2004-09-09 06:19:25 +00:00
|
|
|
Name: iptables
|
2007-08-23 14:54:50 +00:00
|
|
|
Summary: Tools for managing Linux kernel packet filtering capabilities
|
2009-02-20 13:44:58 +00:00
|
|
|
Version: 1.4.2
|
2009-03-05 14:06:37 +00:00
|
|
|
Release: 3%{?dist}
|
2007-08-23 14:54:50 +00:00
|
|
|
Source: http://www.netfilter.org/projects/iptables/files/%{name}-%{version}.tar.bz2
|
2004-09-09 06:19:38 +00:00
|
|
|
Source1: iptables.init
|
2004-09-09 06:22:13 +00:00
|
|
|
Source2: iptables-config
|
2007-09-24 16:03:24 +00:00
|
|
|
Patch4: iptables-1.3.8-typo_latter.patch
|
2008-07-22 15:37:03 +00:00
|
|
|
Patch5: iptables-1.4.1.1-cloexec.patch
|
2004-09-09 06:19:25 +00:00
|
|
|
Group: System Environment/Base
|
2004-09-09 06:20:32 +00:00
|
|
|
URL: http://www.netfilter.org/
|
2007-08-23 14:54:50 +00:00
|
|
|
BuildRoot: %(mktemp -ud %{_tmppath}/%{name}-%{version}-%{release}-XXXXXX)
|
2009-02-20 13:44:58 +00:00
|
|
|
License: GPL+
|
2006-09-19 15:36:43 +00:00
|
|
|
BuildRequires: libselinux-devel
|
2008-06-06 18:59:22 +00:00
|
|
|
BuildRequires: kernel-headers
|
2005-03-18 16:40:36 +00:00
|
|
|
Conflicts: kernel < 2.4.20
|
2007-08-23 14:54:50 +00:00
|
|
|
Requires(post): chkconfig
|
|
|
|
Requires(preun): chkconfig
|
2004-09-09 06:22:13 +00:00
|
|
|
|
2004-09-09 06:19:25 +00:00
|
|
|
%description
|
2004-09-09 06:19:55 +00:00
|
|
|
The iptables utility controls the network packet filtering code in the
|
|
|
|
Linux kernel. If you need to set up firewalls and/or IP masquerading,
|
|
|
|
you should install this package.
|
2004-09-09 06:19:25 +00:00
|
|
|
|
2007-08-23 14:54:50 +00:00
|
|
|
%package ipv6
|
|
|
|
Summary: IPv6 support for iptables
|
|
|
|
Group: System Environment/Base
|
|
|
|
Requires: %{name} = %{version}-%{release}
|
|
|
|
Requires(post): chkconfig
|
|
|
|
Requires(preun): chkconfig
|
|
|
|
|
2004-09-09 06:19:38 +00:00
|
|
|
%description ipv6
|
2004-09-09 06:19:55 +00:00
|
|
|
The iptables package contains IPv6 (the next version of the IP
|
|
|
|
protocol) support for iptables. Iptables controls the Linux kernel
|
|
|
|
network packet filtering code, allowing you to set up firewalls and IP
|
|
|
|
masquerading.
|
2004-09-09 06:19:38 +00:00
|
|
|
|
|
|
|
Install iptables-ipv6 if you need to set up firewalling for your
|
2004-09-09 06:19:55 +00:00
|
|
|
network and you are using ipv6.
|
2004-09-09 06:19:38 +00:00
|
|
|
|
2007-08-23 14:54:50 +00:00
|
|
|
%package devel
|
|
|
|
Summary: Development package for iptables
|
|
|
|
Group: System Environment/Base
|
|
|
|
Requires: %{name} = %{version}-%{release}
|
2009-02-20 13:44:58 +00:00
|
|
|
Requires: pkgconfig
|
2007-08-23 14:54:50 +00:00
|
|
|
|
2004-09-09 06:22:13 +00:00
|
|
|
%description devel
|
2007-08-23 14:54:50 +00:00
|
|
|
iptables development headers and libraries.
|
|
|
|
|
|
|
|
The iptc interface is upstream marked as not public. The interface is not
|
|
|
|
stable and may change with every new version. It is therefore unsupported.
|
2004-09-09 06:22:13 +00:00
|
|
|
|
2004-09-09 06:19:25 +00:00
|
|
|
%prep
|
|
|
|
%setup -q
|
2007-09-24 16:03:24 +00:00
|
|
|
%patch4 -p1 -b .typo_latter
|
2007-11-05 16:41:26 +00:00
|
|
|
%patch5 -p1 -b .cloexec
|
2005-11-25 17:03:17 +00:00
|
|
|
|
2004-09-09 06:19:25 +00:00
|
|
|
%build
|
2009-03-05 14:06:37 +00:00
|
|
|
CFLAGS="$RPM_OPT_FLAGS -fno-strict-aliasing" \
|
2008-06-10 13:08:35 +00:00
|
|
|
./configure --enable-devel --enable-libipq --bindir=/bin --sbindir=/sbin --sysconfdir=/etc --libdir=/%{_libdir} --libexecdir=/%{_lib} --mandir=%{_mandir} --includedir=%{_includedir} --with-kernel=/usr --with-kbuild=/usr --with-ksource=/usr
|
2009-02-20 13:44:58 +00:00
|
|
|
|
|
|
|
# do not use rpath
|
2009-03-05 14:06:37 +00:00
|
|
|
sed -i 's|^hardcode_libdir_flag_spec=.*|hardcode_libdir_flag_spec=""|g' libtool
|
|
|
|
sed -i 's|^runpath_var=LD_RUN_PATH|runpath_var=DIE_RPATH_DIE|g' libtool
|
2009-02-20 13:44:58 +00:00
|
|
|
|
2008-06-10 13:08:35 +00:00
|
|
|
make
|
2004-09-09 06:19:25 +00:00
|
|
|
|
|
|
|
%install
|
2007-08-23 14:54:50 +00:00
|
|
|
rm -rf %{buildroot}
|
2008-06-10 13:08:35 +00:00
|
|
|
|
|
|
|
make install DESTDIR=%{buildroot}
|
2009-02-20 13:44:58 +00:00
|
|
|
# remove la file(s)
|
|
|
|
rm -f %{buildroot}/%{_libdir}/*.la
|
2008-06-10 13:08:35 +00:00
|
|
|
|
2009-02-20 13:44:58 +00:00
|
|
|
# install iptc header files
|
|
|
|
install -d -m 755 %{buildroot}%{_includedir}/libiptc/
|
|
|
|
install -m 644 include/libiptc/*.h %{buildroot}%{_includedir}/libiptc/
|
2008-06-10 13:08:35 +00:00
|
|
|
install -m 644 libiptc/libiptc.a %{buildroot}/%{_libdir}
|
|
|
|
|
2009-02-20 13:44:58 +00:00
|
|
|
# install ip*tables.h header files
|
|
|
|
install -m 644 include/ip*tables.h %{buildroot}%{_includedir}/
|
|
|
|
|
|
|
|
# install ipulog header file
|
|
|
|
install -d -m 755 %{buildroot}%{_includedir}/libipulog/
|
|
|
|
install -m 644 include/libipulog/*.h %{buildroot}%{_includedir}/libipulog/
|
|
|
|
|
2008-06-10 13:08:35 +00:00
|
|
|
# install init scripts and configuration files
|
2009-03-05 14:06:37 +00:00
|
|
|
install -d -m 755 %{buildroot}/etc/rc.d/init.d
|
|
|
|
install -c -m 755 %{SOURCE1} %{buildroot}/etc/rc.d/init.d/iptables
|
2007-08-23 14:54:50 +00:00
|
|
|
sed -e 's;iptables;ip6tables;g' -e 's;IPTABLES;IP6TABLES;g' < %{SOURCE1} > ip6tables.init
|
2009-03-05 14:06:37 +00:00
|
|
|
install -c -m 755 ip6tables.init %{buildroot}/etc/rc.d/init.d/ip6tables
|
|
|
|
install -d -m 755 %{buildroot}/etc/sysconfig
|
|
|
|
install -c -m 755 %{SOURCE2} %{buildroot}/etc/sysconfig/iptables-config
|
2004-09-09 06:22:13 +00:00
|
|
|
sed -e 's;iptables;ip6tables;g' -e 's;IPTABLES;IP6TABLES;g' < %{SOURCE2} > ip6tables-config
|
2009-03-05 14:06:37 +00:00
|
|
|
install -c -m 755 ip6tables-config %{buildroot}/etc/sysconfig/ip6tables-config
|
2004-09-09 06:19:25 +00:00
|
|
|
|
|
|
|
%clean
|
2009-03-05 14:06:37 +00:00
|
|
|
rm -rf %{buildroot}
|
2004-09-09 06:19:38 +00:00
|
|
|
|
|
|
|
%post
|
2009-02-20 13:44:58 +00:00
|
|
|
/sbin/ldconfig
|
2004-09-09 06:20:32 +00:00
|
|
|
/sbin/chkconfig --add iptables
|
2004-09-09 06:19:38 +00:00
|
|
|
|
2009-02-20 13:44:58 +00:00
|
|
|
%postun -p /sbin/ldconfig
|
|
|
|
|
2004-09-09 06:19:38 +00:00
|
|
|
%preun
|
2004-09-09 06:20:13 +00:00
|
|
|
if [ "$1" = 0 ]; then
|
2004-09-09 06:20:32 +00:00
|
|
|
/sbin/chkconfig --del iptables
|
|
|
|
fi
|
|
|
|
|
|
|
|
%post ipv6
|
|
|
|
/sbin/chkconfig --add ip6tables
|
|
|
|
|
|
|
|
%preun ipv6
|
|
|
|
if [ "$1" = 0 ]; then
|
|
|
|
/sbin/chkconfig --del ip6tables
|
2004-09-09 06:19:55 +00:00
|
|
|
fi
|
2004-09-09 06:19:25 +00:00
|
|
|
|
|
|
|
%files
|
2007-08-23 14:54:50 +00:00
|
|
|
%defattr(-,root,root)
|
2004-09-09 06:25:10 +00:00
|
|
|
%doc COPYING INSTALL INCOMPATIBILITIES
|
2007-08-23 14:54:50 +00:00
|
|
|
%attr(0755,root,root) /etc/rc.d/init.d/iptables
|
2004-09-09 06:22:13 +00:00
|
|
|
%config(noreplace) %attr(0600,root,root) /etc/sysconfig/iptables-config
|
2004-09-09 06:19:38 +00:00
|
|
|
/sbin/iptables*
|
2004-09-09 06:22:13 +00:00
|
|
|
%{_mandir}/man8/iptables*
|
2008-06-10 13:08:35 +00:00
|
|
|
%dir /%{_lib}/xtables
|
|
|
|
/%{_lib}/xtables/libipt*
|
|
|
|
/%{_lib}/xtables/libxt*
|
2009-02-20 13:44:58 +00:00
|
|
|
%{_libdir}/libxtables.so.*
|
2004-09-09 06:19:38 +00:00
|
|
|
|
|
|
|
%files ipv6
|
2007-08-23 14:54:50 +00:00
|
|
|
%defattr(-,root,root)
|
|
|
|
%attr(0755,root,root) /etc/rc.d/init.d/ip6tables
|
2004-09-09 06:22:13 +00:00
|
|
|
%config(noreplace) %attr(0600,root,root) /etc/sysconfig/ip6tables-config
|
2004-09-09 06:20:32 +00:00
|
|
|
/sbin/ip6tables*
|
2008-06-10 13:08:35 +00:00
|
|
|
/bin/iptables-xml
|
2004-09-09 06:22:13 +00:00
|
|
|
%{_mandir}/man8/ip6tables*
|
2008-06-10 13:08:35 +00:00
|
|
|
/%{_lib}/xtables/libip6t*
|
2004-09-09 06:22:13 +00:00
|
|
|
|
|
|
|
%files devel
|
2007-08-23 14:54:50 +00:00
|
|
|
%defattr(-,root,root)
|
2008-06-10 13:08:35 +00:00
|
|
|
%{_includedir}/*.h
|
2007-08-23 14:54:50 +00:00
|
|
|
%dir %{_includedir}/libiptc
|
|
|
|
%{_includedir}/libiptc/*.h
|
2009-02-20 13:44:58 +00:00
|
|
|
%dir %{_includedir}/libipulog
|
|
|
|
%{_includedir}/libipulog/*.h
|
2004-09-09 06:22:13 +00:00
|
|
|
%{_libdir}/libipq.a
|
2007-08-23 14:54:50 +00:00
|
|
|
%{_libdir}/libiptc.a
|
2004-09-09 06:22:13 +00:00
|
|
|
%{_mandir}/man3/*
|
2009-02-20 13:44:58 +00:00
|
|
|
%{_libdir}/libxtables.so
|
|
|
|
%{_libdir}/pkgconfig/xtables.pc
|
2004-09-09 06:19:25 +00:00
|
|
|
|
|
|
|
%changelog
|
2009-03-05 14:06:37 +00:00
|
|
|
* Thu Mar 5 2009 Thomas Woerner <twoerner@redhat.com> 1.4.2-3
|
|
|
|
- still more review fixes (rhbz#225906)
|
|
|
|
- consistent macro usage
|
|
|
|
- use sed instead of perl for rpath removal
|
|
|
|
- use standard RPM CFLAGS, but also -fno-strict-aliasing (needed for libiptc*)
|
|
|
|
|
2009-02-25 07:47:47 +00:00
|
|
|
* Wed Feb 25 2009 Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 1.4.2-2
|
|
|
|
- Rebuilt for https://fedoraproject.org/wiki/Fedora_11_Mass_Rebuild
|
|
|
|
|
2009-02-20 13:44:58 +00:00
|
|
|
* Fri Feb 20 2009 Thomas Woerner <twoerner@redhat.com> 1.4.2-1
|
|
|
|
- new version 1.4.2
|
|
|
|
- removed TOS value mask patch (upstream)
|
|
|
|
- more review fixes (rhbz#225906)
|
|
|
|
- install all header files (rhbz#462207)
|
|
|
|
- dropped nf_ext_init (rhbz#472548)
|
|
|
|
|
2008-07-22 15:37:03 +00:00
|
|
|
* Tue Jul 22 2008 Thomas Woerner <twoerner@redhat.com> 1.4.1.1-2
|
|
|
|
- fixed TOS value mask problem (rhbz#456244) (upstream patch)
|
|
|
|
- two more cloexec fixes
|
|
|
|
|
2008-07-01 09:57:56 +00:00
|
|
|
* Tue Jul 1 2008 Thomas Woerner <twoerner@redhat.com> 1.4.1.1-1
|
|
|
|
- upstream bug fix release 1.4.1.1
|
|
|
|
- dropped extra patch for 1.4.1 - not needed anymore
|
|
|
|
|
2008-06-10 13:08:35 +00:00
|
|
|
* Tue Jun 10 2008 Thomas Woerner <twoerner@redhat.com> 1.4.1-1
|
|
|
|
- new version 1.4.1 with new build environment
|
|
|
|
- additional ipv6 network mask patch from Jan Engelhardt
|
|
|
|
- spec file cleanup
|
|
|
|
- removed old patches
|
|
|
|
|
2008-06-06 18:59:22 +00:00
|
|
|
* Fri Jun 6 2008 Tom "spot" Callaway <tcallawa@redhat.com> 1.4.0-5
|
|
|
|
- use normal kernel headers, not linux/compiler.h
|
|
|
|
- change BuildRequires: kernel-devel to kernel-headers
|
|
|
|
- We need to do this to be able to build for both sparcv9 and sparc64
|
|
|
|
(there is no kernel-devel.sparcv9)
|
|
|
|
|
2008-03-20 15:09:55 +00:00
|
|
|
* Thu Mar 20 2008 Thomas Woerner <twoerner@redhat.com> 1.4.0-4
|
|
|
|
- use O_CLOEXEC for all opened files in all applications (rhbz#438189)
|
|
|
|
|
2008-03-03 09:35:13 +00:00
|
|
|
* Mon Mar 3 2008 Thomas Woerner <twoerner@redhat.com> 1.4.0-3
|
|
|
|
- use the kernel headers from the build tree for iptables for now to be able to
|
|
|
|
compile this package, but this makes the package more kernel dependant
|
2008-03-03 13:47:25 +00:00
|
|
|
- use s6_addr32 instead of in6_u.u6_addr32
|
2008-03-03 09:35:13 +00:00
|
|
|
|
2008-02-20 05:58:52 +00:00
|
|
|
* Wed Feb 20 2008 Fedora Release Engineering <rel-eng@fedoraproject.org> - 1.4.0-2
|
|
|
|
- Autorebuild for GCC 4.3
|
|
|
|
|
2008-02-11 13:56:53 +00:00
|
|
|
* Mon Feb 11 2008 Thomas Woerner <twoerner@redhat.com> 1.4.0-1
|
|
|
|
- new version 1.4.0
|
|
|
|
- fixed condrestart (rhbz#428148)
|
|
|
|
- report the module in rmmod_r if there is an error
|
2008-02-11 15:16:43 +00:00
|
|
|
- use nf_ext_init instead of my_init for extension constructors
|
2008-02-11 13:56:53 +00:00
|
|
|
|
2007-11-05 16:41:26 +00:00
|
|
|
* Mon Nov 5 2007 Thomas Woerner <twoerner@redhat.com> 1.3.8-6
|
|
|
|
- fixed leaked file descriptor before fork/exec (rhbz#312191)
|
|
|
|
- blacklisting is not working, use "install X /bin/(true|false)" test instead
|
|
|
|
- return private exit code 150 for disabled ipv6 support
|
|
|
|
- use script name for output messages
|
|
|
|
|
2007-10-16 15:30:01 +00:00
|
|
|
* Tue Oct 16 2007 Thomas Woerner <twoerner@redhat.com> 1.3.8-5
|
|
|
|
- fixed error code for stopping a already stopped firewall (rhbz#321751)
|
|
|
|
- moved blacklist test into start
|
|
|
|
|
2007-09-26 15:59:58 +00:00
|
|
|
* Wed Sep 26 2007 Thomas Woerner <twoerner@redhat.com> 1.3.8-4.1
|
|
|
|
- do not start ip6tables if ipv6 is blacklisted (rhbz#236888)
|
|
|
|
- use simpler fix for (rhbz#295611)
|
|
|
|
Thanks to Linus Torvalds for the patch.
|
|
|
|
|
2007-09-24 16:03:24 +00:00
|
|
|
* Mon Sep 24 2007 Thomas Woerner <twoerner@redhat.com> 1.3.8-4
|
|
|
|
- fixed IPv6 reject type (rhbz#295181)
|
|
|
|
- fixed init script: start, stop and status
|
|
|
|
- support netfilter compiled into kernel in init script (rhbz#295611)
|
|
|
|
- dropped inversion for limit modules from man pages (rhbz#220780)
|
|
|
|
- fixed typo in ip6tables man page (rhbz#236185)
|
|
|
|
|
2007-09-19 16:30:16 +00:00
|
|
|
* Wed Sep 19 2007 Thomas Woerner <twoerner@redhat.com> 1.3.8-3
|
|
|
|
- do not depend on local_fs in lsb header - this delayes start after network
|
|
|
|
- fixed exit code for initscript usage
|
|
|
|
|
2007-09-17 15:46:05 +00:00
|
|
|
* Mon Sep 17 2007 Thomas Woerner <twoerner@redhat.com> 1.3.8-2.1
|
|
|
|
- do not use lock file for condrestart test
|
|
|
|
|
2007-08-23 14:54:50 +00:00
|
|
|
* Thu Aug 23 2007 Thomas Woerner <twoerner@redhat.com> 1.3.8-2
|
|
|
|
- fixed initscript for LSB conformance (rhbz#246953, rhbz#242459)
|
|
|
|
- provide iptc interface again, but unsupported (rhbz#216733)
|
|
|
|
- compile all extension, which are supported by the kernel-headers package
|
|
|
|
- review fixes (rhbz#225906)
|
|
|
|
|
|
|
|
* Tue Jul 31 2007 Thomas Woerner <twoerner@redhat.com>
|
|
|
|
- reverted ipv6 fix, because it disables the ipv6 at all (rhbz#236888)
|
|
|
|
|
2007-07-16 22:03:39 +00:00
|
|
|
* Fri Jul 13 2007 Steve Conklin <sconklin@redhat.com> - 1.3.8-1
|
|
|
|
- New version 1.3.8
|
|
|
|
|
2007-04-23 18:58:32 +00:00
|
|
|
* Mon Apr 23 2007 Jeremy Katz <katzj@redhat.com> - 1.3.7-2
|
|
|
|
- fix error when ipv6 support isn't loaded in the kernel (#236888)
|
|
|
|
|
2007-01-10 11:29:49 +00:00
|
|
|
* Wed Jan 10 2007 Thomas Woerner <twoerner@redhat.com> 1.3.7-1.1
|
|
|
|
- fixed installation of secmark modules
|
|
|
|
|
2007-01-09 18:46:18 +00:00
|
|
|
* Tue Jan 9 2007 Thomas Woerner <twoerner@redhat.com> 1.3.7-1
|
|
|
|
- new verison 1.3.7
|
|
|
|
- iptc is not a public interface and therefore not installed anymore
|
|
|
|
- dropped upstream secmark patch
|
|
|
|
|
2006-09-19 15:36:43 +00:00
|
|
|
* Thu Sep 19 2006 Thomas Woerner <twoerner@redhat.com> 1.3.5-2
|
|
|
|
- added secmark iptables patches (#201573)
|
|
|
|
|
2006-07-12 06:25:39 +00:00
|
|
|
* Wed Jul 12 2006 Jesse Keating <jkeating@redhat.com> - 1.3.5-1.2.1
|
|
|
|
- rebuild
|
|
|
|
|
2006-02-11 03:37:55 +00:00
|
|
|
* Fri Feb 10 2006 Jesse Keating <jkeating@redhat.com> - 1.3.5-1.2
|
|
|
|
- bump again for double-long bug on ppc(64)
|
|
|
|
|
2006-02-07 12:17:14 +00:00
|
|
|
* Tue Feb 07 2006 Jesse Keating <jkeating@redhat.com> - 1.3.5-1.1
|
|
|
|
- rebuilt for new gcc4.1 snapshot and glibc changes
|
|
|
|
|
2006-02-02 13:24:00 +00:00
|
|
|
* Thu Feb 2 2006 Thomas Woerner <twoerner@redhat.com> 1.3.5-1
|
|
|
|
- new version 1.3.5
|
|
|
|
- fixed init script to set policy for raw tables, too (#179094)
|
|
|
|
|
2006-01-24 14:18:57 +00:00
|
|
|
* Tue Jan 24 2006 Thomas Woerner <twoerner@redhat.com> 1.3.4-3
|
|
|
|
- added important iptables header files to devel package
|
|
|
|
|
2005-12-09 22:41:00 +00:00
|
|
|
* Fri Dec 09 2005 Jesse Keating <jkeating@redhat.com>
|
|
|
|
- rebuilt
|
|
|
|
|
2005-11-25 17:03:17 +00:00
|
|
|
* Fri Nov 25 2005 Thomas Woerner <twoerner@redhat.com> 1.3.4-2
|
|
|
|
- fix for plugin problem: link with "gcc -shared" instead of "ld -shared" and
|
|
|
|
replace "_init" with "__attribute((constructor)) my_init"
|
|
|
|
|
2005-11-25 13:27:51 +00:00
|
|
|
* Fri Nov 25 2005 Thomas Woerner <twoerner@redhat.com> 1.3.4-1.1
|
|
|
|
- rebuild due to unresolved symbols in shared libraries
|
|
|
|
|
2005-11-18 12:26:15 +00:00
|
|
|
* Fri Nov 18 2005 Thomas Woerner <twoerner@redhat.com> 1.3.4-1
|
|
|
|
- new version 1.3.4
|
|
|
|
- dropped free_opts patch (upstream fixed)
|
|
|
|
- made libipq PIC (#158623)
|
|
|
|
- additional configuration options for iptables startup script (#172929)
|
|
|
|
Thanks to Jan Gruenwald for the patch
|
|
|
|
- spec file cleanup (dropped linux_header define and usage)
|
|
|
|
|
2005-07-18 12:16:48 +00:00
|
|
|
* Mon Jul 18 2005 Thomas Woerner <twoerner@redhat.com> 1.3.2-1
|
|
|
|
- new version 1.3.2 with additional patch for the misplaced free_opts call
|
|
|
|
from Marcus Sundberg
|
|
|
|
|
2005-05-11 13:49:05 +00:00
|
|
|
* Wed May 11 2005 Thomas Woerner <twoerner@redhat.com> 1.3.1-1
|
|
|
|
- new version 1.3.1
|
|
|
|
|
2005-03-18 16:40:36 +00:00
|
|
|
* Fri Mar 18 2005 Thomas Woerner <twoerner@redhat.com> 1.3.0-2
|
|
|
|
- Remove unnecessary explicit kernel dep (#146142)
|
|
|
|
- Fixed out of bounds accesses (#131848): Thanks to Steve Grubb
|
|
|
|
for the patch
|
|
|
|
- Adapted iptables-config to reference to modprobe.conf (#150143)
|
|
|
|
- Remove misleading message (#140154): Thanks to Ulrich Drepper
|
|
|
|
for the patch
|
|
|
|
|
2005-02-22 11:09:58 +00:00
|
|
|
* Mon Feb 21 2005 Thomas Woerner <twoerner@redhat.com> 1.3.0-1
|
|
|
|
- new version 1.3.0
|
|
|
|
|
2004-11-11 11:55:39 +00:00
|
|
|
* Thu Nov 11 2004 Thomas Woerner <twoerner@redhat.com> 1.2.11-3.2
|
|
|
|
