> -----Original Message----- > From: Intel-wired-lan <[email protected]> On Behalf Of Petr > Oros > Sent: 08 July 2026 18:28 > To: [email protected] > Cc: Vecera, Ivan <[email protected]>; Alice Michael > <[email protected]>; Kitszel, Przemyslaw > <[email protected]>; Eric Dumazet <[email protected]>; > [email protected]; Martyna Szapar-Mudlaw > <[email protected]>; Andrew Lunn <[email protected]>; > Marcin Szycik <[email protected]>; Nguyen, Anthony L > <[email protected]>; Simon Horman <[email protected]>; > [email protected]; Keller, Jacob E <[email protected]>; > Jakub Kicinski <[email protected]>; Paolo Abeni <[email protected]>; David S. > Miller <[email protected]> > Subject: [Intel-wired-lan] [PATCH iwl-net v4 1/2] ice: skip per-VLAN promisc > rules when default VSI Rx rule is set > > When an ice port in a vlan-filtering bridge goes promiscuous (typical for > bond slaves), the driver installs a per-VLAN ICE_SW_LKUP_PROMISC_VLAN rule > for every VID on top of the broad ICE_SW_LKUP_DFLT VSI Rx rule. Each rule > consumes one of > the ~32K Flow Lookup Unit (FLU) entries the device shares > across PFs, so a wide trunk (vid 2-4094) over several PFs overruns the > pool: firmware rejects further Add Switch Rules with ENOSPC (AQ 0x10) and the > DFLT Rx rule itself fails to install: > > ice 0000:5c:00.1: Failed to set VSI 14 as the default forwarding > VSI, error -5 > ice 0000:5c:00.1 ens1f1: Error -5 setting default VSI 14 Rx rule > > Once a switch context is overrun the retries can also come back as ENOENT (AQ > 0x2), which has misled triage toward a perceived recipe binding defect rather > than a capacity issue. > > The DFLT rule already catches every packet on the port regardless of VLAN > tag, so the per-VLAN promisc expansion is redundant while it is installed. > Skip it at the two sites that drive it, ice_set_promisc() and > ice_vlan_rx_add_vid(), keyed on ice_is_vsi_dflt_vsi() rather than the netdev > IFF_PROMISC flag so a failed or LAG-suppressed DFLT install still falls back > to the per-VLAN rules. > > IFF_ALLMULTI and IFF_PROMISC can reach ice_vsi_sync_fltr() in separate passes > (a bridge join sets them through separate calls), so the allmulti pass may > expand the per-VID rules before the DFLT rule exists. Drop those > now-redundant rules right > after ice_set_dflt_vsi() installs the DFLT rule; > ice_vsi_exit_dflt_promisc() reinstates them when promisc is cleared. > > ice_vsi_sync_fltr() subscribed multicast promiscuity only inside the "default > VSI not yet in use" branch, so a promiscuous VSI that finds the default VSI > rule already present (owned by another VSI, or preserved across a switchdev > session) ended up > in unicast promisc with no multicast subscription. Issue > ice_set_promisc(ICE_MCAST_PROMISC_BITS) whenever the netdev is promiscuous; > it is idempotent and returns 0 if the rule is already present. > > Fixes: 1273f89578f2 ("ice: Fix broken IFF_ALLMULTI handling") > Signed-off-by: Petr Oros <[email protected]> > --- > v4 (review comments from Marcin Szycik): > - Reworded the ice_clear_promisc() and the per-VID cleanup comments. > - Flipped the ice_vsi_clear_vlan_mc_promisc() guard to an early return to > reduce indentation, and noted that the clear is best-effort. > No functional change. > > v3: https://lore.kernel.org/all/[email protected]/ > v2: https://lore.kernel.org/all/[email protected]/ > v1: > https://lore.kernel.org/all/89efbea9831175e6f57e9fe8557f7a0e48e050b7.1781786935.git.po...@redhat.com/ > --- > drivers/net/ethernet/intel/ice/ice_main.c | 109 +++++++++++++++++----- > 1 file changed, 88 insertions(+), 21 deletions(-) >
Tested-by: Rinitha S <[email protected]> (A Contingent worker at Intel)
