From: Mark Kettenis Subject: Re: sys/macppc: bound OF_getprop() bounce copy To: Kirill A. Korinsky Cc: tech@openbsd.org Date: Mon, 27 Jul 2026 14:55:41 +0200 > Date: Mon, 27 Jul 2026 12:23:34 +0200 > From: Kirill A. Korinsky > > tech@, > > the Open Firmware getprop service returns the full property size while > copying at most buflen bytes. macppc redirects the firmware write through > OF_buf, but copied the returned size into the caller's buffer, allowing an > oversized property to overwrite adjacent memory. > > Here, I limit the second copy to buflen while preserving getprop's return > value. > > This fixes stack corruption when QEMU OpenBIOS returns the 60 byte e1000 reg > property to pci_intr_map(), which requests one 20 byte PCI record. With this > change, em0 attaches and the ramdisk reaches the installer. > > Ok? ok kettenis@ > Index: sys/arch/macppc/macppc/openfirm.c > =================================================================== > RCS file: /home/cvs/src/sys/arch/macppc/macppc/openfirm.c,v > diff -u -p -r1.13 openfirm.c > --- sys/arch/macppc/macppc/openfirm.c 2 Apr 2020 19:27:51 -0000 1.13 > +++ sys/arch/macppc/macppc/openfirm.c 27 Jul 2026 10:01:58 -0000 > @@ -183,7 +183,7 @@ OF_getprop(int handle, char *prop, void > ret = -1; > else { > if (args.size > 0) > - ofbcopy(OF_buf, buf, args.size); > + ofbcopy(OF_buf, buf, MIN(args.size, buflen)); > ret = args.size; > } > ppc_mtmsr(s); > > -- > wbr, Kirill > >