From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from mail.openvz.org (unknown [69.168.225.77]) by lore.virtuozzo.com (Postfix) with ESMTPS id D223B80375 for ; Mon, 31 Aug 2026 23:43:45 +0000 (UTC) Received: from mail.openvz.org (localhost [127.0.0.1]) by mail.openvz.org (8.14.4/8.14.4) with ESMTP id 67VNgV3S032057; Tue, 1 Sep 2026 02:42:32 +0300 DKIM-Filter: OpenDKIM Filter v2.11.0 mail.openvz.org 67VNgV3S032057 Authentication-Results: mail.openvz.org; dkim=fail reason="signature verification failed" (2048-bit key) header.d=virtuozzo.com header.i=@virtuozzo.com header.b="HF0l7Ikf" Received: from mail-wr1-f70.google.com (mail-wr1-f70.google.com [209.85.221.70]) by mail.openvz.org (8.14.4/8.14.4) with ESMTP id 67VNgLLV032020 (version=TLSv1/SSLv3 cipher=AES128-GCM-SHA256 bits=128 verify=FAIL) for ; Tue, 1 Sep 2026 02:42:21 +0300 DKIM-Filter: OpenDKIM Filter v2.11.0 mail.openvz.org 67VNgLLV032020 Received: by mail-wr1-f70.google.com with SMTP id ffacd0b85a97d-482f09ae253so184603f8f.0 for ; Mon, 31 Aug 2026 16:42:21 -0700 (PDT) X-Gm-Message-State: AFuF++kHI7a0wSK1aUI+ABaDqVgzHM4H6l58IuZ9CyQvUTyGHja2s/UH Wsu8NwSbESJutvF0Os3GvmhTXUsx8oyvaAxfNq4x7AVdze89IDXkLMqk4zb8se2HgLtfhgQh9HV 2/xPyHCV8ju77wGg5RvNmtjGrhH5KV7Rl5au4TfsBCXcvHLOzyYoR6g== X-Gm-Gg: AYBFou1+CRECV9pLqmFsVN28ZUkQECCTWmHm/wITk4ucBgdiAil2gnG84UUpzoDGA3X D3kSj+1IIy3LDG+A+e8qU766bqy5M4E+AAeiXwl0kOIt/IowHi5QBGXY1DPVkB00/wPQ7hwBFSt 99Yet2NTqG66aEc9aRNTKHugZsxYimK3Qg1zDPLqYyUgY74dfLVxaUnlL6YhXSix11zvBk3dVxC 8d3hpopgxmpuL7kXvs+xjri92vuTdRh6btMHcQLnmVVrgMwJOJw423ADIoRYkGYWmtTwMNY5FJ1 sCuSwIRaXm6GHJOIH62OMUPvueLRJ7CEHI8Vu8f6TLYupaM2VI6QIX3fbZ3jniseo9jwBABAr1E ezXmDZ7sI0I7MNfX84QCuikMArw== X-Received: by 2002:a5d:5e01:0:b0:480:c5:d635 with SMTP id ffacd0b85a97d-482f782a4a2mr42158866f8f.0.1788219741075; Mon, 31 Aug 2026 16:42:21 -0700 (PDT) X-Received: by 2002:a5d:5e01:0:b0:480:c5:d635 with SMTP id ffacd0b85a97d-482f782a4a2mr42158805f8f.0.1788219740524; Mon, 31 Aug 2026 16:42:20 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1788219740; cv=none; d=google.com; s=arc-20260327; b=QMk5cMsEvARpdTwIF7YHASLvNYAa3xPO73mEmoI82zndTwDFWXOeQS4VTb305TJFwE S6YNRuXLVSQBgb1iNlsYNwVdXyI8CL50MIr9YhvAZrLwaN5J7NnRETUxDRWw2D5N4r0U pAhKDZF0RhLU5sg1e80ZpEnf3E8/zZyHiNApzFg2rgExIryuVGVTFRDDISEyn817vWdy mroZwJWybFTnO0qbgXkYE4azFev8haN1t0pwRM74uSlqadXG/5Hzu6QUwPPUsWKfbwCE +I2qPgrrHlMdLwDoFIDGesMleUT7e0YcqdBz3Ano0chDmXRgFd8pE5hIRWPWRTGeaLUc Ttrw== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20260327; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:dkim-signature; bh=/yaVxkjLljAeBMA9hiW9rMbmHIAKH89VzsRoD5bh4ss=; fh=WpT6aB7RBAGHZeWZzqAr71yzRFbPTYkPWKsRagLn48Q=; b=XsAVBkhB/isJuJN5EfPKo6f+g80XaKq0w8fJQZSzPW5K8pZ8W/LAgZ652CgrzYzVIY DWfgMV4Z0ClaDu9S0cK5lv79kAurlmKR9oXGbUxY/T+TkkFeAf7vghqJVgADxNbvQ252 