> On 23 Jul 2026, at 9:23 PM, Dumitru Ceara <[email protected]> wrote: > > !-------------------------------------------------------------------| > CAUTION: External Email > > |-------------------------------------------------------------------! > > On 7/13/26 6:06 AM, Naveen Yerramneni wrote: >> For localnet ports, skip_port_from_conntrack() incorrectly emits "next;" >> (without ct_clear) in the egress pre-ACL/pre-LB stages whenever the >> switch has a stateful ACL: a packet that went through ct_lb / ct(commit) >> on ingress carries ct_state (+trk, +est, ct_label, ...) into the egress >> pipeline, and out_acl_eval then matches flows (ct.est, ct.new, ct_label, >> ...) against state from a different zone, causing rules to fire >> incorrectly. >> >> Always emit "flags.pkt_sampled = 0; ct_clear; next;" for localnet >> ports so egress ACL evaluation starts with a clean ct_state. >> Behavior for other port types is unchanged. >> >> Signed-off-by: Naveen Yerramneni <[email protected]> >> Acked-by: Sragdhara Datta Chaudhuri <[email protected]> >> Acked-by: Aditya Mehakare <[email protected]> >> Assisted-by: Claude Opus 4.7, Cursor >> --- > > Hi Naveen, > > Thanks for the new revision. > > Applied to main. I guess we could also backport this to 26.03 but maybe > it's good to give it some soak time on main first.
Thanks Dumitru! Sure, we can wait before back backporting. > > Regards, > Dumitru _______________________________________________ dev mailing list [email protected] https://mail.openvswitch.org/mailman/listinfo/ovs-dev
