From: Vivien Didelot <hidden> Date: 2015-10-11 22:09:38
DSA and its drivers currently hook the NETDEV_CHANGEUPPER net_device event in
order to configure the VLAN map of every port.
This VLAN map is a feature of these switch chips to hardcode and restrict which
output ports a given input port can egress frames to.
A Linux bridge is a simple untagged VLAN propagated by the bridge code itself.
With a proper 802.1Q support, a driver does not need this hook anymore, and
will simply program the related VLAN object.
This patchset improves the hardware bridging code in the mv88e6xxx driver with
a strict 802.1Q mode.
Ideally, the equivalent must be done for Broadcom Starfighter 2 and Rocker,
before completely getting rid of this hook.
Vivien Didelot (4):
net: dsa: mv88e6xxx: bridges do not need an FID
net: dsa: mv88e6xxx: do not support per-port FID
net: dsa: do not warn unsupported bridge ops
net: dsa: mv88e6xxx: fix hardware bridging
drivers/net/dsa/mv88e6171.c | 2 -
drivers/net/dsa/mv88e6352.c | 2 -
drivers/net/dsa/mv88e6xxx.c | 215 ++++++--------------------------------------
drivers/net/dsa/mv88e6xxx.h | 8 --
net/dsa/slave.c | 2 +-
5 files changed, 26 insertions(+), 203 deletions(-)
--
2.6.0
From: Vivien Didelot <hidden> Date: 2015-10-11 22:09:43
Since we configure a switch chip through a Linux bridge, and a bridge is
implemented as a VLAN, there is no need for per-port FID anymore.
This patch gets rid of this and simplifies the driver code since we can
now directly map all 4095 FIDs available to all VLANs.
Signed-off-by: Vivien Didelot <redacted>
---
drivers/net/dsa/mv88e6xxx.c | 69 ++++++++-------------------------------------
drivers/net/dsa/mv88e6xxx.h | 5 ----
2 files changed, 11 insertions(+), 63 deletions(-)
@@ -1468,6 +1468,7 @@ static int _mv88e6xxx_vlan_init(struct dsa_switch *ds, u16 vid,structmv88e6xxx_vtu_stu_entryvlan={.valid=true,.vid=vid,+.fid=vid,/* We use one FID per VLAN */};inti;
@@ -1501,22 +1502,10 @@ static int _mv88e6xxx_vlan_init(struct dsa_switch *ds, u16 vid,returnerr;}-/* Non-bridged ports and bridge groups use FIDs from 1 to-*num_ports;VLANsuseFIDsfromnum_ports+1to4095.-*/-vlan.fid=find_next_zero_bit(ps->fid_bitmap,VLAN_N_VID,-ps->num_ports+1);-if(unlikely(vlan.fid==VLAN_N_VID)){-pr_err("no more FID available for VLAN %d\n",vid);-return-ENOSPC;-}-/* Clear all MAC addresses from the new database */err=_mv88e6xxx_atu_flush(ds,vlan.fid,true);if(err)returnerr;--set_bit(vlan.fid,ps->fid_bitmap);}*entry=vlan;
@@ -1556,7 +1545,6 @@ int mv88e6xxx_port_vlan_del(struct dsa_switch *ds, int port, u16 vid){structmv88e6xxx_priv_state*ps=ds_to_priv(ds);structmv88e6xxx_vtu_stu_entryvlan;-boolkeep=false;inti,err;mutex_lock(&ps->smi_mutex);
@@ -1574,28 +1562,22 @@ int mv88e6xxx_port_vlan_del(struct dsa_switch *ds, int port, u16 vid)vlan.data[port]=GLOBAL_VTU_DATA_MEMBER_TAG_NON_MEMBER;/* keep the VLAN unless all ports are excluded */+vlan.valid=false;for(i=0;i<ps->num_ports;++i){if(dsa_is_cpu_port(ds,i))continue;if(vlan.data[i]!=GLOBAL_VTU_DATA_MEMBER_TAG_NON_MEMBER){-keep=true;+vlan.valid=true;break;}}-vlan.valid=keep;err=_mv88e6xxx_vtu_loadpurge(ds,&vlan);if(err)gotounlock;err=_mv88e6xxx_atu_remove(ds,vlan.fid,port,false);-if(err)-gotounlock;--if(!keep)-clear_bit(vlan.fid,ps->fid_bitmap);-unlock:mutex_unlock(&ps->smi_mutex);
