From nobody Thu Sep 17 17:02:21 2026 X-Original-To: dev-commits-src-all@mlmmj.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mlmmj.nyi.freebsd.org (Postfix) with ESMTP id 4hm29t58Hqz6tHZj for ; Thu, 17 Sep 2026 17:02:26 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from mxrelay.nyi.freebsd.org (mxrelay.nyi.freebsd.org [IPv6:2610:1c1:1:606c::19:3]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature RSA-PSS (4096 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "mxrelay.nyi.freebsd.org", Issuer "YR2" (not verified)) by mx1.freebsd.org (Postfix) with ESMTPS id 4hm29t2sw2z4sxd for ; Thu, 17 Sep 2026 17:02:26 +0000 (UTC) (envelope-from git@FreeBSD.org) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1789664546; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=y6e4kOKLoPz0fQl9g2tWFEvjGlVVlRhhkTxuARPJ3AQ=; b=inh/gjfSQJDUzVd5ueTl6wRhWd0ud7dzjMqHQeSjhS67P4hrlt995gftQDSZQLI2leqopt zafdx5pyNZ4W3hL/J74tCLORtkMWGBQAr13aB4kMFB10tc7ZOvfypivaUdw+XPzsREZzP7 xGM7KpCKjXeaNQyFGPrLI1J7FO+JI7QhmLBPQMOAZ2lAsb7Ea3sRmGleXJTnvHgkUrJCDQ vjOpyxYRP/9qrfuwP1tCcsvSsLPuHZ2japAeHSsBc0V+MP2Vo4jwA3+9qz+sEVSExKNT61 TaBYPOxW0DWB9R/Ovk/g5IhKitGokNrHWQkJfODn/hzDSO5IMjfxE0r7zakf5g== ARC-Seal: i=1; a=rsa-sha256; d=freebsd.org; s=dkim; cv=none; t=1789664546; b=CxHeNafM5A+UzwqnJmsh2bw5kpu+yhtv92WC9W9yZGNzyelnxhbcPXOD4Mo1ssuZBQJA0B /Ie3lP8ZZicEt/D3BcBzOvhW8YAaxGPWrijRj2Fs6ZYGqbFNytQtQVtRCSPp9fRNdAyW7p AOgeTMb9/si/vo8pPmzSHKEYqTZ5wGvU6V3ozed/7NwucumUvcd6SdMGf/3qyWA7aVRa8j 7gkk5DG3/YqKRlWjVghjYizEuOiLfMdUc5/pux3wdE9+BLm/5SzNeWswXd4WbKmg8f5W/J FcKp8QjMkUfmdhnWM6qcQ1rKQfzduyJTXyAtya06tQURnxwRzfBIljw4I66mNg== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1789664546; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=y6e4kOKLoPz0fQl9g2tWFEvjGlVVlRhhkTxuARPJ3AQ=; b=uih9BecGBlP0Fgf7jgga879W4Tw7hQ+fVNKz+lcnjYAu4G0QUJmeIWq7JYtDALXxT7Tgy2 YB+mJF/kgey3W+JZiu6hWMdB0KFXOhG6Rs1vlWgmH+9dD6KfqFft5N+HqTrJx4nIRdN7fz EUIbdSkbt4vUBDCip55HGLDqN9MDrezYLwfOGBYUpwp8SLaMCKvz6fQ2mZrdAA3z2aWONk lbKhfVnE6VZL1BYR0NClUSPKF6Jb8fmw+A4z6bGu0Olj5HQ9TUQVl1Yt39bIyq4E3ornZX qYnqX60Bmy56hVpPGBuqG+H3iVNLnMUWdBJPQ/eanWA2mN2f/aA2aengIp9PVQ== ARC-Authentication-Results: i=1; mx1.freebsd.org; none Received: from gitrepo.freebsd.org (gitrepo.freebsd.org [IPv6:2610:1c1:1:6068::e6a:5]) by mxrelay.nyi.freebsd.org (Postfix) with ESMTP id 4hm29t1yR5zj66 for ; Thu, 17 Sep 2026 17:02:26 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from git (uid 1279) (envelope-from git@FreeBSD.org) id 23fd7 by gitrepo.freebsd.org (DragonFly Mail Agent v0.13+ on gitrepo.freebsd.org); Thu, 17 Sep 2026 17:02:21 +0000 To: src-committers@FreeBSD.org, dev-commits-src-all@FreeBSD.org, dev-commits-src-main@FreeBSD.org From: Kevin Bowling Subject: git: 3bdc281f5df0 - main - ice: Enforce VF MAC anti-spoof policy List-Id: Commit messages for all branches of the src repository List-Archive: https://lists.freebsd.org/archives/dev-commits-src-all List-Help: List-Post: List-Subscribe: List-Unsubscribe: X-BeenThere: dev-commits-src-all@freebsd.org Sender: owner-dev-commits-src-all@FreeBSD.org List-Id: List-Post: List-Help: List-Subscribe: List-Unsubscribe: List-Owner: Precedence: list MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 8bit X-Git-Committer: kbowling X-Git-Repository: src X-Git-Refname: refs/heads/main X-Git-Reftype: branch X-Git-Commit: 3bdc281f5df0003d745b4e911f5d583bf5938317 Auto-Submitted: auto-generated Date: Thu, 17 Sep 2026 17:02:21 +0000 Message-Id: <6aac1d1d.23fd7.42608adf@gitrepo.freebsd.org> The branch main has been updated by kbowling: URL: https://cgit.FreeBSD.org/src/commit/?id=3bdc281f5df0003d745b4e911f5d583bf5938317 commit 3bdc281f5df0003d745b4e911f5d583bf5938317 Author: Kevin Bowling AuthorDate: 2026-08-19 03:28:59 +0000 Commit: Kevin Bowling CommitDate: 2026-09-17 17:01:41 +0000 ice: Enforce VF MAC anti-spoof policy The SR-IOV schema enables MAC anti-spoofing by default, but the driver never programs the VSI security section. A VF can therefore transmit with an arbitrary source address despite the configured policy. Program ICE_AQ_VSI_SEC_FLAG_ENA_MAC_ANTI_SPOOF when the VF VSI is created, and replay the policy when the VSI is rebuilt after a PF or device reset. Fail VF creation or rebuild when firmware cannot install the security policy so an unprotected VF is never published as active. Validated on E810 hardware with host-attached and Linux passthrough VFs. Traffic using the assigned source MAC passed while otherwise identical forged-source frames were dropped. After a PF reset, assigned traffic resumed and zero of ten forged frames reached the peer. An injected MAC anti-spoof update failure left the VF inactive. Destroying and recreating the SR-IOV configuration restored the policy and traffic. MFC after: 2 weeks Sponsored by: BBOX.io Differential Revision: https://reviews.freebsd.org/D59022 --- share/man/man4/ice.4 | 8 ++++++-- sys/dev/ice/ice_iov.c | 49 +++++++++++++++++++++++++++++++++++++++++++++++++ 2 files changed, 55 insertions(+), 2 deletions(-) diff --git a/share/man/man4/ice.4 b/share/man/man4/ice.4 index 31b61136e36b..d1fa58c8c94c 100644 --- a/share/man/man4/ice.4 +++ b/share/man/man4/ice.4 @@ -1107,9 +1107,13 @@ If unspecified, the VF will use a randomly generated MAC address and .Dq allow-set-mac will be set to true. .It mac-anti-spoof Pq bool -Prevent the VF from sending Ethernet frames with a source address -that does not match its own. +Prevent the VF from sending Ethernet frames whose source address does not +match a MAC address installed for that VF. Enabled by default. +The policy is enforced in hardware and replayed after PF and device resets. +If firmware cannot install it during VF creation, the SR-IOV configuration +request fails. +If replay fails during reconstruction, the configured VF remains inactive. .It allow-set-mac Pq bool Allow the VF to set its own Ethernet MAC address. Disallowed by default. diff --git a/sys/dev/ice/ice_iov.c b/sys/dev/ice/ice_iov.c index 0c5d49ebf5b1..57362d8f5a89 100644 --- a/sys/dev/ice/ice_iov.c +++ b/sys/dev/ice/ice_iov.c @@ -54,6 +54,8 @@ SYSCTL_INT(_debug_fail_point_ice_iov, OID_AUTO, vf, "VF eligible for ice SR-IOV fail points (-1 selects every VF)"); #endif /* DRIVER_FAILPOINTS */ static struct ice_vf *ice_iov_get_vf(struct ice_softc *sc, int vf_num); +static int ice_iov_configure_mac_anti_spoof(struct ice_softc *sc, + struct ice_vf *vf); static void ice_iov_ready_vf(struct ice_softc *sc, struct ice_vf *vf); static void ice_reset_vf(struct ice_softc *sc, struct ice_vf *vf, bool trigger_vflr); @@ -242,6 +244,47 @@ ice_iov_get_vf(struct ice_softc *sc, int vf_num) return &sc->vfs[vf_num]; } +/** + * ice_iov_configure_mac_anti_spoof - Apply a VF's source-MAC policy + * @sc: device softc structure + * @vf: VF whose VSI security policy should be configured + * + * PF and device resets discard the hardware VSI context, so callers must + * replay this policy after creating or rebuilding the VF's VSI. + */ +static int +ice_iov_configure_mac_anti_spoof(struct ice_softc *sc, struct ice_vf *vf) +{ + struct ice_vsi_ctx ctx = { 0 }; + struct ice_vsi *vsi = vf->vsi; + struct ice_hw *hw = &sc->hw; + bool enable; + int status; + + enable = (atomic_load_acq_32(&vf->vf_flags) & + VF_FLAG_MAC_ANTI_SPOOF) != 0; + ctx.info.sec_flags = vsi->info.sec_flags; + ctx.info.valid_sections = + CPU_TO_LE16(ICE_AQ_VSI_PROP_SECURITY_VALID); + if (enable) + ctx.info.sec_flags |= ICE_AQ_VSI_SEC_FLAG_ENA_MAC_ANTI_SPOOF; + else + ctx.info.sec_flags &= ~ICE_AQ_VSI_SEC_FLAG_ENA_MAC_ANTI_SPOOF; + + status = ice_update_vsi(hw, vsi->idx, &ctx, NULL); + if (status != 0) { + device_printf(sc->dev, + "Unable to configure VF %u MAC anti-spoof %s, " + "err %s aq_err %s\n", vf->vf_num, + enable ? "on" : "off", ice_status_str(status), + ice_aq_str(hw->adminq.sq_last_status)); + return (EIO); + } + + vsi->info.sec_flags = ctx.info.sec_flags; + return (0); +} + /** * ice_iov_add_vf - Called by the OS for each VF to create * @sc: device softc structure @@ -436,6 +479,9 @@ ice_iov_add_vf(struct ice_softc *sc, uint16_t vfnum, const nvlist_t *params) } ICE_IOV_FAIL_POINT(sc, vfnum, add_after_vsi_init, error, release_imap); + error = ice_iov_configure_mac_anti_spoof(sc, vf); + if (error != 0) + goto release_imap; /* Add the broadcast address */ error = ice_add_vsi_mac_filter(vsi, broadcastaddr); @@ -675,6 +721,9 @@ ice_iov_rebuild_vf(struct ice_softc *sc, struct ice_vsi *vsi) return (error); } vsi->hw_stats.cur = accumulated_stats; + error = ice_iov_configure_mac_anti_spoof(sc, vf); + if (error != 0) + return (error); status = ice_replay_vsi(hw, vsi->idx); if (status != 0) {