Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > comp.lang.c > #402443

Re: Dodging undefined behaviour in printf

From David Brown <david.brown@hesbynett.no>
Newsgroups comp.lang.c
Subject Re: Dodging undefined behaviour in printf
Date 2026-09-28 09:50 +0200
Organization A noiseless patient Spider
Message-ID <119d683$23bo0$1@dont-email.me> (permalink)
References <119bf9d$1fk39$1@dont-email.me>

Show all headers | View raw


On 27/09/2026 18:12, highcrew wrote:
> Dear c.l.c.
> 
> I'm trying to refine my knowledge on the topic of type promotions, and 
> now I know how promotion is implied when passing arguments to a function 
> whose prototype is missing argument definition, or to functions having 
> variadic argument list.
> 
> So I was wondering about the following:
> 
>      unsigned short x = value;
>      printf("%x", x);
> 
> Assuming that sizeof(unsigned short) < sizeof(int), I would guess that x 
> is promoted to signed int, which is however the wrong type, as it should 
> be unsigned int.
> 
> Well, it is is also true that the `int` value is not going to be 
> negative for sure.
> 
> Would this be a problem? Am I supposed to explicitly cast x to (unsigned 
> int) when passing it to printf?
> 
> I find it interesting that the problem is not a problem on architectures 
> where sizeof(unsigned short) == sizeof(unsigned int) -- if I will ever 
> find such a thing.

(There are plenty of such architectures - basically, all 8-bit and 
16-bit microcontrollers.  Those are less popular now than they used to 
be, as 32-bit ARM dominates for new devices, but there are no shortages 
of designs with 16-bit int.  For amateurs, the most common such platform 
is the Arduino.)

> 
> How about %hx then?
> 

Many people, myself included, like to use the "-Wformat" warning in gcc 
(and clang) - it is part of the "-Wall" warning settings, or can be 
enabled or disabled explicitly.  In printf calls where the format string 
is visible to the compiler, typically as a string literal, the compiler 
will check that the format specifiers and the actual arguments match up 
correctly in type.  The checks are fairly fussy, and will give you a 
warning if types don't match up - even if they would work in practice. 
For example, the warning triggers for mismatches between "int" and "long 
int" even on platforms where they are the same size and in practice 
would generally work fine.  But it takes into account the default 
argument promotions (described by other posters).

Checks and warnings from the compiler are not a substitute for knowing 
the rules, but they are a very handy extra check.




Back to comp.lang.c | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread


Thread

Dodging undefined behaviour in printf highcrew <high.crew3868@fastmail.com> - 2026-09-27 18:12 +0200
  Re: Dodging undefined behaviour in printf Johann 'Myrkraverk' Oskarsson <johann@myrkraverk.invalid> - 2026-09-28 01:47 +0800
  Re: Dodging undefined behaviour in printf Tim Rentsch <tr.17687@z991.linuxsc.com> - 2026-09-27 10:48 -0700
  Re: Dodging undefined behaviour in printf James Kuyper <jameskuyper@alumni.caltech.edu> - 2026-09-27 20:30 -0400
  Re: Dodging undefined behaviour in printf David Brown <david.brown@hesbynett.no> - 2026-09-28 09:50 +0200
  Re: Dodging undefined behaviour in printf "Chris M. Thomasson" <chris.m.thomasson.1@gmail.com> - 2026-09-30 13:05 -0700

csiph-web