On 10/5/26 10:31 AM, Ales Musil wrote:
> On Fri, Oct 2, 2026 at 8:34 PM Dumitru Ceara via dev <
> [email protected]> wrote:
> 
>> When a logical switch port has both port_security and "unknown"
>> in its addresses, build_lswitch_learn_fdb_op() skipped FDB
>> learning flow generation because of an early-return guard that
>> checked op->lsp_has_port_sec.
>>
>> When multiple logical switch ports share the same MAC address
>> (e.g., a VRRP virtual MAC) in their LSP.addresses, northd
>> generates duplicate L2 lookup flows at the same priority with
>> the same match but different outport actions.  Since
>> ovn-controller can only install one, traffic to the shared MAC
>> is nondeterministically sent to only one of the ports.
>>
>> The recommended configuration to avoid this is to omit the shared
>> MAC from LSP.addresses (placing it only in port_security) and
>> include "unknown" in addresses, so the shared MAC is resolved
>> dynamically via FDB learning.  However, the early-return guard
>> blocked FDB learning on ports with port_security, preventing
>> this configuration from working.
>>
>> The original guard was added in commit dd94f1266 ("northd: MAC
>> learning: Add logical flows for fdb") under the assumption that
>> ports with port security should not participate in FDB learning.
>> However, ingress port security (ls_in_check_port_sec) validates
>> source MACs before the FDB learning stages (ls_in_lookup_fdb,
>> ls_in_put_fdb), so only MACs that pass port security are
>> recorded.  Egress port security also validates packets after L2
>> lookup.  Removing the lsp_has_port_sec check is therefore safe.
>>
>> Reported-at: https://redhat.atlassian.net/browse/FDP-4286
>> Assisted-by: Claude Opus 4.6, Claude Code
>> Signed-off-by: Dumitru Ceara <[email protected]>
>> ---

...

>>
>>
> Hi Dumitru,
> 

Hi Ales,

> same as in the 1/2 aren't we missing update to ovn-logical-flows.7.rst?

Yeah we are, I'll do that in v2.

> Other than that it looks good.
> 
> Regards,
> Ales
> 

Thanks,
Dumitru

_______________________________________________
dev mailing list
[email protected]
https://mail.openvswitch.org/mailman/listinfo/ovs-dev

Reply via email to