On December 4, 2014 10:31:30 AM PST, Andrew Savchenko <birc...@gentoo.org> 
wrote:
>As for later loop detector, it may break need dependency. Current
>need dependency for iptables is fsck <- localmount <- iptables, so
>it is still unlikely that your daemon will be caught in such
>need-only loop. Though on author's request later loop solver is out
>of scope of this discussion now...

I was indeed talking about the late loop detector, not the early loop detector. 
I agree that the dependencies for iptables are pretty simple right now; I was 
more pointing out that even if the user modifies them to be complicated enough 
to have a loop, it would be preferable to fail secure (start nothing) rather 
than open (omit iptables).

As the late loop detector is no longer under consideration, however, I retract 
my question.

-- 
Christopher Head

Reply via email to