bridge: Verify that a vlan is allowed to egress on given port
[linux-2.6-block.git] / net / bridge / br_netlink.c
CommitLineData
11dc1f36
SH
1/*
2 * Bridge netlink control interface
3 *
4 * Authors:
5 * Stephen Hemminger <shemminger@osdl.org>
6 *
7 * This program is free software; you can redistribute it and/or
8 * modify it under the terms of the GNU General Public License
9 * as published by the Free Software Foundation; either version
10 * 2 of the License, or (at your option) any later version.
11 */
12
13#include <linux/kernel.h>
5a0e3ad6 14#include <linux/slab.h>
bb900b27 15#include <linux/etherdevice.h>
32fe21c0 16#include <net/rtnetlink.h>
881d966b 17#include <net/net_namespace.h>
b854272b 18#include <net/sock.h>
bb900b27 19
11dc1f36 20#include "br_private.h"
b03b6dd5 21#include "br_private_stp.h"
11dc1f36 22
25c71c75 23static inline size_t br_port_info_size(void)
24{
25 return nla_total_size(1) /* IFLA_BRPORT_STATE */
26 + nla_total_size(2) /* IFLA_BRPORT_PRIORITY */
27 + nla_total_size(4) /* IFLA_BRPORT_COST */
28 + nla_total_size(1) /* IFLA_BRPORT_MODE */
a2e01a65 29 + nla_total_size(1) /* IFLA_BRPORT_GUARD */
1007dd1a 30 + nla_total_size(1) /* IFLA_BRPORT_PROTECT */
25c71c75 31 + 0;
32}
33
339bf98f
TG
34static inline size_t br_nlmsg_size(void)
35{
36 return NLMSG_ALIGN(sizeof(struct ifinfomsg))
25c71c75 37 + nla_total_size(IFNAMSIZ) /* IFLA_IFNAME */
38 + nla_total_size(MAX_ADDR_LEN) /* IFLA_ADDRESS */
39 + nla_total_size(4) /* IFLA_MASTER */
40 + nla_total_size(4) /* IFLA_MTU */
41 + nla_total_size(4) /* IFLA_LINK */
42 + nla_total_size(1) /* IFLA_OPERSTATE */
43 + nla_total_size(br_port_info_size()); /* IFLA_PROTINFO */
44}
45
46static int br_port_fill_attrs(struct sk_buff *skb,
47 const struct net_bridge_port *p)
48{
49 u8 mode = !!(p->flags & BR_HAIRPIN_MODE);
50
51 if (nla_put_u8(skb, IFLA_BRPORT_STATE, p->state) ||
52 nla_put_u16(skb, IFLA_BRPORT_PRIORITY, p->priority) ||
53 nla_put_u32(skb, IFLA_BRPORT_COST, p->path_cost) ||
a2e01a65 54 nla_put_u8(skb, IFLA_BRPORT_MODE, mode) ||
1007dd1a 55 nla_put_u8(skb, IFLA_BRPORT_GUARD, !!(p->flags & BR_BPDU_GUARD)) ||
c2d3babf
DM
56 nla_put_u8(skb, IFLA_BRPORT_PROTECT, !!(p->flags & BR_ROOT_BLOCK)) ||
57 nla_put_u8(skb, IFLA_BRPORT_FAST_LEAVE, !!(p->flags & BR_MULTICAST_FAST_LEAVE)))
25c71c75 58 return -EMSGSIZE;
59
60 return 0;
339bf98f
TG
61}
62
11dc1f36
SH
63/*
64 * Create one netlink message for one interface
65 * Contains port and master info as well as carrier and bridge state.
