Package: minicom
Version: 2.11.1-2
X-Debbugs-CC: [email protected]
When connecting to the serial console of Loongson XA612A0
(firmware version V1.0_V5.0.0532_stable202605_dbg) and entering UEFI
firmware setting, at the moment of entering, segmentation fault
happens, with the following backtrace.
#0  _write (c=9472 L'─', doit=<optimizedout>, x=<optimizedout>, y=<optimizedout>, attr=<optimizedout>, color=<optimizedout>) at /var/cache/acbs/build/acbs.6le_6fsq/minicom/src/window.c:383
        e = 0xfff7f67ff8
        cwidth = <optimizedout>
        x0 = -3
        y0 = 0
        attr0 = 2 '\002'
        color0 = 116 't'
        c0 = 9472
#1  0x000000aaaaab6bdc in mc_wputc (win=0xaaaab11610, c=<optimizedout>) at /var/cache/acbs/build/acbs.6le_6fsq/minicom/src/window.c:1022
        cwidth = <optimizedout>
        mv = <optimizedout>
#2  0x000000aaaaacc834 in vt_out (ch=<optimizedout>, wc=<optimizedout>) at /var/cache/acbs/build/acbs.6le_6fsq/minicom/src/vt100.c:1096
        f = <optimizedout>
        c = 226 '\342'
        go_on = <optimizedout>
        last_ch = 226 '\342'
        tmstmp_last = {tv_sec = 0, tv_usec = 0}
#3  0x000000aaaaaabf50 in do_terminal () at /var/cache/acbs/build/acbs.6le_6fsq/minicom/src/main.c:992
        wc = 9472 L'─'
        len = 3
        c = <optimizedout>
        obuf = "\001\000\000\000\000\000\000\000\262\034\002\020\000\000\000\000\000\003\034\177\025\001\005\000\000\021\023\032\000\022\017\027\026\004", '\000' <repeats19times>, "\302\001\000\000\302\001", '\000' <repeats29times>, "af`j", '\000' <repeats 12 times>, "cf`j", '\000' <repeats12times>, "L9Pj\000\000\000"
        ptr = 0xfffffe6949 "─", <incompletesequence\342>
        buf = "\214──\342\000geCommo\000723B EF\00000000\r\n\000 Data H\000\000\000\000\000\000\000\000\330X\371\367\377", '\000' <repeats11times>, "\230X\371\367\377\000\000\000\250X\371\367\377", '\000' <repeats27times>, "\270X\371\367\377\000\000\000\310X\371\367\377\000\000\000\000\000\000\000\000\000\000"
        buf_offset = <optimizedout>
        c = <optimizedout>
        x = 1
        blen = 7
        zauto = 68
        zpos = 0
        s = <optimizedout>
        error_on_open_window = <optimizedout>
        dirty_goto = <optimizedout>
        zsig = <optimizedout>
#4  main (argc=<optimizedout>, argv=<optimizedout>) at /var/cache/acbs/build/acbs.6le_6fsq/minicom/src/minicom.c:1748
        c = <optimizedout>
        quit = 0
        s = <optimizedout>
        bufp = <optimizedout>
        doinit = <optimizedout>
        capname = "minicom.cap\000\000\000\000\000\230>\376\367\377\000\000\000xx\373\367\377\000\000\000\177", '\000' <repeats16times>, "@\371\367\377\000\000\000\250o\376\377\377", '\000' <repeats19times>, "0\300\376\367\377\000\000\000\220h\376\377\377\000\000\000@Q\373\367\377\000\000\000@\000\252\252\252\000\000\000\f\000\000\000\000\000\000\000`䪪\252\000\000"
        pwd = <optimizedout>
        use_port = <optimizedout>
