From nobody Sat Sep 5 05:52:09 2026 Received: from mta0.migadu.com (out-81.mta0.migadu.com [91.218.175.81]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 24CF83A9612 for ; Wed, 2 Sep 2026 06:53:03 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=91.218.175.81 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788331989; cv=none; b=pLHh5bDZLzjr/cmarsBZM+rzrGigghvJSp1vYkBJhmt/UY697M3ZIGGYjLWEXShX4U3ea17aJBfvrI04Sqoq+FZ0HPh1e41rHdJNPPA4dEjSiiYrWyygpaD6GfFm8+nhw4uzioqinNo/P8qONSa4m6q0F5qKouPCoSTaTO9yjqg= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788331989; c=relaxed/simple; bh=CjE4pZlt4icFEu9bJ6HEckDv3cSAsyek8ZM9GiMyKls=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=YmG4eB+pVJ7LkxZAh/snhG+7JIVbKwm3aQ6rHar9IcsFpTvwzGKggTce0awCvFQh1mWEaXkuAuCYdE0e3UOw8GXIEGgtKn6Y6VWXrteR+QYnMB6jxhb/5UtW+C34xZbdDl2S6Vof5dxV0Jx748I2WV471wEFpj2k1rCoQyst/bc= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.dev; spf=pass smtp.mailfrom=linux.dev; dkim=pass (1024-bit key) header.d=linux.dev header.i=@linux.dev header.b=TqInTpfx; arc=none smtp.client-ip=91.218.175.81 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.dev Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=linux.dev Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linux.dev header.i=@linux.dev header.b="TqInTpfx" X-Envelope-To: mptcp@lists.linux.dev DKIM-Signature: a=rsa-sha256; bh=CjE4pZlt4icFEu9bJ6HEckDv3cSAsyek8ZM9GiMyKls=; c=simple/simple; d=linux.dev; h=from:to:subject:date:message-id:mime-version:content-type; s=key1; t=1788331980; v=1; x=1788936780; b=TqInTpfx+dkE6luF7kaMDpmqjMRqzAb0A7KPuYDEcDPT3C/rspbKgaJlqLWuIhU3xTiJLJbi tik4RRLzf9rnzFhqtlpea0ShGNgBJh4i3+2W667dD0uzxjEU3Kjeq/bUyYCN+HB5CfVhs6WdHur /XlRHh5LklUXv6n9Gp8DOeww= X-Envelope-To: mptcp@lists.linux.dev Received: by smtp.migadu.com with ESMTPS id 8cd489d4159e8300; Wed, 02 Sep 2026 06:53:00 +0000 X-Mizu-Trace-ID: 8cd489d4159e8300 X-Migadu-Flow: FLOW_OUT From: Hangbin Liu Date: Wed, 02 Sep 2026 14:52:35 +0800 Subject: [PATCH mptcp-next 1/2] selftests: mptcp: convert iptables to nftables for mptcp_sockopt.sh Precedence: bulk X-Mailing-List: mptcp@lists.linux.dev List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260902-mptcp_nft-v1-1-559caa16f410@kylinos.cn> References: <20260902-mptcp_nft-v1-0-559caa16f410@kylinos.cn> In-Reply-To: <20260902-mptcp_nft-v1-0-559caa16f410@kylinos.cn> To: MPTCP Linux , Matthieu Baerts , Mat Martineau , Geliang Tang , "David S. Miller" , Eric Dumazet , Jakub Kicinski , Paolo Abeni , Simon Horman , Shuah Khan Cc: Hangbin Liu , netdev@vger.kernel.org, linux-kselftest@vger.kernel.org, linux-kernel@vger.kernel.org, bpf@vger.kernel.org, Hangbin Liu X-Mailer: b4 0.14.3 From: Hangbin Liu The per-AF iptables mark rules are replaced with an inet table (msock_table) with separate per-AF counter drop rules for IPv4 and IPv6 drop counting. Signed-off-by: Hangbin Liu --- tools/testing/selftests/net/mptcp/mptcp_lib.sh | 2 +- tools/testing/selftests/net/mptcp/mptcp_sockopt.sh | 56 ++++++++++--------= ---- 2 files changed, 26 insertions(+), 32 deletions(-) diff --git a/tools/testing/selftests/net/mptcp/mptcp_lib.sh b/tools/testing= /selftests/net/mptcp/mptcp_lib.sh index b9d14647f401..41febb1bbbc7 100644 --- a/tools/testing/selftests/net/mptcp/mptcp_lib.sh +++ b/tools/testing/selftests/net/mptcp/mptcp_lib.sh @@ -528,7 +528,7 @@ mptcp_lib_check_tools() { exit ${KSFT_SKIP} fi ;; - "iptables"* | "ip6tables"*) + "iptables"* | "ip6tables"* | "nft"*) if ! "${tool}" -V &> /dev/null; then mptcp_lib_pr_skip "Could not run all tests without ${tool}" exit ${KSFT_SKIP} diff --git a/tools/testing/selftests/net/mptcp/mptcp_sockopt.sh b/tools/tes= ting/selftests/net/mptcp/mptcp_sockopt.sh index e850a87429b6..4d0af2bf9484 100755 --- a/tools/testing/selftests/net/mptcp/mptcp_sockopt.sh +++ b/tools/testing/selftests/net/mptcp/mptcp_sockopt.sh @@ -15,8 +15,6 @@ cin=3D"" cout=3D"" timeout_poll=3D30 timeout_test=3D$((timeout_poll * 2 + 1)) -iptables=3D"iptables" -ip6tables=3D"ip6tables" =20 ns1=3D"" ns2=3D"" @@ -49,17 +47,23 @@ add_mark_rules() local ns=3D$1 local m=3D$2 =20 - local t - for t in ${iptables} ${ip6tables}; do - # just to debug: check we have multiple subflows connection requests - ip netns exec $ns $t -A OUTPUT -p tcp --syn -m mark --mark $m -j ACCEPT - - # RST packets might be handled by a internal dummy socket - ip netns exec $ns $t -A OUTPUT -p tcp --tcp-flags RST RST -m mark --mark= 0 -j ACCEPT - - ip netns exec $ns $t -A OUTPUT -p tcp -m mark --mark $m -j ACCEPT - ip netns exec $ns $t -A OUTPUT -p tcp -m mark --mark 0 -j DROP - done + ip netns exec "$ns" nft add table inet msock_table + ip netns exec "$ns" nft add chain inet msock_table output \ + '{ type filter hook output priority 0; policy accept; }' + + # just to debug: check we have multiple subflows connection requests + ip netns exec "$ns" nft add rule inet msock_table output \ + meta mark "$m" tcp flags syn accept + # RST packets might be handled by a internal dummy socket + ip netns exec "$ns" nft add rule inet msock_table output \ + meta mark 0 tcp flags rst accept + ip netns exec "$ns" nft add rule inet msock_table output \ + meta mark "$m" meta l4proto tcp accept + + ip netns exec "$ns" nft add rule inet msock_table output \ + meta nfproto ipv4 meta mark 0 meta l4proto tcp counter drop + ip netns exec "$ns" nft add rule inet msock_table output \ + meta nfproto ipv6 meta mark 0 meta l4proto tcp counter drop } =20 init() @@ -105,33 +109,23 @@ cleanup() =20 mptcp_lib_check_mptcp mptcp_lib_check_kallsyms -mptcp_lib_check_tools ip "${iptables}" "${ip6tables}" +mptcp_lib_check_tools ip nft =20 check_mark() { local ns=3D$1 local af=3D$2 =20 - local tables=3D${iptables} + drop=3D$(ip netns exec "$ns" nft list table inet msock_table | \ + grep "ipv$af.*packets.