From nobody Sat Jul 25 00:16:24 2026 Received: from mail-pl1-f176.google.com (mail-pl1-f176.google.com [209.85.214.176]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 4AB0B36DA1D for ; Tue, 21 Jul 2026 22:30:02 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.214.176 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784673005; cv=none; b=AW240JsM16QS8XsiTRIRzh6ZnrDI8gDESLEGDTuNzxB6AJFj6Jho0qoR1ZeSaMVcapkhKqSDHkDkfEGBUGh8RXXx3glaD8+w5t8ls2IGdUarQLjuWm1xeFksauZOpS3c+OkqTS3cAfKvbfdCDCnwvKIsMVrKDaPQKeADJ/zM7iI= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784673005; c=relaxed/simple; bh=aCZ1nYC56oVsqz3nAosAp9UeLpyyVDpG1ZflrS+5rQQ=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=bCb+nbYv9SE/s5//hxVd2J74quRgc2U5gQjW8ceELf3z6WrTWikWNLJYOTN0ZR++dfkFP25g2mvoeJ7t7WJO7xVHwntONr6mu03VbHUsCKt/cN90xDyB4GjP4xeRmHePMx+tG4wr9J1/7A8QeJH30zMjUGoZ8pxDRorDS4eLExA= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=OMq8YBBG; arc=none smtp.client-ip=209.85.214.176 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="OMq8YBBG" Received: by mail-pl1-f176.google.com with SMTP id d9443c01a7336-2cee9b74ee1so75691775ad.3 for ; Tue, 21 Jul 2026 15:30:02 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1784673002; x=1785277802; darn=vger.kernel.org; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :content-type:mime-version:subject:date:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=f+L2jaWd7tEXAzV/TnysMQtl4QLqTTYCdiIRJKMNP80=; b=OMq8YBBGMtsqbBzhkAQYk1gcWAHVa4M7LWCKfH+0ooUIn4RIMsl6q8S//StRHpqnJx rknSG8FmTjp9H/wuGMherlkBzOdU/SUZLjX04JTokY4Q3RUGttI3lR5ESvPZ0e7nS5my uHpABcmN4s6a9neuk2YEet8iKSd/L2C/ELz55ddjg2vWQ+koP37nrIuC/6jPDIId/kJW SADHEfKAuFB5dITgwmsvsMr8skN4USKxxyMta38/RgO9IMLPKLkshQmTwJnLkP93OP8u TqbU8GkR1Wi5sV4U9DVVzmOywjMSpuErRR96xTtww72IU8L9+4UJiiF08wvCXX8BRb7i zFbw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784673002; x=1785277802; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :content-type:mime-version:subject:date:from:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=f+L2jaWd7tEXAzV/TnysMQtl4QLqTTYCdiIRJKMNP80=; b=ckkjONB7migaLL6z9nWdN/JvDFVm4R0YgOLqfMt1fMD+7onEVrPxyTfitHRNJU+8hl QXgs7rmQVKbSCaMdLvbCaPsZkFhrALFzYSzIJHvMxCdrtLpiq0M2CO0OI635wgwMeriK mkFaiJzEOApCouXibF6XmuDrSj2JlyM+773kmOJDrkuNJ+Idr93NRWvzetDMAk+MKyle cs1DoOpaEAfl+p3LqGykRLpk23gNaEBWzcaxS59VF/oI32E87N4rxoNi49m7T18aA2o6 m3FdH1TJvFKsOWqJkHBDwgdsdRZdVzukA2YilUmFEH9OT6XWtizclayVTl9Z0JMe8KnK mH9Q== X-Forwarded-Encrypted: i=1; AHgh+RoLcfIKi2EU24RVBIN/c907E2Ao0c5HimfJ+Ixleb/uQTPy3f9lq8a3oJgBVs8HkhV7RpI+h/d/zT3lWPg=@vger.kernel.org X-Gm-Message-State: AOJu0YwdHxLGUh6rBk8AYqv+u3m/guPvo3Jcoa9hSLWycUQwgB7GaDUf mtpwat+bD9FdRhBtPZ8EXSP31KVlq/tqQX5W9MhWfpRNQDADSN7znBBw X-Gm-Gg: AR+sD11gyEH/jiII+EUNpgCp9OYF6ZTmUv0Lj14KWpdwGsOHxd5x5EBh6qEyGh8CyF5 GquZQ8kJXy7oLDW+/arYCNfa3oopUJHGiDKITHQNKP0KHLE825cQJwC/yD2O+fVjQSt5eDsr/6V gZm3tczsMmWDKNauBrIObz4Q4oCOUaDql6b8FravikSLWOgMF6PUQ3boCPIWumMeCEPtN4oOC4X RI8NDoLxjVy0t4oIWk1G0qp5NqY6L2YGttlelIqLhEURUbiokZFHMuSwyfeQVkY78y3K4N4Nim9 XnuHfnEHBZG4zAnDTpkk/Z6xR441z258rnTcNZH4u/8NOlZ+Lpzif8Et6aorJzc1Fe9MWAiU89N D1UGlQOcoikwWGMBJzzFpn+ooL4pjC/VKBgfOLP384SGkRJZGIr+tJMiNUvbBLIRRr/inNqkoIR 2ULDYifLV5W3ls7hQ= X-Received: by 2002:a17:903:1aaf:b0:2ca:c4a5:84bb with SMTP id d9443c01a7336-2cf349c97b5mr219846475ad.38.1784673001667; Tue, 