On 10/7/26 10:38 AM, Eelco Chaudron wrote:
>
>
> On 3 Oct 2026, at 2:22, Ilya Maximets via dev wrote:
>
>> With the recent commit on net-next the ct zone filtering is now
>> discoverable in the kernel:
>> 46da6029bf46 ("netfilter: conntrack: make filtering by zone discoverable")
>>
>> This means we no longer need to rely on the kernel version parsing,
>> which may produce false negative results, especially with distribution
>> kernels. And we'll be able to remove it at some point in the future.
>>
>> Instead, we can probe the feature directly using the CTA_FILTER_ZONE
>> attribute. Kernels that support CTA_FILTER, but not the
>> CTA_FILTER_ZONE will fail the request. Kernels that do not support
>> CTA_FILTER will not report NLM_F_DUMP_FILTERED in the reply.
>> So, a successful GET request with NLM_F_DUMP_FILTERED flag set in the
>> reply guarantees that kernel understands CTA_FILTER_ZONE and hence
>> supports filtering by zone in both GET and DELETE requests.
>>
>> Using the zone 60000 for probing as it is not a default zone and high
>> enough for OVN to not actually use it, so it is unlikely to contain a
>> lot of entries for the dump. In the worst case, if the filtering is
>> not supported we'll dump the entire table twice on this one request.
>> Later requests will only dump once as before.
>>
>> Kernel version parsing is preserved as a fallback for upstream kernels
>> between 6.8 and 7.2.
>>
>> The kernel-level filtering is important for OVN deployments, as OVN
>> allocates separate zones per port and requests to flush them on port
>> additions and removals. On systems with large conntrack tables this
>> may take seconds if filtering is done in user space.
>>
>> Providing CTA_FILTER_ZONE for the actual deletion requests is not
>> necessary as the kernel allows requests without it for backwards
>> compatibility. But it is cleaner if we do.
>>
>> Signed-off-by: Ilya Maximets <[email protected]>
>
> Thanks for the patch Ilya. Did some basic testing, and a full review.
> And it all looks good to me!
>
> Acked-by: Eelco Chaudron <[email protected]>
Thanks, Eelco! Applied to main.
Will backport down to 3.7 once the kernel change hits the mainline,
so we don't have false-negative feature detections on LTS.
Best regards, Ilya Maximets.
_______________________________________________
dev mailing list
[email protected]
https://mail.openvswitch.org/mailman/listinfo/ovs-dev