@@ -1722,37 +1704,13 @@ static int _mv88e6xxx_atu_load(struct dsa_switch *ds,return_mv88e6xxx_atu_cmd(ds,GLOBAL_ATU_OP_LOAD_DB);}-staticint_mv88e6xxx_port_vid_to_fid(structdsa_switch*ds,intport,u16vid)-{-structmv88e6xxx_priv_state*ps=ds_to_priv(ds);-structmv88e6xxx_vtu_stu_entryvlan;-interr;--if(vid==0)-returnps->fid[port];--err=_mv88e6xxx_port_vtu_getnext(ds,port,vid-1,&vlan);-if(err)-returnerr;--if(vlan.vid==vid)-returnvlan.fid;--return-ENOENT;-}-staticint_mv88e6xxx_port_fdb_load(structdsa_switch*ds,intport,constunsignedchar*addr,u16vid,u8state){structmv88e6xxx_atu_entryentry={0};-intret;-ret=_mv88e6xxx_port_vid_to_fid(ds,port,vid);-if(ret<0)-returnret;--entry.fid=ret;+entry.fid=vid;/* We use one FID per VLAN */entry.state=state;ether_addr_copy(entry.mac,addr);if(state!=GLOBAL_ATU_DATA_STATE_UNUSED){
@@ -1767,6 +1725,10 @@ int mv88e6xxx_port_fdb_prepare(struct dsa_switch *ds, int port,conststructswitchdev_obj_port_fdb*fdb,structswitchdev_trans*trans){+/* We don't use per-port FDB */+if(fdb->vid==0)+return-EOPNOTSUPP;+/* We don't need any dynamic resource from the kernel (yet),*soskipthepreparephase.*/
@@ -1864,16 +1826,11 @@ int mv88e6xxx_port_fdb_getnext(struct dsa_switch *ds, int port,{structmv88e6xxx_priv_state*ps=ds_to_priv(ds);structmv88e6xxx_atu_entrynext;-u16fid;+u16fid=*vid;/* We use one FID per VLAN */intret;mutex_lock(&ps->smi_mutex);-ret=_mv88e6xxx_port_vid_to_fid(ds,port,*vid);-if(ret<0)-gotounlock;-fid=ret;-do{if(is_broadcast_ether_addr(addr)){structmv88e6xxx_vtu_stu_entryvtu;
@@ -2145,15 +2102,11 @@ static int mv88e6xxx_setup_port(struct dsa_switch *ds, int port)if(ret)gotoabort;-/* Port based VLAN map: give each port its own address+/* Port based VLAN map: do not give each port its own address*database,allowtheCPUporttotalktoeachofthe'real'*ports,andalloweachofthe'real'portstoonlytalkto*theupstreamport.*/-fid=port+1;-ps->fid[port]=fid;-set_bit(fid,ps->fid_bitmap);-if(dsa_is_cpu_port(ds,port))reg=BIT(ps->num_ports)-1;else
@@ -407,11 +407,6 @@ struct mv88e6xxx_priv_state {intid;/* switch product id */intnum_ports;/* number of switch ports */-/* hw bridging */--DECLARE_BITMAP(fid_bitmap,VLAN_N_VID);/* FIDs 1 to 4095 available */-u16fid[DSA_MAX_PORTS];/* per (non-bridged) port FID */-unsignedlongport_state_update_mask;u8port_state[DSA_MAX_PORTS];
From: Vivien Didelot <hidden> Date: 2015-10-11 22:09:51
With 88E6352 and similar switch chips, each port has a map to restrict
which output port this input port can egress frames to.
The current driver code implements hardware bridging using this feature,
and assigns to a bridge group the FID of its first member.
Now that 802.1Q is fully implemented in this driver, a Linux bridge
which is a simple untagged VLAN, already gets its own FID.
This patch gets rid of the per-bridge FID and explicits the usage of the
port based VLAN map feature.
Signed-off-by: Vivien Didelot <redacted>
---
drivers/net/dsa/mv88e6xxx.c | 157 +++++++++++---------------------------------
drivers/net/dsa/mv88e6xxx.h | 1 -
2 files changed, 40 insertions(+), 118 deletions(-)
@@ -1112,130 +1107,56 @@ abort:returnret;}-/* Must be called with smi lock held */-staticint_mv88e6xxx_update_port_config(structdsa_switch*ds,intport)+staticint_mv88e6xxx_port_vlan_map_set(structdsa_switch*ds,intport,+u16output_ports){structmv88e6xxx_priv_state*ps=ds_to_priv(ds);-u8fid=ps->fid[port];-u16reg=fid<<12;+constu16mask=(1<<ps->num_ports)-1;+intreg;-if(dsa_is_cpu_port(ds,port))-reg|=ds->phys_port_mask;-else-reg|=(ps->bridge_mask[fid]|-(1<<dsa_upstream_port(ds)))&~(1<<port);+reg=_mv88e6xxx_reg_read(ds,REG_PORT(port),PORT_BASE_VLAN);+if(reg<0)+returnreg;++reg&=~mask;+reg|=output_ports&mask;return_mv88e6xxx_reg_write(ds,REG_PORT(port),PORT_BASE_VLAN,reg);}-/* Must be called with smi lock held */-staticint_mv88e6xxx_update_bridge_config(structdsa_switch*ds,intfid)-{-structmv88e6xxx_priv_state*ps=ds_to_priv(ds);-intport;-u32mask;-intret;--mask=ds->phys_port_mask;-while(mask){-port=__ffs(mask);-mask&=~(1<<port);-if(ps->fid[port]!=fid)-continue;--ret=_mv88e6xxx_update_port_config(ds,port);-if(ret)-returnret;-}--return_mv88e6xxx_flush_fid(ds,fid);-}-/* Bridge handling functions */+staticintmv88e6xxx_map_bridge(structdsa_switch*ds,u16members)+{+structmv88e6xxx_priv_state*ps=ds_to_priv(ds);+constunsignedlongoutput=members|BIT(dsa_upstream_port(ds));+intport,err=0;++mutex_lock(&ps->smi_mutex);++for_each_set_bit(port,&output,ps->num_ports){+if(dsa_is_cpu_port(ds,port))+continue;++err=_mv88e6xxx_port_vlan_map_set(ds,port,output&~port);+if(err)+break;+}++mutex_unlock(&ps->smi_mutex);++returnerr;+}++intmv88e6xxx_join_bridge(structdsa_switch*ds,intport,u32br_port_mask){-structmv88e6xxx_priv_state*ps=ds_to_priv(ds);-intret=0;-u32nmask;-intfid;--/* If the bridge group is not empty, join that group.-*Otherwisecreateanewgroup.-*/-fid=ps->fid[port];-nmask=br_port_mask&~(1<<port);-if(nmask)-fid=ps->fid[__ffs(nmask)];--nmask=ps->bridge_mask[fid]|(1<<port);-if(nmask!=br_port_mask){-netdev_err(ds->ports[port],-"join: Bridge port mask mismatch fid=%d mask=0x%x expected 0x%x\n",-fid,br_port_mask,nmask);-return-EINVAL;-}--mutex_lock(&ps->smi_mutex);--ps->bridge_mask[fid]=br_port_mask;--if(fid!=ps->fid[port]){-clear_bit(ps->fid[port],ps->fid_bitmap);-ps->fid[port]=fid;-ret=_mv88e6xxx_update_bridge_config(ds,fid);-}--mutex_unlock(&ps->smi_mutex);--returnret;+returnmv88e6xxx_map_bridge(ds,br_port_mask);}intmv88e6xxx_leave_bridge(structdsa_switch*ds,intport,u32br_port_mask){-structmv88e6xxx_priv_state*ps=ds_to_priv(ds);-u8fid,newfid;-intret;--fid=ps->fid[port];--if(ps->bridge_mask[fid]!=br_port_mask){-netdev_err(ds->ports[port],-"leave: Bridge port mask mismatch fid=%d mask=0x%x expected 0x%x\n",-fid,br_port_mask,ps->bridge_mask[fid]);-return-EINVAL;-}--/* If the port was the last port of a bridge, we are done.-*Otherwiseassignanewfidtotheport,andfixup-*thebridgeconfiguration.-*/-if(br_port_mask==(1<<port))-return0;--mutex_lock(&ps->smi_mutex);--newfid=find_next_zero_bit(ps->fid_bitmap,VLAN_N_VID,1);-if(unlikely(newfid>ps->num_ports)){-netdev_err(ds->ports[port],"all first %d FIDs are used\n",-ps->num_ports);-ret=-ENOSPC;-gotounlock;-}--ps->fid[port]=newfid;-set_bit(newfid,ps->fid_bitmap);-ps->bridge_mask[fid]&=~(1<<port);-ps->bridge_mask[newfid]=1<<port;--ret=_mv88e6xxx_update_bridge_config(ds,fid);-if(!ret)-ret=_mv88e6xxx_update_bridge_config(ds,newfid);--unlock:-mutex_unlock(&ps->smi_mutex);--returnret;+returnmv88e6xxx_map_bridge(ds,br_port_mask&~port);}intmv88e6xxx_port_stp_update(structdsa_switch*ds,intport,u8state)
@@ -2233,10 +2154,12 @@ static int mv88e6xxx_setup_port(struct dsa_switch *ds, int port)ps->fid[port]=fid;set_bit(fid,ps->fid_bitmap);-if(!dsa_is_cpu_port(ds,port))-ps->bridge_mask[fid]=1<<port;+if(dsa_is_cpu_port(ds,port))+reg=BIT(ps->num_ports)-1;+else+reg=BIT(dsa_upstream_port(ds));-ret=_mv88e6xxx_update_port_config(ds,port);+ret=_mv88e6xxx_port_vlan_map_set(ds,port,reg&~port);if(ret)gotoabort;
@@ -411,7 +411,6 @@ struct mv88e6xxx_priv_state {DECLARE_BITMAP(fid_bitmap,VLAN_N_VID);/* FIDs 1 to 4095 available */u16fid[DSA_MAX_PORTS];/* per (non-bridged) port FID */-u16bridge_mask[DSA_MAX_PORTS];/* br groups (indexed by FID) */unsignedlongport_state_update_mask;u8port_state[DSA_MAX_PORTS];
From: Vivien Didelot <hidden> Date: 2015-10-11 22:09:52
Playing with the VLAN map of every port to implement "hardware bridging"
in the 88E6352 driver was a hack until full 802.1Q was supported.
Indeed with 802.1Q port mode "Disabled" or "Fallback", this feature is
used to restrict which output ports an input port can egress frames to.
A Linux bridge is an untagged VLAN. With full 802.1Q support, we don't
need this hack anymore and can use the "Secure" strict 802.1Q port mode.
With this mode, the port-based VLAN map still needs to be configured,
but all the logic is VTU-centric. This means that the switch only cares
about rules described in its hardware VLAN table, which is exactly what
Linux bridge expects and what we want.
Note also that the hardware bridging was broken with the previous
flexible "Fallback" 802.1Q port mode. Here's an example:
Port0 and Port1 belong to the same bridge. If Port0 sends crafted tagged
frames with VID 200 to Port1, Port1 receives it. Even if Port1 is in
hardware VLAN 200, but not Port0, Port1 will still receive it, because
Fallback mode doesn't care about invalid VID or non-member source port.
Signed-off-by: Vivien Didelot <redacted>
---
drivers/net/dsa/mv88e6171.c | 2 --
drivers/net/dsa/mv88e6352.c | 2 --
drivers/net/dsa/mv88e6xxx.c | 47 +++------------------------------------------
drivers/net/dsa/mv88e6xxx.h | 2 --
4 files changed, 3 insertions(+), 50 deletions(-)
@@ -1124,41 +1124,6 @@ static int _mv88e6xxx_port_vlan_map_set(struct dsa_switch *ds, int port,return_mv88e6xxx_reg_write(ds,REG_PORT(port),PORT_BASE_VLAN,reg);}-/* Bridge handling functions */--staticintmv88e6xxx_map_bridge(structdsa_switch*ds,u16members)-{-structmv88e6xxx_priv_state*ps=ds_to_priv(ds);-constunsignedlongoutput=members|BIT(dsa_upstream_port(ds));-intport,err=0;--mutex_lock(&ps->smi_mutex);--for_each_set_bit(port,&output,ps->num_ports){-if(dsa_is_cpu_port(ds,port))-continue;--err=_mv88e6xxx_port_vlan_map_set(ds,port,output&~port);-if(err)-break;-}--mutex_unlock(&ps->smi_mutex);--returnerr;-}---intmv88e6xxx_join_bridge(structdsa_switch*ds,intport,u32br_port_mask)-{-returnmv88e6xxx_map_bridge(ds,br_port_mask);-}--intmv88e6xxx_leave_bridge(structdsa_switch*ds,intport,u32br_port_mask)-{-returnmv88e6xxx_map_bridge(ds,br_port_mask&~port);-}-intmv88e6xxx_port_stp_update(structdsa_switch*ds,intport,u8state){structmv88e6xxx_priv_state*ps=ds_to_priv(ds);
@@ -2007,7 +1972,7 @@ static int mv88e6xxx_setup_port(struct dsa_switch *ds, int port)reg|=PORT_CONTROL_2_FORWARD_UNKNOWN;}-reg|=PORT_CONTROL_2_8021Q_FALLBACK;+reg|=PORT_CONTROL_2_8021Q_SECURE;if(reg){ret=_mv88e6xxx_reg_write(ds,REG_PORT(port),
@@ -2103,15 +2068,9 @@ static int mv88e6xxx_setup_port(struct dsa_switch *ds, int port)gotoabort;/* Port based VLAN map: do not give each port its own address-*database,allowtheCPUporttotalktoeachofthe'real'-*ports,andalloweachofthe'real'portstoonlytalkto-*theupstreamport.+*database,andalloweveryporttoegressframesonallotherports.*/-if(dsa_is_cpu_port(ds,port))-reg=BIT(ps->num_ports)-1;-else-reg=BIT(dsa_upstream_port(ds));-+reg=BIT(ps->num_ports)-1;/* all ports */ret=_mv88e6xxx_port_vlan_map_set(ds,port,reg&~port);if(ret)gotoabort;
@@ -463,8 +463,6 @@ int mv88e6xxx_phy_write_indirect(struct dsa_switch *ds, int addr, int regnum,intmv88e6xxx_get_eee(structdsa_switch*ds,intport,structethtool_eee*e);intmv88e6xxx_set_eee(structdsa_switch*ds,intport,structphy_device*phydev,structethtool_eee*e);-intmv88e6xxx_join_bridge(structdsa_switch*ds,intport,u32br_port_mask);-intmv88e6xxx_leave_bridge(structdsa_switch*ds,intport,u32br_port_mask);intmv88e6xxx_port_stp_update(structdsa_switch*ds,intport,u8state);intmv88e6xxx_port_pvid_get(structdsa_switch*ds,intport,u16*vid);intmv88e6xxx_port_pvid_set(structdsa_switch*ds,intport,u16vid);
From: Vivien Didelot <hidden> Date: 2015-10-11 22:11:32
A DSA driver may not provide the port_join_bridge and port_leave_bridge
functions, so don't warn in such case.
Signed-off-by: Vivien Didelot <redacted>
---
net/dsa/slave.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
From: David Miller <davem@davemloft.net> Date: 2015-10-13 11:11:10
From: Vivien Didelot <redacted>
Date: Sun, 11 Oct 2015 18:08:34 -0400
DSA and its drivers currently hook the NETDEV_CHANGEUPPER net_device event in
order to configure the VLAN map of every port.
This VLAN map is a feature of these switch chips to hardcode and restrict which
output ports a given input port can egress frames to.
A Linux bridge is a simple untagged VLAN propagated by the bridge code itself.
With a proper 802.1Q support, a driver does not need this hook anymore, and
will simply program the related VLAN object.
This patchset improves the hardware bridging code in the mv88e6xxx driver with
a strict 802.1Q mode.
Ideally, the equivalent must be done for Broadcom Starfighter 2 and Rocker,
before completely getting rid of this hook.
From: Andrew Lunn <andrew@lunn.ch> Date: 2015-10-14 22:46:21
On Sun, Oct 11, 2015 at 06:08:34PM -0400, Vivien Didelot wrote:
DSA and its drivers currently hook the NETDEV_CHANGEUPPER net_device event in
order to configure the VLAN map of every port.
This VLAN map is a feature of these switch chips to hardcode and restrict which
output ports a given input port can egress frames to.
A Linux bridge is a simple untagged VLAN propagated by the bridge code itself.
With a proper 802.1Q support, a driver does not need this hook anymore, and
will simply program the related VLAN object.
This patchset improves the hardware bridging code in the mv88e6xxx driver with
a strict 802.1Q mode.
Hi Vivien
I just tested this as part of net-next/master, and found a problem....
If i do:
ip link set lan0 up
ip addr add 192.168.10.2/24 dev lan0
It will not ping. Looking in sys/kernel/debug/dsa0/stats i see
broadcast packets, probably ARP, being received at the port.
But they are not being forwarded out the CPU port.
If however i do
brctl addbr br0
brctl addif br0 lan0
ip addr add 192.168.10.2/24 dev br0
ip link set br0 up
i can ping.
So it looks like we are too restrictive by default. You should be able
to use interfaces as they are, without a bridge.
Andrew
From: Vivien Didelot <hidden> Date: 2015-10-15 01:37:30
On Oct. Thursday 15 (42) 12:46 AM, Andrew Lunn wrote:
On Sun, Oct 11, 2015 at 06:08:34PM -0400, Vivien Didelot wrote:
quoted
DSA and its drivers currently hook the NETDEV_CHANGEUPPER net_device event in
order to configure the VLAN map of every port.
This VLAN map is a feature of these switch chips to hardcode and restrict which
output ports a given input port can egress frames to.
A Linux bridge is a simple untagged VLAN propagated by the bridge code itself.
With a proper 802.1Q support, a driver does not need this hook anymore, and
will simply program the related VLAN object.
This patchset improves the hardware bridging code in the mv88e6xxx driver with
a strict 802.1Q mode.
Hi Vivien
I just tested this as part of net-next/master, and found a problem....
If i do:
ip link set lan0 up
ip addr add 192.168.10.2/24 dev lan0
It will not ping. Looking in sys/kernel/debug/dsa0/stats i see
broadcast packets, probably ARP, being received at the port.
But they are not being forwarded out the CPU port.
If however i do
brctl addbr br0
brctl addif br0 lan0
ip addr add 192.168.10.2/24 dev br0
ip link set br0 up
i can ping.
So it looks like we are too restrictive by default. You should be able
to use interfaces as they are, without a bridge.
Correct, if the ports are not in a VLAN by default, they cannot talk.
If you want to, I think the special VLAN 0 can be used for that purpose.
IIRC, in a given configuration, Linux add the interfaces (thus programs
the hardware) with VLAN 0. I'm not sure when, maybe when the
.ndo_vlan_rx_add_vid is implemented, I need to give it a shot.
Otherwise, I can send you a patch configuring the VLAN 0 on switch
setup if this is the behavior we want.
Thanks,
-v
On Oct. Thursday 15 (42) 12:46 AM, Andrew Lunn wrote:
quoted
On Sun, Oct 11, 2015 at 06:08:34PM -0400, Vivien Didelot wrote:
quoted
DSA and its drivers currently hook the NETDEV_CHANGEUPPER net_device event in
order to configure the VLAN map of every port.
This VLAN map is a feature of these switch chips to hardcode and restrict which
output ports a given input port can egress frames to.
A Linux bridge is a simple untagged VLAN propagated by the bridge code itself.
With a proper 802.1Q support, a driver does not need this hook anymore, and
will simply program the related VLAN object.
This patchset improves the hardware bridging code in the mv88e6xxx driver with
a strict 802.1Q mode.
Hi Vivien
I just tested this as part of net-next/master, and found a problem....
If i do:
ip link set lan0 up
ip addr add 192.168.10.2/24 dev lan0
It will not ping. Looking in sys/kernel/debug/dsa0/stats i see
broadcast packets, probably ARP, being received at the port.
But they are not being forwarded out the CPU port.
If however i do
brctl addbr br0
brctl addif br0 lan0
ip addr add 192.168.10.2/24 dev br0
ip link set br0 up
i can ping.
So it looks like we are too restrictive by default. You should be able
to use interfaces as they are, without a bridge.
Correct, if the ports are not in a VLAN by default, they cannot talk.
The expectation for DSA devices, if no bridge device is configured is to
have each port be able to talk to the CPU port only, but this has to
work out of the box.
If you want to, I think the special VLAN 0 can be used for that purpose.
IIRC, in a given configuration, Linux add the interfaces (thus programs
the hardware) with VLAN 0. I'm not sure when, maybe when the
.ndo_vlan_rx_add_vid is implemented, I need to give it a shot.
But if you do that, won't that put all DSA ports into VLAN 0? Would not
that break isolation between each ports as expected for a DSA switch?
Otherwise, I can send you a patch configuring the VLAN 0 on switch
setup if this is the behavior we want.
Thanks,
-v
From: Andrew Lunn <andrew@lunn.ch> Date: 2015-10-15 02:52:55
On Wed, Oct 14, 2015 at 09:28:55PM -0400, Vivien Didelot wrote:
On Oct. Thursday 15 (42) 12:46 AM, Andrew Lunn wrote:
quoted
On Sun, Oct 11, 2015 at 06:08:34PM -0400, Vivien Didelot wrote:
quoted
DSA and its drivers currently hook the NETDEV_CHANGEUPPER net_device event in
order to configure the VLAN map of every port.
This VLAN map is a feature of these switch chips to hardcode and restrict which
output ports a given input port can egress frames to.
A Linux bridge is a simple untagged VLAN propagated by the bridge code itself.
With a proper 802.1Q support, a driver does not need this hook anymore, and
will simply program the related VLAN object.
This patchset improves the hardware bridging code in the mv88e6xxx driver with
a strict 802.1Q mode.
Hi Vivien
I just tested this as part of net-next/master, and found a problem....
If i do:
ip link set lan0 up
ip addr add 192.168.10.2/24 dev lan0
It will not ping. Looking in sys/kernel/debug/dsa0/stats i see
broadcast packets, probably ARP, being received at the port.
But they are not being forwarded out the CPU port.
If however i do
brctl addbr br0
brctl addif br0 lan0
ip addr add 192.168.10.2/24 dev br0
ip link set br0 up
i can ping.
So it looks like we are too restrictive by default. You should be able
to use interfaces as they are, without a bridge.
Correct, if the ports are not in a VLAN by default, they cannot talk.
Hi Vivien
This is a regression. Ports of the switch should work like normal
Linux interfaces. And up until now, they did. This patchset changed
that.
As Florian pointed out, these interfaces are separated from each
other. So you need something like a bridge per port by default, which
then gets removed and replaced when a port is added to a Linux bridge.
We also need to take care of VLANs. When the port is not a member of a
linux bridge, i expect all VLAN tagged frames to be received, as well
as untagged frames. This is normal Linux behaviour. But i never got
around to testing this with DSA.
Andrew
On Wed, Oct 14, 2015 at 09:28:55PM -0400, Vivien Didelot wrote:
quoted
On Oct. Thursday 15 (42) 12:46 AM, Andrew Lunn wrote:
quoted
On Sun, Oct 11, 2015 at 06:08:34PM -0400, Vivien Didelot wrote:
quoted
DSA and its drivers currently hook the NETDEV_CHANGEUPPER net_device event in
order to configure the VLAN map of every port.
This VLAN map is a feature of these switch chips to hardcode and restrict which
output ports a given input port can egress frames to.
A Linux bridge is a simple untagged VLAN propagated by the bridge code itself.
With a proper 802.1Q support, a driver does not need this hook anymore, and
will simply program the related VLAN object.
This patchset improves the hardware bridging code in the mv88e6xxx driver with
a strict 802.1Q mode.
Hi Vivien
I just tested this as part of net-next/master, and found a problem....
If i do:
ip link set lan0 up
ip addr add 192.168.10.2/24 dev lan0
It will not ping. Looking in sys/kernel/debug/dsa0/stats i see
broadcast packets, probably ARP, being received at the port.
But they are not being forwarded out the CPU port.
If however i do
brctl addbr br0
brctl addif br0 lan0
ip addr add 192.168.10.2/24 dev br0
ip link set br0 up
i can ping.
So it looks like we are too restrictive by default. You should be able
to use interfaces as they are, without a bridge.
Correct, if the ports are not in a VLAN by default, they cannot talk.
Hi Vivien
This is a regression. Ports of the switch should work like normal
Linux interfaces. And up until now, they did. This patchset changed
that.
As Florian pointed out, these interfaces are separated from each
other. So you need something like a bridge per port by default, which
then gets removed and replaced when a port is added to a Linux bridge.
We also need to take care of VLANs. When the port is not a member of a
linux bridge, i expect all VLAN tagged frames to be received, as well
as untagged frames. This is normal Linux behaviour. But i never got
around to testing this with DSA.
There was a reason for the original code. I had wondered how it is now
supposed to work. Guess this exchange explains it. Looking forward to see
how it is going to be fixed, and too bad I don't have time to be more
involved.
Guenter
From: Vivien Didelot <hidden> Date: 2015-10-15 12:47:32
On Oct. Wednesday 14 (42) 06:44 PM, Florian Fainelli wrote:
On 14/10/15 18:28, Vivien Didelot wrote:
quoted
On Oct. Thursday 15 (42) 12:46 AM, Andrew Lunn wrote:
quoted
On Sun, Oct 11, 2015 at 06:08:34PM -0400, Vivien Didelot wrote:
quoted
DSA and its drivers currently hook the NETDEV_CHANGEUPPER net_device event in
order to configure the VLAN map of every port.
This VLAN map is a feature of these switch chips to hardcode and restrict which
output ports a given input port can egress frames to.
A Linux bridge is a simple untagged VLAN propagated by the bridge code itself.
With a proper 802.1Q support, a driver does not need this hook anymore, and
will simply program the related VLAN object.
This patchset improves the hardware bridging code in the mv88e6xxx driver with
a strict 802.1Q mode.
Hi Vivien
I just tested this as part of net-next/master, and found a problem....
If i do:
ip link set lan0 up
ip addr add 192.168.10.2/24 dev lan0
It will not ping. Looking in sys/kernel/debug/dsa0/stats i see
broadcast packets, probably ARP, being received at the port.
But they are not being forwarded out the CPU port.
If however i do
brctl addbr br0
brctl addif br0 lan0
ip addr add 192.168.10.2/24 dev br0
ip link set br0 up
i can ping.
So it looks like we are too restrictive by default. You should be able
to use interfaces as they are, without a bridge.
Correct, if the ports are not in a VLAN by default, they cannot talk.
The expectation for DSA devices, if no bridge device is configured is to
have each port be able to talk to the CPU port only, but this has to
work out of the box.
OK, I might have forgotten this requirement. I also just noticed that
you mentioned it in Documentation/networking/dsa/dsa.txt. Thanks for the
reminder.
quoted
If you want to, I think the special VLAN 0 can be used for that
purpose. IIRC, in a given configuration, Linux add the interfaces
(thus programs the hardware) with VLAN 0. I'm not sure when, maybe
when the .ndo_vlan_rx_add_vid is implemented, I need to give it a
shot.
But if you do that, won't that put all DSA ports into VLAN 0? Would
not that break isolation between each ports as expected for a DSA
switch?
You're correct, then VLAN 0 is not an option. I have something else in
mind, fix coming soon.
quoted
Otherwise, I can send you a patch configuring the VLAN 0 on switch
setup if this is the behavior we want.
From: Vivien Didelot <hidden> Date: 2015-10-15 12:52:27
On Oct. Thursday 15 (42) 04:52 AM, Andrew Lunn wrote:
On Wed, Oct 14, 2015 at 09:28:55PM -0400, Vivien Didelot wrote:
quoted
On Oct. Thursday 15 (42) 12:46 AM, Andrew Lunn wrote:
quoted
On Sun, Oct 11, 2015 at 06:08:34PM -0400, Vivien Didelot wrote:
quoted
DSA and its drivers currently hook the NETDEV_CHANGEUPPER net_device event in
order to configure the VLAN map of every port.
This VLAN map is a feature of these switch chips to hardcode and restrict which
output ports a given input port can egress frames to.
A Linux bridge is a simple untagged VLAN propagated by the bridge code itself.
With a proper 802.1Q support, a driver does not need this hook anymore, and
will simply program the related VLAN object.
This patchset improves the hardware bridging code in the mv88e6xxx driver with
a strict 802.1Q mode.
Hi Vivien
I just tested this as part of net-next/master, and found a problem....
If i do:
ip link set lan0 up
ip addr add 192.168.10.2/24 dev lan0
It will not ping. Looking in sys/kernel/debug/dsa0/stats i see
broadcast packets, probably ARP, being received at the port.
But they are not being forwarded out the CPU port.
If however i do
brctl addbr br0
brctl addif br0 lan0
ip addr add 192.168.10.2/24 dev br0
ip link set br0 up
i can ping.
So it looks like we are too restrictive by default. You should be able
to use interfaces as they are, without a bridge.
Correct, if the ports are not in a VLAN by default, they cannot talk.
Hi Vivien
This is a regression. Ports of the switch should work like normal
Linux interfaces. And up until now, they did. This patchset changed
that.
As Florian pointed out, these interfaces are separated from each
other. So you need something like a bridge per port by default, which
then gets removed and replaced when a port is added to a Linux bridge.
I'll fix this regression and try the exact same example you provided.
We also need to take care of VLANs. When the port is not a member of a
linux bridge, i expect all VLAN tagged frames to be received, as well
as untagged frames. This is normal Linux behaviour. But i never got
around to testing this with DSA.