Page MenuHomeFreeBSD

bhyve: e82545: allow access to the last receive address register
Needs ReviewPublic

Authored by wanpengqian_gmail.com on Fri, Oct 2, 3:38 AM.

Details

Reviewers
None
Group Reviewers
bhyve
Summary

The device model keeps 16 receive addresses (esc_uni[16]) and maps
RAL(0) ... RAH(15) to them, but e82545_read_ra() and e82545_write_ra()
assert that the index is below 15. A guest that reads or writes the
last entry aborts bhyve when assertions are compiled in:

Assertion failed: (idx < 15), function e82545_read_ra, file
pci_e82545.c, line 1609.

Assert against the size of the array instead. QEMU's e1000 model
handles the same 16 pairs (RA ... RA + 31).

Signed-off-by: Wanpeng Qian <wanpengqian@gmail.com>
Sponsored by: keelos.dev

Test Plan

Builds on main at f958aa7e7 (2026-10-02) (usr.sbin/bhyve, amd64; assertions are compiled in there).

Run-tested with a 14.5-based bhyve built with assertions (keelOS), a Debian 13 guest with -s 7,e1000,tap206. In the guest, as root, read the registers through the BAR:

python3 -c "
import mmap,os,struct
f=os.open('/sys/bus/pci/devices/0000:00:07.0/resource0',os.O_RDWR|os.O_SYNC); m=mmap.mmap(f,0x20000)
for i in (0,14,15):
    print('RAL(%d) = %#x' % (i, struct.unpack('<I',m[0x5400+8*i:0x5404+8*i])[0]), flush=True)"

Before: RAL(0) and RAL(14) print, then bhyve exits with Assertion failed: (idx < 15), function e82545_read_ra and the VM is gone.

After: RAL(15) = 0x0, the VM keeps running.

I first hit this with a FreeBSD 16.0-CURRENT guest whose em0 was in netmap mode: when the guest sent an empty netmap packet with a kernel that lacks D60217 (iflib), the host's bhyve aborted with this assertion. I did not trace which access of the guest read the register.

Diff Detail

Repository
rG FreeBSD src repository
Lint
Lint Skipped
Unit
Tests Skipped
Build Status
Buildable 77595
Build 74478: arc lint + arc unit