Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > comp.lang.c > #164423 > unrolled thread

on an analogy for verifying whether another digit fits (into an unsigned type)

Started byMeredith Montgomery <mmontgomery@levado.to>
First post2022-01-15 23:27 -0300
Last post2022-01-28 22:25 -0300
Articles 4 on this page of 64 — 11 participants

Back to article view | Back to comp.lang.c


Contents

  on an analogy for verifying whether another digit fits (into an unsigned type) Meredith Montgomery <mmontgomery@levado.to> - 2022-01-15 23:27 -0300
    Re: on an analogy for verifying whether another digit fits (into an unsigned type) Bart <bc@freeuk.com> - 2022-01-16 18:44 +0000
      Re: on an analogy for verifying whether another digit fits (into an unsigned type) Meredith Montgomery <mmontgomery@levado.to> - 2022-01-17 09:48 -0300
        Re: on an analogy for verifying whether another digit fits (into an unsigned type) Ben Bacarisse <ben.usenet@bsb.me.uk> - 2022-01-17 17:27 +0000
          Re: on an analogy for verifying whether another digit fits (into an unsigned type) scott@slp53.sl.home (Scott Lurndal) - 2022-01-17 18:06 +0000
            Re: on an analogy for verifying whether another digit fits (into an unsigned type) Ben Bacarisse <ben.usenet@bsb.me.uk> - 2022-01-17 20:59 +0000
              Re: on an analogy for verifying whether another digit fits (into an unsigned type) scott@slp53.sl.home (Scott Lurndal) - 2022-01-18 01:01 +0000
          Re: on an analogy for verifying whether another digit fits (into an unsigned type) Meredith Montgomery <mmontgomery@levado.to> - 2022-01-28 22:15 -0300
            Re: on an analogy for verifying whether another digit fits (into an unsigned type) Ben Bacarisse <ben.usenet@bsb.me.uk> - 2022-01-29 02:36 +0000
              Re: on an analogy for verifying whether another digit fits (into an unsigned type) Meredith Montgomery <mmontgomery@levado.to> - 2022-01-30 09:12 -0300
                Re: on an analogy for verifying whether another digit fits (into an unsigned type) Ben Bacarisse <ben.usenet@bsb.me.uk> - 2022-01-30 15:13 +0000
    Re: on an analogy for verifying whether another digit fits (into an unsigned type) Öö Tiib <ootiib@hot.ee> - 2022-01-16 12:15 -0800
      Re: on an analogy for verifying whether another digit fits (into an unsigned type) Meredith Montgomery <mmontgomery@levado.to> - 2022-01-17 09:53 -0300
        Re: on an analogy for verifying whether another digit fits (into an unsigned type) Meredith Montgomery <mmontgomery@levado.to> - 2022-01-17 10:12 -0300
    Re: on an analogy for verifying whether another digit fits (into an unsigned type) Bonita Montero <Bonita.Montero@gmail.com> - 2022-01-19 08:52 +0100
      Re: on an analogy for verifying whether another digit fits (into an unsigned type) Öö Tiib <ootiib@hot.ee> - 2022-01-19 06:08 -0800
        Re: on an analogy for verifying whether another digit fits (into an unsigned type) Bonita Montero <Bonita.Montero@gmail.com> - 2022-01-19 16:31 +0100
          Re: on an analogy for verifying whether another digit fits (into an unsigned type) Bonita Montero <Bonita.Montero@gmail.com> - 2022-01-19 18:02 +0100
            Re: on an analogy for verifying whether another digit fits (into an unsigned type) Bart <bc@freeuk.com> - 2022-01-19 18:27 +0000
              Re: on an analogy for verifying whether another digit fits (into an unsigned type) Bonita Montero <Bonita.Montero@gmail.com> - 2022-01-19 19:44 +0100
                Re: on an analogy for verifying whether another digit fits (into an unsigned type) Bonita Montero <Bonita.Montero@gmail.com> - 2022-01-20 08:08 +0100
                  Re: on an analogy for verifying whether another digit fits (into an unsigned type) Öö Tiib <ootiib@hot.ee> - 2022-01-20 09:47 -0800
              Re: on an analogy for verifying whether another digit fits (into an unsigned type) scott@slp53.sl.home (Scott Lurndal) - 2022-01-19 18:46 +0000
                Re: on an analogy for verifying whether another digit fits (into an unsigned type) Bart <bc@freeuk.com> - 2022-01-19 20:59 +0000
                  Re: on an analogy for verifying whether another digit fits (into an unsigned type) scott@slp53.sl.home (Scott Lurndal) - 2022-01-19 21:12 +0000
                    Re: on an analogy for verifying whether another digit fits (into an unsigned type) Bart <bc@freeuk.com> - 2022-01-19 22:25 +0000
                      Re: on an analogy for verifying whether another digit fits (into an unsigned type) Ben Bacarisse <ben.usenet@bsb.me.uk> - 2022-01-20 03:49 +0000
                        Re: on an analogy for verifying whether another digit fits (into an unsigned type) Bart <bc@freeuk.com> - 2022-01-20 10:05 +0000
                          Re: on an analogy for verifying whether another digit fits (into an unsigned type) Ben Bacarisse <ben.usenet@bsb.me.uk> - 2022-01-20 17:02 +0000
                            Re: on an analogy for verifying whether another digit fits (into an unsigned type) Bart <bc@freeuk.com> - 2022-01-20 19:20 +0000
                              Re: on an analogy for verifying whether another digit fits (into an unsigned type) Bart <bc@freeuk.com> - 2022-01-20 19:31 +0000
                  Re: on an analogy for verifying whether another digit fits (into an unsigned type) Keith Thompson <Keith.S.Thompson+u@gmail.com> - 2022-01-23 14:26 -0800
