The iptables (1.3.5-r1 = current stable on AMD64) extension "condition" (of current POM) has the following tests (iptables-1.3.5-r1/extensions/.condition-test*): [ -f $KERNEL_DIR/include/linux/netfilter_ipv4/ipt_condition.h ] && echo condition [ -f $KERNEL_DIR/include/linux/netfilter_ipv6/ip6t_condition.h ] && echo condition but in the current POM there is just one match for both ip versions. The file to test for is at $KERNEL_DIR/include/linux/netfilter/xt_condition.h I only use ipv4, so I changed two lines: the test and the include to point to the correct file (sym-link would work as well) and it seems to work.
upstream iptables svn is still the same way ... i dont see the condition.h patch in upstream svn though you should file this bug here: https://bugzilla.netfilter.org/bugzilla/