| Index | index by Group | index by Distribution | index by Vendor | index by creation date | index by Name | Mirrors | Help | Search |
| Name: iptables | Distribution: AlmaLinux |
| Version: 1.8.5 | Vendor: AlmaLinux |
| Release: 11.el8_9 | Build date: Tue Apr 2 20:34:27 2024 |
| Group: Unspecified | Build host: x64-builder02.almalinux.org |
| Size: 1784935 | Source RPM: iptables-1.8.5-11.el8_9.src.rpm |
| Packager: AlmaLinux Packaging Team <packager@almalinux.org> | |
| Url: http://www.netfilter.org/projects/iptables | |
| Summary: Tools for managing Linux kernel packet filtering capabilities | |
The iptables utility controls the network packet filtering code in the Linux kernel. If you need to set up firewalls and/or IP masquerading, you should either install nftables or this package. Note: This package contains the nftables-based variants of iptables and ip6tables, which are drop-in replacements of the legacy tools.
GPLv2 and Artistic 2.0 and ISC
* Thu Nov 16 2023 Phil Sutter <psutter@redhat.com> - 1.8.5-11
- iptables-restore: Drop dead code
- iptables-apply: Eliminate shellcheck warnings
- ebtables: Exit gracefully on invalid table names
* Fri Sep 08 2023 Phil Sutter <psutter@redhat.com> - 1.8.5-10
- Bump NVR to fix for wrong build tag
* Wed Sep 06 2023 Phil Sutter <psutter@redhat.com> - 1.8.5-9
- iptables-nft: fix basechain policy configuration
* Fri Jul 28 2023 Phil Sutter <psutter@redhat.com> - 1.8.5-8
- Update fixes from upstream once more
* Wed Jul 19 2023 Phil Sutter <psutter@redhat.com> - 1.8.5-7
- Fix shell test-case for older gawk version
* Tue Jul 18 2023 Phil Sutter <psutter@redhat.com> - 1.8.5-6
- Fix shell testcase for rebased libnftnl package
* Tue Jul 18 2023 Phil Sutter <psutter@redhat.com> - 1.8.5-5
- Missed to copy expected results file to destination.
* Sat Jul 15 2023 Phil Sutter <psutter@redhat.com> - 1.8.5-4
- Bump release for CI.
* Tue Jul 04 2023 Phil Sutter <psutter@redhat.com> - 1.8.5-3
- Add expected test results
- Prepare testsuites for expected results
* Wed Jun 28 2023 Phil Sutter <psutter@redhat.com> - 1.8.5-2
- libnftnl package was rebased, depending on 1.1.6 is fine
* Wed May 10 2023 Phil Sutter <psutter@redhat.com> - 1.8.5-1
- Rebase to version 1.8.5 plus upstream-indicated fixes
- Fix for duplicate files in RPM due to imprecise globbing
- Drop bootstrap code again
* Wed Nov 23 2022 Phil Sutter <psutter@redhat.com> - 1.8.4-24
- ebtables: Support '-p Length'
- nft-shared: Introduce __get_cmp_data()
* Fri Jul 01 2022 Phil Sutter <psutter@redhat.com> - 1.8.4-23
- libxtables: Fix unsupported extension warning corner case
- tests: shell: Check overhead in iptables-save and -restore
- nft: Fix EPERM handling for extensions without rev 0
- Improve error messages for unsupported extensions
- xshared: Fix response to unprivileged users
- libxtables: Register only the highest revision extension
- Use proto_to_name() from xshared in more places
- libxtables: Boost rule target checks by announcing chain names
- libxtables: Implement notargets hash table
- nft: Reject standard targets as chain names when restoring
- xshared: Merge and share parse_chain()
- xshared: Prefer xtables_chain_protos lookup over getprotoent
- nft: Speed up immediate parsing
- nft: Simplify immediate parsing
* Mon Nov 29 2021 Phil Sutter <psutter@redhat.com> - 1.8.4-22
- extensions: hashlimit: Fix tests with HZ=1000
* Thu Oct 07 2021 Phil Sutter <psutter@redhat.com> - 1.8.4-21
- extensions: hashlimit: Fix tests with HZ=100
- ebtables: Dump atomic waste
- doc: ebtables-nft.8: Adjust for missing atomic-options
* Wed Aug 04 2021 Phil Sutter <psutter@redhat.com> - 1.8.4-20
- extensions: SECMARK: Use a better context in test case
- extensions: sctp: Translate --chunk-types option
- extensions: sctp: Fix nftables translation
- extensions: SECMARK: Implement revision 1
- nft: cache: Retry if kernel returns EINTR
* Fri Jun 18 2021 Phil Sutter <psutter@redhat.com> - 1.8.4-19
- Fix for rpminspect results
* Mon May 24 2021 Phil Sutter <psutter@redhat.com> - 1.8.4-18
- xtables-translate: Fix translation of odd netmasks
- nft: Fix bitwise expression avoidance detection
- xtables-monitor: 'LL=0x304' is not very convenient, print LOOPBACK instead.
- xtables-monitor: print packet first
- xtables-monitor: fix packet family protocol
- xtables-monitor: fix rule printing
- xtables-monitor: Fix ip6tables rule printing
* Thu Dec 10 2020 Phil Sutter <psutter@redhat.com> - 1.8.4-17
- extensions: dccp: Fix for DCCP type 'INVALID'
- tests: shell: Merge and extend return codes test
- nft: Fix command name in ip6tables error message
- extensions: libxt_CT: add translation for NOTRACK
- extensions: libipt_icmp: Fix translation of type 'any'
- tests/shell: Test for fixed extension registration
- libxtables: Register multiple extensions in ascending order
- libxtables: Simplify pending extension registration
- libxtables: Make sure extensions register in revision order
* Wed Oct 28 2020 Phil Sutter <psutter@redhat.com> - 1.8.4-16
- tests/shell: Add test for bitwise avoidance fixes
- ebtables: Optimize masked MAC address matches
- nft: Optimize class-based IP prefix matches
- nft: Fix for broken address mask match detection
- nft: cache: Make nft_rebuild_cache() respect fake cache
- tests: shell: Improve concurrent noflush restore test a bit
- nft: Fix for concurrent noflush restore calls
- nft: Fix error reporting for refreshed transactions
- nft: Make batch_add_chain() return the added batch object
* Sat Aug 15 2020 Phil Sutter <psutter@redhat.com> - 1.8.4-15
- Ignore sysctl files not suffixed '.conf'
* Wed Jun 24 2020 Phil Sutter <psutter@redhat.com> - 1.8.4-14
- nft: Fix for '-F' in iptables dumps
- tests: shell: Test -F in dump files
* Fri May 29 2020 Phil Sutter <psutter@redhat.com> - 1.8.4-13
- Fix for endless loop in iptables-restore --test
* Tue May 26 2020 Phil Sutter <psutter@redhat.com> - 1.8.4-12
- Unbreak nfnl_osf tool
* Tue May 19 2020 Phil Sutter <psutter@redhat.com> - 1.8.4-11
- Complete ebtables-nft among match support
- Replace RHEL-only xtables-monitor fix with upstream solution
- xtables: Align effect of -4/-6 options with legacy
- xtables: Drop -4 and -6 support from xtables-{save,restore}
- Review systemd unit files
* Tue Mar 17 2020 Phil Sutter <psutter@redhat.com> - 1.8.4-10
- Fix for iptables-restore segfault under pressure
- Fix for iptables-save segfault under pressure
* Mon Feb 24 2020 Phil Sutter <psutter@redhat.com> - 1.8.4-9
- iptables-test.py: Fix --host mode
- xtables-monitor: Fix segfault when tracing
* Sat Feb 15 2020 Phil Sutter <psutter@redhat.com> - 1.8.4-8
- xtables-translate: Fix for iface++
- tests: shell: Fix skip checks with --host mode
- xtables-restore: fix for --noflush and empty lines
* Wed Feb 12 2020 Phil Sutter <psutter@redhat.com> - 1.8.4-7
- xtables-translate: Fix for interface name corner-cases
* Mon Dec 09 2019 Phil Sutter <psutter@redhat.com> - 1.8.4-6
- Add missing patch in last release, uAPI covscan fix
* Mon Dec 09 2019 Phil Sutter <psutter@redhat.com> - 1.8.4-5
- Fix covscan-indicated problems
* Wed Dec 04 2019 Phil Sutter <psutter@redhat.com> - 1.8.4-4
- Fix for broken xtables-restore --noflush
* Tue Dec 03 2019 Phil Sutter <psutter@redhat.com> - 1.8.4-3
- Reduce globbing in library file names to expose future SONAME changes
- Add bootstrapping for libip*tc SONAME bump
* Mon Dec 02 2019 Phil Sutter <psutter@redhat.com> - 1.8.4-2
- Use upstream-provided man pages for ebtables and arptables
* Mon Dec 02 2019 Phil Sutter <psutter@redhat.com> - 1.8.4-1
- Rebase onto upstream release 1.8.4
* Thu Aug 08 2019 Phil Sutter <psutter@redhat.com> - 1.8.2-16
- nft: Set socket receive buffer
* Wed Jul 31 2019 Phil Sutter <psutter@redhat.com> - 1.8.2-15
- doc: Install ip{6,}tables-restore-translate.8 man pages
* Tue Jul 02 2019 Phil Sutter <psutter@redhat.com> - 1.8.2-14
- arptables: Print space before comma and counters
- extensions: Fix ipvs vproto parsing
- extensions: Fix ipvs vproto option printing
- extensions: Add testcase for libxt_ipvs
* Mon Jul 01 2019 Phil Sutter <psutter@redhat.com> - 1.8.2-13
- doc: Install ip{6,}tables-translate.8 manpages
- nft: Eliminate dead code in __nft_rule_list
* Wed Jun 12 2019 Phil Sutter <psutter@redhat.com> - 1.8.2-12
- Add iptables-test.py testsuite to sources
- extensions: libip6t_mh: fix bogus translation error
- extensions: AUDIT: Document ineffective --type option
- xtables-restore: Fix program names in help texts
- xtables-save: Point at existing man page in help text
- utils: Add a manpage for nfbpf_compile
- Mark man pages in base package as documentation files
* Thu May 23 2019 Phil Sutter <psutter@redhat.com> - 1.8.2-11
- Enable verbose output when building
* Thu May 09 2019 Phil Sutter <psutter@redhat.com> - 1.8.2-10
- arptables-nft: fix decoding of hlen on bigendian platforms
- xtables-save: Fix table not found error message
- xtables: Catch errors when zeroing rule rounters
- extensions: TRACE: Point at xtables-monitor in documentation
- extensions: libipt_realm: Document allowed realm values
* Fri Feb 08 2019 Phil Sutter - 1.8.2-9
- ebtables-nft: Support user-defined chain policies
* Thu Feb 07 2019 Phil Sutter - 1.8.2-8
- arptables.8: Document --set-counters option
* Thu Feb 07 2019 Phil Sutter - 1.8.2-7
- arptables: Support --set-counters option
* Fri Feb 01 2019 Phil Sutter - 1.8.2-6
- Improve performance with large rulesets
- Fix for changes in arptables output
- Fix for inserting rules at wrong position
- Fix segfault when comparing rules with standard target
- Fix ebtables output for negated values
- Document missing arptables FORWARD chain
* Tue Dec 18 2018 Phil Sutter - 1.8.2-5
- Drop change to test snippet not included in tarball from Patch4
* Tue Dec 18 2018 Phil Sutter - 1.8.2-4
- Fix iptables init script for nftables-backend
- Drop references to unsupported broute table from ebtables man page
- xtables: Don't use native nftables comments
* Thu Dec 06 2018 Phil Sutter - 1.8.2-3
- Drop change to test snippet not included in tarball from Patch3
* Thu Dec 06 2018 Phil Sutter - 1.8.2-2
- Point out that nftables-variants are installed in package description
- Fix for deleting arptables rules by referencing them
* Thu Dec 06 2018 Phil Sutter - 1.8.2-1
- Rebase onto upstream version 1.8.2
* Thu Oct 25 2018 Phil Sutter - 1.8.1-2
- Add upstream fixes to 1.8.1 release
* Thu Oct 25 2018 Phil Sutter - 1.8.1-1
- Rebase onto upstream version 1.8.1
* Thu Sep 27 2018 Phil Sutter - 1.8.0-11
- Fix for covscan warnings in init scripts
* Wed Sep 26 2018 Phil Sutter - 1.8.0-10
- Fix short name of Artistic Licence
* Wed Sep 26 2018 Phil Sutter - 1.8.0-9
- Add further fixes for issues identified by covscan
- Fix for bogus "is incompatible" warnings
- Fix layout in License tag
- Replace "Fedora" with "RHEL" in description
- Make devel sub-package depend on libs sub-package
* Mon Sep 17 2018 Phil Sutter - 1.8.0-8
- Fix issues identified by covscan
- xtables-restore: Fix flushing referenced custom chains
- xtables: Accept --wait in iptables-nft-restore
* Mon Sep 03 2018 Phil Sutter - 1.8.0-7
- xtables: Align return codes with legacy iptables
- xtables: Drop use of IP6T_F_PROTO
* Wed Aug 29 2018 Phil Sutter - 1.8.0-6
- xtables: Fix for deleting rules with comment
* Fri Aug 24 2018 Phil Sutter - 1.8.0-5
- xtables: Use meta l4proto for -p match
- ebtables: Fix for listing of non-existent chains
- xtables: Fix for no output in iptables-nft -S
* Sat Aug 18 2018 Phil Sutter - 1.8.0-4
- xtables: Fix for segfault in iptables-nft
- ebtables: Fix entries count in chain listing
- Use %autosetup macro in %prep
* Fri Aug 17 2018 Phil Sutter - 1.8.0-3
- xtables: Make 'iptables -S nonexisting' return non-zero
* Fri Aug 10 2018 Phil Sutter - 1.8.0-2
- Rebase onto upstream master commit 514de4801b731db4712
- Add arptables and ebtables sub-packages
* Wed Jul 11 2018 Phil Sutter - 1.8.0-1
- New upstream version 1.8.0
- Drop compat sub-package
- Use nft tool versions, drop legacy ones
* Thu Mar 01 2018 Phil Sutter <psutter@redhat.com> - 1.6.2-2
- Kill module unloading support
- Support /etc/sysctl.d
- Don't restart services after package update
- Add support for --wait options to restore commands
* Wed Feb 21 2018 Michael Cronenworth <mike@cchtml.com> - 1.6.2-1
- New upstream version 1.6.2
http://www.netfilter.org/projects/iptables/files/changes-iptables-1.6.2.txt
* Wed Feb 07 2018 Fedora Release Engineering <releng@fedoraproject.org> - 1.6.1-6
- Rebuilt for https://fedoraproject.org/wiki/Fedora_28_Mass_Rebuild
* Sun Oct 22 2017 Kevin Fenzi <kevin@scrye.com> - 1.6.1-5
- Rebuild for new libnftnl
* Wed Aug 02 2017 Fedora Release Engineering <releng@fedoraproject.org> - 1.6.1-4
- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Binutils_Mass_Rebuild
* Wed Jul 26 2017 Fedora Release Engineering <releng@fedoraproject.org> - 1.6.1-3
- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild
* Fri Feb 10 2017 Fedora Release Engineering <releng@fedoraproject.org> - 1.6.1-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_26_Mass_Rebuild
* Thu Feb 02 2017 Thomas Woerner <twoerner@redhat.com> - 1.6.1-1
- New upstream version 1.6.1 with enhanced translation to nft support and
several fixes (RHBZ#1417323)
http://netfilter.org/projects/iptables/files/changes-iptables-1.6.1.txt
- Enable parallel build again
* Thu Feb 02 2017 Petr Šabata <contyk@redhat.com> - 1.6.0-4
- Disabling parallel build to avoid build issues with xtables
- See http://patchwork.alpinelinux.org/patch/1787/ for reference
- This should be fixed in 1.6.1; parallel build can be restored after the
update
* Mon Dec 19 2016 Thomas Woerner <twoerner@redhat.com> - 1.6.0-3
- Dropped bad provides for iptables in services sub package (RHBZ#1327786)
* Fri Jul 22 2016 Thomas Woerner <twoerner@redhat.com> - 1.6.0-2
- /etc/ethertypes has been moved into the setup package for F-25+.
(RHBZ#1329256)
* Wed Apr 13 2016 Thomas Woerner <twoerner@redhat.com> - 1.6.0-1
- New upstream version 1.6.0 with nft-compat support and lots of fixes (RHBZ#1292990)
Upstream changelog:
http://netfilter.org/projects/iptables/files/changes-iptables-1.6.0.txt
- New libs sub package containing libxtables and unstable libip*tc libraries (RHBZ#1323161)
- Using scripts form RHEL-7 (RHBZ#1240366)
- New compat sub package for nftables compatibility
- Install iptables-apply (RHBZ#912047)
- Fixed module uninstall (RHBZ#1324101)
- Incorporated changes by Petr Pisar
- Enabled bpf compiler (RHBZ#1170227) Thanks to Yanko Kaneti for the patch
* Thu Feb 04 2016 Fedora Release Engineering <releng@fedoraproject.org> - 1.4.21-16
- Rebuilt for https://fedoraproject.org/wiki/Fedora_24_Mass_Rebuild
* Wed Jun 17 2015 Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 1.4.21-15
- Rebuilt for https://fedoraproject.org/wiki/Fedora_23_Mass_Rebuild
* Mon Dec 01 2014 Jiri Popelka <jpopelka@redhat.com> - 1.4.21-14
- add dhcpv6-client to /etc/sysconfig/ip6tables (RHBZ#1169036)
* Mon Nov 03 2014 Jiri Popelka <jpopelka@redhat.com> - 1.4.21-13
- iptables.init: use /run/lock/subsys/ instead of /var/lock/subsys/ (RHBZ#1159573)
* Mon Sep 29 2014 Jiri Popelka <jpopelka@redhat.com> - 1.4.21-12
- ip[6]tables.init: change shebang from /bin/sh to /bin/bash (RHBZ#1147272)
* Sat Aug 16 2014 Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 1.4.21-11
- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild
* Sat Jul 12 2014 Tom Callaway <spot@fedoraproject.org> - 1.4.21-10
- fix license handling
* Sat Jun 07 2014 Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 1.4.21-9
- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild
* Wed Mar 12 2014 Jiri Popelka <jpopelka@redhat.com> - 1.4.21-8
- add missing reload and panic actions
- BuildRequires: pkgconfig(x) instead of x-devel
- no need to specify file mode bits twice (in %install and %files)
* Sun Jan 19 2014 Ville Skyttä <ville.skytta@iki.fi> - 1.4.21-7
- Don't order services after syslog.target.
* Wed Jan 15 2014 Thomas Woerner <twoerner@redhat.com> 1.4.21-6
- Enable connlabel support again, needs libnetfilter_conntrack
* Wed Jan 15 2014 Thomas Woerner <twoerner@redhat.com> 1.4.21-6
- fixed update from RHEL-6 to RHEL-7 (RHBZ#1043901)
* Tue Jan 14 2014 Jiri Popelka <jpopelka@redhat.com> - 1.4.21-5
- chmod /etc/sysconfig/ip[6]tables 755 -> 600
* Fri Jan 10 2014 Jiri Popelka <jpopelka@redhat.com> - 1.4.21-4
- drop virtual provide for xtables.so.9
- add default /etc/sysconfig/ip[6]tables (RHBZ#1034494)
* Thu Jan 09 2014 Jiri Popelka <jpopelka@redhat.com> - 1.4.21-3
- no need to support the pre-systemd things
- use systemd macros (#850166)
- remove scriptlets for migrating to a systemd unit from a SysV initscripts
- ./configure -> %configure
- spec clean up
- fix self-obsoletion
* Thu Jan 09 2014 Thomas Woerner <twoerner@redhat.com> 1.4.21-2
- fixed system hang at shutdown if root device is network based (RHBZ#1007934)
Thanks to Rodrigo A B Freire for the patch
* Thu Jan 09 2014 Thomas Woerner <twoerner@redhat.com> 1.4.21-1
- no connlabel.conf upstream anymore
- new version 1.4.21
- doc: clarify DEBUG usage macro
- iptables: use autoconf to process .in man pages
- extensions: libipt_ULOG: man page should mention NFLOG as replacement
- extensions: libxt_connlabel: use libnetfilter_conntrack
- Introduce a new revision for the set match with the counters support
- libxt_CT: Add the "NOTRACK" alias
- libip6t_mh: Correct command to list named mh types in manpage
- extensions: libxt_DNAT, libxt_REDIRECT, libxt_NETMAP, libxt_SNAT, libxt_MASQUERADE, libxt_LOG: rename IPv4 manpage and tell about IPv6 support
- extensions: libxt_LED: fix parsing of delay
- ip{6}tables-restore: fix breakage due to new locking approach
- libxt_recent: restore minimum value for --seconds
- iptables-xml: fix parameter parsing (similar to 2165f38)
- extensions: add copyright statements
- xtables: improve get_modprobe handling
- ip[6]tables: Add locking to prevent concurrent instances
- iptables: Fix connlabel.conf install location
- ip6tables: don't print out /128
- libip6t_LOG: target output is different to libipt_LOG
- build: additional include path required after UAPI changes
- iptables: iptables-xml: Fix various parsing bugs
- libxt_recent: restore reap functionality to recent module
- build: fail in configure on missing dependency with --enable-bpf-compiler
- extensions: libxt_NFQUEUE: add --queue-cpu-fanout parameter
- extensions: libxt_set, libxt_SET: check the set family too
- ip6tables: Use consistent exit code for EAGAIN
- iptables: libxt_hashlimit.man: correct address
- iptables: libxt_conntrack.man extraneous commas
- iptables: libip(6)t_REJECT.man default icmp types
- iptables: iptables-xm1.1 correct man section
- iptables: libxt_recent.{c,man} dead URL
- iptables: libxt_string.man add examples
- extensions: libxt_LOG: use generic syslog reference in manpage
- iptables: extensions/GNUMakefile.in use CPPFLAGS
- iptables: correctly reference generated file
- ip[6]tables: fix incorrect alignment in commands_v_options
- build: add software version to manpage first line at configure stage
- extensions: libxt_cluster: add note on arptables-jf
- utils: nfsynproxy: fix error while compiling the BPF filter
- extensions: add SYNPROXY extension
- utils: add nfsynproxy tool
- iptables: state match incompatibilty across versions
- libxtables: xtables_ipmask_to_numeric incorrect with non-CIDR masks
- iptables: improve chain name validation
- iptables: spurious error in load_extension
- xtables: trivial spelling fix
* Sun Dec 22 2013 Ville Skyttä <ville.skytta@iki.fi> - 1.4.19.1-2
- Drop INSTALL from docs, escape macros in %changelog.
* Wed Jul 31 2013 Thomas Woerner <twoerner@redhat.com> 1.4.19.1-1
- new version 1.4.19.1
- libxt_NFQUEUE: fix bypass option documentation
- extensions: add connlabel match
- extensions: add connlabel match
- ip[6]tables: show --protocol instead of --proto in usage
- libxt_recent: Fix missing space in manpage for --mask option
- extensions: libxt_multiport: Update manpage to list valid protocols
- utils: nfnl_osf: use the right nfnetlink lib
- libip6t_NETMAP: Use xtables_ip6mask_to_cidr and get rid of libip6tc dependency
- Revert "build: resolve link failure for ip6t_NETMAP"
- libxt_osf: fix missing --ttl and --log in save output
- libxt_osf: fix bad location for location in --genre
- libip6t_SNPT: add manpage
- libip6t_DNPT: add manpage
- utils: updates .gitignore to include nfbpf_compile
- extensions: libxt_bpf: clarify --bytecode argument
- libxtables: fix parsing of dotted network mask format
- build: bump version to 1.4.19
- libxt_conntrack: fix state match alias state parsing
- extensions: add libxt_bpf extension
- utils: nfbpf_compile
- doc: mention SNAT in INPUT chain since kernel 2.6.36
- fixed changelog date weekdays where needed
* Mon Mar 04 2013 Thomas Woerner <twoerner@redhat.com> 1.4.18-1
- new version 1.4.18
- lots of documentation changes
- Introduce match/target aliases
- Add the "state" alias to the "conntrack" match
- iptables: remove unused leftover definitions
- libxtables: add xtables_rule_matches_free
- libxtables: add xtables_print_num
- extensions: libip6t_DNPT: fix wording in DNPT target
- extension: libip6t_DNAT: allow port DNAT without address
- extensions: libip6t_DNAT: set IPv6 DNAT --to-destination
- extensions: S/DNPT: add missing save function
- changes of 1.4.17:
- libxt_time: add support to ignore day transition
- Convert the NAT targets to use the kernel supplied nf_nat.h header
- extensions: add IPv6 MASQUERADE extension
- extensions: add IPv6 SNAT extension
- extensions: add IPv6 DNAT target
- extensions: add IPv6 REDIRECT extension
- extensions: add IPv6 NETMAP extension
- extensions: add NPT extension
- extensions: libxt_statistic: Fix save output
* Thu Feb 14 2013 Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 1.4.16.2-7
- Rebuilt for https://fedoraproject.org/wiki/Fedora_19_Mass_Rebuild
* Wed Jan 16 2013 Ville Skyttä <ville.skytta@iki.fi> - 1.4.16.2-6
- Own unowned -services libexec dirs (#894464, Michael Scherer).
- Fix -services unit file permissions (#732936, Michal Schmidt).
* Thu Nov 08 2012 Thomas Woerner <twoerner@redhat.com> 1.4.16.2-5
- fixed path of ip6tables.init in ip6tables.service
* Fri Nov 02 2012 Thomas Woerner <twoerner@redhat.com> 1.4.16.2-4
- fixed missing services for update of pre F-18 installations (rhbz#867960)
- provide and obsolete old main package in services sub package
- provide and obsolete old ipv6 sub package (pre F-17) in services sub package
* Sun Oct 14 2012 Dan Horák <dan[at]dany.cz> 1.4.16.2-3
- fix the compat provides for all 64-bit arches
* Fri Oct 12 2012 Thomas Woerner <twoerner@redhat.com> 1.4.16.2-2
- new sub package services providing the systemd services (RHBZ#862922)
- new sub package utils: provides nfnl_osf and the pf.os database
- using %{_libexecdir}/iptables as script path for the original init scripts
- added service iptables save funcitonality using the new way provided by
initscripts 9.37.1 (RHBZ#748134)
- added virtual provide for libxtables.so.7
* Mon Oct 08 2012 Thomas Woerner <twoerner@redhat.com> 1.4.16.2-1
- new version 1.4.16.2
- build: support for automake-1.12
- build: separate AC variable replacements from xtables.h
- build: have `make clean` remove dep files too
- doc: grammatical updates to libxt_SET
- doc: clean up interpunction in state list for xt_conntrack
- doc: deduplicate extension descriptions into a new manpage
- doc: trim "state" manpage and reference conntrack instead
- doc: have NOTRACK manpage point to CT instead
- doc: mention iptables-apply in the SEE ALSO sections
- extensions: libxt_addrtype: fix type in help message
- include: add missing linux/netfilter_ipv4/ip_queue.h
- iptables: fix wrong error messages
- iptables: support for match aliases
- iptables: support for target aliases
- iptables-restore: warn about -t in rule lines
- ip[6]tables-restore: cleanup to reduce one level of indentation
- libip6t_frag: match any frag id by default
- libxtables: consolidate preference logic
- libxt_devgroup: consolidate devgroup specification parsing
- libxt_devgroup: guard against negative numbers
- libxt_LED: guard against negative numbers
- libxt_NOTRACK: replace as an alias to CT --notrack
- libxt_state: replace as an alias to xt_conntrack
- libxt_tcp: print space before, not after "flags:"
- libxt_u32: do bounds checking for @'s operands
- libxt_*limit: avoid division by zero
- Merge branch 'master' of git://git.inai.de/iptables
- Merge remote-tracking branch 'nf/stable'
- New set match revision with --return-nomatch flag support
- dropped fixrestore patch, upstream
* Wed Aug 01 2012 Thomas Woerner <twoerner@redhat.com> 1.4.15-1
- new version 1.4.15
- extensions: add HMARK target
- iptables-restore: fix parameter parsing (shows up with gcc-4.7)
- iptables-restore: move code to add_param_to_argv, cleanup (fix gcc-4.7)
- libxtables: add xtables_ip[6]mask_to_cidr
- libxt_devgroup: add man page snippet
- libxt_hashlimit: add support for byte-based operation
- libxt_recent: add --mask netmask
- libxt_recent: remove unused variable
- libxt_HMARK: correct a number of errors introduced by Pablo's rework
- libxt_HMARK: fix ct case example
- libxt_HMARK: fix output of iptables -L
- Revert "iptables-restore: move code to add_param_to_argv, cleanup (fix gcc-4.7)"
* Wed Jul 18 2012 Thomas Woerner <twoerner@redhat.com> 1.4.14-3
- added fixrestore patch submitted to upstream by fryasu (nfbz#774)
(RHBZ#825796)
* Wed Jul 18 2012 Thomas Woerner <twoerner@redhat.com> 1.4.14-2
- disabled libipq, removed upstream, not provided by kernel anymore
* Wed Jul 18 2012 Thomas Woerner <twoerner@redhat.com> 1.4.14-1
- new version 1.4.14
- extensions: add IPv6 capable ECN match extension
- extensions: add nfacct match
- extensions: add rpfilter module
- extensions: libxt_rateest: output all options in save hook
- iptables: missing free() in function cache_add_entry()
- iptables: missing free() in function delete_entry()
- libiptc: fix retry path in TC_INIT
- libiptc: Returns the position the entry was inserted
- libipt_ULOG: fix --ulog-cprange
- libxt_CT: add --timeout option
- ip(6)tables-restore: make sure argv is NULL terminated
- Revert "libiptc: Returns the position the entry was inserted"
- src: mark newly opened fds as FD_CLOEXEC (close on exec)
- tests: add rateest match rules
- dropped patch5 (cloexec), merged upstream
* Mon Apr 23 2012 Thomas Woerner <twoerner@redhat.com> 1.4.12.2-5
- reenable iptables default services
* Wed Feb 29 2012 Harald Hoyer <harald@redhat.com> 1.4.12.2-4
- install everything in /usr
https://fedoraproject.org/wiki/Features/UsrMove
* Thu Feb 16 2012 Thomas Woerner <twoerner@redhat.com> 1.4.12.2-3
- fixed auto enable check for Fedora > 16 and added rhel > 6 check
* Wed Feb 15 2012 Thomas Woerner <twoerner@redhat.com> 1.4.12.2-2
- disabled autostart and auto enable for iptables.service and ip6tables.service
for Fedora > 16
* Mon Jan 16 2012 Thomas Woerner <twoerner@redhat.com> 1.4.12.2-1
- new version 1.4.12.2 with new pkgconfig/libip4tc.pc and pkgconfig/libip6tc.pc
- build: make check stage not fail when building statically
- build: restore build order of modules
- build: scan for unreferenced symbols
- build: sort file list before build
- doc: clarification on the meaning of -p 0
- doc: document iptables-restore's -T option
- doc: fix undesired newline in ip6tables-restore(8)
- ip6tables-restore: implement missing -T option
- iptables: move kernel version find routing into libxtables
- libiptc: provide separate pkgconfig files
- libipt_SAME: set PROTO_RANDOM on all ranges
- libxtables: Fix file descriptor leak in xtables_lmap_init on error
- libxt_connbytes: fix handling of --connbytes FROM
- libxt_CONNSECMARK: fix spacing in output
- libxt_conntrack: improve error message on parsing violation
- libxt_NFQUEUE: fix --queue-bypass ipt-save output
- libxt_RATEEST: link with -lm
- libxt_statistic: link with -lm
- Merge branch 'stable'
- Merge branch 'stable' of git://dev.medozas.de/iptables
- nfnl_osf: add missing libnfnetlink_CFLAGS to compile process
- xtoptions: fill in fallback value for nvals
- xtoptions: simplify xtables_parse_interface
* Fri Jan 13 2012 Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 1.4.12.1-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild
* Mon Dec 12 2011 Thomas Woerner <twoerner@redhat.com> 1.4.12.1-1
- new version 1.4.12.1 with new pkgconfig/libipq.pc
- build: abort autogen on subcommand failure
- build: strengthen check for overlong lladdr components
- build: workaround broken linux-headers on RHEL-5
- doc: clarify libxt_connlimit defaults
- doc: fix typo in libxt_TRACE
- extensions: use multi-target registration
- libip6t_dst: restore setting IP6T_OPTS_LEN flag
- libip6t_frag: restore inversion support
- libip6t_hbh: restore setting IP6T_OPTS_LEN flag
- libipq: add pkgconfig file
- libipt_ttl: document that negation is available
- libxt_conntrack: fix --ctproto 0 output
- libxt_conntrack: remove one misleading comment
- libxt_dccp: fix deprecated intrapositional ordering of !
- libxt_dccp: fix random output of ! on --dccp-option
- libxt_dccp: provide man pages options in short help too
- libxt_dccp: restore missing XTOPT_INVERT tags for options
- libxt_dccp: spell out option name on save
- libxt_dscp: restore inversion support
- libxt_hashlimit: default htable-expire must be in milliseconds
- libxt_hashlimit: observe new default gc-expire time when saving
- libxt_hashlimit: remove inversion from hashlimit rev 0
- libxt_owner: restore inversion support
- libxt_physdev: restore inversion support
- libxt_policy: remove superfluous inversion
- libxt_set: put differing variable names in directly
- libxt_set: update man page about kernel support on the feature
- libxt_string: define _GNU_SOURCE for strnlen
- libxt_string: escape the escaping char too
- libxt_string: fix space around arguments
- libxt_string: replace hex codes by char equivalents
- libxt_string: simplify hex output routine
- libxt_tcp: always print the mask parts
- libxt_TCPMSS: restore build with IPv6-less libcs
- libxt_TOS: update linux kernel version list for backported fix
- libxt_u32: fix missing allowance for inversion
- src: remove unused IPTABLES_MULTI define
- tests: add negation tests for libxt_statistic
- xtoptions: flag use of XTOPT_POINTER without XTOPT_PUT
- removed include/linux/types.h before build to be able to compile
* Tue Jul 26 2011 Thomas Woerner <twoerner@redhat.com> 1.4.12-2
- dropped temporary provide again
* Tue Jul 26 2011 Thomas Woerner <twoerner@redhat.com> 1.4.12-1.1
- added temporary provides for libxtables.so.6 to be able to rebuild iproute,
which is part of the standard build environment
* Mon Jul 25 2011 Thomas Woerner <twoerner@redhat.com> 1.4.12-1
- new version 1.4.12 with support of all new features of kernel 3.0
- build: attempt to fix building under Linux 2.4
- build: bump soversion for recent data structure change
- build: install modules in arch-dependent location
- doc: fix group range in libxt_NFLOG's man
- doc: fix version string in ip6tables.8
- doc: include matches/targets in manpage again
- doc: mention multiple verbosity flags
- doc: the -m option cannot be inverted
- extensions: support for per-extension instance global variable space
- iptables-apply: select default rule file depending on call name
- iptables: consolidate target/match init call
- iptables: Coverity: DEADCODE
- iptables: Coverity: NEGATIVE_RETURNS
- iptables: Coverity: RESOURCE_LEAK
- iptables: Coverity: REVERSE_INULL
- iptables: Coverity: VARARGS
- iptables: restore negation for -f
- libip6t_HL: fix option names from ttl -> hl
- libipt_LOG: fix ignoring all but last flags
- libxtables: ignore whitespace in the multiaddress argument parser
- libxtables: properly reject empty hostnames
- libxtables: set clone's initial data to NULL
- libxt_conntrack: move more data into the xt_option_entry
- libxt_conntrack: restore network-byte order for v1,v2
- libxt_hashlimit: use a more obvious expiry value by default
- libxt_rateest: abolish global variables
- libxt_RATEEST: abolish global variables
- libxt_RATEEST: fix userspacesize field
- libxt_RATEEST: use guided option parser
- libxt_state: fix regression about inversion of main option
- option: remove last traces of intrapositional negation
- complete changelog:
http://www.netfilter.org/projects/iptables/files/changes-iptables-1.4.12.txt
* Thu Jul 21 2011 Thomas Woerner <twoerner@redhat.com> 1.4.11.1-4
- merged ipv6 sub package into main package
- renamed init scripts to /usr/libexec/ip*tables.init
* Fri Jul 15 2011 Thomas Woerner <twoerner@redhat.com> 1.4.11.1-3
- added support for native systemd file (rhbz#694738)
- new iptables.service file
- additional requires
- moved sysv init scripts to /usr/libexec
- added new post, preun and postun scripts and triggers
* Tue Jul 12 2011 Thomas Woerner <twoerner@redhat.com> 1.4.11.1-2
- dropped temporary provide again
- enabled smp build
* Tue Jul 12 2011 Thomas Woerner <twoerner@redhat.com> 1.4.11.1-1.1
- added temporary provides for libxtables.so.5 to be able to rebuild iproute,
which is part of the standard build environment
* Mon Jul 11 2011 Thomas Woerner <twoerner@redhat.com> 1.4.11.1-1
- new version 1.4.11.1, bug and doc fix release for 1.4.11
* Tue Jun 07 2011 Thomas Woerner <twoerner@redhat.com> 1.4.11-1
- new version 1.4.11 with all new features of 2.6.37-39 (not usable)
- lots of changes and bugfixes for base and extensions
- complete changelog:
http://www.netfilter.org/projects/iptables/files/changes-iptables-1.4.11.txt
* Wed Feb 09 2011 Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 1.4.10-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild
* Mon Jan 10 2011 Thomas Woerner <twoerner@redhat.com> 1.4.10-1
- new version 1.4.10 with all new features of 2.6.36
- all: consistent syntax use in struct option
- build: fix static linking
- doc: let man(1) autoalign the text in xt_cpu
- doc: remove extra empty line from xt_cpu
- doc: minimal spelling updates to xt_cpu
- doc: consistent use of markup
- extensions: libxt_quota: don't ignore the quota value on deletion
- extensions: REDIRECT: add random help
- extensions: add xt_cpu match
- extensions: add idletimer xt target extension
- extensions: libxt_IDLETIMER: use xtables_param_act when checking options
- extensions: libxt_CHECKSUM extension
- extensions: libipt_LOG/libip6t_LOG: support macdecode option
- extensions: fix compilation of the new CHECKSUM target
- extensions: libxt_ipvs: user-space lib for netfilter matcher xt_ipvs
- iptables-xml: resolve compiler warnings
- iptables: limit chain name length to be consistent with targets
- libiptc: add Libs.private to pkgconfig files
- libiptc: build with -Wl,--no-as-needed
- xtables: remove unnecessary cast
- dropped xt_CHECKSUM, added upstream
* Tue Oct 12 2010 Thomas Woerner <twoerner@redhat.com> 1.4.9-2
- added xt_CHECKSUM patch from Michael S. Tsirkin (rhbz#612587)
* Wed Aug 04 2010 Thomas Woerner <twoerner@redhat.com> 1.4.9-1
- new version 1.4.9 with all new features of 2.6.35
- doc: xt_hashlimit: fix a typo
- doc: xt_LED: nroff formatting requirements
- doc: xt_string: correct copy-and-pasting in manpage
- extensions: add the LED target
- extensions: libxt_quota.c: Support option negation
- extensions: libxt_rateest: fix bps options for iptables-save
- extensions: libxt_rateest: fix typo in the man page
- extensions: REDIRECT: add random help
- includes: sync header files from Linux 2.6.35-rc1
- libxt_conntrack: do print netmask
- libxt_hashlimit: always print burst value
- libxt_set: new revision added
- utils: add missing include flags to Makefile
- xtables: another try at chain name length checking
- xtables: remove xtables_set_revision function
- xt_quota: also document negation
- xt_sctp: Trace DATA chunk that supports SACK-IMMEDIATELY extension
- xt_sctp: support FORWARD_TSN chunk type
* Fri Jul 02 2010 Thomas Woerner <twoerner@redhat.com> 1.4.8-1
- new version 1.4.8 all new features of 2.6.34 (rhbz#)
- extensions: REDIRECT: fix --to-ports parser
- iptables: add noreturn attribute to exit_tryhelp()
- extensions: MASQUERADE: fix --to-ports parser
- libxt_comment: avoid use of IPv4-specific examples
- libxt_CT: add a manpage
- iptables: correctly check for too-long chain/target/match names
- doc: libxt_MARK: no longer restricted to mangle table
- doc: remove claim that TCPMSS is limited to mangle
- libxt_recent: add a missing space in output
- doc: add manpage for libxt_osf
- libxt_osf: import nfnl_osf program
- extensions: add support for xt_TEE
- CT: fix --ctevents parsing
- extensions: add CT extension
- libxt_CT: print conntrack zone in ->print/->save
- xtables: fix compilation when debugging is enabled
- libxt_conntrack: document --ctstate UNTRACKED
- iprange: fix xt_iprange v0 parsing
* Wed Mar 24 2010 Thomas Woerner <twoerner@redhat.com> 1.4.7-2
- added default values for IPTABLES_STATUS_VERBOSE and
IPTABLES_STATUS_LINENUMBERS in init script
- added missing lsb keywords Required-Start and Required-Stop to init script
* Fri Mar 05 2010 Thomas Woerner <twoerner@redhat.com> 1.4.7-1
- new version 1.4.7 with support for all new features of 2.6.33 (rhbz#570767)
- libip4tc: Add static qualifier to dump_entry()
- libipq: build as shared library
- recent: reorder cases in code (cosmetic cleanup)
- several man page and documentation fixes
- policy: fix error message showing wrong option
- includes: header updates
- Lift restrictions on interface names
- fixed license and moved iptables-xml into base package according to review
* Wed Jan 27 2010 Thomas Woerner <twoerner@redhat.com> 1.4.6-2
- moved libip*tc and libxtables libs to /lib[64], added symlinks for .so libs
to /usr/lib[64] for compatibility (rhbz#558796)
* Wed Jan 13 2010 Thomas Woerner <twoerner@redhat.com> 1.4.6-1
- new version 1.4.6 with support for all new features of 2.6.32
- several man page fixes
