Repository navigation
fix(router): Remove VIP translation rows no binding owns - #814
Merged
Merged
Conversation
privateip
enabled auto-merge
October 8, 2026 21:54
privateip
force-pushed
the
fix/vipxlat-sweep
branch
from
October 8, 2026 21:56
1709229 to
9baf68e
Compare
galactic-router now sweeps the table on every GC tick after the first pass. controller.VIPXlatSweeper takes the table's generation, lists every ServiceVIPBinding targeting the node, resolves each one's two rows through the same parse and VRF-context lookup the reconciler uses, and calls Reconcile with that live set. Rows registered after the snapshot survive, and skipping the initial pass gives the reconciler a full interval to re-register every live binding first. A binding whose VRF context does not resolve right now (VRF not yet on the node, or briefly gone) has no known Argument, so every row shaped like one of its rows (direction, slot, protocol, address, port) is kept under any Block and Argument, rather than deleted and written back once it resolves. A binding whose spec does not parse never wrote a row, and any error listing bindings or building the index skips the pass. resolveVIPBindingRows is split into parseVIPBindingRows and a VRF placement step so the sweep reuses it, and runCmd's GC ticker moves into runGCTicker to stay under the gocyclo limit. usid.c has no slot-0 fallback, so galactic-gateway and galactic-router must be upgraded together across #799. The docs now say so. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
privateip
force-pushed
the
fix/vipxlat-sweep
branch
from
October 9, 2026 01:51
9baf68e to
6a7c364
Compare
scotwells
approved these changes
Oct 9, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What was wrong
#809 added the backend slot to the key of each VIP translation ingress row. A router built before #809 wrote its ingress rows with slot 0. Binding teardown looks only for the slot the current code computes, and no periodic sweep ran over the table, so nothing ever removed those slot-0 rows.
Rows orphaned any other way also stayed forever. That includes rows left by a crash, a finalizer cleared by hand, or a manual write.
What changed
The router now sweeps the VIP translation table on every GC tick (5 minutes by default). It skips the first pass at startup, so the binding reconciler has one full interval to rewrite every live binding's rows before anything is deleted.
Each pass:
Slot-0 ingress rows are never in the set, so the sweep removes them.
Sometimes a binding's VRF is not on the node yet, or is briefly gone. The sweep then cannot tell which VRF the binding's rows sit in, so it keeps every row that matches the binding's address, port, protocol and slot in any VRF. Deleting those rows would only cause churn. If listing bindings fails, the sweep removes nothing that tick.
Important
The datapath has no slot-0 fallback, so galactic-gateway and galactic-router must be upgraded together across #809. This PR adds no compatibility shim. The gateway configuration guide and the router architecture doc now say this.
Testing
New table-driven unit tests cover these cases:
I disabled the missing-VRF protection to confirm the tests fail without it. Lint, unit tests and build pass. In a worktree, the YAML formatter fails on
.git, so I ran it with a config that excludes.git, and it passed. I did not run the end-to-end tests.🤖 Generated with Claude Code