| From e20a6e7b7cc3be5dc2fea39e52f1ed3c1f2750f6 Mon Sep 17 00:00:00 2001 |
| From: Sasha Levin <sashal@kernel.org> |
| Date: Tue, 20 Jan 2026 23:10:39 +0200 |
| Subject: net: dsa: fix off-by-one in maximum bridge ID determination |
| |
| From: Vladimir Oltean <vladimir.oltean@nxp.com> |
| |
| [ Upstream commit dfca045cd4d0ea07ff4198ba392be3e718acaddc ] |
| |
| Prior to the blamed commit, the bridge_num range was from |
| 0 to ds->max_num_bridges - 1. After the commit, it is from |
| 1 to ds->max_num_bridges. |
| |
| So this check: |
| if (bridge_num >= max) |
| return 0; |
| must be updated to: |
| if (bridge_num > max) |
| return 0; |
| |
| in order to allow the last bridge_num value (==max) to be used. |
| |
| This is easiest visible when a driver sets ds->max_num_bridges=1. |
| The observed behaviour is that even the first created bridge triggers |
| the netlink extack "Range of offloadable bridges exceeded" warning, and |
| is handled in software rather than being offloaded. |
| |
| Fixes: 3f9bb0301d50 ("net: dsa: make dp->bridge_num one-based") |
| Signed-off-by: Vladimir Oltean <vladimir.oltean@nxp.com> |
| Link: https://patch.msgid.link/20260120211039.3228999-1-vladimir.oltean@nxp.com |
| Signed-off-by: Jakub Kicinski <kuba@kernel.org> |
| Signed-off-by: Sasha Levin <sashal@kernel.org> |
| --- |
| net/dsa/dsa.c | 2 +- |
| 1 file changed, 1 insertion(+), 1 deletion(-) |
| |
| diff --git a/net/dsa/dsa.c b/net/dsa/dsa.c |
| index 97599e0d5a1d0..76a086e846c45 100644 |
| --- a/net/dsa/dsa.c |
| +++ b/net/dsa/dsa.c |
| @@ -157,7 +157,7 @@ unsigned int dsa_bridge_num_get(const struct net_device *bridge_dev, int max) |
| bridge_num = find_next_zero_bit(&dsa_fwd_offloading_bridges, |
| DSA_MAX_NUM_OFFLOADING_BRIDGES, |
| 1); |
| - if (bridge_num >= max) |
| + if (bridge_num > max) |
| return 0; |
| |
| set_bit(bridge_num, &dsa_fwd_offloading_bridges); |
| -- |
| 2.51.0 |
| |