From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from mail.openvz.org (unknown [69.168.225.77]) by lore.virtuozzo.com (Postfix) with ESMTPS id 741B180275 for ; Mon, 31 Aug 2026 23:45:30 +0000 (UTC) Received: from mail.openvz.org (localhost [127.0.0.1]) by mail.openvz.org (8.14.4/8.14.4) with ESMTP id 67VNiIl3032122; Tue, 1 Sep 2026 02:44:18 +0300 DKIM-Filter: OpenDKIM Filter v2.11.0 mail.openvz.org 67VNiIl3032122 Authentication-Results: mail.openvz.org; dkim=fail reason="signature verification failed" (2048-bit key) header.d=virtuozzo.com header.i=@virtuozzo.com header.b="Ia5qT8K/" Received: from mail-wr1-f69.google.com (mail-wr1-f69.google.com [209.85.221.69]) by mail.openvz.org (8.14.4/8.14.4) with ESMTP id 67VNiEFH032107 (version=TLSv1/SSLv3 cipher=AES128-GCM-SHA256 bits=128 verify=FAIL) for ; Tue, 1 Sep 2026 02:44:14 +0300 DKIM-Filter: OpenDKIM Filter v2.11.0 mail.openvz.org 67VNiEFH032107 Received: by mail-wr1-f69.google.com with SMTP id ffacd0b85a97d-47f6d70223dso2815733f8f.1 for ; Mon, 31 Aug 2026 16:44:14 -0700 (PDT) X-Gm-Message-State: AFuF++ktRasXSwp4jn/mPnf4thekYm0ygoZ11ZM7OqxkiHAQqi+C9VDq DtQEMh47vVLRJKBKr+NF2bhNvsLvRz2DEQJ/sSAWCRS61eQlAoUDGvBMTyh32QK7DiM0HHHM+Gz Zf5t17caZ9BA39ISyXTPur5KZ9rHe+/RoNQG0pQR06vb6+fyx7vtthQ== X-Gm-Gg: AYBFou10SitUZX3RcVX7FbXVvFiHG9Na1PoNSrt6lK1EJMYYGhIYim0j2V3UVpjbPgh GRNOn01uWWcPZNatmWoFfeNzMWZrmC2cxkixWLX6xf+zzY7tjktn6iWhQ8u6TJrqTLGHWXNJdZ3 eQc/g6JHN2vnB9+9I07BcpE9+BBPHL3l60Cro3StsfB4q4RjiKwW1aYiBI6z77fxPsvOEx/6wL+ JvCwQ5oscUVxCy8ASjLJW8w1qI2EdYTRnepONcsyVwNnIRBrXROOZ08/fQz23pmbOLCZ0QxM0UA FOjaUjuEKNtlUoTY0bnGF9n/5/7HhSaku433VLITYc3WwqC/T4N+AMyWFkVBRpeJH4SAinzMyI6 S2kbxowf2RZrhcx/7rTjal4Zn X-Received: by 2002:adf:ec8c:0:b0:484:4164:af7f with SMTP id ffacd0b85a97d-4844164afafmr4641026f8f.16.1788219854357; Mon, 31 Aug 2026 16:44:14 -0700 (PDT) X-Received: by 2002:adf:ec8c:0:b0:484:4164:af7f with SMTP id ffacd0b85a97d-4844164afafmr4640989f8f.16.1788219853827; Mon, 31 Aug 2026 16:44:13 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1788219853; cv=none; d=google.com; s=arc-20260327; b=RsuXU8Jc+OfUQjWAGkQCFwi4e1s1fYSSTk231vpsBi++qLveBo/J3vX9vPxqAYwQJD 8ckLyJt95Q5f8fPApPodhfSEP39n1J/KgU2k3AqQIq6uJgsG3POtuB9R5ObnrqxaggjB NboqblWqBFlr+GP3j9wBUO8y+/VEF+wF1k4ZAe7OvMfimFzmwyhJhMHKp2Ercl3ZWgqX OXwU5jPZY+fosrjdsK2JczKZdoqNzz8NZq9DPfkKzazzMbloNPmVawb7CK/8GqzKvUQC 4jnAiPQ8OTeQ832HFsDxRufTx5sstwQgs7uJQ8rITvv3/21bGNAcK3sxY1MA0GbqySGm MOmg== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20260327; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:dkim-signature; bh=w7QFXgUbgkH0zDAfGNcJODJ+O9GP70Gwp9o3XCq6E+E=; fh=WpT6aB7RBAGHZeWZzqAr71yzRFbPTYkPWKsRagLn48Q=; b=a0/xeqC+mFpb3IwjZMhnXNzLjg6wUe3L3HmPFHQXR1lUxaQqrX2BEx7OM7wFBjAzvh Tsdb4REoZtUipFxUOOLs1W5LCCn+8D+aMkp2YejzKo3KYQGceLTiQRcVzmD5g+zh/3fo sCKWMMzpmMmM2O9ddO96Wij94TTXwJnAEGPrTax7AZCTAeib6rJHaSIbu4m2f9G0gOPY PMn7rqYAeanO49uSj2L3U5WSq0Knjwe+ose1DUMNR5T8Grs/B5Z2z6zo1xeGe1+3PiV0 wqeejwq35TATVR2eAY8Qb3xAb96tNojKl34qhI3ITYK+kHTXs6Yxyn2lDazuASEuPMbe sFqA==; dara=google.com ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@virtuozzo.com header.s=relay header.b="Ia5qT8K/"; spf=pass (google.com: domain of eva.kurchatova@virtuozzo.com