Skip to content

flow/fdb/bpf: fix stale flows on FDB port migration - #14

Open
danpawlik wants to merge 1 commit into
nbd168:masterfrom
danpawlik:improve-bridger
Open

flow/fdb/bpf: fix stale flows on FDB port migration#14
danpawlik wants to merge 1 commit into
nbd168:masterfrom
danpawlik:improve-bridger

Conversation

@danpawlik

Copy link
Copy Markdown

When a client moves between bridge ports, stale pending_flows entries can leave TC offload filters pointing at the old interface. Commit 95125f0 ("flow: reject pending flows with mismatched fdb device") skipped mismatched pending flows instead of migrating the FDB, which avoids refresh errors but never clears the stale filters.

Additionally, pending_flows are processed in hash order, so a stale entry processed after fdb_set_device() can trigger backwards migration on the same poll cycle and re-install filters for the departed port.

This commonly shows up during WiFi band roaming (e.g. 2.4 GHz to 5 GHz on dual-band APs), but applies to any FDB port migration on a bridged interface.

  • flow.c: migrate FDB when pending flow arrives on a different port
  • bpf.c: flush pending_flows for an interface
  • fdb.c: flush stale pending flows on migration; defer FDB deletion
  • nl.c: schedule deferred FDB delete on neighbor removal

When a client moves between bridge ports, stale pending_flows entries can
leave TC offload filters pointing at the old interface.  Commit 95125f0
("flow: reject pending flows with mismatched fdb device") skipped
mismatched pending flows instead of migrating the FDB, which avoids
refresh errors but never clears the stale filters.

Additionally, pending_flows are processed in hash order, so a stale entry
processed after fdb_set_device() can trigger backwards migration on the
same poll cycle and re-install filters for the departed port.

This commonly shows up during WiFi band roaming (e.g. 2.4 GHz to 5 GHz on
dual-band APs), but applies to any FDB port migration on a bridged
interface.

- flow.c: migrate FDB when pending flow arrives on a different port
- bpf.c: flush pending_flows for an interface
- fdb.c: flush stale pending flows on migration; defer FDB deletion
- nl.c: schedule deferred FDB delete on neighbor removal

Signed-off-by: Daniel Pawlik <pawlik.dan@gmail.com>
@danpawlik

Copy link
Copy Markdown
Author

@nbd168 hey, if the PR is useless, just close it. Thanks

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant