|
From: Kevin Z. <kev...@gm...> - 2015-08-14 14:25:32
|
On 08/14/2015 09:06, jonetsu wrote: > This is a Debian platform. The version is 1.5. If possible, you should upgrade to 1.6.0. > I got the tarball generated by the web site and looked at the > Changes file under 1.6 section, and did not see anything > pertaining to this lock problem. The code does not mention > 'xlock' specifically. You're looking for the last line of the v1.6.0 ChangeLog: "Wait for xtables lock when using iptables command (James Harris)" > If I consider sshguard as a black box, then what I thought of > doing is to add a --wait (-w) switch to my iptables call, which > will make iptables wait until the xlock is removed. That amount > of time looks like rather short, since the xlock condition does > not happen every time. Looks like it's dependent on the CPU being > jusy a bit too busy at that time, from some other process. This is how the issue was fixed in v1.6.0. > I'm curious about how a lock problem appeared *within* > sshguard... Can you explain what the problem was ? My guess is that another program is running 'iptables', or another SSHGuard command did not finish. I'm not entirely sure because I don't run 'iptables' myself. Best, Kevin Zheng -- Kevin Zheng kev...@gm... | ke...@kd... | PGP: 0xC22E1090 |