mirror of
https://github.com/boostorg/safe_numerics.git
synced 2026-02-12 00:13:20 +00:00
109 lines
5.3 KiB
HTML
109 lines
5.3 KiB
HTML
<html>
|
|
<head>
|
|
<meta http-equiv="Content-Type" content="text/html; charset=US-ASCII">
|
|
<title>Implicit conversions change data values</title>
|
|
<link rel="stylesheet" href="../boostbook.css" type="text/css">
|
|
<meta name="generator" content="DocBook XSL Stylesheets V1.76.1">
|
|
<link rel="home" href="../index.html" title="Safe Numerics">
|
|
<link rel="up" href="../tutorial.html" title="Tutorial and Motivating Examples">
|
|
<link rel="prev" href="3.html" title="Undetected underflow">
|
|
<link rel="next" href="5.html" title="Array index value can exceed array limits">
|
|
</head>
|
|
<body bgcolor="white" text="black" link="#0000FF" vlink="#840084" alink="#0000FF">
|
|
<table cellpadding="2" width="100%"><tr>
|
|
<td valign="top"><img alt="pre-boost" width="30%" height="30%" src="../pre-boost.jpg"></td>
|
|
<td align="center"><a href="../../../index.html">Home</a></td>
|
|
<td align="center"><a href="http://www.boost.org/doc/libs">Libraries</a></td>
|
|
<td align="center"><a href="http://www.boost.org/users/people.html">People</a></td>
|
|
<td align="center"><a href="http://www.boost.org/users/faq.html">FAQ</a></td>
|
|
<td align="center"><a href="../../../more/index.htm">More</a></td>
|
|
</tr></table>
|
|
<hr>
|
|
<div class="spirit-nav">
|
|
<a accesskey="p" href="3.html"><img src="../images/prev.png" alt="Prev"></a><a accesskey="u" href="../tutorial.html"><img src="../images/up.png" alt="Up"></a><a accesskey="h" href="../index.html"><img src="../images/home.png" alt="Home"></a><a accesskey="n" href="5.html"><img src="../images/next.png" alt="Next"></a>
|
|
</div>
|
|
<div class="section">
|
|
<div class="titlepage"><div><div><h3 class="title">
|
|
<a name="safe_numerics.tutorial.4"></a>Implicit conversions change data values</h3></div></div></div>
|
|
<p>A simple assignment or arithmetic expression will generally convert
|
|
all the terms to the same type. Sometimes this can silently change values.
|
|
For example, when a signed data variable contains a negative type,
|
|
assigning to a unsigned type will be permitted by any C/C++ compiler but
|
|
will be treated as large unsigned value. Most modern compilers will emit a
|
|
compile time warning when this conversion is performed. The user may then
|
|
decide to change some data types or apply a <code class="computeroutput">static_cast</code>. This
|
|
is less than satisfactory for two reasons:</p>
|
|
<div class="itemizedlist"><ul class="itemizedlist" type="disc">
|
|
<li class="listitem"><p>It may be unwieldy to change all the types to signed or
|
|
unsigned.</p></li>
|
|
<li class="listitem"><p>Littering one's program with <code class="computeroutput">static_cast</code><code class="computeroutput">
|
|
</code>makes it more difficult to read.</p></li>
|
|
<li class="listitem"><p>We may believe that our signed type will never contain a
|
|
negative value. If we use a <code class="computeroutput">static_cast</code> to suppress the
|
|
warning, we'll fail to detect a program error when it is committed.
|
|
This is aways a risk with casts.</p></li>
|
|
</ul></div>
|
|
<p>This solution is simple, Just replace instances of the <code class="computeroutput">int
|
|
</code>with <code class="computeroutput">safe<int></code>.</p>
|
|
<pre class="programlisting">#include <cassert>
|
|
#include <stdexcept>
|
|
#include <iostream>
|
|
|
|
#include "../include/safe_integer.hpp"
|
|
#include "../include/safe_compare.hpp"
|
|
|
|
void detected_msg(bool detected){
|
|
std::cout << (detected ? "error detected!" : "error NOT detected! ") << std::endl;
|
|
}
|
|
|
|
int main(int argc, const char * argv[]){
|
|
std::cout << "example 4:";
|
|
std::cout << "undetected underflow in data type" << std::endl;
|
|
std::cout << "Not using safe numerics" << std::endl;
|
|
try{
|
|
unsigned int x = 0;
|
|
// the following silently produces an incorrect result
|
|
--x;
|
|
// because C/C++ implicitly converts mis-matched arguments to int
|
|
// suggests that the operation is correct
|
|
assert(x == -1);
|
|
// even though it's not !!!
|
|
|
|
// however, safe_compare does detect the error
|
|
assert(! boost::numeric::safe_compare::equal(x, -1));
|
|
std::cout << x << " != " << -1;
|
|
detected_msg(false);
|
|
}
|
|
catch(...){
|
|
assert(false); // never arrive here
|
|
}
|
|
// solution: replace unsigned int with safe<unsigned int>
|
|
std::cout << "Using safe numerics" << std::endl;
|
|
try{
|
|
using namespace boost::numeric;
|
|
safe<unsigned int> x = 0;
|
|
// decrement unsigned to less than zero throws exception
|
|
--x;
|
|
assert(false); // never arrive here
|
|
}
|
|
catch(std::range_error & e){
|
|
std::cout << e.what();
|
|
detected_msg(true);
|
|
}
|
|
return 0;
|
|
}
|
|
</pre>
|
|
</div>
|
|
<table xmlns:rev="http://www.cs.rpi.edu/~gregod/boost/tools/doc/revision" width="100%"><tr>
|
|
<td align="left"></td>
|
|
<td align="right"><div class="copyright-footer">Copyright © 2012 Robert Ramey<p><a href="http://www.boost.org/LICENSE_1_0.txt" target="_top">Subject to Boost
|
|
Software License</a></p>
|
|
</div></td>
|
|
</tr></table>
|
|
<hr>
|
|
<div class="spirit-nav">
|
|
<a accesskey="p" href="3.html"><img src="../images/prev.png" alt="Prev"></a><a accesskey="u" href="../tutorial.html"><img src="../images/up.png" alt="Up"></a><a accesskey="h" href="../index.html"><img src="../images/home.png" alt="Home"></a><a accesskey="n" href="5.html"><img src="../images/next.png" alt="Next"></a>
|
|
</div>
|
|
</body>
|
|
</html>
|