162306a36Sopenharmony_ci// SPDX-License-Identifier: GPL-2.0-or-later
262306a36Sopenharmony_ci/*
362306a36Sopenharmony_ci *	Ioctl handler
462306a36Sopenharmony_ci *	Linux ethernet bridge
562306a36Sopenharmony_ci *
662306a36Sopenharmony_ci *	Authors:
762306a36Sopenharmony_ci *	Lennert Buytenhek		<buytenh@gnu.org>
862306a36Sopenharmony_ci */
962306a36Sopenharmony_ci
1062306a36Sopenharmony_ci#include <linux/capability.h>
1162306a36Sopenharmony_ci#include <linux/compat.h>
1262306a36Sopenharmony_ci#include <linux/kernel.h>
1362306a36Sopenharmony_ci#include <linux/if_bridge.h>
1462306a36Sopenharmony_ci#include <linux/netdevice.h>
1562306a36Sopenharmony_ci#include <linux/slab.h>
1662306a36Sopenharmony_ci#include <linux/times.h>
1762306a36Sopenharmony_ci#include <net/net_namespace.h>
1862306a36Sopenharmony_ci#include <linux/uaccess.h>
1962306a36Sopenharmony_ci#include "br_private.h"
2062306a36Sopenharmony_ci
2162306a36Sopenharmony_cistatic int get_bridge_ifindices(struct net *net, int *indices, int num)
2262306a36Sopenharmony_ci{
2362306a36Sopenharmony_ci	struct net_device *dev;
2462306a36Sopenharmony_ci	int i = 0;
2562306a36Sopenharmony_ci
2662306a36Sopenharmony_ci	rcu_read_lock();
2762306a36Sopenharmony_ci	for_each_netdev_rcu(net, dev) {
2862306a36Sopenharmony_ci		if (i >= num)
2962306a36Sopenharmony_ci			break;
3062306a36Sopenharmony_ci		if (netif_is_bridge_master(dev))
3162306a36Sopenharmony_ci			indices[i++] = dev->ifindex;
3262306a36Sopenharmony_ci	}
3362306a36Sopenharmony_ci	rcu_read_unlock();
3462306a36Sopenharmony_ci
3562306a36Sopenharmony_ci	return i;
3662306a36Sopenharmony_ci}
3762306a36Sopenharmony_ci
3862306a36Sopenharmony_ci/* called with RTNL */
3962306a36Sopenharmony_cistatic void get_port_ifindices(struct net_bridge *br, int *ifindices, int num)
4062306a36Sopenharmony_ci{
4162306a36Sopenharmony_ci	struct net_bridge_port *p;
4262306a36Sopenharmony_ci
4362306a36Sopenharmony_ci	list_for_each_entry(p, &br->port_list, list) {
4462306a36Sopenharmony_ci		if (p->port_no < num)
4562306a36Sopenharmony_ci			ifindices[p->port_no] = p->dev->ifindex;
4662306a36Sopenharmony_ci	}
4762306a36Sopenharmony_ci}
4862306a36Sopenharmony_ci
4962306a36Sopenharmony_ci/*
5062306a36Sopenharmony_ci * Format up to a page worth of forwarding table entries
5162306a36Sopenharmony_ci * userbuf -- where to copy result
5262306a36Sopenharmony_ci * maxnum  -- maximum number of entries desired
5362306a36Sopenharmony_ci *            (limited to a page for sanity)
5462306a36Sopenharmony_ci * offset  -- number of records to skip
5562306a36Sopenharmony_ci */
5662306a36Sopenharmony_cistatic int get_fdb_entries(struct net_bridge *br, void __user *userbuf,
5762306a36Sopenharmony_ci			   unsigned long maxnum, unsigned long offset)
5862306a36Sopenharmony_ci{
5962306a36Sopenharmony_ci	int num;
6062306a36Sopenharmony_ci	void *buf;
6162306a36Sopenharmony_ci	size_t size;
6262306a36Sopenharmony_ci
6362306a36Sopenharmony_ci	/* Clamp size to PAGE_SIZE, test maxnum to avoid overflow */
6462306a36Sopenharmony_ci	if (maxnum > PAGE_SIZE/sizeof(struct __fdb_entry))
6562306a36Sopenharmony_ci		maxnum = PAGE_SIZE/sizeof(struct __fdb_entry);
6662306a36Sopenharmony_ci
6762306a36Sopenharmony_ci	size = maxnum * sizeof(struct __fdb_entry);
6862306a36Sopenharmony_ci
6962306a36Sopenharmony_ci	buf = kmalloc(size, GFP_USER);
7062306a36Sopenharmony_ci	if (!buf)
7162306a36Sopenharmony_ci		return -ENOMEM;
7262306a36Sopenharmony_ci
7362306a36Sopenharmony_ci	num = br_fdb_fillbuf(br, buf, maxnum, offset);
7462306a36Sopenharmony_ci	if (num > 0) {
7562306a36Sopenharmony_ci		if (copy_to_user(userbuf, buf,
7662306a36Sopenharmony_ci				 array_size(num, sizeof(struct __fdb_entry))))
7762306a36Sopenharmony_ci			num = -EFAULT;
7862306a36Sopenharmony_ci	}
7962306a36Sopenharmony_ci	kfree(buf);
8062306a36Sopenharmony_ci
8162306a36Sopenharmony_ci	return num;
8262306a36Sopenharmony_ci}
8362306a36Sopenharmony_ci
8462306a36Sopenharmony_ci/* called with RTNL */
8562306a36Sopenharmony_cistatic int add_del_if(struct net_bridge *br, int ifindex, int isadd)
8662306a36Sopenharmony_ci{
8762306a36Sopenharmony_ci	struct net *net = dev_net(br->dev);
8862306a36Sopenharmony_ci	struct net_device *dev;
8962306a36Sopenharmony_ci	int ret;
9062306a36Sopenharmony_ci
9162306a36Sopenharmony_ci	if (!ns_capable(net->user_ns, CAP_NET_ADMIN))
9262306a36Sopenharmony_ci		return -EPERM;
9362306a36Sopenharmony_ci
9462306a36Sopenharmony_ci	dev = __dev_get_by_index(net, ifindex);
9562306a36Sopenharmony_ci	if (dev == NULL)
9662306a36Sopenharmony_ci		return -EINVAL;
9762306a36Sopenharmony_ci
9862306a36Sopenharmony_ci	if (isadd)
9962306a36Sopenharmony_ci		ret = br_add_if(br, dev, NULL);
10062306a36Sopenharmony_ci	else
10162306a36Sopenharmony_ci		ret = br_del_if(br, dev);
10262306a36Sopenharmony_ci
10362306a36Sopenharmony_ci	return ret;
10462306a36Sopenharmony_ci}
10562306a36Sopenharmony_ci
10662306a36Sopenharmony_ci#define BR_UARGS_MAX 4
10762306a36Sopenharmony_cistatic int br_dev_read_uargs(unsigned long *args, size_t nr_args,
10862306a36Sopenharmony_ci			     void __user **argp, void __user *data)
10962306a36Sopenharmony_ci{
11062306a36Sopenharmony_ci	int ret;
11162306a36Sopenharmony_ci
11262306a36Sopenharmony_ci	if (nr_args < 2 || nr_args > BR_UARGS_MAX)
11362306a36Sopenharmony_ci		return -EINVAL;
11462306a36Sopenharmony_ci
11562306a36Sopenharmony_ci	if (in_compat_syscall()) {
11662306a36Sopenharmony_ci		unsigned int cargs[BR_UARGS_MAX];
11762306a36Sopenharmony_ci		int i;
11862306a36Sopenharmony_ci
11962306a36Sopenharmony_ci		ret = copy_from_user(cargs, data, nr_args * sizeof(*cargs));
12062306a36Sopenharmony_ci		if (ret)
12162306a36Sopenharmony_ci			goto fault;
12262306a36Sopenharmony_ci
12362306a36Sopenharmony_ci		for (i = 0; i < nr_args; ++i)
12462306a36Sopenharmony_ci			args[i] = cargs[i];
12562306a36Sopenharmony_ci
12662306a36Sopenharmony_ci		*argp = compat_ptr(args[1]);
12762306a36Sopenharmony_ci	} else {
12862306a36Sopenharmony_ci		ret = copy_from_user(args, data, nr_args * sizeof(*args));
12962306a36Sopenharmony_ci		if (ret)
13062306a36Sopenharmony_ci			goto fault;
13162306a36Sopenharmony_ci		*argp = (void __user *)args[1];
13262306a36Sopenharmony_ci	}
13362306a36Sopenharmony_ci
13462306a36Sopenharmony_ci	return 0;
13562306a36Sopenharmony_cifault:
13662306a36Sopenharmony_ci	return -EFAULT;
13762306a36Sopenharmony_ci}
13862306a36Sopenharmony_ci
13962306a36Sopenharmony_ci/*
14062306a36Sopenharmony_ci * Legacy ioctl's through SIOCDEVPRIVATE
14162306a36Sopenharmony_ci * This interface is deprecated because it was too difficult
14262306a36Sopenharmony_ci * to do the translation for 32/64bit ioctl compatibility.
14362306a36Sopenharmony_ci */
14462306a36Sopenharmony_ciint br_dev_siocdevprivate(struct net_device *dev, struct ifreq *rq,
14562306a36Sopenharmony_ci			  void __user *data, int cmd)
14662306a36Sopenharmony_ci{
14762306a36Sopenharmony_ci	struct net_bridge *br = netdev_priv(dev);
14862306a36Sopenharmony_ci	struct net_bridge_port *p = NULL;
14962306a36Sopenharmony_ci	unsigned long args[4];
15062306a36Sopenharmony_ci	void __user *argp;
15162306a36Sopenharmony_ci	int ret;
15262306a36Sopenharmony_ci
15362306a36Sopenharmony_ci	ret = br_dev_read_uargs(args, ARRAY_SIZE(args), &argp, data);
15462306a36Sopenharmony_ci	if (ret)
15562306a36Sopenharmony_ci		return ret;
15662306a36Sopenharmony_ci
15762306a36Sopenharmony_ci	switch (args[0]) {
15862306a36Sopenharmony_ci	case BRCTL_ADD_IF:
15962306a36Sopenharmony_ci	case BRCTL_DEL_IF:
16062306a36Sopenharmony_ci		return add_del_if(br, args[1], args[0] == BRCTL_ADD_IF);
16162306a36Sopenharmony_ci
16262306a36Sopenharmony_ci	case BRCTL_GET_BRIDGE_INFO:
16362306a36Sopenharmony_ci	{
16462306a36Sopenharmony_ci		struct __bridge_info b;
16562306a36Sopenharmony_ci
16662306a36Sopenharmony_ci		memset(&b, 0, sizeof(struct __bridge_info));
16762306a36Sopenharmony_ci		rcu_read_lock();
16862306a36Sopenharmony_ci		memcpy(&b.designated_root, &br->designated_root, 8);
16962306a36Sopenharmony_ci		memcpy(&b.bridge_id, &br->bridge_id, 8);
17062306a36Sopenharmony_ci		b.root_path_cost = br->root_path_cost;
17162306a36Sopenharmony_ci		b.max_age = jiffies_to_clock_t(br->max_age);
17262306a36Sopenharmony_ci		b.hello_time = jiffies_to_clock_t(br->hello_time);
17362306a36Sopenharmony_ci		b.forward_delay = br->forward_delay;
17462306a36Sopenharmony_ci		b.bridge_max_age = br->bridge_max_age;
17562306a36Sopenharmony_ci		b.bridge_hello_time = br->bridge_hello_time;
17662306a36Sopenharmony_ci		b.bridge_forward_delay = jiffies_to_clock_t(br->bridge_forward_delay);
17762306a36Sopenharmony_ci		b.topology_change = br->topology_change;
17862306a36Sopenharmony_ci		b.topology_change_detected = br->topology_change_detected;
17962306a36Sopenharmony_ci		b.root_port = br->root_port;
18062306a36Sopenharmony_ci
18162306a36Sopenharmony_ci		b.stp_enabled = (br->stp_enabled != BR_NO_STP);
18262306a36Sopenharmony_ci		b.ageing_time = jiffies_to_clock_t(br->ageing_time);
18362306a36Sopenharmony_ci		b.hello_timer_value = br_timer_value(&br->hello_timer);
18462306a36Sopenharmony_ci		b.tcn_timer_value = br_timer_value(&br->tcn_timer);
18562306a36Sopenharmony_ci		b.topology_change_timer_value = br_timer_value(&br->topology_change_timer);
18662306a36Sopenharmony_ci		b.gc_timer_value = br_timer_value(&br->gc_work.timer);
18762306a36Sopenharmony_ci		rcu_read_unlock();
18862306a36Sopenharmony_ci
18962306a36Sopenharmony_ci		if (copy_to_user((void __user *)args[1], &b, sizeof(b)))
19062306a36Sopenharmony_ci			return -EFAULT;
19162306a36Sopenharmony_ci
