https://gitlab.synchro.net/main/sbbs/-/commit/bb5ff19c182d2d04df90e016
Modified Files:
src/encode/utf8.c utf8.h
Log Message:
utf8: count the NUL-terminator in the conversion buffer size
cp437_to_utf8_str() and its three siblings documented 'maxlen' as the
converted length "sans NUL-terminator", then wrote that terminator at dest[maxlen] - so every caller had to pass one less than the size of its buffer. Five of the thirteen in-tree call sites passed sizeof(buf)
instead, overrunning it by a byte whenever the UTF-8 expansion landed
exactly on the buffer size, which for a 128-byte buffer takes only 64
high-bit source characters.
The reachable one is encode_header_field() in mailsrvr.cpp, which
converts outbound message header text into a 256-byte stack buffer; postmsg.cpp, sbbsecho.c, msgtoqwk.cpp and getmsg.cpp have the same shape.
Rename the parameter to 'size' and treat it as the full extent of the destination, terminator included, the way snprintf() and strlcpy() do.
That makes the five unsafe call sites correct as written and leaves those already passing sizeof(buf) - 1 a harmless byte short of capacity. A size
of zero now writes nothing rather than a stray terminator.
Co-Authored-By: Claude Opus 5 (1M context) <
noreply@anthropic.com>
---
■ Synchronet ■ Vertrauen ■ Home of Synchronet ■ [vert/cvs/bbs].synchro.net