On 2026-10-03 11:44, Christos Zoulas wrote:
I am wondering why size_t was changed to int?
Is it because of the < bufsize comparison?
Yes, a compiler (I forget which) complained about signed vs unsigned comparison
not because it was incorrect, but because it was confusing. I changed one side
to signed without noticing the problem that you noticed.
That works because the negative value on error return
gets promoted to unsigned.
Thanks, good catch. I installed the attached to fix that. I suppose I should be
more skeptical about compiler diagnostics, or more precisely, about my attempts
to silence false alarms....
From 5206e057b5a6c0dec0a7f7f4a2e5d37a60e4b4c1 Mon Sep 17 00:00:00 2001
From: Paul Eggert <[email protected]>
Date: Sat, 3 Oct 2026 14:18:02 -0700
Subject: [PROPOSED] asctime_r checks for negative snprintf again
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
Problem reported by Christos Zoulas.
* asctime.c (asctime_r): Restore negative snprintf return check
that was mistakenly removed in 2026e when we pacified a compiler.
Although in practice these snprintf calls never return -1
so in practice the missing check did not introduce a fault,
it’s better to do things right and on typical platforms
there is no runtime overhead in doing so.
---
asctime.c | 8 +++++---
1 file changed, 5 insertions(+), 3 deletions(-)
diff --git a/asctime.c b/asctime.c
index 696bb97a..86b8e256 100644
--- a/asctime.c
+++ b/asctime.c
@@ -76,6 +76,7 @@ asctime_r(struct tm const *restrict timeptr, char *restrict buf)
register const char * mn;
int year, mday, hour, min, sec;
long long_TM_YEAR_BASE = TM_YEAR_BASE;
+ int buflen;
int bufsize = (buf == buf_asctime
? sizeof buf_asctime : STD_ASCTIME_BUF_SIZE);
@@ -112,7 +113,8 @@ asctime_r(struct tm const *restrict timeptr, char *restrict buf)
Also, avoid overflow when formatting tm_year + TM_YEAR_BASE. */
- if ((year <= LONG_MAX - TM_YEAR_BASE
+ buflen
+ = (year <= LONG_MAX - TM_YEAR_BASE
? snprintf (buf, bufsize,
((-999 - TM_YEAR_BASE <= year
&& year <= 9999 - TM_YEAR_BASE)
@@ -124,8 +126,8 @@ asctime_r(struct tm const *restrict timeptr, char *restrict buf)
"%s %s%3d %.2d:%.2d:%.2d %d%d\n",
wn, mn, mday, hour, min, sec,
year / 10 + TM_YEAR_BASE / 10,
- year % 10))
- < bufsize)
+ year % 10));
+ if (0 <= buflen && buflen < bufsize)
return buf;
else {
errno = EOVERFLOW;
--
2.53.0