xref: /openbmc/linux/net/bridge/br_ioctl.c (revision b6459415)
12874c5fdSThomas Gleixner // SPDX-License-Identifier: GPL-2.0-or-later
21da177e4SLinus Torvalds /*
31da177e4SLinus Torvalds  *	Ioctl handler
41da177e4SLinus Torvalds  *	Linux ethernet bridge
51da177e4SLinus Torvalds  *
61da177e4SLinus Torvalds  *	Authors:
71da177e4SLinus Torvalds  *	Lennert Buytenhek		<buytenh@gnu.org>
81da177e4SLinus Torvalds  */
91da177e4SLinus Torvalds 
104fc268d2SRandy Dunlap #include <linux/capability.h>
11*b6459415SJakub Kicinski #include <linux/compat.h>
121da177e4SLinus Torvalds #include <linux/kernel.h>
131da177e4SLinus Torvalds #include <linux/if_bridge.h>
141da177e4SLinus Torvalds #include <linux/netdevice.h>
155a0e3ad6STejun Heo #include <linux/slab.h>
161da177e4SLinus Torvalds #include <linux/times.h>
17881d966bSEric W. Biederman #include <net/net_namespace.h>
187c0f6ba6SLinus Torvalds #include <linux/uaccess.h>
191da177e4SLinus Torvalds #include "br_private.h"
201da177e4SLinus Torvalds 
get_bridge_ifindices(struct net * net,int * indices,int num)214aa678baSAlexey Dobriyan static int get_bridge_ifindices(struct net *net, int *indices, int num)
221da177e4SLinus Torvalds {
231da177e4SLinus Torvalds 	struct net_device *dev;
241da177e4SLinus Torvalds 	int i = 0;
251da177e4SLinus Torvalds 
2631ca0458SNikolay Aleksandrov 	rcu_read_lock();
2731ca0458SNikolay Aleksandrov 	for_each_netdev_rcu(net, dev) {
287562f876SPavel Emelianov 		if (i >= num)
297562f876SPavel Emelianov 			break;
30254ec036SKyungrok Chung 		if (netif_is_bridge_master(dev))
311da177e4SLinus Torvalds 			indices[i++] = dev->ifindex;
321da177e4SLinus Torvalds 	}
3331ca0458SNikolay Aleksandrov 	rcu_read_unlock();
341da177e4SLinus Torvalds 
351da177e4SLinus Torvalds 	return i;
361da177e4SLinus Torvalds }
371da177e4SLinus Torvalds 
381da177e4SLinus Torvalds /* called with RTNL */
get_port_ifindices(struct net_bridge * br,int * ifindices,int num)391da177e4SLinus Torvalds static void get_port_ifindices(struct net_bridge *br, int *ifindices, int num)
401da177e4SLinus Torvalds {
411da177e4SLinus Torvalds 	struct net_bridge_port *p;
421da177e4SLinus Torvalds 
431da177e4SLinus Torvalds 	list_for_each_entry(p, &br->port_list, list) {
441da177e4SLinus Torvalds 		if (p->port_no < num)
451da177e4SLinus Torvalds 			ifindices[p->port_no] = p->dev->ifindex;
461da177e4SLinus Torvalds 	}
471da177e4SLinus Torvalds }
481da177e4SLinus Torvalds 
491da177e4SLinus Torvalds /*
501da177e4SLinus Torvalds  * Format up to a page worth of forwarding table entries
511da177e4SLinus Torvalds  * userbuf -- where to copy result
521da177e4SLinus Torvalds  * maxnum  -- maximum number of entries desired
531da177e4SLinus Torvalds  *            (limited to a page for sanity)
541da177e4SLinus Torvalds  * offset  -- number of records to skip
551da177e4SLinus Torvalds  */
get_fdb_entries(struct net_bridge * br,void __user * userbuf,unsigned long maxnum,unsigned long offset)561da177e4SLinus Torvalds static int get_fdb_entries(struct net_bridge *br, void __user *userbuf,
571da177e4SLinus Torvalds 			   unsigned long maxnum, unsigned long offset)
581da177e4SLinus Torvalds {
591da177e4SLinus Torvalds 	int num;
601da177e4SLinus Torvalds 	void *buf;
61ba8379b2SChris Wright 	size_t size;
621da177e4SLinus Torvalds 
63ba8379b2SChris Wright 	/* Clamp size to PAGE_SIZE, test maxnum to avoid overflow */
64ba8379b2SChris Wright 	if (maxnum > PAGE_SIZE/sizeof(struct __fdb_entry))
651da177e4SLinus Torvalds 		maxnum = PAGE_SIZE/sizeof(struct __fdb_entry);
66ba8379b2SChris Wright 
67ba8379b2SChris Wright 	size = maxnum * sizeof(struct __fdb_entry);
