]> www.infradead.org Git - users/dwmw2/linux.git/commit
ice: block LAN in case of VF to VF offload
authorMichal Swiatkowski <michal.swiatkowski@linux.intel.com>
Wed, 3 May 2023 15:39:35 +0000 (08:39 -0700)
committerGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Wed, 17 May 2023 09:53:38 +0000 (11:53 +0200)
commit4a61d7965611ea29b57a19d048f3e782f7cf2a09
tree61f95efa63a4878c356ee4bcce8c3d5bd1e23941
parent2f80efc46b737926a69db1207eb928f18fbd176a
ice: block LAN in case of VF to VF offload

[ Upstream commit 9f699b71c2f31c51bd1483a20e1c8ddc5986a8c9 ]

VF to VF traffic shouldn't go outside. To enforce it, set only the loopback
enable bit in case of all ingress type rules added via the tc tool.

Fixes: 0d08a441fb1a ("ice: ndo_setup_tc implementation for PF")
Reported-by: Sujai Buvaneswaran <Sujai.Buvaneswaran@intel.com>
Signed-off-by: Michal Swiatkowski <michal.swiatkowski@linux.intel.com>
Tested-by: George Kuruvinakunnel <george.kuruvinakunnel@intel.com>
Reviewed-by: Simon Horman <simon.horman@corigine.com>
Signed-off-by: Tony Nguyen <anthony.l.nguyen@intel.com>
Reviewed-by: Leon Romanovsky <leonro@nvidia.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Sasha Levin <sashal@kernel.org>
drivers/net/ethernet/intel/ice/ice_tc_lib.c