Le mardi 17 août 2010 à 14:41 +0800, Changli Gao a écrit : > All the matches and targets of iptables, ip6tables are in BH disabled > context, since xt_info_rdlock_bh() disables BH. > Its a thing that might change in a future version. Not a hard fact. You can probably change iptables to allow softirqs while processing OUTPUT chains. We had some attempts in the past to switch to RCU. It failed at that time because of some RCU implementation details, but with recent RCU changes, we might try again, and have a clean implementation, allowing softirqs. So your patch would need to be reverted. -- To unsubscribe from this list: send the line "unsubscribe netfilter-devel" in the body of a message to majordomo@xxxxxxxxxxxxxxx More majordomo info at http://vger.kernel.org/majordomo-info.html