Re: [ovs-dev] [PATCH ovn 3/3] Honor ACL direction when omitting ct for stateless

2021-06-07 Thread Ihar Hrachyshka
On Wed, Jun 2, 2021 at 12:22 AM Han Zhou wrote: > > > > On Tue, Jun 1, 2021 at 12:28 PM Ihar Hrachyshka wrote: > > > > On Thu, May 20, 2021 at 9:55 PM Han Zhou wrote: > > > > > > > > > > > > On Thu, May 20, 2021 at 3:22 PM Han Zhou wrote: > > > > > > > > > > > > > > > > On Mon, May 17, 2021 at

Re: [ovs-dev] [PATCH ovn 3/3] Honor ACL direction when omitting ct for stateless

2021-06-01 Thread Han Zhou
On Tue, Jun 1, 2021 at 12:28 PM Ihar Hrachyshka wrote: > > On Thu, May 20, 2021 at 9:55 PM Han Zhou wrote: > > > > > > > > On Thu, May 20, 2021 at 3:22 PM Han Zhou wrote: > > > > > > > > > > > > On Mon, May 17, 2021 at 2:47 PM Ihar Hrachyshka wrote: > > > > > > > > While we *should not*

Re: [ovs-dev] [PATCH ovn 3/3] Honor ACL direction when omitting ct for stateless

2021-06-01 Thread Ihar Hrachyshka
On Thu, May 20, 2021 at 6:22 PM Han Zhou wrote: > > > > On Mon, May 17, 2021 at 2:47 PM Ihar Hrachyshka wrote: > > > > While we *should not* circumvent conntrack when a stateful ACL of higher > > priority is present on the switch, we should do so only when > > allow-stateless and allow-stateful

Re: [ovs-dev] [PATCH ovn 3/3] Honor ACL direction when omitting ct for stateless

2021-06-01 Thread Ihar Hrachyshka
On Thu, May 20, 2021 at 9:55 PM Han Zhou wrote: > > > > On Thu, May 20, 2021 at 3:22 PM Han Zhou wrote: > > > > > > > > On Mon, May 17, 2021 at 2:47 PM Ihar Hrachyshka wrote: > > > > > > While we *should not* circumvent conntrack when a stateful ACL of higher > > > priority is present on the

Re: [ovs-dev] [PATCH ovn 3/3] Honor ACL direction when omitting ct for stateless

2021-05-20 Thread Han Zhou
On Thu, May 20, 2021 at 3:22 PM Han Zhou wrote: > > > > On Mon, May 17, 2021 at 2:47 PM Ihar Hrachyshka wrote: > > > > While we *should not* circumvent conntrack when a stateful ACL of higher > > priority is present on the switch, we should do so only when > > allow-stateless and allow-stateful

Re: [ovs-dev] [PATCH ovn 3/3] Honor ACL direction when omitting ct for stateless

2021-05-20 Thread Han Zhou
On Mon, May 17, 2021 at 2:47 PM Ihar Hrachyshka wrote: > > While we *should not* circumvent conntrack when a stateful ACL of higher > priority is present on the switch, we should do so only when > allow-stateless and allow-stateful directions are the same, otherwise we > should still skip

[ovs-dev] [PATCH ovn 3/3] Honor ACL direction when omitting ct for stateless

2021-05-17 Thread Ihar Hrachyshka
While we *should not* circumvent conntrack when a stateful ACL of higher priority is present on the switch, we should do so only when allow-stateless and allow-stateful directions are the same, otherwise we should still skip conntrack for allow-stateless ACLs. Fixes: 3187b9fef1 ("ovn-northd: