Page MenuHomeFreeBSD

ice: Enforce VF MAC anti-spoof policy
ClosedPublic

Authored by kbowling on Aug 20 2026, 1:45 AM.
Tags
None
Referenced Files
F174540032: D59022.id184425.diff
Sun, Oct 4, 1:04 AM
F174519391: D59022.id186977.diff
Sat, Oct 3, 9:20 PM
Unknown Object (File)
Fri, Oct 2, 10:48 PM
Unknown Object (File)
Thu, Oct 1, 10:40 PM
Unknown Object (File)
Thu, Oct 1, 7:53 AM
Unknown Object (File)
Wed, Sep 30, 5:13 PM
Unknown Object (File)
Thu, Sep 24, 4:48 AM
Unknown Object (File)
Wed, Sep 23, 3:04 AM
Subscribers

Details

Reviewers
kgalazka
Group Reviewers
Intel Networking
Restricted Owners Package(Owns No Changed Paths)
Commits
rG3bdc281f5df0: ice: Enforce VF MAC anti-spoof policy
Summary
The SR-IOV schema enables MAC anti-spoofing by default and reports
it through VF status, but the driver never programs the VSI security
section.  A VF can therefore transmit with an arbitrary source address
despite the advertised policy.

Program ICE_AQ_VSI_SEC_FLAG_ENA_MAC_ANTI_SPOOF when the VF VSI is
created, and replay the policy when the VSI is rebuilt after a PF or
device reset.  Fail VF creation or rebuild when firmware cannot install
the security policy so an unprotected VF is never published as active.

Validated on E810 hardware with host-attached and Linux passthrough
VFs.  Traffic using the assigned source MAC passed while otherwise
identical forged-source frames were dropped.  After a PF reset, assigned
traffic resumed and zero of ten forged frames reached the peer.

An injected MAC anti-spoof update failure left the VF inactive with
PCI bus mastering disabled.  Destroying and recreating the SR-IOV
configuration restored the policy and traffic.

MFC after:      2 weeks
Sponsored by:   BBOX.io

Diff Detail

Repository
rG FreeBSD src repository
Lint
Lint Not Applicable
Unit
Tests Not Applicable