On Fri, May 17, 2019 at 04:27:29PM +0100, Edward Cree wrote: > On 15/05/2019 20:39, Edward Cree wrote: [...] > Pablo, how do the two options interact with your netfilter offload? I'm > guessing it's easier for you to find a unique pointer than to generate > a unique u32 action_index for each action. I'm also assuming that > netfilter doesn't have a notion of shared actions.
It has that shared actions concept, see: https://netfilter.org/projects/nfacct/ Have a look at 'nfacct' in iptables-extensions(8) manpage.