From mboxrd@z Thu Jan 1 00:00:00 1970 From: David Miller Subject: Re: [PATCH net-next] netfilter: xt_socket: use IP early demux Date: Wed, 22 May 2013 14:27:33 -0700 (PDT) Message-ID: <20130522.142733.458456664835859037.davem@davemloft.net> References: <1369256466.3301.364.camel@edumazet-glaptop> Mime-Version: 1.0 Content-Type: Text/Plain; charset=us-ascii Content-Transfer-Encoding: 7bit Cc: pablo@netfilter.org, netdev@vger.kernel.org, netfilter-devel@vger.kernel.org, kaber@trash.net To: eric.dumazet@gmail.com Return-path: In-Reply-To: <1369256466.3301.364.camel@edumazet-glaptop> Sender: netdev-owner@vger.kernel.org List-Id: netfilter-devel.vger.kernel.org From: Eric Dumazet Date: Wed, 22 May 2013 14:01:06 -0700 > From: Eric Dumazet > > With IP early demux added in linux-3.6, we perform TCP lookup in IP > layer before iptables hooks. > > We can avoid doing a second lookup in xt_socket. > > Signed-off-by: Eric Dumazet Acked-by: David S. Miller