From mboxrd@z Thu Jan 1 00:00:00 1970 From: Eva Kurchatova Date: Fri, 21 Aug 2026 18:18:44 +0300 Subject: [Devel] [PATCH vz10 1/4] selftests: netfilter: do not inherit forwarding and redirects Message-ID: <20260821151850.796438-1-eva.kurchatova@virtuozzo.com> List-Id: A new namespace takes ip_forward and send_redirects from the host, so two tests depend on how the machine outside them is configured. On a host that forwards, which any hypervisor does, nft_fib's ns1 and ns2 send the test packets back at the router until their TTL runs out, and the fib counters end at 31 or 62 packets instead of 1: FAIL: fibif4 not empty elements = { "veth1" . 10.0.1.99 . "veth0" counter packets 62 ... Only nsrouter is meant to forward, so turn forwarding off in the endpoints. conntrack_icmp_related needs the opposite: images routinely turn send_redirects off, and the router then never sends the redirect the test waits for: ERROR: counter redir4 in nsclient1 has unexpected value Set both where the test needs them rather than relying on the host. https://virtuozzo.atlassian.net/browse/VSTOR-139651 Feature: fix selftests Signed-off-by: Eva Kurchatova --- .../selftests/net/netfilter/conntrack_icmp_related.sh | 6 ++++++ tools/testing/selftests/net/netfilter/nft_fib.sh | 8 ++++++++ 2 files changed, 14 insertions(+) diff --git a/tools/testing/selftests/net/netfilter/conntrack_icmp_related.sh b/tools/testing/selftests/net/netfilter/conntrack_icmp_related.sh index c63d840ead61..44a98c53d085 100755 --- a/tools/testing/selftests/net/netfilter/conntrack_icmp_related.sh +++ b/tools/testing/selftests/net/netfilter/conntrack_icmp_related.sh @@ -253,6 +253,12 @@ else fi # add 'bad' route, expect icmp REDIRECT to be generated +# A new namespace inherits send_redirects from the host, where it is +# often turned off; without it the router never sends the redirect this +# part of the test waits for. +ip netns exec "$nsrouter1" sysctl -q net.ipv4.conf.all.send_redirects=1 +ip netns exec "$nsrouter1" sysctl -q net.ipv4.conf.default.send_redirects=1 + ip netns exec "${nsclient1}" ip route add 192.168.1.42 via 192.168.1.1 ip netns exec "${nsclient1}" ip route add dead:1::42 via dead:1::1 diff --git a/tools/testing/selftests/net/netfilter/nft_fib.sh b/tools/testing/selftests/net/netfilter/nft_fib.sh index 9929a9ffef65..c818b544e57b 100755 --- a/tools/testing/selftests/net/netfilter/nft_fib.sh +++ b/tools/testing/selftests/net/netfilter/nft_fib.sh @@ -29,6 +29,14 @@ setup_ns nsrouter ns1 ns2 trap cleanup EXIT +# A new namespace inherits ip_forward from the host, and on a host that +# forwards, ns1 and ns2 bounce the test packets back at the router until +# their TTL runs out. Only nsrouter is meant to forward here. +for ns in "$ns1" "$ns2"; do + ip netns exec "$ns" sysctl -q net.ipv4.ip_forward=0 + ip netns exec "$ns" sysctl -q net.ipv6.conf.all.forwarding=0 +done + if dmesg | grep -q ' nft_rpfilter: ';then dmesg -c | grep ' nft_rpfilter: ' echo "WARN: a previous test run has failed" 1>&2 -- 2.55.0