From: Claudiu Manoil <claudiu.manoil@nxp.com>
To: "Wei Fang (OSS)" <wei.fang@oss.nxp.com>,
Vladimir Oltean <vladimir.oltean@nxp.com>,
Clark Wang <xiaoning.wang@nxp.com>,
"andrew@lunn.ch" <andrew@lunn.ch>,
"olteanv@gmail.com" <olteanv@gmail.com>,
"andrew+netdev@lunn.ch" <andrew+netdev@lunn.ch>,
"davem@davemloft.net" <davem@davemloft.net>,
"edumazet@google.com" <edumazet@google.com>,
"kuba@kernel.org" <kuba@kernel.org>,
"pabeni@redhat.com" <pabeni@redhat.com>,
"linux@armlinux.org.uk" <linux@armlinux.org.uk>
Cc: Wei Fang <wei.fang@nxp.com>,
"imx@lists.linux.dev" <imx@lists.linux.dev>,
"netdev@vger.kernel.org" <netdev@vger.kernel.org>,
"linux-kernel@vger.kernel.org" <linux-kernel@vger.kernel.org>
Subject: RE: [PATCH v4 net-next 11/15] net: enetc: restore VF MAC promiscuous mode after FLR for ENETC v4
Date: Fri, 11 Sep 2026 20:17:38 +0000 [thread overview]
Message-ID: <GV2PR04MB1174092070555DBE69BF8FDBA96BE2@GV2PR04MB11740.eurprd04.prod.outlook.com> (raw)
In-Reply-To: <20260909100733.1139689-12-wei.fang@oss.nxp.com>
NXP Confidential
> -----Original Message-----
> From: Wei Fang (OSS) <wei.fang@oss.nxp.com>
> Sent: Wednesday, September 9, 2026 1:07 PM
[...]
> Subject: [PATCH v4 net-next 11/15] net: enetc: restore VF MAC promiscuous
> mode after FLR for ENETC v4
>
> From: Wei Fang <wei.fang@nxp.com>
>
> On ENETC v4, when VF performs a PCI FLR, it resets PSIPMMR[SIn_MAC_UP]
> and PSIPMMR[SIn_MAC_MP] bits, which control the unicast and multicast
> promiscuous mode for the corresponding SI. The reset (default) value of
> these bits enables promiscuous mode, meaning that after a VF FLR, the
> SI is left in promiscuous mode regardless of the configuration set by
> the PF driver prior to the reset.
>
> This is a potential security vulnerability: a malicious VM could
> deliberately trigger a VF FLR to force promiscuous mode on its SI,
> allowing it to capture network traffic not destined for that VF.
>
> To mitigate this, make the following changes:
>
> - Add ENETC_VF_FLAG_UC_PROMISC and ENETC_VF_FLAG_MC_PROMISC to
> enetc_vf_flags to track the PF-managed promiscuous mode state for each
> VF.
>
> - Update enetc_msg_set_vf_mac_promisc_mode() to keep these flags in sync
> whenever a VF requests a promiscuous mode change via messaging.
>
> - Update enetc_pf_set_vf_trust() to clear both promisc flags when a VF
> is untrusted, so that a subsequent FLR cannot restore promiscuous mode
> that the PF has already revoked.
>
> - Add a vf_flr_handler callback to enetc_pf_ops. The ENETC v4
> implementation re-applies the tracked UC/MC promiscuous mode settings
> to the hardware after each FLR, ensuring the hardware state matches
> the PF-managed policy rather than the insecure reset default.
>
> - Add enetc_vf_flr_handler() in enetc_msg.c to detect FLR events via the
> PSIIDR register and dispatch to the vf_flr_handler callback. Invoke it
> at the start of enetc_msg_task() before processing VF messages.
>
> - Enable FLR interrupts in PSIIER only when a vf_flr_handler callback is
> registered, keeping ENETC v1 behavior unchanged.
>
> Signed-off-by: Wei Fang <wei.fang@nxp.com>
Reviewed-by: Claudiu Manoil <claudiu.manoil@nxp.com>
next prev parent reply other threads:[~2026-09-11 20:17 UTC|newest]
Thread overview: 38+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-09 10:07 [PATCH v4 net-next 00/15] net: enetc: SR-IOV improvements and ENETC v4 VF support wei.fang
2026-09-09 10:07 ` [PATCH v4 net-next 01/15] net: enetc: add trusted " wei.fang
2026-09-10 11:20 ` netdev-bot+sashiko
2026-09-11 2:29 ` Wei Fang
2026-09-09 10:07 ` [PATCH v4 net-next 02/15] net: enetc: move msg_task and msg_int_name to struct enetc_si wei.fang
2026-09-11 20:14 ` Claudiu Manoil
2026-09-09 10:07 ` [PATCH v4 net-next 03/15] net: enetc: add link status message support to PF driver wei.fang
2026-09-10 11:20 ` netdev-bot+sashiko
2026-09-11 5:55 ` Wei Fang
2026-09-11 20:15 ` Claudiu Manoil
2026-09-09 10:07 ` [PATCH v4 net-next 04/15] net: enetc: add link speed " wei.fang
2026-09-10 11:20 ` netdev-bot+sashiko
2026-09-11 2:56 ` Wei Fang
2026-09-11 20:16 ` Claudiu Manoil
2026-09-09 10:07 ` [PATCH v4 net-next 05/15] net: enetc: use enetc_set_si_hw_addr() to set VF MAC address wei.fang
2026-09-09 10:07 ` [PATCH v4 net-next 06/15] net: enetc: relocate enetc_pf_set_vf_mac() for common PF support wei.fang
2026-09-09 10:07 ` [PATCH v4 net-next 07/15] net: enetc: add .ndo_set_vf_mac() to the enetc v4 driver wei.fang
2026-09-10 10:37 ` sashiko-bot
2026-09-09 10:07 ` [PATCH v4 net-next 08/15] net: enetc: move mac_filter from struct enetc_pf to struct enetc_si wei.fang
2026-09-10 10:37 ` sashiko-bot
2026-09-09 10:07 ` [PATCH v4 net-next 09/15] net: enetc: add MAC address filtering support for VFs of ENETC v4 wei.fang
2026-09-10 11:21 ` netdev-bot+sashiko
2026-09-11 6:13 ` Wei Fang
2026-09-09 10:07 ` [PATCH v4 net-next 10/15] net: enetc: simplify and rename PSIIER enable/disable helpers wei.fang
2026-09-09 10:07 ` [PATCH v4 net-next 11/15] net: enetc: restore VF MAC promiscuous mode after FLR for ENETC v4 wei.fang
2026-09-10 11:21 ` netdev-bot+sashiko
2026-09-11 6:23 ` Wei Fang
2026-09-11 20:17 ` Claudiu Manoil [this message]
2026-09-09 10:07 ` [PATCH v4 net-next 12/15] net: enetc: add VF support for i.MX94 and i.MX95 wei.fang
2026-09-10 10:37 ` sashiko-bot
2026-09-11 7:31 ` Wei Fang (OSS)
2026-09-09 10:07 ` [PATCH v4 net-next 13/15] net: enetc: implement ndo_set_rx_mode_async for ENETC v4 VF wei.fang
2026-09-10 10:37 ` sashiko-bot
2026-09-11 8:02 ` Wei Fang (OSS)
2026-09-10 11:21 ` netdev-bot+sashiko
2026-09-11 7:17 ` Wei Fang
2026-09-09 10:07 ` [PATCH v4 net-next 14/15] net: enetc: add PSI-to-VSI link status notification support for VF wei.fang
2026-09-09 10:07 ` [PATCH v4 net-next 15/15] net: enetc: add ndo_get_vf_config() support wei.fang
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=GV2PR04MB1174092070555DBE69BF8FDBA96BE2@GV2PR04MB11740.eurprd04.prod.outlook.com \
--to=claudiu.manoil@nxp.com \
--cc=andrew+netdev@lunn.ch \
--cc=andrew@lunn.ch \
--cc=davem@davemloft.net \
--cc=edumazet@google.com \
--cc=imx@lists.linux.dev \
--cc=kuba@kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux@armlinux.org.uk \
--cc=netdev@vger.kernel.org \
--cc=olteanv@gmail.com \
--cc=pabeni@redhat.com \
--cc=vladimir.oltean@nxp.com \
--cc=wei.fang@nxp.com \
--cc=wei.fang@oss.nxp.com \
--cc=xiaoning.wang@nxp.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox