python3-nftables-0.9.8-150300.3.6.1 >  A db'p9|a@"wyshKbi|`W>᝜zW֌ M>̑c*R0~1u p> {4swbj5J7ToR$0>k4w8ZЩI. P /7]6@"3SkMā t=ZozZ~gR'fX "\ΟKLXwbp1z`nϒ\}Q`9|pk?2/_%TV?c40cd2d5efd61c4d3107ee55ff6f4eeb32887fef94a9d620d91d9bd6fecfcf51ba04f2ba6b1e3118d54c0cb6d64eca3fb7deef9aE4db'p9|&~~p>(?(d & Ddhx| %0P ` p    @h(89 :F#G#H$I$8X$@Y$H\$p]$^%b%c&Bd&e&f&l&u&v'w'Xx'xy'z''''(Cpython3-nftables0.9.8150300.3.6.1Python interface for nftablesA Python module for nftables.db'ibs-centriq-3rASUSE Linux Enterprise 15SUSE LLC GPL-2.0-onlyhttps://www.suse.com/Development/Languages/Pythonhttps://netfilter.org/projects/nftables/linuxaarch64o5n8YA큤A큤db'db'` edb'db'db'` e` e008fdafe301a4865af9a6fac1b3b3033fb1136e0f1d4ac14d309e9e6cecfa569311e5687d5aff2f97900bca92c7d768d1cb5711f31f0fb13816dba22eb3b633782f5f02a5ab34e7b756d6b46c042971e041bd8407478abcc1c07e3d7ec9c14925393a118a696f928dfda6f30203d11425dddab518fefb5af4687391c3dfc9477ceaa498a540861c56992f2d709dc41f0e807ada913bfb403ce72c20d47049b49c0f3ea8eba4398c730990b1d25fd82f86316ab606fee8e6ed71151ceb278a870rootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootnftables-0.9.8-150300.3.6.1.src.rpmpython3-nftablespython3-nftables(aarch-64)@    python(abi)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)3.63.0.4-14.6.0-14.0-15.2-14.14.3dGbo`_ ^@^ۅ@^@^@]7@]N@]Z@\C@[@ZZ@Z@Zu@Z]@YXY@WPU@U`kTmatthias.gerstner@suse.commatthias.gerstner@suse.comjengelh@inai.dejengelh@inai.dejengelh@inai.dejengelh@inai.dejengelh@inai.dejengelh@inai.dejengelh@inai.dejengelh@inai.dejengelh@inai.destefan.bruens@rwth-aachen.dejengelh@inai.dejengelh@inai.dejengelh@inai.dejengelh@inai.dejengelh@inai.dejengelh@inai.dejengelh@inai.dejengelh@inai.dejengelh@inai.dejengelh@inai.demrueckert@suse.dejengelh@inai.de- add 0001-evaluate-reject-support-ethernet-as-L2-protocol-for-.patch: this fixes a crash in nftables if layer2 reject rules are processed (e.g. Ethernet MAC address based reject rich rule in firewalld, bsc#1210773).- add 0001-cache-check-for-NULL-chain-in-cache_init.patch: this fixes rare crashes that could occur e.g. in firewalld (bsc#1197606).- Update to release 0.9.8 * Complete support for matching ICMP header content fields. * Added raw tcp option match support. * Added ability to check for the presence of any tcp option. * Support for rejecting traffic from the ingress chain.- Update to release 0.9.7 * Support for implicit chains * Support for ingress inet chains * Support for reject from prerouting chain * Support for --terse option in json * Support for the reset command with json- Update to release 0.9.6 * Fix two ASAN runtime errors- Update to release 0.9.5 * Support for set counters. * Support for restoring set element counters via nft -f. * Counter support for flowtables. * typeof concatenations support for sets. * Support for concatenated ranges in anonymous sets. * Allow to reject packets with 802.1q from the bridge family. * Support for matching on the conntrack ID. - Drop anonset-crashfix.patch (upstream solved differently)- Add anonset-crashfix.patch [boo#1171321]- Update to release 0.9.4 * Add a helper for concat expression handling. * Add "typeof" build/parse/print support.