net-firewall/nftables: Create systemd unit files
authorNicholas Vinson <nvinson234@gmail.com>
Tue, 3 Nov 2015 06:07:43 +0000 (01:07 -0500)
committerNicholas Vinson <nvinson234@gmail.com>
Tue, 3 Nov 2015 06:11:27 +0000 (01:11 -0500)
Package-Manager: portage-2.2.23

net-firewall/nftables/files/systemd/nftables-restore.service [new file with mode: 0644]
net-firewall/nftables/files/systemd/nftables-store.service [new file with mode: 0644]
net-firewall/nftables/files/systemd/nftables.service [new file with mode: 0644]

diff --git a/net-firewall/nftables/files/systemd/nftables-restore.service b/net-firewall/nftables/files/systemd/nftables-restore.service
new file mode 100644 (file)
index 0000000..7a7eacf
--- /dev/null
@@ -0,0 +1,14 @@
+[Unit]
+Description=Restore nftables firewall rules
+# if both are queued for some reason, don't store before restoring :)
+Before=nftables-store.service
+# sounds reasonable to have firewall up before any of the services go up
+Before=network.target
+Conflicts=shutdown.target
+
+[Service]
+Type=oneshot
+ExecStart=/usr/libexec/nftables/nftables.sh load /var/lib/nftables/rules-save
+
+[Install]
+WantedBy=basic.target
diff --git a/net-firewall/nftables/files/systemd/nftables-store.service b/net-firewall/nftables/files/systemd/nftables-store.service
new file mode 100644 (file)
index 0000000..373f8b9
--- /dev/null
@@ -0,0 +1,11 @@
+[Unit]
+Description=Store nftables firewall rules
+Before=shutdown.target
+DefaultDependencies=No
+
+[Service]
+Type=oneshot
+ExecStart=/usr/libexec/nftables/nftables.sh store /var/lib/nftables/rules-save
+
+[Install]
+WantedBy=shutdown.target
diff --git a/net-firewall/nftables/files/systemd/nftables.service b/net-firewall/nftables/files/systemd/nftables.service
new file mode 100644 (file)
index 0000000..d6f05c7
--- /dev/null
@@ -0,0 +1,6 @@
+[Unit]
+Description=Store and restore nftables firewall rules
+
+[Install]
+Also=nftables-store.service
+Also=nftables-restore.service