public inbox for pve-devel@lists.proxmox.com
 help / color / mirror / Atom feed
From: Hannes Laimer <h.laimer@proxmox.com>
To: Lukas Sichert <l.sichert@proxmox.com>
Cc: pve-devel@lists.proxmox.com
Subject: Re: [PATCH docs/manager/network/perl-rs v4 0/6] sdn: enable force_forwarding for ipv6 forwarding
Date: Mon, 24 Aug 2026 09:33:17 +0200	[thread overview]
Message-ID: <aovyl-alOe35QR7X@nana.intra.proxmox.com> (raw)
In-Reply-To: <20260727135509.14588-1-l.sichert@proxmox.com>

Generally this works well, and is a very solid improvment over what we
currently have. Aside from the comments on the patches, it looks like
some tests need updating :P

```
	modified:   src/test/zones/evpn/bgp_fabric/expected_sdn_interfaces
	modified:   src/test/zones/evpn/openfabric_fabric_ipv6/expected_sdn_interfaces
	modified:   src/test/zones/evpn/openfabric_fabric_ipv6_only/expected_sdn_interfaces
```

On 2026-07-27 15:55, Lukas Sichert wrote:
> Gabriel's upstream kernel patch [1] added
> net.ipv6.conf.<iface>.force_forwarding. This allows enabling IPv6
> forwarding on selected interfaces without requiring
> net.ipv6.conf.all.forwarding.
> 
> This is useful for SDN setups because all.forwarding has host-wide side
> effects. In particular, it disables Router Advertisement processing by
> default, which can break SLAAC on unrelated interfaces. SDN only needs
> forwarding on the VNet, exit-node, or fabric interfaces that participate
> in routed IPv6 traffic.
> 
> This series generates ifupdown post-up/post-down commands for those
> interfaces so force_forwarding is enabled when the interface is brought
> up and reset when it is brought down. /network/interfaces.d/sdn gets
> regenerated on SDN Apply. This means that removing a VNet also removes
> the corresponding 'post-down' commands configured to the interface of
> the VNet. Therefore it cannot happen, that deleting one VNet in the GUI
> removes force_forwarding on the outgoing interfaces, which might be used
> by other VNets as well. The tests are adjusted for the generated
> /etc/network/interfaces.d/sdn output. Also the series rewrites the
> documentation to reflect the updated behaviour and removes the UI warning
> to enable 'all.forwarding'.
> 
> 
> [1] lkml.org/lkml/2025/7/7/577
> 
> changes from v3 to v4 (thanks @Stefan):
> -wrap resolving outgoing interface in eval block
> -remove unnecessary 'ip6-forward' for vrfbr interface
> -Drop the fabric edit GUI hint that told users to enable
> net.ipv6.conf.all.forwarding
> -remove whitespace formatting changes
> 
> changes from v2 to v3 (thanks @Gabriel):
> -Move the IPv6 force_forwarding post-up/post-down commands out of the
> subnet loop, so they are generated only once for the VNet instead of
> once per subnet.
> -Enable ip6-forward and force_forwarding on EVPN L3VNI VRF bridge
> interfaces, fixing IPv6 forwarding when traffic exits through another
> node.
> 
> changes from v1 to v2 (thanks @Gabriel, @Hannes):
> -add force_forwarding also to bgp fabrics
> -explicitly mention the force_forwarding flag in the documentation
> -add a reference link to the sysctl documentation
> -mention bgp as a fabric with ipv6 support
> 
> 
> network:
> 
> Lukas Sichert (2):
>   sdn: evpn: enable force_forwarding for ipv6 forwarding to subnets
>   sdn: simple: enable force_forwarding for ipv6 forwarding to subnets
> 
>  src/PVE/Network/SDN/Zones/EvpnPlugin.pm       | 34 ++++++++++++++++++-
>  src/PVE/Network/SDN/Zones/SimplePlugin.pm     | 25 +++++++++++++-
>  .../expected_sdn_interfaces                   |  6 ++++
>  .../exitnode_snat/expected_sdn_interfaces     |  4 +++
>  .../exitnodenullroute/expected_sdn_interfaces |  6 ++++
>  .../evpn/ipv4ipv6/expected_sdn_interfaces     |  4 +++
>  .../zones/evpn/ipv6/expected_sdn_interfaces   |  4 +++
>  .../evpn/ipv6underlay/expected_sdn_interfaces |  4 +++
>  .../simple/ipv4v6/expected_sdn_interfaces     |  4 +++
>  .../simple/ipv6snat/expected_sdn_interfaces   |  4 +++
>  10 files changed, 93 insertions(+), 2 deletions(-)
> 
> 
> perl-rs:
> 
> Lukas Sichert (2):
>   fabrics: openfabric: enable force_forwarding for ipv6 transit traffic
>   fabrics: bgp: enable force_forwarding for ipv6 transit traffic
> 
>  pve-rs/src/bindings/sdn/fabrics.rs | 18 ++++++++++++++++++
>  1 file changed, 18 insertions(+)
> 
> 
> manager:
> 
> Lukas Sichert (1):
>   ui: sdn: remove IPv6 forwarding hint from fabric edit window
> 
>  www/manager6/sdn/fabrics/FabricEdit.js | 59 +++++++++-----------------
>  1 file changed, 20 insertions(+), 39 deletions(-)
> 
> 
> docs:
> 
> Lukas Sichert (1):
>   sdn: drop global ipv6 forwarding workaround from OpenFabric docs
> 
>  pvesdn.adoc | 21 +++++----------------
>  1 file changed, 5 insertions(+), 16 deletions(-)
> 
> 
> Summary over all repositories:
>   13 files changed, 136 insertions(+), 57 deletions(-)
> 
> -- 
> Generated by murpp 0.12.0
> 
> 
> 
> 




      parent reply	other threads:[~2026-08-24  7:33 UTC|newest]

Thread overview: 10+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-07-27 13:55 [PATCH docs/manager/network/perl-rs v4 0/6] sdn: enable force_forwarding for ipv6 forwarding Lukas Sichert
2026-07-27 13:55 ` [PATCH network v4 1/6] sdn: evpn: enable force_forwarding for ipv6 forwarding to subnets Lukas Sichert
2026-08-24  7:23   ` Hannes Laimer
2026-07-27 13:55 ` [PATCH network v4 2/6] sdn: simple: " Lukas Sichert
2026-07-27 13:55 ` [PATCH perl-rs v4 3/6] fabrics: openfabric: enable force_forwarding for ipv6 transit traffic Lukas Sichert
2026-08-24  7:27   ` Hannes Laimer
2026-07-27 13:55 ` [PATCH perl-rs v4 4/6] fabrics: bgp: " Lukas Sichert
2026-07-27 13:55 ` [PATCH manager v4 5/6] ui: sdn: remove IPv6 forwarding hint from fabric edit window Lukas Sichert
2026-07-27 13:55 ` [PATCH docs v4 6/6] sdn: drop global ipv6 forwarding workaround from OpenFabric docs Lukas Sichert
2026-08-24  7:33 ` Hannes Laimer [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=aovyl-alOe35QR7X@nana.intra.proxmox.com \
    --to=h.laimer@proxmox.com \
    --cc=l.sichert@proxmox.com \
    --cc=pve-devel@lists.proxmox.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
Service provided by Proxmox Server Solutions GmbH | Privacy | Legal