fmt_with_err: add a comment that truncation is OK

Functions like die_errno() use fmt_with_err() to combine the caller-provided format with the strerror() string. We use a fixed stack buffer because we're already handling an error and don't have any way to report another one. Our buffer should generally be big enough to fit this, but if it's not, truncation is our best option. Let's add a comment to that effect, so that anybody auditing the code for truncation bugs knows that this is fine. Signed-off-by: Jeff King <peff@peff.net> Signed-off-by: Junio C Hamano <gitster@pobox.com>

Jeff King committed May 18, 2018 at 18:58 UTC ac4896f007a624c12feda866aeb4abe8a1394e39
1 file changed +1
usage.c
+1
@@ -148,6 +148,7 @@ static const char *fmt_with_err(char *buf, int n, const char *fmt)
148 }
149 }
150 str_error[j] = 0;
151 + /* Truncation is acceptable here */
152 snprintf(buf, n, "%s: %s", fmt, str_error);
153 return buf;
154 }