From nobody Sat Jul 25 22:31:37 2026 Received: from mail-pf1-f179.google.com (mail-pf1-f179.google.com [209.85.210.179]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 2BC8135E926 for ; Sun, 12 Jul 2026 19:16:36 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.210.179 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1783883798; cv=none; b=ohR1wYE/O8OxN8RrqnpYwi94WUV3jGe7ZAfQkZU9KtbakaKcCN/g58bgR83To/26Mf/wFwsP6mkvdILEyOhviLJGecLzMCRe+QtEzHCcx3LqW/YdDwdqZQn0WsIEjNX7xWWIwwyUMT7LTQdtAU14H5j9s1WXYG51N2k1yTNW6Es= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1783883798; c=relaxed/simple; bh=JrTPNvQ0flhd1tFp7KOKk0TjVPFOh/+u3dYBiZMQES0=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=kdqKwdXOVSaH6Ncze/BMDoBi1FK+B5l3pkbg3xpWLD8AUiGT96bG3i5FjcuTD0KF/rQICTQewZKNqJlY0UNS55I8OXF3m67YG6ZgTUiNVFVxt9e6AfIDhwh/LagIRMFmkAWo6k0FFWsIZbLYAA9gxM/HTuEVGVYaUo8/sJsdjHc= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=TlJZBupE; arc=none smtp.client-ip=209.85.210.179 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="TlJZBupE" Received: by mail-pf1-f179.google.com with SMTP id d2e1a72fcca58-8453427d3f4so2040243b3a.3 for ; Sun, 12 Jul 2026 12:16:36 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1783883796; x=1784488596; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=MXvw9tkS7HVFrKwqha0vwk13jo9XOAWNQkd/wZQoS/A=; b=TlJZBupEcB85gkE4FEmh1x97+bEAqphFEC59x3y4lA5rQYmayN/qbipR03gUO1xSlu oo3K8eJvnfWOnWndCUOlyGBesW9GZ/MTl3U3GsaeH2jPx6vSO79DCkKB9FTrQ24jQheX 7dyztGkKo9ae8MM1Gr1x9gasWBzkKRUYHJPJ6gb9WFufkqsyKByG6cO+tNU0wHdAru9O T6sr1aRg0rOScgZOogKSx4cBKDZq08JThbPlaD90XAgN/SXpWkruAod83N+0hHaU+KSb mVc3CtdRDpC35aGMJrNKE8477cakk5J4hd02uE6DtN6n/HgMM0IPu1u6E6uoZWSpQ2PG XFbw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1783883796; x=1784488596; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=MXvw9tkS7HVFrKwqha0vwk13jo9XOAWNQkd/wZQoS/A=; b=qkIneUL5m2bZxoSnaFFQXNWrYxFfSVEMKh+VLR++Nh+M0uSH+kRI4UH/6qQHdqwq4c e2CRvJ4QMqI8W0ySWp49AHcPTIjznggrh/IEga0aTQzLSDtDFzHJXnbW3jG7Z6v/37pm MduoNsrgT5rsvtygBLNQ249W5w689cxF672UBTGmKtEqmfW5wXoyf22RJKzodwcitCGC YlBF6bA76hF72vR8Gj9YeAagzQzEPFH3swVYvNy8q5/u7AgcuLYYkdBkaCYjPzpZBL6x Rfz/NKpJhUL7QMHmO4tZlHv84Y5K3aHQvwhXpHEK3ypdO8uWdkCFedeoKiRRUJpNOKRp tE3Q== X-Forwarded-Encrypted: i=1; AHgh+RpWL1SAKTQ05sinUqhZR8PJcWxmhvWmGlW83E1GeHdxnODBHFmqi5pzyUlsFfT87Nhnms1gJ3sMWpKUjIM=@vger.kernel.org X-Gm-Message-State: AOJu0YyvAeqc6Bkb09v8Gxaj1RgKADmr8Y/ZJc3LmFu5E383adBaPaVV 1nPa9AYW2YDYfIkvK+rEul0K8Aj0R403wpqZDG3jMSa0ull2W9ZOUzLv X-Gm-Gg: AfdE7ck14mp75nRBcbkv+3966cQ4WFsyDFE0pwMk+HHe+9VUCzwHTCZ2Z5at4cSrjHp sa9nhIB0jH/bNFNAnTosT7vwipuTcZ/DNvK1p4ypAwQakQ4Jo+I5opuLfnBiXjzDw0r8i3PfuC/ C1DrjUhoavS9LjgDmhAkohRWOxPXeaNBSFmfFOr0JJfSObXcYJgviMBIgsPUR9scyT4B1Zr2YdW CVl4+UXFPlAAMnXhFeuLHMCmwwRe8Ve2VvASp4uBP/8J65tNUTu8YSM3jlZFLY8tE2E2SU+YYZj c/oOWT52WscM0fTRU/rHsj8dZgbLc1N62eMqIzUoPxjad8Z7c7ATtsjQqS4C+vZEpyF9q060vUc TF4zWX2dwgjlJMgwyBZCyewJUISSx1Af/AM1/n25x8cvN0bUJ6C3ZIGTy0GGRiToX0cz/FTnlYZ UL/1BBOkPTU+p2LAbmJyxOGgrEtqOlrkFYAiwZI7QwcJJrzuiqHCrqyjlv X-Received: by 2002:a05:6a00:18a0:b0:842:2ae0:968d with SMTP id d2e1a72fcca58-84889625055mr5396777b3a.32.1783883796276; Sun, 12 Jul 2026 12:16:36 -0700 (PDT) Received: from CPC-mjac-HKWGEZ.redmond.corp.microsoft.com ([70.37.26.40]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-847f6ddc974sm13079371b3a.60.2026.07.12.12.16.35 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 12 Jul 2026 12:16:35 -0700 (PDT) From: Jack Ma To: netdev@vger.kernel.org, David Ahern Cc: Ido Schimmel , "David S . Miller" , Eric Dumazet , Jakub Kicinski , Paolo Abeni , Simon Horman , Shuah Khan , linux-kselftest@vger.kernel.org, linux-kernel@vger.kernel.org, Jack Ma Subject: [PATCH net-next 1/3] net: nexthop: add NHA_FDB_PORT for fdb nexthops Date: Sun, 12 Jul 2026 19:12:16 +0000 Message-ID: <20260712191218.236-2-jack4it@gmail.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260712191218.236-1-jack4it@gmail.com> References: <20260712191218.236-1-jack4it@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" Commit 1274e1cc4226 ("vxlan: ecmp support for mac fdb entries") lets a single inner MAC be reached through a group of remote VTEPs, with the kernel flow-hashing across the group members. Each member carries its own remote IP, but the UDP destination port is always taken from the VXLAN device (vxlan->cfg.dst_port) and cannot be set per member. Some deployments pack several receivers behind one underlay IP and tell them apart by UDP port, so they need a per-nexthop destination port to spread flows across (IP, port) tuples rather than IP alone. Add a netlink attribute NHA_FDB_PORT (__be16, mirroring NDA_PORT) that carries an optional UDP destination port on an fdb nexthop. It is only accepted together with NHA_FDB and NHA_GATEWAY; it is stored in struct nh_info and echoed back on dump. This patch is control-plane plumbing only; the VXLAN datapath is wired up in a follow-up patch, so behaviour is unchanged for now. Signed-off-by: Jack Ma --- include/net/nexthop.h | 2 ++ include/uapi/linux/nexthop.h | 3 +++ net/ipv4/nexthop.c | 20 +++++++++++++++++++- 3 files changed, 24 insertions(+), 1 deletion(-) diff --git a/include/net/nexthop.h b/include/net/nexthop.h index 572e69cda..9c8227996 100644 --- a/include/net/nexthop.h +++ b/include/net/nexthop.h @@ -28,6 +28,7 @@ struct nh_config { u8 nh_protocol; u8 nh_blackhole; u8 nh_fdb; + __be16 nh_fdb_port; u32 nh_flags; =20 int nh_ifindex; @@ -63,6 +64,7 @@ struct nh_info { u8 family; bool reject_nh; bool fdb_nh; + __be16 fdb_port; =20 union { struct fib_nh_common fib_nhc; diff --git a/include/uapi/linux/nexthop.h b/include/uapi/linux/nexthop.h index bc49baf4a..e587bbf3b 100644 --- a/include/uapi/linux/nexthop.h +++ b/include/uapi/linux/nexthop.h @@ -83,6 +83,9 @@ enum { /* u32; read-only; whether any driver collects HW stats */ NHA_HW_STATS_USED, =20 + /* be16; UDP destination port for an fdb nexthop (e.g. VXLAN) */ + NHA_FDB_PORT, + __NHA_MAX, }; =20 diff --git a/net/ipv4/nexthop.c b/net/ipv4/nexthop.c index 6205bd57a..5b27cc9a9 100644 --- a/net/ipv4/nexthop.c +++ b/net/ipv4/nexthop.c @@ -39,6 +39,7 @@ static const struct nla_policy rtm_nh_policy_new[] =3D { [NHA_ENCAP_TYPE] =3D { .type =3D NLA_U16 }, [NHA_ENCAP] =3D { .type =3D NLA_NESTED }, [NHA_FDB] =3D { .type =3D NLA_FLAG }, + [NHA_FDB_PORT] =3D { .type =3D NLA_U16 }, [NHA_RES_GROUP] =3D { .type =3D NLA_NESTED }, [NHA_HW_STATS_ENABLE] =3D NLA_POLICY_MAX(NLA_U32, true), }; @@ -956,6 +957,9 @@ static int nh_fill_node(struct sk_buff *skb, struct nex= thop *nh, } else if (nhi->fdb_nh) { if (nla_put_flag(skb, NHA_FDB)) goto nla_put_failure; + if (nhi->fdb_port && + nla_put_be16(skb, NHA_FDB_PORT, nhi->fdb_port)) + goto nla_put_failure; } else { const struct net_device *dev; =20 @@ -1055,6 +1059,9 @@ static size_t nh_nlmsg_size_single(struct nexthop *nh) break; } =20 + if (nhi->fdb_nh) + sz +=3D nla_total_size(2); /* NHA_FDB_PORT */ + if (nhi->fib_nhc.nhc_lwtstate) { sz +=3D lwtunnel_get_encap_size(nhi->fib_nhc.nhc_lwtstate); sz +=3D nla_total_size(2); /* NHA_ENCAP_TYPE */ @@ -2956,8 +2963,10 @@ static struct nexthop *nexthop_create(struct net *ne= t, struct nh_config *cfg, nhi->family =3D cfg->nh_family; nhi->fib_nhc.nhc_scope =3D RT_SCOPE_LINK; =20 - if (cfg->nh_fdb) + if (cfg->nh_fdb) { nhi->fdb_nh =3D 1; + nhi->fdb_port =3D cfg->nh_fdb_port; + } =20 if (cfg->nh_blackhole) { nhi->reject_nh =3D 1; @@ -3147,6 +3156,15 @@ static int rtm_to_nh_config(struct net *net, struct = sk_buff *skb, cfg->nh_fdb =3D nla_get_flag(tb[NHA_FDB]); } =20 + if (tb[NHA_FDB_PORT]) { + if (!tb[NHA_FDB] || !tb[NHA_GATEWAY]) { + NL_SET_ERR_MSG(extack, + "FDB port can only be set on fdb nexthops that have a gateway"); + goto out; + } + cfg->nh_fdb_port =3D nla_get_be16(tb[NHA_FDB_PORT]); + } + if (tb[NHA_GROUP]) { if (nhm->nh_family !