Qprintf Rewrite - #97
Conversation
…branch). Fix a bug in qprintf() that caused % and & characters inside conditional printing areas to always print, regardless of the condition. Improve documentation for qpfPrintf_va_internal() and qpf_grow_fn_t(). Clean up.
Reorder some code to improve clarity. Add various comments. Fix spacing mistakes. Add void to function signatures that do not take parameters.
Clean up some overly cleaver code.
…d more comments. Overhaul qpf_internal_Translate() to improve readability. Improve readability of qpf_internal_SetupTable(). Improve code in multiple functions that ensures the module is initialized. Clean up and improve function doc comments.
Add line numbers to errors. Add qpfLogErrors(). Add qpf_internal_getErrorName(). Add qpf_internal_count_zeros(). Add QPF_ERR_T_NO_ERRORS. Add QPF_ERR_COUNT. Improve formating of QPF_ERR_T defines.
…bility using better code patterns.
Add docs for session functions. Add license. Clarify how to use source and filter format specifiers. Simplify wording for filter specifiers to improve readability.
|
@greptileai Please review this PR. |
Greptile SummaryThis PR refactors
Confidence Score: 5/5The refactor is behaviorally equivalent to the original and the previously-flagged bugs have been addressed; only minor documentation and portability observations remain. The core formatting engine logic has been carefully preserved across the refactor. All previously-identified overflow and guard bugs have been fixed and are covered by the two new regression tests. The remaining observations are documentation clarity and a non-standard macro extension the project already implicitly depends on elsewhere. No files require special attention beyond the inline documentation notes in qprintf.c.
|
| Filename | Overview |
|---|---|
| centrallix-lib/src/qprintf.c | Major refactor of the core formatting engine; previously-flagged bugs are fixed; QPERR macro uses GCC statement expressions; a duplicate @PARAM entry and an uncertain comment were left in the docstrings |
| centrallix-lib/include/qprintf.h | Public API extended with new grow helpers and qpfLogErrors; error constants moved from decimal to bit-shift style and QPSession gains ErrorLines array |
| centrallix-lib/tests/test_qprintf_69.c | New test: verifies %STR" with a 2-byte buffer writes opening quote + null terminator and returns full logical count (4) |
| centrallix-lib/tests/test_qprintf_70.c | New test: verifies the size-1 buffer underflow bug is fixed — %STR" with a 1-byte buffer writes only a null terminator and does not clobber adjacent memory |
| centrallix-sysdoc/QPrintf.md | Documentation updated with new API functions, improved specifier descriptions, and formatting improvements |
Reviews (12): Last reviewed commit: "Fix compiler error." | Re-trigger Greptile
Fix is_only_followed_by_nlen using || instead of &&. Fix closing quote space check didn't handle buffer overflows very well. Fix null_session error line numbers not being initialized. Fix qpfClearErrors() being lazy about clearing error line numbers. Fix qpf_internal_count_zeros(0) edge case.
|
@greptileai I think I resolved your comments. Please rereview. Are there any other concerns you have? |
|
@greptileai I think I resolved your comments. Please rereview. Are there any other concerns you have? |
|
The root cause is that Instead of making the write conditional (which breaks your tests), clamp The clamp is a no-op in the normal case — when |
|
@greptileai I've made the changes you've requested but I haven't tested or pushed my code yet. Could you write a test case, following the same style established in |
|
Here's the test following the exact style of Why this reproduces the bug: A 2-byte buffer for
#include <stdio.h>
#include <unistd.h>
#include <fcntl.h>
#include <string.h>
#include <stdlib.h>
#include "qprintf.h"
#include <assert.h>
long long
test(char** tname)
{
int i, rval;
int iter;
unsigned char buf[16];
*tname = "qprintf-53 %STR" with buffer too small for content (null termination)";
iter = 200000;
for(i=0;i<iter;i++)
{
buf[9] = '\n';
buf[8] = '\0';
buf[7] = 0xff;
buf[6] = 0xff; /* sentinel: byte immediately after 2-byte buffer -- must not be clobbered */
/* buf+4 is the 2-byte buffer under test: occupies buf[4] and buf[5] */
buf[3] = '\n';
buf[2] = '\0';
buf[1] = 0xff;
buf[0] = '\0';
rval = qpfPrintf(NULL, buf+4, 2, "%STR"", "ab");
/* The 2-byte buffer must be null-terminated within its own bounds.
* Without dest_offset clamped before the closing-quote write,
* buf[5] holds '\'' and no null terminator is ever written. */
assert(buf[5] == '\0');
/* The byte immediately after the buffer must not be overwritten.
* Without the no_grow guard, an out-of-bounds null-terminator write
* could clobber this sentinel. */
assert(buf[6] == 0xff);
/* Bytes before the buffer must be untouched */
assert(buf[3] == '\n');
assert(buf[2] == '\0');
assert(buf[1] == 0xff);
assert(buf[0] == '\0');
/* Return value must indicate overflow: full output 'ab' + NUL = 5 bytes */
assert(rval == 5);
}
return iter;
}Failure summary by variant:
One caveat: I inferred |
Fix a quote buffer overflow comment from Greptile. Add test_qprintf_69.c to validate that the "fixed" code now works properly. Note: Honestly, I'm so in the weeds that I only understand about 80% of what's going on here, but it works, and this probably isn't worth a ton of additional effort.
|
@greptileai I think I resolved your comments, and I also added your test case with some clean up, bug fixing (on the return value), and other improvements. Please rereview. Are there any other concerns you have? |
gbeeley
left a comment
There was a problem hiding this comment.
A few issues, some are points for discussion, and some for further investigation. Thanks!
| *** @param dstoffs The number of bytes to skip at the start of `dstbuf` | ||
| *** before writing the result. | ||
| *** @param dstsize The size of the currently allocated string at `dstbuf`. | ||
| *** @param limit The maximum amount that the destination string can grow past |
There was a problem hiding this comment.
limit is a hard limit on the maximum size of the insertion. This is independent of the ability to grow the destination: if nLEN / *LEN is used in the spec chain, that places a hard limit on the amount of data that can be inserted for the one specific conversion/translation. The destination may be able to be grown larger (or may otherwise have plenty of space already), but that's a separate issue.
Besides fixing this function doc, review the refactored code to ensure it is consistent with this use of limit.
There was a problem hiding this comment.
I was a little confused by this but now understand much better and I've refined the doc comments.
There was a problem hiding this comment.
I've just conducted a review and I believe my refactored code implements this feature correctly.
|
|
||
| /** Invalid spec: Skip to printing. **/ | ||
| format--; | ||
| break; |
There was a problem hiding this comment.
This appears to ignore filters that aren't found / aren't handled. This at least deserves a warning message (yes, this was from the original code, not from this PR). However, the commit history indicates this was a deliberate choice due to occurring in the format string. It seems that only happens in a few places and could easily be worked around via %&. Not sure if there are other implications.
There was a problem hiding this comment.
After looking into this, it looks like you were right.   directly after a specifier will trigger the warning but %  does not.
According to Claude, this contract change only affects two places in production (both in htdrv_tab.c). I've updated those on this branch so that the merge conflict on apos_autoscale9-slim5 will remind me to scan it for this issue, although I don't expect to find much.
There was a problem hiding this comment.
An unexpected side effect is that this warning caused the tests to fail by lockup because printing this warning hundreds of thousands of times slows down one of the tests a lot.
This doesn't seem like a real bug detected from the test (calling qprintf() with a format that triggers this warning hundreds of thousands of times per second doesn't seem like a usecase we need to support), so I changed the test to pipe stderr to /dev/null, fixing the lockup.
| startspec = QPF_SPEC_T_STARTFILT; | ||
| endspec = QPF_SPEC_T_ENDFILT; | ||
| } | ||
| while (format[0] == '&' && format++); /* Loop as long as there are '&' chars to consume. */ |
There was a problem hiding this comment.
Is there a reason for allowing consecutive & characters without filters?
There was a problem hiding this comment.
I don't think I do? An invalid specifier breaks out of the do {} while() loop (see above). Thus, additional &s after a specifier are not consumed. I think this is the same behavior as master.
For example, the format specifier x%STR&&y& (with "a<b" passed) results in: xa<b&&y&.
| while (format[0] == '&' && format++); /* Loop as long as there are '&' chars to consume. */ | ||
|
|
||
| /** Get the data using the source spec. **/ | ||
| char tmp_buf[318]; /* 318 characters are needed to print DBL_MAX. */ |
There was a problem hiding this comment.
