Netfilter-Devel Archive on lore.kernel.org
 help / color / Atom feed
From: Florian Westphal <fw@strlen.de>
To: Phil Sutter <phil@nwl.cc>, Florian Westphal <fw@strlen.de>,
	netfilter-devel@vger.kernel.org
Subject: Re: [PATCH nf] selftests: netfilter: use randomized netns names
Date: Thu, 5 Dec 2019 00:20:29 +0100
Message-ID: <20191204232029.GW795@breakpoint.cc> (raw)
In-Reply-To: <20191204231404.GA14469@orbyte.nwl.cc>

Phil Sutter <phil@nwl.cc> wrote:
> Hi,
> 
> On Mon, Dec 02, 2019 at 06:35:40PM +0100, Florian Westphal wrote:
> [...]
> > @@ -532,32 +547,32 @@ EOF
> >  	# ns1 should not have seen packets from ns2, due to masquerade
> >  	expect="packets 0 bytes 0"
> >  	for dir in "in" "out" ; do
> > -		cnt=$(ip netns exec ns1 nft list counter inet filter ns2${dir} | grep -q "$expect")
> > +		cnt=$(ip netns exec "$ns1" nft list counter inet filter ns2${dir} | grep -q "$expect")
> >  		if [ $? -ne 0 ]; then
> > -			bad_counter ns1 ns0$dir "$expect"
> > +			bad_counter "$ns1" ns0$dir "$expect" "test_masquerade 5"
> >  			lret=1
> >  		fi
> >  
> > -		cnt=$(ip netns exec ns1 nft list counter inet filter ns2${dir} | grep -q "$expect")
> > +		cnt=$(ip netns exec "$ns0" nft list counter inet filter ns1${dir} | grep -q "$expect")
> 
> This is confusing. You're fixing a bug and it is correct?

It was a duplicate of the check above.

> >  		if [ $? -ne 0 ]; then
> > -			bad_counter ns2 ns1$dir "$expect"
> > +			bad_counter "$ns0" ns1$dir "$expect" "test_masquerade 6"
> 
> And here as well?

Yes, this should test ns0 did not get packets from ns1.

> [...]
> > @@ -708,28 +723,28 @@ EOF
> >  	# ns0 should have seen packets from ns2, due to masquerade
> >  	expect="packets 1 bytes 84"
> >  	for dir in "in" "out" ; do
> > -		cnt=$(ip netns exec ns0 nft list counter inet filter ns2${dir} | grep -q "$expect")
> > +		cnt=$(ip netns exec "$ns0" nft list counter inet filter ns2${dir} | grep -q "$expect")
> >  		if [ $? -ne 0 ]; then
> > -			bad_counter ns1 ns0$dir "$expect"
> > +			bad_counter "$ns0" ns0$dir "$expect" "test_redirect 4"
> 
> This is actually a bugfix, right?

Yes, test is correct but if it fails it dumped the wrong counter.

  reply index

Thread overview: 5+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2019-12-02 17:35 Florian Westphal
2019-12-04 23:14 ` Phil Sutter
2019-12-04 23:20   ` Florian Westphal [this message]
2019-12-06  9:15 ` Stefano Brivio
2019-12-07 18:52 ` Pablo Neira Ayuso

Reply instructions:

You may reply publically to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20191204232029.GW795@breakpoint.cc \
    --to=fw@strlen.de \
    --cc=netfilter-devel@vger.kernel.org \
    --cc=phil@nwl.cc \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link

Netfilter-Devel Archive on lore.kernel.org

Archives are clonable:
	git clone --mirror https://lore.kernel.org/netfilter-devel/0 netfilter-devel/git/0.git

	# If you have public-inbox 1.1+ installed, you may
	# initialize and index your mirror using the following commands:
	public-inbox-init -V2 netfilter-devel netfilter-devel/ https://lore.kernel.org/netfilter-devel \
		netfilter-devel@vger.kernel.org
	public-inbox-index netfilter-devel

Example config snippet for mirrors

Newsgroup available over NNTP:
	nntp://nntp.lore.kernel.org/org.kernel.vger.netfilter-devel


AGPL code for this site: git clone https://public-inbox.org/public-inbox.git