A flowtable flow that transmits straight to a bridge port keeps sending to the old port when the host moves to another port, for example a Wi-Fi station roaming between access points. Patch 1 makes the flowtable gc tear such a flow down. Patch 2 adds selftest cases.
v5 tore flows down on the switchdev fdb delete notification, which the bridge does not send for every move and not at all without CONFIG_NET_SWITCHDEV. v6 checks the path in the gc, as for a stale dst, after Florian's review of v4. Eric Woudstra wrote v1 to v4. Tested on an ipq807x router (OpenWrt, 6.18 backport, out-of-tree PPE driver), three runs: without patch 1 a roaming station's download did not resume within the 29 s observed; with it the longest gap was 1.1 s. Without patch 1 the four selftest cases where the host moves fail; all six pass with it, also with CONFIG_NET_SWITCHDEV=n. Changes in v6: - check the path in the gc instead of using switchdev notifications - leave the flow alone when its fdb entry ages out - drop the v5 patch that stored the bridge vid; nothing reads it - selftest: more cases, including fdb ageing and IPv6 v5: https://lore.kernel.org/netfilter-devel/[email protected]/ v4: https://lore.kernel.org/netfilter-devel/[email protected]/ Julius Bairaktaris (2): netfilter: flowtable: tear down direct xmit flows when the fdb entry moves selftests: netfilter: nft_flowtable.sh: roam a host between two bridge ports include/net/netfilter/nf_flow_table.h | 4 + net/netfilter/nf_flow_table_core.c | 44 ++++ net/netfilter/nf_flow_table_path.c | 7 + .../selftests/net/netfilter/nft_flowtable.sh | 201 ++++++++++++++++++ 4 files changed, 256 insertions(+) base-commit: 87b80c2f6b05cad9f0ff9136709c62a0f59923e3 -- 2.53.0

