I'd *so* like to second that! I've had the displeasure of having to do downstream traffic shaping systems with several downward interfaces and that means having to deal with an IFB interface or the silly limitations Linux has on ingress shaping at the moment.
Why is it that I can't simply pipe traffic via a queue from any arbitrary firewall rule?