all lists on lists.proxmox.com
 help / color / mirror / Atom feed
From: "Thomas Ellmenreich" <t.ellmenreich@proxmox.com>
To: "Arthur Bied-Charreton" <a.bied-charreton@proxmox.com>,
	<pve-devel@lists.proxmox.com>
Subject: Re: [RFC firewall/manager/proxmox{,-firewall} 00/13] fix #5759: keep firewall rules up across boot and shutdown
Date: Fri, 11 Sep 2026 14:26:02 +0200	[thread overview]
Message-ID: <DLCHHY8WE2ZK.21BR9ECG8CK1K@proxmox.com> (raw)
In-Reply-To: <20260721135407.372150-1-a.bied-charreton@proxmox.com>

The approach seems reasonable to me, especially since it was discussed aready
on the bugzilla: [1].

I tested the patches by first disallowing ICMP on the firewall and then
simply rebooting the node while pinging it at the same time. Without the
patches this lead to short periods during shutdown and startup where the
pings got through. With the patches on the other hand, no single ping
was able to reach the node.

On Tue Jul 21, 2026 at 3:53 PM CEST, Arthur Bied-Charreton wrote:

[snip]

> 1. Boot-time firewall config overrides:
>
> I'm honestly not sure if the .override hack is the right design.
> host.fw.override may drift away from the config after network interface
> pinning changes. This can/will be fixed if we decide to go with this
> approach, but I am not sure how I feel about overwriting a config file
> manually edited by users.

I agree that the configs going out of sync will be an annoying issue for users.
But would creating a UI for this be so much work? Technically, a simple
checkbox indicating which file is being written to would be enough. (Not that
that would be great UX, but it would work). Although, as Arthur mentioned off
list, this would require changing all endpoints.

All of that said I was still questioning whether this feature is even
necessary, but after going through this [1] Bugzilla thread it seems that the
conclusion is that it is necessary.

[snip]

[1]: https://bugzilla.proxmox.com/show_bug.cgi?id=5759

Reviewed-by: Thomas Ellmenreich <t.ellmenreich@proxmox.com>
Tested-by: Thomas Ellmenreich <t.ellmenreich@proxmox.com>




      parent reply	other threads:[~2026-09-11 12:26 UTC|newest]

Thread overview: 20+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-07-21 13:53 [RFC firewall/manager/proxmox{,-firewall} 00/13] fix #5759: keep firewall rules up across boot and shutdown Arthur Bied-Charreton
2026-07-21 13:53 ` [PATCH pve-manager 01/13] network interface pinning: write new firewall config to local dir Arthur Bied-Charreton
2026-07-21 13:53 ` [PATCH pve-firewall 02/13] firewall: config: sort OPTIONS when serializing Arthur Bied-Charreton
2026-07-21 13:53 ` [PATCH pve-firewall 03/13] d/control: bump libpve-common-perl Arthur Bied-Charreton
2026-07-21 13:53 ` [PATCH pve-firewall 04/13] firewall: dump configs locally after applying Arthur Bied-Charreton
2026-07-21 13:53 ` [PATCH pve-firewall 05/13] fix #5759: firewall: do not remove chains when host is shutting down Arthur Bied-Charreton
2026-07-21 13:54 ` [PATCH pve-firewall 06/13] firewall: add restore command Arthur Bied-Charreton
2026-07-21 13:54 ` [PATCH pve-firewall 07/13] fix #5759: firewall: restore from dumped config before network-pre Arthur Bied-Charreton
2026-07-21 13:54 ` [PATCH proxmox 08/13] systemd: systemctl: add is-system-running helper Arthur Bied-Charreton
2026-07-21 13:54 ` [PATCH proxmox-firewall 09/13] firewall: fix clippy warnings Arthur Bied-Charreton
2026-07-21 13:54 ` [PATCH proxmox-firewall 10/13] fix #5759: firewall: do not clear rules on system shutdown Arthur Bied-Charreton
2026-07-21 13:54 ` [PATCH proxmox-firewall 11/13] firewall: dump config to local directory after apply Arthur Bied-Charreton
2026-09-11  9:10   ` Thomas Ellmenreich
2026-09-11  9:28     ` Arthur Bied-Charreton
2026-07-21 13:54 ` [PATCH proxmox-firewall 12/13] firewall: add restore command Arthur Bied-Charreton
2026-09-11  9:14   ` Thomas Ellmenreich
2026-09-11  9:37     ` Arthur Bied-Charreton
2026-09-11  9:54       ` Arthur Bied-Charreton
2026-07-21 13:54 ` [PATCH proxmox-firewall 13/13] fix #5759: firewall: restore from dumped config before network-pre Arthur Bied-Charreton
2026-09-11 12:26 ` Thomas Ellmenreich [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=DLCHHY8WE2ZK.21BR9ECG8CK1K@proxmox.com \
    --to=t.ellmenreich@proxmox.com \
    --cc=a.bied-charreton@proxmox.com \
    --cc=pve-devel@lists.proxmox.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.
Service provided by Proxmox Server Solutions GmbH | Privacy | Legal