[PATCH bpf-next] selftests/bpf: Record only the test ICMP echo in tc8 of tc_netkit_scrub

From: Qiliang Yuan

Date: Thu Oct 08 2026 - 21:50:11 EST


tc_netkit_scrub attaches tc8 to the primary netkit device, sends an ICMP
echo with a mark and a priority through it, and checks the mark and the
priority that tc8 saw against what the scrub mode lets through.

tc8 records the mark and priority of every packet it sees, and the
device also carries what the system sends on its own once the device
is up, like IPv6 neighbor discovery or the mDNS of avahi-daemon. When
such a packet goes out after the echo, it overwrites what tc8 recorded,
and the test finds a mark and a priority of 0.

Record only IPv4 ICMP packets in tc8.

Fixes: 716fa7dadf11 ("selftests/bpf: Extend netkit tests to validate skb meta data")
Signed-off-by: Qiliang Yuan <odys.yuan@xxxxxxxxx>
---
tools/testing/selftests/bpf/progs/test_tc_link.c | 10 ++++++++++
1 file changed, 10 insertions(+)

diff --git a/tools/testing/selftests/bpf/progs/test_tc_link.c b/tools/testing/selftests/bpf/progs/test_tc_link.c
index 630f12e51b075..3c44ee06cfae8 100644
--- a/tools/testing/selftests/bpf/progs/test_tc_link.c
+++ b/tools/testing/selftests/bpf/progs/test_tc_link.c
@@ -4,6 +4,8 @@

#include <linux/bpf.h>
#include <linux/if_ether.h>
+#include <linux/in.h>
+#include <linux/ip.h>
#include <linux/stddef.h>
#include <linux/if_packet.h>
#include <bpf/bpf_endian.h>
@@ -119,6 +121,14 @@ SEC("tc/egress")
int tc8(struct __sk_buff *skb)
{
struct net_device *dev = BPF_CORE_READ((struct sk_buff *)skb, dev);
+ __u8 proto;
+
+ /* Look only at the ICMP echo of the test, not at IPv6 ND or mDNS */
+ if (skb->protocol != bpf_htons(ETH_P_IP) ||
+ bpf_skb_load_bytes(skb, sizeof(struct ethhdr) + offsetof(struct iphdr, protocol),
+ &proto, sizeof(proto)) ||
+ proto != IPPROTO_ICMP)
+ return TCX_PASS;

seen_tc8 = true;
mark = skb->mark;

---
base-commit: e1d84a37cba984388988d2f1ddc84561413f0db2
change-id: 20261009-selftests-bpf-tc-netkit-scrub-f0eb9904d0c7

Best regards,
--
Qiliang Yuan <odys.yuan@xxxxxxxxx>