During cleanup / refactoring of the qubes-whonix package, I was wondering...
For Whonix 12, I intent to move
Is there any reason against that?
Then the GATEWAY_IPv4_DROP_INVALID_INCOMING_PACKAGES_POST_HOOK (https://github.com/adrelanos/qubes-whonix/blob/master/etc/whonix_firewall.d/40_qubes) could be deprecated.
I would find that easier to grasp and maintain. From perspective of upgrading packages, time required for that, nothing would change.