Re: Bug? iptables-save dumps resolved uids/gids for owner matches

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



Jan Engelhardt <jengelh@xxxxxxxxxx> writes:

> On Friday 2010-12-03 18:27, Ferenc Wagner wrote:
>
>> I opened http://bugzilla.netfilter.org/show_bug.cgi?id=683 quite some
>> time ago, but it hasn't received a single comment yet.  Don't you think
>> it's a real problem?  If you do, I'm willing to work on fixing it,
>> either by introducing a new option or by changing the default behaviour.
>> Actually, since we're seriously affected by this, I'm determined to
>> solve it, but of course I'd prefer to take a blessed route to get my
>> changes incorporated into the official sources if at all possible.
>
> This was done on purpose by me, because username resolution usually does 
> not take ages like DNS, and user ids can actually change if you copy a 
> ruleset to another machine (this is much more unlikely to be the case 
> with DNS).

This is indeed true if you only use a local passwd and group database.
So we're talking about a design decision, which I'd have taken the other
way, and not for pure consistency alone.  But how do we proceed now?  You
took responsibily of the ticket (thanks for that and the enlightening
comment, too), does it mean you've got an action plan and will carry that
out shortly?  I'm sure you could resolve this in about half an hour, but
have you got the time?  Also, I'd probably need this backported to 1.4.8.
Shall I start hacking or had I better wait for you?
-- 
Thanks,
Feri.
--
To unsubscribe from this list: send the line "unsubscribe netfilter-devel" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at  http://vger.kernel.org/majordomo-info.html


[Index of Archives]     [Netfitler Users]     [LARTC]     [Bugtraq]     [Yosemite Forum]

  Powered by Linux