-
-
Notifications
You must be signed in to change notification settings - Fork 266
Fix ignored snprintf return value in StatusArg.cpp #8967
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: master
Are you sure you want to change the base?
Changes from all commits
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -407,19 +407,25 @@ Num::Num(ISC_STATUS s) noexcept : | |
| Int64::Int64(SINT64 val) noexcept : | ||
| Str(text) | ||
| { | ||
| snprintf(text, sizeof(text), "%" SQUADFORMAT, val); | ||
| [[maybe_unused]] auto result = snprintf(text, sizeof(text), "%" SQUADFORMAT, val); | ||
| fb_assert(result >= 0 && result < sizeof(text)); | ||
| } | ||
|
|
||
| Int64::Int64(FB_UINT64 val) noexcept : | ||
| Str(text) | ||
| { | ||
| snprintf(text, sizeof(text), "%" UQUADFORMAT, val); | ||
| [[maybe_unused]] auto result = snprintf(text, sizeof(text), "%" UQUADFORMAT, val); | ||
| fb_assert(result >= 0 && result < sizeof(text)); | ||
| } | ||
|
|
||
| Quad::Quad(const ISC_QUAD* quad) noexcept : | ||
| Str(text) | ||
| { | ||
| snprintf(text, sizeof(text), "%x:%x", quad->gds_quad_high, quad->gds_quad_low); | ||
| [[maybe_unused]] auto result = snprintf(text, sizeof(text), "%x:%x", | ||
| static_cast<unsigned int>(quad->gds_quad_high), | ||
|
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Format is hexadecimal. What's wrong with signed integer?
Author
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. See page 332 of https://open-std.org/JTC1/SC22/WG14/www/docs/n3220.pdf
Looks like it does not care about sign. Not sure what changes when you pass signed integer instead, probably nothing? Anyway, static_cast makes it more explicit
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more.
Exactly as written in your quote: for There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Static analyzer was triggered just because of different types. I agree, in this case there are not any problems just because of differing types, but there is a reason to consider this cast as a good practice:
page 289 for
... |
||
| quad->gds_quad_low | ||
| ); | ||
| fb_assert(result >= 0 && result < sizeof(text)); | ||
| } | ||
|
|
||
| Interpreted::Interpreted(const char* text) noexcept : | ||
|
|
||
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Adding asserts is good idea - but they should be complete. Look here:
From man:
The functions snprintf() and vsnprintf() do not write more than size bytes (including the terminating null byte ('\0')). If the output was truncated due to this limit, then the return value is the number of characters (excluding the terminating null byte) which would have been written to the final string if enough space had been available. Thus, a return value of size or more means that the output was truncated.
I.e. sizeof(text) should also be taken into an account.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Done. Please, see changes