From: Jakub Slepecki <jakub.slepecki@intel.com>
To: "Loktionov, Aleksandr" <aleksandr.loktionov@intel.com>,
"intel-wired-lan@lists.osuosl.org"
<intel-wired-lan@lists.osuosl.org>
Cc: "linux-kernel@vger.kernel.org" <linux-kernel@vger.kernel.org>,
"netdev@vger.kernel.org" <netdev@vger.kernel.org>,
"Kitszel, Przemyslaw" <przemyslaw.kitszel@intel.com>,
"Nguyen, Anthony L" <anthony.l.nguyen@intel.com>,
"michal.swiatkowski@linux.intel.com"
<michal.swiatkowski@linux.intel.com>
Subject: Re: [PATCH iwl-next v2 5/8] ice: update mac,vlan rules when toggling between VEB and VEPA
Date: Fri, 28 Nov 2025 13:28:39 +0100 [thread overview]
Message-ID: <12bcee25-7ec4-418e-b8c7-60642d8073c0@intel.com> (raw)
In-Reply-To: <IA3PR11MB898691972766E6929CFDF934E5DCA@IA3PR11MB8986.namprd11.prod.outlook.com>
On 2025-11-28 9:36, Loktionov, Aleksandr wrote:
> One small suggestion: please include prerequisites in the 0/8 cover letter (e.g., `iproute2` version and that commands need root privileges), so testers don’t miss that.
Roger that; I plan to use following:
---
To reproduce the issue have a E810 ($pfa) connected to another adapter
($pfb), then:
# echo 2 >/sys/class/net/$pfa/device/sriov_numvfs
# ip l set $pfa vf 0 vlan 4
# ip l set $pfa vf 1 vlan 7
# ip l set $pfa_vf0 netns $pfa_vf0_netns up
# ip l set $pfa_vf1 netns $pfa_vf1_netns up
# ip netns exec $pfa_vf0_netns ip a add 10.0.0.1/24 dev $pfa_vf0
# ip netns exec $pfa_vf1_netns ip a add 10.0.0.2/24 dev $pfa_vf1
And for the $pfb:
# echo 2 >/sys/class/net/$pfb/device/sriov_numvfs
# ip l set $pfb vf 0 trust on spoof off vlan 4
# ip l set $pfb vf 1 trust on spoof off vlan 7
# ip l add $br type bridge
# ip l set $pfb_vf0 master $br up
# ip l set $pfb_vf1 master $br up
# ip l set $br up
We expect $pfa_vf0 to be able to reach $pfa_vf1 through the $br on
the link partner. Instead, ARP is unable to resolve 10.0.0.2/24.
ARP request is fine because it's broadcasted and bounces off $br, but
ARP reply is stuck in the internal switch because the destination MAC
matches $pfa_vf0 and filter restricts it to loopback.
In testing I used: ip utility, iproute2-6.1.0, libbpf 1.3.0
---
> Otherwise, the instructions are fine from my side. Please keep my:
>
> Reviewed-by: Aleksandr Loktionov <aleksandr.loktionov@intel.com>
>
> Thanks!
Thanks!
next prev parent reply other threads:[~2025-11-28 12:28 UTC|newest]
Thread overview: 18+ messages / expand[flat|nested] mbox.gz Atom feed top
2025-11-25 8:34 [PATCH iwl-next v2 0/8] ice: in VEB, prevent "cross-vlan" traffic Jakub Slepecki
2025-11-25 8:34 ` [PATCH iwl-next v2 1/8] ice: in dvm, use outer VLAN in MAC,VLAN lookup Jakub Slepecki
2025-11-25 8:34 ` [PATCH iwl-next v2 2/8] ice: allow creating mac,vlan filters along mac filters Jakub Slepecki
2025-11-25 8:34 ` [PATCH iwl-next v2 3/8] ice: do not check for zero mac when creating " Jakub Slepecki
2025-11-25 8:34 ` [PATCH iwl-next v2 4/8] ice: allow overriding lan_en, lb_en in switch Jakub Slepecki
2025-11-25 8:59 ` Loktionov, Aleksandr
2025-11-28 11:55 ` Jakub Slepecki
2025-12-01 7:37 ` Loktionov, Aleksandr
2025-12-02 13:54 ` Jakub Slepecki
2025-11-25 8:34 ` [PATCH iwl-next v2 5/8] ice: update mac,vlan rules when toggling between VEB and VEPA Jakub Slepecki
2025-11-25 8:52 ` Loktionov, Aleksandr
2025-11-28 8:29 ` Jakub Slepecki
2025-11-28 8:36 ` Loktionov, Aleksandr
2025-11-28 12:28 ` Jakub Slepecki [this message]
2025-12-01 7:41 ` Loktionov, Aleksandr
2025-11-25 8:34 ` [PATCH iwl-next v2 6/8] ice: add functions to query for vsi's pvids Jakub Slepecki
2025-11-25 8:34 ` [PATCH iwl-next v2 7/8] ice: add mac vlan to filter API Jakub Slepecki
2025-11-25 8:34 ` [PATCH iwl-next v2 8/8] ice: in VEB, prevent "cross-vlan" traffic from hitting loopback Jakub Slepecki
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=12bcee25-7ec4-418e-b8c7-60642d8073c0@intel.com \
--to=jakub.slepecki@intel.com \
--cc=aleksandr.loktionov@intel.com \
--cc=anthony.l.nguyen@intel.com \
--cc=intel-wired-lan@lists.osuosl.org \
--cc=linux-kernel@vger.kernel.org \
--cc=michal.swiatkowski@linux.intel.com \
--cc=netdev@vger.kernel.org \
--cc=przemyslaw.kitszel@intel.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox