[netfilter-cvslog] [IPtables] annotated tag, svn_t_iptables_1_3_6, created. svn_t_iptables_1_3_6

Patrick McHardy netfilter-cvslog-bounces at lists.netfilter.org
Wed May 14 19:11:24 CEST 2008


Gitweb:		http://git.netfilter.org/cgi-bin/gitweb.cgi?p=iptables.git;a=commit;h=b107cd81af265f56cba91fccdca2f4a9878027e4
Commit:		b107cd81af265f56cba91fccdca2f4a9878027e4
Parent:		0000000000000000000000000000000000000000

The annotated tag, svn_t_iptables_1_3_6 has been created
        at  b107cd81af265f56cba91fccdca2f4a9878027e4 (tag)
   tagging  685d14eeb02e906c8f7a83e248cab2bc1ec40f27 (commit)
  replaces  svn_t_iptables_1_3_5
 tagged by  Patrick McHardy
        on  Wed May 14 18:58:01 2008 +0200

- Log -----------------------------------------------------------------
Tag svn_t_iptables_1_3_6

/C=DE/ST=Berlin/L=Berlin/O=Netfilter Project/OU=Development/CN=kaber/emailAddress=kaber at netfilter.org (34):
      don't allow to specify protocol of IPv6 extension header (Yasuyuki Kozakai)
      : Correct iptables-save output of osf module (Daniel De Graaf)
      Revert incorrect fix for "Unknown error 4294967295" problem
      Don't overwrite errno with return value of setsockopt (which is -1 on error).
      Replace annoying "Something wrong... deleting dependencies" message by something more useful.
      Add DCCP/SCTP support to multiport. Patch for kernel will go in 2.6.18.
      secmark: Add libselinux support
      secmark: Add libipt_SECMARK
      secmark: Add libip6t_SECMARK
      secmark: Add libipt_CONNSECMARK
      D'oh .. I'm not too smart, forgot to add the new files in the previous patches :)
      secmark: Add libip6t_CONNSECMARK
      Add information about :<port> syntax (Evan Miller <evanm at frap.net>)
      Use lowercase letters for match name (Simon Lodal <simonl at parknet.dk>)
      trivial connlimit manpage fix (Phil Oester <kernel at linuxace.com>)
      : Add new exit value to indicate concurrency issues (Jesper Dangaard Brouer <hawk at comx.dk>)
      REDIRECT does not accept IP (Phil Oester <kernel at linuxace.com>)
      iptables trivial compile warning cleanup (Phil Oester <kernel at linuxace.com>)
      ip6tables multiport does not support x:y (Phil Oester <kernel at linuxace.com>)
      libiptc symbols clash (Phil Oester <kernel at linuxace.com>)
      please kill santa-claus (Pierre-Yves Ritschard <pierre-yves at spootnik.org>)
      iptables: handle cidr notation more sanely (Phil Oester <kernel at linuxace.com>)
      Use gcc to build shared objects (Phil Oester <kernel at linuxace.com>)
      reduce service_to_port duplication (Phil Oester <kernel at linuxace.com>)
      reduce parse_*_port duplication (Phil Oester <kernel at linuxace.com>)
      BUG: libiptc chain references bug (Jesper Brouer <hawk at diku.dk>)
      proto_to_name duplication (Phil Oester <kernel at linuxace.com>)
      Revert "proto_to_name duplication" patch, as noticed by Yasuyuki it can cause
      update quota match for xtables + fix -D bug (Phil Oester <kernel at linuxace.com>)
      : iptables -Z clears the per-rule counters, but not the chain policy counters (Andy Gay <andy at andynet.net>)
      iptables: fix ipt_MARK documentation (Eric Leblond)
      Add statistic match extension
      Named realm (Simon Lodal <simon at parknet.dk>)
      Use negative-list for "weird character in interface" warning instead of warning for basically every non-alphanumeric character.

/C=DE/ST=Berlin/L=Berlin/O=Netfilter Project/OU=Development/CN=kadlec/emailAddress=kadlec at netfilter.org (5):
      Multiple matches of the same type can be specified on the commandline.
      set match negation bug fixed
      size_t changed to socklen_t in getsockopt call
      Use correct types at error reporting (patch sent by H. Nakano)
      Version number was not bumped in Makefile in svn

/C=DE/ST=Berlin/L=Berlin/O=Netfilter Project/OU=Development/CN=laforge/emailAddress=laforge at netfilter.org (8):
      fix segfault or loading of invalid counters in ip[6]tables-restore (Olaf Rempel) (Closes: #437)
      don't install libiptc.a
      fix double-free if a single match is used multiple times within a signle rule
      Make '-p all' a special case that is handled before calling getprotoent() (Closes: #446)
      [IPTABLES,IP6TABLES]: fix the path to detect esp/connbytes support in kernel
      cmdflags is used in cmd2char() to return the option for a command.  It uses the
      In ip[6]tables.c, NUMBER_OF_OPT was increased to 12 for the OPT_COUNTERS
      When entering an invalid command (such as iptables -A INPUT -j MARK --set-mark

/C=DE/ST=Berlin/L=Berlin/O=Netfilter Project/OU=Development/CN=yasuyuki/emailAddress=yasuyuki at netfilter.org (4):
      fix loading shared library of ICMPv6 match.
      [IP6TABLES] kill manual comparing protocol name with "ipv6-icmp".
      [IPTABLES,IP6TABLES]: check invalid esp spi range
      - force user to specify --icmpv6-type if icmpv6 match is required to load

-----------------------------------------------------------------------


hooks/post-receive
--
IPtables



More information about the netfilter-cvslog mailing list