libnftables1-0.9.8-150300.3.6.1<>,qdb'Np9|%+_{U9T[pvb'"D!U:)[6g+knf;͈F+يmlǎ _ l[V4/[P_gS2k; zg|7En[(+vPNV}NnjonjHQAasztیOp_Y1oJ  &Q* yz8:Q%+ݲ"H͡³Х-R>z gi=;̃=|H5mDxHf"{#_cZ>@'x?'hd " I ?EPX \ ` h  D(89<:>$@$F$-G$DH$LI$TX$XY$d\$]$^$b$c%od%e%f%l%u&v&w&x&y&z''''"'dClibnftables10.9.8150300.3.6.1nftables firewalling command interfacelibnftables is the nftables command line interface placed into a library.db'NnebbioloF SUSE Linux Enterprise 15SUSE LLC GPL-2.0-onlyhttps://www.suse.com/System/Librarieshttps://netfilter.org/projects/nftables/linuxppc64leF db'Ldb'Mf211cf4d7514882c9a1ced54dcaaeb75c3cb22cdea3b1c0a3d84a5663331c195libnftables.so.1.0.0rootrootrootrootnftables-0.9.8-150300.3.6.1.src.rpmlibnftables.so.1()(64bit)libnftables1libnftables1(ppc-64)@@@@@@@@@@@@@@    /sbin/ldconfig/sbin/ldconfiglibc.so.6()(64bit)libc.so.6(GLIBC_2.17)(64bit)libc.so.6(GLIBC_2.22)(64bit)libc.so.6(GLIBC_2.27)(64bit)libgmp.so.10()(64bit)libjansson.so.4()(64bit)libmnl.so.0()(64bit)libmnl.so.0(LIBMNL_1.0)(64bit)libnftnl.so.11()(64bit)libnftnl.so.11(LIBNFTNL_11)(64bit)libnftnl.so.11(LIBNFTNL_13)(64bit)libnftnl.so.11(LIBNFTNL_14)(64bit)libnftnl.so.11(LIBNFTNL_15)(64bit)libnftnl.so.11(LIBNFTNL_16)(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)3.0.4-14.6.0-14.0-15.2-14.14.3dGbo`_ ^@^ۅ@^@^@]7@]N@]Z@\C@[@ZZ@Z@Zu@Z]@YXY@WPU@U`kTmatthias.gerstner@suse.commatthias.gerstner@suse.comjengelh@inai.dejengelh@inai.dejengelh@inai.dejengelh@inai.dejengelh@inai.dejengelh@inai.dejengelh@inai.dejengelh@inai.dejengelh@inai.destefan.bruens@rwth-aachen.dejengelh@inai.dejengelh@inai.dejengelh@inai.dejengelh@inai.dejengelh@inai.dejengelh@inai.dejengelh@inai.dejengelh@inai.dejengelh@inai.dejengelh@inai.demrueckert@suse.dejengelh@inai.de- add 0001-evaluate-reject-support-ethernet-as-L2-protocol-for-.patch: this fixes a crash in nftables if layer2 reject rules are processed (e.g. Ethernet MAC address based reject rich rule in firewalld, bsc#1210773).- add 0001-cache-check-for-NULL-chain-in-cache_init.patch: this fixes rare crashes that could occur e.g. in firewalld (bsc#1197606).- Update to release 0.9.8 * Complete support for matching ICMP header content fields. * Added raw tcp option match support. * Added ability to check for the presence of any tcp option. * Support for rejecting traffic from the ingress chain.- Update to release 0.9.7 * Support for implicit chains * Support for ingress inet chains * Support for reject from prerouting chain * Support for --terse option in json * Support for the reset command with json- Update to release 0.9.6 * Fix two ASAN runtime errors- Update to release 0.9.5 * Support for set counters. * Support for restoring set element counters via nft -f. * Counter support for flowtables. * typeof concatenations support for sets. * Support for concatenated ranges in anonymous sets. * Allow to reject packets with 802.1q from the bridge family. * Support for matching on the conntrack ID. - Drop anonset-crashfix.patch (upstream solved differently)- Add anonset-crashfix.patch [boo#1171321]- Update to release 0.9.4 * Add a helper for concat expression handling. * Add "typeof" build/parse/print support.- Add json, python [boo#1158723]- Update to release 0.9.3 * meta: Introduce new conditions "time", "day" and "hour". * src: add ability to set/get secmarks to/from connection. * flowtable: add support for named flowtable listing. * flowtable: add support for delete command by handle. * json: add support for element deletion. * Add `-T` as the short option for `--numeric-time`. * meta: add ibrpvid and ibrvproto support- Update to new upstream release 0.9.2 * Transport header port matching, e.g. "th dport 53" * Support for matching on IPv4 options * Support for synproxy- Remove unused dblatex BuildRequires, only needed for the optional and disabled PDF generation (same contents as shipped manpage).- Update to new upstream release 0.9.0 * Support to check if packet matches an existing socket. * Support to limit number of active connections by arbitrary criteria, such as ip addresses, networks, conntrack zones or any combination thereof. * Added support for "audit" logging.- Update to new upstream release 0.8.5 * support to add/insert a rule at a given index position * meter statement now supports a configureable upper max size * timeouts for sets can now be specified in milliseconds * re-add iptables-like empty skeleton rulesets- Update to new upstream release 0.8.4 * Support to match IPv6 segment routing headers. * New "meta ibrname" and "meta obrname" arguments to match the name of the logical bridge a packet is passing through. These new names replace the old (misnamed) "ibriport"/"obriport". * `nft -a` will now show handle identifier for all objects, including tables and chains. * nft can now delete objects by their handle number. * Support to update maps from the ruleset (packet path). * the "--echo" option now prints handle id for tables and object too. * `nft -f -` will now read from standard input * Support for flow tables, cf. man page or https://lwn.net/Articles/738214/ .- Update to new upstream release 0.8.3 * raw payload support to match headers that do not yet have received a mnemonic.- Update to new upstream release 0.8.2 * add secpath support- Update to new upstream release 0.8.1 * This release deprecates the "flow table" syntax in favor of "meter".- Update to new upstream release 0.8 * This release contains new features available up to the (upcoming) Linux 4.14 kernel release: * Support for stateful objects, these objects are uniquely identified by a user-defined name, you can refer to them from rules, and there is a well established interface to operate with them. * Sort set elements when listing them, from lower to largest. * TCP option matching and mangling support. This includes TCP maximum segment size mangling. * Add new "-s" option for listings without stateful information. * Add new -c/--check option for nft, to tests if your ruleset loads fine, into the kernel, this is a dry run mode. * Connection tracking helper support. * Add --echo option, to print the handle that the kernel allocates to uniquely identify rules. * Conntrack zone support * Symmetric hash support * Add support to include directories from nft natives scripts, files are loaded in alphanumerical order. * Allow to check if IPv6 extension header or TCP option exists or is missing. * Extend quota support to display used bytes. * Add ct average matching, to match average bytes per packet a connection has transferred so far, to map the existing feature available in the iptables connbytes match. * Allow to flush maps and flow tables. * Allow to embed set definition into an existing set. * Conntrack event filtering support via rule.- Update to new upstream release 0.7 * Add new fib expression, which can be used to obtain the output interface from the route table based on either source or destination address of a packet. * Support hashing of any arbitrary key combination, eg. * Add number generation support. Useful for round-robin packet mark setting. * Add quota support, eg. * Introduce routing expression, for routing related data with support for nexthop * Notrack support, to explicitly skip connection tracking for matching packets. * Support to set non-byte bound packet header fields, including checksum adjustment. * Add 'create set' and 'create element' commands. * Allow to