make -C tools/testing/selftests TARGETS=net/netfilter TEST_PROGS=nft_flowttable.sh TEST_GEN_PROGS="" run_tests make: Entering directory '/home/virtme/testing-16/tools/testing/selftests' make[1]: Entering directory '/home/virtme/testing-16/tools/testing/selftests/net/netfilter' make[1]: Nothing to be done for 'all'. make[1]: Leaving directory '/home/virtme/testing-16/tools/testing/selftests/net/netfilter' make[1]: Entering directory '/home/virtme/testing-16/tools/testing/selftests/net/netfilter' TAP version 13 1..1 # overriding timeout to 3600 # selftests: net/netfilter: nft_flowtable.sh # 2024/05/10 23:52:55 socat[17916] E write(7, 0x5573f483f000, 8192): Broken pipe # FAIL: file mismatch for ns1 -> ns2 # -rw------- 1 root root 28984320 May 10 23:52 /tmp/tmp.UbOVF2kQfg # -rw------- 1 root root 20782704 May 10 23:52 /tmp/tmp.8peJPjrPXL # FAIL: file mismatch for ns1 <- ns2 # -rw------- 1 root root 28984320 May 10 23:52 /tmp/tmp.UbOVF2kQfg # -rw------- 1 root root 20897792 May 10 23:52 /tmp/tmp.BgOqv4AiWt # FAIL: flow offload for ns1/ns2: # table inet filter { # counter routed_orig { # packets 1234 bytes 21390916 # } # # counter routed_repl { # packets 10277 bytes 20536248 # } # # flowtable f1 { # hook ingress priority filter # devices = { veth0, veth1 } # } # # chain forward { # type filter hook forward priority filter; policy drop; # oif "veth1" tcp dport 12345 ct mark set 0x00000001 flow add @f1 counter name "routed_orig" accept # ct mark 0x00000001 counter name ct direction map { original : "routed_orig", reply : "routed_repl" } accept # ct state established,related accept # meta l4proto icmp accept # meta l4proto ipv6-icmp accept # } # } # PASS: dscp_none: dscp packet counters match # 2024/05/10 23:53:08 socat[17944] E write(7, 0x5626a0153000, 8192): Broken pipe # FAIL: file mismatch for ns1 -> ns2 # -rw------- 1 root root 28984320 May 10 23:52 /tmp/tmp.UbOVF2kQfg # -rw------- 1 root root 19097500 May 10 23:53 /tmp/tmp.8peJPjrPXL # FAIL: file mismatch for ns1 <- ns2 # -rw------- 1 root root 28984320 May 10 23:52 /tmp/tmp.UbOVF2kQfg # -rw------- 1 root root 19587072 May 10 23:53 /tmp/tmp.BgOqv4AiWt # PASS: dscp_ingress: dscp packet counters match # 2024/05/10 23:53:21 socat[17968] E write(7, 0x55dc642ec000, 8192): Broken pipe # FAIL: file mismatch for ns1 -> ns2 # -rw------- 1 root root 28984320 May 10 23:52 /tmp/tmp.UbOVF2kQfg # -rw------- 1 root root 17829688 May 10 23:53 /tmp/tmp.8peJPjrPXL # FAIL: file mismatch for ns1 <- ns2 # -rw------- 1 root root 28984320 May 10 23:52 /tmp/tmp.UbOVF2kQfg # -rw------- 1 root root 18751488 May 10 23:53 /tmp/tmp.BgOqv4AiWt # PASS: dscp_egress: dscp packet counters match # 2024/05/10 23:53:34 socat[17992] E write(7, 0x558637668000, 8192): Connection reset by peer # FAIL: file mismatch for ns1 -> ns2 # -rw------- 1 root root 28984320 May 10 23:52 /tmp/tmp.UbOVF2kQfg # -rw------- 1 root root 25849656 May 10 23:53 /tmp/tmp.8peJPjrPXL # FAIL: file mismatch for ns1 <- ns2 # -rw------- 1 root root 28984320 May 10 23:52 /tmp/tmp.UbOVF2kQfg # -rw------- 1 root root 23764992 May 10 23:53 /tmp/tmp.BgOqv4AiWt # PASS: dscp_fwd: dscp packet counters match # 2024/05/10 23:53:46 socat[18014] E write(7, 0x55a61cd61000, 8192): Broken pipe # FAIL: file mismatch for ns1 -> ns2 # -rw------- 1 root root 28984320 May 10 23:52 /tmp/tmp.UbOVF2kQfg # -rw------- 1 root root 18206520 May 10 23:53 /tmp/tmp.8peJPjrPXL # FAIL: file mismatch for ns1 <- ns2 # -rw------- 1 root root 28984320 May 10 23:52 /tmp/tmp.UbOVF2kQfg # -rw------- 1 root root 19079168 May 10 23:53 /tmp/tmp.BgOqv4AiWt # FAIL: flow offload for ns1/ns2 with NAT # table inet filter { # counter routed_orig { # packets 7612 bytes 105633780 # } # # counter routed_repl { # packets 50441 bytes 100729688 # } # # flowtable f1 { # hook ingress priority filter # devices = { veth0, veth1 } # } # # chain forward { # type filter hook forward priority filter; policy drop; # ip dscp set cs3 # oif "veth1" tcp dport 12345 ct mark set 0x00000001 flow add @f1 counter name "routed_orig" accept # ct mark 0x00000001 counter name ct direction map { original : "routed_orig", reply : "routed_repl" } accept # ct state established,related accept # meta l4proto icmp accept # meta l4proto ipv6-icmp accept # } # } # table ip nat { # chain prerouting { # type nat hook prerouting priority filter; policy accept; # iif "veth0" ip daddr 10.6.6.6 tcp dport 1666 counter packets 0 bytes 0 dnat to 10.0.2.99:12345 # } # # chain postrouting { # type nat hook postrouting priority filter; policy accept; # oifname "veth1" counter packets 4 bytes 240 masquerade # } # } # table netdev dscpmangle { # chain setdscp0 { # type filter hook egress device "veth1" priority filter; policy accept; # } # } # PASS: flow offload for ns1/ns2 with masquerade and pmtu discovery # PASS: flow offload for ns1/ns2 with dnat and pmtu discovery ns1 <- ns2 # PASS: flow offload for ns1/ns2 with masquerade and pmtu discovery on bridge # PASS: flow offload for ns1/ns2 with dnat and pmtu discovery ns1 <- ns2 # PASS: flow offload for ns1/ns2 with masquerade and pmtu discovery bridge and VLAN # PASS: flow offload for ns1/ns2 with dnat and pmtu discovery ns1 <- ns2 # 2024/05/10 23:54:29 socat[18207] E write(7, 0x55e025197000, 8192): Broken pipe # FAIL: file mismatch for ns1 -> ns2 # -rw------- 1 root root 28984320 May 10 23:52 /tmp/tmp.UbOVF2kQfg # -rw------- 1 root root 14547212 May 10 23:54 /tmp/tmp.8peJPjrPXL # FAIL: file mismatch for ns1 <- ns2 # -rw------- 1 root root 28984320 May 10 23:52 /tmp/tmp.UbOVF2kQfg # -rw------- 1 root root 16670720 May 10 23:54 /tmp/tmp.BgOqv4AiWt # FAIL: ipsec tunnel mode for ns1/ns2 # table inet filter { # counter routed_orig { # packets 2 bytes 112 # } # # counter routed_repl { # packets 3 bytes 164 # } # # flowtable f1 { # hook ingress priority filter # devices = { veth0, veth1 } # } # # chain forward { # type filter hook forward priority filter; policy drop; # ip dscp set cs3 # oif "veth1" tcp dport 12345 ct mark set 0x00000001 flow add @f1 counter name "routed_orig" accept # ct mark 0x00000001 counter name ct direction map { original : "routed_orig", reply : "routed_repl" } accept # ct state established,related accept # meta l4proto icmp accept # meta l4proto ipv6-icmp accept # } # } # table netdev dscpmangle { # chain setdscp0 { # type filter hook egress device "veth1" priority filter; policy accept; # } # } # XfrmInError 0 # XfrmInBufferError 0 # XfrmInHdrError 0 # XfrmInNoStates 0 # XfrmInStateProtoError 0 # XfrmInStateModeError 0 # XfrmInStateSeqError 0 # XfrmInStateExpired 0 # XfrmInStateMismatch 0 # XfrmInStateInvalid 0 # XfrmInTmplMismatch 0 # XfrmInNoPols 0 # XfrmInPolBlock 0 # XfrmInPolError 0 # XfrmOutError 0 # XfrmOutBundleGenError 0 # XfrmOutBundleCheckError 0 # XfrmOutNoStates 0 # XfrmOutStateProtoError 0 # XfrmOutStateModeError 0 # XfrmOutStateSeqError 0 # XfrmOutStateExpired 0 # XfrmOutPolBlock 0 # XfrmOutPolDead 0 # XfrmOutPolError 0 # XfrmFwdHdrError 0 # XfrmOutStateInvalid 0 # XfrmAcquireError 0 # XfrmOutStateDirError 0 # XfrmInStateDirError 0 # re-run with random mtus: -o 9186 -l 12496 -r 7318 # PASS: flow offloaded for ns1/ns2 # PASS: dscp_none: dscp packet counters match # PASS: dscp_ingress: dscp packet counters match # PASS: dscp_egress: dscp packet counters match # PASS: dscp_fwd: dscp packet counters match # PASS: flow offload for ns1/ns2 with masquerade # PASS: flow offload for ns1/ns2 with dnat ns1 <- ns2 # PASS: flow offload for ns1/ns2 with masquerade and pmtu discovery # PASS: flow offload for ns1/ns2 with dnat and pmtu discovery ns1 <- ns2 # PASS: flow offload for ns1/ns2 with masquerade and pmtu discovery on bridge # PASS: flow offload for ns1/ns2 with dnat and pmtu discovery ns1 <- ns2 # PASS: flow offload for ns1/ns2 with masquerade and pmtu discovery bridge and VLAN # PASS: flow offload for ns1/ns2 with dnat and pmtu discovery ns1 <- ns2 # 2024/05/10 23:55:53 socat[18588] E write(7, 0x5608924e8000, 8192): Broken pipe # FAIL: file mismatch for ns1 -> ns2 # -rw------- 1 root root 37406720 May 10 23:54 /tmp/tmp.bE9kkAMMoO # -rw------- 1 root root 18784256 May 10 23:55 /tmp/tmp.zPetbqx9H4 # FAIL: file mismatch for ns1 <- ns2 # -rw------- 1 root root 37406720 May 10 23:54 /tmp/tmp.bE9kkAMMoO # -rw------- 1 root root 18800640 May 10 23:55 /tmp/tmp.tTsgohgZLc # FAIL: ipsec tunnel mode for ns1/ns2 # table inet filter { # counter routed_orig { # packets 2 bytes 112 # } # # counter routed_repl { # packets 3 bytes 164 # } # # flowtable f1 { # hook ingress priority filter # devices = { veth0, veth1 } # } # # chain forward { # type filter hook forward priority filter; policy drop; # ip dscp set cs3 # oif "veth1" tcp dport 12345 ct mark set 0x00000001 flow add @f1 counter name "routed_orig" accept # ct mark 0x00000001 counter name ct direction map { original : "routed_orig", reply : "routed_repl" } accept # ct state established,related accept # meta l4proto icmp accept # meta l4proto ipv6-icmp accept # } # } # table netdev dscpmangle { # chain setdscp0 { # type filter hook egress device "veth1" priority filter; policy accept; # } # } # XfrmInError 0 # XfrmInBufferError 0 # XfrmInHdrError 0 # XfrmInNoStates 0 # XfrmInStateProtoError 0 # XfrmInStateModeError 0 # XfrmInStateSeqError 0 # XfrmInStateExpired 0 # XfrmInStateMismatch 0 # XfrmInStateInvalid 0 # XfrmInTmplMismatch 0 # XfrmInNoPols 0 # XfrmInPolBlock 0 # XfrmInPolError 0 # XfrmOutError 0 # XfrmOutBundleGenError 0 # XfrmOutBundleCheckError 0 # XfrmOutNoStates 0 # XfrmOutStateProtoError 0 # XfrmOutStateModeError 0 # XfrmOutStateSeqError 0 # XfrmOutStateExpired 0 # XfrmOutPolBlock 0 # XfrmOutPolDead 0 # XfrmOutPolError 0 # XfrmFwdHdrError 0 # XfrmOutStateInvalid 0 # XfrmAcquireError 0 # XfrmOutStateDirError 0 # XfrmInStateDirError 0 not ok 1 selftests: net/netfilter: nft_flowtable.sh # exit=1 make[1]: Leaving directory '/home/virtme/testing-16/tools/testing/selftests/net/netfilter' make: Leaving directory '/home/virtme/testing-16/tools/testing/selftests' xx__-> echo $? 0 xx__->