Two hardening fixes flagged by the earlier review:
1. FAIL passed __FILE__ and __func__ directly as the snprintf format string.
__FILE__ expands to a string literal that could contain a '%' (a build path
under a directory with a percent sign), and __func__ is not a literal at all;
either way snprintf would read nonexistent varargs. Pass them as "%s"
arguments instead.
2. akerr_name_for_status guarded the upper bound but not the lower one, so a
negative status indexed __AKERR_ERROR_NAMES[negative] -- an out-of-bounds
read, or an out-of-bounds write when a name was supplied. Reject status < 0.
Regression tests err_format_string (uses #line to put a conversion specifier in
__FILE__) and err_name_bounds fail against the old code (verified) and pass now.
Full suite: 23/23, no warnings.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>