xref: /linux/net/bridge/br_ioctl.c (revision 03ab8e6297acd1bc0eedaa050e2a1635c576fd11)
12874c5fdSThomas Gleixner // SPDX-License-Identifier: GPL-2.0-or-later
21da177e4SLinus Torvalds /*
31da177e4SLinus Torvalds  *	Ioctl handler
41da177e4SLinus Torvalds  *	Linux ethernet bridge
51da177e4SLinus Torvalds  *
61da177e4SLinus Torvalds  *	Authors:
71da177e4SLinus Torvalds  *	Lennert Buytenhek		<buytenh@gnu.org>
81da177e4SLinus Torvalds  */
91da177e4SLinus Torvalds 
104fc268d2SRandy Dunlap #include <linux/capability.h>
11*b6459415SJakub Kicinski #include <linux/compat.h>
121da177e4SLinus Torvalds #include <linux/kernel.h>
131da177e4SLinus Torvalds #include <linux/if_bridge.h>
141da177e4SLinus Torvalds #include <linux/netdevice.h>
155a0e3ad6STejun Heo #include <linux/slab.h>
161da177e4SLinus Torvalds #include <linux/times.h>
17881d966bSEric W. Biederman #include <net/net_namespace.h>
187c0f6ba6SLinus Torvalds #include <linux/uaccess.h>
191da177e4SLinus Torvalds #include "br_private.h"
201da177e4SLinus Torvalds 
get_bridge_ifindices(struct net * net,int * indices,int num)214aa678baSAlexey Dobriyan static int get_bridge_ifindices(struct net *net, int *indices, int num)
221da177e4SLinus Torvalds {
231da177e4SLinus Torvalds 	struct net_device *dev;
241da177e4SLinus Torvalds 	int i = 0;
251da177e4SLinus Torvalds 
2631ca0458SNikolay Aleksandrov 	rcu_read_lock();
2731ca0458SNikolay Aleksandrov 	for_each_netdev_rcu(net, dev) {
287562f876SPavel Emelianov 		if (i >= num)
297562f876SPavel Emelianov 			break;
30254ec036SKyungrok Chung 		if (netif_is_bridge_master(dev))
311da177e4SLinus Torvalds 			indices[i++] = dev->ifindex;
321da177e4SLinus Torvalds 	}
3331ca0458SNikolay Aleksandrov 	rcu_read_unlock();
341da177e4SLinus Torvalds 
351da177e4SLinus Torvalds 	return i;
361da177e4SLinus Torvalds }
371da177e4SLinus Torvalds 
381da177e4SLinus Torvalds /* called with RTNL */
get_port_ifindices(struct net_bridge * br,int * ifindices,int num)391da177e4SLinus Torvalds static void get_port_ifindices(struct net_bridge *br, int *ifindices, int num)
401da177e4SLinus Torvalds {
411da177e4SLinus Torvalds 	struct net_bridge_port *p;
421da177e4SLinus Torvalds 
431da177e4SLinus Torvalds 	list_for_each_entry(p, &br->port_list, list) {
441da177e4SLinus Torvalds 		if (p->port_no < num)
451da177e4SLinus Torvalds 			ifindices[p->port_no] = p->dev->ifindex;
461da177e4SLinus Torvalds 	}
471da177e4SLinus Torvalds }
481da177e4SLinus Torvalds 
491da177e4SLinus Torvalds /*
501da177e4SLinus Torvalds  * Format up to a page worth of forwarding table entries
511da177e4SLinus Torvalds  * userbuf -- where to copy result
521da177e4SLinus Torvalds  * maxnum  -- maximum number of entries desired
531da177e4SLinus Torvalds  *            (limited to a page for sanity)
