Package: minicom
Version: 2.11.1-2
X-Debbugs-CC: [email protected]
The previous email has incorrect line feeding, should be fixed by
now, sorry for any inconvenience.
When connecting to the serial console of Loongson XA612A0
(firmware version V1.0_V5.0.0532_stable202605_dbg) and entering UEFI
firmware setting, at the moment of entering, segmentation fault
happens, with the following backtrace.
#0 _write (c=9472 L'─', doit=<optimized out>, x=<optimized out>,
y=<optimized out>, attr=<optimized out>, color=<optimized out>) at
/var/cache/acbs/build/acbs.6le_6fsq/minicom/src/window.c:383
e = 0xfff7f67ff8
cwidth = <optimized out>
x0 = -3
y0 = 0
attr0 = 2 '\002'
color0 = 116 't'
c0 = 9472
#1 0x000000aaaaab6bdc in mc_wputc (win=0xaaaab11610, c=<optimized out>)
at /var/cache/acbs/build/acbs.6le_6fsq/minicom/src/window.c:1022
cwidth = <optimized out>
mv = <optimized out>
#2 0x000000aaaaacc834 in vt_out (ch=<optimized out>, wc=<optimized
out>) at /var/cache/acbs/build/acbs.6le_6fsq/minicom/src/vt100.c:1096
f = <optimized out>
c = 226 '\342'
go_on = <optimized out>
last_ch = 226 '\342'
tmstmp_last = {tv_sec = 0, tv_usec = 0}
#3 0x000000aaaaaabf50 in do_terminal () at
/var/cache/acbs/build/acbs.6le_6fsq/minicom/src/main.c:992
wc = 9472 L'─'
len = 3
c = <optimized out>
obuf =
"\001\000\000\000\000\000\000\000\262\034\002\020\000\000\000\000\000\003\034\177\025\001\005\000\000\021\023\032\000\022\017\027\026\004",
'\000' <repeats 19 times>, "\302\001\000\000\302\001", '\000' <repeats
29 times>, "af`j", '\000' <repeats 12 times>, "cf`j", '\000' <repeats 12
times>, "L9Pj\000\000\000"
ptr = 0xfffffe6949 "─", <incomplete sequence \342>
buf = "\214──\342\000geCommo\000723B EF\00000000\r\n\000 Data
H\000\000\000\000\000\000\000\000\330X\371\367\377", '\000' <repeats 11
times>, "\230X\371\367\377\000\000\000\250X\371\367\377", '\000'
<repeats 27 times>,
"\270X\371\367\377\000\000\000\310X\371\367\377\000\000\000\000\000\000\000\000\000\000"
buf_offset = <optimized out>
c = <optimized out>
x = 1
blen = 7
zauto = 68
zpos = 0
s = <optimized out>
error_on_open_window = <optimized out>
dirty_goto = <optimized out>
zsig = <optimized out>
#4 main (argc=<optimized out>, argv=<optimized out>) at
/var/cache/acbs/build/acbs.6le_6fsq/minicom/src/minicom.c:1748
c = <optimized out>
quit = 0
s = <optimized out>
bufp = <optimized out>
doinit = <optimized out>
capname =
"minicom.cap\000\000\000\000\000\230>\376\367\377\000\000\000xx\373\367\377\000\000\000\177",
'\000' <repeats 16 times>, "@\371\367\377\000\000\000\250o\376\377\377",
'\000' <repeats 19 times>,
"0\300\376\367\377\000\000\000\220h\376\377\377\000\000\000@Q\373\367\377\000\000\000@\000\252\252\252\000\000\000\f\000\000\000\000\000\000\000`䪪\252\000\000"
pwd = <optimized out>
use_port = <optimized out>
args = {0xaaaaad7a88 "minicom", 0xfffffe7345 "-D", 0xfffffe7348
"/dev/ttyS0", 0x0, 0xfffffe7040 "\003", 0x7e <error: Cannot access
memory at address 0x7e>, 0xfff7fec030 <error: Cannot access memory at
address 0xfff7fec030>, 0xfffffe68f0 "\030V\376\367\377",
0xfff7fb6584 <_dl_start_final+396> "\b", 0xfff7fe5618
