Blame SPECS/iptables.spec

Packit Service 7f19f2
# install init scripts to /usr/libexec with systemd
Packit Service 7f19f2
%global script_path %{_libexecdir}/iptables
Packit Service 7f19f2
Packit Service 7f19f2
# service legacy actions (RHBZ#748134)
Packit Service 7f19f2
%global legacy_actions %{_libexecdir}/initscripts/legacy-actions
Packit Service 7f19f2
Packit Service 7f19f2
# boostrap mode to assist in libip{4,6}tc SONAME bump
Packit Service 7f19f2
%global bootstrap 1
Packit Service 7f19f2
Packit Service 7f19f2
%if 0%{?bootstrap}
Packit Service 7f19f2
%global version_old 1.8.2
Packit Service 7f19f2
%global iptc_so_ver_old 0
Packit Service 7f19f2
%endif
Packit Service 7f19f2
%global iptc_so_ver 2
Packit Service 7f19f2
Packit Service 7f19f2
Name: iptables
Packit Service 7f19f2
Summary: Tools for managing Linux kernel packet filtering capabilities
Packit Service 7f19f2
URL: http://www.netfilter.org/projects/iptables
Packit Service 7f19f2
Version: 1.8.4
Packit Service 7369e7
Release: 15%{?dist}.3
Packit Service 7f19f2
Source: %{url}/files/%{name}-%{version}.tar.bz2
Packit Service 7f19f2
Source1: iptables.init
Packit Service 7f19f2
Source2: iptables-config
Packit Service 7f19f2
Source3: iptables.service
Packit Service 7f19f2
Source4: sysconfig_iptables
Packit Service 7f19f2
Source5: sysconfig_ip6tables
Packit Service 7f19f2
Source6: arptables.service
Packit Service 7f19f2
Source7: arptables-helper
Packit Service 7f19f2
Source8: ebtables.systemd
Packit Service 7f19f2
Source9: ebtables.service
Packit Service 7f19f2
Source10: ebtables-config
Packit Service 7f19f2
%if 0%{?bootstrap}
Packit Service 7f19f2
Source11: %{url}/files/%{name}-%{version_old}.tar.bz2
Packit Service 7f19f2
Source12: 0003-extensions-format-security-fixes-in-libip-6-t_icmp.patch
Packit Service 7f19f2
%endif
Packit Service 7f19f2
Packit Service 7f19f2
Patch01: 0001-iptables-apply-Use-mktemp-instead-of-tempfile.patch
Packit Service 7f19f2
Patch02: 0002-xtables-restore-Fix-parser-feed-from-line-buffer.patch
Packit Service 7f19f2
Patch03: 0003-xtables-restore-Avoid-access-of-uninitialized-data.patch
Packit Service 7f19f2
Patch04: 0004-extensions-time-Avoid-undefined-shift.patch
Packit Service 7f19f2
Patch05: 0005-extensions-cluster-Avoid-undefined-shift.patch
Packit Service 7f19f2
Patch06: 0006-libxtables-Avoid-buffer-overrun-in-xtables_compatibl.patch
Packit Service 7f19f2
Patch07: 0007-xtables-translate-Guard-strcpy-call-in-xlate_ifname.patch
Packit Service 7f19f2
Patch08: 0008-extensions-among-Check-call-to-fstat.patch
Packit Service 7f19f2
Patch09: 0009-uapi-netfilter-Avoid-undefined-left-shift-in-xt_sctp.patch
Packit Service 7f19f2
Patch10: 0010-xtables-translate-Fix-for-interface-name-corner-case.patch
Packit Service 7f19f2
Patch11: 0011-xtables-translate-Fix-for-iface.patch
Packit Service 7f19f2
Patch12: 0012-tests-shell-Fix-skip-checks-with-host-mode.patch
Packit Service 7f19f2
Patch13: 0013-xtables-restore-fix-for-noflush-and-empty-lines.patch
Packit Service 7f19f2
Patch14: 0014-iptables-test.py-Fix-host-mode.patch
Packit Service 7f19f2
Patch15: 0015-xtables-Review-nft_init.patch
Packit Service 7f19f2
Patch16: 0016-nft-cache-Fix-nft_release_cache-under-stress.patch
Packit Service 7f19f2
Patch17: 0017-nft-cache-Fix-iptables-save-segfault-under-stress.patch
Packit Service 7f19f2
Patch18: 0018-ebtables-among-Support-mixed-MAC-and-MAC-IP-entries.patch
Packit Service 7f19f2
Patch19: 0019-xtables-Align-effect-of-4-6-options-with-legacy.patch
Packit Service 7f19f2
Patch20: 0020-xtables-Drop-4-and-6-support-from-xtables-save-resto.patch
Packit Service 7f19f2
Patch21: 0021-nfnl_osf-Fix-broken-conversion-to-nfnl_query.patch
Packit Service 7f19f2
Patch22: 0022-nfnl_osf-Improve-error-handling.patch
Packit Service 7f19f2
Patch23: 0023-nft-cache-Reset-genid-when-rebuilding-cache.patch
Packit Service 7f19f2
Patch24: 0024-nft-Fix-for-F-in-iptables-dumps.patch
Packit Service 7f19f2
Patch25: 0025-tests-shell-Test-F-in-dump-files.patch
Packit Service 7369e7
Patch26: 0026-nft-Make-batch_add_chain-return-the-added-batch-obje.patch
Packit Service 7369e7
Patch27: 0027-nft-Fix-error-reporting-for-refreshed-transactions.patch
Packit Service 7369e7
Patch28: 0028-nft-Fix-for-concurrent-noflush-restore-calls.patch
Packit Service 7369e7
Patch29: 0029-tests-shell-Improve-concurrent-noflush-restore-test-.patch
Packit Service 7369e7
Patch30: 0030-nft-Fix-for-broken-address-mask-match-detection.patch
Packit Service 7369e7
Patch31: 0031-nft-Optimize-class-based-IP-prefix-matches.patch
Packit Service 7369e7
Patch32: 0032-ebtables-Optimize-masked-MAC-address-matches.patch
Packit Service 7369e7
Patch33: 0033-tests-shell-Add-test-for-bitwise-avoidance-fixes.patch
Packit Service 7369e7
Patch34: 0034-nft-cache-Make-nft_rebuild_cache-respect-fake-cache.patch
Packit Service 7f19f2
Packit Service 7f19f2
# pf.os: ISC license
Packit Service 7f19f2
# iptables-apply: Artistic Licence 2.0
Packit Service 7f19f2
License: GPLv2 and Artistic 2.0 and ISC
Packit Service 7f19f2
Packit Service 7f19f2
# libnetfilter_conntrack is needed for xt_connlabel
Packit Service 7f19f2
BuildRequires: pkgconfig(libnetfilter_conntrack)
Packit Service 7f19f2
# libnfnetlink-devel is requires for nfnl_osf
Packit Service 7f19f2
BuildRequires: pkgconfig(libnfnetlink)
Packit Service 7f19f2
BuildRequires: libselinux-devel
Packit Service 7f19f2
BuildRequires: kernel-headers
Packit Service 7f19f2
BuildRequires: systemd
Packit Service 7f19f2
# libmnl, libnftnl, bison, flex for nftables
Packit Service 7f19f2
BuildRequires: bison
Packit Service 7f19f2
BuildRequires: flex
Packit Service 7f19f2
BuildRequires: gcc
Packit Service 7f19f2
BuildRequires: pkgconfig(libmnl) >= 1.0
Packit Service 7f19f2
BuildRequires: pkgconfig(libnftnl) >= 1.1.5-1
Packit Service 7f19f2
# libpcap-devel for nfbpf_compile
Packit Service 7f19f2
BuildRequires: libpcap-devel
Packit Service 7f19f2
BuildRequires:  autoconf
Packit Service 7f19f2
BuildRequires:  automake
Packit Service 7f19f2
BuildRequires:  libtool
Packit Service 7f19f2
Requires: %{name}-libs%{?_isa} = %{version}-%{release}
Packit Service 7f19f2
%if 0%{?fedora} > 24
Packit Service 7f19f2
Conflicts: setup < 2.10.4-1
Packit Service 7f19f2
%endif
Packit Service 7f19f2
Packit Service 7f19f2
%description
Packit Service 7f19f2
The iptables utility controls the network packet filtering code in the
Packit Service 7f19f2
Linux kernel. If you need to set up firewalls and/or IP masquerading,
Packit Service 7f19f2
you should either install nftables or this package.
Packit Service 7f19f2
Packit Service 7f19f2
Note: This package contains the nftables-based variants of iptables and
Packit Service 7f19f2
ip6tables, which are drop-in replacements of the legacy tools.
Packit Service 7f19f2
Packit Service 7f19f2
%package libs
Packit Service 7f19f2
Summary: iptables libraries
Packit Service 7f19f2
Group: System Environment/Base
Packit Service 7f19f2
Packit Service 7f19f2
%description libs
Packit Service 7f19f2
iptables libraries.
Packit Service 7f19f2
Packit Service 7f19f2
Please remember that libip*tc libraries do neither have a stable API nor a real so version.
Packit Service 7f19f2
Packit Service 7f19f2
For more information about this, please have a look at
Packit Service 7f19f2
Packit Service 7f19f2
  http://www.netfilter.org/documentation/FAQ/netfilter-faq-4.html#ss4.5
Packit Service 7f19f2
Packit Service 7f19f2
Packit Service 7f19f2
%package devel
Packit Service 7f19f2
Summary: Development package for iptables
Packit Service 7f19f2
Group: System Environment/Base
Packit Service 7f19f2
Requires: %{name}%{?_isa} = %{version}-%{release}
Packit Service 7f19f2
Requires: iptables-libs = %{version}-%{release}
Packit Service 7f19f2
Requires: pkgconfig
Packit Service 7f19f2
Packit Service 7f19f2
%description devel
Packit Service 7f19f2
iptables development headers and libraries.
Packit Service 7f19f2
Packit Service 7f19f2
The iptc libraries are marked as not public by upstream. The interface is not
Packit Service 7f19f2
stable and may change with every new version. It is therefore unsupported.
Packit Service 7f19f2
Packit Service 7f19f2
%package services
Packit Service 7f19f2
Summary: iptables and ip6tables services for iptables
Packit Service 7f19f2
Group: System Environment/Base
Packit Service 7f19f2
Requires: %{name} = %{version}-%{release}
Packit Service 7f19f2
Requires(post): systemd
Packit Service 7f19f2
Requires(preun): systemd
Packit Service 7f19f2
Requires(postun): systemd
Packit Service 7f19f2
# obsolete old main package
Packit Service 7f19f2
Obsoletes: %{name} < 1.4.16.1
Packit Service 7f19f2
# obsolete ipv6 sub package
Packit Service 7f19f2
Obsoletes: %{name}-ipv6 < 1.4.11.1
Packit Service 7f19f2
Packit Service 7f19f2
%description services
Packit Service 7f19f2
iptables services for IPv4 and IPv6
Packit Service 7f19f2
Packit Service 7f19f2
This package provides the services iptables and ip6tables that have been split
Packit Service 7f19f2
out of the base package since they are not active by default anymore.
Packit Service 7f19f2
Packit Service 7f19f2
%package utils
Packit Service 7f19f2
Summary: iptables and ip6tables services for iptables
Packit Service 7f19f2
Group: System Environment/Base
Packit Service 7f19f2
Requires: %{name} = %{version}-%{release}
Packit Service 7f19f2
Packit Service 7f19f2
%description utils
Packit Service 7f19f2
Utils for iptables.
Packit Service 7f19f2
Packit Service 7f19f2
Currently only provides nfnl_osf with the pf.os database.
Packit Service 7f19f2
Packit Service 7f19f2
%package arptables
Packit Service 7f19f2
Summary: User space tool to set up tables of ARP rules in kernel
Packit Service 7f19f2
Group: System Environment/Base
Packit Service 7f19f2
Requires: %{name} = %{version}-%{release}
Packit Service 7f19f2
Obsoletes: arptables
Packit Service 7f19f2
Provides: arptables
Packit Service 7f19f2
Packit Service 7f19f2
%description arptables
Packit Service 7f19f2
The arptables tool is used to set up and maintain
Packit Service 7f19f2
the tables of ARP rules in the Linux kernel. These rules inspect
Packit Service 7f19f2
the ARP frames which they see. arptables is analogous to the iptables
Packit Service 7f19f2
user space tool, but is less complicated.
Packit Service 7f19f2
Packit Service 7f19f2
Note: This package contains the nftables-based variant of arptables, a drop-in
Packit Service 7f19f2
replacement of the legacy tool.
Packit Service 7f19f2
Packit Service 7f19f2
%package ebtables
Packit Service 7f19f2
Summary: Ethernet Bridge frame table administration tool
Packit Service 7f19f2
Group: System Environment/Base
Packit Service 7f19f2
Requires: %{name} = %{version}-%{release}
Packit Service 7f19f2
Obsoletes: ebtables
Packit Service 7f19f2
Provides: ebtables
Packit Service 7f19f2
Packit Service 7f19f2
%description ebtables
Packit Service 7f19f2
Ethernet bridge tables is a firewalling tool to transparently filter network
Packit Service 7f19f2
traffic passing a bridge. The filtering possibilities are limited to link
Packit Service 7f19f2
layer filtering and some basic filtering on higher network layers.
Packit Service 7f19f2
Packit Service 7f19f2
This tool is the userspace control for the bridge and ebtables kernel
Packit Service 7f19f2
components (built by default in RHEL kernels).
Packit Service 7f19f2
Packit Service 7f19f2
The ebtables tool can be used together with the other Linux filtering tools,
Packit Service 7f19f2
like iptables. There are no known incompatibility issues.
Packit Service 7f19f2
Packit Service 7f19f2
Note: This package contains the nftables-based variant of ebtables, a drop-in
Packit Service 7f19f2
replacement of the legacy tool.
