From mboxrd@z Thu Jan 1 00:00:00 1970 X-Spam-Checker-Version: SpamAssassin 3.4.4 (2020-01-24) on polar.synack.me X-Spam-Level: X-Spam-Status: No, score=-1.9 required=5.0 tests=BAYES_00,FREEMAIL_FROM autolearn=ham autolearn_force=no version=3.4.4 X-Google-Thread: 103376,7d3cb5920e882220 X-Google-Attributes: gid103376,public,usenet X-Google-Language: ENGLISH,ASCII-7-bit Path: g2news1.google.com!news1.google.com!news.glorb.com!newsfeed101.telia.com!nf02.dk.telia.net!news.tele.dk!news.tele.dk!small.news.tele.dk!lnewsinpeer00.lnd.ops.eu.uu.net!emea.uu.net!peer-uk.news.demon.net!kibo.news.demon.net!news.demon.co.uk!demon!not-for-mail From: Simon Wright Newsgroups: comp.lang.ada Subject: Re: Contracted exceptions for Ada Date: Tue, 11 Dec 2007 20:50:07 +0000 Organization: Pushface Message-ID: References: <5947aa62-2547-4fbb-bc46-1111b4a0dcc9@x69g2000hsx.googlegroups.com> <7m9wkymyi5h7.1235e72is9mp9.dlg@40tude.net> <1355376.ahPdGlRDJW@linux1.krischik.com> <1bvj0n3ana6zj.1b1q7na2q2i0a.dlg@40tude.net> <5tw4p3ydoalt$.eyhp82hd04ch.dlg@40tude.net> <1vc7xfiouucfe.14549yzryw44i$.dlg@40tude.net> NNTP-Posting-Host: pogner.demon.co.uk Mime-Version: 1.0 Content-Type: text/plain; charset=us-ascii X-Trace: news.demon.co.uk 1197406208 3860 62.49.19.209 (11 Dec 2007 20:50:08 GMT) X-Complaints-To: abuse@demon.net NNTP-Posting-Date: Tue, 11 Dec 2007 20:50:08 +0000 (UTC) Cancel-Lock: sha1:2YC8os8RaD6y1tbFKs6C3WzZaJc= User-Agent: Gnus/5.11 (Gnus v5.11) Emacs/22.1 (darwin) Xref: g2news1.google.com comp.lang.ada:18903 Date: 2007-12-11T20:50:07+00:00 List-Id: "Dmitry A. Kazakov" writes: > On Mon, 10 Dec 2007 20:25:34 +0000, Simon Wright wrote: > >> The Ariane IV system engineers said to themselves, and probably in >> the design documentation, "The maximum horizontal velocity is >> X. Therefore the conversion to the fixed-point type _Whatever_ >> cannot overflow. Therefore we do not need to handle exceptions for >> this conversion, so (given we are short of CPU power) we will not >> do any extra processing to avoid exceptions." >> >> Not sure they would have recognised "contract" in that context. > > Yes, my premise was that the type of H_Input changed from Ariane IV > to Ariane V. In this case translation of the conversion function > H_Input_To_Whatever could refute the second "therefore" because X > would not be the maximal possible value of H_Input anymore. X was *never* the maximum possible value of H_Input!