On Mon, Sep 28, 2026 at 2:10 PM Xavier Simonart via dev <
[email protected]> wrote:

> The tests were failing if conntrack entry such as [0] use a random port
> containing 2001.
>
> [0]
> tcp,orig=(src=4242::3,dst=4242::2,sport=32001,dport=4242),reply=(src=4242::2,dst=4242::3,sport=4242,dport=32001),zone=4,protoinfo=(state=CLOSING)
>
> Fixes: 0904c9f98f6e ("system-ovn.at: Fix 'load-balancer and firewall
> tuple conflict' tests.")
> Signed-off-by: Xavier Simonart <[email protected]>
> ---
>  tests/system-ovn.at | 8 ++++----
>  1 file changed, 4 insertions(+), 4 deletions(-)
>
> diff --git a/tests/system-ovn.at b/tests/system-ovn.at
> index 5b6ba3731..bcae2dbbd 100644
> --- a/tests/system-ovn.at
> +++ b/tests/system-ovn.at
> @@ -6265,7 +6265,7 @@ NS_CHECK_EXEC([vm2], [ncat 66.66.66.66 666 -p 2001
> -z], [0], [ignore], [ignore])
>  # Check conntrack.  We expect two entries:
>  # - one in vm1's zone (firewall)
>  # - one in vm2's zone (dnat)
> -AT_CHECK([ovs-appctl dpctl/dump-conntrack | grep 2001 |             \
> +AT_CHECK([ovs-appctl dpctl/dump-conntrack | grep "sport=2001," |    \
>  grep "orig=.src=42\.42\.42\.3" |                                    \
>  sed -e 's/sport=2001/sport=<clnt_s_port>/g'                         \
>      -e 's/dport=2001/dport=<clnt_s_port>/g'                         \
> @@ -6284,7 +6284,7 @@ NS_CHECK_EXEC([vm2], [ncat 42.42.42.2 4242 -p 2001
> -z], [0], [ignore], [ignore])
>  # - one in vm1's zone (firewall) - reused from the previous connection.
>  # - one in vm2's zone (dnat) - still in TIME_WAIT after the previous
> connection.
>  # - one in vm2's zone (firewall + additional all-zero SNAT)
> -AT_CHECK([ovs-appctl dpctl/dump-conntrack | grep 2001 |             \
> +AT_CHECK([ovs-appctl dpctl/dump-conntrack | grep "sport=2001," |    \
>  grep "orig=.src=42\.42\.42\.3" |                                    \
>  sed -e 's/port=2001/port=<clnt_s_port>/g'                           \
>      -e 's/sport=4242,dport=[[0-9]]\+/sport=4242,dport=<rnd_port>/g' \
> @@ -6365,7 +6365,7 @@ NS_CHECK_EXEC([vm2], [ncat 6666::1 666 -p 2001 -z],
> [0], [ignore], [ignore])
>  # Check conntrack.  We expect two entries:
>  # - one in vm1's zone (firewall)
>  # - one in vm2's zone (dnat)
> -AT_CHECK([ovs-appctl dpctl/dump-conntrack | grep 2001 |             \
> +AT_CHECK([ovs-appctl dpctl/dump-conntrack | grep "sport=2001," |   \
>  grep "orig=.src=4242::3" |                                         \
>  sed -e 's/sport=2001/sport=<clnt_s_port>/g'                        \
>      -e 's/dport=2001/dport=<clnt_s_port>/g'                        \
> @@ -6384,7 +6384,7 @@ NS_CHECK_EXEC([vm2], [ncat 4242::2 4242 -p 2001 -z],
> [0], [ignore], [ignore])
>  # - one in vm1's zone (firewall) - reused from the previous connection.
>  # - one in vm2's zone (dnat) - still in TIME_WAIT after the previous
> connection.
>  # - one in vm2's zone (firewall + additional all-zero SNAT)
> -AT_CHECK([ovs-appctl dpctl/dump-conntrack | grep 2001 |             \
> +AT_CHECK([ovs-appctl dpctl/dump-conntrack | grep "sport=2001," |    \
>  grep "orig=.src=4242::3" |                                          \
>  sed -e 's/port=2001/port=<clnt_s_port>/g'                           \
>      -e 's/sport=4242,dport=[[0-9]]\+/sport=4242,dport=<rnd_port>/g' \
> --
> 2.47.1
>
> _______________________________________________
> dev mailing list
> [email protected]
> https://mail.openvswitch.org/mailman/listinfo/ovs-dev
>
>

Thank you Xavier,

applied to main and backported down to 26.03.

Regards,
Ales
_______________________________________________
dev mailing list
[email protected]
https://mail.openvswitch.org/mailman/listinfo/ovs-dev

Reply via email to