On December 4, 2014 10:31:30 AM PST, Andrew Savchenko <birc...@gentoo.org> wrote: >As for later loop detector, it may break need dependency. Current >need dependency for iptables is fsck <- localmount <- iptables, so >it is still unlikely that your daemon will be caught in such >need-only loop. Though on author's request later loop solver is out >of scope of this discussion now...
I was indeed talking about the late loop detector, not the early loop detector. I agree that the dependencies for iptables are pretty simple right now; I was more pointing out that even if the user modifies them to be complicated enough to have a loop, it would be preferable to fail secure (start nothing) rather than open (omit iptables). As the late loop detector is no longer under consideration, however, I retract my question. -- Christopher Head