diff options
author | Florian Westphal <fw@strlen.de> | 2024-04-22 12:25:42 +0200 |
---|---|---|
committer | Jakub Kicinski <kuba@kernel.org> | 2024-04-24 17:15:04 -0700 |
commit | 8e2b318a65c30626d49d3bf1940037afb386e596 (patch) | |
tree | 0115c3bee91936b2bef7e40ef079979ee6d626dc /tools | |
parent | f03c528e323b640230b4dac023a52f39836ddb8d (diff) | |
download | linux-stable-8e2b318a65c30626d49d3bf1940037afb386e596.tar.gz linux-stable-8e2b318a65c30626d49d3bf1940037afb386e596.tar.bz2 linux-stable-8e2b318a65c30626d49d3bf1940037afb386e596.zip |
selftests: netfilter: nft_zones_many.sh: set ct sysctl after ruleset load
nf_conntrack_udp_timeout sysctl only exist once conntrack module is loaded,
if this test runs standalone on a modular kernel sysctl setting fails,
this can result in test failure as udp conntrack entries expire too fast.
Signed-off-by: Florian Westphal <fw@strlen.de>
Link: https://lore.kernel.org/r/20240422102546.2494-1-fw@strlen.de
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Diffstat (limited to 'tools')
-rwxr-xr-x | tools/testing/selftests/net/netfilter/nft_zones_many.sh | 4 |
1 files changed, 3 insertions, 1 deletions
diff --git a/tools/testing/selftests/net/netfilter/nft_zones_many.sh b/tools/testing/selftests/net/netfilter/nft_zones_many.sh index db53de348783..4ad75038f6ff 100755 --- a/tools/testing/selftests/net/netfilter/nft_zones_many.sh +++ b/tools/testing/selftests/net/netfilter/nft_zones_many.sh @@ -28,7 +28,6 @@ fi test_zones() { local max_zones=$1 -ip netns exec "$ns1" sysctl -q net.netfilter.nf_conntrack_udp_timeout=3600 ip netns exec "$ns1" nft -f /dev/stdin<<EOF flush ruleset table inet raw { @@ -46,6 +45,9 @@ if [ "$?" -ne 0 ];then echo "SKIP: Cannot add nftables rules" exit $ksft_skip fi + + ip netns exec "$ns1" sysctl -q net.netfilter.nf_conntrack_udp_timeout=3600 + ( echo "add element inet raw rndzone {" for i in $(seq 1 "$max_zones");do |