From 28379e016d4ab80a0d0529d6ca08083c75a0be4d Mon Sep 17 00:00:00 2001 From: Jan Tuomi Date: Thu, 13 Nov 2025 18:45:10 +0200 Subject: WIP --- templates/usr_local_bin_safepf.sh | 36 ++++++++++++++++++++++++++++++++++++ 1 file changed, 36 insertions(+) create mode 100644 templates/usr_local_bin_safepf.sh (limited to 'templates/usr_local_bin_safepf.sh') diff --git a/templates/usr_local_bin_safepf.sh b/templates/usr_local_bin_safepf.sh new file mode 100644 index 0000000..1b6efee --- /dev/null +++ b/templates/usr_local_bin_safepf.sh @@ -0,0 +1,36 @@ +#!/bin/sh + +set -eu + +cmd="pfctl -f /etc/pf.conf" +read -p "Run this command (y/n)? $cmd " answer +if [ "$answer" = "y" ]; then + (set -x; $cmd) +else + exit 0 +fi + +cmd="service pf restart" +read -p "Run this command (y/n)? $cmd " answer +if [ "$answer" = "y" ]; then + (set -x; $cmd) +else + exit 0 +fi + +timeout=60 +echo "Running safety timeout ($timeout seconds). Press CTRL-C if everything is working." +while [ $timeout -gt 0 ] +do + sleep 1 + timeout=$((timeout - 1)) + echo -n "." +done + +echo "Timeout reached. Enabling empty pf rules" + +set -x +mv /etc/pf.conf /etc/pf.conf.locked_out +echo "" > /etc/pf.conf +pfctl -f /etc/pf.conf +service pf restart -- cgit v1.3