The 1.8 patch seems largely incompatible with ipt_netflow 2.0. I tried a rewrite, but with no compatible kernel to test with, I quickly gave up. It would be nice to have a patch we can apply unconditionally, i.e. one that uses an arbitrary label with some #ifdefs.
+*ipt_netflow-2.0-r1 (19 Aug 2014) + + 19 Aug 2014; Sergey Popov <pinkbyte@gentoo.org> -ipt_netflow-2.0.ebuild, + +ipt_netflow-2.0-r1.ebuild, +files/ipt_netflow-2.0-pax-const.patch: + Revision bump: restore compatibility with hardened setups, wrt bug #519480, + add optional debugfs support. Drop old revision Unfortunately, i am not sure how to implement this properly. But adapted patch is in tree now and it works quite well, so this can be fixed for now.