[systemd-devel] [PATCH] Add a network-pre.target to avoid firewall leaks
Zbigniew Jędrzejewski-Szmek
zbyszek at in.waw.pl
Sat Jun 7 16:07:38 PDT 2014
On Sun, Jun 08, 2014 at 12:55:55AM +0200, Michael Biebl wrote:
> Could you elaborate why Before=network.target is too late?
Because then network setup races with e.g. iptables setup. Depending
on the timing, a window in which the network has been set up, but
the firewall is not yet in place.
Zbyszek
More information about the systemd-devel
mailing list