Bug 2224648

Summary: fix: reload on resetting to defaults
Product: Red Hat Enterprise Linux 8 Reporter: Rich Megginson <rmeggins>
Component: rhel-system-rolesAssignee: Rich Megginson <rmeggins>
Status: VERIFIED --- QA Contact: David Jež <djez>
Severity: unspecified Docs Contact:
Priority: unspecified    
Version: 8.9CC: djez, jharuda, rhel-cs-system-management-subsystem-qe, spetrosi, vdanek
Target Milestone: rcKeywords: Triaged
Target Release: 8.9Flags: rmeggins: needinfo? (vdanek)
Hardware: Unspecified   
OS: Unspecified   
Whiteboard: role:firewall
Fixed In Version: rhel-system-roles-1.22.0-0.19.el8 Doc Type: Enhancement
Doc Text:
Enhancement: Make resetting to defaults reload instead of restart firewalld Reason: Reloading in firewalld should successfully complete the configuration reset, and restarting adds downtime which can be used to open a connection that persists after firewalld has finishes restarting; this connection can be used to bypass firewall rules, since firewalld will not block traffic from active connections. Result: Minimal downtime when using `previous: replaced` Addresses an issue brought up in #140, where due to the restart on resetting to defaults, the feature may not be suitable for production environments.
Story Points: ---
Clone Of: 2223764 Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2223764    
Bug Blocks:    

Description Rich Megginson 2023-07-21 18:51:16 UTC
+++ This bug was initially created as a clone of Bug #2223764 +++

Enhancement:
Make resetting to defaults reload instead of restart firewalld

Reason:
Reloading in firewalld should successfully complete the configuration reset, restarting adds downtime

Result:
Minimal downtime when using previous: replaced

Addresses an issue brought up in https://github.com/linux-system-roles/firewall/issues/140 , where due to the restart on resetting to defaults, the feature may not be suitable for production environments.
see https://github.com/linux-system-roles/firewall/pull/159