libnftables1-0.9.8-150300.3.3.1<>,I\b{_p9|5hW>)݉Nml (iGpgsOz8=O9gIMP 1 @г:7Ш-nFnhKƲ@@$Ju2ji!y%DZ`xjBI:$3Pʙ6h\I,+Zߗn>OYKJcI]J&}Ȯ' L_2eK5.*bR|IRJN{ǽI#j ^n>@'L?'<d " I ?ELT X \ d  Dk(89:>#@#F#G$H$I$ X$$Y$0\$X]$`^$b$c%;d%e%f%l%u%v%w&xx&y&z&&&&'8Clibnftables10.9.8150300.3.3.1nftables firewalling command interfacelibnftables is the nftables command line interface placed into a library.b{_s390zl36 (SUSE Linux Enterprise 15SUSE LLC GPL-2.0-onlyhttps://www.suse.com/System/Librarieshttps://netfilter.org/projects/nftables/linuxs390x (b{_b{_8da13119742e7ccd78fa5d74fca84de70114e0d90cc8a8d27671186e571b3e53libnftables.so.1.0.0rootrootrootrootnftables-0.9.8-150300.3.3.1.src.rpmlibnftables.so.1()(64bit)libnftables1libnftables1(s390-64)@@@@@@@@@@@@@@@@@@@@    /sbin/ldconfig/sbin/ldconfiglibc.so.6()(64bit)libc.so.6(GLIBC_2.15)(64bit)libc.so.6(GLIBC_2.2)(64bit)libc.so.6(GLIBC_2.22)(64bit)libc.so.6(GLIBC_2.27)(64bit)libc.so.6(GLIBC_2.3)(64bit)libc.so.6(GLIBC_2.3.4)(64bit)libc.so.6(GLIBC_2.4)(64bit)libc.so.6(GLIBC_2.7)(64bit)libc.so.6(GLIBC_2.8)(64bit)libgmp.so.10()(64bit)libjansson.so.4()(64bit)libmnl.so.0()(64bit)libmnl.so.0(LIBMNL_1.0)(64bit)libnftnl.so.11()(64bit)libnftnl.so.11(LIBNFTNL_11)(64bit)libnftnl.so.11(LIBNFTNL_13)(64bit)libnftnl.so.11(LIBNFTNL_14)(64bit)libnftnl.so.11(LIBNFTNL_15)(64bit)libnftnl.so.11(LIBNFTNL_16)(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)3.0.4-14.6.0-14.0-15.2-14.14.3bo`_ ^@^ۅ@^@^@]7@]N@]Z@\C@[@ZZ@Z@Zu@Z]@YXY@WPU@U`kTmatthias.gerstner@suse.comjengelh@inai.dejengelh@inai.dejengelh@inai.dejengelh@inai.dejengelh@inai.dejengelh@inai.dejengelh@inai.dejengelh@inai.dejengelh@inai.destefan.bruens@rwth-aachen.dejengelh@inai.dejengelh@inai.dejengelh@inai.dejengelh@inai.dejengelh@inai.dejengelh@inai.dejengelh@inai.dejengelh@inai.dejengelh@inai.dejengelh@inai.demrueckert@suse.dejengelh@inai.de- add 0001-cache-check-for-NULL-chain-in-cache_init.patch: this fixes rare crashes that could occur e.g. in firewalld (bsc#1197606).- Update to release 0.9.8 * Complete support for matching ICMP header content fields. * Added raw tcp option match support. * Added ability to check for the presence of any tcp option. * Support for rejecting traffic from the ingress chain.- Update to release 0.9.7 * Support for implicit chains * Support for ingress inet chains * Support for reject from prerouting chain * Support for --terse option in json * Support for the reset command with json- Update to release 0.9.6 * Fix two ASAN runtime errors- Update to release 0.9.5 * Support for set counters. * Support for restoring set element counters via nft -f. * Counter support for flowtables. * typeof concatenations support for sets. * Support for concatenated ranges in anonymous sets. * Allow to reject packets with 802.1q from the bridge family. * Support for matching on the conntrack ID. - Drop anonset-crashfix.patch (upstream solved differently)- Add anonset-crashfix.patch [boo#1171321]- Update to release 0.9.4 * Add a helper for concat expression handling. * Add "typeof" build/parse/print support.