On 18. September 2014 15:35:52 MESZ, Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx> wrote: >Unless I'm missing anything, I think br_netfilter should have been a >separated module since the beginning. Yeah absolutely. Basic rule: don't impose the costs of your cool new feature on all the people who will never need it. Great someone finally fixes this up. Long term we still need a sane design for this though, some direct way of bridging to interact with conntrack, nftables provides for the rest. -- To unsubscribe from this list: send the line "unsubscribe netfilter-devel" in the body of a message to majordomo@xxxxxxxxxxxxxxx More majordomo info at http://vger.kernel.org/majordomo-info.html