[PATCH iwl-next 0/2] ice: fix TC flower filter priority violations

From: Petr Oros

Date: Thu Sep 10 2026 - 12:13:09 EST


Two fixes for TC flower offload in the legacy switch mode. Both
address the same user visible failure, all traffic on a port silently
disappears after installing a filter chain that mixes offloadable and
non offloadable filters.

The first fix covers filters matching on ip_proto alone. The driver
never programmed the protocol lookup, so a filter like "ip_proto udp
action drop" was installed in hardware as a match on eth_type ipv4 and
dropped every IPv4 packet.

The second fix covers the interaction between software only filters and
offloaded drop filters. The E810 switch gives drop rules absolute
precedence over forwarding rules regardless of recipe priority, so a
lower priority drop offloaded into hardware overrides any higher
priority filter that stayed in software. The driver now tracks filters
it could not offload and refuses to offload a drop filter that would
bypass one of them, keeping the drop functional in software instead.

Tested on E810 with the OS default and comms DDP packages, including
the original reproducer from the report, L2TPv3 pass and drop chains
with and without session ID matching.

Petr Oros (2):
ice: fix TC flower filters matching more than the ip_proto key
ice: don't offload drop filters that bypass higher priority filters

drivers/net/ethernet/intel/ice/ice.h | 1 +
drivers/net/ethernet/intel/ice/ice_tc_lib.c | 187 +++++++++++++++++++-
drivers/net/ethernet/intel/ice/ice_tc_lib.h | 22 +++
3 files changed, 201 insertions(+), 9 deletions(-)

--
2.55.0