* [Devel] [PATCH vz10 1/4] selftests: netfilter: do not inherit forwarding and redirects
@ 2026-08-21 15:18 Eva Kurchatova
2026-08-21 15:18 ` [Devel] [PATCH vz10 2/4] selftests: netfilter: add the veth pair from inside the namespace Eva Kurchatova
` (2 more replies)
0 siblings, 3 replies; 4+ messages in thread
From: Eva Kurchatova @ 2026-08-21 15:18 UTC (permalink / raw)
A new namespace takes ip_forward and send_redirects from the host, so
two tests depend on how the machine outside them is configured.
On a host that forwards, which any hypervisor does, nft_fib's ns1 and
ns2 send the test packets back at the router until their TTL runs out,
and the fib counters end at 31 or 62 packets instead of 1:
FAIL: fibif4 not empty
elements = { "veth1" . 10.0.1.99 . "veth0" counter packets 62 ...
Only nsrouter is meant to forward, so turn forwarding off in the
endpoints. conntrack_icmp_related needs the opposite: images routinely
turn send_redirects off, and the router then never sends the redirect
the test waits for:
ERROR: counter redir4 in nsclient1 has unexpected value
Set both where the test needs them rather than relying on the host.
https://virtuozzo.atlassian.net/browse/VSTOR-139651
Feature: fix selftests
Signed-off-by: Eva Kurchatova <eva.kurchatova@virtuozzo.com>
---
.../selftests/net/netfilter/conntrack_icmp_related.sh | 6 ++++++
tools/testing/selftests/net/netfilter/nft_fib.sh | 8 ++++++++
2 files changed, 14 insertions(+)
diff --git a/tools/testing/selftests/net/netfilter/conntrack_icmp_related.sh b/tools/testing/selftests/net/netfilter/conntrack_icmp_related.sh
index c63d840ead61..44a98c53d085 100755
--- a/tools/testing/selftests/net/netfilter/conntrack_icmp_related.sh
+++ b/tools/testing/selftests/net/netfilter/conntrack_icmp_related.sh
@@ -253,6 +253,12 @@ else
fi
# add 'bad' route, expect icmp REDIRECT to be generated
+# A new namespace inherits send_redirects from the host, where it is
+# often turned off; without it the router never sends the redirect this
+# part of the test waits for.
+ip netns exec "$nsrouter1" sysctl -q net.ipv4.conf.all.send_redirects=1
+ip netns exec "$nsrouter1" sysctl -q net.ipv4.conf.default.send_redirects=1
+
ip netns exec "${nsclient1}" ip route add 192.168.1.42 via 192.168.1.1
ip netns exec "${nsclient1}" ip route add dead:1::42 via dead:1::1
diff --git a/tools/testing/selftests/net/netfilter/nft_fib.sh b/tools/testing/selftests/net/netfilter/nft_fib.sh
index 9929a9ffef65..c818b544e57b 100755
--- a/tools/testing/selftests/net/netfilter/nft_fib.sh
+++ b/tools/testing/selftests/net/netfilter/nft_fib.sh
@@ -29,6 +29,14 @@ setup_ns nsrouter ns1 ns2
trap cleanup EXIT
+# A new namespace inherits ip_forward from the host, and on a host that
+# forwards, ns1 and ns2 bounce the test packets back at the router until
+# their TTL runs out. Only nsrouter is meant to forward here.
+for ns in "$ns1" "$ns2"; do
+ ip netns exec "$ns" sysctl -q net.ipv4.ip_forward=0
+ ip netns exec "$ns" sysctl -q net.ipv6.conf.all.forwarding=0
+done
+
if dmesg | grep -q ' nft_rpfilter: ';then
dmesg -c | grep ' nft_rpfilter: '
echo "WARN: a previous test run has failed" 1>&2
--
2.55.0
^ permalink raw reply [flat|nested] 4+ messages in thread* [Devel] [PATCH vz10 2/4] selftests: netfilter: add the veth pair from inside the namespace
2026-08-21 15:18 [Devel] [PATCH vz10 1/4] selftests: netfilter: do not inherit forwarding and redirects Eva Kurchatova
@ 2026-08-21 15:18 ` Eva Kurchatova
2026-08-21 15:18 ` [Devel] [PATCH vz10 3/4] selftests: netfilter: skip rpath.sh without the nft tool Eva Kurchatova
2026-08-21 15:18 ` [Devel] [PATCH vz10 4/4] selftests: netfilter: nf_conntrack_expect_max is pernet here Eva Kurchatova
2 siblings, 0 replies; 4+ messages in thread
From: Eva Kurchatova @ 2026-08-21 15:18 UTC (permalink / raw)
Both tests add a veth by name while running in the initial namespace.