541da177e4SLinus Torvalds  * offset  -- number of records to skip
551da177e4SLinus Torvalds  */
get_fdb_entries(struct net_bridge * br,void __user * userbuf,unsigned long maxnum,unsigned long offset)561da177e4SLinus Torvalds static int get_fdb_entries(struct net_bridge *br, void __user *userbuf,
571da177e4SLinus Torvalds 			   unsigned long maxnum, unsigned long offset)
581da177e4SLinus Torvalds {
591da177e4SLinus Torvalds 	int num;
601da177e4SLinus Torvalds 	void *buf;
61ba8379b2SChris Wright 	size_t size;
621da177e4SLinus Torvalds 
63ba8379b2SChris Wright 	/* Clamp size to PAGE_SIZE, test maxnum to avoid overflow */
64ba8379b2SChris Wright 	if (maxnum > PAGE_SIZE/sizeof(struct __fdb_entry))
651da177e4SLinus Torvalds 		maxnum = PAGE_SIZE/sizeof(struct __fdb_entry);
66ba8379b2SChris Wright 
67ba8379b2SChris Wright 	size = maxnum * sizeof(struct __fdb_entry);
681da177e4SLinus Torvalds 
691da177e4SLinus Torvalds 	buf = kmalloc(size, GFP_USER);
701da177e4SLinus Torvalds 	if (!buf)
711da177e4SLinus Torvalds 		return -ENOMEM;
721da177e4SLinus Torvalds 
731da177e4SLinus Torvalds 	num = br_fdb_fillbuf(br, buf, maxnum, offset);
741da177e4SLinus Torvalds 	if (num > 0) {
75865bfb2aSGustavo A. R. Silva 		if (copy_to_user(userbuf, buf,
76865bfb2aSGustavo A. R. Silva 				 array_size(num, sizeof(struct __fdb_entry))))
771da177e4SLinus Torvalds 			num = -EFAULT;
781da177e4SLinus Torvalds 	}
791da177e4SLinus Torvalds 	kfree(buf);
801da177e4SLinus Torvalds 
811da177e4SLinus Torvalds 	return num;
821da177e4SLinus Torvalds }
831da177e4SLinus Torvalds 
8431ef30c7SEric Dumazet /* called with RTNL */
add_del_if(struct net_bridge * br,int ifindex,int isadd)851da177e4SLinus Torvalds static int add_del_if(struct net_bridge *br, int ifindex, int isadd)
861da177e4SLinus Torvalds {
87cb990503SEric W. Biederman 	struct net *net = dev_net(br->dev);
881da177e4SLinus Torvalds 	struct net_device *dev;
891da177e4SLinus Torvalds 	int ret;
901da177e4SLinus Torvalds 
91cb990503SEric W. Biederman 	if (!ns_capable(net->user_ns, CAP_NET_ADMIN))
921da177e4SLinus Torvalds 		return -EPERM;
931da177e4SLinus Torvalds 
94cb990503SEric W. Biederman 	dev = __dev_get_by_index(net, ifindex);
951da177e4SLinus Torvalds 	if (dev == NULL)
961da177e4SLinus Torvalds 		return -EINVAL;
971da177e4SLinus Torvalds 
981da177e4SLinus Torvalds 	if (isadd)
99ca752be0SDavid Ahern 		ret = br_add_if(br, dev, NULL);
100eccaa9e5SDavid S. Miller 	else
1011da177e4SLinus Torvalds 		ret = br_del_if(br, dev);
1021da177e4SLinus Torvalds 
1031da177e4SLinus Torvalds 	return ret;
1041da177e4SLinus Torvalds }
1051da177e4SLinus Torvalds 
106fd3a4590SRemi Pommarel #define BR_UARGS_MAX 4
br_dev_read_uargs(unsigned long * args,size_t nr_args,void __user ** argp,void __user * data)107fd3a4590SRemi Pommarel static int br_dev_read_uargs(unsigned long *args, size_t nr_args,
108fd3a4590SRemi Pommarel 			     void __user **argp, void __user *data)
109fd3a4590SRemi Pommarel {
110fd3a4590SRemi Pommarel 	int ret;
111fd3a4590SRemi Pommarel 
112fd3a4590SRemi Pommarel 	if (nr_args < 2 || nr_args > BR_UARGS_MAX)
113fd3a4590SRemi Pommarel 		return -EINVAL;
114fd3a4590SRemi Pommarel 
115fd3a4590SRemi Pommarel 	if (in_compat_syscall()) {
116fd3a4590SRemi Pommarel 		unsigned int cargs[BR_UARGS_MAX];
117fd3a4590SRemi Pommarel 		int i;
118fd3a4590SRemi Pommarel 
119fd3a4590SRemi Pommarel 		ret = copy_from_user(cargs, data, nr_args * sizeof(*cargs));
120fd3a4590SRemi Pommarel 		if (ret)
121fd3a4590SRemi Pommarel 			goto fault;
122fd3a4590SRemi Pommarel 
123fd3a4590SRemi Pommarel 		for (i = 0; i < nr_args; ++i)
124fd3a4590SRemi Pommarel 			args[i] = cargs[i];
125fd3a4590SRemi Pommarel 
126fd3a4590SRemi Pommarel 		*argp = compat_ptr(args[1]);
127fd3a4590SRemi Pommarel 	} else {
128fd3a4590SRemi Pommarel 		ret = copy_from_user(args, data, nr_args * sizeof(*args));
129fd3a4590SRemi Pommarel 		if (ret)
130fd3a4590SRemi Pommarel 			goto fault;
131fd3a4590SRemi Pommarel 		*argp = (void __user *)args[1];
132fd3a4590SRemi Pommarel 	}
133fd3a4590SRemi Pommarel 
134fd3a4590SRemi Pommarel 	return 0;
135fd3a4590SRemi Pommarel fault:
136fd3a4590SRemi Pommarel 	return -EFAULT;
137fd3a4590SRemi Pommarel }
138fd3a4590SRemi Pommarel 
1391da177e4SLinus Torvalds /*
1401da177e4SLinus Torvalds  * Legacy ioctl's through SIOCDEVPRIVATE
1414bbd026cSRandy Dunlap  * This interface is deprecated because it was too difficult
14225985edcSLucas De Marchi  * to do the translation for 32/64bit ioctl compatibility.
1431da177e4SLinus Torvalds  */
br_dev_siocdevprivate(struct net_device * dev,struct ifreq * rq,void __user * data,int cmd)144fd3a4590SRemi Pommarel int br_dev_siocdevprivate(struct net_device *dev, struct ifreq *rq,
145fd3a4590SRemi Pommarel 			  void __user *data, int cmd)
1461da177e4SLinus Torvalds {
1471da177e4SLinus Torvalds 	struct net_bridge *br = netdev_priv(dev);
148bf871ad7SXin Long 	struct net_bridge_port *p = NULL;
1491da177e4SLinus Torvalds 	unsigned long args[4];
150561d8352SArnd Bergmann 	void __user *argp;
151fd3a4590SRemi Pommarel 	int ret;
1521da177e4SLinus Torvalds 
153fd3a4590SRemi Pommarel 	ret = br_dev_read_uargs(args, ARRAY_SIZE(args), &argp, data);
154fd3a4590SRemi Pommarel 	if (ret)
155fd3a4590SRemi Pommarel 		return ret;
156561d8352SArnd Bergmann 
1571da177e4SLinus Torvalds 	switch (args[0]) {
1581da177e4SLinus Torvalds 	case BRCTL_ADD_IF:
1591da177e4SLinus Torvalds 	case BRCTL_DEL_IF:
1601da177e4SLinus Torvalds 		return add_del_if(br, args[1], args[0] == BRCTL_ADD_IF);
1611da177e4SLinus Torvalds 
1621da177e4SLinus Torvalds 	case BRCTL_GET_BRIDGE_INFO:
1631da177e4SLinus Torvalds 	{
1641da177e4SLinus Torvalds 		struct __bridge_info b;
1651da177e4SLinus Torvalds 
1661da177e4SLinus Torvalds 		memset(&b, 0, sizeof(struct __bridge_info));
1671da177e4SLinus Torvalds 		rcu_read_lock();
1681da177e4SLinus Torvalds 		memcpy(&b.designated_root, &br->designated_root, 8);
1691da177e4SLinus Torvalds 		memcpy(&b.bridge_id, &br->bridge_id, 8);
1701da177e4SLinus Torvalds 		b.root_path_cost = br->root_path_cost;
1711da177e4SLinus Torvalds 		b.max_age = jiffies_to_clock_t(br->max_age);
1721da177e4SLinus Torvalds 		b.hello_time = jiffies_to_clock_t(br->hello_time);
1731da177e4SLinus Torvalds 		b.forward_delay = br->forward_delay;
1741da177e4SLinus Torvalds 		b.bridge_max_age = br->bridge_max_age;
1751da177e4SLinus Torvalds 		b.bridge_hello_time = br->bridge_hello_time;
1761da177e4SLinus Torvalds 		b.bridge_forward_delay = jiffies_to_clock_t(br->bridge_forward_delay);
1771da177e4SLinus Torvalds 		b.topology_change = br->topology_change;
1781da177e4SLinus Torvalds 		b.topology_change_detected = br->topology_change_detected;
1791da177e4SLinus Torvalds 		b.root_port = br->root_port;
1809cde0708SStephen Hemminger 
1819cde0708SStephen Hemminger 		b.stp_enabled = (br->stp_enabled != BR_NO_STP);
1821da177e4SLinus Torvalds 		b.ageing_time = jiffies_to_clock_t(br->ageing_time);
1831da177e4SLinus Torvalds 		b.hello_timer_value = br_timer_value(&br->hello_timer);
1841da177e4SLinus Torvalds 		b.tcn_timer_value = br_timer_value(&br->tcn_timer);
1851da177e4SLinus Torvalds 		b.topology_change_timer_value = br_timer_value(&br->topology_change_timer);
186f7cdee8aSNikolay Aleksandrov 		b.gc_timer_value = br_timer_value(&br->gc_work.timer);
1871da177e4SLinus Torvalds 		rcu_read_unlock();
1881da177e4SLinus Torvalds 
1891da177e4SLinus Torvalds 		if (copy_to_user((void __user *)args[1], &b, sizeof(b)))
1901da177e4SLinus Torvalds 			return -EFAULT;
1911da177e4SLinus Torvalds 
1921da177e4SLinus Torvalds 		return 0;
1931da177e4SLinus Torvalds 	}
1941da177e4SLinus Torvalds 
1951da177e4SLinus Torvalds 	case BRCTL_GET_PORT_LIST:
1961da177e4SLinus Torvalds 	{
1971da177e4SLinus Torvalds 		int num, *indices;
1981da177e4SLinus Torvalds 
1991da177e4SLinus Torvalds 		num = args[2];
2001da177e4SLinus Torvalds 		if (num < 0)
2011da177e4SLinus Torvalds 			return -EINVAL;
2021da177e4SLinus Torvalds 		if (num == 0)
2031da177e4SLinus Torvalds 			num = 256;
2041da177e4SLinus Torvalds 		if (num > BR_MAX_PORTS)
2051da177e4SLinus Torvalds 			num = BR_MAX_PORTS;
2061da177e4SLinus Torvalds 
2070da974f4SPanagiotis Issaris 		indices = kcalloc(num, sizeof(int), GFP_KERNEL);
2081da177e4SLinus Torvalds 		if (indices == NULL)
2091da177e4SLinus Torvalds 			return -ENOMEM;
2101da177e4SLinus Torvalds 
2111da177e4SLinus Torvalds 		get_port_ifindices(br, indices, num);
212865bfb2aSGustavo A. R. Silva 		if (copy_to_user(argp, indices, array_size(num, sizeof(int))))
2131da177e4SLinus Torvalds 			num =  -EFAULT;
2141da177e4SLinus Torvalds 		kfree(indices);
2151da177e4SLinus Torvalds 		return num;
2161da177e4SLinus Torvalds 	}
2171da177e4SLinus Torvalds 
2181da177e4SLinus Torvalds 	case BRCTL_SET_BRIDGE_FORWARD_DELAY:
219cb990503SEric W. Biederman 		if (!ns_capable(dev_net(dev)->user_ns, CAP_NET_ADMIN))
2201da177e4SLinus Torvalds 			return -EPERM;
2211da177e4SLinus Torvalds 
222bf871ad7SXin Long 		ret = br_set_forward_delay(br, args[1]);
223bf871ad7SXin Long 		break;
2241da177e4SLinus Torvalds 
2251da177e4SLinus Torvalds 	case BRCTL_SET_BRIDGE_HELLO_TIME:
226cb990503SEric W. Biederman 		if (!ns_capable(dev_net(dev)->user_ns, CAP_NET_ADMIN))
2271da177e4SLinus Torvalds 			return -EPERM;
2281da177e4SLinus Torvalds 
229bf871ad7SXin Long 		ret = br_set_hello_time(br, args[1]);
230bf871ad7SXin Long 		break;
2311da177e4SLinus Torvalds 
2321da177e4SLinus Torvalds 	case BRCTL_SET_BRIDGE_MAX_AGE:
233cb990503SEric W. Biederman 		if (!ns_capable(dev_net(dev)->user_ns, CAP_NET_ADMIN))
2341da177e4SLinus Torvalds 			return -EPERM;
2351da177e4SLinus Torvalds 
236bf871ad7SXin Long 		ret = br_set_max_age(br, args[1]);
237bf871ad7SXin Long 		break;
2381da177e4SLinus Torvalds 
2391da177e4SLinus Torvalds 	case BRCTL_SET_AGEING_TIME:
240cb990503SEric W. Biederman 		if (!ns_capable(dev_net(dev)->user_ns, CAP_NET_ADMIN))
2411da177e4SLinus Torvalds 			return -EPERM;
2421da177e4SLinus Torvalds 
243bf871ad7SXin Long 		ret = br_set_ageing_time(br, args[1]);
244bf871ad7SXin Long 		break;
2451da177e4SLinus Torvalds 
2461da177e4SLinus Torvalds 	case BRCTL_GET_PORT_INFO:
2471da177e4SLinus Torvalds 	{
2481da177e4SLinus Torvalds 		struct __port_info p;
2491da177e4SLinus Torvalds 		struct net_bridge_port *pt;
2501da177e4SLinus Torvalds 
2511da177e4SLinus Torvalds 		rcu_read_lock();
2521da177e4SLinus Torvalds 		if ((pt = br_get_port(br, args[2])) == NULL) {
2531da177e4SLinus Torvalds 			rcu_read_unlock();
2541da177e4SLinus Torvalds 			return -EINVAL;
2551da177e4SLinus Torvalds 		}
2561da177e4SLinus Torvalds 
2571da177e4SLinus Torvalds 		memset(&p, 0, sizeof(struct __port_info));
2581da177e4SLinus Torvalds 		memcpy(&p.designated_root, &pt->designated_root, 8);
2591da177e4SLinus Torvalds 		memcpy(&p.designated_bridge, &pt->designated_bridge, 8);
2601da177e4SLinus Torvalds 		p.port_id = pt->port_id;
2611da177e4SLinus Torvalds 		p.designated_port = pt->designated_port;
2621da177e4SLinus Torvalds 		p.path_cost = pt->path_cost;
2631da177e4SLinus Torvalds 		p.designated_cost = pt->designated_cost;
2641da177e4SLinus Torvalds 		p.state = pt->state;
2651da177e4SLinus Torvalds 		p.top_change_ack = pt->topology_change_ack;
2661da177e4SLinus Torvalds 		p.config_pending = pt->config_pending;
2671da177e4SLinus Torvalds 		p.message_age_timer_value = br_timer_value(&pt->message_age_timer);
2681da177e4SLinus Torvalds 		p.forward_delay_timer_value = br_timer_value(&pt->forward_delay_timer);
2691da177e4SLinus Torvalds 		p.hold_timer_value = br_timer_value(&pt->hold_timer);
2701da177e4SLinus Torvalds 
2711da177e4SLinus Torvalds 		rcu_read_unlock();
2721da177e4SLinus Torvalds 
273561d8352SArnd Bergmann 		if (copy_to_user(argp, &p, sizeof(p)))
2741da177e4SLinus Torvalds 			return -EFAULT;
2751da177e4SLinus Torvalds 
2761da177e4SLinus Torvalds 		return 0;
2771da177e4SLinus Torvalds 	}
2781da177e4SLinus Torvalds 
2791da177e4SLinus Torvalds 	case BRCTL_SET_BRIDGE_STP_STATE:
280cb990503SEric W. Biederman 		if (!ns_capable(dev_net(dev)->user_ns, CAP_NET_ADMIN))
2811da177e4SLinus Torvalds 			return -EPERM;
2821da177e4SLinus Torvalds 
283419dba8aSHoratiu Vultur 		ret = br_stp_set_enabled(br, args[1], NULL);
284bf871ad7SXin Long 		break;
2851da177e4SLinus Torvalds 
2861da177e4SLinus Torvalds 	case BRCTL_SET_BRIDGE_PRIORITY:
287cb990503SEric W. Biederman 		if (!ns_capable(dev_net(dev)->user_ns, CAP_NET_ADMIN))
2881da177e4SLinus Torvalds 			return -EPERM;
2891da177e4SLinus Torvalds 
2901da177e4SLinus Torvalds 		br_stp_set_bridge_priority(br, args[1]);
291bf871ad7SXin Long 		ret = 0;
292bf871ad7SXin Long 		break;
2931da177e4SLinus Torvalds 
2941da177e4SLinus Torvalds 	case BRCTL_SET_PORT_PRIORITY:
2951da177e4SLinus Torvalds 	{
296cb990503SEric W. Biederman 		if (!ns_capable(dev_net(dev)->user_ns, CAP_NET_ADMIN))
2971da177e4SLinus Torvalds 			return -EPERM;
2981da177e4SLinus Torvalds 
2991da177e4SLinus Torvalds 		spin_lock_bh(&br->lock);
3001da177e4SLinus Torvalds 		if ((p = br_get_port(br, args[1])) == NULL)
3011da177e4SLinus Torvalds 			ret = -EINVAL;
3021da177e4SLinus Torvalds 		else
30314f98f25Sstephen hemminger 			ret = br_stp_set_port_priority(p, args[2]);
3041da177e4SLinus Torvalds 		spin_unlock_bh(&br->lock);
305bf871ad7SXin Long 		break;
3061da177e4SLinus Torvalds 	}
3071da177e4SLinus Torvalds 
3081da177e4SLinus Torvalds 	case BRCTL_SET_PATH_COST:
3091da177e4SLinus Torvalds 	{
310cb990503SEric W. Biederman 		if (!ns_capable(dev_net(dev)->user_ns, CAP_NET_ADMIN))
3111da177e4SLinus Torvalds 			return -EPERM;
3121da177e4SLinus Torvalds 
31314f98f25Sstephen hemminger 		spin_lock_bh(&br->lock);
3141da177e4SLinus Torvalds 		if ((p = br_get_port(br, args[1])) == NULL)
3151da177e4SLinus Torvalds 			ret = -EINVAL;
3161da177e4SLinus Torvalds 		else
31714f98f25Sstephen hemminger 			ret = br_stp_set_path_cost(p, args[2]);
31814f98f25Sstephen hemminger 		spin_unlock_bh(&br->lock);
319bf871ad7SXin Long 		break;
3201da177e4SLinus Torvalds 	}
