On 19/04/2011 10:03, Maciej Åenczykowski wrote: > And the "Don't load ip6?_tables module when already loaded" patch is > now available in upstream git... > > That patch combined with my previous patch should solve all your woes. > If they don't... let me know. Yep, now I just see an attempt to modprobe "ip_set" (under limited circumstances), which seems reasonable given that I am on 2.6.38 and this isn't compiled in (nor is it a module) That said, I'm also slightly baffled where it's getting probed since I patched out xtables.c/xtables_load_ko(). The modprobe call doesn't have a -q on it, so I suspect somehow it might be the kernel or something else calling it? It's an acceptable casualty for the moment though... Thanks for your interest and looking into this - big increase in performance! Cheers Ed W -- To unsubscribe from this list: send the line "unsubscribe netfilter-devel" in the body of a message to majordomo@xxxxxxxxxxxxxxx More majordomo info at http://vger.kernel.org/majordomo-info.html