p4rt_acl_gribi_interaction_test - openconfig/featureprofiles GitHub Wiki
This test verifies the predictable behavior of the data plane when a packet is matched by both a P4RT-programmed table entry (such as an ACL) and a gRIBI-programmed route. The test ensures that the actual packet treatment conforms to the expected vendor-documented pipeline order (e.g., P4RT ACL taking precedence over gRIBI L3 lookup), and that the interaction is consistent and stable.
- Connect ATE
port-1to DUTport-1and ATEport-2to DUTport-2. - Configure IPv4 addressing on the connected interfaces in the
DEFAULTnetwork instance:- DUT
port-1(subinterface 0):192.0.2.1/30, ATEport-1:192.0.2.2/30(Traffic Ingress Link, subnet192.0.2.0/30) - DUT
port-2(subinterface 0):192.0.2.5/30, ATEport-2:192.0.2.6/30(Traffic Egress Link, subnet192.0.2.4/30)
- DUT
- Bring up the interfaces and verify they are
UPusing telemetry/interfaces/interface/state/oper-status. - Resolve IPv4 ARP on ATE
port-1(192.0.2.2) and ATEport-2(192.0.2.6) before sending traffic. - Configure P4RT node and interface IDs on the DUT via gNMI:
- Configure
/components/component/integrated-circuit/config/node-id(e.g.,device_id = 1) for the target forwarding integrated circuit. - Configure
/interfaces/interface/config/idon DUTport-1(id = 1) and DUTport-2(id = 2).
- Configure
- Establish a P4RT client connection to the DUT (
device_id = 1,election_id = {high: 0, low: 1}), performMasterArbitrationUpdateviaP4Runtime.StreamChannelto become the primary controller, and push the P4Info forwarding pipeline configuration viaP4Runtime.SetForwardingPipelineConfig(action = VERIFY_AND_COMMIT). - Establish a gRIBI client connection to the DUT in the
DEFAULTnetwork instance (persistence: PRESERVE,redundancy: SINGLE_PRIMARY,election_id: {low: 1, high: 0}), verify it becomes the leader, and executegRIBI.FlushonDEFAULTto ensure a clean initial AFT state.
-
Step 1 - Program a gRIBI route
- Use
gRIBI.ModifyRPC (requestingFIB_PROGRAMMEDACK) to install the following AFT entries in network instanceDEFAULT:-
NextHop(index = 1,network-instance = DEFAULT):ip-address = 192.0.2.6(ATEport-2). -
NextHopGroup(id = 1,network-instance = DEFAULT): referencesNextHop(index = 1)withweight = 1. -
IPv4Entry(prefix = 198.51.100.0/24,network-instance = DEFAULT): referencesNextHopGroup(id = 1)(next-hop-group-network-instance = DEFAULT).
-
- Validate route installation using
gNMI.Subscribe(ON_CHANGE) orgNMI.Geton paths:/network-instances/network-instance[name=DEFAULT]/afts/ipv4-unicast/ipv4-entry[prefix=198.51.100.0/24]/state/prefix/network-instances/network-instance[name=DEFAULT]/afts/ipv4-unicast/ipv4-entry[prefix=198.51.100.0/24]/state/next-hop-group/network-instances/network-instance[name=DEFAULT]/afts/next-hop-groups/next-hop-group[id=1]/state/id/network-instances/network-instance[name=DEFAULT]/afts/next-hops/next-hop[index=1]/state/ip-address
- Use
-
Step 2 - Send Traffic
- Send IPv4 test stream (
Flow-1, frame size512bytes, rate1,000 fps) from ATEport-1(source IP192.0.2.2) to destination IP198.51.100.1. - Send IPv4 control stream (
Flow-2, frame size512bytes, rate1,000 fps) from ATEport-1(source IP192.0.2.2) to destination IP198.51.100.2. - Verify
0%packet loss (Rx frames == Tx frames) at ATEport-2for bothFlow-1andFlow-2to confirm baseline gRIBI forwarding is active.
- Send IPv4 test stream (
-
Step 1 - Program a P4RT ACL rule
- Use
P4Runtime.Write(Update.Type = INSERT) to program an ingress ACL table entry (acl_ingress_table,priority = 100) matching IPv4 traffic (is_ipv4 = 0x1) with ternary destination IPdst_ip = 198.51.100.1and/32mask0xffffffff(198.51.100.1/32) and actionacl_drop(DROP). - Validate the P4RT ACL installation by ensuring a successful
P4Runtime.Writeresponse is received and verifying the entry viaP4Runtime.Read.
- Use
-
Step 2 - Send Traffic
- Send test stream (
Flow-1, frame size512bytes, rate1,000 fps): IPv4 traffic from ATEport-1(source IP192.0.2.2) to destination IP198.51.100.1(matching both the gRIBI route198.51.100.0/24and the P4RT ACL198.51.100.1/32). - Send control stream (
Flow-2, frame size512bytes, rate1,000 fps): IPv4 traffic from ATEport-1(source IP192.0.2.2) to destination IP198.51.100.2(matching only the gRIBI route198.51.100.0/24).
- Send test stream (
-
Step 3 - Validation with pass/fail criteria
- Verify traffic to
198.51.100.1(Flow-1) is completely dropped (100%loss,0packets received at ATEport-2) as the P4RT ACLDROPaction takes precedence over the gRIBI route. - Verify traffic to
198.51.100.2(Flow-2) is forwarded correctly to ATEport-2with0%loss (Rx frames == Tx frames), preventing false positives.
- Verify traffic to
-
Step 1 - Program Scaled routes and ACLs
- Use
gRIBI.Modify(requestingFIB_PROGRAMMEDACK) to program 1,000 IPv4 routes in network instanceDEFAULTfor prefixes100.64.0.0/24through100.67.231.0/24(i.e.,100.<64 + floor(i/256)>.<i mod 256>.0/24for$i \in [0, 999]$ ), all referencingNextHopGroup(id = 1)(NextHop(index = 1)=192.0.2.6on ATEport-2). - Verify all 1,000 routes (
100.64.0.0/24through100.67.231.0/24) are programmed in the AFT via batchedgNMI.Get/gNMI.Subscribeon/network-instances/network-instance[name=DEFAULT]/afts/ipv4-unicast/ipv4-entry[prefix=...]/state/prefix. - Use
P4Runtime.Write(Update.Type = INSERT) to program 1,000 P4RT IPv4 ACL rules (acl_ingress_table,priority = 100,is_ipv4 = 0x1) matching the.1/32host IP (mask = 0xffffffff) within each of the 1,000 prefixes:dst_ip = 100.64.0.1 & 0xffffffffthrough100.67.231.1 & 0xffffffff(i.e.,100.<64 + floor(i/256)>.<i mod 256>.1/32for$i \in [0, 999]$ ) with actionacl_drop(DROP). - Validate installation via successful
P4Runtime.Writeresponse andP4Runtime.Readverification.
- Use
-
Step 2 - Send Traffic
- Send matched scaled traffic stream (
Flow-Scaled-Drop, frame size512bytes, rate10,000 fps) from ATEport-1(source IP192.0.2.2) to the 1,000 ACL-matched destination host IPs:100.64.0.1through100.67.231.1(count1,000, i.e.,100.<64 + floor(i/256)>.<i mod 256>.1for$i \in [0, 999]$ ). - Send unmatched scaled traffic stream (
Flow-Scaled-Forward, frame size512bytes, rate10,000 fps) from ATEport-1(source IP192.0.2.2) to the 1,000 ACL-unmatched destination host IPs within the same routed/24subnets:100.64.0.2through100.67.231.2(count1,000, i.e.,100.<64 + floor(i/256)>.<i mod 256>.2for$i \in [0, 999]$ ).
- Send matched scaled traffic stream (
-
Step 3 - Validation with pass/fail criteria
- Verify traffic to the 1,000 matched host IPs (
Flow-Scaled-Drop,100.64.0.1through100.67.231.1) is completely dropped (100%loss,0packets received at ATEport-2). - Verify traffic to the 1,000 unmatched host IPs (
Flow-Scaled-Forward,100.64.0.2through100.67.231.2) is forwarded to ATEport-2with0%loss (Rx frames == Tx frames). - Clean up the scaled entries before proceeding: delete the 1,000 scaled P4RT ACL entries (
100.64.0.1/32through100.67.231.1/32) viaP4Runtime.Write(DELETE) and delete the 1,000 scaled gRIBIIPv4Entryprefixes (100.64.0.0/24through100.67.231.0/24) viagRIBI.Modify(DELETE).
