don't report vsnprintf(3) error as bug

strbuf_addf() has been reporting a negative return value of vsnprintf(3) as a bug since f141bd804d (Handle broken vsnprintf implementations in strbuf, 2007-11-13). Other functions copied that behavior: 7b03c89ebd (add xsnprintf helper function, 2015-09-24) 5ef264dbdb (strbuf.c: add `strbuf_insertf()` and `strbuf_vinsertf()`, 2019-02-25) 8d25663d70 (mem-pool: add mem_pool_strfmt(), 2024-02-25) However, vsnprintf(3) can legitimately return a negative value if the formatted output would be longer than INT_MAX. Stop accusing it of being broken and just report the fact that formatting failed. Suggested-by: Jeff King <peff@peff.net> Signed-off-by: René Scharfe <l.s.r@web.de> Signed-off-by: Junio C Hamano <gitster@pobox.com>

René Scharfe committed Apr 21, 2024 at 14:40 UTC 0283cd5161561b29951c00697679c10b454e541a
3 files changed +5 -4
mem-pool.c
+2 -1
@@ -4,6 +4,7 @@
4
5 #include "git-compat-util.h"
6 #include "mem-pool.h"
7 +#include "gettext.h"
8
9 #define BLOCK_GROWTH_SIZE (1024 * 1024 - sizeof(struct mp_block))
10
@@ -122,7 +123,7 @@ static char *mem_pool_strvfmt(struct mem_pool *pool, const char *fmt,
123 len = vsnprintf(next_free, available, fmt, cp);
124 va_end(cp);
125 if (len < 0)
125 - BUG("your vsnprintf is broken (returned %d)", len);
126 + die(_("unable to format message: %s"), fmt);
127
128 size = st_add(len, 1); /* 1 for NUL */
129 ret = mem_pool_alloc(pool, size);
strbuf.c
+2 -2
@@ -277,7 +277,7 @@ void strbuf_vinsertf(struct strbuf *sb, size_t pos, const char *fmt, va_list ap)
277 len = vsnprintf(sb->buf + sb->len, 0, fmt, cp);
278 va_end(cp);
279 if (len < 0)
280 - BUG("your vsnprintf is broken (returned %d)", len);
280 + die(_("unable to format message: %s"), fmt);
281 if (!len)
282 return; /* nothing to do */
283 if (unsigned_add_overflows(sb->len, len))
@@ -404,7 +404,7 @@ void strbuf_vaddf(struct strbuf *sb, const char *fmt, va_list ap)
404 len = vsnprintf(sb->buf + sb->len, sb->alloc - sb->len, fmt, cp);
405 va_end(cp);
406 if (len < 0)
407 - BUG("your vsnprintf is broken (returned %d)", len);
407 + die(_("unable to format message: %s"), fmt);
408 if (len > strbuf_avail(sb)) {
409 strbuf_grow(sb, len);
410 len = vsnprintf(sb->buf + sb->len, sb->alloc - sb->len, fmt, ap);
wrapper.c
+1 -1
@@ -670,7 +670,7 @@ int xsnprintf(char *dst, size_t max, const char *fmt, ...)
670 va_end(ap);
671
672 if (len < 0)
673 - BUG("your snprintf is broken");
673 + die(_("unable to format message: %s"), fmt);
674 if (len >= max)
675 BUG("attempt to snprintf into too-small buffer");
676 return len;