Utility: Check request sizes like the firmware

InitStart sizes: Netconf and NpSignin accepted any size, then wrote
common.size bytes back from a 64-68 byte host struct, copying host memory
into PSP RAM. GamedataInstall looked for install files before checking the
size, and the HtmlViewer read options before checking the whole request was
in memory. All the dialogs now check the address, then the sizes
sceUtility_Driver accepts (utility/dialog/sizes), before anything else, as
the firmware does (a bad address is INVALID_ADDRESS), and write back no more
than the struct.

Co-Authored-By: Claude Opus 5.5 (1M context) <[email protected]>
This commit is contained in:
Henrik RydgårdandClaude Opus 5.5 committed 2026-09-25 12:50:41 -06:00
1 parent 9e69c1f9aa
commit 6dffcc91d2
11 files changed
+74 -80

No files matched your search

+11 -6
View File
@@ -60,16 +60,21 @@ int PSPNetconfDialog::Init(u32 paramAddr) {
if (ReadStatus() != SCE_UTILITY_STATUS_NONE)
return SCE_ERROR_UTILITY_INVALID_STATUS;
const int check = CheckRequest(paramAddr, { 0x38, 0x40, 0x44 });
if (check < 0) {
return check;
}
if (!ReadVariableSizedStruct(paramAddr, &request)) {
return SCE_KERNEL_ERROR_BAD_ARGUMENT; // untested, it's misaligned
}
requestAddr = paramAddr;
NOTICE_LOG(Log::sceUtility, "PSPNetConfDialog Init");
jsonReady_ = false;
// Kick off a request to the infra-dns.json since we'll need it later.
StartInfraJsonDownload();
requestAddr = paramAddr;
if (!ReadVariableSizedStruct(paramAddr, &request)) {
return SCE_KERNEL_ERROR_BAD_ARGUMENT; // untested
}
ChangeStatusInit(NET_INIT_DELAY_US);
// Eat any keys pressed before the dialog inited.
@@ -340,7 +345,7 @@ int PSPNetconfDialog::Update(int animSpeed) {
}
if (ReadStatus() == SCE_UTILITY_STATUS_FINISHED || pendingStatus == SCE_UTILITY_STATUS_FINISHED)
Memory::Memcpy(requestAddr, &request, request.common.size, "NetConfDialogParam");
Memory::Memcpy(requestAddr, &request, std::min((u32)request.common.size, (u32)sizeof(request)), "NetConfDialogParam");
return 0;
}