Linux Netfilter development
 help / color / mirror / Atom feed
From: Florian Westphal <fw@strlen.de>
To: <netfilter-devel@vger.kernel.org>
Cc: kadlec@netfilter.org, Florian Westphal <fw@strlen.de>
Subject: [PATCH ipset 5/7] tests: setlist_ns.sh: use local ipset binary and don't rely on userns
Date: Thu,  9 Jul 2026 22:03:56 +0200	[thread overview]
Message-ID: <20260709200358.15504-6-fw@strlen.de> (raw)
In-Reply-To: <20260709200358.15504-1-fw@strlen.de>

The script runs command in network+user namespace with remapped uid0.

In case this fails (e.g. because user namespaces are disabled), we
should re-try with plain "-n" before giving up and returning an error.

Also, in case 'ipset' isn't in $PATH, this fails.
Let runtest.sh export the ipset binary to use and refer to that.

While at it, parallelize the test and also run it 124 times, not just
4 times - missing $() resulted in 'for x in a b c d ..'.

Signed-off-by: Florian Westphal <fw@strlen.de>

x
---
 tests/runtest.sh    |  1 +
 tests/setlist_ns.sh | 29 +++++++++++++++++++++++++----
 2 files changed, 26 insertions(+), 4 deletions(-)

diff --git a/tests/runtest.sh b/tests/runtest.sh
index 766335fda768..ba4683f59e5d 100755
--- a/tests/runtest.sh
+++ b/tests/runtest.sh
@@ -22,6 +22,7 @@ tests="$tests comment setlist restore"
 if [ "$IPSET_UNSHARED" = "" ]; then
 	# Re-execute in new network namespace
 	export IPSET_UNSHARED="yes"
+	export IPSET_BIN="$ipset"
 	sysctl net.netfilter.nf_log_all_netns=1
 	exec unshare -n -- "$0" "$@"
 fi
diff --git a/tests/setlist_ns.sh b/tests/setlist_ns.sh
index 9e47d65e95dc..67232acdd906 100755
--- a/tests/setlist_ns.sh
+++ b/tests/setlist_ns.sh
@@ -2,21 +2,42 @@
 
 set -e
 
+[ -z "$IPSET_BIN" ] && IPSET_BIN=ipset
+
 CMD=$(cat <<EOF
 for x in \$(seq 0 127); do
     echo "create h\$x hash:ip"
     echo "create l\$x list:set timeout 10 comment"
-done | ipset restore
+done | $IPSET_BIN restore
 for x in \$(seq 0 127); do
     for y in \$(seq 0 127); do
         echo "add l\$x h\$y timeout 1000 comment \"l\$x h\$y\""
     done
-done | ipset restore
+done | $IPSET_BIN restore
 # Wait for GC
 sleep 15
 EOF
 )
 
-for x in seq 0 123; do
-    unshare -Urn bash -c "$CMD"
+# First try with user namespaces and remapped-root.
+options="-Urn"
+if ! unshare "$options" bash -c "$CMD"; then
+	# Doesn't work - try with plain network namespaces.
+	if unshare -n bash -c "$CMD"; then
+		# "-Ur" unsupported
+		options="-n"
+	else
+		# Either network namespaces are not
+		# supported at all or $CMD is failing.
+		exit 1
+	fi
+fi
+
+parallel=16
+for x in $(seq 1 123); do
+    unshare "$options" bash -c "$CMD" &
+
+    [ $((x % $parallel)) -eq 0 ] && wait
 done
+
+wait
-- 
2.54.0


  parent reply	other threads:[~2026-07-09 20:04 UTC|newest]

Thread overview: 11+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-07-09 20:03 [PATCH ipset 0/7] test updates Florian Westphal
2026-07-09 20:03 ` [PATCH ipset 1/7] tests: make runtest.sh work with readonly-cwd Florian Westphal
2026-07-09 20:03 ` [PATCH ipset 2/7] tests: runtest.sh: run inside namespace Florian Westphal
2026-07-09 20:03 ` [PATCH ipset 3/7] tests: diff.sh: preserve file name Florian Westphal
2026-07-09 20:03 ` [PATCH ipset 4/7] tests: check_klog.sh: unclutter stderr Florian Westphal
2026-07-09 20:03 ` Florian Westphal [this message]
2026-07-09 20:03 ` [PATCH ipset 6/7] tests: make setlist_resize.sh more verbose on error Florian Westphal
2026-07-09 20:03 ` [PATCH ipset 7/7] tests: runtest.sh: add sendip emulation via scapy Florian Westphal
2026-07-13 13:35 ` [PATCH ipset 0/7] test updates Jozsef Kadlecsik
2026-07-13 14:11   ` Pablo Neira Ayuso
2026-07-13 14:25     ` Jozsef Kadlecsik

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260709200358.15504-6-fw@strlen.de \
    --to=fw@strlen.de \
    --cc=kadlec@netfilter.org \
    --cc=netfilter-devel@vger.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox