All of lore.kernel.org
 help / color / mirror / Atom feed
From: Phil Sutter <phil@nwl.cc>
To: Pablo Neira Ayuso <pablo@netfilter.org>
Cc: netfilter-devel@vger.kernel.org,
	Fernando Fernandez Mancera <fmancera@suse.de>
Subject: [nft PATCH] tests: shell: Test odd netdev hook updates
Date: Thu, 27 Aug 2026 22:42:55 +0200	[thread overview]
Message-ID: <20260827204255.274666-1-phil@nwl.cc> (raw)

These should cover what Fernando fixes in his kernel patch "netfilter:
nf_tables: fix device name and prefix match in hook lookup" as well as
some bonus cases I came up with.

Signed-off-by: Phil Sutter <phil@nwl.cc>
---
 .../chains/netdev_chain_update_wildcard_hook  | 45 +++++++++++++++++++
 .../testcases/flowtable/update_wildcard_hook  | 45 +++++++++++++++++++
 2 files changed, 90 insertions(+)
 create mode 100755 tests/shell/testcases/chains/netdev_chain_update_wildcard_hook
 create mode 100755 tests/shell/testcases/flowtable/update_wildcard_hook

diff --git a/tests/shell/testcases/chains/netdev_chain_update_wildcard_hook b/tests/shell/testcases/chains/netdev_chain_update_wildcard_hook
new file mode 100755
index 0000000000000..1381f4be2a5f1
--- /dev/null
+++ b/tests/shell/testcases/chains/netdev_chain_update_wildcard_hook
@@ -0,0 +1,45 @@
+#!/bin/bash
+
+# NFT_TEST_REQUIRES(NFT_TEST_HAVE_ifname_based_hooks)
+
+RC=0
+
+die() {
+	echo "FAIL: $@"
+	((RC++))
+	$NFT list ruleset
+}
+
+$NFT add table netdev t || die "add table failed"
+
+do_chain() { # (cmd, devspec, thp)
+	$NFT $1 chain netdev t c "{ $3 devices = { $2 }; }"
+}
+
+thp='type filter hook ingress priority 0;'
+
+do_chain add foo* "$thp" || die "initial add chain failed"
+do_chain create foo* "$thp" && die "duplicated create initial chain allowed"
+do_chain add foo* || die "duplicated hook add failed"
+
+do_chain add "bar*, bar*" && die "duplicate wildcard add allowed"
+do_chain add "bar, bar" && die "duplicate device add allowed"
+
+do_chain add foo && die "update with non-wildcard allowed"
+do_chain add fo* && die "update with shorter wildcard allowed"
+do_chain add fooo* && die "update with longer wildcard allowed"
+
+# add after testing delete in case deletion is allowed when it should not
+
+do_chain delete foo && die "delete non-wildcard hook allowed"
+do_chain add foo* || die "duplicated hook add failed"
+
+do_chain delete fo* && die "delete shorter wildcard allowed"
+do_chain add foo* || die "duplicated hook add failed"
+
+do_chain delete fooo* && die "delete longer wildcard allowed"
+do_chain add foo* || die "duplicated hook add failed"
+
+do_chain delete foo* || die "delete initial chain hook failed"
+
+exit $RC
diff --git a/tests/shell/testcases/flowtable/update_wildcard_hook b/tests/shell/testcases/flowtable/update_wildcard_hook
new file mode 100755
index 0000000000000..a67c8bffe0687
--- /dev/null
+++ b/tests/shell/testcases/flowtable/update_wildcard_hook
@@ -0,0 +1,45 @@
+#!/bin/bash
+
+# NFT_TEST_REQUIRES(NFT_TEST_HAVE_ifname_based_hooks)
+
+RC=0
+
+die() {
+	echo "FAIL: $@"
+	((RC++))
+	$NFT list ruleset
+}
+
+$NFT add table t || die "add table failed"
+
+do_ft() { # (cmd, devspec, thp)
+	$NFT $1 flowtable t ft "{ $3 devices = { $2 }; }"
+}
+
+thp='hook ingress priority 0;'
+
+do_ft add foo* "$thp" || die "initial add flowtable failed"
+do_ft create foo* "$thp" && die "duplicated create initial flowtable allowed"
+do_ft add foo* || die "duplicated hook add failed"
+
+do_ft add "bar*, bar*" && die "duplicate wildcard add allowed"
+do_ft add "bar, bar" && die "duplicate device add allowed"
+
+do_ft add foo && die "update with non-wildcard allowed"
+do_ft add fo* && die "update with shorter wildcard allowed"
+do_ft add fooo* && die "update with longer wildcard allowed"
+
+# add after testing delete in case deletion is allowed when it should not
+
+do_ft delete foo && die "delete non-wildcard hook allowed"
+do_ft add foo* || die "duplicated hook add failed"
+
+do_ft delete fo* && die "delete shorter wildcard allowed"
+do_ft add foo* || die "duplicated hook add failed"
+
+do_ft delete fooo* && die "delete longer wildcard allowed"
+do_ft add foo* || die "duplicated hook add failed"
+
+do_ft delete foo* || die "delete initial flowtable hook failed"
+
+exit $RC
-- 
2.54.0


             reply	other threads:[~2026-08-27 20:43 UTC|newest]

Thread overview: 5+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-08-27 20:42 Phil Sutter [this message]
2026-09-01  7:54 ` [nft PATCH] tests: shell: Test odd netdev hook updates Fernando Fernandez Mancera
2026-09-01  9:53   ` Phil Sutter
2026-09-01 14:56     ` Pablo Neira Ayuso
2026-09-03  8:10       ` Phil Sutter

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260827204255.274666-1-phil@nwl.cc \
    --to=phil@nwl.cc \
    --cc=fmancera@suse.de \
    --cc=netfilter-devel@vger.kernel.org \
    --cc=pablo@netfilter.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.