From patchwork Thu Feb 5 22:00:50 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Adolf Belka X-Patchwork-Id: 9483 Return-Path: Received: from mail01.ipfire.org (mail01.haj.ipfire.org [172.28.1.202]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature ECDSA (secp384r1 raw public key) server-digest SHA384 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "mail01.haj.ipfire.org", Issuer "R12" (verified OK)) by web04.haj.ipfire.org (Postfix) with ESMTPS id 4f6WPx33X9z3wjn for ; Thu, 05 Feb 2026 22:01:09 +0000 (UTC) Received: from mail02.haj.ipfire.org (mail02.haj.ipfire.org [IPv6:2001:678:b28::201]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519) (Client CN "mail02.haj.ipfire.org", Issuer "E8" (verified OK)) by mail01.ipfire.org (Postfix) with ESMTPS id 4f6WPv6v6mz5dN for ; Thu, 05 Feb 2026 22:01:07 +0000 (UTC) Received: from mail02.haj.ipfire.org (localhost [IPv6:::1]) by mail02.haj.ipfire.org (Postfix) with ESMTP id 4f6WPv1DB5z3397 for ; Thu, 05 Feb 2026 22:01:07 +0000 (UTC) X-Original-To: development@lists.ipfire.org Received: from mail01.ipfire.org (mail01.haj.ipfire.org [172.28.1.202]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature ECDSA (secp384r1 raw public key) server-digest SHA384 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "mail01.haj.ipfire.org", Issuer "R12" (verified OK)) by mail02.haj.ipfire.org (Postfix) with ESMTPS id 4f6WPr30FWz2xKR for ; Thu, 05 Feb 2026 22:01:04 +0000 (UTC) Received: from [127.0.0.1] (localhost [127.0.0.1]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (No client certificate requested) by mail01.ipfire.org (Postfix) with ESMTPSA id 4f6WPq1rcsznL; Thu, 05 Feb 2026 22:01:03 +0000 (UTC) DKIM-Signature: v=1; a=ed25519-sha256; c=relaxed/relaxed; d=ipfire.org; s=202003ed25519; t=1770328863; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding; bh=dJ5JYoU62cY+wbl398m6vIAD1vfDTaoTHGtcZOQt4bA=; b=YOs+ZjqRlXfLOSyvxYZGLVc1gILAaWIFPkHzyE6LetvgAwZJWLLcYlHqpuaPrCrVQ0Nl8J K10JOKgBTiuR3GAw== DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ipfire.org; s=202003rsa; t=1770328863; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding; bh=dJ5JYoU62cY+wbl398m6vIAD1vfDTaoTHGtcZOQt4bA=; b=Px7Z22psQq8X9JJt33J8kgprX7TsQmVAL1OQCbhIT71ZP6AsfcDUakqP2hZ7N9mu/oZD1u 1GinlB/s4DX9g60TugQb4eXxIUDaJbZXDjJTy/sF4og7VhIApVSv+HV4FGClmBdnaRuraL sW78vx3fY1k5MdQRn9zjNoDhKL4B/GVwtYLPXVZqC3ZpiDyjeylspAo7n7DGCrgHSY2hMr RMF8Px7QdhPC4SpT8xBF+QYohdw25UU96zeQMwg1OeAt0IimhlgLHLY0FTNKbtT5ra5oCt x54XEBf/BLtt4xMf3c0Y/QnLTPgO9VRY0q5UN6AWvXv1RV3bwmfwNrgoNw6akw== From: Adolf Belka To: development@lists.ipfire.org Cc: Adolf Belka Subject: [PATCH] conntrack-tools: Update to version 1.4.9 Date: Thu, 5 Feb 2026 23:00:50 +0100 Message-ID: <20260205220059.3721136-1-adolf.belka@ipfire.org> Precedence: list List-Id: List-Subscribe: , List-Unsubscribe: , List-Post: List-Help: Sender: Mail-Followup-To: MIME-Version: 1.0 - Update from version 1.4.8 to 1.4.9 - No change to rootfile - Changelog 1.4.9 This release contains bugfixes, for the conntrack cli: - skip ENOSPC on updates when ct label is not available - don't print [USERSPACE] information in case of XML output - fix parsing of tuple-port-src and tuple-port-dst - improve --secmark,--id,--zone parser - improve --mark parser - fix for ENOENT in delete to align behaviour with updates - fix compiler warnings with -Wcalloc-transposed-args - prefer kernel-provided event timestamp via CTA_TIMESTAMP_EVENT if it is available - introduce --labelmap option to specify connlabel.conf path - Extend error message for EBUSY when registering userspace helper and the conntrackd daemon: - don't add expectation table entry for RPC portmap port - fix signal handler race-condition - restrict multicast reception, otherwise multicast sync messages can be received from any interface if your firewall policy does not restrict the interface used for sending and receiving them. - remove double close() in multicast resulting in EBADFD Signed-off-by: Adolf Belka --- lfs/conntrack-tools | 9 +++++---- 1 file changed, 5 insertions(+), 4 deletions(-) diff --git a/lfs/conntrack-tools b/lfs/conntrack-tools index 65f8b02b7..5872d73b1 100644 --- a/lfs/conntrack-tools +++ b/lfs/conntrack-tools @@ -1,7 +1,7 @@ ############################################################################### # # # IPFire.org - A linux based firewall # -# Copyright (C) 2007-2024 IPFire Team # +# Copyright (C) 2007-2026 IPFire Team # # # # This program is free software: you can redistribute it and/or modify # # it under the terms of the GNU General Public License as published by # @@ -24,7 +24,7 @@ include Config -VER = 1.4.8 +VER = 1.4.9 THISAPP = conntrack-tools-$(VER) DL_FILE = $(THISAPP).tar.xz @@ -42,7 +42,7 @@ objects = $(DL_FILE) $(DL_FILE) = $(DL_FROM)/$(DL_FILE) -$(DL_FILE)_BLAKE2 = 2f8a7d7facf4890a8ca7dec54d5faa1383ad5e449a0599707578567e9c8ed6fd63ca308538afc34e99121e39e80c1ce686c8dda89247abdf4699bb420b52c4fb +$(DL_FILE)_BLAKE2 = afa7aa685e20be510d7a7a916625d83f34d305212b8b86d4de94976d2212886391a45acdba3e906a7b6614b6476e61ead6648ee567458d3a90ebbe2eccbd3e7b install : $(TARGET) @@ -72,7 +72,8 @@ $(subst %,%_BLAKE2,$(objects)) : $(TARGET) : $(patsubst %,$(DIR_DL)/%,$(objects)) @$(PREBUILD) @rm -rf $(DIR_APP) && cd $(DIR_SRC) && tar axf $(DIR_DL)/$(DL_FILE) - cd $(DIR_APP) && ./configure --prefix=/usr + cd $(DIR_APP) && ./configure \ + --prefix=/usr cd $(DIR_APP) && make $(MAKETUNING) cd $(DIR_APP) && make install @rm -rf $(DIR_APP)