2 # SPDX-License-Identifier: GPL-2.0
4 # Copyright (c) 2019 David Ahern <dsahern@gmail.com>. All rights reserved.
5 # Copyright (c) 2020 Michael Jeanson <mjeanson@efficios.com>. All rights reserved.
7 # Requires CONFIG_NET_VRF, CONFIG_VETH, CONFIG_BRIDGE and CONFIG_NET_NS.
10 # Symmetric routing topology
13 # +----+ .253 +----+ .253 +----+
14 # | h1 |-------------------| r1 |-------------------| h2 |
15 # +----+ .1 +----+ .2 +----+
16 # 172.16.1/24 172.16.2/24
17 # 2001:db8:16:1/64 2001:db8:16:2/64
20 # Route from h1 to h2 and back goes through r1, incoming vrf blue has a route
21 # to the outgoing vrf red for the n2 network and red has a route back to n1.
22 # The red VRF interface has a MTU of 1400.
24 # The first test sends a ping with a ttl of 1 from h1 to h2 and parses the
25 # output of the command to check that a ttl expired error is received.
27 # The second test runs traceroute from h1 to h2 and parses the output to check
30 # The third test sends a ping with a packet size of 1450 from h1 to h2 and
31 # parses the output of the command to check that a fragmentation error is
35 # Asymmetric routing topology
37 # This topology represents a customer setup where the issue with icmp errors
38 # and VRF route leaking was initialy reported. The MTU test isn't done here
39 # because of the lack of a return route in the red VRF.
46 # | h1 |--------------+ +--------------| h2 |
47 # +----+ .1 | | .2 +----+
48 # 172.16.1/24 | +----+ | 172.16.2/24
49 # 2001:db8:16:1/64 +----| r2 |----+ 2001:db8:16:2/64
53 # Route from h1 to h2 goes through r1, incoming vrf blue has a route to the
54 # outgoing vrf red for the n2 network but red doesn't have a route back to n1.
55 # Route from h2 to h1 goes through r2.
57 # The objective is to check that the incoming vrf routing table is selected
58 # to send an ICMP error back to the source when the ttl of a packet reaches 1
59 # while it is forwarded between different vrfs.
67 H1_N1_6
=2001:db8
:16:1::/64
73 H1_N1_IP6
=2001:db8
:16:1::1
74 R1_N1_IP6
=2001:db8
:16:1::253
75 R2_N1_IP6
=2001:db8
:16:1::254
78 H2_N2_6
=2001:db8
:16:2::/64
84 H2_N2_IP6
=2001:db8
:16:2::2
85 R1_N2_IP6
=2001:db8
:16:2::253
86 R2_N2_IP6
=2001:db8
:16:2::254
88 ################################################################################
94 echo "###########################################################################"
96 echo "###########################################################################"
106 if [ "${rc}" -eq "${expected}" ]; then
107 printf "TEST: %-60s [ OK ]\n" "${msg}"
108 nsuccess
=$
((nsuccess
+1))
112 printf "TEST: %-60s [FAIL]\n" "${msg}"
113 if [ "${PAUSE_ON_FAIL}" = "yes" ]; then
115 echo "hit enter to continue, 'q' to quit"
117 [ "$a" = "q" ] && exit 1
128 if [ "$VERBOSE" = "1" ]; then
132 # shellcheck disable=SC2086
133 out
=$
(eval $cmd 2>&1)
135 if [ "$VERBOSE" = "1" ] && [ -n "$out" ]; then
139 [ "$VERBOSE" = "1" ] && echo
146 local grep_pattern
="$1"
152 if [ "$VERBOSE" = "1" ]; then
156 # shellcheck disable=SC2086
157 out
=$
(eval $cmd 2>&1)
158 if [ "$VERBOSE" = "1" ] && [ -n "$out" ]; then
162 echo "$out" |
grep -q "$grep_pattern"
165 [ "$VERBOSE" = "1" ] && echo
170 ################################################################################
175 cleanup_ns
$h1 $h2 $r1 $r2
182 ip
-netns "${ns}" rule del pref
0
183 ip
-netns "${ns}" rule add pref
32765 from all lookup
local
184 ip
-netns "${ns}" -6 rule del pref
0
185 ip
-netns "${ns}" -6 rule add pref
32765 from all lookup
local
194 ip
-netns "${ns}" link add "${vrf}" type vrf table "${table}"
195 ip
-netns "${ns}" link
set "${vrf}" up
196 ip
-netns "${ns}" route add vrf
"${vrf}" unreachable default metric
8192
197 ip
-netns "${ns}" -6 route add vrf
"${vrf}" unreachable default metric
8192
199 ip
-netns "${ns}" addr add
127.0.0.1/8 dev
"${vrf}"
200 ip
-netns "${ns}" -6 addr add
::1 dev
"${vrf}" nodad
207 # make sure we are starting with a clean slate
211 # create nodes as namespaces
213 for ns
in $h1 $h2 $r1; do
214 if echo $ns |
grep -q h
[12]-; then
215 ip netns
exec $ns sysctl
-q -w net.ipv6.conf.all.forwarding
=0
216 ip netns
exec $ns sysctl
-q -w net.ipv6.conf.all.keep_addr_on_down
=1
218 ip netns
exec $ns sysctl
-q -w net.ipv4.ip_forward
=1
219 ip netns
exec $ns sysctl
-q -w net.ipv6.conf.all.forwarding
=1
224 # create interconnects
226 ip
-netns $h1 link add eth0
type veth peer name r1h1
227 ip
-netns $h1 link
set r1h1 netns
$r1 name eth0 up
229 ip
-netns $h2 link add eth0
type veth peer name r1h2
230 ip
-netns $h2 link
set r1h2 netns
$r1 name eth1 up
235 ip
-netns $h1 addr add dev eth0
${H1_N1_IP}/24
236 ip
-netns $h1 -6 addr add dev eth0
${H1_N1_IP6}/64 nodad
237 ip
-netns $h1 link
set eth0 up
240 ip
-netns $h1 route add
${H2_N2} via
${R1_N1_IP} dev eth0
241 ip
-netns $h1 -6 route add
${H2_N2_6} via
"${R1_N1_IP6}" dev eth0
246 ip
-netns $h2 addr add dev eth0
${H2_N2_IP}/24
247 ip
-netns $h2 -6 addr add dev eth0
${H2_N2_IP6}/64 nodad
248 ip
-netns $h2 link
set eth0 up
251 ip
-netns $h2 route add default via
${R1_N2_IP} dev eth0
252 ip
-netns $h2 -6 route add default via
${R1_N2_IP6} dev eth0
258 create_vrf
$r1 blue
1101
259 create_vrf
$r1 red
1102
260 ip
-netns $r1 link
set mtu
1400 dev eth1
261 ip
-netns $r1 link
set eth0 vrf blue up
262 ip
-netns $r1 link
set eth1 vrf red up
263 ip
-netns $r1 addr add dev eth0
${R1_N1_IP}/24
264 ip
-netns $r1 -6 addr add dev eth0
${R1_N1_IP6}/64 nodad
265 ip
-netns $r1 addr add dev eth1
${R1_N2_IP}/24
266 ip
-netns $r1 -6 addr add dev eth1
${R1_N2_IP6}/64 nodad
268 # Route leak from blue to red
269 ip
-netns $r1 route add vrf blue
${H2_N2} dev red
270 ip
-netns $r1 -6 route add vrf blue
${H2_N2_6} dev red
272 # Route leak from red to blue
273 ip
-netns $r1 route add vrf red
${H1_N1} dev blue
274 ip
-netns $r1 -6 route add vrf red
${H1_N1_6} dev blue
277 # Wait for ip config to settle
285 # make sure we are starting with a clean slate
289 # create nodes as namespaces
291 for ns
in $h1 $h2 $r1 $r2; do
292 if echo $ns |
grep -q h
[12]-; then
293 ip netns
exec $ns sysctl
-q -w net.ipv6.conf.all.forwarding
=0
294 ip netns
exec $ns sysctl
-q -w net.ipv6.conf.all.keep_addr_on_down
=1
296 ip netns
exec $ns sysctl
-q -w net.ipv4.ip_forward
=1
297 ip netns
exec $ns sysctl
-q -w net.ipv6.conf.all.forwarding
=1
302 # create interconnects
304 ip
-netns $h1 link add eth0
type veth peer name r1h1
305 ip
-netns $h1 link
set r1h1 netns
$r1 name eth0 up
307 ip
-netns $h1 link add eth1
type veth peer name r2h1
308 ip
-netns $h1 link
set r2h1 netns
$r2 name eth0 up
310 ip
-netns $h2 link add eth0
type veth peer name r1h2
311 ip
-netns $h2 link
set r1h2 netns
$r1 name eth1 up
313 ip
-netns $h2 link add eth1
type veth peer name r2h2
314 ip
-netns $h2 link
set r2h2 netns
$r2 name eth1 up
319 ip
-netns $h1 link add br0
type bridge
320 ip
-netns $h1 link
set br0 up
321 ip
-netns $h1 addr add dev br0
${H1_N1_IP}/24
322 ip
-netns $h1 -6 addr add dev br0
${H1_N1_IP6}/64 nodad
323 ip
-netns $h1 link
set eth0 master br0 up
324 ip
-netns $h1 link
set eth1 master br0 up
327 ip
-netns $h1 route add
${H2_N2} via
${R1_N1_IP} dev br0
328 ip
-netns $h1 -6 route add
${H2_N2_6} via
"${R1_N1_IP6}" dev br0
333 ip
-netns $h2 link add br0
type bridge
334 ip
-netns $h2 link
set br0 up
335 ip
-netns $h2 addr add dev br0
${H2_N2_IP}/24
336 ip
-netns $h2 -6 addr add dev br0
${H2_N2_IP6}/64 nodad
337 ip
-netns $h2 link
set eth0 master br0 up
338 ip
-netns $h2 link
set eth1 master br0 up
341 ip
-netns $h2 route add default via
${R2_N2_IP} dev br0
342 ip
-netns $h2 -6 route add default via
${R2_N2_IP6} dev br0
348 create_vrf
$r1 blue
1101
349 create_vrf
$r1 red
1102
350 ip
-netns $r1 link
set mtu
1400 dev eth1
351 ip
-netns $r1 link
set eth0 vrf blue up
352 ip
-netns $r1 link
set eth1 vrf red up
353 ip
-netns $r1 addr add dev eth0
${R1_N1_IP}/24
354 ip
-netns $r1 -6 addr add dev eth0
${R1_N1_IP6}/64 nodad
355 ip
-netns $r1 addr add dev eth1
${R1_N2_IP}/24
356 ip
-netns $r1 -6 addr add dev eth1
${R1_N2_IP6}/64 nodad
358 # Route leak from blue to red
359 ip
-netns $r1 route add vrf blue
${H2_N2} dev red
360 ip
-netns $r1 -6 route add vrf blue
${H2_N2_6} dev red
362 # No route leak from red to blue
367 ip
-netns $r2 addr add dev eth0
${R2_N1_IP}/24
368 ip
-netns $r2 -6 addr add dev eth0
${R2_N1_IP6}/64 nodad
369 ip
-netns $r2 addr add dev eth1
${R2_N2_IP}/24
370 ip
-netns $r2 -6 addr add dev eth1
${R2_N2_IP6}/64 nodad
372 # Wait for ip config to settle
378 ip netns
exec $h1 ping -c1 -w1 ${H2_N2_IP} >/dev
/null
2>&1
379 log_test $?
0 "Basic IPv4 connectivity"
383 check_connectivity6
()
385 ip netns
exec $h1 "${ping6}" -c1 -w1 ${H2_N2_IP6} >/dev
/null
2>&1
386 log_test $?
0 "Basic IPv6 connectivity"
392 if [ ! -x "$(command -v traceroute)" ]; then
393 echo "SKIP: Could not run IPV4 test without traceroute"
400 if [ ! -x "$(command -v traceroute6)" ]; then
401 echo "SKIP: Could not run IPV6 test without traceroute6"
410 [ "x$ttype" = "x" ] && ttype
="$DEFAULT_TTYPE"
412 log_section
"IPv4 ($ttype route): VRF ICMP error route lookup traceroute"
414 check_traceroute ||
return
418 check_connectivity ||
return
420 run_cmd_grep
"${R1_N1_IP}" ip netns
exec $h1 traceroute ${H2_N2_IP}
421 log_test $?
0 "Traceroute reports a hop on r1"
424 ipv4_traceroute_asym
()
433 [ "x$ttype" = "x" ] && ttype
="$DEFAULT_TTYPE"
435 log_section
"IPv6 ($ttype route): VRF ICMP error route lookup traceroute"
437 check_traceroute6 ||
return
441 check_connectivity6 ||
return
443 run_cmd_grep
"${R1_N1_IP6}" ip netns
exec $h1 traceroute6
${H2_N2_IP6}
444 log_test $?
0 "Traceroute6 reports a hop on r1"
447 ipv6_traceroute_asym
()
456 [ "x$ttype" = "x" ] && ttype
="$DEFAULT_TTYPE"
458 log_section
"IPv4 ($ttype route): VRF ICMP ttl error route lookup ping"
462 check_connectivity ||
return
464 run_cmd_grep
"Time to live exceeded" ip netns
exec $h1 ping -t1 -c1 -W2 ${H2_N2_IP}
465 log_test $?
0 "Ping received ICMP ttl exceeded"
477 [ "x$ttype" = "x" ] && ttype
="$DEFAULT_TTYPE"
479 log_section
"IPv4 ($ttype route): VRF ICMP fragmentation error route lookup ping"
483 check_connectivity ||
return
485 run_cmd_grep
"Frag needed" ip netns
exec $h1 ping -s 1450 -Mdo -c1 -W2 ${H2_N2_IP}
486 log_test $?
0 "Ping received ICMP Frag needed"
489 ipv4_ping_frag_asym
()
498 [ "x$ttype" = "x" ] && ttype
="$DEFAULT_TTYPE"
500 log_section
"IPv6 ($ttype route): VRF ICMP ttl error route lookup ping"
504 check_connectivity6 ||
return
506 run_cmd_grep
"Time exceeded: Hop limit" ip netns
exec $h1 "${ping6}" -t1 -c1 -W2 ${H2_N2_IP6}
507 log_test $?
0 "Ping received ICMP Hop limit"
519 [ "x$ttype" = "x" ] && ttype
="$DEFAULT_TTYPE"
521 log_section
"IPv6 ($ttype route): VRF ICMP fragmentation error route lookup ping"
525 check_connectivity6 ||
return
527 run_cmd_grep
"Packet too big" ip netns
exec $h1 "${ping6}" -s 1450 -Mdo -c1 -W2 ${H2_N2_IP6}
528 log_test $?
0 "Ping received ICMP Packet too big"
531 ipv6_ping_frag_asym
()
538 log_section
"IPv4 (sym route): VRF ICMP local error route lookup ping"
542 check_connectivity ||
return
544 run_cmd ip netns
exec $r1 ip vrf
exec blue
ping -c1 -w1 ${H2_N2_IP}
545 log_test $?
0 "VRF ICMP local IPv4"
550 log_section
"IPv4 (sym route): VRF tcp local connection"
554 check_connectivity ||
return
556 run_cmd nettest
-s -O "$h2" -l ${H2_N2_IP} -I eth0
-3 eth0
&
558 run_cmd nettest
-N "$r1" -d blue
-r ${H2_N2_IP}
559 log_test $?
0 "VRF tcp local connection IPv4"
564 log_section
"IPv4 (sym route): VRF udp local connection"
568 check_connectivity ||
return
570 run_cmd nettest
-s -D -O "$h2" -l ${H2_N2_IP} -I eth0
-3 eth0
&
572 run_cmd nettest
-D -N "$r1" -d blue
-r ${H2_N2_IP}
573 log_test $?
0 "VRF udp local connection IPv4"
578 log_section
"IPv6 (sym route): VRF ICMP local error route lookup ping"
582 check_connectivity6 ||
return
584 run_cmd ip netns
exec $r1 ip vrf
exec blue
${ping6} -c1 -w1 ${H2_N2_IP6}
585 log_test $?
0 "VRF ICMP local IPv6"
590 log_section
"IPv6 (sym route): VRF tcp local connection"
594 check_connectivity6 ||
return
596 run_cmd nettest
-s -6 -O "$h2" -l ${H2_N2_IP6} -I eth0
-3 eth0
&
598 run_cmd nettest
-6 -N "$r1" -d blue
-r ${H2_N2_IP6}
599 log_test $?
0 "VRF tcp local connection IPv6"
604 log_section
"IPv6 (sym route): VRF udp local connection"
608 check_connectivity6 ||
return
610 run_cmd nettest
-s -6 -D -O "$h2" -l ${H2_N2_IP6} -I eth0
-3 eth0
&
612 run_cmd nettest
-6 -D -N "$r1" -d blue
-r ${H2_N2_IP6}
613 log_test $?
0 "VRF udp local connection IPv6"
616 ################################################################################
624 -4 Run IPv4 tests only
625 -6 Run IPv6 tests only
626 -t TEST Run only TEST
628 -v verbose mode (show commands and output)
632 ################################################################################
635 # Some systems don't have a ping6 binary anymore
636 command -v ping6
> /dev
/null
2>&1 && ping6
=$
(command -v ping6
) || ping6
=$
(command -v ping)
638 check_gen_prog
"nettest"
640 TESTS_IPV4
="ipv4_ping_ttl ipv4_traceroute ipv4_ping_frag ipv4_ping_local ipv4_tcp_local
641 ipv4_udp_local ipv4_ping_ttl_asym ipv4_traceroute_asym"
642 TESTS_IPV6
="ipv6_ping_ttl ipv6_traceroute ipv6_ping_local ipv6_tcp_local ipv6_udp_local
643 ipv6_ping_ttl_asym ipv6_traceroute_asym"
649 while getopts :46t
:pvh o
655 p
) PAUSE_ON_FAIL
=yes;;
663 # show user test config
665 if [ -z "$TESTS" ]; then
666 TESTS
="$TESTS_IPV4 $TESTS_IPV6"
667 elif [ "$TESTS" = "ipv4" ]; then
669 elif [ "$TESTS" = "ipv6" ]; then
676 ipv4_ping_ttl|
ping) ipv4_ping_ttl
;;&
677 ipv4_ping_ttl_asym|
ping) ipv4_ping_ttl_asym
;;&
678 ipv4_traceroute|
traceroute) ipv4_traceroute
;;&
679 ipv4_traceroute_asym|
traceroute) ipv4_traceroute_asym
;;&
680 ipv4_ping_frag|
ping) ipv4_ping_frag
;;&
681 ipv4_ping_local|
ping) ipv4_ping_local
;;&
682 ipv4_tcp_local
) ipv4_tcp_local
;;&
683 ipv4_udp_local
) ipv4_udp_local
;;&
685 ipv6_ping_ttl|
ping) ipv6_ping_ttl
;;&
686 ipv6_ping_ttl_asym|
ping) ipv6_ping_ttl_asym
;;&
687 ipv6_traceroute|
traceroute) ipv6_traceroute
;;&
688 ipv6_traceroute_asym|
traceroute) ipv6_traceroute_asym
;;&
689 ipv6_ping_frag|
ping) ipv6_ping_frag
;;&
690 ipv6_ping_local|
ping) ipv6_ping_local
;;&
691 ipv6_tcp_local
) ipv6_tcp_local
;;&
692 ipv6_udp_local
) ipv6_udp_local
;;&
694 # setup namespaces and config, but do not run any tests
695 setup_sym|setup
) setup_sym
; exit 0;;
696 setup_asym
) setup_asym
; exit 0;;
698 help) echo "Test names: $TESTS"; exit 0;;
704 printf "\nTests passed: %3d\n" ${nsuccess}
705 printf "Tests failed: %3d\n" ${nfail}