Packit Service 7f19f2
Packit Service 7f19f2
%prep
Packit Service 7f19f2
%autosetup -p1
Packit Service 7f19f2
Packit Service 7f19f2
%if 0%{?bootstrap}
Packit Service 7f19f2
%{__mkdir} -p bootstrap_ver
Packit Service 7f19f2
pushd bootstrap_ver
Packit Service 7f19f2
%{__tar} --strip-components=1 -xf %{SOURCE11}
Packit Service 7f19f2
%{__patch} -p1 <%{SOURCE12}
Packit Service 7f19f2
popd
Packit Service 7f19f2
%endif
Packit Service 7f19f2
Packit Service 7f19f2
%build
Packit Service 7f19f2
./autogen.sh
Packit Service 7f19f2
CFLAGS="$RPM_OPT_FLAGS -fno-strict-aliasing " \
Packit Service 7f19f2
%configure --enable-devel --enable-bpf-compiler --with-kernel=/usr --with-kbuild=/usr --with-ksource=/usr
Packit Service 7f19f2
Packit Service 7f19f2
# do not use rpath
Packit Service 7f19f2
sed -i 's|^hardcode_libdir_flag_spec=.*|hardcode_libdir_flag_spec=""|g' libtool
Packit Service 7f19f2
sed -i 's|^runpath_var=LD_RUN_PATH|runpath_var=DIE_RPATH_DIE|g' libtool
Packit Service 7f19f2
Packit Service 7f19f2
rm -f include/linux/types.h
Packit Service 7f19f2
Packit Service 7f19f2
make %{?_smp_mflags} V=1
Packit Service 7f19f2
Packit Service 7f19f2
%if 0%{?bootstrap}
Packit Service 7f19f2
pushd bootstrap_ver
Packit Service 7f19f2
./autogen.sh
Packit Service 7f19f2
CFLAGS="$RPM_OPT_FLAGS -fno-strict-aliasing " \
Packit Service 7f19f2
%configure --enable-devel --enable-bpf-compiler --with-kernel=/usr --with-kbuild=/usr --with-ksource=/usr
Packit Service 7f19f2
Packit Service 7f19f2
# do not use rpath
Packit Service 7f19f2
sed -i 's|^hardcode_libdir_flag_spec=.*|hardcode_libdir_flag_spec=""|g' libtool
Packit Service 7f19f2
sed -i 's|^runpath_var=LD_RUN_PATH|runpath_var=DIE_RPATH_DIE|g' libtool
Packit Service 7f19f2
Packit Service 7f19f2
rm -f include/linux/types.h
Packit Service 7f19f2
Packit Service 7f19f2
make %{?_smp_mflags} V=1
Packit Service 7f19f2
popd
Packit Service 7f19f2
%endif
Packit Service 7f19f2
Packit Service 7f19f2
%install
Packit Service 7f19f2
%if 0%{?bootstrap}
Packit Service 7f19f2
%make_install -C bootstrap_ver
Packit Service 7f19f2
find %{buildroot} -xtype f -not \
Packit Service 7f19f2
	-name 'libip*tc.so.%{iptc_so_ver_old}*' -delete -print
Packit Service 7f19f2
find %{buildroot} -type l -not \
Packit Service 7f19f2
	-name 'libip*tc.so.%{iptc_so_ver_old}*' -delete -print
Packit Service 7f19f2
%endif
Packit Service 7f19f2
Packit Service 7f19f2
make install DESTDIR=%{buildroot} 
Packit Service 7f19f2
# remove la file(s)
Packit Service 7f19f2
rm -f %{buildroot}/%{_libdir}/*.la
Packit Service 7f19f2
Packit Service 7f19f2
# install ip*tables.h header files
Packit Service 7f19f2
install -m 644 include/ip*tables.h %{buildroot}%{_includedir}/
Packit Service 7f19f2
install -d -m 755 %{buildroot}%{_includedir}/iptables
Packit Service 7f19f2
install -m 644 include/iptables/internal.h %{buildroot}%{_includedir}/iptables/
Packit Service 7f19f2
Packit Service 7f19f2
# install ipulog header file
Packit Service 7f19f2
install -d -m 755 %{buildroot}%{_includedir}/libipulog/
Packit Service 7f19f2
install -m 644 include/libipulog/*.h %{buildroot}%{_includedir}/libipulog/
Packit Service 7f19f2
Packit Service 7f19f2
# install init scripts and configuration files
Packit Service 7f19f2
install -d -m 755 %{buildroot}%{script_path}
Packit Service 7f19f2
install -c -m 755 %{SOURCE1} %{buildroot}%{script_path}/iptables.init
Packit Service 7f19f2
sed -e 's;iptables;ip6tables;g' -e 's;IPTABLES;IP6TABLES;g' < %{SOURCE1} > ip6tables.init
Packit Service 7f19f2
install -c -m 755 ip6tables.init %{buildroot}%{script_path}/ip6tables.init
Packit Service 7f19f2
install -d -m 755 %{buildroot}%{_sysconfdir}/sysconfig
Packit Service 7f19f2
install -c -m 600 %{SOURCE2} %{buildroot}%{_sysconfdir}/sysconfig/iptables-config
Packit Service 7f19f2
sed -e 's;iptables;ip6tables;g' -e 's;IPTABLES;IP6TABLES;g' < %{SOURCE2} > ip6tables-config
Packit Service 7f19f2
install -c -m 600 ip6tables-config %{buildroot}%{_sysconfdir}/sysconfig/ip6tables-config
Packit Service 7f19f2
install -c -m 600 %{SOURCE4} %{buildroot}%{_sysconfdir}/sysconfig/iptables
Packit Service 7f19f2
install -c -m 600 %{SOURCE5} %{buildroot}%{_sysconfdir}/sysconfig/ip6tables
Packit Service 7f19f2
Packit Service 7f19f2
# install systemd service files
Packit Service 7f19f2
install -d -m 755 %{buildroot}/%{_unitdir}
Packit Service 7f19f2
install -c -m 644 %{SOURCE3} %{buildroot}/%{_unitdir}
Packit Service 7f19f2
sed -e 's;iptables;ip6tables;g' -e 's;IPv4;IPv6;g' -e 's;/usr/libexec/ip6tables;/usr/libexec/iptables;g' < %{SOURCE3} > ip6tables.service
Packit Service 7f19f2
install -c -m 644 ip6tables.service %{buildroot}/%{_unitdir}
Packit Service 7f19f2
Packit Service 7f19f2
# install legacy actions for service command
Packit Service 7f19f2
install -d %{buildroot}/%{legacy_actions}/iptables
Packit Service 7f19f2
install -d %{buildroot}/%{legacy_actions}/ip6tables
Packit Service 7f19f2
Packit Service 7f19f2
cat << EOF > %{buildroot}/%{legacy_actions}/iptables/save
Packit Service 7f19f2
#!/bin/bash
Packit Service 7f19f2
exec %{script_path}/iptables.init save
Packit Service 7f19f2
EOF
Packit Service 7f19f2
chmod 755 %{buildroot}/%{legacy_actions}/iptables/save
Packit Service 7f19f2
sed -e 's;iptables.init;ip6tables.init;g' -e 's;IPTABLES;IP6TABLES;g' < %{buildroot}/%{legacy_actions}/iptables/save > ip6tabes.save-legacy
Packit Service 7f19f2
install -c -m 755 ip6tabes.save-legacy %{buildroot}/%{legacy_actions}/ip6tables/save
Packit Service 7f19f2
Packit Service 7f19f2
cat << EOF > %{buildroot}/%{legacy_actions}/iptables/panic
Packit Service 7f19f2
#!/bin/bash
Packit Service 7f19f2
exec %{script_path}/iptables.init panic
Packit Service 7f19f2
EOF
Packit Service 7f19f2
chmod 755 %{buildroot}/%{legacy_actions}/iptables/panic
Packit Service 7f19f2
sed -e 's;iptables.init;ip6tables.init;g' -e 's;IPTABLES;IP6TABLES;g' < %{buildroot}/%{legacy_actions}/iptables/panic > ip6tabes.panic-legacy
Packit Service 7f19f2
install -c -m 755 ip6tabes.panic-legacy %{buildroot}/%{legacy_actions}/ip6tables/panic
Packit Service 7f19f2
Packit Service 7f19f2
# install iptables-apply with man page
Packit Service 7f19f2
install -m 755 iptables/iptables-apply %{buildroot}%{_sbindir}/
Packit Service 7f19f2
install -m 644 iptables/iptables-apply.8 %{buildroot}%{_mandir}/man8/
Packit Service 7f19f2
Packit Service 7f19f2
%if 0%{?fedora} > 24
Packit Service 7f19f2
# Remove /etc/ethertypes (now part of setup)
Packit Service 7f19f2
rm -f %{buildroot}%{_sysconfdir}/ethertypes
Packit Service 7f19f2
%endif
Packit Service 7f19f2
Packit Service 7f19f2
# drop all legacy tools
Packit Service 7f19f2
rm -f %{buildroot}%{_sbindir}/*legacy*
Packit Service 7f19f2
rm -f %{buildroot}%{_bindir}/iptables-xml
Packit Service 7f19f2
rm -f %{buildroot}%{_mandir}/man1/iptables-xml*
Packit Service 7f19f2
rm -f %{buildroot}%{_mandir}/man8/xtables-legacy*
Packit Service 7f19f2
Packit Service 7f19f2
# rename nft versions to standard name
Packit Service 7f19f2
pfx=%{buildroot}%{_sbindir}/iptables
Packit Service 7f19f2
for pfx in %{buildroot}%{_sbindir}/{iptables,ip6tables,arptables,ebtables}; do
Packit Service 7f19f2
	mv $pfx-nft $pfx
Packit Service 7f19f2
	mv $pfx-nft-restore $pfx-restore
Packit Service 7f19f2
	mv $pfx-nft-save $pfx-save
Packit Service 7f19f2
done
Packit Service 7f19f2
Packit Service 7f19f2
# extra sources for arptables
Packit Service 7f19f2
install -p -D -m 644 %{SOURCE6} %{buildroot}%{_unitdir}/arptables.service
Packit Service 7f19f2
mkdir -p %{buildroot}%{_libexecdir}/
Packit Service 7f19f2
install -p -D -m 755 %{SOURCE7} %{buildroot}%{_libexecdir}/
Packit Service 7f19f2
mkdir -p %{buildroot}%{_sysconfdir}/sysconfig
Packit Service 7f19f2
echo '# Configure prior to use' > %{buildroot}%{_sysconfdir}/sysconfig/arptables
Packit Service 7f19f2
for sfx in "" "-restore" "-save"; do
Packit Service 7f19f2
	echo '.so man8/arptables-nft${sfx}.8' > \
Packit Service 7f19f2
		%{buildroot}%{_mandir}/man8/arptables${sfx}.8
Packit Service 7f19f2
done
Packit Service 7f19f2
Packit Service 7f19f2
# extra sources for ebtables
Packit Service 7f19f2
install -p %{SOURCE9} %{buildroot}%{_unitdir}/
Packit Service 7f19f2
install -m0755 %{SOURCE8} %{buildroot}%{_libexecdir}/ebtables
Packit Service 7f19f2
install -m0600 %{SOURCE10} %{buildroot}%{_sysconfdir}/sysconfig/ebtables-config
Packit Service 7f19f2
touch %{buildroot}%{_sysconfdir}/sysconfig/ebtables
Packit Service 7f19f2
echo '.so man8/ebtables-nft.8' > %{buildroot}%{_mandir}/man8/ebtables.8
Packit Service 7f19f2
Packit Service 7f19f2
%if 0%{?rhel}
Packit Service 7f19f2
%pre
Packit Service 7f19f2
for p in %{_sysconfdir}/alternatives/{iptables,ip6tables}.*; do
Packit Service 7f19f2
    if [ -h "$p" ]; then
Packit Service 7f19f2
        ipt=$(readlink "$p")
Packit Service 7f19f2
        echo "Removing alternatives for ${p##*/} with path $ipt"
Packit Service 7f19f2
        %{_sbindir}/alternatives --remove "${p##*/}" "$ipt"
Packit Service 7f19f2
    fi
Packit Service 7f19f2
done
Packit Service 7f19f2
%endif
Packit Service 7f19f2
Packit Service 7f19f2
%post -p /sbin/ldconfig
Packit Service 7f19f2
Packit Service 7f19f2
%postun -p /sbin/ldconfig
Packit Service 7f19f2
Packit Service 7f19f2
%post services
Packit Service 7f19f2
%systemd_post iptables.service ip6tables.service
Packit Service 7f19f2
Packit Service 7f19f2
%preun services
Packit Service 7f19f2
%systemd_preun iptables.service ip6tables.service
Packit Service 7f19f2
Packit Service 7f19f2
%postun services
Packit Service 7f19f2
/sbin/ldconfig
Packit Service 7f19f2
%systemd_postun iptables.service ip6tables.service
Packit Service 7f19f2
Packit Service 7f19f2
%post arptables
Packit Service 7f19f2
%systemd_post arptables.service
Packit Service 7f19f2
Packit Service 7f19f2
%preun arptables
Packit Service 7f19f2
%systemd_preun arptables.service
Packit Service 7f19f2
Packit Service 7f19f2
%postun arptables
Packit Service 7f19f2
%systemd_postun arptables.service
Packit Service 7f19f2
Packit Service 7f19f2
%post ebtables
Packit Service 7f19f2
%systemd_post ebtables.service
Packit Service 7f19f2
Packit Service 7f19f2
%preun ebtables
Packit Service 7f19f2
%systemd_preun ebtables.service
Packit Service 7f19f2
Packit Service 7f19f2
%postun ebtables
Packit Service 7f19f2
%systemd_postun_with_restart ebtables.service
Packit Service 7f19f2
Packit Service 7f19f2
%files
Packit Service 7f19f2
%{!?_licensedir:%global license %%doc}
Packit Service 7f19f2
%license COPYING
Packit Service 7f19f2
%doc INCOMPATIBILITIES
Packit Service 7f19f2
%config(noreplace) %{_sysconfdir}/sysconfig/iptables-config
Packit Service 7f19f2
%config(noreplace) %{_sysconfdir}/sysconfig/ip6tables-config
Packit Service 7f19f2
%if 0%{?fedora} <= 24
Packit Service 7f19f2
%{_sysconfdir}/ethertypes
Packit Service 7f19f2
%endif
Packit Service 7f19f2
%{_sbindir}/iptables
Packit Service 7f19f2
%{_sbindir}/iptables-apply
Packit Service 7f19f2
%{_sbindir}/iptables-restore
Packit Service 7f19f2
%{_sbindir}/iptables-restore-translate
Packit Service 7f19f2
%{_sbindir}/iptables-save
Packit Service 7f19f2
%{_sbindir}/iptables-translate
Packit Service 7f19f2
%{_sbindir}/ip6tables
Packit Service 7f19f2
%{_sbindir}/ip6tables-restore
Packit Service 7f19f2
%{_sbindir}/ip6tables-restore-translate
Packit Service 7f19f2
%{_sbindir}/ip6tables-save
Packit Service 7f19f2
%{_sbindir}/ip6tables-translate
Packit Service 7f19f2
%{_sbindir}/xtables-monitor
Packit Service 7f19f2
%{_sbindir}/xtables-nft-multi
Packit Service 7f19f2
%doc %{_mandir}/man8/iptables*
Packit Service 7f19f2
%doc %{_mandir}/man8/ip6tables*
Packit Service 7f19f2
%doc %{_mandir}/man8/xtables-monitor*
Packit Service 7f19f2
%doc %{_mandir}/man8/xtables-nft*
Packit Service 7f19f2
%doc %{_mandir}/man8/*tables-translate*
Packit Service 7f19f2
%doc %{_mandir}/man8/*tables-restore-translate*
Packit Service 7f19f2
%dir %{_libdir}/xtables
Packit Service 7f19f2
%{_libdir}/xtables/libarpt*
Packit Service 7f19f2
%{_libdir}/xtables/libebt*
Packit Service 7f19f2
%{_libdir}/xtables/libipt*
Packit Service 7f19f2
%{_libdir}/xtables/libip6t*
Packit Service 7f19f2
%{_libdir}/xtables/libxt*
Packit Service 7f19f2
Packit Service 7f19f2
%files libs
Packit Service 7f19f2
%{_libdir}/libip*tc.so.%{iptc_so_ver}*
Packit Service 7f19f2
%if 0%{?bootstrap}
Packit Service 7f19f2
%{_libdir}/libip*tc.so.%{iptc_so_ver_old}*
Packit Service 7f19f2
%endif
Packit Service 7f19f2
%{_libdir}/libxtables.so.12*
Packit Service 7f19f2
Packit Service 7f19f2
%files devel
Packit Service 7f19f2
%dir %{_includedir}/iptables
Packit Service 7f19f2
%{_includedir}/iptables/*.h
Packit Service 7f19f2
%{_includedir}/*.h
Packit Service 7f19f2
%dir %{_includedir}/libiptc
Packit Service 7f19f2
%{_includedir}/libiptc/*.h
Packit Service 7f19f2
%dir %{_includedir}/libipulog
Packit Service 7f19f2
%{_includedir}/libipulog/*.h
Packit Service 7f19f2
%{_libdir}/libip*tc.so
Packit Service 7f19f2
%{_libdir}/libxtables.so
Packit Service 7f19f2
%{_libdir}/pkgconfig/libiptc.pc
Packit Service 7f19f2
%{_libdir}/pkgconfig/libip4tc.pc
Packit Service 7f19f2
%{_libdir}/pkgconfig/libip6tc.pc
Packit Service 7f19f2
%{_libdir}/pkgconfig/xtables.pc
Packit Service 7f19f2
Packit Service 7f19f2
%files services
Packit Service 7f19f2
%dir %{script_path}
Packit Service 7f19f2
%{script_path}/iptables.init
Packit Service 7f19f2
%{script_path}/ip6tables.init
Packit Service 7f19f2
%config(noreplace) %{_sysconfdir}/sysconfig/iptables
Packit Service 7f19f2
%config(noreplace) %{_sysconfdir}/sysconfig/ip6tables
Packit Service 7f19f2
%{_unitdir}/iptables.service
Packit Service 7f19f2
%{_unitdir}/ip6tables.service
Packit Service 7f19f2
%dir %{legacy_actions}/iptables
Packit Service 7f19f2
%{legacy_actions}/iptables/save
Packit Service 7f19f2
%{legacy_actions}/iptables/panic
Packit Service 7f19f2
%dir %{legacy_actions}/ip6tables
Packit Service 7f19f2
%{legacy_actions}/ip6tables/save
Packit Service 7f19f2
%{legacy_actions}/ip6tables/panic
Packit Service 7f19f2
Packit Service 7f19f2
%files utils
Packit Service 7f19f2
%{_sbindir}/nfnl_osf
Packit Service 7f19f2
%{_sbindir}/nfbpf_compile
Packit Service 7f19f2
%dir %{_datadir}/xtables
Packit Service 7f19f2
%{_datadir}/xtables/pf.os
Packit Service 7f19f2
%doc %{_mandir}/man8/nfnl_osf*
Packit Service 7f19f2
%doc %{_mandir}/man8/nfbpf_compile*
Packit Service 7f19f2
Packit Service 7f19f2
%files arptables
Packit Service 7f19f2
%{_sbindir}/arptables*
Packit Service 7f19f2
%{_libexecdir}/arptables-helper
Packit Service 7f19f2
%{_unitdir}/arptables.service
Packit Service 7f19f2
%config(noreplace) %{_sysconfdir}/sysconfig/arptables
Packit Service 7f19f2
%doc %{_mandir}/man8/arptables*.8*
Packit Service 7f19f2
Packit Service 7f19f2
%files ebtables
Packit Service 7f19f2
%{_sbindir}/ebtables*
Packit Service 7f19f2
%{_libexecdir}/ebtables
Packit Service 7f19f2
%{_unitdir}/ebtables.service
Packit Service 7f19f2
%config(noreplace) %{_sysconfdir}/sysconfig/ebtables-config
Packit Service 7f19f2
%ghost %{_sysconfdir}/sysconfig/ebtables
Packit Service 7f19f2
%doc %{_mandir}/man8/ebtables*.8*
Packit Service 7f19f2
Packit Service 7f19f2
%changelog
Packit Service 7369e7
* Tue Nov 10 2020 Phil Sutter <psutter@redhat.com> - 1.8.4-15.3
Packit Service 7369e7
- nft: cache: Make nft_rebuild_cache() respect fake cache
Packit Service 7369e7
Packit Service 7369e7
* Thu Nov 05 2020 Phil Sutter <psutter@redhat.com> - 1.8.4-15.2
Packit Service 7369e7
- tests/shell: Add test for bitwise avoidance fixes
Packit Service 7369e7
- ebtables: Optimize masked MAC address matches
Packit Service 7369e7
- nft: Optimize class-based IP prefix matches
Packit Service 7369e7
- nft: Fix for broken address mask match detection
Packit Service 7369e7
Packit Service 7369e7
* Wed Oct 28 2020 Phil Sutter <psutter@redhat.com> - 1.8.4-15.1
Packit Service 7369e7
- tests: shell: Improve concurrent noflush restore test a bit
Packit Service 7369e7
- nft: Fix for concurrent noflush restore calls
Packit Service 7369e7
- nft: Fix error reporting for refreshed transactions
Packit Service 7369e7
- nft: Make batch_add_chain() return the added batch object
Packit Service 7369e7
Packit Service 7f19f2
* Sat Aug 15 2020 Phil Sutter <psutter@redhat.com> - 1.8.4-15
Packit Service 7f19f2
- Ignore sysctl files not suffixed '.conf'
Packit Service 7f19f2
Packit Service 7f19f2
* Wed Jun 24 2020 Phil Sutter <psutter@redhat.com> - 1.8.4-14
Packit Service 7f19f2
- nft: Fix for '-F' in iptables dumps
Packit Service 7f19f2
- tests: shell: Test -F in dump files
Packit Service 7f19f2
Packit Service 7f19f2
* Fri May 29 2020 Phil Sutter <psutter@redhat.com> - 1.8.4-13
Packit Service 7f19f2
- Fix for endless loop in iptables-restore --test
Packit Service 7f19f2
Packit Service 7f19f2
* Tue May 26 2020 Phil Sutter <psutter@redhat.com> - 1.8.4-12
Packit Service 7f19f2
- Unbreak nfnl_osf tool
Packit Service 7f19f2
Packit Service 7f19f2
* Tue May 19 2020 Phil Sutter <psutter@redhat.com> - 1.8.4-11
Packit Service 7f19f2
- Complete ebtables-nft among match support
Packit Service 7f19f2
- Replace RHEL-only xtables-monitor fix with upstream solution
Packit Service 7f19f2
- xtables: Align effect of -4/-6 options with legacy
Packit Service 7f19f2
- xtables: Drop -4 and -6 support from xtables-{save,restore}
Packit Service 7f19f2
- Review systemd unit files
Packit Service 7f19f2
Packit Service 7f19f2
* Tue Mar 17 2020 Phil Sutter <psutter@redhat.com> - 1.8.4-10
Packit Service 7f19f2
- Fix for iptables-restore segfault under pressure
Packit Service 7f19f2
- Fix for iptables-save segfault under pressure
Packit Service 7f19f2
Packit Service 7f19f2
* Mon Feb 24 2020 Phil Sutter <psutter@redhat.com> - 1.8.4-9
Packit Service 7f19f2
- iptables-test.py: Fix --host mode
Packit Service 7f19f2
- xtables-monitor: Fix segfault when tracing
Packit Service 7f19f2
Packit Service 7f19f2
* Sat Feb 15 2020 Phil Sutter <psutter@redhat.com> - 1.8.4-8
Packit Service 7f19f2
- xtables-translate: Fix for iface++
Packit Service 7f19f2
- tests: shell: Fix skip checks with --host mode
Packit Service 7f19f2
- xtables-restore: fix for --noflush and empty lines
Packit Service 7f19f2
Packit Service 7f19f2
* Wed Feb 12 2020 Phil Sutter <psutter@redhat.com> - 1.8.4-7
Packit Service 7f19f2
- xtables-translate: Fix for interface name corner-cases
Packit Service 7f19f2
Packit Service 7f19f2
* Mon Dec 09 2019 Phil Sutter <psutter@redhat.com> - 1.8.4-6
Packit Service 7f19f2
- Add missing patch in last release, uAPI covscan fix
Packit Service 7f19f2
Packit Service 7f19f2
* Mon Dec 09 2019 Phil Sutter <psutter@redhat.com> - 1.8.4-5
Packit Service 7f19f2
- Fix covscan-indicated problems
Packit Service 7f19f2
Packit Service 7f19f2
* Wed Dec 04 2019 Phil Sutter <psutter@redhat.com> - 1.8.4-4
Packit Service 7f19f2
- Fix for broken xtables-restore --noflush
Packit Service 7f19f2
Packit Service 7f19f2
* Tue Dec 03 2019 Phil Sutter <psutter@redhat.com> - 1.8.4-3
Packit Service 7f19f2
- Reduce globbing in library file names to expose future SONAME changes
Packit Service 7f19f2
- Add bootstrapping for libip*tc SONAME bump
Packit Service 7f19f2
Packit Service 7f19f2
* Mon Dec 02 2019 Phil Sutter <psutter@redhat.com> - 1.8.4-2
Packit Service 7f19f2
- Use upstream-provided man pages for ebtables and arptables
Packit Service 7f19f2
Packit Service 7f19f2
* Mon Dec 02 2019 Phil Sutter <psutter@redhat.com> - 1.8.4-1
Packit Service 7f19f2
- Rebase onto upstream release 1.8.4
Packit Service 7f19f2
Packit Service 7f19f2
* Thu Aug 08 2019 Phil Sutter <psutter@redhat.com> - 1.8.2-16
Packit Service 7f19f2
- nft: Set socket receive buffer
Packit Service 7f19f2
Packit Service 7f19f2
* Wed Jul 31 2019 Phil Sutter <psutter@redhat.com> - 1.8.2-15
Packit Service 7f19f2
- doc: Install ip{6,}tables-restore-translate.8 man pages
Packit Service 7f19f2
Packit Service 7f19f2
* Tue Jul 02 2019 Phil Sutter <psutter@redhat.com> - 1.8.2-14
Packit Service 7f19f2
- arptables: Print space before comma and counters
Packit Service 7f19f2
- extensions: Fix ipvs vproto parsing
Packit Service 7f19f2
- extensions: Fix ipvs vproto option printing
Packit Service 7f19f2
- extensions: Add testcase for libxt_ipvs
Packit Service 7f19f2
Packit Service 7f19f2
* Mon Jul 01 2019 Phil Sutter <psutter@redhat.com> - 1.8.2-13
Packit Service 7f19f2
- doc: Install ip{6,}tables-translate.8 manpages
Packit Service 7f19f2
- nft: Eliminate dead code in __nft_rule_list
Packit Service 7f19f2
Packit Service 7f19f2
* Wed Jun 12 2019 Phil Sutter <psutter@redhat.com> - 1.8.2-12
Packit Service 7f19f2
- Add iptables-test.py testsuite to sources
Packit Service 7f19f2
- extensions: libip6t_mh: fix bogus translation error
Packit Service 7f19f2
- extensions: AUDIT: Document ineffective --type option
Packit Service 7f19f2
- xtables-restore: Fix program names in help texts
Packit Service 7f19f2
- xtables-save: Point at existing man page in help text
Packit Service 7f19f2
- utils: Add a manpage for nfbpf_compile
Packit Service 7f19f2
- Mark man pages in base package as documentation files
Packit Service 7f19f2
Packit Service 7f19f2
* Thu May 23 2019 Phil Sutter <psutter@redhat.com> - 1.8.2-11
Packit Service 7f19f2
- Enable verbose output when building
Packit Service 7f19f2
Packit Service 7f19f2
* Thu May 09 2019 Phil Sutter <psutter@redhat.com> - 1.8.2-10
Packit Service 7f19f2
- arptables-nft: fix decoding of hlen on bigendian platforms
Packit Service 7f19f2
- xtables-save: Fix table not found error message
Packit Service 7f19f2
- xtables: Catch errors when zeroing rule rounters
Packit Service 7f19f2
- extensions: TRACE: Point at xtables-monitor in documentation
Packit Service 7f19f2
- extensions: libipt_realm: Document allowed realm values
Packit Service 7f19f2
Packit Service 7f19f2
* Fri Feb 08 2019 Phil Sutter - 1.8.2-9
Packit Service 7f19f2
- ebtables-nft: Support user-defined chain policies
Packit Service 7f19f2
Packit Service 7f19f2
* Thu Feb 07 2019 Phil Sutter - 1.8.2-8
Packit Service 7f19f2
- arptables.8: Document --set-counters option
Packit Service 7f19f2
Packit Service 7f19f2
* Thu Feb 07 2019 Phil Sutter - 1.8.2-7
Packit Service 7f19f2
- arptables: Support --set-counters option
Packit Service 7f19f2
Packit Service 7f19f2
* Fri Feb 01 2019 Phil Sutter - 1.8.2-6
Packit Service 7f19f2
- Improve performance with large rulesets
Packit Service 7f19f2
- Fix for changes in arptables output
Packit Service 7f19f2
- Fix for inserting rules at wrong position
Packit Service 7f19f2
- Fix segfault when comparing rules with standard target
Packit Service 7f19f2
- Fix ebtables output for negated values
Packit Service 7f19f2
- Document missing arptables FORWARD chain
Packit Service 7f19f2
Packit Service 7f19f2
* Tue Dec 18 2018 Phil Sutter - 1.8.2-5
Packit Service 7f19f2
- Drop change to test snippet not included in tarball from Patch4
Packit Service 7f19f2
Packit Service 7f19f2
* Tue Dec 18 2018 Phil Sutter - 1.8.2-4
Packit Service 7f19f2
- Fix iptables init script for nftables-backend
Packit Service 7f19f2
- Drop references to unsupported broute table from ebtables man page
Packit Service 7f19f2
- xtables: Don't use native nftables comments
Packit Service 7f19f2
Packit Service 7f19f2
* Thu Dec 06 2018 Phil Sutter - 1.8.2-3
Packit Service 7f19f2
- Drop change to test snippet not included in tarball from Patch3
Packit Service 7f19f2
Packit Service 7f19f2
* Thu Dec 06 2018 Phil Sutter - 1.8.2-2
Packit Service 7f19f2
- Point out that nftables-variants are installed in package description
Packit Service 7f19f2
- Fix for deleting arptables rules by referencing them
Packit Service 7f19f2
Packit Service 7f19f2
* Thu Dec 06 2018 Phil Sutter - 1.8.2-1
Packit Service 7f19f2
- Rebase onto upstream version 1.8.2
Packit Service 7f19f2
Packit Service 7f19f2
* Thu Oct 25 2018 Phil Sutter - 1.8.1-2
Packit Service 7f19f2
- Add upstream fixes to 1.8.1 release
Packit Service 7f19f2
Packit Service 7f19f2
* Thu Oct 25 2018 Phil Sutter - 1.8.1-1
Packit Service 7f19f2
- Rebase onto upstream version 1.8.1
Packit Service 7f19f2
Packit Service 7f19f2
* Thu Sep 27 2018 Phil Sutter - 1.8.0-11
Packit Service 7f19f2
- Fix for covscan warnings in init scripts
Packit Service 7f19f2
Packit Service 7f19f2
* Wed Sep 26 2018 Phil Sutter - 1.8.0-10
Packit Service 7f19f2
- Fix short name of Artistic Licence
Packit Service 7f19f2
Packit Service 7f19f2
* Wed Sep 26 2018 Phil Sutter - 1.8.0-9
Packit Service 7f19f2
- Add further fixes for issues identified by covscan
Packit Service 7f19f2
- Fix for bogus "is incompatible" warnings
Packit Service 7f19f2
- Fix layout in License tag
Packit Service 7f19f2
- Replace "Fedora" with "RHEL" in description
Packit Service 7f19f2
- Make devel sub-package depend on libs sub-package
Packit Service 7f19f2
Packit Service 7f19f2
* Mon Sep 17 2018 Phil Sutter - 1.8.0-8
Packit Service 7f19f2
- Fix issues identified by covscan
Packit Service 7f19f2
- xtables-restore: Fix flushing referenced custom chains
Packit Service 7f19f2
- xtables: Accept --wait in iptables-nft-restore
Packit Service 7f19f2
Packit Service 7f19f2
* Mon Sep 03 2018 Phil Sutter - 1.8.0-7
Packit Service 7f19f2
- xtables: Align return codes with legacy iptables
Packit Service 7f19f2
- xtables: Drop use of IP6T_F_PROTO
Packit Service 7f19f2
Packit Service 7f19f2
* Wed Aug 29 2018 Phil Sutter - 1.8.0-6
Packit Service 7f19f2
- xtables: Fix for deleting rules with comment
Packit Service 7f19f2
Packit Service 7f19f2
* Fri Aug 24 2018 Phil Sutter - 1.8.0-5
Packit Service 7f19f2
- xtables: Use meta l4proto for -p match
Packit Service 7f19f2
- ebtables: Fix for listing of non-existent chains
Packit Service 7f19f2
- xtables: Fix for no output in iptables-nft -S
Packit Service 7f19f2
Packit Service 7f19f2
* Sat Aug 18 2018 Phil Sutter - 1.8.0-4
Packit Service 7f19f2
- xtables: Fix for segfault in iptables-nft
Packit Service 7f19f2
- ebtables: Fix entries count in chain listing
Packit Service 7f19f2
- Use %%autosetup macro in %%prep
Packit Service 7f19f2
Packit Service 7f19f2
* Fri Aug 17 2018 Phil Sutter - 1.8.0-3
Packit Service 7f19f2
- xtables: Make 'iptables -S nonexisting' return non-zero
Packit Service 7f19f2
Packit Service 7f19f2
* Fri Aug 10 2018 Phil Sutter - 1.8.0-2
Packit Service 7f19f2
- Rebase onto upstream master commit 514de4801b731db4712
Packit Service 7f19f2
- Add arptables and ebtables sub-packages
Packit Service 7f19f2
Packit Service 7f19f2
* Wed Jul 11 2018 Phil Sutter - 1.8.0-1
Packit Service 7f19f2
- New upstream version 1.8.0
Packit Service 7f19f2
- Drop compat sub-package
Packit Service 7f19f2
- Use nft tool versions, drop legacy ones
Packit Service 7f19f2
Packit Service 7f19f2
* Thu Mar 01 2018 Phil Sutter <psutter@redhat.com> - 1.6.2-2
Packit Service 7f19f2
- Kill module unloading support
Packit Service 7f19f2
- Support /etc/sysctl.d
Packit Service 7f19f2
- Don't restart services after package update
Packit Service 7f19f2
- Add support for --wait options to restore commands
Packit Service 7f19f2
Packit Service 7f19f2
* Wed Feb 21 2018 Michael Cronenworth <mike@cchtml.com> - 1.6.2-1
Packit Service 7f19f2
- New upstream version 1.6.2
Packit Service 7f19f2
  http://www.netfilter.org/projects/iptables/files/changes-iptables-1.6.2.txt
Packit Service 7f19f2
Packit Service 7f19f2
* Wed Feb 07 2018 Fedora Release Engineering <releng@fedoraproject.org> - 1.6.1-6
Packit Service 7f19f2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_28_Mass_Rebuild
Packit Service 7f19f2
Packit Service 7f19f2
* Sun Oct 22 2017 Kevin Fenzi <kevin@scrye.com> - 1.6.1-5
Packit Service 7f19f2
- Rebuild for new libnftnl
Packit Service 7f19f2
Packit Service 7f19f2
* Wed Aug 02 2017 Fedora Release Engineering <releng@fedoraproject.org> - 1.6.1-4
Packit Service 7f19f2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Binutils_Mass_Rebuild
Packit Service 7f19f2
Packit Service 7f19f2
* Wed Jul 26 2017 Fedora Release Engineering <releng@fedoraproject.org> - 1.6.1-3
Packit Service 7f19f2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild
Packit Service 7f19f2
Packit Service 7f19f2
* Fri Feb 10 2017 Fedora Release Engineering <releng@fedoraproject.org> - 1.6.1-2
Packit Service 7f19f2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_26_Mass_Rebuild
Packit Service 7f19f2
Packit Service 7f19f2
* Thu Feb 02 2017 Thomas Woerner <twoerner@redhat.com> - 1.6.1-1
Packit Service 7f19f2
- New upstream version 1.6.1 with enhanced translation to nft support and
Packit Service 7f19f2
  several fixes (RHBZ#1417323)
Packit Service 7f19f2
  http://netfilter.org/projects/iptables/files/changes-iptables-1.6.1.txt
Packit Service 7f19f2
- Enable parallel build again
Packit Service 7f19f2
Packit Service 7f19f2
* Thu Feb 02 2017 Petr Ĺ abata <contyk@redhat.com> - 1.6.0-4
Packit Service 7f19f2
- Disabling parallel build to avoid build issues with xtables
Packit Service 7f19f2
- See http://patchwork.alpinelinux.org/patch/1787/ for reference
Packit Service 7f19f2
- This should be fixed in 1.6.1; parallel build can be restored after the
Packit Service 7f19f2
  update
Packit Service 7f19f2
Packit Service 7f19f2
* Mon Dec 19 2016 Thomas Woerner <twoerner@redhat.com> - 1.6.0-3
Packit Service 7f19f2
- Dropped bad provides for iptables in services sub package (RHBZ#1327786)
Packit Service 7f19f2
Packit Service 7f19f2
* Fri Jul 22 2016 Thomas Woerner <twoerner@redhat.com> - 1.6.0-2
Packit Service 7f19f2
- /etc/ethertypes has been moved into the setup package for F-25+.