<_dl_rtld_map> "", 0xfff7fe3e98 <_rtld_global_ro> "", 0xfff1 <error:
Cannot access memory at address 0xfff1>, 0xfff7fec030 <error: Cannot
access memory at address 0xfff7fec030>, 0xfffffe6920 "",
0xfff7fb6d08 <_dl_start+536> "%\350\300\003\b\a\277",
<incomplete sequence \337>, 0xfff7f94000 "\177ELF\002\001\001", 0x0,
0xfff7f95888 "\016", 0x0, 0x0}
args_buffer = <optimized out>
argk = <optimized out>
mc = <optimized out>
env_args = <optimized out>
cmd_dial = <optimized out>
alt_code = <optimized out>
cmdline_baudrate = <optimized out>
cmdline_device = <optimized out>
remote_charset = <optimized out>
pseudo = '\000' <repeats 40 times>,
"\230>\376\367\377\000\000\000\210>\376\367\377\000\000\000\210H\376\367\377\000\000"
ss = {__val = {8192, 0, 0, 1099377300752, 1099377302752, 0,
1099377251776, 0, 0, 1099377164288, 1099376986344, 1099377069184, 0, 0,
0, 1099377294960}}
dirty_goto = <optimized out>
__PRETTY_FUNCTION__ = "main"
long_options = {{name = 0xaaaaad93a0 "setup", has_arg = 0, flag
= 0x0, val = 115}, {name = 0xaaaaad93a8 "help", has_arg = 0, flag = 0x0,
val = 104}, {name = 0xaaaaad93b0 "ptty", has_arg = 1, flag = 0x0, val =
112}, {name = 0xaaaaad93b8 "metakey", has_arg = 0,
flag = 0x0, val = 109}, {name = 0xaaaaad93c0 "metakey8",
has_arg = 0, flag = 0x0, val = 77}, {name = 0xaaaaad93d0 "ansi", has_arg
= 0, flag = 0x0, val = 108}, {name = 0xaaaaad93d8 "iso", has_arg = 0,
flag = 0x0, val = 76}, {name = 0xaaaaad93e0 "term", has_arg = 1,
flag = 0x0, val = 116}, {name = 0xaaaaad93e8 "noinit",
has_arg = 0, flag = 0x0, val = 111}, {name = 0xaaaaad93f0 "color",
has_arg = 1, flag = 0x0, val = 99}, {name = 0xaaaaad93f8 "attrib",
has_arg = 1, flag = 0x0, val = 97}, {name = 0xaaaaad9400 "dial", has_arg
= 1,
flag = 0x0, val = 100}, {name = 0xaaaaad9408 "statline",
has_arg = 0, flag = 0x0, val = 122}, {name = 0xaaaaad9418 "capturefile",
has_arg = 1, flag = 0x0, val = 67}, {name = 0xaaaaad9428 "script",
has_arg = 1, flag = 0x0, val = 83}, {name = 0xaaaaad9430 "7bit",
has_arg = 0, flag = 0x0, val = 55}, {name = 0xaaaaad9438
"8bit", has_arg = 0, flag = 0x0, val = 56}, {name = 0xaaaaad9440
"version", has_arg = 0, flag = 0x0, val = 118}, {name = 0xaaaaad9448
"wrap", has_arg = 0, flag = 0x0, val = 119}, {
name = 0xaaaaad8ef8 "displayhex", has_arg = 0, flag = 0x0,
val = 72}, {name = 0xaaaaad9450 "disabletime", has_arg = 0, flag = 0x0,
val = 84}, {name = 0xaaaaad8c20 "baudrate", has_arg = 1, flag = 0x0, val
= 98}, {name = 0xaaaaad9460 "device", has_arg = 1, flag = 0x0,
val = 68}, {name = 0xaaaaad9468 "remotecharset", has_arg =
1, flag = 0x0, val = 82}, {name = 0xaaaaad9478 "option", has_arg = 1,
flag = 0x0, val = 79}, {name = 0xaaaaad9480 "statlinefmt", has_arg = 1,
flag = 0x0, val = 70}, {
name = 0xaaaaad9490 "capturefile-buffer-mode", has_arg = 1,
flag = 0x0, val = 256}, {name = 0x0, has_arg = 0, flag = 0x0, val = 0}}
OPT_CAP_BUF_MODE = OPT_CAP_BUF_MODE
The following patch was generated by MiMo Code, using model
mimo-v2.5-pro, and was tested myself by hand. It resolves the
segmentation fault, and no regression occurs so far.
