From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.6 (2021-04-09) on gnuweeb.org X-Spam-Level: X-Spam-Status: No, score=-1.2 required=5.0 tests=ALL_TRUSTED,DKIM_SIGNED, DKIM_VALID,DKIM_VALID_AU,DKIM_VALID_EF autolearn=ham autolearn_force=no version=3.4.6 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=gnuweeb.org; s=default; t=1688421607; bh=WnFYDc7pkaXvD36GByBuzljpALrP4cB3Lbe3trI+eA4=; h=References:In-Reply-To:From:Date:Subject:To:Cc; b=rTzaNYTJAyMkQU3qutbOe0RCBTlBVrTqVAl8cuagTBJUAO+BMlDgO9c3HWZ4XAM3U 9kL4lldQP/vyrz2PU5WGLvkmAMPeypIoS7yq6HRM10MjzjKulkWstFgYBHKLGtstpI xZCbwExL9cYdmwlneU1kMOzq7KJdy2Ntaxw2wRIS9DxoHDmwtHnr+OIasVaTyxbg/M w3+2RXQhd2ExMZo+5C2q1WHNWunyj374dL5Jg3KaXXDw85wmkj8anUcokE171xQMJa GmmlofVTFdHL2Nt4jG8vD5AN6+o37IRzIVYmY/P63ksLPzWDSuFXP2eit5bDorQ76x PzrCtGXgt130Q== Received: from mail-lj1-f176.google.com (mail-lj1-f176.google.com [209.85.208.176]) by gnuweeb.org (Postfix) with ESMTPSA id 7F87923EB0C for ; Tue, 4 Jul 2023 05:00:07 +0700 (WIB) Received: by mail-lj1-f176.google.com with SMTP id 38308e7fff4ca-2b5c231c23aso79412071fa.0 for ; Mon, 03 Jul 2023 15:00:07 -0700 (PDT) X-Gm-Message-State: ABy/qLYQVvegHKAOO8YXN19wNZXFogHUTVCQ/F1ah84XT5kqTMNSnTKb Yj24LGHz4ZJz+eBml0EKX4O0jGFYgiyLBXNHTzk= X-Google-Smtp-Source: APBJJlGJI+ZLQPRLHd+T3q1A/hSvaPPEHMfnihlfhjSgEXqkPCpuRFxeHXpcfUWMtNVWPUzOi4xaQ4T/0KymhhaTDSw= X-Received: by 2002:a05:6512:718:b0:4f9:557e:35ae with SMTP id b24-20020a056512071800b004f9557e35aemr6765536lfs.19.1688421605172; Mon, 03 Jul 2023 15:00:05 -0700 (PDT) MIME-Version: 1.0 References: In-Reply-To: From: Alviro Iskandar Setiawan Date: Tue, 4 Jul 2023 04:59:52 +0700 X-Gmail-Original-Message-ID: Message-ID: Subject: Re: [PATCH server-haj002] init_net: Allow incoming traffic from the master namespace To: Ammar Faizi Cc: Michael William Jonathan , "GNU/Weeb Mailing List" Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable List-Id: On Tue, Jul 4, 2023 at 4:47=E2=80=AFAM Ammar Faizi wrote: > When spawning a shell in the master namespace, I can't perform DNS > requests because the systemd-resolved lives in the default namespace. > This requires the DNS resolver in /etc/resolv.conf to be changed to > 10.3.3.2, then the default namespace has to allow DNS query traffics > from 10.3.3.1. > > Let's just completely allow internal source network within CIDR source > address 10.3.3.0/24. > > Signed-off-by: Ammar Faizi applied, tq -- Viro