The bpf_nf test allocs a ct, sets snat and dnat with random addr and
port via bpf_ct_set_nat_info(), then looks the ct up and checks the
reply tuple against what was set.

The port comes from bpf_get_prandom_u32() and can be 0. For
bpf_ct_set_nat_info(), port 0 means "port not specified", so only the
addr is mapped and the kernel keeps the original port. The check then
compares that port with 0 and fails, which shows up as a flaky
"Test for source natting" failure in CI [1][2].

Keep the random port in 1..65535 so it is always specified.

[1] 
https://github.com/kernel-patches/bpf/actions/runs/33830002889/job/100893868791
[2] 
https://github.com/kernel-patches/bpf/actions/runs/33829976794/job/100893220999

Fixes: b06b45e82b59 ("selftests/bpf: add tests for bpf_ct_set_nat_info kfunc")
Signed-off-by: Jiayuan Chen <[email protected]>
---
 tools/testing/selftests/bpf/progs/test_bpf_nf.c | 8 ++++----
 1 file changed, 4 insertions(+), 4 deletions(-)

diff --git a/tools/testing/selftests/bpf/progs/test_bpf_nf.c 
b/tools/testing/selftests/bpf/progs/test_bpf_nf.c
index df43649ecb78..eda9b7bbab75 100644
--- a/tools/testing/selftests/bpf/progs/test_bpf_nf.c
+++ b/tools/testing/selftests/bpf/progs/test_bpf_nf.c
@@ -190,8 +190,8 @@ nf_ct_test(struct nf_conn *(*lookup_fn)(void *, struct 
bpf_sock_tuple *, u32,
        ct = alloc_fn(ctx, &bpf_tuple, sizeof(bpf_tuple.ipv4), &opts_def,
                      sizeof(opts_def));
        if (ct) {
-               __u16 sport = bpf_get_prandom_u32();
-               __u16 dport = bpf_get_prandom_u32();
+               __u16 sport = bpf_get_prandom_u32() % 65535 + 1;
+               __u16 dport = bpf_get_prandom_u32() % 65535 + 1;
                union nf_inet_addr saddr = {};
                union nf_inet_addr daddr = {};
                struct nf_conn *ct_ins;
@@ -293,8 +293,8 @@ nf_ct_opts_new_test(struct nf_conn *(*lookup_fn)(void *, 
struct bpf_sock_tuple *
        ct = alloc_fn(ctx, &bpf_tuple, sizeof(bpf_tuple.ipv4), &opts_def,
                      sizeof(opts_def));
        if (ct) {
-               __u16 sport = bpf_get_prandom_u32();
-               __u16 dport = bpf_get_prandom_u32();
+               __u16 sport = bpf_get_prandom_u32() % 65535 + 1;
+               __u16 dport = bpf_get_prandom_u32() % 65535 + 1;
                union nf_inet_addr saddr = {};
                union nf_inet_addr daddr = {};
                struct nf_conn *ct_ins;
-- 
2.43.0


Reply via email to