Re: sys/macppc: bound OF_getprop() bounce copy
Mark Kettenis <[email protected]> Mon, 27 Jul 2026 14:55:41 +0200
| Newsgroups | gmane.os.openbsd.tech |
|---|---|
| Message-ID | <[email protected]> |
> Date: Mon, 27 Jul 2026 12:23:34 +0200 > From: Kirill A. Korinsky <[email protected]> > > tech@, > > the Open Firmware getprop service returns the full property size while > copying at most buflen bytes. macppc redirects the firmware write through > OF_buf, but copied the returned size into the caller's buffer, allowing an > oversized property to overwrite adjacent memory. > > Here, I limit the second copy to buflen while preserving getprop's return > value. > > This fixes stack corruption when QEMU OpenBIOS returns the 60 byte e1000 reg > property to pci_intr_map(), which requests one 20 byte PCI record. With this > change, em0 attaches and the ramdisk reaches the installer. > > Ok? ok kettenis@ > Index: sys/arch/macppc/macppc/openfirm.c > =================================================================== > RCS file: /home/cvs/src/sys/arch/macppc/macppc/openfirm.c,v > diff -u -p -r1.13 openfirm.c > --- sys/arch/macppc/macppc/openfirm.c 2 Apr 2020 19:27:51 -0000 1.13 > +++ sys/arch/macppc/macppc/openfirm.c 27 Jul 2026 10:01:58 -0000 > @@ -183,7 +183,7 @@ OF_getprop(int handle, char *prop, void > ret = -1; > else { > if (args.size > 0) > - ofbcopy(OF_buf, buf, args.size); > + ofbcopy(OF_buf, buf, MIN(args.size, buflen)); > ret = args.size; > } > ppc_mtmsr(s); > > -- > wbr, Kirill > >