From nobody Fri May 17 04:49:40 2024 Received: from mail1.fiberby.net (mail1.fiberby.net [193.104.135.124]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id F02DA13C81F; Wed, 17 Apr 2024 13:52:41 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=193.104.135.124 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1713361965; cv=none; b=mgH5L1j905MoQhAOhpKSQfsb1cNrhShHnlIvZmPm6GnW92UkpoPne7QQkGGckSM2gLvGcmjfTRAfPqEpstUcd3MCCJqPKxlRf5B9PdCFsmEPdrSLI7insOWs3NMUVfOvQa9bbCHIuik24bSre9JLg4qLdAu9STkMY5ZTve66/ec= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1713361965; c=relaxed/simple; bh=4Cmcmmzl6A6wun1x2yb3/vcGq9AxnztLrcfzCmZZJlE=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version:Content-Type; b=YFnI0eDi47e6i0IY/69pC58qP59CXn+KDtU/AcszVW5IuSMyGcPYQHoYEW+ecWpm5rDn/xmb3cge7balocECj9EXW9D6igAI3LbzwULMiSHv6UVbfKq5sA8z66PlPIvCBVgfqTfWAAr8DTMkXkXmyie85fVVyjuSl9FYA1FaQpc= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=fiberby.net; spf=pass smtp.mailfrom=fiberby.net; dkim=pass (2048-bit key) header.d=fiberby.net header.i=@fiberby.net header.b=pjcIVCXN; arc=none smtp.client-ip=193.104.135.124 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=fiberby.net Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=fiberby.net Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=fiberby.net header.i=@fiberby.net header.b="pjcIVCXN" Received: from x201s (193-104-135-243.ip4.fiberby.net [193.104.135.243]) by mail1.fiberby.net (Postfix) with ESMTPSA id 8CFC7600A2; Wed, 17 Apr 2024 13:52:27 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=fiberby.net; s=202008; t=1713361953; bh=4Cmcmmzl6A6wun1x2yb3/vcGq9AxnztLrcfzCmZZJlE=; h=From:To:Cc:Subject:Date:From; b=pjcIVCXNTxr1YmJPkL1TWaxn+SQm6stYgn86q/JpDYAOuib5zFrOAuxGrkhxZJ9/o DxS0eRBIftNC5aQ3YBBxxm7/Cd4CcFermzSZrvSi3HaM7Dh4LNtD0rt/a56p99W7MQ TXavCXLc0gO4aaODYZDNY59b3czL+PzunXCT9MIr0h75bT9TzXDVA5sBkhOD7lYVy1 qceVXmTIPWpwY1yeB4kp1yYXS9T5Hi3uX9PRvKZ7OgofZO74fc3EI71Y/BcL3tGOyG tgK8Y3DYlTuHjqVdO8KpyoFwslsewZ+YQXZJ7FVObTUoskGRcwtk+9rOGIkxeBGlEH Q56XSLIdzzyUQ== Received: by x201s (Postfix, from userid 1000) id 07E5520445E; Wed, 17 Apr 2024 13:52:24 +0000 (UTC) From: =?UTF-8?q?Asbj=C3=B8rn=20Sloth=20T=C3=B8nnesen?= To: netdev@vger.kernel.org Cc: =?UTF-8?q?Asbj=C3=B8rn=20Sloth=20T=C3=B8nnesen?= , linux-kernel@vger.kernel.org, "David S. Miller" , Eric Dumazet , Jakub Kicinski , Paolo Abeni , Ido Schimmel , Petr Machata Subject: [PATCH net-next] mlxsw: spectrum_flower: validate control flags Date: Wed, 17 Apr 2024 13:51:20 +0000 Message-ID: <20240417135131.99921-1-ast@fiberby.net> X-Mailer: git-send-email 2.43.0 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable This driver currently doesn't support any control flags. Use flow_rule_has_control_flags() to check for control flags, such as can be set through `tc flower ... ip_flags frag`. In case any control flags are masked, flow_rule_has_control_flags() sets a NL extended error message, and we return -EOPNOTSUPP. Only compile-tested. Signed-off-by: Asbj=C3=B8rn Sloth T=C3=B8nnesen Reviewed-by: Ido Schimmel Tested-by: Ido Schimmel Tested-by: Petr Machata --- drivers/net/ethernet/mellanox/mlxsw/spectrum_flower.c | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/drivers/net/ethernet/mellanox/mlxsw/spectrum_flower.c b/driver= s/net/ethernet/mellanox/mlxsw/spectrum_flower.c index 9fd1ca079258..f07955b5439f 100644 --- a/drivers/net/ethernet/mellanox/mlxsw/spectrum_flower.c +++ b/drivers/net/ethernet/mellanox/mlxsw/spectrum_flower.c @@ -595,6 +595,10 @@ static int mlxsw_sp_flower_parse(struct mlxsw_sp *mlxs= w_sp, =20 flow_rule_match_control(rule, &match); addr_type =3D match.key->addr_type; + + if (flow_rule_has_control_flags(match.mask->flags, + f->common.extack)) + return -EOPNOTSUPP; } =20 if (flow_rule_match_key(rule, FLOW_DISSECTOR_KEY_BASIC)) { --=20 2.43.0