[arch-commits] Commit in nftables/repos (4 files)

Evangelos Foutras foutrelis at archlinux.org
Fri Jan 11 07:52:48 UTC 2019


    Date: Friday, January 11, 2019 @ 07:52:48
  Author: foutrelis
Revision: 343578

archrelease: copy trunk to staging-x86_64

Added:
  nftables/repos/staging-x86_64/
  nftables/repos/staging-x86_64/PKGBUILD
    (from rev 343577, nftables/trunk/PKGBUILD)
  nftables/repos/staging-x86_64/nftables.conf
    (from rev 343577, nftables/trunk/nftables.conf)
  nftables/repos/staging-x86_64/nftables.service
    (from rev 343577, nftables/trunk/nftables.service)

------------------+
 PKGBUILD         |   57 +++++++++++++++++++++++++++++++++++++++++++++++++++++
 nftables.conf    |   38 +++++++++++++++++++++++++++++++++++
 nftables.service |   15 +++++++++++++
 3 files changed, 110 insertions(+)

Copied: nftables/repos/staging-x86_64/PKGBUILD (from rev 343577, nftables/trunk/PKGBUILD)
===================================================================
--- staging-x86_64/PKGBUILD	                        (rev 0)
+++ staging-x86_64/PKGBUILD	2019-01-11 07:52:48 UTC (rev 343578)
@@ -0,0 +1,57 @@
+# Maintainer: Sébastien "Seblu" Luttringer <seblu at archlinux.org>
+
+pkgname=nftables
+epoch=1
+pkgver=0.9.0
+pkgrel=3
+pkgdesc='Netfilter tables userspace tools'
+arch=('x86_64')
+url='https://netfilter.org/projects/nftables/'
+license=('GPL2')
+depends=('libmnl' 'libnftnl' 'gmp' 'readline' 'ncurses' 'jansson')
+makedepends=('docbook2x')
+backup=('etc/nftables.conf')
+validpgpkeys=('C09DB2063F1D7034BA6152ADAB4655A126D292E4') # Netfilter Core Team
+source=("https://netfilter.org/projects/nftables/files/nftables-$pkgver.tar.bz2"{,.sig}
+        'nftables.conf'
+        'nftables.service')
+sha1sums=('a3463fc6589c08631ec3f306f6db7f0905249542'
+          'SKIP'
+          '7869aa31ac802922073310ffd4cbbc16450171e5'
+          '59185e947ebfd599954800ad2c774171b3f4cd58')
+
+prepare() {
+  cd $pkgname-$pkgver
+  # apply patch from the source array (should be a pacman feature)
+  local filename
+  for filename in "${source[@]}"; do
+    if [[ "$filename" =~ \.patch$ ]]; then
+      msg2 "Applying patch ${filename##*/}"
+      patch -p1 -N -i "$srcdir/${filename##*/}"
+    fi
+  done
+  :
+}
+
+build() {
+  cd $pkgname-$pkgver
+  ./configure \
+    --prefix=/usr \
+    --sbindir=/usr/bin \
+    --sysconfdir=/usr/share \
+    --with-json \
+    CONFIG_MAN=y DB2MAN=docbook2man
+  make
+}
+
+package() {
+  pushd $pkgname-$pkgver
+  make DESTDIR="$pkgdir" install
+  popd
+  # basic safe firewall config
+  install -Dm644 nftables.conf "$pkgdir/etc/nftables.conf"
+  # systemd
+  install -Dm644 nftables.service "$pkgdir/usr/lib/systemd/system/nftables.service"
+}
+
+# vim:set ts=2 sw=2 et:

Copied: nftables/repos/staging-x86_64/nftables.conf (from rev 343577, nftables/trunk/nftables.conf)
===================================================================
--- staging-x86_64/nftables.conf	                        (rev 0)
+++ staging-x86_64/nftables.conf	2019-01-11 07:52:48 UTC (rev 343578)
@@ -0,0 +1,38 @@
+#!/usr/bin/nft -f
+# ipv4/ipv6 Simple & Safe Firewall
+# you can find examples in /usr/share/nftables/
+
+table inet filter {
+  chain input {
+    type filter hook input priority 0;
+
+    # allow established/related connections
+    ct state {established, related} accept
+
+    # early drop of invalid connections
+    ct state invalid drop
+
+    # allow from loopback
+    iifname lo accept
+
+    # allow icmp
+    ip protocol icmp accept
+    ip6 nexthdr icmpv6 accept
+
+    # allow ssh
+    tcp dport ssh accept
+
+    # everything else
+    reject with icmpx type port-unreachable
+  }
+  chain forward {
+    type filter hook forward priority 0;
+    drop
+  }
+  chain output {
+    type filter hook output priority 0;
+  }
+
+}
+
+# vim:set ts=2 sw=2 et:

Copied: nftables/repos/staging-x86_64/nftables.service (from rev 343577, nftables/trunk/nftables.service)
===================================================================
--- staging-x86_64/nftables.service	                        (rev 0)
+++ staging-x86_64/nftables.service	2019-01-11 07:52:48 UTC (rev 343578)
@@ -0,0 +1,15 @@
+[Unit]
+Description=Netfilter Tables
+Documentation=man:nft(8)
+Wants=network-pre.target
+Before=network-pre.target
+
+[Service]
+Type=oneshot
+ExecStart=/usr/bin/nft -f /etc/nftables.conf
+ExecReload=/usr/bin/nft flush ruleset ';' include '"/etc/nftables.conf"'
+ExecStop=/usr/bin/nft flush ruleset
+RemainAfterExit=yes
+
+[Install]
+WantedBy=multi-user.target



More information about the arch-commits mailing list