This commit adds the kernel config options needed to run the recently added xdp_synproxy test. Users without these options will hit errors like this: test_synproxy:FAIL:iptables -t raw -I PREROUTING -i tmp1 -p tcp -m tcp --syn --dport 8080 -j CT --notrack unexpected error: 256 (errno 22) Suggested-by: Alexei Starovoitov <alexei.starovoitov@gmail.com> Signed-off-by: Maxim Mikityanskiy <maximmi@nvidia.com> Signed-off-by: Daniel Borkmann <daniel@iogearbox.net> Link: https://lore.kernel.org/bpf/20220620104939.4094104-1-maximmi@nvidia.com
66 lines
1.3 KiB
Plaintext
66 lines
1.3 KiB
Plaintext
CONFIG_BPF=y
|
|
CONFIG_BPF_SYSCALL=y
|
|
CONFIG_NET_CLS_BPF=m
|
|
CONFIG_BPF_EVENTS=y
|
|
CONFIG_TEST_BPF=m
|
|
CONFIG_CGROUP_BPF=y
|
|
CONFIG_NETDEVSIM=m
|
|
CONFIG_NET_CLS_ACT=y
|
|
CONFIG_NET_SCHED=y
|
|
CONFIG_NET_SCH_INGRESS=y
|
|
CONFIG_NET_IPIP=y
|
|
CONFIG_IPV6=y
|
|
CONFIG_NET_IPGRE_DEMUX=y
|
|
CONFIG_NET_IPGRE=y
|
|
CONFIG_IPV6_GRE=y
|
|
CONFIG_CRYPTO_USER_API_HASH=m
|
|
CONFIG_CRYPTO_HMAC=m
|
|
CONFIG_CRYPTO_SHA256=m
|
|
CONFIG_VXLAN=y
|
|
CONFIG_GENEVE=y
|
|
CONFIG_NET_CLS_FLOWER=m
|
|
CONFIG_LWTUNNEL=y
|
|
CONFIG_BPF_STREAM_PARSER=y
|
|
CONFIG_XDP_SOCKETS=y
|
|
CONFIG_FTRACE_SYSCALLS=y
|
|
CONFIG_IPV6_TUNNEL=y
|
|
CONFIG_IPV6_GRE=y
|
|
CONFIG_IPV6_SEG6_BPF=y
|
|
CONFIG_NET_FOU=m
|
|
CONFIG_NET_FOU_IP_TUNNELS=y
|
|
CONFIG_IPV6_FOU=m
|
|
CONFIG_IPV6_FOU_TUNNEL=m
|
|
CONFIG_MPLS=y
|
|
CONFIG_NET_MPLS_GSO=m
|
|
CONFIG_MPLS_ROUTING=m
|
|
CONFIG_MPLS_IPTUNNEL=m
|
|
CONFIG_IPV6_SIT=m
|
|
CONFIG_BPF_JIT=y
|
|
CONFIG_BPF_LSM=y
|
|
CONFIG_SECURITY=y
|
|
CONFIG_RC_CORE=y
|
|
CONFIG_LIRC=y
|
|
CONFIG_BPF_LIRC_MODE2=y
|
|
CONFIG_IMA=y
|
|
CONFIG_SECURITYFS=y
|
|
CONFIG_IMA_WRITE_POLICY=y
|
|
CONFIG_IMA_READ_POLICY=y
|
|
CONFIG_BLK_DEV_LOOP=y
|
|
CONFIG_FUNCTION_TRACER=y
|
|
CONFIG_DYNAMIC_FTRACE=y
|
|
CONFIG_NETFILTER=y
|
|
CONFIG_NF_DEFRAG_IPV4=y
|
|
CONFIG_NF_DEFRAG_IPV6=y
|
|
CONFIG_NF_CONNTRACK=y
|
|
CONFIG_USERFAULTFD=y
|
|
CONFIG_FPROBE=y
|
|
CONFIG_IKCONFIG=y
|
|
CONFIG_IKCONFIG_PROC=y
|
|
CONFIG_MPTCP=y
|
|
CONFIG_NETFILTER_SYNPROXY=y
|
|
CONFIG_NETFILTER_XT_TARGET_CT=y
|
|
CONFIG_NETFILTER_XT_MATCH_STATE=y
|
|
CONFIG_IP_NF_FILTER=y
|
|
CONFIG_IP_NF_TARGET_SYNPROXY=y
|
|
CONFIG_IP_NF_RAW=y
|