The name of the new device is taken there, not in the namespace passed to
netns, so a device of that name left behind by another test makes the add
fail and the test then runs with no connectivity at all:
# RTNETLINK answers: File exists
# Cannot find device "veth1"
# FAIL: socat cannot connect via NAT'd address
Add the pair from inside one of the namespaces instead. Those are made
by setup_ns and are empty, and the peer is created directly in its own
namespace, so no name from the initial namespace is in the way.
br_netfilter.sh checked only the first of its four adds, so a failure of
any of the others was silent and turned up 90 lines later as a ping to a
namespace that had no interface. Check all four.
https://virtuozzo.atlassian.net/browse/VSTOR-139651
Feature: fix selftests
Signed-off-by: Eva Kurchatova <eva.kurchatova@virtuozzo.com>
---
.../selftests/net/netfilter/br_netfilter.sh | 21 ++++++++++++-------
.../selftests/net/netfilter/nf_nat_edemux.sh | 12 +++++++----
2 files changed, 21 insertions(+), 12 deletions(-)
diff --git a/tools/testing/selftests/net/netfilter/br_netfilter.sh b/tools/testing/selftests/net/netfilter/br_netfilter.sh
index 011de8763094..e4480c9db86e 100755
--- a/tools/testing/selftests/net/netfilter/br_netfilter.sh
+++ b/tools/testing/selftests/net/netfilter/br_netfilter.sh
@@ -60,14 +60,19 @@ bcast_ping()
done
}
-if ! ip link add veth1 netns "$ns0" type veth peer name eth0 netns "$ns1"; then
- echo "SKIP: Can't create veth device"
- exit $ksft_skip
-fi
-
-ip link add veth2 netns "$ns0" type veth peer name eth0 netns "$ns2"
-ip link add veth3 netns "$ns0" type veth peer name eth0 netns "$ns3"
-ip link add veth4 netns "$ns0" type veth peer name eth0 netns "$ns4"
+# Add the pairs from inside ns0: the name of the new device is taken in the
+# namespace the command runs in, so adding them here would fail if a device
+# of that name was left behind in the initial namespace. Only veth1 used to
+# be checked, and a silent failure for one of the others left a namespace
+# with no interface at all, which showed up as a ping failure much later.
+for i in $(seq 1 4); do
+ nsvar="ns$i"
+ if ! ip -net "$ns0" link add "veth$i" type veth \
+ peer name eth0 netns "${!nsvar}"; then
+ echo "SKIP: Can't create veth device"
+ exit $ksft_skip
+ fi
+done
for i in $(seq 1 4); do
ip -net "$ns0" link set "veth$i" up
diff --git a/tools/testing/selftests/net/netfilter/nf_nat_edemux.sh b/tools/testing/selftests/net/netfilter/nf_nat_edemux.sh
index 1014551dd769..9d655d525104 100755
--- a/tools/testing/selftests/net/netfilter/nf_nat_edemux.sh
+++ b/tools/testing/selftests/net/netfilter/nf_nat_edemux.sh
@@ -22,10 +22,14 @@ trap cleanup EXIT
setup_ns ns1 ns2
-# Connect the namespaces using a veth pair
-ip link add name veth2 type veth peer name veth1
-ip link set netns "$ns1" dev veth1
-ip link set netns "$ns2" dev veth2
+# Connect the namespaces using a veth pair. Add it from inside ns1: the
+# name of the new device is taken in the namespace the command runs in, so
+# adding it here would fail if a device of that name was left behind in the
+# initial namespace, and the test would then run without connectivity.
+if ! ip -net "$ns1" link add name veth1 type veth peer name veth2 netns "$ns2"; then
+ echo "SKIP: Can't create veth device"
+ exit $ksft_skip
+fi
ip netns exec "$ns1" ip link set up dev lo
ip netns exec "$ns1" ip link set up dev veth1
--
2.55.0
^ permalink raw reply [flat|nested] 4+ messages in thread* [Devel] [PATCH vz10 3/4] selftests: netfilter: skip rpath.sh without the nft tool
2026-08-21 15:18 [Devel] [PATCH vz10 1/4] selftests: netfilter: do not inherit forwarding and redirects Eva Kurchatova
2026-08-21 15:18 ` [Devel] [PATCH vz10 2/4] selftests: netfilter: add the veth pair from inside the namespace Eva Kurchatova
@ 2026-08-21 15:18 ` Eva Kurchatova
2026-08-21 15:18 ` [Devel] [PATCH vz10 4/4] selftests: netfilter: nf_conntrack_expect_max is pernet here Eva Kurchatova
2 siblings, 0 replies; 4+ messages in thread
From: Eva Kurchatova @ 2026-08-21 15:18 UTC (permalink / raw)
Every other netfilter test that needs nft checks for it. rpath.sh does
not, and without the tool it reports "nft IPv4 match not effective"
instead of skipping.
