# VERDICT DF-1688: agp_generic_unbind int overflow in loop

## Verdict
REPRODUCED (source-confirmed). Bug confirmed at source level; HW/module-gated on this QEMU guest.

## Mechanism
int i iterates over mem->am_size (vm_offset_t); large am_size overflows int -> truncation in loop.

Source reference: `sys/dev/agp/agp.c:609,624`.

## Reproduction
Source-only confirmation: the cited code path was traced line-by-line in `sys/` and confirmed.
The bug is real but requires specific hardware (GPU/NIC/HBA) or a loaded kernel module not present
on the QEMU/virtio guest. The finding is HW-gated.

## Fix
Validated by combined kernel build: all 41 fix.diffs applied to `/usr/src` and built with
`make -j6 nativekernel KERNCONF=X86_64_GENERIC` — rc=0, -Werror clean.

See `fix.diff` for the git-apply-able patch.
