Em ter., 11 de ago. de 2026 às 18:34, Lucas Vargas Dias <[email protected]> escreveu:
> The 'ic-route-filter-tag' option on a Logical_Router_Port used to accept > only a single route-tag: the learned route's tag was matched against the > option value with a plain strcmp(), so a comma-separated value would > never match any real tag and the filter would silently do nothing. > > Parse the option as a comma-separated list instead, building an sset of > tags and matching each learned route's tag against it, mirroring the > behavior already used by the 'ic-route-filter-adv' and > 'ic-route-filter-learn' prefix filters. A single tag keeps working > exactly as before. > > The documentation is updated to describe the list form and the test in > tests/ovn-ic.at is extended to verify that a route is filtered when its > tag is one of several listed tags, and learned again when it is not. > > Signed-off-by: Lucas Vargas Dias <[email protected]> > --- > Recheck-request: github-robot-_ovn-kubernetes > ic/ovn-ic.c | 17 +++++++++++------ > ovn-nb.xml | 7 ++++--- > tests/ovn-ic.at | 23 +++++++++++++++++++++++ > 3 files changed, 38 insertions(+), 9 deletions(-) > > diff --git a/ic/ovn-ic.c b/ic/ovn-ic.c > index f7cc41748..8b0cf9e15 100644 > --- a/ic/ovn-ic.c > +++ b/ic/ovn-ic.c > @@ -2537,7 +2537,7 @@ sync_learned_routes(struct ic_context *ctx, > nbrec_nb_global_first(ctx->ovnnb_idl); > ovs_assert(nb_global); > > - const char *lrp_name, *ts_route_table, *route_filter_tag; > + const char *lrp_name, *ts_route_table, *route_tag_filter; > const struct icsbrec_port_binding *isb_pb; > const struct nbrec_logical_router_port *lrp; > VECTOR_FOR_EACH (&ic_lr->isb_pbs, isb_pb) { > @@ -2548,13 +2548,17 @@ sync_learned_routes(struct ic_context *ctx, > lrp = get_lrp_by_lrp_name(ctx, lrp_name); > if (lrp) { > ts_route_table = smap_get_def(&lrp->options, "route_table", > ""); > - route_filter_tag = smap_get_def(&lrp->options, > + route_tag_filter = smap_get_def(&lrp->options, > "ic-route-filter-tag", ""); > } else { > ts_route_table = ""; > - route_filter_tag = ""; > + route_tag_filter = ""; > } > > + /* The filter tag option accepts a comma-separated list of tags. > */ > + struct sset filter_tags = SSET_INITIALIZER(&filter_tags); > + sset_from_delimited_string(&filter_tags, route_tag_filter, ","); > + > isb_route_key = > icsbrec_route_index_init_row(ctx->icsbrec_route_by_ts); > icsbrec_route_index_set_transit_switch(isb_route_key, > isb_pb->transit_switch); > @@ -2578,11 +2582,11 @@ sync_learned_routes(struct ic_context *ctx, > > const char *isb_route_tag = smap_get(&isb_route->external_ids, > "ic-route-tag"); > - if (isb_route_tag && !strcmp(isb_route_tag, > route_filter_tag)) { > + if (isb_route_tag && sset_contains(&filter_tags, > isb_route_tag)) { > VLOG_DBG("Skip learning route %s -> %s as its route tag " > - "[%s] is filtered by the filter tag [%s] of TS > LRP ", > + "[%s] is filtered by the filter tags [%s] of TS > LRP ", > isb_route->ip_prefix, isb_route->nexthop, > - isb_route_tag, route_filter_tag); > + isb_route_tag, route_tag_filter); > continue; > } > > @@ -2650,6 +2654,7 @@ sync_learned_routes(struct ic_context *ctx, > } > } > icsbrec_route_index_destroy_row(isb_route_key); > + sset_destroy(&filter_tags); > } > > /* Delete extra learned routes. */ > diff --git a/ovn-nb.xml b/ovn-nb.xml > index 8a9d19fa9..23d15bb45 100644 > --- a/ovn-nb.xml > +++ b/ovn-nb.xml > @@ -4689,9 +4689,10 @@ or > <column name="options" key="ic-route-filter-tag" > type='{"type": "string"}'> > <p> > - This option expects a name of a filtered route-tag that's > present > - in the Logical Router Port. If set, it causes any route learned > by > - the Logical Router Port with the <code>route-tag</code> present > in > + This option expects a comma-separated list of filtered > route-tags > + that's present in the Logical Router Port. If set, it causes any > + route learned by the Logical Router Port with a > + <code>route-tag</code> matching one of the listed tags, present > in > the external_ids register of the advertised route entry in the > <ref table="Route" db="OVN_IC_Southbound"/> table of the > <ref db="OVN_IC_Southbound"/> database, will be filtered and not > diff --git a/tests/ovn-ic.at b/tests/ovn-ic.at > index 1435a19a3..178bd22ee 100644 > --- a/tests/ovn-ic.at > +++ b/tests/ovn-ic.at > @@ -3711,6 +3711,29 @@ OVS_WAIT_FOR_OUTPUT([ovn_as az1 ovn-nbctl > lr-route-list lr11 | grep 192.168 | > 192.168.1.0/24 169.254.103.22 > ]) > > +# Filter using a comma-separated list of tags that includes vpc1. > +# The vpc1-tagged route (169.254.103.12) must be filtered out. > +ovn_as az1 ovn-nbctl set logical_router_port lrp-lr11-tspeer > options:ic-route-filter-tag=vpc0,vpc1,vpc2 > + > +OVS_WAIT_FOR_OUTPUT([ovn_as az1 ovn-nbctl lr-route-list lr11 | grep > 192.168 | > + grep learned | awk '{print $1, $2}' | sort ], [0], [dnl > +192.168.0.0/24 169.254.101.2 > +192.168.0.0/24 169.254.102.2 > +192.168.1.0/24 169.254.103.22 > +]) > + > +# Change the filter to a list that does not include vpc1. > +# The vpc1-tagged route (169.254.103.12) must be learned again. > +ovn_as az1 ovn-nbctl set logical_router_port lrp-lr11-tspeer > options:ic-route-filter-tag=vpc0,vpc2 > + > +OVS_WAIT_FOR_OUTPUT([ovn_as az1 ovn-nbctl lr-route-list lr11 | grep > 192.168 | > + grep learned | awk '{print $1, $2}' | sort ], [0], [dnl > +192.168.0.0/24 169.254.101.2 > +192.168.0.0/24 169.254.102.2 > +192.168.0.0/24 169.254.103.12 > +192.168.1.0/24 169.254.103.22 > +]) > + > OVN_CLEANUP_IC([az1], [az2]) > > AT_CLEANUP > -- > 2.43.0 > > -- _‘Esta mensagem é direcionada apenas para os endereços constantes no cabeçalho inicial. Se você não está listado nos endereços constantes no cabeçalho, pedimos-lhe que desconsidere completamente o conteúdo dessa mensagem e cuja cópia, encaminhamento e/ou execução das ações citadas estão imediatamente anuladas e proibidas’._ * **‘Apesar do Magazine Luiza tomar todas as precauções razoáveis para assegurar que nenhum vírus esteja presente nesse e-mail, a empresa não poderá aceitar a responsabilidade por quaisquer perdas ou danos causados por esse e-mail ou por seus anexos’.* _______________________________________________ dev mailing list [email protected] https://mail.openvswitch.org/mailman/listinfo/ovs-dev
