Skip to content

Handle overlong AML package lengths - #365

Open
mikamikasuki wants to merge 2 commits into
rust-osdev:mainfrom
mikamikasuki:fix-overlong-aml-package-length-362
Open

mikamikasuki wants to merge 2 commits into
rust-osdev:mainfrom
mikamikasuki:fix-overlong-aml-package-length-362

Conversation

@mikamikasuki

Copy link
Copy Markdown

Fixes #362.

When a Package's declared element count is reached before its encoded PkgLength ends, the parser currently asserts that the block also reached the length boundary. An overlong PkgLength followed by a NameOp therefore panics and prevents later namespace objects from loading.

On package completion, resume at the next AML term only when its prefix cannot encode a PackageElement. Keep the encoded boundary when the next bytes may be a DataRefObject or NameString, whose ownership is ambiguous. Add a raw AML regression with adjacent packages where the first PkgLength overlaps the following NameOp.

Validation:

  • cargo test -p acpi --no-default-features --features aml --test incorrect_package_length (1 passed)
  • cargo +nightly-2026-04-05 fmt --all -- --check
  • git diff --check

@martin-hughes

Copy link
Copy Markdown
Contributor

Thanks for this @mikamikasuki! Before I review / test / merge this I'm going to take some time to explore how other interpreters deal with the ambiguous case mentioned in your comments.

Alternatively, have you already looked into this?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Incorrect pkglength can cause panic

2 participants