]>
review.fuel-infra Code Review - puppet-modules/puppetlabs-firewall.git/log
Simon Humbert [Tue, 3 May 2016 21:18:50 +0000 (17:18 -0400)]
adding iptables string matching extension
Simon Humbert [Tue, 3 May 2016 21:11:29 +0000 (17:11 -0400)]
update handling of length property
Simon Humbert [Tue, 3 May 2016 21:04:19 +0000 (17:04 -0400)]
adding iptables length extension
Hunter Haugen [Mon, 25 Apr 2016 23:03:03 +0000 (16:03 -0700)]
Merge pull request #624 from broadinstitute/freebsd
allow FreeBSD when dependencies require this class
Bryan Jen [Mon, 25 Apr 2016 19:59:56 +0000 (14:59 -0500)]
Merge pull request #625 from hunner/fix_flush
(maint) Remove nat flush
Hunter Haugen [Mon, 25 Apr 2016 17:49:35 +0000 (10:49 -0700)]
(maint) Remove nat flush
The man page says it's not implemented for ip6tables
Riccardo Calixte [Fri, 8 Apr 2016 15:34:47 +0000 (11:34 -0400)]
allow FreeBSD when dependencies require this class
Greg Hardy [Wed, 20 Apr 2016 15:56:24 +0000 (16:56 +0100)]
Merge pull request #623 from DavidS/restore-local-nodesets
(maint) re-add the local nodesets
David Schmitt [Wed, 20 Apr 2016 13:56:35 +0000 (14:56 +0100)]
(maint) re-add the local nodesets
These nodesets are required for internal CI; to set the ssh timeout.
Greg Hardy [Tue, 19 Apr 2016 10:27:10 +0000 (11:27 +0100)]
Merge pull request #622 from puppetlabs/update-msync
Update to newest modulesync_configs [
9ca280f ]
David Schmitt [Wed, 13 Apr 2016 19:49:43 +0000 (20:49 +0100)]
Update to newest modulesync_configs [
9ca280f ]
David Schmitt [Mon, 18 Apr 2016 18:10:21 +0000 (19:10 +0100)]
(maint) remove UNSUPPORTED_PLATFORMS filter and improve spec description
David Schmitt [Thu, 14 Apr 2016 09:58:21 +0000 (10:58 +0100)]
(maint) fix specs to run under STRICT_VARIABLES
TP Honey [Thu, 7 Apr 2016 13:18:02 +0000 (14:18 +0100)]
Merge pull request #621 from mmckinst/align_text
align text properly
Mark McKinstry [Thu, 7 Apr 2016 01:18:02 +0000 (21:18 -0400)]
align text properly
JT (Jonny) [Fri, 1 Apr 2016 10:02:37 +0000 (11:02 +0100)]
Merge pull request #619 from alexharv074/fix_up_rspec_deprecation_warnings
Fix up rspec deprecation warnings
Alex Harvey [Wed, 30 Mar 2016 03:34:35 +0000 (14:34 +1100)]
Fix up all rspec deprecation warnings.
David Schmitt [Wed, 30 Mar 2016 14:58:06 +0000 (15:58 +0100)]
Merge pull request #620 from jonnytpuppet/rspec_puppet_pin
Pinned rspec_puppet to 2.3.2
Jonathan Tripathy [Wed, 30 Mar 2016 13:36:27 +0000 (14:36 +0100)]
Pinned rspec_puppet to 2.3.2
Alex Harvey [Tue, 29 Mar 2016 15:32:37 +0000 (02:32 +1100)]
Add a test.
Demonstrate some surprising behaviour to make it clearer that it's
nevertheless working as designed.
