From nobody Sat Jul 25 06:00:37 2026 Received: from mail-pf1-f181.google.com (mail-pf1-f181.google.com [209.85.210.181]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id D55ED3C3F68 for ; Fri, 17 Jul 2026 06:45:30 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.210.181 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784270743; cv=none; b=JWsM3R7dfE2sdqn3A3m1X1DfISObU0CEdJS3GWQiPRbTOJcDGhZKQF6/SQ2yHt6twdlGR811VEx5efIa3ojkeQbsZiJW5UaVSKt9LzF7GJR7YNb7a95l4XG0yZoc7aLx7NZi1xyQ8txKNbV62qZZP3udItnWTr9AhT7liSZU2Vo= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784270743; c=relaxed/simple; bh=sl8mscsoPTPSyi+19hbwFh+F3vzBp+hyHWcG3uotCtE=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=Cf7DVx6rs6jvB8Kzv8Rp8yvC7H3txZ542wDt8Raeq4PaA6b9ho1Tc9zVdPlma10HQlQqpG5nwA9OQmAO1qgmVcLWIp3EFJ4oF4xRX4RrJLDtboQauw6zQObFUKwgIPvp5+AQwO9CtDYRq6NPv5XelfCpQu/S04dH6rqQJkxwoDE= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=YLsmSDRA; arc=none smtp.client-ip=209.85.210.181 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="YLsmSDRA" Received: by mail-pf1-f181.google.com with SMTP id d2e1a72fcca58-8485ef63b68so6960191b3a.1 for ; Thu, 16 Jul 2026 23:45:30 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1784270726; x=1784875526; darn=vger.kernel.org; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :content-type:mime-version:subject:date:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=eHqB+0XtN75taQRaVYwBwvw8FBQBWfUPu65PH2IoQnQ=; b=YLsmSDRAsprxiUQKmPwTnu/74GufZrN1wqK8+HDkoZ+/5ht+a0y0JMso5paTn8kubr XkUCi1DiNi5gtGoUemA8Cut6maC1ZLmNo8G+omcoG/kYUuE0Shb0S1/8XGagZF+vl/Tk /bDEjNH+HtSCS2sGNpaykDHEfv6Sdc5AIr7qUVLj2Z1NMt57yOM+pZabpQCTad1UTOWS 7uR3gmUUMl1RJdKyJENYeIcLIcvOz3ShACXz0D411ITpA0ugUX2E0tsw/tSPetgyC/ec tIvw+k2P2g8D7JsO9zMpeyK7x8pdGm8XD24e4T9uPAnrt0dASgUE9aiiSF5J+aQ4v0L1 K5tw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784270726; x=1784875526; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :content-type:mime-version:subject:date:from:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=eHqB+0XtN75taQRaVYwBwvw8FBQBWfUPu65PH2IoQnQ=; b=ippOmDdQJoy7YpVNlw512IgaoKzRiX1oAqM1SSbg9A71MewHNHu+EtSP+E5G6L9pJK HRzuN14AHUH4zWi4WhCfGRQcoyq6YLDaMzxp4v7Di46osqGruSYhLagMmfNbweTR3D2P Ulb4uF1tYLBSzD5zYbGdFNPH/8l2Bu37rLCayV5I+J/3vhJvMvzuXivfHYrXo3NmCTYB splVrM5BS/m/u4Bs6WK0JwPeF4Ff+42d1VwvR/5YZ/EkcH+esfFZl8wM2yAPmd1IN5Df lhcZdfLCm/bRz4HyMqv0gulMtQo03oJKu/M38SJorclSuEQJC2Uipm9jxRm3rjdD9T1N e4pQ== X-Forwarded-Encrypted: i=1; AHgh+Roamb/EsydJrJIF52WpgNDEDJOd5cYmTcRe/1P7zMkdMn4OCVAu6XjrDKstt8ijNYAfU+Habk0oLXHhS2I=@vger.kernel.org X-Gm-Message-State: AOJu0YwZPXU3qqUux4Br9t0HR4Dz9jqzygZy273m6hkVHx/AG2oF7oQu 4t2aBes9lRFW7ZqEqNNdFce9XvjMGGCv3SNNjVl2YEO9qlfbY83XGBWsLb/5aNxV X-Gm-Gg: AfdE7cnOk/RwBqNIYrLifVJ91pIQAez0AarQqKHhBkZKjXnIROaWSYFu8EFD64RBLfr u7ciFbdnrZndY4LD3hFdeqRqOIiR+hQTdvM32svBaOG8kLkrAhmHCekxPgrZCVvbcql8hGk/CV5 OJu0TGRmAOHMtzR6on2uss8JOn2ESCkkUT1x+fGgPNU/KY7b3z08ONq2joTOjBZ/DDFd8R5XYDr FJWwsHXgolygSc7swfquJo+5F1XVBX59FSTbLM3pO2EE8f7H9ENLDqWt7wzvHtRM47S0LQBXXg2 alMxOwa+i54PVyggY/OUpgW32ITKDUYdy2nWFyMBEawd5fiZqEthqk1jkrlRXJF+qfwoD+D2hlQ c71xOOlp3TtC2FCx8e22kYFwU1Oym6wtV3sKyRacw6XEg+NZFFEm/3BFAoKBKjYU+UXK+0ovWCz m1xYgIuTc/cDet7Oi1BKG62fWwkQ== X-Received: by 2002:a05:6a00:3c8a:b0:847:973b:3cf6 with SMTP id d2e1a72fcca58-84c290c3bd0mr1280242b3a.0.1784270725719; Thu, 16 Jul 2026 23:45:25 -0700 (PDT) Received: from CPC-mjac-HKWGEZ.localdomain ([70.37.26.34]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-84c2ad8855fsm430531b3a.12.2026.07.16.23.45.25 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 16 Jul 2026 23:45:25 -0700 (PDT) From: Jack Ma Date: Fri, 17 Jul 2026 06:45:16 +0000 Subject: [PATCH net-next v2 1/3] net: nexthop: add NHA_FDB_PORT for fdb nexthops Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260717-b4-vxlan-fdb-port-v2-1-f4862e8fe867@gmail.com> References: <20260717-b4-vxlan-fdb-port-v2-0-f4862e8fe867@gmail.com> In-Reply-To: <20260717-b4-vxlan-fdb-port-v2-0-f4862e8fe867@gmail.com> To: David Ahern , Ido Schimmel , "David S. Miller" , Eric Dumazet , Jakub Kicinski , Paolo Abeni , Simon Horman , Shuah Khan Cc: netdev@vger.kernel.org, linux-kernel@vger.kernel.org, linux-kselftest@vger.kernel.org, Jack Ma X-Mailer: b4 0.15.2 X-Developer-Signature: v=1; a=ed25519-sha256; t=1784270724; l=4085; i=jack4it@gmail.com; s=20260712; h=from:subject:message-id; bh=sl8mscsoPTPSyi+19hbwFh+F3vzBp+hyHWcG3uotCtE=; b=sc8SDB/wC4m7QG+mGDlCeq1eYouPQl1BtyZZ/UqB+9s4ZrHKBorsmm5oDEUMw0T1p6lSkpH3D eUWbyx9x1DyBJmgDaQcB/LN2Atpwq6gNlkJxRET/2nHg4/c2VeCFdkB X-Developer-Key: i=jack4it@gmail.com; a=ed25519; pk=x8xh2Md9yNDil0xBOA9WA/oqC3O4Eg4rdlIul4YUktU= Commit 1274e1cc4226 ("vxlan: ecmp support for mac fdb entries") lets a single inner MAC be reached through a group of remote VTEPs, with the kernel flow-hashing across the group members. Each member carries its own remote IP, but the UDP destination port is always taken from the VXLAN device (vxlan->cfg.dst_port) and cannot be set per member. Some deployments pack several receivers behind one underlay IP and tell them apart by UDP port, so they need a per-nexthop destination port to spread flows across (IP, port) tuples rather than IP alone. Add a netlink attribute NHA_FDB_PORT (__be16, mirroring NDA_PORT) that carries an optional UDP destination port on an fdb nexthop. It is only accepted together with NHA_FDB and NHA_GATEWAY; it is stored in struct nh_info and echoed back on dump. This patch is control-plane plumbing only; the VXLAN datapath is wired up in a follow-up patch, so behaviour is unchanged for now. Signed-off-by: Jack Ma --- include/net/nexthop.h | 2 ++ include/uapi/linux/nexthop.h | 3 +++ net/ipv4/nexthop.c | 20 +++++++++++++++++++- 3 files changed, 24 insertions(+), 1 deletion(-) diff --git a/include/net/nexthop.h b/include/net/nexthop.h index 572e69cda..9c8227996 100644 --- a/include/net/nexthop.h +++ b/include/net/nexthop.h @@ -28,6 +28,7 @@ struct nh_config { u8 nh_protocol; u8 nh_blackhole; u8 nh_fdb; + __be16 nh_fdb_port; u32 nh_flags; =20 int nh_ifindex; @@ -63,6 +64,7 @@ struct nh_info { u8 family; bool reject_nh; bool fdb_nh; + __be16 fdb_port; =20 union { struct fib_nh_common fib_nhc; diff --git a/include/uapi/linux/nexthop.h b/include/uapi/linux/nexthop.h index bc49baf4a..e587bbf3b 100644 --- a/include/uapi/linux/nexthop.h +++ b/include/uapi/linux/nexthop.h @@ -83,6 +83,9 @@ enum { /* u32; read-only; whether any driver collects HW stats */ NHA_HW_STATS_USED, =20 + /* be16; UDP destination port for an fdb nexthop (e.g. VXLAN) */ + NHA_FDB_PORT, + __NHA_MAX, }; =20 diff --git a/net/ipv4/nexthop.c b/net/ipv4/nexthop.c index 6205bd57a..5b27cc9a9 100644 --- a/net/ipv4/nexthop.c +++ b/net/ipv4/nexthop.c @@ -39,6 +39,7 @@ static const struct nla_policy rtm_nh_policy_new[] =3D { [NHA_ENCAP_TYPE] =3D { .type =3D NLA_U16 }, [NHA_ENCAP] =3D { .type =3D NLA_NESTED }, [NHA_FDB] =3D { .type =3D NLA_FLAG }, + [NHA_FDB_PORT] =3D { .type =3D NLA_U16 }, [NHA_RES_GROUP] =3D { .type =3D NLA_NESTED }, [NHA_HW_STATS_ENABLE] =3D NLA_POLICY_MAX(NLA_U32, true), }; @@ -956,6 +957,9 @@ static int nh_fill_node(struct sk_buff *skb, struct nex= thop *nh, } else if (nhi->fdb_nh) { if (nla_put_flag(skb, NHA_FDB)) goto nla_put_failure; + if (nhi->fdb_port && + nla_put_be16(skb, NHA_FDB_PORT, nhi->fdb_port)) + goto nla_put_failure; } else { const struct net_device *dev; =20 @@ -1055,6 +1059,9 @@ static size_t nh_nlmsg_size_single(struct nexthop *nh) break; } =20 + if (nhi->fdb_nh) + sz +=3D nla_total_size(2); /* NHA_FDB_PORT */ + if (nhi->fib_nhc.nhc_lwtstate) { sz +=3D lwtunnel_get_encap_size(nhi->fib_nhc.nhc_lwtstate); sz +=3D nla_total_size(2); /* NHA_ENCAP_TYPE */ @@ -2956,8 +2963,10 @@ static struct nexthop *nexthop_create(struct net *ne= t, struct nh_config *cfg, nhi->family =3D cfg->nh_family; nhi->fib_nhc.nhc_scope =3D RT_SCOPE_LINK; =20 - if (cfg->nh_fdb) + if (cfg->nh_fdb) { nhi->fdb_nh =3D 1; + nhi->fdb_port =3D cfg->nh_fdb_port; + } =20 if (cfg->nh_blackhole) { nhi->reject_nh =3D 1; @@ -3147,6 +3156,15 @@ static int rtm_to_nh_config(struct net *net, struct = sk_buff *skb, cfg->nh_fdb =3D nla_get_flag(tb[NHA_FDB]); } =20 + if (tb[NHA_FDB_PORT]) { + if (!tb[NHA_FDB] || !tb[NHA_GATEWAY]) { + NL_SET_ERR_MSG(extack, + "FDB port can only be set on fdb nexthops that have a gateway"); + goto out; + } + cfg->nh_fdb_port =3D nla_get_be16(tb[NHA_FDB_PORT]); + } + if (tb[NHA_GROUP]) { if (nhm->nh_family !=3D AF_UNSPEC) { NL_SET_ERR_MSG(extack, "Invalid family for group"); --=20 2.43.0 From nobody Sat Jul 25 06:00:37 2026 Received: from mail-pf1-f175.google.com (mail-pf1-f175.google.com [209.85.210.175]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 9F9F83B14B4 for ; Fri, 17 Jul 2026 06:45:33 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.210.175 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784270751; cv=none; b=h+o9xzgQkCUFgY8eiq9HRZnjxJDGjPZm5JOIPOwC0gdgl+Kf14FY0JArC+3NIW/8aHDy55498fTe42/DURvW6F2WRz9XqDh20JLwiK1vZRipqfQG1sYcKCL9kJPEI+z0vbtH8/BhmtyqCdpWZMyp0WtCzEacuHl4pwuEO8uTlJY= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784270751; c=relaxed/simple; bh=xEM4PWSdufJQRFlVx8hDi0jZLJQtFRoDWHIzLk+sx3Y=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=npJPCgWz00hEhh1heQrmVKpAnnyfmRXYDGFZ/K6sbqvWExqc3Ra2czBhC2G2b905oeQjYiI1GJT89hsQhMTG55ttLzkmF8VVG180vsra1D7wDNbtcB8bpX6+sxYl69654z3rVmIqP9zD8j8rej6DYoyddasOTWBe8YoD1GiVVEc= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=O2gmXDsM; arc=none smtp.client-ip=209.85.210.175 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="O2gmXDsM" Received: by mail-pf1-f175.google.com with SMTP id d2e1a72fcca58-848643382fcso8498835b3a.1 for ; Thu, 16 Jul 2026 23:45:32 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1784270726; x=1784875526; darn=vger.kernel.org; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :content-type:mime-version:subject:date:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=pGWzAqMnXIx+QjNO6QbhWdHJZEGF73MjjXZSZbQ8KHE=; b=O2gmXDsMmWZEygqF3pPjKqCS0emvhEZL82wd0/W2DY8LuQjRJiSAxmsGXzlP6ebnGL DkqGCcx54sWYJjw7JKeb74htcfhoeVpGUnmDPHnDq0vvPTelUdadeCt5DlHr2Hde/4me Qffp3nONpOpiOhPn+qca6zTfV5PQI+EMGwgWS7TB9qdWdqU7bJcpJ1C7FGil4ozxTFUK MHeyBslnVAzXK06JVKrx17tdDE8dn6B3u4gUrEjYOxPUEvLsp89j0ZkJ0+wMPahwH7yh lWaLhFZQJ3AEIMBopWgt9Vohq4F5SwH8QtcGaHRdntPxTONllvRlVTYtE5tYCteF+TpB zPNQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784270726; x=1784875526; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :content-type:mime-version:subject:date:from:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=pGWzAqMnXIx+QjNO6QbhWdHJZEGF73MjjXZSZbQ8KHE=; b=STPu6UaTCHl0WGm62n70ZF5izILofp/KeEXvXG4KxwgWBVlfLcC6YzUzqyCNdth5F3 tPSBLK6nX5InxRF5DSi1dPscZ/+CScueLwWrNFn8wP7wa24cLQM08NxgcnA2e6Z9I4qR L8ACopUq0SBpqtDEzNu/NVyqbt+yLJ0a4ejazfdSKx4Rm+054kELIyMcO2EcoSTWivwb MjsVJvLcNC/vo79ULRDiG8RTocBufQjaR9jHWTVqxOwNktY1vbzY47czkGIb7I/GBhyX V8sLEmVw14Zd7uSzWwMPW82E2UsRMpoqmNGX9QuMN5K66zbJxS8me1v8qt09mt5JhVrL 0lpA== X-Forwarded-Encrypted: i=1; AHgh+RpVDzgT+QUVYmNuxOcl1oVhUsPpDbrnUs4YioNuxzLjFWckxrTfgoJYSixm5DOR0c33yD1UIxxpFJB9C4o=@vger.kernel.org X-Gm-Message-State: AOJu0YyraFCqnO920AG+8t7M9iwBPuwd1Ukj41UuoPG0SuHHUPB/huTO EUWfAlJL1N1Ti4/H0ur8pUf+WtmJu46VvPUIRcywiC6QE14yHWE1WJP0 X-Gm-Gg: AfdE7cni9tPCkBsFJRfSOdENmulsX5bNpwy1xmRR3mFSwu+s15D/nPQmBjiQfCxzS6n +3a1mQnWdHYHM+5Er0iJwHZOMU1xGXny80rUZNANn0Q5PH454Dd+FOa4FQ+a0dUkBOXBJMwC77e UyTb/LCX+C4+ZvPWJJVxlAuL0vsgtsRC2CxxyERY7g5kBmQYO+vlQaaaVFfxQEKzgZMSUYtC8BX pQysNdFLjKRgAf7whxUPrGwLckBmhSKFxdVWV2vlaPZOWvybcPXyBPMYQiXXNFwxkNd4YCo+AA0 jka3lL+ewskUPKW2GSs32fToEmwVnbPivjiGPlWrtYxHmcuEO4XGZeEFOyQGPw8PIZ6o+3vTe9U DDGVn5A5CFSsnv3ijJSogqpgWXD4AGyJX4Izs9H9IL05H5zJpGnx8DYNJxrgGSPEeAhCB9hjJAF LUA604kN2LHRNxwS7bNtdp67l2+Q== X-Received: by 2002:a05:6a00:1492:b0:848:2f73:8ffb with SMTP id d2e1a72fcca58-84c29528564mr1412058b3a.68.1784270726474; Thu, 16 Jul 2026 23:45:26 -0700 (PDT) Received: from CPC-mjac-HKWGEZ.localdomain ([70.37.26.34]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-84c2ad8855fsm430531b3a.12.2026.07.16.23.45.25 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 16 Jul 2026 23:45:26 -0700 (PDT) From: Jack Ma Date: Fri, 17 Jul 2026 06:45:17 +0000 Subject: [PATCH net-next v2 2/3] vxlan: honor per-nexthop fdb destination port Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260717-b4-vxlan-fdb-port-v2-2-f4862e8fe867@gmail.com> References: <20260717-b4-vxlan-fdb-port-v2-0-f4862e8fe867@gmail.com> In-Reply-To: <20260717-b4-vxlan-fdb-port-v2-0-f4862e8fe867@gmail.com> To: David Ahern , Ido Schimmel , "David S. Miller" , Eric Dumazet , Jakub Kicinski , Paolo Abeni , Simon Horman , Shuah Khan Cc: netdev@vger.kernel.org, linux-kernel@vger.kernel.org, linux-kselftest@vger.kernel.org, Jack Ma X-Mailer: b4 0.15.2 X-Developer-Signature: v=1; a=ed25519-sha256; t=1784270724; l=2196; i=jack4it@gmail.com; s=20260712; h=from:subject:message-id; bh=xEM4PWSdufJQRFlVx8hDi0jZLJQtFRoDWHIzLk+sx3Y=; b=YhfQRticdo6ewbVHM1o14OsXcOGRoOkDyWL1lmyZ6SYsB5zZVIHJLM9i5b5iwgu0Rz/Nvgv9D EiG7Vf5UwMjA+3l2IAKLgjaslE7mE51uTANXD1z14w+fmFc/Lb5y3iL X-Developer-Key: i=jack4it@gmail.com; a=ed25519; pk=x8xh2Md9yNDil0xBOA9WA/oqC3O4Eg4rdlIul4YUktU= When an fdb entry points at a nexthop group, vxlan_fdb_nh_path_select() resolves the selected leg's remote IP but leaves the UDP destination port at the device default (vxlan->cfg.dst_port). Extend nexthop_path_fdb_result() to also return the selected nexthop's NHA_FDB_PORT (0 when unset) and have vxlan_fdb_nh_path_select() store it in rdst->remote_port. vxlan_xmit_one() already prefers rdst->remote_port when non-zero and falls back to the device port otherwise, so nexthops without a port are unaffected. This lets one fdb nexthop group load-balance a flow across legs that share an underlay IP but differ in UDP destination port. Signed-off-by: Jack Ma --- include/net/nexthop.h | 5 ++++- include/net/vxlan.h | 5 ++++- 2 files changed, 8 insertions(+), 2 deletions(-) diff --git a/include/net/nexthop.h b/include/net/nexthop.h index 9c8227996..7fb612a73 100644 --- a/include/net/nexthop.h +++ b/include/net/nexthop.h @@ -576,7 +576,8 @@ struct fib_nh_common *nexthop_fdb_nhc(struct nexthop *n= h) } =20 static inline struct fib_nh_common *nexthop_path_fdb_result(struct nexthop= *nh, - int hash) + int hash, + __be16 *fdb_port) { struct nh_info *nhi; struct nexthop *nhp; @@ -585,6 +586,8 @@ static inline struct fib_nh_common *nexthop_path_fdb_re= sult(struct nexthop *nh, if (unlikely(!nhp)) return NULL; nhi =3D rcu_dereference(nhp->nh_info); + if (fdb_port) + *fdb_port =3D nhi->fdb_port; return &nhi->fib_nhc; } #endif diff --git a/include/net/vxlan.h b/include/net/vxlan.h index dfba89695..de41b3746 100644 --- a/include/net/vxlan.h +++ b/include/net/vxlan.h @@ -567,8 +567,9 @@ static inline bool vxlan_fdb_nh_path_select(struct next= hop *nh, struct vxlan_rdst *rdst) { struct fib_nh_common *nhc; + __be16 fdb_port =3D 0; =20 - nhc =3D nexthop_path_fdb_result(nh, hash >> 1); + nhc =3D nexthop_path_fdb_result(nh, hash >> 1, &fdb_port); if (unlikely(!nhc)) return false; =20 @@ -583,6 +584,8 @@ static inline bool vxlan_fdb_nh_path_select(struct next= hop *nh, break; } =20 + rdst->remote_port =3D fdb_port; + return true; } =20 --=20 2.43.0 From nobody Sat Jul 25 06:00:37 2026 Received: from mail-pf1-f181.google.com (mail-pf1-f181.google.com [209.85.210.181]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id D5EE8396D13 for ; Fri, 17 Jul 2026 06:45:33 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.210.181 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784270746; cv=none; b=lKrSsXOmIIJnfqp+tbDldKxuGH5TvYFXuFb0tQ1vBi48z7ezR+d6xsbpUJ+mCTTutuL/pNtCWnFZCLy/dOSHHvr4tWJGyWXCTSYBBcSMHIEawglZx0+e5xaKde8u/L3id9aq9clSC5BNZAibXqMENnNE50Dxmk4XV0LN+7ngJz8= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784270746; c=relaxed/simple; bh=HdvJD6U6AZT6Gc6eIdmqO8NWS6WyZ9Y0FP6mOZhzD9U=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=FGu+4HmHrqRmq4TI2wKBo6ZT/ZZ01hGoDv4FPtPnwUBBTUTVoQOP//AyG1JZgBAmaKQD6DbQ1UxRp8Wg/G7ISDRutPUAEs4PnRkmqdHiesvKcc3COzQ77eXctTco/Cbt1sx17/RKYSbLa8CeeGQksDTrjjN8Q22xYihEBCMRVng= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=f71XFf2t; arc=none smtp.client-ip=209.85.210.181 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="f71XFf2t" Received: by mail-pf1-f181.google.com with SMTP id d2e1a72fcca58-848743155bcso1763448b3a.0 for ; Thu, 16 Jul 2026 23:45:32 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1784270727; x=1784875527; darn=vger.kernel.org; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :content-type:mime-version:subject:date:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=HGbSiO1fqjnyGYh3XrxntYuCZ2sL4D2PCmE496WiS64=; b=f71XFf2t7nqW8Z2MfoaHPt6xScs4fXalTUfbqzfs0pUR/GslY8CO7Do3+vj3CECnUp yyy0PNwdbMUEnblkj0ldatz0q/ECfBIwUF/kDHzRQETrzHem2Yht9donVdRg+is5K+fv yZPvctV/CE94ceGzA/XF19gkITVdZKd5VcZUvvqrunD4rBo9qHJtnLDk+WCVGmHUBMkT 3S7GrE/7u6FB3FbR6ZxTdROQL2er01gaqjJJFMOHQpbCMBNp1cO3OJpvHg0Bxev6QiPZ 7EFO6/tnmpKsTmy0kSVE/+z+pqqoRz+1Zf1EU296xPmUI2rTNU539gGBHciG/EQk3dlV pYtQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784270727; x=1784875527; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :content-type:mime-version:subject:date:from:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=HGbSiO1fqjnyGYh3XrxntYuCZ2sL4D2PCmE496WiS64=; b=eCMYec5x01udZahXQwP7iwDCbUWO3llcPc9ksX9IXf59dFS/9EqQGPb1iKTBKh2LAf ZBiVhD/3drIHUPwMyazCiKX+KqhADxj8pQ/Jqhhgr7Q/emo/BW4Q/mJZe9w46llPT8xD X9VwTESdRUalRl2cuYlfOhZUJXHWdygjq30HohWA32gYJWINnDnOJAp/pD+O5IXm+yHD 0W0AzuQkOFUtuDn9OczqcxGHkUX1r1quhSQmJueVsfq4C2w82wiGMoN5FUThKraK98f2 AbOaRhgy0neo+7ntqk0McHVJqLW6nzYohaGO338V4X9aSRbGXEYPAJ4DV1I332TGk1vD dkUg== X-Forwarded-Encrypted: i=1; AHgh+RoLmZVArVtbhiwVJoL50V++KH8NSOlF/tOQE9/Med782E+pTnfE6XeV4BktEhWSxd3DwYAHM9ED8hxALtI=@vger.kernel.org X-Gm-Message-State: AOJu0YwiTZM7lC0u1joQe/9+tES5igQsRzMOSH7qtE+aoGTAuZLb6g7k JbUqC2s9ypNzhpWAZlhLzU6PpBaXYK2/hFcStMZTQug4WEol9hULRQty X-Gm-Gg: AfdE7clJfh89aruj1BsPp7v0iZ0NCiFhhqHgmFJ++gThd4+rdxYZ4MBVI5RdPfI8Wm3 aiSF25nlBix0vy7UJxt9+mEzpkzhPj2WppdyFGJowGHMmN0T45S5w5DXD6tActkltZ/QByDl0yF RcpwOjAh8ax15X9N0HutAIJUTz1vhDs/ts/Yi7PBJpv+hRfd8fQlKhS/H/uNWZNiPJyqr6BnKLx q5Vh0czTjKNboUe/APDeXZ7foBCt4kyZbUTOJepL+mmu/L8KH5D/oNSJbQi5OlfOajjVjAgDjX6 PwSXETd08SVHKjH2UwlguWf8c1TSxKXG3oLtglwzYoDVb3lfzb9LIpql6uVnBsV6bttvQIwf02K XQt+V8m3WAlasUp3GsL6K930bH5o/OeOBHhUW7c+B3ahdswvQuIc0xWh52xFIqtg4hwsl4GhMl2 mMvfZYDHB1qlJlESo= X-Received: by 2002:a05:6a00:288d:b0:848:2f74:1d60 with SMTP id d2e1a72fcca58-84c295777f6mr1268231b3a.70.1784270727152; Thu, 16 Jul 2026 23:45:27 -0700 (PDT) Received: from CPC-mjac-HKWGEZ.localdomain ([70.37.26.34]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-84c2ad8855fsm430531b3a.12.2026.07.16.23.45.26 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 16 Jul 2026 23:45:26 -0700 (PDT) From: Jack Ma Date: Fri, 17 Jul 2026 06:45:18 +0000 Subject: [PATCH net-next v2 3/3] selftests: net: add coverage for fdb nexthop dst port Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260717-b4-vxlan-fdb-port-v2-3-f4862e8fe867@gmail.com> References: <20260717-b4-vxlan-fdb-port-v2-0-f4862e8fe867@gmail.com> In-Reply-To: <20260717-b4-vxlan-fdb-port-v2-0-f4862e8fe867@gmail.com> To: David Ahern , Ido Schimmel , "David S. Miller" , Eric Dumazet , Jakub Kicinski , Paolo Abeni , Simon Horman , Shuah Khan Cc: netdev@vger.kernel.org, linux-kernel@vger.kernel.org, linux-kselftest@vger.kernel.org, Jack Ma X-Mailer: b4 0.15.2 X-Developer-Signature: v=1; a=ed25519-sha256; t=1784270724; l=3980; i=jack4it@gmail.com; s=20260712; h=from:subject:message-id; bh=HdvJD6U6AZT6Gc6eIdmqO8NWS6WyZ9Y0FP6mOZhzD9U=; b=zTZ/Uv5pit4FneIuseQM7CSf9cLsOW0uZli7xlhMP+qPfwOTzIq14VeQVsZJ05ocdBWmd1msK qpX3YjJCLG/C6HsF4sSmqvFm8jgfBNo/sFhQ+gsPFimTtTWYPYov/yA X-Developer-Key: i=jack4it@gmail.com; a=ed25519; pk=x8xh2Md9yNDil0xBOA9WA/oqC3O4Eg4rdlIul4YUktU= Add fib_nexthops_fdb_port.sh, which exercises the NHA_FDB_PORT rules: accept a port on an fdb nexthop that has a gateway and echo it back on dump, reject it on non-fdb or gateway-less nexthops, allow a group whose legs differ only in UDP port, and confirm a portless fdb nexthop omits the attribute. The test SKIPs cleanly on kernels or iproute2 without NHA_FDB_PORT support. Signed-off-by: Jack Ma --- tools/testing/selftests/net/Makefile | 1 + .../testing/selftests/net/fib_nexthops_fdb_port.sh | 78 ++++++++++++++++++= ++++ 2 files changed, 79 insertions(+) diff --git a/tools/testing/selftests/net/Makefile b/tools/testing/selftests= /net/Makefile index 708d960ae..c06eb4927 100644 --- a/tools/testing/selftests/net/Makefile +++ b/tools/testing/selftests/net/Makefile @@ -36,6 +36,7 @@ TEST_PROGS :=3D \ fib_nexthop_multiprefix.sh \ fib_nexthop_nongw.sh \ fib_nexthops.sh \ + fib_nexthops_fdb_port.sh \ fib_rule_tests.sh \ fib_tests.sh \ fin_ack_lat.sh \ diff --git a/tools/testing/selftests/net/fib_nexthops_fdb_port.sh b/tools/t= esting/selftests/net/fib_nexthops_fdb_port.sh new file mode 100755 index 000000000..8b401c6d2 --- /dev/null +++ b/tools/testing/selftests/net/fib_nexthops_fdb_port.sh @@ -0,0 +1,78 @@ +#!