core-agent-linux/network
Marek Marczykowski-Górecki 57a3c2d67e
network: have safe fallback in case of qubes-firewall crash/error
When qubes-firewall service is started, modify firewall to have "DROP"
policy, so if something goes wrong, no data got leaked.
But keep default action "ACCEPT" in case of legitimate service stop, or
not starting it at all - because one may choose to not use this service
at all.
Achieve this by adding "DROP" rule at the end of QBS-FIREWALL chain and
keep it there while qubes-firewall service is running.

Fixes QubesOS/qubes-issues#3269
2017-11-20 01:56:14 +01:00
..
00notify-hook Improved upgrade notifications sent to QVMM. 2015-11-11 15:45:00 +00:00
30-qubes-external-ip network: fix issues found by shellcheck 2017-09-30 04:43:04 +02:00
80-qubes.conf install iptables/forwarding for debian 2014-09-29 05:25:14 +02:00
ip6tables network: have safe fallback in case of qubes-firewall crash/error 2017-11-20 01:56:14 +01:00
iptables network: have safe fallback in case of qubes-firewall crash/error 2017-11-20 01:56:14 +01:00
iptables-updates-proxy network: fix issues found by shellcheck 2017-09-30 04:43:04 +02:00
network-manager-prepare-conf-dir network: fix issues found by shellcheck 2017-09-30 04:43:04 +02:00
nm-30-qubes.conf Configure NetworkManager to keep /etc/resolv.conf as plain file 2016-09-15 01:26:35 +02:00
qubes-fix-nm-conf.sh network: fix issues found by shellcheck 2017-09-30 04:43:04 +02:00
qubes-iptables network: fix issues found by shellcheck 2017-09-30 04:43:04 +02:00
qubes-nmhook network: fix issues found by shellcheck 2017-09-30 04:43:04 +02:00
qubes-setup-dnat-to-ns network: fix issues found by shellcheck 2017-09-30 04:43:04 +02:00
setup-ip network: fix issues found by shellcheck 2017-09-30 04:43:04 +02:00
show-hide-nm-applet.desktop Fix show-hide-nm-applet.desktop - use OnlyShowIn=X-QUBES 2015-09-03 00:43:54 +02:00
show-hide-nm-applet.sh network: fix issues found by shellcheck 2017-09-30 04:43:04 +02:00
tinyproxy-updates.conf updates-proxy: explicitly block connection looping back to the proxy IP 2015-12-04 14:57:07 +01:00
udev-qubes-network.rules network: fix rules for network setup on new udev 2017-10-19 15:10:31 +02:00
update-proxy-configs archlinux: ensure [options] section is present in all pacman drop-ins 2017-10-23 20:22:04 +02:00
updates-blacklist (redo) updates-proxy: explicitly block connection looping back to the proxy IP 2017-09-15 05:00:05 +02:00
vif-qubes-nat.sh network: fix issues found by shellcheck 2017-09-30 04:43:04 +02:00
vif-route-qubes network: fix issues found by shellcheck 2017-09-30 04:43:04 +02:00