- fixed autoload problem in iptables and ip6tables (CAN-2004-0986)
|
|
|
|
|
2004-09-17 10:41:31 +00:00
|
|
|
* Fri Sep 17 2004 Thomas Woerner <twoerner@redhat.com> 1.2.11-3.1
|
|
|
|
- changed default behaviour for IPTABLES_STATUS_NUMERIC to "yes" (#129731)
|
|
|
|
- modified config file to match this change and un-commented variables with
|
|
|
|
default values
|
|
|
|
|
2004-09-16 16:12:07 +00:00
|
|
|
* Thu Sep 16 2004 Thomas Woerner <twoerner@redhat.com> 1.2.11-3
|
|
|
|
- applied second part of cleanup patch from (#131848): thanks to Steve Grubb
|
|
|
|
for the patch
|
|
|
|
|
2004-09-09 06:26:30 +00:00
|
|
|
* Wed Aug 25 2004 Thomas Woerner <twoerner@redhat.com> 1.2.11-2
|
|
|
|
- fixed free bug in iptables (#128322)
|
|
|
|
|
2004-09-09 06:26:05 +00:00
|
|
|
* Tue Jun 22 2004 Thomas Woerner <twoerner@redhat.com> 1.2.11-1
|
|
|
|
- new version 1.2.11
|
|
|
|
|
2004-09-09 06:26:03 +00:00
|
|
|
* Thu Jun 17 2004 Thomas Woerner <twoerner@redhat.com> 1.2.10-1
|
|
|
|
- new version 1.2.10
|
|
|
|
|
2004-09-09 06:25:55 +00:00
|
|
|
* Tue Jun 15 2004 Elliot Lee <sopwith@redhat.com>
|
|
|
|
- rebuilt
|
|
|
|
|
2004-09-09 06:25:49 +00:00
|
|
|
* Tue Mar 02 2004 Elliot Lee <sopwith@redhat.com>
|
|
|
|
- rebuilt
|
|
|
|
|
|
|
|
* Thu Feb 26 2004 Thomas Woerner <twoerner@redhat.com> 1.2.9-2.3
|
|
|
|
- fixed iptables-restore -c fault if there are no counters (#116421)
|
|
|
|
|
|
|
|
* Fri Feb 13 2004 Elliot Lee <sopwith@redhat.com>
|
|
|
|
- rebuilt
|
|
|
|
|
2004-09-09 06:25:17 +00:00
|
|
|
* Sun Jan 25 2004 Dan Walsh <dwalsh@redhat.com> 1.2.9-1.2
|
|
|
|
- Close File descriptors to prevent SELinux error message
|
|
|
|
|
|
|
|
* Wed Jan 7 2004 Thomas Woerner <twoerner@redhat.com> 1.2.9-1.1
|
|
|
|
- rebuild
|
|
|
|
|
|
|
|
* Wed Dec 17 2003 Thomas Woerner <twoerner@redhat.com> 1.2.9-1
|
2004-09-09 06:25:10 +00:00
|
|
|
- vew version 1.2.9
|
|
|
|
- new config options in ipXtables-config:
|
|
|
|
IPTABLES_MODULES_UNLOAD
|
|
|
|
- more documentation in ipXtables-config
|
|
|
|
- fix for netlink security issue in libipq (devel package)
|
|
|
|
- print fix for libipt_icmp (#109546)
|
2004-09-09 06:24:55 +00:00
|
|
|
|
2004-09-09 06:24:45 +00:00
|
|
|
* Thu Oct 23 2003 Thomas Woerner <twoerner@redhat.com> 1.2.8-13
|
|
|
|
- marked all messages in iptables init script for translation (#107462)
|
|
|
|
- enabled devel package (#105884, #106101)
|
|
|
|
- bumped build for fedora for libipt_recent.so (#106002)
|
|
|
|
|
|
|
|
* Tue Sep 23 2003 Thomas Woerner <twoerner@redhat.com> 1.2.8-12.1
|
|
|
|
- fixed lost udp port range in ip6tables-save (#104484)
|
|
|
|
- fixed non numeric multiport port output in ipXtables-savs
|
|
|
|
|
|
|
|
* Mon Sep 22 2003 Florian La Roche <Florian.LaRoche@redhat.de> 1.2.8-11
|
|
|
|
- do not link against -lnsl
|
|
|
|
|
|
|
|
* Wed Sep 17 2003 Thomas Woerner <twoerner@redhat.com> 1.2.8-10
|
2004-09-09 06:23:22 +00:00
|
|
|
- made variables in rmmod_r local
|
|
|
|
|
2004-09-09 06:24:45 +00:00
|
|
|
* Tue Jul 22 2003 Thomas Woerner <twoerner@redhat.com> 1.2.8-9
|
2004-09-09 06:23:13 +00:00
|
|
|
- fixed permission for init script
|
|
|
|
|
|
|
|
* Sat Jul 19 2003 Thomas Woerner <twoerner@redhat.com> 1.2.8-8
|
2004-09-09 06:22:13 +00:00
|
|
|
- fixed save when iptables file is missing and iptables-config permissions
|
|
|
|
|
|
|
|
* Tue Jul 8 2003 Thomas Woerner <twoerner@redhat.com> 1.2.8-7
|
|
|
|
- fixes for ip6tables: module unloading, setting policy only for existing
|
|
|
|
tables
|
|
|
|
|
|
|
|
* Thu Jul 3 2003 Thomas Woerner <twoerner@redhat.com> 1.2.8-6
|
|
|
|
- IPTABLES_SAVE_COUNTER defaults to no, now
|
|
|
|
- install config file in /etc/sysconfig
|
|
|
|
- exchange unload of ip_tables and ip_conntrack
|
|
|
|
- fixed start function
|
|
|
|
|
|
|
|
* Wed Jul 2 2003 Thomas Woerner <twoerner@redhat.com> 1.2.8-5
|
|
|
|
- new config option IPTABLES_SAVE_ON_RESTART
|
|
|
|
- init script: new status, save and restart
|
|
|
|
- fixes #44905, #65389, #80785, #82860, #91040, #91560 and #91374
|
|
|
|
|
|
|
|
* Mon Jun 30 2003 Thomas Woerner <twoerner@redhat.com> 1.2.8-4
|
|
|
|
- new config option IPTABLES_STATUS_NUMERIC
|
|
|
|
- cleared IPTABLES_MODULES in iptables-config
|
|
|
|
|
|
|
|
* Mon Jun 30 2003 Thomas Woerner <twoerner@redhat.com> 1.2.8-3
|
|
|
|
- new init scripts
|
|
|
|
|
|
|
|
* Sat Jun 28 2003 Florian La Roche <Florian.LaRoche@redhat.de>
|
|
|
|
- remove check for very old kernel versions in init scripts
|
|
|
|
- sync up both init scripts and remove some further ugly things
|
|
|
|
- add some docu into rpm
|
|
|
|
|
|
|
|
* Thu Jun 26 2003 Thomas Woerner <twoerner@redhat.com> 1.2.8-2
|
|
|
|
- rebuild
|
|
|
|
|
|
|
|
* Mon Jun 16 2003 Thomas Woerner <twoerner@redhat.com> 1.2.8-1
|
|
|
|
- update to 1.2.8
|
|
|
|
|
2004-09-09 06:21:27 +00:00
|
|
|
* Wed Jan 22 2003 Tim Powers <timp@redhat.com>
|
|
|
|
- rebuilt
|
|
|
|
|
|
|
|
* Mon Jan 13 2003 Bill Nottingham <notting@redhat.com> 1.2.7a-1
|
|
|
|
- update to 1.2.7a
|
|
|
|
- add a plethora of bugfixes courtesy Michael Schwendt <mschewndt@yahoo.com>
|
|
|
|
|
|
|
|
* Fri Dec 13 2002 Elliot Lee <sopwith@redhat.com> 1.2.6a-3
|
|
|
|
- Fix multilib
|
|
|
|
|
2004-09-09 06:21:23 +00:00
|
|
|
* Wed Aug 07 2002 Karsten Hopp <karsten@redhat.de>
|
|
|
|
- fixed iptables and ip6tables initscript output, based on #70511
|
|
|
|
- check return status of all iptables calls, not just the last one
|
|
|
|
in a 'for' loop.
|
|
|
|
|
2004-09-09 06:21:17 +00:00
|
|
|
* Mon Jul 29 2002 Bernhard Rosenkraenzer <bero@redhat.com> 1.2.6a-1
|
|
|
|
- 1.2.6a (bugfix release, #69747)
|
|
|
|
|
|
|
|
* Fri Jun 21 2002 Tim Powers <timp@redhat.com>
|
|
|
|
- automated rebuild
|
|
|
|
|
|
|
|
* Thu May 23 2002 Tim Powers <timp@redhat.com>
|
|
|
|
- automated rebuild
|
|
|
|
|
2004-09-09 06:21:00 +00:00
|
|
|
* Mon Mar 4 2002 Bernhard Rosenkraenzer <bero@redhat.com> 1.2.5-3
|
|
|
|
- Add some fixes from CVS, fixing bug #60465
|
|
|
|
|
2004-09-09 06:20:32 +00:00
|
|
|
* Tue Feb 12 2002 Bernhard Rosenkraenzer <bero@redhat.com> 1.2.5-2
|
|
|
|
- Merge ip6tables improvements from Ian Prowell <iprowell@prowell.org>
|
|
|
|
#59402
|
|
|
|
- Update URL (#59354)
|
2007-08-23 14:54:50 +00:00
|
|
|
- Use /sbin/chkconfig rather than chkconfig in %%postun script
|
2004-09-09 06:20:32 +00:00
|
|
|
|
|
|
|
* Fri Jan 11 2002 Bernhard Rosenkraenzer <bero@redhat.com> 1.2.5-1
|
|
|
|
- 1.2.5
|
|
|
|
|
|
|
|
* Wed Jan 09 2002 Tim Powers <timp@redhat.com>
|
|
|
|
- automated rebuild
|
2004-09-09 06:20:22 +00:00
|
|
|
|
2004-09-09 06:20:13 +00:00
|
|
|
* Mon Nov 5 2001 Bernhard Rosenkraenzer <bero@redhat.com> 1.2.4-2
|
2007-08-23 14:54:50 +00:00
|
|
|
- Fix %%preun script
|
2004-09-09 06:20:13 +00:00
|
|
|
|
|
|
|
* Tue Oct 30 2001 Bernhard Rosenkraenzer <bero@redhat.com> 1.2.4-1
|
|
|
|
- Update to 1.2.4 (various fixes, including security fixes; among others:
|
|
|
|
#42990, #50500, #53325, #54280)
|
|
|
|
- Fix init script (#31133)
|
2004-09-09 06:20:04 +00:00
|
|
|
|
2004-09-09 06:19:55 +00:00
|
|
|
* Mon Sep 3 2001 Bernhard Rosenkraenzer <bero@redhat.com> 1.2.3-1
|
|
|
|
- 1.2.3 (5 security fixes, some other fixes)
|
|
|
|
- Fix updating (#53032)
|
|
|
|
|
|
|
|
* Mon Aug 27 2001 Bernhard Rosenkraenzer <bero@redhat.com> 1.2.2-4
|
|
|
|
- Fix #50990
|
|
|
|
- Add some fixes from current CVS; should fix #52620
|
|
|
|
|
2004-09-09 06:19:48 +00:00
|
|
|
* Mon Jul 16 2001 Bernhard Rosenkraenzer <bero@redhat.com> 1.2.2-3
|
|
|
|
- Add some fixes from the current CVS tree; fixes #49154 and some IPv6
|
|
|
|
issues
|
|
|
|
|
2004-09-09 06:19:45 +00:00
|
|
|
* Tue Jun 26 2001 Bernhard Rosenkraenzer <bero@redhat.com> 1.2.2-2
|
|
|
|
- Fix iptables-save reject-with (#45632), Patch from Michael Schwendt
|
|
|
|
<mschwendt@yahoo.com>
|
|
|
|
|
|
|
|
* Tue May 8 2001 Bernhard Rosenkraenzer <bero@redhat.com> 1.2.2-1
|
|
|
|
- 1.2.2
|
|
|
|
|
2004-09-09 06:19:38 +00:00
|
|
|
* Wed Mar 21 2001 Bernhard Rosenkraenzer <bero@redhat.com>
|
|
|
|
- 1.2.1a, fixes #28412, #31136, #31460, #31133
|
|
|
|
|
|
|
|
* Thu Mar 1 2001 Bernhard Rosenkraenzer <bero@redhat.com>
|
|
|
|
- Yet another initscript fix (#30173)
|
|
|
|
- Fix the fixes; they fixed some issues but broke more important
|
|
|
|
stuff :/ (#30176)
|
|
|
|
|
|
|
|
* Tue Feb 27 2001 Bernhard Rosenkraenzer <bero@redhat.com>
|
|
|
|
- Fix up initscript (#27962)
|
|
|
|
- Add fixes from CVS to iptables-{restore,save}, fixing #28412
|
|
|
|
|
|
|
|
* Fri Feb 09 2001 Karsten Hopp <karsten@redhat.de>
|
|
|
|
- create /etc/sysconfig/iptables mode 600 (same problem as #24245)
|
|
|
|
|
|
|
|
* Mon Feb 05 2001 Karsten Hopp <karsten@redhat.de>
|
|
|
|
- fix bugzilla #25986 (initscript not marked as config file)
|
|
|
|
- fix bugzilla #25962 (iptables-restore)
|
|
|
|
- mv chkconfig --del from postun to preun
|
|
|
|
|
2007-08-23 14:54:50 +00:00
|
|
|
* Thu Feb 1 2001 Trond Eivind Glomsrød <teg@redhat.com>
|
2004-09-09 06:19:38 +00:00
|
|
|
- Fix check for ipchains
|
|
|
|
|
|
|
|
* Mon Jan 29 2001 Bernhard Rosenkraenzer <bero@redhat.com>
|
|
|
|
- Some fixes to init scripts
|
|
|
|
|
|
|
|
* Wed Jan 24 2001 Bernhard Rosenkraenzer <bero@redhat.com>
|
|
|
|
- Add some fixes from CVS, fixes among other things Bug #24732
|
|
|
|
|
|
|
|
* Wed Jan 17 2001 Bernhard Rosenkraenzer <bero@redhat.com>
|
|
|
|
- Add missing man pages, fix up init script (Bug #17676)
|
|
|
|
|
|
|
|
* Mon Jan 15 2001 Bill Nottingham <notting@redhat.com>
|
|
|
|
- add init script
|
|
|
|
|
|
|
|
* Mon Jan 15 2001 Bernhard Rosenkraenzer <bero@redhat.com>
|
|
|
|
- 1.2
|
|
|
|
- fix up ipv6 split
|
|
|
|
- add init script
|
|
|
|
- Move the plugins from /usr/lib/iptables to /lib/iptables.
|
|
|
|
This needs to work before /usr is mounted...
|
|
|
|
- Use -O1 on alpha (compiler bug)
|
|
|
|
|
|
|
|
* Sat Jan 6 2001 Bernhard Rosenkraenzer <bero@redhat.com>
|
|
|
|
- 1.1.2
|
|
|
|
- Add IPv6 support (in separate package)
|
|
|
|
|
2004-09-09 06:19:25 +00:00
|
|
|
* Thu Aug 17 2000 Bill Nottingham <notting@redhat.com>
|
|
|
|
- build everywhere
|
|
|
|
|
|
|
|
* Tue Jul 25 2000 Bernhard Rosenkraenzer <bero@redhat.com>
|
|
|
|
- 1.1.1
|
|
|
|
|
|
|
|
* Thu Jul 13 2000 Prospector <bugzilla@redhat.com>
|
|
|
|
- automatic rebuild
|
|
|
|
|
|
|
|
* Tue Jun 27 2000 Preston Brown <pbrown@redhat.com>
|
|
|
|
- move iptables to /sbin.
|
|
|
|
- excludearch alpha for now, not building there because of compiler bug(?)
|
|
|
|
|
|
|
|
* Fri Jun 9 2000 Bill Nottingham <notting@redhat.com>
|
|
|
|
- don't obsolete ipchains either
|
|
|
|
- update to 1.1.0
|
|
|
|
|
|
|
|
* Mon Jun 4 2000 Bill Nottingham <notting@redhat.com>
|
|
|
|
- remove explicit kernel requirement
|
|
|
|
|
2007-08-23 14:54:50 +00:00
|
|
|
* Tue May 2 2000 Bernhard Rosenkränzer <bero@redhat.com>
|
2004-09-09 06:19:25 +00:00
|
|
|
- initial package
|