Add debug prints for policy setting, don't commit ruleset in print mode
[project/firewall3.git] / iptables.c
index 9c5f80a..fd230d3 100644 (file)
@@ -105,6 +105,9 @@ void
 fw3_ipt_set_policy(struct fw3_ipt_handle *h, const char *chain,
                    enum fw3_flag policy)
 {
 fw3_ipt_set_policy(struct fw3_ipt_handle *h, const char *chain,
                    enum fw3_flag policy)
 {
+       if (fw3_pr_debug)
+               printf("-P %s %s\n", chain, fw3_flag_names[policy]);
+
        if (h->family == FW3_FAMILY_V6)
                ip6tc_set_policy(chain, fw3_flag_names[policy], NULL, h->handle);
        else
        if (h->family == FW3_FAMILY_V6)
                ip6tc_set_policy(chain, fw3_flag_names[policy], NULL, h->handle);
        else