Hi Alexandra! This change makes sense to me. Here are some minor comments.

On 9/25/26 9:57 AM, Alexandra Rukomoinikova via dev wrote:
> Mirroring of type "lport" was done after ingress port security and
> before egress port security, so the mirror did not show the traffic
> that was really present on the port.  For example, if a VM is
> compromised and sends packets with a spoofed source MAC, port security
> drops them and they never reach the mirror target, although this is
> exactly the traffic one would want to see.

An example could also be added for the egress case.

> 
> Mirror the traffic as close to the interface as possible, so that the
> mirror target sees what the port actually sends and receives.
> 
> Signed-off-by: Alexandra Rukomoinikova <[email protected]>

Since this is basically a fix for your previous patch which added lport
mirroring, and thus decided the pipeline ordering, I think it would make
sense to add the Fixes tag:

Fixes: 2a2fe266d09c ("northd: Added support for port mirroring in OVN
overlay.")

Everything else below looks good to me, but I'm open to other input.

> ---
>  Documentation/ref/ovn-logical-flows.7.rst | 107 +++++++++++-----------
>  NEWS                                      |   6 ++
>  lib/ovn-util.c                            |   4 +-
>  northd/northd.c                           |  11 ++-
>  northd/northd.h                           |  21 ++---
>  ovn-nb.xml                                |  12 +++
>  tests/ovn-northd.at                       |  62 ++++++-------
>  tests/ovn-util.at                         |   4 +-
>  tests/ovn.at                              |  22 ++---
>  9 files changed, 134 insertions(+), 115 deletions(-)
> 
> diff --git a/Documentation/ref/ovn-logical-flows.7.rst 
> b/Documentation/ref/ovn-logical-flows.7.rst
> index 44fd560bf..a1cfeea6d 100644
> --- a/Documentation/ref/ovn-logical-flows.7.rst
> +++ b/Documentation/ref/ovn-logical-flows.7.rst
> @@ -16,10 +16,29 @@ Logical Switch Datapaths
>  
>  .. _ls-in-0:
>  
> -Ingress Table 0: Admission Control and Ingress Port Security check
> +Ingress Table 0: Mirror
> +~~~~~~~~~~~~~~~~~~~~~~~~
> +
> +Overlay remote mirror table contains the following logical flows:
> +
> +- For each logical switch port with an attached mirror, a logical flow with a
> +  priority of 100 is added. This flow matches all incoming packets to the
> +  attached port, clones them, and forwards the cloned packets to the mirror
> +  target port.
> +
> +- A priority 0 flow is added which matches on all packets and applies the
> +  action ``next;``.
> +
> +- A logical flow added for each Mirror Rule in Mirror table attached to 
> logical
> +  switch ports, matches all incoming packets that match rules and clones the
> +  packet and sends cloned packet to mirror target port.
> +
> +.. _ls-in-1:
> +
> +Ingress Table 1: Admission Control and Ingress Port Security check
>  ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
>  
> -Ingress table 0 contains these logical flows:
> +Ingress table 1 contains these logical flows:
>  
>  - Priority 100 flows to drop packets with VLAN tags or multicast Ethernet 
> source
>    addresses.
> @@ -61,9 +80,9 @@ Ingress table 0 contains these logical flows:
>    applies the port security rules defined in the ``port_security`` column of
>    ``Logical_Switch_Port`` table.
>  
> -.. _ls-in-1:
> +.. _ls-in-2:
>  
> -Ingress Table 1: Ingress Port Security - Apply
> +Ingress Table 2: Ingress Port Security - Apply
>  ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
>  
>  For each logical switch port *P* of type router connected to a gw router a
> @@ -98,25 +117,6 @@ Ingress table 1 contains these logical flows:
>  - One priority-0 fallback flow that matches all packets and advances to the 
> next
>    table.
>  
> -.. _ls-in-2:
> -
> -Ingress Table 2: Mirror
> -~~~~~~~~~~~~~~~~~~~~~~~~
> -
> -Overlay remote mirror table contains the following logical flows:
> -
> -- For each logical switch port with an attached mirror, a logical flow with a
> -  priority of 100 is added. This flow matches all incoming packets to the
> -  attached port, clones them, and forwards the cloned packets to the mirror
> -  target port.
> -
> -- A priority 0 flow is added which matches on all packets and applies the 
> action
> -  ``next;``.
> -
> -- A logical flow added for each Mirror Rule in Mirror table attached to 
> logical
> -  switch ports, matches all incoming packets that match rules and clones the
> -  packet and sends cloned packet to mirror target port.
> -
>  .. _ls-in-3:
>  
>  Ingress Table 3: Lookup MAC address learning table
> @@ -1799,34 +1799,15 @@ This is similar to ingress table :ref:`ACL action 
> <ls-in-11>`.
>  
>  .. _ls-out-9:
>  
> -Egress Table 9: Mirror
> -~~~~~~~~~~~~~~~~~~~~~~~~
> -
> -Overlay remote mirror table contains the following logical flows:
> -
> -- For each logical switch port with an attached mirror, a logical flow with a
> -  priority of 100 is added. This flow matches all outcoming packets to the
> -  attached port, clones them, and forwards the cloned packets to the mirror
> -  target port.
> -
> -- A priority 0 flow is added which matches on all packets and applies the 
> action
> -  ``next;``.
> -
> -- A logical flow added for each Mirror Rule in Mirror table attached to 
> logical
> -  switch ports, matches all outcoming packets that match rules and clones the
> -  packet and sends cloned packet to mirror target port.
> -
> -.. _ls-out-10:
> -
> -Egress Table 10: ``to-lport`` QoS
> +Egress Table 9: ``to-lport`` QoS
>  ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
>  
>  This is similar to ingress table :ref:`QoS <ls-in-12>` except they apply to
>  ``to-lport`` QoS rules.
>  
> -.. _ls-out-11:
> +.. _ls-out-10:
>  
> -Egress Table 11: Pre Network Function
> +Egress Table 10: Pre Network Function
>  ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
>  
>  This stage selects the active network function from a 
> ``Network_Function_Group``
> @@ -1878,9 +1859,9 @@ support network function load balancing.
>  - In inline, vtap mode: A priority-0 flow that simply moves traffic to the 
> next
>    table.
>  
> -.. _ls-out-12:
> +.. _ls-out-11:
>  
> -Egress Table 12: Stateful
> +Egress Table 11: Stateful
>  ~~~~~~~~~~~~~~~~~~~~~~~~~~
>  
>  This is similar to ingress table :ref:`Stateful <ls-in-24>` except that there
> @@ -1898,9 +1879,9 @@ connection tracking.
>    when it comes out of the other port of the network function (required for
>    cross host traffic redirection for VLAN subnet).
>  
> -.. _ls-out-13:
> +.. _ls-out-12:
>  
> -Egress Table 13: Network Function
> +Egress Table 12: Network Function
>  ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
>  
>  This table handles request packets for ``to-lport`` ACLs and response packets
> @@ -1972,9 +1953,9 @@ in ``ct_label.nf_id`` during request processing.
>  - In inline, vtap mode: One priority-0 flow same as ingress :ref:`Network
>    Function <ls-in-25>`.
>  
> -.. _ls-out-14:
> +.. _ls-out-13:
>  
> -Egress Table 14: Egress Port Security - check
> +Egress Table 13: Egress Port Security - check
>  ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
>  
>  This is similar to the port security logic in table :ref:`Ingress Port 
> Security
> @@ -1994,9 +1975,9 @@ port security rules.  This table adds the below logical 
> flows.
>    addresses defined in the ``port_security`` column of 
> ``Logical_Switch_Port``
>    table before delivering the packet to the ``outport``.
>  
> -.. _ls-out-15:
> +.. _ls-out-14:
>  
> -Egress Table 15: Egress Port Security - Apply
> +Egress Table 14: Egress Port Security - Apply
>  ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
>  
>  This is similar to the ingress port security logic in ingress table
> @@ -2024,6 +2005,26 @@ The following flows are added.
>  
>  - A priority-0 flow that outputs the packet to the ``outport``.
>  
> +.. _ls-out-15:
> +
> +Egress Table 15: Mirror
> +~~~~~~~~~~~~~~~~~~~~~~~~
> +
> +Overlay remote mirror table contains the following logical flows:
> +
> +- For each logical switch port with an attached mirror, a logical flow with a
> +  priority of 100 is added. This flow matches all outcoming packets to the
> +  attached port, clones them, and forwards the cloned packets to the mirror
> +  target port.
> +
> +- A priority 0 flow is added which matches on all packets and applies the
> +  action ``output;``.
> +
> +- A logical flow added for each Mirror Rule in Mirror table attached to 
> logical
> +  switch ports, matches all outcoming packets that match rules and clones the
> +  packet and sends cloned packet to mirror target port.
> +
> +
>  .. _lr-datapaths:
>  
>  Logical Router Datapaths
> diff --git a/NEWS b/NEWS
> index f1c56dd14..ddd013268 100644
> --- a/NEWS
> +++ b/NEWS
> @@ -129,6 +129,12 @@ OVN v26.09.0 - xxx xx xxxx
>       represent a logical router port (e.g. ovn-ic transit switch LSPs).
>       Such ports are treated like type=router, including omission from
>       _MC_flood_l2.
> +   - Mirrors of type "lport" now mirror the traffic that is really present
> +     on the logical port: "from-lport" traffic is mirrored in the first
> +     ingress table, before port security, and "to-lport" traffic in the last
> +     egress table, after port security.  Packets dropped by ingress port
> +     security are now mirrored, while packets dropped by egress port
> +     security are not mirrored anymore.
>  
>  OVN v26.03.0 - xxx xx xxxx
>  --------------------------
> diff --git a/lib/ovn-util.c b/lib/ovn-util.c
> index eb1fa8a06..fd9b40563 100644
> --- a/lib/ovn-util.c
> +++ b/lib/ovn-util.c
> @@ -1007,8 +1007,8 @@ ip_address_and_port_from_lb_key(const char *key, char 
> **ip_address,
>   *
>   * NOTE: If OVN_NORTHD_PIPELINE_CSUM is updated make sure to double check
>   * whether an update of OVN_INTERNAL_MINOR_VER is required. */
> -#define OVN_NORTHD_PIPELINE_CSUM "3980195012 11262"
> -#define OVN_INTERNAL_MINOR_VER 16
> +#define OVN_NORTHD_PIPELINE_CSUM "451923473 11267"
> +#define OVN_INTERNAL_MINOR_VER 17
>  
>  /* Returns the OVN version. The caller must free the returned value. */
>  char *
> diff --git a/northd/northd.c b/northd/northd.c
> index 4eb2ea44b..43f1f052b 100644
> --- a/northd/northd.c
> +++ b/northd/northd.c
> @@ -6402,7 +6402,7 @@ build_mirror_default_lflow(struct ovn_datapath *od,
>                             struct lflow_table *lflows)
>  {
>      ovn_lflow_add(lflows, od, S_SWITCH_IN_MIRROR, 0, "1", "next;", NULL);
> -    ovn_lflow_add(lflows, od, S_SWITCH_OUT_MIRROR, 0, "1", "next;", NULL);
> +    ovn_lflow_add(lflows, od, S_SWITCH_OUT_MIRROR, 0, "1", "output;", NULL);
>  }
>  
>  static void
> @@ -6429,7 +6429,7 @@ build_mirror_lflow(struct ovn_port *op,
>          stage = S_SWITCH_IN_MIRROR;
>      }
>  
> -    ds_put_cstr(&action, "next;");
> +    ds_put_cstr(&action, egress ? "output;" : "next;");
>      ds_put_format(&match, "%s == %s && (%s)", dir, op->json_key, 
> rule->match);
>      ovn_lflow_add(lflows, op->od, stage, priority, ds_cstr(&match),
>                    ds_cstr(&action), op->lflow_ref);
> @@ -6456,7 +6456,8 @@ build_mirror_pass_lflow(struct ovn_port *op,
>          stage = S_SWITCH_IN_MIRROR;
>      }
>  
> -    ds_put_format(&action, "mirror(%s); next;", serving_port->json_key);
> +    ds_put_format(&action, "mirror(%s); %s", serving_port->json_key,
> +                  egress ? "output;" : "next;");
>      ds_put_format(&match, "%s == %s", dir, op->json_key);
>      ovn_lflow_add(lflows, op->od, stage, OVN_LPORT_MIRROR_OFFSET,
>                    ds_cstr(&match), ds_cstr(&action), op->lflow_ref);
> @@ -6591,7 +6592,7 @@ build_lswitch_port_sec_op(struct ovn_port *op, struct 
> lflow_table *lflows,
>          }
>  
>          ds_clear(actions);
> -        ds_put_format(actions, "set_queue(%s); output;", queue_id);
> +        ds_put_format(actions, "set_queue(%s); next;", queue_id);
>  
>          ds_clear(match);
>          if (lsp_is_localnet(op->nbsp)) {
> @@ -6701,7 +6702,7 @@ build_lswitch_output_port_sec_od(struct ovn_datapath 
> *od,
>                    REGBIT_PORT_SEC_DROP" == 1", debug_drop_action(), 
> lflow_ref,
>                    WITH_DESC("Packet does not follow port security rules"));
>      ovn_lflow_add(lflows, od, S_SWITCH_OUT_APPLY_PORT_SEC, 0,
> -                  "1", "output;", lflow_ref);
> +                  "1", "next;", lflow_ref);
>  }
>  
>  static void
> diff --git a/northd/northd.h b/northd/northd.h
> index 9a74a4abc..c38e2e13c 100644
> --- a/northd/northd.h
> +++ b/northd/northd.h
> @@ -527,9 +527,9 @@ ls_has_localnet_port(const struct ovn_datapath *od)
>  
>  /* Logical switch ingress stages. */
>  #define SWITCH_IN_PIPELINE_STAGES                                            
> \
> -    PIPELINE_STAGE(SWITCH, IN,  CHECK_PORT_SEC, 0, "ls_in_check_port_sec")   
> \
> -    PIPELINE_STAGE(SWITCH, IN,  APPLY_PORT_SEC, 1, "ls_in_apply_port_sec")   
> \
> -    PIPELINE_STAGE(SWITCH, IN,  MIRROR,         2, "ls_in_mirror")        \
> +    PIPELINE_STAGE(SWITCH, IN,  MIRROR,         0, "ls_in_mirror")           
> \
> +    PIPELINE_STAGE(SWITCH, IN,  CHECK_PORT_SEC, 1, "ls_in_check_port_sec")   
> \
> +    PIPELINE_STAGE(SWITCH, IN,  APPLY_PORT_SEC, 2, "ls_in_apply_port_sec")   
> \
>      PIPELINE_STAGE(SWITCH, IN,  LOOKUP_FDB,     3, "ls_in_lookup_fdb")    \
>      PIPELINE_STAGE(SWITCH, IN,  PUT_FDB,        4, "ls_in_put_fdb")       \
>      PIPELINE_STAGE(SWITCH, IN,  PRE_ACL,        5, "ls_in_pre_acl")       \
> @@ -579,16 +579,15 @@ ls_has_localnet_port(const struct ovn_datapath *od)
>      PIPELINE_STAGE(SWITCH, OUT, ACL_EVAL,        6, "ls_out_acl_eval")       
> \
>      PIPELINE_STAGE(SWITCH, OUT, ACL_SAMPLE,      7, "ls_out_acl_sample")     
> \
>      PIPELINE_STAGE(SWITCH, OUT, ACL_ACTION,      8, "ls_out_acl_action")     
> \
> -    PIPELINE_STAGE(SWITCH, OUT, MIRROR,          9, "ls_out_mirror")         
> \
> -    PIPELINE_STAGE(SWITCH, OUT, QOS,            10, "ls_out_qos")            
> \
> -    PIPELINE_STAGE(SWITCH, OUT, PRE_NF,         11,                          
> \
> +    PIPELINE_STAGE(SWITCH, OUT, QOS,             9, "ls_out_qos")            
> \
> +    PIPELINE_STAGE(SWITCH, OUT, PRE_NF,         10,                          
> \
>                     "ls_out_pre_network_function")                            
> \
> -    PIPELINE_STAGE(SWITCH, OUT, STATEFUL,       12, "ls_out_stateful")       
> \
> -    PIPELINE_STAGE(SWITCH, OUT, NF,             13,                          
> \
> +    PIPELINE_STAGE(SWITCH, OUT, STATEFUL,       11, "ls_out_stateful")       
> \
> +    PIPELINE_STAGE(SWITCH, OUT, NF,             12,                          
> \
>                     "ls_out_network_function")                                
> \
> -    PIPELINE_STAGE(SWITCH, OUT, CHECK_PORT_SEC, 14, "ls_out_check_port_sec") 
> \
> -    PIPELINE_STAGE(SWITCH, OUT, APPLY_PORT_SEC, 15, "ls_out_apply_port_sec")
> -
> +    PIPELINE_STAGE(SWITCH, OUT, CHECK_PORT_SEC, 13, "ls_out_check_port_sec") 
> \
> +    PIPELINE_STAGE(SWITCH, OUT, APPLY_PORT_SEC, 14, "ls_out_apply_port_sec") 
> \
> +    PIPELINE_STAGE(SWITCH, OUT, MIRROR,         15, "ls_out_mirror")         
> \
>  /* Logical router ingress stages. */
>  #define ROUTER_IN_PIPELINE_STAGES                                         \
>      PIPELINE_STAGE(ROUTER, IN,  ADMISSION,       0, "lr_in_admission")    \
> diff --git a/ovn-nb.xml b/ovn-nb.xml
> index 078bd6068..5f39acb5c 100644
> --- a/ovn-nb.xml
> +++ b/ovn-nb.xml
> @@ -3960,6 +3960,18 @@ or
>          <code>from-lport</code> mirrors the packets going out of logical 
> port.
>          <code>both</code> mirrors for both directions.
>        </p>
> +
> +      <p>
> +        For mirrors of <var>type</var> <code>lport</code>, mirroring is
> +        done as close to the interface as possible, so that the mirror
> +        shows the traffic that is really present on that interface.
> +        Packets coming into the logical port (<code>to-lport</code>) are
> +        mirrored in the last egress table, that is, after ACLs, load
> +        balancing and port security have already been applied.  Packets
> +        going out of the logical port (<code>from-lport</code>) are
> +        mirrored the other way around, in the first ingress table, before
> +        any of those are applied.
> +      </p>
>      </column>
>  
>      <column name="sink">
> diff --git a/tests/ovn-northd.at b/tests/ovn-northd.at
> index 6572b1318..64e9873e5 100644
> --- a/tests/ovn-northd.at
> +++ b/tests/ovn-northd.at
> @@ -10339,7 +10339,7 @@ ovn_strip_lflows ], [0], [dnl
>    table=??(ls_in_l2_lkup      ), priority=72   , match=(eth.mcast && (nd_na 
> || nd_rs || nd_ra)), action=(outport = "_MC_flood"; output;)
>    table=??(ls_in_l2_unknown   ), priority=0    , match=(1), action=(output;)
>    table=??(ls_in_l2_unknown   ), priority=50   , match=(outport == "none"), 
> action=(drop;)
> -  table=??(ls_out_apply_port_sec), priority=0    , match=(1), 
> action=(output;)
> +  table=??(ls_out_apply_port_sec), priority=0    , match=(1), action=(next;)
>    table=??(ls_out_apply_port_sec), priority=50   , match=(reg0[[15]] == 1), 
> action=(drop;)
>    table=??(ls_out_check_port_sec), priority=0    , match=(1), 
> action=(reg0[[15]] = check_out_port_sec(); next;)
>    table=??(ls_out_check_port_sec), priority=100  , match=(eth.mcast), 
> action=(reg0[[15]] = 0; next;)
> @@ -10377,7 +10377,7 @@ ovn_strip_lflows ], [0], [dnl
>    table=??(ls_in_l2_lkup      ), priority=72   , match=(eth.mcast && (nd_na 
> || nd_rs || nd_ra)), action=(outport = "_MC_flood"; output;)
>    table=??(ls_in_l2_unknown   ), priority=0    , match=(1), action=(output;)
>    table=??(ls_in_l2_unknown   ), priority=50   , match=(outport == "none"), 
> action=(drop;)
> -  table=??(ls_out_apply_port_sec), priority=0    , match=(1), 
> action=(output;)
> +  table=??(ls_out_apply_port_sec), priority=0    , match=(1), action=(next;)
>    table=??(ls_out_apply_port_sec), priority=50   , match=(reg0[[15]] == 1), 
> action=(drop;)
>    table=??(ls_out_check_port_sec), priority=0    , match=(1), 
> action=(reg0[[15]] = check_out_port_sec(); next;)
>    table=??(ls_out_check_port_sec), priority=100  , match=(eth.mcast), 
> action=(reg0[[15]] = 0; next;)
> @@ -10414,7 +10414,7 @@ ovn_strip_lflows ], [0], [dnl
>    table=??(ls_in_l2_lkup      ), priority=72   , match=(eth.mcast && (nd_na 
> || nd_rs || nd_ra)), action=(outport = "_MC_flood"; output;)
>    table=??(ls_in_l2_unknown   ), priority=0    , match=(1), action=(output;)
>    table=??(ls_in_l2_unknown   ), priority=50   , match=(outport == "none"), 
> action=(drop;)
> -  table=??(ls_out_apply_port_sec), priority=0    , match=(1), 
> action=(output;)
> +  table=??(ls_out_apply_port_sec), priority=0    , match=(1), action=(next;)
>    table=??(ls_out_apply_port_sec), priority=50   , match=(reg0[[15]] == 1), 
> action=(drop;)
>    table=??(ls_out_check_port_sec), priority=0    , match=(1), 
> action=(reg0[[15]] = check_out_port_sec(); next;)
>    table=??(ls_out_check_port_sec), priority=100  , match=(eth.mcast), 
> action=(reg0[[15]] = 0; next;)
> @@ -10453,7 +10453,7 @@ ovn_strip_lflows ], [0], [dnl
>    table=??(ls_in_l2_unknown   ), priority=0    , match=(1), action=(output;)
>    table=??(ls_in_l2_unknown   ), priority=50   , match=(outport == "none"), 
> action=(drop;)
>    table=??(ls_in_l2_unknown   ), priority=50   , match=(outport == "sw0p1"), 
> action=(drop;)
> -  table=??(ls_out_apply_port_sec), priority=0    , match=(1), 
> action=(output;)
> +  table=??(ls_out_apply_port_sec), priority=0    , match=(1), action=(next;)
>    table=??(ls_out_apply_port_sec), priority=50   , match=(reg0[[15]] == 1), 