This should be a #define somewhere.
There was a problem hiding this comment.
I couldn't find a pre-existing define for this so I defined it above. We should probably have a lint rule against magic numbers in code.
There was a problem hiding this comment.
I added a rule against magic numbers to the style guide.
| case QPF_SPEC_T_LL: | ||
| { | ||
| const long long ll_val = va_arg(ap, long long); | ||
| copy_len = (size_t)snprintf(tmp_buf, sizeof(tmp_buf), "%lld", ll_val); |
There was a problem hiding this comment.
Hopefully snprintf() doesn't fail here. Good to check. (similar in other nearby lines)
There was a problem hiding this comment.
Added error handling.
|
|
||
| case QPF_SPEC_T_QUOT: table = &QPF.quote_matrix; min_room = 2; quote = '\''; goto use_table; | ||
| case QPF_SPEC_T_DQUOT: table = &QPF.quote_matrix; min_room = 2; quote = '"'; goto use_table; | ||
| case QPF_SPEC_T_ESCQ: table = &QPF.quote_matrix; goto use_table; |
There was a problem hiding this comment.
Let's avoid goto in this usage (not an error/exit/retry situation, not a state machine).
There was a problem hiding this comment.
Oh, great. This refactor is about to wreck the git blame.
There was a problem hiding this comment.
I've refactored to use an if statement instead and I think the resulting code is better, thanks for the feedback.
| /** Handle filters. **/ | ||
| pQPConvTable table; | ||
| size_t min_room = 1; | ||
| char quote = 0; |
There was a problem hiding this comment.
Setting min_room and quote here works in the current implementation where we don't allow the chaining of translation/filter specs yet. But they probably should be moved into the spec loop so this doesn't become a latent bug if chaining of multiple filters is implemented in the future.
There was a problem hiding this comment.
On master, these values are defined in the function's top-level scope. I didn't understand them super well so I moved them to the lowest scope I felt I safely could. Thanks for the clarification, I've fixed this.
| /** Update string counters **/ | ||
| cpoffset += cplen; | ||
|
|
||
| /** Translate the string content using the table selected above. **/ |
There was a problem hiding this comment.
There used to be a check here that verified that n_chars returned from Translate matched the change in the dest_offset. The check appears to be aimed at preventing multiple successive failed grow function calls if a grow already failed, as in other areas of the code.
There was a problem hiding this comment.
Ahh, looks like this regression came out of an incorrect fix I made in the past that weakened this check. Fixed.
| goto error; | ||
| } | ||
| if (UNLIKELY(no_grow)) copy_len = 0; | ||
| if (UNLIKELY(no_grow || (space_needed > *dest_size && !grow_fn(dest, dest_size, dest_offset, grow_arg, space_needed)))) |
There was a problem hiding this comment.
This space needed / error logic appears to be different from the original and different from the other plain string copying code early in this function. Do a double check review for correctness on this. The switch from a computed-each-time space needed expression to a computed-once space needed expression could create some divergence in the logic from the original.
There was a problem hiding this comment.
I don't fully understand this logic, but I think I fixed it.
# Conflicts: # centrallix-lib/include/qprintf.h
… thousands of times.
|
We should possibly consider making the repeated grow logic a helper function. Despite my best effort to make it easy to read, it's one of the most confusing parts of the refactored code. |
|
@gbeeley I believe I've addressed all the concerns from your review. |
|
I've fixed several other bugs that I found on my own, now, too. I think that's everything, though. |
qprintf.chad some code that confused me a lot. For example, there was a switch statement inside an if statement inside another switch statement inside a loop inside another if statement inside the else block of different if statement inside another if statement inside another loop... causing my brain to throw a stack overflow exception.After understanding the code (which will be useful for the apos_autoscale proejct), I did some refactoring, and now it's much easier to read, in my opinion. Also, I added some tools for improved error handling, as usual.
GitHub Relationships
qprintf()prints%and&inside skipped conditionals #140.Other Changes
Not in this PR
I also wrote additional tests for qprintf, which passed, but they require several other PRs as dependencies, so I'll add them to the centrallix-lib-tests branch once I update it after the dups PR is merged.