Thread (1 message) 1 message, 1 author, 2017-03-16

Re: [RFC] [net]openvswitch: Clear the ct flow key for the recirculated packet

From: Lance Richardson <hidden>
Date: 2017-03-16 21:11:35

From: "Numan Siddique" <redacted>
To: netdev-u79uwXL29TY76Z2rM5mHXA@public.gmane.org, "ovs dev" <redacted>
Cc: "Joe Stringer" <redacted>, "Andy Zhou" <redacted>, jarno-LZ6Gd1LRuIk@public.gmane.org
Sent: Thursday, March 16, 2017 8:25:06 AM
Subject: [RFC] [net]openvswitch: Clear the ct flow key for the recirculated packet

It is possible that the ct flow key information would have
gone stale for the packets received from the userspace due to
clone or ct_clear actions.

In the case of OVN, it adds ping responder flows, which modifies
the original icmp4 request packet to a reply packet. It uses the
OVS actions - clone and ct_clear. When the reply packet hits the
"ovs_ct_execute" function, and since the ct flow key info is not
cleared, the connection tracker doesn't set the state to
ESTABLISHED state.

Note: This patch is marked as RFC, as I am not sure if this is the correct
place to address this issue or it should be addressed in ovs-vswitchd
to set the OVS_KEY_ATTR_CT_STATE and other related attributes
properly for ct_clear action.

Signed-off-by: Numan Siddique <redacted>
---
Hi Numan,

With this patch applied I'm consistently seeing failures for two of the
kernel datapath unit tests (via "make check-kernel"):

 16: conntrack - force commit                        FAILED (system-traffic.at:692)
 54: conntrack - SNAT with ct_mark change on reply   FAILED (system-traffic.at:2446)
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help