Hi Alexandra! This change makes sense to me. Here are some minor comments. On 9/25/26 9:57 AM, Alexandra Rukomoinikova via dev wrote: > Mirroring of type "lport" was done after ingress port security and > before egress port security, so the mirror did not show the traffic > that was really present on the port. For example, if a VM is > compromised and sends packets with a spoofed source MAC, port security > drops them and they never reach the mirror target, although this is > exactly the traffic one would want to see.
An example could also be added for the egress case. > > Mirror the traffic as close to the interface as possible, so that the > mirror target sees what the port actually sends and receives. > > Signed-off-by: Alexandra Rukomoinikova <[email protected]> Since this is basically a fix for your previous patch which added lport mirroring, and thus decided the pipeline ordering, I think it would make sense to add the Fixes tag: Fixes: 2a2fe266d09c ("northd: Added support for port mirroring in OVN overlay.") Everything else below looks good to me, but I'm open to other input. > --- > Documentation/ref/ovn-logical-flows.7.rst | 107 +++++++++++----------- > NEWS | 6 ++ > lib/ovn-util.c | 4 +- > northd/northd.c | 11 ++- > northd/northd.h | 21 ++--- > ovn-nb.xml | 12 +++ > tests/ovn-northd.at | 62 ++++++------- > tests/ovn-util.at | 4 +- > tests/ovn.at | 22 ++--- > 9 files changed, 134 insertions(+), 115 deletions(-) > > diff --git a/Documentation/ref/ovn-logical-flows.7.rst > b/Documentation/ref/ovn-logical-flows.7.rst > index 44fd560bf..a1cfeea6d 100644 > --- a/Documentation/ref/ovn-logical-flows.7.rst > +++ b/Documentation/ref/ovn-logical-flows.7.rst > @@ -16,10 +16,29 @@ Logical Switch Datapaths > > .. _ls-in-0: > > -Ingress Table 0: Admission Control and Ingress Port Security check > +Ingress Table 0: Mirror > +~~~~~~~~~~~~~~~~~~~~~~~~ > + > +Overlay remote mirror table contains the following logical flows: > + > +- For each logical switch port with an attached mirror, a logical flow with a > + priority of 100 is added. This flow matches all incoming packets to the > + attached port, clones them, and forwards the cloned packets to the mirror > + target port. > + > +- A priority 0 flow is added which matches on all packets and applies the > + action ``next;``. > + > +- A logical flow added for each Mirror Rule in Mirror table attached to > logical > + switch ports, matches all incoming packets that match rules and clones the > + packet and sends cloned packet to mirror target port. > + > +.. _ls-in-1: > + > +Ingress Table 1: Admission Control and Ingress Port Security check > ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ > > -Ingress table 0 contains these logical flows: > +Ingress table 1 contains these logical flows: > > - Priority 100 flows to drop packets with VLAN tags or multicast Ethernet > source > addresses. > @@ -61,9 +80,9 @@ Ingress table 0 contains these logical flows: > applies the port security rules defined in the ``port_security`` column of > ``Logical_Switch_Port`` table. > > -.. _ls-in-1: > +.. _ls-in-2: > > -Ingress Table 1: Ingress Port Security - Apply > +Ingress Table 2: Ingress Port Security - Apply > ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ > > For each logical switch port *P* of type router connected to a gw router a > @@ -98,25 +117,6 @@ Ingress table 1 contains these logical flows: > - One priority-0 fallback flow that matches all packets and advances to the > next > table. > > -.. _ls-in-2: > - > -Ingress Table 2: Mirror > -~~~~~~~~~~~~~~~~~~~~~~~~ > - > -Overlay remote mirror table contains the following logical flows: > - > -- For each logical switch port with an attached mirror, a logical flow with a > - priority of 100 is added. This flow matches all incoming packets to the > - attached port, clones them, and forwards the cloned packets to the mirror > - target port. > - > -- A priority 0 flow is added which matches on all packets and applies the > action > - ``next;``. > - > -- A logical flow added for each Mirror Rule in Mirror table attached to > logical > - switch ports, matches all incoming packets that match rules and clones the > - packet and sends cloned packet to mirror target port. > - > .. _ls-in-3: > > Ingress Table 3: Lookup MAC address learning table > @@ -1799,34 +1799,15 @@ This is similar to ingress table :ref:`ACL action > <ls-in-11>`. > > .. _ls-out-9: > > -Egress Table 9: Mirror > -~~~~~~~~~~~~~~~~~~~~~~~~ > - > -Overlay remote mirror table contains the following logical flows: > - > -- For each logical switch port with an attached mirror, a logical flow with a > - priority of 100 is added. This flow matches all outcoming packets to the > - attached port, clones them, and forwards the cloned packets to the mirror > - target port. > - > -- A priority 0 flow is added which matches on all packets and applies the > action > - ``next;``. > - > -- A logical flow added for each Mirror Rule in Mirror table attached to > logical > - switch ports, matches all outcoming packets that match rules and clones the > - packet and sends cloned packet to mirror target port. > - > -.. _ls-out-10: > - > -Egress Table 10: ``to-lport`` QoS > +Egress Table 9: ``to-lport`` QoS > ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ > > This is similar to ingress table :ref:`QoS <ls-in-12>` except they apply to > ``to-lport`` QoS rules. > > -.. _ls-out-11: > +.. _ls-out-10: > > -Egress Table 11: Pre Network Function > +Egress Table 10: Pre Network Function > ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ > > This stage selects the active network function from a > ``Network_Function_Group`` > @@ -1878,9 +1859,9 @@ support network function load balancing. > - In inline, vtap mode: A priority-0 flow that simply moves traffic to the > next > table. > > -.. _ls-out-12: > +.. _ls-out-11: > > -Egress Table 12: Stateful > +Egress Table 11: Stateful > ~~~~~~~~~~~~~~~~~~~~~~~~~~ > > This is similar to ingress table :ref:`Stateful <ls-in-24>` except that there > @@ -1898,9 +1879,9 @@ connection tracking. > when it comes out of the other port of the network function (required for > cross host traffic redirection for VLAN subnet). > > -.. _ls-out-13: > +.. _ls-out-12: > > -Egress Table 13: Network Function > +Egress Table 12: Network Function > ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ > > This table handles request packets for ``to-lport`` ACLs and response packets > @@ -1972,9 +1953,9 @@ in ``ct_label.nf_id`` during request processing. > - In inline, vtap mode: One priority-0 flow same as ingress :ref:`Network > Function <ls-in-25>`. > > -.. _ls-out-14: > +.. _ls-out-13: > > -Egress Table 14: Egress Port Security - check > +Egress Table 13: Egress Port Security - check > ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ > > This is similar to the port security logic in table :ref:`Ingress Port > Security > @@ -1994,9 +1975,9 @@ port security rules. This table adds the below logical > flows. > addresses defined in the ``port_security`` column of > ``Logical_Switch_Port`` > table before delivering the packet to the ``outport``. > > -.. _ls-out-15: > +.. _ls-out-14: > > -Egress Table 15: Egress Port Security - Apply > +Egress Table 14: Egress Port Security - Apply > ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ > > This is similar to the ingress port security logic in ingress table > @@ -2024,6 +2005,26 @@ The following flows are added. > > - A priority-0 flow that outputs the packet to the ``outport``. > > +.. _ls-out-15: > + > +Egress Table 15: Mirror > +~~~~~~~~~~~~~~~~~~~~~~~~ > + > +Overlay remote mirror table contains the following logical flows: > + > +- For each logical switch port with an attached mirror, a logical flow with a > + priority of 100 is added. This flow matches all outcoming packets to the > + attached port, clones them, and forwards the cloned packets to the mirror > + target port. > + > +- A priority 0 flow is added which matches on all packets and applies the > + action ``output;``. > + > +- A logical flow added for each Mirror Rule in Mirror table attached to > logical > + switch ports, matches all outcoming packets that match rules and clones the > + packet and sends cloned packet to mirror target port. > + > + > .. _lr-datapaths: > > Logical Router Datapaths > diff --git a/NEWS b/NEWS > index f1c56dd14..ddd013268 100644 > --- a/NEWS > +++ b/NEWS > @@ -129,6 +129,12 @@ OVN v26.09.0 - xxx xx xxxx > represent a logical router port (e.g. ovn-ic transit switch LSPs). > Such ports are