DF-1251 / run.log
RUN_START DF-1251 combios_parse_mmio_table harness BIOS allocation = 512 bytes; table starts at 0x40 (no in-bounds terminator) RBIOS8/16/32 reads past BIOS allocation (OOB): 2 WREG32 GPU-MMIO writes with heap-sourced addr/val: 75 PRIMITIVE CONFIRMED: unbounded loop read 2 words past rdev->bios into heap, and wrote 75 (addr,val) pairs to GPU MMIO (WREG32). Bug is REAL. EXIT=0