[package] firewall: run ifdown hotplug events synchronized, fixes a racecondition...
[openwrt/svn-archive/archive.git] / package / firewall / files / lib / core.sh
index 5f06ffe3fbe899a0764c28e8be4978442644f14a..c350e8f0f61b76931d542235c2ca415285387563 100644 (file)
@@ -15,8 +15,6 @@ fw_start() {
                exit 1
        }
 
-       lock /var/lock/firewall.start
-
        uci_set_state firewall core "" firewall_state
 
        fw_clear DROP
@@ -41,7 +39,7 @@ fw_start() {
        echo "Loading includes"
        config_foreach fw_load_include include
 
-       [ -n "$FW_NOTRACK_DISABLED" ] && {
+       [ -z "$FW_NOTRACK_DISABLED" ] && {
                echo "Optimizing conntrack"
                config_foreach fw_load_notrack_zone zone
        }
@@ -51,9 +49,8 @@ fw_start() {
 
        fw_callback post core
 
+       uci_set_state firewall core zones "$FW_ZONES"
        uci_set_state firewall core loaded 1
-
-       lock -u /var/lock/firewall.start
 }
 
 fw_stop() {
@@ -61,6 +58,17 @@ fw_stop() {
 
        fw_callback pre stop
 
+       local z n i
+       config_get z core zones
+       for z in $z; do
+               config_get n core "${z}_networks"
+               for n in $n; do
+                       config_get i core "${n}_ifname"
+                       [ -n "$i" ] && env -i ACTION=remove ZONE="$z" \
+                               INTERFACE="$n" DEVICE="$i" /sbin/hotplug-call firewall
+               done
+       done
+
        fw_clear ACCEPT
 
        fw_callback post stop
@@ -94,7 +102,6 @@ fw_die() {
        echo "Error:" "$@" >&2
        fw_log error "$@"
        fw_stop
-       lock -u /var/lock/firewall.start
        exit 1
 }