On Thu, 5 Mar 2026 00:06:26 +0100 Antonio Quartulli wrote: > Add a selftest to verify that the FW mark socket option is correctly > supported and its value propagated by ovpn. > > The test adds and removes nftables DROP rules based on the mark value, > and checks that the rule counter aligns with the number of lost ping > packets.
This test does not work for us: TAP version 13 1..1 # overriding timeout to 240 # selftests: net/ovpn: test-mark.sh # Creating interface tun0 with mode 1 # Creating interface tun1 with mode 0 # Creating interface tun2 with mode 0 # Creating interface tun3 with mode 0 # cannot open file: any # Cannot execute command: Operation not permitted (-1) not ok 1 selftests: net/ovpn: test-mark.sh # exit=255 kernel config file: https://netdev-ctrl.bots.linux.dev/logs/vmksft/net-extra-dbg/results/545921/config
