce the zone drifting bug as a feature. See #258 and #441. This behavior is disabled by default.
  * improvement: build: add an option to disable building documentation
  * Typo in firewall-config(1)
  * Fix typo in TFTP service description
  * doc: README: add note about language translations
  * fix: rich: source/dest only matching with mark action
  * feat: AllowZoneDrifting config option
  * feat: nftables: support AllowZoneDrifting=yes
  * feat: ipXtables: support AllowZoneDrifting=yes
  * fix: firewall-offline-cmd: Don't print warning about AllowZoneDrifting
  * fix: add logrotate policy
  * fix: tests: regenerate testsuite if .../{cli,python}/*.at changes
  * doc: direct: add CAVEATS section
  * fix: checkIP6: strip leading/trailing square brackets
  * fix: nftables: remove square brackets from IPv6 addresses
  * fix: ipXtables: remove square brackets from IPv6 addresses
  * fix: nftables: zone dispatch with multidimensional ipsets
  * fix: ipset: destroy runtime sets on reload/stop
  * fix: port: support querying sub ranges
  * fix: source_port: support querying sub ranges
  * doc: specify accepted characters for object names
  * fix: doc: address copy/paste mistakes in short/description
  * fix: configure: atlocal: quote variable values
  * fix: nftables: allow set intervals with concatenations
  * doc: clarify --set-target values "default" vs "reject"

OBS-URL: https://build.opensuse.org/request/show/791189
OBS-URL: https://build.opensuse.org/package/show/security:netfilter/firewalld?expand=0&rev=101
2020-04-03 12:30:54 +00:00
Dominique Leuenberger
dc584aa1be Accepting request 783096 from security:netfilter
OBS-URL: https://build.opensuse.org/request/show/783096
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/firewalld?expand=0&rev=46
2020-03-12 21:57:56 +00:00
Michał Rostecki
862debfa2f Accepting request 783084 from home:frispete:Tumbleweed
- Update to version 0.7.3:
  * release: v0.7.3
  * chore: update translations
  * doc: README: add note about integration tests
  * test: check-container: also run check-integration
  * test: integration: NM zone overrides interface on reload
  * test: build: support integration tests
  * test: functions: add macro NMCLI_CHECK
  * test: functions: new macros for starting/stopping NetworkManager
  * fix: test: leave "cleanup" for tests cases
  * test: check-container: add support for fedora rawhide
  * test: check-container: add support for debian sid
  * test: build: add support for running in containers
  * fix: test/functions: FWD_END_TEST: improve grep for errors/warnings
  * fix: test: direct passthrough: no need to check for dummy module
  * fix: test: CHECK_NAT_COEXISTENCE: only check for kernel version
  * fix: reload: let NM interface assignments override permanent config
  * chore: tests: rename IF_IPV6_SUPPORTED to IF_HOST_SUPPORTS_IPV6_RULES
  * fix: tests: convert host ipv6 checks to runtime
  * fix: tests: convert ip6tables checks to runtime
  * fix: tests: convert probe of nft numeric args to runtime
  * fix: tests: convert nftables fib checks to runtime
  * fix: build: distribute testsuite
  * fix: don't probe for available kernel modules
  * fix: failure to load modules no longer fatal
  * fix: tests/functions: canonicalize XML output
  * chore: doc: update authors
  * fix: test: use debug output based on autotest variable
  * fix: src/tests/Makefile: distclean should clean atconfig

OBS-URL: https://build.opensuse.org/request/show/783084
OBS-URL: https://build.opensuse.org/package/show/security:netfilter/firewalld?expand=0&rev=100
2020-03-09 20:49:58 +00:00
Dominique Leuenberger
475280027a Accepting request 781833 from security:netfilter
OBS-URL: https://build.opensuse.org/request/show/781833
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/firewalld?expand=0&rev=45
2020-03-08 21:23:43 +00:00