- Add json, python [boo#1158723]- Update to release 0.9.3 * meta: Introduce new conditions "time", "day" and "hour". * src: add ability to set/get secmarks to/from connection. * flowtable: add support for named flowtable listing. * flowtable: add support for delete command by handle. * json: add support for element deletion. * Add `-T` as the short option for `--numeric-time`. * meta: add ibrpvid and ibrvproto support- Update to new upstream release 0.9.2 * Transport header port matching, e.g. "th dport 53" * Support for matching on IPv4 options * Support for synproxy- Remove unused dblatex BuildRequires, only needed for the optional and disabled PDF generation (same contents as shipped manpage).- Update to new upstream release 0.9.0 * Support to check if packet matches an existing socket. * Support to limit number of active connections by arbitrary criteria, such as ip addresses, networks, conntrack zones or any combination thereof. * Added support for "audit" logging.- Update to new upstream release 0.8.5 * support to add/insert a rule at a given index position * meter statement now supports a configureable upper max size * timeouts for sets can now be specified in milliseconds * re-add iptables-like empty skeleton rulesets- Update to new upstream release 0.8.4 * Support to match IPv6 segment routing headers. * New "meta ibrname" and "meta obrname" arguments to match the name of the logical bridge a packet is passing through. These new names replace the old (misnamed) "ibriport"/"obriport". * `nft -a` will now show handle identifier for all objects, including tables and chains. * nft can now delete objects by their handle number. * Support to update maps from the ruleset (packet path). * the "--echo" option now prints handle id for tables and object too. * `nft -f -` will now read from standard input * Support for flow tables, cf. man page or https://lwn.net/Articles/738214/ .- Update to new upstream release 0.8.3 * raw payload support to match headers that do not yet have received a mnemonic.- Update to new upstream release 0.8.2 * add secpath support- Update to new upstream release 0.8.1 * This release deprecates the "flow table" syntax in favor of "meter".- Update to new upstream release 0.8 * This release contains new features available up to the (upcoming) Linux 4.14 kernel release: * Support for stateful objects, these objects are uniquely identified by a user-defined name, you can refer to them from rules, and there is a well established interface to operate with them. * Sort set elements when listing them, from lower to largest. * TCP option matching and mangling support. This includes TCP maximum segment size mangling. * Add new "-s" option for listings without stateful information. * Add new -c/--check option for nft, to tests if your ruleset loads fine, into the kernel, this is a dry run mode. * Connection tracking