Done, thank you! Initial patch set will be posted in follow-up in
Yes, I see the reasoning behind keep state. If keep state were on
by default, though, I think I'd want it to be pickups rather then
no-pickups. I just can't wrap my head around it blowing up TCP
connections. However, if one explicitly specified a keep state
directive for a rule, I agree the default should be no-pickups.
-Matt