diff --git a/.gitignore b/.gitignore index 4cb5d7a..3814395 100644 --- a/.gitignore +++ b/.gitignore @@ -14,3 +14,6 @@ /iptables-1.8.8.tar.bz2 /iptables-1.8.9.tar.xz /iptables-1.8.10.tar.xz +/iptables-1.8.10.tar.xz.sig +/iptables-1.8.11.tar.xz +/iptables-1.8.11.tar.xz.sig diff --git a/0001-libiptc-Fix-for-another-segfault-due-to-chain-index-.patch b/0001-libiptc-Fix-for-another-segfault-due-to-chain-index-.patch deleted file mode 100644 index 35b5973..0000000 --- a/0001-libiptc-Fix-for-another-segfault-due-to-chain-index-.patch +++ /dev/null @@ -1,81 +0,0 @@ -From 88d7c7c51b4523add8b7d48209b5b6a316442e0f Mon Sep 17 00:00:00 2001 -From: Phil Sutter -Date: Thu, 12 Oct 2023 17:27:42 +0200 -Subject: [PATCH] libiptc: Fix for another segfault due to chain index NULL - pointer - -Chain rename code missed to adjust the num_chains value which is used to -calculate the number of chain index buckets to allocate during an index -rebuild. So with the right number of chains present, the last chain in a -middle bucket being renamed (and ending up in another bucket) triggers -an index rebuild based on false data. The resulting NULL pointer index -bucket then causes a segfault upon reinsertion. - -Closes: https://bugzilla.netfilter.org/show_bug.cgi?id=1713 -Fixes: 64ff47cde38e4 ("libiptc: fix chain rename bug in libiptc") -(cherry picked from commit e2d7ee9c49b582f399ad4ba2da2ee1b3e1f89620) ---- - .../testcases/chain/0008rename-segfault2_0 | 32 +++++++++++++++++++ - libiptc/libiptc.c | 4 +++ - 2 files changed, 36 insertions(+) - create mode 100755 iptables/tests/shell/testcases/chain/0008rename-segfault2_0 - -diff --git a/iptables/tests/shell/testcases/chain/0008rename-segfault2_0 b/iptables/tests/shell/testcases/chain/0008rename-segfault2_0 -new file mode 100755 -index 0000000000000..bc473d2511bbd ---- /dev/null -+++ b/iptables/tests/shell/testcases/chain/0008rename-segfault2_0 -@@ -0,0 +1,32 @@ -+#!/bin/bash -+# -+# Another funny rename bug in libiptc: -+# If there is a chain index bucket with only a single chain in it and it is not -+# the last one and that chain is renamed, a chain index rebuild is triggered. -+# Since TC_RENAME_CHAIN missed to temporarily decrement num_chains value, an -+# extra index is allocated and remains NULL. The following insert of renamed -+# chain then segfaults. -+ -+( -+ echo "*filter" -+ # first bucket -+ for ((i = 0; i < 40; i++)); do -+ echo ":chain-a-$i - [0:0]" -+ done -+ # second bucket -+ for ((i = 0; i < 40; i++)); do -+ echo ":chain-b-$i - [0:0]" -+ done -+ # third bucket, just make sure it exists -+ echo ":chain-c-0 - [0:0]" -+ echo "COMMIT" -+) | $XT_MULTI iptables-restore -+ -+# rename all chains of the middle bucket -+( -+ echo "*filter" -+ for ((i = 0; i < 40; i++)); do -+ echo "-E chain-b-$i chain-d-$i" -+ done -+ echo "COMMIT" -+) | $XT_MULTI iptables-restore --noflush -diff --git a/libiptc/libiptc.c b/libiptc/libiptc.c -index e475063367c26..9712a36353b9a 100644 ---- a/libiptc/libiptc.c -+++ b/libiptc/libiptc.c -@@ -2384,12 +2384,16 @@ int TC_RENAME_CHAIN(const IPT_CHAINLABEL oldname, - return 0; - } - -+ handle->num_chains--; -+ - /* This only unlinks "c" from the list, thus no free(c) */ - iptcc_chain_index_delete_chain(c, handle); - - /* Change the name of the chain */ - strncpy(c->name, newname, sizeof(IPT_CHAINLABEL) - 1); - -+ handle->num_chains++; -+ - /* Insert sorted into to list again */ - iptc_insert_chain(handle, c); - diff --git a/0002-arptables-nft-remove-ARPT_INV-flags-usage.patch b/0002-arptables-nft-remove-ARPT_INV-flags-usage.patch deleted file mode 100644 index c384e4b..0000000 --- a/0002-arptables-nft-remove-ARPT_INV-flags-usage.patch +++ /dev/null @@ -1,81 +0,0 @@ -From 5d2e24d37d56eef0570aca06b590079527678707 Mon Sep 17 00:00:00 2001 -From: Florian Westphal -Date: Fri, 3 Nov 2023 17:33:22 +0100 -Subject: [PATCH] arptables-nft: remove ARPT_INV flags usage - -ARPT_ and IPT_INV flags are not interchangeable, e.g.: -define IPT_INV_SRCDEVADDR 0x0080 -define ARPT_INV_SRCDEVADDR 0x0010 - -as these flags can be tested by libarp_foo.so such checks can yield -incorrect results. - -Because arptables-nft uses existing code, e.g. xt_mark, it makes -sense to unify this completely by converting the last users of -ARPT_INV_ constants. - -Note that arptables-legacy does not do run-time module loading via -dlopen(). Functionaliy implemented by "extensions" in the -arptables-legacy git tree are built-in, so this doesn't break -arptables-legacy binaries. - -Fixes: 44457c080590 ("xtables-arp: Don't use ARPT_INV_*") -Signed-off-by: Florian Westphal -Signed-off-by: Phil Sutter -(cherry picked from commit 3493d40cbba9dbfc00018b419241c93646a97a68) ---- - extensions/libarpt_mangle.c | 4 ++-- - iptables/nft-arp.c | 2 +- - iptables/xshared.h | 4 +++- - 3 files changed, 6 insertions(+), 4 deletions(-) - -diff --git a/extensions/libarpt_mangle.c b/extensions/libarpt_mangle.c -index 765edf34781f3..a846e97ec8f27 100644 ---- a/extensions/libarpt_mangle.c -+++ b/extensions/libarpt_mangle.c -@@ -77,7 +77,7 @@ arpmangle_parse(int c, char **argv, int invert, unsigned int *flags, - if (e->arp.arhln_mask == 0) - xtables_error(PARAMETER_PROBLEM, - "no --h-length defined"); -- if (e->arp.invflags & ARPT_INV_ARPHLN) -+ if (e->arp.invflags & IPT_INV_ARPHLN) - xtables_error(PARAMETER_PROBLEM, - "! --h-length not allowed for " - "--mangle-mac-s"); -@@ -95,7 +95,7 @@ arpmangle_parse(int c, char **argv, int invert, unsigned int *flags, - if (e->arp.arhln_mask == 0) - xtables_error(PARAMETER_PROBLEM, - "no --h-length defined"); -- if (e->arp.invflags & ARPT_INV_ARPHLN) -+ if (e->arp.invflags & IPT_INV_ARPHLN) - xtables_error(PARAMETER_PROBLEM, - "! hln not allowed for --mangle-mac-d"); - if (e->arp.arhln != 6) -diff --git a/iptables/nft-arp.c b/iptables/nft-arp.c -index aed39ebdd5166..535dd6b83237b 100644 ---- a/iptables/nft-arp.c -+++ b/iptables/nft-arp.c -@@ -490,7 +490,7 @@ static void nft_arp_post_parse(int command, - &args->d.naddrs); - - if ((args->s.naddrs > 1 || args->d.naddrs > 1) && -- (cs->arp.arp.invflags & (ARPT_INV_SRCIP | ARPT_INV_TGTIP))) -+ (cs->arp.arp.invflags & (IPT_INV_SRCIP | IPT_INV_DSTIP))) - xtables_error(PARAMETER_PROBLEM, - "! not allowed with multiple" - " source or destination IP addresses"); -diff --git a/iptables/xshared.h b/iptables/xshared.h -index a200e0d620ad3..5586385456a4d 100644 ---- a/iptables/xshared.h -+++ b/iptables/xshared.h -@@ -80,7 +80,9 @@ struct xtables_target; - #define ARPT_OPTSTRING OPTSTRING_COMMON "R:S::" "h::l:nvx" /* "m:" */ - #define EBT_OPTSTRING OPTSTRING_COMMON "hv" - --/* define invflags which won't collide with IPT ones */ -+/* define invflags which won't collide with IPT ones. -+ * arptables-nft does NOT use the legacy ARPT_INV_* defines. -+ */ - #define IPT_INV_SRCDEVADDR 0x0080 - #define IPT_INV_TGTDEVADDR 0x0100 - #define IPT_INV_ARPHLN 0x0200 diff --git a/0003-ebtables-Fix-corner-case-noflush-restore-bug.patch b/0003-ebtables-Fix-corner-case-noflush-restore-bug.patch deleted file mode 100644 index 3386925..0000000 --- a/0003-ebtables-Fix-corner-case-noflush-restore-bug.patch +++ /dev/null @@ -1,63 +0,0 @@ -From b7051898e28854b21bc7a37ef24ca037ef977e4a Mon Sep 17 00:00:00 2001 -From: Phil Sutter -Date: Tue, 7 Nov 2023 19:12:14 +0100 -Subject: [PATCH] ebtables: Fix corner-case noflush restore bug - -Report came from firwalld, but this is actually rather hard to trigger. -Since a regular chain line prevents it, typical dump/restore use-cases -are unaffected. - -Fixes: 73611d5582e72 ("ebtables-nft: add broute table emulation") -Cc: Eric Garver -Signed-off-by: Phil Sutter -(cherry picked from commit c1083acea70787eea3f7929fd04718434bb05ba8) ---- - .../testcases/ebtables/0009-broute-bug_0 | 25 +++++++++++++++++++ - iptables/xtables-eb.c | 2 ++ - 2 files changed, 27 insertions(+) - create mode 100755 iptables/tests/shell/testcases/ebtables/0009-broute-bug_0 - -diff --git a/iptables/tests/shell/testcases/ebtables/0009-broute-bug_0 b/iptables/tests/shell/testcases/ebtables/0009-broute-bug_0 -new file mode 100755 -index 0000000000000..0def0ac58e7be ---- /dev/null -+++ b/iptables/tests/shell/testcases/ebtables/0009-broute-bug_0 -@@ -0,0 +1,25 @@ -+#!/bin/sh -+# -+# Missing BROUTING-awareness in ebt_get_current_chain() caused an odd caching bug when restoring: -+# - with --noflush -+# - a second table after the broute one -+# - A policy command but no chain line for BROUTING chain -+ -+set -e -+ -+case "$XT_MULTI" in -+*xtables-nft-multi) -+ ;; -+*) -+ echo "skip $XT_MULTI" -+ exit 0 -+ ;; -+esac -+ -+$XT_MULTI ebtables-restore --noflush < -Date: Sun, 19 Nov 2023 13:18:26 +0100 -Subject: [PATCH] xshared: struct xt_cmd_parse::xlate is unused - -Drop the boolean, it was meant to disable some existence checks in -do_parse() prior to the caching rework. Now that do_parse() runs before -any caching is done, the checks in question don't exist anymore so drop -this relict. - -Fixes: a7f1e208cdf9c ("nft: split parsing from netlink commands") -Signed-off-by: Phil Sutter -(cherry picked from commit b180d9c86d2cce6ab6fd3e3617faf320a8a1babb) ---- - iptables/xshared.h | 1 - - iptables/xtables-translate.c | 1 - - 2 files changed, 2 deletions(-) - -diff --git a/iptables/xshared.h b/iptables/xshared.h -index 5586385456a4d..c77556a1987dc 100644 ---- a/iptables/xshared.h -+++ b/iptables/xshared.h -@@ -284,7 +284,6 @@ struct xt_cmd_parse { - bool restore; - int line; - int verbose; -- bool xlate; - struct xt_cmd_parse_ops *ops; - }; - -diff --git a/iptables/xtables-translate.c b/iptables/xtables-translate.c -index 88e0a6b639494..c019cd2991305 100644 ---- a/iptables/xtables-translate.c -+++ b/iptables/xtables-translate.c -@@ -249,7 +249,6 @@ static int do_command_xlate(struct nft_handle *h, int argc, char *argv[], - .table = *table, - .restore = restore, - .line = line, -- .xlate = true, - .ops = &h->ops->cmd_parse, - }; - struct iptables_command_state cs = { diff --git a/0005-xshared-All-variants-support-v-update-OPTSTRING_COMM.patch b/0005-xshared-All-variants-support-v-update-OPTSTRING_COMM.patch deleted file mode 100644 index c743e75..0000000 --- a/0005-xshared-All-variants-support-v-update-OPTSTRING_COMM.patch +++ /dev/null @@ -1,31 +0,0 @@ -From 436dd5a6ba5639c8e83183f6252ce7bd37760e1c Mon Sep 17 00:00:00 2001 -From: Phil Sutter -Date: Sun, 19 Nov 2023 13:25:36 +0100 -Subject: [PATCH] xshared: All variants support -v, update OPTSTRING_COMMON - -Fixes: 51d9d9e081344 ("ebtables: Support verbose mode") -Signed-off-by: Phil Sutter -(cherry picked from commit 9a9ff768cab58aea02828e422184873e52e9846a) ---- - iptables/xshared.h | 8 ++++---- - 1 file changed, 4 insertions(+), 4 deletions(-) - -diff --git a/iptables/xshared.h b/iptables/xshared.h -index c77556a1987dc..815b9d3e98726 100644 ---- a/iptables/xshared.h -+++ b/iptables/xshared.h -@@ -75,10 +75,10 @@ struct xtables_globals; - struct xtables_rule_match; - struct xtables_target; - --#define OPTSTRING_COMMON "-:A:C:D:E:F::I:L::M:N:P:VX::Z::" "c:d:i:j:o:p:s:t:" --#define IPT_OPTSTRING OPTSTRING_COMMON "R:S::W::" "46bfg:h::m:nvw::x" --#define ARPT_OPTSTRING OPTSTRING_COMMON "R:S::" "h::l:nvx" /* "m:" */ --#define EBT_OPTSTRING OPTSTRING_COMMON "hv" -+#define OPTSTRING_COMMON "-:A:C:D:E:F::I:L::M:N:P:VX::Z::" "c:d:i:j:o:p:s:t:v" -+#define IPT_OPTSTRING OPTSTRING_COMMON "R:S::W::" "46bfg:h::m:nw::x" -+#define ARPT_OPTSTRING OPTSTRING_COMMON "R:S::" "h::l:nx" /* "m:" */ -+#define EBT_OPTSTRING OPTSTRING_COMMON "h" - - /* define invflags which won't collide with IPT ones. - * arptables-nft does NOT use the legacy ARPT_INV_* defines. diff --git a/0006-ebtables-Align-line-number-formatting-with-legacy.patch b/0006-ebtables-Align-line-number-formatting-with-legacy.patch deleted file mode 100644 index 07bea3a..0000000 --- a/0006-ebtables-Align-line-number-formatting-with-legacy.patch +++ /dev/null @@ -1,28 +0,0 @@ -From ffd0c96de7bbc558b9b7a8bcbeebd9576fec8e59 Mon Sep 17 00:00:00 2001 -From: Phil Sutter -Date: Tue, 21 Nov 2023 22:58:47 +0100 -Subject: [PATCH] ebtables: Align line number formatting with legacy - -Legacy ebtables appends a dot to the number printed in first column if ---Ln flag was given. - -Fixes: da871de2a6efb ("nft: bootstrap ebtables-compat") -Signed-off-by: Phil Sutter -(cherry picked from commit 74253799f0ca0735256327e834b7dffedde96ebf) ---- - iptables/nft-bridge.c | 2 +- - 1 file changed, 1 insertion(+), 1 deletion(-) - -diff --git a/iptables/nft-bridge.c b/iptables/nft-bridge.c -index d9a8ad2b0f373..e414ef5584392 100644 ---- a/iptables/nft-bridge.c -+++ b/iptables/nft-bridge.c -@@ -354,7 +354,7 @@ static void nft_bridge_print_rule(struct nft_handle *h, struct nftnl_rule *r, - struct iptables_command_state cs = {}; - - if (format & FMT_LINENUMBERS) -- printf("%d ", num); -+ printf("%d. ", num); - - nft_rule_to_ebtables_command_state(h, r, &cs); - __nft_bridge_save_rule(&cs, format); diff --git a/0007-man-Do-not-escape-exclamation-marks.patch b/0007-man-Do-not-escape-exclamation-marks.patch deleted file mode 100644 index b088c63..0000000 --- a/0007-man-Do-not-escape-exclamation-marks.patch +++ /dev/null @@ -1,44 +0,0 @@ -From 1c9549af3566e6c0b5573d6f91b25934d8d99f79 Mon Sep 17 00:00:00 2001 -From: Phil Sutter -Date: Tue, 28 Nov 2023 13:29:17 +0100 -Subject: [PATCH] man: Do not escape exclamation marks - -This appears to be not necessary, also mandoc complains about it: - -| mandoc: iptables/iptables-extensions.8:2170:52: UNSUPP: unsupported escape sequence: \! - -Fixes: 71eddedcbf7ae ("libip6t_DNPT: add manpage") -Fixes: 0a4c357cb91e1 ("libip6t_SNPT: add manpage") -Signed-off-by: Phil Sutter -(cherry picked from commit d8c64911cfd602f57354f36e5ca79bbedd62aa7a) ---- - extensions/libip6t_DNPT.man | 2 +- - extensions/libip6t_SNPT.man | 2 +- - 2 files changed, 2 insertions(+), 2 deletions(-) - -diff --git a/extensions/libip6t_DNPT.man b/extensions/libip6t_DNPT.man -index 9b060f5b7179b..72c6ae5d422a2 100644 ---- a/extensions/libip6t_DNPT.man -+++ b/extensions/libip6t_DNPT.man -@@ -15,7 +15,7 @@ Set destination prefix that you want to use in the translation and length - .PP - You have to use the SNPT target to undo the translation. Example: - .IP --ip6tables \-t mangle \-I POSTROUTING \-s fd00::/64 \! \-o vboxnet0 -+ip6tables \-t mangle \-I POSTROUTING \-s fd00::/64 ! \-o vboxnet0 - \-j SNPT \-\-src-pfx fd00::/64 \-\-dst-pfx 2001:e20:2000:40f::/64 - .IP - ip6tables \-t mangle \-I PREROUTING \-i wlan0 \-d 2001:e20:2000:40f::/64 -diff --git a/extensions/libip6t_SNPT.man b/extensions/libip6t_SNPT.man -index 97e0071b43cc1..0c926978377a7 100644 ---- a/extensions/libip6t_SNPT.man -+++ b/extensions/libip6t_SNPT.man -@@ -15,7 +15,7 @@ Set destination prefix that you want to use in the translation and length - .PP - You have to use the DNPT target to undo the translation. Example: - .IP --ip6tables \-t mangle \-I POSTROUTING \-s fd00::/64 \! \-o vboxnet0 -+ip6tables \-t mangle \-I POSTROUTING \-s fd00::/64 ! \-o vboxnet0 - \-j SNPT \-\-src-pfx fd00::/64 \-\-dst-pfx 2001:e20:2000:40f::/64 - .IP - ip6tables \-t mangle \-I PREROUTING \-i wlan0 \-d 2001:e20:2000:40f::/64 diff --git a/0008-libxtables-xtoptions-Fix-for-non-CIDR-compatible-hos.patch b/0008-libxtables-xtoptions-Fix-for-non-CIDR-compatible-hos.patch deleted file mode 100644 index c0bbec2..0000000 --- a/0008-libxtables-xtoptions-Fix-for-non-CIDR-compatible-hos.patch +++ /dev/null @@ -1,49 +0,0 @@ -From f667f577e6d29e62f55cdc4e1e39414913bf7c4c Mon Sep 17 00:00:00 2001 -From: Phil Sutter -Date: Tue, 28 Nov 2023 20:21:49 +0100 -Subject: [PATCH] libxtables: xtoptions: Fix for non-CIDR-compatible hostmasks - -In order to parse the mask, xtopt_parse_hostmask() calls -xtopt_parse_plenmask() thereby limiting netmask support to prefix -lengths (alternatively specified in IP address notation). - -In order to lift this impractical restriction, make -xtopt_parse_plenmask() aware of the fact that xtopt_parse_plen() may -fall back to xtopt_parse_mask() which correctly initializes val.hmask -itself and indicates non-CIDR-compatible masks by setting val.hlen to --1. - -So in order to support these odd masks, it is sufficient for -xtopt_parse_plenmask() to skip its mask building from val.hlen value and -take whatever val.hmask contains. - -Fixes: 66266abd17adc ("libxtables: XTTYPE_HOSTMASK support") -Signed-off-by: Phil Sutter -(cherry picked from commit 41139aee5e53304182a25f1e573f034b313f7232) ---- - libxtables/xtoptions.c | 5 +++++ - 1 file changed, 5 insertions(+) - -diff --git a/libxtables/xtoptions.c b/libxtables/xtoptions.c -index b16bbfbe32311..d91a78f470eda 100644 ---- a/libxtables/xtoptions.c -+++ b/libxtables/xtoptions.c -@@ -711,6 +711,10 @@ static void xtopt_parse_plenmask(struct xt_option_call *cb) - - xtopt_parse_plen(cb); - -+ /* may not be convertible to CIDR notation */ -+ if (cb->val.hlen == (uint8_t)-1) -+ goto out_put; -+ - memset(mask, 0xFF, sizeof(union nf_inet_addr)); - /* This shifting is AF-independent. */ - if (cb->val.hlen == 0) { -@@ -731,6 +735,7 @@ static void xtopt_parse_plenmask(struct xt_option_call *cb) - mask[1] = htonl(mask[1]); - mask[2] = htonl(mask[2]); - mask[3] = htonl(mask[3]); -+out_put: - if (entry->flags & XTOPT_PUT) - memcpy(XTOPT_MKPTR(cb), mask, sizeof(union nf_inet_addr)); - } diff --git a/0009-iptables-legacy-Fix-for-mandatory-lock-waiting.patch b/0009-iptables-legacy-Fix-for-mandatory-lock-waiting.patch deleted file mode 100644 index 7745634..0000000 --- a/0009-iptables-legacy-Fix-for-mandatory-lock-waiting.patch +++ /dev/null @@ -1,114 +0,0 @@ -From 2568af12c3cf96a8b28082e6188dba94441b21c1 Mon Sep 17 00:00:00 2001 -From: Phil Sutter -Date: Tue, 19 Dec 2023 00:56:07 +0100 -Subject: [PATCH] iptables-legacy: Fix for mandatory lock waiting - -Parameter 'wait' passed to xtables_lock() signals three modes of -operation, depending on its value: - - 0: --wait not specified, do not wait if lock is busy --1: --wait specified without value, wait indefinitely until lock becomes - free ->0: Wait for 'wait' seconds for lock to become free, abort otherwise - -Since fixed commit, the first two cases were treated the same apart from -calling alarm(0), but that is a nop if no alarm is pending. Fix the code -by requesting a non-blocking flock() in the second case. While at it, -restrict the alarm setup to the third case only. - -Cc: Jethro Beekman -Cc: howardjohn@google.com -Cc: Antonio Ojea -Closes: https://bugzilla.netfilter.org/show_bug.cgi?id=1728 -Fixes: 07e2107ef0cbc ("xshared: Implement xtables lock timeout using signals") -Signed-off-by: Phil Sutter -(cherry picked from commit 63ab5b8906f6913a14d38ec231f21daa760339a9) ---- - .../shell/testcases/iptables/0010-wait_0 | 55 +++++++++++++++++++ - iptables/xshared.c | 4 +- - 2 files changed, 57 insertions(+), 2 deletions(-) - create mode 100755 iptables/tests/shell/testcases/iptables/0010-wait_0 - -diff --git a/iptables/tests/shell/testcases/iptables/0010-wait_0 b/iptables/tests/shell/testcases/iptables/0010-wait_0 -new file mode 100755 -index 0000000000000..4481f966ce435 ---- /dev/null -+++ b/iptables/tests/shell/testcases/iptables/0010-wait_0 -@@ -0,0 +1,55 @@ -+#!/bin/bash -+ -+case "$XT_MULTI" in -+*xtables-legacy-multi) -+ ;; -+*) -+ echo skip $XT_MULTI -+ exit 0 -+ ;; -+esac -+ -+coproc RESTORE { $XT_MULTI iptables-restore; } -+echo "*filter" >&${RESTORE[1]} -+ -+ -+$XT_MULTI iptables -A FORWARD -j ACCEPT & -+ipt_pid=$! -+ -+waitpid -t 1 $ipt_pid -+[[ $? -eq 3 ]] && { -+ echo "process waits when it should not" -+ exit 1 -+} -+wait $ipt_pid -+[[ $? -eq 0 ]] && { -+ echo "process exited 0 despite busy lock" -+ exit 1 -+} -+ -+t0=$(date +%s) -+$XT_MULTI iptables -w 3 -A FORWARD -j ACCEPT -+t1=$(date +%s) -+[[ $((t1 - t0)) -ge 3 ]] || { -+ echo "wait time not expired" -+ exit 1 -+} -+ -+$XT_MULTI iptables -w -A FORWARD -j ACCEPT & -+ipt_pid=$! -+ -+waitpid -t 3 $ipt_pid -+[[ $? -eq 3 ]] || { -+ echo "no indefinite wait" -+ exit 1 -+} -+kill $ipt_pid -+waitpid -t 3 $ipt_pid -+[[ $? -eq 3 ]] && { -+ echo "killed waiting iptables call did not exit in time" -+ exit 1 -+} -+ -+kill $RESTORE_PID -+wait -+exit 0 -diff --git a/iptables/xshared.c b/iptables/xshared.c -index 5f75a0a57a023..690502c457dd0 100644 ---- a/iptables/xshared.c -+++ b/iptables/xshared.c -@@ -270,7 +270,7 @@ static int xtables_lock(int wait) - return XT_LOCK_FAILED; - } - -- if (wait != -1) { -+ if (wait > 0) { - sigact_alarm.sa_handler = alarm_ignore; - sigact_alarm.sa_flags = SA_RESETHAND; - sigemptyset(&sigact_alarm.sa_mask); -@@ -278,7 +278,7 @@ static int xtables_lock(int wait) - alarm(wait); - } - -- if (flock(fd, LOCK_EX) == 0) -+ if (flock(fd, LOCK_EX | (wait ? 