all lists on lists.proxmox.com
 help / color / mirror / Atom feed
From: Arthur Bied-Charreton <a.bied-charreton@proxmox.com>
To: pve-devel@lists.proxmox.com
Subject: [PATCH proxmox-firewall v2 12/12] fix #5759: firewall: restore from dumped config before network-pre
Date: Thu,  1 Oct 2026 14:26:25 +0200	[thread overview]
Message-ID: <20261001122625.348730-13-a.bied-charreton@proxmox.com> (raw)
In-Reply-To: <20261001122625.348730-1-a.bied-charreton@proxmox.com>

proxmox-firewall depends on pve-cluster, pve-cluster depends on
corosync, which itself depends on network-online. This creates a
boot-time window where the network is up on the PVE host without it
having any firewall protection.

To address this, add a simple oneshot service depending on
network-pre [0] that applies the last remembered rules to bridge the
gap until the configured firewall daemon takes over.

[0] https://systemd.io/NETWORK_ONLINE/

Link: https://bugzilla.proxmox.com/show_bug.cgi?id=5759
Signed-off-by: Arthur Bied-Charreton <a.bied-charreton@proxmox.com>
Reviewed-by: Thomas Ellmenreich <t.ellmenreich@proxmox.com>
Tested-by: Thomas Ellmenreich <t.ellmenreich@proxmox.com>
---
 debian/proxmox-firewall-pre-network.service | 16 ++++++++++++++++
 debian/rules                                |  2 +-
 2 files changed, 17 insertions(+), 1 deletion(-)
 create mode 100644 debian/proxmox-firewall-pre-network.service

diff --git a/debian/proxmox-firewall-pre-network.service b/debian/proxmox-firewall-pre-network.service
new file mode 100644
index 0000000..83c686f
--- /dev/null
+++ b/debian/proxmox-firewall-pre-network.service
@@ -0,0 +1,16 @@
+[Unit]
+Description=Proxmox VE Pre-Network NFT Firewall
+Wants=network-pre.target
+Before=network-pre.target shutdown.target
+Conflicts=shutdown.target
+DefaultDependencies=no
+After=local-fs.target
+
+[Service]
+Type=oneshot
+ExecStart=/usr/libexec/proxmox/proxmox-firewall restore
+RemainAfterExit=true
+Environment=PVE_LOG=info
+
+[Install]
+WantedBy=sysinit.target
diff --git a/debian/rules b/debian/rules
index 0dc4e0f..99a6797 100755
--- a/debian/rules
+++ b/debian/rules
@@ -28,4 +28,4 @@ override_dh_auto_configure:
 
 override_dh_installsystemd:
 	dh_installsystemd proxmox-firewall.service
-
+	dh_installsystemd --no-start --name proxmox-firewall-pre-network proxmox-firewall-pre-network.service
-- 
2.47.3





      parent reply	other threads:[~2026-10-01 12:27 UTC|newest]

Thread overview: 13+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-10-01 12:26 [RFC firewall/manager/proxmox{,-firewall} v2 00/12] fix #5759: keep firewall rules up across boot and shutdown Arthur Bied-Charreton
2026-10-01 12:26 ` [PATCH pve-manager v2 01/12] network interface pinning: write new firewall config to local dir Arthur Bied-Charreton
2026-10-01 12:26 ` [PATCH pve-firewall v2 02/12] firewall: config: sort OPTIONS when serializing Arthur Bied-Charreton
2026-10-01 12:26 ` [PATCH pve-firewall v2 03/12] firewall: dump configs locally after applying Arthur Bied-Charreton
2026-10-01 12:26 ` [PATCH pve-firewall v2 04/12] fix #5759: firewall: do not remove chains when host is shutting down Arthur Bied-Charreton
2026-10-01 12:26 ` [PATCH pve-firewall v2 05/12] firewall: add restore command Arthur Bied-Charreton
2026-10-01 12:26 ` [PATCH pve-firewall v2 06/12] fix #5759: firewall: restore from dumped config before network-pre Arthur Bied-Charreton
2026-10-01 12:26 ` [PATCH proxmox v2 07/12] systemd: systemctl: add is-system-running helper Arthur Bied-Charreton
2026-10-01 12:26 ` [PATCH proxmox-firewall v2 08/12] firewall: fix clippy warnings Arthur Bied-Charreton
2026-10-01 12:26 ` [PATCH proxmox-firewall v2 09/12] fix #5759: firewall: do not clear rules on system shutdown Arthur Bied-Charreton
2026-10-01 12:26 ` [PATCH proxmox-firewall v2 10/12] firewall: dump config to local directory after apply Arthur Bied-Charreton
2026-10-01 12:26 ` [PATCH proxmox-firewall v2 11/12] firewall: add restore command Arthur Bied-Charreton
2026-10-01 12:26 ` Arthur Bied-Charreton [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20261001122625.348730-13-a.bied-charreton@proxmox.com \
    --to=a.bied-charreton@proxmox.com \
    --cc=pve-devel@lists.proxmox.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.
Service provided by Proxmox Server Solutions GmbH | Privacy | Legal