Package: minicom
Version: 2.11.1-2
X-Debbugs-CC: [email protected]

The previous email has incorrect line feeding, should be fixed by
now, sorry for any inconvenience.

When connecting to the serial console of Loongson XA612A0
(firmware version V1.0_V5.0.0532_stable202605_dbg) and entering UEFI
firmware setting, at the moment of entering, segmentation fault
happens, with the following backtrace.

#0  _write (c=9472 L'─', doit=<optimized out>, x=<optimized out>, y=<optimized out>, attr=<optimized out>, color=<optimized out>) at /var/cache/acbs/build/acbs.6le_6fsq/minicom/src/window.c:383
        e = 0xfff7f67ff8
        cwidth = <optimized out>
        x0 = -3
        y0 = 0
        attr0 = 2 '\002'
        color0 = 116 't'
        c0 = 9472
#1  0x000000aaaaab6bdc in mc_wputc (win=0xaaaab11610, c=<optimized out>) at /var/cache/acbs/build/acbs.6le_6fsq/minicom/src/window.c:1022
        cwidth = <optimized out>
        mv = <optimized out>
#2  0x000000aaaaacc834 in vt_out (ch=<optimized out>, wc=<optimized out>) at /var/cache/acbs/build/acbs.6le_6fsq/minicom/src/vt100.c:1096
        f = <optimized out>
        c = 226 '\342'
        go_on = <optimized out>
        last_ch = 226 '\342'
        tmstmp_last = {tv_sec = 0, tv_usec = 0}
#3  0x000000aaaaaabf50 in do_terminal () at /var/cache/acbs/build/acbs.6le_6fsq/minicom/src/main.c:992
        wc = 9472 L'─'
        len = 3
        c = <optimized out>
        obuf = "\001\000\000\000\000\000\000\000\262\034\002\020\000\000\000\000\000\003\034\177\025\001\005\000\000\021\023\032\000\022\017\027\026\004", '\000' <repeats 19 times>, "\302\001\000\000\302\001", '\000' <repeats 29 times>, "af`j", '\000' <repeats 12 times>, "cf`j", '\000' <repeats 12 times>, "L9Pj\000\000\000"
        ptr = 0xfffffe6949 "─", <incomplete sequence \342>
        buf = "\214──\342\000geCommo\000723B EF\00000000\r\n\000 Data H\000\000\000\000\000\000\000\000\330X\371\367\377", '\000' <repeats 11 times>, "\230X\371\367\377\000\000\000\250X\371\367\377", '\000' <repeats 27 times>, "\270X\371\367\377\000\000\000\310X\371\367\377\000\000\000\000\000\000\000\000\000\000"
        buf_offset = <optimized out>
        c = <optimized out>
        x = 1
        blen = 7
        zauto = 68
        zpos = 0
        s = <optimized out>
        error_on_open_window = <optimized out>
        dirty_goto = <optimized out>
        zsig = <optimized out>
#4  main (argc=<optimized out>, argv=<optimized out>) at /var/cache/acbs/build/acbs.6le_6fsq/minicom/src/minicom.c:1748
        c = <optimized out>
        quit = 0
        s = <optimized out>
        bufp = <optimized out>
        doinit = <optimized out>
        capname = "minicom.cap\000\000\000\000\000\230>\376\367\377\000\000\000xx\373\367\377\000\000\000\177", '\000' <repeats 16 times>, "@\371\367\377\000\000\000\250o\376\377\377", '\000' <repeats 19 times>, "0\300\376\367\377\000\000\000\220h\376\377\377\000\000\000@Q\373\367\377\000\000\000@\000\252\252\252\000\000\000\f\000\000\000\000\000\000\000`䪪\252\000\000"
        pwd = <optimized out>
        use_port = <optimized out>
