selftests/bpf: add test for BPF flow dissector in the root namespace
authorStanislav Fomichev <sdf@google.com>
Mon, 7 Oct 2019 16:21:03 +0000 (09:21 -0700)
committerAlexei Starovoitov <ast@kernel.org>
Tue, 8 Oct 2019 03:16:33 +0000 (20:16 -0700)
Make sure non-root namespaces get an error if root flow dissector is
attached.

Cc: Petar Penkov <ppenkov@google.com>
Acked-by: Song Liu <songliubraving@fb.com>
Signed-off-by: Stanislav Fomichev <sdf@google.com>
Signed-off-by: Alexei Starovoitov <ast@kernel.org>
tools/testing/selftests/bpf/test_flow_dissector.sh

index d23d4da66b834858a2307517b65529aba0622e86..2c3a25d64fafa45eef17e8b7e5a1994f77a0c291 100755 (executable)
@@ -18,19 +18,55 @@ fi
 # this is the case and run it with in_netns.sh if it is being run in the root
 # namespace.
 if [[ -z $(ip netns identify $$) ]]; then
+       err=0
+       if bpftool="$(which bpftool)"; then
+               echo "Testing global flow dissector..."
+
+               $bpftool prog loadall ./bpf_flow.o /sys/fs/bpf/flow \
+                       type flow_dissector
+
+               if ! unshare --net $bpftool prog attach pinned \
+                       /sys/fs/bpf/flow/flow_dissector flow_dissector; then
+                       echo "Unexpected unsuccessful attach in namespace" >&2
+                       err=1
+               fi
+
+               $bpftool prog attach pinned /sys/fs/bpf/flow/flow_dissector \
+                       flow_dissector
+
+               if unshare --net $bpftool prog attach pinned \
+                       /sys/fs/bpf/flow/flow_dissector flow_dissector; then
+                       echo "Unexpected successful attach in namespace" >&2
+                       err=1
+               fi
+
+               if ! $bpftool prog detach pinned \
+                       /sys/fs/bpf/flow/flow_dissector flow_dissector; then
+                       echo "Failed to detach flow dissector" >&2
+                       err=1
+               fi
+
+               rm -rf /sys/fs/bpf/flow
+       else
+               echo "Skipping root flow dissector test, bpftool not found" >&2
+       fi
+
+       # Run the rest of the tests in a net namespace.
        ../net/in_netns.sh "$0" "$@"
-       exit $?
-fi
+       err=$(( $err + $? ))
 
-# Determine selftest success via shell exit code
-exit_handler()
-{
-       if (( $? == 0 )); then
+       if (( $err == 0 )); then
                echo "selftests: $TESTNAME [PASS]";
        else
                echo "selftests: $TESTNAME [FAILED]";
        fi
 
+       exit $err
+fi
+
+# Determine selftest success via shell exit code
+exit_handler()
+{
        set +e
 
        # Cleanup