return -EINVAL;
 
                action->flow_tag = ib_spec->flow_tag.tag_id;
-               action->has_flow_tag = true;
+               action->flags |= FLOW_ACT_HAS_TAG;
                break;
        case IB_FLOW_SPEC_ACTION_DROP:
                if (FIELDS_NOT_SUPPORTED(ib_spec->drop,
                return egress ? VALID_SPEC_INVALID : VALID_SPEC_NA;
 
        return is_crypto && is_ipsec &&
-               (!egress || (!is_drop && !flow_act->has_flow_tag)) ?
+               (!egress || (!is_drop && !(flow_act->flags & FLOW_ACT_HAS_TAG))) ?
                VALID_SPEC_VALID : VALID_SPEC_INVALID;
 }
 
                                        MLX5_FLOW_CONTEXT_ACTION_FWD_NEXT_PRIO;
        }
 
-       if (flow_act.has_flow_tag &&
+       if ((flow_act.flags & FLOW_ACT_HAS_TAG)  &&
            (flow_attr->type == IB_FLOW_ATTR_ALL_DEFAULT ||
             flow_attr->type == IB_FLOW_ATTR_MC_DEFAULT)) {
                mlx5_ib_warn(dev, "Flow tag %u and attribute type %x isn't allowed in leftovers\n",
 
        struct mlx5_flow_destination dest[2] = {};
        struct mlx5_flow_act flow_act = {
                .action = attr->action,
-               .has_flow_tag = true,
                .flow_tag = attr->flow_tag,
                .reformat_id = 0,
+               .flags    = FLOW_ACT_HAS_TAG,
        };
        struct mlx5_fc *counter = NULL;
        bool table_created = false;
 
            (match_criteria_enable &
             ~(MLX5_MATCH_OUTER_HEADERS | MLX5_MATCH_MISC_PARAMETERS)) ||
            (flow_act->action & ~(MLX5_FLOW_CONTEXT_ACTION_ENCRYPT | MLX5_FLOW_CONTEXT_ACTION_ALLOW)) ||
-            flow_act->has_flow_tag)
+            (flow_act->flags & FLOW_ACT_HAS_TAG))
                return false;
 
        return true;
 
                return -EEXIST;
        }
 
-       if (flow_act->has_flow_tag &&
+       if ((flow_act->flags & FLOW_ACT_HAS_TAG) &&
            fte->action.flow_tag != flow_act->flow_tag) {
                mlx5_core_warn(get_dev(&fte->node),
                               "FTE flow tag %u already exists with different flow tag %u\n",
 
 search_again_locked:
        version = matched_fgs_get_version(match_head);
+       if (flow_act->flags & FLOW_ACT_NO_APPEND)
+               goto skip_search;
        /* Try to find a fg that already contains a matching fte */
        list_for_each_entry(iter, match_head, list) {
                struct fs_fte *fte_tmp;
                return rule;
        }
 
+skip_search:
+       /* No group with matching fte found, or we skipped the search.
+        * Try to add a new fte to any matching fg.
+        */
+
        /* Check the ft version, for case that new flow group
         * was added while the fgs weren't locked
         */
 
 
 #define MLX5_FS_VLAN_DEPTH     2
 
+enum {
+       FLOW_ACT_HAS_TAG   = BIT(0),
+       FLOW_ACT_NO_APPEND = BIT(1),
+};
+
 struct mlx5_flow_act {
        u32 action;
-       bool has_flow_tag;
        u32 flow_tag;
        u32 reformat_id;
        u32 modify_id;
        uintptr_t esp_id;
+       u32 flags;
        struct mlx5_fs_vlan vlan[MLX5_FS_VLAN_DEPTH];
        struct ib_counters *counters;
 };
 
 #define MLX5_DECLARE_FLOW_ACT(name) \
-       struct mlx5_flow_act name = {MLX5_FLOW_CONTEXT_ACTION_FWD_DEST,\
-                                    MLX5_FS_DEFAULT_FLOW_TAG, 0, 0}
+       struct mlx5_flow_act name = { .action = MLX5_FLOW_CONTEXT_ACTION_FWD_DEST,\
+                                     .flow_tag = MLX5_FS_DEFAULT_FLOW_TAG, \
+                                     .reformat_id = 0, \
+                                     .modify_id = 0, \
+                                     .flags =  0, }
 
 /* Single destination per rule.
  * Group ID is implied by the match criteria.