Linux Audio

Check our new training course

Loading...
v6.8
  1// SPDX-License-Identifier: GPL-2.0-only
  2// Copyright (c) 2020, Nikolay Aleksandrov <nikolay@cumulusnetworks.com>
  3#include <linux/kernel.h>
  4#include <linux/netdevice.h>
  5#include <linux/rtnetlink.h>
  6#include <linux/slab.h>
  7#include <net/ip_tunnels.h>
  8
  9#include "br_private.h"
 10#include "br_private_tunnel.h"
 11
 12static bool __vlan_tun_put(struct sk_buff *skb, const struct net_bridge_vlan *v)
 13{
 14	__be32 tid = tunnel_id_to_key32(v->tinfo.tunnel_id);
 15	struct nlattr *nest;
 16
 17	if (!v->tinfo.tunnel_dst)
 18		return true;
 19
 20	nest = nla_nest_start(skb, BRIDGE_VLANDB_ENTRY_TUNNEL_INFO);
 21	if (!nest)
 22		return false;
 23	if (nla_put_u32(skb, BRIDGE_VLANDB_TINFO_ID, be32_to_cpu(tid))) {
 24		nla_nest_cancel(skb, nest);
 25		return false;
 26	}
 27	nla_nest_end(skb, nest);
 28
 29	return true;
 30}
 31
 32static bool __vlan_tun_can_enter_range(const struct net_bridge_vlan *v_curr,
 33				       const struct net_bridge_vlan *range_end)
 34{
 35	return (!v_curr->tinfo.tunnel_dst && !range_end->tinfo.tunnel_dst) ||
 36	       vlan_tunid_inrange(v_curr, range_end);
 37}
 38
 39/* check if the options' state of v_curr allow it to enter the range */
 40bool br_vlan_opts_eq_range(const struct net_bridge_vlan *v_curr,
 41			   const struct net_bridge_vlan *range_end)
 42{
 43	u8 range_mc_rtr = br_vlan_multicast_router(range_end);
 44	u8 curr_mc_rtr = br_vlan_multicast_router(v_curr);
 45
 46	return v_curr->state == range_end->state &&
 47	       __vlan_tun_can_enter_range(v_curr, range_end) &&
 48	       curr_mc_rtr == range_mc_rtr;
 49}
 50
 51bool br_vlan_opts_fill(struct sk_buff *skb, const struct net_bridge_vlan *v,
 52		       const struct net_bridge_port *p)
 53{
 54	if (nla_put_u8(skb, BRIDGE_VLANDB_ENTRY_STATE, br_vlan_get_state(v)) ||
 55	    !__vlan_tun_put(skb, v) ||
 56	    nla_put_u8(skb, BRIDGE_VLANDB_ENTRY_NEIGH_SUPPRESS,
 57		       !!(v->priv_flags & BR_VLFLAG_NEIGH_SUPPRESS_ENABLED)))
 58		return false;
 59
 60#ifdef CONFIG_BRIDGE_IGMP_SNOOPING
 61	if (nla_put_u8(skb, BRIDGE_VLANDB_ENTRY_MCAST_ROUTER,
 62		       br_vlan_multicast_router(v)))
 63		return false;
 64	if (p && !br_multicast_port_ctx_vlan_disabled(&v->port_mcast_ctx) &&
 65	    (nla_put_u32(skb, BRIDGE_VLANDB_ENTRY_MCAST_N_GROUPS,
 66			 br_multicast_ngroups_get(&v->port_mcast_ctx)) ||
 67	     nla_put_u32(skb, BRIDGE_VLANDB_ENTRY_MCAST_MAX_GROUPS,
 68			 br_multicast_ngroups_get_max(&v->port_mcast_ctx))))
 69		return false;
 70#endif
 71
 72	return true;
 73}
 74
 75size_t br_vlan_opts_nl_size(void)
 76{
 77	return nla_total_size(sizeof(u8)) /* BRIDGE_VLANDB_ENTRY_STATE */
 78	       + nla_total_size(0) /* BRIDGE_VLANDB_ENTRY_TUNNEL_INFO */
 79	       + nla_total_size(sizeof(u32)) /* BRIDGE_VLANDB_TINFO_ID */
 80#ifdef CONFIG_BRIDGE_IGMP_SNOOPING
 81	       + nla_total_size(sizeof(u8)) /* BRIDGE_VLANDB_ENTRY_MCAST_ROUTER */
 82	       + nla_total_size(sizeof(u32)) /* BRIDGE_VLANDB_ENTRY_MCAST_N_GROUPS */
 83	       + nla_total_size(sizeof(u32)) /* BRIDGE_VLANDB_ENTRY_MCAST_MAX_GROUPS */
 84#endif
 85	       + nla_total_size(sizeof(u8)) /* BRIDGE_VLANDB_ENTRY_NEIGH_SUPPRESS */
 86	       + 0;
 87}
 88
 89static int br_vlan_modify_state(struct net_bridge_vlan_group *vg,
 90				struct net_bridge_vlan *v,
 91				u8 state,
 92				bool *changed,
 93				struct netlink_ext_ack *extack)
 94{
 95	struct net_bridge *br;
 96
 97	ASSERT_RTNL();
 98
 99	if (state > BR_STATE_BLOCKING) {
100		NL_SET_ERR_MSG_MOD(extack, "Invalid vlan state");
101		return -EINVAL;
102	}
103
104	if (br_vlan_is_brentry(v))
105		br = v->br;
106	else
107		br = v->port->br;
108
109	if (br->stp_enabled == BR_KERNEL_STP) {
110		NL_SET_ERR_MSG_MOD(extack, "Can't modify vlan state when using kernel STP");
111		return -EBUSY;
112	}
113
114	if (br_opt_get(br, BROPT_MST_ENABLED)) {
115		NL_SET_ERR_MSG_MOD(extack, "Can't modify vlan state directly when MST is enabled");
116		return -EBUSY;
117	}
118
119	if (v->state == state)
120		return 0;
121
122	if (v->vid == br_get_pvid(vg))
123		br_vlan_set_pvid_state(vg, state);
124
125	br_vlan_set_state(v, state);
126	*changed = true;
127
128	return 0;
129}
130
131static const struct nla_policy br_vlandb_tinfo_pol[BRIDGE_VLANDB_TINFO_MAX + 1] = {
132	[BRIDGE_VLANDB_TINFO_ID]	= { .type = NLA_U32 },
133	[BRIDGE_VLANDB_TINFO_CMD]	= { .type = NLA_U32 },
134};
135
136static int br_vlan_modify_tunnel(const struct net_bridge_port *p,
137				 struct net_bridge_vlan *v,
138				 struct nlattr **tb,
139				 bool *changed,
140				 struct netlink_ext_ack *extack)
141{
142	struct nlattr *tun_tb[BRIDGE_VLANDB_TINFO_MAX + 1], *attr;
143	struct bridge_vlan_info *vinfo;
144	u32 tun_id = 0;
145	int cmd, err;
146
147	if (!p) {
148		NL_SET_ERR_MSG_MOD(extack, "Can't modify tunnel mapping of non-port vlans");
149		return -EINVAL;
150	}
151	if (!(p->flags & BR_VLAN_TUNNEL)) {
152		NL_SET_ERR_MSG_MOD(extack, "Port doesn't have tunnel flag set");
153		return -EINVAL;
154	}
155
156	attr = tb[BRIDGE_VLANDB_ENTRY_TUNNEL_INFO];
157	err = nla_parse_nested(tun_tb, BRIDGE_VLANDB_TINFO_MAX, attr,
158			       br_vlandb_tinfo_pol, extack);
159	if (err)
160		return err;
161
162	if (!tun_tb[BRIDGE_VLANDB_TINFO_CMD]) {
163		NL_SET_ERR_MSG_MOD(extack, "Missing tunnel command attribute");
164		return -ENOENT;
165	}
166	cmd = nla_get_u32(tun_tb[BRIDGE_VLANDB_TINFO_CMD]);
167	switch (cmd) {
168	case RTM_SETLINK:
169		if (!tun_tb[BRIDGE_VLANDB_TINFO_ID]) {
170			NL_SET_ERR_MSG_MOD(extack, "Missing tunnel id attribute");
171			return -ENOENT;
172		}
173		/* when working on vlan ranges this is the starting tunnel id */
174		tun_id = nla_get_u32(tun_tb[BRIDGE_VLANDB_TINFO_ID]);
175		/* vlan info attr is guaranteed by br_vlan_rtm_process_one */
176		vinfo = nla_data(tb[BRIDGE_VLANDB_ENTRY_INFO]);
177		/* tunnel ids are mapped to each vlan in increasing order,
178		 * the starting vlan is in BRIDGE_VLANDB_ENTRY_INFO and v is the
179		 * current vlan, so we compute: tun_id + v - vinfo->vid
180		 */
181		tun_id += v->vid - vinfo->vid;
182		break;
183	case RTM_DELLINK:
184		break;
185	default:
186		NL_SET_ERR_MSG_MOD(extack, "Unsupported tunnel command");
187		return -EINVAL;
188	}
189
190	return br_vlan_tunnel_info(p, cmd, v->vid, tun_id, changed);
191}
192
193static int br_vlan_process_one_opts(const struct net_bridge *br,
194				    const struct net_bridge_port *p,
195				    struct net_bridge_vlan_group *vg,
196				    struct net_bridge_vlan *v,
197				    struct nlattr **tb,
198				    bool *changed,
199				    struct netlink_ext_ack *extack)
200{
201	int err;
202
203	*changed = false;
204	if (tb[BRIDGE_VLANDB_ENTRY_STATE]) {
205		u8 state = nla_get_u8(tb[BRIDGE_VLANDB_ENTRY_STATE]);
206
207		err = br_vlan_modify_state(vg, v, state, changed, extack);
208		if (err)
209			return err;
210	}
211	if (tb[BRIDGE_VLANDB_ENTRY_TUNNEL_INFO]) {
212		err = br_vlan_modify_tunnel(p, v, tb, changed, extack);
213		if (err)
214			return err;
215	}
216
217#ifdef CONFIG_BRIDGE_IGMP_SNOOPING
218	if (tb[BRIDGE_VLANDB_ENTRY_MCAST_ROUTER]) {
219		u8 val;
220
221		val = nla_get_u8(tb[BRIDGE_VLANDB_ENTRY_MCAST_ROUTER]);
222		err = br_multicast_set_vlan_router(v, val);
223		if (err)
224			return err;
225		*changed = true;
226	}
227	if (tb[BRIDGE_VLANDB_ENTRY_MCAST_MAX_GROUPS]) {
228		u32 val;
229
230		if (!p) {
231			NL_SET_ERR_MSG_MOD(extack, "Can't set mcast_max_groups for non-port vlans");
232			return -EINVAL;
233		}
234		if (br_multicast_port_ctx_vlan_disabled(&v->port_mcast_ctx)) {
235			NL_SET_ERR_MSG_MOD(extack, "Multicast snooping disabled on this VLAN");
236			return -EINVAL;
237		}
238
239		val = nla_get_u32(tb[BRIDGE_VLANDB_ENTRY_MCAST_MAX_GROUPS]);
240		br_multicast_ngroups_set_max(&v->port_mcast_ctx, val);
241		*changed = true;
242	}
243#endif
244
245	if (tb[BRIDGE_VLANDB_ENTRY_NEIGH_SUPPRESS]) {
246		bool enabled = v->priv_flags & BR_VLFLAG_NEIGH_SUPPRESS_ENABLED;
247		bool val = nla_get_u8(tb[BRIDGE_VLANDB_ENTRY_NEIGH_SUPPRESS]);
248
249		if (!p) {
250			NL_SET_ERR_MSG_MOD(extack, "Can't set neigh_suppress for non-port vlans");
251			return -EINVAL;
252		}
253
254		if (val != enabled) {
255			v->priv_flags ^= BR_VLFLAG_NEIGH_SUPPRESS_ENABLED;
256			*changed = true;
257		}
258	}
259
260	return 0;
261}
262
263int br_vlan_process_options(const struct net_bridge *br,
264			    const struct net_bridge_port *p,
265			    struct net_bridge_vlan *range_start,
266			    struct net_bridge_vlan *range_end,
267			    struct nlattr **tb,
268			    struct netlink_ext_ack *extack)
269{
270	struct net_bridge_vlan *v, *curr_start = NULL, *curr_end = NULL;
271	struct net_bridge_vlan_group *vg;
272	int vid, err = 0;
273	u16 pvid;
274
275	if (p)
276		vg = nbp_vlan_group(p);
277	else
278		vg = br_vlan_group(br);
279
280	if (!range_start || !br_vlan_should_use(range_start)) {
281		NL_SET_ERR_MSG_MOD(extack, "Vlan range start doesn't exist, can't process options");
282		return -ENOENT;
283	}
284	if (!range_end || !br_vlan_should_use(range_end)) {
285		NL_SET_ERR_MSG_MOD(extack, "Vlan range end doesn't exist, can't process options");
286		return -ENOENT;
287	}
288
289	pvid = br_get_pvid(vg);
290	for (vid = range_start->vid; vid <= range_end->vid; vid++) {
291		bool changed = false;
292
293		v = br_vlan_find(vg, vid);
294		if (!v || !br_vlan_should_use(v)) {
295			NL_SET_ERR_MSG_MOD(extack, "Vlan in range doesn't exist, can't process options");
296			err = -ENOENT;
297			break;
298		}
299
300		err = br_vlan_process_one_opts(br, p, vg, v, tb, &changed,
301					       extack);
302		if (err)
303			break;
304
305		if (changed) {
306			/* vlan options changed, check for range */
307			if (!curr_start) {
308				curr_start = v;
309				curr_end = v;
310				continue;
311			}
312
313			if (v->vid == pvid ||
314			    !br_vlan_can_enter_range(v, curr_end)) {
315				br_vlan_notify(br, p, curr_start->vid,
316					       curr_end->vid, RTM_NEWVLAN);
317				curr_start = v;
318			}
319			curr_end = v;
320		} else {
321			/* nothing changed and nothing to notify yet */
322			if (!curr_start)
323				continue;
324
325			br_vlan_notify(br, p, curr_start->vid, curr_end->vid,
326				       RTM_NEWVLAN);
327			curr_start = NULL;
328			curr_end = NULL;
329		}
330	}
331	if (curr_start)
332		br_vlan_notify(br, p, curr_start->vid, curr_end->vid,
333			       RTM_NEWVLAN);
334
335	return err;
336}
337
338bool br_vlan_global_opts_can_enter_range(const struct net_bridge_vlan *v_curr,
339					 const struct net_bridge_vlan *r_end)
340{
341	return v_curr->vid - r_end->vid == 1 &&
342		v_curr->msti == r_end->msti &&
343	       ((v_curr->priv_flags ^ r_end->priv_flags) &
344		BR_VLFLAG_GLOBAL_MCAST_ENABLED) == 0 &&
345		br_multicast_ctx_options_equal(&v_curr->br_mcast_ctx,
346					       &r_end->br_mcast_ctx);
347}
348
349bool br_vlan_global_opts_fill(struct sk_buff *skb, u16 vid, u16 vid_range,
350			      const struct net_bridge_vlan *v_opts)
351{
352	struct nlattr *nest2 __maybe_unused;
353	u64 clockval __maybe_unused;
354	struct nlattr *nest;
355
356	nest = nla_nest_start(skb, BRIDGE_VLANDB_GLOBAL_OPTIONS);
357	if (!nest)
358		return false;
359
360	if (nla_put_u16(skb, BRIDGE_VLANDB_GOPTS_ID, vid))
361		goto out_err;
362
363	if (vid_range && vid < vid_range &&
364	    nla_put_u16(skb, BRIDGE_VLANDB_GOPTS_RANGE, vid_range))
365		goto out_err;
366
367#ifdef CONFIG_BRIDGE_IGMP_SNOOPING
368	if (nla_put_u8(skb, BRIDGE_VLANDB_GOPTS_MCAST_SNOOPING,
369		       !!(v_opts->priv_flags & BR_VLFLAG_GLOBAL_MCAST_ENABLED)) ||
370	    nla_put_u8(skb, BRIDGE_VLANDB_GOPTS_MCAST_IGMP_VERSION,
371		       v_opts->br_mcast_ctx.multicast_igmp_version) ||
372	    nla_put_u32(skb, BRIDGE_VLANDB_GOPTS_MCAST_LAST_MEMBER_CNT,
373			v_opts->br_mcast_ctx.multicast_last_member_count) ||
374	    nla_put_u32(skb, BRIDGE_VLANDB_GOPTS_MCAST_STARTUP_QUERY_CNT,
375			v_opts->br_mcast_ctx.multicast_startup_query_count) ||