19262306a36Sopenharmony_ci		return 0;
19362306a36Sopenharmony_ci	}
19462306a36Sopenharmony_ci
19562306a36Sopenharmony_ci	case BRCTL_GET_PORT_LIST:
19662306a36Sopenharmony_ci	{
19762306a36Sopenharmony_ci		int num, *indices;
19862306a36Sopenharmony_ci
19962306a36Sopenharmony_ci		num = args[2];
20062306a36Sopenharmony_ci		if (num < 0)
20162306a36Sopenharmony_ci			return -EINVAL;
20262306a36Sopenharmony_ci		if (num == 0)
20362306a36Sopenharmony_ci			num = 256;
20462306a36Sopenharmony_ci		if (num > BR_MAX_PORTS)
20562306a36Sopenharmony_ci			num = BR_MAX_PORTS;
20662306a36Sopenharmony_ci
20762306a36Sopenharmony_ci		indices = kcalloc(num, sizeof(int), GFP_KERNEL);
20862306a36Sopenharmony_ci		if (indices == NULL)
20962306a36Sopenharmony_ci			return -ENOMEM;
21062306a36Sopenharmony_ci
21162306a36Sopenharmony_ci		get_port_ifindices(br, indices, num);
21262306a36Sopenharmony_ci		if (copy_to_user(argp, indices, array_size(num, sizeof(int))))
21362306a36Sopenharmony_ci			num =  -EFAULT;
21462306a36Sopenharmony_ci		kfree(indices);
21562306a36Sopenharmony_ci		return num;
21662306a36Sopenharmony_ci	}
21762306a36Sopenharmony_ci
21862306a36Sopenharmony_ci	case BRCTL_SET_BRIDGE_FORWARD_DELAY:
21962306a36Sopenharmony_ci		if (!ns_capable(dev_net(dev)->user_ns, CAP_NET_ADMIN))
22062306a36Sopenharmony_ci			return -EPERM;
22162306a36Sopenharmony_ci
22262306a36Sopenharmony_ci		ret = br_set_forward_delay(br, args[1]);
22362306a36Sopenharmony_ci		break;
22462306a36Sopenharmony_ci
22562306a36Sopenharmony_ci	case BRCTL_SET_BRIDGE_HELLO_TIME:
22662306a36Sopenharmony_ci		if (!ns_capable(dev_net(dev)->user_ns, CAP_NET_ADMIN))
22762306a36Sopenharmony_ci			return -EPERM;
22862306a36Sopenharmony_ci
22962306a36Sopenharmony_ci		ret = br_set_hello_time(br, args[1]);
23062306a36Sopenharmony_ci		break;
23162306a36Sopenharmony_ci
23262306a36Sopenharmony_ci	case BRCTL_SET_BRIDGE_MAX_AGE:
23362306a36Sopenharmony_ci		if (!ns_capable(dev_net(dev)->user_ns, CAP_NET_ADMIN))
23462306a36Sopenharmony_ci			return -EPERM;
23562306a36Sopenharmony_ci
23662306a36Sopenharmony_ci		ret = br_set_max_age(br, args[1]);
23762306a36Sopenharmony_ci		break;
23862306a36Sopenharmony_ci
23962306a36Sopenharmony_ci	case BRCTL_SET_AGEING_TIME:
24062306a36Sopenharmony_ci		if (!ns_capable(dev_net(dev)->user_ns, CAP_NET_ADMIN))
24162306a36Sopenharmony_ci			return -EPERM;
24262306a36Sopenharmony_ci
24362306a36Sopenharmony_ci		ret = br_set_ageing_time(br, args[1]);
24462306a36Sopenharmony_ci		break;
24562306a36Sopenharmony_ci
24662306a36Sopenharmony_ci	case BRCTL_GET_PORT_INFO:
24762306a36Sopenharmony_ci	{
24862306a36Sopenharmony_ci		struct __port_info p;
24962306a36Sopenharmony_ci		struct net_bridge_port *pt;
25062306a36Sopenharmony_ci
25162306a36Sopenharmony_ci		rcu_read_lock();
25262306a36Sopenharmony_ci		if ((pt = br_get_port(br, args[2])) == NULL) {
25362306a36Sopenharmony_ci			rcu_read_unlock();
25462306a36Sopenharmony_ci			return -EINVAL;
25562306a36Sopenharmony_ci		}
25662306a36Sopenharmony_ci
25762306a36Sopenharmony_ci		memset(&p, 0, sizeof(struct __port_info));
25862306a36Sopenharmony_ci		memcpy(&p.designated_root, &pt->designated_root, 8);
25962306a36Sopenharmony_ci		memcpy(&p.designated_bridge, &pt->designated_bridge, 8);
26062306a36Sopenharmony_ci		p.port_id = pt->port_id;
26162306a36Sopenharmony_ci		p.designated_port = pt->designated_port;
26262306a36Sopenharmony_ci		p.path_cost = pt->path_cost;
26362306a36Sopenharmony_ci		p.designated_cost = pt->designated_cost;
26462306a36Sopenharmony_ci		p.state = pt->state;
26562306a36Sopenharmony_ci		p.top_change_ack = pt->topology_change_ack;
26662306a36Sopenharmony_ci		p.config_pending = pt->config_pending;
26762306a36Sopenharmony_ci		p.message_age_timer_value = br_timer_value(&pt->message_age_timer);
26862306a36Sopenharmony_ci		p.forward_delay_timer_value = br_timer_value(&pt->forward_delay_timer);
26962306a36Sopenharmony_ci		p.hold_timer_value = br_timer_value(&pt->hold_timer);
27062306a36Sopenharmony_ci
27162306a36Sopenharmony_ci		rcu_read_unlock();
27262306a36Sopenharmony_ci
27362306a36Sopenharmony_ci		if (copy_to_user(argp, &p, sizeof(p)))
27462306a36Sopenharmony_ci			return -EFAULT;
27562306a36Sopenharmony_ci
27662306a36Sopenharmony_ci		return 0;
27762306a36Sopenharmony_ci	}
27862306a36Sopenharmony_ci
27962306a36Sopenharmony_ci	case BRCTL_SET_BRIDGE_STP_STATE:
28062306a36Sopenharmony_ci		if (!ns_capable(dev_net(dev)->user_ns, CAP_NET_ADMIN))
28162306a36Sopenharmony_ci			return -EPERM;
28262306a36Sopenharmony_ci
28362306a36Sopenharmony_ci		ret = br_stp_set_enabled(br, args[1], NULL);
28462306a36Sopenharmony_ci		break;
28562306a36Sopenharmony_ci
28662306a36Sopenharmony_ci	case BRCTL_SET_BRIDGE_PRIORITY:
28762306a36Sopenharmony_ci		if (!ns_capable(dev_net(dev)->user_ns, CAP_NET_ADMIN))
28862306a36Sopenharmony_ci			return -EPERM;
28962306a36Sopenharmony_ci
29062306a36Sopenharmony_ci		br_stp_set_bridge_priority(br, args[1]);
29162306a36Sopenharmony_ci		ret = 0;
29262306a36Sopenharmony_ci		break;
29362306a36Sopenharmony_ci
29462306a36Sopenharmony_ci	case BRCTL_SET_PORT_PRIORITY:
29562306a36Sopenharmony_ci	{
29662306a36Sopenharmony_ci		if (!ns_capable(dev_net(dev)->user_ns, CAP_NET_ADMIN))
29762306a36Sopenharmony_ci			return -EPERM;
29862306a36Sopenharmony_ci
29962306a36Sopenharmony_ci		spin_lock_bh(&br->lock);
30062306a36Sopenharmony_ci		if ((p = br_get_port(br, args[1])) == NULL)
30162306a36Sopenharmony_ci			ret = -EINVAL;
30262306a36Sopenharmony_ci		else
30362306a36Sopenharmony_ci			ret = br_stp_set_port_priority(p, args[2]);
30462306a36Sopenharmony_ci		spin_unlock_bh(&br->lock);
30562306a36Sopenharmony_ci		break;
30662306a36Sopenharmony_ci	}
30762306a36Sopenharmony_ci
30862306a36Sopenharmony_ci	case BRCTL_SET_PATH_COST:
30962306a36Sopenharmony_ci	{
31062306a36Sopenharmony_ci		if (!ns_capable(dev_net(dev)->user_ns, CAP_NET_ADMIN))
31162306a36Sopenharmony_ci			return -EPERM;
31262306a36Sopenharmony_ci
31362306a36Sopenharmony_ci		spin_lock_bh(&br->lock);
31462306a36Sopenharmony_ci		if ((p = br_get_port(br, args[1])) == NULL)
31562306a36Sopenharmony_ci			ret = -EINVAL;
31662306a36Sopenharmony_ci		else
31762306a36Sopenharmony_ci			ret = br_stp_set_path_cost(p, args[2]);
31862306a36Sopenharmony_ci		spin_unlock_bh(&br->lock);
31962306a36Sopenharmony_ci		break;
32062306a36Sopenharmony_ci	}
32162306a36Sopenharmony_ci
32262306a36Sopenharmony_ci	case BRCTL_GET_FDB_ENTRIES:
32362306a36Sopenharmony_ci		return get_fdb_entries(br, argp, args[2], args[3]);
32462306a36Sopenharmony_ci
32562306a36Sopenharmony_ci	default:
32662306a36Sopenharmony_ci		ret = -EOPNOTSUPP;
32762306a36Sopenharmony_ci	}
32862306a36Sopenharmony_ci
32962306a36Sopenharmony_ci	if (!ret) {
33062306a36Sopenharmony_ci		if (p)
33162306a36Sopenharmony_ci			br_ifinfo_notify(RTM_NEWLINK, NULL, p);
33262306a36Sopenharmony_ci		else
33362306a36Sopenharmony_ci			netdev_state_change(br->dev);
33462306a36Sopenharmony_ci	}
33562306a36Sopenharmony_ci
33662306a36Sopenharmony_ci	return ret;
33762306a36Sopenharmony_ci}
33862306a36Sopenharmony_ci
33962306a36Sopenharmony_cistatic int old_deviceless(struct net *net, void __user *data)
34062306a36Sopenharmony_ci{
34162306a36Sopenharmony_ci	unsigned long args[3];
34262306a36Sopenharmony_ci	void __user *argp;
34362306a36Sopenharmony_ci	int ret;
34462306a36Sopenharmony_ci
34562306a36Sopenharmony_ci	ret = br_dev_read_uargs(args, ARRAY_SIZE(args), &argp, data);
34662306a36Sopenharmony_ci	if (ret)
34762306a36Sopenharmony_ci		return ret;
34862306a36Sopenharmony_ci
34962306a36Sopenharmony_ci	switch (args[0]) {
35062306a36Sopenharmony_ci	case BRCTL_GET_VERSION:
35162306a36Sopenharmony_ci		return BRCTL_VERSION;
35262306a36Sopenharmony_ci
35362306a36Sopenharmony_ci	case BRCTL_GET_BRIDGES:
35462306a36Sopenharmony_ci	{
35562306a36Sopenharmony_ci		int *indices;
35662306a36Sopenharmony_ci		int ret = 0;
35762306a36Sopenharmony_ci
35862306a36Sopenharmony_ci		if (args[2] >= 2048)
35962306a36Sopenharmony_ci			return -ENOMEM;
36062306a36Sopenharmony_ci		indices = kcalloc(args[2], sizeof(int), GFP_KERNEL);
36162306a36Sopenharmony_ci		if (indices == NULL)
36262306a36Sopenharmony_ci			return -ENOMEM;
36362306a36Sopenharmony_ci
36462306a36Sopenharmony_ci		args[2] = get_bridge_ifindices(net, indices, args[2]);
36562306a36Sopenharmony_ci
36662306a36Sopenharmony_ci		ret = copy_to_user(argp, indices,
36762306a36Sopenharmony_ci				   array_size(args[2], sizeof(int)))
36862306a36Sopenharmony_ci			? -EFAULT : args[2];
36962306a36Sopenharmony_ci
37062306a36Sopenharmony_ci		kfree(indices);
37162306a36Sopenharmony_ci		return ret;
37262306a36Sopenharmony_ci	}
37362306a36Sopenharmony_ci
37462306a36Sopenharmony_ci	case BRCTL_ADD_BRIDGE:
37562306a36Sopenharmony_ci	case BRCTL_DEL_BRIDGE:
37662306a36Sopenharmony_ci	{
37762306a36Sopenharmony_ci		char buf[IFNAMSIZ];
37862306a36Sopenharmony_ci
37962306a36Sopenharmony_ci		if (!ns_capable(net->user_ns, CAP_NET_ADMIN))
38062306a36Sopenharmony_ci			return -EPERM;
38162306a36Sopenharmony_ci
38262306a36Sopenharmony_ci		if (copy_from_user(buf, argp, IFNAMSIZ))
38362306a36Sopenharmony_ci			return -EFAULT;
38462306a36Sopenharmony_ci
38562306a36Sopenharmony_ci		buf[IFNAMSIZ-1] = 0;
38662306a36Sopenharmony_ci
38762306a36Sopenharmony_ci		if (args[0] == BRCTL_ADD_BRIDGE)
38862306a36Sopenharmony_ci			return br_add_bridge(net, buf);
38962306a36Sopenharmony_ci
39062306a36Sopenharmony_ci		return br_del_bridge(net, buf);
39162306a36Sopenharmony_ci	}
39262306a36Sopenharmony_ci	}
39362306a36Sopenharmony_ci
39462306a36Sopenharmony_ci	return -EOPNOTSUPP;
39562306a36Sopenharmony_ci}
39662306a36Sopenharmony_ci
39762306a36Sopenharmony_ciint br_ioctl_stub(struct net *net, struct net_bridge *br, unsigned int cmd,
39862306a36Sopenharmony_ci		  struct ifreq *ifr, void __user *uarg)
39962306a36Sopenharmony_ci{
40062306a36Sopenharmony_ci	int ret = -EOPNOTSUPP;
40162306a36Sopenharmony_ci
40262306a36Sopenharmony_ci	rtnl_lock();
40362306a36Sopenharmony_ci
40462306a36Sopenharmony_ci	switch (cmd) {
40562306a36Sopenharmony_ci	case SIOCGIFBR:
40662306a36Sopenharmony_ci	case SIOCSIFBR:
40762306a36Sopenharmony_ci		ret = old_deviceless(net, uarg);
40862306a36Sopenharmony_ci		break;
40962306a36Sopenharmony_ci	case SIOCBRADDBR:
41062306a36Sopenharmony_ci	case SIOCBRDELBR:
41162306a36Sopenharmony_ci	{
41262306a36Sopenharmony_ci		char buf[IFNAMSIZ];
41362306a36Sopenharmony_ci
41462306a36Sopenharmony_ci		if (!ns_capable(net->user_ns, CAP_NET_ADMIN)) {
41562306a36Sopenharmony_ci			ret = -EPERM;
41662306a36Sopenharmony_ci			break;
41762306a36Sopenharmony_ci		}
41862306a36Sopenharmony_ci
41962306a36Sopenharmony_ci		if (copy_from_user(buf, uarg, IFNAMSIZ)) {
42062306a36Sopenharmony_ci			ret = -EFAULT;
42162306a36Sopenharmony_ci			break;
42262306a36Sopenharmony_ci		}
42362306a36Sopenharmony_ci
42462306a36Sopenharmony_ci		buf[IFNAMSIZ-1] = 0;
42562306a36Sopenharmony_ci		if (cmd == SIOCBRADDBR)
42662306a36Sopenharmony_ci			ret = br_add_bridge(net, buf);
42762306a36Sopenharmony_ci		else
42862306a36Sopenharmony_ci			ret = br_del_bridge(net, buf);
42962306a36Sopenharmony_ci	}
43062306a36Sopenharmony_ci		break;
43162306a36Sopenharmony_ci	case SIOCBRADDIF:
43262306a36Sopenharmony_ci	case SIOCBRDELIF:
43362306a36Sopenharmony_ci		ret = add_del_if(br, ifr->ifr_ifindex, cmd == SIOCBRADDIF);
43462306a36Sopenharmony_ci		break;
43562306a36Sopenharmony_ci	}
43662306a36Sopenharmony_ci
43762306a36Sopenharmony_ci	rtnl_unlock();
43862306a36Sopenharmony_ci
43962306a36Sopenharmony_ci	return ret;
44062306a36Sopenharmony_ci}
441