use variable reference for set element definitions. * Allow to use variable definitions from element commands. * Add support to flush set. You can use this new command to remove all existing elements in a set. * Inverted set lookups. * Honor absolute and relative paths via include file, where: * Support log flags, to enable logging TCP sequence and options. * tc classid parser support, eg. * Allow numeric connlabels, so if connlabel still works with undefined labels.- Update to new upstream release 0.6 * Rules may be replaced now * Flow table support (requires Linux >= 4.3) * Support for tracing * Ratelimiting now supports units like bytes/second. * Matchinv VLAN IDs, DSCP/ECN, ICMP RtAdv & RtSol- Update to new upstream release 0.5 * Support combinations of two or more selectors to build a tuple * Timeout support for sets * Dormant flag for tables * Default chain policy specifiable on creation- set the url to the project page - pass --disable-silent-rules to configure to allow gcc post build check to work- Update to new upstream release 0.4 * Since Linux 3.18: support for global ruleset operations * Since 3.17: full logging support for all the families, including nfnetlink_log * 3.16: automatic selection of the optimal set implementation * 3.14: reject support for ip, ip6 and inet * 3.18: reject support for bridge, and reject icmpx abstraction * 3.18: masquerade support * 3.19: redirect support * Extend meta to support pkttype, cpu and devgroup matching./sbin/ldconfig/sbin/ldconfignebbiolo 16841541900.9.8-150300.3.6.10.9.8-150300.3.6.1libnftables.so.1libnftables.so.1.0.0/usr/lib64/-fmessage-length=0 -grecord-gcc-switches -O2 -Wall -D_FORTIFY_SOURCE=2 -fstack-protector-strong -funwind-tables -fasynchronous-unwind-tables -fstack-clash-protection -gobs://build.suse.de/SUSE:Maintenance:28999/SUSE_SLE-15-SP3_Update/ed4025453dccbe5250bf320898c5bdb1-nftables.SUSE_SLE-15-SP3_Updatedrpmxz5ppc64le-suse-linuxELF 64-bit LSB shared object, 64-bit PowerPC or cisco 7500, version 1 (SYSV), dynamically linked, BuildID[sha1]=18fe581764f52ad0ec784ce7ea8e4a591b24429c, strippedPR RRRR RR RR RR RRR`;"g"_)utf-86672553be22e497b3563b5b04c9a333c03e97bd1da246dc2a6b9de0323491764?7zXZ !t/WE']"k%AKqx1@Q¥|p縱q2%&2,Ҟ;1q?66T4JT_ ,TSltDڏo{q|*\\*vtav&>G=T^ TAz'99d%cWjXiϐDrC F(:5Mw BzU+@uӬi3"?& ]Yd(Hh?SΑt9o+=ҒY6V O|0 `F H,_/5uJ~­Fz└bֺssrAiaBR]A!t|[ jl^(o&,|`u-L/!a\(kGv:riYLcIR!&S'<)M \2 w4YcXvh+Idڕ)5b,+r#|2~SF\ۏd+A*T_fkXF5v1\-[+F(ߛ^/\84| n\,D7*0NJ^ $Ԣ|Y {Jqdlb w}TSc޵~֦dRyU@K^o}>Dۘ[;PXA_ @ ψʯI*B<@H-P^gw1v EP ~ZК"Jp$r ^:g%E\[6;@*ilpᣟHowF}L}*E=2n?\]GG9[{Վg"OYUN`5xY߀D;a|Ff+oNг'Lj8l31Ƃ٘M)R9\g9 d?x>T0]kⵈp ,m|d%(> 'H$( ̈2!^pĺU;1(lb"&V狞 e_Fm&B[@y6B⯘"jN?rG˄T-Ul5A?d~ ҫH,c)!;{KhXpҮe gS$vr3ᔐ"tR&,>ZƝ?8{-U/jP;v7#- /;Jҗ&TeÈsm>  45evD~V-Gńamw[]VȜ_[9|P 0¡&].4F.@L2|JJe +ɑQeST-C+]M|N[-x`̄RBzǶ2b ɪF|ihݧ⁌K\Ǜܐ̂L=3hx!lu8Ig|@NM/:V{̔^cVLt'Xڷ^b_TA* ?X*hEP~t8 lGp-6;hǩl9h,-?7 M?֮eRv 2ž]-< 'hgH'5_ t~lώx ba lzx]1afYn ^i~zaehr NX#^vؼT"V̹N~ L 4P+_B>D?H!]ʟ'#st&\u*@椡cfD"ž*t H:CNB%`Il.Gx,ond2'R D*ކ`űbT7Mnla3 ғZ :eoExPg (QWGRn8oOCjN+l `%_H˳R r}weH{& x>v\H"ptr*(t|@. FDʧv̀B8}]yujw*C'0*5H VgdR,^jFAR=0(~;r;N9(bDE/MMq. KA :fohTf2$|~Z%F"Yn3- ;BʄH2' n/ J6 ;(`-O&6I#6$(GQV 'P-]$ fh Y9?M܁+5ɐ~MmxOy7@(&]E$[5t~. TF];iQF|EPI`naU\%et vIF al U %PRzW]sX?ԃpjM ỵuU8'dVfnzzÒ:DLeшRT]_ Rde {r#]-!iEOճNȣ"5-ZDb<-G?q?xwJܚxHmDʊ lRFJX:T;|>G>2 \ bcSfjdEvElRSJ"RaS2"襴T&E8d~M42 gLE' mN*3?\T2z6J>[%Ix~vԟM=`!r;ֲ9Z |;֊E͒h'h;j lVbq緣a`_4;``s1TfxR?fitT7X$ufu;fga!ؐ MI\%+h dX0AKxY AN3؝؇"/ /xюG<hې!uFrl%ItHn7pDʻ*AZ+wax֌:!/H4S2tR:>DKu$?%-f6'|~e]֘C-ӫ W׬yX(7P(^3Ocۀ=9rl>MjМ0 f9XqU$M7ϕ\I f/@5% g "5\QjG=;xѤv(89YfМzd*e{}%y =;ۛLE3;) gߧۚHծ]F?[r4|F ny,K9{S̭*PCH,V,aΊkB!JW݁ BeWPmU(YN~Ѕ,/~6nϚHA؈q"nyo9r+n@a 2W>7gq.1fݥ2KွdΗ[u'O?rկWkf/m7Z Mߴ 5QDc4iI9&+^:!יoN$Zw VUP315Y>F,ڌA"5i5NΛw9 hfC2вI#?"Ϙ| I02,Ln{ 9;o3NB6 (3ecD$)Ҹ{ -dEYqI[#10 _8k`V~LB$'|*G"R[gr:56}K~qQM[o]\CvS QuZHAB1yL9Jr rpf~ND~QD)dpcr@)ig߃կ!;]3cao2zLes X݂AMź KxM06WqX{}͚5 qvTx:OKSPcQtg*F0&[avpe ,ibWo\nQo #vB1q0UVX98q$د:|qpW٘]c&3ӌJKSWNAc(BW_W1P$̮AqN~xv3\܁^Wz`H-b;Sj_]Tj.NU͵a5$*ۢ]jR y iB1"@2^9[G t\yQRj@_P:^p8{ Z s;6r{)"btil;0n<)缕]"{D%c: 6 SF7Ll:ip=9d9@lI ((q!Dv>5 f&[Z(FU~hoDRlGaMlLi˸qO!z򅡧(c4& Aa´"V+8Jp rӝ ߌ8Krs$fI, jCec2WTJ+d[[>YUnq{{Aye~XBE%'V%k{ p18J_[u+Z-齶TJH[s4%}-YmpEvw^K.vmQR(Ļ\Z0nd /G#5ؿ3lknl2ns(HMVg73n";4Y5~CGc:suYʸoL45]nz2Dub]];I4N*F;AfnwagF=k,q_ !rB #-ѻ^&CW=GS1F.PY@3_z{?k>L/eLm;FAv(r/' 0a%q. +Œ_)17A9C eSpΫbۺFP8Y3 EtҊsQbf\MVv/{h]aĺFj|o7vNj6]4k +m@`nghs>H F9#֙+oZc0 X,U#%"}xw4^-n\ cuI+@{7ym Ko 9Oh6(Լp= !@UӖdZNsbۆI=y(wnJm1Ŗsɰ# woRZpDZU'__Ç OZ#|h^fG)gKD{>#`εydk=Љ@_Q}K8^B+b 3ndF) Pm͉z%8EҥZud%{!EN}_#VM`=Op!az8&Üt=OҬDз˿ Z뒟vW#,LS#*]Q )ƛ:=UG6,@: >(r1k5QbДFr@cg}VN{]Ig4T23pN HQ'),}[*/hآerlā:G#_WE2߬HQrZe=vkKSH>fv9OpY ~VՔ,WsAy /0XO'%FЅal*Cw>;ѷ:icڭ 3 dUk)qx@49BזY8۟u\ﰻw4 t#-tdv!n޴aXyy9nW!}hji > ]1Gz2d1܀C VhBS_A"p,#zYI~N2PC%h6)޵d#59uL3m!~ܤf]LCb ]+b}YHKha%okBdw>ӌN\XVGian i_O$]QR4΅!S*]ɖ97wL%q?f"}iiò+nDPSOZin(vaHwwgE)\>0İycח?'