All Virtuozzo development lists (kernel + QEMU)
 help / color / mirror / Atom feed
* [Devel] [PATCH vz10 1/4] selftests: netfilter: do not inherit forwarding and redirects
@ 2026-08-21 15:18 Eva Kurchatova
  2026-08-21 15:18 ` [Devel] [PATCH vz10 2/4] selftests: netfilter: add the veth pair from inside the namespace Eva Kurchatova
                   ` (2 more replies)
  0 siblings, 3 replies; 4+ messages in thread
From: Eva Kurchatova @ 2026-08-21 15:18 UTC (permalink / raw)


A new namespace takes ip_forward and send_redirects from the host, so
two tests depend on how the machine outside them is configured.

On a host that forwards, which any hypervisor does, nft_fib's ns1 and
ns2 send the test packets back at the router until their TTL runs out,
and the fib counters end at 31 or 62 packets instead of 1:

  FAIL: fibif4 not empty
    elements = { "veth1" . 10.0.1.99 . "veth0" counter packets 62 ...

Only nsrouter is meant to forward, so turn forwarding off in the
endpoints.  conntrack_icmp_related needs the opposite: images routinely
turn send_redirects off, and the router then never sends the redirect
the test waits for:

  ERROR: counter redir4 in nsclient1 has unexpected value

Set both where the test needs them rather than relying on the host.

https://virtuozzo.atlassian.net/browse/VSTOR-139651
Feature: fix selftests
Signed-off-by: Eva Kurchatova <eva.kurchatova@virtuozzo.com>
---
 .../selftests/net/netfilter/conntrack_icmp_related.sh     | 6 ++++++
 tools/testing/selftests/net/netfilter/nft_fib.sh          | 8 ++++++++
 2 files changed, 14 insertions(+)

diff --git a/tools/testing/selftests/net/netfilter/conntrack_icmp_related.sh b/tools/testing/selftests/net/netfilter/conntrack_icmp_related.sh
index c63d840ead61..44a98c53d085 100755
--- a/tools/testing/selftests/net/netfilter/conntrack_icmp_related.sh
+++ b/tools/testing/selftests/net/netfilter/conntrack_icmp_related.sh
@@ -253,6 +253,12 @@ else
 fi
 
 # add 'bad' route,  expect icmp REDIRECT to be generated
+# A new namespace inherits send_redirects from the host, where it is
+# often turned off; without it the router never sends the redirect this
+# part of the test waits for.
+ip netns exec "$nsrouter1" sysctl -q net.ipv4.conf.all.send_redirects=1
+ip netns exec "$nsrouter1" sysctl -q net.ipv4.conf.default.send_redirects=1
+
 ip netns exec "${nsclient1}" ip route add 192.168.1.42 via 192.168.1.1
 ip netns exec "${nsclient1}" ip route add dead:1::42 via dead:1::1
 
diff --git a/tools/testing/selftests/net/netfilter/nft_fib.sh b/tools/testing/selftests/net/netfilter/nft_fib.sh
index 9929a9ffef65..c818b544e57b 100755
--- a/tools/testing/selftests/net/netfilter/nft_fib.sh
+++ b/tools/testing/selftests/net/netfilter/nft_fib.sh
@@ -29,6 +29,14 @@ setup_ns nsrouter ns1 ns2
 
 trap cleanup EXIT
 
+# A new namespace inherits ip_forward from the host, and on a host that
+# forwards, ns1 and ns2 bounce the test packets back at the router until
+# their TTL runs out. Only nsrouter is meant to forward here.
+for ns in "$ns1" "$ns2"; do
+	ip netns exec "$ns" sysctl -q net.ipv4.ip_forward=0
+	ip netns exec "$ns" sysctl -q net.ipv6.conf.all.forwarding=0
+done
+
 if dmesg | grep -q ' nft_rpfilter: ';then
 	dmesg -c | grep ' nft_rpfilter: '
 	echo "WARN: a previous test run has failed" 1>&2
-- 
2.55.0


^ permalink raw reply	[flat|nested] 4+ messages in thread

end of thread, other threads:[~2026-08-21 15:18 UTC | newest]

Thread overview: 4+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-08-21 15:18 [Devel] [PATCH vz10 1/4] selftests: netfilter: do not inherit forwarding and redirects Eva Kurchatova
2026-08-21 15:18 ` [Devel] [PATCH vz10 2/4] selftests: netfilter: add the veth pair from inside the namespace Eva Kurchatova
2026-08-21 15:18 ` [Devel] [PATCH vz10 3/4] selftests: netfilter: skip rpath.sh without the nft tool Eva Kurchatova
2026-08-21 15:18 ` [Devel] [PATCH vz10 4/4] selftests: netfilter: nf_conntrack_expect_max is pernet here Eva Kurchatova

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.