Index | Thread | Search

From:
Mark Kettenis <mark.kettenis@xs4all.nl>
Subject:
Re: sys/macppc: bound OF_getprop() bounce copy
To:
Kirill A. Korinsky <kirill@korins.ky>
Cc:
tech@openbsd.org
Date:
Mon, 27 Jul 2026 14:55:41 +0200

Download raw body.

Thread
> Date: Mon, 27 Jul 2026 12:23:34 +0200
> From: Kirill A. Korinsky <kirill@korins.ky>
> 
> tech@,
> 
> the Open Firmware getprop service returns the full property size while
> copying at most buflen bytes. macppc redirects the firmware write through
> OF_buf, but copied the returned size into the caller's buffer, allowing an
> oversized property to overwrite adjacent memory.
> 
> Here, I limit the second copy to buflen while preserving getprop's return
> value.
> 
> This fixes stack corruption when QEMU OpenBIOS returns the 60 byte e1000 reg
> property to pci_intr_map(), which requests one 20 byte PCI record. With this
> change, em0 attaches and the ramdisk reaches the installer.
> 
> Ok?

ok kettenis@

> Index: sys/arch/macppc/macppc/openfirm.c
> ===================================================================
> RCS file: /home/cvs/src/sys/arch/macppc/macppc/openfirm.c,v
> diff -u -p -r1.13 openfirm.c
> --- sys/arch/macppc/macppc/openfirm.c	2 Apr 2020 19:27:51 -0000	1.13
> +++ sys/arch/macppc/macppc/openfirm.c	27 Jul 2026 10:01:58 -0000
> @@ -183,7 +183,7 @@ OF_getprop(int handle, char *prop, void 
>  		ret = -1;
>  	else {
>  		if (args.size > 0)
> -			ofbcopy(OF_buf, buf, args.size);
> +			ofbcopy(OF_buf, buf, MIN(args.size, buflen));
>  		ret = args.size;
>  	}
>  	ppc_mtmsr(s);
> 
> -- 
> wbr, Kirill
> 
>