head	1.21;
access;
symbols
	netbsd-9-5-RELEASE:1.18
	netbsd-11-0-RELEASE:1.21
	netbsd-11-0-RC7:1.21
	netbsd-11-0-RC6:1.21
	netbsd-11-0-RC5:1.21
	netbsd-11-0-RC4:1.21
	netbsd-11-0-RC3:1.21
	netbsd-11-0-RC2:1.21
	netbsd-11-0-RC1:1.21
	perseant-exfatfs-base-20250801:1.21
	netbsd-11:1.21.0.10
	netbsd-11-base:1.21
	netbsd-10-1-RELEASE:1.21
	perseant-exfatfs-base-20240630:1.21
	perseant-exfatfs:1.21.0.8
	perseant-exfatfs-base:1.21
	netbsd-8-3-RELEASE:1.18
	netbsd-9-4-RELEASE:1.18
	netbsd-10-0-RELEASE:1.21
	netbsd-10-0-RC6:1.21
	netbsd-10-0-RC5:1.21
	netbsd-10-0-RC4:1.21
	netbsd-10-0-RC3:1.21
	netbsd-10-0-RC2:1.21
	netbsd-10-0-RC1:1.21
	netbsd-10:1.21.0.6
	netbsd-10-base:1.21
	netbsd-9-3-RELEASE:1.18
	cjep_sun2x-base1:1.21
	cjep_sun2x:1.21.0.4
	cjep_sun2x-base:1.21
	cjep_staticlib_x-base1:1.21
	netbsd-9-2-RELEASE:1.18
	cjep_staticlib_x:1.21.0.2
	cjep_staticlib_x-base:1.21
	netbsd-9-1-RELEASE:1.18
	phil-wifi-20200421:1.18
	phil-wifi-20200411:1.18
	is-mlppp:1.18.0.52
	is-mlppp-base:1.18
	phil-wifi-20200406:1.18
	netbsd-8-2-RELEASE:1.18
	netbsd-9-0-RELEASE:1.18
	netbsd-9-0-RC2:1.18
	netbsd-9-0-RC1:1.18
	phil-wifi-20191119:1.18
	netbsd-9:1.18.0.50
	netbsd-9-base:1.18
	phil-wifi-20190609:1.18
	netbsd-8-1-RELEASE:1.18
	netbsd-8-1-RC1:1.18
	pgoyette-compat-merge-20190127:1.18
	pgoyette-compat-20190127:1.18
	pgoyette-compat-20190118:1.18
	pgoyette-compat-1226:1.18
	pgoyette-compat-1126:1.18
	pgoyette-compat-1020:1.18
	pgoyette-compat-0930:1.18
	pgoyette-compat-0906:1.18
	netbsd-7-2-RELEASE:1.18
	pgoyette-compat-0728:1.18
	netbsd-8-0-RELEASE:1.18
	phil-wifi:1.18.0.48
	phil-wifi-base:1.18
	pgoyette-compat-0625:1.18
	netbsd-8-0-RC2:1.18
	pgoyette-compat-0521:1.18
	pgoyette-compat-0502:1.18
	pgoyette-compat-0422:1.18
	netbsd-8-0-RC1:1.18
	pgoyette-compat-0415:1.18
	pgoyette-compat-0407:1.18
	pgoyette-compat-0330:1.18
	pgoyette-compat-0322:1.18
	pgoyette-compat-0315:1.18
	netbsd-7-1-2-RELEASE:1.18
	pgoyette-compat:1.18.0.46
	pgoyette-compat-base:1.18
	netbsd-7-1-1-RELEASE:1.18
	matt-nb8-mediatek:1.18.0.44
	matt-nb8-mediatek-base:1.18
	perseant-stdc-iso10646:1.18.0.42
	perseant-stdc-iso10646-base:1.18
	netbsd-8:1.18.0.40
	netbsd-8-base:1.18
	prg-localcount2-base3:1.18
	prg-localcount2-base2:1.18
	prg-localcount2-base1:1.18
	prg-localcount2:1.18.0.38
	prg-localcount2-base:1.18
	pgoyette-localcount-20170426:1.18
	bouyer-socketcan-base1:1.18
	pgoyette-localcount-20170320:1.18
	netbsd-7-1:1.18.0.36
	netbsd-7-1-RELEASE:1.18
	netbsd-7-1-RC2:1.18
	netbsd-7-nhusb-base-20170116:1.18
	bouyer-socketcan:1.18.0.34
	bouyer-socketcan-base:1.18
	pgoyette-localcount-20170107:1.18
	netbsd-7-1-RC1:1.18
	pgoyette-localcount-20161104:1.18
	netbsd-7-0-2-RELEASE:1.18
	localcount-20160914:1.18
	netbsd-7-nhusb:1.18.0.32
	netbsd-7-nhusb-base:1.18
	pgoyette-localcount-20160806:1.18
	pgoyette-localcount-20160726:1.18
	pgoyette-localcount:1.18.0.30
	pgoyette-localcount-base:1.18
	netbsd-7-0-1-RELEASE:1.18
	netbsd-7-0:1.18.0.28
	netbsd-7-0-RELEASE:1.18
	netbsd-7-0-RC3:1.18
	netbsd-7-0-RC2:1.18
	netbsd-7-0-RC1:1.18
	netbsd-5-2-3-RELEASE:1.15.20.1
	netbsd-5-1-5-RELEASE:1.15.20.1
	netbsd-6-0-6-RELEASE:1.18
	netbsd-6-1-5-RELEASE:1.18
	netbsd-7:1.18.0.26
	netbsd-7-base:1.18
	yamt-pagecache-base9:1.18
	yamt-pagecache-tag8:1.18
	netbsd-6-1-4-RELEASE:1.18
	netbsd-6-0-5-RELEASE:1.18
	tls-earlyentropy:1.18.0.24
	tls-earlyentropy-base:1.18
	riastradh-xf86-video-intel-2-7-1-pre-2-21-15:1.18
	riastradh-drm2-base3:1.18
	netbsd-6-1-3-RELEASE:1.18
	netbsd-6-0-4-RELEASE:1.18
	netbsd-5-2-2-RELEASE:1.15.20.1
	netbsd-5-1-4-RELEASE:1.15.20.1
	netbsd-6-1-2-RELEASE:1.18
	netbsd-6-0-3-RELEASE:1.18
	netbsd-5-2-1-RELEASE:1.15.20.1
	netbsd-5-1-3-RELEASE:1.15.20.1
	netbsd-6-1-1-RELEASE:1.18
	riastradh-drm2-base2:1.18
	riastradh-drm2-base1:1.18
	riastradh-drm2:1.18.0.16
	riastradh-drm2-base:1.18
	netbsd-6-1:1.18.0.22
	netbsd-6-0-2-RELEASE:1.18
	netbsd-6-1-RELEASE:1.18
	khorben-n900:1.18.0.20
	netbsd-6-1-RC4:1.18
	netbsd-6-1-RC3:1.18
	agc-symver:1.18.0.18
	agc-symver-base:1.18
	netbsd-6-1-RC2:1.18
	netbsd-6-1-RC1:1.18
	yamt-pagecache-base8:1.18
	netbsd-5-2:1.15.20.1.0.10
	netbsd-6-0-1-RELEASE:1.18
	yamt-pagecache-base7:1.18
	netbsd-5-2-RELEASE:1.15.20.1
	netbsd-5-2-RC1:1.15.20.1
	matt-nb6-plus-nbase:1.18
	yamt-pagecache-base6:1.18
	netbsd-6-0:1.18.0.14
	netbsd-6-0-RELEASE:1.18
	netbsd-6-0-RC2:1.18
	tls-maxphys:1.18.0.12
	tls-maxphys-base:1.18
	matt-nb6-plus:1.18.0.10
	matt-nb6-plus-base:1.18
	netbsd-6-0-RC1:1.18
	yamt-pagecache-base5:1.18
	yamt-pagecache-base4:1.18
	netbsd-6:1.18.0.8
	netbsd-6-base:1.18
	netbsd-5-1-2-RELEASE:1.15.20.1
	netbsd-5-1-1-RELEASE:1.15.20.1
	yamt-pagecache-base3:1.18
	yamt-pagecache-base2:1.18
	yamt-pagecache:1.18.0.6
	yamt-pagecache-base:1.18
	cherry-xenmp:1.18.0.4
	cherry-xenmp-base:1.18
	bouyer-quota2-nbase:1.18
	bouyer-quota2:1.18.0.2
	bouyer-quota2-base:1.18
	matt-mips64-premerge-20101231:1.18
	matt-nb5-mips64-premerge-20101231:1.15.20.1
	matt-nb5-pq3:1.15.20.1.0.8
	matt-nb5-pq3-base:1.15.20.1
	netbsd-5-1:1.15.20.1.0.6
	netbsd-5-1-RELEASE:1.15.20.1
	netbsd-5-1-RC4:1.15.20.1
	matt-nb5-mips64-k15:1.15.20.1
	netbsd-5-1-RC3:1.15.20.1
	netbsd-5-1-RC2:1.15.20.1
	netbsd-5-1-RC1:1.15.20.1
	netbsd-5-0-2-RELEASE:1.15.20.1
	matt-nb5-mips64-premerge-20091211:1.15.20.1
	matt-premerge-20091211:1.18
	matt-nb5-mips64-u2-k2-k4-k7-k8-k9:1.15.20.1
	matt-nb4-mips64-k7-u2a-k9b:1.15.20.1
	matt-nb5-mips64-u1-k1-k5:1.15.20.1
	matt-nb5-mips64:1.15.20.1.0.4
	netbsd-5-0-1-RELEASE:1.15.20.1
	jym-xensuspend-nbase:1.18
	netbsd-5-0:1.15.20.1.0.2
	netbsd-5-0-RELEASE:1.15.20.1
	netbsd-5-0-RC4:1.15.20.1
	netbsd-5-0-RC3:1.15
	netbsd-5-0-RC2:1.15
	jym-xensuspend:1.17.0.2
	jym-xensuspend-base:1.18
	netbsd-5-0-RC1:1.15
	mjf-devfs2-base2:1.17
	netbsd-5:1.15.0.20
	netbsd-5-base:1.15
	matt-mips64-base2:1.15
	matt-mips64:1.15.0.18
