[Devel] [PATCH vz10] selftests: drv-net: avoid host firewall interference

Eva Kurchatova (Virtuozzo) eva.kurchatova at virtuozzo.com
Wed Aug 26 01:58:56 MSK 2026


On 8/18/26 20:43, Konstantin Khorenko wrote:
> Please check hci-tests.vhistrg repo for the following commit:
> https://bitbucket.org/virtuozzocore/hci-tests.vhistrg/commits/00e524341ea1e55a11d9de5cb2ab03cb21118208
>
> commit 00e524341ea1e55a11d9de5cb2ab03cb21118208
> Author: Aleksei Oladko <aleksey.oladko at virtuozzo.com>
> Date:   Wed Feb 18 09:33:35 2026 +0000
>
>      hci-kselftests: stop firewalld to prevent test hangs
>
>      Some net/forwarding kselftests disable the default timeout and wait
>      for generated packets to be received. If firewall rules are active,
>      the packets may be dropped and the test can hang indefinitely.
>
>      The hci-kselftest previously attempted to clear firewall rules
>      with "nft flush ruleset", but firewalld restored them, causing the
>      tests to hang.
>
>      Stop firewalld instead to ensure the rules are not reinstalled
>      during test execution.
>
>      vstorage-ui-agent service monitors availability of firewalld and
>      restores it if needed => need to disable it as well.
>
>      /etc/firewalld/firewalld.conf CleanupOnExit option might cause
>      firewalld not to clear rules on a service stop =>
>      clean up rules additionally just in case.
>
>      https://virtuozzo.atlassian.net/browse/VSTOR-125054
>
>      Signed-off-by: Aleksei Oladko <aleksey.oladko at virtuozzo.com>
>
>
> It should already disable all iptables and Co.
>
> And taking this into account - do we still need this patch?
> If yes - why?
>
>
> --
> Best regards,
>
> Konstantin Khorenko,
> Virtuozzo Linux Kernel Team
>
> On 6/25/26 00:33, Eva Kurchatova wrote:
>> The NetDrvEpEnv test environment creates a netdevsim device in
>> init_net and a peer in a separate network namespace. Tests such as
>> ping.py's test_tcp start a socat listener in init_net and expect the
>> remote namespace to connect to it via random port.
>>
>> When a host firewall (e.g. firewalld with nftables backend) is active,
>> its INPUT chain rejects inbound TCP connections to ports not in its
>> allow-list. ICMP is explicitly permitted, so ping tests pass, but
>> TCP-based tests hang indefinitely: the socat listener never receives a
>> connection, and bkg(exit_wait=True) waits forever for it to exit,
>> resulting in a timeout failure.
>>
>> Fix this by adding the local netdevsim interface to the firewalld
>> trusted zone after creating the test topology in create_local().
>> The trusted zone accepts all traffic unconditionally, bypassing any
>> filtering rules. The interface is removed from the zone during
>> cleanup in __del__(). Both operations use fail=False so they are
>> silently skipped on systems without firewalld.
>>
>> Signed-off-by: Eva Kurchatova <eva.kurchatova at virtuozzo.com>
>>
>> https://virtuozzo.atlassian.net/browse/VSTOR-135793
>> Feature: fix selftests
>>
>> ---
>>   tools/testing/selftests/drivers/net/lib/py/env.py | 13 +++++++++++++
>>   1 file changed, 13 insertions(+)
>>
>> diff --git a/tools/testing/selftests/drivers/net/lib/py/env.py b/tools/testing/selftests/drivers/net/lib/py/env.py
>> index 1ea9bb695e94..b3d4c1accb25 100644
>> --- a/tools/testing/selftests/drivers/net/lib/py/env.py
>> +++ b/tools/testing/selftests/drivers/net/lib/py/env.py
>> @@ -92,6 +92,7 @@ class NetDrvEpEnv:
>>           self._netns = None
>>           self._ns = None
>>           self._ns_peer = None
>> +        self._fw_ifname = None
>>   
>>           if "NETIF" in self.env:
>>               if nsim_test is True:
>> @@ -156,6 +157,13 @@ class NetDrvEpEnv:
>>           ip(f"-6 addr add dev {self._ns_peer.nsims[0].ifname} {self.nsim_v6_pfx}2/64 nodad", ns=self._netns)
>>           ip(f"   link set dev {self._ns_peer.nsims[0].ifname} up", ns=self._netns)
>>   
>> +        # Allow all inbound traffic on the local test interface.
>> +        # A host firewall (e.g. firewalld) may reject connections to
>> +        # random test ports, causing TCP-based tests to time out.
>> +        self._fw_ifname = self._ns.nsims[0].ifname
>> +        cmd(f"firewall-cmd --zone=trusted --add-interface={self._fw_ifname}",
>> +            fail=False)
>> +
>>       def _check_env(self):
>>           vars_needed = [
>>               ["LOCAL_V4", "LOCAL_V6"],
>> @@ -190,6 +198,11 @@ class NetDrvEpEnv:
>>           self.__del__()
>>   
>>       def __del__(self):
>> +        if self._fw_ifname:
>> +            cmd(f"firewall-cmd --zone=trusted "
>> +                f"--remove-interface={self._fw_ifname}",
>> +                fail=False)
>> +            self._fw_ifname = None
>>           if self._ns:
>>               self._ns.remove()
>>               self._ns = None
The commit "selftests: drv-net: avoid host firewall interference" is 
superseded by the newer commits to kselftests harnesses, which all use 
dedicated per-test netns as opposed to altering the host firewall. This 
patch should be dropped. Note however, that the "hci-kselftests: stop 
firewalld to prevent test hangs" commit by Alexey Oladko did not 
originally fix the issue as it stands, as it only alters the behavior of 
tests under "net*" wildcard, which for example "drivers.net.netdevsim" 
did not fall under.


More information about the Devel mailing list