Skip to content

Buffer overflow in the replacement getline() and bufio_getline() #4

Description

@mresdev

Hi Phil,
I was compiling/running CSNOBOL4 for Amiga (AmigaOS 3.x using ixemul.library, a POSIX compatibility layer) and encountered an issue while running the performance test (bench.sno v311.sil): a buffer overflow in the replacement getline() and bufio_getline() function for lines longer than 128 characters.

Since neither the Amiga C libraries nor ixemul include a getline() function, the build process utilized
your implementation found in lib/auxil/getline.c and bufio_obj.c.

The variable "avail" is not decremented within the loop, so it never reaches the threshold for realloc().
This results in an overflow of the 128-byte buffer when processing long lines and causes the program to crash during free(). Files with lines ~200 characters long: v311.sil (line 3640) and test/v311.sil (line 3417) - macro PATBRA SELBRA.
The same crash can be reproduced on Linux by using -DNEED_GETLINE.

--- a/lib/auxil/getline.c
+++ b/lib/auxil/getline.c
@@ -53,6 +53,7 @@ getline(char **bufp, size_t *lenp, FILE *fp) {
        if (c == EOF)
            break;
        *cp++ = c;
        count++;
+       avail--;
        } while (c != '\n');

--- a/lib/auxil/bufio_obj.c
+++ b/lib/auxil/bufio_obj.c
@@ -124,6 +124,7 @@ bufio_getline(struct bufio *bp, char **bufp, size_t *lenp) {
        if (c == EOF)
            break;
        *cp++ = c;
        count++;
+       avail--;
        } while (c != '\n');

The test now completes without errors and provides clear statistics - this facilitates porting to older non-Unix
systems and retro platforms that lack modern POSIX libraries.

Best regards,
Marcin

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions