Skip to content

nat: look up address-only static mappings with protocol 0 - #3744

Closed
anvanster wants to merge 1 commit into
FDio:masterfrom
anvanster:nat44-ed-addr-only-proto0
Closed

anvanster wants to merge 1 commit into
FDio:masterfrom
anvanster:nat44-ed-addr-only-proto0

Conversation

@anvanster

Copy link
Copy Markdown

Fixes #3743

What

Address-only static mappings are stored with port 0 and protocol 0
(nat44_ed_add_static_mapping), but three lookups used the packet's protocol
and never matched them:

  • nat44_ed_get_out2in_worker_index fell back to the worker chosen by
    destination port, so every new inbound flow to a given port was handed to
    the same worker;
  • nat44_ed_out2in_slowpath_unknown_proto dropped packets of other IP
    protocols to an address-only mapping as "no translation";
  • the in2out slow path for other IP protocols missed the mapping and fell
    back to dynamic translation.

All three now look the mapping up with protocol 0, as
nat44_ed_external_sm_lookup already does for address-only mappings. Port
mappings are unaffected: they are still looked up with the packet's protocol
and port in the second lookup of the worker selection, and they cannot apply
to other IP protocols.

Testing

On VPP 26.06 (the same change applies cleanly to master 025b64cdbe), 4
workers, with the reproduction script from the issue (veth pairs and
namespaces; 4 VRFs, each with nat44 add static mapping local 172.16.0.2 external 10.20.0.$i vrf $i):

before after
200 new UDP flows to the 4 external addresses, sessions per worker 200 / 0 / 0 / 0 50 / 50 / 50 / 50
20 inbound IP protocol 253 packets to 10.20.0.1 0 delivered, 20 no translation 20 delivered
20 outbound IP protocol 253 packets from 172.16.0.2, VRF 1 0 received 20 received, source 10.20.0.1

Also with Firecracker VMs behind af_packet inside interfaces: 24/24 TCP
transfers of 200 KB through the mappings, sessions spread 6/6/6/6.

make test on this branch (release build, EXTENDED_TESTS=1 so the
multi-worker class TestNAT44EDMW runs too): test_nat44_ed 85/85 passed,
test_nat44_ed_output 1/1 passed.

Address-only static mappings are stored with port 0 and protocol 0
(nat44_ed_add_static_mapping), but three lookups used the packet's
protocol and never matched them:

- nat44_ed_get_out2in_worker_index fell back to the worker chosen by
  destination port, so every new inbound flow to a given port was
  handed to the same worker;
- nat44_ed_out2in_slowpath_unknown_proto dropped packets of other IP
  protocols to an address-only mapping as "no translation";
- the in2out slow path for other IP protocols missed the mapping and
  fell back to dynamic translation.

Look them up with protocol 0, as nat44_ed_external_sm_lookup already
does for address-only mappings.

Type: fix
Signed-off-by: Andrey Vasilevsky <anvanster@gmail.com>
@github-actions

github-actions Bot commented Oct 1, 2026

Copy link
Copy Markdown

This GitHub mirror does not accept pull requests.
Please submit changes to the project's Gerrit server.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

nat44-ed: address-only static mappings looked up with the packet's protocol (all flows on one worker; other IP protocols dropped)

1 participant