libnftables1-0.9.8-150300.3.6.1<>,[db(p9|=2R ;q^J\Pa ?KOC A|E)"SF vgx8XE;ڔvx&R24=69*/$j[E3Bo96]ܘ954!)s%;^#UA|21!{c2YgLf>x/0-q=fұkyOhVPR6 O8‡<\! U\SӃKg 7xJ۞7]j" E>@(H?(8d " I ?ELT X \ d  Dk(89:>$@$F$G% H%I%X% Y%,\%T]%\^%b%c&7d&e&f&l&u&v&w'tx'|y'z''''(4Clibnftables10.9.8150300.3.6.1nftables firewalling command interfacelibnftables is the nftables command line interface placed into a library.db(s390zp36 (SUSE Linux Enterprise 15SUSE LLC GPL-2.0-onlyhttps://www.suse.com/System/Librarieshttps://netfilter.org/projects/nftables/linuxs390x (db(db(a804b4f0277b3570c3ab864803d88281a6d968b3c115933a86f4451eca8c7bf1libnftables.so.1.0.0rootrootrootrootnftables-0.9.8-150300.3.6.1.src.rpmlibnftables.so.1()(64bit)libnftables1libnftables1(s390-64)@@@@@@@@@@@@@@@@@@@@    /sbin/ldconfig/sbin/ldconfiglibc.so.6()(64bit)libc.so.6(GLIBC_2.15)(64bit)libc.so.6(GLIBC_2.2)(64bit)libc.so.6(GLIBC_2.22)(64bit)libc.so.6(GLIBC_2.27)(64bit)libc.so.6(GLIBC_2.3)(64bit)libc.so.6(GLIBC_2.3.4)(64bit)libc.so.6(GLIBC_2.4)(64bit)libc.so.6(GLIBC_2.7)(64bit)libc.so.6(GLIBC_2.8)(64bit)libgmp.so.10()(64bit)libjansson.so.4()(64bit)libmnl.so.0()(64bit)libmnl.so.0(LIBMNL_1.0)(64bit)libnftnl.so.11()(64bit)libnftnl.so.11(LIBNFTNL_11)(64bit)libnftnl.so.11(LIBNFTNL_13)(64bit)libnftnl.so.11(LIBNFTNL_14)(64bit)libnftnl.so.11(LIBNFTNL_15)(64bit)libnftnl.so.11(LIBNFTNL_16)(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)3.0.4-14.6.0-14.0-15.2-14.14.3dGbo`_ ^@^ۅ@^@^@]7@]N@]Z@\C@[@ZZ@Z@Zu@Z]@YXY@WPU@U`kTmatthias.gerstner@suse.commatthias.gerstner@suse.comjengelh@inai.dejengelh@inai.dejengelh@inai.dejengelh@inai.dejengelh@inai.dejengelh@inai.dejengelh@inai.dejengelh@inai.dejengelh@inai.destefan.bruens@rwth-aachen.dejengelh@inai.dejengelh@inai.dejengelh@inai.dejengelh@inai.dejengelh@inai.dejengelh@inai.dejengelh@inai.dejengelh@inai.dejengelh@inai.dejengelh@inai.demrueckert@suse.dejengelh@inai.de- add 0001-evaluate-reject-support-ethernet-as-L2-protocol-for-.patch: this fixes a crash in nftables if layer2 reject rules are processed (e.g. Ethernet MAC address based reject rich rule in firewalld, bsc#1210773).- add 0001-cache-check-for-NULL-chain-in-cache_init.patch: this fixes rare crashes that could occur e.g. in firewalld (bsc#1197606).- Update to release 0.9.8 * Complete support for matching ICMP header content fields. * Added raw tcp option match support. * Added ability to check for the presence of any tcp option. * Support for rejecting traffic from the ingress chain.- Update to release 0.9.7 * Support for implicit chains * Support for ingress inet chains * Support for reject from prerouting chain * Support for --terse option in json * Support for the reset command with json- Update to release 0.9.6 * Fix two ASAN runtime errors- Update to release 0.9.5 * Support for set counters. * Support for restoring set element counters via nft -f. * Counter support for flowtables. * typeof concatenations support for sets. * Support for concatenated ranges in anonymous sets. * Allow to reject packets with 802.1q from the bridge family. * Support for matching on the conntrack ID. - Drop anonset-crashfix.patch (upstream solved differently)- Add anonset-crashfix.patch [boo#1171321]- Update to release 0.9.4 * Add a helper for concat expression handling. * Add "typeof" build/parse/print support.- Add json, python [boo#1158723]- Update to release 0.9.3 * meta: Introduce new conditions "time", "day" and "hour". * src: add ability to set/get secmarks to/from connection. * flowtable: add support for named flowtable listing. * flowtable: add support for delete command by handle. * json: add support for element deletion. * Add `-T` as the short option for `--numeric-time`. * meta: add ibrpvid and ibrvproto support- Update to new upstream release 0.9.2 * Transport header port matching, e.g. "th dport 53" * Support for matching on IPv4 options * Support for synproxy- Remove unused dblatex BuildRequires, only needed for the optional and disabled PDF generation (same contents as shipped manpage).- Update to new upstream release 0.9.0 * Support to check if packet matches an existing socket. * Support to limit number of active connections by arbitrary criteria, such as ip addresses, networks, conntrack zones or any combination thereof. * Added support for "audit" logging.- Update to new upstream release 0.8.5 * support to add/insert a rule at a given index position * meter statement now supports a configureable upper max size * timeouts for sets can now be specified in milliseconds * re-add iptables-like empty skeleton rulesets- Update to new upstream release 0.8.4 * Support to match IPv6 segment routing headers. * New "meta ibrname" and "meta obrname" arguments to match the name of the logical bridge a packet is passing through. These new names replace the old (misnamed) "ibriport"/"obriport". * `nft -a` will now show handle identifier for all objects, including tables and chains. * nft can now delete objects by their handle number. * Support to update maps from the ruleset (packet path). * the "--echo" option now prints handle id for tables and object too. * `nft -f -` will now read from standard input * Support for flow tables, cf. man page or https://lwn.net/Articles/738214/ .