Packit Service 7f19f2
  (RHBZ#1329256)
Packit Service 7f19f2
Packit Service 7f19f2
* Wed Apr 13 2016 Thomas Woerner <twoerner@redhat.com> - 1.6.0-1
Packit Service 7f19f2
- New upstream version 1.6.0 with nft-compat support and lots of fixes (RHBZ#1292990)
Packit Service 7f19f2
  Upstream changelog:
Packit Service 7f19f2
  http://netfilter.org/projects/iptables/files/changes-iptables-1.6.0.txt
Packit Service 7f19f2
- New libs sub package containing libxtables and unstable libip*tc libraries (RHBZ#1323161)
Packit Service 7f19f2
- Using scripts form RHEL-7 (RHBZ#1240366)
Packit Service 7f19f2
- New compat sub package for nftables compatibility
Packit Service 7f19f2
- Install iptables-apply (RHBZ#912047)
Packit Service 7f19f2
- Fixed module uninstall (RHBZ#1324101)
Packit Service 7f19f2
- Incorporated changes by Petr Pisar
Packit Service 7f19f2
- Enabled bpf compiler (RHBZ#1170227) Thanks to Yanko Kaneti for the patch
Packit Service 7f19f2
Packit Service 7f19f2
* Thu Feb 04 2016 Fedora Release Engineering <releng@fedoraproject.org> - 1.4.21-16
Packit Service 7f19f2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_24_Mass_Rebuild
Packit Service 7f19f2
Packit Service 7f19f2
* Wed Jun 17 2015 Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 1.4.21-15
Packit Service 7f19f2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_23_Mass_Rebuild
Packit Service 7f19f2
Packit Service 7f19f2
* Mon Dec 01 2014 Jiri Popelka <jpopelka@redhat.com> - 1.4.21-14
Packit Service 7f19f2
- add dhcpv6-client to /etc/sysconfig/ip6tables (RHBZ#1169036)
Packit Service 7f19f2
Packit Service 7f19f2
* Mon Nov 03 2014 Jiri Popelka <jpopelka@redhat.com> - 1.4.21-13
Packit Service 7f19f2
- iptables.init: use /run/lock/subsys/ instead of /var/lock/subsys/ (RHBZ#1159573)
Packit Service 7f19f2
Packit Service 7f19f2
* Mon Sep 29 2014 Jiri Popelka <jpopelka@redhat.com> - 1.4.21-12
Packit Service 7f19f2
- ip[6]tables.init: change shebang from /bin/sh to /bin/bash (RHBZ#1147272)
Packit Service 7f19f2
Packit Service 7f19f2
* Sat Aug 16 2014 Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 1.4.21-11
Packit Service 7f19f2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild
Packit Service 7f19f2
Packit Service 7f19f2
* Sat Jul 12 2014 Tom Callaway <spot@fedoraproject.org> - 1.4.21-10
Packit Service 7f19f2
- fix license handling
Packit Service 7f19f2
Packit Service 7f19f2
* Sat Jun 07 2014 Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 1.4.21-9
Packit Service 7f19f2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild
Packit Service 7f19f2
Packit Service 7f19f2
* Wed Mar 12 2014 Jiri Popelka <jpopelka@redhat.com> - 1.4.21-8
Packit Service 7f19f2
- add missing reload and panic actions
Packit Service 7f19f2
- BuildRequires: pkgconfig(x) instead of x-devel
Packit Service 7f19f2
- no need to specify file mode bits twice (in %%install and %%files)
Packit Service 7f19f2
Packit Service 7f19f2
* Sun Jan 19 2014 Ville Skyttä <ville.skytta@iki.fi> - 1.4.21-7
Packit Service 7f19f2
- Don't order services after syslog.target.
Packit Service 7f19f2
Packit Service 7f19f2
* Wed Jan 15 2014 Thomas Woerner <twoerner@redhat.com> 1.4.21-6
Packit Service 7f19f2
- Enable connlabel support again, needs libnetfilter_conntrack
Packit Service 7f19f2
Packit Service 7f19f2
* Wed Jan 15 2014 Thomas Woerner <twoerner@redhat.com> 1.4.21-6
Packit Service 7f19f2
- fixed update from RHEL-6 to RHEL-7 (RHBZ#1043901)
Packit Service 7f19f2
Packit Service 7f19f2
* Tue Jan 14 2014 Jiri Popelka <jpopelka@redhat.com> - 1.4.21-5
Packit Service 7f19f2
- chmod /etc/sysconfig/ip[6]tables 755 -> 600
Packit Service 7f19f2
Packit Service 7f19f2
* Fri Jan 10 2014 Jiri Popelka <jpopelka@redhat.com> - 1.4.21-4
Packit Service 7f19f2
- drop virtual provide for xtables.so.9
Packit Service 7f19f2
- add default /etc/sysconfig/ip[6]tables (RHBZ#1034494)
Packit Service 7f19f2
Packit Service 7f19f2
* Thu Jan 09 2014 Jiri Popelka <jpopelka@redhat.com> - 1.4.21-3
Packit Service 7f19f2
- no need to support the pre-systemd things
Packit Service 7f19f2
- use systemd macros (#850166)
Packit Service 7f19f2
- remove scriptlets for migrating to a systemd unit from a SysV initscripts
Packit Service 7f19f2
- ./configure -> %%configure
Packit Service 7f19f2
- spec clean up
Packit Service 7f19f2
- fix self-obsoletion
Packit Service 7f19f2
Packit Service 7f19f2
* Thu Jan  9 2014 Thomas Woerner <twoerner@redhat.com> 1.4.21-2
Packit Service 7f19f2
- fixed system hang at shutdown if root device is network based (RHBZ#1007934)
Packit Service 7f19f2
  Thanks to Rodrigo A B Freire for the patch
Packit Service 7f19f2
Packit Service 7f19f2
* Thu Jan  9 2014 Thomas Woerner <twoerner@redhat.com> 1.4.21-1
Packit Service 7f19f2
- no connlabel.conf upstream anymore
Packit Service 7f19f2
- new version 1.4.21
Packit Service 7f19f2
  - doc: clarify DEBUG usage macro
Packit Service 7f19f2
  - iptables: use autoconf to process .in man pages
Packit Service 7f19f2
  - extensions: libipt_ULOG: man page should mention NFLOG as replacement
Packit Service 7f19f2
  - extensions: libxt_connlabel: use libnetfilter_conntrack
Packit Service 7f19f2
  - Introduce a new revision for the set match with the counters support
Packit Service 7f19f2
  - libxt_CT: Add the "NOTRACK" alias
Packit Service 7f19f2
  - libip6t_mh: Correct command to list named mh types in manpage
Packit Service 7f19f2
  - extensions: libxt_DNAT, libxt_REDIRECT, libxt_NETMAP, libxt_SNAT, libxt_MASQUERADE, libxt_LOG: rename IPv4 manpage and tell about IPv6 support
Packit Service 7f19f2
  - extensions: libxt_LED: fix parsing of delay
Packit Service 7f19f2
  - ip{6}tables-restore: fix breakage due to new locking approach
Packit Service 7f19f2
  - libxt_recent: restore minimum value for --seconds
Packit Service 7f19f2
  - iptables-xml: fix parameter parsing (similar to 2165f38)
Packit Service 7f19f2
  - extensions: add copyright statements
Packit Service 7f19f2
  - xtables: improve get_modprobe handling
Packit Service 7f19f2
  - ip[6]tables: Add locking to prevent concurrent instances
Packit Service 7f19f2
  - iptables: Fix connlabel.conf install location
Packit Service 7f19f2
  - ip6tables: don't print out /128
Packit Service 7f19f2
  - libip6t_LOG: target output is different to libipt_LOG
Packit Service 7f19f2
  - build: additional include path required after UAPI changes
Packit Service 7f19f2
  - iptables: iptables-xml: Fix various parsing bugs
Packit Service 7f19f2
  - libxt_recent: restore reap functionality to recent module
Packit Service 7f19f2
  - build: fail in configure on missing dependency with --enable-bpf-compiler
Packit Service 7f19f2
  - extensions: libxt_NFQUEUE: add --queue-cpu-fanout parameter
Packit Service 7f19f2
  - extensions: libxt_set, libxt_SET: check the set family too
Packit Service 7f19f2
  - ip6tables: Use consistent exit code for EAGAIN
Packit Service 7f19f2
  - iptables: libxt_hashlimit.man: correct address
Packit Service 7f19f2
  - iptables: libxt_conntrack.man extraneous commas
Packit Service 7f19f2
  - iptables: libip(6)t_REJECT.man default icmp types
Packit Service 7f19f2
  - iptables: iptables-xm1.1 correct man section
Packit Service 7f19f2
  - iptables: libxt_recent.{c,man} dead URL
Packit Service 7f19f2
  - iptables: libxt_string.man add examples
Packit Service 7f19f2
  - extensions: libxt_LOG: use generic syslog reference in manpage
Packit Service 7f19f2
  - iptables: extensions/GNUMakefile.in use CPPFLAGS
Packit Service 7f19f2
  - iptables: correctly reference generated file
Packit Service 7f19f2
  - ip[6]tables: fix incorrect alignment in commands_v_options
Packit Service 7f19f2
  - build: add software version to manpage first line at configure stage
Packit Service 7f19f2
  - extensions: libxt_cluster: add note on arptables-jf
Packit Service 7f19f2
  - utils: nfsynproxy: fix error while compiling the BPF filter
Packit Service 7f19f2
  - extensions: add SYNPROXY extension
Packit Service 7f19f2
  - utils: add nfsynproxy tool
Packit Service 7f19f2
  - iptables: state match incompatibilty across versions
Packit Service 7f19f2
  - libxtables: xtables_ipmask_to_numeric incorrect with non-CIDR masks
Packit Service 7f19f2
  - iptables: improve chain name validation
Packit Service 7f19f2
  - iptables: spurious error in load_extension
Packit Service 7f19f2
  - xtables: trivial spelling fix
Packit Service 7f19f2
Packit Service 7f19f2
* Sun Dec 22 2013 Ville Skyttä <ville.skytta@iki.fi> - 1.4.19.1-2
Packit Service 7f19f2
- Drop INSTALL from docs, escape macros in %%changelog.
Packit Service 7f19f2
Packit Service 7f19f2
* Wed Jul 31 2013 Thomas Woerner <twoerner@redhat.com> 1.4.19.1-1
Packit Service 7f19f2
- new version 1.4.19.1
Packit Service 7f19f2
  - libxt_NFQUEUE: fix bypass option documentation
Packit Service 7f19f2
  - extensions: add connlabel match
Packit Service 7f19f2
  - extensions: add connlabel match
Packit Service 7f19f2
  - ip[6]tables: show --protocol instead of --proto in usage
Packit Service 7f19f2
  - libxt_recent: Fix missing space in manpage for --mask option
Packit Service 7f19f2
  - extensions: libxt_multiport: Update manpage to list valid protocols
Packit Service 7f19f2
  - utils: nfnl_osf: use the right nfnetlink lib
Packit Service 7f19f2
  - libip6t_NETMAP: Use xtables_ip6mask_to_cidr and get rid of libip6tc dependency
Packit Service 7f19f2
  - Revert "build: resolve link failure for ip6t_NETMAP"
Packit Service 7f19f2
  - libxt_osf: fix missing --ttl and --log in save output
Packit Service 7f19f2
  - libxt_osf: fix bad location for location in --genre
Packit Service 7f19f2
  - libip6t_SNPT: add manpage
Packit Service 7f19f2
  - libip6t_DNPT: add manpage
Packit Service 7f19f2
  - utils: updates .gitignore to include nfbpf_compile
Packit Service 7f19f2
  - extensions: libxt_bpf: clarify --bytecode argument
Packit Service 7f19f2
  - libxtables: fix parsing of dotted network mask format
Packit Service 7f19f2
  - build: bump version to 1.4.19
Packit Service 7f19f2
  - libxt_conntrack: fix state match alias state parsing
Packit Service 7f19f2
  - extensions: add libxt_bpf extension
Packit Service 7f19f2
  - utils: nfbpf_compile
Packit Service 7f19f2
  - doc: mention SNAT in INPUT chain since kernel 2.6.36
Packit Service 7f19f2
- fixed changelog date weekdays where needed
Packit Service 7f19f2
Packit Service 7f19f2
* Mon Mar  4 2013 Thomas Woerner <twoerner@redhat.com> 1.4.18-1
Packit Service 7f19f2
- new version 1.4.18 
Packit Service 7f19f2
  - lots of documentation changes
Packit Service 7f19f2
  - Introduce match/target aliases
Packit Service 7f19f2
  - Add the "state" alias to the "conntrack" match
Packit Service 7f19f2
  - iptables: remove unused leftover definitions
Packit Service 7f19f2
  - libxtables: add xtables_rule_matches_free
Packit Service 7f19f2
  - libxtables: add xtables_print_num
Packit Service 7f19f2
  - extensions: libip6t_DNPT: fix wording in DNPT target
Packit Service 7f19f2
  - extension: libip6t_DNAT: allow port DNAT without address
Packit Service 7f19f2
  - extensions: libip6t_DNAT: set IPv6 DNAT --to-destination
Packit Service 7f19f2
  - extensions: S/DNPT: add missing save function
Packit Service 7f19f2
- changes of 1.4.17:
Packit Service 7f19f2
  - libxt_time: add support to ignore day transition
Packit Service 7f19f2
  - Convert the NAT targets to use the kernel supplied nf_nat.h header
Packit Service 7f19f2
  - extensions: add IPv6 MASQUERADE extension
Packit Service 7f19f2
  - extensions: add IPv6 SNAT extension
Packit Service 7f19f2
  - extensions: add IPv6 DNAT target
Packit Service 7f19f2
  - extensions: add IPv6 REDIRECT extension
Packit Service 7f19f2
  - extensions: add IPv6 NETMAP extension
Packit Service 7f19f2
  - extensions: add NPT extension
Packit Service 7f19f2
  - extensions: libxt_statistic: Fix save output
Packit Service 7f19f2
Packit Service 7f19f2
* Thu Feb 14 2013 Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 1.4.16.2-7
Packit Service 7f19f2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_19_Mass_Rebuild
Packit Service 7f19f2
Packit Service 7f19f2
* Wed Jan 16 2013 Ville Skyttä <ville.skytta@iki.fi> - 1.4.16.2-6
Packit Service 7f19f2
- Own unowned -services libexec dirs (#894464, Michael Scherer).
Packit Service 7f19f2
- Fix -services unit file permissions (#732936, Michal Schmidt).
Packit Service 7f19f2
Packit Service 7f19f2
* Thu Nov  8 2012 Thomas Woerner <twoerner@redhat.com> 1.4.16.2-5
Packit Service 7f19f2
- fixed path of ip6tables.init in ip6tables.service
Packit Service 7f19f2
Packit Service 7f19f2
* Fri Nov  2 2012 Thomas Woerner <twoerner@redhat.com> 1.4.16.2-4
Packit Service 7f19f2
- fixed missing services for update of pre F-18 installations (rhbz#867960)
Packit Service 7f19f2
  - provide and obsolete old main package in services sub package
Packit Service 7f19f2
  - provide and obsolete old ipv6 sub package (pre F-17) in services sub package
Packit Service 7f19f2
Packit Service 7f19f2
* Sun Oct 14 2012 Dan Horák <dan[at]dany.cz> 1.4.16.2-3
Packit Service 7f19f2
- fix the compat provides for all 64-bit arches
Packit Service 7f19f2
Packit Service 7f19f2
* Fri Oct 12 2012 Thomas Woerner <twoerner@redhat.com> 1.4.16.2-2
Packit Service 7f19f2
- new sub package services providing the systemd services (RHBZ#862922)
Packit Service 7f19f2
- new sub package utils: provides nfnl_osf and the pf.os database
Packit Service 7f19f2
- using %%{_libexecdir}/iptables as script path for the original init scripts
Packit Service 7f19f2
- added service iptables save funcitonality using the new way provided by 
Packit Service 7f19f2
  initscripts 9.37.1 (RHBZ#748134)
Packit Service 7f19f2
- added virtual provide for libxtables.so.7
Packit Service 7f19f2
Packit Service 7f19f2
* Mon Oct  8 2012 Thomas Woerner <twoerner@redhat.com> 1.4.16.2-1
Packit Service 7f19f2
- new version 1.4.16.2
Packit Service 7f19f2
  - build: support for automake-1.12
Packit Service 7f19f2
  - build: separate AC variable replacements from xtables.h
Packit Service 7f19f2
  - build: have `make clean` remove dep files too
Packit Service 7f19f2
  - doc: grammatical updates to libxt_SET
Packit Service 7f19f2
  - doc: clean up interpunction in state list for xt_conntrack
Packit Service 7f19f2
  - doc: deduplicate extension descriptions into a new manpage
Packit Service 7f19f2
  - doc: trim "state" manpage and reference conntrack instead
Packit Service 7f19f2
  - doc: have NOTRACK manpage point to CT instead
Packit Service 7f19f2
  - doc: mention iptables-apply in the SEE ALSO sections
Packit Service 7f19f2
  - extensions: libxt_addrtype: fix type in help message
Packit Service 7f19f2
  - include: add missing linux/netfilter_ipv4/ip_queue.h
Packit Service 7f19f2
  - iptables: fix wrong error messages
Packit Service 7f19f2
  - iptables: support for match aliases
Packit Service 7f19f2
  - iptables: support for target aliases
Packit Service 7f19f2
  - iptables-restore: warn about -t in rule lines
Packit Service 7f19f2
  - ip[6]tables-restore: cleanup to reduce one level of indentation
Packit Service 7f19f2
  - libip6t_frag: match any frag id by default
Packit Service 7f19f2
  - libxtables: consolidate preference logic
Packit Service 7f19f2
  - libxt_devgroup: consolidate devgroup specification parsing
Packit Service 7f19f2
  - libxt_devgroup: guard against negative numbers
Packit Service 7f19f2
  - libxt_LED: guard against negative numbers
Packit Service 7f19f2
  - libxt_NOTRACK: replace as an alias to CT --notrack
Packit Service 7f19f2
  - libxt_state: replace as an alias to xt_conntrack
Packit Service 7f19f2
  - libxt_tcp: print space before, not after "flags:"
Packit Service 7f19f2
  - libxt_u32: do bounds checking for @'s operands
Packit Service 7f19f2
  - libxt_*limit: avoid division by zero
Packit Service 7f19f2
  - Merge branch 'master' of git://git.inai.de/iptables
Packit Service 7f19f2
  - Merge remote-tracking branch 'nf/stable'
Packit Service 7f19f2
  - New set match revision with --return-nomatch flag support
Packit Service 7f19f2
- dropped fixrestore patch, upstream
Packit Service 7f19f2
Packit Service 7f19f2
* Wed Aug  1 2012 Thomas Woerner <twoerner@redhat.com> 1.4.15-1
Packit Service 7f19f2
- new version 1.4.15
Packit Service 7f19f2
  - extensions: add HMARK target
Packit Service 7f19f2
  - iptables-restore: fix parameter parsing (shows up with gcc-4.7)
Packit Service 7f19f2
  - iptables-restore: move code to add_param_to_argv, cleanup (fix gcc-4.7)
Packit Service 7f19f2
  - libxtables: add xtables_ip[6]mask_to_cidr
Packit Service 7f19f2
  - libxt_devgroup: add man page snippet
Packit Service 7f19f2
  - libxt_hashlimit: add support for byte-based operation
Packit Service 7f19f2
  - libxt_recent: add --mask netmask
Packit Service 7f19f2
  - libxt_recent: remove unused variable
Packit Service 7f19f2
  - libxt_HMARK: correct a number of errors introduced by Pablo's rework
Packit Service 7f19f2
  - libxt_HMARK: fix ct case example
Packit Service 7f19f2
  - libxt_HMARK: fix output of iptables -L
Packit Service 7f19f2
  - Revert "iptables-restore: move code to add_param_to_argv, cleanup (fix gcc-4.7)"
Packit Service 7f19f2
Packit Service 7f19f2
* Wed Jul 18 2012 Thomas Woerner <twoerner@redhat.com> 1.4.14-3
Packit Service 7f19f2
- added fixrestore patch submitted to upstream by fryasu (nfbz#774) 
Packit Service 7f19f2
  (RHBZ#825796)
Packit Service 7f19f2
Packit Service 7f19f2
* Wed Jul 18 2012 Thomas Woerner <twoerner@redhat.com> 1.4.14-2
Packit Service 7f19f2
- disabled libipq, removed upstream, not provided by kernel anymore
Packit Service 7f19f2
Packit Service 7f19f2
* Wed Jul 18 2012 Thomas Woerner <twoerner@redhat.com> 1.4.14-1
Packit Service 7f19f2
- new version 1.4.14
Packit Service 7f19f2
  - extensions: add IPv6 capable ECN match extension
Packit Service 7f19f2
  - extensions: add nfacct match
Packit Service 7f19f2
  - extensions: add rpfilter module
Packit Service 7f19f2
  - extensions: libxt_rateest: output all options in save hook
Packit Service 7f19f2
  - iptables: missing free() in function cache_add_entry()
Packit Service 7f19f2
  - iptables: missing free() in function delete_entry()
Packit Service 7f19f2
  - libiptc: fix retry path in TC_INIT
Packit Service 7f19f2
  - libiptc: Returns the position the entry was inserted
Packit Service 7f19f2
  - libipt_ULOG: fix --ulog-cprange
Packit Service 7f19f2
  - libxt_CT: add --timeout option
Packit Service 7f19f2
  - ip(6)tables-restore: make sure argv is NULL terminated
Packit Service 7f19f2
  - Revert "libiptc: Returns the position the entry was inserted"
Packit Service 7f19f2
  - src: mark newly opened fds as FD_CLOEXEC (close on exec)
Packit Service 7f19f2
  - tests: add rateest match rules
Packit Service 7f19f2
- dropped patch5 (cloexec), merged upstream
Packit Service 7f19f2
Packit Service 7f19f2
* Mon Apr 23 2012 Thomas Woerner <twoerner@redhat.com> 1.4.12.2-5
Packit Service 7f19f2
- reenable iptables default services
Packit Service 7f19f2
Packit Service 7f19f2
* Wed Feb 29 2012 Harald Hoyer <harald@redhat.com> 1.4.12.2-4
Packit Service 7f19f2
- install everything in /usr
Packit Service 7f19f2
  https://fedoraproject.org/wiki/Features/UsrMove
Packit Service 7f19f2
Packit Service 7f19f2
* Thu Feb 16 2012 Thomas Woerner <twoerner@redhat.com> 1.4.12.2-3
Packit Service 7f19f2
- fixed auto enable check for Fedora > 16 and added rhel > 6 check
Packit Service 7f19f2
Packit Service 7f19f2
* Wed Feb 15 2012 Thomas Woerner <twoerner@redhat.com> 1.4.12.2-2
Packit Service 7f19f2
- disabled autostart and auto enable for iptables.service and ip6tables.service
Packit Service 7f19f2
  for Fedora > 16
Packit Service 7f19f2
Packit Service 7f19f2
* Mon Jan 16 2012 Thomas Woerner <twoerner@redhat.com> 1.4.12.2-1
Packit Service 7f19f2
- new version 1.4.12.2 with new pkgconfig/libip4tc.pc and pkgconfig/libip6tc.pc
Packit Service 7f19f2
  - build: make check stage not fail when building statically
Packit Service 7f19f2
  - build: restore build order of modules
Packit Service 7f19f2
  - build: scan for unreferenced symbols
Packit Service 7f19f2
  - build: sort file list before build
Packit Service 7f19f2
  - doc: clarification on the meaning of -p 0
Packit Service 7f19f2
  - doc: document iptables-restore's -T option
Packit Service 7f19f2
  - doc: fix undesired newline in ip6tables-restore(8)
Packit Service 7f19f2
  - ip6tables-restore: implement missing -T option
Packit Service 7f19f2
  - iptables: move kernel version find routing into libxtables
Packit Service 7f19f2
  - libiptc: provide separate pkgconfig files
Packit Service 7f19f2
  - libipt_SAME: set PROTO_RANDOM on all ranges
Packit Service 7f19f2
  - libxtables: Fix file descriptor leak in xtables_lmap_init on error
Packit Service 7f19f2
  - libxt_connbytes: fix handling of --connbytes FROM
Packit Service 7f19f2
  - libxt_CONNSECMARK: fix spacing in output
Packit Service 7f19f2
  - libxt_conntrack: improve error message on parsing violation
Packit Service 7f19f2
  - libxt_NFQUEUE: fix --queue-bypass ipt-save output
Packit Service 7f19f2
  - libxt_RATEEST: link with -lm
Packit Service 7f19f2
  - libxt_statistic: link with -lm
Packit Service 7f19f2
  - Merge branch 'stable'
Packit Service 7f19f2
  - Merge branch 'stable' of git://dev.medozas.de/iptables
Packit Service 7f19f2
  - nfnl_osf: add missing libnfnetlink_CFLAGS to compile process
Packit Service 7f19f2
  - xtoptions: fill in fallback value for nvals
Packit Service 7f19f2
  - xtoptions: simplify xtables_parse_interface
Packit Service 7f19f2
Packit Service 7f19f2
* Fri Jan 13 2012 Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 1.4.12.1-2
Packit Service 7f19f2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild
Packit Service 7f19f2
Packit Service 7f19f2
* Mon Dec 12 2011 Thomas Woerner <twoerner@redhat.com> 1.4.12.1-1
Packit Service 7f19f2
- new version 1.4.12.1 with new pkgconfig/libipq.pc
Packit Service 7f19f2
  - build: abort autogen on subcommand failure
Packit Service 7f19f2
  - build: strengthen check for overlong lladdr components
Packit Service 7f19f2
  - build: workaround broken linux-headers on RHEL-5
Packit Service 7f19f2
  - doc: clarify libxt_connlimit defaults
Packit Service 7f19f2
  - doc: fix typo in libxt_TRACE
Packit Service 7f19f2
  - extensions: use multi-target registration
Packit Service 7f19f2
  - libip6t_dst: restore setting IP6T_OPTS_LEN flag
Packit Service 7f19f2
  - libip6t_frag: restore inversion support
Packit Service 7f19f2
  - libip6t_hbh: restore setting IP6T_OPTS_LEN flag
Packit Service 7f19f2
  - libipq: add pkgconfig file
Packit Service 7f19f2
  - libipt_ttl: document that negation is available
Packit Service 7f19f2
  - libxt_conntrack: fix --ctproto 0 output
Packit Service 7f19f2
  - libxt_conntrack: remove one misleading comment
Packit Service 7f19f2
  - libxt_dccp: fix deprecated intrapositional ordering of !
