libnftables1-0.9.8-150300.3.6.1<>,aԉdb'p9|@hKijn'xh%z<+P;yVQJ};Kf##lB?ܴN„RTץ&-Lh WDf 9$ws`"Ћ} 㠿ͺ[22e|?C KdfF.΍ 89THzNitrQeWqǾŊK-RZUhiʮ̢|&CW{5c_2\(dbd'GSIVX ̂X3Z>@(`?(Pd " I ;AHP T X `  <(89 :>$@%F%G%$H%,I%4X%8Y%D\%l]%t^%b%c&Od&e&f&l&u&v&w'x'y'z'((( (LClibnftables10.9.8150300.3.6.1nftables firewalling command interfacelibnftables is the nftables command line interface placed into a library.db'sheep67 SUSE Linux Enterprise 15SUSE LLC GPL-2.0-onlyhttps://www.suse.com/System/Librarieshttps://netfilter.org/projects/nftables/linuxx86_64 db'db'df70df6c88d8a8b52cbf0170ce4cef49faeb7dc67620c93f3375c9f4e86bb2celibnftables.so.1.0.0rootrootrootrootnftables-0.9.8-150300.3.6.1.src.rpmlibnftables.so.1()(64bit)libnftables1libnftables1(x86-64)@@@@@@@@@@@@@@@@@@@@@    /sbin/ldconfig/sbin/ldconfiglibc.so.6()(64bit)libc.so.6(GLIBC_2.14)(64bit)libc.so.6(GLIBC_2.15)(64bit)libc.so.6(GLIBC_2.2.5)(64bit)libc.so.6(GLIBC_2.22)(64bit)libc.so.6(GLIBC_2.27)(64bit)libc.so.6(GLIBC_2.3)(64bit)libc.so.6(GLIBC_2.3.4)(64bit)libc.so.6(GLIBC_2.4)(64bit)libc.so.6(GLIBC_2.7)(64bit)libc.so.6(GLIBC_2.8)(64bit)libgmp.so.10()(64bit)libjansson.so.4()(64bit)libmnl.so.0()(64bit)libmnl.so.0(LIBMNL_1.0)(64bit)libnftnl.so.11()(64bit)libnftnl.so.11(LIBNFTNL_11)(64bit)libnftnl.so.11(LIBNFTNL_13)(64bit)libnftnl.so.11(LIBNFTNL_14)(64bit)libnftnl.so.11(LIBNFTNL_15)(64bit)libnftnl.so.11(LIBNFTNL_16)(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)3.0.4-14.6.0-14.0-15.2-14.14.3dGbo`_ ^@^ۅ@^@^@]7@]N@]Z@\C@[@ZZ@Z@Zu@Z]@YXY@WPU@U`kTmatthias.gerstner@suse.commatthias.gerstner@suse.comjengelh@inai.dejengelh@inai.dejengelh@inai.dejengelh@inai.dejengelh@inai.dejengelh@inai.dejengelh@inai.dejengelh@inai.dejengelh@inai.destefan.bruens@rwth-aachen.dejengelh@inai.dejengelh@inai.dejengelh@inai.dejengelh@inai.dejengelh@inai.dejengelh@inai.dejengelh@inai.dejengelh@inai.dejengelh@inai.dejengelh@inai.demrueckert@suse.dejengelh@inai.de- add 0001-evaluate-reject-support-ethernet-as-L2-protocol-for-.patch: this fixes a crash in nftables if layer2 reject rules are processed (e.g. Ethernet MAC address based reject rich rule in firewalld, bsc#1210773).- add 0001-cache-check-for-NULL-chain-in-cache_init.patch: this fixes rare crashes that could occur e.g. in firewalld (bsc#1197606).- Update to release 0.9.8 * Complete support for matching ICMP header content fields. * Added raw tcp option match support. * Added ability to check for the presence of any tcp option. * Support for rejecting traffic from the ingress chain.