- Verify traffic to the 1,000 matched host IPs (
-
Step 1 - Delete P4RT ACL rule
- Use
P4Runtime.Write(Update.Type = DELETE) to delete the P4RT IPv4 ACL rule matchingdst_ip = 198.51.100.1 & 0xffffffff(198.51.100.1/32, configured in TE-1.3.2). - Validate deletion via successful
P4Runtime.Writeresponse and confirm viaP4Runtime.Readthat the rule is no longer present.
- Use
-
Step 2 - Send Traffic
- Send
Flow-1(source IP192.0.2.2to destination IP198.51.100.1, frame size512bytes, rate1,000 fps) andFlow-2(source IP192.0.2.2to destination IP198.51.100.2, frame size512bytes, rate1,000 fps) from ATEport-1.
- Send
-
Step 3 - Validation with pass/fail criteria
- Verify traffic to
198.51.100.1(Flow-1) and198.51.100.2(Flow-2) is forwarded correctly to ATEport-2with0%loss (Rx frames == Tx frames), confirming traffic to198.51.100.1falls back to the active gRIBI route (198.51.100.0/24).
- Verify traffic to
-
Step 1 - Delete gRIBI route
- Re-program (
P4Runtime.Write,Update.Type = INSERT) the P4RT IPv4 ACL rule (acl_ingress_table,priority = 100,is_ipv4 = 0x1) matchingdst_ip = 198.51.100.1 & 0xffffffff(198.51.100.1/32) with actionacl_drop(DROP), and verify installation viaP4Runtime.Read. - Use
gRIBI.Modify(DELETE, requestingFIB_PROGRAMMEDACK) to delete the gRIBIIPv4Entryfor destination prefix198.51.100.0/24in network instanceDEFAULT. - Validate route deletion via gNMI telemetry ensuring
/network-instances/network-instance[name=DEFAULT]/afts/ipv4-unicast/ipv4-entry[prefix=198.51.100.0/24]/state/prefixis removed from the AFT state.
- Re-program (
-
Step 2 - Send Traffic
- Send test stream (
Flow-1, frame size512bytes, rate1,000 fps): IPv4 traffic from ATEport-1(source IP192.0.2.2) to destination IP198.51.100.1(matches active P4RT ACL198.51.100.1/32). - Send control stream (
Flow-2, frame size512bytes, rate1,000 fps): IPv4 traffic from ATEport-1(source IP192.0.2.2) to destination IP198.51.100.2(no matching route in AFT).
- Send test stream (
-
Step 3 - Validation with pass/fail criteria
- Verify traffic to
198.51.100.1(Flow-1) is completely dropped (100%loss,0packets received at ATEport-2) as it matches the active P4RT ACL rule. - Verify traffic to
198.51.100.2(Flow-2) is completely dropped (100%loss,0packets received at ATEport-2) because there is no matching route in the FIB.
- Verify traffic to
{
"network-instances": {
"network-instance": [
{
"name": "DEFAULT",
"config": {
"name": "DEFAULT"
}
}
]
}
}paths:
/components/component/integrated-circuit/config/node-id:
platform_type: ["INTEGRATED_CIRCUIT"]
/interfaces/interface/config/id:
/interfaces/interface/state/oper-status:
/interfaces/interface/config/enabled:
/network-instances/network-instance/afts/ipv4-unicast/ipv4-entry/state/prefix:
/network-instances/network-instance/afts/ipv4-unicast/ipv4-entry/state/next-hop-group:
/network-instances/network-instance/afts/next-hop-groups/next-hop-group/state/id:
/network-instances/network-instance/afts/next-hops/next-hop/state/index:
/network-instances/network-instance/afts/next-hops/next-hop/state/ip-address:
/network-instances/network-instance/config/name:
rpcs:
gnmi:
gNMI.Get:
gNMI.Set:
union_replace: true
gNMI.Subscribe:
on_change: true
gribi:
gRIBI.Flush:
gRIBI.Get:
gRIBI.Modify:- FFF