ctnetlink_get_conntrack is always called from user context, so GFP_KERNEL is enough. -- The dawn of the fourth age of Linux firewalling is coming; a time of great struggle and heroic deeds -- J.Kadlecsik got inspired by J.Morris