libnftables1-0.9.8-150300.3.6.1<>,g|db(p9|Iu֥' d约MQ(P8Skv_?T^aY䇑t|.@S̈́ &l9=E7lޜy%c'^'?fJ̟WQ_C5!D uF:STFC+PbŜ0@Q >"AL{kb:O !9SA+{Uu2/b .>K̾XK. dF585Mcwu$D$Hm}GxYt(L m>@(H?(8d " I ?ELT X \ d  Dk(89:>$@$F$G% H%I%X% Y%,\%T]%\^%b%c&7d&e&f&l&u&v&w'tx'|y'z''''(4Clibnftables10.9.8150300.3.6.1nftables firewalling command interfacelibnftables is the nftables command line interface placed into a library.db(s390zp36 (SUSE Linux Enterprise 15SUSE LLC GPL-2.0-onlyhttps://www.suse.com/System/Librarieshttps://netfilter.org/projects/nftables/linuxs390x (db(db(a804b4f0277b3570c3ab864803d88281a6d968b3c115933a86f4451eca8c7bf1libnftables.so.1.0.0rootrootrootrootnftables-0.9.8-150300.3.6.1.src.rpmlibnftables.so.1()(64bit)libnftables1libnftables1(s390-64)@@@@@@@@@@@@@@@@@@@@    /sbin/ldconfig/sbin/ldconfiglibc.so.6()(64bit)libc.so.6(GLIBC_2.15)(64bit)libc.so.6(GLIBC_2.2)(64bit)libc.so.6(GLIBC_2.22)(64bit)libc.so.6(GLIBC_2.27)(64bit)libc.so.6(GLIBC_2.3)(64bit)libc.so.6(GLIBC_2.3.4)(64bit)libc.so.6(GLIBC_2.4)(64bit)libc.so.6(GLIBC_2.7)(64bit)libc.so.6(GLIBC_2.8)(64bit)libgmp.so.10()(64bit)libjansson.so.4()(64bit)libmnl.so.0()(64bit)libmnl.so.0(LIBMNL_1.0)(64bit)libnftnl.so.11()(64bit)libnftnl.so.11(LIBNFTNL_11)(64bit)libnftnl.so.11(LIBNFTNL_13)(64bit)libnftnl.so.11(LIBNFTNL_14)(64bit)libnftnl.so.11(LIBNFTNL_15)(64bit)libnftnl.so.11(LIBNFTNL_16)(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)3.0.4-14.6.0-14.0-15.2-14.14.3dGbo`_ ^@^ۅ@^@^@]7@]N@]Z@\C@[@ZZ@Z@Zu@Z]@YXY@WPU@U`kTmatthias.gerstner@suse.commatthias.gerstner@suse.comjengelh@inai.dejengelh@inai.dejengelh@inai.dejengelh@inai.dejengelh@inai.dejengelh@inai.dejengelh@inai.dejengelh@inai.dejengelh@inai.destefan.bruens@rwth-aachen.dejengelh@inai.dejengelh@inai.dejengelh@inai.dejengelh@inai.dejengelh@inai.dejengelh@inai.dejengelh@inai.dejengelh@inai.dejengelh@inai.dejengelh@inai.demrueckert@suse.dejengelh@inai.de- add 0001-evaluate-reject-support-ethernet-as-L2-protocol-for-.patch: this fixes a crash in nftables if layer2 reject rules are processed (e.g. Ethernet MAC address based reject rich rule in firewalld, bsc#1210773).- add 0001-cache-check-for-NULL-chain-in-cache_init.patch: this fixes rare crashes that could occur e.g. in firewalld (bsc#1197606).- Update to release 0.9.8 * Complete support for matching ICMP header content fields. * Added raw tcp option match support. * Added ability to check for the presence of any tcp option. * Support for rejecting traffic from the ingress chain.