[Devel] [PATCH vz10 v2 1/5] selftests: net: turn ip_forward off in setup_ns

Eva Kurchatova eva.kurchatova at virtuozzo.com
Tue Sep 1 02:45:29 MSK 2026


A new network namespace takes net.ipv4.ip_forward from the namespace it
is created in:

  # sysctl -wq net.ipv4.ip_forward=1
  # ip netns add probe
  # ip netns exec probe cat /proc/sys/net/ipv4/ip_forward
  1

so on a machine that routes, every test namespace forwards. nft_fib.sh
is one that cannot work that way: the two hosts either side of its
router forward the test packets back at it until the TTL runs out, and
the fib expressions the test checks see the wrong thing.

setup_ns already takes rp_filter out of the way for the same reason, so
take ip_forward too, and let the tests that want a router turn it on
themselves, which the ones that need it already do.

net.ipv6.conf.all.forwarding is not inherited, verified the same way, so
it needs no such treatment.

https://virtuozzo.atlassian.net/browse/VSTOR-139651
Feature: fix selftests
Signed-off-by: Eva Kurchatova <eva.kurchatova at virtuozzo.com>
---
 tools/testing/selftests/net/lib.sh | 1 +
 1 file changed, 1 insertion(+)

diff --git a/tools/testing/selftests/net/lib.sh b/tools/testing/selftests/net/lib.sh
index c712a5897075..0a38c1ed4b49 100644
--- a/tools/testing/selftests/net/lib.sh
+++ b/tools/testing/selftests/net/lib.sh
@@ -219,6 +219,7 @@ setup_ns()
 		ip -n "${!ns_name}" link set lo up
 		ip netns exec "${!ns_name}" sysctl -wq net.ipv4.conf.all.rp_filter=0
 		ip netns exec "${!ns_name}" sysctl -wq net.ipv4.conf.default.rp_filter=0
+		ip netns exec "${!ns_name}" sysctl -wq net.ipv4.ip_forward=0
 		ns_list+=("${!ns_name}")
 	done
 	NS_LIST+=("${ns_list[@]}")
-- 
2.55.0



More information about the Devel mailing list