Thread (28 messages) 28 messages, 4 authors, 7d ago

Re: [PATCH net-next 01/12] net: bridge: introduce a bridge destination type

flat view

From: Nikolay Aleksandrov <razor@blackwall.org>
Date: 2026-10-01 07:24:20
Also in: bridge

On 30/09/2026 10:14, Nikolay Aleksandrov wrote:
quoted hunk ↗ jump to hunk
Add an opaque destination type and helpers for representing bridge port
destinations. Using a separate structure makes raw pointer assignments and
comparisons fail at build time while marking its value member __private
makes sparse warn about accesses that bypass the helpers.

Reviewed-by: Ido Schimmel <idosch@nvidia.com>
Signed-off-by: Nikolay Aleksandrov <razor@blackwall.org>
---
  net/bridge/br_private.h | 38 ++++++++++++++++++++++++++++++++++++++
  1 file changed, 38 insertions(+)
diff --git a/net/bridge/br_private.h b/net/bridge/br_private.h
index 67117fb3dc88..1146187aa2ba 100644
--- a/net/bridge/br_private.h
+++ b/net/bridge/br_private.h
@@ -306,6 +306,10 @@ struct net_bridge_fdb_key {
  	u16 vlan_id;
  };
  
+struct net_bridge_dst {
+	unsigned long __private value;
+};
+
  struct net_bridge_fdb_entry {
  	struct rhash_head		rhnode;
  	struct net_bridge_port		*dst;
@@ -670,6 +674,40 @@ struct br_input_skb_cb {
  #define br_debug(br, format, args...)			\
  	pr_debug("%s: " format,  (br)->dev->name, ##args)
  
+static inline struct net_bridge_dst
+br_dst_read(const struct net_bridge_dst *src)
+{
+	struct net_bridge_dst dst;
+
+	ACCESS_PRIVATE(&dst, value) =
+		READ_ONCE(ACCESS_PRIVATE(src, value));
+
+	return dst;
+}
+
+static inline void br_dst_write(struct net_bridge_dst *dst,
+				struct net_bridge_dst src)
+{
+	WRITE_ONCE(ACCESS_PRIVATE(dst, value),
+		   ACCESS_PRIVATE(&src, value));
+}
+
+static inline struct net_bridge_dst
+br_port_to_dst(const struct net_bridge_port *p)
+{
+	struct net_bridge_dst dst;
+
+	ACCESS_PRIVATE(&dst, value) = (unsigned long)p;
+

Sashiko says:
 Does casting this const-qualified struct net_bridge_port pointer to an
 unsigned long drop the const restriction?

 - Yes, it does but that is expected.
quoted hunk ↗ jump to hunk
+	return dst;
+}
+
+static inline struct net_bridge_port *
+br_dst_port(struct net_bridge_dst dst)
+{
+	return (struct net_bridge_port *)ACCESS_PRIVATE(&dst, value);
+}
Sashiko says:
 When the opaque token from br_port_to_dst() is resolved here in
 br_dst_port(), is it unconditionally cast back to a mutable
 struct net_bridge_port pointer?
 Could this provide a silent mechanism to cast away const, bypassing C type
 safety constraints in the API design?

 - That is again expected and wanted behaviour, we're extracting the dst.

quoted hunk ↗ jump to hunk
+
  /* called under bridge lock */
  static inline int br_is_root_bridge(const struct net_bridge *br)
  {
  
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help