On 10/5/26 10:31 AM, Ales Musil wrote: > On Fri, Oct 2, 2026 at 8:34 PM Dumitru Ceara via dev < > [email protected]> wrote: > >> When a logical switch port has both port_security and "unknown" >> in its addresses, build_lswitch_learn_fdb_op() skipped FDB >> learning flow generation because of an early-return guard that >> checked op->lsp_has_port_sec. >> >> When multiple logical switch ports share the same MAC address >> (e.g., a VRRP virtual MAC) in their LSP.addresses, northd >> generates duplicate L2 lookup flows at the same priority with >> the same match but different outport actions. Since >> ovn-controller can only install one, traffic to the shared MAC >> is nondeterministically sent to only one of the ports. >> >> The recommended configuration to avoid this is to omit the shared >> MAC from LSP.addresses (placing it only in port_security) and >> include "unknown" in addresses, so the shared MAC is resolved >> dynamically via FDB learning. However, the early-return guard >> blocked FDB learning on ports with port_security, preventing >> this configuration from working. >> >> The original guard was added in commit dd94f1266 ("northd: MAC >> learning: Add logical flows for fdb") under the assumption that >> ports with port security should not participate in FDB learning. >> However, ingress port security (ls_in_check_port_sec) validates >> source MACs before the FDB learning stages (ls_in_lookup_fdb, >> ls_in_put_fdb), so only MACs that pass port security are >> recorded. Egress port security also validates packets after L2 >> lookup. Removing the lsp_has_port_sec check is therefore safe. >> >> Reported-at: https://redhat.atlassian.net/browse/FDP-4286 >> Assisted-by: Claude Opus 4.6, Claude Code >> Signed-off-by: Dumitru Ceara <[email protected]> >> ---
... >> >> > Hi Dumitru, > Hi Ales, > same as in the 1/2 aren't we missing update to ovn-logical-flows.7.rst? Yeah we are, I'll do that in v2. > Other than that it looks good. > > Regards, > Ales > Thanks, Dumitru _______________________________________________ dev mailing list [email protected] https://mail.openvswitch.org/mailman/listinfo/ovs-dev