3211da177e4SLinus Torvalds 
3221da177e4SLinus Torvalds 	case BRCTL_GET_FDB_ENTRIES:
323561d8352SArnd Bergmann 		return get_fdb_entries(br, argp, args[2], args[3]);
324fd3a4590SRemi Pommarel 
325fd3a4590SRemi Pommarel 	default:
326fd3a4590SRemi Pommarel 		ret = -EOPNOTSUPP;
3271da177e4SLinus Torvalds 	}
3281da177e4SLinus Torvalds 
329bf871ad7SXin Long 	if (!ret) {
330bf871ad7SXin Long 		if (p)
33192899063SNikolay Aleksandrov 			br_ifinfo_notify(RTM_NEWLINK, NULL, p);
332bf871ad7SXin Long 		else
333bf871ad7SXin Long 			netdev_state_change(br->dev);
334bf871ad7SXin Long 	}
335bf871ad7SXin Long 
336bf871ad7SXin Long 	return ret;
3371da177e4SLinus Torvalds }
3381da177e4SLinus Torvalds 
old_deviceless(struct net * net,void __user * data)339fd3a4590SRemi Pommarel static int old_deviceless(struct net *net, void __user *data)
3401da177e4SLinus Torvalds {
3411da177e4SLinus Torvalds 	unsigned long args[3];
342fd3a4590SRemi Pommarel 	void __user *argp;
343fd3a4590SRemi Pommarel 	int ret;
3441da177e4SLinus Torvalds 
345fd3a4590SRemi Pommarel 	ret = br_dev_read_uargs(args, ARRAY_SIZE(args), &argp, data);
346fd3a4590SRemi Pommarel 	if (ret)
347fd3a4590SRemi Pommarel 		return ret;
3481da177e4SLinus Torvalds 
3491da177e4SLinus Torvalds 	switch (args[0]) {
3501da177e4SLinus Torvalds 	case BRCTL_GET_VERSION:
3511da177e4SLinus Torvalds 		return BRCTL_VERSION;
3521da177e4SLinus Torvalds 
3531da177e4SLinus Torvalds 	case BRCTL_GET_BRIDGES:
3541da177e4SLinus Torvalds 	{
3551da177e4SLinus Torvalds 		int *indices;
3561da177e4SLinus Torvalds 		int ret = 0;
3571da177e4SLinus Torvalds 
3581da177e4SLinus Torvalds 		if (args[2] >= 2048)
3591da177e4SLinus Torvalds 			return -ENOMEM;
3600da974f4SPanagiotis Issaris 		indices = kcalloc(args[2], sizeof(int), GFP_KERNEL);
3611da177e4SLinus Torvalds 		if (indices == NULL)
3621da177e4SLinus Torvalds 			return -ENOMEM;
3631da177e4SLinus Torvalds 
3644aa678baSAlexey Dobriyan 		args[2] = get_bridge_ifindices(net, indices, args[2]);
3651da177e4SLinus Torvalds 
366fd3a4590SRemi Pommarel 		ret = copy_to_user(argp, indices,
367865bfb2aSGustavo A. R. Silva 				   array_size(args[2], sizeof(int)))
3681da177e4SLinus Torvalds 			? -EFAULT : args[2];
3691da177e4SLinus Torvalds 
3701da177e4SLinus Torvalds 		kfree(indices);
3711da177e4SLinus Torvalds 		return ret;
3721da177e4SLinus Torvalds 	}
3731da177e4SLinus Torvalds 
3741da177e4SLinus Torvalds 	case BRCTL_ADD_BRIDGE:
3751da177e4SLinus Torvalds 	case BRCTL_DEL_BRIDGE:
3761da177e4SLinus Torvalds 	{
3771da177e4SLinus Torvalds 		char buf[IFNAMSIZ];
3781da177e4SLinus Torvalds 
379cb990503SEric W. Biederman 		if (!ns_capable(net->user_ns, CAP_NET_ADMIN))
3801da177e4SLinus Torvalds 			return -EPERM;
3811da177e4SLinus Torvalds 
382fd3a4590SRemi Pommarel 		if (copy_from_user(buf, argp, IFNAMSIZ))
3831da177e4SLinus Torvalds 			return -EFAULT;
3841da177e4SLinus Torvalds 
3851da177e4SLinus Torvalds 		buf[IFNAMSIZ-1] = 0;
3861da177e4SLinus Torvalds 
3871da177e4SLinus Torvalds 		if (args[0] == BRCTL_ADD_BRIDGE)
3884aa678baSAlexey Dobriyan 			return br_add_bridge(net, buf);
3891da177e4SLinus Torvalds 
3904aa678baSAlexey Dobriyan 		return br_del_bridge(net, buf);
3911da177e4SLinus Torvalds 	}
3921da177e4SLinus Torvalds 	}
3931da177e4SLinus Torvalds 
3941da177e4SLinus Torvalds 	return -EOPNOTSUPP;
3951da177e4SLinus Torvalds }
3961da177e4SLinus Torvalds 
br_ioctl_stub(struct net * net,struct net_bridge * br,unsigned int cmd,struct ifreq * ifr,void __user * uarg)397ad2f99aeSArnd Bergmann int br_ioctl_stub(struct net *net, struct net_bridge *br, unsigned int cmd,
398ad2f99aeSArnd Bergmann 		  struct ifreq *ifr, void __user *uarg)
3991da177e4SLinus Torvalds {
400893b1958SNikolay Aleksandrov 	int ret = -EOPNOTSUPP;
401893b1958SNikolay Aleksandrov 
402893b1958SNikolay Aleksandrov 	rtnl_lock();
403893b1958SNikolay Aleksandrov 
4041da177e4SLinus Torvalds 	switch (cmd) {
4051da177e4SLinus Torvalds 	case SIOCGIFBR:
4061da177e4SLinus Torvalds 	case SIOCSIFBR:
407893b1958SNikolay Aleksandrov 		ret = old_deviceless(net, uarg);
408893b1958SNikolay Aleksandrov 		break;
4091da177e4SLinus Torvalds 	case SIOCBRADDBR:
4101da177e4SLinus Torvalds 	case SIOCBRDELBR:
4111da177e4SLinus Torvalds 	{
4121da177e4SLinus Torvalds 		char buf[IFNAMSIZ];
4131da177e4SLinus Torvalds 
414893b1958SNikolay Aleksandrov 		if (!ns_capable(net->user_ns, CAP_NET_ADMIN)) {
415893b1958SNikolay Aleksandrov 			ret = -EPERM;
416893b1958SNikolay Aleksandrov 			break;
417893b1958SNikolay Aleksandrov 		}
4181da177e4SLinus Torvalds 
419893b1958SNikolay Aleksandrov 		if (copy_from_user(buf, uarg, IFNAMSIZ)) {
420893b1958SNikolay Aleksandrov 			ret = -EFAULT;
421893b1958SNikolay Aleksandrov 			break;
422893b1958SNikolay Aleksandrov 		}
4231da177e4SLinus Torvalds 
4241da177e4SLinus Torvalds 		buf[IFNAMSIZ-1] = 0;
4251da177e4SLinus Torvalds 		if (cmd == SIOCBRADDBR)
426893b1958SNikolay Aleksandrov 			ret = br_add_bridge(net, buf);
427893b1958SNikolay Aleksandrov 		else
428893b1958SNikolay Aleksandrov 			ret = br_del_bridge(net, buf);
4291da177e4SLinus Torvalds 	}
430893b1958SNikolay Aleksandrov 		break;
4311da177e4SLinus Torvalds 	case SIOCBRADDIF:
4321da177e4SLinus Torvalds 	case SIOCBRDELIF:
433893b1958SNikolay Aleksandrov 		ret = add_del_if(br, ifr->ifr_ifindex, cmd == SIOCBRADDIF);
434893b1958SNikolay Aleksandrov 		break;
4351da177e4SLinus Torvalds 	}
436893b1958SNikolay Aleksandrov 
437893b1958SNikolay Aleksandrov 	rtnl_unlock();
438893b1958SNikolay Aleksandrov 
439893b1958SNikolay Aleksandrov 	return ret;
4401da177e4SLinus Torvalds }
441