On Mon, Sep 28, 2026 at 2:10 PM Xavier Simonart via dev <
[email protected]> wrote:
> The tests were failing if conntrack entry such as [0] use a random port
> containing 2001.
>
> [0]
> tcp,orig=(src=4242::3,dst=4242::2,sport=32001,dport=4242),reply=(src=4242::2,dst=4242::3,sport=4242,dport=32001),zone=4,protoinfo=(state=CLOSING)
>
> Fixes: 0904c9f98f6e ("system-ovn.at: Fix 'load-balancer and firewall
> tuple conflict' tests.")
> Signed-off-by: Xavier Simonart <[email protected]>
> ---
> tests/system-ovn.at | 8 ++++----
> 1 file changed, 4 insertions(+), 4 deletions(-)
>
> diff --git a/tests/system-ovn.at b/tests/system-ovn.at
> index 5b6ba3731..bcae2dbbd 100644
> --- a/tests/system-ovn.at
> +++ b/tests/system-ovn.at
> @@ -6265,7 +6265,7 @@ NS_CHECK_EXEC([vm2], [ncat 66.66.66.66 666 -p 2001
> -z], [0], [ignore], [ignore])
> # Check conntrack. We expect two entries:
> # - one in vm1's zone (firewall)
> # - one in vm2's zone (dnat)
> -AT_CHECK([ovs-appctl dpctl/dump-conntrack | grep 2001 | \
> +AT_CHECK([ovs-appctl dpctl/dump-conntrack | grep "sport=2001," | \
> grep "orig=.src=42\.42\.42\.3" | \
> sed -e 's/sport=2001/sport=<clnt_s_port>/g' \
> -e 's/dport=2001/dport=<clnt_s_port>/g' \
> @@ -6284,7 +6284,7 @@ NS_CHECK_EXEC([vm2], [ncat 42.42.42.2 4242 -p 2001
> -z], [0], [ignore], [ignore])
> # - one in vm1's zone (firewall) - reused from the previous connection.
> # - one in vm2's zone (dnat) - still in TIME_WAIT after the previous
> connection.
> # - one in vm2's zone (firewall + additional all-zero SNAT)
> -AT_CHECK([ovs-appctl dpctl/dump-conntrack | grep 2001 | \
> +AT_CHECK([ovs-appctl dpctl/dump-conntrack | grep "sport=2001," | \
> grep "orig=.src=42\.42\.42\.3" | \
> sed -e 's/port=2001/port=<clnt_s_port>/g' \
> -e 's/sport=4242,dport=[[0-9]]\+/sport=4242,dport=<rnd_port>/g' \
> @@ -6365,7 +6365,7 @@ NS_CHECK_EXEC([vm2], [ncat 6666::1 666 -p 2001 -z],
> [0], [ignore], [ignore])
> # Check conntrack. We expect two entries:
> # - one in vm1's zone (firewall)
> # - one in vm2's zone (dnat)
> -AT_CHECK([ovs-appctl dpctl/dump-conntrack | grep 2001 | \
> +AT_CHECK([ovs-appctl dpctl/dump-conntrack | grep "sport=2001," | \
> grep "orig=.src=4242::3" | \
> sed -e 's/sport=2001/sport=<clnt_s_port>/g' \
> -e 's/dport=2001/dport=<clnt_s_port>/g' \
> @@ -6384,7 +6384,7 @@ NS_CHECK_EXEC([vm2], [ncat 4242::2 4242 -p 2001 -z],
> [0], [ignore], [ignore])
> # - one in vm1's zone (firewall) - reused from the previous connection.
> # - one in vm2's zone (dnat) - still in TIME_WAIT after the previous
> connection.
> # - one in vm2's zone (firewall + additional all-zero SNAT)
> -AT_CHECK([ovs-appctl dpctl/dump-conntrack | grep 2001 | \
> +AT_CHECK([ovs-appctl dpctl/dump-conntrack | grep "sport=2001," | \
> grep "orig=.src=4242::3" | \
> sed -e 's/port=2001/port=<clnt_s_port>/g' \
> -e 's/sport=4242,dport=[[0-9]]\+/sport=4242,dport=<rnd_port>/g' \
> --
> 2.47.1
>
> _______________________________________________
> dev mailing list
> [email protected]
> https://mail.openvswitch.org/mailman/listinfo/ovs-dev
>
>
Thank you Xavier,
applied to main and backported down to 26.03.
Regards,
Ales
_______________________________________________
dev mailing list
[email protected]
https://mail.openvswitch.org/mailman/listinfo/ovs-dev