2016-07-20 16:17:47 -04:00
|
|
|
///////////////////////////////////////////////////////////////////////////////
|
|
|
|
//
|
|
|
|
// Copyright (c) 2015 Microsoft Corporation. All rights reserved.
|
|
|
|
//
|
|
|
|
// This code is licensed under the MIT License (MIT).
|
|
|
|
//
|
|
|
|
// THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
|
|
|
|
// IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
|
|
|
|
// FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
|
|
|
|
// AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
|
|
|
|
// LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
|
|
|
|
// OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN
|
|
|
|
// THE SOFTWARE.
|
|
|
|
//
|
2015-11-20 19:03:00 -05:00
|
|
|
///////////////////////////////////////////////////////////////////////////////
|
|
|
|
|
|
|
|
#ifndef GSL_CONTRACTS_H
|
|
|
|
#define GSL_CONTRACTS_H
|
|
|
|
|
|
|
|
#include <exception>
|
2017-11-28 10:13:49 -05:00
|
|
|
#include <stdexcept> // for logic_error
|
2015-11-20 19:03:00 -05:00
|
|
|
|
|
|
|
//
|
|
|
|
// There are three configuration options for this GSL implementation's behavior
|
|
|
|
// when pre/post conditions on the GSL types are violated:
|
|
|
|
//
|
|
|
|
// 1. GSL_TERMINATE_ON_CONTRACT_VIOLATION: std::terminate will be called (default)
|
|
|
|
// 2. GSL_THROW_ON_CONTRACT_VIOLATION: a gsl::fail_fast exception will be thrown
|
2016-07-20 16:17:47 -04:00
|
|
|
// 3. GSL_UNENFORCED_ON_CONTRACT_VIOLATION: nothing happens
|
2015-11-20 19:03:00 -05:00
|
|
|
//
|
2017-03-20 12:30:14 -04:00
|
|
|
#if !(defined(GSL_THROW_ON_CONTRACT_VIOLATION) || defined(GSL_TERMINATE_ON_CONTRACT_VIOLATION) || \
|
2016-07-20 16:17:47 -04:00
|
|
|
defined(GSL_UNENFORCED_ON_CONTRACT_VIOLATION))
|
2017-04-20 10:51:37 -04:00
|
|
|
#define GSL_TERMINATE_ON_CONTRACT_VIOLATION
|
2015-11-20 19:03:00 -05:00
|
|
|
#endif
|
|
|
|
|
|
|
|
#define GSL_STRINGIFY_DETAIL(x) #x
|
|
|
|
#define GSL_STRINGIFY(x) GSL_STRINGIFY_DETAIL(x)
|
|
|
|
|
2016-09-28 11:43:13 -04:00
|
|
|
#if defined(__clang__) || defined(__GNUC__)
|
2017-04-20 10:51:37 -04:00
|
|
|
#define GSL_LIKELY(x) __builtin_expect(!!(x), 1)
|
|
|
|
#define GSL_UNLIKELY(x) __builtin_expect(!!(x), 0)
|
2016-09-28 11:43:13 -04:00
|
|
|
#else
|
2017-04-20 10:51:37 -04:00
|
|
|
#define GSL_LIKELY(x) (!!(x))
|
|
|
|
#define GSL_UNLIKELY(x) (!!(x))
|
2017-03-20 12:30:14 -04:00
|
|
|
#endif
|
|
|
|
|
|
|
|
//
|
|
|
|
// GSL_ASSUME(cond)
|
|
|
|
//
|
|
|
|
// Tell the optimizer that the predicate cond must hold. It is unspecified
|
|
|
|
// whether or not cond is actually evaluated.
|
|
|
|
//
|
|
|
|
#ifdef _MSC_VER
|
2017-04-20 10:51:37 -04:00
|
|
|
#define GSL_ASSUME(cond) __assume(cond)
|
2017-03-20 12:30:14 -04:00
|
|
|
#elif defined(__GNUC__)
|
2017-04-20 10:51:37 -04:00
|
|
|
#define GSL_ASSUME(cond) ((cond) ? static_cast<void>(0) : __builtin_unreachable())
|
2017-03-20 12:30:14 -04:00
|
|
|
#else
|
2018-02-11 15:16:39 -05:00
|
|
|
#define GSL_ASSUME(cond) static_cast<void>((cond) ? 0 : 0)
|
2016-09-28 11:43:13 -04:00
|
|
|
#endif
|
|
|
|
|
2015-11-20 19:03:00 -05:00
|
|
|
//
|
|
|
|
// GSL.assert: assertions
|
|
|
|
//
|
|
|
|
|
|
|
|
namespace gsl
|
|
|
|
{
|
2017-04-03 14:09:47 -04:00
|
|
|
struct fail_fast : public std::logic_error
|
2015-11-20 19:03:00 -05:00
|
|
|
{
|
2017-04-03 14:09:47 -04:00
|
|
|
explicit fail_fast(char const* const message) : std::logic_error(message) {}
|
2015-11-20 19:03:00 -05:00
|
|
|
};
|
|
|
|
}
|
|
|
|
|
2016-02-15 19:57:04 -05:00
|
|
|
#if defined(GSL_THROW_ON_CONTRACT_VIOLATION)
|
|
|
|
|
2017-04-20 10:51:37 -04:00
|
|
|
#define GSL_CONTRACT_CHECK(type, cond) \
|
|
|
|
(GSL_LIKELY(cond) ? static_cast<void>(0) \
|
|
|
|
: throw gsl::fail_fast("GSL: " type " failure at " __FILE__ \
|
|
|
|
": " GSL_STRINGIFY(__LINE__)))
|
2015-11-20 19:03:00 -05:00
|
|
|
|
|
|
|
#elif defined(GSL_TERMINATE_ON_CONTRACT_VIOLATION)
|
|
|
|
|
2017-04-20 10:51:37 -04:00
|
|
|
#define GSL_CONTRACT_CHECK(type, cond) (GSL_LIKELY(cond) ? static_cast<void>(0) : std::terminate())
|
2015-11-20 19:03:00 -05:00
|
|
|
|
|
|
|
#elif defined(GSL_UNENFORCED_ON_CONTRACT_VIOLATION)
|
|
|
|
|
2017-04-20 10:51:37 -04:00
|
|
|
#define GSL_CONTRACT_CHECK(type, cond) GSL_ASSUME(cond)
|
2015-11-20 19:03:00 -05:00
|
|
|
|
2016-07-20 16:17:47 -04:00
|
|
|
#endif
|
2015-11-20 19:03:00 -05:00
|
|
|
|
2017-03-20 12:30:14 -04:00
|
|
|
#define Expects(cond) GSL_CONTRACT_CHECK("Precondition", cond)
|
2018-03-08 16:49:36 -05:00
|
|
|
|
|
|
|
#if defined(GSL_UNENFORCED_ON_CONTRACT_VIOLATION)
|
|
|
|
|
|
|
|
#define Ensures(cond) static_cast<void>(0)
|
|
|
|
#define AlwaysEnsures(cond) static_cast<void>(0)
|
|
|
|
|
|
|
|
#else // GSL_UNENFORCED_ON_CONTRACT_VIOLATION
|
|
|
|
|
|
|
|
// Ensures uses an object that checks the condition on destruction
|
|
|
|
// Setting `always` to true means we want the ensurer to trigger even when
|
|
|
|
// exiting via exception (this will call std::terminate).
|
|
|
|
template<class A, bool always> class gsl_ensurer {
|
|
|
|
gsl_ensurer (const gsl_ensurer&) = delete;
|
|
|
|
gsl_ensurer& operator=(const gsl_ensurer&) = delete;
|
|
|
|
A& asserter;
|
|
|
|
public:
|
|
|
|
gsl_ensurer(A& asserter) : asserter(asserter) {}
|
|
|
|
~gsl_ensurer() noexcept(false)
|
|
|
|
{ if (!std::uncaught_exceptions() || always) asserter(); }
|
|
|
|
};
|
|
|
|
|
|
|
|
// Use line numbers to create unique names for each ensurer.
|
|
|
|
#define GSL_UNIQUE(a) GSL_JOIN(a, __LINE__)
|
|
|
|
#define GSL_JOIN(a, b) GSL_PASTE(a, b)
|
|
|
|
#define GSL_PASTE(a, b) a##b
|
|
|
|
|
|
|
|
// Ensure along all non-exception exit paths.
|
|
|
|
#define Ensures(cond) \
|
|
|
|
auto GSL_UNIQUE(GSL_ENSURER_) = [&]() { \
|
|
|
|
GSL_CONTRACT_CHECK("Postcondition", cond); \
|
|
|
|
}; \
|
|
|
|
gsl_ensurer<decltype(GSL_UNIQUE(GSL_ENSURER_)), false> \
|
|
|
|
GSL_UNIQUE(GSL_ENSURE_)(GSL_UNIQUE(GSL_ENSURER_));
|
|
|
|
|
|
|
|
// Ensure even when exiting via exception.
|
|
|
|
#define AlwaysEnsures(cond) \
|
|
|
|
auto GSL_UNIQUE(GSL_ENSURER_) = [&]() { \
|
|
|
|
GSL_CONTRACT_CHECK("Postcondition", cond); \
|
|
|
|
}; \
|
|
|
|
gsl_ensurer<decltype(GSL_UNIQUE(GSL_ENSURER_)), true> \
|
|
|
|
GSL_UNIQUE(GSL_ENSURE_)(GSL_UNIQUE(GSL_ENSURER_));
|
|
|
|
|
|
|
|
#endif // GSL_UNENFORCED_ON_CONTRACT_VIOLATION
|
|
|
|
|
|
|
|
// Assert that a function maintains an invariant during normal control flow
|
|
|
|
#define Maintains(cond) \
|
|
|
|
Expects(cond); \
|
|
|
|
Ensures(cond) \
|
|
|
|
|
|
|
|
// Assert that the invariant is maintained even when exiting via exception
|
|
|
|
#define AlwaysMaintains(cond) \
|
|
|
|
Expects(cond); \
|
|
|
|
AlwaysEnsures(cond) \
|
2017-03-20 12:30:14 -04:00
|
|
|
|
2015-11-20 19:03:00 -05:00
|
|
|
#endif // GSL_CONTRACTS_H
|