Mirroring of type "lport" was done after ingress port security and before egress port security, so the mirror did not show the traffic that was really present on the port. For example, if a VM is compromised and sends packets with a spoofed source MAC, port security drops them and they never reach the mirror target, although this is exactly the traffic one would want to see.
Mirror the traffic as close to the interface as possible, so that the mirror target sees what the port actually sends and receives. Signed-off-by: Alexandra Rukomoinikova <[email protected]> --- Documentation/ref/ovn-logical-flows.7.rst | 107 +++++++++++----------- NEWS | 6 ++ lib/ovn-util.c | 4 +- northd/northd.c | 11 ++- northd/northd.h | 21 ++--- ovn-nb.xml | 12 +++ tests/ovn-northd.at | 62 ++++++------- tests/ovn-util.at | 4 +- tests/ovn.at | 22 ++--- 9 files changed, 134 insertions(+), 115 deletions(-) diff --git a/Documentation/ref/ovn-logical-flows.7.rst b/Documentation/ref/ovn-logical-flows.7.rst index 44fd560bf..a1cfeea6d 100644 --- a/Documentation/ref/ovn-logical-flows.7.rst +++ b/Documentation/ref/ovn-logical-flows.7.rst @@ -16,10 +16,29 @@ Logical Switch Datapaths .. _ls-in-0: -Ingress Table 0: Admission Control and Ingress Port Security check +Ingress Table 0: Mirror +~~~~~~~~~~~~~~~~~~~~~~~~ + +Overlay remote mirror table contains the following logical flows: + +- For each logical switch port with an attached mirror, a logical flow with a + priority of 100 is added. This flow matches all incoming packets to the + attached port, clones them, and forwards the cloned packets to the mirror + target port. + +- A priority 0 flow is added which matches on all packets and applies the + action ``next;``. + +- A logical flow added for each Mirror Rule in Mirror table attached to logical + switch ports, matches all incoming packets that match rules and clones the + packet and sends cloned packet to mirror target port. + +.. _ls-in-1: + +Ingress Table 1: Admission Control and Ingress Port Security check ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -Ingress table 0 contains these logical flows: +Ingress table 1 contains these logical flows: - Priority 100 flows to drop packets with VLAN tags or multicast Ethernet source addresses. @@ -61,9 +80,9 @@ Ingress table 0 contains these logical flows: applies the port security rules defined in the ``port_security`` column of ``Logical_Switch_Port`` table. -.. _ls-in-1: +.. _ls-in-2: -Ingress Table 1: Ingress Port Security - Apply +Ingress Table 2: Ingress Port Security - Apply ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ For each logical switch port *P* of type router connected to a gw router a @@ -98,25 +117,6 @@ Ingress table 1 contains these logical flows: - One priority-0 fallback flow that matches all packets and advances to the next table. -.. _ls-in-2: - -Ingress Table 2: Mirror -~~~~~~~~~~~~~~~~~~~~~~~~ - -Overlay remote mirror table contains the following logical flows: - -- For each logical switch port with an attached mirror, a logical flow with a - priority of 100 is added. This flow matches all incoming packets to the - attached port, clones them, and forwards the cloned packets to the mirror - target port. - -- A priority 0 flow is added which matches on all packets and applies the action - ``next;``. - -- A logical flow added for each Mirror Rule in Mirror table attached to logical - switch ports, matches all incoming packets that match rules and clones the - packet and sends cloned packet to mirror target port. - .. _ls-in-3: Ingress Table 3: Lookup MAC address learning table @@ -1799,34 +1799,15 @@ This is similar to ingress table :ref:`ACL action <ls-in-11>`. .. _ls-out-9: -Egress Table 9: Mirror -~~~~~~~~~~~~~~~~~~~~~~~~ - -Overlay remote mirror table contains the following logical flows: - -- For each logical switch port with an attached mirror, a logical flow with a - priority of 100 is added. This flow matches all outcoming packets to the - attached port, clones them, and forwards the cloned packets to the mirror - target port. - -- A priority 0 flow is added which matches on all packets and applies the action - ``next;``. - -- A logical flow added for each Mirror Rule in Mirror table attached to logical - switch ports, matches all outcoming packets that match rules and clones the - packet and sends cloned packet to mirror target port. - -.. _ls-out-10: - -Egress Table 10: ``to-lport`` QoS +Egress Table 9: ``to-lport`` QoS ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ This is similar to ingress table :ref:`QoS <ls-in-12>` except they apply to ``to-lport`` QoS rules. -.. _ls-out-11: +.. _ls-out-10: -Egress Table 11: Pre Network Function +Egress Table 10: Pre Network Function ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ This stage selects the active network function from a ``Network_Function_Group`` @@ -1878,9 +1859,9 @@ support network function load balancing. - In inline, vtap mode: A priority-0 flow that simply moves traffic to the next table. -.. _ls-out-12: +.. _ls-out-11: -Egress Table 12: Stateful +Egress Table 11: Stateful ~~~~~~~~~~~~~~~~~~~~~~~~~~ This is similar to ingress table :ref:`Stateful <ls-in-24>` except that there @@ -1898,9 +1879,9 @@ connection tracking. when it comes out of the other port of the network function (required for cross host traffic redirection for VLAN subnet). -.. _ls-out-13: +.. _ls-out-12: -Egress Table 13: Network Function +Egress Table 12: Network Function ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ This table handles request packets for ``to-lport`` ACLs and response packets @@ -1972,9 +1953,9 @@ in ``ct_label.nf_id`` during request processing. - In inline, vtap mode: One priority-0 flow same as ingress :ref:`Network Function <ls-in-25>`. -.. _ls-out-14: +.. _ls-out-13: -Egress Table 14: Egress Port Security - check +Egress Table 13: Egress Port Security - check ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ This is similar to the port security logic in table :ref:`Ingress Port Security @@ -1994,9 +1975,9 @@ port security rules. This table adds the below logical flows. addresses defined in the ``port_security`` column of ``Logical_Switch_Port`` table before delivering the packet to the ``outport``. -.. _ls-out-15: +.. _ls-out-14: -Egress Table 15: Egress Port Security - Apply +Egress Table 14: Egress Port Security - Apply ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ This is similar to the ingress port security logic in ingress table @@ -2024,6 +2005,26 @@ The following flows are added. - A priority-0 flow that outputs the packet to the ``outport``. +.. _ls-out-15: + +Egress Table 15: Mirror +~~~~~~~~~~~~~~~~~~~~~~~~ + +Overlay remote mirror table contains the following logical flows: + +- For each logical switch port with an attached mirror, a logical flow with a + priority of 100 is added. This flow matches all outcoming packets to the + attached port, clones them, and forwards the cloned packets to the mirror + target port. + +- A priority 0 flow is added which matches on all packets and applies the + action ``output;``. + +- A logical flow added for each Mirror Rule in Mirror table attached to logical + switch ports, matches all outcoming packets that match rules and clones the + packet and sends cloned packet to mirror target port. + + .. _lr-datapaths: Logical Router Datapaths diff --git a/NEWS b/NEWS index f1c56dd14..ddd013268 100644 --- a/NEWS +++ b/NEWS @@ -129,6 +129,12 @@ OVN v26.09.0 - xxx xx xxxx represent a logical router port (e.g. ovn-ic transit switch LSPs). Such ports are treated like type=router, including omission from _MC_flood_l2. + - Mirrors of type "lport" now mirror the traffic that is really present + on the logical port: "from-lport" traffic is mirrored in the first + ingress table, before port security, and "to-lport" traffic in the last + egress table, after port security. Packets dropped by ingress port + security are now mirrored, while packets dropped by egress port + security are not mirrored anymore. OVN v26.03.0 - xxx xx xxxx -------------------------- diff --git a/lib/ovn-util.c b/lib/ovn-util.c index eb1fa8a06..fd9b40563 100644 --- a/lib/ovn-util.c +++ b/lib/ovn-util.c @@ -1007,8 +1007,8 @@ ip_address_and_port_from_lb_key(const char *key, char **ip_address, * * NOTE: If OVN_NORTHD_PIPELINE_CSUM is updated make sure to double check * whether an update of OVN_INTERNAL_MINOR_VER is required. */ -#define OVN_NORTHD_PIPELINE_CSUM "3980195012 11262" -#define OVN_INTERNAL_MINOR_VER 16 +#define OVN_NORTHD_PIPELINE_CSUM "451923473 11267" +#define OVN_INTERNAL_MINOR_VER 17 /* Returns the OVN version. The caller must free the returned value. */ char * diff --git a/northd/northd.c b/northd/northd.c index 4eb2ea44b..43f1f052b 100644 --- a/northd/northd.c +++ b/northd/northd.c @@ -6402,7 +6402,7 @@ build_mirror_default_lflow(struct ovn_datapath *od, struct lflow_table *lflows) { ovn_lflow_add(lflows, od, S_SWITCH_IN_MIRROR, 0, "1", "next;", NULL); - ovn_lflow_add(lflows, od, S_SWITCH_OUT_MIRROR, 0, "1", "next;", NULL); + ovn_lflow_add(lflows, od, S_SWITCH_OUT_MIRROR, 0, "1", "output;", NULL); } static void @@ -6429,7 +6429,7 @@ build_mirror_lflow(struct ovn_port *op, stage = S_SWITCH_IN_MIRROR; } - ds_put_cstr(&action, "next;"); + ds_put_cstr(&action, egress ? "output;" : "next;"); ds_put_format(&match, "%s == %s && (%s)", dir, op->json_key, rule->match); ovn_lflow_add(lflows, op->od, stage, priority, ds_cstr(&match), ds_cstr(&action), op->lflow_ref); @@ -6456,7 +6456,8 @@ build_mirror_pass_lflow(struct ovn_port *op, stage = S_SWITCH_IN_MIRROR; } - ds_put_format(&action, "mirror(%s); next;", serving_port->json_key); + ds_put_format(&action, "mirror(%s); %s", serving_port->json_key, + egress ? "output;" : "next;"); ds_put_format(&match, "%s == %s", dir, op->json_key); ovn_lflow_add(lflows, op->od, stage, OVN_LPORT_MIRROR_OFFSET, ds_cstr(&match), ds_cstr(&action), op->lflow_ref); @@ -6591,7 +6592,7 @@ build_lswitch_port_sec_op(struct ovn_port *op, struct lflow_table *lflows, } ds_clear(actions); - ds_put_format(actions, "set_queue(%s); output;", queue_id); + ds_put_format(actions, "set_queue(%s); next;", queue_id); ds_clear(match); if (lsp_is_localnet(op->nbsp)) { @@ -6701,7 +6702,7 @@ build_lswitch_output_port_sec_od(struct ovn_datapath *od, REGBIT_PORT_SEC_DROP" == 1", debug_drop_action(), lflow_ref, WITH_DESC("Packet does not follow port security rules")); ovn_lflow_add(lflows, od, S_SWITCH_OUT_APPLY_PORT_SEC, 0, - "1", "output;", lflow_ref); + "1", "next;", lflow_ref); } static void diff --git a/northd/northd.h b/northd/northd.h index 9a74a4abc..c38e2e13c 100644 --- a/northd/northd.h +++ b/northd/northd.h @@ -527,9 +527,9 @@ ls_has_localnet_port(const struct ovn_datapath *od) /* Logical switch ingress stages. */ #define SWITCH_IN_PIPELINE_STAGES \ - PIPELINE_STAGE(SWITCH, IN, CHECK_PORT_SEC, 0, "ls_in_check_port_sec") \ - PIPELINE_STAGE(SWITCH, IN, APPLY_PORT_SEC, 1, "ls_in_apply_port_sec") \ - PIPELINE_STAGE(SWITCH, IN, MIRROR, 2, "ls_in_mirror") \ + PIPELINE_STAGE(SWITCH, IN, MIRROR, 0, "ls_in_mirror") \ + PIPELINE_STAGE(SWITCH, IN, CHECK_PORT_SEC, 1, "ls_in_check_port_sec") \ + PIPELINE_STAGE(SWITCH, IN, APPLY_PORT_SEC, 2, "ls_in_apply_port_sec") \ PIPELINE_STAGE(SWITCH, IN, LOOKUP_FDB, 3, "ls_in_lookup_fdb") \ PIPELINE_STAGE(SWITCH, IN, PUT_FDB, 4, "ls_in_put_fdb") \ PIPELINE_STAGE(SWITCH, IN, PRE_ACL, 5, "ls_in_pre_acl") \ @@ -579,16 +579,15 @@ ls_has_localnet_port(const struct ovn_datapath *od) PIPELINE_STAGE(SWITCH, OUT, ACL_EVAL, 6, "ls_out_acl_eval") \ PIPELINE_STAGE(SWITCH, OUT, ACL_SAMPLE, 7, "ls_out_acl_sample") \ PIPELINE_STAGE(SWITCH, OUT, ACL_ACTION, 8, "ls_out_acl_action") \ - PIPELINE_STAGE(SWITCH, OUT, MIRROR, 9, "ls_out_mirror") \ - PIPELINE_STAGE(SWITCH, OUT, QOS, 10, "ls_out_qos") \ - PIPELINE_STAGE(SWITCH, OUT, PRE_NF, 11, \ + PIPELINE_STAGE(SWITCH, OUT, QOS, 9, "ls_out_qos") \ + PIPELINE_STAGE(SWITCH, OUT, PRE_NF, 10, \ "ls_out_pre_network_function") \ - PIPELINE_STAGE(SWITCH, OUT, STATEFUL, 12, "ls_out_stateful") \ - PIPELINE_STAGE(SWITCH, OUT, NF, 13, \ + PIPELINE_STAGE(SWITCH, OUT, STATEFUL, 11, "ls_out_stateful") \ + PIPELINE_STAGE(SWITCH, OUT, NF, 12, \ "ls_out_network_function") \ - PIPELINE_STAGE(SWITCH, OUT, CHECK_PORT_SEC, 14, "ls_out_check_port_sec") \ - PIPELINE_STAGE(SWITCH, OUT, APPLY_PORT_SEC, 15, "ls_out_apply_port_sec") - + PIPELINE_STAGE(SWITCH, OUT, CHECK_PORT_SEC, 13, "ls_out_check_port_sec") \ + PIPELINE_STAGE(SWITCH, OUT, APPLY_PORT_SEC, 14, "ls_out_apply_port_sec") \ + PIPELINE_STAGE(SWITCH, OUT, MIRROR, 15, "ls_out_mirror") \ /* Logical router ingress stages. */ #define ROUTER_IN_PIPELINE_STAGES \ PIPELINE_STAGE(ROUTER, IN, ADMISSION, 0, "lr_in_admission") \ diff --git a/ovn-nb.xml b/ovn-nb.xml index 078bd6068..5f39acb5c 100644 --- a/ovn-nb.xml +++ b/ovn-nb.xml @@ -3960,6 +3960,18 @@ or <code>from-lport</code> mirrors the packets going out of logical port. <code>both</code> mirrors for both directions. </p> + + <p> + For mirrors of <var>type</var> <code>lport</code>, mirroring is + done as close to the interface as possible, so that the mirror + shows the traffic that is really present on that interface. + Packets coming into the logical port (<code>to-lport</code>) are + mirrored in the last egress table, that is, after ACLs, load + balancing and port security have already been applied. Packets + going out of the logical port (<code>from-lport</code>) are + mirrored the other way around, in the first ingress table, before + any of those are applied. + </p> </column> <column name="sink"> diff --git a/tests/ovn-northd.at b/tests/ovn-northd.at index 6572b1318..64e9873e5 100644 --- a/tests/ovn-northd.at +++ b/tests/ovn-northd.at @@ -10339,7 +10339,7 @@ ovn_strip_lflows ], [0], [dnl table=??(ls_in_l2_lkup ), priority=72 , match=(eth.mcast && (nd_na || nd_rs || nd_ra)), action=(outport = "_MC_flood"; output;) table=??(ls_in_l2_unknown ), priority=0 , match=(1), action=(output;) table=??(ls_in_l2_unknown ), priority=50 , match=(outport == "none"), action=(drop;) - table=??(ls_out_apply_port_sec), priority=0 , match=(1), action=(output;) + table=??(ls_out_apply_port_sec), priority=0 , match=(1), action=(next;) table=??(ls_out_apply_port_sec), priority=50 , match=(reg0[[15]] == 1), action=(drop;) table=??(ls_out_check_port_sec), priority=0 , match=(1), action=(reg0[[15]] = check_out_port_sec(); next;) table=??(ls_out_check_port_sec), priority=100 , match=(eth.mcast), action=(reg0[[15]] = 0; next;) @@ -10377,7 +10377,7 @@ ovn_strip_lflows ], [0], [dnl table=??(ls_in_l2_lkup ), priority=72 , match=(eth.mcast && (nd_na || nd_rs || nd_ra)), action=(outport = "_MC_flood"; output;) table=??(ls_in_l2_unknown ), priority=0 , match=(1), action=(output;) table=??(ls_in_l2_unknown ), priority=50 , match=(outport == "none"), action=(drop;) - table=??(ls_out_apply_port_sec), priority=0 , match=(1), action=(output;) + table=??(ls_out_apply_port_sec), priority=0 , match=(1), action=(next;) table=??(ls_out_apply_port_sec), priority=50 , match=(reg0[[15]] == 1), action=(drop;) table=??(ls_out_check_port_sec), priority=0 , match=(1), action=(reg0[[15]] = check_out_port_sec(); next;) table=??(ls_out_check_port_sec), priority=100 , match=(eth.mcast), action=(reg0[[15]] = 0; next;) @@ -10414,7 +10414,7 @@ ovn_strip_lflows ], [0], [dnl table=??(ls_in_l2_lkup ), priority=72 , match=(eth.mcast && (nd_na || nd_rs || nd_ra)), action=(outport = "_MC_flood"; output;) table=??(ls_in_l2_unknown ), priority=0 , match=(1), action=(output;) table=??(ls_in_l2_unknown ), priority=50 , match=(outport == "none"), action=(drop;) - table=??(ls_out_apply_port_sec), priority=0 , match=(1), action=(output;) + table=??(ls_out_apply_port_sec), priority=0 , match=(1), action=(next;) table=??(ls_out_apply_port_sec), priority=50 , match=(reg0[[15]] == 1), action=(drop;) table=??(ls_out_check_port_sec), priority=0 , match=(1), action=(reg0[[15]] = check_out_port_sec(); next;) table=??(ls_out_check_port_sec), priority=100 , match=(eth.mcast), action=(reg0[[15]] = 0; next;) @@ -10453,7 +10453,7 @@ ovn_strip_lflows ], [0], [dnl table=??