*drop" | awk '{print $(NF-3)}') =20 - if [ $af -eq 6 ];then - tables=3D${ip6tables} + if [ "$drop" -ne 0 ]; then + mptcp_lib_pr_fail "got $drop pkt drops in ns $ns IPv{$af} tables," \ + "not 0 - not all expected packets marked" + ret=3D${KSFT_FAIL} + return 1 fi =20 - local counters values - counters=3D$(ip netns exec $ns $tables -v -L OUTPUT | grep DROP) - values=3D${counters%DROP*} - - local v - for v in $values; do - if [ $v -ne 0 ]; then - mptcp_lib_pr_fail "got $tables $values in ns $ns," \ - "not 0 - not all expected packets marked" - ret=3D${KSFT_FAIL} - return 1 - fi - done - return 0 } =20 --=20 2.55.0 From nobody Sat Sep 5 05:52:09 2026 Received: from mta0.migadu.com (out-91.mta0.migadu.com [91.218.175.91]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 6728D3A7193 for ; Wed, 2 Sep 2026 06:53:12 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=91.218.175.91 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788332005; cv=none; b=qOY7FXTsR1UvqXc4q8ManQrWP09scFrUsaVaO/o5UC3r+AHPR6vK15ajSnL254hxWHaIMyT+Qee6fAKvxCaFopk6MEAV/1KLfYbe0iY1w6xpFW16M0UcgFnd8HuCS2+NljzMd04Gd10G08Ftzp3W87v/6laNAHklYRWJ/YrEnuo= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788332005; c=relaxed/simple; bh=tzhagK+5mhsLI1q5ngfc7YTxWnKP6EPrEW2qBYCoKj0=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=rusbQ7gOUEiwg0WQiM/z3CK2a87gcG0AGtnkrOo5JC8ea74OrqrjZvSuhEy1/z9BwvHuddK5COak04c5Zt9LyR64keWxdaffwUqRHtxvzc6DHfBjB8C2owqrEKV2XyChRum4kk/ylQba9Or6joUSG1Q/U9gYy40Ps1t+pCX8LrI= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.dev; spf=pass smtp.mailfrom=linux.dev; dkim=pass (1024-bit key) header.d=linux.dev header.i=@linux.dev header.b=LF1ozaMj; arc=none smtp.client-ip=91.218.175.91 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.dev Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=linux.dev Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linux.dev header.i=@linux.dev header.b="LF1ozaMj" X-Envelope-To: mptcp@lists.linux.dev DKIM-Signature: a=rsa-sha256; bh=tzhagK+5mhsLI1q5ngfc7YTxWnKP6EPrEW2qBYCoKj0=; c=simple/simple; d=linux.dev; h=from:to:subject:date:message-id:mime-version:content-type; s=key1; t=1788331988; v=1; x=1788936788; b=LF1ozaMjZ0nd8RsQFRrQp6JvNTVpy3A/kOufTvP/HmQ+/mZLh8y30ya1JgH0qI3QDTp4uIKP 1ltvXzpxQDfea2AD73KMKWt9AGik6HlOTOMF9rupEHmM0/ReLda9+c6wmRrGIfCXtEL3iF72ngm pQkjXkGwyvZJzUktBDbVIFE4= X-Envelope-To: mptcp@lists.linux.dev Received: by smtp.migadu.com with ESMTPS id c90996bd6c406713; Wed, 02 Sep 2026 06:53:07 +0000 X-Mizu-Trace-ID: c90996bd6c406713 X-Migadu-Flow: FLOW_OUT From: Hangbin Liu Date: Wed, 02 Sep 2026 14:52:36 +0800 Subject: [PATCH mptcp-next 2/2] selftests: mptcp: convert iptables to nftables for mptcp_join.sh Precedence: bulk X-Mailing-List: mptcp@lists.linux.dev List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260902-mptcp_nft-v1-2-559caa16f410@kylinos.cn> References: <20260902-mptcp_nft-v1-0-559caa16f410@kylinos.cn> In-Reply-To: <20260902-mptcp_nft-v1-0-559caa16f410@kylinos.cn> To: MPTCP Linux , Matthieu Baerts , Mat Martineau , Geliang Tang , "David S. Miller" , Eric Dumazet , Jakub Kicinski , Paolo Abeni , Simon Horman , Shuah Khan Cc: Hangbin Liu , netdev@vger.kernel.org, linux-kselftest@vger.kernel.org, linux-kernel@vger.kernel.org, bpf@vger.kernel.org, Hangbin Liu X-Mailer: b4 0.14.3 From: Hangbin Liu Replace the per-address-family iptables rules with a single inet table (mjoin_table) that handles both IPv4 and IPv6. The BPF bytecode for matching MPTCP add-addr