Closes internal-consistency items 1 through 6, 12 and 13. Every include guard is _AKGL_<FILE>_H_, every in-project header include is angled, and every exported function, type and global carries the akgl_ prefix. This is an ABI break; the soname goes to libakgl.so.0.5. TODO.md carries the full rename table. The renames were driven by renaming each declaration and letting the compiler find the uses, not by pattern substitution: renderer, physics and camera are also parameter and struct-member names, and a sed would have rewritten map->physics and every akgl_RenderBackend *renderer parameter without a word. Item 4 turned out not to be cosmetic. The library exported a global called renderer and tests/character.c defined an SDL_Renderer *renderer of its own; the executable's definition preempted the library's, akgl_sprite_load_json read a SDL_Renderer * through an akgl_RenderBackend *, and every texture load in that suite failed. The suite reported success anyway, because libakerror's unhandled-error handler ends in exit(errctx->status), exit keeps only the low byte, and AKGL_ERR_SDL is exactly 256. So character had been green while running one of its four tests, and every suite in the tree was unable to fail on the most common status in a library built on SDL. Both are fixed. tests/testutil.h gains TEST_TRAP_UNHANDLED_ERRORS(), which collapses any status a byte cannot carry onto 1, and every suite installs it. character binds a real backend with akgl_render_2d_bind. Its fourth test then runs for the first time and fails on a defect it has asserted all along, so akgl_heap_release_character now walks state_sprites with AKGL_ITERATOR_OP_RELEASE and destroys the property set before zeroing the slot -- TODO.md Defects item 21 and half of Carried over item 1. AKGL_TIME_ONESEC_MS said "one second in milliseconds" and held 1000000, so akgl_game_state_lock waited roughly sixteen minutes rather than one second. It is AKGL_TIME_ONEMS_NS now, the budget is its own named constant, and tests/game.c holds the mutex from a second thread to assert the wait -- the contended path had no coverage at all. Headers are self-contained and it is enforced: AKGL_PUBLIC_HEADERS drives both install() and a generated translation unit per header, so a header that ships is a header that is checked. Writing that found registry.h, which used SDL_PropertiesID in eight declarations and included no SDL header. 23/23 suites pass, memcheck is clean, reindent --check is clean. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
175 lines
5.1 KiB
C
175 lines
5.1 KiB
C
#include <SDL3/SDL.h>
|
|
#include <stdlib.h>
|
|
#include <string.h>
|
|
#include <akerror.h>
|
|
#include <akgl/error.h>
|
|
#include <akgl/heap.h>
|
|
#include <akgl/registry.h>
|
|
#include <akgl/staticstring.h>
|
|
|
|
#include "testutil.h"
|
|
|
|
typedef akerr_ErrorContext *(*RegistryFuncPtr)(void);
|
|
|
|
void *sdl_calloc_always_fails(size_t a, size_t b)
|
|
{
|
|
// This forces SDL to simulate an out of memory condition
|
|
return NULL;
|
|
}
|
|
|
|
akerr_ErrorContext *test_akgl_registry_init(RegistryFuncPtr funcptr)
|
|
{
|
|
SDL_malloc_func malloc_func;
|
|
SDL_calloc_func calloc_func;
|
|
SDL_realloc_func realloc_func;
|
|
SDL_free_func free_func;
|
|
|
|
SDL_GetMemoryFunctions(
|
|
&malloc_func,
|
|
&calloc_func,
|
|
&realloc_func,
|
|
&free_func
|
|
);
|
|
PREPARE_ERROR(errctx);
|
|
ATTEMPT {
|
|
SDL_SetMemoryFunctions(
|
|
malloc_func,
|
|
(SDL_calloc_func)&sdl_calloc_always_fails,
|
|
realloc_func,
|
|
free_func
|
|
);
|
|
CATCH(errctx, funcptr());
|
|
} CLEANUP {
|
|
SDL_SetMemoryFunctions(
|
|
malloc_func,
|
|
calloc_func,
|
|
realloc_func,
|
|
free_func
|
|
);
|
|
} PROCESS(errctx) {
|
|
} FINISH(errctx, true);
|
|
|
|
FAIL_RETURN(errctx, AKGL_ERR_BEHAVIOR, "SDL memory allocator fails but registry reports successful property creation");
|
|
}
|
|
|
|
akerr_ErrorContext *test_akgl_registry_init_creation_failures(void)
|
|
{
|
|
PREPARE_ERROR(errctx);
|
|
ATTEMPT {
|
|
CATCH(errctx, test_akgl_registry_init(&akgl_registry_init_actor));
|
|
} CLEANUP {
|
|
} PROCESS(errctx) {
|
|
} HANDLE(errctx, AKERR_NULLPOINTER) {
|
|
printf("Sucess\n");
|
|
} FINISH(errctx, true);
|
|
|
|
ATTEMPT {
|
|
CATCH(errctx, test_akgl_registry_init(&akgl_registry_init_sprite));
|
|
} CLEANUP {
|
|
} PROCESS(errctx) {
|
|
} HANDLE(errctx, AKERR_NULLPOINTER) {
|
|
printf("Sucess\n");
|
|
} FINISH(errctx, true);
|
|
|
|
ATTEMPT {
|
|
CATCH(errctx, test_akgl_registry_init(&akgl_registry_init_spritesheet));
|
|
} CLEANUP {
|
|
} PROCESS(errctx) {
|
|
} HANDLE(errctx, AKERR_NULLPOINTER) {
|
|
printf("Sucess\n");
|
|
} FINISH(errctx, true);
|
|
|
|
ATTEMPT {
|
|
CATCH(errctx, test_akgl_registry_init(&akgl_registry_init_character));
|
|
} CLEANUP {
|
|
} PROCESS(errctx) {
|
|
} HANDLE(errctx, AKERR_NULLPOINTER) {
|
|
printf("Sucess\n");
|
|
} FINISH(errctx, true);
|
|
SUCCEED_RETURN(errctx);
|
|
}
|
|
|
|
/**
|
|
* @brief akgl_get_property must copy the value, and not a byte more.
|
|
*
|
|
* It used to copy a fixed AKGL_MAX_STRING_LENGTH bytes out of whatever SDL
|
|
* returned, and what SDL returns is its own strdup of the value -- four bytes
|
|
* for "0.0". That read up to 4 KiB past the end of somebody else's allocation on
|
|
* every call, which valgrind reported twelve times over in tests/physics.c
|
|
* alone.
|
|
*
|
|
* The destination is filled with a sentinel first, so the assertion is not
|
|
* "the value arrived" -- that would pass either way -- but "the bytes past the
|
|
* terminator were left alone", which is only true if the copy was bounded by
|
|
* the source.
|
|
*/
|
|
akerr_ErrorContext *test_akgl_get_property_copies_only_the_value(void)
|
|
{
|
|
PREPARE_ERROR(errctx);
|
|
akgl_String *value = NULL;
|
|
char oversized[AKGL_MAX_STRING_LENGTH + 8];
|
|
size_t valuelen = 0;
|
|
size_t i = 0;
|
|
bool untouched = true;
|
|
|
|
ATTEMPT {
|
|
CATCH(errctx, akgl_heap_init());
|
|
CATCH(errctx, akgl_registry_init_properties());
|
|
CATCH(errctx, akgl_heap_next_string(&value));
|
|
|
|
memset(&value->data, 0x5a, AKGL_MAX_STRING_LENGTH);
|
|
CATCH(errctx, akgl_set_property("registry.short", "0.0"));
|
|
CATCH(errctx, akgl_get_property("registry.short", &value, "unset"));
|
|
|
|
valuelen = strlen("0.0");
|
|
TEST_ASSERT(errctx, strcmp(value->data, "0.0") == 0,
|
|
"akgl_get_property returned \"%s\", expected \"0.0\"", value->data);
|
|
for ( i = (valuelen + 1); i < AKGL_MAX_STRING_LENGTH; i++ ) {
|
|
TEST_ASSERT_FLAG(untouched, (value->data[i] == 0x5a));
|
|
}
|
|
TEST_ASSERT(errctx, untouched,
|
|
"akgl_get_property wrote past the end of a %zu byte value", valuelen);
|
|
|
|
// The default takes the same path as a stored value.
|
|
CATCH(errctx, akgl_get_property("registry.absent", &value, "fallback"));
|
|
TEST_ASSERT(errctx, strcmp(value->data, "fallback") == 0,
|
|
"akgl_get_property returned \"%s\" for an unset property, expected the default",
|
|
value->data);
|
|
|
|
// A value too long for an akgl_String is refused rather than truncated
|
|
// into an unterminated buffer.
|
|
memset(&oversized, 'x', sizeof(oversized));
|
|
oversized[AKGL_MAX_STRING_LENGTH + 7] = '\0';
|
|
CATCH(errctx, akgl_set_property("registry.oversized", (char *)&oversized));
|
|
TEST_EXPECT_STATUS(errctx, AKERR_OUTOFBOUNDS,
|
|
akgl_get_property("registry.oversized", &value, "unset"),
|
|
"reading a property longer than an akgl_String");
|
|
|
|
// And the documented refusal survives: unset, with no default.
|
|
TEST_EXPECT_STATUS(errctx, AKERR_NULLPOINTER,
|
|
akgl_get_property("registry.absent", &value, NULL),
|
|
"reading an unset property with no default");
|
|
} CLEANUP {
|
|
if ( value != NULL ) {
|
|
IGNORE(akgl_heap_release_string(value));
|
|
}
|
|
} PROCESS(errctx) {
|
|
} FINISH(errctx, true);
|
|
SUCCEED_RETURN(errctx);
|
|
}
|
|
|
|
int main(void)
|
|
{
|
|
PREPARE_ERROR(errctx);
|
|
ATTEMPT {
|
|
CATCH(errctx, akgl_error_init());
|
|
TEST_TRAP_UNHANDLED_ERRORS();
|
|
CATCH(errctx, test_akgl_registry_init_creation_failures());
|
|
CATCH(errctx, test_akgl_get_property_copies_only_the_value());
|
|
} CLEANUP {
|
|
} PROCESS(errctx) {
|
|
} FINISH_NORETURN(errctx);
|
|
|
|
|
|
}
|