On Tue, 2 Apr 2019 at 00:37, Kevin Darbyshire-Bryant <ke...@darbyshire-bryant.me.uk> wrote: > > > > > On 23 Mar 2019, at 18:35, Kevin Darbyshire-Bryant > > <ke...@darbyshire-bryant.me.uk> wrote: > > > > > > > >> On 22 Mar 2019, at 21:24, Kevin Darbyshire-Bryant > >> <ke...@darbyshire-bryant.me.uk> wrote: > >> > >> It looks like act_conndscp has been shot down by the kernel people, at > >> least in its current form. Setting a conntrack mark from tc is regarded > >> as “not sure if it is a good idea”. The other way (conntrack to skb) is > >> fine. That’s sort of good news in that ingress is the hard bit as it’s > >> problematic with iptables. > >> > >> egress is within iptables coverage - ‘just’ need a way to store a DSCP & > >> flag to conntrack mark. > > > > Never give in, never surrender. > > > > Given in. Surrendered.
:( FWIW I've applied an updated patch with your iptables 'abomination' and it's been working without issue. _______________________________________________ Cake mailing list Cake@lists.bufferbloat.net https://lists.bufferbloat.net/listinfo/cake