Support for sonic-mgmt ACL testing on VPP#1599
Merged
yue-fred-gao merged 6 commits intosonic-net:masterfrom Dec 9, 2025
Merged
Support for sonic-mgmt ACL testing on VPP#1599yue-fred-gao merged 6 commits intosonic-net:masterfrom
yue-fred-gao merged 6 commits intosonic-net:masterfrom
Conversation
Collaborator
|
/azp run |
|
Azure Pipelines successfully started running 1 pipeline(s). |
This was referenced May 12, 2025
Collaborator
|
/azp run |
|
Azure Pipelines successfully started running 1 pipeline(s). |
kcudnik
approved these changes
Jun 12, 2025
Collaborator
|
there are no unittests for this code |
Collaborator
|
/azp run |
|
Azure Pipelines successfully started running 1 pipeline(s). |
Collaborator
|
/azp run |
|
Azure Pipelines successfully started running 1 pipeline(s). |
Contributor
|
/azpw run |
Collaborator
|
/AzurePipelines run |
|
Azure Pipelines successfully started running 1 pipeline(s). |
Contributor
|
/azpw run Azure.sonic-sairedis (BuildAsan amd64) |
Collaborator
|
/AzurePipelines run Azure.sonic-sairedis (BuildAsan amd64) |
|
No pipelines are associated with this pull request. |
Collaborator
|
/azp run |
|
Azure Pipelines successfully started running 1 pipeline(s). |
vikram-nexthop
pushed a commit
to nexthop-ai/sonic-sairedis
that referenced
this pull request
Dec 12, 2025
* Enabling sonic-mgmt ACL testing for Sonic-VPP * Use retval in debugs Signed-off-by: Vikram Menon <vikram@nexthop.ai>
croos12
pushed a commit
to croos12/sonic-sairedis
that referenced
this pull request
Dec 14, 2025
* Enabling sonic-mgmt ACL testing for Sonic-VPP * Use retval in debugs
croos12
pushed a commit
to croos12/sonic-sairedis
that referenced
this pull request
Jan 14, 2026
* Enabling sonic-mgmt ACL testing for Sonic-VPP * Use retval in debugs
yue-fred-gao
pushed a commit
to yue-fred-gao/sonic-sairedis
that referenced
this pull request
Mar 3, 2026
* Enabling sonic-mgmt ACL testing for Sonic-VPP * Use retval in debugs
yue-fred-gao
pushed a commit
that referenced
this pull request
Mar 3, 2026
* Enabling sonic-mgmt ACL testing for Sonic-VPP * Use retval in debugs Signed-off-by: Yue Gao <yuega2@cisco.com>
vmittal-msft
pushed a commit
that referenced
this pull request
Mar 9, 2026
* Support for sonic-mgmt ACL testing on VPP (#1599) * Enabling sonic-mgmt ACL testing for Sonic-VPP * Use retval in debugs * Graceful shutdown vpp to avoid core dump (#1714) Signed-off-by: Yue Gao <yuega2@cisco.com> * vpp: support ACL attached to LAG and UDP in ACE (#1718) * Handle acl attachment through LAG update * Add default permit-all rules * Support ACL with UDP protocol * if protocol is not specified but port or port-range is create 2 rules with proto UDP and TCP. vpp requires proto to be set if port or port-range is used * realign ace stats index because each ace can map to multiple acl rules Signed-off-by: Yue Gao <yuega2@cisco.com> * vpp: support binding multiple ACL tables by priority (#1732) why currently vpp doesn't support binding multiple ACL tables. Each table is appended with default permit-all rules. With multiple tables, this may cause acl matched by such rules and skip the actual rule to make in the tables after this one. what this PR does remove the default permit-all rules for each table If a table is empty, create a dummy rule that won't match any traffic because vpp doesn't allow empty table. The dummy rule matches dest-ip to 0.0.0.0/32 sort all the tables by priority in the table group. vpp doesn't support parallel matching added catch-all acl group to the end. vpp default behavior of no match is drop but sonic is accept. Fix sonic-vpp crashing due to race condition during stats pull. If the interface to get stats has been removed, stat_segment_ls_r returns null. Signed-off-by: Yue Gao <yuega2@cisco.com> * changes for vpp release 202510 --------- Signed-off-by: Yue Gao <yuega2@cisco.com> Co-authored-by: AkeelAli <701916+AkeelAli@users.noreply.github.com> Co-authored-by: Mihut Aronovici <aronovic@cisco.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Changes in VPP's SAI ACL code to successfully run sonic-mgmt ACL testing on Sonic-VPP.
Related PRs:
Sonic-mgmt changes: sonic-net/sonic-mgmt#18313
Sonic-VPP changes: sonic-net/sonic-platform-vpp#178