PHP 4.0 Bug #6192: printf(): right aligned zero padded negative numbers wrongly zero terminated
| From: | dq at altern dot org | Date: | Wed, 16 Aug 2000 10:57:47 +0000 |
| Subject: | PHP 4.0 Bug #6192: printf(): right aligned zero padded negative numbers wrongly zero terminated | ||
| Groups: | php.dev | ||
| Request: | Send a blank email to php-dev+get-29111@lists.php.net to get a copy of this message | ||
From: dq@altern.org
Operating system: Windows NT
PHP version: 4.0.1pl2
PHP Bug Type: Misbehaving function
Bug description: printf(): right aligned zero padded negative numbers wrongly zero terminated
An unneeded zero "\0" is inserted after a right aligned zero padded negative number,
as can be seen with following examples:
printf("number='%5d'\n",-321);
// works as expected: number=' -321'
printf("number='%5f'\n",-321.0123456789);
// works as expected: number=' -321.012346'
printf("number='%05d'\n",-321);
// a \0 is inserted between 1 and closing quote :-(
printf("number='%05f'\n",-321.0123456789);
// a \0 is inserted between 6 and closing quote :-(
The bug is IMO in the function php_sprintf_appendstring() in the source
.../ext/standard/formatted_print.c
In the following code fragment of the PHP sources, only the "len" variable is decremented
when a negative number is encountered.
if (alignment == ALIGN_RIGHT) {
if (sign && padding=='0') { (*buffer)[(*pos)++] = '-'; add++; len--;
}
If "max_width" is also decremented next to "len", then this bug is squashed :-)
if (alignment == ALIGN_RIGHT) {
if (sign && padding=='0') { (*buffer)[(*pos)++] = '-'; add++; len--;
max_width--; }
Kind regards,
DQ