(Due to @afonsojanu in #231:)
If we call:
printf_("%*d", INT_MIN, 5);
we're passing a width due to the use of *. Now, when the argument is negative, format_string_loop() negates it so it can fall through the usual positive-width-plus-left-justify path:
else if (*format == '*') {
const int w = va_arg(args, int);
if (w < 0) {
flags |= FLAGS_LEFT;
width = (printf_size_t)-w;
}
...
and with w being INT_MIN, -w overflows - which is undefined behavior in C89, I'm pretty sure. The C99 standard quote is (emphasis mine):
§6.5 Expressions
- If an exceptional condition occurs during the evaluation of an expression (that is, if the result is not mathematically defined or not in the range of representable values for its type), the behavior is undefined.
(Due to @afonsojanu in #231:)
If we call:
we're passing a width due to the use of
*. Now, when the argument is negative,format_string_loop()negates it so it can fall through the usual positive-width-plus-left-justify path:and with
wbeingINT_MIN,-woverflows - which is undefined behavior in C89, I'm pretty sure. The C99 standard quote is (emphasis mine):