3 ms·
I like to write assertions that aren't always easy to check. Like asserting that a list is sorted.
by mcherm 1y ago
I like to write assertions that aren't always easy to check. Like asserting that a list is sorted.
- flir 1y agoThat sounds easy to check. Can you expand on this, because I don't understand.
- maverwa 1y agoits easy as in "simple to implement and execute" but not cheap, because it may require scanning large amounts of memory. You have to visit every list entry. Whats trivial for a very small list, may be a no-go for gigabyte-sized lists.
- flir 1y agoAh I see. That's the bit of the conversation I was trying to head off with "rhetorical" :)
- hxtk 1y agoMeaning computationally. It would cost a lot of cycles to keep that enabled in production. It’s only O(n), but if I check that assertion in my binary search function then it might as well have been linear search.
- pjmlp 1y agoBasically this could be something like this, D based example: void process_list(List aList) in(aList.isSorted, "List must be sorted!") do { // do something } However the O() cost of calling isSorted() has an impact on overall cost for process_list() on every call, hence why the way contracts are executed is usually configurable in languages that have them available.
- pjmlp 1y agoThen you want Design By Contract, dependent types, or formal verification. However, several factors have to be taken into account regarding performance impact when they get cleverly written, thus in manys cases they can only be fully turned on during debug builds.
- justinclift 1y agoOut of curiosity, have you looked at Cue before? It seems to be used for stuff like this, though I'm yet to really look into it properly. https://cuelang.org https://cuelang.org
- pjmlp 1y agoNo, yet another language to discover, thanks.
- matklad 1y agoYeah, there's actually trickiness here. Another curveball is that, with simulation testing, you generally want more assertions to catch more bugs, but slow assertions can _reduce_ testing efficiency by requiring more CPU time per iteration! But then, if you know, at comptime, that the list is going to be short, you might as well do O(N^2) verification! We captured these consideration in the internal docs here: https://github.com/tigerbeetle/tigerbeetle/blob/0.16.60/src/constants.zig#L776-L795 https://github.com/tigerbeetle/tigerbeetle/blob/0.16.60/src/...