* The fix that was submitted via PR was accepted and commited.
+- NPF
+ - Lack of proper diagnostics/stats
+ - Lacks various old ipfilter features which are necessary
+ - Things like icmp-type and icmp-code symbolic names undocumented, numbers
+ must be used except for some
+ - Can display as syntax errors other problems
+ - Documentation not properly synchronized with implementation, and lacking
+ - npfctl show bogus
+ - npfctl stop may lock in a busy loop, unkillable process
+ - npfctl stats cannot show per-rule hits
+ - Annoying syntax changes between versions
+ - Appears too immature on netbsd-6, to recheck on netbsd-7
+
- veriexec
- Lock related panic when attempting to write to a veriexec protected file
in strict level 2.