treated like type=router, including omission from > _MC_flood_l2. > + - Mirrors of type "lport" now mirror the traffic that is really present > + on the logical port: "from-lport" traffic is mirrored in the first > + ingress table, before port security, and "to-lport" traffic in the last > + egress table, after port security. Packets dropped by ingress port > + security are now mirrored, while packets dropped by egress port > + security are not mirrored anymore. > > OVN v26.03.0 - xxx xx xxxx > -------------------------- > diff --git a/lib/ovn-util.c b/lib/ovn-util.c > index eb1fa8a06..fd9b40563 100644 > --- a/lib/ovn-util.c > +++ b/lib/ovn-util.c > @@ -1007,8 +1007,8 @@ ip_address_and_port_from_lb_key(const char *key, char > **ip_address, > * > * NOTE: If OVN_NORTHD_PIPELINE_CSUM is updated make sure to double check > * whether an update of OVN_INTERNAL_MINOR_VER is required. */ > -#define OVN_NORTHD_PIPELINE_CSUM "3980195012 11262" > -#define OVN_INTERNAL_MINOR_VER 16 > +#define OVN_NORTHD_PIPELINE_CSUM "451923473 11267" > +#define OVN_INTERNAL_MINOR_VER 17 > > /* Returns the OVN version. The caller must free the returned value. */ > char * > diff --git a/northd/northd.c b/northd/northd.c > index 4eb2ea44b..43f1f052b 100644 > --- a/northd/northd.c > +++ b/northd/northd.c > @@ -6402,7 +6402,7 @@ build_mirror_default_lflow(struct ovn_datapath *od, > struct lflow_table *lflows) > { > ovn_lflow_add(lflows, od, S_SWITCH_IN_MIRROR, 0, "1", "next;", NULL); > - ovn_lflow_add(lflows, od, S_SWITCH_OUT_MIRROR, 0, "1", "next;", NULL); > + ovn_lflow_add(lflows, od, S_SWITCH_OUT_MIRROR, 0, "1", "output;", NULL); > } > > static void > @@ -6429,7 +6429,7 @@ build_mirror_lflow(struct ovn_port *op, > stage = S_SWITCH_IN_MIRROR; > } > > - ds_put_cstr(&action, "next;"); > + ds_put_cstr(&action, egress ? "output;" : "next;"); > ds_put_format(&match, "%s == %s && (%s)", dir, op->json_key, > rule->match); > ovn_lflow_add(lflows, op->od, stage, priority, ds_cstr(&match), > ds_cstr(&action), op->lflow_ref); > @@ -6456,7 +6456,8 @@ build_mirror_pass_lflow(struct ovn_port *op, > stage = S_SWITCH_IN_MIRROR; > } > > - ds_put_format(&action, "mirror(%s); next;", serving_port->json_key); > + ds_put_format(&action, "mirror(%s); %s", serving_port->json_key, > + egress ? "output;" : "next;"); > ds_put_format(&match, "%s == %s", dir, op->json_key); > ovn_lflow_add(lflows, op->od, stage, OVN_LPORT_MIRROR_OFFSET, > ds_cstr(&match), ds_cstr(&action), op->lflow_ref); > @@ -6591,7 +6592,7 @@ build_lswitch_port_sec_op(struct ovn_port *op, struct > lflow_table *lflows, > } > > ds_clear(actions); > - ds_put_format(actions, "set_queue(%s); output;", queue_id); > + ds_put_format(actions, "set_queue(%s); next;", queue_id); > > ds_clear(match); > if (lsp_is_localnet(op->nbsp)) { > @@ -6701,7 +6702,7 @@ build_lswitch_output_port_sec_od(struct ovn_datapath > *od, > REGBIT_PORT_SEC_DROP" == 1", debug_drop_action(), > lflow_ref, > WITH_DESC("Packet does not follow port security rules")); > ovn_lflow_add(lflows, od, S_SWITCH_OUT_APPLY_PORT_SEC, 0, > - "1", "output;", lflow_ref); > + "1", "next;", lflow_ref); > } > > static void > diff --git a/northd/northd.h b/northd/northd.h > index 9a74a4abc..c38e2e13c 100644 > --- a/northd/northd.h > +++ b/northd/northd.h > @@ -527,9 +527,9 @@ ls_has_localnet_port(const struct ovn_datapath *od) > > /* Logical switch ingress stages. */ > #define SWITCH_IN_PIPELINE_STAGES > \ > - PIPELINE_STAGE(SWITCH, IN, CHECK_PORT_SEC, 0, "ls_in_check_port_sec") > \ > - PIPELINE_STAGE(SWITCH, IN, APPLY_PORT_SEC, 1, "ls_in_apply_port_sec") > \ > - PIPELINE_STAGE(SWITCH, IN, MIRROR, 2, "ls_in_mirror") \ > + PIPELINE_STAGE(SWITCH, IN, MIRROR, 0, "ls_in_mirror") > \ > + PIPELINE_STAGE(SWITCH, IN, CHECK_PORT_SEC, 1, "ls_in_check_port_sec") > \ > + PIPELINE_STAGE(SWITCH, IN, APPLY_PORT_SEC, 2, "ls_in_apply_port_sec") > \ > PIPELINE_STAGE(SWITCH, IN, LOOKUP_FDB, 3, "ls_in_lookup_fdb") \ > PIPELINE_STAGE(SWITCH, IN, PUT_FDB, 4, "ls_in_put_fdb") \ > PIPELINE_STAGE(SWITCH, IN, PRE_ACL, 5, "ls_in_pre_acl") \ > @@ -579,16 +579,15 @@ ls_has_localnet_port(const struct ovn_datapath *od) > PIPELINE_STAGE(SWITCH, OUT, ACL_EVAL, 6, "ls_out_acl_eval") > \ > PIPELINE_STAGE(SWITCH, OUT, ACL_SAMPLE, 7, "ls_out_acl_sample") > \ > PIPELINE_STAGE(SWITCH, OUT, ACL_ACTION, 8, "ls_out_acl_action") > \ > - PIPELINE_STAGE(SWITCH, OUT, MIRROR, 9, "ls_out_mirror") > \ > - PIPELINE_STAGE(SWITCH, OUT, QOS, 10, "ls_out_qos") > \ > - PIPELINE_STAGE(SWITCH, OUT, PRE_NF, 11, > \ > + PIPELINE_STAGE(SWITCH, OUT, QOS, 9, "ls_out_qos") > \ > + PIPELINE_STAGE(SWITCH, OUT, PRE_NF, 10, > \ > "ls_out_pre_network_function") > \ > - PIPELINE_STAGE(SWITCH, OUT, STATEFUL, 12, "ls_out_stateful") > \ > - PIPELINE_STAGE(SWITCH, OUT, NF, 13, > \ > + PIPELINE_STAGE(SWITCH, OUT, STATEFUL, 11, "ls_out_stateful") > \ > + PIPELINE_STAGE(SWITCH, OUT, NF, 12, > \ > "ls_out_network_function") > \ > - PIPELINE_STAGE(SWITCH, OUT, CHECK_PORT_SEC, 14, "ls_out_check_port_sec") > \ > - PIPELINE_STAGE(SWITCH, OUT, APPLY_PORT_SEC, 15, "ls_out_apply_port_sec") > - > + PIPELINE_STAGE(SWITCH, OUT, CHECK_PORT_SEC, 13, "ls_out_check_port_sec") > \ > + PIPELINE_STAGE(SWITCH, OUT, APPLY_PORT_SEC, 14, "ls_out_apply_port_sec") > \ > + PIPELINE_STAGE(SWITCH, OUT, MIRROR, 15, "ls_out_mirror") > \ > /* Logical router ingress stages. */ > #define ROUTER_IN_PIPELINE_STAGES \ > PIPELINE_STAGE(ROUTER, IN, ADMISSION, 0, "lr_in_admission") \ > diff --git a/ovn-nb.xml b/ovn-nb.xml > index 078bd6068..5f39acb5c 100644 > --- a/ovn-nb.xml > +++ b/ovn-nb.xml > @@ -3960,6 +3960,18 @@ or > <code>from-lport</code> mirrors the packets going out of logical > port. > <code>both</code> mirrors for both directions. > </p> > + > + <p> > + For mirrors of <var>type</var> <code>lport</code>, mirroring is > + done as close to the interface as possible, so that the mirror > + shows the traffic that is really present on that interface. > + Packets coming into the logical port (<code>to-lport</code>) are > + mirrored in the last egress table, that is, after ACLs, load > + balancing and port security have already been applied. Packets > + going out of the logical port (<code>from-lport</code>) are > + mirrored the other way around, in the first ingress table, before > + any of those are applied. > + </p> > </column> > > <column name="sink"> > diff --git a/tests/ovn-northd.at b/tests/ovn-northd.at > index 6572b1318..64e9873e5 100644 > --- a/tests/ovn-northd.at > +++ b/tests/ovn-northd.at > @@ -10339,7 +10339,7 @@ ovn_strip_lflows ], [0], [dnl > table=??(ls_in_l2_lkup ), priority=72 , match=(eth.mcast && (nd_na > || nd_rs || nd_ra)), action=(outport = "_MC_flood"; output;) > table=??(ls_in_l2_unknown ), priority=0 , match=(1), action=(output;) > table=??(ls_in_l2_unknown ), priority=50 , match=(outport == "none"), > action=(drop;) > - table=??(ls_out_apply_port_sec), priority=0 , match=(1), > action=(output;) > + table=??(ls_out_apply_port_sec), priority=0 , match=(1), action=(next;) > table=??(ls_out_apply_port_sec), priority=50 , match=(reg0[[15]] == 1), > action=(drop;) > table=??(ls_out_check_port_sec), priority=0 , match=(1), > action=(reg0[[15]] = check_out_port_sec(); next;) > table=??(ls_out_check_port_sec), priority=100 , match=(eth.mcast), > action=(reg0[[15]] = 0; next;) > @@ -10377,7 +10377,7 @@ ovn_strip_lflows ], [0], [dnl > table=??(ls_in_l2_lkup ), priority=72 , match=(eth.mcast && (nd_na > || nd_rs || nd_ra)), action=(outport = "_MC_flood"; output;) > table=??(ls_in_l2_unknown ), priority=0 , match=(1), action=(output;) > table=??(ls_in_l2_unknown ), priority=50 , match=(outport == "none"), > action=(drop;) > - table=??(ls_out_apply_port_sec), priority=0 , match=(1), > action=(output;) > + table=??(ls_out_apply_port_sec), priority=0 , match=(1), action=(next;) > table=??(ls_out_apply_port_sec), priority=50 , match=(reg0[[15]] == 1), > action=(drop;) > table=??(ls_out_check_port_sec), priority=0 , match=(1), > action=(reg0[[15]] = check_out_port_sec(); next;) > table=??(ls_out_check_port_sec), priority=100 , match=(eth.mcast), > action=(reg0[[15]] = 0; next;) > @@ -10414,7 +10414,7 @@ ovn_strip_lflows ], [0], [dnl > table=??(ls_in_l2_lkup ), priority=72 , match=(eth.mcast && (nd_na > || nd_rs || nd_ra)), action=(outport = "_MC_flood"; output;) > table=??(ls_in_l2_unknown ), priority=0 , match=(1), action=(output;) > table=??(ls_in_l2_unknown ), priority=50 , match=(outport == "none"), > action=(drop;) > - table=??(ls_out_apply_port_sec), priority=0 , match=(1), > action=(output;) > + table=??(ls_out_apply_port_sec), priority=0 , match=(1), action=(next;) > table=??(ls_out_apply_port_sec), priority=50 , match=(reg0[[15]] == 1), > action=(drop;) > table=??(ls_out_check_port_sec), priority=0 , match=(1), > action=(reg0[[15]] = check_out_port_sec(); next;) > table=??(ls_out_check_port_sec), priority=100 , match=(eth.mcast), > action=(reg0[[15]] = 0; next;) > @@ -10453,7 +10453,7 @@ ovn_strip_lflows ], [0], [dnl > table=??(ls_in_l2_unknown ), priority=0 , match=(1), action=(output;) > table=??(ls_in_l2_unknown ), priority=50 , match=(outport == "none"), > action=(drop;) > table=??(ls_in_l2_unknown ), priority=50 , match=(outport == "sw0p1"), > action=(drop;) > - table=??(ls_out_apply_port_sec), priority=0 , match=(1), > action=(output;) > + table=??(ls_out_apply_port_sec), priority=0 , match=(1), action=(next;) > table=??(ls_out_apply_port_sec), priority=50 , match=(reg0[[15]] == 1), > action=(drop;) > table=??(ls_out_check_port_sec), priority=0 , match=(1), > action=(reg0[[15]] = check_out_port_sec(); next;) > table=??(ls_out_check_port_sec), priority=100 , match=(eth.mcast), > action=(reg0[[15]] = 0; next;) > @@ -10491,8 +10491,8 @@ ovn_strip_lflows ], [0], [dnl > table=??(ls_in_l2_unknown ), priority=0 , match=(1), action=(output;) > table=??(ls_in_l2_unknown ), priority=50 , match=(outport == "none"), > action=(drop;) > table=??(ls_in_l2_unknown ), priority=50 , match=(outport == "sw0p1"), > action=(drop;) > - table=??(ls_out_apply_port_sec), priority=0 , match=(1), > action=(output;) > - table=??(ls_out_apply_port_sec), priority=110 , match=(outport == > "localnetport" && inport == "sw0p2"), action=(set_queue(10); output;) > + table=??(ls_out_apply_port_sec), priority=0 , match=(1), action=(next;) > + table=??(ls_out_apply_port_sec), priority=110 , match=(outport == > "localnetport" && inport == "sw0p2"), action=(set_queue(10); next;) > table=??(ls_out_apply_port_sec), priority=50 , match=(reg0[[15]] == 1), > action=(drop;) > table=??(ls_out_check_port_sec), priority=0 , match=(1), > action=(reg0[[15]] = check_out_port_sec(); next;) > table=??(ls_out_check_port_sec), priority=100 , match=(eth.mcast), > action=(reg0[[15]] = 0; next;) > @@ -10532,9 +10532,9 @@ ovn_strip_lflows ], [0], [dnl > table=??(ls_in_l2_lkup ), priority=72 , match=(eth.mcast && (nd_na > || nd_rs || nd_ra)), action=(outport = "_MC_flood"; output;) > table=??(ls_in_l2_unknown ), priority=0 , match=(1), action=(output;) > table=??(ls_in_l2_unknown ), priority=50 , match=(outport == "none"), > action=(drop;) > - table=??(ls_out_apply_port_sec), priority=0 , match=(1), > action=(output;) > - table=??(ls_out_apply_port_sec), priority=100 , match=(outport == > "localnetport"), action=(set_queue(10); output;) > - table=??(ls_out_apply_port_sec), priority=110 , match=(outport == > "localnetport" && inport == "sw0p2"), action=(set_queue(10); output;) > + table=??(ls_out_apply_port_sec), priority=0 , match=(1), action=(next;) > + table=??(ls_out_apply_port_sec), priority=100 , match=(outport == > "localnetport"), action=(set_queue(10); next;) > + table=??(ls_out_apply_port_sec), priority=110 , match=(outport == > "localnetport" && inport == "sw0p2"), action=(set_queue(10); next;) > table=??(ls_out_apply_port_sec), priority=50 , match=(reg0[[15]] == 1), > action=(drop;) > table=??(ls_out_check_port_sec), priority=0 , match=(1), > action=(reg0[[15]] = check_out_port_sec(); next;) > table=??(ls_out_check_port_sec), priority=100 , match=(eth.mcast), > action=(reg0[[15]] = 0; next;) > @@ -20276,7 +20276,7 @@ ovn-sbctl lflow-list sw0 > lflow-list > > AT_CHECK([grep -e "ls_in_mirror" -e "ls_out_mirror" lflow-list | > ovn_strip_lflows], [0], [dnl > table=??(ls_in_mirror ), priority=0 , match=(1), action=(next;) > - table=??(ls_out_mirror ), priority=0 , match=(1), action=(next;) > + table=??(ls_out_mirror ), priority=0 , match=(1), action=(output;) > ]) > > check ovn-nbctl lsp-attach-mirror sw0-p1 mirror0 > @@ -20289,8 +20289,8 @@ check_column mirror Port_Binding type > logical_port=mp-sw0-sw0-target0 > ovn-sbctl lflow-list sw0 > lflow-list > AT_CHECK([grep -e "ls_in_mirror" -e "ls_out_mirror" lflow-list | > ovn_strip_lflows], [0], [dnl > table=??(ls_in_mirror ), priority=0 , match=(1), action=(next;) > - table=??(ls_out_mirror ), priority=0 , match=(1), action=(next;) > - table=??(ls_out_mirror ), priority=100 , match=(outport == > "sw0-p1"), action=(mirror("mp-sw0-sw0-target0"); next;) > + table=??(ls_out_mirror ), priority=0 , match=(1), action=(output;) > + table=??(ls_out_mirror ), priority=100 , match=(outport == > "sw0-p1"), action=(mirror("mp-sw0-sw0-target0"); output;) > ]) > > ovn-sbctl lflow-list sw0 > lflow-list > @@ -20312,10 +20312,10 @@ AT_CHECK([grep -e "ls_in_mirror" -e "ls_out_mirror" > lflow-list | ovn_strip_lflow > table=??(ls_in_mirror ), priority=100 , match=(inport == "sw0-p1"), > action=(mirror("mp-sw0-sw0-target0"); next;) > table=??(ls_in_mirror ), priority=200 , match=(inport == "sw0-p1" > && (ip)), action=(mirror("mp-sw0-sw0-target0"); next;) > table=??(ls_in_mirror ), priority=250 , match=(inport == "sw0-p1" > && (icmp)), action=(next;) > - table=??(ls_out_mirror ), priority=0 , match=(1), action=(next;) > - table=??(ls_out_mirror ), priority=100 , match=(outport == > "sw0-p1"), action=(mirror("mp-sw0-sw0-target0"); next;) > - table=??(ls_out_mirror ), priority=200 , match=(outport == "sw0-p1" > && (ip)), action=(mirror("mp-sw0-sw0-target0"); next;) > - table=??(ls_out_mirror ), priority=250 , match=(outport == "sw0-p1" > && (icmp)), action=(next;) > + table=??(ls_out_mirror ), priority=0 , match=(1), action=(output;) > + table=??(ls_out_mirror ), priority=100 , match=(outport == > "sw0-p1"), action=(mirror("mp-sw0-sw0-target0"); output;) > + table=??(ls_out_mirror ), priority=200 , match=(outport == "sw0-p1" > && (ip)), action=(mirror("mp-sw0-sw0-target0"); output;) > + table=??(ls_out_mirror ), priority=250 , match=(outport == "sw0-p1" > && (icmp)), action=(output;) > ]) > > check ovn-nbctl lsp-attach-mirror sw0-p1 mirror2 > @@ -20334,10 +20334,10 @@ AT_CHECK([grep -e "ls_in_mirror" -e "ls_out_mirror" > lflow-list | ovn_strip_lflow > table=??(ls_in_mirror ), priority=200 , match=(inport == "sw0-p1" > && (ip4.dst == 192.168.0.1)), action=(mirror("mp-sw0-sw1-target1"); next;) > table=??(ls_in_mirror ), priority=250 , match=(inport == "sw0-p1" > && (1)), action=(next;) > table=??(ls_in_mirror ), priority=250 , match=(inport == "sw0-p1" > && (icmp)), action=(next;) > - table=??(ls_out_mirror ), priority=0 , match=(1), action=(next;) > - table=??(ls_out_mirror ), priority=100 , match=(outport == > "sw0-p1"), action=(mirror("mp-sw0-sw0-target0"); next;) > - table=??(ls_out_mirror ), priority=200 , match=(outport == "sw0-p1" > && (ip)), action=(mirror("mp-sw0-sw0-target0"); next;) > - table=??(ls_out_mirror ), priority=250 , match=(outport == "sw0-p1" > && (icmp)), action=(next;) > + table=??(ls_out_mirror ), priority=0 , match=(1), action=(output;) > + table=??(ls_out_mirror ), priority=100 , match=(outport == > "sw0-p1"), action=(mirror("mp-sw0-sw0-target0"); output;) > + table=??(ls_out_mirror ), priority=200 , match=(outport == "sw0-p1" > && (ip)), action=(mirror("mp-sw0-sw0-target0"); output;) > + table=??(ls_out_mirror ), priority=250 , match=(outport == "sw0-p1" > && (icmp)), action=(output;) > ]) > > ovn-sbctl lflow-list sw0 > lflow-list > @@ -20360,7 +20360,7 @@ AT_CHECK([grep -e "ls_in_mirror" -e "ls_out_mirror" > lflow-list | ovn_strip_lflow > table=??(ls_in_mirror ), priority=100 , match=(inport == "sw0-p1"), > action=(mirror("mp-sw0-sw1-target1"); next;) > table=??(ls_in_mirror ), priority=200 , match=(inport == "sw0-p1" > && (ip4.dst == 192.168.0.1)), action=(mirror("mp-sw0-sw1-target1"); next;) > table=??(ls_in_mirror ), priority=250 , match=(inport == "sw0-p1" > && (1)), action=(next;) > - table=??(ls_out_mirror ), priority=0 , match=(1), action=(next;) > + table=??(ls_out_mirror ), priority=0 , match=(1), action=(output;) > ]) > > AT_CHECK([grep -e "ls_out_pre_acl" lflow-list | ovn_strip_lflows], [0], [dnl > @@ -20385,10 +20385,10 @@ AT_CHECK([grep -e "ls_in_mirror" -e "ls_out_mirror" > lflow-list | ovn_strip_lflow > table=??(ls_in_mirror ), priority=200 , match=(inport == "sw0-p1" > && (ip4.dst == 192.168.0.1)), action=(mirror("mp-sw0-sw1-target1"); next;) > table=??(ls_in_mirror ), priority=250 , match=(inport == "sw0-p1" > && (1)), action=(next;) > table=??(ls_in_mirror ), priority=250 , match=(inport == "sw0-p1" > && (icmp)), action=(next;) > - table=??