On Thursday 2009-03-12 16:49, Christoph Paasch wrote: >On Thu March 12 2009 wrote Jan Engelhardt: >> On Thursday 2009-03-12 16:13, Christoph Paasch wrote: >> >As NF_DROP = 0, no packets would ever have been dropped. >> >> Mh would not it be safer to actually give NF_DROP a real value so that >> -NF_DROP also makes sense? >Yes, why not... > >> (Might need checking places where NF_DROP is used.) >NF_DROP is used only in tcp_packet (as far as I can see, no other l4 proto >uses it in *_packet) NF_DROP is also used in net/netfilter/x_tables.c - that's what I meant. -- To unsubscribe from this list: send the line "unsubscribe netfilter-devel" in the body of a message to majordomo@xxxxxxxxxxxxxxx More majordomo info at http://vger.kernel.org/majordomo-info.html