I do not use IPV6 on my systems. When emerging net-firewall/ufw-0.31.1 with USE="-ipv6", it fails because CONFIG_IP6_NF_MATCH_HL is not set in kernel configuration. Probably this check should be enforced only when compiling with support for IPV6.
It looks that it's an option provided only for backward compatibility and CONFIG_NETFILTER_XT_MATCH_HL should be checked instead. The change in Linux kernel "netfilter: Combine ipt_TTL and ip6t_HL source" was made in commit 563d36eb3fb22dd04da9aa6f12e1b9ba0ac115f3 and merged with 2.6.30 if I was looking correctly. The warning about unset option is non fatal so please ignore it until it's fixed.
Change commited to CVS. Sync in a couple of hours.