I am using AOSC OS instead of Debian, which builds minicom based on
https://salsa.debian.org/minicom-team/minicom/-/releases/2.11.1
From 98535e4f65d8d1dd5fce238b029fbe71a3edb409 Mon Sep 17 00:00:00 2001
From: Kexy Biscuit <[email protected]>
Date: Wed, 22 Jul 2026 15:33:56 +0800
Subject: [PATCH 2/2] AOSCOS: vt100: fix segfault on multi-byte UTF-8 input
When do_terminal() receives multi-byte UTF-8 characters (e.g. U+2500
BOX DRAWINGS LIGHT HORIZONTAL), it decodes them to wchar_t via
one_mbtowc() and passes both the raw first byte (ch) and the decoded
wide character (wc) to vt_out().
However, vt_out() always processes the raw byte through vt_inmap[] and
vt_trans[] translation tables before checking whether wc is already set.
For multi-byte sequences, these byte-level translations corrupt the
first byte (e.g. 0xe2 becomes a different value), and the subsequent
wc value passed to mc_wputc() may no longer correspond to the intended
character.
Repeated occurrences corrupt the terminal cursor state (win->curx),
eventually driving it negative. The _write() function's bounds check
(x < COLS && y < LINES) did not guard against negative coordinates,
so a negative x was used to index into gmap[], causing a segmentation
fault.
Fix by moving the byte-level translation (vt_inmap/vt_trans) inside
the wc == 0 branch so it is only applied when no pre-decoded wide
character is available. Also add x >= 0 && y >= 0 guards to _write()
as a defensive measure.
This commit is authored with assistance from AI/LLM:
- Model: xiaomi/mimo-v2.5-pro
- Platform: Xiaomi MiMo
- Agent platform: MiMoCode
- Prompt:
Investigate the reason of a segmentation fault on version 2.11.1
with the provided backtrace.
Assisted-by: MiMo <[email protected]>
---
src/vt100.c | 13 +++++++------
src/window.c | 4 ++--
2 files changed, 9 insertions(+), 8 deletions(-)
diff --git a/src/vt100.c b/src/vt100.c
index 2f0f62e..3b1eba6 100644
--- a/src/vt100.c
+++ b/src/vt100.c
@@ -1083,13 +1083,14 @@ void vt_out(int ch, wchar_t wc)
case 0: /* Normal character */
if (vt_docap == 1)
fputc(P_CONVCAP[0] == 'Y' ? vt_inmap[c] : c, capfp);
- if (!using_iconv()) {
- c = vt_inmap[c]; /* conversion 04.09.97 / jl */
- if (vt_type == VT100 && vt_trans[vt_charset] && vt_asis == 0)
- c = vt_trans[vt_charset][c];
- }
- if (wc == 0)
+ if (wc == 0) {
+ if (!using_iconv()) {
+ c = vt_inmap[c]; /* conversion 04.09.97 / jl */
+ if (vt_type == VT100 && vt_trans[vt_charset] && vt_asis == 0)
+ c = vt_trans[vt_charset][c];
+ }
one_mbtowc (&wc, (char *)&c, 1); /* returns 1 */
+ }
if (vt_insert)
mc_winschar2(vt_win, wc, 1);
else
diff --git a/src/window.c b/src/window.c
index a41b928..80d4c53 100644
--- a/src/window.c
+++ b/src/window.c
@@ -351,9 +351,9 @@ static int _write(wchar_t c, int doit, int x, int y,
char attr, char color)
oldc.color = color;
}
#ifdef ST_LINE
- if (x < COLS && y <= LINES)
+ if (x >= 0 && y >= 0 && x < COLS && y <= LINES)
#else
- if (x < COLS && y < LINES)
+ if (x >= 0 && y >= 0 && x < COLS && y < LINES)
#endif
{
if (doit != 0) {
--
2.55.0.windows.3