[package] firewall:

- defer firewall start until the first interface is brought up by hotplug, fixes race conditions on slow devices
	- create a file lock during firewall start and wait for it in hotplug events, prevents race conditions between start and addif
	- start firewall actions in background from hotplug handler since the firewall itself fires further hotplug events which results in a deadlock if not forked off
	- get loaded state direcly from the uci binary since updated value is not recognized by config_get after uci_set_state
	- bump package revision to r2


git-svn-id: svn://svn.openwrt.org/openwrt/trunk@21486 3c298f89-4303-0410-b956-a3cf2f4a3e73
This commit is contained in:
Jo-Philipp Wich
2010-05-17 12:47:14 +00:00
parent 5bb4773eb4
commit fa11019822
4 changed files with 21 additions and 7 deletions

View File

@@ -9,11 +9,20 @@
. /lib/firewall/core.sh
fw_init
fw_is_loaded || exit 0
# Wait for firewall if startup is in progress
lock -w /var/lock/firewall.start
case "$ACTION" in
ifup)
fw_configure_interface "$INTERFACE" add "$DEVICE" ;;
fw_is_loaded && {
fw_configure_interface "$INTERFACE" add "$DEVICE" &
} || {
/etc/init.d/firewall enabled && fw_start &
}
;;
ifdown)
fw_configure_interface "$INTERFACE" del "$DEVICE" ;;
fw_is_loaded && fw_configure_interface "$INTERFACE" del "$DEVICE" &
;;
esac