and remove-addr suboptions is replaced with native nft matching via "tcp option mptcp subtype". Rule handles are captured via "nft -e --handle" so that rules can be selectively removed during tests. The config file adds CONFIG_NFT_NUMGEN (replaces iptables statistic nth), CONFIG_NFT_REJECT and CONFIG_NFT_REJECT_IPV4 for reject=E2=80=91related rul= es. The iptables/ip6tables check inside mptcp_lib.sh is kept in case any one still need them. Signed-off-by: Hangbin Liu --- tools/testing/selftests/net/mptcp/config | 3 + tools/testing/selftests/net/mptcp/mptcp_join.sh | 136 +++++++++-----------= ---- 2 files changed, 51 insertions(+), 88 deletions(-) diff --git a/tools/testing/selftests/net/mptcp/config b/tools/testing/selft= ests/net/mptcp/config index 59051ee2a986..0d0a744c4ca8 100644 --- a/tools/testing/selftests/net/mptcp/config +++ b/tools/testing/selftests/net/mptcp/config @@ -30,6 +30,9 @@ CONFIG_NET_SCH_NETEM=3Dm CONFIG_NF_TABLES=3Dm CONFIG_NF_TABLES_INET=3Dy CONFIG_NFT_COMPAT=3Dm +CONFIG_NFT_NUMGEN=3Dy +CONFIG_NFT_REJECT=3Dm +CONFIG_NFT_REJECT_IPV4=3Dm CONFIG_NFT_SOCKET=3Dm CONFIG_NFT_TPROXY=3Dm CONFIG_SYN_COOKIES=3Dy diff --git a/tools/testing/selftests/net/mptcp/mptcp_join.sh b/tools/testin= g/selftests/net/mptcp/mptcp_join.sh index 18ce7136a2b0..05cbaddb8261 100755 --- a/tools/testing/selftests/net/mptcp/mptcp_join.sh +++ b/tools/testing/selftests/net/mptcp/mptcp_join.sh @@ -26,8 +26,6 @@ capout=3D"" cappid=3D"" ns1=3D"" ns2=3D"" -iptables=3D"iptables" -ip6tables=3D"ip6tables" timeout_poll=3D30 timeout_test=3D$((timeout_poll * 2 + 1)) capture=3Dfalse @@ -50,6 +48,7 @@ declare -A failed_tests MPTCP_LIB_TEST_FORMAT=3D"%03u %s\n" TEST_NAME=3D"" nr_blank=3D6 +nft_handle=3D"" =20 # These var are used only in some tests, make sure they are not already set unset FAILING_LINKS @@ -99,42 +98,6 @@ unset add_addr_tx_nr unset add_addr_echo_tx_nr unset add_addr_drop_tx_nr =20 -# generated using "nfbpf_compile '(ip && (ip[54] & 0xf0) =3D=3D 0x30) || -# (ip6 && (ip6[74] & 0xf0) =3D=3D 0x30)'" -CBPF_MPTCP_SUBOPTION_ADD_ADDR=3D"14, - 48 0 0 0, - 84 0 0 240, - 21 0 3 64, - 48 0 0 54, - 84 0 0 240, - 21 6 7 48, - 48 0 0 0, - 84 0 0 240, - 21 0 4 96, - 48 0 0 74, - 84 0 0 240, - 21 0 1 48, - 6 0 0 65535, - 6 0 0 0" - -# IPv4: TCP hdr of 48B, a first suboption of 12B (DACK8), the RM_ADDR subo= ption -# generated using "nfbpf_compile '(ip[32] & 0xf0) =3D=3D 0xc0 && ip[53] = =3D=3D 0x0c && -# (ip[66] & 0xf0) =3D=3D 0x40'" -CBPF_MPTCP_SUBOPTION_RM_ADDR=3D"13, - 48 0 0 0, - 84 0 0 240, - 21 0 9 64, - 48 0 0 32, - 84 0 0 240, - 21 0 6 192, - 48 0 0 53, - 21 0 4 12, - 48 0 0 66, - 84 0 0 240, - 21 0 1 64, - 6 0 0 65535, - 6 0 0 0" - init_partial() { capout=3D$(mktemp) @@ -147,6 +110,14 @@ init_partial() if $checksum; then ip netns exec $netns sysctl -q net.mptcp.checksum_enabled=3D1 fi + + ip netns exec "$netns" nft add table inet mjoin_table + ip netns exec "$netns" nft add chain inet mjoin_table input \ + '{ type filter hook input priority filter; policy accept; }' + ip netns exec "$netns" nft add chain inet mjoin_table output \ + '{ type