Hi Florian, On Sat, 11 Jan 2025, Florian Westphal wrote: > > Also, why the "mark" match was not split into NFPROTO_IPV4, > > NFPROTO_ARP, NFPROTO_IPV6 explicitly (and other matches where the > > target was split)? > > mark match is fine, afaics. Whats the concern? > > The target got split because ebtables EBT_CONTINUE isn't equal to > XT_CONTINUE, so it won't do the right thing. I have just reread the description of your patch "netfilter: xtables: avoid NFPROTO_UNSPEC where needed" and now I see why the match is fine as is. Thanks! Best regards, Jozsef -- E-mail : kadlec@xxxxxxxxxxxxx, kadlec@xxxxxxxxxxxxxxxxx, kadlecsik.jozsef@xxxxxxxxx Address: Wigner Research Centre for Physics H-1525 Budapest 114, POB. 49, Hungary