- CONFIG_CONNECTOR y/m if you wish to receive userspace
notifications from pknock through netlink/connector
- For ipset-5 you need:
-Extra notes:
-
- * in the kernel 2.6.18.x series, >= 2.6.18.5 is required
-
- * requires that no vendor backports interfere
-
+ For ipset-6 you need:
* libmnl
HEAD
====
+ Enhancements:
+ - update to ipset 6.0
+ * allow "new" as a commad alias to "create"
+ * ipset: improve command argument parsing
+ * ipset: avoid the unnecessary argv[] loop
+ * ipset: pass ipset_arg argument pointer
+ * separate ipset errnos completely from system ones and bump protocol version
+ * resolving IP addresses did not work at listing/saving sets, fixed
+ * ipset: fix spelling error
+ * ipset: fix the Netlink sequence number
+ * ipset: turn Set name[] into a const pointer
+ * check ICMP and ICMPv6 with the set match and target in the testsuite
+ * avoid possible syntax clashing at saving hostnames
+ * fix linking with CONFIG_IPV6=n
+ - update to ipset 6.1
+ * sctp, udplite support for the hash:*port* types
+ * fix hash:*port* types ignoring the address range for non-{tcp,udp}
+ * revision reporting fixes
+ - update to ipset 6.2
+ * list:set timeout variant fixes
+ - update to ipset 6.3
+ * bitmap:ip,mac type requires "src" for MAC, enforce it
+ - ipset-genl: handle EAGAIN return value emitted from autoloader
+ - ipset-genl: resolve nfgenmsg remains and fix spurious protocol abort
+v1.34 (2011-04-07)
+==================
+Fixes:
+- xt_pknock: avoid crash when hash TFM could not be allocated
+- xt_pknock: avoid inversion of rule lookup that led to warnings
+- xt_DNETMAP: add missing module alias
+- xt_DNETMAP: support for kernels below 2.6.34
+Changes:
+- Linux kernel versions below 2.6.29 are no longer officially
+ supported, and will not be part of compilation testing.
+ Expect that compat code will be removed shortly.
+
+
v1.33 (2011-02-02)
==================
Fixes: