libnftables1-0.9.8-150300.3.3.1<>,Ub{_Yp9|=SJfʧ//@y1(T0[M DsFL]A|{Qif>!i0iDFHZH wsKCԀ#hpG"娅fra@G-6m;+kW#k}'r'{""SaY_kb:y9|K+>7zux>hȏ`?.=k,MRe:5E!\/̫zzdCD=o*"-0s>o CW>@&|?&ld " I ?EPX \ ` h  D(898:>#@#"F#1G#HH#PI#XX#\Y#h\#]#^#b#c$sd$e$f$l%u%v%w%x%y%z& && &&&hClibnftables10.9.8150300.3.3.1nftables firewalling command interfacelibnftables is the nftables command line interface placed into a library.b{_YsangioveseF SUSE Linux Enterprise 15SUSE LLC GPL-2.0-onlyhttps://www.suse.com/System/Librarieshttps://netfilter.org/projects/nftables/linuxppc64leF b{_Vb{_X8cdaafaaf190ed87152bce34fc2a95b0dc0b97a3fd70ab3254ebe14d32de75eelibnftables.so.1.0.0rootrootrootrootnftables-0.9.8-150300.3.3.1.src.rpmlibnftables.so.1()(64bit)libnftables1libnftables1(ppc-64)@@@@@@@@@@@@@@    /sbin/ldconfig/sbin/ldconfiglibc.so.6()(64bit)libc.so.6(GLIBC_2.17)(64bit)libc.so.6(GLIBC_2.22)(64bit)libc.so.6(GLIBC_2.27)(64bit)libgmp.so.10()(64bit)libjansson.so.4()(64bit)libmnl.so.0()(64bit)libmnl.so.0(LIBMNL_1.0)(64bit)libnftnl.so.11()(64bit)libnftnl.so.11(LIBNFTNL_11)(64bit)libnftnl.so.11(LIBNFTNL_13)(64bit)libnftnl.so.11(LIBNFTNL_14)(64bit)libnftnl.so.11(LIBNFTNL_15)(64bit)libnftnl.so.11(LIBNFTNL_16)(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)3.0.4-14.6.0-14.0-15.2-14.14.3bo`_ ^@^ۅ@^@^@]7@]N@]Z@\C@[@ZZ@Z@Zu@Z]@YXY@WPU@U`kTmatthias.gerstner@suse.comjengelh@inai.dejengelh@inai.dejengelh@inai.dejengelh@inai.dejengelh@inai.dejengelh@inai.dejengelh@inai.dejengelh@inai.dejengelh@inai.destefan.bruens@rwth-aachen.dejengelh@inai.dejengelh@inai.dejengelh@inai.dejengelh@inai.dejengelh@inai.dejengelh@inai.dejengelh@inai.dejengelh@inai.dejengelh@inai.dejengelh@inai.demrueckert@suse.dejengelh@inai.de- add 0001-cache-check-for-NULL-chain-in-cache_init.patch: this fixes rare crashes that could occur e.g. in firewalld (bsc#1197606).- Update to release 0.9.8 * Complete support for matching ICMP header content fields. * Added raw tcp option match support. * Added ability to check for the presence of any tcp option. * Support for rejecting traffic from the ingress chain.- Update to release 0.9.7 * Support for implicit chains * Support for ingress inet chains * Support for reject from prerouting chain * Support for --terse option in json * Support for the reset command with json- Update to release 0.9.6 * Fix two ASAN runtime errors- Update to release 0.9.5 * Support for set counters. * Support for restoring set element counters via nft -f. * Counter support for flowtables. * typeof concatenations support for sets. * Support for concatenated ranges in anonymous sets. * Allow to reject packets with 802.1q from the bridge family. * Support for matching on the conntrack ID. - Drop anonset-crashfix.patch (upstream solved differently)- Add anonset-crashfix.patch [boo#1171321]- Update to release 0.9.4 * Add a helper for concat expression handling. * Add "typeof" build/parse/print support.- Add json, python [boo#1158723]- Update to release 0.9.3 * meta: Introduce new conditions "time", "day" and "hour". * src: add ability to set/get secmarks to/from connection. * flowtable: add support for named flowtable listing. * flowtable: add support for delete command by handle. * json: add support for element deletion. * Add `-T` as the short option for `--numeric-time`. * meta: add ibrpvid and ibrvproto support- Update to new upstream release 0.9.2 * Transport header port matching, e.g. "th dport 53" * Support for matching on IPv4 options * Support for synproxy- Remove unused dblatex BuildRequires, only needed for the optional and disabled PDF generation (same contents as shipped manpage).- Update to new upstream release 0.9.0 * Support to check if packet matches an existing socket. * Support to limit number of active connections by arbitrary criteria, such as ip addresses, networks, conntrack zones or any combination thereof. * Added support for "audit" logging.- Update to new upstream release 0.8.5 * support to add/insert a rule at a given index position * meter statement now supports a configureable upper max size * timeouts for sets can now be specified in milliseconds * re-add iptables-like empty skeleton rulesets- Update to new upstream release 0.8.4 * Support to match IPv6 segment routing headers. * New "meta ibrname" and "meta obrname" arguments to match the name of the logical bridge a packet is passing through. These new names replace the old (misnamed) "ibriport"/"obriport". * `nft -a` will now show handle identifier for all objects, including tables and chains. * nft can now delete objects by their handle number. * Support to update maps from the ruleset (packet path). * the "--echo" option now prints handle id for tables and object too. * `nft -f -` will now read from standard input * Support for flow tables, cf. man page or https://lwn.net/Articles/738214/ .- Update to new upstream release 0.8.3 * raw payload support to match headers that do not yet have received a mnemonic.- Update to new upstream release 0.8.2 * add secpath support- Update to new upstream release 0.8.1 * This release deprecates the "flow table" syntax in favor of "meter".- Update to new upstream release 0.8 * This release contains new features available up to the (upcoming) Linux 4.14 kernel release: * Support for stateful objects, these objects are uniquely identified by a user-defined name, you can refer to them from rules, and there is a well established interface to operate with them. * Sort set elements when listing them, from lower to largest. * TCP option matching and mangling support. This includes TCP maximum segment size mangling. * Add new "-s" option for listings without stateful information. * Add new -c/--check option for nft, to tests if your ruleset loads fine, into the kernel, this is a dry run mode. * Connection tracking helper support. * Add --echo option, to print the handle that the kernel allocates to uniquely identify rules. * Conntrack zone support * Symmetric hash support * Add support to include directories from nft natives scripts, files are loaded in alphanumerical order. * Allow to check if IPv6 extension header or TCP option exists or is missing. * Extend quota support to display used bytes. * Add ct average matching, to match average bytes per packet a connection has transferred so far, to map the existing feature available in the iptables connbytes match. * Allow to flush maps and flow tables. * Allow to embed set definition into an existing set. * Conntrack event filtering support via rule.