From 709dcb5279fdda8f40dc3baefa6e0b58a5ccfb61 Mon Sep 17 00:00:00 2001 From: dhartmei <> Date: Tue, 14 Jun 2005 22:49:06 +0000 Subject: [PATCH] split the dummy ruleset pfctl -f - -e into separate -f - and -e. relevant when the dummy ruleset can't be loaded, we still want to enable pf, otherwise the real ruleset (even if that does load correctly) won't be active. might happen on a non-GENERIC kernel or after an update (before /etc is manually updated). reported by Jim Rees. ok frantzen@ --- src/etc/rc | 5 +++-- 1 file changed, 3 insertions(+), 2 deletions(-) diff --git a/src/etc/rc b/src/etc/rc index e3245baf..4fa90438 100644 --- a/src/etc/rc +++ b/src/etc/rc @@ -1,4 +1,4 @@ -# $OpenBSD: rc,v 1.268 2005/06/02 20:09:38 tholo Exp $ +# $OpenBSD: rc,v 1.269 2005/06/14 22:49:06 dhartmei Exp $ # System startup script run by init on autoboot # or after single-user. @@ -234,7 +234,8 @@ if [ X"${pf}" != X"NO" ]; then RULES="$RULES\npass out proto udp from any to any port { 111, 2049 }" ;; esac - echo $RULES | pfctl -f - -e + echo $RULES | pfctl -f - + pfctl -e fi sysctl_conf