- Add json, python [boo#1158723]- Update to release 0.9.3 * meta: Introduce new conditions "time", "day" and "hour". * src: add ability to set/get secmarks to/from connection. * flowtable: add support for named flowtable listing. * flowtable: add support for delete command by handle. * json: add support for element deletion. * Add `-T` as the short option for `--numeric-time`. * meta: add ibrpvid and ibrvproto support- Update to new upstream release 0.9.2 * Transport header port matching, e.g. "th dport 53" * Support for matching on IPv4 options * Support for synproxy- Remove unused dblatex BuildRequires, only needed for the optional and disabled PDF generation (same contents as shipped manpage).- Update to new upstream release 0.9.0 * Support to check if packet matches an existing socket. * Support to limit number of active connections by arbitrary criteria, such as ip addresses, networks, conntrack zones or any combination thereof. * Added support for "audit" logging.- Update to new upstream release 0.8.5 * support to add/insert a rule at a given index position * meter statement now supports a configureable upper max size * timeouts for sets can now be specified in milliseconds * re-add iptables-like empty skeleton rulesets- Update to new upstream release 0.8.4 * Support to match IPv6 segment routing headers. * New "meta ibrname" and "meta obrname" arguments to match the name of the logical bridge a packet is passing through. These new names replace the old (misnamed) "ibriport"/"obriport". * `nft -a` will now show handle identifier for all objects, including tables and chains. * nft can now delete objects by their handle number. * Support to update maps from the ruleset (packet path). * the "--echo" option now prints handle id for tables and object too. * `nft -f -` will now read from standard input * Support for flow tables, cf. man page or https://lwn.net/Articles/738214/ .- Update to new upstream release 0.8.3 * raw payload support to match headers that do not yet have received a mnemonic.- Update to new upstream release 0.8.2 * add secpath support- Update to new upstream release 0.8.1 * This release deprecates the "flow table" syntax in favor of "meter".- Update to new upstream release 0.8 * This release contains new features available up to the (upcoming) Linux 4.14 kernel release: * Support for stateful objects, these objects are uniquely identified by a user-defined name, you can refer to them from rules, and there is a well established interface to operate with them. * Sort set elements when listing them, from lower to largest. * TCP option matching and mangling support. This includes TCP maximum segment size mangling. * Add new "-s" option for listings without stateful information. * Add new -c/--check option for nft, to tests if your ruleset loads fine, into the kernel, this