66 */
67static int br_fill_ifinfo(struct sk_buff *skb, const struct net_bridge_port *port,
68 u32 pid, u32 seq, int event, unsigned int flags)
69{
70 const struct net_bridge *br = port->br;
71 const struct net_device *dev = port->dev;
74685962 72 struct ifinfomsg *hdr;
11dc1f36 73 struct nlmsghdr *nlh;
11dc1f36 74 u8 operstate = netif_running(dev) ? dev->operstate : IF_OPER_DOWN;
11dc1f36 75
28a16c97 76 br_debug(br, "br_fill_info event %d port %s master %s\n",
77 event, dev->name, br->dev->name);
11dc1f36 78
74685962
TG
79 nlh = nlmsg_put(skb, pid, seq, event, sizeof(*hdr), flags);
80 if (nlh == NULL)
26932566 81 return -EMSGSIZE;
11dc1f36 82
74685962
TG
83 hdr = nlmsg_data(nlh);
84 hdr->ifi_family = AF_BRIDGE;
85 hdr->__ifi_pad = 0;
86 hdr->ifi_type = dev->type;
87 hdr->ifi_index = dev->ifindex;
88 hdr->ifi_flags = dev_get_flags(dev);
89 hdr->ifi_change = 0;
11dc1f36 90
2eb812e6
DM
91 if (nla_put_string(skb, IFLA_IFNAME, dev->name) ||
92 nla_put_u32(skb, IFLA_MASTER, br->dev->ifindex) ||
93 nla_put_u32(skb, IFLA_MTU, dev->mtu) ||
94 nla_put_u8(skb, IFLA_OPERSTATE, operstate) ||
95 (dev->addr_len &&
96 nla_put(skb, IFLA_ADDRESS, dev->addr_len, dev->dev_addr)) ||
97 (dev->ifindex != dev->iflink &&
25c71c75 98 nla_put_u32(skb, IFLA_LINK, dev->iflink)))
2eb812e6 99 goto nla_put_failure;
25c71c75 100
101 if (event == RTM_NEWLINK) {
102 struct nlattr *nest
103 = nla_nest_start(skb, IFLA_PROTINFO | NLA_F_NESTED);
104
105 if (nest == NULL || br_port_fill_attrs(skb, port) < 0)
106 goto nla_put_failure;
107 nla_nest_end(skb, nest);
108 }
109
74685962 110 return nlmsg_end(skb, nlh);
11dc1f36 111
74685962 112nla_put_failure:
26932566
PM
113 nlmsg_cancel(skb, nlh);
114 return -EMSGSIZE;
11dc1f36
SH
115}
116
117/*
118 * Notify listeners of a change in port information
119 */
120void br_ifinfo_notify(int event, struct net_bridge_port *port)
121{
4aa678ba 122 struct net *net = dev_net(port->dev);
11dc1f36 123 struct sk_buff *skb;
280a306c 124 int err = -ENOBUFS;
11dc1f36 125
28a16c97 126 br_debug(port->br, "port %u(%s) event %d\n",
95c96174 127 (unsigned int)port->port_no, port->dev->name, event);
28a16c97 128
339bf98f 129 skb = nlmsg_new(br_nlmsg_size(), GFP_ATOMIC);
280a306c
TG
130 if (skb == NULL)
131 goto errout;
132
133 err = br_fill_ifinfo(skb, port, 0, 0, event, 0);
26932566
PM
134 if (err < 0) {
135 /* -EMSGSIZE implies BUG in br_nlmsg_size() */
136 WARN_ON(err == -EMSGSIZE);
137 kfree_skb(skb);
138 goto errout;
139 }
1ce85fe4
PNA
140 rtnl_notify(skb, net, 0, RTNLGRP_LINK, NULL, GFP_ATOMIC);
141 return;
280a306c 142errout:
bea1b42e 143 if (err < 0)
4aa678ba 144 rtnl_set_sk_err(net, RTNLGRP_LINK, err);
11dc1f36
SH
145}
146
147/*
148 * Dump information about all ports, in response to GETLINK
149 */
e5a55a89
JF
150int br_getlink(struct sk_buff *skb, u32 pid, u32 seq,
151 struct net_device *dev)
11dc1f36 152{
e5a55a89
JF
153 int err = 0;
154 struct net_bridge_port *port = br_port_get_rcu(dev);
155
156 /* not a bridge port */
157 if (!port)
158 goto out;
11dc1f36 159
e5a55a89
JF
160 err = br_fill_ifinfo(skb, port, pid, seq, RTM_NEWLINK, NLM_F_MULTI);
161out:
162 return err;
11dc1f36
SH
163}
164
25c71c75 165static const struct nla_policy ifla_brport_policy[IFLA_BRPORT_MAX + 1] = {
166 [IFLA_BRPORT_STATE] = { .type = NLA_U8 },
167 [IFLA_BRPORT_COST] = { .type = NLA_U32 },
168 [IFLA_BRPORT_PRIORITY] = { .type = NLA_U16 },
169 [IFLA_BRPORT_MODE] = { .type = NLA_U8 },
a2e01a65 170 [IFLA_BRPORT_GUARD] = { .type = NLA_U8 },
1007dd1a 171 [IFLA_BRPORT_PROTECT] = { .type = NLA_U8 },
25c71c75 172};
173
174/* Change the state of the port and notify spanning tree */
175static int br_set_port_state(struct net_bridge_port *p, u8 state)
176{
177 if (state > BR_STATE_BLOCKING)
178 return -EINVAL;
179
180 /* if kernel STP is running, don't allow changes */
181 if (p->br->stp_enabled == BR_KERNEL_STP)
182 return -EBUSY;
183
576eb625 184 /* if device is not up, change is not allowed
185 * if link is not present, only allowable state is disabled
186 */
25c71c75 187 if (!netif_running(p->dev) ||
576eb625 188 (!netif_oper_up(p->dev) && state != BR_STATE_DISABLED))
25c71c75 189 return -ENETDOWN;
190
191 p->state = state;
192 br_log_state(p);
193 br_port_state_selection(p->br);
194 return 0;
195}
196
197/* Set/clear or port flags based on attribute */
198static void br_set_port_flag(struct net_bridge_port *p, struct nlattr *tb[],
199 int attrtype, unsigned long mask)
200{
201 if (tb[attrtype]) {
202 u8 flag = nla_get_u8(tb[attrtype]);
203 if (flag)
204 p->flags |= mask;
205 else
206 p->flags &= ~mask;
207 }
208}
209
210/* Process bridge protocol info on port */
211static int br_setport(struct net_bridge_port *p, struct nlattr *tb[])
212{
213 int err;
214
215 br_set_port_flag(p, tb, IFLA_BRPORT_MODE, BR_HAIRPIN_MODE);
a2e01a65 216 br_set_port_flag(p, tb, IFLA_BRPORT_GUARD, BR_BPDU_GUARD);
c2d3babf 217 br_set_port_flag(p, tb, IFLA_BRPORT_FAST_LEAVE, BR_MULTICAST_FAST_LEAVE);
25c71c75 218
219 if (tb[IFLA_BRPORT_COST]) {
220 err = br_stp_set_path_cost(p, nla_get_u32(tb[IFLA_BRPORT_COST]));
221 if (err)
222 return err;
223 }
224
225 if (tb[IFLA_BRPORT_PRIORITY]) {
226 err = br_stp_set_port_priority(p, nla_get_u16(tb[IFLA_BRPORT_PRIORITY]));
227 if (err)
228 return err;
229 }
230
231 if (tb[IFLA_BRPORT_STATE]) {
232 err = br_set_port_state(p, nla_get_u8(tb[IFLA_BRPORT_STATE]));
233 if (err)
234 return err;
235 }
236 return 0;
237}
238
239/* Change state and parameters on port. */
e5a55a89 240int br_setlink(struct net_device *dev, struct nlmsghdr *nlh)
11dc1f36 241{
74685962
TG
242 struct ifinfomsg *ifm;
243 struct nlattr *protinfo;
11dc1f36 244 struct net_bridge_port *p;
2062cc20 245 struct nlattr *tb[IFLA_BRPORT_MAX + 1];
25c71c75 246 int err;
11dc1f36 247
74685962 248 ifm = nlmsg_data(nlh);
11dc1f36 249
74685962 250 protinfo = nlmsg_find_attr(nlh, sizeof(*ifm), IFLA_PROTINFO);
25c71c75 251 if (!protinfo)
252 return 0;
11dc1f36 253
ec1e5610 254 p = br_port_get_rtnl(dev);
b5ed54e9 255 if (!p)
256 return -EINVAL;
11dc1f36 257
25c71c75 258 if (protinfo->nla_type & NLA_F_NESTED) {
259 err = nla_parse_nested(tb, IFLA_BRPORT_MAX,
260 protinfo, ifla_brport_policy);
261 if (err)
262 return err;
11dc1f36 263
25c71c75 264 spin_lock_bh(&p->br->lock);
265 err = br_setport(p, tb);
266 spin_unlock_bh(&p->br->lock);
267 } else {
268 /* Binary compatability with old RSTP */
269 if (nla_len(protinfo) < sizeof(u8))
270 return -EINVAL;
11dc1f36 271
25c71c75 272 spin_lock_bh(&p->br->lock);
273 err = br_set_port_state(p, nla_get_u8(protinfo));
274 spin_unlock_bh(&p->br->lock);
275 }
b03b6dd5 276
25c71c75 277 if (err == 0)
278 br_ifinfo_notify(RTM_NEWLINK, p);
b03b6dd5 279
25c71c75 280 return err;
11dc1f36
SH
281}
282
bb900b27 283static int br_validate(struct nlattr *tb[], struct nlattr *data[])
284{
285 if (tb[IFLA_ADDRESS]) {
286 if (nla_len(tb[IFLA_ADDRESS]) != ETH_ALEN)
287 return -EINVAL;
288 if (!is_valid_ether_addr(nla_data(tb[IFLA_ADDRESS])))
289 return -EADDRNOTAVAIL;
290 }
291
292 return 0;
293}
294
149ddd83 295struct rtnl_link_ops br_link_ops __read_mostly = {
bb900b27 296 .kind = "bridge",
297 .priv_size = sizeof(struct net_bridge),
298 .setup = br_dev_setup,
299 .validate = br_validate,
1ce5cce8 300 .dellink = br_dev_delete,
bb900b27 301};
11dc1f36 302
32fe21c0 303int __init br_netlink_init(void)
11dc1f36 304{
3ec8e9f0
VY
305 int err;
306
307 br_mdb_init();
308 err = rtnl_link_register(&br_link_ops);
309 if (err)
310 goto out;
311
312 return 0;
313out:
314 br_mdb_uninit();
315 return err;
11dc1f36
SH
316}
317
318void __exit br_netlink_fini(void)
319{
3ec8e9f0 320 br_mdb_uninit();
bb900b27 321 rtnl_link_unregister(&br_link_ops);
11dc1f36 322}