From nobody Thu Sep 17 16:40:16 2026 X-Original-To: dev-commits-src-main@mlmmj.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mlmmj.nyi.freebsd.org (Postfix) with ESMTP id 4hm1hJ4bmdz6tGD5 for ; Thu, 17 Sep 2026 16:40:16 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from mxrelay.nyi.freebsd.org (mxrelay.nyi.freebsd.org [IPv6:2610:1c1:1:606c::19:3]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature RSA-PSS (4096 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "mxrelay.nyi.freebsd.org", Issuer "YR2" (not verified)) by mx1.freebsd.org (Postfix) with ESMTPS id 4hm1hJ46tcz4mcJ for ; Thu, 17 Sep 2026 16:40:16 +0000 (UTC) (envelope-from git@FreeBSD.org) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1789663216; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=AlN/An8pv0uV12Y1Fg3INXVKtUY41NpLuT0Np8Ywqv0=; b=A9bulMDsCG6iYHA5qs1ejR50xq256HIwD6cuWkp/1Sedr8UKIQrTKsnxjqxiSHDHXzkfNx eCEkWz/Dpf22AnAuF2V75KaVdybrHdjn4i62RX6lQACaeh7VCGafiM69M5QOmqEcasdlPR w7dun5Y4xqRZwtaoCHCem7xmTpDbyNKAF4jW0C5mv9e1lRw+PVawss7AhmVen53CaCb5nX fAS9dn1DSSSU6RMl4cxFR7RsSmS9DtYtAvczpKo/7Y8QOyrg4xMsFi6i9WAddtImOAiqaz sqpdyTBMZfUgWE3A8sobN/tcvNJN7Yw0pRnfVxOYwjSsmA/CTk7Ztomb16H2eg== ARC-Seal: i=1; a=rsa-sha256; d=freebsd.org; s=dkim; cv=none; t=1789663216; b=LjEzGciRmMKhJycUb0zZOR6tBxPtB0BK1YXCSdHhoUsnygOTjHQJojIcJxlA+LNED6sz8e HjAC82jHP1cYxiPBmrB3Miky9gbA7Un8c8Aw/UGvTm+MYNfeecHm7ZZew995jl9H5USf7j VDMkSd3rBN34HvIVVNizQYRGXLfMAPSPcj+OQPO6INwI1K4vKxs0yceQ3AT28SMyfOCMdF uv0xjYtrhmFcXDLugc6iYU6T8fTmOb9FN/KKxGU61uGmpn51ViFwTVOOfembeiDJxkZfJI 4qUQjtwwtzfUDsFjXjDxtr2pwI2xPbyKSkMm1nQc17/uc2fThPG3Qu72mwyGJw== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1789663216; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=AlN/An8pv0uV12Y1Fg3INXVKtUY41NpLuT0Np8Ywqv0=; b=o8kaVV6uca4QM/eNFfMoLBnFZRLhD/zAa2aTO8pxiagMdiehFpcWh+l5nO0uIrQN70mdjc Hba4D1dAg5AOz802NQD7hR7GnTaY0oaWRB52OI7fk0n+UtJDDE96HTAFQ7ZOPVmWbH+TH8 /FzEI1f8S9Sz3PA+LmrnYUVtlRWMn2chabrYq6W12pToP8aAcPwowoG7cmT7TKk9WGU7i+ l9pb+z6dfes6pmXOJdJ6OWHSAen9mvRyUjGXb3c+010LfFzG0YZBDX7z1+NpIiMMTLYqyg 4i0Yir93DXyT8E84U5AUzn1w7NR4/p9vpOKrEKod5Xm8KSLLJuJbaCzJFplAlA== ARC-Authentication-Results: i=1; mx1.freebsd.org; none Received: from gitrepo.freebsd.org (gitrepo.freebsd.org [IPv6:2610:1c1:1:6068::e6a:5]) by mxrelay.nyi.freebsd.org (Postfix) with ESMTP id 4hm1hJ2td6zgY5 for ; Thu, 17 Sep 2026 16:40:16 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from git (uid 1279) (envelope-from git@FreeBSD.org) id 20cd8 by gitrepo.freebsd.org (DragonFly Mail Agent v0.13+ on gitrepo.freebsd.org); Thu, 17 Sep 2026 16:40:16 +0000 To: src-committers@FreeBSD.org, dev-commits-src-all@FreeBSD.org, dev-commits-src-main@FreeBSD.org From: Kevin Bowling Subject: git: e70ff92d2431 - main - ice: Add malformed virtchnl injection points List-Id: Commit messages for the main branch of the src repository List-Archive: https://lists.freebsd.org/archives/dev-commits-src-main List-Help: List-Post: List-Subscribe: List-Unsubscribe: X-BeenThere: dev-commits-src-main@freebsd.org Sender: owner-dev-commits-src-main@FreeBSD.org List-Id: List-Post: List-Help: List-Subscribe: List-Unsubscribe: List-Owner: Precedence: list MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 8bit X-Git-Committer: kbowling X-Git-Repository: src X-Git-Refname: refs/heads/main X-Git-Reftype: branch X-Git-Commit: e70ff92d243104834ad40581c3562a55d7525cc8 Auto-Submitted: auto-generated Date: Thu, 17 Sep 2026 16:40:16 +0000 Message-Id: <6aac17f0.20cd8.518e4aeb@gitrepo.freebsd.org> The branch main has been updated by kbowling: URL: https://cgit.FreeBSD.org/src/commit/?id=e70ff92d243104834ad40581c3562a55d7525cc8 commit e70ff92d243104834ad40581c3562a55d7525cc8 Author: Kevin Bowling AuthorDate: 2026-08-19 03:18:53 +0000 Commit: Kevin Bowling CommitDate: 2026-09-17 16:36:36 +0000 ice: Add malformed virtchnl injection points Extend the optional ice(4) failure injection