designates 130.117.225.111 as permitted sender) smtp.mailfrom=eva.kurchatova@virtuozzo.com; dmarc=pass (p=QUARANTINE sp=QUARANTINE dis=NONE) header.from=virtuozzo.com Received: from relay.virtuozzo.com (relay.virtuozzo.com. [130.117.225.111]) by mx.google.com with ESMTPS id ffacd0b85a97d-48442d37269si1016491f8f.47.2026.08.31.16.44.13 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 31 Aug 2026 16:44:13 -0700 (PDT) Received-SPF: pass (google.com: domain of eva.kurchatova@virtuozzo.com designates 130.117.225.111 as permitted sender) client-ip=130.117.225.111; Authentication-Results: mx.google.com; dkim=pass header.i=@virtuozzo.com header.s=relay header.b="Ia5qT8K/"; spf=pass (google.com: domain of eva.kurchatova@virtuozzo.com designates 130.117.225.111 as permitted sender) smtp.mailfrom=eva.kurchatova@virtuozzo.com; dmarc=pass (p=QUARANTINE sp=QUARANTINE dis=NONE) header.from=virtuozzo.com DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=virtuozzo.com; s=relay; h=MIME-Version:Message-ID:Date:Subject:From: Content-Type; bh=w7QFXgUbgkH0zDAfGNcJODJ+O9GP70Gwp9o3XCq6E+E=; b=Ia5qT8K/fTUe AHiR1Z4Bm7YI3TugeMeWpyz0MLiH8hR+F1iEpHr3/ZNMlY4k/V6rbhN+aToEF+8GaFIW5wWUqEZis r9Ckbftb1C/cbFeySX21JBlkavw8V+UlZcp/3TMFb4nMZp/QBjM2oeSLCmBUFAgyk2HjDSgLlN4rb smbRSp+hR4WcwgsYoQd29Ph33TN0Z3fQkflz+WXyjTvAlHfaKh0RF2o1U/m1KkBPBkX6hesZvvYls 1HQyPgeQD/UPtlxShvY0aJYSw2K2m/l6H+vqnVmyhF3D6q4jBV+hrEoi9GtUcWQP4BAYzogHHLBDe oKafcfGOOB2yhZ7r6RGPkg==; Received: from ch-vpn.virtuozzo.com ([130.117.225.6] helo=LekKit-T14) by relay.virtuozzo.com with esmtp (Exim 4.96) (envelope-from ) id 1x1BdK-00AoFq-2L; Tue, 01 Sep 2026 01:44:04 +0200 From: Eva Kurchatova To: khorenko@virtuozzo.com Date: Tue, 1 Sep 2026 02:43:48 +0300 Message-ID: <20260831234411.1649762-2-eva.kurchatova@virtuozzo.com> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260831234411.1649762-1-eva.kurchatova@virtuozzo.com> References: <20260831234411.1649762-1-eva.kurchatova@virtuozzo.com> MIME-Version: 1.0 X-OZ-Fwd: true Cc: devel@openvz.org Subject: [Devel] [PATCH vz10 2/3] selftests: drv-net: run ping in its own netns X-BeenThere: devel@openvz.org X-Mailman-Version: 2.1.12 Precedence: list List-Id: OpenVZ development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: 7bit Sender: devel-bounces@openvz.org Errors-To: devel-bounces@openvz.org In netdevsim mode NetDrvEpEnv gives the remote end a namespace of its own and leaves the local end in the one the test was started in, so the filtering of the host applies to the traffic the test sends to itself. A host that drops it fails the test: # nft add rule inet t input ip saddr 192.0.2.0/24 tcp flags syn drop # ./ping.py ok 1 ping.test_v4 ok 2 ping.test_v6 not ok 3 ping.test_tcp # Stopping tests due to KsftTerminate. ICMP is let through where TCP is not, which is why the first two pass and the test then sits there until it is killed. Re-execute the test in a namespace of its own, the way nft_audit.sh and nft_concat_range.sh already do, and mount sysfs again there so that the netdevsim devices the test creates are the ones it sees. https://virtuozzo.atlassian.net/browse/VSTOR-139651 Feature: fix selftests Signed-off-by: Eva Kurchatova --- .../selftests/drivers/net/lib/py/__init__.py | 2 +- tools/testing/selftests/drivers/net/ping.py | 5 ++++ tools/testing/selftests/net/lib/py/utils.py | 24 +++++++++++++++++++ 3 files changed, 30 insertions(+), 1 deletion(-) diff --git a/tools/testing/selftests/drivers/net/lib/py/__init__.py b/tools/testing/selftests/drivers/net/lib/py/__init__.py index fce5d9218f1d..2d3fdaa81550 100644 --- a/tools/testing/selftests/drivers/net/lib/py/__init__.py +++ b/tools/testing/selftests/drivers/net/lib/py/__init__.py @@ -15,7 +15,7 @@ try: NlError, RtnlFamily, DevlinkFamily from net.lib.py import CmdExitFailure from net.lib.py import bkg, cmd, defer, ethtool, fd_read_timeout, ip, \ - rand_port, tool, wait_port_listen + rand_port, rexec_in_netns, tool, wait_port_listen from net.lib.py import fd_read_timeout from net.lib.py import KsftSkipEx, KsftFailEx, KsftXfailEx from net.lib.py import ksft_disruptive, ksft_exit, ksft_pr, ksft_run, \ diff --git a/tools/testing/selftests/drivers/net/ping.py b/tools/testing/selftests/drivers/net/ping.py index dfcf6ddd4c01..4799c94369d4 100755 --- a/tools/testing/selftests/drivers/net/ping.py +++ b/tools/testing/selftests/drivers/net/ping.py @@ -5,6 +5,7 @@ from lib.py import ksft_run, ksft_exit from lib.py import ksft_eq from lib.py import NetDrvEpEnv from lib.py import bkg, cmd, wait_port_listen, rand_port +from lib.py import rexec_in_netns def test_v4(cfg) -> None: @@ -42,6 +43,10 @@ def test_tcp(cfg) -> None: def main() -> None: + # In netdevsim mode the local end of the test stays in the namespace + # the test was started in, so the rules of the host apply to it. + rexec_in_netns(__file__) + with NetDrvEpEnv(__file__) as cfg: ksft_run(globs=globals(), case_pfx={"test_"}, args=(cfg, )) ksft_exit() diff --git a/tools/testing/selftests/net/lib/py/utils.py b/tools/testing/selftests/net/lib/py/utils.py index afce547bcab0..13d7a7e6562e 100644 --- a/tools/testing/selftests/net/lib/py/utils.py +++ b/tools/testing/selftests/net/lib/py/utils.py @@ -8,6 +8,7 @@ import re import select import socket import subprocess +import sys import time @@ -131,6 +132,29 @@ def ethtool(args, json=None, ns=None, host=None): return tool('ethtool', args, json=json, ns=ns, host=host) +def rexec_in_netns(path): + """ + Re-exec the test in a network namespace of its own. + + A test that puts one end of its traffic in the namespace it was + started in otherwise depends on what the host filters. sysfs is + mounted again in the new namespace, without it the netdevsim + devices the test creates are not the ones it sees. The test is + left where it is if unshare is not there to move it. + """ + if os.environ.get("KSFT_IN_NETNS"): + return + + os.environ["KSFT_IN_NETNS"] = "1" + try: + os.execvp("unshare", + ["unshare", "-n", "-m", + "sh", "-c", 'mount -t sysfs sysfs /sys && exec "$@"', + "sh", sys.executable, os.path.abspath(path)] + sys.argv[1:]) + except OSError: + del os.environ["KSFT_IN_NETNS"] + + def rand_port(type=socket.SOCK_STREAM): """ Get a random unprivileged port. -- 2.55.0 _______________________________________________ Devel mailing list Devel@openvz.org https://lists.openvz.org/mailman/listinfo/devel