git: 4505445ccdb9 - main - bhyve: tpm: allow the last dword of the CRB command buffer

From: Kyle Evans <kevans_at_FreeBSD.org>
Date: Tue, 15 Sep 2026 14:04:57 UTC
The branch main has been updated by kevans:

URL: https://cgit.FreeBSD.org/src/commit/?id=4505445ccdb9555efc23262a971a18ca03486969

commit 4505445ccdb9555efc23262a971a18ca03486969
Author:     Quentin Thébault <quentin.thebault@defenso.fr>
AuthorDate: 2026-08-07 14:02:08 +0000
Commit:     Kyle Evans <kevans@FreeBSD.org>
CommitDate: 2026-09-15 14:04:28 +0000

    bhyve: tpm: allow the last dword of the CRB command buffer
    
    The bounds check rejected any access ending exactly at the end of the
    register block, so a four byte write at offset 0xffc was refused,
    returning EINVAL and killing the VM.
    
    MFC after:      1 week
    PR:             291063
    Fixes:          75909086a45d ("bhyve: allow read/write to full CRB buffer")
    Sponsored by:   Defenso
    
    Signed-off-by: Quentin Thébault <quentin.thebault@defenso.fr>
    Reviewed-by: aokblast, kevans, markj
    Pull-Request: https://github.com/freebsd/freebsd-src/pull/2362
---
 usr.sbin/bhyve/tpm_intf_crb.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/usr.sbin/bhyve/tpm_intf_crb.c b/usr.sbin/bhyve/tpm_intf_crb.c
index 7058b47733f3..ef1a3a6bf34a 100644
--- a/usr.sbin/bhyve/tpm_intf_crb.c
+++ b/usr.sbin/bhyve/tpm_intf_crb.c
@@ -321,7 +321,7 @@ tpm_crb_mem_handler(struct vcpu *vcpu __unused, const int dir,
 	crb = arg1;
 
 	off = addr - TPM_CRB_ADDRESS;
-	if (off > TPM_CRB_REGS_SIZE || off + size >= TPM_CRB_REGS_SIZE) {
+	if (off > TPM_CRB_REGS_SIZE || off + size > TPM_CRB_REGS_SIZE) {
 		return (EINVAL);
 	}