- Update to release 0.9.7 * Support for implicit chains * Support for ingress inet chains * Support for reject from prerouting chain * Support for --terse option in json * Support for the reset command with json- Update to release 0.9.6 * Fix two ASAN runtime errors- Update to release 0.9.5 * Support for set counters. * Support for restoring set element counters via nft -f. * Counter support for flowtables. * typeof concatenations support for sets. * Support for concatenated ranges in anonymous sets. * Allow to reject packets with 802.1q from the bridge family. * Support for matching on the conntrack ID. - Drop anonset-crashfix.patch (upstream solved differently)- Add anonset-crashfix.patch [boo#1171321]- Update to release 0.9.4 * Add a helper for concat expression handling. * Add "typeof" build/parse/print support.- Add json, python [boo#1158723]- Update to release 0.9.3 * meta: Introduce new conditions "time", "day" and "hour". * src: add ability to set/get secmarks to/from connection. * flowtable: add support for named flowtable listing. * flowtable: add support for delete command by handle. * json: add support for element deletion. * Add `-T` as the short option for `--numeric-time`. * meta: add ibrpvid and ibrvproto support- Update to new upstream release 0.9.2 * Transport header port matching, e.g. "th dport 53" * Support for matching on IPv4 options * Support for synproxy- Remove unused dblatex BuildRequires, only needed for the optional and disabled PDF generation (same contents as shipped manpage).- Update to new upstream release 0.9.0 * Support to check if packet matches an existing socket. * Support to limit number of active connections by arbitrary criteria, such as ip addresses, networks, conntrack zones or any combination thereof. * Added support for "audit" logging.- Update to new upstream release 0.8.5 * support to add/insert a rule at a given index position * meter statement now supports a configureable upper max size * timeouts for sets can now be specified in milliseconds * re-add iptables-like empty skeleton rulesets- Update to new upstream release 0.8.4 * Support to match IPv6 segment routing headers. * New "meta ibrname" and "meta obrname" arguments to match the name of the logical bridge a packet is passing through. These new names replace the old (misnamed) "ibriport"/"obriport". * `nft -a` will now show handle identifier for all objects, including tables and chains. * nft can now delete objects by their handle number. * Support to update maps from the ruleset (packet path). * the "--echo" option now prints handle id for tables and object too. * `nft -f -` will now read from standard input * Support for flow tables, cf. man page or https://lwn.net/Articles/738214/ .- Update to new upstream release 0.8.3 * raw payload support to match headers that do not yet have received a mnemonic.- Update to new upstream release 0.8.2 * add secpath support- Update to new upstream release 0.8.1 * This release deprecates the "flow table" syntax in favor of "meter".- Update to new upstream release 0.8 * This release contains new features available up to the (upcoming) Linux 4.14 kernel release: * Support for stateful objects, these objects are uniquely identified by a user-defined name, you can refer to them from rules, and there is a well established interface to operate with them. * Sort set elements when listing them, from lower to largest. * TCP option matching and mangling support. This includes TCP maximum segment size mangling. * Add new "-s" option for listings without stateful information. * Add new -c/--check option for nft, to tests if your ruleset loads fine, into the kernel, this is a dry run mode. * Connection tracking helper support. * Add --echo option, to print the handle that the kernel allocates to uniquely identify rules. * Conntrack zone support * Symmetric hash support * Add support to include directories from nft natives scripts, files are loaded in alphanumerical order. * Allow to check if IPv6 extension header or TCP option exists or is missing. * Extend quota support to display used bytes. * Add ct average matching, to match average bytes per packet a connection has transferred so far, to map the existing feature available in the iptables connbytes match. * Allow to flush maps and flow tables. * Allow to embed set definition into an existing set. * Conntrack event filtering support via rule.- Update to new upstream release 0.7 * Add new fib expression, which can be used to obtain the output interface from the route table based on either source or destination address of a packet. * Support hashing of any arbitrary key combination, eg. * Add number generation support. Useful for round-robin packet mark setting. * Add quota support, eg. * Introduce routing expression, for routing related data with support for nexthop * Notrack support, to explicitly skip connection tracking for matching packets. * Support to set non-byte bound packet header fields, including checksum adjustment. * Add 'create set' and 'create element' commands. * Allow to use variable reference for set element definitions. * Allow to use variable definitions from element commands. * Add support to flush set. You can use this new command to remove all existing elements in a set. * Inverted set lookups. * Honor absolute and relative paths via include file, where: * Support log flags, to enable logging TCP sequence and options. * tc classid parser support, eg. * Allow numeric connlabels, so if connlabel still works with undefined labels.- Update to new upstream release 0.6 * Rules may be replaced now * Flow table support (requires Linux >= 4.3) * Support for tracing * Ratelimiting now supports units like bytes/second. * Matchinv VLAN IDs, DSCP/ECN, ICMP RtAdv & RtSol- Update to new upstream release 0.5 * Support combinations of two or more selectors to build a tuple * Timeout support for sets * Dormant flag for tables * Default chain policy specifiable on creation- set the url to the project page - pass --disable-silent-rules to configure to allow gcc post build check to work- Update to new upstream release 0.4 * Since Linux 3.18: support for global ruleset operations * Since 3.17: full logging support for all the families, including nfnetlink_log * 3.16: automatic selection of the optimal set implementation * 3.14: reject support for ip, ip6 and inet * 3.18: reject support for bridge, and reject icmpx abstraction * 3.18: masquerade support * 3.19: redirect support * Extend meta to support pkttype, cpu and devgroup matching./sbin/ldconfig/sbin/ldconfigs390zp36 16841545240.9.8-150300.3.6.10.9.8-150300.3.6.1libnftables.so.1libnftables.so.1.0.0/usr/lib64/-fmessage-length=0 -grecord-gcc-switches -O2 -Wall -D_FORTIFY_SOURCE=2 -fstack-protector-strong -funwind-tables -fasynchronous-unwind-tables -fstack-clash-protection -gobs://build.suse.de/SUSE:Maintenance:28999/SUSE_SLE-15-SP3_Update/ed4025453dccbe5250bf320898c5bdb1-nftables.SUSE_SLE-15-SP3_Updatedrpmxz5s390x-suse-linuxELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=af5165343ed6b4a33123251133880aeea68a6e45, strippedPRRRR RR RR RRRRRRRRRR R R*zx 厁=utf-8170dd97d68491540bccf3f9c8fb9915f83e2ad6ac62c3f996f037dff0888e7f6?7zXZ !t/M:]"k%f0]dZaȗ2v=ZB T#IE,:lW?)6]]Iez+f6e"v,N '8X_lY2m(%}Mdjߥk.{?F8 ,p;2SŲ͠[-yY'Mӳ-rЌc5^OvqV ynRq#浲]L.`©Oq*5O&H}1-9_Z^GE N;2# ډo%-m9:v>ˈBU';vn;^!_͚=Ϛͬ,_}qCѷa_|e=wm" )ħ0\n>pQDtOf;hhv١4x懌^3s$ux~+Pr[n1k'|Chn.B,%^#r`=(\$qEvH3#g \W'0a-*W=yK$ԋdrq:y00ZkByUr݀ ƣLd<Z8qx!h-%[6I8zOERMq[Oniω'v-kVmhULvr'qqn dFݍqK(*Ij9Ԅ_`ǂ(mk|t`s3L_ 5.Ork(y%GF֥`$j9$^3ZY}r8nXL15[)f g|<Ӑ>}ZH ś;;R69xTey>ù1w:3hH?}; Z}ek?^HyjD^u%@Q(eR$vy—_ Q 4sm3o2nSz#MZyH!V?p3ƒK6^wpFe>S1eP"lT"m#m _tZdOY:)O"4Bx 6A&@Ekh;5,IKh;z=mcnŧ"^1~m E}ac(,ZW'L`J3lE?}h61mC5m@<"|̂G%=蟪0Bibpɦ14q^ 3(RU_tNx3@1LIQV@Q&2S sq.LH'Oƻ&9'vJ-@XEAV nՎLBi66rIuQDv -3`K¢Ym8%kWJ5xa՛,eY2RMTޣ( Pl@s#jt ǘ7_bV~J渣iR瞊 b. 9oTV5oLsUse1]B 9āFo2=Ox"YVL EهQ7-Mh];pY.܉ҙfr$9 q!r<9c | (}~g q' oN'xNU^o*NNLi?4fM?VOޫ&.58M{BRi˔bm^rFeb~*ij@@؍8,yB"ό_Ht?p>|Y9E ؝7WoX<<$~e]j5(ܻsI壍-L S=A^ֆveP.SioLW-]VÂ{A5/O-~ЂW)%ۅÚz*%8%J=\0T: K4jqN5z=F%R@8{o AM_'MJ) ܤJ Cy*!f8+E+MfNKk?x߃IX{\R LC9g-pޔy4XF şơ yζAGYWMWUbE' T/u~C yR#tj?G/yh[>1:'F)uF, _g7 Ҡ#xt^,W6X+W4M|2|+x\Ret0k]3%t@/>~;P?hpK+ex dn W6L-}db+i'-8һ8: 鵮7=AOh2}:tݒzկ$efZv2_Yԑ KdAo~"W)4 #7O!xcn0_\r9*jk(uu_1:8u q ~<6S "#k-`V8R;"x ރJ{BdJb75!: \ [2Mᘃ]Z)6pCKlxj3(o;WԊ֬U\b‰ĺ򔌩!Pz m|7]-%Lp֖e<2C".x7) [jLlfk,)ݛC|JL3i^Z_ ,b@n!~]r`*G\q kV.gQ?odVFps 9ӽGUODany`\"# c2g#S$#yWQ]8Gb!Pob~/$qRWFTg H< 6 i<^Gq4# 2#D#{0S s /dJԖwm˨.`V2ź:8y5m77P펗 (xteińNc鐚Q$a., P %^t7+y4kZ>f!J, E(iuSڜ!&9.j&Lϵ-fzI]mtbBʗƐ-J;r8jvQkt"NlnK<%I!f}ʥ#)&:Д4R#!i*_ TP¾c,.yFҭ*6;[yOQsʑ ~'=_neeRM$(O-xߗIR~ՋcvJ)Nj2+{! QQg :TI^} W wV0Gg5]<Ѓkp;tv{ۜx$,iI5C>t9X}|(A}NAښ_TbYHW#+ג,ŀy]{o"3rbgRr|ա)#b]·r) 4UsI^O$Fc; |Ě]A5L+^jO=7GsO0n$HV.LF1ѩ\8%vbfեBk׊"O ]٘gס UP JꑲrO0K/I!UL`"j>XJ߳"gK۷3S@vg)>>b_+/nrHi]fg9x]X{':#-AeIkOL̶2|s uRhù,\02kәYv. } 2<\Ulzڔys8;1V1@Mg(-t1o;MP5HS.ʮу.ŤأbVENi) c%d%yEL'it<1rPXw mA嬗$xAA{n H7l2}=г}] /c[2j2oE*K >*,FwCZ^ ^Pteh>3AڎMIv~ݞ:4 f7]L z-,X@LI@s0ex׾/@طŤ>3'Ny{(nX "mZW3ʤs=X' >޾"Gp'U>螭3z7A،JDZ4PM=̹\t^`دɿ)qV۱L#.4$y=T&^ԊjPU}O$jbžöUuA(# /Af݃ya\w+W@\M\Β Ӷ͵ĞLMZ+?XHgܴ~mD;ެ:>+('zSR妇=kF8@!PMvvG6p0NF?bzw/lwd!hCsAY-Bp؇3Ό0MC1%r:#cpB!f@gk <^$КMsNqaL9O.( ?!S&fe OgT1j}bVHK2L87LPCq} n}D4:Z1tD͎2俍\d*iC'x.W[T\P[r!xaBsQX[>Ip[zafW&JݗOy ޤ˥v;sǟtvqO8cd&Gʓٟ*,ʠP )Q $x 17$^!{m(=-nPJUϪS.{r$,R9Ew19Zkʒ`SSuFv+%E7ȾRzFmX/k2Dm֮)A*"5΢0 y5N< LR^O߃bDhTs ڇiuH{1ܧ} \ȁ .&@ix53vW4ܣiGG,CA0ˢPTNlv_8) G{Wխ?|'!lձzV4dz9v ]zL`deN=3MZ?x &蟉4zf6hWj+^dΞ{altxO̬  s*cw>|1 KaYp/t'A )\  vK/ y?+OzU?.Cm:S6u J1U,6xU`MG> 7"JJ pPKD`W iĝ$ՁQ@\\D87-'x@BU!>4N"JݼĴD5/ݒ*W7ۂLB(.l3*$黢G{`u|Q̫Z|Yߟb^v\­zĤ"fgeʅuYOU~H.KPDxWMMnrT[KqB%WRjM:&VA[@rzgZ𴱬TˡEgis$SC/)G$VSNkzs!-$Qko5~u+7x7Ad䐒h/5!y)hU:?Ӕ1xTA|:;Sxz yMfǼ$A0la8h4vMXHJnB-׳1T.sxv@qп\3nkx#jSi+bY`$a&fV_CgnQa(ms tPs'pr8{+U`R QW!ՖNsbn>& 1WV׳c #l؎-FDA,ߴn>+F_؂lQMI 7hB/н Lce-–z޼blNcT\!Un Sc(!~nzu5zvyZf=Mۆjߋh{YR@;+hP>|t(\|oFy9qp#D?WyWп EmH[EΟ{?a$o&¶}&K]R9_pS.Cֿh!ͫ>(ԵƒZ$Վ6`"&HwU~fvaE Mlۤ9{JwVq+P1b%_a]g live>¹4צ K{˖,ѷv}C-tKϹtnb6+>@xHmqPhs)ĦQaІ.b@&ya\5[[AA6&"SS}dUr Ny""j״8}V b1<Ŕb>=9k7Ɋ†'IrKQ514{_]fvK].*YQ[{bƭʑa׷{j/J-zݚUE*>:Sp KJe(l gۀSgfNˑϷra_'(i w}V#^ w. $_Oy쮛+~Eܭhc8ܓ<4GvّͳKй s.L9SN l3͞ətO2`Ń>`]m%Y[+Nl,b45'eQn+4Zu=*Pvbdt^Yye5r^ϥj5E{X\~ؼE|fekzP7Q<*jtk1/F В6am[Dk7e<|yEb s4hc&4 TTI1m#^師Pr0vCќ\m6F,Yft,Ƭ7+7mv07evpt{C4WNR)&SL# ȍjL/T(m_7!}fn}XCx.ҍQ)lUJA}k*=A5NG5}hkЕOXVFq{!1YB:qC̭kL%3<~9E5:[+2kĻ}IeFeǕ (N~G𭗻}"Lߜ*β/ n'QwЊ8\0aXX G&Hj{: "<qg˴eQ@h@׺SRC¾3Lҭ=_2M_QMR&!*Yd3 J2M'j\ *6ѥB|B Prdp$:R5W{ŝOw2Ny*Y` & \b懀5Soܾe*Eߊz{=|4[⣑ ;L0B#iO )\MyC֐v3uDBbz1:O4.FjXqK5VBV Sw +ȯzܠX0:ϡdOFs7I~e/ɡ]J""&"SVREWLQC3$͠e33d PLaJQGY,< j _ {cW†S%iPMuk;=3$Y@߆M<ɾ]jFы[H^yۨ=yڴ*cϔ4_0@kFh[& zn[:uL !VcjTi)O8wA9.D *Ȭwn;]rz8H*jÏ68t5Y&qkWq N<-B74FuעZcofbWdP6cArmd#*WL eN29-*cO0ij ݋SͱE("xʛ aRg!ە4!޿j9]׸HiPNVUPm% k{6 vKYjr#9 >.סּdp M4QTw$# M=!w%Ew./ŔvM^}npl`C)A @[-|`-[ \RHST:=VB iz[-c/@1Q!EZlك?Ј-䜙W ۵m/"奂E=ahD=4?Nk0&{J7>1OLS;HGY_4:VeIy+LjdkU~A6G"~@vP~$;J.|-cی˂cG# 6GN6{ukȨewg>"0*A2t"%>Ť2C}ByuB&8ry;.r]q5|jJO[ܢϧ<6I"uF[C_+6$oo5vtӔy[L.D[ĶEHTUVLܳ¬P;/W,\f 9ySftDl+:l΀mh7s=-쌸%jfF3}/c\z8~e$.]W,d@sNx$ !v"eю hxX,+MO2Tמ׎246뚰QQ+?9: eG6^ڸr .r] } ,[e6&>˦ho4>W t;C6ĺ ׳Ay4bH$ie_%*C|[i,|΃Bk{ 57a. x܄IĘŵ M`ݐ=tp K`̞ P֊ݡ ^nJKf0<c`*tYr3W%4`)Wo}S< Z3H7۫g9mbn"u$}׵}TMdoV1񩶡5FP/| @&&Xҡ$fՌ$߲9ݢ9T9_ضV##urZK7s G&NEcs1 Βz޶ءBZPK=[cO͘K1U_&C`?[*A_9θB]Nu;ʜ$G< I9z(u\ YZ