BTW, we need a follow up patch. If the osf extension is used, then nft should automagically load the pf.os file under /etc/nftables/pf.os. This should only happen if only if the osf extension is used. Like this, we don't need to explicit run "nfnl_osf". Then next question is: a) Should we just import iptables/utils/nfnl_osf.c into nftables and use it. So we keep two copies in the tree? b) We add a libnetfilter_osf library, probably too much for a small codebase, but I don't like code redundancy. Not sure.. Any comments? In any case, would you work on this? Thanks! -- To unsubscribe from this list: send the line "unsubscribe netfilter-devel" in the body of a message to majordomo@xxxxxxxxxxxxxxx More majordomo info at http://vger.kernel.org/majordomo-info.html