=3D AF_UNSPEC) { NL_SET_ERR_MSG(extack, "Invalid family for group"); --=20 2.43.0 From nobody Sat Jul 25 22:31:37 2026 Received: from mail-pf1-f175.google.com (mail-pf1-f175.google.com [209.85.210.175]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 772593B42C0 for ; Sun, 12 Jul 2026 19:16:40 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.210.175 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1783883801; cv=none; b=G3Qjx1pZ1KENGkq9eM2gGbKmcH+51y1CBAdCDiXsZJwCwyfFC/qRgMqamja1vYzxxAGhSqutHxHElxdt+uWsrP6BaN94raC84lWP1etLN0G+4Ku0pohVU68E1fnROgh0g1k/Kzt0TF+s7nSTJMIZ6KZjXON09YOoOMaCSi00mt8= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1783883801; c=relaxed/simple; bh=3omQbdkzxVMUTQWPVFWGZOcimZIiLKSzRtsVqayRl6I=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=oe7SAYx+5rDIhwY1ElkHoIVjMmYsTZDQq/NJj8kLDk91Axxchvm2LD0k1pv4osXt8+UnQSNSNzmy7sDuVBArAigKpy6Lmrm6s20FgmDFRDLzQW/ZmLiYoupw9ofl+xaYItnOJ818PAaWKUyZuCbA0nOYCANiHWr26GTD2WBdfRE= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=OPjCV2Si; arc=none smtp.client-ip=209.85.210.175 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="OPjCV2Si" Received: by mail-pf1-f175.google.com with SMTP id d2e1a72fcca58-84a2dcede83so743697b3a.3 for ; Sun, 12 Jul 2026 12:16:40 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1783883800; x=1784488600; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=5uUX9nBMX6dend7Nz469oivKMBhodrKtUvZhGLjA08A=; b=OPjCV2SifqQTkWTJ0FWmhRPFqvsoxA/pKlZu7TfAeYBDojM7ZJ1RJiR2V3ok0VfafT pLGo4vX/HedlPvxZ0WNL0lgh4HzcwxFGUPP4SX3GjYa4ikZ1l0jFqNLu3czfMkrXURL3 YIhDqmy4ICz5dFa67x3/hp/WPJ+YhKy1elPxNrAYymifwbGq4Xa+kgNO4Eox+z9irOt7 Dd6ZptwYuqsXNpmnzyPMhzh3+8hWU3FKA0CXDdi7Cpj5cQfqITZ+LzB3J9FTmdr2LE8J tYl7kFMCEkvW8WnZY3RSLF9xfvE6VJqhwPBdEk23l1k1406T9goChOPK2HCrAB55sMag mDiQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1783883800; x=1784488600; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=5uUX9nBMX6dend7Nz469oivKMBhodrKtUvZhGLjA08A=; b=VPS2FFw47s24oTEjLFUAjhx2XtcAxYwm0cJE8padpamLgZW/p539ys6DrdCl7gI2Ab aaBOaNzRnxtiLhU7f+rs0pUoBtKDOQ8r/wfFn1Hl2kNBr5pEj0ndqp63ioukhWwi6dUI Qj3UTiKKEdejUMu5eOpEIPPVrcd+FyDLEHZW91sxjdTZLDxLV86dI0le93hXsZXq5ov6 fLtJZR/t/rg2xUUVDRIXj26QXUb3iE34S2Qsl/cFXZ2xQ5fJAwVPopS/fLI7IAWOHHk3 nS5CPcHcAUVsQCIhHwIXDZUjIVQrxn38ZOw//LkbGZcbLHemFXRG06ZViz4WTC8Yv/Ym DcSQ== X-Forwarded-Encrypted: i=1; AHgh+Rrp/c5udksER7WULcDI1ORov5vvhYkM/1yYAVS+0zR+YnAAKVJce5KmKC1a5xVVNSrMtE/ppmXorwLlY84=@vger.kernel.org X-Gm-Message-State: AOJu0YxSifbtCj32gVH3iyG/mTOA2EQoHVkNyxbHTMqabrNTJ25t+gqF NZTph4OEgJlBCpnn3OEUviS1DGAxXfo94Rh/wBbrdF3zYnqR7mnj2hTo X-Gm-Gg: AfdE7cnn2QiuoDSBeCCHfCnm4wxEDYfwy5X6UBIpkJPxaRWzydCdHZ9chX0CDnut7KT DTZVz95/KGGOWwEribXJyk3/T5Z3ElnhDJzlKSBn6lpN9wRWoh/ITAFK3nD84zQV5Xkkm/1UxUf 9zgY/dAdhSz47COHv7GDwOO6DaQEbFJQnHiaf4peg1UESI33UMYMo0ylofu/IQBRZE04cMqGYbv gyO5dbjOLyIn/rT25Q+hGVnncAfrh3PoIMOTB5hC+TbJRwN8MzMjzIzyo42EXi5kPw4J944XmSy qlnrVeddR0S5w37Ks5HzsZYuSfXycYfE1fwjp5EubrjQ4GwS0dIQi3Q6E85CDBQvAmLrVqrNGLa pBfPMGPguFdewb5niCSuvF2kORyoSlYM6YrsLzLD5BBw+nSOUrl0HaiUAPSMxWq21aH9Pgbqmi/ k3GjvDpEs46z3PTE6788/a9AaJ1E8n7U0maBn1HCbdPFwN/A== X-Received: by 2002:a05:6a00:2d02:b0:842:6004:3fda with