681da177e4SLinus Torvalds 
691da177e4SLinus Torvalds 	buf = kmalloc(size, GFP_USER);
701da177e4SLinus Torvalds 	if (!buf)
711da177e4SLinus Torvalds 		return -ENOMEM;
721da177e4SLinus Torvalds 
731da177e4SLinus Torvalds 	num = br_fdb_fillbuf(br, buf, maxnum, offset);
741da177e4SLinus Torvalds 	if (num > 0) {
75865bfb2aSGustavo A. R. Silva 		if (copy_to_user(userbuf, buf,
76865bfb2aSGustavo A. R. Silva 				 array_size(num, sizeof(struct __fdb_entry))))
771da177e4SLinus Torvalds 			num = -EFAULT;
781da177e4SLinus Torvalds 	}
791da177e4SLinus Torvalds 	kfree(buf);
801da177e4SLinus Torvalds 
811da177e4SLinus Torvalds 	return num;
821da177e4SLinus Torvalds }
831da177e4SLinus Torvalds 
8431ef30c7SEric Dumazet /* called with RTNL */
add_del_if(struct net_bridge * br,int ifindex,int isadd)851da177e4SLinus Torvalds static int add_del_if(struct net_bridge *br, int ifindex, int isadd)
861da177e4SLinus Torvalds {
87cb990503SEric W. Biederman 	struct net *net = dev_net(br->dev);
881da177e4SLinus Torvalds 	struct net_device *dev;
891da177e4SLinus Torvalds 	int ret;
901da177e4SLinus Torvalds 
91cb990503SEric W. Biederman 	if (!ns_capable(net->user_ns, CAP_NET_ADMIN))
921da177e4SLinus Torvalds 		return -EPERM;
931da177e4SLinus Torvalds 
94cb990503SEric W. Biederman 	dev = __dev_get_by_index(net, ifindex);
951da177e4SLinus Torvalds 	if (dev == NULL)
961da177e4SLinus Torvalds 		return -EINVAL;
971da177e4SLinus Torvalds 
981da177e4SLinus Torvalds 	if (isadd)
99ca752be0SDavid Ahern 		ret = br_add_if(br, dev, NULL);
100eccaa9e5SDavid S. Miller 	else
1011da177e4SLinus Torvalds 		ret = br_del_if(br, dev);
1021da177e4SLinus Torvalds 
1031da177e4SLinus Torvalds 	return ret;
1041da177e4SLinus Torvalds }
1051da177e4SLinus Torvalds 
1061da177e4SLinus Torvalds #define BR_UARGS_MAX 4
br_dev_read_uargs(unsigned long * args,size_t nr_args,void __user ** argp,void __user * data)1071da177e4SLinus Torvalds static int br_dev_read_uargs(unsigned long *args, size_t nr_args,
1084bbd026cSRandy Dunlap 			     void __user **argp, void __user *data)
10925985edcSLucas De Marchi {
1101da177e4SLinus Torvalds 	int ret;
111561d8352SArnd Bergmann 
1121da177e4SLinus Torvalds 	if (nr_args < 2 || nr_args > BR_UARGS_MAX)
1131da177e4SLinus Torvalds 		return -EINVAL;
114bf871ad7SXin Long 
1151da177e4SLinus Torvalds 	if (in_compat_syscall()) {
116561d8352SArnd Bergmann 		unsigned int cargs[BR_UARGS_MAX];
117bf871ad7SXin Long 		int i;
1181da177e4SLinus Torvalds 
119561d8352SArnd Bergmann 		ret = copy_from_user(cargs, data, nr_args * sizeof(*cargs));
120561d8352SArnd Bergmann 		if (ret)
121561d8352SArnd Bergmann 			goto fault;
122561d8352SArnd Bergmann 
1231da177e4SLinus Torvalds 		for (i = 0; i < nr_args; ++i)
1241da177e4SLinus Torvalds 			args[i] = cargs[i];
125561d8352SArnd Bergmann 
126561d8352SArnd Bergmann 		*argp = compat_ptr(args[1]);
127561d8352SArnd Bergmann 	} else {
128561d8352SArnd Bergmann 		ret = copy_from_user(args, data, nr_args * sizeof(*args));
129561d8352SArnd Bergmann 		if (ret)
130561d8352SArnd Bergmann 			goto fault;
131561d8352SArnd Bergmann 		*argp = (void __user *)args[1];
132561d8352SArnd Bergmann 	}
133561d8352SArnd Bergmann 
134561d8352SArnd Bergmann 	return 0;
135561d8352SArnd Bergmann fault:
136561d8352SArnd Bergmann 	return -EFAULT;
137561d8352SArnd Bergmann }
1381da177e4SLinus Torvalds 
1391da177e4SLinus Torvalds /*
1401da177e4SLinus Torvalds  * Legacy ioctl's through SIOCDEVPRIVATE
1411da177e4SLinus Torvalds  * This interface is deprecated because it was too difficult
1421da177e4SLinus Torvalds  * to do the translation for 32/64bit ioctl compatibility.
1431da177e4SLinus Torvalds  */
br_dev_siocdevprivate(struct net_device * dev,struct ifreq * rq,void __user * data,int cmd)1441da177e4SLinus Torvalds int br_dev_siocdevprivate(struct net_device *dev, struct ifreq *rq,
1451da177e4SLinus Torvalds 			  void __user *data, int cmd)
1461da177e4SLinus Torvalds {
1471da177e4SLinus Torvalds 	struct net_bridge *br = netdev_priv(dev);
1481da177e4SLinus Torvalds 	struct net_bridge_port *p = NULL;
1491da177e4SLinus Torvalds 	unsigned long args[4];
1501da177e4SLinus Torvalds 	void __user *argp;
1511da177e4SLinus Torvalds 	int ret;
1521da177e4SLinus Torvalds 
1531da177e4SLinus Torvalds 	ret = br_dev_read_uargs(args, ARRAY_SIZE(args), &argp, data);
1541da177e4SLinus Torvalds 	if (ret)
1551da177e4SLinus Torvalds 		return ret;
1561da177e4SLinus Torvalds 
1571da177e4SLinus Torvalds 	switch (args[0]) {
1581da177e4SLinus Torvalds 	case BRCTL_ADD_IF:
1591da177e4SLinus Torvalds 	case BRCTL_DEL_IF:
1601da177e4SLinus Torvalds 		return add_del_if(br, args[1], args[0] == BRCTL_ADD_IF);
1619cde0708SStephen Hemminger 
1629cde0708SStephen Hemminger 	case BRCTL_GET_BRIDGE_INFO:
1631da177e4SLinus Torvalds 	{
1641da177e4SLinus Torvalds 		struct __bridge_info b;
1651da177e4SLinus Torvalds 
1661da177e4SLinus Torvalds 		memset(&b, 0, sizeof(struct __bridge_info));
167f7cdee8aSNikolay Aleksandrov 		rcu_read_lock();
1681da177e4SLinus Torvalds 		memcpy(&b.designated_root, &br->designated_root, 8);
1691da177e4SLinus Torvalds 		memcpy(&b.bridge_id, &br->bridge_id, 8);
1701da177e4SLinus Torvalds 		b.root_path_cost = br->root_path_cost;
1711da177e4SLinus Torvalds 		b.max_age = jiffies_to_clock_t(br->max_age);
1721da177e4SLinus Torvalds 		b.hello_time = jiffies_to_clock_t(br->hello_time);
1731da177e4SLinus Torvalds 		b.forward_delay = br->forward_delay;
1741da177e4SLinus Torvalds 		b.bridge_max_age = br->bridge_max_age;
1751da177e4SLinus Torvalds 		b.bridge_hello_time = br->bridge_hello_time;
1761da177e4SLinus Torvalds 		b.bridge_forward_delay = jiffies_to_clock_t(br->bridge_forward_delay);
1771da177e4SLinus Torvalds 		b.topology_change = br->topology_change;
1781da177e4SLinus Torvalds 		b.topology_change_detected = br->topology_change_detected;
1791da177e4SLinus Torvalds 		b.root_port = br->root_port;
1801da177e4SLinus Torvalds 
1811da177e4SLinus Torvalds 		b.stp_enabled = (br->stp_enabled != BR_NO_STP);
1821da177e4SLinus Torvalds 		b.ageing_time = jiffies_to_clock_t(br->ageing_time);
1831da177e4SLinus Torvalds 		b.hello_timer_value = br_timer_value(&br->hello_timer);
1841da177e4SLinus Torvalds 		b.tcn_timer_value = br_timer_value(&br->tcn_timer);
1851da177e4SLinus Torvalds 		b.topology_change_timer_value = br_timer_value(&br->topology_change_timer);
1861da177e4SLinus Torvalds 		b.gc_timer_value = br_timer_value(&br->gc_work.timer);
1871da177e4SLinus Torvalds 		rcu_read_unlock();
1880da974f4SPanagiotis Issaris 
1891da177e4SLinus Torvalds 		if (copy_to_user((void __user *)args[1], &b, sizeof(b)))
1901da177e4SLinus Torvalds 			return -EFAULT;
1911da177e4SLinus Torvalds 
1921da177e4SLinus Torvalds 		return 0;
193865bfb2aSGustavo A. R. Silva 	}
1941da177e4SLinus Torvalds 
1951da177e4SLinus Torvalds 	case BRCTL_GET_PORT_LIST:
1961da177e4SLinus Torvalds 	{
1971da177e4SLinus Torvalds 		int num, *indices;
1981da177e4SLinus Torvalds 
1991da177e4SLinus Torvalds 		num = args[2];
200cb990503SEric W. Biederman 		if (num < 0)
2011da177e4SLinus Torvalds 			return -EINVAL;
2021da177e4SLinus Torvalds 		if (num == 0)
203bf871ad7SXin Long 			num = 256;
204bf871ad7SXin Long 		if (num > BR_MAX_PORTS)
2051da177e4SLinus Torvalds 			num = BR_MAX_PORTS;
2061da177e4SLinus Torvalds 
207cb990503SEric W. Biederman 		indices = kcalloc(num, sizeof(int), GFP_KERNEL);
2081da177e4SLinus Torvalds 		if (indices == NULL)
2091da177e4SLinus Torvalds 			return -ENOMEM;
210bf871ad7SXin Long 
211bf871ad7SXin Long 		get_port_ifindices(br, indices, num);
2121da177e4SLinus Torvalds 		if (copy_to_user(argp, indices, array_size(num, sizeof(int))))
2131da177e4SLinus Torvalds 			num =  -EFAULT;
214cb990503SEric W. Biederman 		kfree(indices);
2151da177e4SLinus Torvalds 		return num;
2161da177e4SLinus Torvalds 	}
217bf871ad7SXin Long 
218bf871ad7SXin Long 	case BRCTL_SET_BRIDGE_FORWARD_DELAY:
2191da177e4SLinus Torvalds 		if (!ns_capable(dev_net(dev)->user_ns, CAP_NET_ADMIN))
2201da177e4SLinus Torvalds 			return -EPERM;
221cb990503SEric W. Biederman 
2221da177e4SLinus Torvalds 		ret = br_set_forward_delay(br, args[1]);
2231da177e4SLinus Torvalds 		break;
224bf871ad7SXin Long 
225bf871ad7SXin Long 	case BRCTL_SET_BRIDGE_HELLO_TIME:
2261da177e4SLinus Torvalds 		if (!ns_capable(dev_net(dev)->user_ns, CAP_NET_ADMIN))
2271da177e4SLinus Torvalds 			return -EPERM;
2281da177e4SLinus Torvalds 
2291da177e4SLinus Torvalds 		ret = br_set_hello_time(br, args[1]);
2301da177e4SLinus Torvalds 		break;
2311da177e4SLinus Torvalds 
2321da177e4SLinus Torvalds 	case BRCTL_SET_BRIDGE_MAX_AGE:
2331da177e4SLinus Torvalds 		if (!ns_capable(dev_net(dev)->user_ns, CAP_NET_ADMIN))
2341da177e4SLinus Torvalds 			return -EPERM;
2351da177e4SLinus Torvalds 
2361da177e4SLinus Torvalds 		ret = br_set_max_age(br, args[1]);
2371da177e4SLinus Torvalds 		break;
2381da177e4SLinus Torvalds 
2391da177e4SLinus Torvalds 	case BRCTL_SET_AGEING_TIME:
2401da177e4SLinus Torvalds 		if (!ns_capable(dev_net(dev)->user_ns, CAP_NET_ADMIN))
2411da177e4SLinus Torvalds 			return -EPERM;
2421da177e4SLinus Torvalds 
2431da177e4SLinus Torvalds 		ret = br_set_ageing_time(br, args[1]);
2441da177e4SLinus Torvalds 		break;
2451da177e4SLinus Torvalds 
2461da177e4SLinus Torvalds 	case BRCTL_GET_PORT_INFO:
2471da177e4SLinus Torvalds 	{
2481da177e4SLinus Torvalds 		struct __port_info p;
2491da177e4SLinus Torvalds 		struct net_bridge_port *pt;
