[Devel] [PATCH RHEL10 COMMIT] selftests: mptcp: turn forwarding off in the test namespaces

Konstantin Khorenko khorenko at virtuozzo.com
Mon Aug 24 19:47:52 MSK 2026


The commit is pushed to "branch-rh10-6.12.0-211.39.1.16.x.vz10-ovz" and will appear at git at bitbucket.org:openvz/vzkernel.git
after rh10-6.12.0-211.39.1.16.8.vz10
------>
commit 38b336063172bfdcdcc0460edf97794870c0a2d4
Author: Eva Kurchatova <eva.kurchatova at virtuozzo.com>
Date:   Fri Aug 21 18:20:28 2026 +0300

    selftests: mptcp: turn forwarding off in the test namespaces
    
    A new namespace inherits net.ipv4.ip_forward from the host, so on a host
    that routes, so do the namespaces these tests build.
    IPv6 forwarding is inheritable too, depending on
    net.core.devconf_inherit_init_net, so turn both off.
    
    Only IPv4 is inherited with the default
    net.core.devconf_inherit_init_net: devinet_init_net() copies devconf
    from init_net for 0 and 1, while addrconf_init_net() uses the compiled
    defaults for 0. Turn IPv6 forwarding off as well, it becomes inheritable
    once that knob is 1 or 3, and the tests which do need a router enable
    both anyway.
    
    "invalid address, ADD_ADDR timeout" then reports 0 JOINs where it wants
    1. The server announces an unreachable address first and a valid one
    after it. With forwarding on, the SYN to the unreachable address draws
    an ICMP error instead of being dropped, so the subflow attempt fails at
    once and the next ADD_ADDR retransmission starts another one. Every
    attempt that no longer finds its predecessor bumps add_addr_accepted, so
    the unreachable address alone uses up both accepted slots and the valid
    address that follows is dropped without ever getting a subflow.
    
    The two tests that do need a router, mptcp_connect.sh and
    simult_flows.sh, turn forwarding on themselves for those namespaces, so
    switching it off in the common setup is enough.
    
    https://virtuozzo.atlassian.net/browse/VSTOR-139651
    Feature: fix selftests
    Signed-off-by: Eva Kurchatova <eva.kurchatova at virtuozzo.com>
    Reviewed-by: Konstantin Khorenko <khorenko at virtuozzo.com>
---
 tools/testing/selftests/net/mptcp/mptcp_lib.sh | 7 +++++++
 1 file changed, 7 insertions(+)

diff --git a/tools/testing/selftests/net/mptcp/mptcp_lib.sh b/tools/testing/selftests/net/mptcp/mptcp_lib.sh
index a326f34fc719..43112e1c8c59 100644
--- a/tools/testing/selftests/net/mptcp/mptcp_lib.sh
+++ b/tools/testing/selftests/net/mptcp/mptcp_lib.sh
@@ -455,6 +455,13 @@ mptcp_lib_ns_init() {
 	local netns
 	for netns in "${@}"; do
 		ip netns exec "${!netns}" sysctl -q net.mptcp.enabled=1
+		# The tests that need a router enable forwarding themselves,
+		# everywhere else it has to be off: a new namespace inherits
+		# the setting, so on a host that routes, an unreachable
+		# announced address is answered with an ICMP error instead of
+		# being silently dropped.
+		ip netns exec "${!netns}" sysctl -q net.ipv4.ip_forward=0
+		ip netns exec "${!netns}" sysctl -q net.ipv6.conf.all.forwarding=0
 	done
 }
 


More information about the Devel mailing list