- Update to new upstream release 0.7 * Add new fib expression, which can be used to obtain the output interface from the route table based on either source or destination address of a packet. * Support hashing of any arbitrary key combination, eg. * Add number generation support. Useful for round-robin packet mark setting. * Add quota support, eg. * Introduce routing expression, for routing related data with support for nexthop * Notrack support, to explicitly skip connection tracking for matching packets. * Support to set non-byte bound packet header fields, including checksum adjustment. * Add 'create set' and 'create element' commands. * Allow to use variable reference for set element definitions. * Allow to use variable definitions from element commands. * Add support to flush set. You can use this new command to remove all existing elements in a set. * Inverted set lookups. * Honor absolute and relative paths via include file, where: * Support log flags, to enable logging TCP sequence and options. * tc classid parser support, eg. * Allow numeric connlabels, so if connlabel still works with undefined labels.- Update to new upstream release 0.6 * Rules may be replaced now * Flow table support (requires Linux >= 4.3) * Support for tracing * Ratelimiting now supports units like bytes/second. * Matchinv VLAN IDs, DSCP/ECN, ICMP RtAdv & RtSol- Update to new upstream release 0.5 * Support combinations of two or more selectors to build a tuple * Timeout support for sets * Dormant flag for tables * Default chain policy specifiable on creation- set the url to the project page - pass --disable-silent-rules to configure to allow gcc post build check to work- Update to new upstream release 0.4 * Since Linux 3.18: support for global ruleset operations * Since 3.17: full logging support for all the families, including nfnetlink_log * 3.16: automatic selection of the optimal set implementation * 3.14: reject support for ip, ip6 and inet * 3.18: reject support for bridge, and reject icmpx abstraction * 3.18: masquerade support * 3.19: redirect support * Extend meta to support pkttype, cpu and devgroup matching./sbin/ldconfig/sbin/ldconfigsangiovese 16522525050.9.8-150300.3.3.10.9.8-150300.3.3.1libnftables.so.1libnftables.so.1.0.0/usr/lib64/-fmessage-length=0 -grecord-gcc-switches -O2 -Wall -D_FORTIFY_SOURCE=2 -fstack-protector-strong -funwind-tables -fasynchronous-unwind-tables -fstack-clash-protection -gobs://build.suse.de/SUSE:Maintenance:24179/SUSE_SLE-15-SP3_Update/66ac1bca1b33139dd80ec031930f1675-nftables.SUSE_SLE-15-SP3_Updatedrpmxz5ppc64le-suse-linuxELF 64-bit LSB shared object, 64-bit PowerPC or cisco 7500, version 1 (SYSV), dynamically linked, BuildID[sha1]=6ee2a870244df093e8b975b2f71c98ca56e84b1a, strippedPR RRRR RR RR RR RRRM„+Rߚ utf-8c8279aa69981dca6f82549d74c189321899936d9094d9e97ace70a7591077b27?7zXZ !t/;*]"k%f0]dZaȗ2v=ZB T#Iqi%ٜɵ9?]Q9؅.duķhε>a_)2 YͦES_3S1@.:Eη{}O~)/ bd,,uwIͱ6;;vCINӕ#u"I*_/ݥ~?bnW"B|GUY7#_0]i.