From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from mail-we0-x22e.google.com (mail-we0-x22e.google.com [IPv6:2a00:1450:400c:c03::22e]) (using TLSv1 with cipher RC4-SHA (128/128 bits)) (Client CN "smtp.gmail.com", Issuer "Google Internet Authority G2" (verified OK)) by huchra.bufferbloat.net (Postfix) with ESMTPS id 2FEE8201B02 for ; Mon, 21 Oct 2013 11:37:16 -0700 (PDT) Received: by mail-we0-f174.google.com with SMTP id u56so7040342wes.33 for ; Mon, 21 Oct 2013 11:37:14 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113; h=mime-version:date:message-id:subject:from:to:content-type :content-transfer-encoding; bh=3McHiRDv5thgDqqo7XUqAL0ExHKxDJzEe23AWZ22R9c=; b=YM8a231PJRpWdjCCN7smdN/ddQoZQdNk4EW6HlxWojlpfJkbvPpNDeoH8b2CY/C4nc jQFLNFq1aFB8tY29eNcrlBLIr30zRPvuJe5M2LBn59UHR7JWUai65ues2aeg7+ijiIA6 EGMG0cTK8d3FV4Q92AsSX+UOkuDgqfpEZsEvj4QymcmcIviawGfD2aWm5g5r2N+iJ9Ak 34akcYCkOuLnfmAFIawsF1bu5EAfaRhc7E9eNUbowVahVm7jypolugRJvakdQFdZol9o u2rKVlYVwv5LPHpYgoqXY6T6tPR8N/ew38eJnUfJbzdoX1ALSnPPZ54E73zneUQ1Go6j HxIg== MIME-Version: 1.0 X-Received: by 10.194.94.137 with SMTP id dc9mr6585252wjb.38.1382380634435; Mon, 21 Oct 2013 11:37:14 -0700 (PDT) Received: by 10.217.67.202 with HTTP; Mon, 21 Oct 2013 11:37:14 -0700 (PDT) Date: Mon, 21 Oct 2013 11:37:14 -0700 Message-ID: From: Dave Taht To: "cerowrt-devel@lists.bufferbloat.net" Content-Type: text/plain; charset=ISO-8859-1 Content-Transfer-Encoding: quoted-printable Subject: [Cerowrt-devel] nftables X-BeenThere: cerowrt-devel@lists.bufferbloat.net X-Mailman-Version: 2.1.13 Precedence: list List-Id: Development issues regarding the cerowrt test router project List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Mon, 21 Oct 2013 18:37:16 -0000 I am happy to see a replacement for iptables begin to emerge. There's lots of cool things about it, and it's my hope the vm is actually fast enough to use in complex ways. It's generally the "expressibility" of iptables that makes me bats; it's very difficult to automatically make efficient rules - a human can generally do much, much better. But that said: I don't plan to fiddle with it in this release cycle, nor, probably, the next. It's cool that it's landing in 3.13, but I would anticipate it taking several releases to shake out enough to even try out on a non-x86 platform. At the moment I plan to be on 3.10.X for a long time. And I'd like to get the "I" out of the paragraphs above and more into a "we= ". --=20 Dave T=E4ht Fixing bufferbloat with cerowrt: http://www.teklibre.com/cerowrt/subscribe.= html