Packit Service 7f19f2
  - libxt_dccp: fix random output of ! on --dccp-option
Packit Service 7f19f2
  - libxt_dccp: provide man pages options in short help too
Packit Service 7f19f2
  - libxt_dccp: restore missing XTOPT_INVERT tags for options
Packit Service 7f19f2
  - libxt_dccp: spell out option name on save
Packit Service 7f19f2
  - libxt_dscp: restore inversion support
Packit Service 7f19f2
  - libxt_hashlimit: default htable-expire must be in milliseconds
Packit Service 7f19f2
  - libxt_hashlimit: observe new default gc-expire time when saving
Packit Service 7f19f2
  - libxt_hashlimit: remove inversion from hashlimit rev 0
Packit Service 7f19f2
  - libxt_owner: restore inversion support
Packit Service 7f19f2
  - libxt_physdev: restore inversion support
Packit Service 7f19f2
  - libxt_policy: remove superfluous inversion
Packit Service 7f19f2
  - libxt_set: put differing variable names in directly
Packit Service 7f19f2
  - libxt_set: update man page about kernel support on the feature
Packit Service 7f19f2
  - libxt_string: define _GNU_SOURCE for strnlen
Packit Service 7f19f2
  - libxt_string: escape the escaping char too
Packit Service 7f19f2
  - libxt_string: fix space around arguments
Packit Service 7f19f2
  - libxt_string: replace hex codes by char equivalents
Packit Service 7f19f2
  - libxt_string: simplify hex output routine
Packit Service 7f19f2
  - libxt_tcp: always print the mask parts
Packit Service 7f19f2
  - libxt_TCPMSS: restore build with IPv6-less libcs
Packit Service 7f19f2
  - libxt_TOS: update linux kernel version list for backported fix
Packit Service 7f19f2
  - libxt_u32: fix missing allowance for inversion
Packit Service 7f19f2
  - src: remove unused IPTABLES_MULTI define
Packit Service 7f19f2
  - tests: add negation tests for libxt_statistic
Packit Service 7f19f2
  - xtoptions: flag use of XTOPT_POINTER without XTOPT_PUT
Packit Service 7f19f2
- removed include/linux/types.h before build to be able to compile
Packit Service 7f19f2
Packit Service 7f19f2
* Tue Jul 26 2011 Thomas Woerner <twoerner@redhat.com> 1.4.12-2
Packit Service 7f19f2
- dropped temporary provide again
Packit Service 7f19f2
Packit Service 7f19f2
* Tue Jul 26 2011 Thomas Woerner <twoerner@redhat.com> 1.4.12-1.1
Packit Service 7f19f2
- added temporary provides for libxtables.so.6 to be able to rebuild iproute,
Packit Service 7f19f2
  which is part of the standard build environment
Packit Service 7f19f2
Packit Service 7f19f2
* Mon Jul 25 2011 Thomas Woerner <twoerner@redhat.com> 1.4.12-1
Packit Service 7f19f2
- new version 1.4.12 with support of all new features of kernel 3.0
Packit Service 7f19f2
  - build: attempt to fix building under Linux 2.4
Packit Service 7f19f2
  - build: bump soversion for recent data structure change
Packit Service 7f19f2
  - build: install modules in arch-dependent location
Packit Service 7f19f2
  - doc: fix group range in libxt_NFLOG's man
Packit Service 7f19f2
  - doc: fix version string in ip6tables.8
Packit Service 7f19f2
  - doc: include matches/targets in manpage again
Packit Service 7f19f2
  - doc: mention multiple verbosity flags
Packit Service 7f19f2
  - doc: the -m option cannot be inverted
Packit Service 7f19f2
  - extensions: support for per-extension instance global variable space
Packit Service 7f19f2
  - iptables-apply: select default rule file depending on call name
Packit Service 7f19f2
  - iptables: consolidate target/match init call
Packit Service 7f19f2
  - iptables: Coverity: DEADCODE
Packit Service 7f19f2
  - iptables: Coverity: NEGATIVE_RETURNS
Packit Service 7f19f2
  - iptables: Coverity: RESOURCE_LEAK
Packit Service 7f19f2
  - iptables: Coverity: REVERSE_INULL
Packit Service 7f19f2
  - iptables: Coverity: VARARGS
Packit Service 7f19f2
  - iptables: restore negation for -f
Packit Service 7f19f2
  - libip6t_HL: fix option names from ttl -> hl
Packit Service 7f19f2
  - libipt_LOG: fix ignoring all but last flags
Packit Service 7f19f2
  - libxtables: ignore whitespace in the multiaddress argument parser
Packit Service 7f19f2
  - libxtables: properly reject empty hostnames
Packit Service 7f19f2
  - libxtables: set clone's initial data to NULL
Packit Service 7f19f2
  - libxt_conntrack: move more data into the xt_option_entry
Packit Service 7f19f2
  - libxt_conntrack: restore network-byte order for v1,v2
Packit Service 7f19f2
  - libxt_hashlimit: use a more obvious expiry value by default
Packit Service 7f19f2
  - libxt_rateest: abolish global variables
Packit Service 7f19f2
  - libxt_RATEEST: abolish global variables
Packit Service 7f19f2
  - libxt_RATEEST: fix userspacesize field
Packit Service 7f19f2
  - libxt_RATEEST: use guided option parser
Packit Service 7f19f2
  - libxt_state: fix regression about inversion of main option
Packit Service 7f19f2
  - option: remove last traces of intrapositional negation
Packit Service 7f19f2
- complete changelog:
Packit Service 7f19f2
  http://www.netfilter.org/projects/iptables/files/changes-iptables-1.4.12.txt
Packit Service 7f19f2
Packit Service 7f19f2
* Thu Jul 21 2011 Thomas Woerner <twoerner@redhat.com> 1.4.11.1-4
Packit Service 7f19f2
- merged ipv6 sub package into main package
Packit Service 7f19f2
- renamed init scripts to /usr/libexec/ip*tables.init
Packit Service 7f19f2
Packit Service 7f19f2
* Fri Jul 15 2011 Thomas Woerner <twoerner@redhat.com> 1.4.11.1-3
Packit Service 7f19f2
- added support for native systemd file (rhbz#694738)
Packit Service 7f19f2
  - new iptables.service file
Packit Service 7f19f2
  - additional requires
Packit Service 7f19f2
  - moved sysv init scripts to /usr/libexec
Packit Service 7f19f2
  - added new post, preun and postun scripts and triggers
Packit Service 7f19f2
Packit Service 7f19f2
* Tue Jul 12 2011 Thomas Woerner <twoerner@redhat.com> 1.4.11.1-2
Packit Service 7f19f2
- dropped temporary provide again
Packit Service 7f19f2
- enabled smp build
Packit Service 7f19f2
Packit Service 7f19f2
* Tue Jul 12 2011 Thomas Woerner <twoerner@redhat.com> 1.4.11.1-1.1
Packit Service 7f19f2
-  added temporary provides for libxtables.so.5 to be able to rebuild iproute,
Packit Service 7f19f2
   which is part of the standard build environment
Packit Service 7f19f2
Packit Service 7f19f2
* Mon Jul 11 2011 Thomas Woerner <twoerner@redhat.com> 1.4.11.1-1
Packit Service 7f19f2
- new version 1.4.11.1, bug and doc fix release for 1.4.11
Packit Service 7f19f2
Packit Service 7f19f2
* Tue Jun  7 2011 Thomas Woerner <twoerner@redhat.com> 1.4.11-1
Packit Service 7f19f2
- new version 1.4.11 with all new features of 2.6.37-39 (not usable)
Packit Service 7f19f2
  - lots of changes and bugfixes for base and extensions
Packit Service 7f19f2
  - complete changelog:
Packit Service 7f19f2
    http://www.netfilter.org/projects/iptables/files/changes-iptables-1.4.11.txt
Packit Service 7f19f2
Packit Service 7f19f2
* Wed Feb 09 2011 Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 1.4.10-2
Packit Service 7f19f2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild
Packit Service 7f19f2
Packit Service 7f19f2
* Mon Jan 10 2011 Thomas Woerner <twoerner@redhat.com> 1.4.10-1
Packit Service 7f19f2
- new version 1.4.10 with all new features of 2.6.36
Packit Service 7f19f2
  - all: consistent syntax use in struct option
Packit Service 7f19f2
  - build: fix static linking
Packit Service 7f19f2
  - doc: let man(1) autoalign the text in xt_cpu
Packit Service 7f19f2
  - doc: remove extra empty line from xt_cpu
Packit Service 7f19f2
  - doc: minimal spelling updates to xt_cpu
Packit Service 7f19f2
  - doc: consistent use of markup
Packit Service 7f19f2
  - extensions: libxt_quota: don't ignore the quota value on deletion
Packit Service 7f19f2
  - extensions: REDIRECT: add random help
Packit Service 7f19f2
  - extensions: add xt_cpu match
Packit Service 7f19f2
  - extensions: add idletimer xt target extension
Packit Service 7f19f2
  - extensions: libxt_IDLETIMER: use xtables_param_act when checking options
Packit Service 7f19f2
  - extensions: libxt_CHECKSUM extension
Packit Service 7f19f2
  - extensions: libipt_LOG/libip6t_LOG: support macdecode option
Packit Service 7f19f2
  - extensions: fix compilation of the new CHECKSUM target
Packit Service 7f19f2
  - extensions: libxt_ipvs: user-space lib for netfilter matcher xt_ipvs
Packit Service 7f19f2
  - iptables-xml: resolve compiler warnings
Packit Service 7f19f2
  - iptables: limit chain name length to be consistent with targets
Packit Service 7f19f2
  - libiptc: add Libs.private to pkgconfig files
Packit Service 7f19f2
  - libiptc: build with -Wl,--no-as-needed
Packit Service 7f19f2
  - xtables: remove unnecessary cast
Packit Service 7f19f2
- dropped xt_CHECKSUM, added upstream
Packit Service 7f19f2
Packit Service 7f19f2
* Tue Oct 12 2010 Thomas Woerner <twoerner@redhat.com> 1.4.9-2
Packit Service 7f19f2
- added xt_CHECKSUM patch from Michael S. Tsirkin (rhbz#612587)
Packit Service 7f19f2
Packit Service 7f19f2
* Wed Aug  4 2010 Thomas Woerner <twoerner@redhat.com> 1.4.9-1
Packit Service 7f19f2
- new version 1.4.9 with all new features of 2.6.35
Packit Service 7f19f2
  - doc: xt_hashlimit: fix a typo
Packit Service 7f19f2
  - doc: xt_LED: nroff formatting requirements
Packit Service 7f19f2
  - doc: xt_string: correct copy-and-pasting in manpage
Packit Service 7f19f2
  - extensions: add the LED target
Packit Service 7f19f2
  - extensions: libxt_quota.c: Support option negation
Packit Service 7f19f2
  - extensions: libxt_rateest: fix bps options for iptables-save
Packit Service 7f19f2
  - extensions: libxt_rateest: fix typo in the man page
Packit Service 7f19f2
  - extensions: REDIRECT: add random help
Packit Service 7f19f2
  - includes: sync header files from Linux 2.6.35-rc1
Packit Service 7f19f2
  - libxt_conntrack: do print netmask
Packit Service 7f19f2
  - libxt_hashlimit: always print burst value
Packit Service 7f19f2
  - libxt_set: new revision added
Packit Service 7f19f2
  - utils: add missing include flags to Makefile
Packit Service 7f19f2
  - xtables: another try at chain name length checking
Packit Service 7f19f2
  - xtables: remove xtables_set_revision function
Packit Service 7f19f2
  - xt_quota: also document negation
Packit Service 7f19f2
  - xt_sctp: Trace DATA chunk that supports SACK-IMMEDIATELY extension
Packit Service 7f19f2
  - xt_sctp: support FORWARD_TSN chunk type
Packit Service 7f19f2
Packit Service 7f19f2
* Fri Jul  2 2010 Thomas Woerner <twoerner@redhat.com> 1.4.8-1
Packit Service 7f19f2
- new version 1.4.8 all new features of 2.6.34 (rhbz#)
Packit Service 7f19f2
  - extensions: REDIRECT: fix --to-ports parser
Packit Service 7f19f2
  - iptables: add noreturn attribute to exit_tryhelp()
Packit Service 7f19f2
  - extensions: MASQUERADE: fix --to-ports parser
Packit Service 7f19f2
  - libxt_comment: avoid use of IPv4-specific examples
Packit Service 7f19f2
  - libxt_CT: add a manpage
Packit Service 7f19f2
  - iptables: correctly check for too-long chain/target/match names
Packit Service 7f19f2
  - doc: libxt_MARK: no longer restricted to mangle table
Packit Service 7f19f2
  - doc: remove claim that TCPMSS is limited to mangle
Packit Service 7f19f2
  - libxt_recent: add a missing space in output
Packit Service 7f19f2
  - doc: add manpage for libxt_osf
Packit Service 7f19f2
  - libxt_osf: import nfnl_osf program
Packit Service 7f19f2
  - extensions: add support for xt_TEE
Packit Service 7f19f2
  - CT: fix --ctevents parsing
Packit Service 7f19f2
  - extensions: add CT extension
Packit Service 7f19f2
  - libxt_CT: print conntrack zone in ->print/->save
Packit Service 7f19f2
  - xtables: fix compilation when debugging is enabled
Packit Service 7f19f2
  - libxt_conntrack: document --ctstate UNTRACKED
Packit Service 7f19f2
  - iprange: fix xt_iprange v0 parsing
Packit Service 7f19f2
Packit Service 7f19f2
* Wed Mar 24 2010 Thomas Woerner <twoerner@redhat.com> 1.4.7-2
Packit Service 7f19f2
- added default values for IPTABLES_STATUS_VERBOSE and
Packit Service 7f19f2
  IPTABLES_STATUS_LINENUMBERS in init script
Packit Service 7f19f2
- added missing lsb keywords Required-Start and Required-Stop to init script
Packit Service 7f19f2
Packit Service 7f19f2
* Fri Mar  5 2010 Thomas Woerner <twoerner@redhat.com> 1.4.7-1
Packit Service 7f19f2
- new version 1.4.7 with support for all new features of 2.6.33 (rhbz#570767)
Packit Service 7f19f2
  - libip4tc: Add static qualifier to dump_entry()
Packit Service 7f19f2
  - libipq: build as shared library
Packit Service 7f19f2
  - recent: reorder cases in code (cosmetic cleanup)
Packit Service 7f19f2
  - several man page and documentation fixes
Packit Service 7f19f2
  - policy: fix error message showing wrong option
Packit Service 7f19f2
  - includes: header updates
Packit Service 7f19f2
  - Lift restrictions on interface names
Packit Service 7f19f2
- fixed license and moved iptables-xml into base package according to review
Packit Service 7f19f2
Packit Service 7f19f2
* Wed Jan 27 2010 Thomas Woerner <twoerner@redhat.com> 1.4.6-2
Packit Service 7f19f2
- moved libip*tc and libxtables libs to /lib[64], added symlinks for .so libs
Packit Service 7f19f2
  to /usr/lib[64] for compatibility (rhbz#558796)
Packit Service 7f19f2
Packit Service 7f19f2
* Wed Jan 13 2010 Thomas Woerner <twoerner@redhat.com> 1.4.6-1
Packit Service 7f19f2
- new version 1.4.6 with support for all new features of 2.6.32
Packit Service 7f19f2
  - several man page fixes
Packit Service 7f19f2
  - Support for nommu arches
Packit Service 7f19f2
  - realm: remove static initializations
Packit Service 7f19f2
  - libiptc: remove unused functions
Packit Service 7f19f2
  - libiptc: avoid strict-aliasing warnings
Packit Service 7f19f2
  - iprange: do accept non-ranges for xt_iprange v1
Packit Service 7f19f2
  - iprange: warn on reverse range
Packit Service 7f19f2
  - iprange: roll address parsing into a loop
Packit Service 7f19f2
  - iprange: do accept non-ranges for xt_iprange v1 (log)
Packit Service 7f19f2
  - iprange: warn on reverse range (log)
Packit Service 7f19f2
  - libiptc: fix wrong maptype of base chain counters on restore
Packit Service 7f19f2
  - iptables: fix undersized deletion mask creation
Packit Service 7f19f2
  - style: reduce indent in xtables_check_inverse
Packit Service 7f19f2
  - libxtables: hand argv to xtables_check_inverse
Packit Service 7f19f2
  - iptables/extensions: make bundled options work again
Packit Service 7f19f2
  - CONNMARK: print mark rules with mask 0xffffffff as set instead of xset
Packit Service 7f19f2
  - iptables: take masks into consideration for replace command
Packit Service 7f19f2
  - doc: explain experienced --hitcount limit
Packit Service 7f19f2
  - doc: name resolution clarification
Packit Service 7f19f2
  - iptables: expose option to zero packet/byte counters for a specific rule
Packit Service 7f19f2
  - build: restore --disable-ipv6 functionality on system w/o v6 headers
Packit Service 7f19f2
  - MARK: print mark rules with mask 0xffffffff as --set-mark instead of --set-xmark
Packit Service 7f19f2
  - DNAT: fix incorrect check during parsing
Packit Service 7f19f2
  - extensions: add osf extension
Packit Service 7f19f2
  - conntrack: fix --expires parsing
Packit Service 7f19f2
Packit Service 7f19f2
* Thu Dec 17 2009 Thomas Woerner <twoerner@redhat.com> 1.4.5-2
Packit Service 7f19f2
- dropped nf_ext_init remains from cloexec patch
Packit Service 7f19f2
Packit Service 7f19f2
* Thu Sep 17 2009 Thomas Woerner <twoerner@redhat.com> 1.4.5-1
Packit Service 7f19f2
- new version 1.4.5 with support for all new features of 2.6.31
Packit Service 7f19f2
  - libxt_NFQUEUE: add new v1 version with queue-balance option
Packit Service 7f19f2
  - xt_conntrack: revision 2 for enlarged state_mask member
Packit Service 7f19f2
  - libxt_helper: fix invalid passed option to check_inverse
Packit Service 7f19f2
  - libiptc: split v4 and v6
Packit Service 7f19f2
  - extensions: collapse registration structures
Packit Service 7f19f2
  - iptables: allow for parse-less extensions
Packit Service 7f19f2
  - iptables: allow for help-less extensions
Packit Service 7f19f2
  - extensions: remove empty help and parse functions
Packit Service 7f19f2
  - xtables: add multi-registration functions
Packit Service 7f19f2
  - extensions: collapse data variables to use multi-reg calls
Packit Service 7f19f2
  - xtables: warn of missing version identifier in extensions
Packit Service 7f19f2
  - multi binary: allow subcommand via argv[1]
Packit Service 7f19f2
  - iptables: accept multiple IP address specifications for -s, -d
Packit Service 7f19f2
  - several build fixes
Packit Service 7f19f2
  - several man page fixes
Packit Service 7f19f2
- fixed two leaked file descriptors on sockets (rhbz#521397)
Packit Service 7f19f2
Packit Service 7f19f2
* Mon Aug 24 2009 Thomas Woerner <twoerner@redhat.com> 1.4.4-1
Packit Service 7f19f2
- new version 1.4.4 with support for all new features of 2.6.30
Packit Service 7f19f2
  - several man page fixes
Packit Service 7f19f2
  - iptables: replace open-coded sizeof by ARRAY_SIZE
Packit Service 7f19f2
  - libip6t_policy: remove redundant functions
Packit Service 7f19f2
  - policy: use direct xt_policy_info instead of ipt/ip6t
Packit Service 7f19f2
  - policy: merge ipv6 and ipv4 variant
Packit Service 7f19f2
  - extensions: add `cluster' match support
Packit Service 7f19f2
  - extensions: add const qualifiers in print/save functions
Packit Service 7f19f2
  - extensions: use NFPROTO_UNSPEC for .family field
Packit Service 7f19f2
  - extensions: remove redundant casts
Packit Service 7f19f2
  - iptables: close open file descriptors
Packit Service 7f19f2
  - fix segfault if incorrect protocol name is used
Packit Service 7f19f2
  - replace open-coded sizeof by ARRAY_SIZE
Packit Service 7f19f2
  - do not include v4-only modules in ip6tables manpage
Packit Service 7f19f2
  - use direct xt_policy_info instead of ipt/ip6t
Packit Service 7f19f2
  - xtables: fix segfault if incorrect protocol name is used
Packit Service 7f19f2
  - libxt_connlimit: initialize v6_mask
Packit Service 7f19f2
  - SNAT/DNAT: add support for persistent multi-range NAT mappings
Packit Service 7f19f2
Packit Service 7f19f2
* Fri Jul 24 2009 Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 1.4.3.2-2
Packit Service 7f19f2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild
Packit Service 7f19f2
Packit Service 7f19f2
* Wed Apr 15 2009 Thomas Woerner <twoerner@redhat.com> 1.4.3.2-1
Packit Service 7f19f2
- new version 1.4.3.2
Packit Service 7f19f2
- also install iptables/internal.h, needed for iptables.h and ip6tables.h
Packit Service 7f19f2
Packit Service 7f19f2
* Mon Mar 30 2009 Thomas Woerner <twoerner@redhat.com> 1.4.3.1-1
Packit Service 7f19f2
- new version 1.4.3.1
Packit Service 7f19f2
  - libiptc is now shared
Packit Service 7f19f2
  - supports all new features of the 2.6.29 kernel
Packit Service 7f19f2
- dropped typo_latter patch
Packit Service 7f19f2
Packit Service 7f19f2
* Thu Mar  5 2009 Thomas Woerner <twoerner@redhat.com> 1.4.2-3
Packit Service 7f19f2
- still more review fixes (rhbz#225906)
Packit Service 7f19f2
  - consistent macro usage
Packit Service 7f19f2
  - use sed instead of perl for rpath removal
Packit Service 7f19f2
  - use standard RPM CFLAGS, but also -fno-strict-aliasing (needed for libiptc*)
Packit Service 7f19f2
Packit Service 7f19f2
* Wed Feb 25 2009 Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 1.4.2-2
Packit Service 7f19f2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_11_Mass_Rebuild
Packit Service 7f19f2
Packit Service 7f19f2
* Fri Feb 20 2009 Thomas Woerner <twoerner@redhat.com> 1.4.2-1
Packit Service 7f19f2
- new version 1.4.2
Packit Service 7f19f2
- removed TOS value mask patch (upstream)
Packit Service 7f19f2
- more review fixes (rhbz#225906)
Packit Service 7f19f2
- install all header files (rhbz#462207)
Packit Service 7f19f2
- dropped nf_ext_init (rhbz#472548)
Packit Service 7f19f2
Packit Service 7f19f2
* Tue Jul 22 2008 Thomas Woerner <twoerner@redhat.com> 1.4.1.1-2
Packit Service 7f19f2
- fixed TOS value mask problem (rhbz#456244) (upstream patch)
Packit Service 7f19f2
- two more cloexec fixes
Packit Service 7f19f2
Packit Service 7f19f2
* Tue Jul  1 2008 Thomas Woerner <twoerner@redhat.com> 1.4.1.1-1
Packit Service 7f19f2
- upstream bug fix release 1.4.1.1
Packit Service 7f19f2
- dropped extra patch for 1.4.1 - not needed anymore
Packit Service 7f19f2
Packit Service 7f19f2
* Tue Jun 10 2008 Thomas Woerner <twoerner@redhat.com> 1.4.1-1
Packit Service 7f19f2
- new version 1.4.1 with new build environment
Packit Service 7f19f2
- additional ipv6 network mask patch from Jan Engelhardt
Packit Service 7f19f2
- spec file cleanup
Packit Service 7f19f2
- removed old patches
Packit Service 7f19f2
Packit Service 7f19f2
* Fri Jun  6 2008 Tom "spot" Callaway <tcallawa@redhat.com> 1.4.0-5
Packit Service 7f19f2
- use normal kernel headers, not linux/compiler.h
Packit Service 7f19f2
- change BuildRequires: kernel-devel to kernel-headers
Packit Service 7f19f2
- We need to do this to be able to build for both sparcv9 and sparc64 
Packit Service 7f19f2
  (there is no kernel-devel.sparcv9)
Packit Service 7f19f2
Packit Service 7f19f2
* Thu Mar 20 2008 Thomas Woerner <twoerner@redhat.com> 1.4.0-4
Packit Service 7f19f2
- use O_CLOEXEC for all opened files in all applications (rhbz#438189)
Packit Service 7f19f2
Packit Service 7f19f2
* Mon Mar  3 2008 Thomas Woerner <twoerner@redhat.com> 1.4.0-3
Packit Service 7f19f2
- use the kernel headers from the build tree for iptables for now to be able to 
Packit Service 7f19f2
  compile this package, but this makes the package more kernel dependant
Packit Service 7f19f2
- use s6_addr32 instead of in6_u.u6_addr32
Packit Service 7f19f2
Packit Service 7f19f2
* Wed Feb 20 2008 Fedora Release Engineering <rel-eng@fedoraproject.org> - 1.4.0-2
Packit Service 7f19f2
- Autorebuild for GCC 4.3
Packit Service 7f19f2
Packit Service 7f19f2
* Mon Feb 11 2008 Thomas Woerner <twoerner@redhat.com> 1.4.0-1
Packit Service 7f19f2
- new version 1.4.0
Packit Service 7f19f2
- fixed condrestart (rhbz#428148)
Packit Service 7f19f2
- report the module in rmmod_r if there is an error
Packit Service 7f19f2
- use nf_ext_init instead of my_init for extension constructors
Packit Service 7f19f2
Packit Service 7f19f2
* Mon Nov  5 2007 Thomas Woerner <twoerner@redhat.com> 1.3.8-6
Packit Service 7f19f2
- fixed leaked file descriptor before fork/exec (rhbz#312191)
Packit Service 7f19f2
- blacklisting is not working, use "install X /bin/(true|false)" test instead
Packit Service 7f19f2
- return private exit code 150 for disabled ipv6 support
Packit Service 7f19f2
- use script name for output messages
Packit Service 7f19f2
Packit Service 7f19f2
* Tue Oct 16 2007 Thomas Woerner <twoerner@redhat.com> 1.3.8-5
Packit Service 7f19f2
- fixed error code for stopping a already stopped firewall (rhbz#321751)
Packit Service 7f19f2
- moved blacklist test into start
Packit Service 7f19f2
Packit Service 7f19f2
* Wed Sep 26 2007 Thomas Woerner <twoerner@redhat.com> 1.3.8-4.1
Packit Service 7f19f2
- do not start ip6tables if ipv6 is blacklisted (rhbz#236888)
Packit Service 7f19f2
- use simpler fix for (rhbz#295611)
Packit Service 7f19f2
  Thanks to Linus Torvalds for the patch.
Packit Service 7f19f2
Packit Service 7f19f2
* Mon Sep 24 2007 Thomas Woerner <twoerner@redhat.com> 1.3.8-4
Packit Service 7f19f2
- fixed IPv6 reject type (rhbz#295181)
Packit Service 7f19f2
- fixed init script: start, stop and status
Packit Service 7f19f2
- support netfilter compiled into kernel in init script (rhbz#295611)
Packit Service 7f19f2
- dropped inversion for limit modules from man pages (rhbz#220780)
Packit Service 7f19f2
- fixed typo in ip6tables man page (rhbz#236185)
Packit Service 7f19f2
Packit Service 7f19f2
* Wed Sep 19 2007 Thomas Woerner <twoerner@redhat.com> 1.3.8-3
Packit Service 7f19f2
- do not depend on local_fs in lsb header - this delayes start after network
Packit Service 7f19f2
- fixed exit code for initscript usage
Packit Service 7f19f2
Packit Service 7f19f2
* Mon Sep 17 2007 Thomas Woerner <twoerner@redhat.com> 1.3.8-2.1
Packit Service 7f19f2
- do not use lock file for condrestart test
Packit Service 7f19f2
Packit Service 7f19f2
* Thu Aug 23 2007 Thomas Woerner <twoerner@redhat.com> 1.3.8-2
Packit Service 7f19f2
- fixed initscript for LSB conformance (rhbz#246953, rhbz#242459)
Packit Service 7f19f2
- provide iptc interface again, but unsupported (rhbz#216733)
Packit Service 7f19f2
- compile all extension, which are supported by the kernel-headers package
Packit Service 7f19f2
- review fixes (rhbz#225906)
Packit Service 7f19f2
Packit Service 7f19f2
* Tue Jul 31 2007 Thomas Woerner <twoerner@redhat.com>
Packit Service 7f19f2
- reverted ipv6 fix, because it disables the ipv6 at all (rhbz#236888)
Packit Service 7f19f2
Packit Service 7f19f2
* Fri Jul 13 2007 Steve Conklin <sconklin@redhat.com> - 1.3.8-1
Packit Service 7f19f2
- New version 1.3.8
Packit Service 7f19f2
Packit Service 7f19f2
* Mon Apr 23 2007 Jeremy Katz <katzj@redhat.com> - 1.3.7-2
Packit Service 7f19f2
- fix error when ipv6 support isn't loaded in the kernel (#236888)
Packit Service 7f19f2
Packit Service 7f19f2
* Wed Jan 10 2007 Thomas Woerner <twoerner@redhat.com> 1.3.7-1.1
Packit Service 7f19f2
- fixed installation of secmark modules
Packit Service 7f19f2
Packit Service 7f19f2
* Tue Jan  9 2007 Thomas Woerner <twoerner@redhat.com> 1.3.7-1
Packit Service 7f19f2
- new verison 1.3.7
Packit Service 7f19f2
- iptc is not a public interface and therefore not installed anymore
Packit Service 7f19f2
- dropped upstream secmark patch
Packit Service 7f19f2
Packit Service 7f19f2
* Tue Sep 19 2006 Thomas Woerner <twoerner@redhat.com> 1.3.5-2
Packit Service 7f19f2
- added secmark iptables patches (#201573)
Packit Service 7f19f2
Packit Service 7f19f2
* Wed Jul 12 2006 Jesse Keating <jkeating@redhat.com> - 1.3.5-1.2.1
Packit Service 7f19f2
- rebuild
Packit Service 7f19f2
Packit Service 7f19f2
* Fri Feb 10 2006 Jesse Keating <jkeating@redhat.com> - 1.3.5-1.2
Packit Service 7f19f2
- bump again for double-long bug on ppc(64)
Packit Service 7f19f2
Packit Service 7f19f2
* Tue Feb 07 2006 Jesse Keating <jkeating@redhat.com> - 1.3.5-1.1
Packit Service 7f19f2
- rebuilt for new gcc4.1 snapshot and glibc changes
Packit Service 7f19f2
Packit Service 7f19f2
* Thu Feb  2 2006 Thomas Woerner <twoerner@redhat.com> 1.3.5-1
Packit Service 7f19f2
- new version 1.3.5
Packit Service 7f19f2
- fixed init script to set policy for raw tables, too (#179094)
Packit Service 7f19f2
Packit Service 7f19f2
* Tue Jan 24 2006 Thomas Woerner <twoerner@redhat.com> 1.3.4-3
Packit Service 7f19f2
- added important iptables header files to devel package
Packit Service 7f19f2
Packit Service 7f19f2
* Fri Dec 09 2005 Jesse Keating <jkeating@redhat.com>
Packit Service 7f19f2
- rebuilt
Packit Service 7f19f2
Packit Service 7f19f2
* Fri Nov 25 2005 Thomas Woerner <twoerner@redhat.com> 1.3.4-2
Packit Service 7f19f2
- fix for plugin problem: link with "gcc -shared" instead of "ld -shared" and 
Packit Service 7f19f2
  replace "_init" with "__attribute((constructor)) my_init"
Packit Service 7f19f2
Packit Service 7f19f2
* Fri Nov 25 2005 Thomas Woerner <twoerner@redhat.com> 1.3.4-1.1
Packit Service 7f19f2
- rebuild due to unresolved symbols in shared libraries
Packit Service 7f19f2
Packit Service 7f19f2
* Fri Nov 18 2005 Thomas Woerner <twoerner@redhat.com> 1.3.4-1
Packit Service 7f19f2
- new version 1.3.4
Packit Service 7f19f2
- dropped free_opts patch (upstream fixed)
Packit Service 7f19f2
- made libipq PIC (#158623)
Packit Service 7f19f2
- additional configuration options for iptables startup script (#172929)
Packit Service 7f19f2
  Thanks to Jan Gruenwald for the patch
Packit Service 7f19f2
- spec file cleanup (dropped linux_header define and usage)
Packit Service 7f19f2
Packit Service 7f19f2
* Mon Jul 18 2005 Thomas Woerner <twoerner@redhat.com> 1.3.2-1
Packit Service 7f19f2
- new version 1.3.2 with additional patch for the misplaced free_opts call
Packit Service 7f19f2
  from Marcus Sundberg
Packit Service 7f19f2
Packit Service 7f19f2
* Wed May 11 2005 Thomas Woerner <twoerner@redhat.com> 1.3.1-1
Packit Service 7f19f2
- new version 1.3.1
Packit Service 7f19f2
Packit Service 7f19f2
* Fri Mar 18 2005 Thomas Woerner <twoerner@redhat.com> 1.3.0-2
Packit Service 7f19f2
- Remove unnecessary explicit kernel dep (#146142)
Packit Service 7f19f2
- Fixed out of bounds accesses (#131848): Thanks to Steve Grubb
Packit Service 7f19f2
  for the patch
Packit Service 7f19f2
- Adapted iptables-config to reference to modprobe.conf (#150143)
Packit Service 7f19f2
- Remove misleading message (#140154): Thanks to Ulrich Drepper
Packit Service 7f19f2
  for the patch
Packit Service 7f19f2
Packit Service 7f19f2
* Mon Feb 21 2005 Thomas Woerner <twoerner@redhat.com> 1.3.0-1
Packit Service 7f19f2
- new version 1.3.0
Packit Service 7f19f2
Packit Service 7f19f2
* Thu Nov 11 2004 Thomas Woerner <twoerner@redhat.com> 1.2.11-3.2
Packit Service 7f19f2
- fixed autoload problem in iptables and ip6tables (CAN-2004-0986)
Packit Service 7f19f2
Packit Service 7f19f2
* Fri Sep 17 2004 Thomas Woerner <twoerner@redhat.com> 1.2.11-3.1
Packit Service 7f19f2
- changed default behaviour for IPTABLES_STATUS_NUMERIC to "yes" (#129731)
Packit Service 7f19f2
- modified config file to match this change and un-commented variables with
Packit Service 7f19f2
  default values
Packit Service 7f19f2
Packit Service 7f19f2
* Thu Sep 16 2004 Thomas Woerner <twoerner@redhat.com> 1.2.11-3
Packit Service 7f19f2
- applied second part of cleanup patch from (#131848): thanks to Steve Grubb
Packit Service 7f19f2
  for the patch
Packit Service 7f19f2
Packit Service 7f19f2
* Wed Aug 25 2004 Thomas Woerner <twoerner@redhat.com> 1.2.11-2
Packit Service 7f19f2
- fixed free bug in iptables (#128322)
Packit Service 7f19f2
Packit Service 7f19f2
* Tue Jun 22 2004 Thomas Woerner <twoerner@redhat.com> 1.2.11-1
Packit Service 7f19f2
- new version 1.2.11
Packit Service 7f19f2
Packit Service 7f19f2
* Thu Jun 17 2004 Thomas Woerner <twoerner@redhat.com> 1.2.10-1
Packit Service 7f19f2
- new version 1.2.10
Packit Service 7f19f2
Packit Service 7f19f2
* Tue Jun 15 2004 Elliot Lee <sopwith@redhat.com>
Packit Service 7f19f2
- rebuilt
Packit Service 7f19f2
Packit Service 7f19f2
* Tue Mar 02 2004 Elliot Lee <sopwith@redhat.com>
Packit Service 7f19f2
- rebuilt
Packit Service 7f19f2
Packit Service 7f19f2
* Thu Feb 26 2004 Thomas Woerner <twoerner@redhat.com> 1.2.9-2.3
Packit Service 7f19f2
- fixed iptables-restore -c fault if there are no counters (#116421)
Packit Service 7f19f2
Packit Service 7f19f2
* Fri Feb 13 2004 Elliot Lee <sopwith@redhat.com>
Packit Service 7f19f2
- rebuilt
Packit Service 7f19f2
Packit Service 7f19f2
* Sun Jan  25 2004 Dan Walsh <dwalsh@redhat.com> 1.2.9-1.2
Packit Service 7f19f2
- Close File descriptors to prevent SELinux error message
Packit Service 7f19f2
Packit Service 7f19f2
* Wed Jan  7 2004 Thomas Woerner <twoerner@redhat.com> 1.2.9-1.1
Packit Service 7f19f2
- rebuild
Packit Service 7f19f2
Packit Service 7f19f2
* Wed Dec 17 2003 Thomas Woerner <twoerner@redhat.com> 1.2.9-1
Packit Service 7f19f2
- vew version 1.2.9
Packit Service 7f19f2
- new config options in ipXtables-config:
Packit Service 7f19f2
  IPTABLES_MODULES_UNLOAD
Packit Service 7f19f2
- more documentation in ipXtables-config
Packit Service 7f19f2
- fix for netlink security issue in libipq (devel package)
Packit Service 7f19f2
- print fix for libipt_icmp (#109546)
Packit Service 7f19f2
Packit Service 7f19f2
* Thu Oct 23 2003 Thomas Woerner <twoerner@redhat.com> 1.2.8-13
Packit Service 7f19f2
- marked all messages in iptables init script for translation (#107462)
Packit Service 7f19f2
- enabled devel package (#105884, #106101)
Packit Service 7f19f2
- bumped build for fedora for libipt_recent.so (#106002)
Packit Service 7f19f2
Packit Service 7f19f2
* Tue Sep 23 2003 Thomas Woerner <twoerner@redhat.com> 1.2.8-12.1
Packit Service 7f19f2
- fixed lost udp port range in ip6tables-save (#104484)
Packit Service 7f19f2
- fixed non numeric multiport port output in ipXtables-savs
Packit Service 7f19f2
Packit Service 7f19f2
* Mon Sep 22 2003 Florian La Roche <Florian.LaRoche@redhat.de> 1.2.8-11
Packit Service 7f19f2
- do not link against -lnsl
Packit Service 7f19f2
Packit Service 7f19f2
* Wed Sep 17 2003 Thomas Woerner <twoerner@redhat.com> 1.2.8-10
Packit Service 7f19f2
- made variables in rmmod_r local
Packit Service 7f19f2
Packit Service 7f19f2
* Tue Jul 22 2003 Thomas Woerner <twoerner@redhat.com> 1.2.8-9
Packit Service 7f19f2
- fixed permission for init script
Packit Service 7f19f2
Packit Service 7f19f2
* Sat Jul 19 2003 Thomas Woerner <twoerner@redhat.com> 1.2.8-8
Packit Service 7f19f2
- fixed save when iptables file is missing and iptables-config permissions
Packit Service 7f19f2
Packit Service 7f19f2
* Tue Jul  8 2003 Thomas Woerner <twoerner@redhat.com> 1.2.8-7
Packit Service 7f19f2
- fixes for ip6tables: module unloading, setting policy only for existing 
Packit Service 7f19f2
  tables
Packit Service 7f19f2
Packit Service 7f19f2
* Thu Jul  3 2003 Thomas Woerner <twoerner@redhat.com> 1.2.8-6
Packit Service 7f19f2
- IPTABLES_SAVE_COUNTER defaults to no, now
Packit Service 7f19f2
- install config file in /etc/sysconfig
Packit Service 7f19f2
- exchange unload of ip_tables and ip_conntrack
Packit Service 7f19f2
- fixed start function
Packit Service 7f19f2
Packit Service 7f19f2
* Wed Jul  2 2003 Thomas Woerner <twoerner@redhat.com> 1.2.8-5
Packit Service 7f19f2
- new config option IPTABLES_SAVE_ON_RESTART
Packit Service 7f19f2
- init script: new status, save and restart
Packit Service 7f19f2
- fixes #44905, #65389, #80785, #82860, #91040, #91560 and #91374
Packit Service 7f19f2
Packit Service 7f19f2
* Mon Jun 30 2003 Thomas Woerner <twoerner@redhat.com> 1.2.8-4
Packit Service 7f19f2
- new config option IPTABLES_STATUS_NUMERIC
Packit Service 7f19f2
- cleared IPTABLES_MODULES in iptables-config
Packit Service 7f19f2
Packit Service 7f19f2
* Mon Jun 30 2003 Thomas Woerner <twoerner@redhat.com> 1.2.8-3
Packit Service 7f19f2
- new init scripts
Packit Service 7f19f2
Packit Service 7f19f2
* Sat Jun 28 2003 Florian La Roche <Florian.LaRoche@redhat.de>
Packit Service 7f19f2
- remove check for very old kernel versions in init scripts
Packit Service 7f19f2
- sync up both init scripts and remove some further ugly things
Packit Service 7f19f2
- add some docu into rpm
Packit Service 7f19f2
Packit Service 7f19f2
* Thu Jun 26  2003 Thomas Woerner <twoerner@redhat.com> 1.2.8-2
Packit Service 7f19f2
- rebuild
Packit Service 7f19f2
Packit Service 7f19f2
* Mon Jun 16 2003 Thomas Woerner <twoerner@redhat.com> 1.2.8-1
Packit Service 7f19f2
- update to 1.2.8
Packit Service 7f19f2
Packit Service 7f19f2
* Wed Jan 22 2003 Tim Powers <timp@redhat.com>
Packit Service 7f19f2
- rebuilt
Packit Service 7f19f2
Packit Service 7f19f2
* Mon Jan 13 2003 Bill Nottingham <notting@redhat.com> 1.2.7a-1
Packit Service 7f19f2
- update to 1.2.7a
Packit Service 7f19f2
- add a plethora of bugfixes courtesy Michael Schwendt <mschewndt@yahoo.com>
Packit Service 7f19f2
Packit Service 7f19f2
* Fri Dec 13 2002 Elliot Lee <sopwith@redhat.com> 1.2.6a-3
Packit Service 7f19f2
- Fix multilib
Packit Service 7f19f2
Packit Service 7f19f2
* Wed Aug 07 2002 Karsten Hopp <karsten@redhat.de>
Packit Service 7f19f2
- fixed iptables and ip6tables initscript output, based on #70511
Packit Service 7f19f2
- check return status of all iptables calls, not just the last one
Packit Service 7f19f2
  in a 'for' loop.
Packit Service 7f19f2
Packit Service 7f19f2
* Mon Jul 29 2002 Bernhard Rosenkraenzer <bero@redhat.com> 1.2.6a-1
Packit Service 7f19f2
- 1.2.6a (bugfix release, #69747)
Packit Service 7f19f2
Packit Service 7f19f2
* Fri Jun 21 2002 Tim Powers <timp@redhat.com>
Packit Service 7f19f2
- automated rebuild
Packit Service 7f19f2
Packit Service 7f19f2
* Thu May 23 2002 Tim Powers <timp@redhat.com>
Packit Service 7f19f2
- automated rebuild
Packit Service 7f19f2
Packit Service 7f19f2
* Mon Mar  4 2002 Bernhard Rosenkraenzer <bero@redhat.com> 1.2.5-3
Packit Service 7f19f2
- Add some fixes from CVS, fixing bug #60465
Packit Service 7f19f2
Packit Service 7f19f2
* Tue Feb 12 2002 Bernhard Rosenkraenzer <bero@redhat.com> 1.2.5-2
Packit Service 7f19f2
- Merge ip6tables improvements from Ian Prowell <iprowell@prowell.org>
Packit Service 7f19f2
  #59402
Packit Service 7f19f2
- Update URL (#59354)
Packit Service 7f19f2
- Use /sbin/chkconfig rather than chkconfig in %%postun script
Packit Service 7f19f2
Packit Service 7f19f2
* Fri Jan 11 2002 Bernhard Rosenkraenzer <bero@redhat.com> 1.2.5-1
Packit Service 7f19f2
- 1.2.5
Packit Service 7f19f2
Packit Service 7f19f2
* Wed Jan 09 2002 Tim Powers <timp@redhat.com>
Packit Service 7f19f2
- automated rebuild
Packit Service 7f19f2
Packit Service 7f19f2
* Mon Nov  5 2001 Bernhard Rosenkraenzer <bero@redhat.com> 1.2.4-2
Packit Service 7f19f2
- Fix %%preun script
Packit Service 7f19f2
Packit Service 7f19f2
* Tue Oct 30 2001 Bernhard Rosenkraenzer <bero@redhat.com> 1.2.4-1
Packit Service 7f19f2
- Update to 1.2.4 (various fixes, including security fixes; among others:
Packit Service 7f19f2
  #42990, #50500, #53325, #54280)
Packit Service 7f19f2
- Fix init script (#31133)
Packit Service 7f19f2
Packit Service 7f19f2
* Mon Sep  3 2001 Bernhard Rosenkraenzer <bero@redhat.com> 1.2.3-1
Packit Service 7f19f2
- 1.2.3 (5 security fixes, some other fixes)
Packit Service 7f19f2
- Fix updating (#53032)
Packit Service 7f19f2
Packit Service 7f19f2
* Mon Aug 27 2001 Bernhard Rosenkraenzer <bero@redhat.com> 1.2.2-4
Packit Service 7f19f2
- Fix #50990
Packit Service 7f19f2
- Add some fixes from current CVS; should fix #52620
Packit Service 7f19f2
Packit Service 7f19f2
* Mon Jul 16 2001 Bernhard Rosenkraenzer <bero@redhat.com> 1.2.2-3
Packit Service 7f19f2
- Add some fixes from the current CVS tree; fixes #49154 and some IPv6
Packit Service 7f19f2
  issues
Packit Service 7f19f2
Packit Service 7f19f2
* Tue Jun 26 2001 Bernhard Rosenkraenzer <bero@redhat.com> 1.2.2-2
Packit Service 7f19f2
- Fix iptables-save reject-with (#45632), Patch from Michael Schwendt
Packit Service 7f19f2
  <mschwendt@yahoo.com>
Packit Service 7f19f2
Packit Service 7f19f2
* Tue May  8 2001 Bernhard Rosenkraenzer <bero@redhat.com> 1.2.2-1
Packit Service 7f19f2
- 1.2.2
Packit Service 7f19f2
Packit Service 7f19f2
* Wed Mar 21 2001 Bernhard Rosenkraenzer <bero@redhat.com>
Packit Service 7f19f2
- 1.2.1a, fixes #28412, #31136, #31460, #31133
Packit Service 7f19f2
Packit Service 7f19f2
* Thu Mar  1 2001 Bernhard Rosenkraenzer <bero@redhat.com>
Packit Service 7f19f2
- Yet another initscript fix (#30173)
Packit Service 7f19f2
- Fix the fixes; they fixed some issues but broke more important
Packit Service 7f19f2
  stuff :/ (#30176)
Packit Service 7f19f2
Packit Service 7f19f2
* Tue Feb 27 2001 Bernhard Rosenkraenzer <bero@redhat.com>
Packit Service 7f19f2
- Fix up initscript (#27962)
Packit Service 7f19f2
- Add fixes from CVS to iptables-{restore,save}, fixing #28412
Packit Service 7f19f2
Packit Service 7f19f2
* Fri Feb 09 2001 Karsten Hopp <karsten@redhat.de>
Packit Service 7f19f2
- create /etc/sysconfig/iptables mode 600 (same problem as #24245)
Packit Service 7f19f2
Packit Service 7f19f2
* Mon Feb 05 2001 Karsten Hopp <karsten@redhat.de>
Packit Service 7f19f2
- fix bugzilla #25986 (initscript not marked as config file)
Packit Service 7f19f2
- fix bugzilla #25962 (iptables-restore)
Packit Service 7f19f2
- mv chkconfig --del from postun to preun
Packit Service 7f19f2
Packit Service 7f19f2
* Thu Feb  1 2001 Trond Eivind Glomsrød <teg@redhat.com>
Packit Service 7f19f2
- Fix check for ipchains
Packit Service 7f19f2
Packit Service 7f19f2
* Mon Jan 29 2001 Bernhard Rosenkraenzer <bero@redhat.com>
Packit Service 7f19f2
- Some fixes to init scripts
Packit Service 7f19f2
Packit Service 7f19f2
* Wed Jan 24 2001 Bernhard Rosenkraenzer <bero@redhat.com>
Packit Service 7f19f2
- Add some fixes from CVS, fixes among other things Bug #24732
Packit Service 7f19f2
Packit Service 7f19f2
* Wed Jan 17 2001 Bernhard Rosenkraenzer <bero@redhat.com>
Packit Service 7f19f2
- Add missing man pages, fix up init script (Bug #17676)
Packit Service 7f19f2
Packit Service 7f19f2
* Mon Jan 15 2001 Bill Nottingham <notting@redhat.com>
Packit Service 7f19f2
- add init script
Packit Service 7f19f2
Packit Service 7f19f2
* Mon Jan 15 2001 Bernhard Rosenkraenzer <bero@redhat.com>
Packit Service 7f19f2
- 1.2
Packit Service 7f19f2
- fix up ipv6 split
Packit Service 7f19f2
- add init script
Packit Service 7f19f2
- Move the plugins from /usr/lib/iptables to /lib/iptables.
Packit Service 7f19f2
  This needs to work before /usr is mounted...
Packit Service 7f19f2
- Use -O1 on alpha (compiler bug)
Packit Service 7f19f2
Packit Service 7f19f2
* Sat Jan  6 2001 Bernhard Rosenkraenzer <bero@redhat.com>
Packit Service 7f19f2
- 1.1.2
Packit Service 7f19f2
- Add IPv6 support (in separate package)
Packit Service 7f19f2
Packit Service 7f19f2
* Thu Aug 17 2000 Bill Nottingham <notting@redhat.com>
Packit Service 7f19f2
- build everywhere
Packit Service 7f19f2
Packit Service 7f19f2
* Tue Jul 25 2000 Bernhard Rosenkraenzer <bero@redhat.com>
Packit Service 7f19f2
- 1.1.1
Packit Service 7f19f2
Packit Service 7f19f2
* Thu Jul 13 2000 Prospector <bugzilla@redhat.com>
Packit Service 7f19f2
- automatic rebuild
Packit Service 7f19f2
Packit Service 7f19f2
* Tue Jun 27 2000 Preston Brown <pbrown@redhat.com>
Packit Service 7f19f2
- move iptables to /sbin.
Packit Service 7f19f2
- excludearch alpha for now, not building there because of compiler bug(?)
Packit Service 7f19f2
Packit Service 7f19f2
* Fri Jun  9 2000 Bill Nottingham <notting@redhat.com>
Packit Service 7f19f2
- don't obsolete ipchains either
Packit Service 7f19f2
- update to 1.1.0
Packit Service 7f19f2
Packit Service 7f19f2
* Sun Jun  4 2000 Bill Nottingham <notting@redhat.com>
Packit Service 7f19f2
- remove explicit kernel requirement
Packit Service 7f19f2
Packit Service 7f19f2
* Tue May  2 2000 Bernhard Rosenkränzer <bero@redhat.com>
Packit Service 7f19f2
- initial package