This is preliminary. I have reworked the module so it either use the
kernel 2.0 way or use the /sbin/ipchain utility. I did not use the
ipchain-wrapper. I generate (each time) a script in /var/run/ipchain.sh
and execute it. Check the output and test your firewall to make sure the
behavior is unchanged.
I have notice one problem with forwarding rules. It seems that the
semantic associated with the interface is different. Not sure. I have to
check in the kernel code to understand what is happening here.
Again, check it out and retest carefully before committing your firewall
to this new version.