Hi Phil,
I was compiling/running CSNOBOL4 for Amiga (AmigaOS 3.x using ixemul.library, a POSIX compatibility layer) and encountered an issue while running the performance test (bench.sno v311.sil): a buffer overflow in the replacement getline() and bufio_getline() function for lines longer than 128 characters.
Since neither the Amiga C libraries nor ixemul include a getline() function, the build process utilized
your implementation found in lib/auxil/getline.c and bufio_obj.c.
The variable "avail" is not decremented within the loop, so it never reaches the threshold for realloc().
This results in an overflow of the 128-byte buffer when processing long lines and causes the program to crash during free(). Files with lines ~200 characters long: v311.sil (line 3640) and test/v311.sil (line 3417) - macro PATBRA SELBRA.
The same crash can be reproduced on Linux by using -DNEED_GETLINE.
--- a/lib/auxil/getline.c
+++ b/lib/auxil/getline.c
@@ -53,6 +53,7 @@ getline(char **bufp, size_t *lenp, FILE *fp) {
if (c == EOF)
break;
*cp++ = c;
count++;
+ avail--;
} while (c != '\n');
--- a/lib/auxil/bufio_obj.c
+++ b/lib/auxil/bufio_obj.c
@@ -124,6 +124,7 @@ bufio_getline(struct bufio *bp, char **bufp, size_t *lenp) {
if (c == EOF)
break;
*cp++ = c;
count++;
+ avail--;
} while (c != '\n');
The test now completes without errors and provides clear statistics - this facilitates porting to older non-Unix
systems and retro platforms that lack modern POSIX libraries.
Best regards,
Marcin
Hi Phil,
I was compiling/running CSNOBOL4 for Amiga (AmigaOS 3.x using ixemul.library, a POSIX compatibility layer) and encountered an issue while running the performance test (bench.sno v311.sil): a buffer overflow in the replacement getline() and bufio_getline() function for lines longer than 128 characters.
Since neither the Amiga C libraries nor ixemul include a getline() function, the build process utilized
your implementation found in lib/auxil/getline.c and bufio_obj.c.
The variable "avail" is not decremented within the loop, so it never reaches the threshold for realloc().
This results in an overflow of the 128-byte buffer when processing long lines and causes the program to crash during free(). Files with lines ~200 characters long: v311.sil (line 3640) and test/v311.sil (line 3417) - macro PATBRA SELBRA.
The same crash can be reproduced on Linux by using -DNEED_GETLINE.
The test now completes without errors and provides clear statistics - this facilitates porting to older non-Unix
systems and retro platforms that lack modern POSIX libraries.
Best regards,
Marcin