net-firewall/nftables: Update support & service files
authorNicholas Vinson <nvinson234@gmail.com>
Sat, 4 Jun 2016 23:41:47 +0000 (16:41 -0700)
committerGöktürk Yüksek <gokturk@gentoo.org>
Sun, 3 Jul 2016 22:00:24 +0000 (18:00 -0400)
    - remove extraneous "exit $?" from files/libexec/nftables.sh
    - rename nftables.init-r2 to nftables.init
    - recreate & rewrite files/systemd/nftables.service into a proper systemd service
    - Update nftables-0.6.ebuild to use new file names.

Package-Manager: portage-2.3.0_rc1

net-firewall/nftables/files/libexec/nftables.sh
net-firewall/nftables/files/nftables.init [moved from net-firewall/nftables/files/nftables.init-r2 with 97% similarity]
net-firewall/nftables/files/systemd/nftables-restore.service [new file with mode: 0644]
net-firewall/nftables/nftables-0.6-r1.ebuild [moved from net-firewall/nftables/nftables-0.6.ebuild with 64% similarity]

index 2d8c9f04d69da407cf26875fe22f657b0545035b..f720b9bfc514f24f33ea637d767b292d0a17e88b 100755 (executable)
@@ -147,4 +147,3 @@ deletetable() {
 }
 
 main "$@"
-exit $?
similarity index 97%
rename from net-firewall/nftables/files/nftables.init-r2
rename to net-firewall/nftables/files/nftables.init
index 5a59fbc003876531f7bd49caab01707f78a571b7..217251e41db49ecdf3bdfa90485a8a67340ef699 100644 (file)
@@ -1,6 +1,6 @@
 #!/sbin/openrc-run
-# Copyright 2014 Nicholas Vinson
-# Copyright 1999-2014 Gentoo Foundation
+# Copyright 2014-2016 Nicholas Vinson
+# Copyright 1999-2016 Gentoo Foundation
 # Distributed under the terms of the GNU General Public License v2
 
 extra_commands="clear list panic save"
diff --git a/net-firewall/nftables/files/systemd/nftables-restore.service b/net-firewall/nftables/files/systemd/nftables-restore.service
new file mode 100644 (file)
index 0000000..61eaee2
--- /dev/null
@@ -0,0 +1,14 @@
+[Unit]
+Description=Store and restore nftables firewall rules
+ConditionPathExists=/var/lib/nftables-rules-save
+Before=network.target
+Before=shutdown.target
+
+[Service]
+Type=oneshot
+RemainAfterExit=yes
+ExecStart=/usr/libexec/nftables/nftables.sh load /var/lib/nftables/rules-save
+ExecStop=/usr/libexec/nftables/nftables.sh store /var/lib/nftables/rules-save
+
+[Install]
+WantedBy=basic.target
similarity index 64%
rename from net-firewall/nftables/nftables-0.6.ebuild
rename to net-firewall/nftables/nftables-0.6-r1.ebuild
index d97df4d2716f1feaeb4d4a6c24a77f9302dabeac..550c6da95816cbce9f67403fe5315c205dd29291 100644 (file)
@@ -57,12 +57,28 @@ src_install() {
        default
 
        dodir /usr/libexec/${PN}
-       insinto /usr/libexec/${PN}
-       doins /usr/libexec/${PN}/${PN}.sh
+       exeinto /usr/libexec/${PN}
+       doexe "${FILESDIR}"/libexec/${PN}.sh
 
        newconfd "${FILESDIR}"/${PN}.confd ${PN}
-       newinitd "${FILESDIR}"/${PN}.init-r2 ${PN}
+       newinitd "${FILESDIR}"/${PN}.init ${PN}
        keepdir /var/lib/nftables
 
-       systemd_dounit "${FILESDIR}"/systemd/${PN}{,-{re,}store}.service
+       systemd_dounit "${FILESDIR}"/systemd/${PN}-restore.service
+       systemd_enable_service basic.target ${PN}-restore.service
+}
+
+pkg_postinst() {
+       local save_file
+       save_file="${EROOT}var/lib/nftables/rules-save"
+
+       elog "In order for the nftables-restore systemd service to start, "
+       elog "the file, ${save_file}, must exist.  To create this "
+       elog "file run the following command: "
+       elog ""
+       elog "  touch '${save_file}'"
+       elog ""
+       elog "Afterwards, the nftables-restore service should be manually started "
+       elog "to ensure firewall changes are stored on system shutdown.  The "
+       elog "systemd service will function normally thereafter."
 }