From: Jason Xing <kernelxing@xxxxxxxxxxx> Just simply replace the -NF_DROP with NF_DROP since it is just zero. Jason Xing (3): netfilter: using NF_DROP in test statement in nf_conntrack_in() netfilter: use NF_DROP in iptable_filter_table_init() netfilter: use NF_DROP in ip6table_filter_table_init() net/ipv4/netfilter/iptable_filter.c | 2 +- net/ipv6/netfilter/ip6table_filter.c | 2 +- net/netfilter/nf_conntrack_core.c | 2 +- 3 files changed, 3 insertions(+), 3 deletions(-) -- 2.37.3