https://gitlab.synchro.net/main/sbbs/-/commit/cf6d568170a047dbb6647208
Modified Files:
docs/v322_new.md src/sbbs3/atcodes.cpp exec.cpp execmisc.cpp inkey.cpp sbbs.h xtrn.cpp
Log Message:
cmdstr(): bound the output by the caller's buffer size
Fixes #1191
cmdstr() limited its output to the size of its own member buffer even when writing into a caller-supplied one whose size it was never told, so a
caller with a smaller buffer could be overflowed. @TYPE: and @INCLUDE: did exactly that, expanding into atcode()'s output buffer with a bound of 511.
Add an overload that takes the output buffer's size (with the mode as a required argument, so a call passing a NULL buffer and a mode can never
resolve to it by accident) and route the unsized form through it with the member buffer's size. Every caller that passes its own buffer now passes
its size too: atcode() hands over the maxlen it already had, and the Baja interpreter, the hot-key handler and execmisc pass sizeof their arrays.
An expansion that does not fit is now logged as truncated instead of
silently cut.
Verified on a scratch terminal server: a short @INCLUDE: still displays the file through the sized path, and a 400-character one is handled within
the caller's buffer.
Co-Authored-By: Claude Fable 5.1 <
noreply@anthropic.com>
---
þ Synchronet þ Vertrauen þ Home of Synchronet þ [vert/cvs/bbs].synchro.net