From: Matthieu Baerts <matttbe@kernel.org>
To: Hangbin Liu <hangbin.liu@linux.dev>
Cc: MPTCP Linux <mptcp@lists.linux.dev>
Subject: Re: [PATCH mptcp-next 2/2] selftests: mptcp: convert iptables to nftables for mptcp_join.sh
Date: Mon, 7 Sep 2026 09:55:39 +0200 [thread overview]
Message-ID: <225ce3d3-be08-4247-9d72-7986b8313114@kernel.org> (raw)
In-Reply-To: <ap5gzozOFWNTJPDc@fedora>
On 07/09/2026 08:59, Hangbin Liu wrote:
> On Mon, Sep 07, 2026 at 07:50:04AM +0200, Matthieu Baerts wrote:
>>>> If a global nft_handle var is used, that doesn't seem clear, and I think
>>>> it would be clearer/easier to:
>>>>
>>>> - either delete a specific rule (but I don't think that's supported)
>>>>
>>>> - get the handle from the test and use it to delete the rule
>>>>
>>>> - or flush the table.
>>>>
>>>> So up to you, but probably best to avoid using nft_handle as global var.
>>>
>>> Thanks, endpoint_tests is the only test that could delete iptables rules.
>>> I use the nft_handle mainly because the iptables also delete rules with
>>> specific match (iptables -D OUTPUT -s .. -p tcp -j REJECT) other than flush
>>> the table directly.
>>>
>>> endpoint_tests
>>> - reset_with_tcp_filter
>>> - iptables -D
>>> - iptables -I
>>> - iptables -D
>>> - reset_with_events
>>> - iptables -I
>>> - iptables -D
>>> - reset_with_tcp_filter
>>> - iptables -D
>>>
>>> While from the logic it should be safe to flush the tables. I can avoid the
>>> nft_handle in v4 (after v3 review).
>>
>> Just to be sure it is clear: nft_handle can be used, just better to
>> avoid using it globally I think. An alternative could be to pass a local
>> nft_handle to reset_with_tcp_filter and set it there, but in bash,
>> that's not very clear either.
>
> reset_with_tcp_filter is also used by subflows_error_tests(). It's not easy
> to just passing nft_handle to reset_with_tcp_filter for endpoint_tests and
> leave subflows_error_tests() not affect. If there is a new version,
> I'd prefer to just flush the table if you have no objections.
Fine by me. Deleting a specific rule doesn't seem to be as easy as with
IPTables. Please mention in the commit message that flushing is fine and
easier/clearer.
Cheers,
Matt
--
Sponsored by the NGI0 Core fund.
next prev parent reply other threads:[~2026-09-07 7:55 UTC|newest]
Thread overview: 21+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-02 6:52 [PATCH mptcp-next 0/2] selftests: mptcp: convert iptables to nftables Hangbin Liu
2026-09-02 6:52 ` [PATCH mptcp-next 1/2] selftests: mptcp: convert iptables to nftables for mptcp_sockopt.sh Hangbin Liu
2026-09-02 7:02 ` sashiko-bot
2026-09-02 7:47 ` Hangbin Liu
2026-09-02 9:17 ` Matthieu Baerts
2026-09-03 2:15 ` Hangbin Liu
2026-09-02 6:52 ` [PATCH mptcp-next 2/2] selftests: mptcp: convert iptables to nftables for mptcp_join.sh Hangbin Liu
2026-09-02 10:00 ` Matthieu Baerts
2026-09-03 2:02 ` Hangbin Liu
2026-09-03 6:35 ` Hangbin Liu
2026-09-03 6:54 ` Florian Westphal
2026-09-03 7:35 ` Hangbin Liu
2026-09-03 9:28 ` Matthieu Baerts
2026-09-04 8:01 ` Hangbin Liu
2026-09-04 16:40 ` Matthieu Baerts
2026-09-07 1:02 ` Hangbin Liu
2026-09-07 5:50 ` Matthieu Baerts
2026-09-07 6:59 ` Hangbin Liu
2026-09-07 7:55 ` Matthieu Baerts [this message]
2026-09-02 7:23 ` [PATCH mptcp-next 0/2] selftests: mptcp: convert iptables to nftables MPTCP CI
2026-09-02 8:14 ` MPTCP CI
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=225ce3d3-be08-4247-9d72-7986b8313114@kernel.org \
--to=matttbe@kernel.org \
--cc=hangbin.liu@linux.dev \
--cc=mptcp@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.