Avoid active connection prevent timeout of idle conns after it
Fix a logic error related to timing out of the connections following the active one. To avoid this class of issue in the future, create corresponding testcases, as well as some trivial sanity testcases for both IPv4 and IPv6. Since these tests are timing-dependent and take up time, mark them as extended tests. Change-Id: I2c72bad5efda7db8aa9cb05801fe47928dc47927 Signed-off-by: Andrew Yourtchenko <>
Diffstat (limited to 'src/plugins')
2 files changed, 12 insertions, 10 deletions
diff --git a/src/plugins/acl/fa_node.c b/src/plugins/acl/fa_node.c
index b706fce87a8..c71429e76c6 100644
--- a/src/plugins/acl/fa_node.c
+++ b/src/plugins/acl/fa_node.c
@@ -570,10 +570,11 @@ acl_fa_ifc_init_sessions (acl_main_t * am, int sw_if_index0)
static void
-acl_fa_conn_list_add_session (acl_main_t * am, u32 sess_id)
+acl_fa_conn_list_add_session (acl_main_t * am, u32 sess_id, u64 now)
fa_session_t *sess = am->fa_sessions_pool + sess_id;
u8 list_id = fa_session_get_timeout_type(am, sess);
+ sess->link_enqueue_time = now;
sess->link_list_id = list_id;
sess->link_next_idx = ~0;
sess->link_prev_idx = am->fa_conn_list_tail[list_id];
@@ -629,7 +630,7 @@ acl_fa_restart_timer_for_session (acl_main_t * am, u64 now, u32 sess_id)
// fa_session_t *sess = am->fa_sessions_pool + sess_id;
acl_fa_conn_list_delete_session(am, sess_id);
- acl_fa_conn_list_add_session(am, sess_id);
+ acl_fa_conn_list_add_session(am, sess_id, now);
@@ -720,7 +721,7 @@ acl_fa_add_session (acl_main_t * am, int is_input, u32 sw_if_index, u64 now,
BV (clib_bihash_add_del) (&am->fa_sessions_by_sw_if_index[sw_if_index],
&kv, 1);
- acl_fa_conn_list_add_session(am, sess_id);
+ acl_fa_conn_list_add_session(am, sess_id, now);
vec_validate (am->fa_session_adds_by_sw_if_index, sw_if_index);
@@ -1097,12 +1098,12 @@ acl_fa_clean_sessions_by_sw_if_index (acl_main_t *am, u32 sw_if_index, u32 *coun
static vlib_node_registration_t acl_fa_session_cleaner_process_node;
static int
-acl_fa_conn_has_timed_out (acl_main_t *am, u64 now, u32 session_index)
+acl_fa_conn_time_to_check (acl_main_t *am, u64 now, u32 session_index)
fa_session_t *sess = am->fa_sessions_pool + session_index;
- u64 sess_timeout_time =
- sess->last_active_time + fa_session_get_timeout (am, sess);
- return (sess_timeout_time < now);
+ u64 timeout_time =
+ sess->link_enqueue_time + fa_session_get_timeout (am, sess);
+ return (timeout_time < now);
@@ -1210,7 +1211,7 @@ acl_fa_session_cleaner_process (vlib_main_t * vm, vlib_node_runtime_t * rt,
for(tt = 0; tt < ACL_N_TIMEOUTS; tt++) {
while((vec_len(expired) < 2*am->fa_max_deleted_sessions_per_interval)
&& (~0 != am->fa_conn_list_head[tt])
- && (acl_fa_conn_has_timed_out(am, now,
+ && (acl_fa_conn_time_to_check(am, now,
am->fa_conn_list_head[tt]))) {
u32 sess_id = am->fa_conn_list_head[tt];
vec_add1(expired, sess_id);
@@ -1237,7 +1238,7 @@ acl_fa_session_cleaner_process (vlib_main_t * vm, vlib_node_runtime_t * rt,
/* There was activity on the session, so the idle timeout
has not passed. Enqueue for another time period. */
- acl_fa_conn_list_add_session(am, session_index);
+ acl_fa_conn_list_add_session(am, session_index, now);
/* FIXME: When/if moving to timer wheel,
pretend we did this in the past,
diff --git a/src/plugins/acl/fa_node.h b/src/plugins/acl/fa_node.h
index 8edd0069217..861836226da 100644
--- a/src/plugins/acl/fa_node.h
+++ b/src/plugins/acl/fa_node.h
@@ -63,7 +63,8 @@ typedef struct {
u8 reserved1; /* +1 bytes = 64 */
u32 link_prev_idx;
u32 link_next_idx;
- u64 reserved2[7];
+ u64 link_enqueue_time;
+ u64 reserved2[6];
} fa_session_t;
141 142 143 144 145 146 147 148 149 150 151 152 153 154 155 156 157 158 159 160 161 162 163 164 165 166 167 168 169 170 171 172 173 174 175 176 177 178 179 180 181 182 183 184 185 186 187 188 189 190 191 192 193 194 195 196 197 198 199 200 201 202 203 204 205 206 207 208 209 210 211 212 213 214 215 216 217 218 219 220 221 222 223 224 225 226 227 228 229 230 231 232 233 234 235 236 237 238 239 240 241 242 243 244 245 246 247 248 249 250 251 252 253 254 255 256 257 258 259 260 261 262 263 264 265 266 267 268 269 270 271 272 273 274 275 276 277 278 279 280

# Specify a configuration file.

# Python code to execute, usually for sys.path manipulation such as
# pygtk.require().

# Profiled execution.

# Add files or directories to the blacklist. They should be base names, not
# paths.

# Pickle collected data for later comparisons.

# List of plugins (as comma separated values of python modules names) to load,
# usually to register additional checkers.


# Enable the message, report, category or checker with the given id(s). You can
# either give multiple identifier separated by comma (,) or put this option
# multiple time. See also the "--disable" option for examples.

# Disable the message, report, category or checker with the given id(s). You
# can either give multiple identifiers separated by comma (,) or put this
# option multiple times (only on the command line, not in the configuration
# file where it should appear only once).You can also use "--disable=all" to
# disable everything first and then reenable specific checks. For example, if
# you want to run only the similarities checker, you can use "--disable=all
# --enable=similarities". If you want to run only the classes checker, but have
# no Warning level messages displayed, use"--disable=all --enable=classes
# --disable=W"
disable=redefined-variable-type, locally-disabled


# Set the output format. Available formats are text, parseable, colorized, msvs
# (visual studio) and html. You can also give a reporter class, eg
# mypackage.mymodule.MyReporterClass.

# Put messages in a separate file for each module / package specified on the
# command line instead of printing them on stdout. Reports (if any) will be
# written in a file name "pylint_global.[txt|html]".

# Tells whether to display a full report or only the messages

# Python expression which should return a note less than 10 (10 is the highest
# note). You have access to the variables errors warning, statement which
# respectively contain the number of errors / warnings messages and the total
# number of statements analyzed. This is used by the global evaluation report
# (RP0004).
evaluation=10.0 - ((float(5 * error + warning + refactor + convention) / statement) * 10)

# Add a comment according to your evaluation note. This is used by the global
# evaluation report (RP0004).

# Template used to display messages. This is a python new-style format string
# used to format the message information. See doc for all details


# Maximum number of characters on a single line.

# Regexp for a line that is allowed to be longer than the limit.
ignore-long-lines=^\s*(# )?<?https?://\S+>?$

# Allow the body of an if to be on the same line as the test if there is no
# else.

# List of optional constructs for which whitespace checking is disabled

# Maximum number of lines in a module

# String used as indentation unit. This is usually " " (4 spaces) or "\t" (1
# tab).
indent-string='    '


# Tells whether we should check for unused import in __init__ files.

# A regular expression matching the beginning of the name of dummy variables
# (i.e. not used).

# List of additional names supposed to be defined in builtins. Remember that
# you should avoid to define new builtins when possible.


# Minimum lines number of a similarity.

# Ignore comments when computing similarities.

# Ignore docstrings when computing similarities.

# Ignore imports when computing similarities.


# Required attributes for module, separated by a comma

# List of builtins function names that should not be used, separated by a comma

# Regular expression which should only match correct module names

# Regular expression which should only match correct module level names

# Regular expression which should only match correct class names

# Regular expression which should only match correct function names

# Regular expression which should only match correct method names

# Regular expression which should only match correct instance attribute names

# Regular expression which should only match correct argument names

# Regular expression which should only match correct variable names

# Regular expression which should only match correct attribute names in class
# bodies

# Regular expression which should only match correct list comprehension /
# generator expression variable names

# Good variable names which should always be accepted, separated by a comma

# Bad variable names which should always be refused, separated by a comma

# Regular expression which should only match function or class names that do
# not require a docstring.

# Minimum line length for functions/classes that require docstrings, shorter
# ones are exempt.


# List of note tags to take in consideration, separated by a comma.


# Tells whether missing members accessed in mixin class should be ignored. A
# mixin class is detected if its name ends with "mixin" (case insensitive).

# List of classes names for which member attributes should not be checked
# (useful for classes with attributes dynamically set).

# When zope mode is activated, add a predefined set of Zope acquired attributes
# to generated-members.

# List of members which are set dynamically and missed by pylint inference
# system, and so shouldn't trigger E0201 when accessed. Python regular
# expressions are accepted.


# List of interface methods to ignore, separated by a comma. This is used for
# instance to not check methods defines in Zope's Interface base class.

# List of method names used to declare (i.e. assign) instance attributes.

# List of valid names for the first argument in a class method.

# List of valid names for the first argument in a metaclass class method.


# Deprecated modules which should not be used, separated by a comma

# Create a graph of every (i.e. internal and external) dependencies in the
# given file (report RP0402 must not be disabled)

# Create a graph of external dependencies in the given file (report RP0402 must
# not be disabled)

# Create a graph of internal dependencies in the given file (report RP0402 must
# not be disabled)


# Maximum number of arguments for function / method

# Argument names that match this expression will be ignored. Default to name
# with leading underscore

# Maximum number of locals for function / method body

# Maximum number of return / yield for function / method body

# Maximum number of branch for function / method body

# Maximum number of statements in function / method body

# Maximum number of parents for a class (see R0901).

# Maximum number of attributes for a class (see R0902).

# Minimum number of public methods for a class (see R0903).

# Maximum number of public methods for a class (see R0904).


# Exceptions that will emit a warning when being caught. Defaults to
# "Exception"