SMTP id d2e1a72fcca58-84889643027mr6044387b3a.25.1783883799726; Sun, 12 Jul 2026 12:16:39 -0700 (PDT) Received: from CPC-mjac-HKWGEZ.redmond.corp.microsoft.com ([70.37.26.40]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-847f6ddc974sm13079371b3a.60.2026.07.12.12.16.39 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 12 Jul 2026 12:16:39 -0700 (PDT) From: Jack Ma To: netdev@vger.kernel.org, David Ahern Cc: Ido Schimmel , "David S . Miller" , Eric Dumazet , Jakub Kicinski , Paolo Abeni , Simon Horman , Shuah Khan , linux-kselftest@vger.kernel.org, linux-kernel@vger.kernel.org, Jack Ma Subject: [PATCH net-next 2/3] vxlan: honor per-nexthop fdb destination port Date: Sun, 12 Jul 2026 19:12:17 +0000 Message-ID: <20260712191218.236-3-jack4it@gmail.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260712191218.236-1-jack4it@gmail.com> References: <20260712191218.236-1-jack4it@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" When an fdb entry points at a nexthop group, vxlan_fdb_nh_path_select() resolves the selected leg's remote IP but leaves the UDP destination port at the device default (vxlan->cfg.dst_port). Extend nexthop_path_fdb_result() to also return the selected nexthop's NHA_FDB_PORT (0 when unset) and have vxlan_fdb_nh_path_select() store it in rdst->remote_port. vxlan_xmit_one() already prefers rdst->remote_port when non-zero and falls back to the device port otherwise, so nexthops without a port are unaffected. This lets one fdb nexthop group load-balance a flow across legs that share an underlay IP but differ in UDP destination port. Signed-off-by: Jack Ma --- include/net/nexthop.h | 5 ++++- include/net/vxlan.h | 5 ++++- 2 files changed, 8 insertions(+), 2 deletions(-) diff --git a/include/net/nexthop.h b/include/net/nexthop.h index 9c8227996..7fb612a73 100644 --- a/include/net/nexthop.h +++ b/include/net/nexthop.h @@ -576,7 +576,8 @@ struct fib_nh_common *nexthop_fdb_nhc(struct nexthop *n= h) } =20 static inline struct fib_nh_common *nexthop_path_fdb_result(struct nexthop= *nh, - int hash) + int hash, + __be16 *fdb_port) { struct nh_info *nhi; struct nexthop *nhp; @@ -585,6 +586,8 @@ static inline struct fib_nh_common *nexthop_path_fdb_re= sult(struct nexthop *nh, if (unlikely(!nhp)) return NULL; nhi =3D rcu_dereference(nhp->nh_info); + if (fdb_port) + *fdb_port =3D nhi->fdb_port; return &nhi->fib_nhc; } #endif diff --git a/include/net/vxlan.h b/include/net/vxlan.h index dfba89695..de41b3746 100644 --- a/include/net/vxlan.h +++ b/include/net/vxlan.h @@ -567,8 +567,9 @@ static inline bool vxlan_fdb_nh_path_select(struct next= hop *nh, struct vxlan_rdst *rdst) { struct fib_nh_common *nhc; + __be16 fdb_port =3D 0; =20 - nhc =3D nexthop_path_fdb_result(nh, hash >> 1); + nhc =3D nexthop_path_fdb_result(nh, hash >> 1, &fdb_port); if (unlikely(!nhc)) return false; =20 @@ -583,6 +584,8 @@ static inline bool vxlan_fdb_nh_path_select(struct next= hop *nh, break; } =20 + rdst->remote_port =3D fdb_port; + return true; } =20 --=20 2.43.0 From nobody Sat Jul 25 22:31:37 2026 Received: from mail-pf1-f173.google.com (mail-pf1-f173.google.com [209.85.210.173]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id BA4163B2D0A for ; Sun, 12 Jul 2026 19:16:44 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.210.173 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1783883806; cv=none; b=lElO2mc6L+vSeN+efLb2zTW9YXia+MgH9XmEr8bT96Jt2xJQUi3wFouD8IMmpIhFmx2ufgFHcvucKRZBoHpw95Jo2d9H6fk7NG0YiA9+u/OrJsf7UpNbzDbbUn8ivPaMznuo1MfQ/8iGKSxjgsPtlzMiiT3IEcvP135DvaIYkjE= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1783883806; c=relaxed/simple; bh=4A2wcwDC6TPVtBJOGPAh+xGITBtauaoPQY/X+WGFWGg=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=O/AsQylOt/npKX3WKhgmA7AlX3bKAV7IfklsINWaX7YaWha2CWCW/XysVwgEpnEUzGssBM+DXwwW5Yt4kx7GQ/xcVPNuaD3y0xWGR1eWMY3HQIQVcDZ86c1iIO3cgGa1geZeNcDGiTrQNxsWCb80pdi2tWkhb9cT5IjyxILg/q0= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=cjkQ/WcZ; arc=none smtp.client-ip=209.85.210.173 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="cjkQ/WcZ" Received: by mail-pf1-f173.google.com with SMTP id d2e1a72fcca58-848d21bbaffso1080260b3a.0 for ; Sun, 12 Jul 2026 12:16:44 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1783883804; x=1784488604; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=aESVowwE0I7p07cBsP5Kpg2lfQJQkDpRnjETImztddg=; b=cjkQ/WcZVfZJxirWLyDzNe2Pu0IRE6qnUPmNMmqYY/vMK4qYvYNlFDkao7QdQMsAtc LJbwWfb467VFctkWLIMJiFLfC7OKq9rIa0AIO5Fq3iC/9rtnp5xTCrUezgRHnZFNhObd cMEziYVJqbyCzg6xFkRI9HLJb3J/TrQxOBs5Q8dVE0M+aYnNgzj0DUHSkuvvmilXspJ0 cAzQ7RF9Je6awvcczSKPEjCxItH2dxoOYXt0yZ+ibJdk/phz04VmjcESJuOUGiIAMuPS u3n79h3XD7c7cbzj3E4v3NHIohtljscCv4guHyXtv2Id4yo1uGdLj0TtymjTQcoq13zs 5jOQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1783883804; x=1784488604; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=aESVowwE0I7p07cBsP5Kpg2lfQJQkDpRnjETImztddg=; b=SDePPozLdTe//7UtWcNCg2rHAR5thevksFIASHNlqzGuY/xwAV8bitWQIDSTJ62y7F JBLlk15YypN0xaHbpadqL7nbapom6e7zkW8VALNcw7SsqdDxeTBSXPKdx9f5j0WaseFl 18HoOj+fUXQ6jQ1i5o10A+7dDSbgsRu2skg6N9k6woD3LS4h3J/YUaSIpTq+6ObHbl8V bjqrjLtVtKbRHQxgwz+aK1NMiN7e/QD5QkrMr0IyuENHFEArk5rHgqWuD0zibb+zSWSw av6sEVGxbm5lZUVGn8k0GLq8RFXSl9o3AhO+KqYYYP01F2dwdUb06DyDujyg/Ymh0epT BZHQ== X-Forwarded-Encrypted: i=1; AHgh+Rrjb0/XjNWcAXwY1s5THzl0Sz5E5nEo31AmSmf1exDbeG68qfK/P27AsnHUaBVdlvhyrlyhsK0h3RuLxos=@vger.kernel.org X-Gm-Message-State: AOJu0YzDXakznvdrEj4dRNQPsJ42thqlJm2+PjlYr/KhVrRmJi8pYWiP UtEPCxqdViZ3/KO5iNI79n4BwGUq4FaIx9rp61MAtkh1yB4qJvUPS7qy X-Gm-Gg: AfdE7clA/wgiHVilvl8esJOpiNnIepwf2aVlrluXxwepfVpifk2L3tvUazuDu2JHoDM Alj/EtlaSLRWKzfb3fFYG7y//goQvpRBO9jzbIo9G6Tio9gIA6lmC/sMesH/mnobjPm76G8QJcg aKfuapwAPTuKbx9r6VmiETitKa2cAaAbaNhtURkEJCSQvAnMA1XPhq89vEJ2B6LUWXV2CPE3hb+ A9jYYFR8x5mV33kqdEbKbffGtEE4/Shs2k6qoYpWViPicbEsgODU5Wq+3269fHxru7kP5uRuzBP mwUwtFoMJVwp9fc6wVdfq3Ck4eGf9fSvncUgAjzbnbAkgQYLO6HOTyGzjuXnlM8xCVVR63C1MW3 K2lPsFoBXjjhukyZ7t+TmegY+umAwWg8rY9GnRf6hqaadlUxK5qB8Ezi3KeNQng+0AfUzEYWAuB 2DBB86WERkxNS5CJTStztGNyAiURwKwIlSqzYJFiJR42ltCw== X-Received: by 2002:a05:6a00:2346:b0:848:2f84:736 with SMTP id d2e1a72fcca58-8488990b70amr6054703b3a.73.1783883804156; Sun, 12 Jul 2026 12:16:44 -0700 (PDT) Received: from CPC-mjac-HKWGEZ.redmond.corp.microsoft.com ([70.37.26.40]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-847f6ddc974sm13079371b3a.60.2026.07.12.12.16.43 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 12 Jul 2026 12:16:43 -0700 (PDT) From: Jack Ma To: netdev@vger.kernel.org, David Ahern Cc: Ido Schimmel , "David S . Miller" , Eric Dumazet , Jakub Kicinski , Paolo Abeni , Simon Horman , Shuah Khan , linux-kselftest@vger.kernel.org, linux-kernel@vger.kernel.org, Jack Ma Subject: [PATCH net-next 3/3] selftests: net: add coverage for fdb nexthop dst port Date: Sun, 12 Jul 2026 19:12:18 +0000 Message-ID: <20260712191218.236-4-jack4it@gmail.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260712191218.236-1-jack4it@gmail.com> References: <20260712191218.236-1-jack4it@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" Add fib_nexthops_fdb_port.sh, which exercises the NHA_FDB_PORT rules: accept a port on an fdb nexthop that has a gateway and echo it back on dump, reject it on non-fdb or gateway-less nexthops, allow a group whose legs differ only in UDP port, and confirm a portless fdb nexthop omits the attribute. The test SKIPs cleanly on kernels or iproute2 without NHA_FDB_PORT support. Signed-off-by: Jack Ma --- tools/testing/selftests/net/Makefile | 1 + .../selftests/net/fib_nexthops_fdb_port.sh | 78 +++++++++++++++++++ 2 files changed, 79 insertions(+) create mode 100755 tools/testing/selftests/net/fib_nexthops_fdb_port.sh diff --git a/tools/testing/selftests/net/Makefile b/tools/testing/selftests= /net/Makefile index 708d960ae..c06eb4927 100644 --- a/tools/testing/selftests/net/Makefile +++ b/tools/testing/selftests/net/Makefile @@ -36,6 +36,7 @@ TEST_PROGS :=3D \ fib_nexthop_multiprefix.sh \ fib_nexthop_nongw.sh \ fib_nexthops.sh \ + fib_nexthops_fdb_port.sh \ fib_rule_tests.sh \ fib_tests.sh \ fin_ack_lat.sh \ diff --git a/tools/testing/selftests/net/fib_nexthops_fdb_port.sh b/tools/t= esting/selftests/net/fib_nexthops_fdb_port.sh new file mode 100755 index 000000000..8b401c6d2 --- /dev/null +++ b/tools/testing/selftests/net/fib_nexthops_fdb_port.sh @@ -0,0 +1,78 @@ +#!/bin/bash +# SPDX-License-Identifier: GPL-2.0 +# +# Control-plane selftest for per-nexthop VXLAN fdb destination port +# (NHA_FDB_PORT). Verifies the accept/reject rules and the dump roundtrip. +# No datapath traffic here -- see tests/integ/vxlan-fdb-port-integ.sh for = the +# real forwarding test. +# +# Requires: patched kernel (NHA_FDB_PORT) and patched iproute2 (the "port" +# keyword on "ip nexthop ... fdb"). SKIPs cleanly otherwise. + +set -u + +ksft_skip=3D4 +NS=3D"nhfdbport-$$" +IP=3D"ip -netns $NS" +ret=3D0 + +log_test() { # $1 actual_rc $2 expected_rc $3 name + if [ "$1" =3D "$2" ]; then + printf "TEST: %-58s [ OK ]\n" "$3" + else + printf "TEST: %-58s [FAIL] (rc=3D$1 want=3D$2)\n" "$3" + ret=3D1 + fi +} + +# passes (returns 0) iff the command FAILS +expect_fail() { + if "$@" >/dev/null 2>&1; then return 1; else return 0; fi +} + +cleanup() { ip netns del "$NS" 2>/dev/null; } + +command -v ip >/dev/null 2>&1 || { echo "SKIP: iproute2 not found"; exit $= ksft_skip; } +ip nexthop help 2>&1 | grep -q fdb || { echo "SKIP: no fdb nexthop support= "; exit $ksft_skip; } + +trap cleanup EXIT +cleanup +ip netns add "$NS" || { echo "SKIP: cannot create netns"; exit $ksft_skip;= } +$IP link set lo up + +# Probe for "port" keyword + kernel NHA_FDB_PORT support; SKIP if missing. +if ! $IP nexthop add id 1 via 10.0.0.1 fdb port 4790 2>/dev/null; then + echo "SKIP: 'ip nexthop ... fdb port' unsupported (needs patched kernel += iproute2)" + exit $ksft_skip +fi +log_test 0 0 "add fdb nexthop with port" + +# Dump roundtrip must echo the port back. +$IP nexthop show id 1 | grep -qw "port 4790" +log_test $? 0 "dump shows fdb port 4790" + +# Reject: port on a routed (non-fdb) nexthop. +expect_fail $IP nexthop add id 2 via 10.0.0.1 dev lo port 4790 +log_test $? 0 "reject port on non-fdb nexthop" + +# Reject: fdb port without a gateway. +expect_fail $IP nexthop add id 3 fdb port 4790 +log_test $? 0 "reject fdb port without gateway" + +# The HA case: a group whose legs share the gateway but differ in port. +$IP nexthop add id 10 via 10.0.0.1 fdb port 4789 && \ +$IP nexthop add id 11 via 10.0.0.1 fdb port 5789 && \ +$IP nexthop add id 100 group 10/11 fdb +log_test $? 0 "add fdb nexthop group with differing ports" + +# A fdb nexthop without a port must NOT emit one (backward compat). +$IP nexthop add id 20 via 10.0.0.1 fdb +$IP nexthop show id 20 | grep -qw "port" +log_test $? 1 "fdb nexthop without port omits NHA_FDB_PORT" + +if [ $ret -eq 0 ]; then + echo "PASS: all NHA_FDB_PORT control-plane checks" +else + echo "FAIL: one or more NHA_FDB_PORT checks failed" +fi +exit $ret --=20 2.43.0