(08) dpdk: typed flow wrappers - #1880
daniel-noland wants to merge 8 commits into
Conversation
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> Signed-off-by: Daniel Noland <daniel@githedgehog.com>
FlowRule borrows a started device and destroys the rule on drop. Domain types select ingress, egress, or transfer; FlowError classifies PMD errors. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> Signed-off-by: Daniel Noland <daniel@githedgehog.com>
Async flow destruction requires queue management rather than this Drop lifecycle. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> Signed-off-by: Daniel Noland <daniel@githedgehog.com>
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> Signed-off-by: Daniel Noland <daniel@githedgehog.com>
Track the last matched header in FlowBuilder and constrain the next match using the existing header adjacency rules. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> Signed-off-by: Daniel Noland <daniel@githedgehog.com>
Sort actions by mlx5 pipeline order, preserving order within each rank. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> Signed-off-by: Daniel Noland <daniel@githedgehog.com>
Use MODIFY_FIELD for immediate values. mlx5 VNI changes still require decap and encap; per-VNI rules can stamp the VNI into META. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> Signed-off-by: Daniel Noland <daniel@githedgehog.com>
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Signed-off-by: Daniel Noland <daniel@githedgehog.com>
|
Important Draft PR not reviewedDraft PRs are not automatically reviewed by default.
To automatically review draft PRs, update your CodeRabbit configuration: reviews:
auto_review:
drafts: true
Comment |
| if let Some(vni) = self.vni { | ||
| let v = vni.as_u32(); | ||
| let bytes = [(v >> 16) as u8, (v >> 8) as u8, v as u8]; | ||
| // Writing a union field is safe (only reads are unsafe). |
Codecov Report❌ Patch coverage is
📢 Thoughts on this report? Let us know! |
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
Flow destruction can lose live handles, mlx5 actions are reordered incorrectly, and inner VXLAN patterns cannot be constructed.
Review effort: Balanced
Findings: 3
Open (3)
What changed in this PR
Replaces the previous flow API with typed DPDK flow construction, lowering, error handling, and RAII-managed rules.
Changes:
- Adds typestate-based flow domains and protocol ordering.
- Adds typed match/action lowering, including VLAN and VXLAN support.
- Adds structured PMD errors and automatic rule destruction.
| File | Description |
|---|---|
dpdk/src/flow/mod.rs |
Defines and exports the typed flow API. |
dpdk/src/flow/builder.rs |
Builds, validates, and creates hardware flow rules. |
dpdk/src/flow/pattern.rs |
Lowers typed match criteria into DPDK structures. |
dpdk/src/flow/error.rs |
Classifies PMD flow errors. |
dpdk/src/flow/rule.rs |
Manages installed rules through an RAII handle. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
| /// mlx5 action order: remove headers, mark, rewrite, push headers, forward. | ||
| /// Actions of equal rank retain their insertion order. | ||
| fn rank(&self) -> u8 { | ||
| match self { | ||
| Action::OfPopVlan | Action::VxlanDecap => 0, |
| /// | ||
| /// Available only after UDP (VXLAN is UDP-encapsulated). Inner (decapsulated) headers can then be | ||
| /// matched as the pattern continues, since the `net` lattice resumes at the tunnel's inner start. | ||
| pub fn match_vxlan(mut self, criteria: VxlanMatch) -> FlowBuilder<'dev, D, Vxlan> |
| // Suppress the `Drop` below so the handle is freed exactly once. | ||
| let this = ManuallyDrop::new(self); | ||
| // SAFETY: `this.flow` is a live handle for `this.port`, owned solely by `self`, and the | ||
| // `ManuallyDrop` guarantees `Drop` will not free it a second time. | ||
| unsafe { destroy(this.port, this.flow) } |

Basically all meaningful testing of this logic requires physical hardware. And expensive / fancy hardware at that.
We can validate it on the lab systems, but I can't really help you regarding testing here.
Any mock / fake I craft is just doubling or tripling the amount of code in play without actually validating anything meaningful.