[netfilter-cvslog] [IPtables] annotated tag, svn_t_iptables_1_3_6, created. svn_t_iptables_1_3_6
Patrick McHardy
netfilter-cvslog-bounces at lists.netfilter.org
Wed May 14 19:11:24 CEST 2008
Gitweb: http://git.netfilter.org/cgi-bin/gitweb.cgi?p=iptables.git;a=commit;h=b107cd81af265f56cba91fccdca2f4a9878027e4
Commit: b107cd81af265f56cba91fccdca2f4a9878027e4
Parent: 0000000000000000000000000000000000000000
The annotated tag, svn_t_iptables_1_3_6 has been created
at b107cd81af265f56cba91fccdca2f4a9878027e4 (tag)
tagging 685d14eeb02e906c8f7a83e248cab2bc1ec40f27 (commit)
replaces svn_t_iptables_1_3_5
tagged by Patrick McHardy
on Wed May 14 18:58:01 2008 +0200
- Log -----------------------------------------------------------------
Tag svn_t_iptables_1_3_6
/C=DE/ST=Berlin/L=Berlin/O=Netfilter Project/OU=Development/CN=kaber/emailAddress=kaber at netfilter.org (34):
don't allow to specify protocol of IPv6 extension header (Yasuyuki Kozakai)
: Correct iptables-save output of osf module (Daniel De Graaf)
Revert incorrect fix for "Unknown error 4294967295" problem
Don't overwrite errno with return value of setsockopt (which is -1 on error).
Replace annoying "Something wrong... deleting dependencies" message by something more useful.
Add DCCP/SCTP support to multiport. Patch for kernel will go in 2.6.18.
secmark: Add libselinux support
secmark: Add libipt_SECMARK
secmark: Add libip6t_SECMARK
secmark: Add libipt_CONNSECMARK
D'oh .. I'm not too smart, forgot to add the new files in the previous patches :)
secmark: Add libip6t_CONNSECMARK
Add information about :<port> syntax (Evan Miller <evanm at frap.net>)
Use lowercase letters for match name (Simon Lodal <simonl at parknet.dk>)
trivial connlimit manpage fix (Phil Oester <kernel at linuxace.com>)
: Add new exit value to indicate concurrency issues (Jesper Dangaard Brouer <hawk at comx.dk>)
REDIRECT does not accept IP (Phil Oester <kernel at linuxace.com>)
iptables trivial compile warning cleanup (Phil Oester <kernel at linuxace.com>)
ip6tables multiport does not support x:y (Phil Oester <kernel at linuxace.com>)
libiptc symbols clash (Phil Oester <kernel at linuxace.com>)
please kill santa-claus (Pierre-Yves Ritschard <pierre-yves at spootnik.org>)
iptables: handle cidr notation more sanely (Phil Oester <kernel at linuxace.com>)
Use gcc to build shared objects (Phil Oester <kernel at linuxace.com>)
reduce service_to_port duplication (Phil Oester <kernel at linuxace.com>)
reduce parse_*_port duplication (Phil Oester <kernel at linuxace.com>)
BUG: libiptc chain references bug (Jesper Brouer <hawk at diku.dk>)
proto_to_name duplication (Phil Oester <kernel at linuxace.com>)
Revert "proto_to_name duplication" patch, as noticed by Yasuyuki it can cause
update quota match for xtables + fix -D bug (Phil Oester <kernel at linuxace.com>)
: iptables -Z clears the per-rule counters, but not the chain policy counters (Andy Gay <andy at andynet.net>)
iptables: fix ipt_MARK documentation (Eric Leblond)
Add statistic match extension
Named realm (Simon Lodal <simon at parknet.dk>)
Use negative-list for "weird character in interface" warning instead of warning for basically every non-alphanumeric character.
/C=DE/ST=Berlin/L=Berlin/O=Netfilter Project/OU=Development/CN=kadlec/emailAddress=kadlec at netfilter.org (5):
Multiple matches of the same type can be specified on the commandline.
set match negation bug fixed
size_t changed to socklen_t in getsockopt call
Use correct types at error reporting (patch sent by H. Nakano)
Version number was not bumped in Makefile in svn
/C=DE/ST=Berlin/L=Berlin/O=Netfilter Project/OU=Development/CN=laforge/emailAddress=laforge at netfilter.org (8):
fix segfault or loading of invalid counters in ip[6]tables-restore (Olaf Rempel) (Closes: #437)
don't install libiptc.a
fix double-free if a single match is used multiple times within a signle rule
Make '-p all' a special case that is handled before calling getprotoent() (Closes: #446)
[IPTABLES,IP6TABLES]: fix the path to detect esp/connbytes support in kernel
cmdflags is used in cmd2char() to return the option for a command. It uses the
In ip[6]tables.c, NUMBER_OF_OPT was increased to 12 for the OPT_COUNTERS
When entering an invalid command (such as iptables -A INPUT -j MARK --set-mark
/C=DE/ST=Berlin/L=Berlin/O=Netfilter Project/OU=Development/CN=yasuyuki/emailAddress=yasuyuki at netfilter.org (4):
fix loading shared library of ICMPv6 match.
[IP6TABLES] kill manual comparing protocol name with "ipv6-icmp".
[IPTABLES,IP6TABLES]: check invalid esp spi range
- force user to specify --icmpv6-type if icmpv6 match is required to load
-----------------------------------------------------------------------
hooks/post-receive
--
IPtables
More information about the netfilter-cvslog
mailing list