From: Joachim Wiberg <troglobit@gmail.com>
To: Roopa Prabhu <roopa@nvidia.com>,
Nikolay Aleksandrov <razor@blackwall.org>
Cc: netdev@vger.kernel.org, bridge@lists.linux-foundation.org,
"David S . Miller" <davem@davemloft.net>,
Jakub Kicinski <kuba@kernel.org>,
Joachim Wiberg <troglobit@gmail.com>,
Tobias Waldekranz <tobias@waldekranz.com>,
Vladimir Oltean <vladimir.oltean@nxp.com>
Subject: [PATCH RFC net-next 12/13] selftests: forwarding: verify strict filtering doesn't leak
Date: Mon, 11 Apr 2022 15:38:36 +0200 [thread overview]
Message-ID: <20220411133837.318876-13-troglobit@gmail.com> (raw)
In-Reply-To: <20220411133837.318876-1-troglobit@gmail.com>
Add a another veth pair to get a dedicated canary port. This to help us
verify that multicast is received by only a subset of the ports in the
MDB filter.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
---
.../selftests/net/forwarding/bridge_mdb.sh | 32 ++++++++++++++++++-
1 file changed, 31 insertions(+), 1 deletion(-)
diff --git a/tools/testing/selftests/net/forwarding/bridge_mdb.sh b/tools/testing/selftests/net/forwarding/bridge_mdb.sh
index 4e3bb950263f..137bc79fd677 100755
--- a/tools/testing/selftests/net/forwarding/bridge_mdb.sh
+++ b/tools/testing/selftests/net/forwarding/bridge_mdb.sh
@@ -17,7 +17,7 @@
#
ALL_TESTS="mdb_add_del_test mdb_compat_fwd_test mdb_mac_fwd_test mdb_ip4_fwd_test mdb_ip6_fwd_test"
-NUM_NETIFS=4
+NUM_NETIFS=6
SRC_PORT="1234"
DST_PORT="4321"
@@ -70,6 +70,16 @@ h2_destroy()
simple_if_fini $h2 192.0.2.2/24 2001:db8:1::2/64
}
+h3_create()
+{
+ simple_if_init $h3 192.0.2.3/24 2001:db8:1::3/64
+}
+
+h3_destroy()
+{
+ simple_if_fini $h3 192.0.2.3/24 2001:db8:1::3/64
+}
+
switch_create()
{
# Enable multicast filtering w/ querier, reduce query response
@@ -88,10 +98,12 @@ switch_create()
ip link set dev $swp1 master br0
ip link set dev $swp2 master br0
+ ip link set dev $swp3 master br0
ip link set dev br0 up
ip link set dev $swp1 up
ip link set dev $swp2 up
+ ip link set dev $swp3 up
# Initial delay, when bridge floods all mcast, is set to 200
# above (2 sec.) We wait 3 sec to handle the case when a single
@@ -102,6 +114,7 @@ switch_create()
switch_destroy()
{
+ ip link set dev $swp3 down
ip link set dev $swp2 down
ip link set dev $swp1 down
@@ -116,6 +129,9 @@ setup_prepare()
swp2=${NETIFS[p3]}
h2=${NETIFS[p4]}
+ swp3=${NETIFS[p5]}
+ h3=${NETIFS[p6]}
+
# Disable all IPv6 autoconfiguration during test, we want
# full control of when MLD queries start etc.
sysctl_set net.ipv6.conf.default.accept_ra 0
@@ -123,6 +139,7 @@ setup_prepare()
h1_create
h2_create
+ h3_create
switch_create
}
@@ -133,6 +150,7 @@ cleanup()
switch_destroy
+ h3_destroy
h2_destroy
h1_destroy
@@ -249,11 +267,15 @@ do_mdb_fwd()
fi
if [ "$port" = "$h2" ]; then
swp=$swp2
+ nop="$h3"
+ else
+ nop="$h2"
fi
# Disable flooding of unknown multicast, strict MDB forwarding
bridge link set dev "$swp1" mcast_flood off
bridge link set dev "$swp2" mcast_flood off
+ bridge link set dev "$swp3" mcast_flood off
bridge link set dev "br0" mcast_flood off self
# Static filter only to this port
@@ -261,6 +283,7 @@ do_mdb_fwd()
check_err $? "Failed adding $type multicast group $pass_grp to bridge port $swp"
tcpdump_start "$port"
+ tcpdump_start "$nop"
# Real data we're expecting
$MZ -q "$h1" "$pass_pkt"
@@ -268,6 +291,7 @@ do_mdb_fwd()
$MZ -q "$h1" "$fail_pkt"
sleep 1
+ tcpdump_stop "$nop"
tcpdump_stop "$port"
tcpdump_show "$port" |grep -q "$src$spt > $pass_grp$dpt"
@@ -276,6 +300,12 @@ do_mdb_fwd()
tcpdump_show "$port" |grep -q "$src$spt > $fail_grp$dpt"
check_err_fail 1 $? "Received $type multicast group $fail_grp from $h1 to port $port"
+ # Verify we don't get multicast to the canary port
+ tcpdump_show "$nop" |grep -q "$src$spt > $pass_grp$dpt"
+ check_err_fail 1 $? "Received $type multicast group $pass_grp from $h1 to port $nop"
+ tcpdump_show "$nop" |grep -q "$src$spt > $fail_grp$dpt"
+ check_err_fail 1 $? "Received $type multicast group $fail_grp from $h1 to port $nop"
+
bridge mdb del dev br0 port "$swp" grp "$pass_grp"
log_test "MDB forward $type multicast to bridge port $port"
--
2.25.1
next prev parent reply other threads:[~2022-04-11 13:39 UTC|newest]
Thread overview: 38+ messages / expand[flat|nested] mbox.gz Atom feed top
2022-04-11 13:38 [PATCH RFC net-next 00/13] net: bridge: forwarding of unknown IPv4/IPv6/MAC BUM traffic Joachim Wiberg
2022-04-11 13:38 ` [PATCH RFC net-next 01/13] net: bridge: add control of bum flooding to bridge itself Joachim Wiberg
2022-04-12 18:27 ` Nikolay Aleksandrov
2022-04-12 20:29 ` Nikolay Aleksandrov
2022-04-13 9:51 ` Joachim Wiberg
2022-04-13 9:58 ` Nikolay Aleksandrov
2022-04-13 10:09 ` Joachim Wiberg
2022-04-11 13:38 ` [PATCH RFC net-next 02/13] net: bridge: rename br_switchdev_set_port_flag() to .._dev_flag() Joachim Wiberg
2022-04-11 13:38 ` [PATCH RFC net-next 03/13] net: bridge: minor refactor of br_setlink() for readability Joachim Wiberg
2022-04-12 18:36 ` Nikolay Aleksandrov
2022-04-13 9:22 ` Joachim Wiberg
2022-04-11 13:38 ` [PATCH RFC net-next 04/13] net: bridge: netlink support for controlling BUM flooding to bridge Joachim Wiberg
2022-04-12 18:24 ` Nikolay Aleksandrov
2022-04-13 10:04 ` Joachim Wiberg
2022-04-11 13:38 ` [PATCH RFC net-next 05/13] selftests: forwarding: add TCPDUMP_EXTRA_FLAGS to lib.sh Joachim Wiberg
2022-04-11 17:20 ` Vladimir Oltean
2022-04-12 7:39 ` Joachim Wiberg
2022-04-11 13:38 ` [PATCH RFC net-next 06/13] selftests: forwarding: multiple instances in tcpdump helper Joachim Wiberg
2022-04-11 17:26 ` Vladimir Oltean
2022-04-11 13:38 ` [PATCH RFC net-next 07/13] selftests: forwarding: new test, verify bridge flood flags Joachim Wiberg
2022-04-11 20:21 ` Vladimir Oltean
2022-04-12 7:55 ` Joachim Wiberg
2022-04-12 13:40 ` Vladimir Oltean
2022-04-11 13:38 ` [PATCH RFC net-next 08/13] net: bridge: avoid classifying unknown multicast as mrouters_only Joachim Wiberg
2022-04-12 13:59 ` Nikolay Aleksandrov
2022-04-12 17:27 ` Joachim Wiberg
2022-04-12 17:37 ` Nikolay Aleksandrov
2022-04-13 8:51 ` Joachim Wiberg
2022-04-13 8:55 ` Nikolay Aleksandrov
2022-04-13 9:00 ` Nikolay Aleksandrov
2022-04-13 10:12 ` Joachim Wiberg
2022-04-11 13:38 ` [PATCH RFC net-next 09/13] selftests: forwarding: rename test groups for next bridge mdb tests Joachim Wiberg
2022-04-11 20:23 ` Vladimir Oltean
2022-04-12 7:57 ` Joachim Wiberg
2022-04-11 13:38 ` [PATCH RFC net-next 10/13] selftests: forwarding: verify flooding of unknown multicast Joachim Wiberg
2022-04-11 13:38 ` [PATCH RFC net-next 11/13] selftests: forwarding: verify strict mdb fwd of known multicast Joachim Wiberg
2022-04-11 13:38 ` Joachim Wiberg [this message]
2022-04-11 13:38 ` [PATCH RFC net-next 13/13] selftests: forwarding: verify flood of known mc on mcast_router port Joachim Wiberg
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20220411133837.318876-13-troglobit@gmail.com \
--to=troglobit@gmail.com \
--cc=bridge@lists.linux-foundation.org \
--cc=davem@davemloft.net \
--cc=kuba@kernel.org \
--cc=netdev@vger.kernel.org \
--cc=razor@blackwall.org \
--cc=roopa@nvidia.com \
--cc=tobias@waldekranz.com \
--cc=vladimir.oltean@nxp.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).