- Support for nommu arches
- realm: remove static initializations
- libiptc: remove unused functions
- libiptc: avoid strict-aliasing warnings
- iprange: do accept non-ranges for xt_iprange v1
- iprange: warn on reverse range
- iprange: roll address parsing into a loop
- iprange: do accept non-ranges for xt_iprange v1 (log)
- iprange: warn on reverse range (log)
- libiptc: fix wrong maptype of base chain counters on restore
- iptables: fix undersized deletion mask creation
- style: reduce indent in xtables_check_inverse
- libxtables: hand argv to xtables_check_inverse
- iptables/extensions: make bundled options work again
- CONNMARK: print mark rules with mask 0xffffffff as set instead of xset
- iptables: take masks into consideration for replace command
- doc: explain experienced --hitcount limit
- doc: name resolution clarification
- iptables: expose option to zero packet/byte counters for a specific rule
- build: restore --disable-ipv6 functionality on system w/o v6 headers
- MARK: print mark rules with mask 0xffffffff as --set-mark instead of --set-xmark
- DNAT: fix incorrect check during parsing
- extensions: add osf extension
- conntrack: fix --expires parsing
* Thu Dec 17 2009 Thomas Woerner <twoerner@redhat.com> 1.4.5-2
- dropped nf_ext_init remains from cloexec patch
* Thu Sep 17 2009 Thomas Woerner <twoerner@redhat.com> 1.4.5-1
- new version 1.4.5 with support for all new features of 2.6.31
- libxt_NFQUEUE: add new v1 version with queue-balance option
- xt_conntrack: revision 2 for enlarged state_mask member
- libxt_helper: fix invalid passed option to check_inverse
- libiptc: split v4 and v6
- extensions: collapse registration structures
- iptables: allow for parse-less extensions
- iptables: allow for help-less extensions
- extensions: remove empty help and parse functions
- xtables: add multi-registration functions
- extensions: collapse data variables to use multi-reg calls
- xtables: warn of missing version identifier in extensions
- multi binary: allow subcommand via argv[1]
- iptables: accept multiple IP address specifications for -s, -d
- several build fixes
- several man page fixes
- fixed two leaked file descriptors on sockets (rhbz#521397)
* Mon Aug 24 2009 Thomas Woerner <twoerner@redhat.com> 1.4.4-1
- new version 1.4.4 with support for all new features of 2.6.30
- several man page fixes
- iptables: replace open-coded sizeof by ARRAY_SIZE
- libip6t_policy: remove redundant functions
- policy: use direct xt_policy_info instead of ipt/ip6t
- policy: merge ipv6 and ipv4 variant
- extensions: add `cluster' match support
- extensions: add const qualifiers in print/save functions
- extensions: use NFPROTO_UNSPEC for .family field
- extensions: remove redundant casts
- iptables: close open file descriptors
- fix segfault if incorrect protocol name is used
- replace open-coded sizeof by ARRAY_SIZE
- do not include v4-only modules in ip6tables manpage
- use direct xt_policy_info instead of ipt/ip6t
- xtables: fix segfault if incorrect protocol name is used
- libxt_connlimit: initialize v6_mask
- SNAT/DNAT: add support for persistent multi-range NAT mappings
* Fri Jul 24 2009 Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 1.4.3.2-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild
* Wed Apr 15 2009 Thomas Woerner <twoerner@redhat.com> 1.4.3.2-1
- new version 1.4.3.2
- also install iptables/internal.h, needed for iptables.h and ip6tables.h
* Mon Mar 30 2009 Thomas Woerner <twoerner@redhat.com> 1.4.3.1-1
- new version 1.4.3.1
- libiptc is now shared
- supports all new features of the 2.6.29 kernel
- dropped typo_latter patch
* Thu Mar 05 2009 Thomas Woerner <twoerner@redhat.com> 1.4.2-3
- still more review fixes (rhbz#225906)
- consistent macro usage
- use sed instead of perl for rpath removal
- use standard RPM CFLAGS, but also -fno-strict-aliasing (needed for libiptc*)
* Wed Feb 25 2009 Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 1.4.2-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_11_Mass_Rebuild
* Fri Feb 20 2009 Thomas Woerner <twoerner@redhat.com> 1.4.2-1
- new version 1.4.2
- removed TOS value mask patch (upstream)
- more review fixes (rhbz#225906)
- install all header files (rhbz#462207)
- dropped nf_ext_init (rhbz#472548)
* Tue Jul 22 2008 Thomas Woerner <twoerner@redhat.com> 1.4.1.1-2
- fixed TOS value mask problem (rhbz#456244) (upstream patch)
- two more cloexec fixes
* Tue Jul 01 2008 Thomas Woerner <twoerner@redhat.com> 1.4.1.1-1
- upstream bug fix release 1.4.1.1
- dropped extra patch for 1.4.1 - not needed anymore
* Tue Jun 10 2008 Thomas Woerner <twoerner@redhat.com> 1.4.1-1
- new version 1.4.1 with new build environment
- additional ipv6 network mask patch from Jan Engelhardt
- spec file cleanup
- removed old patches
* Fri Jun 06 2008 Tom "spot" Callaway <tcallawa@redhat.com> 1.4.0-5
- use normal kernel headers, not linux/compiler.h
- change BuildRequires: kernel-devel to kernel-headers
- We need to do this to be able to build for both sparcv9 and sparc64
(there is no kernel-devel.sparcv9)
* Thu Mar 20 2008 Thomas Woerner <twoerner@redhat.com> 1.4.0-4
- use O_CLOEXEC for all opened files in all applications (rhbz#438189)
* Mon Mar 03 2008 Thomas Woerner <twoerner@redhat.com> 1.4.0-3
- use the kernel headers from the build tree for iptables for now to be able to
compile this package, but this makes the package more kernel dependant
- use s6_addr32 instead of in6_u.u6_addr32
* Wed Feb 20 2008 Fedora Release Engineering <rel-eng@fedoraproject.org> - 1.4.0-2
- Autorebuild for GCC 4.3
* Mon Feb 11 2008 Thomas Woerner <twoerner@redhat.com> 1.4.0-1
- new version 1.4.0
- fixed condrestart (rhbz#428148)
- report the module in rmmod_r if there is an error
- use nf_ext_init instead of my_init for extension constructors
* Mon Nov 05 2007 Thomas Woerner <twoerner@redhat.com> 1.3.8-6
- fixed leaked file descriptor before fork/exec (rhbz#312191)
- blacklisting is not working, use "install X /bin/(true|false)" test instead
- return private exit code 150 for disabled ipv6 support
- use script name for output messages
* Tue Oct 16 2007 Thomas Woerner <twoerner@redhat.com> 1.3.8-5
- fixed error code for stopping a already stopped firewall (rhbz#321751)
- moved blacklist test into start
* Wed Sep 26 2007 Thomas Woerner <twoerner@redhat.com> 1.3.8-4.1
- do not start ip6tables if ipv6 is blacklisted (rhbz#236888)
- use simpler fix for (rhbz#295611)
Thanks to Linus Torvalds for the patch.
* Mon Sep 24 2007 Thomas Woerner <twoerner@redhat.com> 1.3.8-4
- fixed IPv6 reject type (rhbz#295181)
- fixed init script: start, stop and status
- support netfilter compiled into kernel in init script (rhbz#295611)
- dropped inversion for limit modules from man pages (rhbz#220780)
- fixed typo in ip6tables man page (rhbz#236185)
* Wed Sep 19 2007 Thomas Woerner <twoerner@redhat.com> 1.3.8-3
- do not depend on local_fs in lsb header - this delayes start after network
- fixed exit code for initscript usage
* Mon Sep 17 2007 Thomas Woerner <twoerner@redhat.com> 1.3.8-2.1
- do not use lock file for condrestart test
* Thu Aug 23 2007 Thomas Woerner <twoerner@redhat.com> 1.3.8-2
- fixed initscript for LSB conformance (rhbz#246953, rhbz#242459)
- provide iptc interface again, but unsupported (rhbz#216733)
- compile all extension, which are supported by the kernel-headers package
- review fixes (rhbz#225906)
* Tue Jul 31 2007 Thomas Woerner <twoerner@redhat.com>
- reverted ipv6 fix, because it disables the ipv6 at all (rhbz#236888)
* Fri Jul 13 2007 Steve Conklin <sconklin@redhat.com> - 1.3.8-1
- New version 1.3.8
* Mon Apr 23 2007 Jeremy Katz <katzj@redhat.com> - 1.3.7-2
- fix error when ipv6 support isn't loaded in the kernel (#236888)
* Wed Jan 10 2007 Thomas Woerner <twoerner@redhat.com> 1.3.7-1.1
- fixed installation of secmark modules
* Tue Jan 09 2007 Thomas Woerner <twoerner@redhat.com> 1.3.7-1
- new verison 1.3.7
- iptc is not a public interface and therefore not installed anymore
- dropped upstream secmark patch
* Tue Sep 19 2006 Thomas Woerner <twoerner@redhat.com> 1.3.5-2
- added secmark iptables patches (#201573)
* Wed Jul 12 2006 Jesse Keating <jkeating@redhat.com> - 1.3.5-1.2.1
- rebuild
* Fri Feb 10 2006 Jesse Keating <jkeating@redhat.com> - 1.3.5-1.2
- bump again for double-long bug on ppc(64)
* Tue Feb 07 2006 Jesse Keating <jkeating@redhat.com> - 1.3.5-1.1
- rebuilt for new gcc4.1 snapshot and glibc changes
* Thu Feb 02 2006 Thomas Woerner <twoerner@redhat.com> 1.3.5-1
- new version 1.3.5
- fixed init script to set policy for raw tables, too (#179094)
* Tue Jan 24 2006 Thomas Woerner <twoerner@redhat.com> 1.3.4-3
- added important iptables header files to devel package
* Fri Dec 09 2005 Jesse Keating <jkeating@redhat.com>
- rebuilt
* Fri Nov 25 2005 Thomas Woerner <twoerner@redhat.com> 1.3.4-2
- fix for plugin problem: link with "gcc -shared" instead of "ld -shared" and
replace "_init" with "__attribute((constructor)) my_init"
* Fri Nov 25 2005 Thomas Woerner <twoerner@redhat.com> 1.3.4-1.1
- rebuild due to unresolved symbols in shared libraries
* Fri Nov 18 2005 Thomas Woerner <twoerner@redhat.com> 1.3.4-1
- new version 1.3.4
- dropped free_opts patch (upstream fixed)
- made libipq PIC (#158623)
- additional configuration options for iptables startup script (#172929)
Thanks to Jan Gruenwald for the patch
- spec file cleanup (dropped linux_header define and usage)
* Mon Jul 18 2005 Thomas Woerner <twoerner@redhat.com> 1.3.2-1
- new version 1.3.2 with additional patch for the misplaced free_opts call
from Marcus Sundberg
* Wed May 11 2005 Thomas Woerner <twoerner@redhat.com> 1.3.1-1
- new version 1.3.1
* Fri Mar 18 2005 Thomas Woerner <twoerner@redhat.com> 1.3.0-2
- Remove unnecessary explicit kernel dep (#146142)
- Fixed out of bounds accesses (#131848): Thanks to Steve Grubb
for the patch
- Adapted iptables-config to reference to modprobe.conf (#150143)
- Remove misleading message (#140154): Thanks to Ulrich Drepper
for the patch
* Mon Feb 21 2005 Thomas Woerner <twoerner@redhat.com> 1.3.0-1
- new version 1.3.0
* Thu Nov 11 2004 Thomas Woerner <twoerner@redhat.com> 1.2.11-3.2
- fixed autoload problem in iptables and ip6tables (CAN-2004-0986)
* Fri Sep 17 2004 Thomas Woerner <twoerner@redhat.com> 1.2.11-3.1
- changed default behaviour for IPTABLES_STATUS_NUMERIC to "yes" (#129731)
- modified config file to match this change and un-commented variables with
default values
* Thu Sep 16 2004 Thomas Woerner <twoerner@redhat.com> 1.2.11-3
- applied second part of cleanup patch from (#131848): thanks to Steve Grubb
for the patch
* Wed Aug 25 2004 Thomas Woerner <twoerner@redhat.com> 1.2.11-2
- fixed free bug in iptables (#128322)
* Tue Jun 22 2004 Thomas Woerner <twoerner@redhat.com> 1.2.11-1
- new version 1.2.11
* Thu Jun 17 2004 Thomas Woerner <twoerner@redhat.com> 1.2.10-1
- new version 1.2.10
* Tue Jun 15 2004 Elliot Lee <sopwith@redhat.com>
- rebuilt
* Tue Mar 02 2004 Elliot Lee <sopwith@redhat.com>
- rebuilt
* Thu Feb 26 2004 Thomas Woerner <twoerner@redhat.com> 1.2.9-2.3
- fixed iptables-restore -c fault if there are no counters (#116421)
* Fri Feb 13 2004 Elliot Lee <sopwith@redhat.com>
- rebuilt
* Sun Jan 25 2004 Dan Walsh <dwalsh@redhat.com> 1.2.9-1.2
- Close File descriptors to prevent SELinux error message
* Wed Jan 07 2004 Thomas Woerner <twoerner@redhat.com> 1.2.9-1.1
- rebuild
* Wed Dec 17 2003 Thomas Woerner <twoerner@redhat.com> 1.2.9-1
- vew version 1.2.9
- new config options in ipXtables-config:
IPTABLES_MODULES_UNLOAD
- more documentation in ipXtables-config
- fix for netlink security issue in libipq (devel package)
- print fix for libipt_icmp (#109546)
* Thu Oct 23 2003 Thomas Woerner <twoerner@redhat.com> 1.2.8-13
- marked all messages in iptables init script for translation (#107462)
- enabled devel package (#105884, #106101)
- bumped build for fedora for libipt_recent.so (#106002)
* Tue Sep 23 2003 Thomas Woerner <twoerner@redhat.com> 1.2.8-12.1
- fixed lost udp port range in ip6tables-save (#104484)
- fixed non numeric multiport port output in ipXtables-savs
* Mon Sep 22 2003 Florian La Roche <Florian.LaRoche@redhat.de> 1.2.8-11
- do not link against -lnsl
* Wed Sep 17 2003 Thomas Woerner <twoerner@redhat.com> 1.2.8-10
- made variables in rmmod_r local
* Tue Jul 22 2003 Thomas Woerner <twoerner@redhat.com> 1.2.8-9
- fixed permission for init script
* Sat Jul 19 2003 Thomas Woerner <twoerner@redhat.com> 1.2.8-8
- fixed save when iptables file is missing and iptables-config permissions
* Tue Jul 08 2003 Thomas Woerner <twoerner@redhat.com> 1.2.8-7
- fixes for ip6tables: module unloading, setting policy only for existing
tables
* Thu Jul 03 2003 Thomas Woerner <twoerner@redhat.com> 1.2.8-6
- IPTABLES_SAVE_COUNTER defaults to no, now
- install config file in /etc/sysconfig
- exchange unload of ip_tables and ip_conntrack
- fixed start function
* Wed Jul 02 2003 Thomas Woerner <twoerner@redhat.com> 1.2.8-5
- new config option IPTABLES_SAVE_ON_RESTART
- init script: new status, save and restart
- fixes #44905, #65389, #80785, #82860, #91040, #91560 and #91374
* Mon Jun 30 2003 Thomas Woerner <twoerner@redhat.com> 1.2.8-4
- new config option IPTABLES_STATUS_NUMERIC
- cleared IPTABLES_MODULES in iptables-config
* Mon Jun 30 2003 Thomas Woerner <twoerner@redhat.com> 1.2.8-3
- new init scripts
* Sat Jun 28 2003 Florian La Roche <Florian.LaRoche@redhat.de>
- remove check for very old kernel versions in init scripts
- sync up both init scripts and remove some further ugly things
- add some docu into rpm
* Thu Jun 26 2003 Thomas Woerner <twoerner@redhat.com> 1.2.8-2
- rebuild
* Mon Jun 16 2003 Thomas Woerner <twoerner@redhat.com> 1.2.8-1
- update to 1.2.8
* Wed Jan 22 2003 Tim Powers <timp@redhat.com>
- rebuilt
* Mon Jan 13 2003 Bill Nottingham <notting@redhat.com> 1.2.7a-1
- update to 1.2.7a
- add a plethora of bugfixes courtesy Michael Schwendt <mschewndt@yahoo.com>
* Fri Dec 13 2002 Elliot Lee <sopwith@redhat.com> 1.2.6a-3
- Fix multilib
* Wed Aug 07 2002 Karsten Hopp <karsten@redhat.de>
- fixed iptables and ip6tables initscript output, based on #70511
- check return status of all iptables calls, not just the last one
in a 'for' loop.
* Mon Jul 29 2002 Bernhard Rosenkraenzer <bero@redhat.com> 1.2.6a-1
- 1.2.6a (bugfix release, #69747)
* Fri Jun 21 2002 Tim Powers <timp@redhat.com>
- automated rebuild
* Thu May 23 2002 Tim Powers <timp@redhat.com>
- automated rebuild
* Mon Mar 04 2002 Bernhard Rosenkraenzer <bero@redhat.com> 1.2.5-3
- Add some fixes from CVS, fixing bug #60465
* Tue Feb 12 2002 Bernhard Rosenkraenzer <bero@redhat.com> 1.2.5-2
- Merge ip6tables improvements from Ian Prowell <iprowell@prowell.org>
- Update URL (#59354)
- Use /sbin/chkconfig rather than chkconfig in %postun script
* Fri Jan 11 2002 Bernhard Rosenkraenzer <bero@redhat.com> 1.2.5-1
- 1.2.5
* Wed Jan 09 2002 Tim Powers <timp@redhat.com>
- automated rebuild
* Mon Nov 05 2001 Bernhard Rosenkraenzer <bero@redhat.com> 1.2.4-2
- Fix %preun script
* Tue Oct 30 2001 Bernhard Rosenkraenzer <bero@redhat.com> 1.2.4-1
- Update to 1.2.4 (various fixes, including security fixes; among others:
- Fix init script (#31133)
* Mon Sep 03 2001 Bernhard Rosenkraenzer <bero@redhat.com> 1.2.3-1
- 1.2.3 (5 security fixes, some other fixes)
- Fix updating (#53032)
* Mon Aug 27 2001 Bernhard Rosenkraenzer <bero@redhat.com> 1.2.2-4
- Fix #50990
- Add some fixes from current CVS; should fix #52620
* Mon Jul 16 2001 Bernhard Rosenkraenzer <bero@redhat.com> 1.2.2-3
- Add some fixes from the current CVS tree; fixes #49154 and some IPv6
issues
* Tue Jun 26 2001 Bernhard Rosenkraenzer <bero@redhat.com> 1.2.2-2
- Fix iptables-save reject-with (#45632), Patch from Michael Schwendt
<mschwendt@yahoo.com>
* Tue May 08 2001 Bernhard Rosenkraenzer <bero@redhat.com> 1.2.2-1
- 1.2.2
* Wed Mar 21 2001 Bernhard Rosenkraenzer <bero@redhat.com>
- 1.2.1a, fixes #28412, #31136, #31460, #31133
* Thu Mar 01 2001 Bernhard Rosenkraenzer <bero@redhat.com>
- Yet another initscript fix (#30173)
- Fix the fixes; they fixed some issues but broke more important
stuff :/ (#30176)
* Tue Feb 27 2001 Bernhard Rosenkraenzer <bero@redhat.com>
- Fix up initscript (#27962)
- Add fixes from CVS to iptables-{restore,save}, fixing #28412
* Fri Feb 09 2001 Karsten Hopp <karsten@redhat.de>
- create /etc/sysconfig/iptables mode 600 (same problem as #24245)
* Mon Feb 05 2001 Karsten Hopp <karsten@redhat.de>
- fix bugzilla #25986 (initscript not marked as config file)
- fix bugzilla #25962 (iptables-restore)
- mv chkconfig --del from postun to preun
* Thu Feb 01 2001 Trond Eivind Glomsrød <teg@redhat.com>
- Fix check for ipchains
* Mon Jan 29 2001 Bernhard Rosenkraenzer <bero@redhat.com>
- Some fixes to init scripts
* Wed Jan 24 2001 Bernhard Rosenkraenzer <bero@redhat.com>
- Add some fixes from CVS, fixes among other things Bug #24732
* Wed Jan 17 2001 Bernhard Rosenkraenzer <bero@redhat.com>
- Add missing man pages, fix up init script (Bug #17676)
* Mon Jan 15 2001 Bill Nottingham <notting@redhat.com>
- add init script
* Mon Jan 15 2001 Bernhard Rosenkraenzer <bero@redhat.com>
- 1.2
- fix up ipv6 split
- add init script
- Move the plugins from /usr/lib/iptables to /lib/iptables.
This needs to work before /usr is mounted...
- Use -O1 on alpha (compiler bug)
* Sat Jan 06 2001 Bernhard Rosenkraenzer <bero@redhat.com>
- 1.1.2
- Add IPv6 support (in separate package)
* Thu Aug 17 2000 Bill Nottingham <notting@redhat.com>
- build everywhere
* Tue Jul 25 2000 Bernhard Rosenkraenzer <bero@redhat.com>
- 1.1.1
* Thu Jul 13 2000 Prospector <bugzilla@redhat.com>
- automatic rebuild
* Tue Jun 27 2000 Preston Brown <pbrown@redhat.com>
- move iptables to /sbin.
- excludearch alpha for now, not building there because of compiler bug(?)
* Fri Jun 09 2000 Bill Nottingham <notting@redhat.com>
- don't obsolete ipchains either
- update to 1.1.0
* Sun Jun 04 2000 Bill Nottingham <notting@redhat.com>
- remove explicit kernel requirement
* Tue May 02 2000 Bernhard Rosenkränzer <bero@redhat.com>
- initial package
/etc/ethertypes /etc/sysconfig/ip6tables-config /etc/sysconfig/iptables-config /usr/lib/.build-id /usr/lib/.build-id/00 /usr/lib/.build-id/00/d8325635089f77b243e6bb8aec08a0fa55d125 /usr/lib/.build-id/01 /usr/lib/.build-id/01/303e655facbbac4e43186ad8c429c95c66475e /usr/lib/.build-id/03 /usr/lib/.build-id/03/4057d88ddfc5868abbb3577f5a93653f42c5d1 /usr/lib/.build-id/06 /usr/lib/.build-id/06/6701422c620b02fb91cc42f248a2360c7467f5 /usr/lib/.build-id/06/7c6284faf43a33f093ce0dd8439c202b758027 /usr/lib/.build-id/06/b306e8fc173b3b75d799442c66d31f369011a7 /usr/lib/.build-id/07 /usr/lib/.build-id/07/93224ddcaa9a2e7a8eba9075b7fdc7868bafa2 /usr/lib/.build-id/0b /usr/lib/.build-id/0b/fdf011eda5126c5c8cd6352df9ca79af69658f /usr/lib/.build-id/0c /usr/lib/.build-id/0c/947a513f9fe2018d822502369904b9a4955ee9 /usr/lib/.build-id/11 /usr/lib/.build-id/11/45e92c26d6e64a954a87d537e11a1b21ea294a /usr/lib/.build-id/12 /usr/lib/.build-id/12/748bab11551d44ce701ab41dc57102cbebe64f /usr/lib/.build-id/14 /usr/lib/.build-id/14/5740ce68e043b48a17695ff0311d1d694e0c31 /usr/lib/.build-id/15 /usr/lib/.build-id/15/262d620ff73b76379224f82b64b97e705356c3 /usr/lib/.build-id/16 /usr/lib/.build-id/16/7213bc96e40f5458af9866444c77d98eebc854 /usr/lib/.build-id/19 /usr/lib/.build-id/19/a6e67999ed437ceec50c32d93b08ae67276684 /usr/lib/.build-id/1c /usr/lib/.build-id/1c/dc6a9cfa6ee2f96d87822639a768ef5dc3f0b0 /usr/lib/.build-id/1d /usr/lib/.build-id/1d/e6e6bd002beb5c1c870a73c92bd60fec19969d /usr/lib/.build-id/23 /usr/lib/.build-id/23/56506021e45d998dcef7a0af4330b4f6a73144 /usr/lib/.build-id/24 /usr/lib/.build-id/24/9c649fe755d7cd1fb21b9f7d38d45300ca9dd3 /usr/lib/.build-id/25 /usr/lib/.build-id/25/63fa1a015f0b4fd88e6cabfd3a23f75de10fb5 /usr/lib/.build-id/26 /usr/lib/.build-id/26/ec8b4d3988679fbc8e34ede5fe427e71d8f4d1 /usr/lib/.build-id/2a /usr/lib/.build-id/2a/86ef169f67fb93df50a47aa576559e3a4ac5c0 /usr/lib/.build-id/2b /usr/lib/.build-id/2b/324c439f0ec1da8b40c51e13e50bc390d3f3f1 /usr/lib/.build-id/30 /usr/lib/.build-id/30/e8fe905f542e5d39496d0e2195aab942e1b231 /usr/lib/.build-id/34 /usr/lib/.build-id/34/aeb190f9930071e9707ca164cfce4275e4cdfe /usr/lib/.build-id/35 /usr/lib/.build-id/35/3d12bf9d4a03acd77b08d882886681f858c2ea /usr/lib/.build-id/36 /usr/lib/.build-id/36/1cb26f0796b0624f221b9e4d611e60db040e5c /usr/lib/.build-id/36/552407c1adc37819c45ed7ecbd88845ad9a8b8 /usr/lib/.build-id/36/cd6017697d8f075525e6aa6bc355a9ea43e423 /usr/lib/.build-id/3f /usr/lib/.build-id/3f/dd0f9c1fb8631585971b8bfbed30f1b96a377f /usr/lib/.build-id/43 /usr/lib/.build-id/43/4fa508cd7cee35eec7357729665a2afaa057f3 /usr/lib/.build-id/45 /usr/lib/.build-id/45/3a9710a13f8cbdf82a91155ac464d923feb0b6 /usr/lib/.build-id/45/8f43e05ec5da9fce1ee4bc4286848cfe3bc39b /usr/lib/.build-id/45/c73b04abdc15b91a064ae2f67e3f9794c2c548 /usr/lib/.build-id/46 /usr/lib/.build-id/46/5cd693e8e223ff71e0baa4c209cce0c977967b /usr/lib/.build-id/47 /usr/lib/.build-id/47/e18ec10f9b6795fccfd3cc4afd08112dcaca38 /usr/lib/.build-id/47/fecf6677782254eab0222673b2d55da53d4a36 /usr/lib/.build-id/49 /usr/lib/.build-id/49/8cf50cd6d0949d7111b4f56e576e006a93ff41 /usr/lib/.build-id/4a /usr/lib/.build-id/4a/8b5b45e155233c83f93c5676f6ba2d957bea15 /usr/lib/.build-id/4f /usr/lib/.build-id/4f/6294c477765934fdc52259346804a2dd38a592 /usr/lib/.build-id/4f/e5f6e29befbf3c3d3b17df8b0c4034c53c1cb4 /usr/lib/.build-id/54 /usr/lib/.build-id/54/4b095f009c5ab18819baef1f32cb233dfcab4e /usr/lib/.build-id/55 /usr/lib/.build-id/55/ef60bfe65c4cab90aad7dadd81d3f03f2eb39f /usr/lib/.build-id/57 /usr/lib/.build-id/57/798b9c056f2ae0e4c1f39248c502aef1cbd620 /usr/lib/.build-id/58 /usr/lib/.build-id/58/a382070cc6582c0f661fc51ff2b7c841d3fde7 /usr/lib/.build-id/63 /usr/lib/.build-id/63/4f6c29463158982ac070a3bf400b51c41f675e /usr/lib/.build-id/66 /usr/lib/.build-id/66/e66365a676ec3d2f3994dedeb60cd2fdf43330 /usr/lib/.build-id/67 /usr/lib/.build-id/67/a7899f25c8cfa21621d88c35a04ad6cd3e76c2 /usr/lib/.build-id/6a /usr/lib/.build-id/6a/e42cc22b84604ee47292acaecf37e2604bcebd /usr/lib/.build-id/6b /usr/lib/.build-id/6b/a763f74462f6ad901d37f87e558fae47551679 /usr/lib/.build-id/6f /usr/lib/.build-id/6f/ec67ffa6f03082a4dbbe2da435c48d1b554ce7 /usr/lib/.build-id/70 /usr/lib/.build-id/70/2484f8632455619b92fc92e4fac26bdfacfaab /usr/lib/.build-id/76 /usr/lib/.build-id/76/7354ee21a813fb467561018894eb1def9af35d /usr/lib/.build-id/79 /usr/lib/.build-id/79/1b16dd19ddebc45c1e9f6c94a116bce201cf86 /usr/lib/.build-id/7c /usr/lib/.build-id/7c/b8a375861f1cf4a40b3409509d1d02325ec018 /usr/lib/.build-id/7d /usr/lib/.build-id/7d/6b6f55d76e34ff1edc3d955d8406c1d7ed0596 /usr/lib/.build-id/7e /usr/lib/.build-id/7e/74a3375be91855320cb3643c76322455513547 /usr/lib/.build-id/82 /usr/lib/.build-id/82/84be0ac06bef307103dcfe75d9f4fd27c9a50b /usr/lib/.build-id/83 /usr/lib/.build-id/83/4751b685c39bfcd648eb3f21a307e7c352a00d /usr/lib/.build-id/83/c9e4d73e8758050fed80ec78900139db7e85ae /usr/lib/.build-id/84 /usr/lib/.build-id/84/2cc6567c4783cdc9be3325b154991255c82488 /usr/lib/.build-id/8a /usr/lib/.build-id/8a/df0e6ec9855834e8db5aa12a248ba0e3d3c56a /usr/lib/.build-id/8f /usr/lib/.build-id/8f/c663842821c8401946887280d3c02113421124 /usr/lib/.build-id/90 /usr/lib/.build-id/90/e439b5fa62b34b197551f79395036da049233e /usr/lib/.build-id/92 /usr/lib/.build-id/92/f2a7f7f4b563020fa61e8ad9a68dbd0db18cd2 /usr/lib/.build-id/95 /usr/lib/.build-id/95/c41eab7a5f3f49b3b3d006b1377e9e92b07d12 /usr/lib/.build-id/9a /usr/lib/.build-id/9a/c14d58a541d5dc27dc6dd8d2625ba00dbc82b7 /usr/lib/.build-id/9a/d8e4b1dea765a434b31e9ac80df3858cd3c7aa /usr/lib/.build-id/9c /usr/lib/.build-id/9c/5bbecc7036e7746fbd85b070736becddf4721e /usr/lib/.build-id/a0 /usr/lib/.build-id/a0/a51a8fd776e3aa04727148d36002c436c9e8e3 /usr/lib/.build-id/a3 /usr/lib/.build-id/a3/f847772cf40ab1c43877ea31720e5df8adb882 /usr/lib/.build-id/a5 /usr/lib/.build-id/a5/b1dddc812c8ecf2e818df7e0bac93f61445460 /usr/lib/.build-id/af /usr/lib/.build-id/af/4869d439299207c5d75a2be1e87cfef5511baa /usr/lib/.build-id/b0 /usr/lib/.build-id/b0/3c1ac40c4ae431ff181ca181fb78b009895224 /usr/lib/.build-id/b1 /usr/lib/.build-id/b1/5afea5c4bd5c287d8cdb1dfbce81c2dfff0ba1 /usr/lib/.build-id/b1/bb0e665339e1e55ced0bb3d904eca8662bb415 /usr/lib/.build-id/b3 /usr/lib/.build-id/b3/c1f948140c625a7dbe6a0a146731c661178d41 /usr/lib/.build-id/b5 /usr/lib/.build-id/b5/a40cf84102883db42bb043d3b27be934de60fb /usr/lib/.build-id/b6 /usr/lib/.build-id/b6/8d414e88f187c95b9eb4fdab61275534f9946c /usr/lib/.build-id/b7 /usr/lib/.build-id/b7/246d94b734ea4a40d239d56bc7b56221764fc8 /usr/lib/.build-id/b9 /usr/lib/.build-id/b9/ec09a5a4d3119dec8dee6f5d2ea8a6645577be /usr/lib/.build-id/bb /usr/lib/.build-id/bb/2c8eaa2ddad15742ecd52e737e116fd718a0fb /usr/lib/.build-id/c2 /usr/lib/.build-id/c2/ac28c9ff2d71a9a99364ab709264b0cd6e8ffe /usr/lib/.build-id/c4 /usr/lib/.build-id/c4/82659c61774ad330947cdfe93685eb35135d07 /usr/lib/.build-id/c8 /usr/lib/.build-id/c8/d9b891d083f404072a10796073e227136c2ac5 /usr/lib/.build-id/cb /usr/lib/.build-id/cb/3993aa13ee980d473e88d4a51bd8b86adce769 /usr/lib/.build-id/cc /usr/lib/.build-id/cc/8caf3ecdbb726637a71e10527919fc4f6a9680 /usr/lib/.build-id/cd /usr/lib/.build-id/cd/f72cabfc5f1007dedfc1ccd49e839345ef8ac6 /usr/lib/.build-id/cf /usr/lib/.build-id/cf/2db847aa606a03dd7f0d63d0bf9d641e2eb688 /usr/lib/.build-id/d1 /usr/lib/.build-id/d1/df09b337da6694561aca6aff5f0e09af97dc34 /usr/lib/.build-id/d2 /usr/lib/.build-id/d2/2862810c631381e2e6954e42391ba008b0a6f8 /usr/lib/.build-id/d3 /usr/lib/.build-id/d3/4ff769904a1bcda120d4e12e8908dd77cccb40 /usr/lib/.build-id/d4 /usr/lib/.build-id/d4/235f6a7233be26df95a4be9535c81d84aa7fc2 /usr/lib/.build-id/d4/43e2d20074115b9f67f74d16cfd3da6969e1e9 /usr/lib/.build-id/d5 /usr/lib/.build-id/d5/8cfe4a162fffd0e3ef7bf3618b3b6cbce1bfaf /usr/lib/.build-id/d6 /usr/lib/.build-id/d6/3e9f50cb3a2fb31207022ac89857b06803ff78 /usr/lib/.build-id/d6/4ef6b7036524ffc4fc6d345c5538b186dd1291 /usr/lib/.build-id/d7 /usr/lib/.build-id/d7/3e6e0c93065e0547a93c5307d3f4a70e89428c /usr/lib/.build-id/d7/4824e3334f528f7344b74431cbb5f62f400c3b /usr/lib/.build-id/d7/8d2c9d2540ed40f8113e5924b9d2658922bdf3 /usr/lib/.build-id/de /usr/lib/.build-id/de/5b105374f92e34399b0c2e81d0ae3da3a51202 /usr/lib/.build-id/df /usr/lib/.build-id/df/af1a94b38fca184bbc7e12ee0cbab2d83c97e7 /usr/lib/.build-id/e1 /usr/lib/.build-id/e1/083de2d0908360d4c1de4e9b3e03c7b7375ba5 /usr/lib/.build-id/e3 /usr/lib/.build-id/e3/fb59caf0676b1f611d80d887b602d5ae685fad /usr/lib/.build-id/e5 /usr/lib/.build-id/e5/4b956303b591db93e48f70ae0db108f7dca417 /usr/lib/.build-id/e6 /usr/lib/.build-id/e6/a7bd21793bbd89fcd5a2ec82801de61ee138fd /usr/lib/.build-id/e7 /usr/lib/.build-id/e7/ae293f7ed7a57f6435d8b3ccc3350b1d348759 /usr/lib/.build-id/e8 /usr/lib/.build-id/e8/4285954b07bca8d4dbfb273239578b2e5ed98e /usr/lib/.build-id/eb /usr/lib/.build-id/eb/419710de8d33e3552f1ab85c6ce91477c974b7 /usr/lib/.build-id/ec /usr/lib/.build-id/ec/3218683af184ca17d8c37bfbd851bc986afbf7 /usr/lib/.build-id/ed /usr/lib/.build-id/ed/fd7e6e628052f4d67f5e902821956fe05c98db /usr/lib/.build-id/ee /usr/lib/.build-id/ee/c61d27df68135d55c3e336efa232152683b85a /usr/lib/.build-id/ef /usr/lib/.build-id/ef/bd87f43d3c360d304df8ede50a44e069d812ec /usr/lib/.build-id/f0 /usr/lib/.build-id/f0/68cc66c86fb05bec2ee7fd2a611283c67e946f /usr/lib/.build-id/f4 /usr/lib/.build-id/f4/2cc0cd7fac8ae966693fb15b7a9ae15182f76c /usr/lib/.build-id/f5 /usr/lib/.build-id/f5/b82773de325e68b493d394210846341feb5181 /usr/lib/.build-id/f6 /usr/lib/.build-id/f6/e36f69dfb4825d12cbb5a852c006da00f8cc9f /usr/lib/.build-id/f8 /usr/lib/.build-id/f8/74609e51f6be0fd56987f4bcbc6a0f60d68ea5 /usr/lib/.build-id/f9 /usr/lib/.build-id/f9/1eec40fd87e022020ac133eb965289478c4827 /usr/lib/.build-id/f9/e6932b8d74e8c260ec61ddb6dfda290a31b2c0 /usr/lib/.build-id/fc /usr/lib/.build-id/fc/cfc238c18745643a5cab75830d28ed6aa17565 /usr/lib/.build-id/fe /usr/lib/.build-id/fe/212d413b84a919bd97804e238997f1b434676e /usr/lib/.build-id/ff /usr/lib/.build-id/ff/5e9fb0b331001e8a921ab563bbfcdea952a56a /usr/lib/.build-id/ff/b535d972f334b5a1045090babe9eb056b47bf9 /usr/lib/.build-id/ff/dc10800e61b9122a1df4dadeb23935da73ac29 /usr/lib/xtables /usr/lib/xtables/libarpt_mangle.so /usr/lib/xtables/libebt_802_3.so /usr/lib/xtables/libebt_among.so /usr/lib/xtables/libebt_arp.so /usr/lib/xtables/libebt_arpreply.so /usr/lib/xtables/libebt_dnat.so /usr/lib/xtables/libebt_ip.so /usr/lib/xtables/libebt_ip6.so /usr/lib/xtables/libebt_log.so /usr/lib/xtables/libebt_mark.so /usr/lib/xtables/libebt_mark_m.so /usr/lib/xtables/libebt_nflog.so /usr/lib/xtables/libebt_pkttype.so /usr/lib/xtables/libebt_redirect.so /usr/lib/xtables/libebt_snat.so /usr/lib/xtables/libebt_stp.so /usr/lib/xtables/libebt_vlan.so /usr/lib/xtables/libip6t_DNAT.so /usr/lib/xtables/libip6t_DNPT.so /usr/lib/xtables/libip6t_HL.so /usr/lib/xtables/libip6t_LOG.so /usr/lib/xtables/libip6t_MASQUERADE.so /usr/lib/xtables/libip6t_NETMAP.so /usr/lib/xtables/libip6t_REDIRECT.so /usr/lib/xtables/libip6t_REJECT.so /usr/lib/xtables/libip6t_SNAT.so /usr/lib/xtables/libip6t_SNPT.so /usr/lib/xtables/libip6t_ah.so /usr/lib/xtables/libip6t_dst.so /usr/lib/xtables/libip6t_eui64.so /usr/lib/xtables/libip6t_frag.so /usr/lib/xtables/libip6t_hbh.so /usr/lib/xtables/libip6t_hl.so /usr/lib/xtables/libip6t_icmp6.so /usr/lib/xtables/libip6t_ipv6header.so /usr/lib/xtables/libip6t_mh.so /usr/lib/xtables/libip6t_rt.so /usr/lib/xtables/libip6t_srh.so /usr/lib/xtables/libipt_CLUSTERIP.so /usr/lib/xtables/libipt_DNAT.so /usr/lib/xtables/libipt_ECN.so /usr/lib/xtables/libipt_LOG.so /usr/lib/xtables/libipt_MASQUERADE.so /usr/lib/xtables/libipt_NETMAP.so /usr/lib/xtables/libipt_REDIRECT.so /usr/lib/xtables/libipt_REJECT.so /usr/lib/xtables/libipt_SNAT.so /usr/lib/xtables/libipt_TTL.so /usr/lib/xtables/libipt_ULOG.so /usr/lib/xtables/libipt_ah.so /usr/lib/xtables/libipt_icmp.so /usr/lib/xtables/libipt_realm.so /usr/lib/xtables/libipt_ttl.so /usr/lib/xtables/libxt_AUDIT.so /usr/lib/xtables/libxt_CHECKSUM.so /usr/lib/xtables/libxt_CLASSIFY.so /usr/lib/xtables/libxt_CONNMARK.so /usr/lib/xtables/libxt_CONNSECMARK.so /usr/lib/xtables/libxt_CT.so /usr/lib/xtables/libxt_DSCP.so /usr/lib/xtables/libxt_HMARK.so /usr/lib/xtables/libxt_IDLETIMER.so /usr/lib/xtables/libxt_LED.so /usr/lib/xtables/libxt_MARK.so /usr/lib/xtables/libxt_NFLOG.so /usr/lib/xtables/libxt_NFQUEUE.so /usr/lib/xtables/libxt_NOTRACK.so /usr/lib/xtables/libxt_RATEEST.so /usr/lib/xtables/libxt_SECMARK.so /usr/lib/xtables/libxt_SET.so /usr/lib/xtables/libxt_SYNPROXY.so /usr/lib/xtables/libxt_TCPMSS.so /usr/lib/xtables/libxt_TCPOPTSTRIP.so /usr/lib/xtables/libxt_TEE.so /usr/lib/xtables/libxt_TOS.so /usr/lib/xtables/libxt_TPROXY.so /usr/lib/xtables/libxt_TRACE.so /usr/lib/xtables/libxt_addrtype.so /usr/lib/xtables/libxt_bpf.so /usr/lib/xtables/libxt_cgroup.so /usr/lib/xtables/libxt_cluster.so /usr/lib/xtables/libxt_comment.so /usr/lib/xtables/libxt_connbytes.so /usr/lib/xtables/libxt_connlabel.so /usr/lib/xtables/libxt_connlimit.so /usr/lib/xtables/libxt_connmark.so /usr/lib/xtables/libxt_conntrack.so /usr/lib/xtables/libxt_cpu.so /usr/lib/xtables/libxt_dccp.so /usr/lib/xtables/libxt_devgroup.so /usr/lib/xtables/libxt_dscp.so /usr/lib/xtables/libxt_ecn.so /usr/lib/xtables/libxt_esp.so /usr/lib/xtables/libxt_hashlimit.so /usr/lib/xtables/libxt_helper.so /usr/lib/xtables/libxt_ipcomp.so /usr/lib/xtables/libxt_iprange.so /usr/lib/xtables/libxt_ipvs.so /usr/lib/xtables/libxt_length.so /usr/lib/xtables/libxt_limit.so /usr/lib/xtables/libxt_mac.so /usr/lib/xtables/libxt_mark.so /usr/lib/xtables/libxt_multiport.so /usr/lib/xtables/libxt_nfacct.so /usr/lib/xtables/libxt_osf.so /usr/lib/xtables/libxt_owner.so /usr/lib/xtables/libxt_physdev.so /usr/lib/xtables/libxt_pkttype.so /usr/lib/xtables/libxt_policy.so /usr/lib/xtables/libxt_quota.so /usr/lib/xtables/libxt_rateest.so /usr/lib/xtables/libxt_recent.so /usr/lib/xtables/libxt_rpfilter.so /usr/lib/xtables/libxt_sctp.so /usr/lib/xtables/libxt_set.so /usr/lib/xtables/libxt_socket.so /usr/lib/xtables/libxt_standard.so /usr/lib/xtables/libxt_state.so /usr/lib/xtables/libxt_statistic.so /usr/lib/xtables/libxt_string.so /usr/lib/xtables/libxt_tcp.so /usr/lib/xtables/libxt_tcpmss.so /usr/lib/xtables/libxt_time.so /usr/lib/xtables/libxt_tos.so /usr/lib/xtables/libxt_u32.so /usr/lib/xtables/libxt_udp.so /usr/sbin/ip6tables /usr/sbin/ip6tables-apply /usr/sbin/ip6tables-restore /usr/sbin/ip6tables-restore-translate /usr/sbin/ip6tables-save /usr/sbin/ip6tables-translate /usr/sbin/iptables /usr/sbin/iptables-apply /usr/sbin/iptables-restore /usr/sbin/iptables-restore-translate /usr/sbin/iptables-save /usr/sbin/iptables-translate /usr/sbin/xtables-monitor /usr/sbin/xtables-nft-multi /usr/share/doc/iptables /usr/share/doc/iptables/INCOMPATIBILITIES /usr/share/licenses/iptables /usr/share/licenses/iptables/COPYING /usr/share/man/man8/ip6tables-apply.8.gz /usr/share/man/man8/ip6tables-restore-translate.8.gz /usr/share/man/man8/ip6tables-restore.8.gz /usr/share/man/man8/ip6tables-save.8.gz /usr/share/man/man8/ip6tables-translate.8.gz /usr/share/man/man8/ip6tables.8.gz /usr/share/man/man8/iptables-apply.8.gz /usr/share/man/man8/iptables-extensions.8.gz /usr/share/man/man8/iptables-restore-translate.8.gz /usr/share/man/man8/iptables-restore.8.gz /usr/share/man/man8/iptables-save.8.gz /usr/share/man/man8/iptables-translate.8.gz /usr/share/man/man8/iptables.8.gz /usr/share/man/man8/xtables-monitor.8.gz /usr/share/man/man8/xtables-nft.8.gz /usr/share/man/man8/xtables-translate.8.gz
Generated by rpm2html 1.8.1
Fabrice Bellet, Sat Nov 1 05:33:35 2025