From: Konstantin Khorenko <khorenko@virtuozzo.com>
Subject: [Devel] [PATCH RHEL10 COMMIT] selftests: mptcp: turn forwarding off in the test namespaces
Date: Mon, 24 Aug 2026 18:47:52 +0200 [thread overview]
Message-ID: <202608241647.67OGlqX3463207@hci8VM.finist.virtuozzo.com> (raw)
In-Reply-To: <20260821152029.796830-1-eva.kurchatova@virtuozzo.com>
The commit is pushed to "branch-rh10-6.12.0-211.39.1.16.x.vz10-ovz" and will appear at git at bitbucket.org:openvz/vzkernel.git
after rh10-6.12.0-211.39.1.16.8.vz10
------>
commit 38b336063172bfdcdcc0460edf97794870c0a2d4
Author: Eva Kurchatova <eva.kurchatova@virtuozzo.com>
Date: Fri Aug 21 18:20:28 2026 +0300
selftests: mptcp: turn forwarding off in the test namespaces
A new namespace inherits net.ipv4.ip_forward from the host, so on a host
that routes, so do the namespaces these tests build.
IPv6 forwarding is inheritable too, depending on
net.core.devconf_inherit_init_net, so turn both off.
Only IPv4 is inherited with the default
net.core.devconf_inherit_init_net: devinet_init_net() copies devconf
from init_net for 0 and 1, while addrconf_init_net() uses the compiled
defaults for 0. Turn IPv6 forwarding off as well, it becomes inheritable
once that knob is 1 or 3, and the tests which do need a router enable
both anyway.
"invalid address, ADD_ADDR timeout" then reports 0 JOINs where it wants
1. The server announces an unreachable address first and a valid one
after it. With forwarding on, the SYN to the unreachable address draws
an ICMP error instead of being dropped, so the subflow attempt fails at
once and the next ADD_ADDR retransmission starts another one. Every
attempt that no longer finds its predecessor bumps add_addr_accepted, so
the unreachable address alone uses up both accepted slots and the valid
address that follows is dropped without ever getting a subflow.
The two tests that do need a router, mptcp_connect.sh and
simult_flows.sh, turn forwarding on themselves for those namespaces, so
switching it off in the common setup is enough.
https://virtuozzo.atlassian.net/browse/VSTOR-139651
Feature: fix selftests
Signed-off-by: Eva Kurchatova <eva.kurchatova@virtuozzo.com>
Reviewed-by: Konstantin Khorenko <khorenko@virtuozzo.com>
---
tools/testing/selftests/net/mptcp/mptcp_lib.sh | 7 +++++++
1 file changed, 7 insertions(+)
diff --git a/tools/testing/selftests/net/mptcp/mptcp_lib.sh b/tools/testing/selftests/net/mptcp/mptcp_lib.sh
index a326f34fc719..43112e1c8c59 100644
--- a/tools/testing/selftests/net/mptcp/mptcp_lib.sh
+++ b/tools/testing/selftests/net/mptcp/mptcp_lib.sh
@@ -455,6 +455,13 @@ mptcp_lib_ns_init() {
local netns
for netns in "${@}"; do
ip netns exec "${!netns}" sysctl -q net.mptcp.enabled=1
+ # The tests that need a router enable forwarding themselves,
+ # everywhere else it has to be off: a new namespace inherits
+ # the setting, so on a host that routes, an unreachable
+ # announced address is answered with an ICMP error instead of
+ # being silently dropped.
+ ip netns exec "${!netns}" sysctl -q net.ipv4.ip_forward=0
+ ip netns exec "${!netns}" sysctl -q net.ipv6.conf.all.forwarding=0
done
}
prev parent reply other threads:[~2026-08-24 16:47 UTC|newest]
Thread overview: 2+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-21 15:20 [Devel] [PATCH vz10] " Eva Kurchatova
2026-08-24 16:47 ` Konstantin Khorenko [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=202608241647.67OGlqX3463207@hci8VM.finist.virtuozzo.com \
--to=khorenko@virtuozzo.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.