Re: [PATCH nf-next,v1 1/4] bridge: Add filling forward path from port to port
Eric Woudstra <[email protected]>
| Newsgroups | gmane.comp.security.firewalls.netfilter.devel |
|---|---|
| Message-ID | <[email protected]> |
On 7/8/26 11:32 AM, Pablo Neira Ayuso wrote: > From: Eric Woudstra <[email protected]> > > If a port is passed as argument instead of the master, then: > > At br_fill_forward_path(): find the master and use it to fill the > forward path. > > At br_vlan_fill_forward_path_pvid(): lookup vlan group from port > instead. > > Changed call to br_vlan_group() into br_vlan_group_rcu() while at it. > > Acked-by: Nikolay Aleksandrov <[email protected]> > Signed-off-by: Eric Woudstra <[email protected]> > Signed-off-by: Pablo Neira Ayuso <[email protected]> > --- > v1: I took this existing patch for the bridge vlan filtering, but > bridge vlan filtering is untested at this stage at least for me. > > net/bridge/br_device.c | 19 ++++++++++++++----- > net/bridge/br_private.h | 2 ++ > net/bridge/br_vlan.c | 6 +++++- > 3 files changed, 21 insertions(+), 6 deletions(-) > > diff --git a/net/bridge/br_device.c b/net/bridge/br_device.c > index e7f343ab22d3..89f4525a7279 100644 > --- a/net/bridge/br_device.c > +++ b/net/bridge/br_device.c > @@ -385,16 +385,25 @@ static int br_del_slave(struct net_device *dev, struct net_device *slave_dev) > static int br_fill_forward_path(struct net_device_path_ctx *ctx, > struct net_device_path *path) > { > + struct net_bridge_port *src, *dst; > struct net_bridge_fdb_entry *f; > - struct net_bridge_port *dst; > struct net_bridge *br; > > - if (netif_is_bridge_port(ctx->dev)) > - return -1; > + if (netif_is_bridge_port(ctx->dev)) { > + struct net_device *br_dev; > + > + br_dev = netdev_master_upper_dev_get_rcu((struct net_device *)ctx->dev); > + if (!br_dev) > + return -1; > > - br = netdev_priv(ctx->dev); > + src = br_port_get_rcu(ctx->dev); > + br = netdev_priv(br_dev); > + } else { So as per Nikolay's comment on another thread, Can add here: if (!netif_is_bridge_master(ctx->dev)) return -1; So that it can continue normally if ctx->dev is a bridge master. > + src = NULL; > + br = netdev_priv(ctx->dev); > + } > > - br_vlan_fill_forward_path_pvid(br, ctx, path); > + br_vlan_fill_forward_path_pvid(br, src, ctx, path); > > f = br_fdb_find_rcu(br, ctx->daddr, path->bridge.vlan_id); > if (!f) > diff --git a/net/bridge/br_private.h b/net/bridge/br_private.h > index d55ea9516e3e..00f5b72ff42d 100644 > --- a/net/bridge/br_private.h > +++ b/net/bridge/br_private.h > @@ -1630,6 +1630,7 @@ bool br_vlan_can_enter_range(const struct net_bridge_vlan *v_curr, > const struct net_bridge_vlan *range_end); > > void br_vlan_fill_forward_path_pvid(struct net_bridge *br, > + struct net_bridge_port *p, > struct net_device_path_ctx *ctx, > struct net_device_path *path); > int br_vlan_fill_forward_path_mode(struct net_bridge *br, > @@ -1799,6 +1800,7 @@ static inline int nbp_get_num_vlan_infos(struct net_bridge_port *p, > } > > static inline void br_vlan_fill_forward_path_pvid(struct net_bridge *br, > + struct net_bridge_port *p, > struct net_device_path_ctx *ctx, > struct net_device_path *path) > { > diff --git a/net/bridge/br_vlan.c b/net/bridge/br_vlan.c > index 5560afcaaca3..71531499bc73 100644 > --- a/net/bridge/br_vlan.c > +++ b/net/bridge/br_vlan.c > @@ -1450,6 +1450,7 @@ int br_vlan_get_pvid_rcu(const struct net_device *dev, u16 *p_pvid) > EXPORT_SYMBOL_GPL(br_vlan_get_pvid_rcu); > > void br_vlan_fill_forward_path_pvid(struct net_bridge *br, > + struct net_bridge_port *p, > struct net_device_path_ctx *ctx, > struct net_device_path *path) > { > @@ -1462,7 +1463,10 @@ void br_vlan_fill_forward_path_pvid(struct net_bridge *br, > if (!br_opt_get(br, BROPT_VLAN_ENABLED)) > return; > > - vg = br_vlan_group_rcu(br); > + if (p) > + vg = nbp_vlan_group_rcu(p); > + else > + vg = br_vlan_group_rcu(br); > > if (idx >= 0 && > ctx->vlan[idx].proto == br->vlan_proto) {