Version at 0.2.0: complete the wishlist, document it, gate the docs
Closes what was left of TODO.md sections 1, 2 and 3, and rewrites that
file to hold outstanding items only.
The API break gets a minor bump, because pre-1.0 the soname carries
MAJOR.MINOR and 0.1 and 0.2 are therefore different ABIs. Five
signatures changed and the ato* contract with them; UPGRADING.md is new
and lists every one, with the before/after for the cases the compiler
cannot warn about.
Section 3.1 is finished: reallocarray with the multiplication checked,
aligned_alloc and posix_memalign, asprintf/vasprintf, scanf/vscanf.
Four functions on that list are deliberately absent rather than missing
-- sprintf, strtok, setbuf and perror -- and TODO.md now says which and
why, so nobody adds them thinking they were forgotten.
Section 1.9, the cross-cutting tests:
tests/test_pool.c drives every failure path AKERR_MAX_ARRAY_ERROR
+ 10 times and checks the pool after each round,
because a wrapper that leaks a slot fails a
hundred calls later in unrelated code. It also
asserts that each error names the function and
file it was raised from, which is what catches a
FAIL that migrates into a helper during a
refactor: status right, message right, origin
quietly lying.
tests/negative/ two sources that must FAIL to compile, built with
-Werror and registered WILL_FAIL. AKERR_NOIGNORE
and the format attributes are enforced by the
compiler and by nothing else; drop either and
every ordinary test still passes.
Thread safety is answered rather than tested: the library is not
thread-safe and cannot be made so from here, because libakerror's error
pool is an unlocked process-global array. README.md says so plainly and
TODO.md carries it as the item blocking any future pthread wrappers.
Doxygen is configured and gated. All 147 public functions have @brief,
a @param each, @throws per status and @return; EXTRACT_ALL is off and
WARN_NO_PARAMDOC on, so `cmake --build build --target docs` fails on an
undocumented entity. It ran to 0 warnings. The Doxyfile carries no
version -- cmake/RunDoxygen.cmake feeds PROJECT_NUMBER in from
project(), so that stays the one place a version is written.
CI now builds against the submodule it pins instead of also installing
libakerror@main and never linking it, adds -Werror, and gains a
sanitizer job. The pre-push hook matches, and runs the docs check too.
Coverage: 99.5% of lines (1643/1651), 100% of functions (147/147). The
eight uncovered lines are each uncovered on purpose and TODO.md says
which and why.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
26
tests/negative/format_mismatch.c
Normal file
26
tests/negative/format_mismatch.c
Normal file
@@ -0,0 +1,26 @@
|
||||
/*
|
||||
* NEGATIVE COMPILE TEST -- TODO.md sections 1.3 and 2.2.5.
|
||||
*
|
||||
* This file must NOT compile. It is built by the CTest entry
|
||||
* `negative_format_mismatch` with -Werror, and that test is marked WILL_FAIL.
|
||||
*
|
||||
* What it asserts: the format attributes on the variadic wrappers are attached
|
||||
* and effective. Going through a wrapper is exactly how a caller loses the
|
||||
* compile-time format checking it would have had calling printf(3) directly --
|
||||
* printf("%d", "str") is caught and an unattributed wrapper's equivalent is not.
|
||||
* AKSL_PRINTF_FORMAT is what restores it, and this is what proves it is there.
|
||||
*/
|
||||
|
||||
#include <akstdlib.h>
|
||||
|
||||
int main(void)
|
||||
{
|
||||
char buf[64];
|
||||
int count = 0;
|
||||
akerr_ErrorContext *raised = NULL;
|
||||
|
||||
/* %d against a string. This is the line that must not build. */
|
||||
raised = aksl_snprintf(&count, buf, sizeof(buf), "%d", "not an int");
|
||||
|
||||
return raised == NULL ? 0 : 1;
|
||||
}
|
||||
26
tests/negative/noignore.c
Normal file
26
tests/negative/noignore.c
Normal file
@@ -0,0 +1,26 @@
|
||||
/*
|
||||
* NEGATIVE COMPILE TEST -- TODO.md section 1.9.
|
||||
*
|
||||
* This file must NOT compile. It is built by the CTest entry `negative_noignore`
|
||||
* with -Werror, and that test is marked WILL_FAIL, so a successful build is a
|
||||
* test failure.
|
||||
*
|
||||
* What it asserts: AKERR_NOIGNORE is actually attached and actually effective.
|
||||
* Every entry point in this library returns an error context the caller must
|
||||
* look at, and the whole design rests on discarding one being hard rather than
|
||||
* merely inadvisable. AKERR_NOIGNORE expands to warn_unused_result, which does
|
||||
* nothing at all if it is dropped from a declaration during a refactor -- and
|
||||
* nothing about the resulting library would look wrong.
|
||||
*/
|
||||
|
||||
#include <akstdlib.h>
|
||||
|
||||
int main(void)
|
||||
{
|
||||
void *ptr = NULL;
|
||||
|
||||
/* Discarding the returned context. This is the line that must not build. */
|
||||
aksl_malloc(32, &ptr);
|
||||
|
||||
return 0;
|
||||
}
|
||||
Reference in New Issue
Block a user