From mboxrd@z Thu Jan 1 00:00:00 1970 Authentication-Results: passt.top; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: passt.top; dkim=pass (2048-bit key; unprotected) header.d=gmail.com header.i=@gmail.com header.a=rsa-sha256 header.s=20251104 header.b=HnF5KK3g; dkim-atps=neutral Received: from mail-wm1-x331.google.com (mail-wm1-x331.google.com [IPv6:2a00:1450:4864:20::331]) by passt.top (Postfix) with ESMTPS id 8E58A5A026E for ; Mon, 27 Jul 2026 21:46:54 +0200 (CEST) Received: by mail-wm1-x331.google.com with SMTP id 5b1f17b1804b1-4953de5be0aso20639115e9.0 for ; Mon, 27 Jul 2026 12:46:54 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1785181614; x=1785786414; darn=passt.top; h=in-reply-to:references:subject:cc:to:from:message-id:date :content-type:content-transfer-encoding:mime-version:from:to:cc :subject:date:message-id:reply-to:content-type; bh=YLSpL6+HUr53wUM1OIX/LiR5anTOcq7jL/MysngPkEI=; b=HnF5KK3gKYfr9X1qjqB8jD6aVdWCbmIBVoKWeb2XWX7OBrDJEyo+ZsZnr1nhXB/iOQ xB6XdYBkJ5Uota0w9Ates8PSvL1zcODTj76ZQa3NFCjvshZaRO2f86QsoAUtaNlYR1oY 65EBH0hIGJ2ql6N4ZVZ5AuKDRr2/HtJ3kjHjVSqd60EXp4OwAGL51qh6w+v0S8XXiR8h 5QU5vfbPLA4iojiwrSDX4r8BGzubp9VYasyutdBwz7FQpjKKiSO0F8h8DkLUyi93lxfz KaXBIwWQiSqfjsXAg2cT/ntsoQv3Xv44CJpyEB759Q4kR2vm4x3myvIGoltbdG67Jj2G MPAQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785181614; x=1785786414; h=in-reply-to:references:subject:cc:to:from:message-id:date :content-type:content-transfer-encoding:mime-version:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=YLSpL6+HUr53wUM1OIX/LiR5anTOcq7jL/MysngPkEI=; b=CEr1Y4+cRe3YyMw4EH+salybZrh7npyz7+GuBXjDBjpXwt6is5Vj07Wwv2aEN1x0yk jSbnAkEJe0Oxl7+5LZdihM7AZHyxGb9pDcgevPLSjrZEhzNavEJy8gichMDyKIoxieqH FWpLV+97Vj2GbT36KXbNm9HBRLYhJq52lydG94vsGjBpvwbvYvtzKBaO9kwnUpBwC4MN frdkGg3SDCmblShGUcT+zqlmToBSgSajaZE5mFNHOTQ+9RM3qwk4fLTItRqKnqws5lfz KeRz8ItTud1bZshyn+ou4Hy4g94kg/g1poZbbiTGhZkuQsuh0VTocoET9OFfpgeupWAU iyLA== X-Gm-Message-State: AOJu0YzFe3QTvTMYQc8x7Lj/cmCEEbpG5ZP1njepU6/SOGfTJ8CbRvvd fApNP9z8AwSXwmfmI0CC5o5FoUDrSaqIe4Jr9YT8LbfJpSh/Hr393hKf X-Gm-Gg: AR+sD13iPcqCuBdX++wh8otCXzZQaFPkS+FN2AZaH8Uf1iYKhv7e9s/YdzQg5Za49qp 65xpgCq5345bA4SHK1X0ti/Enpz5P5xlR/nLbFEOU0lhQ8xHe8kJU+uUpOMrC204cx23dcIfMm6 Mq2uvmMBnFmyJH0xeB/6gyRXC3ZB2xzilXxAYCJ/kHu6Z33dCdVtB3vokkwSxnHRWQkktLfEeXm lZXhJleLFkSHwF1kBTMbX4qtewZw4dEHoBl2dcZgmfZCdRC7WubcFE82plR+W1X2JdPGw9Vrego I2BBRQFGAwrPlG0nWFmpvHMSZ2XR0oOpiClU7xQHAABCphJhX9BApCsLPimDpXNIBFDvLOzaxwP M75haxE3ApjAvpZlbxOE5CHkT2bqbsWIUzeoEMwj0wc4somwl7ouL42Tp2DiIobk4dhtT7BKHtl Ey81OWcYPFBDsWrdly8xXC3xgVP6Csa/WKxS0FRltbLr0RF+I= X-Received: by 2002:a05:600c:4194:b0:495:6a24:a92d with SMTP id 5b1f17b1804b1-496b5719fcemr70798645e9.22.1785181613887; Mon, 27 Jul 2026 12:46:53 -0700 (PDT) Received: from localhost ([196.156.129.176]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-496c45e6d38sm18201555e9.14.2026.07.27.12.46.52 (version=TLS1_3 cipher=TLS_AES_128_GCM_SHA256 bits=128/128); Mon, 27 Jul 2026 12:46:53 -0700 (PDT) Mime-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset=UTF-8 Date: Mon, 27 Jul 2026 22:46:50 +0300 Message-Id: From: "Ammar Yasser" To: "David Gibson" , "Stefano Brivio" Subject: Re: [PATCH] passt.1: Clearer and more detailed description of --map-guest-addr X-Mailer: aerc 0.21.0 References: <20260721022012.44338-1-david@gibson.dropbear.id.au> <20260723012848.7c5479f6@elisabeth> <20260725144437.161d8e44@elisabeth> In-Reply-To: Message-ID-Hash: XTPQHOTASLYVMC4LULHBHDTMZ5VN553O X-Message-ID-Hash: XTPQHOTASLYVMC4LULHBHDTMZ5VN553O X-MailFrom: aerosound161@gmail.com X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header CC: passt-dev@passt.top, Paul Holzinger , =?utf-8?q?Jan_Rod=C3=A1k?= X-Mailman-Version: 3.3.8 Precedence: list List-Id: Development discussion and patches for passt Archived-At: Archived-At: List-Archive: List-Archive: List-Help: List-Owner: List-Post: List-Subscribe: List-Unsubscribe: On Mon Jul 27, 2026 at 6:30 AM EEST, David Gibson wrote: >> and a >> conceptual equivalent *might* be used to explain things but I think >> it's more complicated than the alternative), and just refer to >> addresses like the implementation does, after all. Adjusted attempt >> below. > > It's difficult to explain clearly in terms of addresses only, because > the whole trouble is the same address refers to two different things: > on the inside it refers to the guest on the outside it refers to > .. something, usually the host but not always. The whole "shadowed > whatever" term is trying to get at "the thing on the outside that has > the same address as the guest does on the inside". I do agree that the notion of "shadowing" did confuse me a bit while reading through the rewrite. If i had to use my own words to describe whats going on with my current level of knowledge, i'd say: passt can't allocate addresses in the host namespace. to overcome this, an address will be picked and the guest will be made to believe that=20 this is its own. by default, this is the host primary address. Unless=20 another was specified through the -a option.=20 Keeping it at that, without mentioning that -a can refer to remote addresses is enough context for me as someone finding out about this option for the first time to understand how to use --map-guest-addr=20 in this paragraph >> > > > +own primary interface, because that's the address given to the gu= est. >> > > > +If the guest address is assigned with \fB-a\fR, however, the shad= owed >> > > > +interface will be whatever host-visible interface has the same >> > > > +address, which could belong to any node on the host's network or = the >> > > > +internet. =20 >> > >=20 >> > > I'm not sure if -a changes this in any substantial way. I would rath= er >> > > leave this paragraph out, as this is already documented. =20 >> >=20 >> > I would say the interaction with -a is exactly what makes this >> > confusing. That's why it has to be "map guest addr" not "map host >> > addr" or "map template addr". >>=20 >> I see now. I considered it a corner case which didn't deserve much >> attention, but, even with -a, I still think it's possible to include >> that in the description, talking about addresses, and avoid referring to >> interfaces. > > Well, maybe, it's demonstrably difficult though... I don't think it was entirely harmful for me to get the additional context around interfaces. but nevertheless, as Stefano says, we can do without it >> > > > +The guest or namespace cannot communicate with the shadowed inter= face >> > > > +using its host-visible address: because that's the same as the gu= est's >> > > > +address, sending packets there would loop back to the guest befor= e >> > > > +they're seen by passt to forward. =20 >> > >=20 >> > > I think this consideration should come after the description of the >> > > option. In general we always follow a structure where we describe th= e >> > > option first, and then any consideration or motivation, so that if t= he >> > > user is not interested in the motivation, they can skip it more >> > > conveniently. =20 >> >=20 >> > I agree in principle, but I'm really struggling to find a >> > non-confusing way of describing what it does without giving this >> > background first. Then again, from the below I'm evidently failing to >> > find a non-confusing way of describing even with the background first. Yes, actually giving the background, then saying that as a result to the guest cannot communicate with this address was pretty valuable in me understanding the problem statement >> > > What matters, I think, are the addresses we use, so I would try to >> > > rephrase this to just reflect what we actually do, that is, somethin= g >> > > on the lines of: >> > >=20 >> > > --- >> > >=20 >> > > Forward packets from the guest or container, originally directed to >> > > \fIaddr\fR, to the host, =20 >> >=20 >> > It's *not* to the host if -a gives an address that doesn't belong to >> > the host. >>=20 >> I'd say it still is, at Layer-2, because fwd_nat_from_tap() always >> returns PIF_HOST (and the packets will reach the host somehow). I'm not >> talking about routing or local delivery. > > The option is controlling L3 NAT, so we need to describe its behaviour > in terms of L3 - specifically what the final L3 destination of the > packet will be. What's happening at L2 and exactly how it's routed > there is secondary. Thats why i am in favor of leaving this detail entirely out of the description of --map-guest-addr. The relevant piece of information i need as i am specifying this option is to know why it exists (the background + the inability to communicate with the guest assigned from=20 the guest) and the layer 3 description of what will be the source and destination from both sides, who will the guest and passt (by whoever is on the other side whether its a local or remote interface) see the packets coming from