filter hook output priority filter; policy accept; }' + ip netns exec "$netns" nft add chain inet mjoin_table mangle \ + '{ type filter hook output priority mangle; policy accept; }' done =20 check_invert=3D0 @@ -196,7 +167,7 @@ init() { =20 mptcp_lib_check_mptcp mptcp_lib_check_kallsyms - mptcp_lib_check_tools ip tc ss "${iptables}" "${ip6tables}" + mptcp_lib_check_tools ip tc ss nft =20 sin=3D$(mktemp) sout=3D$(mktemp) @@ -381,23 +352,18 @@ reset_with_cookies() reset_with_add_addr_timeout() { local ip=3D"${2:-4}" - local tables =20 reset "${1}" || return 1 =20 - tables=3D"${iptables}" - if [ $ip -eq 6 ]; then - tables=3D"${ip6tables}" - fi - # set a maximum, to avoid too long timeout with exponential backoff ip netns exec $ns1 sysctl -q net.mptcp.add_addr_timeout=3D1 =20 - if ! ip netns exec $ns2 $tables -A OUTPUT -p tcp \ - -m tcp --tcp-option 30 \ - -m bpf --bytecode \ - "$CBPF_MPTCP_SUBOPTION_ADD_ADDR" \ - -j DROP; then + + nft_handle=3D$(ip netns exec "$ns2" nft -e --handle add rule \ + inet mjoin_table output meta nfproto ipv${ip} \ + tcp option mptcp subtype add-addr \ + drop | head -n1 | awk '{print $NF}') + if [ -z "$nft_handle" ]; then mark_as_skipped "unable to set the 'add addr' rule" return 1 fi @@ -450,22 +416,16 @@ setup_fail_rules() validate_checksum=3Dtrue local i=3D"$1" local ip=3D"${2:-4}" - local tables =20 - tables=3D"${iptables}" - if [ $ip -eq 6 ]; then - tables=3D"${ip6tables}" + nft_handle=3D$(ip netns exec "$ns2" nft -e --handle add rule \ + inet mjoin_table mangle oifname ns2eth$i \ + meta nfproto ipv${ip} meta l4proto tcp \ + meta length 150-9999 numgen inc mod 99999 =3D=3D 1 \ + meta mark set 42 | head -n1 | awk '{print $NF}') + if [ -z "$nft_handle" ]; then + return ${KSFT_SKIP} fi =20 - ip netns exec $ns2 $tables \ - -t mangle \ - -A OUTPUT \ - -o ns2eth$i \ - -p tcp \ - -m length --length 150:9999 \ - -m statistic --mode nth --packet 1 --every 99999 \ - -j MARK --set-mark 42 || return ${KSFT_SKIP} - tc -n $ns2 qdisc add dev ns2eth$i clsact || return ${KSFT_SKIP} tc -n $ns2 filter add dev ns2eth$i egress \ protocol ip prio 1000 \ @@ -515,11 +475,11 @@ reset_with_tcp_filter() local target=3D"${3}" local chain=3D"${4:-INPUT}" =20 - if ! ip netns exec "${ns}" ${iptables} \ - -A "${chain}" \ - -s "${src}" \ - -p tcp \ - -j "${target}"; then + nft_handle=3D$(ip netns exec "$ns" nft -e --handle add rule \ + inet mjoin_table "${chain,,}" \ + ip saddr "{ ${src} }" meta l4proto tcp "${target,,}" | \ + head -n1 | awk '{print $NF}') + if [ -z "$nft_handle" ]; then mark_as_skipped "unable to set the filter rules" return 1 fi @@ -4315,10 +4275,12 @@ userspace_tests() =20 # force quick loss ip netns exec $ns2 sysctl -q net.ipv4.tcp_syn_retries=3D1 - if ip netns exec "${ns1}" ${iptables} -A INPUT -s "10.0.1.2" \ - -p tcp --tcp-option 30 -j REJECT --reject-with tcp-reset && - ip netns exec "${ns2}" ${iptables} -A INPUT -d "10.0.1.2" \ - -p tcp --tcp-option 30 -j REJECT --reject-with tcp-reset; then + if ip netns exec "${ns1}" nft add rule inet mjoin_table \ + input ip saddr "10.0.1.2" meta l4proto tcp \ + tcp option