Hunter Haugen [Thu, 17 Mar 2016 16:00:30 +0000 (09:00 -0700)]
Merge pull request #617 from jpnc/master
Add VirtuozzoLinux to the RedHat family
James Pannacciulli [Mon, 14 Mar 2016 22:24:16 +0000 (15:24 -0700)]
Add VirtuozzoLinux to the RedHat family
Hunter Haugen [Fri, 11 Mar 2016 00:53:57 +0000 (16:53 -0800)]
Merge pull request #616 from mmckinst/align_more_arrows
align arrows
Mark McKinstry [Tue, 8 Mar 2016 23:01:25 +0000 (18:01 -0500)]
align arrows
Hunter Haugen [Tue, 8 Mar 2016 18:26:30 +0000 (10:26 -0800)]
Merge pull request #614 from mmckinst/align_arrow
align arrows
Mark McKinstry [Tue, 8 Mar 2016 17:45:28 +0000 (12:45 -0500)]
align arrows
Hunter Haugen [Thu, 3 Mar 2016 19:50:05 +0000 (11:50 -0800)]
Merge pull request #612 from pulecp/master
match rules with -m ttl
Pavel Pulec [Thu, 3 Mar 2016 16:08:43 +0000 (17:08 +0100)]
match rules with -m ttl
TP Honey [Thu, 18 Feb 2016 16:10:55 +0000 (16:10 +0000)]
Merge pull request #611 from puppetlabs/1.8.x
Mergeback 1.8.x to master
Hunter Haugen [Wed, 17 Feb 2016 18:06:51 +0000 (10:06 -0800)]
Merge pull request #610 from UNINETT/master
Add 'ip' and 'pim' to proto
Morten Brekkevold [Wed, 17 Feb 2016 12:07:24 +0000 (13:07 +0100)]
Add ip protocol to puppetlabs-firewall
Morten Brekkevold [Wed, 17 Feb 2016 11:59:47 +0000 (12:59 +0100)]
Add pim protocol to puppetlabs-firewall
Hunter Haugen [Tue, 16 Feb 2016 22:04:00 +0000 (14:04 -0800)]
Merge pull request #609 from bmjen/fix-ver
Fixes version in metadata
Bryan Jen [Tue, 16 Feb 2016 22:02:56 +0000 (15:02 -0700)]
Fixes version in metadata
TP Honey [Tue, 16 Feb 2016 17:03:42 +0000 (17:03 +0000)]
Merge pull request #607 from DavidS/fm-4046-update-msync
(FM-4046) Update to current msync configs [
006831f ]
David Schmitt [Tue, 16 Feb 2016 16:00:12 +0000 (16:00 +0000)]
(FM-4046) Update to current msync configs [
006831f ]
This moves all copyright statements to the NOTICE file in accordance with the ASFs guidelines on applying the Apache-2.0 license.
Hunter Haugen [Thu, 11 Feb 2016 23:12:40 +0000 (15:12 -0800)]
Merge pull request #606 from aequitas/master
(MODULES-3079) Add support for goto argument.
Johan Bloemberg [Thu, 11 Feb 2016 20:22:11 +0000 (21:22 +0100)]
Add support for goto argument.
Jonathan Tripathy [Tue, 9 Feb 2016 13:01:53 +0000 (13:01 +0000)]
Release Prep 1.8.0
Hunter Haugen [Wed, 10 Feb 2016 14:47:47 +0000 (06:47 -0800)]
Merge pull request #605 from jonnytpuppet/modules-2159
Updated acceptance test for modules-2159
Jonathan Tripathy [Wed, 10 Feb 2016 14:31:20 +0000 (14:31 +0000)]
Updated acceptance test for modules-2159
JT (Jonny) [Wed, 10 Feb 2016 14:16:46 +0000 (14:16 +0000)]
Merge pull request #602 from uobnetops/MODULES-2159
(MODULES-2159) ignore the --connlimit-saddr switch when parsing rules
TP Honey [Wed, 10 Feb 2016 10:57:31 +0000 (10:57 +0000)]
Merge pull request #604 from jonnytpuppet/facter_flush
Made Facter flushing specific to a single fact.
Jonathan Tripathy [Wed, 10 Feb 2016 10:49:15 +0000 (10:49 +0000)]
Made Facter flushing specific to a single fact.
Hunter Haugen [Tue, 9 Feb 2016 16:53:04 +0000 (08:53 -0800)]
Merge pull request #603 from jonnytpuppet/modules-3032
(MODULES 3932) - We need to call Facter.flush to clear Facter cache
Jonathan Tripathy [Tue, 9 Feb 2016 16:11:40 +0000 (16:11 +0000)]
(MODULES 3932) - We need to call Facter.flush to clear Facter cache to
get up to date value for :iptables_persistent_version.
TP Honey [Wed, 3 Feb 2016 15:48:59 +0000 (15:48 +0000)]
Merge pull request #583 from cristifalcas/update_iptables
allow iptables package to be updated
Cristian Falcas [Wed, 25 Nov 2015 12:26:10 +0000 (14:26 +0200)]
allow iptables package to be updated
Paul Seward [Mon, 1 Feb 2016 12:05:39 +0000 (12:05 +0000)]
(MODULES-2159) ignore the --connlimit-saddr switch when parsing rules
Workaround for https://tickets.puppetlabs.com/browse/MODULES-2159 (as described by Greg Murphy in that ticket)
On some distributions (notably on Ubuntu 14.04 and above, and Centos7 and above) the --connlimit-saddr switch is added after the rule is applied causing rule_to_hash to ignore the rule. Puppet then attempts (and failes) to re-create the rule every time it runs.
