Commit f12064d1 authored by Florian Westphal's avatar Florian Westphal Committed by Pablo Neira Ayuso

bridge: reduce size of input cb to 16 bytes

Reduce size of br_input_skb_cb from 24 to 16 bytes by
using bitfield for those values that can only be 0 or 1.

igmp is the igmp type value, so it needs to be at least u8.

Furthermore, the bridge currently relies on step-by-step initialization
of br_input_skb_cb fields as the skb passes through the stack.

Explicitly zero out the bridge input cb instead, this avoids having to
review/validate that no BR_INPUT_SKB_CB(skb)->foo test can see a
'random' value from previous protocol cb.

AFAICS all current fields are always set up before they are read again,
so this is not a bug fix.
Signed-off-by: default avatarFlorian Westphal <fw@strlen.de>
Acked-by: default avatarDavid S. Miller <davem@davemloft.net>
Acked-by: default avatarNikolay Aleksandrov <nikolay@cumulusnetworks.com>
Signed-off-by: default avatarPablo Neira Ayuso <pablo@netfilter.org>
parent 26f7fe4a
...@@ -131,7 +131,7 @@ void br_do_proxy_suppress_arp(struct sk_buff *skb, struct net_bridge *br, ...@@ -131,7 +131,7 @@ void br_do_proxy_suppress_arp(struct sk_buff *skb, struct net_bridge *br,
u8 *arpptr, *sha; u8 *arpptr, *sha;
__be32 sip, tip; __be32 sip, tip;
BR_INPUT_SKB_CB(skb)->proxyarp_replied = false; BR_INPUT_SKB_CB(skb)->proxyarp_replied = 0;
if ((dev->flags & IFF_NOARP) || if ((dev->flags & IFF_NOARP) ||
!pskb_may_pull(skb, arp_hdr_len(dev))) !pskb_may_pull(skb, arp_hdr_len(dev)))
...@@ -161,7 +161,7 @@ void br_do_proxy_suppress_arp(struct sk_buff *skb, struct net_bridge *br, ...@@ -161,7 +161,7 @@ void br_do_proxy_suppress_arp(struct sk_buff *skb, struct net_bridge *br,
return; return;
if (ipv4_is_zeronet(sip) || sip == tip) { if (ipv4_is_zeronet(sip) || sip == tip) {
/* prevent flooding to neigh suppress ports */ /* prevent flooding to neigh suppress ports */
BR_INPUT_SKB_CB(skb)->proxyarp_replied = true; BR_INPUT_SKB_CB(skb)->proxyarp_replied = 1;
return; return;
} }
} }
...@@ -181,7 +181,7 @@ void br_do_proxy_suppress_arp(struct sk_buff *skb, struct net_bridge *br, ...@@ -181,7 +181,7 @@ void br_do_proxy_suppress_arp(struct sk_buff *skb, struct net_bridge *br,
/* its our local ip, so don't proxy reply /* its our local ip, so don't proxy reply
* and don't forward to neigh suppress ports * and don't forward to neigh suppress ports
*/ */
BR_INPUT_SKB_CB(skb)->proxyarp_replied = true; BR_INPUT_SKB_CB(skb)->proxyarp_replied = 1;
return; return;
} }
...@@ -217,7 +217,7 @@ void br_do_proxy_suppress_arp(struct sk_buff *skb, struct net_bridge *br, ...@@ -217,7 +217,7 @@ void br_do_proxy_suppress_arp(struct sk_buff *skb, struct net_bridge *br,
*/ */
if (replied || if (replied ||
br_opt_get(br, BROPT_NEIGH_SUPPRESS_ENABLED)) br_opt_get(br, BROPT_NEIGH_SUPPRESS_ENABLED))
BR_INPUT_SKB_CB(skb)->proxyarp_replied = true; BR_INPUT_SKB_CB(skb)->proxyarp_replied = 1;
} }
neigh_release(n); neigh_release(n);
...@@ -393,7 +393,7 @@ void br_do_suppress_nd(struct sk_buff *skb, struct net_bridge *br, ...@@ -393,7 +393,7 @@ void br_do_suppress_nd(struct sk_buff *skb, struct net_bridge *br,
struct ipv6hdr *iphdr; struct ipv6hdr *iphdr;
struct neighbour *n; struct neighbour *n;
BR_INPUT_SKB_CB(skb)->proxyarp_replied = false; BR_INPUT_SKB_CB(skb)->proxyarp_replied = 0;
if (p && (p->flags & BR_NEIGH_SUPPRESS)) if (p && (p->flags & BR_NEIGH_SUPPRESS))
return; return;
...@@ -401,7 +401,7 @@ void br_do_suppress_nd(struct sk_buff *skb, struct net_bridge *br, ...@@ -401,7 +401,7 @@ void br_do_suppress_nd(struct sk_buff *skb, struct net_bridge *br,
if (msg->icmph.icmp6_type == NDISC_NEIGHBOUR_ADVERTISEMENT && if (msg->icmph.icmp6_type == NDISC_NEIGHBOUR_ADVERTISEMENT &&
!msg->icmph.icmp6_solicited) { !msg->icmph.icmp6_solicited) {
/* prevent flooding to neigh suppress ports */ /* prevent flooding to neigh suppress ports */
BR_INPUT_SKB_CB(skb)->proxyarp_replied = true; BR_INPUT_SKB_CB(skb)->proxyarp_replied = 1;
return; return;
} }
...@@ -414,7 +414,7 @@ void br_do_suppress_nd(struct sk_buff *skb, struct net_bridge *br, ...@@ -414,7 +414,7 @@ void br_do_suppress_nd(struct sk_buff *skb, struct net_bridge *br,
if (ipv6_addr_any(saddr) || !ipv6_addr_cmp(saddr, daddr)) { if (ipv6_addr_any(saddr) || !ipv6_addr_cmp(saddr, daddr)) {
/* prevent flooding to neigh suppress ports */ /* prevent flooding to neigh suppress ports */
BR_INPUT_SKB_CB(skb)->proxyarp_replied = true; BR_INPUT_SKB_CB(skb)->proxyarp_replied = 1;
return; return;
} }
...@@ -432,7 +432,7 @@ void br_do_suppress_nd(struct sk_buff *skb, struct net_bridge *br, ...@@ -432,7 +432,7 @@ void br_do_suppress_nd(struct sk_buff *skb, struct net_bridge *br,
/* its our own ip, so don't proxy reply /* its our own ip, so don't proxy reply
* and don't forward to arp suppress ports * and don't forward to arp suppress ports
*/ */
BR_INPUT_SKB_CB(skb)->proxyarp_replied = true; BR_INPUT_SKB_CB(skb)->proxyarp_replied = 1;
return; return;
} }
...@@ -465,7 +465,7 @@ void br_do_suppress_nd(struct sk_buff *skb, struct net_bridge *br, ...@@ -465,7 +465,7 @@ void br_do_suppress_nd(struct sk_buff *skb, struct net_bridge *br,
*/ */
if (replied || if (replied ||
br_opt_get(br, BROPT_NEIGH_SUPPRESS_ENABLED)) br_opt_get(br, BROPT_NEIGH_SUPPRESS_ENABLED))
BR_INPUT_SKB_CB(skb)->proxyarp_replied = true; BR_INPUT_SKB_CB(skb)->proxyarp_replied = 1;
} }
neigh_release(n); neigh_release(n);
} }
......
...@@ -227,6 +227,8 @@ rx_handler_result_t br_handle_frame(struct sk_buff **pskb) ...@@ -227,6 +227,8 @@ rx_handler_result_t br_handle_frame(struct sk_buff **pskb)
if (!skb) if (!skb)
return RX_HANDLER_CONSUMED; return RX_HANDLER_CONSUMED;
memset(skb->cb, 0, sizeof(struct br_input_skb_cb));
p = br_port_get_rcu(skb->dev); p = br_port_get_rcu(skb->dev);
if (p->flags & BR_VLAN_TUNNEL) { if (p->flags & BR_VLAN_TUNNEL) {
if (br_handle_ingress_vlan_tunnel(skb, p, if (br_handle_ingress_vlan_tunnel(skb, p,
......
...@@ -425,15 +425,13 @@ struct br_input_skb_cb { ...@@ -425,15 +425,13 @@ struct br_input_skb_cb {
struct net_device *brdev; struct net_device *brdev;
#ifdef CONFIG_BRIDGE_IGMP_SNOOPING #ifdef CONFIG_BRIDGE_IGMP_SNOOPING
int igmp; u8 igmp;
int mrouters_only; u8 mrouters_only:1;
#endif #endif
u8 proxyarp_replied:1;
bool proxyarp_replied; u8 src_port_isolated:1;
bool src_port_isolated;
#ifdef CONFIG_BRIDGE_VLAN_FILTERING #ifdef CONFIG_BRIDGE_VLAN_FILTERING
bool vlan_filtered; u8 vlan_filtered:1;
#endif #endif
#ifdef CONFIG_NET_SWITCHDEV #ifdef CONFIG_NET_SWITCHDEV
......
Markdown is supported
0%
or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment