add kernel support for iptables comment match