From mboxrd@z Thu Jan 1 00:00:00 1970 From: James Morris Subject: Re: [RFC] SECMARK 1.1 Date: Mon, 15 May 2006 02:22:14 -0400 (EDT) Message-ID: References: <446778F0.6000705@trash.net> <446811D3.5080905@trash.net> <446819FE.8050300@trash.net> Mime-Version: 1.0 Content-Type: TEXT/PLAIN; charset=US-ASCII Cc: selinux@tycho.nsa.gov, netdev@vger.kernel.org, netfilter-devel@lists.netfilter.org, Stephen Smalley , Daniel J Walsh , Karl MacMillan , "David S. Miller" , Thomas Bleher Return-path: Received: from mail1.sea5.speakeasy.net ([69.17.117.3]:23954 "EHLO mail1.sea5.speakeasy.net") by vger.kernel.org with ESMTP id S932273AbWEOGWQ (ORCPT ); Mon, 15 May 2006 02:22:16 -0400 To: Patrick McHardy In-Reply-To: <446819FE.8050300@trash.net> Sender: netdev-owner@vger.kernel.org List-Id: netdev.vger.kernel.org On Mon, 15 May 2006, Patrick McHardy wrote: > > Not sure what you mean: it will cause ip_conntrack to be loaded, which > > is needed when you specify the track flag. > > > Yes, but the reason why it is loaded is because the module loader needs > to resolve the symbol, not because of anything done at module runtime. Am I missing something? This is what I want to happen. If you specify SECMARK --track, ip_conntrack is to be loaded. -- James Morris