- Update to release 0.9.7 * Support for implicit chains * Support for ingress inet chains * Support for reject from prerouting chain * Support for --terse option in json * Support for the reset command with json- Update to release 0.9.6 * Fix two ASAN runtime errors- Update to release 0.9.5 * Support for set counters. * Support for restoring set element counters via nft -f. * Counter support for flowtables. * typeof concatenations support for sets. * Support for concatenated ranges in anonymous sets. * Allow to reject packets with 802.1q from the bridge family. * Support for matching on the conntrack ID. - Drop anonset-crashfix.patch (upstream solved differently)- Add anonset-crashfix.patch [boo#1171321]- Update to release 0.9.4 * Add a helper for concat expression handling. * Add "typeof" build/parse/print support.- Add json, python [boo#1158723]- Update to release 0.9.3 * meta: Introduce new conditions "time", "day" and "hour". * src: add ability to set/get secmarks to/from connection. * flowtable: add support for named flowtable listing. * flowtable: add support for delete command by handle. * json: add support for element deletion. * Add `-T` as the short option for `--numeric-time`. * meta: add ibrpvid and ibrvproto support- Update to new upstream release 0.9.2 * Transport header port matching, e.g. "th dport 53" * Support for matching on IPv4 options * Support for synproxy- Remove unused dblatex BuildRequires, only needed for the optional and disabled PDF generation (same contents as shipped manpage).- Update to new upstream release 0.9.0 * Support to check if packet matches an existing socket. * Support to limit number of active connections by arbitrary criteria, such as ip addresses, networks, conntrack zones or any combination thereof. * Added support for "audit" logging.- Update to new upstream release 0.8.5 * support to add/insert a rule at a given index position * meter statement now supports a configureable upper max size * timeouts for sets can now be specified in milliseconds * re-add iptables-like empty skeleton rulesets- Update to new upstream release 0.8.4 * Support to match IPv6 segment routing headers. * New "meta ibrname" and "meta obrname" arguments to match the name of the logical bridge a packet is passing through. These new names replace the old (misnamed) "ibriport"/"obriport". * `nft -a` will now show handle identifier for all objects, including tables and chains. * nft can now delete objects by their handle number. * Support to update maps from the ruleset (packet path). * the "--echo" option now prints handle id for tables and object too. * `nft -f -` will now read from standard input * Support for flow tables, cf. man page or https://lwn.net/Articles/738214/ .