mptcp exists reject with tcp reset && + ip netns exec "${ns2}" nft add rule inet mjoin_table \ + input ip daddr "10.0.1.2" meta l4proto tcp \ + tcp option mptcp exists reject with tcp reset; then wait_event ns2 MPTCP_LIB_EVENT_SUB_CLOSED 1 wait_event ns1 MPTCP_LIB_EVENT_SUB_CLOSED 1 chk_subflows_total 1 1 @@ -4393,7 +4355,7 @@ endpoint_tests() chk_subflow_nr "after new reject" 2 chk_mptcp_info subflows 1 subflows 1 =20 - ip netns exec "${ns2}" ${iptables} -D OUTPUT -s "10.0.3.2" -p tcp -j REJ= ECT + ip netns exec "${ns2}" nft delete rule inet mjoin_table output handle "$= nft_handle" pm_nl_del_endpoint $ns2 3 10.0.3.2 pm_nl_add_endpoint $ns2 10.0.3.2 id 3 flags subflow wait_mpj 3 @@ -4402,12 +4364,10 @@ endpoint_tests() =20 # To make sure RM_ADDR are sent over a different subflow, but # allow the rest to quickly and cleanly close the subflow - local ipt=3D1 - ip netns exec "${ns2}" ${iptables} -I OUTPUT -s "10.0.1.2" \ - -p tcp -m tcp --tcp-option 30 \ - -m bpf --bytecode \ - "$CBPF_MPTCP_SUBOPTION_RM_ADDR" \ - -j DROP || ipt=3D0 + nft_handle=3D$(ip netns exec "${ns2}" nft -e --handle insert rule \ + inet mjoin_table output ip saddr 10.0.1.2 meta l4proto tcp \ + tcp option mptcp subtype remove-addr \ + drop | head -n1 | awk '{print $NF}') local i for i in $(seq 3); do pm_nl_del_endpoint $ns2 1 10.0.1.2 @@ -4420,7 +4380,8 @@ endpoint_tests() chk_subflow_nr "after re-add id 0 ($i)" 3 chk_mptcp_info subflows 3 subflows 3 done - [ ${ipt} =3D 1 ] && ip netns exec "${ns2}" ${iptables} -D OUTPUT 1 + [ -n "${nft_handle}" ] && ip netns exec "${ns2}" nft delete rule \ + inet mjoin_table output handle "${nft_handle}" =20 mptcp_lib_kill_group_wait $tests_pid =20 @@ -4482,18 +4443,17 @@ endpoint_tests() =20 # To make sure RM_ADDR are sent over a different subflow, but # allow the rest to quickly and cleanly close the subflow - local ipt=3D1 - ip netns exec "${ns1}" ${iptables} -I OUTPUT -s "10.0.1.1" \ - -p tcp -m tcp --tcp-option 30 \ - -m bpf --bytecode \ - "$CBPF_MPTCP_SUBOPTION_RM_ADDR" \ - -j DROP || ipt=3D0 + nft_handle=3D$(ip netns exec "${ns1}" nft -e --handle insert rule \ + inet mjoin_table output ip saddr 10.0.1.1 meta l4proto tcp \ + tcp option mptcp subtype remove-addr \ + drop | head -n1 | awk '{print $NF}') pm_nl_del_endpoint $ns1 42 10.0.1.1 sleep 0.5 chk_subflow_nr "after delete ID 0" 2 chk_mptcp_info subflows 2 subflows 2 chk_mptcp_info add_addr_signal 2 add_addr_accepted 2 - [ ${ipt} =3D 1 ] && ip netns exec "${ns1}" ${iptables} -D OUTPUT 1 + [ -n "${nft_handle}" ] && ip netns exec "${ns1}" nft delete rule \ + inet mjoin_table output handle "${nft_handle}" =20 pm_nl_add_endpoint $ns1 10.0.1.1 id 42 flags signal wait_mpj 4 @@ -4555,7 +4515,7 @@ endpoint_tests() pm_nl_flush_endpoint $ns2 pm_nl_flush_endpoint $ns1 wait_rm_addr $ns2 0 - ip netns exec "${ns2}" ${iptables} -D OUTPUT -s "10.0.3.2" -p tcp -j REJ= ECT + ip netns exec "${ns2}" nft delete rule inet mjoin_table output handle "$= nft_handle" pm_nl_add_endpoint $ns2 10.0.3.2 id 3 flags subflow wait_mpj 1 pm_nl_add_endpoint $ns1 10.0.3.1 id 2 flags signal --=20 2.55.0