	netbsd-4-0-1-RELEASE:1.14
	wrstuden-revivesa-base-3:1.15
	wrstuden-revivesa-base-2:1.15
	wrstuden-fixsa-newbase:1.14
	wrstuden-revivesa-base-1:1.15
	yamt-pf42-base4:1.15
	yamt-pf42-base3:1.15
	hpcarm-cleanup-nbase:1.15
	yamt-pf42-baseX:1.15
	yamt-pf42-base2:1.15
	wrstuden-revivesa:1.15.0.16
	wrstuden-revivesa-base:1.15
	yamt-pf42:1.15.0.14
	yamt-pf42-base:1.15
	mjf-devfs2:1.15.0.12
	mjf-devfs2-base:1.15
	keiichi-mipv6:1.15.0.10
	keiichi-mipv6-base:1.15
	mjf-devfs:1.15.0.8
	mjf-devfs-base:1.15
	matt-armv6-nbase:1.15
	matt-armv6-prevmlocking:1.15
	wrstuden-fixsa-base-1:1.14
	netbsd-4-0:1.14.0.14
	netbsd-4-0-RELEASE:1.14
	cube-autoconf:1.15.0.6
	cube-autoconf-base:1.15
	netbsd-4-0-RC5:1.14
	netbsd-4-0-RC4:1.14
	netbsd-4-0-RC3:1.14
	netbsd-4-0-RC2:1.14
	netbsd-4-0-RC1:1.14
	matt-armv6:1.15.0.4
	matt-armv6-base:1.15
	matt-mips64-base:1.15
	hpcarm-cleanup:1.15.0.2
	hpcarm-cleanup-base:1.15
	netbsd-3-1-1-RELEASE:1.14
	netbsd-3-0-3-RELEASE:1.14
	wrstuden-fixsa:1.14.0.12
	wrstuden-fixsa-base:1.14
	abandoned-netbsd-4-base:1.14
	abandoned-netbsd-4:1.14.0.6
	netbsd-3-1:1.14.0.8
	netbsd-3-1-RELEASE:1.14
	netbsd-3-0-2-RELEASE:1.14
	netbsd-3-1-RC4:1.14
	netbsd-3-1-RC3:1.14
	netbsd-3-1-RC2:1.14
	netbsd-3-1-RC1:1.14
	netbsd-4:1.14.0.10
	netbsd-4-base:1.14
	netbsd-3-0-1-RELEASE:1.14
	netbsd-3-0:1.14.0.4
	netbsd-3-0-RELEASE:1.14
	netbsd-3-0-RC6:1.14
	netbsd-3-0-RC5:1.14
	netbsd-3-0-RC4:1.14
	netbsd-3-0-RC3:1.14
	netbsd-3-0-RC2:1.14
	netbsd-3-0-RC1:1.14
	netbsd-2-0-3-RELEASE:1.10.4.2
	netbsd-2-1:1.10.4.2.0.4
	netbsd-2-1-RELEASE:1.10.4.2
	netbsd-2-1-RC6:1.10.4.2
	netbsd-2-1-RC5:1.10.4.2
	netbsd-2-1-RC4:1.10.4.2
	netbsd-2-1-RC3:1.10.4.2
	netbsd-2-1-RC2:1.10.4.2
	netbsd-2-1-RC1:1.10.4.2
	netbsd-2-0-2-RELEASE:1.10.4.2
	netbsd-3:1.14.0.2
	netbsd-3-base:1.14
	netbsd-2-0-1-RELEASE:1.10.4.2
	netbsd-2:1.10.4.2.0.2
	netbsd-2-base:1.10.4.2
	netbsd-2-0-RELEASE:1.10.4.2
	netbsd-2-0-RC5:1.10.4.2
	netbsd-2-0-RC4:1.10.4.1
	netbsd-2-0-RC3:1.10.4.1
	netbsd-2-0-RC2:1.10.4.1
	netbsd-2-0-RC1:1.10.4.1
	netbsd-2-0:1.10.0.4
	netbsd-2-0-base:1.10
	netbsd-1-6-PATCH002-RELEASE:1.10
	netbsd-1-6-PATCH002:1.10
	netbsd-1-6-PATCH002-RC4:1.10
	netbsd-1-6-PATCH002-RC3:1.10
	netbsd-1-6-PATCH002-RC2:1.10
	netbsd-1-6-PATCH002-RC1:1.10
	netbsd-1-6-PATCH001:1.10
	netbsd-1-6-PATCH001-RELEASE:1.10
	netbsd-1-6-PATCH001-RC3:1.10
	netbsd-1-6-PATCH001-RC2:1.10
	netbsd-1-6-PATCH001-RC1:1.10
	fvdl_fs64_base:1.10
	netbsd-1-6-RELEASE:1.10
	netbsd-1-6-RC3:1.10
	netbsd-1-6-RC2:1.10
	netbsd-1-6-RC1:1.10
	netbsd-1-6:1.10.0.2
	netbsd-1-6-base:1.10
	netbsd-1-5-PATCH003:1.4.4.3
	netbsd-1-5-PATCH002:1.4.4.2
	netbsd-1-5-PATCH001:1.4.4.2
	netbsd-1-5-RELEASE:1.4.4.2
	netbsd-1-5-BETA2:1.4.4.2
	netbsd-1-5-BETA:1.4.4.2
	netbsd-1-5-ALPHA2:1.4.4.1
	netbsd-1-5:1.4.0.4
	netbsd-1-5-base:1.4
	minoura-xpg4dl:1.4.0.2
	minoura-xpg4dl-base:1.4
	rc-d-2000-03-10:1.1.1.1
	TNF:1.1.1;
locks; strict;
comment	@# @;


