[Devel] [PATCH vz10 v2] selftests: ve_printk: match the conntrack overflow message

Konstantin Khorenko khorenko at virtuozzo.com
Mon Aug 24 17:53:37 MSK 2026


From: Eva Kurchatova <eva.kurchatova at virtuozzo.com>

The kernel prints

  VE%s: nf_conntrack table full in netns %u, dropping packet

while the test looks for "nf_conntrack table full, dropping packet".
The "in netns %u" part sits between the two halves the test expects to
be adjacent, so strstr() never matched: ve_log_both counted zero
messages and failed even when the container produced all ten of them.

Match the part of the message which carries no netns number, and drop
the stale quote from the comment above the test.

Fixes: d5ec8836f50d ("tests: add ve_printk selftest")
https://virtuozzo.atlassian.net/browse/VSTOR-139673
Feature: fix vz selftests
Signed-off-by: Eva Kurchatova <eva.kurchatova at virtuozzo.com>
Signed-off-by: Konstantin Khorenko <khorenko at virtuozzo.com>
---
Changes in v2:
- fix the stale quote in the comment above ve_log_both as well.  It
  still spelled out the message the test used to look for, which is
  exactly what would mislead the next reader.
- add a Fixes: tag.  The kernel message has carried "in netns %u"
  since 2015, so the test has been looking for a string that never
  existed rather than falling behind a later kernel change.
- commit message: quote the kernel format string instead of a made up
  log line with a VE0 prefix.  Inside the test the message is emitted
  for the container's netns, so the prefix is the container, not VE0.

 tools/testing/selftests/ve_printk/ve_printk_test.c | 12 ++++++------
 1 file changed, 6 insertions(+), 6 deletions(-)

diff --git a/tools/testing/selftests/ve_printk/ve_printk_test.c b/tools/testing/selftests/ve_printk/ve_printk_test.c
index 2df672d75e00..020df691e5d5 100644
--- a/tools/testing/selftests/ve_printk/ve_printk_test.c
+++ b/tools/testing/selftests/ve_printk/ve_printk_test.c
@@ -286,7 +286,7 @@ int ve_printk_test_logboth(void)
 	ret = TEST_RATELIMIT_BURST;
 	/* verify that only 10 records were added */
 	while (fgets(buf, sizeof(buf), pdmesg)) {
-		if (strstr(buf, "nf_conntrack table full, dropping packet")) {
+		if (strstr(buf, "nf_conntrack table full")) {
 			ret--;
 		}
 	}
@@ -614,10 +614,10 @@ TEST_F(ve_printk, ve0_log)
  * Test verifies net_veboth_ratelimited function which logs messages simultaneously
  * to both the container (VE_LOG) and VE0 (VE0_LOG), but with ratelimit throttling.
  * Inside the container, a small conntrack table (size 2) is configured, then many ping
- * packets are sent, causing table overflow and generation of "nf_conntrack table full,
- * dropping packet" messages. The test verifies that exactly TEST_RATELIMIT_BURST (10)
- * messages appeared on the host - ratelimit should limit the number of messages even
- * if more were generated.
+ * packets are sent, causing table overflow and generation of "nf_conntrack table
+ * full in netns N, dropping packet" messages. The test verifies that exactly
+ * TEST_RATELIMIT_BURST (10) messages appeared on the host - ratelimit should
+ * limit the number of messages even if more were generated.
  */
 TEST_F(ve_printk, ve_log_both)
 {
@@ -635,7 +635,7 @@ TEST_F(ve_printk, ve_log_both)
 	ASSERT_EQ(ret, 0);
 
 	while (fgets(buf, sizeof(buf), fdmesg)) {
-		if (strstr(buf, "nf_conntrack table full, dropping packet")) {
+		if (strstr(buf, "nf_conntrack table full")) {
 			ret++;
 		}
 	}
-- 
2.47.1



More information about the Devel mailing list