From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from mail.openvz.org (unknown [69.168.225.77]) by lore.virtuozzo.com (Postfix) with ESMTPS id 7B01A802E4 for ; Mon, 31 Aug 2026 23:47:29 +0000 (UTC) Received: from mail.openvz.org (localhost [127.0.0.1]) by mail.openvz.org (8.14.4/8.14.4) with ESMTP id 67VNkILW032230; Tue, 1 Sep 2026 02:46:19 +0300 DKIM-Filter: OpenDKIM Filter v2.11.0 mail.openvz.org 67VNkILW032230 Authentication-Results: mail.openvz.org; dkim=fail reason="signature verification failed" (2048-bit key) header.d=virtuozzo.com header.i=@virtuozzo.com header.b="bB+dPnpE" Received: from mail-wr1-f70.google.com (mail-wr1-f70.google.com [209.85.221.70]) by mail.openvz.org (8.14.4/8.14.4) with ESMTP id 67VNkCZS032202 (version=TLSv1/SSLv3 cipher=AES128-GCM-SHA256 bits=128 verify=FAIL) for ; Tue, 1 Sep 2026 02:46:13 +0300 DKIM-Filter: OpenDKIM Filter v2.11.0 mail.openvz.org 67VNkCZS032202 Received: by mail-wr1-f70.google.com with SMTP id ffacd0b85a97d-48439ef42d8so1597978f8f.2 for ; Mon, 31 Aug 2026 16:46:13 -0700 (PDT) X-Gm-Message-State: AFuF++mUvB2WqYg7pBvToQzffsplyHiIAOUCDidD5we7XUhS+LHa4oIb kRdwFWcgIlQuanr9wUTay2tBqz5cmCLkH79xJrUz9kNm4lS6lgtwR8pBump72grFMZRaDBTmJKZ VI03N7+DJN9ahSDX0Y7/YBNoWrJJABoc14vaurlONlySkte8yxBr3Hg== X-Gm-Gg: AYBFou1GATpTKwRm7mQO8YFCx+GAwGfgiJGLKMPHHucHFVFNyXQEYhD66Au1qA/hJMY 1CerqrZv9YOkF/k7uGM193lbsxR09nzrnVzDrbYPdh4HPZjGb4TyJX38wXjER3+5puPmtzv5A3f v/Wm+IR5o7wMF8N7XQgi5SrBLXz79TPeadgT+c2Swv77xecCBmg+0fFXX5D5eIAWfBSN53vyO6U tzvBO32CwSIKyvfd2OAqlO8+lgMDtzs8XjlR/+06o9vBy+pH2AoxBBw3Ke7K2RtSBeF2fHsLU30 9MHO07f5whE4esRrVi6EiUgoU3yA1A1E+GlBusKhMl3Cz6YUdk6mrXik3bqseZEo1oyWItN6UEX gQGi/vYTrJvMbDSJfLf2RgvmZuA== X-Received: by 2002:a05:6000:480c:b0:484:3f5d:7dc3 with SMTP id ffacd0b85a97d-4843f5d7de3mr10346441f8f.5.1788219972806; Mon, 31 Aug 2026 16:46:12 -0700 (PDT) X-Received: by 2002:a05:6000:480c:b0:484:3f5d:7dc3 with SMTP id ffacd0b85a97d-4843f5d7de3mr10346382f8f.5.1788219972308; Mon, 31 Aug 2026 16:46:12 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1788219972; cv=none; d=google.com; s=arc-20260327; b=eQoAvwoZq/vGcHAuNtoVIFWgQdLex6MbnM/PCJTmUpaO1EAeGrIRXcgdrBdvnow+VS G+skyCqte+DPS8eSOwOTiS8+kzG+3otbueu4hWJzS7ics33+tzfy01sICyxbGZVdEAqf /rVWbI7So7VlPITpTtzAb+r0LAW5odFwIpH3E/zRjcfcrm0R6Wn+dovf9oGVNQp0xAE7 qoJklx6CvYJ6Li7KG6EHR4HkvxgGQS5Bx9lKqrwd2uQU8ztF3E3YqliCGKc0OIDpWsgu F7bYKowaZkYkRPxH7Cj456YhfIpj7kIYvGJ34l12MXWWAH6Y59jqfdDJJ0Qf/uhMdbuN 6AAA== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20260327; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:dkim-signature; bh=x/ArLiBDV3XF0Bd4lvK+sCD0Fnvh06JQwcCgWmbPoa4=; fh=WpT6aB7RBAGHZeWZzqAr71yzRFbPTYkPWKsRagLn48Q=; b=TBsuG5ML45YcslRIBDkjhAWK6v3AqIS13EBmjsjtM2C5l9XhNub82xQn5Ys1xq9TmN 6VO69kQSzA3tOvN/KCNT/d6B9fSa+nPttEBpFe7o79op20eCeJzp9uX0g5x8MRpClOiB JyRCga8suO4ecpH7iJOqI3AS34SJIWQqESHJroMUqGV41v90FQvy+A9M9uy5RHOo9w4/ P5l4a8XS2xsu7wpEo5H8pv+WDhOu0fMfwmkQIt7pN0VJ6eETj1Xg+xQYmCe+r/WoMA3C k2qTFphahShqaxN/K9funcVwQjLdFo/Yn1mlPRmcJI+Wa6Rcc7nooITDBMaZKZ4r2bx4 W2IA==; dara=google.com ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@virtuozzo.com header.s=relay header.b=bB+dPnpE; spf=pass (google.com: domain of eva.kurchatova@virtuozzo.com designates 130.117.225.111 as permitted sender) smtp.mailfrom=eva.kurchatova@virtuozzo.com; dmarc=pass (p=QUARANTINE sp=QUARANTINE dis=NONE) header.from=virtuozzo.com Received: from relay.virtuozzo.com (relay.virtuozzo.com. [130.117.225.111]) by mx.google.com with ESMTPS id ffacd0b85a97d-48442d71b99si871395f8f.164.2026.08.31.16.46.12 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 31 Aug 2026 16:46:12 -0700 (PDT) Received-SPF: pass (google.com: domain of eva.kurchatova@virtuozzo.com designates 130.117.225.111 as permitted sender) client-ip=130.117.225.111; Authentication-Results: mx.google.com; dkim=pass header.i=@virtuozzo.com header.s=relay header.b=bB+dPnpE; spf=pass (google.com: domain of eva.kurchatova@virtuozzo.com designates 130.117.225.111 as permitted sender) smtp.mailfrom=eva.kurchatova@virtuozzo.com; dmarc=pass (p=QUARANTINE sp=QUARANTINE dis=NONE) header.from=virtuozzo.com DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=virtuozzo.com; s=relay; h=MIME-Version:Message-ID:Date:Subject:From: Content-Type; bh=x/ArLiBDV3XF0Bd4lvK+sCD0Fnvh06JQwcCgWmbPoa4=; b=bB+dPnpE4dgZ BBgUI25IVg35i2WiNScf/JVFGO8RvA4/8OcQ5rxwrKMLVM6aZGIr6TRmzSi2T9tFMyC7FM6RF1Oah RxwPakuA5LBdtNpD+rkhXvEgZcF7BhXZsvx2/fHk8jMkYuH5Rd+r5Q03nc8gqBP3eUch79qBZa4fS x4FVRcNx7/u16J9fQuLbV2xtHk6DG2d5S33fBijmBkj/VeRVas5V8plbh2kjGlSuy6AY4s6LB5UYZ WWIolPnbIhHmQ0EGl7vOUhnJQENYBKNRE+y3RrpZGNa6mrWOhivLCwwnTd2+85brOh4hGlyftLSDM UTLbMwDcLwya0Y7aLond5Q==; Received: from ch-vpn.virtuozzo.com ([130.117.225.6] helo=LekKit-T14) by relay.virtuozzo.com with esmtp (Exim 4.96) (envelope-from ) id 1x1BfF-00AqVc-0l; Tue, 01 Sep 2026 01:46:03 +0200 From: Eva Kurchatova To: khorenko@virtuozzo.com Date: Tue, 1 Sep 2026 02:45:31 +0300 Message-ID: <20260831234610.1650091-3-eva.kurchatova@virtuozzo.com> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260831234610.1650091-1-eva.kurchatova@virtuozzo.com> References: <20260831234610.1650091-1-eva.kurchatova@virtuozzo.com> MIME-Version: 1.0 X-OZ-Fwd: true Cc: devel@openvz.org Subject: [Devel] [PATCH vz10 v2 3/5] selftests: netfilter: add the veth pair from inside the namespace X-BeenThere: devel@openvz.org X-Mailman-Version: 2.1.12 Precedence: list List-Id: OpenVZ development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: 7bit Sender: devel-bounces@openvz.org Errors-To: devel-bounces@openvz.org Both tests add a veth by name while running in the initial namespace. The name of the new device is taken there, not in the namespace passed to netns, so a device of that name left behind by another test makes the add fail and the test then runs with no connectivity at all: # RTNETLINK answers: File exists # Cannot find device "veth1" # FAIL: socat cannot connect via NAT'd address Add the pair from inside one of the namespaces instead. Those are made by setup_ns and are empty, and the peer is created directly in its own namespace, so no name from the initial namespace is in the way. br_netfilter.sh checked only the first of its four adds, so a failure of any of the others was silent and turned up 90 lines later as a ping to a namespace that had no interface. Check all four. https://virtuozzo.atlassian.net/browse/VSTOR-139651 Feature: fix selftests Signed-off-by: Eva Kurchatova --- .../selftests/net/netfilter/br_netfilter.sh | 21 ++++++++++++------- .../selftests/net/netfilter/nf_nat_edemux.sh | 12 +++++++---- 2 files changed, 21 insertions(+), 12 deletions(-) diff --git a/tools/testing/selftests/net/netfilter/br_netfilter.sh b/tools/testing/selftests/net/netfilter/br_netfilter.sh index 011de8763094..e4480c9db86e 100755 --- a/tools/testing/selftests/net/netfilter/br_netfilter.sh +++ b/tools/testing/selftests/net/netfilter/br_netfilter.sh @@ -60,14 +60,19 @@ bcast_ping() done } -if ! ip link add veth1 netns "$ns0" type veth peer name eth0 netns "$ns1"; then - echo "SKIP: Can't create veth device" - exit $ksft_skip -fi - -ip link add veth2 netns "$ns0" type veth peer name eth0 netns "$ns2" -ip link add veth3 netns "$ns0" type veth peer name eth0 netns "$ns3" -ip link add veth4 netns "$ns0" type veth peer name eth0 netns "$ns4" +# Add the pairs from inside ns0: the name of the new device is taken in the +# namespace the command runs in, so adding them here would fail if a device +# of that name was left behind in the initial namespace. Only veth1 used to +# be checked, and a silent failure for one of the others left a namespace +# with no interface at all, which showed up as a ping failure much later. +for i in $(seq 1 4); do + nsvar="ns$i" + if ! ip -net "$ns0" link add "veth$i" type veth \ + peer name eth0 netns "${!nsvar}"; then + echo "SKIP: Can't create veth device" + exit $ksft_skip + fi +done for i in $(seq 1 4); do ip -net "$ns0" link set "veth$i" up diff --git a/tools/testing/selftests/net/netfilter/nf_nat_edemux.sh b/tools/testing/selftests/net/netfilter/nf_nat_edemux.sh index 1014551dd769..9d655d525104 100755 --- a/tools/testing/selftests/net/netfilter/nf_nat_edemux.sh +++ b/tools/testing/selftests/net/netfilter/nf_nat_edemux.sh @@ -22,10 +22,14 @@ trap cleanup EXIT setup_ns ns1 ns2 -# Connect the namespaces using a veth pair -ip link add name veth2 type veth peer name veth1 -ip link set netns "$ns1" dev veth1 -ip link set netns "$ns2" dev veth2 +# Connect the namespaces using a veth pair. Add it from inside ns1: the +# name of the new device is taken in the namespace the command runs in, so +# adding it here would fail if a device of that name was left behind in the +# initial namespace, and the test would then run without connectivity. +if ! ip -net "$ns1" link add name veth1 type veth peer name veth2 netns "$ns2"; then + echo "SKIP: Can't create veth device" + exit $ksft_skip +fi ip netns exec "$ns1" ip link set up dev lo ip netns exec "$ns1" ip link set up dev veth1 -- 2.55.0 _______________________________________________ Devel mailing list Devel@openvz.org https://lists.openvz.org/mailman/listinfo/devel