/bin/bash +# SPDX-License-Identifier: GPL-2.0 +# +# Control-plane selftest for per-nexthop VXLAN fdb destination port +# (NHA_FDB_PORT). Verifies the accept/reject rules and the dump roundtrip. +# No datapath traffic here -- see tests/integ/vxlan-fdb-port-integ.sh for = the +# real forwarding test. +# +# Requires: patched kernel (NHA_FDB_PORT) and patched iproute2 (the "port" +# keyword on "ip nexthop ... fdb"). SKIPs cleanly otherwise. + +set -u + +ksft_skip=3D4 +NS=3D"nhfdbport-$$" +IP=3D"ip -netns $NS" +ret=3D0 + +log_test() { # $1 actual_rc $2 expected_rc $3 name + if [ "$1" =3D "$2" ]; then + printf "TEST: %-58s [ OK ]\n" "$3" + else + printf "TEST: %-58s [FAIL] (rc=3D$1 want=3D$2)\n" "$3" + ret=3D1 + fi +} + +# passes (returns 0) iff the command FAILS +expect_fail() { + if "$@" >/dev/null 2>&1; then return 1; else return 0; fi +} + +cleanup() { ip netns del "$NS" 2>/dev/null; } + +command -v ip >/dev/null 2>&1 || { echo "SKIP: iproute2 not found"; exit $= ksft_skip; } +ip nexthop help 2>&1 | grep -q fdb || { echo "SKIP: no fdb nexthop support= "; exit $ksft_skip; } + +trap cleanup EXIT +cleanup +ip netns add "$NS" || { echo "SKIP: cannot create netns"; exit $ksft_skip;= } +$IP link set lo up + +# Probe for "port" keyword + kernel NHA_FDB_PORT support; SKIP if missing. +if ! $IP nexthop add id 1 via 10.0.0.1 fdb port 4790 2>/dev/null; then + echo "SKIP: 'ip nexthop ... fdb port' unsupported (needs patched kernel += iproute2)" + exit $ksft_skip +fi +log_test 0 0 "add fdb nexthop with port" + +# Dump roundtrip must echo the port back. +$IP nexthop show id 1 | grep -qw "port 4790" +log_test $? 0 "dump shows fdb port 4790" + +# Reject: port on a routed (non-fdb) nexthop. +expect_fail $IP nexthop add id 2 via 10.0.0.1 dev lo port 4790 +log_test $? 0 "reject port on non-fdb nexthop" + +# Reject: fdb port without a gateway. +expect_fail $IP nexthop add id 3 fdb port 4790 +log_test $? 0 "reject fdb port without gateway" + +# The HA case: a group whose legs share the gateway but differ in port. +$IP nexthop add id 10 via 10.0.0.1 fdb port 4789 && \ +$IP nexthop add id 11 via 10.0.0.1 fdb port 5789 && \ +$IP nexthop add id 100 group 10/11 fdb +log_test $? 0 "add fdb nexthop group with differing ports" + +# A fdb nexthop without a port must NOT emit one (backward compat). +$IP nexthop add id 20 via 10.0.0.1 fdb +$IP nexthop show id 20 | grep -qw "port" +log_test $? 1 "fdb nexthop without port omits NHA_FDB_PORT" + +if [ $ret -eq 0 ]; then + echo "PASS: all NHA_FDB_PORT control-plane checks" +else + echo "FAIL: one or more NHA_FDB_PORT checks failed" +fi +exit $ret --=20 2.43.0