oem-meta: http-boot: fix heap OOB write on read with offset past EOF

HttpBootHandler::read() for READ_DATA revised the response length with

```
    if (offset + data->length >= sb.st_size)
        data->length = sb.st_size - offset;
```

Both offset (uint16_t) and length (uint8_t) are host-supplied. When the
host passes an offset beyond the end of the bios-rootcert file, lseek()
past EOF succeeds and sb.st_size - offset is negative; the implicit
conversion to uint8_t wraps (e.g. 2000 - 2001 -> 255). The memcpy()
into the respbuf data[] region sized from the original request length
then writes out of bounds, corrupting the heap, and the over-written
bytes are encoded back into the response.

Reject offsets at or beyond EOF so the subtraction cannot underflow,
and clamp the revised length to min(requested, remaining) so it can
never exceed the caller's response buffer. Also fail short reads
instead of returning uninitialized bytes, and clamp any over-long
handler length in FileIOHandler::readFileIO as defense in depth.

Signed-off-by: Patrick Williams <patrick@stwcx.xyz>
Reported-by: Yu Chen <paloaltoalex@gmail.com>
Assisted-by: opencode:meta/muse-spark-1.3
Change-Id: Ic9c26aeeb933aeed2ec1f267be661329cc9507e2
2 files changed
tree: fbd23c93a2dcb776f02d6213c63044ba548f02b6
  1. common/
  2. configurations/
  3. docs/
  4. fw-update/
  5. host-bmc/
  6. libpldmresponder/
  7. oem/
  8. platform-mc/
  9. pldmd/
  10. pldmtool/
  11. requester/
  12. softoff/
  13. subprojects/
  14. test/
  15. tools/
  16. utilities/
  17. .clang-format
  18. .clang-tidy
  19. .eslintignore
  20. .gitignore
  21. .linter-ignore
  22. LICENSE
  23. meson.build
  24. meson.options
  25. OWNERS
  26. README.md
README.md

PLDM - Platform Level Data Model

License

Overview

PLDM (Platform Level Data Model) is a key component of the OpenBMC project, providing a standardized data model and message formats for various platform management functionalities. It defines a method to manage, monitor, and control the firmware and hardware of a system.

The OpenBMC PLDM project aims to implement the specifications defined by the Distributed Management Task Force (DMTF), allowing for interoperable management interfaces across different hardware and firmware components.

Features

  • Standardized Messaging: Adheres to the DMTF's PLDM specifications, enabling consistent and interoperable communication between different components.
  • Modularity: Supports multiple PLDM types, including base, FRU,Firmware update, Platform Monitoring and Control, and BIOS Control and Configuration.
  • Extensibility: Easily extendable to support new PLDM types and custom OEM commands.
  • Integration: Seamlessly integrates with other OpenBMC components for comprehensive system management.

Getting Started

Prerequisites

To build and run PLDM, you need the following dependencies:

  • Meson
  • Ninja

Alternatively, source an OpenBMC ARM/x86 SDK.

Building

To build the PLDM project, follow these steps:

meson setup build && meson compile -C build

To run unit tests

The simplest way of running the tests is as described by the meson man page:

meson test -C build

Alternatively, tests can be run in the OpenBMC CI docker container using these steps.

To enable pldm verbosity

pldm daemon accepts a command line argument --verbose or --v or -v to enable the daemon to run in verbose mode. It can be done via adding this option to the environment file that pldm service consumes.

echo 'PLDMD_ARGS="--verbose"' > /etc/default/pldmd
systemctl restart pldmd

To disable pldm verbosity

rm /etc/default/pldmd
systemctl restart pldmd

Documentation

For complete documentation on the functionality and usage of this repository, please refer to the docs folder.