All Virtuozzo development lists (kernel + QEMU)
 help / color / mirror / Atom feed
* [Devel] [PATCH vz10 1/4] selftests: netfilter: do not inherit forwarding and redirects
@ 2026-08-21 15:18 Eva Kurchatova
  2026-08-21 15:18 ` [Devel] [PATCH vz10 2/4] selftests: netfilter: add the veth pair from inside the namespace Eva Kurchatova
                   ` (2 more replies)
  0 siblings, 3 replies; 4+ messages in thread
From: Eva Kurchatova @ 2026-08-21 15:18 UTC (permalink / raw)


A new namespace takes ip_forward and send_redirects from the host, so
two tests depend on how the machine outside them is configured.

On a host that forwards, which any hypervisor does, nft_fib's ns1 and
ns2 send the test packets back at the router until their TTL runs out,
and the fib counters end at 31 or 62 packets instead of 1:

  FAIL: fibif4 not empty
    elements = { "veth1" . 10.0.1.99 . "veth0" counter packets 62 ...

Only nsrouter is meant to forward, so turn forwarding off in the
endpoints.  conntrack_icmp_related needs the opposite: images routinely
turn send_redirects off, and the router then never sends the redirect
the test waits for:

  ERROR: counter redir4 in nsclient1 has unexpected value

Set both where the test needs them rather than relying on the host.

https://virtuozzo.atlassian.net/browse/VSTOR-139651
Feature: fix selftests
Signed-off-by: Eva Kurchatova <eva.kurchatova@virtuozzo.com>
---
 .../selftests/net/netfilter/conntrack_icmp_related.sh     | 6 ++++++
 tools/testing/selftests/net/netfilter/nft_fib.sh          | 8 ++++++++
 2 files changed, 14 insertions(+)

diff --git a/tools/testing/selftests/net/netfilter/conntrack_icmp_related.sh b/tools/testing/selftests/net/netfilter/conntrack_icmp_related.sh
index c63d840ead61..44a98c53d085 100755
--- a/tools/testing/selftests/net/netfilter/conntrack_icmp_related.sh
+++ b/tools/testing/selftests/net/netfilter/conntrack_icmp_related.sh
@@ -253,6 +253,12 @@ else
 fi
 
 # add 'bad' route,  expect icmp REDIRECT to be generated
+# A new namespace inherits send_redirects from the host, where it is
+# often turned off; without it the router never sends the redirect this
+# part of the test waits for.
+ip netns exec "$nsrouter1" sysctl -q net.ipv4.conf.all.send_redirects=1
+ip netns exec "$nsrouter1" sysctl -q net.ipv4.conf.default.send_redirects=1
+
 ip netns exec "${nsclient1}" ip route add 192.168.1.42 via 192.168.1.1
 ip netns exec "${nsclient1}" ip route add dead:1::42 via dead:1::1
 
diff --git a/tools/testing/selftests/net/netfilter/nft_fib.sh b/tools/testing/selftests/net/netfilter/nft_fib.sh
index 9929a9ffef65..c818b544e57b 100755
--- a/tools/testing/selftests/net/netfilter/nft_fib.sh
+++ b/tools/testing/selftests/net/netfilter/nft_fib.sh
@@ -29,6 +29,14 @@ setup_ns nsrouter ns1 ns2
 
 trap cleanup EXIT
 
+# A new namespace inherits ip_forward from the host, and on a host that
+# forwards, ns1 and ns2 bounce the test packets back at the router until
+# their TTL runs out. Only nsrouter is meant to forward here.
+for ns in "$ns1" "$ns2"; do
+	ip netns exec "$ns" sysctl -q net.ipv4.ip_forward=0
+	ip netns exec "$ns" sysctl -q net.ipv6.conf.all.forwarding=0
+done
+
 if dmesg | grep -q ' nft_rpfilter: ';then
 	dmesg -c | grep ' nft_rpfilter: '
 	echo "WARN: a previous test run has failed" 1>&2
-- 
2.55.0


^ permalink raw reply	[flat|nested] 4+ messages in thread

* [Devel] [PATCH vz10 2/4] selftests: netfilter: add the veth pair from inside the namespace
  2026-08-21 15:18 [Devel] [PATCH vz10 1/4] selftests: netfilter: do not inherit forwarding and redirects Eva Kurchatova
@ 2026-08-21 15:18 ` Eva Kurchatova
  2026-08-21 15:18 ` [Devel] [PATCH vz10 3/4] selftests: netfilter: skip rpath.sh without the nft tool Eva Kurchatova
  2026-08-21 15:18 ` [Devel] [PATCH vz10 4/4] selftests: netfilter: nf_conntrack_expect_max is pernet here Eva Kurchatova
  2 siblings, 0 replies; 4+ messages in thread
From: Eva Kurchatova @ 2026-08-21 15:18 UTC (permalink / raw)


Both tests add a veth by name while running in the initial namespace.
The name of the new device is taken there, not in the namespace passed to
netns, so a device of that name left behind by another test makes the add
fail and the test then runs with no connectivity at all:

  # RTNETLINK answers: File exists
  # Cannot find device "veth1"
  # FAIL: socat cannot connect via NAT'd address

Add the pair from inside one of the namespaces instead.  Those are made
by setup_ns and are empty, and the peer is created directly in its own
namespace, so no name from the initial namespace is in the way.

br_netfilter.sh checked only the first of its four adds, so a failure of
any of the others was silent and turned up 90 lines later as a ping to a
namespace that had no interface.  Check all four.

https://virtuozzo.atlassian.net/browse/VSTOR-139651
Feature: fix selftests
Signed-off-by: Eva Kurchatova <eva.kurchatova@virtuozzo.com>
---
 .../selftests/net/netfilter/br_netfilter.sh   | 21 ++++++++++++-------
 .../selftests/net/netfilter/nf_nat_edemux.sh  | 12 +++++++----
 2 files changed, 21 insertions(+), 12 deletions(-)

diff --git a/tools/testing/selftests/net/netfilter/br_netfilter.sh b/tools/testing/selftests/net/netfilter/br_netfilter.sh
index 011de8763094..e4480c9db86e 100755
--- a/tools/testing/selftests/net/netfilter/br_netfilter.sh
+++ b/tools/testing/selftests/net/netfilter/br_netfilter.sh
@@ -60,14 +60,19 @@ bcast_ping()
 	done
 }
 
-if ! ip link add veth1 netns "$ns0" type veth peer name eth0 netns "$ns1"; then
-	echo "SKIP: Can't create veth device"
-	exit $ksft_skip
-fi
-
-ip link add veth2 netns "$ns0" type veth peer name eth0 netns "$ns2"
-ip link add veth3 netns "$ns0" type veth peer name eth0 netns "$ns3"
-ip link add veth4 netns "$ns0" type veth peer name eth0 netns "$ns4"
+# Add the pairs from inside ns0: the name of the new device is taken in the
+# namespace the command runs in, so adding them here would fail if a device
+# of that name was left behind in the initial namespace.  Only veth1 used to
+# be checked, and a silent failure for one of the others left a namespace
+# with no interface at all, which showed up as a ping failure much later.
+for i in $(seq 1 4); do
+	nsvar="ns$i"
+	if ! ip -net "$ns0" link add "veth$i" type veth \
+		peer name eth0 netns "${!nsvar}"; then
+		echo "SKIP: Can't create veth device"
+		exit $ksft_skip
+	fi
+done
 
 for i in $(seq 1 4); do
   ip -net "$ns0" link set "veth$i" up
diff --git a/tools/testing/selftests/net/netfilter/nf_nat_edemux.sh b/tools/testing/selftests/net/netfilter/nf_nat_edemux.sh
index 1014551dd769..9d655d525104 100755
--- a/tools/testing/selftests/net/netfilter/nf_nat_edemux.sh
+++ b/tools/testing/selftests/net/netfilter/nf_nat_edemux.sh
@@ -22,10 +22,14 @@ trap cleanup EXIT
 
 setup_ns ns1 ns2
 
-# Connect the namespaces using a veth pair
-ip link add name veth2 type veth peer name veth1
-ip link set netns "$ns1" dev veth1
-ip link set netns "$ns2" dev veth2
+# Connect the namespaces using a veth pair.  Add it from inside ns1: the
+# name of the new device is taken in the namespace the command runs in, so
+# adding it here would fail if a device of that name was left behind in the
+# initial namespace, and the test would then run without connectivity.
+if ! ip -net "$ns1" link add name veth1 type veth peer name veth2 netns "$ns2"; then
+	echo "SKIP: Can't create veth device"
+	exit $ksft_skip
+fi
 
 ip netns exec "$ns1" ip link set up dev lo
 ip netns exec "$ns1" ip link set up dev veth1
-- 
2.55.0


^ permalink raw reply	[flat|nested] 4+ messages in thread

* [Devel] [PATCH vz10 3/4] selftests: netfilter: skip rpath.sh without the nft tool
  2026-08-21 15:18 [Devel] [PATCH vz10 1/4] selftests: netfilter: do not inherit forwarding and redirects Eva Kurchatova
  2026-08-21 15:18 ` [Devel] [PATCH vz10 2/4] selftests: netfilter: add the veth pair from inside the namespace Eva Kurchatova
@ 2026-08-21 15:18 ` Eva Kurchatova
  2026-08-21 15:18 ` [Devel] [PATCH vz10 4/4] selftests: netfilter: nf_conntrack_expect_max is pernet here Eva Kurchatova
  2 siblings, 0 replies; 4+ messages in thread
From: Eva Kurchatova @ 2026-08-21 15:18 UTC (permalink / raw)


