unofficial mirror of guix-patches@gnu.org 
 help / color / mirror / code / Atom feed
* [bug#49540] [PATCH 0/2] services: nftables: Make it extandable
@ 2021-07-12 21:05 Brice Waegeneire
  2021-07-12 21:08 ` [bug#49540] [PATCH 1/2] services: nftables: Only manage delete our own table Brice Waegeneire
  2021-07-12 21:08 ` [bug#49540] [PATCH 2/2] services: nftables: Make it extendable Brice Waegeneire
  0 siblings, 2 replies; 3+ messages in thread
From: Brice Waegeneire @ 2021-07-12 21:05 UTC (permalink / raw)
  To: 49540; +Cc: iyzsong, solene

This patchset make "nftables-service-type" extendable, so other services could
open port.  I wrote this to be able to use libvirt with nftables (another
patch is comming about that) like this:

--8<---------------cut here---------------start------------->8---
(simple-service 'nftables-libvirt nftables-service-type
                   (list "# Libvirt?
add rule inet guix forward ct state established,related accept
add rule inet guix forward iifname \"virbr*\" accept

add chain inet guix libvirt
insert rule inet guix input iifname \"virbr*\" jump libvirt
insert rule inet guix libvirt udp dport 53 accept
insert rule inet guix libvirt tcp dport 53 accept
insert rule inet guix libvirt udp dport 67 accept
"))
--8<---------------cut here---------------end--------------->8---

So this should make it possible to implement Solene's
"simple-firewall-service"¹ by simply extending "nftables-service-type".

Also, now, stopping nftables only remove the "guix" table so other software
can use their own namespaces without being purged when that service is
stopped.

WDYT?

¹ <https://issues.guix.gnu.org/48975>

Brice Waegeneire (2): services: nftables: Only manage delete our
own table.  services: nftables: Make it extendable.

 gnu/services/networking.scm | 51 +++++++++++++++++++++++++++++--------
 1 file changed, 41 insertions(+), 10 deletions(-)

-- 
2.31.1





^ permalink raw reply	[flat|nested] 3+ messages in thread

end of thread, other threads:[~2021-07-12 21:09 UTC | newest]

Thread overview: 3+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2021-07-12 21:05 [bug#49540] [PATCH 0/2] services: nftables: Make it extandable Brice Waegeneire
2021-07-12 21:08 ` [bug#49540] [PATCH 1/2] services: nftables: Only manage delete our own table Brice Waegeneire
2021-07-12 21:08 ` [bug#49540] [PATCH 2/2] services: nftables: Make it extendable Brice Waegeneire

Code repositories for project(s) associated with this public inbox

	https://git.savannah.gnu.org/cgit/guix.git

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for read-only IMAP folder(s) and NNTP newsgroup(s).