Skip to content
packerlschupfer edited this page Jun 4, 2026 · 2 revisions

octeon-flowtable

Clean-room nftables flow-offload backend for the Cavium Octeon+ (CN50xx) — hardware-accelerated NAT/routing on mainline OpenWrt for the EdgeRouter Lite 3, matching the proprietary EdgeOS offload using only GPL sources + the public OCTEON hardware reference manual.

Repo: https://github.com/packerlschupfer/octeon-flowtable

Start here

You want to… Read
Build it from source BUILDING · prompts/build
Install + turn on offload INSTALLING · prompts/deploy
See what it does + the numbers PROJECT-OUTCOME
Understand the design design RFC
Understand the hardware fast-path model · per-block notes (PIP/IPD, POW, PKO, FPA/FAU)
Extend it (capability matrix, what's a HW limit) FUTURE-WORK
The vendor it reverse-engineers behavioural spec · integration gap

What's accelerated

IPv4 + IPv6, NAT + routing, untagged + 802.1Q (retag/pop/push) + QinQ — all hardware-verified. Plus a global FAU counter and a PKO tail-drop AQM (54 ms → 4 ms bufferbloat at equal throughput).

Hardware ceilings (not bugs)

CN50xx PIP parses ≤ 2 VLAN tags; the Linux flowtable offloads TCP/UDP/GRE only (no ESP); IPv6 extension headers / fragments go slow-path. Details in FUTURE-WORK.

Questions

Issues/PRs welcome, or drop into the Discord.