* Disabled gputest
* The package is failing to install.
* Now using Midori GTK3 build
* GTK2 was pulled from main repos for security reasons
* Removed warnings about missing UFD
* For use with live sessions
* Wallpaper updated for live sessions
* Wallpaper is now set at startup
* Checks for UFD source but defaults to included file
* Bugfix: Wallpaper is now set for multiple monitor/workspace setups
* Disabled choose-mirror service
* Better permission handling
* build-wk now checks if running as root
* build-wk now sets permissions before calling build.sh
* Should prevent build failues as build.sh expects files to be owned by root
* build-wk sets ownership back to builduser.builduser during cleanup
* Better menu for HW-Diags
* The script now returns to the menu after running a selection
* Unless the mode was set directly by passing a valid argument
* NOTE: This allows for easier use in CLI mode
* Add delay before removing /media/wktech
* Adjusted TMP_DIR in build-wk
* Fixed path to custom repo
* Trimming the fat
* hostname / hosts now configured by customize_airootfs.sh
* removed files from etc that were at default settings
* removed grml zsh config since oh-my-zsh/lean is used
* Defined a LOG_DIR for build-wk
* Introducing libinput
* Switched to libinput over synaptics as it has been deprecated.
* Should restore touchpad functionality going forward.
* Full mount path SHOULD now be displayed for mount-all-volumes.
* Added CLI Screensavers
* diag-network works now
* network connection tests now passes all ipv4 private ip ranges
* 10.0.0.0/8, 172.16.0.0/12, & 192.168.0.0/24
* need to add ipv6 at some point
* hw-diag menu flow adjusted
* New hostname and more bugfixes
* hostname switched to wk-arch
* ufw package is now installed
* adjusted upload section of hw-diags
* Added alias for start-wifi
* Booting to CLI mode will autologin wktech
* When booting to the CLI the motd shows some avail commands
* Adjusted HW-Diags menu for use in CLI mode
39 lines
1.4 KiB
Text
39 lines
1.4 KiB
Text
*filter
|
|
:ufw6-user-input - [0:0]
|
|
:ufw6-user-output - [0:0]
|
|
:ufw6-user-forward - [0:0]
|
|
:ufw6-before-logging-input - [0:0]
|
|
:ufw6-before-logging-output - [0:0]
|
|
:ufw6-before-logging-forward - [0:0]
|
|
:ufw6-user-logging-input - [0:0]
|
|
:ufw6-user-logging-output - [0:0]
|
|
:ufw6-user-logging-forward - [0:0]
|
|
:ufw6-after-logging-input - [0:0]
|
|
:ufw6-after-logging-output - [0:0]
|
|
:ufw6-after-logging-forward - [0:0]
|
|
:ufw6-logging-deny - [0:0]
|
|
:ufw6-logging-allow - [0:0]
|
|
:ufw6-user-limit - [0:0]
|
|
:ufw6-user-limit-accept - [0:0]
|
|
### RULES ###
|
|
|
|
### tuple ### allow any 22 ::/0 any ::/0 in
|
|
-A ufw6-user-input -p tcp --dport 22 -j ACCEPT
|
|
-A ufw6-user-input -p udp --dport 22 -j ACCEPT
|
|
|
|
### END RULES ###
|
|
|
|
### LOGGING ###
|
|
-A ufw6-after-logging-input -j LOG --log-prefix "[UFW BLOCK] " -m limit --limit 3/min --limit-burst 10
|
|
-A ufw6-after-logging-forward -j LOG --log-prefix "[UFW BLOCK] " -m limit --limit 3/min --limit-burst 10
|
|
-I ufw6-logging-deny -m conntrack --ctstate INVALID -j RETURN -m limit --limit 3/min --limit-burst 10
|
|
-A ufw6-logging-deny -j LOG --log-prefix "[UFW BLOCK] " -m limit --limit 3/min --limit-burst 10
|
|
-A ufw6-logging-allow -j LOG --log-prefix "[UFW ALLOW] " -m limit --limit 3/min --limit-burst 10
|
|
### END LOGGING ###
|
|
|
|
### RATE LIMITING ###
|
|
-A ufw6-user-limit -m limit --limit 3/minute -j LOG --log-prefix "[UFW LIMIT BLOCK] "
|
|
-A ufw6-user-limit -j REJECT
|
|
-A ufw6-user-limit-accept -j ACCEPT
|
|
### END RATE LIMITING ###
|
|
COMMIT
|