Nevermind, I think I know what's going on, I've found a bug in the new table=7* flows: the higher priority flows that are supposed to allow NAs for the ipv6 addresses match against nw_ttl=225 instead of nw_ttl=255, so legit NAs are not matching and fall back down to the default drop flow.
I will post the fix upstream this week. I will link it here.
Nevermind, I think I know what's going on, I've found a bug in the new table=7* flows: the higher priority flows that are supposed to allow NAs for the ipv6 addresses match against nw_ttl=225 instead of nw_ttl=255, so legit NAs are not matching and fall back down to the default drop flow.
I will post the fix upstream this week. I will link it here.