Propose calling it -a --atomic instead of -d --delay and maybe --sequence --sequential or --onebyone for the opposite. Either way doing all the parsing, then attempting to apply, and if it fails attempting to undo it is probably the right default behaviour. -- To unsubscribe from this list: send the line "unsubscribe netfilter-devel" in the body of a message to majordomo@xxxxxxxxxxxxxxx More majordomo info at http://vger.kernel.org/majordomo-info.html