mbuf tags - pf(4) hack pf(4) was massive user of mbuf tags Every packet got an mbuf tag if pf(4) enabled Instead pf meta data was moved directly into packet header pkt header grew a bit no malloc(9) overhead remaining data still big enough for small packets Doubled performance of pf(4) on a soekris box!