Re: [PATCH] tst_test.sh: TCONF on xfrm algorithms rejected via netlink extack

Petr Vorel <[email protected]>
Newsgroups gmane.linux.ltp
Message-ID <20260708140154.GC125128@pevik>
Hi Avinesh,

> TST_RTNL_CHK maps a kernel's "not supported" reply to TCONF by matching
> the "RTNETLINK answers: ..." strings. Since v6.1 the kernel reports an
> unknown/removed xfrm algorithm with -ENOSYS plus a netlink extack
> message, which iproute2 prints as:

> Error: Requested AUTH algorithm not found.

> This matches none of the existing strings, so TST_RTNL_CHK() reports
> TBROK instead of skipping.

> tcp_ipsec 1 TBROK: ip xfrm state add src 10.0.0.2 dst 10.0.0.1 spi 0x1000 proto esp enc serpent 0x81ea7757e7c71dc8f95bee692c0e8b1a2ac6e006066e74ce0024a54ee0175b70 auth hmac(rmd160) 0xf46316501051af3e3b2abd0bdfed7cf21a76fe04 mode transport sel src 10.0.0.2 dst 10.0.0.1 failed: Error: Requested AUTH algorithm not found.

Thanks for finding it!

> This surfaced with kernel v7.1 commit
> 05d42dc8ab92 ("xfrm: Drop support for HMAC-RIPEMD-160")
> which removed hmac(rmd160) and broke the
> net_stress.ipsec_* "-a rmd160" variants. Match the extack form too.

+1 for documenting the change.

> Signed-off-by: Avinesh Kumar <avinesh.kumar-IBi9RG/[email protected]>
> ---
>  testcases/lib/tst_test.sh | 11 ++++++++---
>  1 file changed, 8 insertions(+), 3 deletions(-)

> diff --git a/testcases/lib/tst_test.sh b/testcases/lib/tst_test.sh
> index 2a83c17a5efb..8701bb390388 100644
> --- a/testcases/lib/tst_test.sh
> +++ b/testcases/lib/tst_test.sh
> @@ -266,13 +266,18 @@ TST_RTNL_CHK()
>  	local msg1="RTNETLINK answers: Function not implemented"
>  	local msg2="RTNETLINK answers: Operation not supported"
>  	local msg3="RTNETLINK answers: Protocol not supported"
> +	# Since v6.1 the kernel reports an unknown/removed xfrm algorithm via
> +	# netlink extack (-ENOSYS + NL_SET_ERR_MSG), which iproute2 prints as
> +	# "Error: Requested AUTH algorithm not found."
> +	local msg4="Requested .* algorithm not found"
>  	local output="$($@ 2>&1 || echo 'LTP_ERR')"
nit: we have in $output also "LTP_ERR" in the end (on error)...

> -	local msg
> +	local msg match

>  	echo "$output" | grep -q "LTP_ERR" || return 0

> -	for msg in "$msg1" "$msg2" "$msg3"; do
> -		echo "$output" | grep -q "$msg" && tst_brk TCONF "'$@': $msg"
> +	for msg in "$msg1" "$msg2" "$msg3" "$msg4"; do
> +		match=$(echo "$output" | grep "$msg") && \
> +				tst_brk TCONF "'$@': $match"
... now we print error message also with "LTP_ERR" in the end.
I wonder if we should bother with removing it, e.g. with sed:

-		match=$(echo "$output" | grep "$msg") && \
+		match=$(echo "$output" | grep "$msg" | sed 's/LTP_ERR$//') && \

(untested)

Both w/a this change (can be done before merge).
Reviewed-by: Petr Vorel <[email protected]>

Kind regards,
Petr

-- 
Mailing list info: https://lists.linux.it/listinfo/ltp
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.