On 2026-10-03 11:44, Christos Zoulas wrote:
I am wondering why size_t was changed to int?
Is it because of the < bufsize comparison?

Yes, a compiler (I forget which) complained about signed vs unsigned comparison 
not because it was incorrect, but because it was confusing. I changed one side 
to signed without noticing the problem that you noticed.

That works because the negative value on error return
gets promoted to unsigned.

Thanks, good catch. I installed the attached to fix that. I suppose I should be 
more skeptical about compiler diagnostics, or more precisely, about my attempts 
to silence false alarms....
From 5206e057b5a6c0dec0a7f7f4a2e5d37a60e4b4c1 Mon Sep 17 00:00:00 2001
From: Paul Eggert <[email protected]>
Date: Sat, 3 Oct 2026 14:18:02 -0700
Subject: [PROPOSED] asctime_r checks for negative snprintf again
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit

Problem reported by Christos Zoulas.
* asctime.c (asctime_r): Restore negative snprintf return check
that was mistakenly removed in 2026e when we pacified a compiler.
Although in practice these snprintf calls never return -1
so in practice the missing check did not introduce a fault,
it’s better to do things right and on typical platforms
there is no runtime overhead in doing so.
---
 asctime.c | 8 +++++---
 1 file changed, 5 insertions(+), 3 deletions(-)

diff --git a/asctime.c b/asctime.c
index 696bb97a..86b8e256 100644
--- a/asctime.c
+++ b/asctime.c
@@ -76,6 +76,7 @@ asctime_r(struct tm const *restrict timeptr, char *restrict buf)
 	register const char *	mn;
 	int year, mday, hour, min, sec;
 	long long_TM_YEAR_BASE = TM_YEAR_BASE;
+	int buflen;
 	int bufsize = (buf == buf_asctime
 		       ? sizeof buf_asctime : STD_ASCTIME_BUF_SIZE);
 
@@ -112,7 +113,8 @@ asctime_r(struct tm const *restrict timeptr, char *restrict buf)
 
 	   Also, avoid overflow when formatting tm_year + TM_YEAR_BASE.  */
 
-	if ((year <= LONG_MAX - TM_YEAR_BASE
+	buflen
+	  = (year <= LONG_MAX - TM_YEAR_BASE
 	     ? snprintf (buf, bufsize,
 			 ((-999 - TM_YEAR_BASE <= year
 			   && year <= 9999 - TM_YEAR_BASE)
@@ -124,8 +126,8 @@ asctime_r(struct tm const *restrict timeptr, char *restrict buf)
 			 "%s %s%3d %.2d:%.2d:%.2d     %d%d\n",
 			 wn, mn, mday, hour, min, sec,
 			 year / 10 + TM_YEAR_BASE / 10,
-			 year % 10))
-	    < bufsize)
+			 year % 10));
+	if (0 <= buflen && buflen < bufsize)
 		return buf;
 	else {
 		errno = EOVERFLOW;
-- 
2.53.0

Reply via email to