safe_numerics_unittest.cc 24 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579
  1. // Copyright 2013 The Chromium Authors. All rights reserved.
  2. // Use of this source code is governed by a BSD-style license that can be
  3. // found in the LICENSE file.
  4. #if defined(COMPILER_MSVC) && defined(ARCH_CPU_32_BITS)
  5. #include <mmintrin.h>
  6. #endif
  7. #include <stdint.h>
  8. #include <limits>
  9. #include "butil/compiler_specific.h"
  10. #include "butil/numerics/safe_conversions.h"
  11. #include "butil/numerics/safe_math.h"
  12. #include "butil/type_traits.h"
  13. #include <gtest/gtest.h>
  14. using std::numeric_limits;
  15. using butil::CheckedNumeric;
  16. using butil::checked_cast;
  17. using butil::saturated_cast;
  18. using butil::internal::MaxExponent;
  19. using butil::internal::RANGE_VALID;
  20. using butil::internal::RANGE_INVALID;
  21. using butil::internal::RANGE_OVERFLOW;
  22. using butil::internal::RANGE_UNDERFLOW;
  23. using butil::enable_if;
  24. // MSVS 2013 ia32 may not reset the FPU between calculations, and the test
  25. // framework masks the exceptions. So we just force a manual reset after NaN.
  26. inline void ResetFloatingPointUnit() {
  27. #if defined(COMPILER_MSVC) && defined(ARCH_CPU_32_BITS)
  28. _mm_empty();
  29. #endif
  30. }
  31. // Helper macros to wrap displaying the conversion types and line numbers.
  32. #define TEST_EXPECTED_VALIDITY(expected, actual) \
  33. EXPECT_EQ(expected, CheckedNumeric<Dst>(actual).validity()) \
  34. << "Result test: Value " << +(actual).ValueUnsafe() << " as " << dst \
  35. << " on line " << line;
  36. #define TEST_EXPECTED_VALUE(expected, actual) \
  37. EXPECT_EQ(static_cast<Dst>(expected), \
  38. CheckedNumeric<Dst>(actual).ValueUnsafe()) \
  39. << "Result test: Value " << +((actual).ValueUnsafe()) << " as " << dst \
  40. << " on line " << line;
  41. // Signed integer arithmetic.
  42. template <typename Dst>
  43. static void TestSpecializedArithmetic(
  44. const char* dst,
  45. int line,
  46. typename enable_if<
  47. numeric_limits<Dst>::is_integer&& numeric_limits<Dst>::is_signed,
  48. int>::type = 0) {
  49. typedef numeric_limits<Dst> DstLimits;
  50. TEST_EXPECTED_VALIDITY(RANGE_OVERFLOW,
  51. -CheckedNumeric<Dst>(DstLimits::min()));
  52. TEST_EXPECTED_VALIDITY(RANGE_OVERFLOW,
  53. CheckedNumeric<Dst>(DstLimits::min()).Abs());
  54. TEST_EXPECTED_VALUE(1, CheckedNumeric<Dst>(-1).Abs());
  55. TEST_EXPECTED_VALIDITY(RANGE_VALID,
  56. CheckedNumeric<Dst>(DstLimits::max()) + -1);
  57. TEST_EXPECTED_VALIDITY(RANGE_UNDERFLOW,
  58. CheckedNumeric<Dst>(DstLimits::min()) + -1);
  59. TEST_EXPECTED_VALIDITY(
  60. RANGE_UNDERFLOW,
  61. CheckedNumeric<Dst>(-DstLimits::max()) + -DstLimits::max());
  62. TEST_EXPECTED_VALIDITY(RANGE_UNDERFLOW,
  63. CheckedNumeric<Dst>(DstLimits::min()) - 1);
  64. TEST_EXPECTED_VALIDITY(RANGE_VALID,
  65. CheckedNumeric<Dst>(DstLimits::min()) - -1);
  66. TEST_EXPECTED_VALIDITY(
  67. RANGE_OVERFLOW,
  68. CheckedNumeric<Dst>(DstLimits::max()) - -DstLimits::max());
  69. TEST_EXPECTED_VALIDITY(
  70. RANGE_UNDERFLOW,
  71. CheckedNumeric<Dst>(-DstLimits::max()) - DstLimits::max());
  72. TEST_EXPECTED_VALIDITY(RANGE_UNDERFLOW,
  73. CheckedNumeric<Dst>(DstLimits::min()) * 2);
  74. TEST_EXPECTED_VALIDITY(RANGE_OVERFLOW,
  75. CheckedNumeric<Dst>(DstLimits::min()) / -1);
  76. TEST_EXPECTED_VALUE(0, CheckedNumeric<Dst>(-1) / 2);
  77. // Modulus is legal only for integers.
  78. TEST_EXPECTED_VALUE(0, CheckedNumeric<Dst>() % 1);
  79. TEST_EXPECTED_VALUE(0, CheckedNumeric<Dst>(1) % 1);
  80. TEST_EXPECTED_VALUE(-1, CheckedNumeric<Dst>(-1) % 2);
  81. TEST_EXPECTED_VALIDITY(RANGE_INVALID, CheckedNumeric<Dst>(-1) % -2);
  82. TEST_EXPECTED_VALUE(0, CheckedNumeric<Dst>(DstLimits::min()) % 2);
  83. TEST_EXPECTED_VALUE(1, CheckedNumeric<Dst>(DstLimits::max()) % 2);
  84. // Test all the different modulus combinations.
  85. TEST_EXPECTED_VALUE(0, CheckedNumeric<Dst>(1) % CheckedNumeric<Dst>(1));
  86. TEST_EXPECTED_VALUE(0, 1 % CheckedNumeric<Dst>(1));
  87. TEST_EXPECTED_VALUE(0, CheckedNumeric<Dst>(1) % 1);
  88. CheckedNumeric<Dst> checked_dst = 1;
  89. TEST_EXPECTED_VALUE(0, checked_dst %= 1);
  90. }
  91. // Unsigned integer arithmetic.
  92. template <typename Dst>
  93. static void TestSpecializedArithmetic(
  94. const char* dst,
  95. int line,
  96. typename enable_if<
  97. numeric_limits<Dst>::is_integer && !numeric_limits<Dst>::is_signed,
  98. int>::type = 0) {
  99. typedef numeric_limits<Dst> DstLimits;
  100. TEST_EXPECTED_VALIDITY(RANGE_VALID, -CheckedNumeric<Dst>(DstLimits::min()));
  101. TEST_EXPECTED_VALIDITY(RANGE_VALID,
  102. CheckedNumeric<Dst>(DstLimits::min()).Abs());
  103. TEST_EXPECTED_VALIDITY(RANGE_UNDERFLOW,
  104. CheckedNumeric<Dst>(DstLimits::min()) + -1);
  105. TEST_EXPECTED_VALIDITY(RANGE_UNDERFLOW,
  106. CheckedNumeric<Dst>(DstLimits::min()) - 1);
  107. TEST_EXPECTED_VALUE(0, CheckedNumeric<Dst>(DstLimits::min()) * 2);
  108. TEST_EXPECTED_VALUE(0, CheckedNumeric<Dst>(1) / 2);
  109. // Modulus is legal only for integers.
  110. TEST_EXPECTED_VALUE(0, CheckedNumeric<Dst>() % 1);
  111. TEST_EXPECTED_VALUE(0, CheckedNumeric<Dst>(1) % 1);
  112. TEST_EXPECTED_VALUE(1, CheckedNumeric<Dst>(1) % 2);
  113. TEST_EXPECTED_VALUE(0, CheckedNumeric<Dst>(DstLimits::min()) % 2);
  114. TEST_EXPECTED_VALUE(1, CheckedNumeric<Dst>(DstLimits::max()) % 2);
  115. // Test all the different modulus combinations.
  116. TEST_EXPECTED_VALUE(0, CheckedNumeric<Dst>(1) % CheckedNumeric<Dst>(1));
  117. TEST_EXPECTED_VALUE(0, 1 % CheckedNumeric<Dst>(1));
  118. TEST_EXPECTED_VALUE(0, CheckedNumeric<Dst>(1) % 1);
  119. CheckedNumeric<Dst> checked_dst = 1;
  120. TEST_EXPECTED_VALUE(0, checked_dst %= 1);
  121. }
  122. // Floating point arithmetic.
  123. template <typename Dst>
  124. void TestSpecializedArithmetic(
  125. const char* dst,
  126. int line,
  127. typename enable_if<numeric_limits<Dst>::is_iec559, int>::type = 0) {
  128. typedef numeric_limits<Dst> DstLimits;
  129. TEST_EXPECTED_VALIDITY(RANGE_VALID, -CheckedNumeric<Dst>(DstLimits::min()));
  130. TEST_EXPECTED_VALIDITY(RANGE_VALID,
  131. CheckedNumeric<Dst>(DstLimits::min()).Abs());
  132. TEST_EXPECTED_VALUE(1, CheckedNumeric<Dst>(-1).Abs());
  133. TEST_EXPECTED_VALIDITY(RANGE_VALID,
  134. CheckedNumeric<Dst>(DstLimits::min()) + -1);
  135. TEST_EXPECTED_VALIDITY(RANGE_VALID,
  136. CheckedNumeric<Dst>(DstLimits::max()) + 1);
  137. TEST_EXPECTED_VALIDITY(
  138. RANGE_UNDERFLOW,
  139. CheckedNumeric<Dst>(-DstLimits::max()) + -DstLimits::max());
  140. TEST_EXPECTED_VALIDITY(
  141. RANGE_OVERFLOW,
  142. CheckedNumeric<Dst>(DstLimits::max()) - -DstLimits::max());
  143. TEST_EXPECTED_VALIDITY(
  144. RANGE_UNDERFLOW,
  145. CheckedNumeric<Dst>(-DstLimits::max()) - DstLimits::max());
  146. TEST_EXPECTED_VALIDITY(RANGE_VALID,
  147. CheckedNumeric<Dst>(DstLimits::min()) * 2);
  148. TEST_EXPECTED_VALUE(-0.5, CheckedNumeric<Dst>(-1.0) / 2);
  149. EXPECT_EQ(static_cast<Dst>(1.0), CheckedNumeric<Dst>(1.0).ValueFloating());
  150. }
  151. // Generic arithmetic tests.
  152. template <typename Dst>
  153. static void TestArithmetic(const char* dst, int line) {
  154. typedef numeric_limits<Dst> DstLimits;
  155. EXPECT_EQ(true, CheckedNumeric<Dst>().IsValid());
  156. EXPECT_EQ(false,
  157. CheckedNumeric<Dst>(CheckedNumeric<Dst>(DstLimits::max()) *
  158. DstLimits::max()).IsValid());
  159. EXPECT_EQ(static_cast<Dst>(0), CheckedNumeric<Dst>().ValueOrDie());
  160. EXPECT_EQ(static_cast<Dst>(0), CheckedNumeric<Dst>().ValueOrDefault(1));
  161. EXPECT_EQ(static_cast<Dst>(1),
  162. CheckedNumeric<Dst>(CheckedNumeric<Dst>(DstLimits::max()) *
  163. DstLimits::max()).ValueOrDefault(1));
  164. // Test the operator combinations.
  165. TEST_EXPECTED_VALUE(2, CheckedNumeric<Dst>(1) + CheckedNumeric<Dst>(1));
  166. TEST_EXPECTED_VALUE(0, CheckedNumeric<Dst>(1) - CheckedNumeric<Dst>(1));
  167. TEST_EXPECTED_VALUE(1, CheckedNumeric<Dst>(1) * CheckedNumeric<Dst>(1));
  168. TEST_EXPECTED_VALUE(1, CheckedNumeric<Dst>(1) / CheckedNumeric<Dst>(1));
  169. TEST_EXPECTED_VALUE(2, 1 + CheckedNumeric<Dst>(1));
  170. TEST_EXPECTED_VALUE(0, 1 - CheckedNumeric<Dst>(1));
  171. TEST_EXPECTED_VALUE(1, 1 * CheckedNumeric<Dst>(1));
  172. TEST_EXPECTED_VALUE(1, 1 / CheckedNumeric<Dst>(1));
  173. TEST_EXPECTED_VALUE(2, CheckedNumeric<Dst>(1) + 1);
  174. TEST_EXPECTED_VALUE(0, CheckedNumeric<Dst>(1) - 1);
  175. TEST_EXPECTED_VALUE(1, CheckedNumeric<Dst>(1) * 1);
  176. TEST_EXPECTED_VALUE(1, CheckedNumeric<Dst>(1) / 1);
  177. CheckedNumeric<Dst> checked_dst = 1;
  178. TEST_EXPECTED_VALUE(2, checked_dst += 1);
  179. checked_dst = 1;
  180. TEST_EXPECTED_VALUE(0, checked_dst -= 1);
  181. checked_dst = 1;
  182. TEST_EXPECTED_VALUE(1, checked_dst *= 1);
  183. checked_dst = 1;
  184. TEST_EXPECTED_VALUE(1, checked_dst /= 1);
  185. // Generic negation.
  186. TEST_EXPECTED_VALUE(0, -CheckedNumeric<Dst>());
  187. TEST_EXPECTED_VALUE(-1, -CheckedNumeric<Dst>(1));
  188. TEST_EXPECTED_VALUE(1, -CheckedNumeric<Dst>(-1));
  189. TEST_EXPECTED_VALUE(static_cast<Dst>(DstLimits::max() * -1),
  190. -CheckedNumeric<Dst>(DstLimits::max()));
  191. // Generic absolute value.
  192. TEST_EXPECTED_VALUE(0, CheckedNumeric<Dst>().Abs());
  193. TEST_EXPECTED_VALUE(1, CheckedNumeric<Dst>(1).Abs());
  194. TEST_EXPECTED_VALUE(DstLimits::max(),
  195. CheckedNumeric<Dst>(DstLimits::max()).Abs());
  196. // Generic addition.
  197. TEST_EXPECTED_VALUE(1, (CheckedNumeric<Dst>() + 1));
  198. TEST_EXPECTED_VALUE(2, (CheckedNumeric<Dst>(1) + 1));
  199. TEST_EXPECTED_VALUE(0, (CheckedNumeric<Dst>(-1) + 1));
  200. TEST_EXPECTED_VALIDITY(RANGE_VALID,
  201. CheckedNumeric<Dst>(DstLimits::min()) + 1);
  202. TEST_EXPECTED_VALIDITY(
  203. RANGE_OVERFLOW, CheckedNumeric<Dst>(DstLimits::max()) + DstLimits::max());
  204. // Generic subtraction.
  205. TEST_EXPECTED_VALUE(-1, (CheckedNumeric<Dst>() - 1));
  206. TEST_EXPECTED_VALUE(0, (CheckedNumeric<Dst>(1) - 1));
  207. TEST_EXPECTED_VALUE(-2, (CheckedNumeric<Dst>(-1) - 1));
  208. TEST_EXPECTED_VALIDITY(RANGE_VALID,
  209. CheckedNumeric<Dst>(DstLimits::max()) - 1);
  210. // Generic multiplication.
  211. TEST_EXPECTED_VALUE(0, (CheckedNumeric<Dst>() * 1));
  212. TEST_EXPECTED_VALUE(1, (CheckedNumeric<Dst>(1) * 1));
  213. TEST_EXPECTED_VALUE(-2, (CheckedNumeric<Dst>(-1) * 2));
  214. TEST_EXPECTED_VALIDITY(
  215. RANGE_OVERFLOW, CheckedNumeric<Dst>(DstLimits::max()) * DstLimits::max());
  216. // Generic division.
  217. TEST_EXPECTED_VALUE(0, CheckedNumeric<Dst>() / 1);
  218. TEST_EXPECTED_VALUE(1, CheckedNumeric<Dst>(1) / 1);
  219. TEST_EXPECTED_VALUE(DstLimits::min() / 2,
  220. CheckedNumeric<Dst>(DstLimits::min()) / 2);
  221. TEST_EXPECTED_VALUE(DstLimits::max() / 2,
  222. CheckedNumeric<Dst>(DstLimits::max()) / 2);
  223. TestSpecializedArithmetic<Dst>(dst, line);
  224. }
  225. // Helper macro to wrap displaying the conversion types and line numbers.
  226. #define TEST_ARITHMETIC(Dst) TestArithmetic<Dst>(#Dst, __LINE__)
  227. TEST(SafeNumerics, SignedIntegerMath) {
  228. TEST_ARITHMETIC(int8_t);
  229. TEST_ARITHMETIC(int);
  230. TEST_ARITHMETIC(intptr_t);
  231. TEST_ARITHMETIC(intmax_t);
  232. }
  233. TEST(SafeNumerics, UnsignedIntegerMath) {
  234. TEST_ARITHMETIC(uint8_t);
  235. TEST_ARITHMETIC(unsigned int);
  236. TEST_ARITHMETIC(uintptr_t);
  237. TEST_ARITHMETIC(uintmax_t);
  238. }
  239. TEST(SafeNumerics, FloatingPointMath) {
  240. TEST_ARITHMETIC(float);
  241. TEST_ARITHMETIC(double);
  242. }
  243. // Enumerates the five different conversions types we need to test.
  244. enum NumericConversionType {
  245. SIGN_PRESERVING_VALUE_PRESERVING,
  246. SIGN_PRESERVING_NARROW,
  247. SIGN_TO_UNSIGN_WIDEN_OR_EQUAL,
  248. SIGN_TO_UNSIGN_NARROW,
  249. UNSIGN_TO_SIGN_NARROW_OR_EQUAL,
  250. };
  251. // Template covering the different conversion tests.
  252. template <typename Dst, typename Src, NumericConversionType conversion>
  253. struct TestNumericConversion {};
  254. // EXPECT_EQ wrappers providing specific detail on test failures.
  255. #define TEST_EXPECTED_RANGE(expected, actual) \
  256. EXPECT_EQ(expected, butil::internal::DstRangeRelationToSrcRange<Dst>(actual)) \
  257. << "Conversion test: " << src << " value " << actual << " to " << dst \
  258. << " on line " << line;
  259. template <typename Dst, typename Src>
  260. struct TestNumericConversion<Dst, Src, SIGN_PRESERVING_VALUE_PRESERVING> {
  261. static void Test(const char *dst, const char *src, int line) {
  262. typedef numeric_limits<Src> SrcLimits;
  263. typedef numeric_limits<Dst> DstLimits;
  264. // Integral to floating.
  265. COMPILE_ASSERT((DstLimits::is_iec559 && SrcLimits::is_integer) ||
  266. // Not floating to integral and...
  267. (!(DstLimits::is_integer && SrcLimits::is_iec559) &&
  268. // Same sign, same numeric, source is narrower or same.
  269. ((SrcLimits::is_signed == DstLimits::is_signed &&
  270. sizeof(Dst) >= sizeof(Src)) ||
  271. // Or signed destination and source is smaller
  272. (DstLimits::is_signed && sizeof(Dst) > sizeof(Src)))),
  273. comparison_must_be_sign_preserving_and_value_preserving);
  274. const CheckedNumeric<Dst> checked_dst = SrcLimits::max();
  275. ;
  276. TEST_EXPECTED_VALIDITY(RANGE_VALID, checked_dst);
  277. if (MaxExponent<Dst>::value > MaxExponent<Src>::value) {
  278. if (MaxExponent<Dst>::value >= MaxExponent<Src>::value * 2 - 1) {
  279. // At least twice larger type.
  280. TEST_EXPECTED_VALIDITY(RANGE_VALID, SrcLimits::max() * checked_dst);
  281. } else { // Larger, but not at least twice as large.
  282. TEST_EXPECTED_VALIDITY(RANGE_OVERFLOW, SrcLimits::max() * checked_dst);
  283. TEST_EXPECTED_VALIDITY(RANGE_VALID, checked_dst + 1);
  284. }
  285. } else { // Same width type.
  286. TEST_EXPECTED_VALIDITY(RANGE_OVERFLOW, checked_dst + 1);
  287. }
  288. TEST_EXPECTED_RANGE(RANGE_VALID, SrcLimits::max());
  289. TEST_EXPECTED_RANGE(RANGE_VALID, static_cast<Src>(1));
  290. if (SrcLimits::is_iec559) {
  291. TEST_EXPECTED_RANGE(RANGE_VALID, SrcLimits::max() * static_cast<Src>(-1));
  292. TEST_EXPECTED_RANGE(RANGE_OVERFLOW, SrcLimits::infinity());
  293. TEST_EXPECTED_RANGE(RANGE_UNDERFLOW, SrcLimits::infinity() * -1);
  294. TEST_EXPECTED_RANGE(RANGE_INVALID, SrcLimits::quiet_NaN());
  295. ResetFloatingPointUnit();
  296. } else if (numeric_limits<Src>::is_signed) {
  297. TEST_EXPECTED_RANGE(RANGE_VALID, static_cast<Src>(-1));
  298. TEST_EXPECTED_RANGE(RANGE_VALID, SrcLimits::min());
  299. }
  300. }
  301. };
  302. template <typename Dst, typename Src>
  303. struct TestNumericConversion<Dst, Src, SIGN_PRESERVING_NARROW> {
  304. static void Test(const char *dst, const char *src, int line) {
  305. typedef numeric_limits<Src> SrcLimits;
  306. typedef numeric_limits<Dst> DstLimits;
  307. COMPILE_ASSERT(SrcLimits::is_signed == DstLimits::is_signed,
  308. destination_and_source_sign_must_be_the_same);
  309. COMPILE_ASSERT(sizeof(Dst) < sizeof(Src) ||
  310. (DstLimits::is_integer && SrcLimits::is_iec559),
  311. destination_must_be_narrower_than_source);
  312. const CheckedNumeric<Dst> checked_dst;
  313. TEST_EXPECTED_VALIDITY(RANGE_OVERFLOW, checked_dst + SrcLimits::max());
  314. TEST_EXPECTED_VALUE(1, checked_dst + static_cast<Src>(1));
  315. TEST_EXPECTED_VALIDITY(RANGE_UNDERFLOW, checked_dst - SrcLimits::max());
  316. TEST_EXPECTED_RANGE(RANGE_OVERFLOW, SrcLimits::max());
  317. TEST_EXPECTED_RANGE(RANGE_VALID, static_cast<Src>(1));
  318. if (SrcLimits::is_iec559) {
  319. TEST_EXPECTED_RANGE(RANGE_UNDERFLOW, SrcLimits::max() * -1);
  320. TEST_EXPECTED_RANGE(RANGE_VALID, static_cast<Src>(-1));
  321. TEST_EXPECTED_RANGE(RANGE_OVERFLOW, SrcLimits::infinity());
  322. TEST_EXPECTED_RANGE(RANGE_UNDERFLOW, SrcLimits::infinity() * -1);
  323. TEST_EXPECTED_RANGE(RANGE_INVALID, SrcLimits::quiet_NaN());
  324. ResetFloatingPointUnit();
  325. } else if (SrcLimits::is_signed) {
  326. TEST_EXPECTED_VALUE(-1, checked_dst - static_cast<Src>(1));
  327. TEST_EXPECTED_RANGE(RANGE_UNDERFLOW, SrcLimits::min());
  328. TEST_EXPECTED_RANGE(RANGE_VALID, static_cast<Src>(-1));
  329. } else {
  330. TEST_EXPECTED_VALIDITY(RANGE_INVALID, checked_dst - static_cast<Src>(1));
  331. TEST_EXPECTED_RANGE(RANGE_VALID, SrcLimits::min());
  332. }
  333. }
  334. };
  335. template <typename Dst, typename Src>
  336. struct TestNumericConversion<Dst, Src, SIGN_TO_UNSIGN_WIDEN_OR_EQUAL> {
  337. static void Test(const char *dst, const char *src, int line) {
  338. typedef numeric_limits<Src> SrcLimits;
  339. typedef numeric_limits<Dst> DstLimits;
  340. COMPILE_ASSERT(sizeof(Dst) >= sizeof(Src),
  341. destination_must_be_equal_or_wider_than_source);
  342. COMPILE_ASSERT(SrcLimits::is_signed, source_must_be_signed);
  343. COMPILE_ASSERT(!DstLimits::is_signed, destination_must_be_unsigned);
  344. const CheckedNumeric<Dst> checked_dst;
  345. TEST_EXPECTED_VALUE(SrcLimits::max(), checked_dst + SrcLimits::max());
  346. TEST_EXPECTED_VALIDITY(RANGE_UNDERFLOW, checked_dst + static_cast<Src>(-1));
  347. TEST_EXPECTED_VALIDITY(RANGE_UNDERFLOW, checked_dst + -SrcLimits::max());
  348. TEST_EXPECTED_RANGE(RANGE_UNDERFLOW, SrcLimits::min());
  349. TEST_EXPECTED_RANGE(RANGE_VALID, SrcLimits::max());
  350. TEST_EXPECTED_RANGE(RANGE_VALID, static_cast<Src>(1));
  351. TEST_EXPECTED_RANGE(RANGE_UNDERFLOW, static_cast<Src>(-1));
  352. }
  353. };
  354. template <typename Dst, typename Src>
  355. struct TestNumericConversion<Dst, Src, SIGN_TO_UNSIGN_NARROW> {
  356. static void Test(const char *dst, const char *src, int line) {
  357. typedef numeric_limits<Src> SrcLimits;
  358. typedef numeric_limits<Dst> DstLimits;
  359. COMPILE_ASSERT((DstLimits::is_integer && SrcLimits::is_iec559) ||
  360. (sizeof(Dst) < sizeof(Src)),
  361. destination_must_be_narrower_than_source);
  362. COMPILE_ASSERT(SrcLimits::is_signed, source_must_be_signed);
  363. COMPILE_ASSERT(!DstLimits::is_signed, destination_must_be_unsigned);
  364. const CheckedNumeric<Dst> checked_dst;
  365. TEST_EXPECTED_VALUE(1, checked_dst + static_cast<Src>(1));
  366. TEST_EXPECTED_VALIDITY(RANGE_OVERFLOW, checked_dst + SrcLimits::max());
  367. TEST_EXPECTED_VALIDITY(RANGE_UNDERFLOW, checked_dst + static_cast<Src>(-1));
  368. TEST_EXPECTED_VALIDITY(RANGE_UNDERFLOW, checked_dst + -SrcLimits::max());
  369. TEST_EXPECTED_RANGE(RANGE_OVERFLOW, SrcLimits::max());
  370. TEST_EXPECTED_RANGE(RANGE_VALID, static_cast<Src>(1));
  371. TEST_EXPECTED_RANGE(RANGE_UNDERFLOW, static_cast<Src>(-1));
  372. if (SrcLimits::is_iec559) {
  373. TEST_EXPECTED_RANGE(RANGE_UNDERFLOW, SrcLimits::max() * -1);
  374. TEST_EXPECTED_RANGE(RANGE_OVERFLOW, SrcLimits::infinity());
  375. TEST_EXPECTED_RANGE(RANGE_UNDERFLOW, SrcLimits::infinity() * -1);
  376. TEST_EXPECTED_RANGE(RANGE_INVALID, SrcLimits::quiet_NaN());
  377. ResetFloatingPointUnit();
  378. } else {
  379. TEST_EXPECTED_RANGE(RANGE_UNDERFLOW, SrcLimits::min());
  380. }
  381. }
  382. };
  383. template <typename Dst, typename Src>
  384. struct TestNumericConversion<Dst, Src, UNSIGN_TO_SIGN_NARROW_OR_EQUAL> {
  385. static void Test(const char *dst, const char *src, int line) {
  386. typedef numeric_limits<Src> SrcLimits;
  387. typedef numeric_limits<Dst> DstLimits;
  388. COMPILE_ASSERT(sizeof(Dst) <= sizeof(Src),
  389. destination_must_be_narrower_or_equal_to_source);
