All of lore.kernel.org
 help / color / mirror / Atom feed
From: "Sébastien RICCIO" <sr@swisscenter.com>
To: xen-devel@lists.xensource.com
Subject: HELP:) vif-common.sh call on xm shutdown / xm destroy
Date: Fri, 23 May 2008 12:04:39 +0200	[thread overview]
Message-ID: <483696B7.5050600@swisscenter.com> (raw)


Dear list,

I'm currently modifying the vif-common.sh script in order to be able
to implement custom iptables rules for different guests.

As I can see, when a guest is created with xm create, vif-common.sh is
called with the "online" command. Perfect.

When the guest shutdown itself, vif-common.sh is not called, neither
when I shut down the guest with "xm shutdown" command.

But if I kill the guest with "xm destroy", the vif-common.sh is called
with command "offline".

Is it right that xm shutdown doesn't call vif-common.sh ?

I was expecting it to be executed when a shutdown is issued, in order
to clean the iptables rules for this particular guest.

Any ideas ?

btw: here is my custom vif-common.sh code:

frob_iptable()
{
if [ "$command" == "online" ]
then
   # Adding custom chain
   iptables -N "$vif"
   if [ -e /etc/xen/fw/$vif.rules ]
   then
     source /etc/xen/fw/$vif.rules
   else
     if [ -e /etc/xen/fw/default.rules ]
     then
       source /etc/xen/fw/default.rules
     else
       iptables -A "$vif" -j ACCEPT
     fi
   fi
    # Forwarding the packets to the right chain
   iptables -A FORWARD -m physdev --physdev-in "$vif" "$@" -j "$vif"
  else
   echo "debug" >>/tmp/debug.log
   # Removing the chain forward
   iptables -D FORWARD -m physdev --physdev-in "$vif" "$@" -j "$vif"
   # Flushing the custom chain
   iptables -F "$vif"
   # Removing the custom chain
   iptables -X "$vif"
fi
}




-- 
Sébastien Riccio
SwissCenter / OpenBusiness SA
sr@openbusiness.com
________________________________________________

OpenBusiness S.A.
World Trade Center
Av Gratta-Paille 1-2        Tel: +41 21 641 1010
CH-1000 Lausanne 30         FAX: +41 21 641 1011
Switzerland                  www.openbusiness.ch
__________________________________________________________________________
Disclaimer

This email is confidential and intended solely for the use of the
individual to whom it is addressed. Any views or opinions presented are
solely those of the author and do not necessarily represent those of the
OpenBusiness Group.
If you are not the intended recipient, be advised that you have received
this email in error and that any use, dissemination, forwarding,
printing, or copy-ing of this email is strictly prohibited.

If you have received this email in error please notify the OpenBusiness
help-desk by telephone on +41 21 641 10 10.


_______________________________________________
Xen-devel mailing list
Xen-devel@lists.xensource.com
http://lists.xensource.com/xen-devel




-- 
Sébastien Riccio
SwissCenter / OpenBusiness SA
sr@openbusiness.com
________________________________________________

OpenBusiness S.A.
World Trade Center
Av Gratta-Paille 1-2        Tel: +41 21 641 1010
CH-1000 Lausanne 30         FAX: +41 21 641 1011
Switzerland                  www.openbusiness.ch
__________________________________________________________________________
Disclaimer

This email is confidential and intended solely for the use of the
individual to whom it is addressed. Any views or opinions presented are
solely those of the author and do not necessarily represent those of the
OpenBusiness Group.
If you are not the intended recipient, be advised that you have received
this email in error and that any use, dissemination, forwarding,
printing, or copy-ing of this email is strictly prohibited.

If you have received this email in error please notify the OpenBusiness
help-desk by telephone on +41 21 641 10 10.

             reply	other threads:[~2008-05-23 10:04 UTC|newest]

Thread overview: 4+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2008-05-23 10:04 Sébastien RICCIO [this message]
2008-05-23 10:47 ` HELP:) vif-common.sh call on xm shutdown / xm destroy Ian Jackson
2008-05-23 10:58   ` Sébastien RICCIO
2008-06-13 17:43   ` Christopher Thunes

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=483696B7.5050600@swisscenter.com \
    --to=sr@swisscenter.com \
    --cc=xen-devel@lists.xensource.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.