[Scummvm-git-logs] scummvm master -> ab6127b839e1abc2b044af8b540dca51f1529ab1
bluegr
noreply at scummvm.org
Thu Sep 24 06:19:20 UTC 2026
This automated email contains information about 1 new commit which have been
pushed to the 'scummvm' repo located at https://api.github.com/repos/scummvm/scummvm .
Summary:
ab6127b839 COMMON: Don't hang when vsnprintf fails
Commit: ab6127b839e1abc2b044af8b540dca51f1529ab1
https://github.com/scummvm/scummvm/commit/ab6127b839e1abc2b044af8b540dca51f1529ab1
Author: Le Philousophe (lephilousophe at users.noreply.github.com)
Date: 2026-09-24T09:19:15+03:00
Commit Message:
COMMON: Don't hang when vsnprintf fails
If vsnprintf fails because the format string is invalid or there is a
problem with some argument, it returns -1.
This triggers an infinite loop as we are just trying to allocate more
memory while the function continue to fail because buffer size is not
the issue.
Instead, make special treatment for IRIX to handle non C99 conforming
functions.
Since MSVC 2015, vsnprintf is C99 conformant and the special treatment
can be removed.
Changed paths:
common/str.cpp
diff --git a/common/str.cpp b/common/str.cpp
index 67a1cefbc69..3d40115aa5d 100644
--- a/common/str.cpp
+++ b/common/str.cpp
@@ -188,15 +188,13 @@ String String::vformat(const char *fmt, va_list args) {
int len = vsnprintf(output._str, _builtinCapacity, fmt, va);
va_end(va);
- if (len == -1 || len == _builtinCapacity - 1) {
- // MSVC and IRIX don't return the size the full string would take up.
- // MSVC returns -1, IRIX returns the number of characters actually written,
- // which is at the most the size of the buffer minus one, as the string is
- // truncated to fit.
-
- // We assume MSVC failed to output the correct, null-terminated string
- // if the return value is either -1 or size.
- // For IRIX, because we lack a better mechanism, we assume failure
+#if defined(IRIX)
+ if (len == _builtinCapacity - 1) {
+ // IRIX doesn't return the size the full string would take up but
+ // the number of characters actually written, which is at the most
+ // the size of the buffer minus one, as the string is truncated to fit.
+
+ // For IRIX, because we lack a better mechanism, we assume a too small buffer
// if the return value equals size - 1.
// The downside to this is that whenever we try to format a string where the
// size is 1 below the built-in capacity, the size is needlessly increased.
@@ -212,8 +210,19 @@ String String::vformat(const char *fmt, va_list args) {
scumm_va_copy(va, args);
len = vsnprintf(output._str, size, fmt, va);
va_end(va);
- } while (len == -1 || len >= size - 1);
+ } while (len >= size - 1);
output._size = len;
+ return output;
+ }
+#endif
+ if (len < 0) {
+ // there is an error with the vsnprintf call,
+ // avoid an infinite recursive loop if vsnprintf
+ // is broken beyond repair: format ourselves
+ output = "<vsnprintf error for \"";
+ output += fmt;
+ output += "\">";
+ return output;
} else if (len < (int)_builtinCapacity) {
// vsnprintf succeeded
output._size = len;
More information about the Scummvm-git-logs
mailing list