Created attachment 294025 [details] Kernel config before editing Kconfig to allow NET_ACT_CONNMARK I have disabled iptables in kernel config (only nftables enabled). There is a dependency to IP_NF_IPTABLES for NET_ACT_CONNMARK. I edited the Kconfig file and it compiles and works fine on my machine without IP_NF_IPTABLES. Maybe the dependency should be changed some way? Here is what I did to make the module compile: diff --git a/net/sched/Kconfig b/net/sched/Kconfig index a3b37d88800e..4bb5c04b72d3 100644 --- a/net/sched/Kconfig +++ b/net/sched/Kconfig @@ -912,7 +912,7 @@ config NET_ACT_BPF config NET_ACT_CONNMARK tristate "Netfilter Connection Mark Retriever" - depends on NET_CLS_ACT && NETFILTER && IP_NF_IPTABLES + depends on NET_CLS_ACT && NETFILTER depends on NF_CONNTRACK && NF_CONNTRACK_MARK help Say Y here to allow retrieving of conn mark
IP_NF_IPTABLES is a superfluous dependency. Would you mind you submit this patch to netfilter-devel@vger.kernel.org? Please, also add your Signed-off-by: tag Thanks.