aboutsummaryrefslogtreecommitdiffstats
path: root/templates/usr_local_bin_safepf.sh
diff options
context:
space:
mode:
authorJan Tuomi <jan@jantuomi.fi>2025-11-13 18:45:10 +0200
committerJan Tuomi <jan@jantuomi.fi>2025-11-13 18:45:10 +0200
commit28379e016d4ab80a0d0529d6ca08083c75a0be4d (patch)
treeadf5c7edbf5903de6d7023db200bbd74172a41c4 /templates/usr_local_bin_safepf.sh
parent1df3d09ae131bf4709820205b562a04c22bdd85b (diff)
WIP
Diffstat (limited to 'templates/usr_local_bin_safepf.sh')
-rw-r--r--templates/usr_local_bin_safepf.sh36
1 files changed, 36 insertions, 0 deletions
diff --git a/templates/usr_local_bin_safepf.sh b/templates/usr_local_bin_safepf.sh
new file mode 100644
index 0000000..1b6efee
--- /dev/null
+++ b/templates/usr_local_bin_safepf.sh
@@ -0,0 +1,36 @@
+#!/bin/sh
+
+set -eu
+
+cmd="pfctl -f /etc/pf.conf"
+read -p "Run this command (y/n)? $cmd " answer
+if [ "$answer" = "y" ]; then
+ (set -x; $cmd)
+else
+ exit 0
+fi
+
+cmd="service pf restart"
+read -p "Run this command (y/n)? $cmd " answer
+if [ "$answer" = "y" ]; then
+ (set -x; $cmd)
+else
+ exit 0
+fi
+
+timeout=60
+echo "Running safety timeout ($timeout seconds). Press CTRL-C if everything is working."
+while [ $timeout -gt 0 ]
+do
+ sleep 1
+ timeout=$((timeout - 1))
+ echo -n "."
+done
+
+echo "Timeout reached. Enabling empty pf rules"
+
+set -x
+mv /etc/pf.conf /etc/pf.conf.locked_out
+echo "" > /etc/pf.conf
+pfctl -f /etc/pf.conf
+service pf restart