Acked-by: Vladimir Medvedkin <[email protected]>

On 10/9/2026 11:59 AM, Anatoly Burakov wrote:
Currently, when parsing ntuple flows, we may hit an empty L4 protocol item
(i.e. one that does not have a mask or spec), in which case we just skip to
the end. However, we do not set a protocol mask, which means we will not
be matching L4 flows even though the flow structure implies that we should.

Fix it by setting up match-by-protocol when we have an empty L4 flow.

Additionally, there's a separate issue with how empty L4 protocol items are
handled in that once we see one, we do not check whether there's anything
else past it, and instead go straight to exit. This means that we might
have any other flow item after L4 (e.g. ipv4 / tcp / gtp) and this will be
silently accepted. Fix by enforcing that last item is END.

Fixes: 46ea969177f3 ("net/ixgbe: add ntuple support to flow parser")
Cc: [email protected]

Signed-off-by: Anatoly Burakov <[email protected]>
---
  drivers/net/intel/ixgbe/ixgbe_flow.c | 22 +++++++++++++++++++++-
  1 file changed, 21 insertions(+), 1 deletion(-)

diff --git a/drivers/net/intel/ixgbe/ixgbe_flow.c 
b/drivers/net/intel/ixgbe/ixgbe_flow.c
index 547c6621d3e..808d3b955d8 100644
--- a/drivers/net/intel/ixgbe/ixgbe_flow.c
+++ b/drivers/net/intel/ixgbe/ixgbe_flow.c
@@ -358,9 +358,28 @@ cons_parse_ntuple_filter(const struct rte_flow_attr *attr,
                return -rte_errno;
        }
+ /* an empty L4 item still implies its protocol */
        if ((item->type != RTE_FLOW_ITEM_TYPE_END) &&
                (!item->spec && !item->mask)) {
-               goto action;
+               uint8_t proto;
+
+               if (item->type == RTE_FLOW_ITEM_TYPE_TCP)
+                       proto = IPPROTO_TCP;
+               else if (item->type == RTE_FLOW_ITEM_TYPE_UDP)
+                       proto = IPPROTO_UDP;
+               else
+                       proto = IPPROTO_SCTP;
+
+               if (filter->proto_mask != 0 && filter->proto != proto) {
+                       *filter = (struct rte_eth_ntuple_filter){0};
+                       rte_flow_error_set(error, EINVAL,
+                               RTE_FLOW_ERROR_TYPE_ITEM,
+                               item, "L4 item conflicts with IPv4 protocol");
+                       return -rte_errno;
+               }
+               filter->proto = proto;
+               filter->proto_mask = UINT8_MAX;
+               goto check_end;
        }
/* get the TCP/UDP/SCTP info */
@@ -490,6 +509,7 @@ cons_parse_ntuple_filter(const struct rte_flow_attr *attr,
                goto action;
        }
+check_end:
        /* check if the next not void item is END */
        item = next_no_void_pattern(pattern, item);
        if (item->type != RTE_FLOW_ITEM_TYPE_END) {

--
Regards,
Vladimir

Reply via email to