4 ms·
>unsigned is trivial (just test `a+b < b`) Nitpicking, the test itself should avoid overflowing. Instead, test "a <= UINT_MAX - b" to prove no overflow occurs.
by amavect 2y ago
>unsigned is trivial (just test `a+b < b`)
Nitpicking, the test itself should avoid overflowing. Instead, test "a <= UINT_MAX - b" to prove no overflow occurs.
For signed integers, we need to prove the following without overflowing in the test: "a+b <= INT_MAX && a+b >= INT_MIN". The algorithm follows: test "b >= 0", which implies "INT_MAX-b <= INT_MAX && a+b >= INT_MIN", so then test "a <= INT_MAX-b". Otherwise, "b < 0", which implies "INT_MIN-b >= INT_MIN && a+b <= INT_MAX", so then test "a >= INT_MIN-b".
- lelanthran 2y ago> Nitpicking, the test itself should avoid overflowing. Why? Overflowing is well defined for unsigned.
- amavect 2y agoPersonal preference, hence nitpicking. It forms a special case of the signed integer algorithm, which feels nice.