Bug #4088


Buggy squidgurd config file is created

Added by Volker Kuhlmann over 8 years ago. Updated about 2 years ago.

Viktor Gurov
Target version:
Start date:
Due date:
% Done:


Estimated time:
Plus Target Version:
Affected Version:
Affected Plus Version:
Affected Architecture:


The config file that is generated for squidguard 1.4_4 pkg v.1.9.6 is buggy in two ways, leading to unexpected and dangerous behaviour.

1) Do not write out sources for disabled ACLs, or squidguard treats these
sources as "always pass"!

2) Squidguard doesn't know log statements in the action block for sources in the
acl block.

Patch attached.

Files (2.32 KB) Fix 2 areas where teh created config is buggy. Volker Kuhlmann, 12/09/2014 05:44 AM
squidguard-src-disabled-and-log-statements_1.9.15.diff (5.25 KB) squidguard-src-disabled-and-log-statements_1.9.15.diff Fix for both problems, pfsense pkg 1.9.15. Volker Kuhlmann, 09/28/2015 07:06 PM
Actions #1

Updated by Volker Kuhlmann about 8 years ago

Issue 1) renders squidguard useless because it bypasses it entirely.

I can't seem to change the bug priority. I was hoping the squidguard package updates actually fix problems :-(

Actions #2

Updated by Kill Bill over 7 years ago

1/ The patch appears incomplete at least regarding #2 - consider
2/ Please, submit any fixes as pull requests on GitHub:

Actions #3

Updated by Volker Kuhlmann over 7 years ago

If you can't have log statements in ACL blocks then you can't have log statements in ACL blocks, so best to give up on that idea. The case is already been taken care of by the log statement in the dest block, the ACL statements are only about whether to pass the request, whether that is decided by time is irrelevant. As I understand it your objection is invalid.
Do not put unexpected config material into squidguard ever, it is very unpredictable then!

Sorry, no github yet. I have already provided the fix for problems, running patch should be managable. I am attaching a new patch for those who don't want to wait for a substantally broken squidguard to get sorted out.

Actions #4

Updated by Viktor Gurov about 2 years ago

1) Do not write out sources for disabled ACLs, or squidguard treats these

sources as "always pass"!


Actions #5

Updated by Renato Botelho about 2 years ago

  • Status changed from New to Feedback
  • Assignee set to Viktor Gurov

PR has been merged. Thanks!


Also available in: Atom PDF