21 Jul 2026 15:30:01 -0700 (PDT) Received: from CPC-mjac-HKWGEZ.localdomain ([70.37.26.40]) by smtp.gmail.com with ESMTPSA id d9443c01a7336-2cf8efde5cfsm3787685ad.31.2026.07.21.15.30.00 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 21 Jul 2026 15:30:00 -0700 (PDT) From: Jack Ma Date: Tue, 21 Jul 2026 22:29:50 +0000 Subject: [PATCH net-next v3 1/3] net: nexthop: add NHA_FDB_PORT for fdb nexthops Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260721-b4-vxlan-fdb-port-v3-1-9aa0a543a78a@gmail.com> References: <20260721-b4-vxlan-fdb-port-v3-0-9aa0a543a78a@gmail.com> In-Reply-To: <20260721-b4-vxlan-fdb-port-v3-0-9aa0a543a78a@gmail.com> To: David Ahern , Ido Schimmel , "David S. Miller" , Eric Dumazet , Jakub Kicinski , Paolo Abeni , Simon Horman , Shuah Khan Cc: netdev@vger.kernel.org, linux-kernel@vger.kernel.org, linux-kselftest@vger.kernel.org, Jack Ma X-Mailer: b4 0.15.2 X-Developer-Signature: v=1; a=ed25519-sha256; t=1784672999; l=4113; i=jack4it@gmail.com; s=20260712; h=from:subject:message-id; bh=aCZ1nYC56oVsqz3nAosAp9UeLpyyVDpG1ZflrS+5rQQ=; b=MRlo23ob5K6AxEbeRkC+A1AErbdt8EJ+9bV7J0EAYYqyUK5XwbhjpzXXd/mtnUuYGNWpfjhvD nxmmJ/NBC++CJENoDX6RHxQ9/v592SQm0XWhFxJiP12jhc6UJ1wCd+O X-Developer-Key: i=jack4it@gmail.com; a=ed25519; pk=x8xh2Md9yNDil0xBOA9WA/oqC3O4Eg4rdlIul4YUktU= Commit 1274e1cc4226 ("vxlan: ecmp support for mac fdb entries") lets a single inner MAC be reached through a group of remote VTEPs, with the kernel flow-hashing across the group members. Each member carries its own remote IP, but the UDP destination port is always taken from the VXLAN device (vxlan->cfg.dst_port) and cannot be set per member. Some deployments pack several receivers behind one underlay IP and tell them apart by UDP port, so they need a per-nexthop destination port to spread flows across (IP, port) tuples rather than IP alone. Add a netlink attribute NHA_FDB_PORT (__be16, mirroring NDA_PORT) that carries an optional UDP destination port on an fdb nexthop. It is only accepted together with NHA_FDB and NHA_GATEWAY; it is stored in struct nh_info and echoed back on dump. This patch is control-plane plumbing only; the VXLAN datapath is wired up in a follow-up patch, so behaviour is unchanged for now. Signed-off-by: Jack Ma --- include/net/nexthop.h | 2 ++ include/uapi/linux/nexthop.h | 3 +++ net/ipv4/nexthop.c | 20 +++++++++++++++++++- 3 files changed, 24 insertions(+), 1 deletion(-) diff --git a/include/net/nexthop.h b/include/net/nexthop.h index 572e69cda476..9c822799634f 100644 --- a/include/net/nexthop.h +++ b/include/net/nexthop.h @@ -28,6 +28,7 @@ struct nh_config { u8 nh_protocol; u8 nh_blackhole; u8 nh_fdb; + __be16 nh_fdb_port; u32 nh_flags; =20 int nh_ifindex; @@ -63,6 +64,7 @@ struct nh_info { u8 family; bool reject_nh; bool fdb_nh; + __be16 fdb_port; =20 union { struct fib_nh_common fib_nhc; diff --git a/include/uapi/linux/nexthop.h b/include/uapi/linux/nexthop.h index bc49baf4a267..e587bbf3b890 100644 --- a/include/uapi/linux/nexthop.h +++ b/include/uapi/linux/nexthop.h @@ -83,6 +83,9 @@ enum { /* u32; read-only; whether any driver collects HW stats */ NHA_HW_STATS_USED, =20 + /* be16; UDP destination port for an fdb nexthop (e.g. VXLAN) */ + NHA_FDB_PORT, + __NHA_MAX, }; =20 diff --git a/net/ipv4/nexthop.c b/net/ipv4/nexthop.c index 6205bd57aa85..b82da3eff63c 100644 --- a/net/ipv4/nexthop.c +++ b/net/ipv4/nexthop.c @@ -39,6 +39,7 @@ static const struct nla_policy rtm_nh_policy_new[] =3D { [NHA_ENCAP_TYPE] =3D { .type =3D NLA_U16 }, [NHA_ENCAP] =3D { .type =3D NLA_NESTED }, [NHA_FDB] =3D { .type =3D NLA_FLAG }, + [NHA_FDB_PORT] =3D NLA_POLICY_MIN(NLA_BE16, 1), [NHA_RES_GROUP] =3D { .type =3D NLA_NESTED }, [NHA_HW_STATS_ENABLE] =3D NLA_POLICY_MAX(NLA_U32, true), }; @@ -956,6 +957,9 @@ static int nh_fill_node(struct sk_buff *skb, struct nex= thop *nh, } else if (nhi->fdb_nh) { if (nla_put_flag(skb, NHA_FDB)) goto nla_put_failure; + if (nhi->fdb_port && + nla_put_be16(skb, NHA_FDB_PORT, nhi->fdb_port)) + goto nla_put_failure; } else { const struct net_device *dev; =20 @@ -1055,6 +1059,9 @@ static size_t nh_nlmsg_size_single(struct nexthop *nh) break; } =20 + if (nhi->fdb_port) + sz +=3D nla_total_size(2); /* NHA_FDB_PORT */ + if (nhi->fib_nhc.nhc_lwtstate) { sz +=3D lwtunnel_get_encap_size(nhi->fib_nhc.nhc_lwtstate); sz +=3D nla_total_size(2); /* NHA_ENCAP_TYPE */ @@ -2956,8 +2963,10 @@ static struct nexthop *nexthop_create(struct net *ne= t, struct nh_config *cfg, nhi->family =3D cfg->nh_family; nhi->fib_nhc.nhc_scope =3D RT_SCOPE_LINK; =20 - if (cfg->nh_fdb) + if (cfg->nh_fdb) { nhi->fdb_nh =3D 1; + nhi->fdb_port =3D cfg->nh_fdb_port; + } =20 if (cfg->nh_blackhole) { nhi->reject_nh =3D 1; @@ -3147,6 +3156,15 @@ static int rtm_to_nh_config(struct net *net, struct = sk_buff *skb, cfg->nh_fdb =3D nla_get_flag(tb[NHA_FDB]); } =20 + if (tb[NHA_FDB_PORT]) { + if (!tb[NHA_FDB] || !tb[NHA_GATEWAY]) { + NL_SET_ERR_MSG(extack, + "FDB port can only be set on fdb nexthops that have a gateway"); + goto out; + } + cfg->nh_fdb_port =3D nla_get_be16(tb[NHA_FDB_PORT]); + } + if (tb[NHA_GROUP]) { if (nhm->nh_family !=3D AF_UNSPEC) { NL_SET_ERR_MSG(extack, "Invalid family for group"); --=20 2.43.0 From nobody Sat Jul 25 00:16:24 2026 Received: from mail-pl1-f172.google.com (mail-pl1-f172.google.com [209.85.214.172]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 4DA1343F8DE for ; Tue, 21 Jul 2026 22:30:03 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.214.172 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784673004; cv=none; b=Zs/tgdAvUjkynT8Lby3N7W0m2S1z3ZXkN4by03YahSu7i68FAVFTmlQ7uk7oHl5r685UtQHpylklC9UnLu7U2UjrwqIj8DWpwx18P9GaR98IToXWCyixm3aZG6ErgeFIgNfSX3E8BZ3iqm+TJJtyzaOdGMqx7/YiWnCuPEBfUjA= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784673004; c=relaxed/simple; bh=FxAaKZNrqIYMFVFz0kxYus4A4eLSft8cn0LfWd09iUQ=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=fHEAqpfQU7F5lh/Nhdg8n7mAvcZwkAsKzdL8xFpXivcLMh5OhdLZEwLDtpvC5qMPzZTeh0Qpi6+u0rrJ/ycO865IwvrGldNULSx4Uu3Oe5WaBhZgN+30Kzdq9op9z+CWTkabdhkiRz6xVscAsm9MqlnFximXxuzViBVI7Fds7CU= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=YDbkqWYl; arc=none smtp.client-ip=209.85.214.172 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="YDbkqWYl" Received: by mail-pl1-f172.google.com with SMTP id d9443c01a7336-2ce87c7e3bbso133491965ad.1 for ; Tue, 21 Jul 2026 15:30:03 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1784673003; x=1785277803; darn=vger.kernel.org; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :content-type:mime-version:subject:date:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=DBZyOnBzaFrr93xN0hje2B80zLLVKQ4FJDvNO4Frc1g=; b=YDbkqWYlj686Fp99HZKHs0WazBQymjQxVrdy479Bkqg39eX8zhYDCf47OABEjjT3EZ qICR2Ct9MFQbL5npbkPDhYKK4VtH/YYNuiub5ZAXSTFhogYm+ENW2l2oxabItOPzCbbg Vs4C0xwb3GMs5qUmWYWdanTzosG1AA2nTzYEfo9wOuE7YiEQmXkEhoxaBKJ+Rp1ibAsO ZeNTH/A5HkfQWDyhpmAqNL4dihnavOWTSzBdSmRci12NMutnKNU0ghkNkTTrlPmJ4udc h53Ga6kC1eP7Bmymfu3k5cQvND4Z1GbtpK9QXah4ipXeNWOMRKh4H1qOahJfWYNwt+EK YZAQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784673003; x=1785277803; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :content-type:mime-version:subject:date:from:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=DBZyOnBzaFrr93xN0hje2B80zLLVKQ4FJDvNO4Frc1g=; b=Jdr9nFjtzYALRGjTCzx9d8/ZWpcIrsLOzdFHNRqQzzTc0f2CqR4kpqAyI+9gP3V/u/ G4lMfhzXRufff9MlGQ3QrZiQrpahjYCt2Jq9cOJ2UdmhDGNC3YYsDs0AGtucDs/0gwPU iywztAHgXUQMCQnPWktOXIHrA34dHcUO9aLZOZ6QtGtjQ5mo2uPxFcHx2NgTlgqJRHUI fKCGQe/C1ve9PCLWYbRUBFDudUy+9Bxd3nmtLKJ2QFIc3yPyZMtkZzd1+zimxo7S8Hz4 Juk4caSA5aJnxo6dqMTn1ulmaCPKhmlH/iI3HhTrZaAt1G7GZaEZ4plWqjKRFaXRCWbk ZMJQ== X-Forwarded-Encrypted: i=1; AHgh+Ro2X+B/nXw93rgKpt+xLIXPSHTfjFPxRNb+6v1nhVSDaJ54JxTUoDgtxumqBYmLG3rr7ykiS1iejSGGqWc=@vger.kernel.org X-Gm-Message-State: AOJu0YzkWXAAf8X4OXmhKBjHEYv/7H/so4TDfnO9+VeZxa1P7xDzmufj uo7xHD84D65OcC9D1J/tmYLO6vgIOddVU9/ZhpPzaeOEWuJrok5NrhJG X-Gm-Gg: AR+sD110v6Tf7CusHqvFcBnIadSAiG2frOx4jo4iioXVM6XSB2nfmCjRPS60Sl2Zs4T oN4+ngJGSrXTox83pEni/ZC1cDUjkproIs7aUWGXrDYo7L7/JBd4UcfLtkS0bkz9WTbEdzQckR7 R7QpKOMlWaYRz4ikgjwrJeB8Cg8BuxYQ6CrdQQlLYD317PjPqaymqCSsqnkWKSRyFBTqCEeey4M WOdp+xKNtEkPKGaOxA8AlQ7HkLosWONIGiX5zygxwkBA0IKZBLoERqYGZEkq2xXTFtOSpgSYhod N+gYwRPULEI+MYoFPz/wZe1Q14oS2uh0hDR0Po6GNW5NHS7MV6dfZhA2ZMx/EtH/4hzxu+S/MUz LcTpZQGYqdjcXEvxkxT2Pd7W84XMbSA7SEO6bHPoQSBtvsBKiSQSYZoPEMbJD0TfItQGVltQY3R 5nQlJzygsHS4x8p/4= X-Received: by 2002:a17:903:988:b0:2cc:f5aa:9513 with SMTP id d9443c01a7336-2cf34821a87mr233529595ad.10.1784673002699; Tue, 21 Jul 2026 15:30:02 -0700 (PDT) Received: from CPC-mjac-HKWGEZ.localdomain ([70.37.26.40]) by smtp.gmail.com with ESMTPSA id d9443c01a7336-2cf8efde5cfsm3787685ad.31.2026.07.21.15.30.01 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 21 Jul 2026 15:30:02 -0700 (PDT) From: Jack Ma Date: Tue, 21 Jul 2026 22:29:51 +0000 Subject: [PATCH net-next v3 2/3] vxlan: honor per-nexthop fdb destination port Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260721-b4-vxlan-fdb-port-v3-2-9aa0a543a78a@gmail.com> References: <20260721-b4-vxlan-fdb-port-v3-0-9aa0a543a78a@gmail.com> In-Reply-To: <20260721-b4-vxlan-fdb-port-v3-0-9aa0a543a78a@gmail.com> To: David Ahern , Ido Schimmel , "David S. Miller" , Eric Dumazet , Jakub Kicinski , Paolo Abeni , Simon Horman , Shuah Khan Cc: netdev@vger.kernel.org, linux-kernel@vger.kernel.org, linux-kselftest@vger.kernel.org, Jack Ma X-Mailer: b4 0.15.2 X-Developer-Signature: v=1; a=ed25519-sha256; t=1784672999; l=2191; i=jack4it@gmail.com; s=20260712; h=from:subject:message-id; bh=FxAaKZNrqIYMFVFz0kxYus4A4eLSft8cn0LfWd09iUQ=; b=TpM/CzrB56PS+2og2O88NqgEelFcCWHLRmmLI+3lhGXZM4Fq3vAjkzu4rskxzu3jPSMf+HO/o 2cxKb8SeSpFAZ9tQ/19VTWFsy/w27NYb7s6NZHscCYs1ojq6HU3Ov8d X-Developer-Key: i=jack4it@gmail.com; a=ed25519; pk=x8xh2Md9yNDil0xBOA9WA/oqC3O4Eg4rdlIul4YUktU= When an fdb entry points at a nexthop group, vxlan_fdb_nh_path_select() resolves the selected leg's remote IP but leaves the UDP destination port at the device default (vxlan->cfg.dst_port). Extend nexthop_path_fdb_result() to also return the selected nexthop's NHA_FDB_PORT (0 when unset) and have vxlan_fdb_nh_path_select() store it in rdst->remote_port. vxlan_xmit_one() already prefers rdst->remote_port when non-zero and falls back to the device port otherwise, so nexthops without a port are unaffected. This lets one fdb nexthop group load-balance a flow across legs that share an underlay IP but differ in UDP destination port. Signed-off-by: Jack Ma --- include/net/nexthop.h | 4 +++- include/net/vxlan.h | 5 ++++- 2 files changed, 7 insertions(+), 2 deletions(-) diff --git a/include/net/nexthop.h b/include/net/nexthop.h index 9c822799634f..19e8670d964d 100644 --- a/include/net/nexthop.h +++ b/include/net/nexthop.h @@ -576,7 +576,8 @@ struct fib_nh_common *nexthop_fdb_nhc(struct nexthop *n= h) } =20 static inline struct fib_nh_common *nexthop_path_fdb_result(struct nexthop= *nh, - int hash) + int hash, + __be16 *fdb_port) { struct nh_info *nhi; struct nexthop *nhp; @@ -585,6 +586,7 @@ static inline struct fib_nh_common *nexthop_path_fdb_re= sult(struct nexthop *nh, if (unlikely(!nhp)) return NULL; nhi =3D rcu_dereference(nhp->nh_info); + *fdb_port =3D nhi->fdb_port; return &nhi->fib_nhc; } #endif diff --git a/include/net/vxlan.h b/include/net/vxlan.h index dfba89695efc..de41b374688f 100644 --- a/include/net/vxlan.h +++ b/include/net/vxlan.h @@ -567,8 +567,9 @@ static inline bool vxlan_fdb_nh_path_select(struct next= hop *nh, struct vxlan_rdst *rdst) { struct fib_nh_common *nhc; + __be16 fdb_port =3D 0; =20 - nhc =3D nexthop_path_fdb_result(nh, hash >> 1); + nhc =3D nexthop_path_fdb_result(nh, hash >> 1, &fdb_port); if (unlikely(!nhc)) return false; =20 @@ -583,6 +584,8 @@ static inline bool vxlan_fdb_nh_path_select(struct next= hop *nh, break; } =20 + rdst->remote_port =3D fdb_port; + return true; } =20 --=20 2.43.0 From nobody Sat Jul 25 00:16:24 2026 Received: from mail-pl1-f171.google.com (mail-pl1-f171.google.com [209.85.214.171]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 39644407CDA for ; Tue, 21 Jul 2026 22:30:03 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.214.171 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784673005; cv=none; b=Wv7EtXOLyTE7hefOH9mMx6b8wioz6JFgr9BK38AFVDeh16ZBQ4or/IOjKveywntV3Sbb3fOyXf8cX7gCGi9Py0CL9oUuLcNi0O+bSDkaAfN1VyJSanSbwdcDoHozpmNyAZsNNF30Kg3X3eRY24vWiEdDpTiSPCP+BeFrrsa7UBQ= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784673005; c=relaxed/simple; bh=uZRZ2VN44Q5XzL/F2XgrEb/jhTB2g8aztDio6kTbBac=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=YnHDkLbjXmy9P/FKAQeVYleitHpU43vjtG4adLXzepmPkzcZ+8IrEtoVd2S3beeZ7fwZOdI1tqe1WYwtAK5+icCn0RitroowBk+Wx6TwlCgMILyaJS8BkExG46wmuOp1n+ksD8mZIMCvIvEewfB8K8a4Ac2qpGNnuMwQ8l+LFkA= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=OqcWIT40; arc=none smtp.client-ip=209.85.214.171 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="OqcWIT40" Received: by mail-pl1-f171.google.com with SMTP id d9443c01a7336-2ceaf8a1265so118929335ad.2 for ; Tue, 21 Jul 2026 15:30:03 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1784673003; x=1785277803; darn=vger.kernel.org; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :content-type:mime-version:subject:date:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=SACM/ZkSy0Q+E/W2IAydC2E/hnHraYOT4Rhvc9t0KKg=; b=OqcWIT40tDSudduOZs8F03lSCMn6UZ//ZYcJrqY9XoHSTtGJb//4Up/A2FTboQfQKV nXmFjhfSVdKN9ToWdqiLo/qQ7piYtpdCdvCdJI/Ryc44j86vpIB/7LLwrB1QR9/vmhrF gJs69+4A0wiBqq6giCoobd4PeYgm/DbCwBANs/GlQA/BEfbGGonRQmD2i0bdljlE3rtq thDhy2N8sufPrwaAIWsGhFDCT0+d1zYJtjaMDTYytZLrWPc2XEhpJcbPillmjoRSL83+ Ya3lsxnLa9OUXp+oiftesrAaXRJElF6TfrO7Dx7RWT1xMgPReBIY8DYjBv0lqLutOMx5 V4vw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784673003; x=1785277803; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :content-type:mime-version:subject:date:from:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=SACM/ZkSy0Q+E/W2IAydC2E/hnHraYOT4Rhvc9t0KKg=; b=dZIY358LWMsPKA0Hdr3cirzMOYHBSeqN1DY2TdO/vWmlHiR8QGLP6yI3Xd66Wa4g9z gJvZ/NhB6N+2fW9nLalFwWi/iHXwy7+YenL38FctmkkrGNDL91sdy06GNybTL6+Zu3Vr KF4l/9OyMVGsX1jn9wBDnrzUOYzUCu2Sq0ywXko0FpSQjpVhBAMXqt3CYpxndggtRoN9 LJCG81Vw0d5Jn5uMrb0FBhlx1vwe3590V64/ahJWVEZwHjGvkBjOeXqp292ovLrippWp LZeJVln6gFz98FPpuMUVn0QV7ciAVOwtHUl/rpoARurhzTO26LO7FHXkB6ROT1NJLCc/ OFNg== X-Forwarded-Encrypted: i=1; AHgh+RrHZUV4cFniegbW2laqkhlO8wbIzwl/NnVf3LQxgj3UzNGm5P81UZx5U9E/mksvZOD8xUCEfD6fDcNdQew=@vger.kernel.org X-Gm-Message-State: AOJu0Yy+LXhxtpl2Xdtoiko/SQ7VLJfQqR8OSYe34eXjE9nFGO3NY8Ni nsLYNPqZMOiiqTBk+yjP62YpMr8yYvMIAmTMFZgF33j/QXbobPcMgZiW X-Gm-Gg: AR+sD113RGCpcOnkZMFK68p04fkfwEYiYqIBbQJg/31ahUyLNJEZtrxR8iwoJZHZEZg rH7ZeOiIsx+3ThXcVC34WhuprLZRaLcFsNt3j5uz3d5vqHw6Mx89MJQiwuUr7IOJ0RNysaIryjW Cg49WEjvbLHH19ccBtLBbKtaMYwGuB3eQmxtvcWQdpKNYbObeDWbHox61v6XZ7V9gHIQMz3g8z9 q165n8FBS3JPrcY8i26R7ZNmeqwkx5lqo0CiG9IERWKDl5BIpyOJCF5+h9Qliw9zgabvH9QY6IA H69ujuRZSLGq48D5DumhdO8+H5CuqoCewF2JzWiVhgm+eDeA916cnC0Uvfw6jXJ1IsoVHM7IQA8 1dkIjDg3MTZQKHCfuh3pIEf01CB72RQ062Qtml6cR9AlS5bkOl78HGJy1Ekpirb+Lw/TUjg6fEN 1HKnZtYoaq01f9zuY= X-Received: by 2002:a17:903:298c:b0:2ca:4b7a:4a02 with SMTP id d9443c01a7336-2cf34a7bfe4mr218688335ad.43.1784673003421; Tue, 21 Jul 2026 15:30:03 -0700 (PDT) Received: from CPC-mjac-HKWGEZ.localdomain ([70.37.26.40]) by smtp.gmail.com with ESMTPSA id d9443c01a7336-2cf8efde5cfsm3787685ad.31.2026.07.21.15.30.02 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 21 Jul 2026 15:30:03 -0700 (PDT) From: Jack Ma Date: Tue, 21 Jul 2026 22:29:52 +0000 Subject: [PATCH net-next v3 3/3] selftests: net: add coverage for fdb nexthop dst port Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260721-b4-vxlan-fdb-port-v3-3-9aa0a543a78a@gmail.com> References: <20260721-b4-vxlan-fdb-port-v3-0-9aa0a543a78a@gmail.com> In-Reply-To: <20260721-b4-vxlan-fdb-port-v3-0-9aa0a543a78a@gmail.com> To: David Ahern , Ido Schimmel , "David S. Miller" , Eric Dumazet , Jakub Kicinski , Paolo Abeni , Simon Horman , Shuah Khan Cc: netdev@vger.kernel.org, linux-kernel@vger.kernel.org, linux-kselftest@vger.kernel.org, Jack Ma X-Mailer: b4 0.15.2 X-Developer-Signature: v=1; a=ed25519-sha256; t=1784672999; l=6796; i=jack4it@gmail.com; s=20260712; h=from:subject:message-id; bh=uZRZ2VN44Q5XzL/F2XgrEb/jhTB2g8aztDio6kTbBac=; b=T+jPlHObpnglpfTY7pQTXNgn13M0Do7klKkxPmWXYTvfkPm/6VhFmmazfpfpWHkmg6H/Xpfx/ 8CXZ7ADb1ziCllIrvcE3ycKiuFPJqv6nhGFMcr62tLZPIIZlMcbjVzo X-Developer-Key: i=jack4it@gmail.com; a=ed25519; pk=x8xh2Md9yNDil0xBOA9WA/oqC3O4Eg4rdlIul4YUktU= Extend the existing fdb nexthop group tests with cases for the new per-nexthop VXLAN destination port (NHA_FDB_PORT). In fib_nexthops.sh, ipv4_fdb_grp_fcnal() and ipv6_fdb_grp_fcnal() now check that a port is accepted on an fdb nexthop that has a gateway and echoed back on dump, that it is rejected without a gateway and rejected when zero, that a group may hold legs that differ only in UDP port, and that a portless fdb nexthop omits the attribute. The cases SKIP when iproute2 lacks the "port" keyword. In test_vxlan_nh.sh, basic_tx_common() gains a second fdb nexthop group whose nexthop carries a destination port that differs from the VXLAN device default, plus a flower filter keyed on that port, to confirm the per-nexthop port is used on the wire. Signed-off-by: Jack Ma --- tools/testing/selftests/net/fib_nexthops.sh | 59 ++++++++++++++++++++++++= ++++ tools/testing/selftests/net/test_vxlan_nh.sh | 31 +++++++++++++++ 2 files changed, 90 insertions(+) diff --git a/tools/testing/selftests/net/fib_nexthops.sh b/tools/testing/se= lftests/net/fib_nexthops.sh index ac868a731694..1ce4f45fa651 100755 --- a/tools/testing/selftests/net/fib_nexthops.sh +++ b/tools/testing/selftests/net/fib_nexthops.sh @@ -432,6 +432,15 @@ check_nexthop_fdb_support() fi } =20 +check_nexthop_fdb_port_support() +{ + $IP nexthop help 2>&1 | grep -q "fdb \[ port" + if [ $? -ne 0 ]; then + echo "SKIP: iproute2 too old, missing fdb nexthop port support" + return $ksft_skip + fi +} + check_nexthop_res_support() { $IP nexthop help 2>&1 | grep -q resilient @@ -514,6 +523,31 @@ ipv6_fdb_grp_fcnal() run_cmd "$IP nexthop replace id 72 via 2001:db8:91::2 fdb" log_test $? 2 "Replace non-FDB nexthop to FDB nexthop while in a group" =20 + # NHA_FDB_PORT: optional per-nexthop VXLAN destination UDP port, + # letting an fdb nexthop group balance a flow across legs that share + # an underlay IP but listen on different UDP ports. + if check_nexthop_fdb_port_support; then + run_cmd "$IP nexthop add id 80 via 2001:db8:91::2 fdb port 4790" + check_nexthop "id 80" "id 80 via 2001:db8:91::2 scope link fdb port 4790" + log_test $? 0 "Fdb nexthop with port" + + run_cmd "$IP nexthop add id 81 fdb port 4790" + log_test $? 2 "Fdb nexthop with port but no gateway" + + run_cmd "$IP nexthop add id 81 via 2001:db8:91::2 fdb port 0" + log_test $? 2 "Fdb nexthop with port 0" + + run_cmd "$IP nexthop add id 82 via 2001:db8:91::2 fdb port 4789" + run_cmd "$IP nexthop add id 83 via 2001:db8:91::3 fdb port 5789" + run_cmd "$IP nexthop add id 106 group 82/83 fdb" + check_nexthop "id 106" "id 106 group 82/83 fdb" + log_test $? 0 "Fdb nexthop group with legs differing in port" + + run_cmd "$IP nexthop add id 84 via 2001:db8:91::2 fdb" + check_nexthop "id 84" "id 84 via 2001:db8:91::2 scope link fdb" + log_test $? 0 "Fdb nexthop without port omits port" + fi + run_cmd "$IP link add name vx10 type vxlan id 1010 local 2001:db8:91::9 r= emote 2001:db8:91::10 dstport 4789 nolearning noudpcsum tos inherit ttl 100" run_cmd "$BRIDGE fdb add 02:02:00:00:00:13 dev vx10 nhid 102 self" log_test $? 0 "Fdb mac add with nexthop group" @@ -614,6 +648,31 @@ ipv4_fdb_grp_fcnal() run_cmd "$IP nexthop replace id 20 via 172.16.1.2 fdb" log_test $? 2 "Replace non-FDB nexthop to FDB nexthop while in a group" =20 + # NHA_FDB_PORT: optional per-nexthop VXLAN destination UDP port, + # letting an fdb nexthop group balance a flow across legs that share + # an underlay IP but listen on different UDP ports. + if check_nexthop_fdb_port_support; then + run_cmd "$IP nexthop add id 30 via 172.16.1.2 fdb port 4790" + check_nexthop "id 30" "id 30 via 172.16.1.2 scope link fdb port 4790" + log_test $? 0 "Fdb nexthop with port" + + run_cmd "$IP nexthop add id 31 fdb port 4790" + log_test $? 2 "Fdb nexthop with port but no gateway" + + run_cmd "$IP nexthop add id 31 via 172.16.1.2 fdb port 0" + log_test $? 2 "Fdb nexthop with port 0" + + run_cmd "$IP nexthop add id 32 via 172.16.1.2 fdb port 4789" + run_cmd "$IP nexthop add id 33 via 172.16.1.3 fdb port 5789" + run_cmd "$IP nexthop add id 105 group 32/33 fdb" + check_nexthop "id 105" "id 105 group 32/33 fdb" + log_test $? 0 "Fdb nexthop group with legs differing in port" + + run_cmd "$IP nexthop add id 34 via 172.16.1.2 fdb" + check_nexthop "id 34" "id 34 via 172.16.1.2 scope link fdb" + log_test $? 0 "Fdb nexthop without port omits port" + fi + run_cmd "$IP link add name vx10 type vxlan id 1010 local 10.0.0.1 remote = 10.0.0.2 dstport 4789 nolearning noudpcsum tos inherit ttl 100" run_cmd "$BRIDGE fdb add 02:02:00:00:00:13 dev vx10 nhid 102 self" log_test $? 0 "Fdb mac add with nexthop group" diff --git a/tools/testing/selftests/net/test_vxlan_nh.sh b/tools/testing/s= elftests/net/test_vxlan_nh.sh index 20f3369f776b..34a24a4f95bf 100755 --- a/tools/testing/selftests/net/test_vxlan_nh.sh +++ b/tools/testing/selftests/net/test_vxlan_nh.sh @@ -56,6 +56,16 @@ tc_stats_get() tc_rule_handle_stats_get "dev dummy1 egress" 101 ".packets" "-n $ns1" } =20 +nh_stats_get_port() +{ + ip -n "$ns1" -s -j nexthop show id 20 | jq ".[][\"group_stats\"][][\"pack= ets\"]" +} + +tc_stats_get_port() +{ + tc_rule_handle_stats_get "dev dummy1 egress" 102 ".packets" "-n $ns1" +} + basic_tx_common() { local af_str=3D$1; shift @@ -90,6 +100,27 @@ basic_tx_common() busywait "$BUSYWAIT_TIMEOUT" until_counter_is "=3D=3D 1" tc_stats_get > /= dev/null check_err $? "tc filter stats did not increase" =20 + # Add a second FDB nexthop group whose nexthop carries a per-nexthop + # destination port (NHA_FDB_PORT) that differs from the VXLAN device + # default. Matching outer traffic must egress with that port, so a + # separate flower filter keyed on the new port catches it. + if ip nexthop help 2>&1 | grep -q "fdb \[ port"; then + run_cmd "tc -n $ns1 filter add dev dummy1 egress proto $proto pref 1 han= dle 102 flower ip_proto udp dst_ip $remote_addr dst_port 4790 action pass" + + run_cmd "ip -n $ns1 nexthop add id 2 via $remote_addr fdb port 4790" + run_cmd "ip -n $ns1 nexthop add id 20 group 2 fdb" + + run_cmd "bridge -n $ns1 fdb add 00:11:22:33:44:66 dev vx0 self static nh= id 20" + + run_cmd "ip netns exec $ns1 mausezahn vx0 -a own -b 00:11:22:33:44:66 -c= 1 -q" + + busywait "$BUSYWAIT_TIMEOUT" until_counter_is "=3D=3D 1" nh_stats_get_po= rt > /dev/null + check_err $? "FDB nexthop group stats did not increase (with port)" + + busywait "$BUSYWAIT_TIMEOUT" until_counter_is "=3D=3D 1" tc_stats_get_po= rt > /dev/null + check_err $? "tc filter stats did not increase (with port)" + fi + log_test "VXLAN FDB nexthop: $af_str basic Tx" } =20 --=20 2.43.0