|
(v)sprint() is supposed to return the number of bytes written to s,
excluding the terminating null byte. however, when these functions
return INT_MAX, only INT_MAX - 1 bytes (excluding the terminating null
byte) are written.
this is caused by the way vsprintf() is implemented: calling
vsnprintf() with n = INT_MAX. vsnprintf() returns the number of bytes
that would be written to s had n been sufficiently large excluding the
terminating null byte. output bytes beyond the n-1st are discarded.
to accommodate the largest strings (v)sprintf() can produce (length
INT_MAX, the return value is of type int), vsnprintf() has to be
called with n >= INT_MAX + 1.
calling vsnprintf() with n > INT_MAX is possible since commit
11fb383275d20f5f94c00425bd888a02ecbd218e.
|