[8_:"WYUoe-~x.D䐗k9_"~w$[;(&ZZEC-fa@oA--z+Z$sP*ErY<+ybG~VPxgϻQ6O >l*b=.gzB Eq(هe= ڐpQf4"c}TgFJ]neՊrxK#B*'jĉwR#YR~Ƣ^ 퍇KS%I*/[RåJ(͚DLp]_T#rF?d`ׂO!v]*\M6{Pu0e< Q~;2%cO0xB# z-K ((8%=HA҈;@^xxi^d2A`"UNT;Єkᅽϋ1mBhē $ 4i0)mtzo:RbK{+Mfw~1n7*H;yqM]мcҷp=Kᆳq5wrZNFTDχ>Y(S;n4̚Z} &nm=GEB &)a1|޵=@עLpWoL.ɑP5uqS7.gG}{-&z1`UU*qmmlQmvy_п\'?L-n۾6,a9OF~wAp=o&a1 2I_z1$豛~ dxDx:9M(>m͍Wؖ`C/|fZ&}Z=?Bg%a?KRLϿFgnI&KY#mM8S:\|++@;?&|f9̓ʈȀrVӦ,6;{,>u}ύ Jb"5rbi}hAJ'.EJ^,Dd@^O,{\KBtzWW:݄͋4P@ii/ 5 l H9lƻ!p0¢M)<3Dfh7zm>d}^y;]1 4}4Kf`?a[^TXG3G ;2vesYo54HWm'u|aȑÚ[f#VIXBIMK}7V뱕*U's'QK}78ᜐD%8#~ ?OD CVxz:S lCvBQMI*%scL'Aov<ha>rwB\g7T TiZxgJySt2r{Vgyu\o׫PZ?dT}5Y6 glI .Xz)5uɣqM\pprQ"g} 8f=No|zGL_T+=l bS Pd5`UM3cFtΪG+ZeǓ5^ܗ}yETS3::#N^&!aњWR}N!xI%7E*ta/@yuq,ʿ'9$tk9E:,/Y^D$⮆;~3<9{9 1װ#|Gtw!υ,BIJk/((#~' "k~xNVl M}J+SZdw_(cMSp];䍼2WTҥkPltJ3?<۹be~[]Ep0oX"U}j3aUwc=vI'cnUaml(wnxmütglۗVx)c=i*>{l4a녋kgRE1 C<9D0$)YsDУhV?N{9uDWZZQ/ہ\hK$xF;VtxJ~ g; JY/e޸jt[-l1Uw,VF8!CR/uʹ SN#7{=8{.;7A<I&2x/o_]/>.ϓ`F1٢$k1v!-qNQ^׆n YJ=I\  Hݻ=\C0 Bwt&e}V&(v;O uM,>R]| bGܺOr{gT6}2+YТpVxG@9/=89ҜcZzχDnLc/O Ҥ_Zì?T'=Ea<7Gdi!ҲwQ<*whkk쬾]V=yA"s}Svw`8%a: X}B3;{OQX|XkD3ks-SšHwx̄4fƓ3WW) CHEpa,W%ūefYh_8;Xb׋mo.&App(jxZ 3YY2i+d9tvՍűnO'iz ^ )jTv^ C0ٱm= 4#E]G4Q: 궦R#4nX6, HȺ@qZaXOҩk9#JLf. (T0y o\tdFK:+*w@o+SQ%::C"VZ`#_"\M@j뒊SHF'8S2p"jp;Ei>G$jXU3Tg+qf|~&դ#hJ?[C$@[2/&DkJ[wiTjo3K0{MZ?TbJ̗yzAΣrZm^F_dgGq]qjJͩ)pG~_7gc [&^<%⻢Pm$-Oe;}qN Ѡ: LZp_iwԢrx;{y?%Z. $E#-q~5h؄<**J#ȂTATMg+-V_&0. voZ+!72폦ԩ7SJ+Ӱ.Ӕt9o3FcߒB,j=0W6g:3)9 ]+|nƌ rބ>bsAԏ2J];)o"`Bܕ۝(8؞>fRނ~#^$8G'g̔s9b:Ee>lw7ss)1yeAU/-$h*R.ge.AzXikSHRgT #Q(\zƹ8 섨n-6s7\RZ"JɓD `~`h}J ńP8י7DGM& t ؇pBfCM+;-"L_?cxo 8pK™0992;%J :I85⟡BϏ x^DAA/` f fSZK:!HB4Y:U{B@GA ,‘L m@[y؏CLjmۥ|@(=6#Цm6Wl"RXCH _0@Xiv@3\xMWڪ2`e)|Fۓ )Y՝B8u xHݤI'`Crt!L{`iS4}~$ΞpXy1.u= )r#EcS+HdJ+7 eVvgؽiU:o`f- ו2z"YjHyⓓ*jTX'N(b&Õ\z$~d\܃DX\mg"* ITf~[t/95bϜ*,HJV2O s|?FW+ZYl{˂Jjϊ<&E,=ń@H{-YBj\s{i`8ťh}E-Z\Jn?LdI24nAћH:qRM.?zI׹fmFw E)"$!Î0!YIW]zsL`CnW%޹ESUHޘlN;_ Lx7/pu)\hI C*H|⡧U47vxTU{ؑv銒a([S&_&Tl6sz D+`8%)Y_.Vr U/ŽoO^|LpM L 5YTZ2|jr {x( 1 I  7( *;]p,´ Jj?Yɸi`o. 1|]}Te/M<<e^X@B zPw-$[6uLF9Vm["dU>pV$$!}<ɭ݁q֧?}]t"il*8!ݣbVvMs 3,PBK:Tꂆ#A\YPh>+lq"^ZZuo;!)d[?Kn,%bp\-B:/Rlæְa5kMР9LW{k_K1).G<w&9w:=/+udQl3<Ixu' C S+aLmf=r"d 9G(z3ə`HiD[ eM'$t5Y@P/)OO׊k gc!9{%Kiv.[{:.=t!2`ȳϽ@ca]L{ sUpw[ bڲӉ"z?οjt–`Bl {.>cL=;`%;aa믴G1CucO9.i<hu¸4L\ hMͺ. Ɣsc(9 g0AB+لOۢdV |1u|^|HjY9~i]WaFX#OĎ`Tr琺|eBa@pչj\i&ZoS(L6B $ boTQq:I^|,#4^]G6ov^7ʁȘ9Z}ѽ-[RCq.[0>JdMɸ˕ 0;Z. sx<2MHC5%[Ok7)Wb4`^ʩ5nk?~؝Б S"{A&9!tOJ(=:nT|$-imqr<C6Hԛ@0{2eX)?YlS_Ag"4 hj~3y |WRRokQ{|d?pb{$7^xyAg9 >W@h#RP;.̵XS w`S4p3NY}r' akn?$@<r5C%Ts=aF$II< GITs'#޶u їmCjd?PEenۊtLS YZ