On Wed, Sep 06, 2023 at 07:08:40PM +0200, Phil Sutter wrote: [...] > The last six come from the 'reset rules table t1' command. While on one > hand it looks like nftables fits only three rules into a single skb, > your fix seems to have a problem in that it doesn't subtract s_idx from > *idx. Please, feel free to follow up to refine, thanks.