2501da177e4SLinus Torvalds 
2511da177e4SLinus Torvalds 		rcu_read_lock();
2521da177e4SLinus Torvalds 		if ((pt = br_get_port(br, args[2])) == NULL) {
2531da177e4SLinus Torvalds 			rcu_read_unlock();
254561d8352SArnd Bergmann 			return -EINVAL;
2551da177e4SLinus Torvalds 		}
2561da177e4SLinus Torvalds 
2571da177e4SLinus Torvalds 		memset(&p, 0, sizeof(struct __port_info));
2581da177e4SLinus Torvalds 		memcpy(&p.designated_root, &pt->designated_root, 8);
2591da177e4SLinus Torvalds 		memcpy(&p.designated_bridge, &pt->designated_bridge, 8);
2601da177e4SLinus Torvalds 		p.port_id = pt->port_id;
261cb990503SEric W. Biederman 		p.designated_port = pt->designated_port;
2621da177e4SLinus Torvalds 		p.path_cost = pt->path_cost;
2631da177e4SLinus Torvalds 		p.designated_cost = pt->designated_cost;
264419dba8aSHoratiu Vultur 		p.state = pt->state;
265bf871ad7SXin Long 		p.top_change_ack = pt->topology_change_ack;
2661da177e4SLinus Torvalds 		p.config_pending = pt->config_pending;
2671da177e4SLinus Torvalds 		p.message_age_timer_value = br_timer_value(&pt->message_age_timer);
268cb990503SEric W. Biederman 		p.forward_delay_timer_value = br_timer_value(&pt->forward_delay_timer);
2691da177e4SLinus Torvalds 		p.hold_timer_value = br_timer_value(&pt->hold_timer);
2701da177e4SLinus Torvalds 
2711da177e4SLinus Torvalds 		rcu_read_unlock();
272bf871ad7SXin Long 
273bf871ad7SXin Long 		if (copy_to_user(argp, &p, sizeof(p)))
2741da177e4SLinus Torvalds 			return -EFAULT;
2751da177e4SLinus Torvalds 
2761da177e4SLinus Torvalds 		return 0;
277cb990503SEric W. Biederman 	}
2781da177e4SLinus Torvalds 
2791da177e4SLinus Torvalds 	case BRCTL_SET_BRIDGE_STP_STATE:
2801da177e4SLinus Torvalds 		if (!ns_capable(dev_net(dev)->user_ns, CAP_NET_ADMIN))
2811da177e4SLinus Torvalds 			return -EPERM;
2821da177e4SLinus Torvalds 
2831da177e4SLinus Torvalds 		ret = br_stp_set_enabled(br, args[1], NULL);
28414f98f25Sstephen hemminger 		break;
2851da177e4SLinus Torvalds 
286bf871ad7SXin Long 	case BRCTL_SET_BRIDGE_PRIORITY:
2871da177e4SLinus Torvalds 		if (!ns_capable(dev_net(dev)->user_ns, CAP_NET_ADMIN))
2881da177e4SLinus Torvalds 			return -EPERM;
2891da177e4SLinus Torvalds 
2901da177e4SLinus Torvalds 		br_stp_set_bridge_priority(br, args[1]);
291cb990503SEric W. Biederman 		ret = 0;
2921da177e4SLinus Torvalds 		break;
2931da177e4SLinus Torvalds 
29414f98f25Sstephen hemminger 	case BRCTL_SET_PORT_PRIORITY:
2951da177e4SLinus Torvalds 	{
2961da177e4SLinus Torvalds 		if (!ns_capable(dev_net(dev)->user_ns, CAP_NET_ADMIN))
2971da177e4SLinus Torvalds 			return -EPERM;
29814f98f25Sstephen hemminger 
29914f98f25Sstephen hemminger 		spin_lock_bh(&br->lock);
300bf871ad7SXin Long 		if ((p = br_get_port(br, args[1])) == NULL)
3011da177e4SLinus Torvalds 			ret = -EINVAL;
3021da177e4SLinus Torvalds 		else
3031da177e4SLinus Torvalds 			ret = br_stp_set_port_priority(p, args[2]);
304561d8352SArnd Bergmann 		spin_unlock_bh(&br->lock);
3051da177e4SLinus Torvalds 		break;
3061da177e4SLinus Torvalds 	}
307bf871ad7SXin Long 
308bf871ad7SXin Long 	case BRCTL_SET_PATH_COST:
30992899063SNikolay Aleksandrov 	{
310bf871ad7SXin Long 		if (!ns_capable(dev_net(dev)->user_ns, CAP_NET_ADMIN))
311bf871ad7SXin Long 			return -EPERM;
312bf871ad7SXin Long 
313bf871ad7SXin Long 		spin_lock_bh(&br->lock);
314bf871ad7SXin Long 		if ((p = br_get_port(br, args[1])) == NULL)
3151da177e4SLinus Torvalds 			ret = -EINVAL;
3161da177e4SLinus Torvalds 		else
3174aa678baSAlexey Dobriyan 			ret = br_stp_set_path_cost(p, args[2]);
3181da177e4SLinus Torvalds 		spin_unlock_bh(&br->lock);
3191da177e4SLinus Torvalds 		break;
3201da177e4SLinus Torvalds 	}
3211da177e4SLinus Torvalds 
3221da177e4SLinus Torvalds 	case BRCTL_GET_FDB_ENTRIES:
3231da177e4SLinus Torvalds 		return get_fdb_entries(br, argp, args[2], args[3]);
3241da177e4SLinus Torvalds 
3251da177e4SLinus Torvalds 	default:
3261da177e4SLinus Torvalds 		ret = -EOPNOTSUPP;
3271da177e4SLinus Torvalds 	}
3281da177e4SLinus Torvalds 
3291da177e4SLinus Torvalds 	if (!ret) {
3301da177e4SLinus Torvalds 		if (p)
3311da177e4SLinus Torvalds 			br_ifinfo_notify(RTM_NEWLINK, NULL, p);
3321da177e4SLinus Torvalds 		else
3331da177e4SLinus Torvalds 			netdev_state_change(br->dev);
3341da177e4SLinus Torvalds 	}
3350da974f4SPanagiotis Issaris 
3361da177e4SLinus Torvalds 	return ret;
3371da177e4SLinus Torvalds }
3381da177e4SLinus Torvalds 
old_deviceless(struct net * net,void __user * data)3394aa678baSAlexey Dobriyan static int old_deviceless(struct net *net, void __user *data)
3401da177e4SLinus Torvalds {
341865bfb2aSGustavo A. R. Silva 	unsigned long args[3];
342865bfb2aSGustavo A. R. Silva 	void __user *argp;
3431da177e4SLinus Torvalds 	int ret;
3441da177e4SLinus Torvalds 
3451da177e4SLinus Torvalds 	ret = br_dev_read_uargs(args, ARRAY_SIZE(args), &argp, data);
3461da177e4SLinus Torvalds 	if (ret)
3471da177e4SLinus Torvalds 		return ret;
3481da177e4SLinus Torvalds 
3491da177e4SLinus Torvalds 	switch (args[0]) {
3501da177e4SLinus Torvalds 	case BRCTL_GET_VERSION:
3511da177e4SLinus Torvalds 		return BRCTL_VERSION;
3521da177e4SLinus Torvalds 
3531da177e4SLinus Torvalds 	case BRCTL_GET_BRIDGES:
354cb990503SEric W. Biederman 	{
3551da177e4SLinus Torvalds 		int *indices;
3561da177e4SLinus Torvalds 		int ret = 0;
357cbd7ad29SNikolay Aleksandrov 
3581da177e4SLinus Torvalds 		if (args[2] >= 2048)
3591da177e4SLinus Torvalds 			return -ENOMEM;
3601da177e4SLinus Torvalds 		indices = kcalloc(args[2], sizeof(int), GFP_KERNEL);
3611da177e4SLinus Torvalds 		if (indices == NULL)
3621da177e4SLinus Torvalds 			return -ENOMEM;
3634aa678baSAlexey Dobriyan 
3641da177e4SLinus Torvalds 		args[2] = get_bridge_ifindices(net, indices, args[2]);
3654aa678baSAlexey Dobriyan 
3661da177e4SLinus Torvalds 		ret = copy_to_user(argp, indices,
3671da177e4SLinus Torvalds 				   array_size(args[2], sizeof(int)))
3681da177e4SLinus Torvalds 			? -EFAULT : args[2];
3691da177e4SLinus Torvalds 
3701da177e4SLinus Torvalds 		kfree(indices);
3711da177e4SLinus Torvalds 		return ret;
372ad2f99aeSArnd Bergmann 	}
373ad2f99aeSArnd Bergmann 
3741da177e4SLinus Torvalds 	case BRCTL_ADD_BRIDGE:
375893b1958SNikolay Aleksandrov 	case BRCTL_DEL_BRIDGE:
376893b1958SNikolay Aleksandrov 	{
377893b1958SNikolay Aleksandrov 		char buf[IFNAMSIZ];
378893b1958SNikolay Aleksandrov 
3791da177e4SLinus Torvalds 		if (!ns_capable(net->user_ns, CAP_NET_ADMIN))
3801da177e4SLinus Torvalds 			return -EPERM;
3811da177e4SLinus Torvalds 
382893b1958SNikolay Aleksandrov 		if (copy_from_user(buf, argp, IFNAMSIZ))
383893b1958SNikolay Aleksandrov 			return -EFAULT;
3841da177e4SLinus Torvalds 
3851da177e4SLinus Torvalds 		buf[IFNAMSIZ-1] = 0;
3861da177e4SLinus Torvalds 
3871da177e4SLinus Torvalds 		if (args[0] == BRCTL_ADD_BRIDGE)
3881da177e4SLinus Torvalds 			return br_add_bridge(net, buf);
389893b1958SNikolay Aleksandrov 
390893b1958SNikolay Aleksandrov 		return br_del_bridge(net, buf);
391893b1958SNikolay Aleksandrov 	}
392893b1958SNikolay Aleksandrov 	}
3931da177e4SLinus Torvalds 
394893b1958SNikolay Aleksandrov 	return -EOPNOTSUPP;
395893b1958SNikolay Aleksandrov }
396893b1958SNikolay Aleksandrov 
br_ioctl_stub(struct net * net,struct net_bridge * br,unsigned int cmd,struct ifreq * ifr,void __user * uarg)397893b1958SNikolay Aleksandrov int br_ioctl_stub(struct net *net, struct net_bridge *br, unsigned int cmd,
3981da177e4SLinus Torvalds 		  struct ifreq *ifr, void __user *uarg)
3991da177e4SLinus Torvalds {
4001da177e4SLinus Torvalds 	int ret = -EOPNOTSUPP;
401893b1958SNikolay Aleksandrov 
402893b1958SNikolay Aleksandrov 	rtnl_lock();
403893b1958SNikolay Aleksandrov 
4041da177e4SLinus Torvalds 	switch (cmd) {
405893b1958SNikolay Aleksandrov 	case SIOCGIFBR:
4061da177e4SLinus Torvalds 	case SIOCSIFBR:
4071da177e4SLinus Torvalds 		ret = old_deviceless(net, uarg);
408893b1958SNikolay Aleksandrov 		break;
409893b1958SNikolay Aleksandrov 	case SIOCBRADDBR:
4101da177e4SLinus Torvalds 	case SIOCBRDELBR:
411893b1958SNikolay Aleksandrov 	{
412893b1958SNikolay Aleksandrov 		char buf[IFNAMSIZ];
413893b1958SNikolay Aleksandrov 
414893b1958SNikolay Aleksandrov 		if (!ns_capable(net->user_ns, CAP_NET_ADMIN)) {
4151da177e4SLinus Torvalds 			ret = -EPERM;
416 			break;
417 		}
418 
419 		if (copy_from_user(buf, uarg, IFNAMSIZ)) {
420 			ret = -EFAULT;
421 			break;
422 		}
423 
424 		buf[IFNAMSIZ-1] = 0;
425 		if (cmd == SIOCBRADDBR)
426 			ret = br_add_bridge(net, buf);
427 		else
428 			ret = br_del_bridge(net, buf);
429 	}
430 		break;
431 	case SIOCBRADDIF:
432 	case SIOCBRDELIF:
433 		ret = add_del_if(br, ifr->ifr_ifindex, cmd == SIOCBRADDIF);
434 		break;
435 	}
436 
437 	rtnl_unlock();
438 
439 	return ret;
440 }
441