> On 23 Jul 2026, at 2:45 PM, Ales Musil <[email protected]> wrote:
> 
> CAUTION: External Email
> 
> 
> On Tue, Jul 21, 2026 at 9:04 AM Aditya Mehakare <[email protected]> 
> wrote:
> Add "ovn-debug lflow-pipeline-oftable-start-list" to print the starting
> OpenFlow table numbers of the ingress and egress logical pipelines.
> 
> This lets external consumers that read OpenFlow table statistics safely
> compute the actual OpenFlow table of a logical flow (pipeline base +
> logical flow table number) during upgrades, avoiding reliance on
> lflow-stage-to-ltable, which can be inaccurate when ovn-controller and
> ovn-northd run different versions.
> 
> Assisted-by: Cursor, with model: claude-4.8-opus-high
> Signed-off-by: Aditya Mehakare <[email protected]>
> Acked-by: Naveen Yerramneni <[email protected]>
> ---
> 
> Hi Aditya,

Hi Ales,
Thank you for the review.

> 
> I'm slightly confused by this patch, you might still get wrong
> result during the upgrade if you don't use the right ovn-debug
> version. Also running "flow-stage-to-oftable ls_in_check_port_sec"
> or "flow-stage-to-oftable ls_out_lookup_fdb" will give you the
> number you are looking for. I don't think we need to add extra
> command for that.

You're right that lflow-stage-to-oftable ls_in_check_port_sec /
ls_out_lookup_fdb returns the pipeline start today, since those
stages are currently table 0. The reason for a dedicated command
is to avoid depending on that.

The external consumer computes:
  oftable = pipeline_base + Logical_Flow.table_id

It reads table_id per flow from the SB DB, so it always matches
the running ovn-northd. However, getting pipeline_base via
lflow-stage-to-oftable <stage> forces the caller to hard-code a
stage that is table 0 in the installed ovn-debug version.

That breaks during a rolling upgrade. The OVN RPMs are updated
on all hosts first, upgrading ovn-controller and ovn-debug. The
ovn-northd is upgraded only afterwards. If a release adds a new first
ingress stage and shifts ls_in_check_port_sec to table 1, then on an
upgraded host "lflow-stage-to-oftable ls_in_check_port_sec” returns
base + 1, while the still-old ovn-northd emits that flow with table_id = 0
(installed at base + 0). The consumer therefore reads the wrong table
until ovn-northd is upgraded.

This new command reports the base directly, independent of stage
names, so the consumer can safely consume it.


Regards,
Aditya


> 
> 
>  NEWS                      |  3 +++
>  tests/ovn-util.at [ovn-util.at]         |  7 +++++++
>  utilities/ovn-debug.8.xml |  5 +++++
>  utilities/ovn-debug.c     | 12 ++++++++++++
>  4 files changed, 27 insertions(+)
> 
> diff --git a/NEWS b/NEWS
> index 384e30820..bb6129189 100644
> --- a/NEWS
> +++ b/NEWS
> @@ -1,5 +1,8 @@
>  Post v26.03.0
>  -------------
> +   - Added a new "ovn-debug lflow-pipeline-oftable-start-list" command that
> +     prints the starting OpenFlow table number of the logical ingress and
> +     egress pipelines.
>     - Load balancer health checks now "fail closed" for newly added backends:
>       ovn-northd initializes a newly created Service_Monitor row to the
>       "offline" state, so traffic is not forwarded to a backend until its 
> first
> diff --git a/tests/ovn-util.at [ovn-util.at] b/tests/ovn-util.at [ovn-util.at]
> index 76bb568e7..315539342 100644
> --- a/tests/ovn-util.at [ovn-util.at]
> +++ b/tests/ovn-util.at [ovn-util.at]
> @@ -106,3 +106,10 @@ cookie=$egress, priority=0,metadata=0x1 
> actions=resubmit(,??)
>  OVN_CLEANUP([hv1])
> 
>  AT_CLEANUP
> +
> +AT_SETUP([ovn-debug - lflow-pipeline-oftable-start-list])
> +AT_CHECK([ovn-debug lflow-pipeline-oftable-start-list], [0], [dnl
> +ingress OFTABLE_LOG_INGRESS_PIPELINE
> +egress OFTABLE_LOG_EGRESS_PIPELINE
> +])
> +AT_CLEANUP
> diff --git a/utilities/ovn-debug.8.xml b/utilities/ovn-debug.8.xml
> index bdd208328..ffb9baf3d 100644
> --- a/utilities/ovn-debug.8.xml
> +++ b/utilities/ovn-debug.8.xml
> @@ -24,5 +24,10 @@
>              Convert the logical flow stage name e.g. <code>ls_in_lb</code> 
> into
>              the OpenFlow table number e.g. <code>21</code>.
>          </dd>
> +        <dt><code>lflow-pipeline-oftable-start-list</code></dt>
> +        <dd>
> +            Print the starting OpenFlow table number of the
> +            <code>ingress</code> and <code>egress</code> pipelines.
> +        </dd>
>      </dl>
>  </manpage>
> diff --git a/utilities/ovn-debug.c b/utilities/ovn-debug.c
> index 0a0d2202b..a238cc2d6 100644
> --- a/utilities/ovn-debug.c
> +++ b/utilities/ovn-debug.c
> @@ -76,6 +76,14 @@ lflow_stage_to_table(struct ovs_cmdl_context *ctx)
>      exit(EXIT_SUCCESS);
>  }
> 
> +static void
> +lflow_pipeline_oftable_start_list(struct ovs_cmdl_context *ctx OVS_UNUSED)
> +{
> +    printf("ingress %"PRIu8"\n", (uint8_t) OFTABLE_LOG_INGRESS_PIPELINE);
> +    printf("egress %"PRIu8"\n", (uint8_t) OFTABLE_LOG_EGRESS_PIPELINE);
> +    exit(EXIT_SUCCESS);
> +}
> +
>  static void
>  uuid_to_cookie_str(struct ovs_cmdl_context *ctx)
>  {
> @@ -102,6 +110,8 @@ lflow-stage-to-ltable STAGE_NAME\n\
>    Converts STAGE_NAME into logical flow table number.\n\
>  lflow-stage-to-oftable STAGE_NAME\n\
>    Converts STAGE_NAME into OpenFlow table number.\n\
> +lflow-pipeline-oftable-start-list\n\
> +  Prints the starting OpenFlow table number of the logical pipelines.\n\
>  uuid-to-cookie UUID\n\
>    Converts UUID into cookie format.\n\
>  \n\
> @@ -161,6 +171,8 @@ main(int argc, char *argv[])
>               OVS_RO},
>              {"lflow-stage-to-ltable", NULL, 1, 1, lflow_stage_to_table,
>               OVS_RO},
> +            {"lflow-pipeline-oftable-start-list", NULL, 0, 0,
> +             lflow_pipeline_oftable_start_list, OVS_RO},
>              {"uuid-to-cookie", NULL, 1, 1, uuid_to_cookie_str,
>               OVS_RO},
>              { "help", NULL, 0, INT_MAX, help, OVS_RO },
> -- 
> 2.43.5
> 
> _______________________________________________
> dev mailing list
> [email protected]
> https://mail.openvswitch.org/mailman/listinfo/ovs-dev [mail.openvswitch.org]
> 
> 
> Thanks,
> Ales 


_______________________________________________
dev mailing list
[email protected]
https://mail.openvswitch.org/mailman/listinfo/ovs-dev

Reply via email to