Recent commit to add NETFILTER_XTABLES_LEGACY missed setting a couple of configs to y. They are still enabled but as modules which appears to have upset BPF CI, e.g.: test_bpf_nf_ct:FAIL:iptables-legacy -t raw -A PREROUTING -j CONNMARK --set-mark 42/0 unexpected error: 768 (errno 0) Fixes: 3c3ab65f00eb ("selftests: net: Enable legacy netfilter legacy options.") Signed-off-by: Jakub Kicinski <kuba@xxxxxxxxxx> --- Targeting net-next 'cause that's where the bad commit is. CC: ast@xxxxxxxxxx CC: daniel@xxxxxxxxxxxxx CC: andrii@xxxxxxxxxx CC: martin.lau@xxxxxxxxx CC: eddyz87@xxxxxxxxx CC: song@xxxxxxxxxx CC: yonghong.song@xxxxxxxxx CC: john.fastabend@xxxxxxxxx CC: kpsingh@xxxxxxxxxx CC: sdf@xxxxxxxxxxx CC: haoluo@xxxxxxxxxx CC: jolsa@xxxxxxxxxx CC: mykolal@xxxxxx CC: shuah@xxxxxxxxxx CC: pablo@xxxxxxxxxxxxx CC: bigeasy@xxxxxxxxxxxxx CC: fw@xxxxxxxxx CC: bpf@xxxxxxxxxxxxxxx CC: linux-kselftest@xxxxxxxxxxxxxxx --- tools/testing/selftests/bpf/config | 2 ++ 1 file changed, 2 insertions(+) diff --git a/tools/testing/selftests/bpf/config b/tools/testing/selftests/bpf/config index 521836776733..e8c6c77b96cb 100644 --- a/tools/testing/selftests/bpf/config +++ b/tools/testing/selftests/bpf/config @@ -97,6 +97,8 @@ CONFIG_NF_TABLES_NETDEV=y CONFIG_NF_TABLES_IPV4=y CONFIG_NF_TABLES_IPV6=y CONFIG_NETFILTER_INGRESS=y +CONFIG_IP_NF_IPTABLES_LEGACY=y +CONFIG_IP6_NF_IPTABLES_LEGACY=y CONFIG_NETFILTER_XTABLES_LEGACY=y CONFIG_NF_FLOW_TABLE=y CONFIG_NF_FLOW_TABLE_INET=y -- 2.50.1