From nobody Thu Sep 17 16:40:16 2026 X-Original-To: dev-commits-src-all@mlmmj.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mlmmj.nyi.freebsd.org (Postfix) with ESMTP id 4hm1hP6RFVz6tGTm for ; Thu, 17 Sep 2026 16:40:21 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from mxrelay.nyi.freebsd.org (mxrelay.nyi.freebsd.org [IPv6:2610:1c1:1:606c::19:3]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature RSA-PSS (4096 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "mxrelay.nyi.freebsd.org", Issuer "YR2" (not verified)) by mx1.freebsd.org (Postfix) with ESMTPS id 4hm1hP3X2dz4mRV for ; Thu, 17 Sep 2026 16:40:21 +0000 (UTC) (envelope-from git@FreeBSD.org) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1789663221; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=AlN/An8pv0uV12Y1Fg3INXVKtUY41NpLuT0Np8Ywqv0=; b=Cjm5iFJnVNAfoMyfN9iCNzCDBBGjc8OKmjerOckYAu0dYFZZLbqUjlwpn38mamEFFTau+F FEoLqo4n9Gvf8+5dBa2sT9zKZraWG56Rpk1xupIBZi/OOq3qvPP09Pu3Ac2Ug1JnKCxpaG +x3vYfJ/HntkrLfP4IHJw6NEqj0UD8uvZq9LfYpYRrKYW7jFU+RzrOJGMqRLu4RtFwTO+J DGXclyJW2gMl8y+NIxageRqkmaQlxKBUrF1occWja5olZIAgwODCpuHCqWmPxwufKrCIiL GMpYTNUjLZR1stQMNqS0Fc1mcYDQEVJh44UQvv+YqqWyfvoze7fRQwRP1mnhfQ== ARC-Seal: i=1; a=rsa-sha256; d=freebsd.org; s=dkim; cv=none; t=1789663221; b=VxXEmPU+KfjehbPGWUd1YTQ3WkqsQKxr9ud6D4xuPcsvtVpb2Ad+EuRqiwGhZHujzm/XQq yd9jhq+A2EPbLJKDQwEftbeJwdGcAFlZYac17gADBGJS+MNFlxXkUb8meOMa1v1tqvTOLT cZygd/KUPH+Dkd1b4J6GScnKRnvunoD/0xtZEt7zPQTZl8KriHmb4kCa+210vhihcXYDX9 DyVZLPgSR9woXKtGD76UWI7uPsNqOHgDYujrU7pUrxeuVldpSkVZ8wxvTJh34koHBPTdHZ MiM7eoYkANQIg8r5dJ1dqB3etusuzHcMC8Lccfa6mKPfY+YON2Kji3lRjK2wNQ== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1789663221; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=AlN/An8pv0uV12Y1Fg3INXVKtUY41NpLuT0Np8Ywqv0=; b=XaZ8HGfnAx8eiG2URwVuJbF8nvdeewyNtIr5y3kuU8Qt9JdFqoewp1fC1Uuvpx3yONIYNt WLtjB46+dBatmK3RCuOfUQ+OFgtw3vWuE4MrTJ93b4xv3lQ10DyX/QnORLzzDP37Tkcecc 6XbgNBbwSxTOKacnFyTDo2qgqccior52SZ8LV2L1ANZj7XTdE4cdYK0Mivqz6XwR4c4MF1 qYjfc3LDdT3l0jeMABSW+bRl5w6iANj+HLnoU+Oyd5U90NzF9Z6q9EdvALDSBiGPxQMDdc JhfxAEOKalgnC90LUgMR7IDosV5e9FTE0LepzyP2Dw/cruBoMhPYt1WrbPkBIw== ARC-Authentication-Results: i=1; mx1.freebsd.org; none Received: from gitrepo.freebsd.org (gitrepo.freebsd.org [IPv6:2610:1c1:1:6068::e6a:5]) by mxrelay.nyi.freebsd.org (Postfix) with ESMTP id 4hm1hP2Hy3zhKs for ; Thu, 17 Sep 2026 16:40:21 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from git (uid 1279) (envelope-from git@FreeBSD.org) id 20cd8 by gitrepo.freebsd.org (DragonFly Mail Agent v0.13+ on gitrepo.freebsd.org); Thu, 17 Sep 2026 16:40:16 +0000 To: src-committers@FreeBSD.org, dev-commits-src-all@FreeBSD.org, dev-commits-src-main@FreeBSD.org From: Kevin Bowling Subject: git: e70ff92d2431 - main - ice: Add malformed virtchnl injection points List-Id: Commit messages for all branches of the src repository List-Archive: https://lists.freebsd.org/archives/dev-commits-src-all List-Help: List-Post: List-Subscribe: List-Unsubscribe: X-BeenThere: dev-commits-src-all@freebsd.org Sender: owner-dev-commits-src-all@FreeBSD.org List-Id: List-Post: List-Help: List-Subscribe: List-Unsubscribe: List-Owner: Precedence: list MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 8bit X-Git-Committer: kbowling X-Git-Repository: src X-Git-Refname: refs/heads/main X-Git-Reftype: branch X-Git-Commit: e70ff92d243104834ad40581c3562a55d7525cc8 Auto-Submitted: auto-generated Date: Thu, 17 Sep 2026 16:40:16 +0000 Message-Id: <6aac17f0.20cd8.518e4aeb@gitrepo.freebsd.org> The branch main has been updated by kbowling: URL: https://cgit.FreeBSD.org/src/commit/?id=e70ff92d243104834ad40581c3562a55d7525cc8 commit e70ff92d243104834ad40581c3562a55d7525cc8 Author: Kevin Bowling AuthorDate: 2026-08-19 03:18:53 +0000 Commit: Kevin Bowling CommitDate: 2026-09-17 16:36:36 +0000 ice: Add malformed virtchnl injection points Extend the optional ice(4) failure injection facility with semantic corruption points for queue configuration, RSS keys and tables, and interrupt mappings. Each point mutates an otherwise valid request after the common virtchnl length check. This exercises the PF semantic validators with a real VF while preserving the normal wire format and mailbox path. The queue point selects unaligned Tx or Rx bases, an unaligned or unrepresentable receive buffer, an invalid frame size, duplicate queue IDs, or a bad VSI. The RSS points select short advertised data or an out-of-range LUT entry. The interrupt point selects an invalid ITR, traffic on vector zero, duplicate vectors, or a bad VSI. The points remain absent unless the kernel is built with options DRIVER_FAILPOINTS and retain the existing PF and VF selectors. MFC after: 2 weeks Sponsored by: BBOX.io Differential Revision: https://reviews.freebsd.org/D59021 --- sys/dev/ice/ice_iov.c | 72 +++++++++++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 72 insertions(+) diff --git a/sys/dev/ice/ice_iov.c b/sys/dev/ice/ice_iov.c index eab735820f8e..0c5d49ebf5b1 100644 --- a/sys/dev/ice/ice_iov.c +++ b/sys/dev/ice/ice_iov.c @@ -1421,6 +1421,41 @@ ice_vc_cfg_vsi_qs_msg(struct ice_softc *sc, struct ice_vf *vf, u8 *msg_buf) int i, error = 0; vqci = (struct virtchnl_vsi_queue_config_info *)msg_buf; + ICE_FAIL_POINT_CODE_COND(sc, _debug_fail_point_ice_iov, + malformed_queues, ice_iov_fail_vf_matches(vf->vf_num), + FAIL_POINT_NONSLEEPABLE, { + switch (RETURN_VALUE) { + case 1: + vqci->qpair[0].txq.dma_ring_addr |= 1; + break; + case 2: + vqci->qpair[0].rxq.dma_ring_addr |= 1; + break; + case 3: + vqci->qpair[0].rxq.databuffer_size++; + break; + case 4: + vqci->qpair[0].rxq.max_pkt_size = 0; + break; + case 5: + if (vqci->num_queue_pairs > 1) { + vqci->qpair[1].txq.queue_id = + vqci->qpair[0].txq.queue_id; + vqci->qpair[1].rxq.queue_id = + vqci->qpair[0].rxq.queue_id; + } else { + vqci->qpair[0].txq.queue_id++; + } + break; + case 6: + vqci->qpair[0].rxq.databuffer_size = + ICE_VC_MAX_RX_BUFFER + BIT(ICE_RLAN_CTX_DBUF_S); + break; + default: + vqci->vsi_id++; + break; + } + }); if (vqci->vsi_id != vsi->idx || vqci->num_queue_pairs == 0 || vqci->num_queue_pairs > sizeof(queue_map) * NBBY || @@ -1569,6 +1604,11 @@ ice_vc_cfg_rss_key_msg(struct ice_softc *sc, struct ice_vf *vf, u8 *msg_buf) struct ice_vsi *vsi = vf->vsi; vrk = (struct virtchnl_rss_key *)msg_buf; + ICE_FAIL_POINT_CODE_COND(sc, _debug_fail_point_ice_iov, + malformed_rss_key, ice_iov_fail_vf_matches(vf->vf_num), + FAIL_POINT_NONSLEEPABLE, { + vrk->key_len--; + }); if (vrk->vsi_id != vsi->idx) { device_printf(sc->dev, @@ -1619,6 +1659,14 @@ ice_vc_cfg_rss_lut_msg(struct ice_softc *sc, struct ice_vf *vf, u8 *msg_buf) struct ice_vsi *vsi = vf->vsi; vrl = (struct virtchnl_rss_lut *)msg_buf; + ICE_FAIL_POINT_CODE_COND(sc, _debug_fail_point_ice_iov, + malformed_rss_lut, ice_iov_fail_vf_matches(vf->vf_num), + FAIL_POINT_NONSLEEPABLE, { + if (RETURN_VALUE == 1) + vrl->lut_entries--; + else + vrl->lut[0] = vsi->num_rx_queues; + }); if (vrl->vsi_id != vsi->idx) { device_printf(sc->dev, @@ -1824,6 +1872,30 @@ ice_vc_cfg_irq_map_msg(struct ice_softc *sc, struct ice_vf *vf, u8 *msg_buf) u16 rxqs_seen, txqs_seen, valid_rxqs, valid_txqs, vector; vimi = (struct virtchnl_irq_map_info *)msg_buf; + ICE_FAIL_POINT_CODE_COND(sc, _debug_fail_point_ice_iov, + malformed_irq_map, ice_iov_fail_vf_matches(vf->vf_num), + FAIL_POINT_NONSLEEPABLE, { + switch (RETURN_VALUE) { + case 1: + vimi->vecmap[0].rxitr_idx = VIRTCHNL_ITR_IDX_NO_ITR + 1; + break; + case 2: + vimi->vecmap[0].vector_id = 0; + vimi->vecmap[0].rxq_map = 1; + break; + case 3: + if (vimi->num_vectors > 1) { + vimi->vecmap[1].vector_id = + vimi->vecmap[0].vector_id; + } else { + vimi->vecmap[0].vsi_id++; + } + break; + default: + vimi->vecmap[0].vsi_id++; + break; + } + }); if (vimi->num_vectors == 0 || vimi->num_vectors > vf->num_irq_vectors ||