helper support. * Add --echo option, to print the handle that the kernel allocates to uniquely identify rules. * Conntrack zone support * Symmetric hash support * Add support to include directories from nft natives scripts, files are loaded in alphanumerical order. * Allow to check if IPv6 extension header or TCP option exists or is missing. * Extend quota support to display used bytes. * Add ct average matching, to match average bytes per packet a connection has transferred so far, to map the existing feature available in the iptables connbytes match. * Allow to flush maps and flow tables. * Allow to embed set definition into an existing set. * Conntrack event filtering support via rule.- Update to new upstream release 0.7 * Add new fib expression, which can be used to obtain the output interface from the route table based on either source or destination address of a packet. * Support hashing of any arbitrary key combination, eg. * Add number generation support. Useful for round-robin packet mark setting. * Add quota support, eg. * Introduce routing expression, for routing related data with support for nexthop * Notrack support, to explicitly skip connection tracking for matching packets. * Support to set non-byte bound packet header fields, including checksum adjustment. * Add 'create set' and 'create element' commands. * Allow to use variable reference for set element definitions. * Allow to use variable definitions from element commands. * Add support to flush set. You can use this new command to remove all existing elements in a set. * Inverted set lookups. * Honor absolute and relative paths via include file, where: * Support log flags, to enable logging TCP sequence and options. * tc classid parser support, eg. * Allow numeric connlabels, so if connlabel still works with undefined labels.- Update to new upstream release 0.6 * Rules may be replaced now * Flow table support (requires Linux >= 4.3) * Support for tracing * Ratelimiting now supports units like bytes/second. * Matchinv VLAN IDs, DSCP/ECN, ICMP RtAdv & RtSol- Update to new upstream release 0.5 * Support combinations of two or more selectors to build a tuple * Timeout support for sets * Dormant flag for tables * Default chain policy specifiable on creation- set the url to the project page - pass --disable-silent-rules to configure to allow gcc post build check to work- Update to new upstream release 0.4 * Since Linux 3.18: support for global ruleset operations * Since 3.17: full logging support for all the families, including nfnetlink_log * 3.16: automatic selection of the optimal set implementation * 3.14: reject support for ip, ip6 and inet * 3.18: reject support for bridge, and reject icmpx abstraction * 3.18: masquerade support * 3.19: redirect support * Extend meta to support pkttype, cpu and devgroup matching.ibs-centriq-3 16841542570.9.8-150300.3.6.10.9.8-150300.3.6.1nftablesnftables-0.1-py3.6.egg-info__init__.py__pycache____init__.cpython-36.pycnftables.cpython-36.pycnftables.pyschema.json/usr/lib/python3.6/site-packages//usr/lib/python3.6/site-packages/nftables//usr/lib/python3.6/site-packages/nftables/__pycache__/-fmessage-length=0 -grecord-gcc-switches -O2 -Wall -D_FORTIFY_SOURCE=2 -fstack-protector-strong -funwind-tables -fasynchronous-unwind-tables -fstack-clash-protection -gobs://build.suse.de/SUSE:Maintenance:28999/SUSE_SLE-15-SP3_Update/ed4025453dccbe5250bf320898c5bdb1-nftables.SUSE_SLE-15-SP3_Updatecpioxz5aarch64-suse-linuxdirectoryASCII textPython script, ASCII text executablepython 3.6 byte-compiledRRRR!4>$utf-8252ff647e9be5b84b2662ce7feece43b1dedfbdb32421d1aa12c35de3fc394ed? 7zXZ !t/x+] crt:bLL ` XQ-ug}RPɼa4_ĦgJwT1=99Yd ~L}Y/لj7 +Pr^W(q R九bӂ>}r 'ơg5CWMO{g'@Z4nNv"c.)zh7&1:{i@F) d{f^(16\;[EkKq $Z8%e{Kq)F1)UWg |UQe>Oo-Q<{7F@}n~V݌kMsi7 ܝ/iQyUmcRR gFGz)/o:ewqDE1>Q3X'bI߬2v{٪Bl0KxTfWI( mRbARkb7<~$ P|I-_e؞l-B'鮍Tl2U3fD1] Xس p^`&l*`xz /̲@4pYJ BgZ,Q< 5sAfTZG+x{ͼf"ȜfY.f1 .gT0?vl~&֐pq_&oPTsxr8DW+R^L%-MKRJd`9`(*'ڿ.kҳ׼KGޕ%qWt_[P0W٠;y:ƅh޸42|#CQk۶Aͨn9SN+Q_M$R>Lx.Ν>%Y~m9ƍi*~۴޸dx s|YL-/K@O(Ԣ@6J=ysI&I2)5 სxwRBa]+M^k=rz;;JUS0"dMsI6ea8M)^e+XMgId/.o1f#\[{n>t[ "9#;%6*[bWRɒ%$y1Bd"R$?ePE/{uXKV{fY9xqy]fRxI#%k&J"=MN&Va&Iݫ// r-z *,Q'Iaԇ1ɘ`WG 1/BraU6铽,UmdotYg#F)ڿRd̷sA].O1gQkVC?vOh I)~:𲺏w+T%%|Q_75J#{|8 =ޓk1U(k`y˘:7YSk+8|zoB ˃VX=a|+5Lad%H]&l:$oi7\ko=՞ݎCn 9z>@at$4i;)F+sщ\s.h J*-hFzC|y9 @"YF9YV|<<#Ch&!*8 ub\lHf/]1 G`B x '#(ȯEN&AO1WVhت8dۖ9(-ߚGqOC3M@">6h7o r3ȳ`qVW!?1PQ!7' DwnB0N AoP/ҵ"N(`3{z Տm⢔;nY<aE6 A3ςl=)ΎeCQYaw8(1؜ *e3Zz&W:# aG7\ISjn"G5X%I˦_䱇xk;Ԇ-Cvp=6^@P4Z ݖٹwU K1FjSRqarLԉ\jLb1?%<t"m/g؅I`TzP-DFCA2YcD9#)sOiQKsVQSbGac,FAp fRKPT-Srxe(X]* 3r" (,9,wEwd`@$<OTR_}-Z+ r1p\mqLk͊P%ODؕg0CFRm6=X-vxf:}M4M!-xUk,hv9k=jd}!%GZO-CK&1..S+ LMu@7!*(΄`]'bX4u8Y[{y|6]ȣ@NnIEVIsORcH*l702ѷ!gl3jBr6!bP:SpY(C./ƣi&{S!t(y2[r(RW.lcnaXLn SY 4.Hn#)7ɍ" \8 ulI MOs˛溘)HZ<-9mer%T(^q݃0SLedИYf?% ʲnJQ@T]^8ir:-ln`?A1bج (e@H5@SF:}Rdc8u<=ۙ>2a%UԸ"aab&soUHhd F7nvيi"`\h1֖bp8Um+P'Y*Cz2LUROjlw 5B­T \c}9"e2[}k ckV%\w4{sQo5ne?riQ DBܟfK_Nڰ7#!\g: #>FN]]Ak!2-8n^|XsAw2082:}g*4=9\<+P% RBHwr{+:m_ٝ`Pĝa9G}% Zs~[%l>"AАkŒ胹J^vJ+S;}ac.!ܧC]Pȯ%-Z& ;e~g_=&p[exP䄝 _8-XlT3[U:XO1T;Y0.QitO>(E0WnJԷfߪ9{d좈enFq`F%BaW37?1e*;J% Oll(lbt7^Vp,a7?b+oך{5w}%67_} M [(ic `D-@"(Ä+J[0zЂ"qbfIUC2]zWzr&zCߕzbbCu=|#J(`C3Wqp+ d$R9#$}qֳ̓%W ⧂5yq$,je/1"]F +h3;o ~0} Qg^w̝yM#}3NI[3lpag_VagmmFfwtHz1-()+1Fޔ_]}6\ax6ʤ\[I>hj~oi{!Z p љXQFv^< WᾴIMᣋns hhq^Pw&Dh 7$cb? +Z:* Nd85M<1d[2 ǤB~DZSrғ?h&`)0zk/\L %wR 5"`IƕZ&8[soahVp7RҌWM0q iG+0D6X. _NߴHJQ.l-ÍuKɠ>qէ5&<+42!ȅxmݳR+hU_vV GK)-j"Y8f_E !j;| s P&%|wq-Rj4CBhؽmh2eO'Vԥԅ+PA.5m*YSg2sdI pF2ZKAvKɝ'Gb Zo :b$f˞ եw"MiQ4I) eՐ"m<:eY/EJF"u ΰr#/+hoW&Az\C R'wC9 ŭ({jOlSo y'(0RJCDn_mm& nx"RHzQ`#O(2r/ X$/!Ec1|,0O/O$ߘ.gXcf\*R*LNI0)0sH/]w`,YFIҘj9n  ˖jCt[Y~bftK޽~p2.'z?<&$X< 'F)f b3DCW:+%k1U->J`q3|1K||7b=+Jh=mB$^=*)c[=HԞC)O@M6i!1!iC4$arq>s%1˷XF&]wy`՟b2KtlL zPnU)ʘ5Z=$ڞژ[|t5 A+o3N"m0W۫ чWݽ:Sn! u熲hV/"ꀾ6W V}_7}Hr_Dq٣&r W /#&<>GrN0 V ;nQB>P%;ql/baDoX]ҹYmwQyRbQs[a>yOfn-l( 07+- ޼?2j~ngbqu,pxP'MɊWpK=c(y bdEQ[ʭFg+[Ϣ;, ݴ/}Re/ǿ`ϔJWO]2S'KRZ`#XB{|d @M,Mݢt6+r踓wҖm^*b9t'TBBln 6ht ul}.^AdzpچQ' h@jOHFò$kyZswj^@tR`4un_ Nғ٩^Lo@ bZ1f9r쐫l>b;Dof}\^槵!5ѪA<]`ġ=K(