        args = {0xaaaaad7a88 "minicom", 0xfffffe7345 "-D", 0xfffffe7348 "/dev/ttyS0", 0x0, 0xfffffe7040 "\003", 0x7e <error: Cannot access memory at address 0x7e>, 0xfff7fec030 <error: Cannot access memory at address 0xfff7fec030>, 0xfffffe68f0 "\030V\376\367\377",           0xfff7fb6584 <_dl_start_final+396> "\b", 0xfff7fe5618 <_dl_rtld_map> "", 0xfff7fe3e98 <_rtld_global_ro> "", 0xfff1 <error: Cannot access memory at address 0xfff1>, 0xfff7fec030 <error: Cannot access memory at address 0xfff7fec030>, 0xfffffe6920 "",           0xfff7fb6d08 <_dl_start+536> "%\350\300\003\b\a\277", <incomplete sequence \337>, 0xfff7f94000 "\177ELF\002\001\001", 0x0, 0xfff7f95888 "\016", 0x0, 0x0}
        args_buffer = <optimized out>
        argk = <optimized out>
        mc = <optimized out>
        env_args = <optimized out>
        cmd_dial = <optimized out>
        alt_code = <optimized out>
        cmdline_baudrate = <optimized out>
        cmdline_device = <optimized out>
        remote_charset = <optimized out>
        pseudo = '\000' <repeats 40 times>, "\230>\376\367\377\000\000\000\210>\376\367\377\000\000\000\210H\376\367\377\000\000"         ss = {__val = {8192, 0, 0, 1099377300752, 1099377302752, 0, 1099377251776, 0, 0, 1099377164288, 1099376986344, 1099377069184, 0, 0, 0, 1099377294960}}
        dirty_goto = <optimized out>
        __PRETTY_FUNCTION__ = "main"
        long_options = {{name = 0xaaaaad93a0 "setup", has_arg = 0, flag = 0x0, val = 115}, {name = 0xaaaaad93a8 "help", has_arg = 0, flag = 0x0, val = 104}, {name = 0xaaaaad93b0 "ptty", has_arg = 1, flag = 0x0, val = 112}, {name = 0xaaaaad93b8 "metakey", has_arg = 0,             flag = 0x0, val = 109}, {name = 0xaaaaad93c0 "metakey8", has_arg = 0, flag = 0x0, val = 77}, {name = 0xaaaaad93d0 "ansi", has_arg = 0, flag = 0x0, val = 108}, {name = 0xaaaaad93d8 "iso", has_arg = 0, flag = 0x0, val = 76}, {name = 0xaaaaad93e0 "term", has_arg = 1,             flag = 0x0, val = 116}, {name = 0xaaaaad93e8 "noinit", has_arg = 0, flag = 0x0, val = 111}, {name = 0xaaaaad93f0 "color", has_arg = 1, flag = 0x0, val = 99}, {name = 0xaaaaad93f8 "attrib", has_arg = 1, flag = 0x0, val = 97}, {name = 0xaaaaad9400 "dial", has_arg = 1,             flag = 0x0, val = 100}, {name = 0xaaaaad9408 "statline", has_arg = 0, flag = 0x0, val = 122}, {name = 0xaaaaad9418 "capturefile", has_arg = 1, flag = 0x0, val = 67}, {name = 0xaaaaad9428 "script", has_arg = 1, flag = 0x0, val = 83}, {name = 0xaaaaad9430 "7bit",             has_arg = 0, flag = 0x0, val = 55}, {name = 0xaaaaad9438 "8bit", has_arg = 0, flag = 0x0, val = 56}, {name = 0xaaaaad9440 "version", has_arg = 0, flag = 0x0, val = 118}, {name = 0xaaaaad9448 "wrap", has_arg = 0, flag = 0x0, val = 119}, {             name = 0xaaaaad8ef8 "displayhex", has_arg = 0, flag = 0x0, val = 72}, {name = 0xaaaaad9450 "disabletime", has_arg = 0, flag = 0x0, val = 84}, {name = 0xaaaaad8c20 "baudrate", has_arg = 1, flag = 0x0, val = 98}, {name = 0xaaaaad9460 "device", has_arg = 1, flag = 0x0,             val = 68}, {name = 0xaaaaad9468 "remotecharset", has_arg = 1, flag = 0x0, val = 82}, {name = 0xaaaaad9478 "option", has_arg = 1, flag = 0x0, val = 79}, {name = 0xaaaaad9480 "statlinefmt", has_arg = 1, flag = 0x0, val = 70}, {             name = 0xaaaaad9490 "capturefile-buffer-mode", has_arg = 1, flag = 0x0, val = 256}, {name = 0x0, has_arg = 0, flag = 0x0, val = 0}}
        OPT_CAP_BUF_MODE = OPT_CAP_BUF_MODE

The following patch was generated by MiMo Code, using model
mimo-v2.5-pro, and was tested myself by hand. It resolves the
segmentation fault, and no regression occurs so far.

I am using AOSC OS instead of Debian, which builds minicom based on
https://salsa.debian.org/minicom-team/minicom/-/releases/2.11.1

From 98535e4f65d8d1dd5fce238b029fbe71a3edb409 Mon Sep 17 00:00:00 2001
From: Kexy Biscuit <[email protected]>
Date: Wed, 22 Jul 2026 15:33:56 +0800
Subject: [PATCH 2/2] AOSCOS: vt100: fix segfault on multi-byte UTF-8 input

When do_terminal() receives multi-byte UTF-8 characters (e.g. U+2500
BOX DRAWINGS LIGHT HORIZONTAL), it decodes them to wchar_t via
one_mbtowc() and passes both the raw first byte (ch) and the decoded
wide character (wc) to vt_out().

However, vt_out() always processes the raw byte through vt_inmap[] and
vt_trans[] translation tables before checking whether wc is already set.
For multi-byte sequences, these byte-level translations corrupt the
first byte (e.g. 0xe2 becomes a different value), and the subsequent
wc value passed to mc_wputc() may no longer correspond to the intended
character.

Repeated occurrences corrupt the terminal cursor state (win->curx),
eventually driving it negative.  The _write() function's bounds check
(x < COLS && y < LINES) did not guard against negative coordinates,
so a negative x was used to index into gmap[], causing a segmentation
fault.

Fix by moving the byte-level translation (vt_inmap/vt_trans) inside
the wc == 0 branch so it is only applied when no pre-decoded wide
character is available.  Also add x >= 0 && y >= 0 guards to _write()
as a defensive measure.

This commit is authored with assistance from AI/LLM:

- Model: xiaomi/mimo-v2.5-pro
- Platform: Xiaomi MiMo
- Agent platform: MiMoCode
- Prompt:
  Investigate the reason of a segmentation fault on version 2.11.1
  with the provided backtrace.

Assisted-by: MiMo <[email protected]>
---
 src/vt100.c  | 13 +++++++------
 src/window.c |  4 ++--
 2 files changed, 9 insertions(+), 8 deletions(-)

diff --git a/src/vt100.c b/src/vt100.c
index 2f0f62e..3b1eba6 100644
--- a/src/vt100.c
+++ b/src/vt100.c
@@ -1083,13 +1083,14 @@ void vt_out(int ch, wchar_t wc)
     case 0: /* Normal character */
       if (vt_docap == 1)
         fputc(P_CONVCAP[0] == 'Y' ? vt_inmap[c] : c, capfp);
-      if (!using_iconv()) {
-        c = vt_inmap[c];    /* conversion 04.09.97 / jl */
-        if (vt_type == VT100 && vt_trans[vt_charset] && vt_asis == 0)
-          c = vt_trans[vt_charset][c];
-      }
-      if (wc == 0)
+      if (wc == 0) {
+        if (!using_iconv()) {
+          c = vt_inmap[c];    /* conversion 04.09.97 / jl */
+          if (vt_type == VT100 && vt_trans[vt_charset] && vt_asis == 0)
+            c = vt_trans[vt_charset][c];
+        }
         one_mbtowc (&wc, (char *)&c, 1); /* returns 1 */
+      }
       if (vt_insert)
         mc_winschar2(vt_win, wc, 1);
       else
diff --git a/src/window.c b/src/window.c
index a41b928..80d4c53 100644
--- a/src/window.c
+++ b/src/window.c
@@ -351,9 +351,9 @@ static int _write(wchar_t c, int doit, int x, int y, char attr, char color)
     oldc.color = color;
   }
 #ifdef ST_LINE
-  if (x < COLS && y <= LINES)
+  if (x >= 0 && y >= 0 && x < COLS && y <= LINES)
 #else
-  if (x < COLS && y < LINES)
+  if (x >= 0 && y >= 0 && x < COLS && y < LINES)
 #endif
   {
     if (doit != 0) {
--
2.55.0.windows.3

Reply via email to