1.21
date	2020.09.08.12.52.18;	author martin;	state Exp;
branches;
next	1.20;
commitid	IL2vGNw0FVFgcfnC;

1.20
date	2020.07.22.16.50.41;	author martin;	state Exp;
branches;
next	1.19;
commitid	ZlFyZCKhX3U036hC;

1.19
date	2020.07.04.06.24.53;	author skrll;	state Exp;
branches;
next	1.18;
commitid	hRPK9EPvuxkZaJeC;

1.18
date	2009.03.23.18.52.02;	author hannken;	state Exp;
branches;
next	1.17;

1.17
date	2008.11.22.20.23.33;	author tsutsui;	state Exp;
branches
	1.17.2.1;
next	1.16;

1.16
date	2008.11.12.12.35.52;	author ad;	state Exp;
branches;
next	1.15;

1.15
date	2007.04.06.14.20.17;	author apb;	state Exp;
branches
	1.15.12.1
	1.15.20.1;
next	1.14;

1.14
date	2004.12.23.03.31.54;	author lukem;	state Exp;
branches;
next	1.13;

1.13
date	2004.11.08.02.09.01;	author lukem;	state Exp;
branches;
next	1.12;

1.12
date	2004.09.09.00.33.03;	author lukem;	state Exp;
branches;
next	1.11;

1.11
date	2004.08.13.18.08.03;	author mycroft;	state Exp;
branches;
next	1.10;

1.10
date	2001.02.28.17.03.50;	author lukem;	state Exp;
branches
	1.10.4.1;
next	1.9;

1.9
date	2000.10.09.06.11.38;	author nisimura;	state Exp;
branches;
next	1.8;

1.8
date	2000.10.01.05.58.06;	author lukem;	state Exp;
branches;
next	1.7;

1.7
date	2000.09.19.13.04.38;	author lukem;	state Exp;
branches;
next	1.6;

1.6
date	2000.07.21.01.14.23;	author lukem;	state Exp;
branches;
next	1.5;

1.5
date	2000.07.17.12.58.14;	author lukem;	state Exp;
branches;
next	1.4;

1.4
date	2000.05.13.08.45.07;	author lukem;	state Exp;
branches
	1.4.4.1;
next	1.3;

1.3
date	2000.04.30.13.23.33;	author lukem;	state Exp;
branches;
next	1.2;

1.2
date	2000.03.11.20.10.21;	author veego;	state Exp;
branches;
next	1.1;

1.1
date	2000.03.10.11.53.25;	author lukem;	state Exp;
branches
	1.1.1.1;
next	;

1.17.2.1
date	2009.05.13.19.18.03;	author jym;	state Exp;
branches;
next	;

1.15.12.1
date	2009.01.17.20.43.44;	author mjf;	state Exp;
branches;
next	;

1.15.20.1
date	2009.03.26.17.45.38;	author snj;	state Exp;
branches;
next	;

1.10.4.1
date	2004.09.21.15.14.20;	author tron;	state Exp;
branches;
next	1.10.4.2;

1.10.4.2
date	2004.11.12.06.44.17;	author jmc;	state Exp;
branches;
next	;

1.4.4.1
date	2000.08.09.18.45.22;	author lukem;	state Exp;
branches;
next	1.4.4.2;

1.4.4.2
date	2000.10.02.00.37.08;	author lukem;	state Exp;
branches;
next	1.4.4.3;

1.4.4.3
date	2001.12.27.12.17.20;	author he;	state Exp;
branches;
next	;

1.1.1.1
date	2000.03.10.11.53.25;	author lukem;	state Exp;
branches;
next	;


desc
@@


1.21
log
@Rename MOUNTCRITLOCAL to CRITLOCALMOUNTED to avoid a name collision
on case insensitive file systems
@
text
@#!/bin/sh
#
# $NetBSD: ipfilter,v 1.20 2020/07/22 16:50:41 martin Exp $
#

# PROVIDE: ipfilter
# REQUIRE: root bootconf CRITLOCALMOUNTED tty

$_rc_subr_loaded . /etc/rc.subr

name="ipfilter"
rcvar=$name
start_precmd="ipfilter_prestart"
start_cmd="ipfilter_start"
stop_precmd="test -f /etc/ipf.conf -o -f /etc/ipf6.conf"
stop_cmd="ipfilter_stop"
reload_precmd="$stop_precmd"
reload_cmd="ipfilter_reload"
resync_precmd="$stop_precmd"
resync_cmd="ipfilter_resync"
status_precmd="$stop_precmd"
status_cmd="ipfilter_status"
extra_commands="reload resync status"

ipfilter_prestart()
{
	if [ ! -f /etc/ipf.conf ] && [ ! -f /etc/ipf6.conf ]; then
		warn "/etc/ipf*.conf not readable; ipfilter start aborted."

		stop_boot
		return 1
	fi
	return 0
}

ipfilter_start()
{
	echo "Enabling ipfilter."
	/sbin/ipf ${rc_flags} -E

		# Do the flush first; since older ipf has different semantics.
		#
	if [ -f /etc/ipf.conf ]; then
		/sbin/ipf -Fa
	fi
	if [ -f /etc/ipf6.conf ]; then
		/sbin/ipf -6 -Fa
	fi

		# Now load the config files
		#
	if [ -f /etc/ipf.conf ]; then
		/sbin/ipf -f /etc/ipf.conf
	fi
	if [ -f /etc/ipf6.conf ]; then
		/sbin/ipf -6 -f /etc/ipf6.conf
	fi
}

ipfilter_stop()
{
	echo "Disabling ipfilter."
	/sbin/ipf -D
}

ipfilter_reload()
{
	echo "Reloading ipfilter rules."

		# Do the flush first; since older ipf has different semantics.
		#
	if [ -f /etc/ipf.conf ]; then
		/sbin/ipf -I -Fa
	fi
	if [ -f /etc/ipf6.conf ]; then
		/sbin/ipf -6 -I -Fa
	fi

		# Now load the config files into the Inactive set
		#
	if [ -f /etc/ipf.conf ] && ! /sbin/ipf -I -f /etc/ipf.conf; then
		err 1 "reload of ipf.conf failed; not swapping to new ruleset."
	fi
	if [ -f /etc/ipf6.conf ] && ! /sbin/ipf -I -6 -f /etc/ipf6.conf; then
		err 1 "reload of ipf6.conf failed; not swapping to new ruleset."
	fi

		# Swap in the new rules
		#
	/sbin/ipf -s
}

ipfilter_resync()
{
	/sbin/ipf -y
}

ipfilter_status()
{
	/sbin/ipf -V
}

load_rc_config $name
run_rc_command "$1"
@


1.20
log
@Split the local disk availability step into two phases to allow scripts
that pre-populate parts of the system (e.g. a tmpfs based /var) an
easy place to plug in like:

# REQUIRE: mountcritlocal
# BEFORE: MOUNTCRITLOCAL

This also cleans up the existing special handling a bit by separating it
into new scripts. All later scripts now depend on MOUNTCRITLOCAL.
Discussed on tech-userlevel some time ago.
@
text
@d3 1
a3 1
# $NetBSD: ipfilter,v 1.19 2020/07/04 06:24:53 skrll Exp $
d7 1
a7 1
# REQUIRE: root bootconf MOUNTCRITLOCAL tty
@


1.19
log
@Trailing whitespace
@
text
@d3 1
a3 1
# $NetBSD: ipfilter,v 1.18 2009/03/23 18:52:02 hannken Exp $
d7 1
a7 1
# REQUIRE: root bootconf mountcritlocal tty
@


1.18
log
@Add flags to rc.d/ipfilter.  Use it from rc.conf like

	ipfilter=YES ipfilter_flags="-T fr_statemax=18963,fr_statesize=27091"

Ok: Christos Zoulas <christos@@netbsd.org>
@
text
@d3 1
a3 1
# $NetBSD: ipfilter,v 1.17 2008/11/22 20:23:33 tsutsui Exp $
d87 1
a87 1
		
@


1.17
log
@Add "bootconf" to REQUIRE: lines which had beforenetlkm
since removed beforenetlkm required bootconf.
@
text
@d3 1
a3 1
# $NetBSD: ipfilter,v 1.16 2008/11/12 12:35:52 ad Exp $
d39 1
a39 1
	/sbin/ipf -E
@


1.17.2.1
log
@Sync with HEAD.

Third (and last) commit. See http://mail-index.netbsd.org/source-changes/2009/05/13/msg221222.html
@
text
@d3 1
a3 1
# $NetBSD: ipfilter,v 1.18 2009/03/23 18:52:02 hannken Exp $
d39 1
a39 1
	/sbin/ipf ${rc_flags} -E
@


1.16
log
@Remove LKMs and switch to the module framework, pass 1.

Proposed on tech-kern@@.
@
text
@d3 1
a3 1
# $NetBSD: ipfilter,v 1.15 2007/04/06 14:20:17 apb Exp $
d7 1
a7 1
# REQUIRE: root mountcritlocal tty
@


1.15
log
@* Add a stop_boot() function in rc.subr, to terminate a multi-user boot
  by killing the parent process.  The parent's PID is saved in $RC_PID.
* In all rc.d/* scripts that previously tried to stop the boot,
  replace in-line code with "stop_boot".
* Document this.

This should fix PR 29822.
@
text
@d3 1
a3 1
# $NetBSD: ipfilter,v 1.14 2004/12/23 03:31:54 lukem Exp $
d7 1
a7 1
# REQUIRE: root beforenetlkm mountcritlocal tty
@


1.15.20.1
log
@Pull up following revision(s) (requested by hannken in ticket #606):
	etc/defaults/rc.conf: revision 1.101
	etc/rc.d/ipfilter: revision 1.18
Add flags to rc.d/ipfilter.  Use it from rc.conf like
	ipfilter=YES ipfilter_flags="-T fr_statemax=18963,fr_statesize=27091"
Ok: Christos Zoulas <christos@@netbsd.org>
@
text
@d3 1
a3 1
# $NetBSD: ipfilter,v 1.15 2007/04/06 14:20:17 apb Exp $
d39 1
a39 1
	/sbin/ipf ${rc_flags} -E
@


1.15.12.1
log
@Sync with HEAD.
@
text
@d3 1
a3 1
# $NetBSD$
d7 1
a7 1
# REQUIRE: root bootconf mountcritlocal tty
@


1.14
log
@* Conditionalize flushing of IPv4 vs IPv6 rules based on the existance
  of the appropriate configuration file.
  Based on PR 28757 from Jason White.

* Add comments explaining why we flush separately from the reload
  (backwards compat with older ipf(8) binaries).
@
text
@d3 1
a3 1
# $NetBSD: ipfilter,v 1.13 2004/11/08 02:09:01 lukem Exp $
d30 1
a30 8
			# If booting directly to multiuser, send SIGTERM to
			# the parent (/etc/rc) to abort the boot
			#
		if [ "$autoboot" = yes ]; then
			echo "ERROR: ABORTING BOOT (sending SIGTERM to parent)!"
			kill -TERM $$
			exit 1
		fi
@


1.13
log
@Redo previous (rev 1.12) in a manner that allows this rc.d script to operate
correctly on ipf(8) from prior to 4.1.3 (where -Fa flushes both protocols)
and 4.1.3 (where -Fa only flushes the current protocol).
Fix from Kimmo Suominen, per private discussion.
@
text
@d3 1
a3 1
# $NetBSD: ipfilter,v 1.11 2004/08/13 18:08:03 mycroft Exp $
d29 1
a29 1
			#
d47 12
a58 2
	/sbin/ipf -Fa
	/sbin/ipf -6 -Fa
d77 11
a87 2
	/sbin/ipf -I -Fa
	/sbin/ipf -6 -I -Fa
d94 3
@


1.12
log
@Explicitly flush (-Fa) rules when loading or reloading IPv4 and IPv6 rules,
rather than relying upon running "ipf -Fa" beforehand (which only flushes IPv4)
Should fix PR 26885 and PR 26857.
@
text
@d46 3
a48 1
	/sbin/ipf -E -Fa
d50 1
a50 1
		/sbin/ipf -Fa -f /etc/ipf.conf
d53 1
a53 1
		/sbin/ipf -6 -Fa -f /etc/ipf6.conf
d67 3
a69 1
	if [ -f /etc/ipf.conf ] && ! /sbin/ipf -I -Fa -f /etc/ipf.conf; then
d72 1
a72 1
	if [ -f /etc/ipf6.conf ] && ! /sbin/ipf -6 -I -Fa -f /etc/ipf6.conf; then
@


1.11
log
@Add an _rc_subr_loaded variable, set to ":" by rc.subr.  Scripts can use this
for a speedup by doing:
$_rc_subr_loaded . /etc/rc.subr
@
text
@d3 1
a3 1
# $NetBSD: ipfilter,v 1.10 2001/02/28 17:03:50 lukem Exp $
d48 1
a48 1
		/sbin/ipf -f /etc/ipf.conf
d51 1
a51 1
		/sbin/ipf -6 -f /etc/ipf6.conf
d65 1
a65 2
	/sbin/ipf -I -Fa
	if [ -f /etc/ipf.conf ] && ! /sbin/ipf -I -f /etc/ipf.conf; then
d68 1
a68 1
	if [ -f /etc/ipf6.conf ] && ! /sbin/ipf -I -6 -f /etc/ipf6.conf; then
@


1.10
log
@support `resync' (ipf -y).
suggested by Johnny C. Lam in [misc/12300]
@
text
@d3 1
a3 1
# $NetBSD: ipfilter,v 1.9 2000/10/09 06:11:38 nisimura Exp $
d9 1
a9 1
. /etc/rc.subr
@


1.10.4.1
log
@Pull up revision 1.12 (requested by martti in ticket #866):
Explicitly flush (-Fa) rules when loading or reloading IPv4 and IPv6 rules,
rather than relying upon running "ipf -Fa" beforehand (which only flushes IPv4)
Should fix PR 26885 and PR 26857.
@
text
@d3 1
a3 1
# $NetBSD$
d48 1
a48 1
		/sbin/ipf -Fa -f /etc/ipf.conf
d51 1
a51 1
		/sbin/ipf -6 -Fa -f /etc/ipf6.conf
d65 2
a66 1
	if [ -f /etc/ipf.conf ] && ! /sbin/ipf -I -Fa -f /etc/ipf.conf; then
d69 1
a69 1
	if [ -f /etc/ipf6.conf ] && ! /sbin/ipf -6 -I -Fa -f /etc/ipf6.conf; then
@


1.10.4.2
log
@Pullup rev 1.13 (requested by lukem in ticket #963)

Redo previous (rev 1.12) in a manner that allows this rc.d script to operate
correctly on ipf(8) from prior to 4.1.3 (where -Fa flushes both protocols)
and 4.1.3 (where -Fa only flushes the current protocol).
@
text
@d3 1
a3 1
# $NetBSD: ipfilter,v 1.10.4.1 2004/09/21 15:14:20 tron Exp $
d46 1
a46 3
	/sbin/ipf -E
	/sbin/ipf -Fa
	/sbin/ipf -6 -Fa
d48 1
a48 1
		/sbin/ipf -f /etc/ipf.conf
d51 1
a51 1
		/sbin/ipf -6 -f /etc/ipf6.conf
d65 1
a65 3
	/sbin/ipf -I -Fa
	/sbin/ipf -6 -I -Fa
	if [ -f /etc/ipf.conf ] && ! /sbin/ipf -I -f /etc/ipf.conf; then
d68 1
a68 1
	if [ -f /etc/ipf6.conf ] && ! /sbin/ipf -I -6 -f /etc/ipf6.conf; then
@


1.9
log
@Use && and || for logical concatenations instead of -a/-o test operators.
@
text
@d3 1
a3 1
# $NetBSD: ipfilter,v 1.8 2000/10/01 05:58:06 lukem Exp $
d19 2
d23 1
a23 1
extra_commands="reload status"
d73 5
@


1.8
log
@support loading ipf6.conf as well as ipf.conf.
inspired by [misc/11033] by Gregory McGarry <g.mcgarry@@ieee.org>
@
text
@d3 1
a3 1
# $NetBSD: ipfilter,v 1.7 2000/09/19 13:04:38 lukem Exp $
d25 1
a25 1
	if [ ! -f /etc/ipf.conf -a ! -f /etc/ipf6.conf ]; then
@


1.7
log
@- only perform the checkyesno on the variable named in $rcvar (rather than
  implicitly using $name if $rcvar isn't set), and always perform this check,
  even when using start_cmd (et al).
  this check is performed before the pidcmd
  is run, speeding up scripts that weren't going to be run anyway.
  this should speed up booting slow systems.

- take advantage of the above and remove
	start_precmd="checkyesno foo"
  in scripts that use start_cmd.

- explicitly set rcvar=foo in the rc.d/foo scripts which have an equivalent
  rc.conf entry

- fix `rcvar' and `restart' when $rcvar isn't set.
  these above changes fix PR [bin/11027].

- when doing `force*', ignore the return value of *_precmd.
  this fixes PR [bin/10781].

- rename what sysdb provides from `databases' to `sysdb', to reflect
  the name of the script.

- improve the comments in rc.subr
@
text
@d3 1
a3 1
# $NetBSD: ipfilter,v 1.6 2000/07/21 01:14:23 lukem Exp $
d15 1
a15 1
stop_precmd="test -f /etc/ipf.conf"
d25 2
a26 2
	if [ ! -f /etc/ipf.conf ]; then
		warn "/etc/ipf.conf not readable; ipfilter start aborted."
d44 7
a50 1
	/sbin/ipf -E -Fa -f /etc/ipf.conf
d62 7
a68 5
	/sbin/ipf -I -Fa -f /etc/ipf.conf
	if [ $? -eq 0 ]; then
		/sbin/ipf -s
	else
		warn "Reload failed; not swapping to new ruleset."
d70 1
@


1.6
log
@if ipf.conf isn't readable and the system is booting directly to multiuser,
send SIGTERM to the parent (/etc/rc) so that init(8) aborts the boot.
@
text
@d3 1
a3 1
# $NetBSD: ipfilter,v 1.5 2000/07/17 12:58:14 lukem Exp $
d12 1
d15 1
a15 1
stop_precmd="checkyesno ipfilter && [ -f /etc/ipf.conf ]"
a24 3
	if ! checkyesno ipfilter; then
		return 1
	fi
@


1.5
log
@* add support for `status'
* remove bogus comment about aborting the boot if ipf fails; this hasn't
  been supported since the rc.d migration and is too messy to resolve...
@
text
@d3 1
a3 1
# $NetBSD: ipfilter,v 1.4 2000/05/13 08:45:07 lukem Exp $
d29 9
@