(ls_in_l2_unknown ), priority=0 , match=(1), action=(output;) table=??(ls_in_l2_unknown ), priority=50 , match=(outport == "none"), action=(drop;) table=??(ls_in_l2_unknown ), priority=50 , match=(outport == "sw0p1"), action=(drop;) - table=??(ls_out_apply_port_sec), priority=0 , match=(1), action=(output;) + table=??(ls_out_apply_port_sec), priority=0 , match=(1), action=(next;) table=??(ls_out_apply_port_sec), priority=50 , match=(reg0[[15]] == 1), action=(drop;) table=??(ls_out_check_port_sec), priority=0 , match=(1), action=(reg0[[15]] = check_out_port_sec(); next;) table=??(ls_out_check_port_sec), priority=100 , match=(eth.mcast), action=(reg0[[15]] = 0; next;) @@ -10491,8 +10491,8 @@ ovn_strip_lflows ], [0], [dnl table=??(ls_in_l2_unknown ), priority=0 , match=(1), action=(output;) table=??(ls_in_l2_unknown ), priority=50 , match=(outport == "none"), action=(drop;) table=??(ls_in_l2_unknown ), priority=50 , match=(outport == "sw0p1"), action=(drop;) - table=??(ls_out_apply_port_sec), priority=0 , match=(1), action=(output;) - table=??(ls_out_apply_port_sec), priority=110 , match=(outport == "localnetport" && inport == "sw0p2"), action=(set_queue(10); output;) + table=??(ls_out_apply_port_sec), priority=0 , match=(1), action=(next;) + table=??(ls_out_apply_port_sec), priority=110 , match=(outport == "localnetport" && inport == "sw0p2"), action=(set_queue(10); next;) table=??(ls_out_apply_port_sec), priority=50 , match=(reg0[[15]] == 1), action=(drop;) table=??(ls_out_check_port_sec), priority=0 , match=(1), action=(reg0[[15]] = check_out_port_sec(); next;) table=??(ls_out_check_port_sec), priority=100 , match=(eth.mcast), action=(reg0[[15]] = 0; next;) @@ -10532,9 +10532,9 @@ ovn_strip_lflows ], [0], [dnl table=??(ls_in_l2_lkup ), priority=72 , match=(eth.mcast && (nd_na || nd_rs || nd_ra)), action=(outport = "_MC_flood"; output;) table=??(ls_in_l2_unknown ), priority=0 , match=(1), action=(output;) table=??(ls_in_l2_unknown ), priority=50 , match=(outport == "none"), action=(drop;) - table=??(ls_out_apply_port_sec), priority=0 , match=(1), action=(output;) - table=??(ls_out_apply_port_sec), priority=100 , match=(outport == "localnetport"), action=(set_queue(10); output;) - table=??(ls_out_apply_port_sec), priority=110 , match=(outport == "localnetport" && inport == "sw0p2"), action=(set_queue(10); output;) + table=??(ls_out_apply_port_sec), priority=0 , match=(1), action=(next;) + table=??(ls_out_apply_port_sec), priority=100 , match=(outport == "localnetport"), action=(set_queue(10); next;) + table=??(ls_out_apply_port_sec), priority=110 , match=(outport == "localnetport" && inport == "sw0p2"), action=(set_queue(10); next;) table=??(ls_out_apply_port_sec), priority=50 , match=(reg0[[15]] == 1), action=(drop;) table=??(ls_out_check_port_sec), priority=0 , match=(1), action=(reg0[[15]] = check_out_port_sec(); next;) table=??(ls_out_check_port_sec), priority=100 , match=(eth.mcast), action=(reg0[[15]] = 0; next;) @@ -20276,7 +20276,7 @@ ovn-sbctl lflow-list sw0 > lflow-list AT_CHECK([grep -e "ls_in_mirror" -e "ls_out_mirror" lflow-list | ovn_strip_lflows], [0], [dnl table=??(ls_in_mirror ), priority=0 , match=(1), action=(next;) - table=??(ls_out_mirror ), priority=0 , match=(1), action=(next;) + table=??(ls_out_mirror ), priority=0 , match=(1), action=(output;) ]) check ovn-nbctl lsp-attach-mirror sw0-p1 mirror0 @@ -20289,8 +20289,8 @@ check_column mirror Port_Binding type logical_port=mp-sw0-sw0-target0 ovn-sbctl lflow-list sw0 > lflow-list AT_CHECK([grep -e "ls_in_mirror" -e "ls_out_mirror" lflow-list | ovn_strip_lflows], [0], [dnl table=??(ls_in_mirror ), priority=0 , match=(1), action=(next;) - table=??(ls_out_mirror ), priority=0 , match=(1), action=(next;) - table=??(ls_out_mirror ), priority=100 , match=(outport == "sw0-p1"), action=(mirror("mp-sw0-sw0-target0"); next;) + table=??(ls_out_mirror ), priority=0 , match=(1), action=(output;) + table=??(ls_out_mirror ), priority=100 , match=(outport == "sw0-p1"), action=(mirror("mp-sw0-sw0-target0"); output;) ]) ovn-sbctl lflow-list sw0 > lflow-list @@ -20312,10 +20312,10 @@ AT_CHECK([grep -e "ls_in_mirror" -e "ls_out_mirror" lflow-list | ovn_strip_lflow table=??(ls_in_mirror ), priority=100 , match=(inport == "sw0-p1"), action=(mirror("mp-sw0-sw0-target0"); next;) table=??(ls_in_mirror ), priority=200 , match=(inport == "sw0-p1" && (ip)), action=(mirror("mp-sw0-sw0-target0"); next;) table=??(ls_in_mirror ), priority=250 , match=(inport == "sw0-p1" && (icmp)), action=(next;) - table=??(ls_out_mirror ), priority=0 , match=(1), action=(next;) - table=??(ls_out_mirror ), priority=100 , match=(outport == "sw0-p1"), action=(mirror("mp-sw0-sw0-target0"); next;) - table=??(ls_out_mirror ), priority=200 , match=(outport == "sw0-p1" && (ip)), action=(mirror("mp-sw0-sw0-target0"); next;) - table=??(ls_out_mirror ), priority=250 , match=(outport == "sw0-p1" && (icmp)), action=(next;) + table=??(ls_out_mirror ), priority=0 , match=(1), action=(output;) + table=??(ls_out_mirror ), priority=100 , match=(outport == "sw0-p1"), action=(mirror("mp-sw0-sw0-target0"); output;) + table=??(ls_out_mirror ), priority=200 , match=(outport == "sw0-p1" && (ip)), action=(mirror("mp-sw0-sw0-target0"); output;) + table=??(ls_out_mirror ), priority=250 , match=(outport == "sw0-p1" && (icmp)), action=(output;) ]) check ovn-nbctl lsp-attach-mirror sw0-p1 mirror2 @@ -20334,10 +20334,10 @@ AT_CHECK([grep -e "ls_in_mirror" -e "ls_out_mirror" lflow-list | ovn_strip_lflow table=??(ls_in_mirror ), priority=200 , match=(inport == "sw0-p1" && (ip4.dst == 192.168.0.1)), action=(mirror("mp-sw0-sw1-target1"); next;) table=??(ls_in_mirror ), priority=250 , match=(inport == "sw0-p1" && (1)), action=(next;) table=??(ls_in_mirror ), priority=250 , match=(inport == "sw0-p1" && (icmp)), action=(next;) - table=??(ls_out_mirror ), priority=0 , match=(1), action=(next;) - table=??(ls_out_mirror ), priority=100 , match=(outport == "sw0-p1"), action=(mirror("mp-sw0-sw0-target0"); next;) - table=??(ls_out_mirror ), priority=200 , match=(outport == "sw0-p1" && (ip)), action=(mirror("mp-sw0-sw0-target0"); next;) - table=??(ls_out_mirror ), priority=250 , match=(outport == "sw0-p1" && (icmp)), action=(next;) + table=??(ls_out_mirror ), priority=0 , match=(1), action=(output;) + table=??(ls_out_mirror ), priority=100 , match=(outport == "sw0-p1"), action=(mirror("mp-sw0-sw0-target0"); output;) + table=??(ls_out_mirror ), priority=200 , match=(outport == "sw0-p1" && (ip)), action=(mirror("mp-sw0-sw0-target0"); output;) + table=??(ls_out_mirror ), priority=250 , match=(outport == "sw0-p1" && (icmp)), action=(output;) ]) ovn-sbctl lflow-list sw0 > lflow-list @@ -20360,7 +20360,7 @@ AT_CHECK([grep -e "ls_in_mirror" -e "ls_out_mirror" lflow-list | ovn_strip_lflow table=??(ls_in_mirror ), priority=100 , match=(inport == "sw0-p1"), action=(mirror("mp-sw0-sw1-target1"); next;) table=??(ls_in_mirror ), priority=200 , match=(inport == "sw0-p1" && (ip4.dst == 192.168.0.1)), action=(mirror("mp-sw0-sw1-target1"); next;) table=??(ls_in_mirror ), priority=250 , match=(inport == "sw0-p1" && (1)), action=(next;) - table=??(ls_out_mirror ), priority=0 , match=(1), action=(next;) + table=??(ls_out_mirror ), priority=0 , match=(1), action=(output;) ]) AT_CHECK([grep -e "ls_out_pre_acl" lflow-list | ovn_strip_lflows], [0], [dnl @@ -20385,10 +20385,10 @@ AT_CHECK([grep -e "ls_in_mirror" -e "ls_out_mirror" lflow-list | ovn_strip_lflow table=??(ls_in_mirror ), priority=200 , match=(inport == "sw0-p1" && (ip4.dst == 192.168.0.1)), action=(mirror("mp-sw0-sw1-target1"); next;) table=??(ls_in_mirror ), priority=250 , match=(inport == "sw0-p1" && (1)), action=(next;) table=??(ls_in_mirror ), priority=250 , match=(inport == "sw0-p1" && (icmp)), action=(next;) - table=??(ls_out_mirror ), priority=0 , match=(1), action=(next;) - table=??(ls_out_mirror ), priority=100 , match=(outport == "sw0-p1"), action=(mirror("mp-sw0-sw0-target0"); next;) - table=??(ls_out_mirror ), priority=200 , match=(outport == "sw0-p1" && (ip)), action=(mirror("mp-sw0-sw0-target0"); next;) - table=??(ls_out_mirror ), priority=250 , match=(outport == "sw0-p1" && (icmp)), action=(next;) + table=??(ls_out_mirror ), priority=0 , match=(1), action=(output;) + table=??(ls_out_mirror ), priority=100 , match=(outport == "sw0-p1"), action=(mirror("mp-sw0-sw0-target0"); output;) + table=??(ls_out_mirror ), priority=200 , match=(outport == "sw0-p1" && (ip)), action=(mirror("mp-sw0-sw0-target0"); output;) + table=??(ls_out_mirror ), priority=250 , match=(outport == "sw0-p1" && (icmp)), action=(output;) ]) mirror1uuid_uuid=`ovn-nbctl --bare --columns _uuid find Mirror name="mirror1"` @@ -20405,11 +20405,11 @@ AT_CHECK([grep -e "ls_in_mirror" -e "ls_out_mirror" lflow-list | ovn_strip_lflow table=??(ls_in_mirror ), priority=200 , match=(inport == "sw0-p1" && (ip4.dst == 192.168.0.1)), action=(mirror("mp-sw0-sw1-target1"); next;) table=??(ls_in_mirror ), priority=250 , match=(inport == "sw0-p1" && (1)), action=(next;) table=??(ls_in_mirror ), priority=250 , match=(inport == "sw0-p1" && (icmp)), action=(next;) - table=??(ls_out_mirror ), priority=0 , match=(1), action=(next;) - table=??(ls_out_mirror ), priority=100 , match=(outport == "sw0-p1"), action=(mirror("mp-sw0-sw0-target0"); next;) - table=??(ls_out_mirror ), priority=100 , match=(outport == "sw0-p1"), action=(mirror("mp-sw0-sw1-target1"); next;) - table=??(ls_out_mirror ), priority=200 , match=(outport == "sw0-p1" && (ip)), action=(mirror("mp-sw0-sw1-target1"); next;) - table=??(ls_out_mirror ), priority=250 , match=(outport == "sw0-p1" && (icmp)), action=(next;) + table=??(ls_out_mirror ), priority=0 , match=(1), action=(output;) + table=??(ls_out_mirror ), priority=100 , match=(outport == "sw0-p1"), action=(mirror("mp-sw0-sw0-target0"); output;) + table=??(ls_out_mirror ), priority=100 , match=(outport == "sw0-p1"), action=(mirror("mp-sw0-sw1-target1"); output;) + table=??(ls_out_mirror ), priority=200 , match=(outport == "sw0-p1" && (ip)), action=(mirror("mp-sw0-sw1-target1"); output;) + table=??(ls_out_mirror ), priority=250 , match=(outport == "sw0-p1" && (icmp)), action=(output;) ]) check_row_count Port_Binding 1 logical_port=mp-sw0-sw0-target0 @@ -20425,7 +20425,7 @@ check ovn-nbctl --wait=sb sync ovn-sbctl lflow-list sw0 > lflow-list AT_CHECK([grep -e "ls_in_mirror" -e "ls_out_mirror" lflow-list | ovn_strip_lflows], [0], [dnl table=??(ls_in_mirror ), priority=0 , match=(1), action=(next;) - table=??(ls_out_mirror ), priority=0 , match=(1), action=(next;) + table=??(ls_out_mirror ), priority=0 , match=(1), action=(output;) ]) ovn-sbctl lflow-list sw0 > lflow-list diff --git a/tests/ovn-util.at b/tests/ovn-util.at index 315539342..aecf908ef 100644 --- a/tests/ovn-util.at +++ b/tests/ovn-util.at @@ -78,7 +78,7 @@ AT_CHECK_UNQUOTED([cat trace | $PYTHON $top_srcdir/utilities/ovn_detrace.py.in], resubmit(,??) * Logical datapaths: * "ls" ($dp_uuid) [[egress]] - * Logical flow: table=$egress_table (ls_out_apply_port_sec), priority=0, match=(1), actions=(output;) + * Logical flow: table=$egress_table (ls_out_apply_port_sec), priority=0, match=(1), actions=(next;) 65. reg15=0x2,metadata=0x1, priority 100, cookie $pb_vm1 output:2 * Logical datapath: "ls" ($dp_uuid) @@ -99,7 +99,7 @@ cookie=$ingress, priority=50,metadata=0x1 actions=load:0->NXM_NX_REG10[[12]],res cookie=$egress, priority=0,metadata=0x1 actions=resubmit(,??) * Logical datapaths: * "ls" ($dp_uuid) [[egress]] - * Logical flow: table=$egress_table (ls_out_apply_port_sec), priority=0, match=(1), actions=(output;) + * Logical flow: table=$egress_table (ls_out_apply_port_sec), priority=0, match=(1), actions=(next;) ]) diff --git a/tests/ovn.at b/tests/ovn.at index 13e95f9db..2c90c5ce4 100644 --- a/tests/ovn.at +++ b/tests/ovn.at @@ -19593,8 +19593,8 @@ check_column "$hv3_uuid" sb:Port_Binding chassis logical_port=mp-ls1-ls2-lp2 AT_CHECK([ovn-sbctl lflow-list ls1 | grep mirror| ovn_strip_lflows], [0], [dnl table=??(ls_in_mirror ), priority=0 , match=(1), action=(next;) table=??(ls_in_mirror ), priority=100 , match=(inport == "ls1-lp1"), action=(mirror("mp-ls1-ls2-lp2"); next;) - table=??(ls_out_mirror ), priority=0 , match=(1), action=(next;) - table=??(ls_out_mirror ), priority=100 , match=(outport == "ls1-lp1"), action=(mirror("mp-ls1-ls2-lp2"); next;) + table=??(ls_out_mirror ), priority=0 , match=(1), action=(output;) + table=??(ls_out_mirror ), priority=100 , match=(outport == "ls1-lp1"), action=(mirror("mp-ls1-ls2-lp2"); output;) ]) as hv2 reset_pcap_file hv2-vif1 hv2/vif1 @@ -19644,7 +19644,7 @@ check_row_count Port_Binding 0 logical_port=mp-ls1-ls2-lp2 AT_CHECK([ovn-sbctl lflow-list ls1 | grep mirror| ovn_strip_lflows], [0], [dnl table=??(ls_in_mirror ), priority=0 , match=(1), action=(next;) - table=??(ls_out_mirror ), priority=0 , match=(1), action=(next;) + table=??(ls_out_mirror ), priority=0 , match=(1), action=(output;) ]) as hv3 reset_pcap_file hv3-vif1 hv3/vif1 @@ -19679,9 +19679,9 @@ AT_CHECK([ovn-sbctl lflow-list ls1 | grep mirror | ovn_strip_lflows], [0], [dnl table=??(ls_in_mirror ), priority=0 , match=(1), action=(next;) table=??(ls_in_mirror ), priority=100 , match=(inport == "ls1-lp1"), action=(mirror("mp-ls1-ls2-lp2"); next;) table=??(ls_in_mirror ), priority=300 , match=(inport == "ls1-lp1" && (1)), action=(next;) - table=??(ls_out_mirror ), priority=0 , match=(1), action=(next;) - table=??(ls_out_mirror ), priority=100 , match=(outport == "ls1-lp1"), action=(mirror("mp-ls1-ls2-lp2"); next;) - table=??(ls_out_mirror ), priority=300 , match=(outport == "ls1-lp1" && (1)), action=(next;) + table=??(ls_out_mirror ), priority=0 , match=(1), action=(output;) + table=??(ls_out_mirror ), priority=100 , match=(outport == "ls1-lp1"), action=(mirror("mp-ls1-ls2-lp2"); output;) + table=??(ls_out_mirror ), priority=300 , match=(outport == "ls1-lp1" && (1)), action=(output;) ]) AT_CHECK([ovn-sbctl lflow-list ls1 | grep ls_out_pre_acl | ovn_strip_lflows], [0], [dnl @@ -19694,7 +19694,7 @@ AT_CHECK([ovn-sbctl lflow-list ls1 | grep ls_out_pre_acl | ovn_strip_lflows], [0 check ovn-nbctl --wait=sb lsp-del ls2-lp2 AT_CHECK([ovn-sbctl lflow-list ls1 | grep mirror | ovn_strip_lflows], [0], [dnl table=??(ls_in_mirror ), priority=0 , match=(1), action=(next;) - table=??(ls_out_mirror ), priority=0 , match=(1), action=(next;) + table=??(ls_out_mirror ), priority=0 , match=(1), action=(output;) ]) check ovn-nbctl lsp-add ls2 ls2-lp2 @@ -19717,10 +19717,10 @@ AT_CHECK([ovn-sbctl lflow-list ls1 | grep mirror| ovn_strip_lflows], [0], [dnl table=??(ls_in_mirror ), priority=100 , match=(inport == "ls1-lp1"), action=(mirror("mp-ls1-ls2-lp2"); next;) table=??(ls_in_mirror ), priority=300 , match=(inport == "ls1-lp1" && (1)), action=(next;) table=??(ls_in_mirror ), priority=400 , match=(inport == "ls1-lp1" && (udp.dst == 4369)), action=(mirror("mp-ls1-ls2-lp2"); next;) - table=??(ls_out_mirror ), priority=0 , match=(1), action=(next;) - table=??(ls_out_mirror ), priority=100 , match=(outport == "ls1-lp1"), action=(mirror("mp-ls1-ls2-lp2"); next;) - table=??(ls_out_mirror ), priority=300 , match=(outport == "ls1-lp1" && (1)), action=(next;) - table=??(ls_out_mirror ), priority=400 , match=(outport == "ls1-lp1" && (udp.dst == 4369)), action=(mirror("mp-ls1-ls2-lp2"); next;) + table=??(ls_out_mirror ), priority=0 , match=(1), action=(output;) + table=??(ls_out_mirror ), priority=100 , match=(outport == "ls1-lp1"), action=(mirror("mp-ls1-ls2-lp2"); output;) + table=??(ls_out_mirror ), priority=300 , match=(outport == "ls1-lp1" && (1)), action=(output;) + table=??(ls_out_mirror ), priority=400 , match=(outport == "ls1-lp1" && (udp.dst == 4369)), action=(mirror("mp-ls1-ls2-lp2"); output;) ]) AT_CHECK([ovn-sbctl lflow-list ls1 | grep ls_out_pre_acl | ovn_strip_lflows], [0], [dnl -- 2.48.1 _______________________________________________ dev mailing list [email protected] https://mail.openvswitch.org/mailman/listinfo/ovs-dev
