提交 5a46facb 编写于 作者: N Nikolay Aleksandrov 提交者: David S. Miller

net: bridge: vlan: add helpers to check for vlan id/range validity

Add helpers to check if a vlan id or range are valid. The range helper
must be called when range start or end are detected.
Signed-off-by: NNikolay Aleksandrov <nikolay@cumulusnetworks.com>
Signed-off-by: NDavid S. Miller <davem@davemloft.net>
上级 f6310b61
...@@ -568,17 +568,13 @@ static int br_process_vlan_info(struct net_bridge *br, ...@@ -568,17 +568,13 @@ static int br_process_vlan_info(struct net_bridge *br,
bool *changed, bool *changed,
struct netlink_ext_ack *extack) struct netlink_ext_ack *extack)
{ {
if (!vinfo_curr->vid || vinfo_curr->vid >= VLAN_VID_MASK) if (!br_vlan_valid_id(vinfo_curr->vid))
return -EINVAL; return -EINVAL;
if (vinfo_curr->flags & BRIDGE_VLAN_INFO_RANGE_BEGIN) { if (vinfo_curr->flags & BRIDGE_VLAN_INFO_RANGE_BEGIN) {
/* check if we are already processing a range */ if (!br_vlan_valid_range(vinfo_curr, *vinfo_last))
if (*vinfo_last)
return -EINVAL; return -EINVAL;
*vinfo_last = vinfo_curr; *vinfo_last = vinfo_curr;
/* don't allow range of pvids */
if ((*vinfo_last)->flags & BRIDGE_VLAN_INFO_PVID)
return -EINVAL;
return 0; return 0;
} }
...@@ -586,10 +582,7 @@ static int br_process_vlan_info(struct net_bridge *br, ...@@ -586,10 +582,7 @@ static int br_process_vlan_info(struct net_bridge *br,
struct bridge_vlan_info tmp_vinfo; struct bridge_vlan_info tmp_vinfo;
int v, err; int v, err;
if (!(vinfo_curr->flags & BRIDGE_VLAN_INFO_RANGE_END)) if (!br_vlan_valid_range(vinfo_curr, *vinfo_last))
return -EINVAL;
if (vinfo_curr->vid <= (*vinfo_last)->vid)
return -EINVAL; return -EINVAL;
memcpy(&tmp_vinfo, *vinfo_last, memcpy(&tmp_vinfo, *vinfo_last,
......
...@@ -507,6 +507,37 @@ static inline bool nbp_state_should_learn(const struct net_bridge_port *p) ...@@ -507,6 +507,37 @@ static inline bool nbp_state_should_learn(const struct net_bridge_port *p)
return p->state == BR_STATE_LEARNING || p->state == BR_STATE_FORWARDING; return p->state == BR_STATE_LEARNING || p->state == BR_STATE_FORWARDING;
} }
static inline bool br_vlan_valid_id(u16 vid)
{
return vid > 0 && vid < VLAN_VID_MASK;
}
static inline bool br_vlan_valid_range(const struct bridge_vlan_info *cur,
const struct bridge_vlan_info *last)
{
/* pvid flag is not allowed in ranges */
if (cur->flags & BRIDGE_VLAN_INFO_PVID)
return false;
/* check for required range flags */
if (!(cur->flags & (BRIDGE_VLAN_INFO_RANGE_BEGIN |
BRIDGE_VLAN_INFO_RANGE_END)))
return false;
/* when cur is the range end, check if:
* - it has range start flag
* - range ids are invalid (end is equal to or before start)
*/
if (last) {
if (cur->flags & BRIDGE_VLAN_INFO_RANGE_BEGIN)
return false;
else if (cur->vid <= last->vid)
return false;
}
return true;
}
static inline int br_opt_get(const struct net_bridge *br, static inline int br_opt_get(const struct net_bridge *br,
enum net_bridge_opts opt) enum net_bridge_opts opt)
{ {
......
Markdown is supported
0% .
You are about to add 0 people to the discussion. Proceed with caution.
先完成此消息的编辑!
想要评论请 注册