Commit 59c93583 authored by Jakub Kicinski's avatar Jakub Kicinski

selftests: net: add missing config for nftables-backed iptables

Modern OSes use iptables implementation with nf_tables as a backend,
e.g.:

$ iptables -V
iptables v1.8.8 (nf_tables)

Pablo points out that we need CONFIG_NFT_COMPAT to make that work,
otherwise we see a lot of:

  Warning: Extension DNAT revision 0 not supported, missing kernel module?

with DNAT being just an example here, other modules we need
include udp, TTL, length etc.

Link: https://lore.kernel.org/r/20240126201308.2903602-1-kuba@kernel.orgSigned-off-by: default avatarJakub Kicinski <kuba@kernel.org>
parent c44fc98f
...@@ -60,6 +60,7 @@ CONFIG_NET_SCH_HTB=m ...@@ -60,6 +60,7 @@ CONFIG_NET_SCH_HTB=m
CONFIG_NET_SCH_FQ=m CONFIG_NET_SCH_FQ=m
CONFIG_NET_SCH_ETF=m CONFIG_NET_SCH_ETF=m
CONFIG_NET_SCH_NETEM=y CONFIG_NET_SCH_NETEM=y
CONFIG_NFT_COMPAT=m
CONFIG_NF_FLOW_TABLE=m CONFIG_NF_FLOW_TABLE=m
CONFIG_PSAMPLE=m CONFIG_PSAMPLE=m
CONFIG_TCP_MD5SIG=y CONFIG_TCP_MD5SIG=y
......
Markdown is supported
0%
or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment