Repository navigation
Conversation
Address-only static mappings are stored with port 0 and protocol 0 (nat44_ed_add_static_mapping), but three lookups used the packet's protocol and never matched them: - nat44_ed_get_out2in_worker_index fell back to the worker chosen by destination port, so every new inbound flow to a given port was handed to the same worker; - nat44_ed_out2in_slowpath_unknown_proto dropped packets of other IP protocols to an address-only mapping as "no translation"; - the in2out slow path for other IP protocols missed the mapping and fell back to dynamic translation. Look them up with protocol 0, as nat44_ed_external_sm_lookup already does for address-only mappings. Type: fix Signed-off-by: Andrey Vasilevsky <anvanster@gmail.com>
|
This GitHub mirror does not accept pull requests. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes #3743
What
Address-only static mappings are stored with port 0 and protocol 0
(
nat44_ed_add_static_mapping), but three lookups used the packet's protocoland never matched them:
nat44_ed_get_out2in_worker_indexfell back to the worker chosen bydestination port, so every new inbound flow to a given port was handed to
the same worker;
nat44_ed_out2in_slowpath_unknown_protodropped packets of other IPprotocols to an address-only mapping as "no translation";
back to dynamic translation.
All three now look the mapping up with protocol 0, as
nat44_ed_external_sm_lookupalready does for address-only mappings. Portmappings are unaffected: they are still looked up with the packet's protocol
and port in the second lookup of the worker selection, and they cannot apply
to other IP protocols.
Testing
On VPP 26.06 (the same change applies cleanly to master
025b64cdbe), 4workers, with the reproduction script from the issue (veth pairs and
namespaces; 4 VRFs, each with
nat44 add static mapping local 172.16.0.2 external 10.20.0.$i vrf $i):no translationAlso with Firecracker VMs behind af_packet inside interfaces: 24/24 TCP
transfers of 200 KB through the mappings, sessions spread 6/6/6/6.
make teston this branch (release build,EXTENDED_TESTS=1so themulti-worker class
TestNAT44EDMWruns too):test_nat44_ed85/85 passed,test_nat44_ed_output1/1 passed.