From nobody Sat Sep 5 05:52:46 2026 Received: from mta1.migadu.com (out-222.mta1.migadu.com [95.215.58.222]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id A55B32FE56F for ; Thu, 3 Sep 2026 01:12:48 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=95.215.58.222 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788397971; cv=none; b=n0+6WdVkMqxVcZr5E8ENxh6QXwMfK2pwYiV6sFxy+5EI6CvagT8rmp+1yGTkmyjxj1Zy99PGuP51HQ4b0kMk3dMRpXFOJf5B+smaN25z4TipXvVVSi11oTC7vGxkk7kwKa3CnUi7kV/QPXpUJzZyg5KQ403Y5ubeM7NOFqEHr5Y= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788397971; c=relaxed/simple; bh=39pxQ+8r3RU5eygXIOghhOBqOETu0gPB89a8qb+tmzY=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=f414t7NgxGCWahWhRMhB8zw+cmEShTNCxu8xGppX8TM7QiFcd1ccvcQmoaK0B6uXivIDfrwE4KaidNzDeQMFoEx26v6jBL5q7OnGNDH5yht9kRCMXVxvOrs4d5dwbY4zDZsNdvvilhlPihu48XIe+8Ipm0b8BAaNerxIYndggTo= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.dev; spf=pass smtp.mailfrom=linux.dev; dkim=pass (1024-bit key) header.d=linux.dev header.i=@linux.dev header.b=sFx35fMJ; arc=none smtp.client-ip=95.215.58.222 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.dev Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=linux.dev Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linux.dev header.i=@linux.dev header.b="sFx35fMJ" X-Envelope-To: linux-kernel@vger.kernel.org DKIM-Signature: a=rsa-sha256; bh=39pxQ+8r3RU5eygXIOghhOBqOETu0gPB89a8qb+tmzY=; c=simple/simple; d=linux.dev; h=from:to:subject:date:message-id:mime-version:content-type; s=key1; t=1788397966; v=1; x=1789002766; b=sFx35fMJ2NHFcl2Ytio+Tz22Xp8MYclJhiCIIf2879D9D7dLS5hoMFtuKqCtItP/iSZ/XIIi KkupRpiLeOtmWzF7IQK24uiEl0QiIsWCwywgnmquBbi2/kOM/mSD38neX+4QpS/RyGfNyKbIzX6 f6uzykRjVJQKkdNCcpTvzDms= X-Envelope-To: linux-kernel@vger.kernel.org Received: by smtp.migadu.com with ESMTPS id 4c6741134375e7c5; Thu, 03 Sep 2026 01:12:46 +0000 X-Mizu-Trace-ID: 4c6741134375e7c5 X-Migadu-Flow: FLOW_OUT From: Hangbin Liu Date: Thu, 03 Sep 2026 09:12:20 +0800 Subject: [PATCH mptcp-next v2 1/2] selftests: mptcp: convert iptables to nftables for mptcp_sockopt.sh Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260903-mptcp_nft-v2-1-66283e4b9c3b@kylinos.cn> References: <20260903-mptcp_nft-v2-0-66283e4b9c3b@kylinos.cn> In-Reply-To: <20260903-mptcp_nft-v2-0-66283e4b9c3b@kylinos.cn> To: MPTCP Linux , Matthieu Baerts , Mat Martineau , Geliang Tang , "David S. Miller" , Eric Dumazet , Jakub Kicinski , Paolo Abeni , Simon Horman , Shuah Khan Cc: Hangbin Liu , netdev@vger.kernel.org, linux-kselftest@vger.kernel.org, linux-kernel@vger.kernel.org, bpf@vger.kernel.org, Hangbin Liu X-Mailer: b4 0.14.3 From: Hangbin Liu During the conversion, we retain the same filter and chain names previously used by iptables/ip6tables. Counters are not added to accept rules because the test does not inspect them. After conversion, the generated output matches the original iptables/ip6tables behavior. Signed-off-by: Hangbin Liu --- tools/testing/selftests/net/mptcp/mptcp_lib.sh | 2 +- tools/testing/selftests/net/mptcp/mptcp_sockopt.sh | 51 ++++++++++++------= ---- 2 files changed, 29 insertions(+), 24 deletions(-) diff --git a/tools/testing/selftests/net/mptcp/mptcp_lib.sh b/tools/testing= /selftests/net/mptcp/mptcp_lib.sh index b9d14647f401..41febb1bbbc7 100644 --- a/tools/testing/selftests/net/mptcp/mptcp_lib.sh +++ b/tools/testing/selftests/net/mptcp/mptcp_lib.sh @@ -528,7 +528,7 @@ mptcp_lib_check_tools() { exit ${KSFT_SKIP} fi ;; - "iptables"* | "ip6tables"*) + "iptables"* | "ip6tables"* | "nft"*) if ! "${tool}" -V &> /dev/null; then mptcp_lib_pr_skip "Could not run all tests without ${tool}" exit ${KSFT_SKIP} diff --git a/tools/testing/selftests/net/mptcp/mptcp_sockopt.sh b/tools/tes= ting/selftests/net/mptcp/mptcp_sockopt.sh index e850a87429b6..a2c20483986d 100755 --- a/tools/testing/selftests/net/mptcp/mptcp_sockopt.sh +++ b/tools/testing/selftests/net/mptcp/mptcp_sockopt.sh @@ -15,8 +15,6 @@ cin=3D"" cout=3D"" timeout_poll=3D30 timeout_test=3D$((timeout_poll * 2 + 1)) -iptables=3D"iptables" -ip6tables=3D"ip6tables" =20 ns1=3D"" ns2=3D"" @@ -50,15 +48,25 @@ add_mark_rules() local m=3D$2 =20 local t - for t in ${iptables} ${ip6tables}; do + for t in ip ip6; do + ip netns exec "$ns" nft add table "$t" filter + ip netns exec "$ns" nft add chain "$t" filter OUTPUT \ + '{ type filter hook output priority 0; policy accept; }' + # just to debug: check we have multiple subflows connection requests - ip netns exec $ns $t -A OUTPUT -p tcp --syn -m mark --mark $m -j ACCEPT + ip netns exec "$ns" nft add rule "$t" filter OUTPUT \ + tcp flags \& \(fin \| syn \| rst \| ack\) =3D=3D syn \ + meta mark "$m" accept =20 # RST packets might be handled by a internal dummy socket - ip netns exec $ns $t -A OUTPUT -p tcp --tcp-flags RST RST -m mark --mark= 0 -j ACCEPT + ip netns exec "$ns" nft add rule "$t" filter OUTPUT \ + tcp flags \& rst =3D=3D rst meta mark 0x0 accept + + ip netns exec "$ns" nft add rule "$t" filter OUTPUT \ + meta l4proto tcp meta mark "$m" accept + ip netns exec "$ns" nft add rule "$t" filter OUTPUT \ + meta l4proto tcp meta mark 0 counter drop =20 - ip netns exec $ns $t -A OUTPUT -p tcp -m mark --mark $m -j ACCEPT - ip netns exec $ns $t -A OUTPUT -p tcp -m mark --mark 0 -j DROP done } =20 @@ -105,32 +113,29 @@ cleanup() =20 mptcp_lib_check_mptcp mptcp_lib_check_kallsyms -mptcp_lib_check_tools ip "${iptables}" "${ip6tables}" +mptcp_lib_check_tools ip nft =20 check_mark() { local ns=3D$1 local af=3D$2 =20 - local tables=3D${iptables} + local tables=3D"ip" =20 if [ $af -eq 6 ];then - tables=3D${ip6tables} + tables=3D"ip6" fi =20 - local counters values - counters=3D$(ip netns exec $ns $tables -v -L OUTPUT | grep DROP) - values=3D${counters%DROP*} - - local v - for v in $values; do - if [ $v -ne 0 ]; then - mptcp_lib_pr_fail "got $tables $values in ns $ns," \ - "not 0 - not all expected packets marked" - ret=3D${KSFT_FAIL} - return 1 - fi - done + local values + values=3D$(ip netns exec "$ns" nft list table "$tables" filter | \ + grep -o "packets.*drop" | awk '{print $2}') + + if [[ ! "$values" =3D~ ^[0-9]+$ ]] || [ "$values" -ne 0 ]; then + mptcp_lib_pr_fail "got $tables $values in ns $ns," \ + "not 0 - not all expected packets marked" + ret=3D${KSFT_FAIL} + return 1 + fi =20 return 0 } --=20 2.55.0 From nobody Sat Sep 5 05:52:46 2026 Received: from mta1.migadu.com (out-232.mta1.migadu.com [95.215.58.232]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 845152F7EE3 for ; Thu, 3 Sep 2026 01:12:54 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=95.215.58.232 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788397977; cv=none; b=hqNRIFz4lcOX/Qzgm4JHcHr57zjmd5PRP0V/9Ow1bGaRASED5V8EMggoqgNQ7PlfZIU2WCaUxzOG7N2a6ghBnr3m0kMk5l2kXteDnbAUbK1BFYn8EC5Oebu9/LSZadBAfSRg/a04kJCG1TsA50mEqAO9TR+CLWLQ9L4RdXe8YMg= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788397977; c=relaxed/simple; bh=SoCjmJDRTGL4GPTeItrahykbmnY8odwSPEzVpIL1zAI=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=Of/fjUa3MysoLTMlHOWFclYe3HEmdzrUSPe3TQSpQP2d85DA4dD3FyUyZOBNUvBQaiSX+ceoI53I8iofmUSZZuH4GFbodK4gAN/FdIxDEHJnXGWh4f7NSbSM3mTAimXFFmuTcnKnk4fFGygdd/aI+JfinuVvGTsmG5Nu/KdBpWI= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.dev; spf=pass smtp.mailfrom=linux.dev; dkim=pass (1024-bit key) header.d=linux.dev header.i=@linux.dev header.b=nlnRHlPM; arc=none smtp.client-ip=95.215.58.232 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.dev Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=linux.dev Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linux.dev header.i=@linux.dev header.b="nlnRHlPM" X-Envelope-To: mptcp@lists.linux.dev DKIM-Signature: a=rsa-sha256; bh=SoCjmJDRTGL4GPTeItrahykbmnY8odwSPEzVpIL1zAI=; c=simple/simple; d=linux.dev; h=from:to:subject:date:message-id:mime-version:content-type; s=key1; t=1788397972; v=1; x=1789002772; b=nlnRHlPM2g/PaiahFZx5JmUWN8jKL0YpCA8rSuQ45x4hBCL0k6Yv9cFx62izhD8iO/gGEugt e6pMd1QyTMCF0pM8uajzmsnyuaqnEwSz9lvwA9WDyJRR0U01n7U2umDAJHuo5VXibCdlYfPG0Bf uuqOWvSNrGqd1pnlRK55wsns= X-Envelope-To: mptcp@lists.linux.dev Received: by smtp.migadu.com with ESMTPS id 468a22590f8604bb; Thu, 03 Sep 2026 01:12:52 +0000 X-Mizu-Trace-ID: 468a22590f8604bb X-Migadu-Flow: FLOW_OUT From: Hangbin Liu Date: Thu, 03 Sep 2026 09:12:21 +0800 Subject: [PATCH mptcp-next v2 2/2] selftests: mptcp: convert iptables to nftables for mptcp_join.sh Precedence: bulk X-Mailing-List: mptcp@lists.linux.dev List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260903-mptcp_nft-v2-2-66283e4b9c3b@kylinos.cn> References: <20260903-mptcp_nft-v2-0-66283e4b9c3b@kylinos.cn> In-Reply-To: <20260903-mptcp_nft-v2-0-66283e4b9c3b@kylinos.cn> To: MPTCP Linux , Matthieu Baerts , Mat Martineau , Geliang Tang , "David S. Miller" , Eric Dumazet , Jakub Kicinski , Paolo Abeni , Simon Horman , Shuah Khan Cc: Hangbin Liu , netdev@vger.kernel.org, linux-kselftest@vger.kernel.org, linux-kernel@vger.kernel.org, bpf@vger.kernel.org, Hangbin Liu X-Mailer: b4 0.14.3 From: Hangbin Liu During conversion, we retain the same table and chain names used by the original iptables/ip6tables setup, so rule output is identical to the former iptables/ip6tables output. The BPF bytecode matching MPTCP add=E2=80=91addr and remove=E2=80=91addr su= boptions is replaced with native nft matching using "tcp option mptcp subtype". Unlike iptables, nftables cannot match rules based on their full specification. Rule handles are captured via "nft -e --handle" so rules can be selectively removed during tests. The config file adds CONFIG_NFT_NUMGEN (replaces iptables statistic nth), CONFIG_NFT_REJECT and CONFIG_NFT_REJECT_IPV4 for reject=E2=80=91related rul= es. The iptables/ip6tables check within mptcp_lib.sh is preserved in case some users still require it. Signed-off-by: Hangbin Liu --- tools/testing/selftests/net/mptcp/config | 3 + tools/testing/selftests/net/mptcp/mptcp_join.sh | 142 +++++++++-----------= ---- 2 files changed, 55 insertions(+), 90 deletions(-) diff --git a/tools/testing/selftests/net/mptcp/config b/tools/testing/selft= ests/net/mptcp/config index 59051ee2a986..0d0a744c4ca8 100644 --- a/tools/testing/selftests/net/mptcp/config +++ b/tools/testing/selftests/net/mptcp/config @@ -30,6 +30,9 @@ CONFIG_NET_SCH_NETEM=3Dm CONFIG_NF_TABLES=3Dm CONFIG_NF_TABLES_INET=3Dy CONFIG_NFT_COMPAT=3Dm +CONFIG_NFT_NUMGEN=3Dy +CONFIG_NFT_REJECT=3Dm +CONFIG_NFT_REJECT_IPV4=3Dm CONFIG_NFT_SOCKET=3Dm CONFIG_NFT_TPROXY=3Dm CONFIG_SYN_COOKIES=3Dy diff --git a/tools/testing/selftests/net/mptcp/mptcp_join.sh b/tools/testin= g/selftests/net/mptcp/mptcp_join.sh index 18ce7136a2b0..7c56680cc422 100755 --- a/tools/testing/selftests/net/mptcp/mptcp_join.sh +++ b/tools/testing/selftests/net/mptcp/mptcp_join.sh @@ -26,8 +26,6 @@ capout=3D"" cappid=3D"" ns1=3D"" ns2=3D"" -iptables=3D"iptables" -ip6tables=3D"ip6tables" timeout_poll=3D30 timeout_test=3D$((timeout_poll * 2 + 1)) capture=3Dfalse @@ -50,6 +48,7 @@ declare -A failed_tests MPTCP_LIB_TEST_FORMAT=3D"%03u %s\n" TEST_NAME=3D"" nr_blank=3D6 +nft_handle=3D"" =20 # These var are used only in some tests, make sure they are not already set unset FAILING_LINKS @@ -99,42 +98,6 @@ unset add_addr_tx_nr unset add_addr_echo_tx_nr unset add_addr_drop_tx_nr =20 -# generated using "nfbpf_compile '(ip && (ip[54] & 0xf0) =3D=3D 0x30) || -# (ip6 && (ip6[74] & 0xf0) =3D=3D 0x30)'" -CBPF_MPTCP_SUBOPTION_ADD_ADDR=3D"14, - 48 0 0 0, - 84 0 0 240, - 21 0 3 64, - 48 0 0 54, - 84 0 0 240, - 21 6 7 48, - 48 0 0 0, - 84 0 0 240, - 21 0 4 96, - 48 0 0 74, - 84 0 0 240, - 21 0 1 48, - 6 0 0 65535, - 6 0 0 0" - -# IPv4: TCP hdr of 48B, a first suboption of 12B (DACK8), the RM_ADDR subo= ption -# generated using "nfbpf_compile '(ip[32] & 0xf0) =3D=3D 0xc0 && ip[53] = =3D=3D 0x0c && -# (ip[66] & 0xf0) =3D=3D 0x40'" -CBPF_MPTCP_SUBOPTION_RM_ADDR=3D"13, - 48 0 0 0, - 84 0 0 240, - 21 0 9 64, - 48 0 0 32, - 84 0 0 240, - 21 0 6 192, - 48 0 0 53, - 21 0 4 12, - 48 0 0 66, - 84 0 0 240, - 21 0 1 64, - 6 0 0 65535, - 6 0 0 0" - init_partial() { capout=3D$(mktemp) @@ -147,6 +110,18 @@ init_partial() if $checksum; then ip netns exec $netns sysctl -q net.mptcp.checksum_enabled=3D1 fi + + for t in ip ip6; do + ip netns exec "$netns" nft add table "$t" filter + ip netns exec "$netns" nft add chain "$t" filter INPUT \ + '{ type filter hook input priority filter; policy accept; }' + ip netns exec "$netns" nft add chain "$t" filter OUTPUT \ + '{ type filter hook output priority filter; policy accept; }' + + ip netns exec "$netns" nft add table "$t" mangle + ip netns exec "$netns" nft add chain "$t" mangle OUTPUT \ + '{ type route hook output priority mangle; policy accept; }' + done done =20 check_invert=3D0 @@ -196,7 +171,7 @@ init() { =20 mptcp_lib_check_mptcp mptcp_lib_check_kallsyms - mptcp_lib_check_tools ip tc ss "${iptables}" "${ip6tables}" + mptcp_lib_check_tools ip tc ss nft =20 sin=3D$(mktemp) sout=3D$(mktemp) @@ -380,24 +355,18 @@ reset_with_cookies() # $1: test name reset_with_add_addr_timeout() { - local ip=3D"${2:-4}" - local tables + local ip=3D"${2:-}" =20 reset "${1}" || return 1 =20 - tables=3D"${iptables}" - if [ $ip -eq 6 ]; then - tables=3D"${ip6tables}" - fi - # set a maximum, to avoid too long timeout with exponential backoff ip netns exec $ns1 sysctl -q net.mptcp.add_addr_timeout=3D1 =20 - if ! ip netns exec $ns2 $tables -A OUTPUT -p tcp \ - -m tcp --tcp-option 30 \ - -m bpf --bytecode \ - "$CBPF_MPTCP_SUBOPTION_ADD_ADDR" \ - -j DROP; then + nft_handle=3D$(ip netns exec "$ns2" nft -e --handle add rule \ + ip"$ip" filter OUTPUT meta l4proto tcp \ + tcp option mptcp subtype add-addr \ + drop | head -n1 | awk '{print $NF}') + if [ -z "$nft_handle" ]; then mark_as_skipped "unable to set the 'add addr' rule" return 1 fi @@ -449,23 +418,17 @@ setup_fail_rules() check_invert=3D1 validate_checksum=3Dtrue local i=3D"$1" - local ip=3D"${2:-4}" - local tables + local ip=3D"${2:-}" =20 - tables=3D"${iptables}" - if [ $ip -eq 6 ]; then - tables=3D"${ip6tables}" + nft_handle=3D$(ip netns exec "$ns2" nft -e --handle add rule \ + ip"$ip" mangle OUTPUT oifname ns2eth$i \ + meta l4proto tcp \ + meta length 150-9999 numgen inc mod 99999 1 \ + meta mark set 42 | head -n1 | awk '{print $NF}') + if [ -z "$nft_handle" ]; then + return ${KSFT_SKIP} fi =20 - ip netns exec $ns2 $tables \ - -t mangle \ - -A OUTPUT \ - -o ns2eth$i \ - -p tcp \ - -m length --length 150:9999 \ - -m statistic --mode nth --packet 1 --every 99999 \ - -j MARK --set-mark 42 || return ${KSFT_SKIP} - tc -n $ns2 qdisc add dev ns2eth$i clsact || return ${KSFT_SKIP} tc -n $ns2 filter add dev ns2eth$i egress \ protocol ip prio 1000 \ @@ -515,11 +478,10 @@ reset_with_tcp_filter() local target=3D"${3}" local chain=3D"${4:-INPUT}" =20 - if ! ip netns exec "${ns}" ${iptables} \ - -A "${chain}" \ - -s "${src}" \ - -p tcp \ - -j "${target}"; then + nft_handle=3D$(ip netns exec "$ns" nft -e --handle add rule \ + ip filter "${chain}" ip saddr "{ ${src} }" \ + meta l4proto tcp "${target,,}" | head -n1 | awk '{print $NF}') + if [ -z "$nft_handle" ]; then mark_as_skipped "unable to set the filter rules" return 1 fi @@ -4315,10 +4277,12 @@ userspace_tests() =20 # force quick loss ip netns exec $ns2 sysctl -q net.ipv4.tcp_syn_retries=3D1 - if ip netns exec "${ns1}" ${iptables} -A INPUT -s "10.0.1.2" \ - -p tcp --tcp-option 30 -j REJECT --reject-with tcp-reset && - ip netns exec "${ns2}" ${iptables} -A INPUT -d "10.0.1.2" \ - -p tcp --tcp-option 30 -j REJECT --reject-with tcp-reset; then + if ip netns exec "${ns1}" nft add rule ip filter INPUT \ + ip saddr "10.0.1.2" meta l4proto tcp \ + tcp option mptcp exists reject with tcp reset && + ip netns exec "${ns2}" nft add rule ip filter INPUT \ + ip daddr "10.0.1.2" meta l4proto tcp \ + tcp option mptcp exists reject with tcp reset; then wait_event ns2 MPTCP_LIB_EVENT_SUB_CLOSED 1 wait_event ns1 MPTCP_LIB_EVENT_SUB_CLOSED 1 chk_subflows_total 1 1 @@ -4393,7 +4357,7 @@ endpoint_tests() chk_subflow_nr "after new reject" 2 chk_mptcp_info subflows 1 subflows 1 =20 - ip netns exec "${ns2}" ${iptables} -D OUTPUT -s "10.0.3.2" -p tcp -j REJ= ECT + ip netns exec "${ns2}" nft delete rule ip filter OUTPUT handle "$nft_han= dle" pm_nl_del_endpoint $ns2 3 10.0.3.2 pm_nl_add_endpoint $ns2 10.0.3.2 id 3 flags subflow wait_mpj 3 @@ -4402,12 +4366,10 @@ endpoint_tests() =20 # To make sure RM_ADDR are sent over a different subflow, but # allow the rest to quickly and cleanly close the subflow - local ipt=3D1 - ip netns exec "${ns2}" ${iptables} -I OUTPUT -s "10.0.1.2" \ - -p tcp -m tcp --tcp-option 30 \ - -m bpf --bytecode \ - "$CBPF_MPTCP_SUBOPTION_RM_ADDR" \ - -j DROP || ipt=3D0 + nft_handle=3D$(ip netns exec "${ns2}" nft -e --handle insert rule \ + ip filter OUTPUT ip saddr 10.0.1.2 meta l4proto tcp \ + tcp option mptcp subtype remove-addr \ + drop | head -n1 | awk '{print $NF}') local i for i in $(seq 3); do pm_nl_del_endpoint $ns2 1 10.0.1.2 @@ -4420,7 +4382,8 @@ endpoint_tests() chk_subflow_nr "after re-add id 0 ($i)" 3 chk_mptcp_info subflows 3 subflows 3 done - [ ${ipt} =3D 1 ] && ip netns exec "${ns2}" ${iptables} -D OUTPUT 1 + [ -n "${nft_handle}" ] && ip netns exec "${ns2}" nft delete rule \ + ip filter OUTPUT handle "${nft_handle}" =20 mptcp_lib_kill_group_wait $tests_pid =20 @@ -4482,18 +4445,17 @@ endpoint_tests() =20 # To make sure RM_ADDR are sent over a different subflow, but # allow the rest to quickly and cleanly close the subflow - local ipt=3D1 - ip netns exec "${ns1}" ${iptables} -I OUTPUT -s "10.0.1.1" \ - -p tcp -m tcp --tcp-option 30 \ - -m bpf --bytecode \ - "$CBPF_MPTCP_SUBOPTION_RM_ADDR" \ - -j DROP || ipt=3D0 + nft_handle=3D$(ip netns exec "${ns1}" nft -e --handle insert rule \ + ip filter OUTPUT ip saddr 10.0.1.1 meta l4proto tcp \ + tcp option mptcp subtype remove-addr \ + drop | head -n1 | awk '{print $NF}') pm_nl_del_endpoint $ns1 42 10.0.1.1 sleep 0.5 chk_subflow_nr "after delete ID 0" 2 chk_mptcp_info subflows 2 subflows 2 chk_mptcp_info add_addr_signal 2 add_addr_accepted 2 - [ ${ipt} =3D 1 ] && ip netns exec "${ns1}" ${iptables} -D OUTPUT 1 + [ -n "${nft_handle}" ] && ip netns exec "${ns1}" nft delete rule \ + ip filter OUTPUT handle "${nft_handle}" =20 pm_nl_add_endpoint $ns1 10.0.1.1 id 42 flags signal wait_mpj 4 @@ -4555,7 +4517,7 @@ endpoint_tests() pm_nl_flush_endpoint $ns2 pm_nl_flush_endpoint $ns1 wait_rm_addr $ns2 0 - ip netns exec "${ns2}" ${iptables} -D OUTPUT -s "10.0.3.2" -p tcp -j REJ= ECT + ip netns exec "${ns2}" nft delete rule ip filter OUTPUT handle "$nft_han= dle" pm_nl_add_endpoint $ns2 10.0.3.2 id 3 flags subflow wait_mpj 1 pm_nl_add_endpoint $ns1 10.0.3.1 id 2 flags signal --=20 2.55.0