On 3 Oct 2026, at 2:22, Ilya Maximets via dev wrote:
> With the recent commit on net-next the ct zone filtering is now
> discoverable in the kernel:
> 46da6029bf46 ("netfilter: conntrack: make filtering by zone discoverable")
>
> This means we no longer need to rely on the kernel version parsing,
> which may produce false negative results, especially with distribution
> kernels. And we'll be able to remove it at some point in the future.
>
> Instead, we can probe the feature directly using the CTA_FILTER_ZONE
> attribute. Kernels that support CTA_FILTER, but not the
> CTA_FILTER_ZONE will fail the request. Kernels that do not support
> CTA_FILTER will not report NLM_F_DUMP_FILTERED in the reply.
> So, a successful GET request with NLM_F_DUMP_FILTERED flag set in the
> reply guarantees that kernel understands CTA_FILTER_ZONE and hence
> supports filtering by zone in both GET and DELETE requests.
>
> Using the zone 60000 for probing as it is not a default zone and high
> enough for OVN to not actually use it, so it is unlikely to contain a
> lot of entries for the dump. In the worst case, if the filtering is
> not supported we'll dump the entire table twice on this one request.
> Later requests will only dump once as before.
>
> Kernel version parsing is preserved as a fallback for upstream kernels
> between 6.8 and 7.2.
>
> The kernel-level filtering is important for OVN deployments, as OVN
> allocates separate zones per port and requests to flush them on port
> additions and removals. On systems with large conntrack tables this
> may take seconds if filtering is done in user space.
>
> Providing CTA_FILTER_ZONE for the actual deletion requests is not
> necessary as the kernel allows requests without it for backwards
> compatibility. But it is cleaner if we do.
>
> Signed-off-by: Ilya Maximets <[email protected]>
Thanks for the patch Ilya. Did some basic testing, and a full review.
And it all looks good to me!
Acked-by: Eelco Chaudron <[email protected]>
_______________________________________________
dev mailing list
[email protected]
https://mail.openvswitch.org/mailman/listinfo/ovs-dev