facility with semantic corruption points for queue configuration, RSS keys and tables, and interrupt mappings. Each point mutates an otherwise valid request after the common virtchnl length check. This exercises the PF semantic validators with a real VF while preserving the normal wire format and mailbox path. The queue point selects unaligned Tx or Rx bases, an unaligned or unrepresentable receive buffer, an invalid frame size, duplicate queue IDs, or a bad VSI. The RSS points select short advertised data or an out-of-range LUT entry. The interrupt point selects an invalid ITR, traffic on vector zero, duplicate vectors, or a bad VSI. The points remain absent unless the kernel is built with options DRIVER_FAILPOINTS and retain the existing PF and VF selectors. MFC after: 2 weeks Sponsored by: BBOX.io Differential Revision: https://reviews.freebsd.org/D59021 --- sys/dev/ice/ice_iov.c | 72 +++++++++++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 72 insertions(+) diff --git a/sys/dev/ice/ice_iov.c b/sys/dev/ice/ice_iov.c index eab735820f8e..0c5d49ebf5b1 100644 --- a/sys/dev/ice/ice_iov.c +++ b/sys/dev/ice/ice_iov.c @@ -1421,6 +1421,41 @@ ice_vc_cfg_vsi_qs_msg(struct ice_softc *sc, struct ice_vf *vf, u8 *msg_buf) int i, error = 0; vqci = (struct virtchnl_vsi_queue_config_info *)msg_buf; + ICE_FAIL_POINT_CODE_COND(sc, _debug_fail_point_ice_iov, + malformed_queues, ice_iov_fail_vf_matches(vf->vf_num), + FAIL_POINT_NONSLEEPABLE, { + switch (RETURN_VALUE) { + case 1: + vqci->qpair[0].txq.dma_ring_addr |= 1; + break; + case 2: + vqci->qpair[0].rxq.dma_ring_addr |= 1; + break; + case 3: + vqci->qpair[0].rxq.databuffer_size++; + break; + case 4: + vqci->qpair[0].rxq.max_pkt_size = 0; + break; + case 5: + if (vqci->num_queue_pairs > 1) { + vqci->qpair[1].txq.queue_id = + vqci->qpair[0].txq.queue_id; + vqci->qpair[1].rxq.queue_id = + vqci->qpair[0].rxq.queue_id; + } else { + vqci->qpair[0].txq.queue_id++; + } + break; + case 6: + vqci->qpair[0].rxq.databuffer_size = + ICE_VC_MAX_RX_BUFFER + BIT(ICE_RLAN_CTX_DBUF_S); + break; + default: + vqci->vsi_id++; + break; + } + }); if (vqci->vsi_id != vsi->idx || vqci->num_queue_pairs == 0 || vqci->num_queue_pairs > sizeof(queue_map) * NBBY || @@ -1569,6 +1604,11 @@ ice_vc_cfg_rss_key_msg(struct ice_softc *sc, struct ice_vf *vf, u8 *msg_buf) struct ice_vsi *vsi = vf->vsi; vrk = (struct virtchnl_rss_key *)msg_buf; + ICE_FAIL_POINT_CODE_COND(sc, _debug_fail_point_ice_iov, + malformed_rss_key, ice_iov_fail_vf_matches(vf->vf_num), + FAIL_POINT_NONSLEEPABLE, { + vrk->key_len--; + }); if (vrk->vsi_id != vsi->idx) { device_printf(sc->dev, @@ -1619,6 +1659,14 @@ ice_vc_cfg_rss_lut_msg(struct ice_softc *sc, struct ice_vf *vf, u8 *msg_buf) struct ice_vsi *vsi = vf->vsi; vrl = (struct virtchnl_rss_lut *)msg_buf; + ICE_FAIL_POINT_CODE_COND(sc, _debug_fail_point_ice_iov, + malformed_rss_lut, ice_iov_fail_vf_matches(vf->vf_num), + FAIL_POINT_NONSLEEPABLE, { + if (RETURN_VALUE == 1) + vrl->lut_entries--; + else + vrl->lut[0] = vsi->num_rx_queues; + }); if (vrl->vsi_id != vsi->idx) { device_printf(sc->dev, @@ -1824,6 +1872,30 @@ ice_vc_cfg_irq_map_msg(struct ice_softc *sc, struct ice_vf *vf, u8 *msg_buf) u16 rxqs_seen, txqs_seen, valid_rxqs, valid_txqs, vector; vimi = (struct virtchnl_irq_map_info *)msg_buf; + ICE_FAIL_POINT_CODE_COND(sc, _debug_fail_point_ice_iov, + malformed_irq_map, ice_iov_fail_vf_matches(vf->vf_num), + FAIL_POINT_NONSLEEPABLE, { + switch (RETURN_VALUE) { + case 1: + vimi->vecmap[0].rxitr_idx = VIRTCHNL_ITR_IDX_NO_ITR + 1; + break; + case 2: + vimi->vecmap[0].vector_id = 0; + vimi->vecmap[0].rxq_map = 1; + break; + case 3: + if (vimi->num_vectors > 1) { + vimi->vecmap[1].vector_id = + vimi->vecmap[0].vector_id; + } else { + vimi->vecmap[0].vsi_id++; + } + break; + default: + vimi->vecmap[0].vsi_id++; + break; + } + }); if (vimi->num_vectors == 0 || vimi->num_vectors > vf->num_irq_vectors ||