]> git.ipfire.org Git - thirdparty/linux.git/commitdiff
bridge: No DEV_PATH_BR_VLAN_UNTAG_HW for dsa foreign
authorEric Woudstra <ericwouds@gmail.com>
Tue, 17 Mar 2026 11:03:47 +0000 (12:03 +0100)
committerPaolo Abeni <pabeni@redhat.com>
Thu, 19 Mar 2026 12:14:00 +0000 (13:14 +0100)
In network setup as below:

             fastpath bypass
 .----------------------------------------.
/                                          \
|                        IP - forwarding    |
|                       /                \  v
|                      /                  wan ...
|                     /
|                     |
|                     |
|                   brlan.1
|                     |
|    +-------------------------------+
|    |           vlan 1              |
|    |                               |
|    |     brlan (vlan-filtering)    |
|    |               +---------------+
|    |               |  DSA-SWITCH   |
|    |    vlan 1     |               |
|    |      to       |               |
|    |   untagged    1     vlan 1    |
|    +---------------+---------------+
.         /                   \
 ----->wlan1                 lan0
       .                       .
       .                       ^
       ^                     vlan 1 tagged packets
     untagged packets

br_vlan_fill_forward_path_mode() sets DEV_PATH_BR_VLAN_UNTAG_HW when
filling in from brlan.1 towards wlan1. But it should be set to
DEV_PATH_BR_VLAN_UNTAG in this case. Using BR_VLFLAG_ADDED_BY_SWITCHDEV
is not correct. The dsa switchdev adds it as a foreign port.

The same problem for all foreignly added dsa vlans on the bridge.

First add the vlan, trying only native devices.
If this fails, we know this may be a vlan from a foreign device.

Use BR_VLFLAG_TAGGING_BY_SWITCHDEV to make sure DEV_PATH_BR_VLAN_UNTAG_HW
is set only when there if no foreign device involved.

Acked-by: Nikolay Aleksandrov <razor@blackwall.org>
Signed-off-by: Eric Woudstra <ericwouds@gmail.com>
Link: https://patch.msgid.link/20260317110347.363875-1-ericwouds@gmail.com
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
include/net/switchdev.h
net/bridge/br_private.h
net/bridge/br_switchdev.c
net/bridge/br_vlan.c
net/switchdev/switchdev.c

index 8346b0d29542c3d5569b94b35eaa12461f78d62a..ee500706496b08cf49f23489f995ecc2d4126f88 100644 (file)
@@ -15,6 +15,7 @@
 #define SWITCHDEV_F_NO_RECURSE         BIT(0)
 #define SWITCHDEV_F_SKIP_EOPNOTSUPP    BIT(1)
 #define SWITCHDEV_F_DEFER              BIT(2)
+#define SWITCHDEV_F_NO_FOREIGN         BIT(3)
 
 enum switchdev_attr_id {
        SWITCHDEV_ATTR_ID_UNDEFINED,
index 9b55d38ea9edbf76c79c0dd3857c23f0f672b809..6dbca845e625dd4757967f124b8e7faef3c38e11 100644 (file)
@@ -182,6 +182,7 @@ enum {
        BR_VLFLAG_MCAST_ENABLED = BIT(2),
        BR_VLFLAG_GLOBAL_MCAST_ENABLED = BIT(3),
        BR_VLFLAG_NEIGH_SUPPRESS_ENABLED = BIT(4),
+       BR_VLFLAG_TAGGING_BY_SWITCHDEV = BIT(5),
 };
 
 /**
@@ -2234,6 +2235,8 @@ void br_switchdev_mdb_notify(struct net_device *dev,
                             int type);
 int br_switchdev_port_vlan_add(struct net_device *dev, u16 vid, u16 flags,
                               bool changed, struct netlink_ext_ack *extack);
+int br_switchdev_port_vlan_no_foreign_add(struct net_device *dev, u16 vid, u16 flags,
+                                         bool changed, struct netlink_ext_ack *extack);
 int br_switchdev_port_vlan_del(struct net_device *dev, u16 vid);
 void br_switchdev_init(struct net_bridge *br);
 
@@ -2317,6 +2320,13 @@ static inline int br_switchdev_port_vlan_add(struct net_device *dev, u16 vid,
        return -EOPNOTSUPP;
 }
 
+static inline int br_switchdev_port_vlan_no_foreign_add(struct net_device *dev, u16 vid,
+                                                       u16 flags, bool changed,
+                                                       struct netlink_ext_ack *extack)
+{
+       return -EOPNOTSUPP;
+}
+
 static inline int br_switchdev_port_vlan_del(struct net_device *dev, u16 vid)
 {
        return -EOPNOTSUPP;
index 4fac002922d22a80ba144f330569d354d039a662..18b558a931ad97c72b3abe7753df40b440d44466 100644 (file)
@@ -190,6 +190,21 @@ int br_switchdev_port_vlan_add(struct net_device *dev, u16 vid, u16 flags,
        return switchdev_port_obj_add(dev, &v.obj, extack);
 }
 
+int br_switchdev_port_vlan_no_foreign_add(struct net_device *dev, u16 vid, u16 flags,
+                                         bool changed, struct netlink_ext_ack *extack)
+{
+       struct switchdev_obj_port_vlan v = {
+               .obj.orig_dev = dev,
+               .obj.id = SWITCHDEV_OBJ_ID_PORT_VLAN,
+               .obj.flags = SWITCHDEV_F_NO_FOREIGN,
+               .flags = flags,
+               .vid = vid,
+               .changed = changed,
+       };
+
+       return switchdev_port_obj_add(dev, &v.obj, extack);
+}
+
 int br_switchdev_port_vlan_del(struct net_device *dev, u16 vid)
 {
        struct switchdev_obj_port_vlan v = {
index 326933b455b36ade928a41483edb439d71d56c4e..84a180927eb73b73c0ef1bb2c92a17c8c96ded59 100644 (file)
@@ -109,6 +109,11 @@ static int __vlan_vid_add(struct net_device *dev, struct net_bridge *br,
        /* Try switchdev op first. In case it is not supported, fallback to
         * 8021q add.
         */
+       err = br_switchdev_port_vlan_no_foreign_add(dev, v->vid, flags, false, extack);
+       if (err != -EOPNOTSUPP) {
+               v->priv_flags |= BR_VLFLAG_ADDED_BY_SWITCHDEV | BR_VLFLAG_TAGGING_BY_SWITCHDEV;
+               return err;
+       }
        err = br_switchdev_port_vlan_add(dev, v->vid, flags, false, extack);
        if (err == -EOPNOTSUPP)
                return vlan_vid_add(dev, br->vlan_proto, v->vid);
@@ -1491,7 +1496,7 @@ int br_vlan_fill_forward_path_mode(struct net_bridge *br,
 
        if (path->bridge.vlan_mode == DEV_PATH_BR_VLAN_TAG)
                path->bridge.vlan_mode = DEV_PATH_BR_VLAN_KEEP;
-       else if (v->priv_flags & BR_VLFLAG_ADDED_BY_SWITCHDEV)
+       else if (v->priv_flags & BR_VLFLAG_TAGGING_BY_SWITCHDEV)
                path->bridge.vlan_mode = DEV_PATH_BR_VLAN_UNTAG_HW;
        else
                path->bridge.vlan_mode = DEV_PATH_BR_VLAN_UNTAG;
index b55df183e6d55907baae1ac1368fc4adc1fdb6b0..474df25e96a005143b8f16d33aec047a5a8ea690 100644 (file)
@@ -760,7 +760,7 @@ static int __switchdev_handle_port_obj_add(struct net_device *dev,
        /* Event is neither on a bridge nor a LAG. Check whether it is on an
         * interface that is in a bridge with us.
         */
-       if (!foreign_dev_check_cb)
+       if (!foreign_dev_check_cb || port_obj_info->obj->flags & SWITCHDEV_F_NO_FOREIGN)
                return err;
 
        br = netdev_master_upper_dev_get(dev);