~V OUh_bw*x=նpO 2Ba jKO9A8}rr+uĘ*Qx/,=ch_5u+cT43yV~x]̚am}r+"3!HKר ^k'.]gOoHR5"hu&?a b I3LTcu([;"=ZfTJG`ര o)#%b,ԅgCp\']qfsp=u)ǯQˍ`{Q"V}#'hR0WD'-قtRV"|49fQWkK*S#)>iZ| ;PQ];JJdD\AZV7Ir&-G]zHb2#oJa>iEaԺV;~>T.0!-hpxё-'g[_S?81d˺<҈5PR D<9 q"jځR a>(IL>:b8ޤ@Jfα'"k>4v4bsq1E|IV^AeE+,_3i<^+ݯHW$vbQz"T?W}"=gRkn5XYO\>e{p.pV,g̅Axnzf"W H;0dNJ@ Lr9?tz;& v_S2 ?D?s?u#G @+ôϑ$@(#vl^]H􏍎ey?šz%jL1sytTT-?YLbbQfd Ȏd1hS'Je'@'¦Օ+tHNhnNڿ>/ڛ ׮K2t Q&DֺQakDiDp^-4by 7&T$G"i\d{˝z2A]ng /P"AeytV >7]|[¿ x/fWEyPߞߤ8Ow/-kO=Nw0K ibha+gחB\*,nkGO̗v![ x۬UԐ+gLOr8mUX4~Tx)sؐ}ȏ*=D\q8>fWI%rGykPɥy\rjj%z6?yn;%]_w Z~Bk=o;e7:)Q^ MFo4)\D9ҐO% -gmaʻ[i&yVr$-}Y¾)@fޅ >auQuNwN愼Qmtk8fPٜ¬0wlK ';\۟826CzXqX^cb ԩ')DPOM'&G+^)l9=׏jbY 5扌ft.-^c*z۷^ ԣD1x/Uph}"z,$y23UXol;ڊ"/0{D$ٻCX9׀p4 aX-?-5cP_\ziql 咾6l*ƴ}a/6G u xs1 %y,(t= nPlXYVzVď0G\`&Dg#}s8u On&D}TnD@YDaa:| *֊K?-\*8>jdc>~W5ju1͛.j.|8|:iVGT*ޜ IasΪ}x4#wS(0!ϸx L!Ht՝8'}7>qUІb\3a~LRQ'00UxC+Uv]F!ڱҀٜ7xpe8>.Pzuӎބ:pdb&.ZJ@+Ѱ.3C0&)Uw{8]J SS5zMۥ,>%u@W@noS _ԏbٗ?p@_a٧ZXDs$R!J9Z: #}!Ɨ 00?? .%62*='i^j_F A;iyˡjo_=kv:$tnjҫxМmoJ +coĆƯ8ѱ1aWCc+89m sɐk z }dēpaM0>XDzsYwLJH-(\.X!~t;]ٙZƑ}쿧U2{ZIt,gJfGڄ"Gd|BglX':\/RFH<0,Ą 0cv}2K/uSyfz6c:N946ԭ@﶑g-h<#~uS᳙Og2}!xQhj[b:#;NqM9tGf]S^StNIsEfo&~429Ϩfܠ CSW;nDކPH*˩%z9Ywf(4֕/'#OD\J[~A ~x+"EB)WEK9?q֮MU}`&|mw9eBXiɿ[Ħ[r%)evݕJ~dXPzyd2۟KƗX$VfqX_s%Sy󡿋zĆ8C/ͬ-\l!9o+)bD#տ=myir+8SPl[9e}͸AE?}7U," .UOz!5c^v{ɇh*&` ѭ|+3 @Ȓ-vڥ}zF'ز۫WBy|8}-ۇr.ĥ'GD#6r͐DB1ݧvzoDO`Qc:JIGe8z5 % !#A!:;&`uhl.ܲΛsӇ5 sRȘ@MƊ?ГbO bq7euX'C.zkk-b R&Y)X65ͩJA|Ѹ-KUpISl@ t^O}mmMi9$@|5ACuJ?E(J\A<ȞoJgp!w?|+[)ę0mW%[cUh{2e"9'H0"!j%qVT> DpAbxTCnxYMۉ*"CewltX%w1H{ۘzπE0G2A|ACڜ,2IȔUMo` uMKf|AJ/ב> yT=`Sy"=S_HL_U#o!Z5P%+ e63xq26i?jYpG+Q}p}ZȮ<#Y"=ҷKR=hd~vg {y;AoI kEAΊ#kU |]̟MhWύ@xGjD%yafPY(8-E6_+J&稻 ]LM~ kTx-%BFVK݆'?C3ޘPeDbWGuj \'DF]5O4c/a%eyζe> 2}cV񇕩 .X7\zq)Pj@w,J .sM ӠK'ZbD2 &/a?Qǧ0ZۑK<\a jt9i+,͞'R|N0՘2`^N|D/=/躌^֬Dfzf) 3!ESMD+]uU0LM9gfKsx! IES^N莪Gf*@?U lY1۬+Beد2Q_|;y m,dcߘԷpr.jWEr5\6$\ƥd on1~kuR]M+|4 :#6U +9^tvd^HD ڋ2-vK/f- L]@z Pq swHpBcS;pİۜ%F*'XFF̣@P& x* !M;?y~ +Tn_d%#+\H% ]q_vbLDqabji.uG֧PFemr :_M+Zh}H; g9 &Hl/`ޅq~%@Gᑪ _o׀{"' 1UB*ʗs`Jo.+orKv@=[(e”V:r[9՛l=$-=J(5Ros.H0d? ;"oNJS*(ᦓf \!z%:Jb.F|R9d}Rm'=׳h5/ٞ[:sLAڄE[΋/53mX*e~] [I1i7nErtYp5Nӛ|ԅ}HDj}Y߈'{]OPO#WqwUr@;J[o&\gYz:|qM牵~bݢtw lyW=`&Gq!wT$D<XMⰊTPsXY`I8#Kl(zB%\ƌp:Ŀq9dRk6TwG 1v?@0RtrEOn*eS.wQNB:JsvTZ=ý2cS07scY X|ݒVﲢa7KrX+AteK.5i%Fr OV[f3' \$SYVfBn;66)'ZcEqhp^D`$J~b8#.4 ln)M{r0 yz&yev '_&7C9w?7U}iG;w%E˪a7%mn Ț9u |Bk=UuKS엯H>ƹ3Հ#U0aK)bKF&DDnN-hENu˦ }e蔺 \ _DUXVZkZ~S":r6[ʎO8$!'vh:*4J[^W{wBGfi`-G4 F]Ԍ[K>yb$_y_%1alP-˜z2 n hg508rХmjiݶ"mh7-4*ɦ&ƭ[6Q}Ha ʨ֌2{n!<@p x L͞Fe&}l&F 2#-, PLHU|N_/VT-=/Q8(dzq\Q6zv(|wdNøa:GMk;9dKjkfdk6}ky_FlRN+FrAH혚̨Í Qw,Vvk`rjJ+mlQِpgy7=}dh(SHKhhd›b@~aE>~6P=hY$Ϥ֊2vc+TQr78ӿ*$}s"|GЋ5@m(h/ M8$*}u뚃D;@+]hjvKC"Cb3Rm躙G sLg $Ʌ=3orxWsKLdqLlEy =c kr*GݖЁDb>U@۳Ň$J~$/=C k.=YPZ\w)¡7]ߡ6OcF5/ӟ"T*re]9"4cY5gRC}I."L̽-7`6=}KIo"\m\ٕak- e@YREzъN>M&5_m^OqCZ9IM9mL]ӲTs3Qۅ/^(=!a {mw1CVhKcTGbxVƲv6I%xUH6Av:9.%T":aob81roOWT(0)3Ȑ7w15|WА)Y}m1OʊKo?y5h<5 'd@c&2&tYYC8b-(:&wi@.;<2iejɱ:}*+jE9pz_[6&?$a&#>e۫:a;B+u#d/Zwdlۙ|R&4$$HuXOB̍%gKCb]u"Ѕ3*MʧF9ń%|:[h7, <LS3s}q.uET E CJ8>4W;3~j xPoyuVLۡwLF05-BL((>&|~t/֛H?f?،+M={K3;?G=}=_qs11GpIc>,H2DL&uo2Pp#g8C7gl_W1/.FM5w9{Ӕ\' >anZL`*"܍]\S{w?H:ea[GoLR &e>\KbN~|uEr'g4D@[YUiqR7yYvDbߡ ̝ou9J: RVaJZuf*= 7sfGe^PGɒIwؔd'&Klx]<`D>!YO$DVwj4P YZ