rRveXAX0Q5jqNtcOdpuJ45zDy6fkqgfEQSRWAtgXLg/vZjk7QlQuCn7FJHa+OIw+ijM5 FqkvbBlYIVEnT9QbY3lui8/UU7WhWoH5Wwoxia/YzfoXx2AMywQlJHbu0osHD5yi7MlX 5ojPj5Y+vN8UE57d4IphZdh5ZW+yiaZf58Ek9fZzjbvybQWqOuGXWonKgo4Rm29DCuQd R65A==; dara=google.com ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@virtuozzo.com header.s=relay header.b=HF0l7Ikf; spf=pass (google.com: domain of eva.kurchatova@virtuozzo.com designates 130.117.225.111 as permitted sender) smtp.mailfrom=eva.kurchatova@virtuozzo.com; dmarc=pass (p=QUARANTINE sp=QUARANTINE dis=NONE) header.from=virtuozzo.com Received: from relay.virtuozzo.com (relay.virtuozzo.com. [130.117.225.111]) by mx.google.com with ESMTPS id ffacd0b85a97d-48442d3c3d2si994746f8f.133.2026.08.31.16.42.20 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 31 Aug 2026 16:42:20 -0700 (PDT) Received-SPF: pass (google.com: domain of eva.kurchatova@virtuozzo.com designates 130.117.225.111 as permitted sender) client-ip=130.117.225.111; Authentication-Results: mx.google.com; dkim=pass header.i=@virtuozzo.com header.s=relay header.b=HF0l7Ikf; spf=pass (google.com: domain of eva.kurchatova@virtuozzo.com designates 130.117.225.111 as permitted sender) smtp.mailfrom=eva.kurchatova@virtuozzo.com; dmarc=pass (p=QUARANTINE sp=QUARANTINE dis=NONE) header.from=virtuozzo.com DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=virtuozzo.com; s=relay; h=MIME-Version:Message-ID:Date:Subject:From: Content-Type; bh=/yaVxkjLljAeBMA9hiW9rMbmHIAKH89VzsRoD5bh4ss=; b=HF0l7Ikfextm v9E0pFUWk6a+EMoVIY0qlDqpyL+lYhPrdEbjSDMnYIqr5D0DJUcoZTpJLZkiGzwsFy3wSOW6IR6dG hKKYaSkRrbwVRs+Xm5SruC23Zl4tGpiF6h0L4/Gn0kZtbSzuqQN+9LPgCrcNSYfDpx4XS+Q3DMaDz WlvOMuPxYutR/DOf5bMSt5mh5Ywyr6abo5Y4Muxjo3rqQJE3ddp45q/vJ3/wHgbm5BhE/1WF8NPZm GvI3s4sByF02+9ibWuolBYoDXFj4JTzPGClQzuFNK2Aw8D+nIk1SRHqeg4yzPJbMK4X11XJ6OOUi/ knSSdulS+o6ce5btcLxlnw==; Received: from ch-vpn.virtuozzo.com ([130.117.225.6] helo=LekKit-T14) by relay.virtuozzo.com with esmtp (Exim 4.96) (envelope-from ) id 1x1BbV-00Alra-1Q; Tue, 01 Sep 2026 01:42:11 +0200 From: Eva Kurchatova To: khorenko@virtuozzo.com Date: Tue, 1 Sep 2026 02:41:51 +0300 Message-ID: <20260831234217.1649428-4-eva.kurchatova@virtuozzo.com> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260831234217.1649428-1-eva.kurchatova@virtuozzo.com> References: <20260831234217.1649428-1-eva.kurchatova@virtuozzo.com> MIME-Version: 1.0 X-OZ-Fwd: true Cc: devel@openvz.org Subject: [Devel] [PATCH vz10 v2 4/5] selftests: bpf: run test_sock and test_tunnel in their own netns X-BeenThere: devel@openvz.org X-Mailman-Version: 2.1.12 Precedence: list List-Id: OpenVZ development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: 7bit Sender: devel-bounces@openvz.org Errors-To: devel-bounces@openvz.org Both use the initial namespace and fail on what the machine has