Hunter Haugen [Wed, 27 Jan 2016 16:36:48 +0000 (08:36 -0800)]
Merge pull request #599 from DavidS/fm-4049-update-msync
(FM-4049) update to modulesync_configs
David Schmitt [Mon, 25 Jan 2016 16:01:02 +0000 (16:01 +0000)]
(FM-4049) Update to current msync configs [
2c99161 ]
Helen [Fri, 22 Jan 2016 15:56:57 +0000 (15:56 +0000)]
Merge pull request #600 from jonnytpuppet/gem_version_workaround
Workaround for https://github.com/bundler/bundler/issues/3187
Jonathan Tripathy [Fri, 22 Jan 2016 14:36:40 +0000 (14:36 +0000)]
Workaround for https://github.com/bundler/bundler/issues/3187
David Schmitt [Thu, 21 Jan 2016 15:54:56 +0000 (15:54 +0000)]
Merge pull request #598 from jonnytpuppet/add_debian_8_nodesets
Added Debian 8 nodesets
Jonathan Tripathy [Thu, 21 Jan 2016 15:47:26 +0000 (15:47 +0000)]
Added Debian 8 nodesets
David Schmitt [Thu, 21 Jan 2016 14:54:33 +0000 (14:54 +0000)]
Merge pull request #597 from jonnytpuppet/rspec_core_update
Updated Gemfile to avoid BKR-537
Jonathan Tripathy [Thu, 21 Jan 2016 14:37:15 +0000 (14:37 +0000)]
Updated Gemfile to avoid BKR-537
JT (Jonny) [Fri, 15 Jan 2016 13:36:00 +0000 (13:36 +0000)]
Merge pull request #576 from nward/support_ipv6_nat
Support IPv6 NAT on Linux 3.7+
David Schmitt [Fri, 8 Jan 2016 14:16:24 +0000 (14:16 +0000)]
Merge pull request #578 from abednarik/fix/master/redhat_service_name_references
(MODULES-2783) Missing ip6tables service name
abednarik [Wed, 4 Nov 2015 22:02:56 +0000 (19:02 -0300)]
(MODULES-2783) Missing ip6tables service name
Replaced hardcoded iptables service references with $service_name
variable.
Jesse Lovelace [Thu, 17 Dec 2015 17:59:36 +0000 (11:59 -0600)]
Merge pull request #596 from bmjen/fix-ci
(maint) fixes acceptance tests
Bryan Jen [Thu, 17 Dec 2015 17:58:11 +0000 (10:58 -0700)]
(maint) fixes acceptance tests
Jesse Lovelace [Thu, 17 Dec 2015 15:39:59 +0000 (09:39 -0600)]
Merge pull request #595 from bmjen/fix-ci
(maint) fixes typo in firewall acceptance test.
Bryan Jen [Thu, 17 Dec 2015 15:38:26 +0000 (08:38 -0700)]
(maint) fixes typo in firewall acceptance test.
Bryan Jen [Tue, 15 Dec 2015 15:57:06 +0000 (08:57 -0700)]
Merge pull request #594 from mentat/fix_ci_bug
Fix for CI acceptance fail.
Jesse Lovelace [Tue, 15 Dec 2015 15:35:13 +0000 (09:35 -0600)]
Fix for CI acceptance fail.
TP Honey [Mon, 14 Dec 2015 15:02:16 +0000 (15:02 +0000)]
Merge pull request #593 from mlosapio/feature/log-uid
Adding in log_uid boolean for LOG
Michael LoSapio [Wed, 18 Nov 2015 22:18:39 +0000 (17:18 -0500)]
Adding in log_uid boolean for LOG
Jesse Lovelace [Thu, 10 Dec 2015 18:07:27 +0000 (12:07 -0600)]
Merge pull request #579 from maxvozeler/fix/chain_f_fix
(MODULES-2836) Fix handling of chains that contain '-f'
Max Vozeler [Mon, 16 Nov 2015 13:01:35 +0000 (14:01 +0100)]
Fix handling of chain names that contain -f
TP Honey [Tue, 8 Dec 2015 15:26:56 +0000 (15:26 +0000)]
Merge pull request #592 from puppetlabs/1.7.x
Mergeback 1.7.x
JT (Jonny) [Mon, 7 Dec 2015 16:48:31 +0000 (16:48 +0000)]
Merge pull request #580 from tphoney/release_1.7.2
release prep 1.7.2
David Schmitt [Fri, 4 Dec 2015 15:50:04 +0000 (15:50 +0000)]
Merge pull request #591 from jonnytpuppet/1.7.x_rel_prep_ci_fixes
1.7.x rel prep ci fixes
Jonathan Tripathy [Thu, 3 Dec 2015 15:42:48 +0000 (15:42 +0000)]
Updated logic to debian manifest file
Jonathan Tripathy [Thu, 26 Nov 2015 16:48:18 +0000 (16:48 +0000)]
(MAINT) - Commented out CLUSTERIP tests as there are suspicions that the
ipt module is causing system reboots.
Jonathan Tripathy [Thu, 26 Nov 2015 15:21:31 +0000 (15:21 +0000)]
Unit test fixes
Jonathan Tripathy [Thu, 26 Nov 2015 14:33:23 +0000 (14:33 +0000)]
More file renames
Jonathan Tripathy [Thu, 26 Nov 2015 14:14:15 +0000 (14:14 +0000)]
Rename internal custom nodeset files
Jonathan Tripathy [Wed, 25 Nov 2015 17:41:16 +0000 (17:41 +0000)]
Further nodeset changes from internal CI
Jonathan Tripathy [Tue, 24 Nov 2015 16:54:06 +0000 (16:54 +0000)]
Added nodeset files for internal Puppet CI.
David Schmitt [Thu, 3 Dec 2015 15:48:07 +0000 (15:48 +0000)]
Merge pull request #590 from jonnytpuppet/fact_variable_fix
Updated logic to debian manifest file
Jonathan Tripathy [Thu, 3 Dec 2015 15:42:48 +0000 (15:42 +0000)]
Updated logic to debian manifest file
David Schmitt [Thu, 3 Dec 2015 14:18:07 +0000 (14:18 +0000)]
Merge pull request #589 from DavidS/modules-2866-add-sctp
Add: sctp-protocol to "proto"-Parameter
Nold [Tue, 24 Nov 2015 07:27:34 +0000 (08:27 +0100)]
Add: sctp-protocol to "proto"-Parameter
Helen [Thu, 26 Nov 2015 16:51:20 +0000 (16:51 +0000)]
Merge pull request #588 from jonnytpuppet/hang_fix2
(MAINT) - Commented out CLUSTERIP tests as there are suspicions that the
Jonathan Tripathy [Thu, 26 Nov 2015 16:48:18 +0000 (16:48 +0000)]
(MAINT) - Commented out CLUSTERIP tests as there are suspicions that the
ipt module is causing system reboots.
David Schmitt [Thu, 26 Nov 2015 15:33:15 +0000 (15:33 +0000)]
Merge pull request #587 from jonnytpuppet/unit_test_fix
Unit test fixes
Jonathan Tripathy [Thu, 26 Nov 2015 15:21:31 +0000 (15:21 +0000)]
Unit test fixes
Helen [Thu, 26 Nov 2015 14:34:04 +0000 (14:34 +0000)]
Merge pull request #586 from jonnytpuppet/hang_fix2
More file renames
Jonathan Tripathy [Thu, 26 Nov 2015 14:33:23 +0000 (14:33 +0000)]
More file renames
TP Honey [Thu, 26 Nov 2015 14:16:52 +0000 (14:16 +0000)]
Merge pull request #585 from jonnytpuppet/hang_fix2
Rename internal custom nodeset files
Jonathan Tripathy [Thu, 26 Nov 2015 14:14:15 +0000 (14:14 +0000)]
Rename internal custom nodeset files
JT (Jonny) [Wed, 25 Nov 2015 17:57:10 +0000 (17:57 +0000)]
Merge pull request #584 from jonnytpuppet/hang_fix2
Further nodeset changes from internal CI
Jonathan Tripathy [Wed, 25 Nov 2015 17:41:16 +0000 (17:41 +0000)]
Further nodeset changes from internal CI
TP Honey [Wed, 25 Nov 2015 16:41:08 +0000 (16:41 +0000)]
Merge pull request #582 from jonnytpuppet/hang_fix
Added nodeset files for internal Puppet CI.
Jonathan Tripathy [Tue, 24 Nov 2015 16:54:06 +0000 (16:54 +0000)]
Added nodeset files for internal Puppet CI.
JT (Jonny) [Tue, 24 Nov 2015 15:58:00 +0000 (15:58 +0000)]
Merge pull request #577 from reidmv/modules-1341
(MODULES-1341) Recover when deleting absent rules
tphoney [Fri, 20 Nov 2015 11:59:26 +0000 (11:59 +0000)]
release prep 1.7.2
Bryan Jen [Fri, 20 Nov 2015 16:38:01 +0000 (09:38 -0700)]
Merge pull request #575 from werekraken/security_table
MODULES-2769 - Add security table for iptables.
Reid Vandewiele [Wed, 4 Nov 2015 18:40:20 +0000 (10:40 -0800)]
(MODULES-1341) Recover when deleting absent rules
Some types, specifically the resources type, will call Firewall
instances and then use generate to build and add to the catalog firewall
resources very early in a Puppet run. Later, those resources might be
removed as a side effect of another action, such as shutting down the
firewalld service.
Prior to this commit, Puppet would try to delete firewall resources
which were already absent, and throw an error. This commit adds an
exception catcher which will check to see if the rule being removed is
absent, and if so, consider the change a success even if the firewall
command failed. It will adjust the change message to reflect the
uncertainty over how the rule was removed, though it was verified
removed.