0 : LOCK_NB)) == 0) - return fd; - - if (errno == EINTR) { diff --git a/0010-libxtables-xtoptions-Prevent-XTOPT_PUT-with-XTTYPE_H.patch b/0010-libxtables-xtoptions-Prevent-XTOPT_PUT-with-XTTYPE_H.patch deleted file mode 100644 index ea88fa3..0000000 --- a/0010-libxtables-xtoptions-Prevent-XTOPT_PUT-with-XTTYPE_H.patch +++ /dev/null @@ -1,40 +0,0 @@ -From 07ab8c7e7a1eeb6a5bb4028d92d713034df39167 Mon Sep 17 00:00:00 2001 -From: Phil Sutter -Date: Sun, 17 Dec 2023 13:02:36 +0100 -Subject: [PATCH] libxtables: xtoptions: Prevent XTOPT_PUT with XTTYPE_HOSTMASK - -Do as the comment in xtopt_parse_hostmask() claims and omit -XTTYPE_HOSTMASK from xtopt_psize array so xtables_option_metavalidate() -will catch the incompatibility. - -Fixes: 66266abd17adc ("libxtables: XTTYPE_HOSTMASK support") -(cherry picked from commit 17d724f20e3c97ea8ce8765ca532a3cf49a98b31) ---- - include/xtables.h | 1 - - libxtables/xtoptions.c | 1 - - 2 files changed, 2 deletions(-) - -diff --git a/include/xtables.h b/include/xtables.h -index 087a1d600f9ae..9def9b43b6e58 100644 ---- a/include/xtables.h -+++ b/include/xtables.h -@@ -61,7 +61,6 @@ struct in_addr; - * %XTTYPE_SYSLOGLEVEL: syslog level by name or number - * %XTTYPE_HOST: one host or address (ptr: union nf_inet_addr) - * %XTTYPE_HOSTMASK: one host or address, with an optional prefix length -- * (ptr: union nf_inet_addr; only host portion is stored) - * %XTTYPE_PROTOCOL: protocol number/name from /etc/protocols (ptr: uint8_t) - * %XTTYPE_PORT: 16-bit port name or number (supports %XTOPT_NBO) - * %XTTYPE_PORTRC: colon-separated port range (names acceptable), -diff --git a/libxtables/xtoptions.c b/libxtables/xtoptions.c -index d91a78f470eda..ba68056dc99f7 100644 ---- a/libxtables/xtoptions.c -+++ b/libxtables/xtoptions.c -@@ -57,7 +57,6 @@ static const size_t xtopt_psize[] = { - [XTTYPE_STRING] = -1, - [XTTYPE_SYSLOGLEVEL] = sizeof(uint8_t), - [XTTYPE_HOST] = sizeof(union nf_inet_addr), -- [XTTYPE_HOSTMASK] = sizeof(union nf_inet_addr), - [XTTYPE_PROTOCOL] = sizeof(uint8_t), - [XTTYPE_PORT] = sizeof(uint16_t), - [XTTYPE_PORTRC] = sizeof(uint16_t[2]), diff --git a/arptables-nft-helper b/arptables-helper similarity index 100% rename from arptables-nft-helper rename to arptables-helper diff --git a/arptables.service b/arptables.service new file mode 100644 index 0000000..df6c7d6 --- /dev/null +++ b/arptables.service @@ -0,0 +1,12 @@ +[Unit] +Description=Automates a packet filtering firewall with arptables +After=network.target + +[Service] +Type=oneshot +ExecStart=/usr/libexec/arptables-helper start +ExecStop=/usr/libexec/arptables-helper stop +RemainAfterExit=yes + +[Install] +WantedBy=multi-user.target diff --git a/coreteam-gpg-key-0xD70D1A666ACF2B21.txt b/coreteam-gpg-key-0xD70D1A666ACF2B21.txt new file mode 100644 index 0000000..cd4a35b --- /dev/null +++ b/coreteam-gpg-key-0xD70D1A666ACF2B21.txt @@ -0,0 +1,64 @@ +-----BEGIN PGP PUBLIC KEY BLOCK----- + +mQINBGcLlIQBEADH+pWx2d5XgY2JCOHTVaOpbNlNfp1k9Ul0W5zaZ7EFHIGSj06E +o3+OM0eI6+d51PnqwRE+WbV4T3ooGnfgXN4fmKgq2TwkxlhKeFSzNGMuzzuoEwD+ +2cvSF9VIrwif1o9oa9KMNfKTY/qjuWZS0QWZ08thPAf/tWpoaA3gaqYQUshj5G3w +nTMdYlHUj7wkZCMg63tDygAe/7fDT3zurKCMbFoyiyQkp7V1SLxZpvuyuyPH6HtQ +P5xcbXsp5ots0BgN+BplMX89DrspxJXqi7AsTf4QnC78KbchMJJxLKZQS759dQHF +qHUTb3YdlxXFou6Si5LiBzvmqBRFj6m/WV1a8mDy5fPDkOLoTCUFHLmgvYHPJdtK +5EqNkwYAbSnZKe9aSeVa4XhaZqyyQb9vIsKyOnwdJ/l222J95qHQapZSLcRdqgQz +ZgxuEdOHacEaJ1IJ21CE8EtJfFA5DMZtkZNIGF3OFlXhw7YxJoPgsodtlVspQsfX +u2FGP9yg0fd4zLgHnotKqfJQ9ZjMB6bbJUd6Au9jv0SiM+kVGeVfyaaX7TDeQ3TT +/e44uFvkHkbYFQPcqsTalxtre6v7pMG2iu2mbkhQOC7qbL5MKMSdA93w/lF7w20b +cwyDavEoKk9vgDjSkVjaffvdy4cESa5JY4lM4ZmzoujnAZMwbzQeGcBtqQARAQAB +tCxOZXRmaWx0ZXIgQ29yZSBUZWFtIDxjb3JldGVhbUBuZXRmaWx0ZXIub3JnPokC +VAQTAQoAPhYhBIxfcUahdXpl4kIqlNcNGmZqzyshBQJnC5SEAhsDBQkHhM4ABQsJ +CAcCBhUKCQgLAgQWAgMBAh4BAheAAAoJENcNGmZqzyshRE4P/AknD3DAWuCT7x7L +LFIUCkfl7WUou9zMQKy62JRK/+/lNyG1dkmvBu7XWLl/+IRv1uIb25I4xwaze6GF +8yhZDNXZLhUjComr864fMEdKNdXInAClLRNY0InkFmHw/SizvwDld4PgsLzoS+qL +5JY4FBlYEnd4wlIwH/w3gPycmdmQNVOjeWJhDrYKGLnjolpGRQPYRME4kjasWPbK +AWG/lpINQEB1DgtK8e6kcbUA8wSU6MMEsJjPY0o7lr9NvPfRpPXq34LjoFUXk3Hi +Bt8OuVVMo+wTmlZWkXdknFKS4IPVxUA53oJOVMFW8divmF/l676KBogSnczoX4vR +VW8sgDEKqb0NicKWJ2Fou+/KueY5OXsO8aZrZtXOsXIAMberdrNDYhyTUSYF8mZF +RdL6Jcm5GbQB/zOQElgzMwPQq5AD7SkziMzGOusWjqGmu9qphed/FimVbyRhMl5B +uDvGHthhy1KlPkqVcddN6i3/Kd/AMqXAuWMZH9FXJkUUWe+VAyeNHfEuBtSK2rqE +zf8TYGg5Gz+oNspWuqEyWUwoH7eQkRx2GIbwu2rwcIzrh8L0rsyu+6FNNHnQfnNq +ytbE888dxKkXeJ5T09Pp/hPwkNM8X8ZLcTTsAknrvqLNp2As49dP6iJwysfYLf/v +3Cyvz23JNeSQiTcC4YfKLs4LtCFkiQIzBBABCgAdFiEEN9lkrMBJgcdVAPub1V2X +iooUIOQFAmcLlJ0ACgkQ1V2XiooUIOQGJRAAsz/jYoNkSAhzvrY1t/5kSaa3Hyqi +wpaJNIb6YCNT9JFlEvfsIlikjK28I+LNqVrWoLZyX1np8h0AGfNUPo/rLzVXzqZ/ +UHZi5AjzXM6BVnR84LahFVVLISBtjt3DvY4xvl8cIh03ShJe/yAKIXZUbxXevtnj +M0/5bLaLjlVf3KldR+gFjUaTT1nxfkQnzxbk2yKe+1tuQzFsYPLG9Elzyagb4QYm +97CTxim3QcO0qWweoeusBqCkh7qD/ght76JrSnzq859XS//2jaq3A5ZsX5UJk5/E +FkzL4zersQZwQE10BByBBJbxC8DzMuGeV+eTVVHKU81cEnzZFxfyOtQBD+oHBauW +IC/v509TiH4qhZshJwcznsDZK1xAxxm3mryVtHbfSDSqzc5r/kNQt9mijD6wdsRb +0yQy1P2xkk1zyvOw3BRI2NVXq6+642cp21tjsY136JT/3a6KwIlIIdzIUqejbLoF +GgGZPJiQXthfmLpDgvduD6YgaSHyhtJesX3SIGvYBdCGT69blrB7lHazYRE/xKNu +bhnVzsaWlOXg52ChAMzsAAi5DV1669xUqRgj7zJHUq72bItZWdAvDSTIrQB4z7u8 +QW+XZsveWM2sKjzpLZjQaxdS7dFvGepYY5liA01w7Bx2lU75ejgaWrm/hlaT//RD +Al9IQzw14mOtm0e5Ag0EZwuUhAEQANmO+fv67llu3nOZh9mcTbKa0MTT6cNjpEVU +3MDImbN7pKTc/P+s6TVYBYn1q1U0XTXQlfh2HGdrLebAOdWW0Wcz4Kj9oOlRHOAR +yq3mRzb9hiCB89mJcw5xNIn83d5L/IJqONSaVLKnTwfwnTVaCJYuF5yIqDMOSXgS +C3sbGLx/yEchAhQEWUG8nm9WTybFfq98mFrHEKRGsSgfCHq6KMNn9NuhW149ZK+K +klPXZqFyDoRHdyivt9j9hfA0lr4t6sfXEfJedzjNO2f0Z8r2sQhmw3ykYDkzEF8I +zkgiik1Ke4+TmpD/4uL/hfgbkoVxZV6gI3M9rqs5o1glAuSFjsrGyog1EkUXplST +Qn4ea/vQ6t1iBkTb2r3qzhK+VL7GWlvZa9DGq8btNAiOjKKqa0+3zRTXyPJAdMQM +X+FBAhmaHJoylArEHdzv5haB7rv0aGjKV4O1ifonSGE2pllmSDbTO3exIeslLgDh +5GqVmQW30K5JvecKnb871c0utzRLHBF34HOYgRWBcl18DGD+SzXKj1//+4AatcAB +woNJHTEh6N3/mD3fJyWkyMwLJzo1x43Pmm1DkzioO9VMSxG7ReaH9WRDty3R83gT +njEI0CDkG7m0nXctrsDcmBCYMSnvriWVr7kNYQ9tSi9WUa8Cs0xCmy49fF+7ihIl +yANR2aMrABEBAAGJAjwEGAEKACYWIQSMX3FGoXV6ZeJCKpTXDRpmas8rIQUCZwuU +hAIbDAUJB4TOAAAKCRDXDRpmas8rIZPuD/4qYhAdmCtaicOjeuMI0EhKA0O0cnXv +BRwKXKGISZ6bt/f5fify78NQ4VdQzcpsRk1VvaEHRF5H+qxCQJ8MdzKcYpolCphj +ir1gE+zNP7gtzH4HOBzz3/q6GK5HmqwWth3X35ySrgrhnUZZX+plm9gRIRIqmijh +hdDp/3/2FcskQzr9UvIQDB14TbbSVAsDx5cQUM5F1nS1AAJNSrebuEcBeeM0N1HP +tqWmcJuAHtTlk+K5yk02cgbP9926vlty1uI46UyI4t/xOxmIY6gXlcSMbBnVmB0s +E+sKJTE7QrDpRRNiseCNLZcr/TNp9lrFpaUXz/JwXc+c1VC8UmARk9NLHsfoGz5H +fvhiUwl96wtvu1YKIev9nfVp1bb3/XeNAVJd+hNxOlkv68s3feutvv7vQR14E8cv +CVTXK7aAZKkWJl2n8pPohsXs5vwrsG36oFSH98jehLtzLrpgtWj6N7U8SWhI9JlT +EaIpEL/C1foVJeSZs8Tq1sqYaw81lovDFk8wuS1eFhWeEVodJQsfCPBgsQGZ46oZ +gWz3AU3KrB4ruNxjkJJxfgKu39pHDrv3o5ZufAHoIAHRdPTPlcH1Wi/1LLgLqHVC +9+i7N1ClsO1/VgtYmZwzxWxsEJOcE2+vOROoVzgMh5lGhCLh6/3VTL96hIjcMp4W +oD8ElPP+m/v6iA== +=70vD +-----END PGP PUBLIC KEY BLOCK----- diff --git a/ebtables-config b/ebtables-config new file mode 100644 index 0000000..69d9289 --- /dev/null +++ b/ebtables-config @@ -0,0 +1,11 @@ +# Save current firewall rules on stop. +# Value: yes|no, default: no +# Saves all firewall rules if firewall gets stopped +# (e.g. on system shutdown). +EBTABLES_SAVE_ON_STOP="no" + +# Save (and restore) rule counters. +# Value: yes|no, default: no +# Save rule counters when saving a kernel table to a file. If the +# rule counters were saved, they will be restored when restoring the table. +EBTABLES_SAVE_COUNTER="no" diff --git a/ebtables-helper b/ebtables-helper new file mode 100644 index 0000000..e63bd2b --- /dev/null +++ b/ebtables-helper @@ -0,0 +1,102 @@ +#!/bin/bash + +# compat for removed initscripts dependency + +success() { + echo "[ OK ]" + return 0 +} + +failure() { + echo "[FAILED]" + return 1 +} + +# internal variables +EBTABLES_CONFIG=/etc/sysconfig/ebtables-config +EBTABLES_DATA=/etc/sysconfig/ebtables +EBTABLES_TABLES="broute filter nat" +VAR_SUBSYS_EBTABLES=/var/lock/subsys/ebtables + +# ebtables-config defaults +EBTABLES_SAVE_ON_STOP="no" +EBTABLES_SAVE_ON_RESTART="no" +EBTABLES_SAVE_COUNTER="no" + +# load config if existing +[ -f "$EBTABLES_CONFIG" ] && . "$EBTABLES_CONFIG" + +initialize() { + local ret=0 + for table in $EBTABLES_TABLES; do + ebtables -t $table --init-table || ret=1 + done + return $ret +} + +sanitize_dump() { + local drop=false + + export EBTABLES_TABLES + + cat $1 | while read line; do + case $line in + \**) + drop=false + local table="${line#\*}" + local found=false + for t in $EBTABLES_TABLES; do + if [[ $t == $table ]]; then + found=true + break + fi + done + $found || drop=true + ;; + esac + $drop || echo "$line" + done +} + +start() { + if [ -f $EBTABLES_DATA ]; then + echo -n $"ebtables: loading ruleset from $EBTABLES_DATA: " + sanitize_dump $EBTABLES_DATA | ebtables-restore + else + echo -n $"ebtables: no stored ruleset, initializing empty tables: " + initialize + fi + local ret=$? + touch $VAR_SUBSYS_EBTABLES + return $ret +} + +save() { + echo -n $"ebtables: saving active ruleset to $EBTABLES_DATA: " + export EBTABLES_SAVE_COUNTER + ebtables-save >$EBTABLES_DATA && success || failure +} + +case $1 in + start) + [ -f "$VAR_SUBSYS_EBTABLES" ] && exit 0 + start && success || failure + RETVAL=$? + ;; + stop) + [ "x$EBTABLES_SAVE_ON_STOP" = "xyes" ] && save + echo -n $"ebtables: stopping firewall: " + initialize && success || failure + RETVAL=$? + rm -f $VAR_SUBSYS_EBTABLES + ;; + save) + save + ;; + *) + echo "usage: ${0##*/} {start|stop|save}" >&2 + RETVAL=2 + ;; +esac + +exit $RETVAL diff --git a/ebtables.service b/ebtables.service new file mode 100644 index 0000000..b096f1d --- /dev/null +++ b/ebtables.service @@ -0,0 +1,11 @@ +[Unit] +Description=Ethernet Bridge Filtering tables + +[Service] +Type=oneshot +RemainAfterExit=yes +ExecStart=/usr/libexec/ebtables-helper start +ExecStop=/usr/libexec/ebtables-helper stop + +[Install] +WantedBy=multi-user.target diff --git a/iptables-1.8.11-command-options-fix.patch b/iptables-1.8.11-command-options-fix.patch new file mode 100644 index 0000000..f6eecb1 --- /dev/null +++ b/iptables-1.8.11-command-options-fix.patch @@ -0,0 +1,27 @@ +commit 192c3a6bc18f206895ec5e38812d648ccfe7e281 +Author: Phil Sutter +Date: Wed Apr 23 12:36:13 2025 +0200 + + xshared: Accept an option if any given command allows it + + Fixed commit made option checking overly strict: Some commands may be + commbined (foremost --list and --zero), reject a given option only if it + is not allowed by any of the given commands. + + Reported-by: Adam Nielsen + Fixes: 9c09d28102bb4 ("xshared: Simplify generic_opt_check()") + Signed-off-by: Phil Sutter + +diff --git a/iptables/xshared.c b/iptables/xshared.c +index cdfd11ab..fc61e0fd 100644 +--- a/iptables/xshared.c ++++ b/iptables/xshared.c +@@ -980,7 +980,7 @@ static void generic_opt_check(struct xt_cmd_parse_ops *ops, + */ + for (i = 0, optval = 1; i < NUMBER_OF_OPT; optval = (1 << ++i)) { + if ((options & optval) && +- (options_v_commands[i] & command) != command) ++ !(options_v_commands[i] & command)) + xtables_error(PARAMETER_PROBLEM, + "Illegal option `%s' with this command", + ops->option_name(optval)); diff --git a/iptables-1.8.11-fix-interface-comparisons.patch b/iptables-1.8.11-fix-interface-comparisons.patch new file mode 100644 index 0000000..b038616 --- /dev/null +++ b/iptables-1.8.11-fix-interface-comparisons.patch @@ -0,0 +1,172 @@ +From 40406dbfaefbc204134452b2747bae4f6a122848 Mon Sep 17 00:00:00 2001 +From: Jeremy Sowden +Date: Mon, 18 Nov 2024 13:56:50 +0000 +Subject: nft: fix interface comparisons in `-C` commands + +Commit 9ccae6397475 ("nft: Leave interface masks alone when parsing from +kernel") removed code which explicitly set interface masks to all ones. The +result of this is that they are zero. However, they are used to mask interfaces +in `is_same_interfaces`. Consequently, the masked values are alway zero, the +comparisons are always true, and check commands which ought to fail succeed: + + # iptables -N test + # iptables -A test -i lo \! -o lo -j REJECT + # iptables -v -L test + Chain test (0 references) + pkts bytes target prot opt in out source destination + 0 0 REJECT all -- lo !lo anywhere anywhere reject-with icmp-port-unreachable + # iptables -v -C test -i abcdefgh \! -o abcdefgh -j REJECT + REJECT all opt -- in lo out !lo 0.0.0.0/0 -> 0.0.0.0/0 reject-with icmp-port-unreachable + +Remove the mask parameters from `is_same_interfaces`. Add a test-case. + +Fixes: 9ccae6397475 ("nft: Leave interface masks alone when parsing from kernel") +Signed-off-by: Jeremy Sowden +Signed-off-by: Phil Sutter +--- + iptables/nft-arp.c | 10 ++---- + iptables/nft-ipv4.c | 4 +-- + iptables/nft-ipv6.c | 6 +--- + iptables/nft-shared.c | 36 +++++----------------- + iptables/nft-shared.h | 6 +--- + .../testcases/nft-only/0020-compare-interfaces_0 | 9 ++++++ + 6 files changed, 22 insertions(+), 49 deletions(-) + create mode 100755 iptables/tests/shell/testcases/nft-only/0020-compare-interfaces_0 + +diff --git a/iptables/nft-arp.c b/iptables/nft-arp.c +index 264864c3..c11d64c3 100644 +--- a/iptables/nft-arp.c ++++ b/iptables/nft-arp.c +@@ -385,14 +385,8 @@ static bool nft_arp_is_same(const struct iptables_command_state *cs_a, + return false; + } + +- return is_same_interfaces(a->arp.iniface, +- a->arp.outiface, +- (unsigned char *)a->arp.iniface_mask, +- (unsigned char *)a->arp.outiface_mask, +- b->arp.iniface, +- b->arp.outiface, +- (unsigned char *)b->arp.iniface_mask, +- (unsigned char *)b->arp.outiface_mask); ++ return is_same_interfaces(a->arp.iniface, a->arp.outiface, ++ b->arp.iniface, b->arp.outiface); + } + + static void nft_arp_save_chain(const struct nftnl_chain *c, const char *policy) +diff --git a/iptables/nft-ipv4.c b/iptables/nft-ipv4.c +index 74092875..0c8bd291 100644 +--- a/iptables/nft-ipv4.c ++++ b/iptables/nft-ipv4.c +@@ -113,9 +113,7 @@ static bool nft_ipv4_is_same(const struct iptables_command_state *a, + } + + return is_same_interfaces(a->fw.ip.iniface, a->fw.ip.outiface, +- a->fw.ip.iniface_mask, a->fw.ip.outiface_mask, +- b->fw.ip.iniface, b->fw.ip.outiface, +- b->fw.ip.iniface_mask, b->fw.ip.outiface_mask); ++ b->fw.ip.iniface, b->fw.ip.outiface); + } + + static void nft_ipv4_set_goto_flag(struct iptables_command_state *cs) +diff --git a/iptables/nft-ipv6.c b/iptables/nft-ipv6.c +index b184f8af..4dbb2af2 100644 +--- a/iptables/nft-ipv6.c ++++ b/iptables/nft-ipv6.c +@@ -99,11 +99,7 @@ static bool nft_ipv6_is_same(const struct iptables_command_state *a, + } + + return is_same_interfaces(a->fw6.ipv6.iniface, a->fw6.ipv6.outiface, +- a->fw6.ipv6.iniface_mask, +- a->fw6.ipv6.outiface_mask, +- b->fw6.ipv6.iniface, b->fw6.ipv6.outiface, +- b->fw6.ipv6.iniface_mask, +- b->fw6.ipv6.outiface_mask); ++ b->fw6.ipv6.iniface, b->fw6.ipv6.outiface); + } + + static void nft_ipv6_set_goto_flag(struct iptables_command_state *cs) +diff --git a/iptables/nft-shared.c b/iptables/nft-shared.c +index 6775578b..2c29e68f 100644 +--- a/iptables/nft-shared.c ++++ b/iptables/nft-shared.c +@@ -220,36 +220,16 @@ void add_l4proto(struct nft_handle *h, struct nftnl_rule *r, + } + + bool is_same_interfaces(const char *a_iniface, const char *a_outiface, +- unsigned const char *a_iniface_mask, +- unsigned const char *a_outiface_mask, +- const char *b_iniface, const char *b_outiface, +- unsigned const char *b_iniface_mask, +- unsigned const char *b_outiface_mask) ++ const char *b_iniface, const char *b_outiface) + { +- int i; +- +- for (i = 0; i < IFNAMSIZ; i++) { +- if (a_iniface_mask[i] != b_iniface_mask[i]) { +- DEBUGP("different iniface mask %x, %x (%d)\n", +- a_iniface_mask[i] & 0xff, b_iniface_mask[i] & 0xff, i); +- return false; +- } +- if ((a_iniface[i] & a_iniface_mask[i]) +- != (b_iniface[i] & b_iniface_mask[i])) { +- DEBUGP("different iniface\n"); +- return false; +- } +- if (a_outiface_mask[i] != b_outiface_mask[i]) { +- DEBUGP("different outiface mask\n"); +- return false; +- } +- if ((a_outiface[i] & a_outiface_mask[i]) +- != (b_outiface[i] & b_outiface_mask[i])) { +- DEBUGP("different outiface\n"); +- return false; +- } ++ if (strncmp(a_iniface, b_iniface, IFNAMSIZ)) { ++ DEBUGP("different iniface\n"); ++ return false; ++ } ++ if (strncmp(a_outiface, b_outiface, IFNAMSIZ)) { ++ DEBUGP("different outiface\n"); ++ return false; + } +- + return true; + } + +diff --git a/iptables/nft-shared.h b/iptables/nft-shared.h +index 51d1e460..b57aee1f 100644 +--- a/iptables/nft-shared.h ++++ b/iptables/nft-shared.h +@@ -105,11 +105,7 @@ void add_l4proto(struct nft_handle *h, struct nftnl_rule *r, uint8_t proto, uint + void add_compat(struct nftnl_rule *r, uint32_t proto, bool inv); + + bool is_same_interfaces(const char *a_iniface, const char *a_outiface, +- unsigned const char *a_iniface_mask, +- unsigned const char *a_outiface_mask, +- const char *b_iniface, const char *b_outiface, +- unsigned const char *b_iniface_mask, +- unsigned const char *b_outiface_mask); ++ const char *b_iniface, const char *b_outiface); + + void __get_cmp_data(struct nftnl_expr *e, void *data, size_t dlen, uint8_t *op); + void get_cmp_data(struct nftnl_expr *e, void *data, size_t dlen, bool *inv); +diff --git a/iptables/tests/shell/testcases/nft-only/0020-compare-interfaces_0 b/iptables/tests/shell/testcases/nft-only/0020-compare-interfaces_0 +new file mode 100755 +index 00000000..278cd648 +--- /dev/null ++++ b/iptables/tests/shell/testcases/nft-only/0020-compare-interfaces_0 +@@ -0,0 +1,9 @@ ++#!/bin/bash ++ ++[[ $XT_MULTI == *xtables-nft-multi ]] || { echo "skip $XT_MULTI"; exit 0; } ++ ++$XT_MULTI iptables -N test ++$XT_MULTI iptables -A test -i lo \! -o lo -j REJECT ++$XT_MULTI iptables -C test -i abcdefgh \! -o abcdefgh -j REJECT 2>/dev/null && exit 1 ++ ++exit 0 +-- +cgit v1.2.3 + diff --git a/iptables.spec b/iptables.spec index 7c995da..c999d94 100644 --- a/iptables.spec +++ b/iptables.spec @@ -10,26 +10,27 @@ Name: iptables Summary: Tools for managing Linux kernel packet filtering capabilities URL: https://www.netfilter.org/projects/iptables -Version: 1.8.10 -Release: 7%{?dist} -Source: %{url}/files/%{name}-%{version}.tar.xz -Source1: iptables.init -Source2: iptables-config -Source3: iptables.service -Source4: sysconfig_iptables -Source5: sysconfig_ip6tables -Source6: arptables-nft-helper - -Patch001: 0001-libiptc-Fix-for-another-segfault-due-to-chain-index-.patch -Patch002: 0002-arptables-nft-remove-ARPT_INV-flags-usage.patch -Patch003: 0003-ebtables-Fix-corner-case-noflush-restore-bug.patch -Patch004: 0004-xshared-struct-xt_cmd_parse-xlate-is-unused.patch -Patch005: 0005-xshared-All-variants-support-v-update-OPTSTRING_COMM.patch -Patch006: 0006-ebtables-Align-line-number-formatting-with-legacy.patch -Patch007: 0007-man-Do-not-escape-exclamation-marks.patch -Patch008: 0008-libxtables-xtoptions-Fix-for-non-CIDR-compatible-hos.patch -Patch009: 0009-iptables-legacy-Fix-for-mandatory-lock-waiting.patch -Patch010: 0010-libxtables-xtoptions-Prevent-XTOPT_PUT-with-XTTYPE_H.patch +Version: 1.8.11 +Release: 12%{?dist} +Source0: %{url}/files/%{name}-%{version}.tar.xz +source1: %{url}/files/%{name}-%{version}.tar.xz.sig +Source2: coreteam-gpg-key-0xD70D1A666ACF2B21.txt +Source3: iptables.init +Source4: iptables-config +Source5: iptables.service +Source6: sysconfig_iptables +Source7: sysconfig_ip6tables +Source8: arptables-helper +Source9: arptables.service +Source10: ebtables.service +Source11: ebtables-helper +Source12: ebtables-config +# Patch to fix -C handling, already upstream +# https://git.netfilter.org/iptables/patch/?id=40406dbfaefbc204134452b2747bae4f6a122848 +Patch1: iptables-1.8.11-fix-interface-comparisons.patch +# Patch to fix overly strict command option checking +# https://git.netfilter.org/iptables/patch/?id=192c3a6bc18f206895ec5e38812d648ccfe7e281 +Patch2: iptables-1.8.11-command-options-fix.patch # pf.os: ISC license # iptables-apply: Artistic Licence 2.0 @@ -37,7 +38,7 @@ License: GPL-2.0-only AND Artistic-2.0 AND ISC # libnetfilter_conntrack is needed for xt_connlabel BuildRequires: pkgconfig(libnetfilter_conntrack) -# libnfnetlink-devel is requires for nfnl_osf +# libnfnetlink-devel is required for nfnl_osf BuildRequires: pkgconfig(libnfnetlink) BuildRequires: libselinux-devel BuildRequires: kernel-headers @@ -54,6 +55,7 @@ BuildRequires: autoconf BuildRequires: automake BuildRequires: libtool BuildRequires: make +BuildRequires: gnupg2 %description The iptables utility controls the network packet filtering code in the @@ -65,6 +67,7 @@ Summary: Legacy tools for managing Linux kernel packet filtering capabilities Requires: %{name}-legacy-libs%{?_isa} = %{version}-%{release} Requires: %{name}-libs%{?_isa} = %{version}-%{release} Conflicts: setup < 2.10.4-1 +Conflicts: alternatives < 1.32-1 Requires(post): /usr/sbin/update-alternatives Requires(postun): /usr/sbin/update-alternatives %if 0%{?rhel} < 9 @@ -73,6 +76,8 @@ Provides: iptables Provides: %{name}-compat = %{version}-%{release} Obsoletes: %{name}-compat < 1.8.9-7 +%sbin_merge_compat %{_prefix}/sbin/iptables + %description legacy The iptables utility controls the network packet filtering code in the Linux kernel. This package contains the legacy tools which are obsoleted by @@ -95,9 +100,8 @@ Summary: iptables legacy libraries %description legacy-libs iptables libraries. -Please remember that libip*tc libraries do neither have a stable API nor a real so version. - -For more information about this, please have a look at +Please remember that libip*tc libraries do neither have a stable API nor a real +so version. For more information about this, please have a look at http://www.netfilter.org/documentation/FAQ/netfilter-faq-4.html#ss4.5 @@ -131,6 +135,14 @@ Requires: %{name}-utils = %{version}-%{release} Obsoletes: %{name} < 1.4.16.1 # obsolete ipv6 sub package Obsoletes: %{name}-ipv6 < 1.4.11.1 +# Look at me, I'm the new arptables-services now! +Conflicts: %{name}-nft < 1.8.11-5 +Obsoletes: arptables-services < 0.0.5-16 +Provides: arptables-services = %{version}-%{release} +# Look at me, I'm the new ebtables-services now! +# (With epoch to turn our version number higher value) +Obsoletes: ebtables-services < 2.0.11-20 +Provides: ebtables-services = 1:%{version}-%{release} BuildArch: noarch %description services @@ -161,11 +173,17 @@ Provides: arptables-helper Provides: iptables Provides: arptables Provides: ebtables +# allowing old arptables-legacy will break when switching alternatives +# due to the dropped arptables-helper symlink +Conflicts: arptables-legacy < 0.0.5-16 + +%sbin_merge_compat %{_prefix}/sbin/iptables %description nft nftables compatibility for iptables, arptables and ebtables. %prep +%{gpgverify} --keyring='%{SOURCE2}' --signature='%{SOURCE1}' --data='%{SOURCE0}' %autosetup -p1 %build @@ -188,20 +206,24 @@ rm -f %{buildroot}%{_libdir}/*.la # install init scripts and configuration files install -d -m 755 %{buildroot}%{script_path} -install -c -m 755 %{SOURCE1} %{buildroot}%{script_path}/iptables.init -sed -e 's;iptables;ip6tables;g' -e 's;IPTABLES;IP6TABLES;g' < %{SOURCE1} > ip6tables.init +install -c -m 755 %{SOURCE3} %{buildroot}%{script_path}/iptables.init +sed -e 's;iptables;ip6tables;g' -e 's;IPTABLES;IP6TABLES;g' < %{SOURCE3} > ip6tables.init install -c -m 755 ip6tables.init %{buildroot}%{script_path}/ip6tables.init +install -p -m 755 %{SOURCE8} %{SOURCE11} %{buildroot}%{_libexecdir}/ install -d -m 755 %{buildroot}%{_sysconfdir}/sysconfig -install -c -m 600 %{SOURCE2} %{buildroot}%{_sysconfdir}/sysconfig/iptables-config -sed -e 's;iptables;ip6tables;g' -e 's;IPTABLES;IP6TABLES;g' < %{SOURCE2} > ip6tables-config +install -c -m 600 %{SOURCE4} %{buildroot}%{_sysconfdir}/sysconfig/iptables-config +sed -e 's;iptables;ip6tables;g' -e 's;IPTABLES;IP6TABLES;g' < %{SOURCE4} > ip6tables-config install -c -m 600 ip6tables-config %{buildroot}%{_sysconfdir}/sysconfig/ip6tables-config -install -c -m 600 %{SOURCE4} %{buildroot}%{_sysconfdir}/sysconfig/iptables -install -c -m 600 %{SOURCE5} %{buildroot}%{_sysconfdir}/sysconfig/ip6tables +install -c -m 600 %{SOURCE6} %{buildroot}%{_sysconfdir}/sysconfig/iptables +install -c -m 600 %{SOURCE7} %{buildroot}%{_sysconfdir}/sysconfig/ip6tables +echo '# Configure prior to use' > %{buildroot}%{_sysconfdir}/sysconfig/arptables +install -c -m 600 %{SOURCE12} %{buildroot}%{_sysconfdir}/sysconfig/ +touch %{buildroot}%{_sysconfdir}/sysconfig/ebtables # install systemd service files install -d -m 755 %{buildroot}/%{_unitdir} -install -c -m 644 %{SOURCE3} %{buildroot}/%{_unitdir} -sed -e 's;iptables;ip6tables;g' -e 's;IPv4;IPv6;g' -e 's;/usr/libexec/ip6tables;/usr/libexec/iptables;g' < %{SOURCE3} > ip6tables.service +install -c -m 644 %{SOURCE5} %{SOURCE9} %{SOURCE10} %{buildroot}/%{_unitdir} +sed -e 's;iptables;ip6tables;g' -e 's;IPv4;IPv6;g' -e 's;/usr/libexec/ip6tables;/usr/libexec/iptables;g' < %{SOURCE5} > ip6tables.service install -c -m 644 ip6tables.service %{buildroot}/%{_unitdir} # install legacy actions for service command @@ -227,35 +249,42 @@ install -c -m 755 ip6tabes.panic-legacy %{buildroot}/%{legacy_actions}/ip6tables # Remove /etc/ethertypes (now part of setup) rm -f %{buildroot}%{_sysconfdir}/ethertypes -install -p -D -m 755 %{SOURCE6} %{buildroot}%{_libexecdir}/ -touch %{buildroot}%{_libexecdir}/arptables-helper - # prepare for alternatives touch %{buildroot}%{_mandir}/man8/arptables.8 touch %{buildroot}%{_mandir}/man8/arptables-save.8 touch %{buildroot}%{_mandir}/man8/arptables-restore.8 touch %{buildroot}%{_mandir}/man8/ebtables.8 +rm %{buildroot}%{_sbindir}/{ip,ip6,arp,eb}tables{,-save,-restore} +touch %{buildroot}%{_sbindir}/{ip,ip6,arp,eb}tables{,-save,-restore} # fix absolute symlink -rm -f %{buildroot}%{_bindir}/iptables-xml -ln -s ../sbin/xtables-legacy-multi %{buildroot}%{_bindir}/iptables-xml +ln -sf --relative %{buildroot}%{_sbindir}/xtables-legacy-multi %{buildroot}%{_bindir}/iptables-xml %ldconfig_scriptlets %post legacy pfx=%{_sbindir}/iptables pfx6=%{_sbindir}/ip6tables -/usr/sbin/update-alternatives --install \ +update-alternatives --install \ $pfx iptables $pfx-legacy 10 \ - --slave $pfx6 ip6tables $pfx6-legacy \ - --slave $pfx-restore iptables-restore $pfx-legacy-restore \ - --slave $pfx-save iptables-save $pfx-legacy-save \ - --slave $pfx6-restore ip6tables-restore $pfx6-legacy-restore \ - --slave $pfx6-save ip6tables-save $pfx6-legacy-save + --follower $pfx6 ip6tables $pfx6-legacy \ + --follower $pfx-restore iptables-restore $pfx-legacy-restore \ + --follower $pfx-save iptables-save $pfx-legacy-save \ + --follower $pfx6-restore ip6tables-restore $pfx6-legacy-restore \ + --follower $pfx6-save ip6tables-save $pfx6-legacy-save + +%if "%{_sbindir}" == "%{_bindir}" +# Make sure that symlinks in /usr/sbin/ are not missing, if /usr/sbin is a +# directory. Those symlinks will only be created if there is no symlink +# or file already. +for name in ip{,6}tables{,-save,-restore}; do + test -h /usr/sbin || ln -s ../bin/$name /usr/sbin/$name 2>/dev/null || : +done +%endif %postun legacy if [ $1 -eq 0 ]; then - /usr/sbin/update-alternatives --remove \ + update-alternatives --remove \ iptables %{_sbindir}/iptables-legacy fi @@ -271,84 +300,100 @@ cp /var/lib/alternatives/iptables /var/tmp/alternatives.iptables.setup %triggerpostun legacy -- iptables > 1.8.0 pfx=%{_sbindir}/iptables pfx6=%{_sbindir}/ip6tables -/usr/sbin/update-alternatives --install \ +update-alternatives --install \ $pfx iptables $pfx-legacy 10 \ - --slave $pfx6 ip6tables $pfx6-legacy \ - --slave $pfx-restore iptables-restore $pfx-legacy-restore \ - --slave $pfx-save iptables-save $pfx-legacy-save \ - --slave $pfx6-restore ip6tables-restore $pfx6-legacy-restore \ - --slave $pfx6-save ip6tables-save $pfx6-legacy-save + --follower $pfx6 ip6tables $pfx6-legacy \ + --follower $pfx-restore iptables-restore $pfx-legacy-restore \ + --follower $pfx-save iptables-save $pfx-legacy-save \ + --follower $pfx6-restore ip6tables-restore $pfx6-legacy-restore \ + --follower $pfx6-save ip6tables-save $pfx6-legacy-save alternatives --set iptables $(/dev/null || : +done +%endif + %post services +%systemd_post arptables.service ebtables.service %systemd_post iptables.service ip6tables.service %preun services +%systemd_preun arptables.service ebtables.service %systemd_preun iptables.service ip6tables.service %postun services %?ldconfig +%systemd_postun arptables.service ebtables.service %systemd_postun iptables.service ip6tables.service %post -e nft [[ %%{_excludedocs} == 1 ]] || do_man=true +# remove non-symlinks in spots managed by alternatives +# to cover for updates from not-yet-alternatived versions +for pfx in %{_prefix}/sbin/{eb,arp}tables; do + for sfx in "" "-restore" "-save"; do + if [ "$(readlink -e $pfx$sfx)" == $pfx$sfx ]; then + rm -f $pfx$sfx + fi + done +done +for manpfx in %{_mandir}/man8/{eb,arp}tables; do + for sfx in {,-restore,-save}.8.gz; do + if [ "$(readlink -e $manpfx$sfx)" == $manpfx$sfx ]; then + rm -f $manpfx$sfx + fi + done +done + pfx=%{_sbindir}/iptables pfx6=%{_sbindir}/ip6tables -/usr/sbin/update-alternatives --install \ +update-alternatives --install \ $pfx iptables $pfx-nft 10 \ - --slave $pfx6 ip6tables $pfx6-nft \ - --slave $pfx-restore iptables-restore $pfx-nft-restore \ - --slave $pfx-save iptables-save $pfx-nft-save \ - --slave $pfx6-restore ip6tables-restore $pfx6-nft-restore \ - --slave $pfx6-save ip6tables-save $pfx6-nft-save + --follower $pfx6 ip6tables $pfx6-nft \ + --follower $pfx-restore iptables-restore $pfx-nft-restore \ + --follower $pfx-save iptables-save $pfx-nft-save \ + --follower $pfx6-restore ip6tables-restore $pfx6-nft-restore \ + --follower $pfx6-save