Commit ee0f3c5315d for php
commit ee0f3c5315dfa659bd0a6f0812259feaa7329561
Author: Ilia Alshanetsky <ilia@ilia.ws>
Date: Fri Aug 21 12:48:01 2026 -0400
Fix alternate form flag for %x testing stale signed value
The alternate-form branch for %x/%X gated the "0x" prefix on i_num,
which is only ever assigned by the signed/unsigned decimal
conversions. A standalone "%#x" with a nonzero value therefore
printed no prefix (i_num still held its zero initializer), while "%d
%#x" consumed the earlier conversion's value and could print a prefix
for zero.
Test the unsigned conversion result ui_num instead, matching the "0"
check the octal case already performs on the converted digits.
Closes GH-23410
diff --git a/ext/fileinfo/tests/cdf_unknown_property_id.phpt b/ext/fileinfo/tests/cdf_unknown_property_id.phpt
new file mode 100644
index 00000000000..f93a5c7b0b1
--- /dev/null
+++ b/ext/fileinfo/tests/cdf_unknown_property_id.phpt
@@ -0,0 +1,13 @@
+--TEST--
+Unknown CDF property IDs are printed with the 0x prefix
+--EXTENSIONS--
+fileinfo
+--FILE--
+<?php
+$data = file_get_contents(__DIR__ . '/resources/test.ppt');
+$data[40576] = "\x1f";
+$desc = (new finfo())->buffer($data);
+echo substr($desc, strrpos($desc, ', ') + 2), "\n";
+?>
+--EXPECT--
+0x1f: 0
diff --git a/main/snprintf.c b/main/snprintf.c
index 78aa6cc3a8d..11b58e74e16 100644
--- a/main/snprintf.c
+++ b/main/snprintf.c
@@ -830,7 +830,7 @@ static size_t format_converter(buffy * odp, const char *fmt, va_list ap) /* {{{
}
s = ap_php_conv_p2(ui_num, 4, *fmt, &num_buf[NUM_BUF_SIZE], &s_len);
FIX_PRECISION(adjust_precision, precision, s, s_len);
- if (alternate_form && i_num != 0) {
+ if (alternate_form && ui_num != 0) {
*--s = *fmt; /* 'x' or 'X' */
*--s = '0';
s_len += 2;