All of lore.kernel.org
 help / color / mirror / Atom feed
* "AVX2-based lookup implementation" has broken ebtables --among-src
@ 2021-11-16  8:51 Nikita Yushchenko
  2021-11-16 16:33 ` Stefano Brivio
  0 siblings, 1 reply; 7+ messages in thread
From: Nikita Yushchenko @ 2021-11-16  8:51 UTC (permalink / raw)
  To: Stefano Brivio; +Cc: Netdev

Hello Stefano.

I've found that nftables rule added by

# ebtables -A INPUT --among-src 8:0:27:40:f7:9=192.168.56.10 -j log

does not match packets on kernel 5.14 and on current mainline.
Although it matched correctly on kernel 4.18

I've bisected this issue. It was introduced by your commit 7400b063969b ("nft_set_pipapo: Introduce 
AVX2-based lookup implementation") from 5.7 development cycle.

The nftables rule created by the above command uses concatenation:

# nft list chain bridge filter INPUT
table bridge filter {
         chain INPUT {
                 type filter hook input priority filter; policy accept;
                 ether saddr . ip saddr { 08:00:27:40:f7:09 . 192.168.56.10 } counter packets 0 bytes 0 
log level notice flags ether
         }
}

Looks like the AVX2-based lookup does not process this correctly.


Nikita

^ permalink raw reply	[flat|nested] 7+ messages in thread

end of thread, other threads:[~2021-11-24 17:38 UTC | newest]

Thread overview: 7+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2021-11-16  8:51 "AVX2-based lookup implementation" has broken ebtables --among-src Nikita Yushchenko
2021-11-16 16:33 ` Stefano Brivio
2021-11-17 12:06   ` Florian Westphal
2021-11-17 12:08     ` Nikita Yushchenko
2021-11-22 13:29       ` Stefano Brivio
2021-11-24 17:38         ` Stefano Brivio
2021-11-17 13:12     ` Florian Westphal

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.