snprintf heads-up
| From: | Stanislav Malyshev | Date: | Fri, 08 Sep 2000 12:50:01 +0000 |
| Subject: | snprintf heads-up | ||
| Groups: | php.dev | ||
| Request: | Send a blank email to php-dev+get-32653@lists.php.net to get a copy of this message | ||
In a number of places in PHP code, the following construct is used:
char buffer[LEN];
...
buf_len = snprintf(buffer, sizeof(buffer)-1, ....);
<code basing on buf_len, like memcpy(s,buffer,buf_len)>
Now, the newest Linux manual I have states about snprintf:
RETURN VALUE
If the output was truncated, the return value is -1, oth-
erwise it is the number of characters stored, not includ-
ing the terminating null. (Thus until glibc 2.0.6. Since
glibc 2.1 these functions return the number of characters
(excluding the trailing null) which would have been writ-
ten to the final string if enough space had been avail-
able.)
That means, output of snprintf *can not* be trusted. You should check it
for being inside the array. I don't know yet how the other systems'
snprintfs behave, but at least Linux one cannot be trusted to return
usable value.
--
Stanislav Malyshev stas@zend.com http://www.zend.com/
+972-3-6139665 ext.106