cmd: validate the port argument of mtu and pvid

Both handlers turned the first character of the port word into an index
with no check at all. "mtu 0 100" computes '0' - '1' = 255, reads far past
the end of phys_to_log_port[9], and writes the size to whatever register
0x1250 plus that garbage points at. "pvid 0 2" walks the same path into
port_pvid_set(). lag and vlan already validate their port arguments; these
two just did not.

The port now has to be a single digit 1 to 9, which is exactly the range
the mapping table holds. A second digit or a stray letter falls to the
usage message.

"mtu show" also gained the return it was missing: after printing the table
it fell through, derived a port from the word "show" and printed the
garbage byte before the length check stopped it.
This commit is contained in:
d00f
2026-08-08 17:46:24 +02:00
parent 1701d4dc53
commit 930a08ec52
+11 -9
View File
@@ -730,14 +730,16 @@ void parse_mtu(void)
print_string("Port "); print_byte(machine.log_to_phys_port[p]); print_string("Port "); print_byte(machine.log_to_phys_port[p]);
write_char(' '); print_short(mtu); write_char('\n'); write_char(' '); print_short(mtu); write_char('\n');
} }
return;
} }
p = cmd_buffer[cmd_words_b[1]] - '1'; if (cmd_words_len != 3 || cmd_buffer[cmd_words_b[1]] < '1'
p = machine.phys_to_log_port[p]; || cmd_buffer[cmd_words_b[1]] > '9'
print_byte(p); || cmd_buffer[cmd_words_b[1] + 1] > ' ') {
if (cmd_words_len != 3) {
print_string("mtu [port] [size]\n"); print_string("mtu [port] [size]\n");
return; return;
} }
p = machine.phys_to_log_port[cmd_buffer[cmd_words_b[1]] - '1'];
print_byte(p);
if (atoi_short(&mtu, cmd_words_b[2]) || mtu < 64 || mtu > 0x3fff) { if (atoi_short(&mtu, cmd_words_b[2]) || mtu < 64 || mtu > 0x3fff) {
print_string("MTU must be 64..16383\n"); print_string("MTU must be 64..16383\n");
return; return;
@@ -1567,11 +1569,11 @@ void cmd_parser(void) __banked
} }
} else if (cmd_compare(0, "pvid") && cmd_words_len == 3) { } else if (cmd_compare(0, "pvid") && cmd_words_len == 3) {
__xdata uint16_t pvid; __xdata uint16_t pvid;
uint8_t port; if (cmd_buffer[cmd_words_b[1]] >= '1'
port = cmd_buffer[cmd_words_b[1]] - '1'; && cmd_buffer[cmd_words_b[1]] <= '9'
port = machine.phys_to_log_port[port]; && cmd_buffer[cmd_words_b[1] + 1] <= ' '
if (!atoi_short(&pvid, cmd_words_b[2]) && pvid && pvid <= 4094) && !atoi_short(&pvid, cmd_words_b[2]) && pvid && pvid <= 4094)
port_pvid_set(port, pvid); port_pvid_set(machine.phys_to_log_port[cmd_buffer[cmd_words_b[1]] - '1'], pvid);
else else
print_string("Error: pvid <port> <1-4094>\n"); print_string("Error: pvid <port> <1-4094>\n");
} else if (cmd_compare(0, "vlan")) { } else if (cmd_compare(0, "vlan")) {