oem-meta: http-boot: fix heap OOB write on read with offset past EOF
HttpBootHandler::read() for READ_DATA revised the response length with
```
if (offset + data->length >= sb.st_size)
data->length = sb.st_size - offset;
```
Both offset (uint16_t) and length (uint8_t) are host-supplied. When the
host passes an offset beyond the end of the bios-rootcert file, lseek()
past EOF succeeds and sb.st_size - offset is negative; the implicit
conversion to uint8_t wraps (e.g. 2000 - 2001 -> 255). The memcpy()
into the respbuf data[] region sized from the original request length
then writes out of bounds, corrupting the heap, and the over-written
bytes are encoded back into the response.
Reject offsets at or beyond EOF so the subtraction cannot underflow,
and clamp the revised length to min(requested, remaining) so it can
never exceed the caller's response buffer. Also fail short reads
instead of returning uninitialized bytes, and clamp any over-long
handler length in FileIOHandler::readFileIO as defense in depth.
Signed-off-by: Patrick Williams <patrick@stwcx.xyz>
Reported-by: Yu Chen <paloaltoalex@gmail.com>
Assisted-by: opencode:meta/muse-spark-1.3
Change-Id: Ic9c26aeeb933aeed2ec1f267be661329cc9507e2
PLDM (Platform Level Data Model) is a key component of the OpenBMC project, providing a standardized data model and message formats for various platform management functionalities. It defines a method to manage, monitor, and control the firmware and hardware of a system.
The OpenBMC PLDM project aims to implement the specifications defined by the Distributed Management Task Force (DMTF), allowing for interoperable management interfaces across different hardware and firmware components.
To build and run PLDM, you need the following dependencies:
MesonNinjaAlternatively, source an OpenBMC ARM/x86 SDK.
To build the PLDM project, follow these steps:
meson setup build && meson compile -C build
The simplest way of running the tests is as described by the meson man page:
meson test -C build
Alternatively, tests can be run in the OpenBMC CI docker container using these steps.
pldm daemon accepts a command line argument --verbose or --v or -v to enable the daemon to run in verbose mode. It can be done via adding this option to the environment file that pldm service consumes.
echo 'PLDMD_ARGS="--verbose"' > /etc/default/pldmd systemctl restart pldmd
rm /etc/default/pldmd systemctl restart pldmd
For complete documentation on the functionality and usage of this repository, please refer to the docs folder.