Your message dated Sat, 01 Jun 2013 04:48:24 +0000
with message-id <[email protected]>
and subject line Bug#710446: fixed in sanewall 1.0.2+ds-2
has caused the Debian Bug report #710446,
regarding sanewall: firehol conflict unexpected & uneeded
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)
--
710446: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=710446
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Package: sanewall
Version: 1.0.2+ds-1
Severity: normal
The sanewall package conflicts with firehol. I guess this makes a certain
degree of sense, because only one set of rules can be active at a time.
But no similar conflict exists for other iptables based firewall tools
(e.g. ufw, shorewall, uruk, ipkungfu, etc). Having multiple tools
installed isn't really a problem so long as only one is setup to restore on
boot. For both sanewall and firehol this is controlled by a file in
/etc/default.
The policy manual lists 3 reasons for conflicts
http://www.debian.org/doc/debian-policy/ch-relationships.html#s-conflicts
- when two packages provide the same file
- in conjunction with Provides when only one package providing a given
virtual facility may be unpacked at a time..
- in other cases where one must prevent simultaneous installation of two
packages for reasons that are ongoing (not fixed in a later version of one
of the packages) or that must prevent both packages from being unpacked at
the same time, not just configured.
I don't think firehol meets the criteria.
- Firehol and Sanewall don't have a file conflict.
- Both packages can be installed and un-configured and not cause problems.
- There is currently no virtual package related to an iptables management
tool.
This is a problem for me. I was thinking I could pre-install sanewall on
all my systems, and as I start to implement IPv6 switch from firehol to
sanewall along with updating the rules. Preinstalling isn't possible since
sanewall removes firehol.
Chris Francy
--- End Message ---
--- Begin Message ---
Source: sanewall
Source-Version: 1.0.2+ds-2
We believe that the bug you reported is fixed in the latest version of
sanewall, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Jerome Benoit <[email protected]> (supplier of updated sanewall package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Format: 1.8
Date: Fri, 31 May 2013 21:03:57 +0000
Source: sanewall
Binary: sanewall sanewall-doc
Architecture: source all
Version: 1.0.2+ds-2
Distribution: unstable
Urgency: low
Maintainer: Jerome Benoit <[email protected]>
Changed-By: Jerome Benoit <[email protected]>
Description:
sanewall - easy to use but powerful iptables stateful firewall (program)
sanewall-doc - easy to use but powerful iptables stateful firewall (docs)
Closes: 710446
Changes:
sanewall (1.0.2+ds-2) unstable; urgency=low
.
* Debianization:
- debian/control:
- drop out the Replaces and Conflicts fields against firehol, thanks to
Chris Francy <[email protected]> for the insight (Closes: #710446);
- in Depends, remove bash as it is an essential package;
- in Description, revisit with respect to the remove of bash in Depends.
Checksums-Sha1:
aad5fc8837e1adb104e2b53da4c6e76073110a53 1970 sanewall_1.0.2+ds-2.dsc
23834756dfaecd8c640d1d6c6cfae5c2a608e6b8 6348 sanewall_1.0.2+ds-2.debian.tar.xz
7725454c56a388e84bed469fc992bdbb3255cf9e 61744 sanewall_1.0.2+ds-2_all.deb
aecdac8488ffbff5b4f1cdaae34e6b98497cd60c 473798 sanewall-doc_1.0.2+ds-2_all.deb
Checksums-Sha256:
07b56ee3eeb1e4f154719b3e06cd782ee12b29aaf2abe0fcacb4c1680c9d9018 1970
sanewall_1.0.2+ds-2.dsc
147e0ffa11393ab392e299211ca5fc189db3647c869e79fec43ba7ae94595de3 6348
sanewall_1.0.2+ds-2.debian.tar.xz
2d1a1426740a4d0651173ef0cef1f8beab4420cef5ae558fdbb28a3d7b22ad34 61744
sanewall_1.0.2+ds-2_all.deb
9242278624875f1d670ce75807e71d6bf169af223be1b4d0cf5f4bdd4e377a50 473798
sanewall-doc_1.0.2+ds-2_all.deb
Files:
a13424aa45f2db668e2459460325e4ea 1970 net optional sanewall_1.0.2+ds-2.dsc
2baabcd593da003fba20b7e24dce60af 6348 net optional
sanewall_1.0.2+ds-2.debian.tar.xz
6c609a12fcd1fe1aac558f01367632b0 61744 net optional sanewall_1.0.2+ds-2_all.deb
18a9f7261cd184cc7a903af1d5a26a59 473798 doc optional
sanewall-doc_1.0.2+ds-2_all.deb
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)
iQIcBAEBAgAGBQJRqXoPAAoJECHSBYmXSz6WAi0QAIIIJw0y6r7EKOPqdmXahURq
52fmlQJtznqSxaUBvnYTtX9Gk9Xiy0po75bEkCBtaxPv0bLjdampy3XjpbxGNtaG
whp3/+l914pFuR7KaBd3PBsUBQrQ1vGJpcREXJsiXb/plcoWSnb9Kl4qLyRETzaW
GMYBKsumeigAe+XsY8MNMpcP99/Lf8I8cfvCMjBiGHGVHr+jE5RC7ad74U2lsKsl
3dWR3FieV+Rhlh3dRyL0OwLW1rFpDIJPRMZCLjRt2kQl18WvF9vWoQ/q72tPeCeW
w02E0uuLHPXdSBfzr6RxMSSqoROxfQgcKlcszfhntrim5WLn3cGrXg0IlaLxNCHt
6hahO+ttaA26h4/3w1++/UP6t3uzH5CFDegMB0+jXwDVnHjWYxlJ7B+KGHapdbG5
ynEdc/NfEzlfy7+bXmoCun84b8vrX3WJxPRdnUCa4iNwpBOyyJMPRzgN/LnBzk9q
SvasIOO48pZ661etD7q+RhzwT9q9omP5hq0XpACbP9ma0Am0lnlQQ33BiGjdMN6B
AIv0wq310O9emcX56nx4HAvS+JaXfr2yhPJEqUwPsxQl/gAXwa2M74VTMHh8qNfG
tetYAp91g9dLDMjphO+hzD+5g/V5ZT/Sc/yG3uOK3UW1VzRTrkm0c6dFI+A592eG
vO+jeFss6TnmkjiGd1IX
=nEHD
-----END PGP SIGNATURE-----
--- End Message ---