From 299a512c8b7148a3f4e8db8322484841bfdf2c98 Mon Sep 17 00:00:00 2001 From: whd <7058128+superwhd@users.noreply.github.com> Date: Wed, 12 Jan 2022 13:24:07 +0800 Subject: [PATCH] [firewall] disable firewall by default (#7305) The firewall feature should not be enabled on some targets, e.g. ot-daemon. Although leaving it enabled does not break the behavior, it creates confusing logs. --- etc/cmake/options.cmake | 5 +++++ src/posix/platform/openthread-posix-config.h | 8 -------- 2 files changed, 5 insertions(+), 8 deletions(-) diff --git a/etc/cmake/options.cmake b/etc/cmake/options.cmake index 9d31ecac0..fc1a39bec 100644 --- a/etc/cmake/options.cmake +++ b/etc/cmake/options.cmake @@ -360,6 +360,11 @@ if(OT_UPTIME) target_compile_definitions(ot-config INTERFACE "OPENTHREAD_CONFIG_UPTIME_ENABLE=1") endif() +option(OT_FIREWALL "enable firewall") +if (OT_FIREWALL) + target_compile_definitions(ot-config INTERFACE "OPENTHREAD_POSIX_CONFIG_FIREWALL_ENABLE=1") +endif() + option(OT_FULL_LOGS "enable full logs") if(OT_FULL_LOGS) if(NOT OT_LOG_LEVEL) diff --git a/src/posix/platform/openthread-posix-config.h b/src/posix/platform/openthread-posix-config.h index 2bb116672..49de56500 100644 --- a/src/posix/platform/openthread-posix-config.h +++ b/src/posix/platform/openthread-posix-config.h @@ -202,14 +202,6 @@ * ip6tables -A $OTBR_FORWARD_INGRESS_CHAIN -p ip -j ACCEPT * */ -#ifdef __linux__ -#if OPENTHREAD_CONFIG_BORDER_ROUTER_ENABLE & OPENTHREAD_CONFIG_PLATFORM_NETIF_ENABLE -#ifndef OPENTHREAD_POSIX_CONFIG_FIREWALL_ENABLE -#define OPENTHREAD_POSIX_CONFIG_FIREWALL_ENABLE 1 -#endif -#endif -#endif - #ifndef OPENTHREAD_POSIX_CONFIG_FIREWALL_ENABLE #define OPENTHREAD_POSIX_CONFIG_FIREWALL_ENABLE 0 #endif