Skip to content

Security policy

Reporting a vulnerability

Please do not open a public issue for a security problem.

Use GitHub's private reporting instead: go to the Security tab of this repository and choose Report a vulnerability. That opens a private advisory visible only to the maintainers, and it lets us work on a fix and publish it together with the disclosure.

What helps, in rough order of usefulness:

  • what an attacker gains - read a file they should not, crash the process, run code;
  • the shortest input that triggers it. A capture, a disk image or a byte sequence is worth far more than a description of one;
  • which component and which version or commit;
  • whether it needs a valid session, a local account, or nothing at all.

You will get an acknowledgement. This is a small project maintained in spare time, so please do not read a slow reply as a lack of interest - if a week passes with no word, send a reminder through the same advisory.

What is in scope

This repository is a hardware design: the Norsk Data ND-120 CPU board in Verilog, the bitstreams built from it, and the Python and shell tools used to test and debug it. Nothing in it listens on a network. What it does read from outside:

  • The SD card. On the Tang Nano 20K, Nexys 4 DDR and QMTECH boards, the logic in Verilog/SD-FAT/ initialises the card, reads its partition table and boot sector, mounts a FAT16 or FAT32 file system, scans the root directory (8.3 and long names), follows cluster chains, and writes back into image files. The files it opens are floppy, Winchester and tape images whose contents the emulated ND-100 bus devices then serve to SINTRAN III. A card or an image that makes this logic read or write outside the file it opened, or hang, is in scope.
  • Disc images picked in a menu. On the MiSTer and the MEGA65 the images are chosen in the framework's menu and read through nd_storage_hps.v and nd_storage_vdrives.v.
  • The console. The serial console (the SC2661 UART, and the operator console OPCOM behind it) and, on the boards with a screen, the TDV2200 terminal core in Verilog/Terminals/, which takes PS/2 or MEGA65 keyboard input and escape sequences from the running machine.
  • The tools. The Python and shell scripts under Verilog/ and Code/ read simulator traces, waveform files, disc images and serial-port output, and build FAT test images. They are development tools, meant to run on your own machine on files you made.

Also in scope: anything in this repository that handles a file or a stream it did not create - a disk image, a configuration file, a capture, a saved session.

What is not in scope

  • The age of the machine itself. The ND-120 and SINTRAN III are a 1988 computer and its operating system. What the original hardware, microcode or operating system allowed - a program with the right privileges reading any memory, the operator console stopping the CPU - is what they were; reproducing them faithfully is the purpose of this project, not a defect. Do not connect the console of a running board to a network you do not control.
  • A report generated by a scanner with no demonstration that the finding is reachable.
  • Denial of service by sending an unreasonable volume of traffic.
  • Anything requiring the attacker to already be able to run code as the user.

Supported versions

The most recent bitstream release (tagged bitstreams-YYYY-MM) and the default branch are supported. An older release is fixed by a newer one, not patched.

Credit

Unless you ask otherwise, you will be named in the advisory and in the release notes for the fix.