  390. COMPILE_ASSERT(!SrcLimits::is_signed, source_must_be_unsigned);
  391. COMPILE_ASSERT(DstLimits::is_signed, destination_must_be_signed);
  392. const CheckedNumeric<Dst> checked_dst;
  393. TEST_EXPECTED_VALUE(1, checked_dst + static_cast<Src>(1));
  394. TEST_EXPECTED_VALIDITY(RANGE_OVERFLOW, checked_dst + SrcLimits::max());
  395. TEST_EXPECTED_VALUE(SrcLimits::min(), checked_dst + SrcLimits::min());
  396. TEST_EXPECTED_RANGE(RANGE_VALID, SrcLimits::min());
  397. TEST_EXPECTED_RANGE(RANGE_OVERFLOW, SrcLimits::max());
  398. TEST_EXPECTED_RANGE(RANGE_VALID, static_cast<Src>(1));
  399. }
  400. };
  401. // Helper macro to wrap displaying the conversion types and line numbers
  402. #define TEST_NUMERIC_CONVERSION(d, s, t) \
  403. TestNumericConversion<d, s, t>::Test(#d, #s, __LINE__)
  404. TEST(SafeNumerics, IntMinOperations) {
  405. TEST_NUMERIC_CONVERSION(int8_t, int8_t, SIGN_PRESERVING_VALUE_PRESERVING);
  406. TEST_NUMERIC_CONVERSION(uint8_t, uint8_t, SIGN_PRESERVING_VALUE_PRESERVING);
  407. TEST_NUMERIC_CONVERSION(int8_t, int, SIGN_PRESERVING_NARROW);
  408. TEST_NUMERIC_CONVERSION(uint8_t, unsigned int, SIGN_PRESERVING_NARROW);
  409. TEST_NUMERIC_CONVERSION(int8_t, float, SIGN_PRESERVING_NARROW);
  410. TEST_NUMERIC_CONVERSION(uint8_t, int8_t, SIGN_TO_UNSIGN_WIDEN_OR_EQUAL);
  411. TEST_NUMERIC_CONVERSION(uint8_t, int, SIGN_TO_UNSIGN_NARROW);
  412. TEST_NUMERIC_CONVERSION(uint8_t, intmax_t, SIGN_TO_UNSIGN_NARROW);
  413. TEST_NUMERIC_CONVERSION(uint8_t, float, SIGN_TO_UNSIGN_NARROW);
  414. TEST_NUMERIC_CONVERSION(int8_t, unsigned int, UNSIGN_TO_SIGN_NARROW_OR_EQUAL);
  415. TEST_NUMERIC_CONVERSION(int8_t, uintmax_t, UNSIGN_TO_SIGN_NARROW_OR_EQUAL);
  416. }
  417. TEST(SafeNumerics, IntOperations) {
  418. TEST_NUMERIC_CONVERSION(int, int, SIGN_PRESERVING_VALUE_PRESERVING);
  419. TEST_NUMERIC_CONVERSION(unsigned int, unsigned int,
  420. SIGN_PRESERVING_VALUE_PRESERVING);
  421. TEST_NUMERIC_CONVERSION(int, int8_t, SIGN_PRESERVING_VALUE_PRESERVING);
  422. TEST_NUMERIC_CONVERSION(unsigned int, uint8_t,
  423. SIGN_PRESERVING_VALUE_PRESERVING);
  424. TEST_NUMERIC_CONVERSION(int, uint8_t, SIGN_PRESERVING_VALUE_PRESERVING);
  425. TEST_NUMERIC_CONVERSION(int, intmax_t, SIGN_PRESERVING_NARROW);
  426. TEST_NUMERIC_CONVERSION(unsigned int, uintmax_t, SIGN_PRESERVING_NARROW);
  427. TEST_NUMERIC_CONVERSION(int, float, SIGN_PRESERVING_NARROW);
  428. TEST_NUMERIC_CONVERSION(int, double, SIGN_PRESERVING_NARROW);
  429. TEST_NUMERIC_CONVERSION(unsigned int, int, SIGN_TO_UNSIGN_WIDEN_OR_EQUAL);
  430. TEST_NUMERIC_CONVERSION(unsigned int, int8_t, SIGN_TO_UNSIGN_WIDEN_OR_EQUAL);
  431. TEST_NUMERIC_CONVERSION(unsigned int, intmax_t, SIGN_TO_UNSIGN_NARROW);
  432. TEST_NUMERIC_CONVERSION(unsigned int, float, SIGN_TO_UNSIGN_NARROW);
  433. TEST_NUMERIC_CONVERSION(unsigned int, double, SIGN_TO_UNSIGN_NARROW);
  434. TEST_NUMERIC_CONVERSION(int, unsigned int, UNSIGN_TO_SIGN_NARROW_OR_EQUAL);
  435. TEST_NUMERIC_CONVERSION(int, uintmax_t, UNSIGN_TO_SIGN_NARROW_OR_EQUAL);
  436. }
  437. TEST(SafeNumerics, IntMaxOperations) {
  438. TEST_NUMERIC_CONVERSION(intmax_t, intmax_t, SIGN_PRESERVING_VALUE_PRESERVING);
  439. TEST_NUMERIC_CONVERSION(uintmax_t, uintmax_t,
  440. SIGN_PRESERVING_VALUE_PRESERVING);
  441. TEST_NUMERIC_CONVERSION(intmax_t, int, SIGN_PRESERVING_VALUE_PRESERVING);
  442. TEST_NUMERIC_CONVERSION(uintmax_t, unsigned int,
  443. SIGN_PRESERVING_VALUE_PRESERVING);
  444. TEST_NUMERIC_CONVERSION(intmax_t, unsigned int,
  445. SIGN_PRESERVING_VALUE_PRESERVING);
  446. TEST_NUMERIC_CONVERSION(intmax_t, uint8_t, SIGN_PRESERVING_VALUE_PRESERVING);
  447. TEST_NUMERIC_CONVERSION(intmax_t, float, SIGN_PRESERVING_NARROW);
  448. TEST_NUMERIC_CONVERSION(intmax_t, double, SIGN_PRESERVING_NARROW);
  449. TEST_NUMERIC_CONVERSION(uintmax_t, int, SIGN_TO_UNSIGN_WIDEN_OR_EQUAL);
  450. TEST_NUMERIC_CONVERSION(uintmax_t, int8_t, SIGN_TO_UNSIGN_WIDEN_OR_EQUAL);
  451. TEST_NUMERIC_CONVERSION(uintmax_t, float, SIGN_TO_UNSIGN_NARROW);
  452. TEST_NUMERIC_CONVERSION(uintmax_t, double, SIGN_TO_UNSIGN_NARROW);
  453. TEST_NUMERIC_CONVERSION(intmax_t, uintmax_t, UNSIGN_TO_SIGN_NARROW_OR_EQUAL);
  454. }
  455. TEST(SafeNumerics, FloatOperations) {
  456. TEST_NUMERIC_CONVERSION(float, intmax_t, SIGN_PRESERVING_VALUE_PRESERVING);
  457. TEST_NUMERIC_CONVERSION(float, uintmax_t,
  458. SIGN_PRESERVING_VALUE_PRESERVING);
  459. TEST_NUMERIC_CONVERSION(float, int, SIGN_PRESERVING_VALUE_PRESERVING);
  460. TEST_NUMERIC_CONVERSION(float, unsigned int,
  461. SIGN_PRESERVING_VALUE_PRESERVING);
  462. TEST_NUMERIC_CONVERSION(float, double, SIGN_PRESERVING_NARROW);
  463. }
  464. TEST(SafeNumerics, DoubleOperations) {
  465. TEST_NUMERIC_CONVERSION(double, intmax_t, SIGN_PRESERVING_VALUE_PRESERVING);
  466. TEST_NUMERIC_CONVERSION(double, uintmax_t,
  467. SIGN_PRESERVING_VALUE_PRESERVING);
  468. TEST_NUMERIC_CONVERSION(double, int, SIGN_PRESERVING_VALUE_PRESERVING);
  469. TEST_NUMERIC_CONVERSION(double, unsigned int,
  470. SIGN_PRESERVING_VALUE_PRESERVING);
  471. }
  472. TEST(SafeNumerics, SizeTOperations) {
  473. TEST_NUMERIC_CONVERSION(size_t, int, SIGN_TO_UNSIGN_WIDEN_OR_EQUAL);
  474. TEST_NUMERIC_CONVERSION(int, size_t, UNSIGN_TO_SIGN_NARROW_OR_EQUAL);
  475. }
  476. TEST(SafeNumerics, CastTests) {
  477. // MSVC catches and warns that we're forcing saturation in these tests.
  478. // Since that's intentional, we need to shut this warning off.
  479. #if defined(COMPILER_MSVC)
  480. #pragma warning(disable : 4756)
  481. #endif
  482. int small_positive = 1;
  483. int small_negative = -1;
  484. double double_small = 1.0;
  485. double double_large = numeric_limits<double>::max();
  486. double double_infinity = numeric_limits<float>::infinity();
  487. // Just test that the cast compiles, since the other tests cover logic.
  488. EXPECT_EQ(0, checked_cast<int>(static_cast<size_t>(0)));
  489. // Test various saturation corner cases.
  490. EXPECT_EQ(saturated_cast<int>(small_negative),
  491. static_cast<int>(small_negative));
  492. EXPECT_EQ(saturated_cast<int>(small_positive),
  493. static_cast<int>(small_positive));
  494. EXPECT_EQ(saturated_cast<unsigned>(small_negative),
  495. static_cast<unsigned>(0));
  496. EXPECT_EQ(saturated_cast<int>(double_small),
  497. static_cast<int>(double_small));
  498. EXPECT_EQ(saturated_cast<int>(double_large), numeric_limits<int>::max());
  499. EXPECT_EQ(saturated_cast<float>(double_large), double_infinity);
  500. EXPECT_EQ(saturated_cast<float>(-double_large), -double_infinity);
  501. }