<feed xmlns='http://www.w3.org/2005/Atom'>
<title>src/sys/dev/netmap, branch main</title>
<subtitle>FreeBSD source tree</subtitle>
<id>http://cgit.freebsd.org/src/atom?h=main</id>
<link rel='self' href='http://cgit.freebsd.org/src/atom?h=main'/>
<link rel='alternate' type='text/html' href='http://cgit.freebsd.org/src/'/>
<updated>2026-08-27T13:33:10Z</updated>
<entry>
<title>netmap: Use ckdint.h helpers to check for overflow</title>
<updated>2026-08-27T13:33:10Z</updated>
<author>
<name>Mark Johnston</name>
<email>markj@FreeBSD.org</email>
</author>
<published>2026-08-27T13:06:20Z</published>
<link rel='alternate' type='text/html' href='http://cgit.freebsd.org/src/commit/?id=d6f5c6531e4848086478961d03f4d13170eff02a'/>
<id>urn:sha1:d6f5c6531e4848086478961d03f4d13170eff02a</id>
<content type='text'>
This addresses a bug in the addition overflow check added in commit
319414a926af ("netmap: Handle overflow when computing ring sizes"): that
overflow wasn't actually caught by the check because "len" is promoted
to size_t.

PR:		297300
Fixes:		319414a926af ("netmap: Handle overflow when computing ring sizes")
Sponsored by:	The FreeBSD Foundation
Differential Revision:	https://reviews.freebsd.org/D58896
</content>
</entry>
<entry>
<title>vtnet: move offload functions to virtio_net.h</title>
<updated>2026-08-27T03:15:17Z</updated>
<author>
<name>Timo Völker</name>
<email>timo.voelker@fh-muenster.de</email>
</author>
<published>2026-08-27T03:09:55Z</published>
<link rel='alternate' type='text/html' href='http://cgit.freebsd.org/src/commit/?id=bb50bb45f5f650873b202e644bfcd9f2992cdace'/>
<id>urn:sha1:bb50bb45f5f650873b202e644bfcd9f2992cdace</id>
<content type='text'>
Move the functions vtnet_rxq_csum() and vtnet_txq_offload() and the
subfunctions they call from if_vtnet.c to virtio_net.h. This allows
us to call these functions from if_tuntap.c and if_ptnet.c.
virtio_net.h already contained a copy of these functions, but a copy
of an outdated version. The functions evolved in if_vtnet.c.
In if_vtnet.c, the copy has never been used because it increments
counters in their own functions.
This patch removes the outdated copy from virtio_net.h and moves the
new version of the functions from if_vtnet.c to virtio_net.h.
if_tuntap.c, if_ptnet.c, and if_vtnet.c just call these functions,
and if_vtnet.c increments its counters depending on the return value.

Reviewed by:		tuexen
MFC after:		1 month
MFC to:			stable/15
Differential Revision:	https://reviews.freebsd.org/D57299
</content>
</entry>
<entry>
<title>Revert "vtnet: move offload functions to virtio_net.h to share them"</title>
<updated>2026-08-21T20:16:05Z</updated>
<author>
<name>Michael Tuexen</name>
<email>tuexen@FreeBSD.org</email>
</author>
<published>2026-08-21T20:16:05Z</published>
<link rel='alternate' type='text/html' href='http://cgit.freebsd.org/src/commit/?id=8bea280f4325d10858ec58ae7251db7604fa77a2'/>
<id>urn:sha1:8bea280f4325d10858ec58ae7251db7604fa77a2</id>
<content type='text'>
This reverts commit 44cddaa99dee0a634cf2713f71e799eb41397355.
It breaks the LINT-NOIP config.
</content>
</entry>
<entry>
<title>vtnet: move offload functions to virtio_net.h to share them</title>
<updated>2026-08-18T12:49:40Z</updated>
<author>
<name>Timo Völker</name>
<email>timo.voelker@fh-muenster.de</email>
</author>
<published>2026-08-18T12:49:40Z</published>
<link rel='alternate' type='text/html' href='http://cgit.freebsd.org/src/commit/?id=44cddaa99dee0a634cf2713f71e799eb41397355'/>
<id>urn:sha1:44cddaa99dee0a634cf2713f71e799eb41397355</id>
<content type='text'>
Move the functions vtnet_rxq_csum() and vtnet_txq_offload() and the
subfunctions they call from if_vtnet.c to virtio_net.h. This allows
us to call these functions from if_tuntap.c and if_ptnet.c.
virtio_net.h already contained a copy of these functions, but a copy
of an outdated version. The functions evolved in if_vtnet.c.
In if_vtnet.c, the copy has never been used because it increments
counters in their own functions.
This patch removes the outdated copy from virtio_net.h and moves the
new version of the functions from if_vtnet.c to virtio_net.h.
if_tuntap.c, if_ptnet.c, and if_vtnet.c just call these functions,
and if_vtnet.c increments its counters depending on the return value.

Reviewed by:		tuexen
MFC after:		1 month
MFC to:			stable/15
Differential Revision:	https://reviews.freebsd.org/D57299
</content>
</entry>
<entry>
<title>netmap: Handle overflow when computing ring sizes</title>
<updated>2026-08-07T16:30:24Z</updated>
<author>
<name>Mark Johnston</name>
<email>markj@FreeBSD.org</email>
</author>
<published>2026-08-07T14:47:13Z</published>
<link rel='alternate' type='text/html' href='http://cgit.freebsd.org/src/commit/?id=319414a926af1515e2572f89f0636e5505e762d5'/>
<id>urn:sha1:319414a926af1515e2572f89f0636e5505e762d5</id>
<content type='text'>
PR:		297300
Reported by:	Robert Morris
Reported by:	syzkaller
Reviewed by:	vmaffione
MFC after:	2 weeks
Sponsored by:	The FreeBSD Foundation
Differential Revision:	https://reviews.freebsd.org/D58678
</content>
</entry>
<entry>
<title>netmap: Fix a race in kqueue registration</title>
<updated>2026-08-07T16:30:24Z</updated>
<author>
<name>Mark Johnston</name>
<email>markj@FreeBSD.org</email>
</author>
<published>2026-08-07T14:47:06Z</published>
<link rel='alternate' type='text/html' href='http://cgit.freebsd.org/src/commit/?id=6de818285f066c6705816674c671761dc09bff90'/>
<id>urn:sha1:6de818285f066c6705816674c671761dc09bff90</id>
<content type='text'>
We need to acquire the netmap global lock earlier, to avoid racing with
the NETMAP_REQ_REGISTER ioctl handler.

Reported by:	syzkaller
Reviewed by:	vmaffione
MFC after:	2 weeks
Sponsored by:	The FreeBSD Foundation
Differential Revision:	https://reviews.freebsd.org/D58677
</content>
</entry>
<entry>
<title>netmap: Fix driver name handling</title>
<updated>2026-08-07T16:30:24Z</updated>
<author>
<name>Mark Johnston</name>
<email>markj@FreeBSD.org</email>
</author>
<published>2026-08-07T14:46:52Z</published>
<link rel='alternate' type='text/html' href='http://cgit.freebsd.org/src/commit/?id=800d5b7a8a4f5665ced0453e090f8d563366bd47'/>
<id>urn:sha1:800d5b7a8a4f5665ced0453e090f8d563366bd47</id>
<content type='text'>
if_initname() requires the caller to ensure that the lifetime of the
interface's name buffer contains that of the ifnet itself.
netmap_vi_create() wasn't respecting that; we were instead passing the
stack-allocated buffer provided by the ioctl handler.

While here, add a check to avoid assuming that the caller-provided
buffer is nul-terminated.

Reported by:	syzkaller
Reviewed by:	vmaffione
MFC after:	2 weeks
Sponsored by:	The FreeBSD Foundation
Differential Revision:	https://reviews.freebsd.org/D58676
</content>
</entry>
<entry>
<title>netmap: Don't assume that user-provided strings are nul-terminated</title>
<updated>2026-07-09T13:41:19Z</updated>
<author>
<name>Mark Johnston</name>
<email>markj@FreeBSD.org</email>
</author>
<published>2026-07-08T17:11:05Z</published>
<link rel='alternate' type='text/html' href='http://cgit.freebsd.org/src/commit/?id=e1ab35148dd425340a88a2acaf10b972cb119f8f'/>
<id>urn:sha1:e1ab35148dd425340a88a2acaf10b972cb119f8f</id>
<content type='text'>
MFC after:	1 week
Sponsored by:	The FreeBSD Foundation
</content>
</entry>
<entry>
<title>netmap: Drain selinfo sleepers in nm_os_selinfo_uninit()</title>
<updated>2026-05-20T19:34:50Z</updated>
<author>
<name>Mark Johnston</name>
<email>markj@FreeBSD.org</email>
</author>
<published>2026-05-19T00:09:54Z</published>
<link rel='alternate' type='text/html' href='http://cgit.freebsd.org/src/commit/?id=4c09834afad02f97f7daeabc3c281784a04880a3'/>
<id>urn:sha1:4c09834afad02f97f7daeabc3c281784a04880a3</id>
<content type='text'>
Approved by:	so
Security:	FreeBSD-SA-26:19.file
Security:	CVE-2026-45251
</content>
</entry>
<entry>
<title>netmap: check for possible out-of-bound write with options</title>
<updated>2026-04-29T21:13:09Z</updated>
<author>
<name>Vincenzo Maffione</name>
<email>vmaffione@FreeBSD.org</email>
</author>
<published>2026-04-29T20:59:17Z</published>
<link rel='alternate' type='text/html' href='http://cgit.freebsd.org/src/commit/?id=0216ea8598af7d4170a8660f48981fb12b7b1d67'/>
<id>urn:sha1:0216ea8598af7d4170a8660f48981fb12b7b1d67</id>
<content type='text'>
Submitted by:	hari.thirusangu@sophos.com
MFC after:	2 weeks
</content>
</entry>
</feed>
