mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: Hangbin Liu <hangbin.liu@linux.dev>
To: Matthieu Baerts <matttbe@kernel.org>
Cc: netdev-bot+sashiko@kernel.org,
	Hangbin Liu <liuhangbin@kylinos.cn>,
	martineau@kernel.org, geliang@kernel.org, davem@davemloft.net,
	edumazet@google.com, kuba@kernel.org, pabeni@redhat.com,
	horms@kernel.org, netdev@vger.kernel.org, mptcp@lists.linux.dev,
	linux-kernel@vger.kernel.org, quanyeyang@proton.me
Subject: Re: [PATCH net-next 5/5] selftests: mptcp: convert iptables to nftables for mptcp_join.sh
Date: Wed, 30 Sep 2026 10:48:18 +0800	[thread overview]
Message-ID: <arx4cn3ZPDtuUNBM@fedora> (raw)
In-Reply-To: <4278a970-2957-4387-8f20-604ae4ae97e9@kernel.org>

On Mon, Sep 28, 2026 at 11:17:59PM +0200, Matthieu Baerts wrote:
> On 28/09/2026 13:24, Matthieu Baerts wrote:
> >>> diff --git a/tools/testing/selftests/net/mptcp/mptcp_join.sh b/tools/testing/selftests/net/mptcp/mptcp_join.sh
> >>> index 18ce7136a2b0e..b16e24418e737 100755
> >>> --- a/tools/testing/selftests/net/mptcp/mptcp_join.sh
> >>> +++ b/tools/testing/selftests/net/mptcp/mptcp_join.sh
> >>
> >> [ ... ]
> >>
> >>> @@ -4402,12 +4372,10 @@ endpoint_tests()
> >>>  
> >>>  		# To make sure RM_ADDR are sent over a different subflow, but
> >>>  		# allow the rest to quickly and cleanly close the subflow
> >>> -		local ipt=1
> >>> -		ip netns exec "${ns2}" ${iptables} -I OUTPUT -s "10.0.1.2" \
> >>> -			-p tcp -m tcp --tcp-option 30 \
> >>> -			-m bpf --bytecode \
> >>> -			"$CBPF_MPTCP_SUBOPTION_RM_ADDR" \
> >>> -			-j DROP || ipt=0
> >>> +		local nft=1
> >>> +		ip netns exec "${ns2}" nft insert rule ip filter OUTPUT \
> >>> +			ip saddr 10.0.1.2 meta l4proto tcp \
> >>> +			tcp option mptcp subtype remove-addr drop || nft=0
> >>
> >> [Severity: Medium]
> >> Can this rule ever match an RM_ADDR packet on an established connection?
> >>
> >> nft_exthdr_tcp_eval() stops at the first TCP option whose kind matches
> >> (30 for MPTCP). The subtype check therefore only ever sees the first
> >> MPTCP suboption:
> >>
> >> net/netfilter/nft_exthdr.c:nft_exthdr_tcp_eval() {
> >>     ...
> >> 	for (i = sizeof(*tcph); i < tcphdr_len - 1; i += optl) {
> >> 		optl = optlen(opt, i);
> >>
> >> 		if (priv->type != opt[i])
> >> 			continue;
> >> 		...
> >> 		return;
> >> 	}
> >>     ...
> >> }
> > 
> > Indeed, the RM_ADDR will be added in a second MPTCP option. It looks
> > like Netfilter doesn't handle that case. But that seems to be an issue
> > on the Netfilter side, rather than with the command that should work. I
> > will follow up with Netfilter devs. If a fix cannot be added on their
> > side, I will change the nft command to look at a specific offset.
> > 
> > Note that the command here is just to check there is no RM_ADDR sent on
> > the wrong side: it shouldn't catch any packets here anyway.
> 
> After a discussion with Netfilter devs, it looks like a fix will not be
> easy to have. Yet, I wonder if it wouldn't be better to apply this patch
> like that (it doesn't break things), and have an explicit follow-up/fix
> to document this issue somehow.
> 
> @Hangbin: do you plan to look at a fix for that? I guess a raw payload
> looking at the same fields as what the previous cBPF rule was doing
> would be enough.

Yes, I will add this on my todo list and fix it after holiday.

> 
> Don't hesitate to fix the "low" priority comments as well.
> 
> https://lore.kernel.org/all/20260926-net-next-mptcp-misc-feat-7-4-v1-0-67af4ab37406@kernel.org/T/#u

Sure, I will.

Thanks
Hangbin

  parent reply	other threads:[~2026-09-30  2:48 UTC|newest]

Thread overview: 14+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-26 15:30 [PATCH net-next 0/5] mptcp: misc improvements for v7.4 Matthieu Baerts (NGI0)
2026-09-26 15:30 ` [PATCH net-next 1/5] mptcp: remove thmac from subflow ctx Matthieu Baerts (NGI0)
2026-09-26 15:30 ` [PATCH net-next 2/5] mptcp: split FASTCLOSE key from rcvr_key Matthieu Baerts (NGI0)
2026-09-26 15:30 ` [PATCH net-next 3/5] mptcp: shrink struct mptcp_options_received Matthieu Baerts (NGI0)
2026-09-26 15:30 ` [PATCH net-next 4/5] selftests: mptcp: convert iptables to nftables for mptcp_sockopt.sh Matthieu Baerts (NGI0)
2026-09-28  8:00   ` netdev-bot+sashiko
2026-09-28 11:24     ` Matthieu Baerts
2026-09-26 15:30 ` [PATCH net-next 5/5] selftests: mptcp: convert iptables to nftables for mptcp_join.sh Matthieu Baerts (NGI0)
2026-09-28  8:00   ` netdev-bot+sashiko
2026-09-28 11:24     ` Matthieu Baerts
2026-09-28 21:17       ` Matthieu Baerts
2026-09-30  2:10         ` Jakub Kicinski
2026-09-30  2:48         ` Hangbin Liu [this message]
2026-09-30  2:20 ` [PATCH net-next 0/5] mptcp: misc improvements for v7.4 patchwork-bot+netdevbpf

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=arx4cn3ZPDtuUNBM@fedora \
    --to=hangbin.liu@linux.dev \
    --cc=davem@davemloft.net \
    --cc=edumazet@google.com \
    --cc=geliang@kernel.org \
    --cc=horms@kernel.org \
    --cc=kuba@kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=liuhangbin@kylinos.cn \
    --cc=martineau@kernel.org \
    --cc=matttbe@kernel.org \
    --cc=mptcp@lists.linux.dev \
    --cc=netdev-bot+sashiko@kernel.org \
    --cc=netdev@vger.kernel.org \
    --cc=pabeni@redhat.com \
    --cc=quanyeyang@proton.me \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®