Every other netfilter test that needs nft checks for it. rpath.sh does
not, and without the tool it reports "nft IPv4 match not effective"
instead of skipping.

https://virtuozzo.atlassian.net/browse/VSTOR-139651
Feature: fix selftests
Signed-off-by: Eva Kurchatova <eva.kurchatova@virtuozzo.com>
---
 tools/testing/selftests/net/netfilter/rpath.sh | 3 +++
 1 file changed, 3 insertions(+)

diff --git a/tools/testing/selftests/net/netfilter/rpath.sh b/tools/testing/selftests/net/netfilter/rpath.sh
index 90cc21233235..5c71cb43ae0a 100755
--- a/tools/testing/selftests/net/netfilter/rpath.sh
+++ b/tools/testing/selftests/net/netfilter/rpath.sh
@@ -3,6 +3,9 @@
 
 source lib.sh
 
+checktool "nft --version" "run test without nft tool"
+checktool "ip -Version" "run test without ip tool"
+
 # search for legacy iptables (it uses the xtables extensions
 if iptables-legacy --version >/dev/null 2>&1; then
 	iptables='iptables-legacy'
-- 
2.55.0


^ permalink raw reply	[flat|nested] 4+ messages in thread

* [Devel] [PATCH vz10 4/4] selftests: netfilter: nf_conntrack_expect_max is pernet here
  2026-08-21 15:18 [Devel] [PATCH vz10 1/4] selftests: netfilter: do not inherit forwarding and redirects Eva Kurchatova
  2026-08-21 15:18 ` [Devel] [PATCH vz10 2/4] selftests: netfilter: add the veth pair from inside the namespace Eva Kurchatova
  2026-08-21 15:18 ` [Devel] [PATCH vz10 3/4] selftests: netfilter: skip rpath.sh without the nft tool Eva Kurchatova
@ 2026-08-21 15:18 ` Eva Kurchatova
  2 siblings, 0 replies; 4+ messages in thread
From: Eva Kurchatova @ 2026-08-21 15:18 UTC (permalink / raw)


The test requires it to be settable from init_net only, while vz
virtualizes it deliberately:

  6d854968102f ("ve/netfilter: Implement pernet expect_max / virtualize
  "net.netfilter.nf_conntrack_expect_max" sysctl")

https://virtuozzo.atlassian.net/browse/VSTOR-139651
Feature: fix vz selftests
Signed-off-by: Eva Kurchatova <eva.kurchatova@virtuozzo.com>
---
 tools/testing/selftests/net/netfilter/conntrack_resize.sh | 6 ++++--
 1 file changed, 4 insertions(+), 2 deletions(-)

diff --git a/tools/testing/selftests/net/netfilter/conntrack_resize.sh b/tools/testing/selftests/net/netfilter/conntrack_resize.sh
index aa1ba07eaf50..324259632daa 100755
--- a/tools/testing/selftests/net/netfilter/conntrack_resize.sh
+++ b/tools/testing/selftests/net/netfilter/conntrack_resize.sh
@@ -457,8 +457,10 @@ check_max_alias 262000
 
 setup_ns nsclient1 nsclient2
 
-# check this only works from init_net
-for n in netfilter.nf_conntrack_buckets netfilter.nf_conntrack_expect_max net.nf_conntrack_max;do
+# check this only works from init_net.  nf_conntrack_expect_max is left
+# out: vz virtualizes it on purpose, see "ve/netfilter: Implement pernet
+# expect_max".
+for n in netfilter.nf_conntrack_buckets net.nf_conntrack_max;do
 	check_sysctl_immutable "$nsclient1" "net.$n" 1
 done
 
-- 
2.55.0


^ permalink raw reply	[flat|nested] 4+ messages in thread

end of thread, other threads:[~2026-08-21 15:18 UTC | newest]

Thread overview: 4+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-08-21 15:18 [Devel] [PATCH vz10 1/4] selftests: netfilter: do not inherit forwarding and redirects Eva Kurchatova
2026-08-21 15:18 ` [Devel] [PATCH vz10 2/4] selftests: netfilter: add the veth pair from inside the namespace Eva Kurchatova
2026-08-21 15:18 ` [Devel] [PATCH vz10 3/4] selftests: netfilter: skip rpath.sh without the nft tool Eva Kurchatova
2026-08-21 15:18 ` [Devel] [PATCH vz10 4/4] selftests: netfilter: nf_conntrack_expect_max is pernet here Eva Kurchatova

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.