iptables-1.4.21-9.1<>,RYq*%/=„Yg)td#3V43]鉆cmpM둎L^&{/p3Qg ʽ˷$ɬό0S_{블c[,ZZB!_~p:7?7td   @ 6W  <  j <4W(8)9 ,): )F.hG.|H.I/,X/DY/L\/d]/^1b1c2d2e2f2l2u2v3$ w6@x6y6z7dCiptables1.4.219.1IP Packet Filter Administration utilitiesiptables is used to set up, maintain, and inspect the tables of IP packet filter rules in the Linux kernel. This version requires kernel 3.0 or newer.Yq*%build74openSUSE Leap 42.3openSUSEGPL-2.0 and Artistic-2.0http://bugs.opensuse.orgProductivity/Networking/Securityhttp://netfilter.org/projects/iptables/linuxx86_64 ` ` W@F0-(|.XA큤Yq*#Yq* Yq*"Yq* Yq* Yq* Yq* Yq*"Yq* Yq* Yq*"Yq*$R=uYq* Yq* Yq* Yq* Yq* Yq* Yq* Yq* Yq* 5023d81639d3de495d02c4cf2cb6736a4def0653ff8648f32452929d06dcfbfaad5d4520732e8da9025cd9e4f0b0051b80b7986f0448283a33cea7ed8809890eb234ee4d69f5fce4486a80fdaf4a4263dcf413e62b42b482822b379c3dd30c3040a9fcbd60adf070ea48bb8d58fbb9c0209812a22152646be79bc3d1263f3de9b0301de748bd4ba9e74015111d92994456e8f8cc58926ac835ae809a74923d9df207d578d399a89fa47e82e3c5cf38dbaf2adc076462cfbf8a59ba9025462bfe17e0b8d300b82102474dd7006c27caa5fd9ecdae70c83c6ec9b2f1707ad1f71b../sbin/xtables-multixtables-multixtables-multixtables-multixtables-multixtables-multixtables-multirootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootiptables-1.4.21-9.1.src.rpmiptablesiptables(x86-64)@@@@@@@@@@@   /bin/bashlibc.so.6()(64bit)libc.so.6(GLIBC_2.14)(64bit)libc.so.6(GLIBC_2.2.5)(64bit)libc.so.6(GLIBC_2.3)(64bit)libc.so.6(GLIBC_2.3.4)(64bit)libc.so.6(GLIBC_2.4)(64bit)libc.so.6(GLIBC_2.7)(64bit)libip4tc.so.0()(64bit)libip6tc.so.0()(64bit)libxtables.so.10()(64bit)rpmlib(CompressedFileNames)rpmlib(PayloadFilesHavePrefix)xtables-pluginsrpmlib(PayloadIsLzma)3.0.4-14.0-11.4.214.4.6-14.11.2YTSW@RR6QQkQIQ4Pٕ@PP@P@Pr@POOqO@NNN@N_sNEN?N)f@Md@M5@Lʷ@L_LYV@K @K@K@KqK;@K0JJ]J8J8J@I@matthias.gerstner@suse.comdmueller@suse.comjengelh@inai.dejengelh@inai.dejengelh@inai.dejengelh@inai.decfarrell@suse.comjengelh@inai.dejengelh@inai.desbrabec@suse.czlnussel@suse.dejengelh@inai.dejengelh@inai.dejengelh@inai.dejengelh@inai.dejengelh@medozas.dejengelh@medozas.depuzel@suse.comcoolo@suse.comjengelh@medozas.dejengelh@medozas.dedraht@suse.dejengelh@medozas.dejengelh@medozas.dejengelh@medozas.dejengelh@medozas.dejengelh@medozas.depuzel@novell.compuzel@novell.comjengelh@medozas.decoolo@novell.comjengelh@medozas.dejengelh@medozas.depuzel@novell.comjengelh@medozas.depuzel@novell.comkay.sievers@novell.compuzel@novell.compuzel@suse.czpuzel@suse.czpuzel@suse.cz- iptables-batch-lock.patch: fix a locking issue of iptables-batch which can cause it to spuriously fail when other programs modify the iptables rules in parallel (bnc#1045130). This can especially affect SuSEfirewall2 during startup.- remove dependency on sgmltool: doesn't seem to be used and reduces rebuild time on aarch64 by 8 hours- Update to new upstream release 1.4.21 * --nowildcard option for xt_socket, available since Linux kernel 3.11 * SYNPROXY support, available since Linux kernel 3.12- Update to new upstream release 1.4.20 * Introduce a new revision for the set match with the counters support * Add locking to prevent concurrent instances- Update to new upstream release 1.4.19.1 * New connlabel and bpf matches - Remove 0001-Revert-build-resolve-link-failure-for-ip6t_NETMAP.patch, 0001-libip6t_NETMAP-Use-xtables_ip6mask_to_cidr-and-get-r.patch (are upstream)- libxt_state.so symlink was not installed (bnc#815182); fix by removing 0001-build-also-use-libtool-for-install-stage.patch, removing 0001-build-do-not-dereference-symlinks-on-installation.patch, adding 0001-libip6t_NETMAP-Use-xtables_ip6mask_to_cidr-and-get-r.patch, adding 0001-Revert-build-resolve-link-failure-for-ip6t_NETMAP.patch- license update: GPL-2.0 and Artistic-2.0 GPL version does not have ^or later^ due to inclusion of numerous GPL 2 ^only^ files. Also, aggregation of Artistic-2.0 content- Update to new upstream release 1.4.18 * documentation updates - Create subpackage xtables-plugins, to aid packaging of xtadm - Add 0001-build-do-not-dereference-symlinks-on-installation.patch as a prerequisite for: - Add 0001-build-also-use-libtool-for-install-stage.patch to kill of undesired DT_RPATH entries- Update to new upstream release 1.4.17 * libxt_time: add support to ignore day transition * libxt_statistic: fix save output- Verify GPG signature- list all required binaries explicitly to make sure all of them are actually compiled- Always regenerate files due to SUSE's iptables-batch patch- Update to new upstream release 1.4.16.3 * This release includes aliasing support which translates command lines using obsolete extensions into new ones. The option parser now flags illegal negative numbers in some more extensions. A division by zero was resolved in libxt_limit as well.- Update to new upstream release 1.4.15 * libxt_recent: add --mask netmask * libxt_hashlimit: add support for byte-based operation- Update to new upstream release 1.4.14 * Support for the new cttimeout infrastructure. This allows you to attach specific timeout policies to flow via iptables CT target.- Update to new upstream release 1.4.13 * Add the rpfilter, nfacct and IPv6 ECN extensions- Update to newer git snapshot (v1.4.12.2-28-g2117f2b, but master branch), tag locally as 1.4.12.90. * ships missing pkgconfig files, compile fix for libnfnetlink * libxt_NFQUEUE: fix --queue-bypass ipt-save output * libxt_connbytes: fix handling of --connbytes FROM * libxt_recent: Add support for --reap option - split iptables-devel into libiptc-devel and libxtables-devel- iptables-apply-mktemp-fix.patch (bnc#730161)- add automake as buildrequire to avoid implicit dependency- Update to a newer git snapshot of the stable branch (to v1.4.12.1-16-gd2b0eaa) * resolve failure to load extensions that depend on libm.so - rediff of iptables-batch due to fuzz - relax runtime requires- Update to new upstream release 1.4.12.1 * regression fixes for the new (stricter) command-line parser - restore --includedir= in spec file - Put libxtables into its own subpackage so that one does not need a lockstep update of iproute2 on a new iptables package - Remove redundant fields (Autoreqprov defaults to on, License is inherited from main package)- include path is /usr/include- Put include files into a separate directory to flag up missing CFLAGS. libipq.pc will now be provided. - Enable build of nfnl_osf, a tool to upload OS fingerprints to the kernel for use with xt_osf.- Update to new upstream release 1.4.12 * Include lost match/target descriptions in manpage again * libxt_LOG: fix ignorance of all but the last flag * libxt_HL: restore hl-* option names * libxt_hashlimit: use a more obvious expiry value by default * libxt_RATEEST: fix find-and-delete of rules with -j RATEEST * ipv4: restore negation for the -f option * Reject empty host specifications (e.g. -s "") * libxt_conntrack: restore network byteordering for ABI v1 & v2 * Documentation updates- Update to snapshot 1.4.11+git16 * libxt_owner: restore inversion support * option: fix ignored negation before implicit extension loading * build: fix installation of symlinks * build: fix absence of xml translator in IPv6-only builds - Drop merged patches- Update to new upstream release 1.4.11 * stricter option parsing * support for the current xt_SET target as contained in 2.6.39 * support for the new xt_devgroup match * support for the new xt_AUDIT target * support for a new NFQUEUE bypass option, allowing to bypass the queue if no userspace listener is present * a new iptables option "-C" to check for existence of a rules - Fixes on top * allow negation of --uid-owner/--gid-owner again * fix installation of symlinks - Run spec-beautifier- Update to new upstream release 1.4.10 * this is the release for the Linux 2.6.36 kernel * support for the cpu match, which can be used to improve cache locality when running multiple server instances * support for the IDLETIMER target, which can be used to notify userspace of interfaces being idle * support for the CHECKSUM target * support for the ipvs match * a fix for deletion of rules using the quota match- update to new upstream release 1.4.9.1 * fixes a compilation problem with static linking in the 1.4.9 release- update to new upstream release 1.4.9 * this is the release for the Linux 2.6.35 kernel * support for the LED target * a new version of the set extension for the upcoming release supporting IPv6 * negation support for the quota match * support for the SACK-IMMEDIATELY SCTP extension and FORWARD_TSN chunk type in the sctp match * documentation updates and various smaller bugfixes- update to new upstream release 1.4.8 * this is the release for the Linux 2.6.34 kernel * add support for the new xt_CT extension * import the nfnl_osf program required for proper operation of the xt_osf extension- buildrequire pkg-config to fix provides- update to new upstream release 1.4.7 * libipq is built as a shared library * removal of some restrictions on interface names * documentation updates - rebase and fix linking of iptables-batch - fix libdir->libexecdir- only run configure when needed - use %_smp_mflags - use newer git snapshot to fix compile error due to missing ipt_DSCP.h in newer linux-glibc-devel (>= 2.6.32)- fix bnc#561793 - do not include unclean module documentation in iptables manpage- update specfile descriptions (bnc#553801) - update to iptables 1.4.6: * combine iptables subprograms into a new multi-purpose binary * support for new implementations: NFQUEUE v1, conntrack v2 * helper: fix invalid passed option to check_inverse * iprange accepts single host specifications again * iprange: do accept non-ranges for xt_iprange v1 * iprange: warn on reverse range * libiptc: fix wrong maptype of base chain counters on restore * iptables: fix undersized deletion mask creation * iptables/extensions: make bundled options work again * iptables: take masks into consideration for replace command * xtables: warn of missing version identifier in extensions * documentation updates - refresh iptables-batch- remove outdated howtos (bnc#551748)- fix libdir/libexecdir on 64bit installation- install iptables-apply- update to iptables-1.4.4 * support for the new features in the 2.6.30 kernel, namely the cluster match and persistent multi-range NAT mappings * support for the ipset set match and target * various minor fixes and cleanups * documentation updates- make explicit 'commit' in iptables-batch do nothing (bnc#500990)- update to 1.4.3.2 - numerous documentation updates and bugfixes - set of changes to move some of the iptables functionality to a shared library for tc and m_ipt - make libiptc available as shared library (closes bnc#487629) - IPv6 support for the recent match - TPROXY support - SCTP/DCCP NAT support - INCOMPATIBILITY: This release starts enforcing the deprecation of NAT filtering that was added in 1.4.2-rc1, filtering rules in the NAT tables will cause an error instead of a warning from now on. - rework iptables-batch.patch (libiptc interface has changed) - update howtosbuild74 1500588581 1.4.21-9.11.4.21-9.1iptables-xmlip6tablesip6tables-batchip6tables-restoreip6tables-saveiptablesiptables-applyiptables-batchiptables-restoreiptables-savextables-multiiptablesCOPYINGiptables-xml.1.gzip6tables-restore.8.gzip6tables-save.8.gzip6tables.8.gziptables-apply.8.gziptables-extensions.8.gziptables-restore.8.gziptables-save.8.gziptables.8.gz/usr/bin//usr/sbin//usr/share/doc/packages//usr/share/doc/packages/iptables//usr/share/man/man1//usr/share/man/man8/-fmessage-length=0 -grecord-gcc-switches -O2 -Wall -D_FORTIFY_SOURCE=2 -fstack-protector -funwind-tables -fasynchronous-unwind-tables -gobs://build.opensuse.org/openSUSE:Maintenance:7015/openSUSE_Leap_42.3_Update/6aa664858d0d19c1c5a86ed6befb7c7a-iptables.openSUSE_Leap_42.3_Updatedrpmlzma5x86_64-suse-linuxELF 64-bit LSB executable, x86-64, version 1 (SYSV), dynamically linked (uses shared libs), for GNU/Linux 3.0.0, BuildID[sha1]=e11daf7da79a59491ad6e12270b292e350863051, strippedBourne-Again shell script, UTF-8 Unicode text executableELF 64-bit LSB executable, x86-64, version 1 (SYSV), dynamically linked (uses shared libs), for GNU/Linux 3.0.0, BuildID[sha1]=ab9eb8573a1136ec0eefef94e8989183f2537805, strippedELF 64-bit LSB executable, x86-64, version 1 (SYSV), dynamically linked (uses shared libs), for GNU/Linux 3.0.0, BuildID[sha1]=bdb00763aa9276d84597f73443dc3b07d8504164, strippeddirectoryPascal source, ASCII textHTML document, ASCII text (gzip compressed data, max compression, from Unix)troff or preprocessor input, ASCII text (gzip compressed data, max compression, from Unix)   RRRRRRR R RRRRRRRRRR RRRRRRRRR R Rq%\₼6c$*?`]"k%YyšY(!Vܹj7 yQe;p܌NK{hȿ,.~bOvT8K >O˼^ p2:sGm( ɋVpgFl&SdDu=*oղU$a 1MPC1M1nK$`5IFƏ:20\I^ (LF8FNh+w7K/{*$eIO MmBdFab e/hcB0WVW%q_Ms^> h Ue*^K8(֓R˶yҁ6TW}oCᕫ4Lj1xea>TSkDپPYּnG6E%R1% }96VaqmQ RtЙY{עZ=JVMR!&8+Q<-լk!D 78_})՚\cT )A_(}a{|kV`<H:f-&mOPJ`] B7IǛ+;eJ޼|JSA1w_Eaw7UOOׇa^kڞt:Ⅽ A9"pLIOD!^X=:Nga^.TWyt,1g2IzU`M4IUJܤ]!Eci_jIvw&>q~rɝ?Z}ЭY`OR)LTcԙ]"@<tPSc?D>3 Zcsy2<$_հfԚ S\[-mV(/x@H暴HG6Uc2+lxk?RUh̵c%Cx8'i78<` 񏚇P,[DkARj4˸ L^ٴ[Ye0v \[.y;gcDQ Cy@Gd.rcX 0ܕbcT_JSȭJi2= quʎN>|)통0UO Dϛ}Чz.B8GVA׃9?fJ()$4/}dGü1#Q*ݵoNTTczRWSw*ᯓfgB{ooB Y8 3A/A+}ͻ&U>Jt _ ~^(M}1AP\.FGSHП};:b\]P{q5Dhrx9˺|g:(Ptc{|6V_isac{Q .]8z1裃X(V"TUZj>.䆯7Vfl0BQ hwXh|Ci*XFC 4Z^Z|\H`gY.)L H^^!&+CצfHQ`+M Qz!fs:2T$_cG$ f猃8!ؼgwRt#>K[j鈄iEԜ;wŵ)ǵ0_c us~ BQR@g[-)Jy&l?m]s5 oZ&GNrU$\G2<_5{QAf8 Bȇ}jj~~f-ggH6M3j3b-NݬxnNF >8<:y] =hI 8ʐ(XjJ1;K;/J^B_Ȑu RbP*4u'TtJV4,!\I;~9.p P:M+7Yҡ٤k/v$~vh3gP~vwK7,'Ơy;@كlm F 8ۄ>:ǯOPjDW29.zeF  !n?n%4}ʎޝj+ovcw[]\s b 1>/ߗ CHyfͦNuN ^1-z$TnskJI8N!vx7#0t$LX*gᮍ\}gwM#'9QpdܜWG ^ n2T] Rf9vVf<.)eyN- 峉TnFDQ/2n,eB@! (=b hi7; hF7M ֱ@QG Kܮb\4uNRX8B8\o 7n.ç-' )uh%3,unр$%nP;:ɁqʙwOlKiH٣@%gɊAP h8V5)l ̱_TcQ5Wr [Vy$Iɀ1'ֱ8n`I\M w.,Ar%Vg5|&Ap*Σ-h;*d)!C4;9e7۳[0#L]e빌!ܺ|gk̒W/9/ 'EwU>*KmiPAW;MqVk5Q?lWuM 9OO=8lF+EոCOcؾho|OɷɭOQ-MfU?ӓ#['DUhc& .Y`! %Go̶TtNYW׏$1Ac2KQ|$jR[`s%-ɦGKEhC6'