ip6tables-save $pfx6-nft-save pfx=%{_sbindir}/ebtables manpfx=%{_mandir}/man8/ebtables -for sfx in "" "-restore" "-save"; do - if [ "$(readlink -e $pfx$sfx)" == $pfx$sfx ]; then - rm -f $pfx$sfx - fi -done -if [ "$(readlink -e $manpfx.8.gz)" == $manpfx.8.gz ]; then - rm -f $manpfx.8.gz -fi -/usr/sbin/update-alternatives --install \ +update-alternatives --install \ $pfx ebtables $pfx-nft 10 \ - --slave $pfx-save ebtables-save $pfx-nft-save \ - --slave $pfx-restore ebtables-restore $pfx-nft-restore \ - ${do_man:+--slave $manpfx.8.gz ebtables-man $manpfx-nft.8.gz} + --follower $pfx-save ebtables-save $pfx-nft-save \ + --follower $pfx-restore ebtables-restore $pfx-nft-restore \ + ${do_man:+--follower $manpfx.8.gz ebtables-man $manpfx-nft.8.gz} pfx=%{_sbindir}/arptables manpfx=%{_mandir}/man8/arptables -lepfx=%{_libexecdir}/arptables -for sfx in "" "-restore" "-save"; do - if [ "$(readlink -e $pfx$sfx)" == $pfx$sfx ]; then - rm -f $pfx$sfx - fi - if [ "$(readlink -e $manpfx$sfx.8.gz)" == $manpfx$sfx.8.gz ]; then - rm -f $manpfx$sfx.8.gz - fi -done -if [ "$(readlink -e $lepfx-helper)" == $lepfx-helper ]; then - rm -f $lepfx-helper -fi -/usr/sbin/update-alternatives --install \ +update-alternatives --install \ $pfx arptables $pfx-nft 10 \ - --slave $pfx-save arptables-save $pfx-nft-save \ - --slave $pfx-restore arptables-restore $pfx-nft-restore \ - ${do_man:+--slave $manpfx.8.gz arptables-man $manpfx-nft.8.gz} \ - ${do_man:+--slave $manpfx-save.8.gz arptables-save-man $manpfx-nft-save.8.gz} \ - ${do_man:+--slave $manpfx-restore.8.gz arptables-restore-man $manpfx-nft-restore.8.gz} \ - --slave $lepfx-helper arptables-helper $lepfx-nft-helper + --follower $pfx-save arptables-save $pfx-nft-save \ + --follower $pfx-restore arptables-restore $pfx-nft-restore \ + ${do_man:+--follower $manpfx.8.gz arptables-man $manpfx-nft.8.gz} \ + ${do_man:+--follower $manpfx-save.8.gz arptables-save-man $manpfx-nft-save.8.gz} \ + ${do_man:+--follower $manpfx-restore.8.gz arptables-restore-man $manpfx-nft-restore.8.gz} + +%if "%{_sbindir}" == "%{_bindir}" +# Make sure that symlinks in /usr/sbin/ are not missing, if /usr/sbin is a +# directory. Those symlinks will only be created if there is no symlink +# or file already. +for name in ip{,6}tables{,-save,-restore} ebtables{,-save,-restore} arptables{,-save,-restore}; do + test -h /usr/sbin || ln -s ../bin/$name /usr/sbin/$name 2>/dev/null || : +done +%endif %postun nft if [ $1 -eq 0 ]; then for cmd in iptables ebtables arptables; do - /usr/sbin/update-alternatives --remove \ - $cmd %{_sbindir}/$cmd-nft + update-alternatives --remove $cmd %{_sbindir}/$cmd-nft done fi @@ -358,8 +403,9 @@ fi %{_bindir}/iptables-xml %{_mandir}/man1/iptables-xml* %{_mandir}/man8/xtables-legacy* +%dir %{_datadir}/xtables %{_datadir}/xtables/iptables.xslt -%ghost %{_sbindir}/ip{,6}tables{,-save,-restore} +%ghost %attr(0755,root,root) %{_sbindir}/ip{,6}tables{,-save,-restore} %files libs %license COPYING @@ -388,9 +434,13 @@ fi %dir %{script_path} %{script_path}/ip{,6}tables.init %config(noreplace) %{_sysconfdir}/sysconfig/ip{,6}tables{,-config} -%{_unitdir}/ip{,6}tables.service +%config(noreplace) %{_sysconfdir}/sysconfig/arptables +%config(noreplace) %{_sysconfdir}/sysconfig/ebtables-config +%ghost %{_sysconfdir}/sysconfig/ebtables +%{_unitdir}/{arp,eb,ip,ip6}tables.service %dir %{legacy_actions}/ip{,6}tables %{legacy_actions}/ip{,6}tables/{save,panic} +%{_libexecdir}/{arp,eb}tables-helper %files utils %license COPYING @@ -410,22 +460,83 @@ fi %{_sbindir}/xtables-nft-multi %{_sbindir}/xtables-monitor %{_sbindir}/ebtables-translate +%{_sbindir}/arptables-translate %dir %{_libdir}/xtables %{_libdir}/xtables/lib{arp,eb}t* -%{_libexecdir}/arptables-nft-helper %{_mandir}/man8/xtables-monitor* %{_mandir}/man8/xtables-translate* %{_mandir}/man8/*-nft* %{_mandir}/man8/ip{,6}tables{,-restore}-translate* %{_mandir}/man8/ebtables-translate* -%ghost %{_sbindir}/ip{,6}tables{,-save,-restore} -%ghost %{_sbindir}/{eb,arp}tables{,-save,-restore} -%ghost %{_libexecdir}/arptables-helper +%{_mandir}/man8/arptables-translate* +%ghost %attr(0755,root,root) %{_sbindir}/ip{,6}tables{,-save,-restore} +%ghost %attr(0755,root,root) %{_sbindir}/{eb,arp}tables{,-save,-restore} %ghost %{_mandir}/man8/arptables{,-save,-restore}.8.gz %ghost %{_mandir}/man8/ebtables.8.gz %changelog +* Tue Oct 28 2025 Paul Wouters - 1.8.11-12 +- Pull in upstream fix for too strict command option parsing + +* Thu Jul 24 2025 Fedora Release Engineering - 1.8.11-11 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild + +* Tue May 20 2025 Phil Sutter - 1.8.11-10 +- Fix for ghost files not present in iptables-nft RPM + +* Wed May 07 2025 Zbigniew Jedrzejewski-Szmek - 1.8.11-9 +- Reapply the change to keep symlinks managed by alternatives under /usr/bin, + this time with a scriptlet create symlinks if /usr/sbin is unmerged. + +* Sat May 03 2025 Phil Sutter - 1.8.11-8 +- Revert last release, it breaks alternatives symlinks + +* Fri Apr 25 2025 Zbigniew Jedrzejewski-Szmek - 1.8.11-7 +- Keep symlinks managed by alternatives under /usr/bin + +* Sun Apr 20 2025 Kevin Fenzi - 1.8.11-6 +- Add patch to fix -C handling ( fixes rhbz#2360423 ) + +* Thu Apr 03 2025 Phil Sutter - 1.8.11-5 +- iptables-services to assimilate arptables- and ebtables-services + +* Fri Jan 17 2025 Fedora Release Engineering +- Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild + +* Tue Jan 14 2025 Zbigniew Jedrzejewski-Szmek - 1.8.11-3 +- Keep symlinks managed by alternatives under /usr/sbin + +* Sun Jan 12 2025 Zbigniew Jędrzejewski-Szmek - 1.8.11-2 +- Rebuilt for the bin-sbin merge (2nd attempt) + +* Fri Nov 08 2024 Phil Sutter - 1.8.11-1 +- new version + +* Thu Jul 18 2024 Fedora Release Engineering - 1.8.10-15 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_41_Mass_Rebuild + +* Sat Jul 13 2024 Zbigniew Jędrzejewski-Szmek - 1.8.10-14 +- Add unmerged-sbin compat also for -legacy subpackage + +* Fri Jul 12 2024 Zbigniew Jędrzejewski-Szmek - 1.8.10-13 +- Bump release and add changelog entry + +* Tue Jul 09 2024 Zbigniew Jędrzejewski-Szmek - 1.8.10-12 +- Rebuilt for the bin-sbin merge + +* Fri Jul 05 2024 Phil Sutter - 1.8.10-11 +- Add missing build dependency + +* Fri Jul 05 2024 Phil Sutter - 1.8.10-10 +- Verify tarball GPG signature + +* Wed Jul 03 2024 Phil Sutter - 1.8.10-9 +- Backport fixes from upstream + +* Tue May 21 2024 Phil Sutter - 1.8.10-8 +- Make iptables-legacy own %%{_datadir}/xtables + * Wed Jan 24 2024 Fedora Release Engineering - 1.8.10-7 - Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild diff --git a/sources b/sources index 59e259b..1f7b750 100644 --- a/sources +++ b/sources @@ -1 +1,2 @@ -SHA512 (iptables-1.8.10.tar.xz) = 71e6ed2260859157d61981a4fe5039dc9e8d7da885a626a4b5dae8164c509a9d9f874286b9468bb6a462d6e259d4d32d5967777ecefdd8a293011ae80c00f153 +SHA512 (iptables-1.8.11.tar.xz) = 4937020bf52d57a45b76e1eba125214a2f4531de52ff1d15185faeef8bea0cd90eb77f99f81baa573944aa122f350a7198cef41d70594e1b65514784addbcc40 +SHA512 (iptables-1.8.11.tar.xz.sig) = 8bde9436b6c6c9d97d9b1cadc417035c209e39b49111ea08fe35b714bbf94721ad0b8b2870791d3bf98154f64912109c6bdeb0ee33f954d0d3a8c3582a97f3f2