- Update to new upstream release 0.8.3 * raw payload support to match headers that do not yet have received a mnemonic.- Update to new upstream release 0.8.2 * add secpath support- Update to new upstream release 0.8.1 * This release deprecates the "flow table" syntax in favor of "meter".- Update to new upstream release 0.8 * This release contains new features available up to the (upcoming) Linux 4.14 kernel release: * Support for stateful objects, these objects are uniquely identified by a user-defined name, you can refer to them from rules, and there is a well established interface to operate with them. * Sort set elements when listing them, from lower to largest. * TCP option matching and mangling support. This includes TCP maximum segment size mangling. * Add new "-s" option for listings without stateful information. * Add new -c/--check option for nft, to tests if your ruleset loads fine, into the kernel, this is a dry run mode. * Connection tracking helper support. * Add --echo option, to print the handle that the kernel allocates to uniquely identify rules. * Conntrack zone support * Symmetric hash support * Add support to include directories from nft natives scripts, files are loaded in alphanumerical order. * Allow to check if IPv6 extension header or TCP option exists or is missing. * Extend quota support to display used bytes. * Add ct average matching, to match average bytes per packet a connection has transferred so far, to map the existing feature available in the iptables connbytes match. * Allow to flush maps and flow tables. * Allow to embed set definition into an existing set. * Conntrack event filtering support via rule.- Update to new upstream release 0.7 * Add new fib expression, which can be used to obtain the output interface from the route table based on either source or destination address of a packet. * Support hashing of any arbitrary key combination, eg. * Add number generation support. Useful for round-robin packet mark setting. * Add quota support, eg. * Introduce routing expression, for routing related data with support for nexthop * Notrack support, to explicitly skip connection tracking for matching packets. * Support to set non-byte bound packet header fields, including checksum adjustment. * Add 'create set' and 'create element' commands. * Allow to use variable reference for set element definitions. * Allow to use variable definitions from element commands. * Add support to flush set. You can use this new command to remove all existing elements in a set. * Inverted set lookups. * Honor absolute and relative paths via include file, where: * Support log flags, to enable logging TCP sequence and options. * tc classid parser support, eg. * Allow numeric connlabels, so if connlabel still works with undefined labels.- Update to new upstream release 0.6 * Rules may be replaced now * Flow table support (requires Linux >= 4.3) * Support for tracing * Ratelimiting now supports units like bytes/second. * Matchinv VLAN IDs, DSCP/ECN, ICMP RtAdv & RtSol- Update to new upstream release 0.5 * Support combinations of two or more selectors to build a tuple * Timeout support for sets * Dormant flag for tables * Default chain policy specifiable on creation- set the url to the project page - pass --disable-silent-rules to configure to allow gcc post build check to work- Update to new upstream release 0.4 * Since Linux 3.18: support for global ruleset operations * Since 3.17: full logging support for all the families, including nfnetlink_log * 3.16: automatic selection of the optimal set implementation * 3.14: reject support for ip, ip6 and inet * 3.18: reject support for bridge, and reject icmpx abstraction * 3.18: masquerade support * 3.19: redirect support * Extend meta to support pkttype, cpu and devgroup matching./sbin/ldconfig/sbin/ldconfigs390zp36 16841545240.9.8-150300.3.6.10.9.8-150300.3.6.1libnftables.so.1libnftables.so.1.0.0/usr/lib64/-fmessage-length=0 -grecord-gcc-switches -O2 -Wall -D_FORTIFY_SOURCE=2 -fstack-protector-strong -funwind-tables -fasynchronous-unwind-tables -fstack-clash-protection -gobs://build.suse.de/SUSE:Maintenance:28999/SUSE_SLE-15-SP3_Update/ed4025453dccbe5250bf320898c5bdb1-nftables.SUSE_SLE-15-SP3_Updatedrpmxz5s390x-suse-linuxELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=af5165343ed6b4a33123251133880aeea68a6e45, strippedPRRRR RR RR RRRRRRRRRR R R*zx 厁=utf-8170dd97d68491540bccf3f9c8fb9915f83e2ad6ac62c3f996f037dff0888e7f6?7zXZ !t/A|.]]"k%AKqx1@Q¥|p縱q2%& -y:E&ρ0l>`"6:N)V9JHJ ġg% xAb\{_;ls0 ̰8x*vg,)as%Z3~*ockF}i!BƊE:5gShxcn-AO~Vŋ4/lv8d'v#֤FԤP:Z>4(+560V[YCl tv&U$oqe&FOsټƼ*zt DZ s.$,ٿN)n'tٙ4έ)bw'߽ C^zY(70&bRCDY(J"VWiHjIX21S,х#FKZ" we5%&ӊ2)> \0vS݊<SW&Kp_kɥU: &WHzr;^J,*Yd}(o )ykqA/^1/6\?T#퐘3|^?җ4g'5;|z7vb氬IR/K4RGr<]VXOI`W0~Suƒ]G&ƷOF?q ՉE]H˫{TD8݉Rʂ+F>ՊZӜjJe|[1HT2\Vzh!)r_8-\*> ?~G;'3. ȽpN_ En#!1iԄ}|IƗ1TZD]1-N]7n{=gn6V9j9;5fx$kg$'*/JϾ݃ l,a!'6AhJҋ6L%Y&\6o3ؘ =C3o=7jeR lN\7q=6~4\EF0΀ԪA%_jʌ9#:8ty*솿kyH+R\BJVeGSQaŏY䠽cJgFZ=t{}n?T6MOۖ!0 6p[Ф(Xa#c g~ B]Y |er fym=Kշq7'Ktu\N'QmS7dyKZ#xRf˾kz0vI/~|a87+u]G⊯e'3xr۾4`"ډDb2f94Z,U *ͣf. N8@]P?N:}D4A.S'n&!a*!*r *q1gJiKó?=K^4ɼ|Gp1: [soXP x4fY!1{B֞6e~05SIoiH5f5bڋV=!Ob ڈU{0ƍ,ns1kxYN0Qt*RD}kGu|` |}Ne_<@~g8DsߺWȈ+fQ{D8 Ң0AqL]9> 6%KY5ܼ=wTD_eq""/ CAq7+r 8\0w̭–Y=H)탐^&AR՛p$hz`l{),- Є n&-0ŝa~HԘ#8&o8v7t`ZZOX4ٌǑBeb_Ǥp95/Ѻg!!e4`duUJbzcådfi1 (CBkDfBi&{Èq(>loHZXo^~poײ%b/BYUP)!zTUOoyR胳Aj"NjT==9JICH|I9Iciz_BhF2X WNvJO>S`A+BEfQ8js Wh-I1BFeGtjyo;H0`xXn%tX˔O!NDayEO8J71Ǐn FFf HOѾ΃G3" MP_j O쪗ps_tpk*prtPoԺ2)~2I&ͅ_e4KxJWb=,,PXʣ&&O}\WX8ʬT2zGC9ҵc`ַA|oiI(JՄKvWFO*D) j:%!Ǟ?x8D"QS ب)+NDh?ͥNe[+]c qBedR83 0bkcf Ύs"}8GPJzH~ټ|r: 66/H~ONךOL~5bTRް4rxMy).ܾw~jHHԌ.̍ _\Nc{Ω1 iQ,ΒbLpk:pod mT@ã%Y3rQhby#n)W+g&rn>kqr[L2$gRдARf(SS3FnÅ OT2K;B'M(fmTAWnן(\g=-&(ٴ-c97#܌Iitf,$4a9Y3ik~itIJ r2SƭpԬA]Aj/!,3WuCz^p)oBR"!fy|]PLV9R -1IFB$-TVb Vl0=P4JI2Л1p2^>j1}l <=D ςKmDs02Uԧk㣴DaT-t95^mh[D4@KC uӎZ?կ{ĩSݘoҦKZ[#) |OW)0 {-=)Ŷ>(:NEgb{EPeoaRE1!F2&NEJH ˙ɂr+J<|@XffƪV ɂ'ײoDini-:zv[dtC»#~S ʊ?^Sj$_RxHlN ْ&RsD%]bU,`Ԝ"I=k}?E㑱R>PfI^5Z>tESǖoل&Mʉ|!?["hØKl:,x79bZ% 1ffX}^% BJ9b[yxYozqٛH~͕̩|8d{:%^Li1u! B/(f!%Dg19wwݺԙ@W쎲F#!56g+X[[Ym<ZğB}W0>7.o2 ~*ae@6fpHhgFulސ{_-w Y"hEV ;˞Zq3i4aG^B^P l`z䞎0vhjvz=/EJR{ -̮(߸a?~Y#M"5+}8tbl5*"n7ҽ$S&jiubK-!*\`z.U|dr,Q{JWv>BdXIlт& S ,m4]sߑn9BH簺 XљØrU%ԤŇ @%q;Ar~݄cz#e)uBKF88);ʱ-}:,'Iy`>ު(h#4OR" +]Dظj Hp.Du*u9`B<04*m ˊ£lf >8~mҵ%AC2pT}W7~Z-{G f#RǾK~+(Oty&~WG{ɼOwL|¸6 [ʕ1`o Ky]r3uټ>#qddsx I:e}.lkn =}!Y>0rgupg<0c]//fEhUkr;Cv 2qFLL4] 62b q ȊA)3IC-'_). /qOivcS B76'3&<Ƚm/VHrN;YV~[bA?sjӋSL֯h:R[ G) SXs;:t1_fqo<ZN pX'T{}k$+&b.KL2fx؀YGX7Dw\7>a_nk3HN@Tm1<䑿sԑjh="H@cU}u UuM6w:ڍ^Q( XTW T@Zu l> {<'j8W̡lM'e0o_"NSֱqrl7\)B?L;Z퉑?TIuЛs`IU.oNINb1Ժ.J7p޹sSiW~Nk95sY KWHǙBڧ޹&Vd[&y(r@ƹ R=,go˩~,e2u$58/o@)&@z.J"Sp}K֪:@]9דaJk AS' W17+mBւ)tWMIL;\cKԜcRBેLM{Uk>Bcɦ0(LV@dܞ`/chXe[2\Iwf'I]BI?:^vf) !r϶mFTQ,w%C_ULGƐ EpHCԄ%bJg)I(T®:R3^Ŭ&fhy9MV =HJ/|u]|^AG *gFo4ʺ8qXu]HjT^JXbN1YMÁn5Xb6RDPksiΑ2Hlϗ:0yXZzcWʞYe<2 ِ<I{vF~;$F' t 7;7G&[ zS9bp.b#lT(CuC/CB.AǾsB@9R&ݻ9ڛP@Ik[jx.gh}ieIaE7OP=!hjRRX_GPO]@s% R+je5r\s}#EC[d'#)^}ڕY}Nwi2M'l Jc=Fe<1}V;㊶m͈Qo1ׄQ0| a {ܠ=L rF`K`I5K]}\Uݐs*Dp1s22Ӄ26YYRk΁~x Vưr3 bG \y68OR`>jKr(nvנ@[;օ7r,rifI5-r| mcx~qTRA!=@s'8(\g3" -Ou3QQA$Q@9+3u\Ŧr(۞ 3{P]Ք xUs"w*i(4n:>rM]v29Ԇk Vg1,tCJ5e>tڋy+V~.Fz%hNl@'vH"JעP>?|_@GwyCgk3H-̵w%eRU%R4᭴u}elW=&C m ZOu:vi5ۀ~Q{LFIggoS%4s DXV648֛Pᶨ*1|['f7G){c,o0<1)7YzÒ᥾ [J%&m:==1̜+kjCP5w[6HņbBs1Hʡ*\S_e, @gP*9 Qgz3OPҁ^`8:EkTBw@[穾(FA P"x6AzT-)>$nG;9K۾hNivn&Sx-x?gV_NPQ?LWح s05~!$}RseAcܳ8 ?4)ȸP^bؕ>VG@S g>d'jyƩdb\Uַ2H ek^ESEm~a7=N-[z͆*M}e12|Ct~+G-$B53={0d0rHY t ;%g0*;cH6f nS_F -ƙMUKxi:?"0bOd+{ o[%n&_u8c|Aikf*=H=uPHo|a5O]G'D(eNc]ڛj|٭ǰTهghhGahJT:zaG[8aщ+jrO0x$Y0eꭡ)e RdrÚmswEϠv D&rl82qcn-)Gؙ%opSsLT@FjCɴIm/xMޡZ篤\+ 詘mԑ?f4uCGO@ʋq6ۏؐ&ʗ#9#/]f7{ȯ <̶&uy~⋳jY$=ώ]9WGiu[O~vKtX=h${!r~c}ٚ=mi R؄+o![D|8%h9:Si4-MSݺ9#Lw٢fя<b'{_J8`rߡ塸x%IlK6C͍S-+b{ ~z_F"=:-ƬẀ܋[b%v5s]VН^tъjOcUC0˲>&۪'RuZkܲ]:.G1رuR8<板teXF!2~V`у^s=vQd<ׁES#es: =7]]:c+4aT: ة\3ƎRU=W9ߋ֡1$;H3ڄx7da`1 #v\LX]*JZ YZ