The first patch completes the marking of inbound kernel SAs. The second enables to configure the mark_in_sa option in ipsec.conf connection section. Since it is a compatibility option with an older behavior, let us enable to configure it via this legacy API.