(ls_out_mirror ), priority=0 , match=(1), action=(next;) > - table=??(ls_out_mirror ), priority=100 , match=(outport == > "sw0-p1"), action=(mirror("mp-sw0-sw0-target0"); next;) > - table=??(ls_out_mirror ), priority=200 , match=(outport == "sw0-p1" > && (ip)), action=(mirror("mp-sw0-sw0-target0"); next;) > - table=??(ls_out_mirror ), priority=250 , match=(outport == "sw0-p1" > && (icmp)), action=(next;) > + table=??(ls_out_mirror ), priority=0 , match=(1), action=(output;) > + table=??(ls_out_mirror ), priority=100 , match=(outport == > "sw0-p1"), action=(mirror("mp-sw0-sw0-target0"); output;) > + table=??(ls_out_mirror ), priority=200 , match=(outport == "sw0-p1" > && (ip)), action=(mirror("mp-sw0-sw0-target0"); output;) > + table=??(ls_out_mirror ), priority=250 , match=(outport == "sw0-p1" > && (icmp)), action=(output;) > ]) > > mirror1uuid_uuid=`ovn-nbctl --bare --columns _uuid find Mirror > name="mirror1"` > @@ -20405,11 +20405,11 @@ AT_CHECK([grep -e "ls_in_mirror" -e "ls_out_mirror" > lflow-list | ovn_strip_lflow > table=??(ls_in_mirror ), priority=200 , match=(inport == "sw0-p1" > && (ip4.dst == 192.168.0.1)), action=(mirror("mp-sw0-sw1-target1"); next;) > table=??(ls_in_mirror ), priority=250 , match=(inport == "sw0-p1" > && (1)), action=(next;) > table=??(ls_in_mirror ), priority=250 , match=(inport == "sw0-p1" > && (icmp)), action=(next;) > - table=??(ls_out_mirror ), priority=0 , match=(1), action=(next;) > - table=??(ls_out_mirror ), priority=100 , match=(outport == > "sw0-p1"), action=(mirror("mp-sw0-sw0-target0"); next;) > - table=??(ls_out_mirror ), priority=100 , match=(outport == > "sw0-p1"), action=(mirror("mp-sw0-sw1-target1"); next;) > - table=??(ls_out_mirror ), priority=200 , match=(outport == "sw0-p1" > && (ip)), action=(mirror("mp-sw0-sw1-target1"); next;) > - table=??(ls_out_mirror ), priority=250 , match=(outport == "sw0-p1" > && (icmp)), action=(next;) > + table=??(ls_out_mirror ), priority=0 , match=(1), action=(output;) > + table=??(ls_out_mirror ), priority=100 , match=(outport == > "sw0-p1"), action=(mirror("mp-sw0-sw0-target0"); output;) > + table=??(ls_out_mirror ), priority=100 , match=(outport == > "sw0-p1"), action=(mirror("mp-sw0-sw1-target1"); output;) > + table=??(ls_out_mirror ), priority=200 , match=(outport == "sw0-p1" > && (ip)), action=(mirror("mp-sw0-sw1-target1"); output;) > + table=??(ls_out_mirror ), priority=250 , match=(outport == "sw0-p1" > && (icmp)), action=(output;) > ]) > > check_row_count Port_Binding 1 logical_port=mp-sw0-sw0-target0 > @@ -20425,7 +20425,7 @@ check ovn-nbctl --wait=sb sync > ovn-sbctl lflow-list sw0 > lflow-list > AT_CHECK([grep -e "ls_in_mirror" -e "ls_out_mirror" lflow-list | > ovn_strip_lflows], [0], [dnl > table=??(ls_in_mirror ), priority=0 , match=(1), action=(next;) > - table=??(ls_out_mirror ), priority=0 , match=(1), action=(next;) > + table=??(ls_out_mirror ), priority=0 , match=(1), action=(output;) > ]) > > ovn-sbctl lflow-list sw0 > lflow-list > diff --git a/tests/ovn-util.at b/tests/ovn-util.at > index 315539342..aecf908ef 100644 > --- a/tests/ovn-util.at > +++ b/tests/ovn-util.at > @@ -78,7 +78,7 @@ AT_CHECK_UNQUOTED([cat trace | $PYTHON > $top_srcdir/utilities/ovn_detrace.py.in], > resubmit(,??) > * Logical datapaths: > * "ls" ($dp_uuid) [[egress]] > - * Logical flow: table=$egress_table (ls_out_apply_port_sec), > priority=0, match=(1), actions=(output;) > + * Logical flow: table=$egress_table (ls_out_apply_port_sec), > priority=0, match=(1), actions=(next;) > 65. reg15=0x2,metadata=0x1, priority 100, cookie $pb_vm1 > output:2 > * Logical datapath: "ls" ($dp_uuid) > @@ -99,7 +99,7 @@ cookie=$ingress, priority=50,metadata=0x1 > actions=load:0->NXM_NX_REG10[[12]],res > cookie=$egress, priority=0,metadata=0x1 actions=resubmit(,??) > * Logical datapaths: > * "ls" ($dp_uuid) [[egress]] > - * Logical flow: table=$egress_table (ls_out_apply_port_sec), priority=0, > match=(1), actions=(output;) > + * Logical flow: table=$egress_table (ls_out_apply_port_sec), priority=0, > match=(1), actions=(next;) > > ]) > > diff --git a/tests/ovn.at b/tests/ovn.at > index 13e95f9db..2c90c5ce4 100644 > --- a/tests/ovn.at > +++ b/tests/ovn.at > @@ -19593,8 +19593,8 @@ check_column "$hv3_uuid" sb:Port_Binding chassis > logical_port=mp-ls1-ls2-lp2 > AT_CHECK([ovn-sbctl lflow-list ls1 | grep mirror| ovn_strip_lflows], [0], > [dnl > table=??(ls_in_mirror ), priority=0 , match=(1), action=(next;) > table=??(ls_in_mirror ), priority=100 , match=(inport == > "ls1-lp1"), action=(mirror("mp-ls1-ls2-lp2"); next;) > - table=??(ls_out_mirror ), priority=0 , match=(1), action=(next;) > - table=??(ls_out_mirror ), priority=100 , match=(outport == > "ls1-lp1"), action=(mirror("mp-ls1-ls2-lp2"); next;) > + table=??(ls_out_mirror ), priority=0 , match=(1), action=(output;) > + table=??(ls_out_mirror ), priority=100 , match=(outport == > "ls1-lp1"), action=(mirror("mp-ls1-ls2-lp2"); output;) > ]) > > as hv2 reset_pcap_file hv2-vif1 hv2/vif1 > @@ -19644,7 +19644,7 @@ check_row_count Port_Binding 0 > logical_port=mp-ls1-ls2-lp2 > > AT_CHECK([ovn-sbctl lflow-list ls1 | grep mirror| ovn_strip_lflows], [0], > [dnl > table=??(ls_in_mirror ), priority=0 , match=(1), action=(next;) > - table=??(ls_out_mirror ), priority=0 , match=(1), action=(next;) > + table=??(ls_out_mirror ), priority=0 , match=(1), action=(output;) > ]) > > as hv3 reset_pcap_file hv3-vif1 hv3/vif1 > @@ -19679,9 +19679,9 @@ AT_CHECK([ovn-sbctl lflow-list ls1 | grep mirror | > ovn_strip_lflows], [0], [dnl > table=??(ls_in_mirror ), priority=0 , match=(1), action=(next;) > table=??(ls_in_mirror ), priority=100 , match=(inport == > "ls1-lp1"), action=(mirror("mp-ls1-ls2-lp2"); next;) > table=??(ls_in_mirror ), priority=300 , match=(inport == "ls1-lp1" > && (1)), action=(next;) > - table=??(ls_out_mirror ), priority=0 , match=(1), action=(next;) > - table=??(ls_out_mirror ), priority=100 , match=(outport == > "ls1-lp1"), action=(mirror("mp-ls1-ls2-lp2"); next;) > - table=??(ls_out_mirror ), priority=300 , match=(outport == "ls1-lp1" > && (1)), action=(next;) > + table=??(ls_out_mirror ), priority=0 , match=(1), action=(output;) > + table=??(ls_out_mirror ), priority=100 , match=(outport == > "ls1-lp1"), action=(mirror("mp-ls1-ls2-lp2"); output;) > + table=??(ls_out_mirror ), priority=300 , match=(outport == "ls1-lp1" > && (1)), action=(output;) > ]) > > AT_CHECK([ovn-sbctl lflow-list ls1 | grep ls_out_pre_acl | > ovn_strip_lflows], [0], [dnl > @@ -19694,7 +19694,7 @@ AT_CHECK([ovn-sbctl lflow-list ls1 | grep > ls_out_pre_acl | ovn_strip_lflows], [0 > check ovn-nbctl --wait=sb lsp-del ls2-lp2 > AT_CHECK([ovn-sbctl lflow-list ls1 | grep mirror | ovn_strip_lflows], [0], > [dnl > table=??(ls_in_mirror ), priority=0 , match=(1), action=(next;) > - table=??(ls_out_mirror ), priority=0 , match=(1), action=(next;) > + table=??(ls_out_mirror ), priority=0 , match=(1), action=(output;) > ]) > > check ovn-nbctl lsp-add ls2 ls2-lp2 > @@ -19717,10 +19717,10 @@ AT_CHECK([ovn-sbctl lflow-list ls1 | grep mirror| > ovn_strip_lflows], [0], [dnl > table=??(ls_in_mirror ), priority=100 , match=(inport == > "ls1-lp1"), action=(mirror("mp-ls1-ls2-lp2"); next;) > table=??(ls_in_mirror ), priority=300 , match=(inport == "ls1-lp1" > && (1)), action=(next;) > table=??(ls_in_mirror ), priority=400 , match=(inport == "ls1-lp1" > && (udp.dst == 4369)), action=(mirror("mp-ls1-ls2-lp2"); next;) > - table=??(ls_out_mirror ), priority=0 , match=(1), action=(next;) > - table=??(ls_out_mirror ), priority=100 , match=(outport == > "ls1-lp1"), action=(mirror("mp-ls1-ls2-lp2"); next;) > - table=??(ls_out_mirror ), priority=300 , match=(outport == "ls1-lp1" > && (1)), action=(next;) > - table=??(ls_out_mirror ), priority=400 , match=(outport == "ls1-lp1" > && (udp.dst == 4369)), action=(mirror("mp-ls1-ls2-lp2"); next;) > + table=??(ls_out_mirror ), priority=0 , match=(1), action=(output;) > + table=??(ls_out_mirror ), priority=100 , match=(outport == > "ls1-lp1"), action=(mirror("mp-ls1-ls2-lp2"); output;) > + table=??(ls_out_mirror ), priority=300 , match=(outport == "ls1-lp1" > && (1)), action=(output;) > + table=??(ls_out_mirror ), priority=400 , match=(outport == "ls1-lp1" > && (udp.dst == 4369)), action=(mirror("mp-ls1-ls2-lp2"); output;) > ]) > > AT_CHECK([ovn-sbctl lflow-list ls1 | grep ls_out_pre_acl | > ovn_strip_lflows], [0], [dnl -- Rosemarie O'Riorden Boston & Lowell, MA, USA [email protected] _______________________________________________ dev mailing list [email protected] https://mail.openvswitch.org/mailman/listinfo/ovs-dev