in it rather than on the kernel under test. test_sock binds 127.0.0.1:5000 and fails if anything already listens there. test_tunnel needs the fou module, which nothing loads, and asks for encapsulations this kernel may not have. Run both in a namespace of their own, load the module, and let check() probe the kernel so the callers skip an encapsulation that is missing instead of failing. Upstream carries neither test any more: commit eea6c14c10ce ("selftests/bpf: Retire test_sock.c") and commit a54e7006967f ("selftests/bpf: test_tunnel: Remove test_tunnel.sh") dropped them once their cases had moved to test_progs. Both are still in this tree and still run, so they are fixed in this tree. https://virtuozzo.atlassian.net/browse/VSTOR-139677 Feature: fix vz selftests Signed-off-by: Eva Kurchatova --- tools/testing/selftests/bpf/test_sock.c | 17 ++++++++ tools/testing/selftests/bpf/test_tunnel.sh | 50 +++++++++++++++++----- 2 files changed, 56 insertions(+), 11 deletions(-) diff --git a/tools/testing/selftests/bpf/test_sock.c b/tools/testing/selftests/bpf/test_sock.c index 810c3740b2cc..0298ff2e5cf7 100644 --- a/tools/testing/selftests/bpf/test_sock.c +++ b/tools/testing/selftests/bpf/test_sock.c @@ -1,7 +1,10 @@ // SPDX-License-Identifier: GPL-2.0 // Copyright (c) 2018 Facebook +#define _GNU_SOURCE +#include #include +#include #include #include @@ -536,6 +539,20 @@ int main(int argc, char **argv) int cgfd = -1; int err = 0; + /* The tests bind fixed ports on the loopback address, and one of + * them retries on 5000, which a service on the machine may well be + * listening on. Take a network namespace of our own so that only + * the sockets of this test are in it. + */ + if (unshare(CLONE_NEWNET)) { + log_err("unshare(CLONE_NEWNET)"); + return -1; + } + if (system("ip link set lo up")) { + log_err("bringing loopback up"); + return -1; + } + cgfd = cgroup_setup_and_join(CG_PATH); if (cgfd < 0) goto err; diff --git a/tools/testing/selftests/bpf/test_tunnel.sh b/tools/testing/selftests/bpf/test_tunnel.sh index d9661b9988ba..172aac4dae4f 100755 --- a/tools/testing/selftests/bpf/test_tunnel.sh +++ b/tools/testing/selftests/bpf/test_tunnel.sh @@ -45,6 +45,22 @@ # 5) Tunnel protocol handler, ex: vxlan_rcv, decap the packet # 6) Forward the packet to the overlay tnl dev +# The tunnels are built between this namespace and at_ns0, so a firewall +# on the machine filters the encapsulated traffic: our nodes reject IPv6 +# with admin-prohibited, which the ip6geneve case never survives. A +# namespace of our own has no such rules, and takes the devices with it +# when the test ends. +if [ -z "${BPF_TUNNEL_NETNS:-}" ]; then + BPF_TUNNEL_NETNS=1 export BPF_TUNNEL_NETNS + exec unshare -n sh -c 'ip link set lo up; exec "$0" "$@"' "$0" "$@" +fi + +# The BPF object refers to the FOU kfuncs, and libbpf has to resolve them +# against kernel or module BTF before it can load the object at all, also +# for the tunnel types that do not use FOU. Nothing to do where FOU is +# built in. +modprobe fou 2>/dev/null + BPF_FILE="test_tunnel_kern.bpf.o" BPF_PIN_TUNNEL_DIR="/sys/fs/bpf/tc/tunnel" PING_ARG="-c 3 -w 10 -q" @@ -241,7 +257,7 @@ test_gre() DEV=gretap11 ret=0 - check $TYPE + check $TYPE || return 0 config_device add_gre_tunnel 2 attach_bpf $DEV gre_set_tunnel gre_get_tunnel @@ -265,7 +281,7 @@ test_gre_no_tunnel_key() DEV=gre11 ret=0 - check $TYPE + check $TYPE || return 0 config_device add_gre_tunnel attach_bpf $DEV gre_set_tunnel_no_key gre_get_tunnel @@ -289,7 +305,7 @@ test_ip6gre() DEV=ip6gre11 ret=0 - check $TYPE + check $TYPE || return 0 config_device # reuse the ip6gretap function add_ip6gretap_tunnel @@ -319,7 +335,7 @@ test_ip6gretap() DEV=ip6gretap11 ret=0 - check $TYPE + check $TYPE || return 0 config_device add_ip6gretap_tunnel attach_bpf $DEV ip6gretap_set_tunnel ip6gretap_get_tunnel @@ -348,7 +364,7 @@ test_erspan() DEV=erspan11 ret=0 - check $TYPE + check $TYPE || return 0 config_device add_erspan_tunnel $1 attach_bpf $DEV erspan_set_tunnel erspan_get_tunnel @@ -372,7 +388,7 @@ test_ip6erspan() DEV=ip6erspan11 ret=0 - check $TYPE + check $TYPE || return 0 config_device add_ip6erspan_tunnel $1 attach_bpf $DEV ip4ip6erspan_set_tunnel ip4ip6erspan_get_tunnel @@ -395,7 +411,7 @@ test_geneve() DEV=geneve11 ret=0 - check $TYPE + check $TYPE || return 0 config_device add_geneve_tunnel attach_bpf $DEV geneve_set_tunnel geneve_get_tunnel @@ -419,7 +435,7 @@ test_ip6geneve() DEV=ip6geneve11 ret=0 - check $TYPE + check $TYPE || return 0 config_device add_ip6geneve_tunnel attach_bpf $DEV ip6geneve_set_tunnel ip6geneve_get_tunnel @@ -443,7 +459,7 @@ test_ipip() DEV=ipip11 ret=0 - check $TYPE + check $TYPE || return 0 config_device add_ipip_tunnel ip link set dev veth1 mtu 1500 @@ -468,7 +484,7 @@ test_ipip6() DEV=ipip6tnl11 ret=0 - check $TYPE + check $TYPE || return 0 config_device add_ip6tnl_tunnel ip link set dev veth1 mtu 1500 @@ -496,7 +512,7 @@ test_ip6ip6() DEV=ip6ip6tnl11 ret=0 - check $TYPE + check $TYPE || return 0 config_device add_ip6tnl_tunnel ip link set dev veth1 mtu 1500 @@ -563,6 +579,18 @@ check() cleanup return 1 fi + + # The kernel can be built without a tunnel type, and then rtnetlink + # has no ops for it and says so. + if ip link add dev "probe_$1" type "$1" 2>&1 | \ + grep -q "Unknown device type"; then + echo "SKIP $1: kernel does not support $1" + cleanup + return 1 + fi + ip link del dev "probe_$1" 2>/dev/null + + return 0 } enable_debug() -- 2.55.0 _______________________________________________ Devel mailing list Devel@openvz.org https://lists.openvz.org/mailman/listinfo/devel