is a dry run mode. * Connection tracking helper support. * Add --echo option, to print the handle that the kernel allocates to uniquely identify rules. * Conntrack zone support * Symmetric hash support * Add support to include directories from nft natives scripts, files are loaded in alphanumerical order. * Allow to check if IPv6 extension header or TCP option exists or is missing. * Extend quota support to display used bytes. * Add ct average matching, to match average bytes per packet a connection has transferred so far, to map the existing feature available in the iptables connbytes match. * Allow to flush maps and flow tables. * Allow to embed set definition into an existing set. * Conntrack event filtering support via rule.- Update to new upstream release 0.7 * Add new fib expression, which can be used to obtain the output interface from the route table based on either source or destination address of a packet. * Support hashing of any arbitrary key combination, eg. * Add number generation support. Useful for round-robin packet mark setting. * Add quota support, eg. * Introduce routing expression, for routing related data with support for nexthop * Notrack support, to explicitly skip connection tracking for matching packets. * Support to set non-byte bound packet header fields, including checksum adjustment. * Add 'create set' and 'create element' commands. * Allow to use variable reference for set element definitions. * Allow to use variable definitions from element commands. * Add support to flush set. You can use this new command to remove all existing elements in a set. * Inverted set lookups. * Honor absolute and relative paths via include file, where: * Support log flags, to enable logging TCP sequence and options. * tc classid parser support, eg. * Allow numeric connlabels, so if connlabel still works with undefined labels.- Update to new upstream release 0.6 * Rules may be replaced now * Flow table support (requires Linux >= 4.3) * Support for tracing * Ratelimiting now supports units like bytes/second. * Matchinv VLAN IDs, DSCP/ECN, ICMP RtAdv & RtSol- Update to new upstream release 0.5 * Support combinations of two or more selectors to build a tuple * Timeout support for sets * Dormant flag for tables * Default chain policy specifiable on creation- set the url to the project page - pass --disable-silent-rules to configure to allow gcc post build check to work- Update to new upstream release 0.4 * Since Linux 3.18: support for global ruleset operations * Since 3.17: full logging support for all the families, including nfnetlink_log * 3.16: automatic selection of the optimal set implementation * 3.14: reject support for ip, ip6 and inet * 3.18: reject support for bridge, and reject icmpx abstraction * 3.18: masquerade support * 3.19: redirect support * Extend meta to support pkttype, cpu and devgroup matching./sbin/ldconfig/sbin/ldconfigs390zl36 