# VERDICT -- DF-1371

## Verdict: INCONCLUSIVE at runtime; source bug CONFIRMED; fix COMPILE-VALIDATED

**Citations confirmed:**
  - sys/dev/netif/oce/oce_if.c:1274
  - sys/dev/netif/oce/oce_if.c:1276
  - sys/dev/netif/oce/oce_if.c:1283
  - sys/dev/netif/oce/oce_if.c:1291
  - sys/dev/netif/oce/oce_if.c:1401
  - sys/dev/netif/oce/oce_if.c:1414

### Is the bug real? -- YES (source trace)

oce_rx() loops `for (i=0;i<cqe->u0.s.num_fragments;i++)` driven by firmware.
    When `rq->packets_out == rq->packets_in` (ring empty), only a printf fires,
    NO break. pd = &rq->pckts[packets_out] then has pd->mbuf NULL (fresh ring is
    M_ZERO'd, or after consume) -> NULL deref panic. rq->pending-- also
    underflows. oce_discard_rx_comp() :1401 has the same pattern. Triggered by
    memory pressure (m_getcl fail) or firmware bug.

### Can it be reproduced on this guest? -- NO (hardware-gated)

No Emulex OneConnect NIC in PCI list (only virtio_pci 0x10001af4); if_oce.ko not in kldstat.

The oce driver is compiled into `X86_64_GENERIC`, is not loaded, and cannot be `kldload`'d by an unprivileged user (kldload is root-only). Even loaded, it would not attach without the hardware.
Therefore the vulnerable code is unreachable at runtime here. Because the sinks are device-integrated parsers / DRM ioctls / DMA-supplied indices / hardware-dependent paths, no userspace harness on this guest can exercise them. This is the documented valid hard-blocker "unreachable at runtime + no feasible harness"; the bug is a real latent defect with the live trigger conditions noted above.

### No escalation chain (and why that is correct here)
There is no memory-corruption primitive to escalate on this guest: the corruption sinks live entirely inside the not-attached driver behind hardware that is absent. The escalation work the audit expects (slab groom -> victim -> uid0) presupposes a reachable write primitive; here there is none on the guest. The deliverable is therefore the confirmed root-cause + a compile-validated fix.

### Fix (fix.diff) -- authored and COMPILE-VALIDATED
Added `break;` after the device_printf in both oce_rx (:1276) and
oce_discard_rx_comp (:1402). (matches finding proposal.)

The fix was applied to in-guest `/usr/src` (all hunks applied cleanly) and the
kernel was rebuilt with `make -j6 nativekernel KERNCONF=X86_64_GENERIC` => rc=0 (see `build_fix.log`). No warnings or errors in the patched translation unit. The runtime before/after of the bug cannot be tested on this guest (no hardware), so fix_status is `not_testable` (diff applies + compiles; code path traced closed).

### Why not `not_reproduced` (false-positive)?
This is NOT a false positive. The cited `sys/` code is genuinely missing the guard / has the overflow / has the unclamped loop -- verified by reading the source. It is a real bug that is simply out of reach of this particular (driverless) QEMU guest.
