public inbox for pve-devel@lists.proxmox.com
 help / color / mirror / Atom feed
* [PATCH pve-network] sdn: zones: vxlan: restore the flood entries after an FRR reload
@ 2026-09-29  9:28 Hannes Laimer
  0 siblings, 0 replies; only message in thread
From: Hannes Laimer @ 2026-09-29  9:28 UTC (permalink / raw)
  To: pve-devel

With advertise-all-vni, which an EVPN controller sets even without an
EVPN zone, FRR treats every vxlan device on a node as an EVPN VNI.
That includes the devices of a VXLAN zone, for which the other nodes
running FRR become remote VTEPs.

When the controller is removed, FRR drops its VNIs and deletes the
flood entries of their remote VTEPs. The kernel identifies such an
entry by its address and not by who added it, so the zone's static
flood entries to those nodes are deleted. The zone can no longer
flood, so nothing resolves across nodes, and no reload repairs it,
since ifupdown2 re-applies the peer list only when the configured list
changed.

Re-append the entries after every FRR apply. The kernel treats an
existing remote as a no-op, so the entries are simply added where
missing.

Signed-off-by: Hannes Laimer <h.laimer@proxmox.com>
---
 src/PVE/Network/SDN.pm       |  7 ++++++-
 src/PVE/Network/SDN/Zones.pm | 18 ++++++++++++++++++
 2 files changed, 24 insertions(+), 1 deletion(-)

diff --git a/src/PVE/Network/SDN.pm b/src/PVE/Network/SDN.pm
index 33a3cf3..42af00d 100644
--- a/src/PVE/Network/SDN.pm
+++ b/src/PVE/Network/SDN.pm
@@ -492,7 +492,12 @@ sub generate_frr_config {
     my $raw_config = PVE::Network::SDN::generate_frr_raw_config($running_config, $fabric_config);
     PVE::Network::SDN::Frr::write_raw_config($raw_config);
 
-    PVE::Network::SDN::Frr::apply($needs_restart) if $apply;
+    return if !$apply;
+
+    PVE::Network::SDN::Frr::apply($needs_restart);
+
+    # zebra removes a VXLAN zone's static flood entries with the VTEPs it withdraws
+    PVE::Network::SDN::Zones::restore_vxlan_flood_entries();
 }
 
 sub generate_dhcp_config {
diff --git a/src/PVE/Network/SDN/Zones.pm b/src/PVE/Network/SDN/Zones.pm
index f668303..2c3c69c 100644
--- a/src/PVE/Network/SDN/Zones.pm
+++ b/src/PVE/Network/SDN/Zones.pm
@@ -178,6 +178,24 @@ sub generate_etc_network_config {
     return $raw_network_config;
 }
 
+sub restore_vxlan_flood_entries {
+    my $raw_config = eval { PVE::Tools::file_get_contents($local_network_sdn_file) };
+    return if !defined($raw_config);
+
+    my $iface;
+    for my $line (split(/\n/, $raw_config)) {
+        if ($line =~ m/^iface (\S+)$/) {
+            $iface = $1;
+        } elsif ($line =~ m/^\s+vxlan_remoteip (\S+)$/) {
+            my $address = $1;
+            my $cmd =
+                ['bridge', 'fdb', 'append', '00:00:00:00:00:00', 'dev', $iface, 'dst', $address];
+            eval { run_command($cmd) };
+            warn "$iface: restoring the flood entry to $address failed: $@" if $@;
+        }
+    }
+}
+
 sub read_etc_network_config_version {
     my $versionstr = PVE::Tools::file_read_firstline($local_network_sdn_file);
 
-- 
2.47.3





^ permalink raw reply related	[flat|nested] only message in thread

only message in thread, other threads:[~2026-09-29  9:28 UTC | newest]

Thread overview: (only message) (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-29  9:28 [PATCH pve-network] sdn: zones: vxlan: restore the flood entries after an FRR reload Hannes Laimer

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
Service provided by Proxmox Server Solutions GmbH | Privacy | Legal