RE: [PATCH iwl-net 06/10] ice: keep adding MAC filters after one that already exists

From: Loktionov, Aleksandr

Date: Mon Oct 05 2026 - 06:28:32 EST




> -----Original Message-----
> From: Petr Oros <poros@xxxxxxxxxx>
> Sent: Friday, October 2, 2026 3:08 PM
> To: netdev@xxxxxxxxxxxxxxx
> Cc: Oros, Petr <poros@xxxxxxxxxx>; Nguyen, Anthony L
> <anthony.l.nguyen@xxxxxxxxx>; Kitszel, Przemyslaw
> <przemyslaw.kitszel@xxxxxxxxx>; Andrew Lunn <andrew+netdev@xxxxxxx>;
> David S. Miller <davem@xxxxxxxxxxxxx>; Eric Dumazet
> <edumazet@xxxxxxxxxx>; Jakub Kicinski <kuba@xxxxxxxxxx>; Paolo Abeni
> <pabeni@xxxxxxxxxx>; Lobakin, Aleksander
> <aleksander.lobakin@xxxxxxxxx>; Alexei Starovoitov <ast@xxxxxxxxxx>;
> Daniel Borkmann <daniel@xxxxxxxxxxxxx>; Jesper Dangaard Brouer
> <hawk@xxxxxxxxxx>; John Fastabend <john.fastabend@xxxxxxxxx>;
> Stanislav Fomichev <sdf@xxxxxxxxxxx>; Henry Tieman
> <henry.w.tieman@xxxxxxxxx>; Anirudh Venkataramanan
> <anirudh.venkataramanan@xxxxxxxxx>; Michal Swiatkowski
> <michal.swiatkowski@xxxxxxxxxxxxxxx>; Jesse Brandeburg
> <jbrandeb@xxxxxxxxxx>; Preethi Banala <preethi.banala@xxxxxxxxx>;
> Kiran Patil <kiran.patil@xxxxxxxxx>; Dan Nowlin
> <dan.nowlin@xxxxxxxxx>; Stephen Hemminger
> <stephen@xxxxxxxxxxxxxxxxxx>; intel-wired-lan@xxxxxxxxxxxxxxxx; linux-
> kernel@xxxxxxxxxxxxxxx; bpf@xxxxxxxxxxxxxxx
> Subject: [PATCH iwl-net 06/10] ice: keep adding MAC filters after one
> that already exists
>
> ice_add_mac() returns as soon as one entry of the list fails,
> including -EEXIST for a filter that is already programmed for the VSI.
> The rest of the list is never added. ice_vsi_sync_fltr() treats -
> EEXIST as success, so the skipped addresses are considered synced and
> their traffic is dropped until they are removed and added again.
>
> In a test that adds 50 multicast addresses to a port in a burst with
> the port MAC address in the middle of it, 19 of them were left without
> a filter.
>
> Continue with the next entry on -EEXIST and report it once the whole
> list has been processed. Other errors still stop the loop.
>
> There is no i40e counterpart of this fix, i40e keeps its MAC filters
> in a hash with a state per filter and syncs them differently. It was
> found while building a reproducer for the MAC filter overflow handling
> that i40e fixed in commit e58872398684 ("i40e: fix disabling overflow
> promiscuous mode") and commit 7363115efb04 ("i40e: do not force filter
> failure in overflow promiscuous").
>
> Commit bbb968e8b34c ("ice: Fix issues updating VSI MAC filters") dealt
> with the same problem for the VF MAC filter requests, which are now
> added one by one with -EEXIST tolerated, but left ice_add_mac() and
> the PF filter sync as they were.
>
> Fixes: 89f3e4a5b762 ("ice: Do not bail out when filter already
> exists")
> Assisted-by: LLM
> Signed-off-by: Petr Oros <poros@xxxxxxxxxx>
> ---
> drivers/net/ethernet/intel/ice/ice_switch.c | 4 +++-
> 1 file changed, 3 insertions(+), 1 deletion(-)
>
> diff --git a/drivers/net/ethernet/intel/ice/ice_switch.c
> b/drivers/net/ethernet/intel/ice/ice_switch.c
> index 2ee5cb6ffdab1f..239d4d9633baa6 100644
> --- a/drivers/net/ethernet/intel/ice/ice_switch.c
> +++ b/drivers/net/ethernet/intel/ice/ice_switch.c
> @@ -3659,7 +3659,9 @@ int ice_add_mac(struct ice_hw *hw, struct
> list_head *m_list)
>
> m_list_itr->status = ice_add_rule_internal(hw,
> ICE_SW_LKUP_MAC,
> m_list_itr);
> - if (m_list_itr->status)
> + if (m_list_itr->status == -EEXIST)
> + status = -EEXIST;
> + else if (m_list_itr->status)
> return m_list_itr->status;
> }
>
> --
> 2.55.0

Reviewed-by: Aleksandr Loktionov <aleksandr.loktionov@xxxxxxxxx>