[ANNOUNCE] nftables 1.1.1 release

From: Pablo Neira Ayuso <pablo@netfilter.org>
Date: 2024-10-02 22:57:38
Also in: netfilter-devel

Hi!

The Netfilter project proudly presents:

        nftables 1.1.1

This release contains mostly fixes, listed in no particular order:

- reduce netlink cache dependencies to speed up incremental updates.
- fix UDP packet mangling when checksum field is zero.
- several fixes for nft reset command.
- JSON parser fixes.
- variables are not supported by -o/--optimize.
- allow zero burst in byte ratelimiter.

  table netdev filter {
       set test123 {
               typeof ip saddr
               limit rate over 1 mbytes/second
               elements = { 1.2.3.4 limit rate over 1 mbytes/second }
       }
  }

- fix double-free when users call nft_ctx_clear_vars() first, then nft_ctx_free().
- document that tproxy statement is non-terminal (compared to iptables).
  This allows for tproxy+log and tproxy+mark combos, see man nft(8) for details.
- add egress support for 'list hooks'.

  # nft list hooks netdev device eth0
  family netdev {
          hook ingress device eth0 {
                   0000000000 chain inet ingress in_public [nf_tables]
                   0000000000 chain netdev ingress in_public [nf_tables]
          }
          hook egress device eth0 {
                   0000000000 chain netdev ingress out_public [nf_tables]
          }
  }

- fix listing inconsistencies in "nft list hooks".
- "nft list hooks netdev" now iterates all interfaces and then list all of them.
- document "nft list hooks" command, see man nft(8).

... including manpage updates too and tests enhancements.

See changelog for more details (attached to this email).

You can download this new release from:

https://www.netfilter.org/projects/nftables/downloads.html
https://www.netfilter.org/pub/nftables/

[ NOTE: We have switched to .tar.xz files for releases. ]

To build the code, libnftnl >= 1.2.8 and libmnl >= 1.0.4 are required:

* https://netfilter.org/projects/libnftnl/index.html
* https://netfilter.org/projects/libmnl/index.html

Visit our wikipage for user documentation at:

* https://wiki.nftables.org

For the manpage reference, check man(8) nft.

In case of bugs and feature requests, file them via:

* https://bugzilla.netfilter.org

Happy firewalling.

Attachments

Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help