nftables-devel-0.9.8-150300.3.6.1 >  A db'p9|> \F"z h!‘+{ Сrt +ҲDkw$x;)*'A R߽+R&;jQa^Qi# $;J2Wx7T+Dn?@J~$nmg>^kb8rX1IF}PkwcF1V6/Bn=TI@?ٱ:6W:飝nR(L 0Ip[KHD542d40d9d0e6ab895ad6b4ac27750b22fea168423626fca7df064092eae4ba414ca003a3e24670390393c70ae45484899ce0698bCdb'p9|x@Dʱ-"I֪NoTrf=;Qe2LJ{ƂZsz9($M[?z1 ewB7^I著J>fuʨ\iU5䇋mx46=2L{TKg0Br 26 ʇ8V,Ɋ_,p,w,MʉЭ( [}~hvëq]w:Rf~%lG5e8sݎ b, a"̗Nh}[}UT!L>p>'?'d $ ^6C Yy     ,PhD(g8p9:uF#G#H#I#X#Y$\$,]$D^$b%c%d&;e&@f&Cl&Eu&Xv&pw'x'(y'@z'H'X'\'b'Cnftables-devel0.9.8150300.3.6.1Development files for the nftables command line interfacelibnftables is the nftables command line interface placed into a library. This package contains the header files for the library.db'ibs-centriq-3PSUSE Linux Enterprise 15SUSE LLC GPL-2.0-onlyhttps://www.suse.com/Development/Libraries/C and C++https://netfilter.org/projects/nftables/linuxaarch64 6AA큤db'db'db'db'db'db'326da31e471a394fc3bcabed2678284caad2a06e0631db51aad4bbe1c66452e6193e9f84b975fa8c908af297bf45403737f6f12702ad0eacd7edc0fe92d01276585a01a0e39c1685e655bf4945b6a06f4cd9904af71612b74f9d8abe738f7062libnftables.so.1.0.0rootrootrootrootrootrootrootrootrootrootrootrootnftables-0.9.8-150300.3.6.1.src.rpmnftables-develnftables-devel(aarch-64)pkgconfig(libnftables)@    /usr/bin/pkg-configlibnftables1rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)0.9.83.0.4-14.6.0-14.0-15.2-14.14.3dGbo`_ ^@^ۅ@^@^@]7@]N@]Z@\C@[@ZZ@Z@Zu@Z]@YXY@WPU@U`kTmatthias.gerstner@suse.commatthias.gerstner@suse.comjengelh@inai.dejengelh@inai.dejengelh@inai.dejengelh@inai.dejengelh@inai.dejengelh@inai.dejengelh@inai.dejengelh@inai.dejengelh@inai.destefan.bruens@rwth-aachen.dejengelh@inai.dejengelh@inai.dejengelh@inai.dejengelh@inai.dejengelh@inai.dejengelh@inai.dejengelh@inai.dejengelh@inai.dejengelh@inai.dejengelh@inai.demrueckert@suse.dejengelh@inai.de- add 0001-evaluate-reject-support-ethernet-as-L2-protocol-for-.patch: this fixes a crash in nftables if layer2 reject rules are processed (e.g. Ethernet MAC address based reject rich rule in firewalld, bsc#1210773).- add 0001-cache-check-for-NULL-chain-in-cache_init.patch: this fixes rare crashes that could occur e.g. in firewalld (bsc#1197606).- Update to release 0.9.8 * Complete support for matching ICMP header content fields. * Added raw tcp option match support. * Added ability to check for the presence of any tcp option. * Support for rejecting traffic from the ingress chain.- Update to release 0.9.7 * Support for implicit chains * Support for ingress inet chains * Support for reject from prerouting chain * Support for --terse option in json * Support for the reset command with json- Update to release 0.9.6 * Fix two ASAN runtime errors- Update to release 0.9.5 * Support for set counters. * Support for restoring set element counters via nft -f. * Counter support for flowtables. * typeof concatenations support for sets. * Support for concatenated ranges in anonymous sets. * Allow to reject packets with 802.1q from the bridge family. * Support for matching on the conntrack ID. - Drop anonset-crashfix.patch (upstream solved differently)- Add anonset-crashfix.patch [boo#1171321]- Update to release 0.9.4 * Add a helper for concat expression handling. * Add "typeof" build/parse/print support.- Add json, python [boo#1158723]- Update to release 0.9.3 * meta: Introduce new conditions "time", "day" and "hour". * src: add ability to set/get secmarks to/from connection. * flowtable: add support for named flowtable listing. * flowtable: add support for delete command by handle. * json: add support for element deletion. * Add `-T` as the short option for `--numeric-time`. * meta: add ibrpvid and ibrvproto support- Update to new upstream release 0.9.2 * Transport header port matching, e.g. "th dport 53" * Support for matching on IPv4 options * Support for synproxy- Remove unused dblatex BuildRequires, only needed for the optional and disabled PDF generation (same contents as shipped manpage).- Update to new upstream release 0.9.0 * Support to check if packet matches an existing socket. * Support to limit number of active connections by arbitrary criteria, such as ip addresses, networks, conntrack zones or any combination thereof. * Added support for "audit" logging.- Update to new upstream release 0.8.5 * support to add/insert a rule at a given index position * meter statement now supports a configureable upper max size * timeouts for sets can now be specified in milliseconds * re-add iptables-like empty skeleton rulesets- Update to new upstream release 0.8.4 * Support to match IPv6 segment routing headers. * New "meta ibrname" and "meta obrname" arguments to match the name of the logical bridge a packet is passing through. These new names replace the old (misnamed) "ibriport"/"obriport". * `nft -a` will now show handle identifier for all objects, including tables and chains. * nft can now delete objects by their handle number. * Support to update maps from the ruleset (packet path). * the "--echo" option now prints handle id for tables and object too. * `nft -f -` will now read from standard input * Support for flow tables, cf. man page or https://lwn.net/Articles/738214/ .- Update to new upstream release 0.8.3 * raw payload support to match headers that do not yet have received a mnemonic.- Update to new upstream release 0.8.2 * add secpath support- Update to new upstream release 0.8.1 * This release deprecates the "flow table" syntax in favor of "meter".- Update to new upstream release 0.8 * This release contains new features available up to the (upcoming) Linux 4.14 kernel release: * Support for stateful objects, these objects are uniquely identified by a user-defined name, you can refer to them from rules, and there is a well established interface to operate with them. * Sort set elements when listing them, from lower to largest. * TCP option matching and mangling support. This includes TCP maximum segment size mangling. * Add new "-s" option for listings without stateful information. * Add new -c/--check option for nft, to tests if your ruleset loads fine, into the kernel, this is a dry run mode. * Connection tracking helper support. * Add --echo option, to print the handle that the kernel allocates to uniquely identify rules. * Conntrack zone support * Symmetric hash support * Add support to include directories from nft natives scripts, files are loaded in alphanumerical order. * Allow to check if IPv6 extension header or TCP option exists or is missing. * Extend quota support to display used bytes. * Add ct average matching, to match average bytes per packet a connection has transferred so far, to map the existing feature available in the iptables connbytes match. * Allow to flush maps and flow tables. * Allow to embed set definition into an existing set. * Conntrack event filtering support via rule.- Update to new upstream release 0.7 * Add new fib expression, which can be used to obtain the output interface from the route table based on either source or destination address of a packet. * Support hashing of any arbitrary key combination, eg. * Add number generation support. Useful for round-robin packet mark setting. * Add quota support, eg. * Introduce routing expression, for routing related data with support for nexthop * Notrack support, to explicitly skip connection tracking for matching packets. * Support to set non-byte bound packet header fields, including checksum adjustment. * Add 'create set' and 'create element' commands. * Allow to use variable reference for set element definitions. * Allow to use variable definitions from element commands. * Add support to flush set. You can use this new command to remove all existing elements in a set. * Inverted set lookups. * Honor absolute and relative paths via include file, where: * Support log flags, to enable logging TCP sequence and options. * tc classid parser support, eg. * Allow numeric connlabels, so if connlabel still works with undefined labels.- Update to new upstream release 0.6 * Rules may be replaced now * Flow table support (requires Linux >= 4.3) * Support for tracing * Ratelimiting now supports units like bytes/second. * Matchinv VLAN IDs, DSCP/ECN, ICMP RtAdv & RtSol- Update to new upstream release 0.5 * Support combinations of two or more selectors to build a tuple * Timeout support for sets * Dormant flag for tables * Default chain policy specifiable on creation- set the url to the project page - pass --disable-silent-rules to configure to allow gcc post build check to work- Update to new upstream release 0.4 * Since Linux 3.18: support for global ruleset operations * Since 3.17: full logging support for all the families, including nfnetlink_log * 3.16: automatic selection of the optimal set implementation * 3.14: reject support for ip, ip6 and inet * 3.18: reject support for bridge, and reject icmpx abstraction * 3.18: masquerade support * 3.19: redirect support * Extend meta to support pkttype, cpu and devgroup matching.ibs-centriq-3 16841542570.9.8-150300.3.6.10.9.8-150300.3.6.10.9.8nftablesnftableslibnftables.hlibnftables.solibnftables.pclibnftables.3.gz/usr/include//usr/include/nftables//usr/include/nftables/nftables//usr/lib64//usr/lib64/pkgconfig//usr/share/man/man3/-fmessage-length=0 -grecord-gcc-switches -O2 -Wall -D_FORTIFY_SOURCE=2 -fstack-protector-strong -funwind-tables -fasynchronous-unwind-tables -fstack-clash-protection -gobs://build.suse.de/SUSE:Maintenance:28999/SUSE_SLE-15-SP3_Update/ed4025453dccbe5250bf320898c5bdb1-nftables.SUSE_SLE-15-SP3_Updatecpioxz5aarch64-suse-linuxdirectoryC source, ASCII textpkgconfig filetroff or preprocessor input, ASCII text, with very long lines (gzip compressed data, max compression, from Unix)PR!4>$utf-834f7c249003043855f3a23249a80ddee8af3b1430ddb8a505c6b5bcf96ee2783? 7zXZ !t/!K] crt:bLL ` XQ-t,>  Z +z(R0 f+W,(p| 1G U̻9sͅLË +jD{"SX#Ĥ8H#_xWߨq t!@l:u-?Q7e?w!S[}2I@d55 _VLaWk#|'OpK %S18aek [5{>q-h~si׆,Q]㚷_PB5FӞȐcʕcpAC{$\;:͆WK@bSaKO+꬝3@-?~_ʔnmBͩΰc2e_tQ$I=ː㎳lC| 6Q FTRZ8.05GŔD XĽ@?'WcSW4L<~6H~/AdzTdɬ; { TX~D ڮzK%5<zN̐&*Př *X8 YAfMKRxM҂Rqu +l|^h\]^->!ʭ9+-i{"+tv8[ciG94Y_Ux\V+-S4C41=@7'pA}6Pyt-co;7ێn;-}d;Eods914lD0tyk/a^e`ͻXa%,)Tl7(ip7cz@z%/#:1k[$)Om/I& ĝ<'nEfA/scK+f N]k)^ irik XN+[ѥxy5NƏ6*>, m.i V/uEykex?#n,8~@*l%`V#&F++0[ۗ"~eWsz mvX]F@]_)-I^tvFNT-:lC6fSt;=Dot DYq`%إ T.R٘d fqBIK Z#:,/oɹaW;1XfdߐfmBz qdydp5.;7D}*cj?S򾶬)0sw1ܧՈ7γj)q-jۛ8{qʔOeXmdOlxowqlg'j: 9Ox#r|ަѹ5̦ŎnZN=u'En鯰Pl}i"YH*-NZ6pӆ3ĝd 'SLD1r*:Nipa+JD![V_XS>nB GG\}H"OXaIZoï||{\d;4w;RZ0XB] o WnoF-7y9ꪂPw?[5ZO"'v~ Dǡe9+^_`9RWSU@*{d-\3 ZLUq!ORfeD#x|z^g6pdk{^wZnٍd|_rTnVoK F/s$x!>H1m-tc+)$whb@?LїSϵgRZT2 0N'P遞?/i[sPNg-?xL"n>m5/~ \Ƽ@L4ێ׭ZtuHa|NpjTKfzxP̐eGܞHX |L2l&Qz>:I}ģ¤Ɩ~.W\hPuo}87Ӄ^?8 h9QDa+}/,OF/Ӹ+!  #͕\5/ 'î$0yb38-Vįw쐽G1ɋeŲcy#Z)cjT=|<"%2)qȱ&\N].]UM9=HȞ'_gS9fv%I!qdso$*CR6־%o0tm _I=ãu cӴ9'AK- (uT:V ddO47)ZB?jaL.vӰI~6()]<)=^-S| "yLj$;:&y{ RػI xRj =[T n]h l¶g;ܗxifB˧;N6kX\ѩ2JǒAv}P;Ѭ< ؾhNbj;q1+e]{ENDp%#4A#Jg5p'OJjj?_y~w4GBu!t:6g']q8h!4B'{eSl#7ZX;)e 1UߘQf%@toU't$嚶!5 ~G_SsxT`z)Kː_y `Q4{e&A<8Vdi eQRn6^Oɋ*2DZ:`>eސ㟩l*o hV=PoV /88bdnO& q*B&ӝH1F)tlg<,J@tb|P| Pj]o˖!6u8tٕ0hɴ $'IXfprxS% dG7t ṇgg f"7Λ'ϩS n3KQf1Ihd ޟIpeYJIü/ٔƲO~h#̭x^N6VubK.W 8NP˒_e~ɷw W2֢OB{FF۳箕+xI//n'R4HF0E+c2G^Kѧ>KMnA(~y_o.Q)\ұ{LGk>04: }$(lk͈)Qm}4tyob"p}v3RUՀn/ u,GG{=ҐF4ːS% *APq#sGL {WH۲GMق` νyK!( b2&I8),H;ŨR\>X_M d_E+EiZsFY[~= ^6vh{OnΡ oA޲GfxYFNI5q]-E,5]':cM$4yj|J\UThUHr^祡Ǒ2}`UO=@.{"D偮{-൧=z &[Y l'+QRϲJnr}!e:7 v=#0h׽?u}P=ڥl0{{u WعD)M[3ϣs* I;QDV _+hh4/k 5톚!-V6.l0dTW ,6[ qG+:?݋y7"Ij[_0w~CN[~Jn=Qo vOϗ[=}NAQ^I6 [r#8 ]'T`T2kǕSɖ#CSBP3@^_!9h[ '8OpwR{sϴT*tN sD~/#pW%X!jncriU/uݚ͚yI"XI$x%yË[+*Dr?H)8)au~/ӈJuۙͰQ,抴3OH0bXTY1Q(Qa]7:j/[?x0}j!H03\6!%R&fR3?*nڨt^9n|^'fob*6h#_ ]cV=H%Aܼ[o`2;kф0;>895c ef-qmbQeqDKȧ8}(aPMԩ{e-;+?/.B Xx YZ