16522525740.9.8-150300.3.3.10.9.8-150300.3.3.1libnftables.so.1libnftables.so.1.0.0/usr/lib64/-fmessage-length=0 -grecord-gcc-switches -O2 -Wall -D_FORTIFY_SOURCE=2 -fstack-protector-strong -funwind-tables -fasynchronous-unwind-tables -fstack-clash-protection -gobs://build.suse.de/SUSE:Maintenance:24179/SUSE_SLE-15-SP3_Update/66ac1bca1b33139dd80ec031930f1675-nftables.SUSE_SLE-15-SP3_Updatedrpmxz5s390x-suse-linuxELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=47f99c325381fcb2d5458cd91eb4d7977fa03eec, strippedPRRRR RR RR RRRRRRRRRR R Rp|} ^/Outf-830a365e43d739919e8f32506bd1e173f4eded9d9ba197dc02645c31c6ffc77cf?7zXZ !t/.~]"k%f0]dZaȗ2v=ZB T#IE,:lW?)6]^_\-uN\]d7;neq1b.."di՜vЩrᡀ^\s|'V\E wBk?uF41CmuV?(*2sq Fded`q\Xj_Y0Z$v]=W$׽R[YֻlAw޸>PAw}*…&95oMuveٞV=*=d;!6% p=Q^Mbx.XܠZ,ﯽդU@_f}`fc&7j1cz0f@Va ujN6 ѣMA/\ףAV}Ƅ 5hIx잜rDٱMAUx- 4|3 "+yܜߟH{{S٨ӷZÎ_;K `I|كiB񗯦YrP09w&u֢BE ^QH4Qd˔+[U3q e§28dأ%="tN`ԅ#ˈ3e(F O慸{"03Y,bq|X{n>Ngr_\;# sD7b쎲ڎPDS|w& sࡖsL bX5ew#̆7N=׍/c8w/G~1Bl5B|X\YnqVI umM򯐀$iT|!|M0`TSe7}JKSw!l5s3b %I 8Jŋ2 gv؏ʮ%4NԢ8>*'wd*] cD.{TixcL=; {;/{E4I,OM"φ@U, P JZۆ;"S5Lgh 2 ~^EYuaoOAݫ }UW8tv˛Da]RAB{,!.Fq%@hl$n+!<%i~y8i2`-Jc%'~20D~Pb6uۭ|&2;4铇`ѹ`F?X!s.iOEgDnIgHpar*5FzO2g|NrƼV,zjQb D`_AFhXy.H 5dqתEŘ "{?x}k&3ͷ>G|c̔f$v8n}t {h 4 1HGQk1#Wg+n̼;*O:ф݉S/[7ImVNpKBwaG7J9\CY-'XOO9#'u?(x&d̃sX W0} ,Dk/a^I9.*L2VJsVxf*RK᪒*MP2nL<4Gg ^+]ʌ*]hm>hBc(zK8|XT:=j Az?Xk43XlV+Oi>u~adrͰXЌ֮jbP*~ޡHQMWBsgdxIhMJ3UMr3WYwV0m Y Ӟhjj`ퟕ_#[V</drBlOo8Kh~b E- ^3mþC]q5tw.o0;%i!8t)JokzX]Y燷&[=9fZ/,[w/ dmP;/+aT ߯ h ͫt~]+cN<(_HOa Lj.r& ʤHDg:m/Ve˗@^fq~2BẒiXX<ԄȺִ )L[4 כwPyPhh(R]ɂRű%P&h#4^zb?pȴ/5KFW|& Dp Z]{3^)NGZ&(=r;PF@4 KÈ'co~ }l3W %΋h aŨ<*Ekq>%MGDn,uʔy>/I3CUt)*6j^Uu2@ p1rޅ w3ܠ Z4 eū|2 mj9h8VszIir"W>VqP7.3NK8lKf'QݻBMCy5H+t(ĿVI$4nE6a ׏.'<$i"~"d vպw*Zoi$|ܼn=<1%:h/@jd!NF.G2T9Rߦ׽p (,rf3Eeįl JHf/T\b<()Fj&>0%WA#si.}=o4I dfɝ)._$QMojt|pjB WobW[ f^ݳ_}9bl[fIl .fŽ fX2'j$w/}; rbn6d됨Gv&Dj}wDksBedyV'Q-H$\U. vSiQۖ U幀Ӱ͏AlN-z_;+=`&)-#RSZl(+ĐPq5cS/I {(~&|8L >IF\[)i,Q7+Z~7knny1"wREL̾ fK%lр"UW pd~8o2 o=XOX\Ei3oǂޚh7Ӧ*dN-uX(fRq1몂fecw״.Cm7 `]ҽ6כ 'Fd( u(i}N%|30rU̹`Rk3\ľ|tl^pUmCJM=t!?0,윢 bK]q pPV[ 9A/.|!{~%4s^s@ Ga$2 t}}G^IJnV!5r!Ry@fKm3HjՋXc8ъ1~OZ)Nms-S WqfǍ.3\ 4$90xVE4ʠ73uCl`l8Ko$`* a6IFߓ@@NK|zM!EbN"4vE2Nv$^ux@(M#e~Ј4-@wZsFHĐ 5_{|#*fZ#m6Al BګIum}M$:`*T 3n,FM7H ZsUWwFztzmt7:zsH3/SwٕcVɜVN}cW۬}5*k~<7|{]l8ׂ>!n!ZF,߲]̒+,L$TnNʼtj2oL4M7P̌g/ٕ{~,z'tӍն dPrㄯQE#˺l. wPG j9Y@fc >gaA st^)1qp:狶M-K.z1$szl|p727D ݞ?,X0|TVr)8Q0FyXuY{K!F=`|m?7fs$oZ gFUo0Kmg5Њ\Tߌ6SC[Aew[qI A~r?k/҈agv/ ~1/+[ڮN/bL=KʑqH=k/=}72ֲ|(W >?(lMv{:h %G{P&ŋn㶺>W_DQaea1kBY:aE~:쌒IXx5St|ʔl 8Vq[A5F 0I -A ӌU,DŽABQ3$1BPGQ鼝Wa;CPLQu#VpO>'5t4;GVX~\cU~R)na.MdҨac՛څbѠt2 \wҐ/OGr7G$ki6tK%y868͢:)q7&z]CGMFH܆  {2tݯIBwptuڴg멙 p][MauNLrNNu7RXLƺ@*[w`|2,݃;pRp>/o ǽ ~ﹳ$O%g@W1ܤ:2)B0uŮRnA;C6MOB>^7z#g4NےngƗTDJ ]/IӨߐ9t(e0$,CZr-} .Eu.=.9[^@ NܶoBbn1H"hi(gf:X\ 3Я8[}gsP!k<71ծQ))Jz X]cWjU (PF8kF}jV5En>V"S&.`SRJ-O #=&˦4c6^1M`2=3a,X5_+wVUy^t 4D xACtfU`u +d$gm+#K0X"l#{ Gt49PG5w0#u\2Myǡ>MU0aDgEq?Dn}d>Y@NM1rHq Jec_7^V="vʦF.$qKA\_jx~@Mg 缵% mS4R1Vd\6 CB*'zFA3p6o@fYO;\;P˶ YZ