- Update to new upstream release 0.8.3 * raw payload support to match headers that do not yet have received a mnemonic.- Update to new upstream release 0.8.2 * add secpath support- Update to new upstream release 0.8.1 * This release deprecates the "flow table" syntax in favor of "meter".- Update to new upstream release 0.8 * This release contains new features available up to the (upcoming) Linux 4.14 kernel release: * Support for stateful objects, these objects are uniquely identified by a user-defined name, you can refer to them from rules, and there is a well established interface to operate with them. * Sort set elements when listing them, from lower to largest. * TCP option matching and mangling support. This includes TCP maximum segment size mangling. * Add new "-s" option for listings without stateful information. * Add new -c/--check option for nft, to tests if your ruleset loads fine, into the kernel, this is a dry run mode. * Connection tracking helper support. * Add --echo option, to print the handle that the kernel allocates to uniquely identify rules. * Conntrack zone support * Symmetric hash support * Add support to include directories from nft natives scripts, files are loaded in alphanumerical order. * Allow to check if IPv6 extension header or TCP option exists or is missing. * Extend quota support to display used bytes. * Add ct average matching, to match average bytes per packet a connection has transferred so far, to map the existing feature available in the iptables connbytes match. * Allow to flush maps and flow tables. * Allow to embed set definition into an existing set. * Conntrack event filtering support via rule.- Update to new upstream release 0.7 * Add new fib expression, which can be used to obtain the output interface from the route table based on either source or destination address of a packet. * Support hashing of any arbitrary key combination, eg. * Add number generation support. Useful for round-robin packet mark setting. * Add quota support, eg. * Introduce routing expression, for routing related data with support for nexthop * Notrack support, to explicitly skip connection tracking for matching packets. * Support to set non-byte bound packet header fields, including checksum adjustment. * Add 'create set' and 'create element' commands. * Allow to use variable reference for set element definitions. * Allow to use variable definitions from element commands. * Add support to flush set. You can use this new command to remove all existing elements in a set. * Inverted set lookups. * Honor absolute and relative paths via include file, where: * Support log flags, to enable logging TCP sequence and options. * tc classid parser support, eg. * Allow numeric connlabels, so if connlabel still works with undefined labels.- Update to new upstream release 0.6 * Rules may be replaced now * Flow table support (requires Linux >= 4.3) * Support for tracing * Ratelimiting now supports units like bytes/second. * Matchinv VLAN IDs, DSCP/ECN, ICMP RtAdv & RtSol- Update to new upstream release 0.5 * Support combinations of two or more selectors to build a tuple * Timeout support for sets * Dormant flag for tables * Default chain policy specifiable on creation- set the url to the project page - pass --disable-silent-rules to configure to allow gcc post build check to work- Update to new upstream release 0.4 * Since Linux 3.18: support for global ruleset operations * Since 3.17: full logging support for all the families, including nfnetlink_log * 3.16: automatic selection of the optimal set implementation * 3.14: reject support for ip, ip6 and inet * 3.18: reject support for bridge, and reject icmpx abstraction * 3.18: masquerade support * 3.19: redirect support * Extend meta to support pkttype, cpu and devgroup matching./sbin/ldconfig/sbin/ldconfigsheep67 16841542460.9.8-150300.3.6.10.9.8-150300.3.6.1libnftables.so.1libnftables.so.1.0.0/usr/lib64/-fmessage-length=0 -grecord-gcc-switches -O2 -Wall -D_FORTIFY_SOURCE=2 -fstack-protector-strong -funwind-tables -fasynchronous-unwind-tables -fstack-clash-protection -gobs://build.suse.de/SUSE:Maintenance:28999/SUSE_SLE-15-SP3_Update/ed4025453dccbe5250bf320898c5bdb1-nftables.SUSE_SLE-15-SP3_Updatedrpmxz5x86_64-suse-linuxELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=32550c3dd59c2e14e92cf1fb2c0139333820733c, strippedPRRRR RR RR RR RRRRRRRRRR RxWR uZ4PFutf-8090be6ba5e1cf38667efc3c1375a71a0b147e399d6d458e0393ad86d338cc758?7zXZ !t/G5 ]"k%AKqx1@Q¥|p縱q2%&0܃oSpY)CiC.68E* @ ?g՞T@YRaIS%-CrX*t*x3|7@,L"Kݣ5V2 ͏5&  %#n}h2kaIXL>S+E#lXa~]G#nH6Ix@āD۬,ZƎ: <.^؁bߊ;!Rz߄ =0:}0X|X!5@Eve=5rq_w9i@̖= ܰػ)ҪD?Z| i*#2Ʊ`w1Az2L θi u@S4;4|l}QՈoPNh4-Q=lI3l^i2ߖGTK΃~UB)LǦ$]VDl4)-Nɟd[5waXvi^zʣqbO5T>2=#dhX3yFyAHٜzt/N @QJJ(3o&MFȖ~T=1?:MVrg]s#-y+o&#yoGCm h0,u<|L R"EkmE$bOF3`@{8n߂\8bHl#>55 GggTQ77o VmU= "A|UTƅfG`  m3ӟE;Ƣp- Li<DJ&JtE'ӰbY5 {9Kw/Hܕgyx&*V"RU25 _t Sdx2yg:sxbKKbΦ[B|%1*knlY3u޻*18Ñi o0+"!R/jJ`LCRal$+hqKLPh ~Xw,/7cڨ1  /\XL+LR3 z ?IEN=^&K*dg1etϷS P]wc%5p={x#rc7)<_,re<"c"9sfCc|,τBxu_?giqL7% _=g mwB/{o] ZНPz,,vvj3q۶pce^s4z_)$j ɔ&(]ANK0\3$?qj埇dJ">uN'C^gcŤdU&N Po$iCy:e]rjsj CsM%b{t$O[JhI:UAOhcbݭ߹s}9,ి~ꦄ:+;5hvo?&IJh lsMr0|~k&R@sa~ .x79;D XR{hK,)smi񢨥TRrcnzc9_&zgN:6jI[rD \X'"5<@&c7Mb8sy=8]ȴ$4 4U?ٗR=L-7| YNz-3ѳw(魪0VwGPR{ ;5w7&5nwjuEQD{tr:~7ɓaeznQ,̻^_"m>⦩W;zՑ9Og rC8 i xZyps$/BK4N"⫬iVl<0\ Dgp:8[o&# =8HaVԥkzBFЮjS)Fm;+[U.3R0Ldس6z_~:uxP ǸGN"Ɩh5JVT"rR Q-|YB *ܦ,Zi Ϸb]C/=྽R/RFϊAjݻ.WFcdx5Ax$`s^_ qE'"jp:wCެy|uALAO"cw77cOU>f\iI]l_/( *Q\(LSyl<XuG Q? G9s[/U$з@\_i2ŀu_XZԘy/~ժ7/IO0q Ӡ FD逝q[Ҍn_B#ݚ5=&Y) ->OHG1(z޹?,RaHTJZ$GTm|Xӣ/"j&LH5KO/y-l2לl;+8ROFEge$| { @)}I&>sYϩRp:Qh7v?Y*W$MmvHdڕ$ R\폑0Si+ʶ(gtI|YBGp!s%}Ӱk˔Wq9꒍'D͡%IEF<%ABU -{MMhYB ӏӾX)%}7/q܈C~ tӿÓMt 2ܢ{>)\05Nk *:E6!]kB:)OS@UɾX׏2cEΦaM)*p2P0%:z R"-BӒy2^Qc:B^(_FL31txE) % K .wtM39V|}A]y؉?w] ;%@q-e )gkO_ B`8=@)'vxBT!$şĻ~ 7ȎY m/Θ>YmtR=( j30^(8%*eL\C7A*a.jbVTǟPȝB"~4zn|r-)}JZF6;bK~GbMCⳇwrICp}ǧcѕic/ 5 l`l]5>9=%r +.;MAzo=悻nԒ9#i K}%7; &%MYsǿp*l7?s;Wτ  ށEpLg^6+S} u!=4Z=[yF(IJ?O-SPjTopbUKV0_.󼨯$s1fZT$_ze.E|V5xsCD is .0KcHo^vohfڌa5nsLL5 YE\9:LV__>&G5\@S90׊jb̶#;~T,ćhk 5nOn°W>fyE!4ҼAҿ'tt3 ]|) oDB9+P(Vhc 6rGLeXb o9˳Ɩ/2XAӯ iȲ*ͣ5ʻ⍻2%6SFZ""E)hĆPG714cP+.Fhx@ŠV!Ll6۰T<3~pÑQ0B4YeB 3TZSKJP$ ~rt Xt_i/ӧtzOC;]>YbK?rzwƻp?YxWꮝ;a N2Zu,v3ڸ0Sf R RU  +/u kIsێ^[Kyzψbӑ`WOYb .U athBTy|n|  Ujӽ[!Dd'V\g-x.7 lL "?dNJn̻(9"l볺NNӝ 3`N <4kœ.أb[UÊatx!m}GBيf7͕Kk rUN|g:/|];#kHc7 (]}̹m9klFǒlٜ~{ЀkwCU}w\hj ;H|KFӇiziJ:7ŔdLAԘO eڧ(Nkv!s@V-z)ֻ)T04Fm]2aJ֭#lPUGNs3 UG{3mJ̘ibTTK4R4Q1dlD QdA,s~HOIVӟrVꔼUMބ0.3\\XL|,MldokƴKk B0 m#_D&sAdF&[K#ߚz9_eERS~x2Tt0ġa.R,^*T o>{k*3`Pb(iBߥzIXVHbp^֘V=fߔuuN]|-^/Qqд Rjԝh+n";"7f2YL1<*\9џVgʆ}*FXڜ , %hעೕ!Z^7۞3Ȍ2I%OlUvk (!NNМۢHO0b<~FscCY>Di:DO EX_:d"=[б20Y4Mi.JޘV]ua#=tV1O<ǘQvEIpl w/mM6;:c i_O,RWt*%RpmJ׭IU(8G$UeX5*>%1?ힴ*Ϩ{o8ޝ;qOͯ%@ /-H&7Y/HV"m|gM\Z90+#Ͳ7 e2.,ġmù/Ѓh&5qޒY6ޑ#dB_WH,?WC*Z]6sH:UDE!=ٺcS K%#I互6.Jf@ r]$[hlwBrkrM$E+4yJl[2=\U}.?RH߄VuK逑$3($mzzou&,53#̳i;uiRGfP&0psbWqpS}hIq|_K/r\udJ^r9}vd $am^IŝtLNKqMIK p*Wc1 YpEU=PMԒ&t,!M& I$%97®(E`.SHd8D2}py'g(5_Yk@@ qzh\4Cüy7q94tO0Yr2DV{w8@"&Hӱ//<]L 88p_Zdy(vgn߁ua~ XZr8;]b73Ȋnsr|OaIzPt~^n$3S1j6w5 i*ةbO'{6وbS H%zҫ6Xشc}(~Rg*8>WaPDIYMpN;H, Ky6jM5Vv_ĝH Hr]8$#^'d La?en EFi)`%&^2<'ڄ6t6mlf~=Ofڸb?>ZՀt6WsN潪.a9֕n1Q:Tv{ 1ki;F(sgAlN>9o>4/@jY,n]]ڰ жgS;ePNP yru 8z 򅭛t'Sٍ6 _ĄUPZI&v#C`7M5XO"JZfr]&s$cI$+[̎5GqmZ@W& &Qf!lA(Y JyS,:)6F9=h6fOAlRSvfM ;s)Tct0W #6Dy{-Vou fmTp׮[?+kQ;/80zQڛP}tKj'E&SO^!eͭWR=9Cu|wP4 Kg^s%gxX{=9vXTn}l@s6j'Sk1at1=;쵮 5I'[=e#k7H((\qB"^Wǿ9]Y,w?0QO"%=m)ISxFprWIq-sunnP`S6+{Fx .b3@s#X-_3f~GouAq "l^tE ?r?)k`[.NP(v6|߷=x$-i碊0c@뗌_aS`3@X إ4#u\"PLqySu0c}ad=l&|?` Qm2B[1fmvC9l.ހ1ԁVqd@2d]TH5yӸO$v DC A2;- *OIqWi*SӢSaZ~l8y:V f2YRJ!D%*- InM'*'Ҙ"wAMeH}\-\>O?'Шl2匽Os>P;h!ua%gʹxKc?R.(G9spU]^RlH"߱"F%,9!D',os- vhy/+paGf LWaO`8MT8F "A3{V| P,rkX~)Su B>:; s(I M'_8 ݄5bD_قSYeB_v$gUW3N!N\%%akhU?vPgْ6wj{m_%߲@%=ShLrŞ.} j`+c 緌@臆K멮D.A TIUK[o4DF(=̝ j2O]A cXx [.@L4+eٱ̏-Jfo$'7-a1}Hxu)! fOJ8aFgl*0PD]n/YS,t"orebO4׻`΢'Uǁ<&@a'gz^s'M|V9|kl@ {Gtg<\F/2%|1V&(܏WQZ eCIE, }HEđ=WY@Z#EW8W;ُAzk/i#tɭ> y4&/ 럆 Q‘rf6Z$/@7x6MʬtZBdkhmxCZjlll?n' StD5!Na32ܱ8 e uͺ\jö YZ