376	    nla_put_u8(skb, BRIDGE_VLANDB_GOPTS_MCAST_QUERIER,
377		       v_opts->br_mcast_ctx.multicast_querier) ||
378	    br_multicast_dump_querier_state(skb, &v_opts->br_mcast_ctx,
379					    BRIDGE_VLANDB_GOPTS_MCAST_QUERIER_STATE))
380		goto out_err;
381
382	clockval = jiffies_to_clock_t(v_opts->br_mcast_ctx.multicast_last_member_interval);
383	if (nla_put_u64_64bit(skb, BRIDGE_VLANDB_GOPTS_MCAST_LAST_MEMBER_INTVL,
384			      clockval, BRIDGE_VLANDB_GOPTS_PAD))
385		goto out_err;
386	clockval = jiffies_to_clock_t(v_opts->br_mcast_ctx.multicast_membership_interval);
387	if (nla_put_u64_64bit(skb, BRIDGE_VLANDB_GOPTS_MCAST_MEMBERSHIP_INTVL,
388			      clockval, BRIDGE_VLANDB_GOPTS_PAD))
389		goto out_err;
390	clockval = jiffies_to_clock_t(v_opts->br_mcast_ctx.multicast_querier_interval);
391	if (nla_put_u64_64bit(skb, BRIDGE_VLANDB_GOPTS_MCAST_QUERIER_INTVL,
392			      clockval, BRIDGE_VLANDB_GOPTS_PAD))
393		goto out_err;
394	clockval = jiffies_to_clock_t(v_opts->br_mcast_ctx.multicast_query_interval);
395	if (nla_put_u64_64bit(skb, BRIDGE_VLANDB_GOPTS_MCAST_QUERY_INTVL,
396			      clockval, BRIDGE_VLANDB_GOPTS_PAD))
397		goto out_err;
398	clockval = jiffies_to_clock_t(v_opts->br_mcast_ctx.multicast_query_response_interval);
399	if (nla_put_u64_64bit(skb, BRIDGE_VLANDB_GOPTS_MCAST_QUERY_RESPONSE_INTVL,
400			      clockval, BRIDGE_VLANDB_GOPTS_PAD))
401		goto out_err;
402	clockval = jiffies_to_clock_t(v_opts->br_mcast_ctx.multicast_startup_query_interval);
403	if (nla_put_u64_64bit(skb, BRIDGE_VLANDB_GOPTS_MCAST_STARTUP_QUERY_INTVL,
404			      clockval, BRIDGE_VLANDB_GOPTS_PAD))
405		goto out_err;
406
407	if (br_rports_have_mc_router(&v_opts->br_mcast_ctx)) {
408		nest2 = nla_nest_start(skb,
409				       BRIDGE_VLANDB_GOPTS_MCAST_ROUTER_PORTS);
410		if (!nest2)
411			goto out_err;
412
413		rcu_read_lock();
414		if (br_rports_fill_info(skb, &v_opts->br_mcast_ctx)) {
415			rcu_read_unlock();
416			nla_nest_cancel(skb, nest2);
417			goto out_err;
418		}
419		rcu_read_unlock();
420
421		nla_nest_end(skb, nest2);
422	}
423
424#if IS_ENABLED(CONFIG_IPV6)
425	if (nla_put_u8(skb, BRIDGE_VLANDB_GOPTS_MCAST_MLD_VERSION,
426		       v_opts->br_mcast_ctx.multicast_mld_version))
427		goto out_err;
428#endif
429#endif
430
431	if (nla_put_u16(skb, BRIDGE_VLANDB_GOPTS_MSTI, v_opts->msti))
432		goto out_err;
433
434	nla_nest_end(skb, nest);
435
436	return true;
437
438out_err:
439	nla_nest_cancel(skb, nest);
440	return false;
441}
442
443static size_t rtnl_vlan_global_opts_nlmsg_size(const struct net_bridge_vlan *v)
444{
445	return NLMSG_ALIGN(sizeof(struct br_vlan_msg))
446		+ nla_total_size(0) /* BRIDGE_VLANDB_GLOBAL_OPTIONS */
447		+ nla_total_size(sizeof(u16)) /* BRIDGE_VLANDB_GOPTS_ID */
448#ifdef CONFIG_BRIDGE_IGMP_SNOOPING
449		+ nla_total_size(sizeof(u8)) /* BRIDGE_VLANDB_GOPTS_MCAST_SNOOPING */
450		+ nla_total_size(sizeof(u8)) /* BRIDGE_VLANDB_GOPTS_MCAST_IGMP_VERSION */
451		+ nla_total_size(sizeof(u8)) /* BRIDGE_VLANDB_GOPTS_MCAST_MLD_VERSION */
452		+ nla_total_size(sizeof(u32)) /* BRIDGE_VLANDB_GOPTS_MCAST_LAST_MEMBER_CNT */
453		+ nla_total_size(sizeof(u32)) /* BRIDGE_VLANDB_GOPTS_MCAST_STARTUP_QUERY_CNT */
454		+ nla_total_size(sizeof(u64)) /* BRIDGE_VLANDB_GOPTS_MCAST_LAST_MEMBER_INTVL */
455		+ nla_total_size(sizeof(u64)) /* BRIDGE_VLANDB_GOPTS_MCAST_MEMBERSHIP_INTVL */
456		+ nla_total_size(sizeof(u64)) /* BRIDGE_VLANDB_GOPTS_MCAST_QUERIER_INTVL */
457		+ nla_total_size(sizeof(u64)) /* BRIDGE_VLANDB_GOPTS_MCAST_QUERY_INTVL */
458		+ nla_total_size(sizeof(u64)) /* BRIDGE_VLANDB_GOPTS_MCAST_QUERY_RESPONSE_INTVL */
459		+ nla_total_size(sizeof(u64)) /* BRIDGE_VLANDB_GOPTS_MCAST_STARTUP_QUERY_INTVL */
460		+ nla_total_size(sizeof(u8)) /* BRIDGE_VLANDB_GOPTS_MCAST_QUERIER */
461		+ br_multicast_querier_state_size() /* BRIDGE_VLANDB_GOPTS_MCAST_QUERIER_STATE */
462		+ nla_total_size(0) /* BRIDGE_VLANDB_GOPTS_MCAST_ROUTER_PORTS */
463		+ br_rports_size(&v->br_mcast_ctx) /* BRIDGE_VLANDB_GOPTS_MCAST_ROUTER_PORTS */
464#endif
465		+ nla_total_size(sizeof(u16)) /* BRIDGE_VLANDB_GOPTS_MSTI */
466		+ nla_total_size(sizeof(u16)); /* BRIDGE_VLANDB_GOPTS_RANGE */
467}
468
469static void br_vlan_global_opts_notify(const struct net_bridge *br,
470				       u16 vid, u16 vid_range)
471{
472	struct net_bridge_vlan *v;
473	struct br_vlan_msg *bvm;
474	struct nlmsghdr *nlh;
475	struct sk_buff *skb;
476	int err = -ENOBUFS;
477
478	/* right now notifications are done only with rtnl held */
479	ASSERT_RTNL();
480
481	/* need to find the vlan due to flags/options */
482	v = br_vlan_find(br_vlan_group(br), vid);
483	if (!v)
484		return;
485
486	skb = nlmsg_new(rtnl_vlan_global_opts_nlmsg_size(v), GFP_KERNEL);
487	if (!skb)
488		goto out_err;
489
490	err = -EMSGSIZE;
491	nlh = nlmsg_put(skb, 0, 0, RTM_NEWVLAN, sizeof(*bvm), 0);
492	if (!nlh)
493		goto out_err;
494	bvm = nlmsg_data(nlh);
495	memset(bvm, 0, sizeof(*bvm));
496	bvm->family = AF_BRIDGE;
497	bvm->ifindex = br->dev->ifindex;
498
499	if (!br_vlan_global_opts_fill(skb, vid, vid_range, v))
500		goto out_err;
501
502	nlmsg_end(skb, nlh);
503	rtnl_notify(skb, dev_net(br->dev), 0, RTNLGRP_BRVLAN, NULL, GFP_KERNEL);
504	return;
505
506out_err:
507	rtnl_set_sk_err(dev_net(br->dev), RTNLGRP_BRVLAN, err);
508	kfree_skb(skb);
509}
510
511static int br_vlan_process_global_one_opts(const struct net_bridge *br,
512					   struct net_bridge_vlan_group *vg,
513					   struct net_bridge_vlan *v,
514					   struct nlattr **tb,
515					   bool *changed,
516					   struct netlink_ext_ack *extack)
517{
518	int err __maybe_unused;
519
520	*changed = false;
521#ifdef CONFIG_BRIDGE_IGMP_SNOOPING
522	if (tb[BRIDGE_VLANDB_GOPTS_MCAST_SNOOPING]) {
523		u8 mc_snooping;
524
525		mc_snooping = nla_get_u8(tb[BRIDGE_VLANDB_GOPTS_MCAST_SNOOPING]);
526		if (br_multicast_toggle_global_vlan(v, !!mc_snooping))
527			*changed = true;
528	}
529	if (tb[BRIDGE_VLANDB_GOPTS_MCAST_IGMP_VERSION]) {
530		u8 ver;
531
532		ver = nla_get_u8(tb[BRIDGE_VLANDB_GOPTS_MCAST_IGMP_VERSION]);
533		err = br_multicast_set_igmp_version(&v->br_mcast_ctx, ver);
534		if (err)
535			return err;
536		*changed = true;
537	}
538	if (tb[BRIDGE_VLANDB_GOPTS_MCAST_LAST_MEMBER_CNT]) {
539		u32 cnt;
540
541		cnt = nla_get_u32(tb[BRIDGE_VLANDB_GOPTS_MCAST_LAST_MEMBER_CNT]);
542		v->br_mcast_ctx.multicast_last_member_count = cnt;
543		*changed = true;
544	}
545	if (tb[BRIDGE_VLANDB_GOPTS_MCAST_STARTUP_QUERY_CNT]) {
546		u32 cnt;
547
548		cnt = nla_get_u32(tb[BRIDGE_VLANDB_GOPTS_MCAST_STARTUP_QUERY_CNT]);
549		v->br_mcast_ctx.multicast_startup_query_count = cnt;
550		*changed = true;
551	}
552	if (tb[BRIDGE_VLANDB_GOPTS_MCAST_LAST_MEMBER_INTVL]) {
553		u64 val;
554
555		val = nla_get_u64(tb[BRIDGE_VLANDB_GOPTS_MCAST_LAST_MEMBER_INTVL]);
556		v->br_mcast_ctx.multicast_last_member_interval = clock_t_to_jiffies(val);
557		*changed = true;
558	}
559	if (tb[BRIDGE_VLANDB_GOPTS_MCAST_MEMBERSHIP_INTVL]) {
560		u64 val;
561
562		val = nla_get_u64(tb[BRIDGE_VLANDB_GOPTS_MCAST_MEMBERSHIP_INTVL]);
563		v->br_mcast_ctx.multicast_membership_interval = clock_t_to_jiffies(val);
564		*changed = true;
565	}
566	if (tb[BRIDGE_VLANDB_GOPTS_MCAST_QUERIER_INTVL]) {
567		u64 val;
568
569		val = nla_get_u64(tb[BRIDGE_VLANDB_GOPTS_MCAST_QUERIER_INTVL]);
570		v->br_mcast_ctx.multicast_querier_interval = clock_t_to_jiffies(val);
571		*changed = true;
572	}
573	if (tb[BRIDGE_VLANDB_GOPTS_MCAST_QUERY_INTVL]) {
574		u64 val;
575
576		val = nla_get_u64(tb[BRIDGE_VLANDB_GOPTS_MCAST_QUERY_INTVL]);
577		br_multicast_set_query_intvl(&v->br_mcast_ctx, val);
578		*changed = true;
579	}
580	if (tb[BRIDGE_VLANDB_GOPTS_MCAST_QUERY_RESPONSE_INTVL]) {
581		u64 val;
582
583		val = nla_get_u64(tb[BRIDGE_VLANDB_GOPTS_MCAST_QUERY_RESPONSE_INTVL]);
584		v->br_mcast_ctx.multicast_query_response_interval = clock_t_to_jiffies(val);
585		*changed = true;
586	}
587	if (tb[BRIDGE_VLANDB_GOPTS_MCAST_STARTUP_QUERY_INTVL]) {
588		u64 val;
589
590		val = nla_get_u64(tb[BRIDGE_VLANDB_GOPTS_MCAST_STARTUP_QUERY_INTVL]);
591		br_multicast_set_startup_query_intvl(&v->br_mcast_ctx, val);
592		*changed = true;
593	}
594	if (tb[BRIDGE_VLANDB_GOPTS_MCAST_QUERIER]) {
595		u8 val;
596
597		val = nla_get_u8(tb[BRIDGE_VLANDB_GOPTS_MCAST_QUERIER]);
598		err = br_multicast_set_querier(&v->br_mcast_ctx, val);
599		if (err)
600			return err;
601		*changed = true;
602	}
603#if IS_ENABLED(CONFIG_IPV6)
604	if (tb[BRIDGE_VLANDB_GOPTS_MCAST_MLD_VERSION]) {
605		u8 ver;
606
607		ver = nla_get_u8(tb[BRIDGE_VLANDB_GOPTS_MCAST_MLD_VERSION]);
608		err = br_multicast_set_mld_version(&v->br_mcast_ctx, ver);
609		if (err)
610			return err;
611		*changed = true;
612	}
613#endif
614#endif
615	if (tb[BRIDGE_VLANDB_GOPTS_MSTI]) {
616		u16 msti;
617
618		msti = nla_get_u16(tb[BRIDGE_VLANDB_GOPTS_MSTI]);
619		err = br_mst_vlan_set_msti(v, msti);
620		if (err)
621			return err;
622		*changed = true;
623	}
624
625	return 0;
626}
627
628static const struct nla_policy br_vlan_db_gpol[BRIDGE_VLANDB_GOPTS_MAX + 1] = {
629	[BRIDGE_VLANDB_GOPTS_ID]	= { .type = NLA_U16 },
630	[BRIDGE_VLANDB_GOPTS_RANGE]	= { .type = NLA_U16 },
631	[BRIDGE_VLANDB_GOPTS_MCAST_SNOOPING]	= { .type = NLA_U8 },
632	[BRIDGE_VLANDB_GOPTS_MCAST_MLD_VERSION]	= { .type = NLA_U8 },
633	[BRIDGE_VLANDB_GOPTS_MCAST_QUERY_INTVL]	= { .type = NLA_U64 },
634	[BRIDGE_VLANDB_GOPTS_MCAST_QUERIER]	= { .type = NLA_U8 },
635	[BRIDGE_VLANDB_GOPTS_MCAST_IGMP_VERSION]	= { .type = NLA_U8 },
636	[BRIDGE_VLANDB_GOPTS_MCAST_LAST_MEMBER_CNT]	= { .type = NLA_U32 },
637	[BRIDGE_VLANDB_GOPTS_MCAST_STARTUP_QUERY_CNT]	= { .type = NLA_U32 },
638	[BRIDGE_VLANDB_GOPTS_MCAST_LAST_MEMBER_INTVL]	= { .type = NLA_U64 },
639	[BRIDGE_VLANDB_GOPTS_MCAST_MEMBERSHIP_INTVL]	= { .type = NLA_U64 },
640	[BRIDGE_VLANDB_GOPTS_MCAST_QUERIER_INTVL]	= { .type = NLA_U64 },
641	[BRIDGE_VLANDB_GOPTS_MCAST_STARTUP_QUERY_INTVL]	= { .type = NLA_U64 },
642	[BRIDGE_VLANDB_GOPTS_MCAST_QUERY_RESPONSE_INTVL] = { .type = NLA_U64 },
643	[BRIDGE_VLANDB_GOPTS_MSTI] = NLA_POLICY_MAX(NLA_U16, VLAN_N_VID - 1),
644};
645
646int br_vlan_rtm_process_global_options(struct net_device *dev,
647				       const struct nlattr *attr,
648				       int cmd,
649				       struct netlink_ext_ack *extack)
650{
651	struct net_bridge_vlan *v, *curr_start = NULL, *curr_end = NULL;
652	struct nlattr *tb[BRIDGE_VLANDB_GOPTS_MAX + 1];
653	struct net_bridge_vlan_group *vg;
654	u16 vid, vid_range = 0;
655	struct net_bridge *br;
656	int err = 0;
657
658	if (cmd != RTM_NEWVLAN) {
659		NL_SET_ERR_MSG_MOD(extack, "Global vlan options support only set operation");
660		return -EINVAL;
661	}
662	if (!netif_is_bridge_master(dev)) {
663		NL_SET_ERR_MSG_MOD(extack, "Global vlan options can only be set on bridge device");
664		return -EINVAL;
665	}
666	br = netdev_priv(dev);
667	vg = br_vlan_group(br);
668	if (WARN_ON(!vg))
669		return -ENODEV;
670
671	err = nla_parse_nested(tb, BRIDGE_VLANDB_GOPTS_MAX, attr,
672			       br_vlan_db_gpol, extack);
673	if (err)
674		return err;
675
676	if (!tb[BRIDGE_VLANDB_GOPTS_ID]) {
677		NL_SET_ERR_MSG_MOD(extack, "Missing vlan entry id");
678		return -EINVAL;
679	}
680	vid = nla_get_u16(tb[BRIDGE_VLANDB_GOPTS_ID]);
681	if (!br_vlan_valid_id(vid, extack))
682		return -EINVAL;
683
684	if (tb[BRIDGE_VLANDB_GOPTS_RANGE]) {
685		vid_range = nla_get_u16(tb[BRIDGE_VLANDB_GOPTS_RANGE]);
686		if (!br_vlan_valid_id(vid_range, extack))
687			return -EINVAL;
688		if (vid >= vid_range) {
689			NL_SET_ERR_MSG_MOD(extack, "End vlan id is less than or equal to start vlan id");
690			return -EINVAL;
691		}
692	} else {
693		vid_range = vid;
694	}
695
696	for (; vid <= vid_range; vid++) {
697		bool changed = false;
698
699		v = br_vlan_find(vg, vid);
700		if (!v) {
701			NL_SET_ERR_MSG_MOD(extack, "Vlan in range doesn't exist, can't process global options");
702			err = -ENOENT;
703			break;
704		}
705
706		err = br_vlan_process_global_one_opts(br, vg, v, tb, &changed,
707						      extack);
708		if (err)
709			break;
710
711		if (changed) {
712			/* vlan options changed, check for range */
713			if (!curr_start) {
714				curr_start = v;
715				curr_end = v;
716				continue;
717			}
718
719			if (!br_vlan_global_opts_can_enter_range(v, curr_end)) {
720				br_vlan_global_opts_notify(br, curr_start->vid,
721							   curr_end->vid);
722				curr_start = v;
723			}
724			curr_end = v;
725		} else {
726			/* nothing changed and nothing to notify yet */
727			if (!curr_start)
728				continue;
729
730			br_vlan_global_opts_notify(br, curr_start->vid,
731						   curr_end->vid);
732			curr_start = NULL;
733			curr_end = NULL;
734		}
735	}
736	if (curr_start)
737		br_vlan_global_opts_notify(br, curr_start->vid, curr_end->vid);
738
739	return err;
740}
v6.2
  1// SPDX-License-Identifier: GPL-2.0-only
  2// Copyright (c) 2020, Nikolay Aleksandrov <nikolay@cumulusnetworks.com>
  3#include <linux/kernel.h>
  4#include <linux/netdevice.h>
  5#include <linux/rtnetlink.h>
  6#include <linux/slab.h>
  7#include <net/ip_tunnels.h>
  8
  9#include "br_private.h"
 10#include "br_private_tunnel.h"
 11
 12static bool __vlan_tun_put(struct sk_buff *skb, const struct net_bridge_vlan *v)
 13{
 14	__be32 tid = tunnel_id_to_key32(v->tinfo.tunnel_id);
 15	struct nlattr *nest;
 16
 17	if (!v->tinfo.tunnel_dst)
 18		return true;
 19
 20	nest = nla_nest_start(skb, BRIDGE_VLANDB_ENTRY_TUNNEL_INFO);
 21	if (!nest)
 22		return false;
 23	if (nla_put_u32(skb, BRIDGE_VLANDB_TINFO_ID, be32_to_cpu(tid))) {
 24		nla_nest_cancel(skb, nest);
 25		return false;
 26	}
 27	nla_nest_end(skb, nest);
 28
 29	return true;
 30}
 31
 32static bool __vlan_tun_can_enter_range(const struct net_bridge_vlan *v_curr,
 33				       const struct net_bridge_vlan *range_end)
 34{
 35	return (!v_curr->tinfo.tunnel_dst && !range_end->tinfo.tunnel_dst) ||
 36	       vlan_tunid_inrange(v_curr, range_end);
 37}
 38
 39/* check if the options' state of v_curr allow it to enter the range */
 40bool br_vlan_opts_eq_range(const struct net_bridge_vlan *v_curr,
 41			   const struct net_bridge_vlan *range_end)
 42{
 43	u8 range_mc_rtr = br_vlan_multicast_router(range_end);
 44	u8 curr_mc_rtr = br_vlan_multicast_router(v_curr);
 45
 46	return v_curr->state == range_end->state &&
 47	       __vlan_tun_can_enter_range(v_curr, range_end) &&
 48	       curr_mc_rtr == range_mc_rtr;
 49}
 50
 51bool br_vlan_opts_fill(struct sk_buff *skb, const struct net_bridge_vlan *v)
 
 52{
 53	if (nla_put_u8(skb, BRIDGE_VLANDB_ENTRY_STATE, br_vlan_get_state(v)) ||
 54	    !__vlan_tun_put(skb, v))
 
 
 55		return false;
 56
 57#ifdef CONFIG_BRIDGE_IGMP_SNOOPING
 58	if (nla_put_u8(skb, BRIDGE_VLANDB_ENTRY_MCAST_ROUTER,
 59		       br_vlan_multicast_router(v)))
 60		return false;
 
 
 
 
 
 
 61#endif
 62
 63	return true;
 64}
 65
 66size_t br_vlan_opts_nl_size(void)
 67{
 68	return nla_total_size(sizeof(u8)) /* BRIDGE_VLANDB_ENTRY_STATE */
 69	       + nla_total_size(0) /* BRIDGE_VLANDB_ENTRY_TUNNEL_INFO */
 70	       + nla_total_size(sizeof(u32)) /* BRIDGE_VLANDB_TINFO_ID */
 71#ifdef CONFIG_BRIDGE_IGMP_SNOOPING
 72	       + nla_total_size(sizeof(u8)) /* BRIDGE_VLANDB_ENTRY_MCAST_ROUTER */
 
 
 73#endif
 
 74	       + 0;
 75}
 76
 77static int br_vlan_modify_state(struct net_bridge_vlan_group *vg,
 78				struct net_bridge_vlan *v,
 79				u8 state,
 80				bool *changed,
 81				struct netlink_ext_ack *extack)
 82{
 83	struct net_bridge *br;
 84
 85	ASSERT_RTNL();
 86
 87	if (state > BR_STATE_BLOCKING) {
 88		NL_SET_ERR_MSG_MOD(extack, "Invalid vlan state");
 89		return -EINVAL;
 90	}
 91
 92	if (br_vlan_is_brentry(v))
 93		br = v->br;
 94	else
 95		br = v->port->br;
 96
 97	if (br->stp_enabled == BR_KERNEL_STP) {
 98		NL_SET_ERR_MSG_MOD(extack, "Can't modify vlan state when using kernel STP");
 99		return -EBUSY;
100	}
101
102	if (br_opt_get(br, BROPT_MST_ENABLED)) {
103		NL_SET_ERR_MSG_MOD(extack, "Can't modify vlan state directly when MST is enabled");
104		return -EBUSY;
105	}
106
107	if (v->state == state)
108		return 0;
109
110	if (v->vid == br_get_pvid(vg))
111		br_vlan_set_pvid_state(vg, state);
112
113	br_vlan_set_state(v, state);
114	*changed = true;
115
116	return 0;
117}
118
119static const struct nla_policy br_vlandb_tinfo_pol[BRIDGE_VLANDB_TINFO_MAX + 1] = {
120	[BRIDGE_VLANDB_TINFO_ID]	= { .type = NLA_U32 },
121	[BRIDGE_VLANDB_TINFO_CMD]	= { .type = NLA_U32 },
122};
123
124static int br_vlan_modify_tunnel(const struct net_bridge_port *p,
125				 struct net_bridge_vlan *v,
126				 struct nlattr **tb,
127				 bool *changed,
128				 struct netlink_ext_ack *extack)
129{
130	struct nlattr *tun_tb[BRIDGE_VLANDB_TINFO_MAX + 1], *attr;
131	struct bridge_vlan_info *vinfo;
132	u32 tun_id = 0;
133	int cmd, err;
134
135	if (!p) {
136		NL_SET_ERR_MSG_MOD(extack, "Can't modify tunnel mapping of non-port vlans");
137		return -EINVAL;
138	}
139	if (!(p->flags & BR_VLAN_TUNNEL)) {
140		NL_SET_ERR_MSG_MOD(extack, "Port doesn't have tunnel flag set");
141		return -EINVAL;
142	}
143
144	attr = tb[BRIDGE_VLANDB_ENTRY_TUNNEL_INFO];
145	err = nla_parse_nested(tun_tb, BRIDGE_VLANDB_TINFO_MAX, attr,
146			       br_vlandb_tinfo_pol, extack);
147	if (err)
148		return err;
149
150	if (!tun_tb[BRIDGE_VLANDB_TINFO_CMD]) {
151		NL_SET_ERR_MSG_MOD(extack, "Missing tunnel command attribute");
152		return -ENOENT;
153	}
154	cmd = nla_get_u32(tun_tb[BRIDGE_VLANDB_TINFO_CMD]);
155	switch (cmd) {
156	case RTM_SETLINK:
157		if (!tun_tb[BRIDGE_VLANDB_TINFO_ID]) {
158			NL_SET_ERR_MSG_MOD(extack, "Missing tunnel id attribute");
159			return -ENOENT;
160		}
161		/* when working on vlan ranges this is the starting tunnel id */
162		tun_id = nla_get_u32(tun_tb[BRIDGE_VLANDB_TINFO_ID]);
163		/* vlan info attr is guaranteed by br_vlan_rtm_process_one */
164		vinfo = nla_data(tb[BRIDGE_VLANDB_ENTRY_INFO]);
165		/* tunnel ids are mapped to each vlan in increasing order,
166		 * the starting vlan is in BRIDGE_VLANDB_ENTRY_INFO and v is the
167		 * current vlan, so we compute: tun_id + v - vinfo->vid
168		 */
169		tun_id += v->vid - vinfo->vid;
170		break;
171	case RTM_DELLINK:
172		break;
173	default:
174		NL_SET_ERR_MSG_MOD(extack, "Unsupported tunnel command");
175		return -EINVAL;
176	}
177
178	return br_vlan_tunnel_info(p, cmd, v->vid, tun_id, changed);
179}
180
181static int br_vlan_process_one_opts(const struct net_bridge *br,
182				    const struct net_bridge_port *p,
183				    struct net_bridge_vlan_group *vg,
184				    struct net_bridge_vlan *v,
185				    struct nlattr **tb,
186				    bool *changed,
187				    struct netlink_ext_ack *extack)
188{
189	int err;
190
191	*changed = false;
192	if (tb[BRIDGE_VLANDB_ENTRY_STATE]) {
193		u8 state = nla_get_u8(tb[BRIDGE_VLANDB_ENTRY_STATE]);
194
195		err = br_vlan_modify_state(vg, v, state, changed, extack);
196		if (err)
197			return err;
198	}
199	if (tb[BRIDGE_VLANDB_ENTRY_TUNNEL_INFO]) {
200		err = br_vlan_modify_tunnel(p, v, tb, changed, extack);
201		if (err)
202			return err;
203	}
204
205#ifdef CONFIG_BRIDGE_IGMP_SNOOPING
206	if (tb[BRIDGE_VLANDB_ENTRY_MCAST_ROUTER]) {
207		u8 val;
208
209		val = nla_get_u8(tb[BRIDGE_VLANDB_ENTRY_MCAST_ROUTER]);
210		err = br_multicast_set_vlan_router(v, val);
211		if (err)
212			return err;
213		*changed = true;
214	}
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
215#endif
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
216
217	return 0;
218}
219
220int br_vlan_process_options(const struct net_bridge *br,
221			    const struct net_bridge_port *p,
222			    struct net_bridge_vlan *range_start,
223			    struct net_bridge_vlan *range_end,
224			    struct nlattr **tb,
225			    struct netlink_ext_ack *extack)
226{
227	struct net_bridge_vlan *v, *curr_start = NULL, *curr_end = NULL;
228	struct net_bridge_vlan_group *vg;
229	int vid, err = 0;
230	u16 pvid;
231
232	if (p)
233		vg = nbp_vlan_group(p);
234	else
235		vg = br_vlan_group(br);
236
237	if (!range_start || !br_vlan_should_use(range_start)) {
238		NL_SET_ERR_MSG_MOD(extack, "Vlan range start doesn't exist, can't process options");
239		return -ENOENT;
240	}
241	if (!range_end || !br_vlan_should_use(range_end)) {
242		NL_SET_ERR_MSG_MOD(extack, "Vlan range end doesn't exist, can't process options");
243		return -ENOENT;
244	}
245
246	pvid = br_get_pvid(vg);
247	for (vid = range_start->vid; vid <= range_end->vid; vid++) {
248		bool changed = false;
249
250		v = br_vlan_find(vg, vid);
251		if (!v || !br_vlan_should_use(v)) {
252			NL_SET_ERR_MSG_MOD(extack, "Vlan in range doesn't exist, can't process options");
253			err = -ENOENT;
254			break;
255		}
256
257		err = br_vlan_process_one_opts(br, p, vg, v, tb, &changed,
258					       extack);
259		if (err)
260			break;
261
262		if (changed) {
263			/* vlan options changed, check for range */
264			if (!curr_start) {
265				curr_start = v;
266				curr_end = v;
267				continue;
268			}
269
270			if (v->vid == pvid ||
271			    !br_vlan_can_enter_range(v, curr_end)) {
272				br_vlan_notify(br, p, curr_start->vid,
273					       curr_end->vid, RTM_NEWVLAN);
274				curr_start = v;
275			}
276			curr_end = v;
277		} else {
278			/* nothing changed and nothing to notify yet */
279			if (!curr_start)
280				continue;
281
282			br_vlan_notify(br, p, curr_start->vid, curr_end->vid,
283				       RTM_NEWVLAN);
284			curr_start = NULL;
285			curr_end = NULL;
286		}
287	}
288	if (curr_start)
289		br_vlan_notify(br, p, curr_start->vid, curr_end->vid,
290			       RTM_NEWVLAN);
291
292	return err;
293}
294
295bool br_vlan_global_opts_can_enter_range(const struct net_bridge_vlan *v_curr,
296					 const struct net_bridge_vlan *r_end)
297{
298	return v_curr->vid - r_end->vid == 1 &&
299		v_curr->msti == r_end->msti &&
300	       ((v_curr->priv_flags ^ r_end->priv_flags) &
301		BR_VLFLAG_GLOBAL_MCAST_ENABLED) == 0 &&
302		br_multicast_ctx_options_equal(&v_curr->br_mcast_ctx,
303					       &r_end->br_mcast_ctx);
304}
305
306bool br_vlan_global_opts_fill(struct sk_buff *skb, u16 vid, u16 vid_range,
307			      const struct net_bridge_vlan *v_opts)
308{
309	struct nlattr *nest2 __maybe_unused;
310	u64 clockval __maybe_unused;
311	struct nlattr *nest;
312
313	nest = nla_nest_start(skb, BRIDGE_VLANDB_GLOBAL_OPTIONS);
314	if (!nest)
315		return false;
316
317	if (nla_put_u16(skb, BRIDGE_VLANDB_GOPTS_ID, vid))
318		goto out_err;
319
320	if (vid_range && vid < vid_range &&
321	    nla_put_u16(skb, BRIDGE_VLANDB_GOPTS_RANGE, vid_range))
322		goto out_err;
323
324#ifdef CONFIG_BRIDGE_IGMP_SNOOPING
325	if (nla_put_u8(skb, BRIDGE_VLANDB_GOPTS_MCAST_SNOOPING,
326		       !!(v_opts->priv_flags & BR_VLFLAG_GLOBAL_MCAST_ENABLED)) ||
327	    nla_put_u8(skb, BRIDGE_VLANDB_GOPTS_MCAST_IGMP_VERSION,
328		       v_opts->br_mcast_ctx.multicast_igmp_version) ||
329	    nla_put_u32(skb, BRIDGE_VLANDB_GOPTS_MCAST_LAST_MEMBER_CNT,
330			v_opts->br_mcast_ctx.multicast_last_member_count) ||
331	    nla_put_u32(skb, BRIDGE_VLANDB_GOPTS_MCAST_STARTUP_QUERY_CNT,
332			v_opts->br_mcast_ctx.multicast_startup_query_count) ||
333	    nla_put_u8(skb, BRIDGE_VLANDB_GOPTS_MCAST_QUERIER,
334		       v_opts->br_mcast_ctx.multicast_querier) ||
335	    br_multicast_dump_querier_state(skb, &v_opts->br_mcast_ctx,
336					    BRIDGE_VLANDB_GOPTS_MCAST_QUERIER_STATE))
337		goto out_err;
338
339	clockval = jiffies_to_clock_t(v_opts->br_mcast_ctx.multicast_last_member_interval);
340	if (nla_put_u64_64bit(skb, BRIDGE_VLANDB_GOPTS_MCAST_LAST_MEMBER_INTVL,
341			      clockval, BRIDGE_VLANDB_GOPTS_PAD))
342		goto out_err;
343	clockval = jiffies_to_clock_t(v_opts->br_mcast_ctx.multicast_membership_interval);
344	if (nla_put_u64_64bit(skb, BRIDGE_VLANDB_GOPTS_MCAST_MEMBERSHIP_INTVL,
345			      clockval, BRIDGE_VLANDB_GOPTS_PAD))
346		goto out_err;
347	clockval = jiffies_to_clock_t(v_opts->br_mcast_ctx.multicast_querier_interval);
348	if (nla_put_u64_64bit(skb, BRIDGE_VLANDB_GOPTS_MCAST_QUERIER_INTVL,
349			      clockval, BRIDGE_VLANDB_GOPTS_PAD))
350		goto out_err;
351	clockval = jiffies_to_clock_t(v_opts->br_mcast_ctx.multicast_query_interval);
352	if (nla_put_u64_64bit(skb, BRIDGE_VLANDB_GOPTS_MCAST_QUERY_INTVL,
353			      clockval, BRIDGE_VLANDB_GOPTS_PAD))
354		goto out_err;
355	clockval = jiffies_to_clock_t(v_opts->br_mcast_ctx.multicast_query_response_interval);
356	if (nla_put_u64_64bit(skb, BRIDGE_VLANDB_GOPTS_MCAST_QUERY_RESPONSE_INTVL,
357			      clockval, BRIDGE_VLANDB_GOPTS_PAD))
358		goto out_err;
359	clockval = jiffies_to_clock_t(v_opts->br_mcast_ctx.multicast_startup_query_interval);
360	if (nla_put_u64_64bit(skb, BRIDGE_VLANDB_GOPTS_MCAST_STARTUP_QUERY_INTVL,
361			      clockval, BRIDGE_VLANDB_GOPTS_PAD))
362		goto out_err;
363
364	if (br_rports_have_mc_router(&v_opts->br_mcast_ctx)) {
365		nest2 = nla_nest_start(skb,
366				       BRIDGE_VLANDB_GOPTS_MCAST_ROUTER_PORTS);
367		if (!nest2)
368			goto out_err;
369
370		rcu_read_lock();
371		if (br_rports_fill_info(skb, &v_opts->br_mcast_ctx)) {
372			rcu_read_unlock();
373			nla_nest_cancel(skb, nest2);
374			goto out_err;
375		}
376		rcu_read_unlock();
377
378		nla_nest_end(skb, nest2);
379	}
380
381#if IS_ENABLED(CONFIG_IPV6)
382	if (nla_put_u8(skb, BRIDGE_VLANDB_GOPTS_MCAST_MLD_VERSION,
383		       v_opts->br_mcast_ctx.multicast_mld_version))
384		goto out_err;
385#endif
386#endif
387
388	if (nla_put_u16(skb, BRIDGE_VLANDB_GOPTS_MSTI, v_opts->msti))
389		goto out_err;
390
391	nla_nest_end(skb, nest);
392
393	return true;
394
395out_err:
396	nla_nest_cancel(skb, nest);
397	return false;
398}
399
400static size_t rtnl_vlan_global_opts_nlmsg_size(const struct net_bridge_vlan *v)
401{
402	return NLMSG_ALIGN(sizeof(struct br_vlan_msg))
403		+ nla_total_size(0) /* BRIDGE_VLANDB_GLOBAL_OPTIONS */
404		+ nla_total_size(sizeof(u16)) /* BRIDGE_VLANDB_GOPTS_ID */
405#ifdef CONFIG_BRIDGE_IGMP_SNOOPING
406		+ nla_total_size(sizeof(u8)) /* BRIDGE_VLANDB_GOPTS_MCAST_SNOOPING */
407		+ nla_total_size(sizeof(u8)) /* BRIDGE_VLANDB_GOPTS_MCAST_IGMP_VERSION */
408		+ nla_total_size(sizeof(u8)) /* BRIDGE_VLANDB_GOPTS_MCAST_MLD_VERSION */
409		+ nla_total_size(sizeof(u32)) /* BRIDGE_VLANDB_GOPTS_MCAST_LAST_MEMBER_CNT */
410		+ nla_total_size(sizeof(u32)) /* BRIDGE_VLANDB_GOPTS_MCAST_STARTUP_QUERY_CNT */
411		+ nla_total_size(sizeof(u64)) /* BRIDGE_VLANDB_GOPTS_MCAST_LAST_MEMBER_INTVL */
412		+ nla_total_size(sizeof(u64)) /* BRIDGE_VLANDB_GOPTS_MCAST_MEMBERSHIP_INTVL */
413		+ nla_total_size(sizeof(u64)) /* BRIDGE_VLANDB_GOPTS_MCAST_QUERIER_INTVL */
414		+ nla_total_size(sizeof(u64)) /* BRIDGE_VLANDB_GOPTS_MCAST_QUERY_INTVL */
415		+ nla_total_size(sizeof(u64)) /* BRIDGE_VLANDB_GOPTS_MCAST_QUERY_RESPONSE_INTVL */
416		+ nla_total_size(sizeof(u64)) /* BRIDGE_VLANDB_GOPTS_MCAST_STARTUP_QUERY_INTVL */
417		+ nla_total_size(sizeof(u8)) /* BRIDGE_VLANDB_GOPTS_MCAST_QUERIER */
418		+ br_multicast_querier_state_size() /* BRIDGE_VLANDB_GOPTS_MCAST_QUERIER_STATE */
419		+ nla_total_size(0) /* BRIDGE_VLANDB_GOPTS_MCAST_ROUTER_PORTS */
420		+ br_rports_size(&v->br_mcast_ctx) /* BRIDGE_VLANDB_GOPTS_MCAST_ROUTER_PORTS */
421#endif
422		+ nla_total_size(sizeof(u16)) /* BRIDGE_VLANDB_GOPTS_MSTI */
423		+ nla_total_size(sizeof(u16)); /* BRIDGE_VLANDB_GOPTS_RANGE */
424}
425
426static void br_vlan_global_opts_notify(const struct net_bridge *br,
427				       u16 vid, u16 vid_range)
428{
429	struct net_bridge_vlan *v;
430	struct br_vlan_msg *bvm;
431	struct nlmsghdr *nlh;
432	struct sk_buff *skb;
433	int err = -ENOBUFS;
434
435	/* right now notifications are done only with rtnl held */
436	ASSERT_RTNL();
437
438	/* need to find the vlan due to flags/options */
439	v = br_vlan_find(br_vlan_group(br), vid);
440	if (!v)
441		return;
442
443	skb = nlmsg_new(rtnl_vlan_global_opts_nlmsg_size(v), GFP_KERNEL);
444	if (!skb)
445		goto out_err;
446
447	err = -EMSGSIZE;
448	nlh = nlmsg_put(skb, 0, 0, RTM_NEWVLAN, sizeof(*bvm), 0);
449	if (!nlh)
450		goto out_err;
451	bvm = nlmsg_data(nlh);
452	memset(bvm, 0, sizeof(*bvm));
453	bvm->family = AF_BRIDGE;
454	bvm->ifindex = br->dev->ifindex;
455
456	if (!br_vlan_global_opts_fill(skb, vid, vid_range, v))
457		goto out_err;
458
459	nlmsg_end(skb, nlh);
460	rtnl_notify(skb, dev_net(br->dev), 0, RTNLGRP_BRVLAN, NULL, GFP_KERNEL);
461	return;
462
463out_err:
464	rtnl_set_sk_err(dev_net(br->dev), RTNLGRP_BRVLAN, err);
465	kfree_skb(skb);
466}
467
468static int br_vlan_process_global_one_opts(const struct net_bridge *br,
469					   struct net_bridge_vlan_group *vg,
470					   struct net_bridge_vlan *v,
471					   struct nlattr **tb,
472					   bool *changed,
473					   struct netlink_ext_ack *extack)
474{
475	int err __maybe_unused;
476
477	*changed = false;
478#ifdef CONFIG_BRIDGE_IGMP_SNOOPING
479	if (tb[BRIDGE_VLANDB_GOPTS_MCAST_SNOOPING]) {
480		u8 mc_snooping;
481
482		mc_snooping = nla_get_u8(tb[BRIDGE_VLANDB_GOPTS_MCAST_SNOOPING]);
483		if (br_multicast_toggle_global_vlan(v, !!mc_snooping))
484			*changed = true;
485	}
486	if (tb[BRIDGE_VLANDB_GOPTS_MCAST_IGMP_VERSION]) {
487		u8 ver;
488
489		ver = nla_get_u8(tb[BRIDGE_VLANDB_GOPTS_MCAST_IGMP_VERSION]);
490		err = br_multicast_set_igmp_version(&v->br_mcast_ctx, ver);
491		if (err)
492			return err;
493		*changed = true;
494	}
495	if (tb[BRIDGE_VLANDB_GOPTS_MCAST_LAST_MEMBER_CNT]) {
496		u32 cnt;
497
498		cnt = nla_get_u32(tb[BRIDGE_VLANDB_GOPTS_MCAST_LAST_MEMBER_CNT]);
499		v->br_mcast_ctx.multicast_last_member_count = cnt;
500		*changed = true;
501	}
502	if (tb[BRIDGE_VLANDB_GOPTS_MCAST_STARTUP_QUERY_CNT]) {
503		u32 cnt;
504
505		cnt = nla_get_u32(tb[BRIDGE_VLANDB_GOPTS_MCAST_STARTUP_QUERY_CNT]);
506		v->br_mcast_ctx.multicast_startup_query_count = cnt;
507		*changed = true;
508	}
509	if (tb[BRIDGE_VLANDB_GOPTS_MCAST_LAST_MEMBER_INTVL]) {
510		u64 val;
511
512		val = nla_get_u64(tb[BRIDGE_VLANDB_GOPTS_MCAST_LAST_MEMBER_INTVL]);
513		v->br_mcast_ctx.multicast_last_member_interval = clock_t_to_jiffies(val);
514		*changed = true;
515	}
516	if (tb[BRIDGE_VLANDB_GOPTS_MCAST_MEMBERSHIP_INTVL]) {
517		u64 val;
518
519		val = nla_get_u64(tb[BRIDGE_VLANDB_GOPTS_MCAST_MEMBERSHIP_INTVL]);
520		v->br_mcast_ctx.multicast_membership_interval = clock_t_to_jiffies(val);
521		*changed = true;
522	}
523	if (tb[BRIDGE_VLANDB_GOPTS_MCAST_QUERIER_INTVL]) {
524		u64 val;
525
526		val = nla_get_u64(tb[BRIDGE_VLANDB_GOPTS_MCAST_QUERIER_INTVL]);
527		v->br_mcast_ctx.multicast_querier_interval = clock_t_to_jiffies(val);
528		*changed = true;
529	}
530	if (tb[BRIDGE_VLANDB_GOPTS_MCAST_QUERY_INTVL]) {
531		u64 val;
532
533		val = nla_get_u64(tb[BRIDGE_VLANDB_GOPTS_MCAST_QUERY_INTVL]);
534		br_multicast_set_query_intvl(&v->br_mcast_ctx, val);
535		*changed = true;
536	}
537	if (tb[BRIDGE_VLANDB_GOPTS_MCAST_QUERY_RESPONSE_INTVL]) {
538		u64 val;
539
540		val = nla_get_u64(tb[BRIDGE_VLANDB_GOPTS_MCAST_QUERY_RESPONSE_INTVL]);
541		v->br_mcast_ctx.multicast_query_response_interval = clock_t_to_jiffies(val);
542		*changed = true;
543	}
544	if (tb[BRIDGE_VLANDB_GOPTS_MCAST_STARTUP_QUERY_INTVL]) {
545		u64 val;
546
547		val = nla_get_u64(tb[BRIDGE_VLANDB_GOPTS_MCAST_STARTUP_QUERY_INTVL]);
548		br_multicast_set_startup_query_intvl(&v->br_mcast_ctx, val);
549		*changed = true;
550	}
551	if (tb[BRIDGE_VLANDB_GOPTS_MCAST_QUERIER]) {
552		u8 val;
553
554		val = nla_get_u8(tb[BRIDGE_VLANDB_GOPTS_MCAST_QUERIER]);
555		err = br_multicast_set_querier(&v->br_mcast_ctx, val);
556		if (err)
557			return err;
558		*changed = true;
559	}
560#if IS_ENABLED(CONFIG_IPV6)
561	if (tb[BRIDGE_VLANDB_GOPTS_MCAST_MLD_VERSION]) {
562		u8 ver;
563
564		ver = nla_get_u8(tb[BRIDGE_VLANDB_GOPTS_MCAST_MLD_VERSION]);
565		err = br_multicast_set_mld_version(&v->br_mcast_ctx, ver);
566		if (err)
567			return err;
568		*changed = true;
569	}
570#endif
571#endif
572	if (tb[BRIDGE_VLANDB_GOPTS_MSTI]) {
573		u16 msti;
574
575		msti = nla_get_u16(tb[BRIDGE_VLANDB_GOPTS_MSTI]);
576		err = br_mst_vlan_set_msti(v, msti);
577		if (err)
578			return err;
579		*changed = true;
580	}
581
582	return 0;
583}
584
585static const struct nla_policy br_vlan_db_gpol[BRIDGE_VLANDB_GOPTS_MAX + 1] = {
586	[BRIDGE_VLANDB_GOPTS_ID]	= { .type = NLA_U16 },
587	[BRIDGE_VLANDB_GOPTS_RANGE]	= { .type = NLA_U16 },
588	[BRIDGE_VLANDB_GOPTS_MCAST_SNOOPING]	= { .type = NLA_U8 },
589	[BRIDGE_VLANDB_GOPTS_MCAST_MLD_VERSION]	= { .type = NLA_U8 },
590	[BRIDGE_VLANDB_GOPTS_MCAST_QUERY_INTVL]	= { .type = NLA_U64 },
591	[BRIDGE_VLANDB_GOPTS_MCAST_QUERIER]	= { .type = NLA_U8 },
592	[BRIDGE_VLANDB_GOPTS_MCAST_IGMP_VERSION]	= { .type = NLA_U8 },
593	[BRIDGE_VLANDB_GOPTS_MCAST_LAST_MEMBER_CNT]	= { .type = NLA_U32 },
594	[BRIDGE_VLANDB_GOPTS_MCAST_STARTUP_QUERY_CNT]	= { .type = NLA_U32 },
595	[BRIDGE_VLANDB_GOPTS_MCAST_LAST_MEMBER_INTVL]	= { .type = NLA_U64 },
596	[BRIDGE_VLANDB_GOPTS_MCAST_MEMBERSHIP_INTVL]	= { .type = NLA_U64 },
597	[BRIDGE_VLANDB_GOPTS_MCAST_QUERIER_INTVL]	= { .type = NLA_U64 },
598	[BRIDGE_VLANDB_GOPTS_MCAST_STARTUP_QUERY_INTVL]	= { .type = NLA_U64 },
599	[BRIDGE_VLANDB_GOPTS_MCAST_QUERY_RESPONSE_INTVL] = { .type = NLA_U64 },
600	[BRIDGE_VLANDB_GOPTS_MSTI] = NLA_POLICY_MAX(NLA_U16, VLAN_N_VID - 1),
601};
602
603int br_vlan_rtm_process_global_options(struct net_device *dev,
604				       const struct nlattr *attr,
605				       int cmd,
606				       struct netlink_ext_ack *extack)
607{
608	struct net_bridge_vlan *v, *curr_start = NULL, *curr_end = NULL;
609	struct nlattr *tb[BRIDGE_VLANDB_GOPTS_MAX + 1];
610	struct net_bridge_vlan_group *vg;
611	u16 vid, vid_range = 0;
612	struct net_bridge *br;
613	int err = 0;
614
615	if (cmd != RTM_NEWVLAN) {
616		NL_SET_ERR_MSG_MOD(extack, "Global vlan options support only set operation");
617		return -EINVAL;
618	}
619	if (!netif_is_bridge_master(dev)) {
620		NL_SET_ERR_MSG_MOD(extack, "Global vlan options can only be set on bridge device");
621		return -EINVAL;
622	}
623	br = netdev_priv(dev);
624	vg = br_vlan_group(br);
625	if (WARN_ON(!vg))
626		return -ENODEV;
627
628	err = nla_parse_nested(tb, BRIDGE_VLANDB_GOPTS_MAX, attr,
629			       br_vlan_db_gpol, extack);
630	if (err)
631		return err;
632
633	if (!tb[BRIDGE_VLANDB_GOPTS_ID]) {
634		NL_SET_ERR_MSG_MOD(extack, "Missing vlan entry id");
635		return -EINVAL;
636	}
637	vid = nla_get_u16(tb[BRIDGE_VLANDB_GOPTS_ID]);
638	if (!br_vlan_valid_id(vid, extack))
639		return -EINVAL;
640
641	if (tb[BRIDGE_VLANDB_GOPTS_RANGE]) {
642		vid_range = nla_get_u16(tb[BRIDGE_VLANDB_GOPTS_RANGE]);
643		if (!br_vlan_valid_id(vid_range, extack))
644			return -EINVAL;
645		if (vid >= vid_range) {
646			NL_SET_ERR_MSG_MOD(extack, "End vlan id is less than or equal to start vlan id");
647			return -EINVAL;
648		}
649	} else {
650		vid_range = vid;
651	}
652
653	for (; vid <= vid_range; vid++) {
654		bool changed = false;
655
656		v = br_vlan_find(vg, vid);
657		if (!v) {
658			NL_SET_ERR_MSG_MOD(extack, "Vlan in range doesn't exist, can't process global options");
659			err = -ENOENT;
660			break;
661		}
662
663		err = br_vlan_process_global_one_opts(br, vg, v, tb, &changed,
664						      extack);
665		if (err)
666			break;
667
668		if (changed) {
669			/* vlan options changed, check for range */
670			if (!curr_start) {
671				curr_start = v;
672				curr_end = v;
673				continue;
674			}
675
676			if (!br_vlan_global_opts_can_enter_range(v, curr_end)) {
677				br_vlan_global_opts_notify(br, curr_start->vid,
678							   curr_end->vid);
679				curr_start = v;
680			}
681			curr_end = v;
682		} else {
683			/* nothing changed and nothing to notify yet */
684			if (!curr_start)
685				continue;
686
687			br_vlan_global_opts_notify(br, curr_start->vid,
688						   curr_end->vid);
689			curr_start = NULL;
690			curr_end = NULL;
691		}
692	}
693	if (curr_start)
694		br_vlan_global_opts_notify(br, curr_start->vid, curr_end->vid);
695
696	return err;
697}