Utility: Check request sizes like the firmware

InitStart sizes: Netconf and NpSignin accepted any size, then wrote
common.size bytes back from a 64-68 byte host struct, copying host memory
into PSP RAM. GamedataInstall looked for install files before checking the
size, and the HtmlViewer read options before checking the whole request was
in memory. All the dialogs now check the address, then the sizes
sceUtility_Driver accepts (utility/dialog/sizes), before anything else, as
the firmware does (a bad address is INVALID_ADDRESS), and write back no more
than the struct.

Co-Authored-By: Claude Opus 5.5 (1M context) <[email protected]>
This commit is contained in:
Henrik RydgårdandClaude Opus 5.5 committed 2026-09-25 12:50:41 -06:00
1 parent 9e69c1f9aa
commit 6dffcc91d2
11 files changed
+74 -80

No files matched your search

+8 -26
View File
@@ -52,23 +52,10 @@ struct SceUtilityHtmlViewerParam {
};
// From sceUtility_Driver's InitStart for the HtmlViewer, firmware 6.61: the request size says which
// firmware's layout it is, and the working memory it allocates for the browser depends on that and
// on bit 0x400 of options. Any other size is INVALID_PARAM_SIZE.
static bool HtmlViewerWorkSize(u32 size, u32 options, u32 *workSize) {
switch (size) {
case 0x70: // 2.00
case 0x78: // 2.50
case 0x80: // 2.60
*workSize = 0x380000;
return true;
case 0x98: // 2.70
case 0xA4: // 2.80
case 0xA8: // 3.00
*workSize = (options & 0x400) ? 0x480000 : 0x380000;
return true;
default:
return false;
}
// firmware's layout it is: 0x70, 0x78 and 0x80 are 2.00 to 2.60, 0x98, 0xA4 and 0xA8 2.70 to 3.00.
// The working memory it allocates for the browser depends on that and on bit 0x400 of options.
static u32 HtmlViewerWorkSize(u32 size, u32 options) {
return size >= 0x98 && (options & 0x400) ? 0x480000 : 0x380000;
}
static std::string ReadUrl(u32 addr) {
@@ -99,18 +86,13 @@ int PSPHtmlViewerDialog::Init(u32 paramAddr) {
if (GetStatus() != SCE_UTILITY_STATUS_NONE) {
return SCE_ERROR_UTILITY_INVALID_STATUS;
}
if (!Memory::IsValidRange(paramAddr, sizeof(pspUtilityDialogCommon))) {
return SCE_ERROR_UTILITY_INVALID_ADDRESS;
const int check = CheckRequest(paramAddr, { 0x70, 0x78, 0x80, 0x98, 0xA4, 0xA8 });
if (check < 0) {
return check;
}
const u32 size = Memory::ReadUnchecked_U32(paramAddr);
const SceUtilityHtmlViewerParam *param = (const SceUtilityHtmlViewerParam *)Memory::GetPointerUnchecked(paramAddr);
u32 workSize = 0;
if (!HtmlViewerWorkSize(size, param->options, &workSize)) {
return SCE_ERROR_UTILITY_INVALID_PARAM_SIZE;
}
if (!Memory::IsValidRange(paramAddr, size)) {
return SCE_ERROR_UTILITY_INVALID_ADDRESS;
}
u32 workSize = HtmlViewerWorkSize(size, param->options);
u32 addr = userMemory.Alloc(workSize, false, "HtmlViewer");
if (addr == (u32)-1) {