Ragel shares part of the blame. Why did it use a strict equality check when it could have trivially done a >=?
/* generated code */
if ( ++p == pe )
goto _test_eof;
or /* generated code */
if ( ++p >= pe )
goto _test_eof;
they should have had /* generated code */
if ( ++p == pe )
goto _test_eof;
assert(p < pe);
since having servers core dumping would have drawn attention to the bug in a way that counting one byte too many and then hitting _test_eof would not.Consecutive pointer increments without a bounds check in between sounds like a bug to me. But I don't really know Ragel, and perhaps the compiler doesn't have enough information to determine this is what's happening.