>That means that kernfs WOULD BE REQUIRED to support large numbers of >IPsec SAs. Where's the flaw in Matt Thomas' suggestion? That approach seems a much better approach to me, and it doesn't involve re-opening the thorny question of the status of kernfs.