        args = {0xaaaaad7a88 "minicom", 0xfffffe7345 "-D", 0xfffffe7348 "/dev/ttyS0", 0x0, 0xfffffe7040 "\003", 0x7e <error:Cannotaccessmemoryataddress0x7e>, 0xfff7fec030 <error:Cannotaccessmemoryataddress0xfff7fec030>, 0xfffffe68f0 "\030V\376\367\377",           0xfff7fb6584 <_dl_start_final+396> "\b", 0xfff7fe5618 <_dl_rtld_map> "", 0xfff7fe3e98 <_rtld_global_ro> "", 0xfff1 <error:Cannotaccessmemoryataddress0xfff1>, 0xfff7fec030 <error:Cannotaccessmemoryataddress0xfff7fec030>, 0xfffffe6920 "",           0xfff7fb6d08 <_dl_start+536> "%\350\300\003\b\a\277", <incompletesequence\337>, 0xfff7f94000 "\177ELF\002\001\001", 0x0, 0xfff7f95888 "\016", 0x0, 0x0}
        args_buffer = <optimizedout>
        argk = <optimizedout>
        mc = <optimizedout>
        env_args = <optimizedout>
        cmd_dial = <optimizedout>
        alt_code = <optimizedout>
        cmdline_baudrate = <optimizedout>
        cmdline_device = <optimizedout>
        remote_charset = <optimizedout>
        pseudo = '\000' <repeats40times>, "\230>\376\367\377\000\000\000\210>\376\367\377\000\000\000\210H\376\367\377\000\000"         ss = {__val = {8192, 0, 0, 1099377300752, 1099377302752, 0, 1099377251776, 0, 0, 1099377164288, 1099376986344, 1099377069184, 0, 0, 0, 1099377294960}}
        dirty_goto = <optimizedout>
__PRETTY_FUNCTION__= "main"
        long_options = {{name = 0xaaaaad93a0 "setup", has_arg = 0, flag = 0x0, val = 115}, {name = 0xaaaaad93a8 "help", has_arg = 0, flag = 0x0, val = 104}, {name = 0xaaaaad93b0 "ptty", has_arg = 1, flag = 0x0, val = 112}, {name = 0xaaaaad93b8 "metakey", has_arg = 0,             flag = 0x0, val = 109}, {name = 0xaaaaad93c0 "metakey8", has_arg = 0, flag = 0x0, val = 77}, {name = 0xaaaaad93d0 "ansi", has_arg = 0, flag = 0x0, val = 108}, {name = 0xaaaaad93d8 "iso", has_arg = 0, flag = 0x0, val = 76}, {name = 0xaaaaad93e0 "term", has_arg = 1,             flag = 0x0, val = 116}, {name = 0xaaaaad93e8 "noinit", has_arg = 0, flag = 0x0, val = 111}, {name = 0xaaaaad93f0 "color", has_arg = 1, flag = 0x0, val = 99}, {name = 0xaaaaad93f8 "attrib", has_arg = 1, flag = 0x0, val = 97}, {name = 0xaaaaad9400 "dial", has_arg = 1,             flag = 0x0, val = 100}, {name = 0xaaaaad9408 "statline", has_arg = 0, flag = 0x0, val = 122}, {name = 0xaaaaad9418 "capturefile", has_arg = 1, flag = 0x0, val = 67}, {name = 0xaaaaad9428 "script", has_arg = 1, flag = 0x0, val = 83}, {name = 0xaaaaad9430 "7bit",             has_arg = 0, flag = 0x0, val = 55}, {name = 0xaaaaad9438 "8bit", has_arg = 0, flag = 0x0, val = 56}, {name = 0xaaaaad9440 "version", has_arg = 0, flag = 0x0, val = 118}, {name = 0xaaaaad9448 "wrap", has_arg = 0, flag = 0x0, val = 119}, {             name = 0xaaaaad8ef8 "displayhex", has_arg = 0, flag = 0x0, val = 72}, {name = 0xaaaaad9450 "disabletime", has_arg = 0, flag = 0x0, val = 84}, {name = 0xaaaaad8c20 "baudrate", has_arg = 1, flag = 0x0, val = 98}, {name = 0xaaaaad9460 "device", has_arg = 1, flag = 0x0,             val = 68}, {name = 0xaaaaad9468 "remotecharset", has_arg = 1, flag = 0x0, val = 82}, {name = 0xaaaaad9478 "option", has_arg = 1, flag = 0x0, val = 79}, {name = 0xaaaaad9480 "statlinefmt", has_arg = 1, flag = 0x0, val = 70}, {             name = 0xaaaaad9490 "capturefile-buffer-mode", has_arg = 1, flag = 0x0, val = 256}, {name = 0x0, has_arg = 0, flag = 0x0, val = 0}}
        OPT_CAP_BUF_MODE = OPT_CAP_BUF_MODE
The following patch was generated by MiMo Code, using model
mimo-v2.5-pro, and was tested myself by hand. It resolves the
segmentation fault, and no regression occurs so far.
I am using AOSC OS instead of Debian, which builds minicom based on
https://salsa.debian.org/minicom-team/minicom/-/releases/2.11.1
From 98535e4f65d8d1dd5fce238b029fbe71a3edb409 Mon Sep 17 00:00:00 2001
From: Kexy Biscuit <[email protected]>
Date: Wed, 22 Jul 2026 15:33:56 +0800
Subject: [PATCH 2/2] vt100: fix segfault on multi-byte UTF-8 input
When do_terminal() receives multi-byte UTF-8 characters (e.g. U+2500
BOX DRAWINGS LIGHT HORIZONTAL), it decodes them to wchar_t via
one_mbtowc() and passes both the raw first byte (ch) and the decoded
wide character (wc) to vt_out().
However, vt_out() always processes the raw byte through vt_inmap[] and
vt_trans[] translation tables before checking whether wc is already set.
For multi-byte sequences, these byte-level translations corrupt the
first byte (e.g. 0xe2 becomes a different value), and the subsequent
wc value passed to mc_wputc() may no longer correspond to the intended
character.
Repeated occurrences corrupt the terminal cursor state (win->curx),
eventually driving it negative.  The _write() function's bounds check
(x < COLS && y < LINES) did not guard against negative coordinates,
so a negative x was used to index into gmap[], causing a segmentation
fault.
Fix by moving the byte-level translation (vt_inmap/vt_trans) inside
the wc == 0 branch so it is only applied when no pre-decoded wide
character is available.  Also add x >= 0 && y >= 0 guards to _write()
as a defensive measure.
This commit is authored with assistance from AI/LLM:
-Model: xiaomi/mimo-v2.5-pro
-Platform: Xiaomi MiMo
-Agent platform: MiMoCode
-Prompt:
  Investigate the reason of a segmentation fault on version 2.11.1
  with the provided backtrace.
Assisted-by: MiMo <[email protected]>
---
 src/vt100.c  | 13 +++++++------
 src/window.c |  4 ++--
 2 files changed, 9 insertions(+), 8 deletions(-)
diff --git a/src/vt100.c b/src/vt100.c
index 2f0f62e..3b1eba6 100644
--- a/src/vt100.c
+++ b/src/vt100.c
@@ -1083,13 +1083,14 @@ void vt_out(int ch, wchar_t wc)
     case 0: /* Normal character */
       if (vt_docap == 1)
         fputc(P_CONVCAP[0] == 'Y' ? vt_inmap[c] : c, capfp);
-     if (!using_iconv()) {
-       c = vt_inmap[c];    /* conversion 04.09.97 / jl */
-       if (vt_type == VT100 && vt_trans[vt_charset] && vt_asis == 0)
-         c = vt_trans[vt_charset][c];
-     }
-     if (wc == 0)
+     if (wc == 0) {
+       if (!using_iconv()) {
+         c = vt_inmap[c];    /* conversion 04.09.97 / jl */
+         if (vt_type == VT100 && vt_trans[vt_charset] && vt_asis == 0)
+           c = vt_trans[vt_charset][c];
+       }
         one_mbtowc (&wc, (char *)&c, 1); /* returns 1 */
+     }
       if (vt_insert)
         mc_winschar2(vt_win, wc, 1);
       else
diff --git a/src/window.c b/src/window.c
index a41b928..80d4c53 100644
--- a/src/window.c
+++ b/src/window.c
@@ -351,9 +351,9 @@ static int _write(wchar_t c, int doit, int x, int y, char attr, char color)
     oldc.color = color;
   }
 #ifdef ST_LINE
- if (x < COLS && y <= LINES)
+ if (x >= 0 && y >= 0 && x < COLS && y <= LINES)
 #else
- if (x < COLS && y < LINES)
+ if (x >= 0 && y >= 0 && x < COLS && y < LINES)
 #endif
   {
     if (doit != 0) {
--
2.55.0.windows.3

Reply via email to