On Thu, Feb 08, 2024 at 04:43:06PM -0800, Stanislav Fomichev wrote: > The check is here to make sure we only run this hook on non-req sockets. > Dropping it would mean we'd be running the hook on the listeners > instead. I don't think we want that. You are correct that we don't want to run the code on listeners. However the check for that is in the function this macro calls, __cgroup_bpf_run_filter_skb (the check is on line 1367 of kernel/bpf/cgroup.c, for 6.8.0-rc3). The check doesn't need to be done twice, so it can be removed in this macro.