https://virtuozzo.atlassian.net/browse/VSTOR-139651
Feature: fix selftests
Signed-off-by: Eva Kurchatova <eva.kurchatova@virtuozzo.com>
---
tools/testing/selftests/net/netfilter/rpath.sh | 3 +++
1 file changed, 3 insertions(+)
diff --git a/tools/testing/selftests/net/netfilter/rpath.sh b/tools/testing/selftests/net/netfilter/rpath.sh
index 90cc21233235..5c71cb43ae0a 100755
--- a/tools/testing/selftests/net/netfilter/rpath.sh
+++ b/tools/testing/selftests/net/netfilter/rpath.sh
@@ -3,6 +3,9 @@
source lib.sh
+checktool "nft --version" "run test without nft tool"
+checktool "ip -Version" "run test without ip tool"
+
# search for legacy iptables (it uses the xtables extensions
if iptables-legacy --version >/dev/null 2>&1; then
iptables='iptables-legacy'
--
2.55.0
^ permalink raw reply [flat|nested] 4+ messages in thread
* [Devel] [PATCH vz10 4/4] selftests: netfilter: nf_conntrack_expect_max is pernet here
2026-08-21 15:18 [Devel] [PATCH vz10 1/4] selftests: netfilter: do not inherit forwarding and redirects Eva Kurchatova
2026-08-21 15:18 ` [Devel] [PATCH vz10 2/4] selftests: netfilter: add the veth pair from inside the namespace Eva Kurchatova
2026-08-21 15:18 ` [Devel] [PATCH vz10 3/4] selftests: netfilter: skip rpath.sh without the nft tool Eva Kurchatova
@ 2026-08-21 15:18 ` Eva Kurchatova
2 siblings, 0 replies; 4+ messages in thread
From: Eva Kurchatova @ 2026-08-21 15:18 UTC (permalink / raw)
The test requires it to be settable from init_net only, while vz
virtualizes it deliberately:
6d854968102f ("ve/netfilter: Implement pernet expect_max / virtualize
"net.netfilter.nf_conntrack_expect_max" sysctl")
https://virtuozzo.atlassian.net/browse/VSTOR-139651
Feature: fix vz selftests
Signed-off-by: Eva Kurchatova <eva.kurchatova@virtuozzo.com>
---
tools/testing/selftests/net/netfilter/conntrack_resize.sh | 6 ++++--
1 file changed, 4 insertions(+), 2 deletions(-)
diff --git a/tools/testing/selftests/net/netfilter/conntrack_resize.sh b/tools/testing/selftests/net/netfilter/conntrack_resize.sh
index aa1ba07eaf50..324259632daa 100755
--- a/tools/testing/selftests/net/netfilter/conntrack_resize.sh
+++ b/tools/testing/selftests/net/netfilter/conntrack_resize.sh
@@ -457,8 +457,10 @@ check_max_alias 262000
setup_ns nsclient1 nsclient2
-# check this only works from init_net
-for n in netfilter.nf_conntrack_buckets netfilter.nf_conntrack_expect_max net.nf_conntrack_max;do
+# check this only works from init_net. nf_conntrack_expect_max is left
+# out: vz virtualizes it on purpose, see "ve/netfilter: Implement pernet
+# expect_max".
+for n in netfilter.nf_conntrack_buckets net.nf_conntrack_max;do
check_sysctl_immutable "$nsclient1" "net.$n" 1
done
--
2.55.0
^ permalink raw reply [flat|nested] 4+ messages in thread
end of thread, other threads:[~2026-08-21 15:18 UTC | newest]
Thread overview: 4+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-08-21 15:18 [Devel] [PATCH vz10 1/4] selftests: netfilter: do not inherit forwarding and redirects Eva Kurchatova
2026-08-21 15:18 ` [Devel] [PATCH vz10 2/4] selftests: netfilter: add the veth pair from inside the namespace Eva Kurchatova
2026-08-21 15:18 ` [Devel] [PATCH vz10 3/4] selftests: netfilter: skip rpath.sh without the nft tool Eva Kurchatova
2026-08-21 15:18 ` [Devel] [PATCH vz10 4/4] selftests: netfilter: nf_conntrack_expect_max is pernet here Eva Kurchatova
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox