Re: [PATCH nf-next,v1 1/4] bridge: Add filling forward path from port to port

Eric Woudstra <[email protected]>
Newsgroups gmane.comp.security.firewalls.netfilter.devel
Message-ID <[email protected]>

On 7/8/26 11:32 AM, Pablo Neira Ayuso wrote:
> From: Eric Woudstra <[email protected]>
> 
> If a port is passed as argument instead of the master, then:
> 
> At br_fill_forward_path(): find the master and use it to fill the
> forward path.
> 
> At br_vlan_fill_forward_path_pvid(): lookup vlan group from port
> instead.
> 
> Changed call to br_vlan_group() into br_vlan_group_rcu() while at it.
> 
> Acked-by: Nikolay Aleksandrov <[email protected]>
> Signed-off-by: Eric Woudstra <[email protected]>
> Signed-off-by: Pablo Neira Ayuso <[email protected]>
> ---
> v1: I took this existing patch for the bridge vlan filtering, but
>     bridge vlan filtering is untested at this stage at least for me.
> 
>  net/bridge/br_device.c  | 19 ++++++++++++++-----
>  net/bridge/br_private.h |  2 ++
>  net/bridge/br_vlan.c    |  6 +++++-
>  3 files changed, 21 insertions(+), 6 deletions(-)
> 
> diff --git a/net/bridge/br_device.c b/net/bridge/br_device.c
> index e7f343ab22d3..89f4525a7279 100644
> --- a/net/bridge/br_device.c
> +++ b/net/bridge/br_device.c
> @@ -385,16 +385,25 @@ static int br_del_slave(struct net_device *dev, struct net_device *slave_dev)
>  static int br_fill_forward_path(struct net_device_path_ctx *ctx,
>  				struct net_device_path *path)
>  {
> +	struct net_bridge_port *src, *dst;
>  	struct net_bridge_fdb_entry *f;
> -	struct net_bridge_port *dst;
>  	struct net_bridge *br;
>  
> -	if (netif_is_bridge_port(ctx->dev))
> -		return -1;
> +	if (netif_is_bridge_port(ctx->dev)) {
> +		struct net_device *br_dev;
> +
> +		br_dev = netdev_master_upper_dev_get_rcu((struct net_device *)ctx->dev);
> +		if (!br_dev)
> +			return -1;
>  
> -	br = netdev_priv(ctx->dev);
> +		src = br_port_get_rcu(ctx->dev);
> +		br = netdev_priv(br_dev);
> +	} else {

So as per Nikolay's comment on another thread, Can add here:

		if (!netif_is_bridge_master(ctx->dev))
			return -1;

So that it can continue normally if ctx->dev is a bridge master.

> +		src = NULL;
> +		br = netdev_priv(ctx->dev);
> +	}
>  
> -	br_vlan_fill_forward_path_pvid(br, ctx, path);
> +	br_vlan_fill_forward_path_pvid(br, src, ctx, path);
>  
>  	f = br_fdb_find_rcu(br, ctx->daddr, path->bridge.vlan_id);
>  	if (!f)
> diff --git a/net/bridge/br_private.h b/net/bridge/br_private.h
> index d55ea9516e3e..00f5b72ff42d 100644
> --- a/net/bridge/br_private.h
> +++ b/net/bridge/br_private.h
> @@ -1630,6 +1630,7 @@ bool br_vlan_can_enter_range(const struct net_bridge_vlan *v_curr,
>  			     const struct net_bridge_vlan *range_end);
>  
>  void br_vlan_fill_forward_path_pvid(struct net_bridge *br,
> +				    struct net_bridge_port *p,
>  				    struct net_device_path_ctx *ctx,
>  				    struct net_device_path *path);
>  int br_vlan_fill_forward_path_mode(struct net_bridge *br,
> @@ -1799,6 +1800,7 @@ static inline int nbp_get_num_vlan_infos(struct net_bridge_port *p,
>  }
>  
>  static inline void br_vlan_fill_forward_path_pvid(struct net_bridge *br,
> +						  struct net_bridge_port *p,
>  						  struct net_device_path_ctx *ctx,
>  						  struct net_device_path *path)
>  {
> diff --git a/net/bridge/br_vlan.c b/net/bridge/br_vlan.c
> index 5560afcaaca3..71531499bc73 100644
> --- a/net/bridge/br_vlan.c
> +++ b/net/bridge/br_vlan.c
> @@ -1450,6 +1450,7 @@ int br_vlan_get_pvid_rcu(const struct net_device *dev, u16 *p_pvid)
>  EXPORT_SYMBOL_GPL(br_vlan_get_pvid_rcu);
>  
>  void br_vlan_fill_forward_path_pvid(struct net_bridge *br,
> +				    struct net_bridge_port *p,
>  				    struct net_device_path_ctx *ctx,
>  				    struct net_device_path *path)
>  {
> @@ -1462,7 +1463,10 @@ void br_vlan_fill_forward_path_pvid(struct net_bridge *br,
>  	if (!br_opt_get(br, BROPT_VLAN_ENABLED))
>  		return;
>  
> -	vg = br_vlan_group_rcu(br);
> +	if (p)
> +		vg = nbp_vlan_group_rcu(p);
> +	else
> +		vg = br_vlan_group_rcu(br);
>  
>  	if (idx >= 0 &&
>  	    ctx->vlan[idx].proto == br->vlan_proto) {
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.