> action=(drop;)
>    table=??(ls_out_check_port_sec), priority=0    , match=(1), 
> action=(reg0[[15]] = check_out_port_sec(); next;)
>    table=??(ls_out_check_port_sec), priority=100  , match=(eth.mcast), 
> action=(reg0[[15]] = 0; next;)
> @@ -10491,8 +10491,8 @@ ovn_strip_lflows ], [0], [dnl
>    table=??(ls_in_l2_unknown   ), priority=0    , match=(1), action=(output;)
>    table=??(ls_in_l2_unknown   ), priority=50   , match=(outport == "none"), 
> action=(drop;)
>    table=??(ls_in_l2_unknown   ), priority=50   , match=(outport == "sw0p1"), 
> action=(drop;)
> -  table=??(ls_out_apply_port_sec), priority=0    , match=(1), 
> action=(output;)
> -  table=??(ls_out_apply_port_sec), priority=110  , match=(outport == 
> "localnetport" && inport == "sw0p2"), action=(set_queue(10); output;)
> +  table=??(ls_out_apply_port_sec), priority=0    , match=(1), action=(next;)
> +  table=??(ls_out_apply_port_sec), priority=110  , match=(outport == 
> "localnetport" && inport == "sw0p2"), action=(set_queue(10); next;)
>    table=??(ls_out_apply_port_sec), priority=50   , match=(reg0[[15]] == 1), 
> action=(drop;)
>    table=??(ls_out_check_port_sec), priority=0    , match=(1), 
> action=(reg0[[15]] = check_out_port_sec(); next;)
>    table=??(ls_out_check_port_sec), priority=100  , match=(eth.mcast), 
> action=(reg0[[15]] = 0; next;)
> @@ -10532,9 +10532,9 @@ ovn_strip_lflows ], [0], [dnl
>    table=??(ls_in_l2_lkup      ), priority=72   , match=(eth.mcast && (nd_na 
> || nd_rs || nd_ra)), action=(outport = "_MC_flood"; output;)
>    table=??(ls_in_l2_unknown   ), priority=0    , match=(1), action=(output;)
>    table=??(ls_in_l2_unknown   ), priority=50   , match=(outport == "none"), 
> action=(drop;)
> -  table=??(ls_out_apply_port_sec), priority=0    , match=(1), 
> action=(output;)
> -  table=??(ls_out_apply_port_sec), priority=100  , match=(outport == 
> "localnetport"), action=(set_queue(10); output;)
> -  table=??(ls_out_apply_port_sec), priority=110  , match=(outport == 
> "localnetport" && inport == "sw0p2"), action=(set_queue(10); output;)
> +  table=??(ls_out_apply_port_sec), priority=0    , match=(1), action=(next;)
> +  table=??(ls_out_apply_port_sec), priority=100  , match=(outport == 
> "localnetport"), action=(set_queue(10); next;)
> +  table=??(ls_out_apply_port_sec), priority=110  , match=(outport == 
> "localnetport" && inport == "sw0p2"), action=(set_queue(10); next;)
>    table=??(ls_out_apply_port_sec), priority=50   , match=(reg0[[15]] == 1), 
> action=(drop;)
>    table=??(ls_out_check_port_sec), priority=0    , match=(1), 
> action=(reg0[[15]] = check_out_port_sec(); next;)
>    table=??(ls_out_check_port_sec), priority=100  , match=(eth.mcast), 
> action=(reg0[[15]] = 0; next;)
> @@ -20276,7 +20276,7 @@ ovn-sbctl lflow-list sw0 > lflow-list
>  
>  AT_CHECK([grep -e "ls_in_mirror" -e "ls_out_mirror" lflow-list | 
> ovn_strip_lflows], [0], [dnl
>    table=??(ls_in_mirror       ), priority=0    , match=(1), action=(next;)
> -  table=??(ls_out_mirror      ), priority=0    , match=(1), action=(next;)
> +  table=??(ls_out_mirror      ), priority=0    , match=(1), action=(output;)
>  ])
>  
>  check ovn-nbctl lsp-attach-mirror sw0-p1 mirror0
> @@ -20289,8 +20289,8 @@ check_column mirror Port_Binding type 
> logical_port=mp-sw0-sw0-target0
>  ovn-sbctl lflow-list sw0 > lflow-list
>  AT_CHECK([grep -e "ls_in_mirror" -e "ls_out_mirror" lflow-list | 
> ovn_strip_lflows], [0], [dnl
>    table=??(ls_in_mirror       ), priority=0    , match=(1), action=(next;)
> -  table=??(ls_out_mirror      ), priority=0    , match=(1), action=(next;)
> -  table=??(ls_out_mirror      ), priority=100  , match=(outport == 
> "sw0-p1"), action=(mirror("mp-sw0-sw0-target0"); next;)
> +  table=??(ls_out_mirror      ), priority=0    , match=(1), action=(output;)
> +  table=??(ls_out_mirror      ), priority=100  , match=(outport == 
> "sw0-p1"), action=(mirror("mp-sw0-sw0-target0"); output;)
>  ])
>  
>  ovn-sbctl lflow-list sw0 > lflow-list
> @@ -20312,10 +20312,10 @@ AT_CHECK([grep -e "ls_in_mirror" -e "ls_out_mirror" 
> lflow-list | ovn_strip_lflow
>    table=??(ls_in_mirror       ), priority=100  , match=(inport == "sw0-p1"), 
> action=(mirror("mp-sw0-sw0-target0"); next;)
>    table=??(ls_in_mirror       ), priority=200  , match=(inport == "sw0-p1" 
> && (ip)), action=(mirror("mp-sw0-sw0-target0"); next;)
>    table=??(ls_in_mirror       ), priority=250  , match=(inport == "sw0-p1" 
> && (icmp)), action=(next;)
> -  table=??(ls_out_mirror      ), priority=0    , match=(1), action=(next;)
> -  table=??(ls_out_mirror      ), priority=100  , match=(outport == 
> "sw0-p1"), action=(mirror("mp-sw0-sw0-target0"); next;)
> -  table=??(ls_out_mirror      ), priority=200  , match=(outport == "sw0-p1" 
> && (ip)), action=(mirror("mp-sw0-sw0-target0"); next;)
> -  table=??(ls_out_mirror      ), priority=250  , match=(outport == "sw0-p1" 
> && (icmp)), action=(next;)
> +  table=??(ls_out_mirror      ), priority=0    , match=(1), action=(output;)
> +  table=??(ls_out_mirror      ), priority=100  , match=(outport == 
> "sw0-p1"), action=(mirror("mp-sw0-sw0-target0"); output;)
> +  table=??(ls_out_mirror      ), priority=200  , match=(outport == "sw0-p1" 
> && (ip)), action=(mirror("mp-sw0-sw0-target0"); output;)
> +  table=??(ls_out_mirror      ), priority=250  , match=(outport == "sw0-p1" 
> && (icmp)), action=(output;)
>  ])
>  
>  check ovn-nbctl lsp-attach-mirror sw0-p1 mirror2
> @@ -20334,10 +20334,10 @@ AT_CHECK([grep -e "ls_in_mirror" -e "ls_out_mirror" 
> lflow-list | ovn_strip_lflow
>    table=??(ls_in_mirror       ), priority=200  , match=(inport == "sw0-p1" 
> && (ip4.dst == 192.168.0.1)), action=(mirror("mp-sw0-sw1-target1"); next;)
>    table=??(ls_in_mirror       ), priority=250  , match=(inport == "sw0-p1" 
> && (1)), action=(next;)
>    table=??(ls_in_mirror       ), priority=250  , match=(inport == "sw0-p1" 
> && (icmp)), action=(next;)
> -  table=??(ls_out_mirror      ), priority=0    , match=(1), action=(next;)
> -  table=??(ls_out_mirror      ), priority=100  , match=(outport == 
> "sw0-p1"), action=(mirror("mp-sw0-sw0-target0"); next;)
> -  table=??(ls_out_mirror      ), priority=200  , match=(outport == "sw0-p1" 
> && (ip)), action=(mirror("mp-sw0-sw0-target0"); next;)
> -  table=??(ls_out_mirror      ), priority=250  , match=(outport == "sw0-p1" 
> && (icmp)), action=(next;)
> +  table=??(ls_out_mirror      ), priority=0    , match=(1), action=(output;)
> +  table=??(ls_out_mirror      ), priority=100  , match=(outport == 
> "sw0-p1"), action=(mirror("mp-sw0-sw0-target0"); output;)
> +  table=??(ls_out_mirror      ), priority=200  , match=(outport == "sw0-p1" 
> && (ip)), action=(mirror("mp-sw0-sw0-target0"); output;)
> +  table=??(ls_out_mirror      ), priority=250  , match=(outport == "sw0-p1" 
> && (icmp)), action=(output;)
>  ])
>  
>  ovn-sbctl lflow-list sw0 > lflow-list
> @@ -20360,7 +20360,7 @@ AT_CHECK([grep -e "ls_in_mirror" -e "ls_out_mirror" 
> lflow-list | ovn_strip_lflow
>    table=??(ls_in_mirror       ), priority=100  , match=(inport == "sw0-p1"), 
> action=(mirror("mp-sw0-sw1-target1"); next;)
>    table=??(ls_in_mirror       ), priority=200  , match=(inport == "sw0-p1" 
> && (ip4.dst == 192.168.0.1)), action=(mirror("mp-sw0-sw1-target1"); next;)
>    table=??(ls_in_mirror       ), priority=250  , match=(inport == "sw0-p1" 
> && (1)), action=(next;)
> -  table=??(ls_out_mirror      ), priority=0    , match=(1), action=(next;)
> +  table=??(ls_out_mirror      ), priority=0    , match=(1), action=(output;)
>  ])
>  
>  AT_CHECK([grep -e "ls_out_pre_acl" lflow-list | ovn_strip_lflows], [0], [dnl
> @@ -20385,10 +20385,10 @@ AT_CHECK([grep -e "ls_in_mirror" -e "ls_out_mirror" 
> lflow-list | ovn_strip_lflow
>    table=??(ls_in_mirror       ), priority=200  , match=(inport == "sw0-p1" 
> && (ip4.dst == 192.168.0.1)), action=(mirror("mp-sw0-sw1-target1"); next;)
>    table=??(ls_in_mirror       ), priority=250  , match=(inport == "sw0-p1" 
> && (1)), action=(next;)
>    table=??(ls_in_mirror       ), priority=250  , match=(inport == "sw0-p1" 
> && (icmp)), action=(next;)
> -  table=??(ls_out_mirror      ), priority=0    , match=(1), action=(next;)
> -  table=??(ls_out_mirror      ), priority=100  , match=(outport == 
> "sw0-p1"), action=(mirror("mp-sw0-sw0-target0"); next;)
> -  table=??(ls_out_mirror      ), priority=200  , match=(outport == "sw0-p1" 
> && (ip)), action=(mirror("mp-sw0-sw0-target0"); next;)
> -  table=??(ls_out_mirror      ), priority=250  , match=(outport == "sw0-p1" 
> && (icmp)), action=(next;)
> +  table=??(ls_out_mirror      ), priority=0    , match=(1), action=(output;)
> +  table=??(ls_out_mirror      ), priority=100  , match=(outport == 
> "sw0-p1"), action=(mirror("mp-sw0-sw0-target0"); output;)
> +  table=??(ls_out_mirror      ), priority=200  , match=(outport == "sw0-p1" 
> && (ip)), action=(mirror("mp-sw0-sw0-target0"); output;)
> +  table=??(ls_out_mirror      ), priority=250  , match=(outport == "sw0-p1" 
> && (icmp)), action=(output;)
>  ])
>  
>  mirror1uuid_uuid=`ovn-nbctl --bare --columns _uuid find Mirror 
> name="mirror1"`
> @@ -20405,11 +20405,11 @@ AT_CHECK([grep -e "ls_in_mirror" -e "ls_out_mirror" 
> lflow-list | ovn_strip_lflow
>    table=??(ls_in_mirror       ), priority=200  , match=(inport == "sw0-p1" 
> && (ip4.dst == 192.168.0.1)), action=(mirror("mp-sw0-sw1-target1"); next;)
>    table=??(ls_in_mirror       ), priority=250  , match=(inport == "sw0-p1" 
> && (1)), action=(next;)
>    table=??(ls_in_mirror       ), priority=250  , match=(inport == "sw0-p1" 
> && (icmp)), action=(next;)
> -  table=??(ls_out_mirror      ), priority=0    , match=(1), action=(next;)
> -  table=??(ls_out_mirror      ), priority=100  , match=(outport == 
> "sw0-p1"), action=(mirror("mp-sw0-sw0-target0"); next;)
> -  table=??(ls_out_mirror      ), priority=100  , match=(outport == 
> "sw0-p1"), action=(mirror("mp-sw0-sw1-target1"); next;)
> -  table=??(ls_out_mirror      ), priority=200  , match=(outport == "sw0-p1" 
> && (ip)), action=(mirror("mp-sw0-sw1-target1"); next;)
> -  table=??(ls_out_mirror      ), priority=250  , match=(outport == "sw0-p1" 
> && (icmp)), action=(next;)
> +  table=??(ls_out_mirror      ), priority=0    , match=(1), action=(output;)
> +  table=??(ls_out_mirror      ), priority=100  , match=(outport == 
> "sw0-p1"), action=(mirror("mp-sw0-sw0-target0"); output;)
> +  table=??(ls_out_mirror      ), priority=100  , match=(outport == 
> "sw0-p1"), action=(mirror("mp-sw0-sw1-target1"); output;)
> +  table=??(ls_out_mirror      ), priority=200  , match=(outport == "sw0-p1" 
> && (ip)), action=(mirror("mp-sw0-sw1-target1"); output;)
> +  table=??(ls_out_mirror      ), priority=250  , match=(outport == "sw0-p1" 
> && (icmp)), action=(output;)
>  ])
>  
>  check_row_count Port_Binding 1 logical_port=mp-sw0-sw0-target0
> @@ -20425,7 +20425,7 @@ check ovn-nbctl --wait=sb sync
>  ovn-sbctl lflow-list sw0 > lflow-list
>  AT_CHECK([grep -e "ls_in_mirror" -e "ls_out_mirror" lflow-list | 
> ovn_strip_lflows], [0], [dnl
>    table=??(ls_in_mirror       ), priority=0    , match=(1), action=(next;)
> -  table=??(ls_out_mirror      ), priority=0    , match=(1), action=(next;)
> +  table=??(ls_out_mirror      ), priority=0    , match=(1), action=(output;)
>  ])
>  
>  ovn-sbctl lflow-list sw0 > lflow-list
> diff --git a/tests/ovn-util.at b/tests/ovn-util.at
> index 315539342..aecf908ef 100644
> --- a/tests/ovn-util.at
> +++ b/tests/ovn-util.at
> @@ -78,7 +78,7 @@ AT_CHECK_UNQUOTED([cat trace | $PYTHON 
> $top_srcdir/utilities/ovn_detrace.py.in],
>          resubmit(,??)
>        * Logical datapaths:
>        *     "ls" ($dp_uuid) [[egress]]
> -      * Logical flow: table=$egress_table (ls_out_apply_port_sec), 
> priority=0, match=(1), actions=(output;)
> +      * Logical flow: table=$egress_table (ls_out_apply_port_sec), 
> priority=0, match=(1), actions=(next;)
>          65. reg15=0x2,metadata=0x1, priority 100, cookie $pb_vm1
>              output:2
>            * Logical datapath: "ls" ($dp_uuid)
> @@ -99,7 +99,7 @@ cookie=$ingress, priority=50,metadata=0x1 
> actions=load:0->NXM_NX_REG10[[12]],res
>  cookie=$egress, priority=0,metadata=0x1 actions=resubmit(,??)
>    * Logical datapaths:
>    *     "ls" ($dp_uuid) [[egress]]
> -  * Logical flow: table=$egress_table (ls_out_apply_port_sec), priority=0, 
> match=(1), actions=(output;)
> +  * Logical flow: table=$egress_table (ls_out_apply_port_sec), priority=0, 
> match=(1), actions=(next;)
>  
>  ])
>  
> diff --git a/tests/ovn.at b/tests/ovn.at
> index 13e95f9db..2c90c5ce4 100644
> --- a/tests/ovn.at
> +++ b/tests/ovn.at
> @@ -19593,8 +19593,8 @@ check_column "$hv3_uuid" sb:Port_Binding chassis 
> logical_port=mp-ls1-ls2-lp2
>  AT_CHECK([ovn-sbctl lflow-list ls1 | grep mirror| ovn_strip_lflows], [0], 
> [dnl
>    table=??(ls_in_mirror       ), priority=0    , match=(1), action=(next;)
>    table=??(ls_in_mirror       ), priority=100  , match=(inport == 
> "ls1-lp1"), action=(mirror("mp-ls1-ls2-lp2"); next;)
> -  table=??(ls_out_mirror      ), priority=0    , match=(1), action=(next;)
> -  table=??(ls_out_mirror      ), priority=100  , match=(outport == 
> "ls1-lp1"), action=(mirror("mp-ls1-ls2-lp2"); next;)
> +  table=??(ls_out_mirror      ), priority=0    , match=(1), action=(output;)
> +  table=??(ls_out_mirror      ), priority=100  , match=(outport == 
> "ls1-lp1"), action=(mirror("mp-ls1-ls2-lp2"); output;)
>  ])
>  
>  as hv2 reset_pcap_file hv2-vif1 hv2/vif1
> @@ -19644,7 +19644,7 @@ check_row_count Port_Binding 0 
> logical_port=mp-ls1-ls2-lp2
>  
>  AT_CHECK([ovn-sbctl lflow-list ls1 | grep mirror| ovn_strip_lflows], [0], 
> [dnl
>    table=??(ls_in_mirror       ), priority=0    , match=(1), action=(next;)
> -  table=??(ls_out_mirror      ), priority=0    , match=(1), action=(next;)
> +  table=??(ls_out_mirror      ), priority=0    , match=(1), action=(output;)
>  ])
>  
>  as hv3 reset_pcap_file hv3-vif1 hv3/vif1
> @@ -19679,9 +19679,9 @@ AT_CHECK([ovn-sbctl lflow-list ls1 | grep mirror | 
> ovn_strip_lflows], [0], [dnl
>    table=??(ls_in_mirror       ), priority=0    , match=(1), action=(next;)
>    table=??(ls_in_mirror       ), priority=100  , match=(inport == 
> "ls1-lp1"), action=(mirror("mp-ls1-ls2-lp2"); next;)
>    table=??(ls_in_mirror       ), priority=300  , match=(inport == "ls1-lp1" 
> && (1)), action=(next;)
> -  table=??(ls_out_mirror      ), priority=0    , match=(1), action=(next;)
> -  table=??(ls_out_mirror      ), priority=100  , match=(outport == 
> "ls1-lp1"), action=(mirror("mp-ls1-ls2-lp2"); next;)
> -  table=??(ls_out_mirror      ), priority=300  , match=(outport == "ls1-lp1" 
> && (1)), action=(next;)
> +  table=??(ls_out_mirror      ), priority=0    , match=(1), action=(output;)
> +  table=??(ls_out_mirror      ), priority=100  , match=(outport == 
> "ls1-lp1"), action=(mirror("mp-ls1-ls2-lp2"); output;)
> +  table=??(ls_out_mirror      ), priority=300  , match=(outport == "ls1-lp1" 
> && (1)), action=(output;)
>  ])
>  
>  AT_CHECK([ovn-sbctl lflow-list ls1 | grep ls_out_pre_acl | 
> ovn_strip_lflows], [0], [dnl
> @@ -19694,7 +19694,7 @@ AT_CHECK([ovn-sbctl lflow-list ls1 | grep 
> ls_out_pre_acl | ovn_strip_lflows], [0
>  check ovn-nbctl --wait=sb lsp-del ls2-lp2
>  AT_CHECK([ovn-sbctl lflow-list ls1 | grep mirror | ovn_strip_lflows], [0], 
> [dnl
>    table=??(ls_in_mirror       ), priority=0    , match=(1), action=(next;)
> -  table=??(ls_out_mirror      ), priority=0    , match=(1), action=(next;)
> +  table=??(ls_out_mirror      ), priority=0    , match=(1), action=(output;)
>  ])
>  
>  check ovn-nbctl lsp-add ls2 ls2-lp2
> @@ -19717,10 +19717,10 @@ AT_CHECK([ovn-sbctl lflow-list ls1 | grep mirror| 
> ovn_strip_lflows], [0], [dnl
>    table=??(ls_in_mirror       ), priority=100  , match=(inport == 
> "ls1-lp1"), action=(mirror("mp-ls1-ls2-lp2"); next;)
>    table=??(ls_in_mirror       ), priority=300  , match=(inport == "ls1-lp1" 
> && (1)), action=(next;)
>    table=??(ls_in_mirror       ), priority=400  , match=(inport == "ls1-lp1" 
> && (udp.dst == 4369)), action=(mirror("mp-ls1-ls2-lp2"); next;)
> -  table=??(ls_out_mirror      ), priority=0    , match=(1), action=(next;)
> -  table=??(ls_out_mirror      ), priority=100  , match=(outport == 
> "ls1-lp1"), action=(mirror("mp-ls1-ls2-lp2"); next;)
> -  table=??(ls_out_mirror      ), priority=300  , match=(outport == "ls1-lp1" 
> && (1)), action=(next;)
> -  table=??(ls_out_mirror      ), priority=400  , match=(outport == "ls1-lp1" 
> && (udp.dst == 4369)), action=(mirror("mp-ls1-ls2-lp2"); next;)
> +  table=??(ls_out_mirror      ), priority=0    , match=(1), action=(output;)
> +  table=??(ls_out_mirror      ), priority=100  , match=(outport == 
> "ls1-lp1"), action=(mirror("mp-ls1-ls2-lp2"); output;)
> +  table=??(ls_out_mirror      ), priority=300  , match=(outport == "ls1-lp1" 
> && (1)), action=(output;)
> +  table=??(ls_out_mirror      ), priority=400  , match=(outport == "ls1-lp1" 
> && (udp.dst == 4369)), action=(mirror("mp-ls1-ls2-lp2"); output;)
>  ])
>  
>  AT_CHECK([ovn-sbctl lflow-list ls1 | grep ls_out_pre_acl | 
> ovn_strip_lflows], [0], [dnl

-- 
Rosemarie O'Riorden
Boston & Lowell, MA, USA
[email protected]

_______________________________________________
dev mailing list
[email protected]
https://mail.openvswitch.org/mailman/listinfo/ovs-dev

Reply via email to