Created https://github.com/openSUSE/aaa_base/pull/35 for Factory. One more observation: while testing the udev workaround, I realized that in kernel 3.18 bridge netfilter was moved out into a separate module br_netfilter so that these two sysctls only exist when br_netfilter module is loaded. As this module is even less likely to be loaded at sysctl processing time and one could argue that just the fact of loading it indicates user does want netfilter on bridges, I'm inclined to revert the change wherever kernel 3.18 or newer is used (i.e. Factory, all Leap 42.* and SLE12-SP{2,3}) and apply the udev trick only to SLE12-SP1.