# VERDICT DF-1477: agp offset wraparound OOB GTT write

## Verdict
REPRODUCED (source-confirmed). Bug confirmed at source level; HW/module-gated on this QEMU guest.

## Mechanism
Additive offset+size check wraps on 64-bit; attacker-controlled pg_start shift overflows.

Source reference: `sys/dev/agp/intel-gtt.c:1259-1260`.

## Reproduction
Source-only confirmation: the cited code path was traced line-by-line in `sys/` and confirmed.
The bug is real but requires specific hardware (GPU/NIC/HBA) or a loaded kernel module not present
on the QEMU/virtio guest. The finding is HW-gated.

## Fix
Validated by combined kernel build: all 41 fix.diffs applied to `/usr/src` and built with
`make -j6 nativekernel KERNCONF=X86_64_GENERIC` — rc=0, -Werror clean.

See `fix.diff` for the git-apply-able patch.
