[Cfp-interest] printf, NaN, infinity

Fred J. Tydeman tydeman at tybor.com
Mon Nov 26 13:07:07 PST 2018


On Mon, 26 Nov 2018 10:33:04 -0800 Jim Thomas wrote:
>
>Couldn't the security problem be addressed by limiting the length of any n-char-sequence that might appear in printf output of nan(n-char-sequence), perhaps to the value of an implementation-defined macro? The macro value could be zero if the implementation never printed n-char-sequences.
>

While that would work, would it not also introduce release-to-release 
incompatible changes?

My understanding is some implementations output English text describing
what the payload means.

---
Fred J. Tydeman        Tydeman Consulting
tydeman at tybor.com      Testing, numerics, programming
+1 (702) 608-6093      Vice-chair of PL22.11 (ANSI "C")
Sample C99+FPCE tests: http://www.tybor.com
Savers sleep well, investors eat well, spenders work forever.



More information about the Cfp-interest mailing list