1.4
log
@Use load_rc_config() (from rc.subr) instead of sourcing /etc/rc.conf.
This allows us or a user to change the configuration file method in
one place - rc.subr - without having to edit all of the rc.d/* files.
@
text
@d3 1
a3 1
# $NetBSD: ipfilter,v 1.3 2000/04/30 13:23:33 lukem Exp $
d12 1
d18 3
a20 1
extra_commands="reload"
d22 1
a22 1
ipfilter_start()
d25 1
a25 1
		return 0
a26 4

	#	if /etc/ipf.conf isn't readable, abort the boot rather
	#	than risk a security problem
	#
d28 2
a29 1
		err 1 "/etc/ipf.conf not readable; ipfilter start aborted."
d31 5
d55 5
@


1.4.4.1
log
@pull up revs 1.5-1.6
approved by: thorpej

* add support for `status'
* if ipf.conf isn't readable and the system is booting directly to multiuser,
  send SIGTERM to the parent (/etc/rc) so that init(8) aborts the boot.
@
text
@d3 1
a3 1
# $NetBSD: ipfilter,v 1.6 2000/07/21 01:14:23 lukem Exp $
a11 1
start_precmd="ipfilter_prestart"
d17 1
a17 3
status_precmd="$stop_precmd"
status_cmd="ipfilter_status"
extra_commands="reload status"
d19 1
a19 1
ipfilter_prestart()
d22 1
a22 1
		return 1
d24 4
d29 1
a29 11
		warn "/etc/ipf.conf not readable; ipfilter start aborted."
			#
			# If booting directly to multiuser, send SIGTERM to
			# the parent (/etc/rc) to abort the boot
			#
		if [ "$autoboot" = yes ]; then
			echo "ERROR: ABORTING BOOT (sending SIGTERM to parent)!"
			kill -TERM $$
			exit 1
		fi
		return 1
a30 5
	return 0
}

ipfilter_start()
{
a49 5
}

ipfilter_status()
{
	/sbin/ipf -V
@


1.4.4.2
log
@pull up rev 1.7-1.8 (approved by thorpej):
	- support loading ipf6.conf as well as ipf.conf
	- always use $rcvar to determine the name of the var to checkyesno
	- fix force*
@
text
@d3 1
a3 1
# $NetBSD: ipfilter,v 1.8 2000/10/01 05:58:06 lukem Exp $
a11 1
rcvar=$name
d14 1
a14 1
stop_precmd="test -f /etc/ipf.conf -o -f /etc/ipf6.conf"
d24 5
a28 2
	if [ ! -f /etc/ipf.conf -a ! -f /etc/ipf6.conf ]; then
		warn "/etc/ipf*.conf not readable; ipfilter start aborted."
d46 1
a46 7
	/sbin/ipf -E -Fa
	if [ -f /etc/ipf.conf ]; then
		/sbin/ipf -f /etc/ipf.conf
	fi
	if [ -f /etc/ipf6.conf ]; then
		/sbin/ipf -6 -f /etc/ipf6.conf
	fi
d58 5
a62 7

	/sbin/ipf -I -Fa
	if [ -f /etc/ipf.conf ] && ! /sbin/ipf -I -f /etc/ipf.conf; then
		err 1 "reload of ipf.conf failed; not swapping to new ruleset."
	fi
	if [ -f /etc/ipf6.conf ] && ! /sbin/ipf -I -6 -f /etc/ipf6.conf; then
		err 1 "reload of ipf6.conf failed; not swapping to new ruleset."
a63 1
	/sbin/ipf -s
@


1.4.4.3
log
@Pull up revisions 1.9-1.10 (requested by jlam):
  Use && and || for logical concatenations instead of -a/-o operators,
  and support ``resync'' (ipf -y).
@
text
@d3 1
a3 1
# $NetBSD: ipfilter,v 1.4.4.2 2000/10/02 00:37:08 lukem Exp $
a18 2
resync_precmd="$stop_precmd"
resync_cmd="ipfilter_resync"
d21 1
a21 1
extra_commands="reload resync status"
d25 1
a25 1
	if [ ! -f /etc/ipf.conf ] && [ ! -f /etc/ipf6.conf ]; then
a70 5
}

ipfilter_resync()
{
	/sbin/ipf -y
@


1.3
log
@use extra_commands= instead of using 2nd argument to run_rc_command
@
text
@d3 1
a3 1
# $NetBSD: ipfilter,v 1.2 2000/03/11 20:10:21 veego Exp $
a9 1
. /etc/rc.conf
d52 1
@


1.2
log
@Add missing checkyesno's.
@
text
@d3 1
a3 1
# $NetBSD: ipfilter,v 1.1.1.1 2000/03/10 11:53:25 lukem Exp $
d18 1
d53 1
a53 1
run_rc_command "$1" "reload"
@


1.1
log
@Initial revision
@
text
@d3 1
a3 1
# $NetBSD$
d21 1
a21 1
	if [ ! checkyesno ipfilter ]; then
@


1.1.1.1
log
@rc.d scripts derived from /etc/rc
@
text
@@
