The SG_SET_RESERVED_SIZE loop could overflow in tweak_SG_buffer, and