                    Re: on an analogy for verifying whether another digit fits (into an unsigned type) Bart <bc@freeuk.com> - 2022-01-24 00:13 +0000
                      Re: on an analogy for verifying whether another digit fits (into an unsigned type) Lew Pitcher <lew.pitcher@digitalfreehold.ca> - 2022-01-24 00:38 +0000
                        Re: on an analogy for verifying whether another digit fits (into an unsigned type) Bart <bc@freeuk.com> - 2022-01-24 01:09 +0000
                      Re: on an analogy for verifying whether another digit fits (into an unsigned type) Ben Bacarisse <ben.usenet@bsb.me.uk> - 2022-01-24 01:15 +0000
                        Re: on an analogy for verifying whether another digit fits (into an unsigned type) Bart <bc@freeuk.com> - 2022-01-24 11:21 +0000
                          Re: on an analogy for verifying whether another digit fits (into an unsigned type) scott@slp53.sl.home (Scott Lurndal) - 2022-01-24 15:54 +0000
                            Re: on an analogy for verifying whether another digit fits (into an unsigned type) Keith Thompson <Keith.S.Thompson+u@gmail.com> - 2022-01-24 13:08 -0800
                              Re: on an analogy for verifying whether another digit fits (into an unsigned type) scott@slp53.sl.home (Scott Lurndal) - 2022-01-24 22:51 +0000
                          Re: on an analogy for verifying whether another digit fits (into an unsigned type) Ben Bacarisse <ben.usenet@bsb.me.uk> - 2022-01-24 15:57 +0000
                            Re: on an analogy for verifying whether another digit fits (into an unsigned type) Bart <bc@freeuk.com> - 2022-01-24 16:52 +0000
                              Re: on an analogy for verifying whether another digit fits (into an unsigned type) Öö Tiib <ootiib@hot.ee> - 2022-01-24 10:17 -0800
                                Re: on an analogy for verifying whether another digit fits (into an unsigned type) scott@slp53.sl.home (Scott Lurndal) - 2022-01-24 18:23 +0000
                          Re: on an analogy for verifying whether another digit fits (into an unsigned type) Keith Thompson <Keith.S.Thompson+u@gmail.com> - 2022-01-24 13:15 -0800
                        Re: on an analogy for verifying whether another digit fits (into an unsigned type) Bart <bc@freeuk.com> - 2022-01-24 11:51 +0000
                      Re: on an analogy for verifying whether another digit fits (into an unsigned type) Keith Thompson <Keith.S.Thompson+u@gmail.com> - 2022-01-23 17:38 -0800
                        Re: on an analogy for verifying whether another digit fits (into an unsigned type) Bart <bc@freeuk.com> - 2022-01-24 11:22 +0000
                      Re: on an analogy for verifying whether another digit fits (into an unsigned type) scott@slp53.sl.home (Scott Lurndal) - 2022-01-24 15:51 +0000
                        Re: on an analogy for verifying whether another digit fits (into an unsigned type) Bart <bc@freeuk.com> - 2022-01-24 22:03 +0000
                          Re: on an analogy for verifying whether another digit fits (into an unsigned type) Keith Thompson <Keith.S.Thompson+u@gmail.com> - 2022-01-24 15:33 -0800
                            Re: on an analogy for verifying whether another digit fits (into an unsigned type) Bart <bc@freeuk.com> - 2022-01-25 00:09 +0000
                              Re: on an analogy for verifying whether another digit fits (into an unsigned type) Keith Thompson <Keith.S.Thompson+u@gmail.com> - 2022-01-24 21:14 -0800
                              Re: on an analogy for verifying whether another digit fits (into an unsigned type) Manfred <invalid@invalid.add> - 2022-01-26 21:01 +0100
                                Re: on an analogy for verifying whether another digit fits (into an unsigned type) Bart <bc@freeuk.com> - 2022-01-26 20:53 +0000
                                  Re: on an analogy for verifying whether another digit fits (into an unsigned type) Manfred <noname@add.invalid> - 2022-01-27 03:42 +0100
    Re: on an analogy for verifying whether another digit fits (into an unsigned type) Tim Rentsch <tr.17687@z991.linuxsc.com> - 2022-01-20 19:24 -0800
      Re: on an analogy for verifying whether another digit fits (into an unsigned type) Bonita Montero <Bonita.Montero@gmail.com> - 2022-01-21 08:07 +0100
        Re: on an analogy for verifying whether another digit fits (into an unsigned type) Tim Rentsch <tr.17687@z991.linuxsc.com> - 2022-01-21 06:01 -0800
          Re: on an analogy for verifying whether another digit fits (into an unsigned type) Bonita Montero <Bonita.Montero@gmail.com> - 2022-01-21 17:59 +0100
            Re: on an analogy for verifying whether another digit fits (into an unsigned type) scott@slp53.sl.home (Scott Lurndal) - 2022-01-21 17:41 +0000
              Re: on an analogy for verifying whether another digit fits (into an unsigned type) Bonita Montero <Bonita.Montero@gmail.com> - 2022-01-21 19:26 +0100
            Re: on an analogy for verifying whether another digit fits (into an unsigned type) Tim Rentsch <tr.17687@z991.linuxsc.com> - 2022-01-21 17:12 -0800
      Re: on an analogy for verifying whether another digit fits (into an unsigned type) Meredith Montgomery <mmontgomery@levado.to> - 2022-01-28 22:25 -0300

Page 4 of 4 — ← Prev page 1 2 3 [4]


#164519

Fromscott@slp53.sl.home (Scott Lurndal)
Date2022-01-21 17:41 +0000
Message-ID<lfCGJ.309808$tX27.109231@fx04.ams4>
In reply to#164510
Bonita Montero <Bonita.Montero@gmail.com> writes:
>Am 21.01.2022 um 15:01 schrieb Tim Rentsch:
>> Bonita Montero <Bonita.Montero@gmail.com> writes:
>> 
>>> Am 21.01.2022 um 04:24 schrieb Tim Rentsch:
>>>
>>>> Meredith Montgomery <mmontgomery@levado.to> writes:
>>>>
>>>>> I've been trying to think of an analogy for the verification
>>>>>
>>>>>         if( ((UINT64_MAX - c) / 10) >= r)
>>>>>           r = r * 10 + c;
>>>>>         else return -1; /* doesn't fit */
>>>>>
>>>>> in the procedure below.  [...]
>>>>
>>>> No analogy needed.  The condition that needs to be
>>>> satisfied is
>>>>
>>>>       r * 10 + c <= UINT64_MAX
>>>>
>>>> which is the same as
>>>>
>>>>       r * 10 <= UINT64_MAX - c
>>>>
>>>> which is the same as
>>>>
>>>>       r <= (UINT64_MAX - c) / 10
>>>>
>>>> which is the same as
>>>>
>>>>       (UINT64_MAX - c) / 10 >= r
>>>>
>>>> giving the expression in the if() test.  Done.
>>>
>>> Doesn't help because c isn't a constant.
>> 
>> It's hard to know what to say to such an obviously
>> inapplicable comment.
>
>If your exchanges would result in a constant instead of a calucaltion
>they would be favourable. But the overhead for your swapped calculation
>is exactly the same and the code isn't more readable than before.
>

Although the ordering can be significant from a security perspective,
consider this:

        if (len > PAGE_SIZE - 2 - size)

vs. this:

        if (size + len + 2 > PAGE_SIZE)

Which is better, and why?

[toc] | [prev] | [next] | [standalone]


#164522

FromBonita Montero <Bonita.Montero@gmail.com>
Date2022-01-21 19:26 +0100
Message-ID<ssetti$4v4$1@dont-email.me>
In reply to#164519
Am 21.01.2022 um 18:41 schrieb Scott Lurndal:
> Bonita Montero <Bonita.Montero@gmail.com> writes:
>> Am 21.01.2022 um 15:01 schrieb Tim Rentsch:
>>> Bonita Montero <Bonita.Montero@gmail.com> writes:
>>>
>>>> Am 21.01.2022 um 04:24 schrieb Tim Rentsch:
>>>>
>>>>> Meredith Montgomery <mmontgomery@levado.to> writes:
>>>>>
>>>>>> I've been trying to think of an analogy for the verification
>>>>>>
>>>>>>          if( ((UINT64_MAX - c) / 10) >= r)
>>>>>>            r = r * 10 + c;
>>>>>>          else return -1; /* doesn't fit */
>>>>>>
>>>>>> in the procedure below.  [...]
>>>>>
>>>>> No analogy needed.  The condition that needs to be
>>>>> satisfied is
>>>>>
>>>>>        r * 10 + c <= UINT64_MAX
>>>>>
>>>>> which is the same as
>>>>>
>>>>>        r * 10 <= UINT64_MAX - c
>>>>>
>>>>> which is the same as
>>>>>
>>>>>        r <= (UINT64_MAX - c) / 10
>>>>>
>>>>> which is the same as
>>>>>
>>>>>        (UINT64_MAX - c) / 10 >= r
>>>>>
>>>>> giving the expression in the if() test.  Done.
>>>>
>>>> Doesn't help because c isn't a constant.
>>>
>>> It's hard to know what to say to such an obviously
>>> inapplicable comment.
>>
>> If your exchanges would result in a constant instead of a calucaltion
>> they would be favourable. But the overhead for your swapped calculation
>> is exactly the same and the code isn't more readable than before.
>>
> 
> Although the ordering can be significant from a security perspective,
> consider this:
> 
>          if (len > PAGE_SIZE - 2 - size)
> 
> vs. this:
> 
>          if (size + len + 2 > PAGE_SIZE)
> 
> Which is better, and why?

Totally different discussion.

[toc] | [prev] | [next] | [standalone]


#164529

FromTim Rentsch <tr.17687@z991.linuxsc.com>
Date2022-01-21 17:12 -0800
Message-ID<86ilucpo9d.fsf@linuxsc.com>
In reply to#164510
Bonita Montero <Bonita.Montero@gmail.com> writes:

> Am 21.01.2022 um 15:01 schrieb Tim Rentsch:
>
>> Bonita Montero <Bonita.Montero@gmail.com> writes:
>>
>>> Am 21.01.2022 um 04:24 schrieb Tim Rentsch:
>>>
>>>> Meredith Montgomery <mmontgomery@levado.to> writes:
>>>>
>>>>> I've been trying to think of an analogy for the verification
>>>>>
>>>>>         if( ((UINT64_MAX - c) / 10) >= r)
>>>>>           r = r * 10 + c;
>>>>>         else return -1; /* doesn't fit */
>>>>>
>>>>> in the procedure below.  [...]
>>>>
>>>> No analogy needed.  The condition that needs to be
>>>> satisfied is
>>>>
>>>>       r * 10 + c <= UINT64_MAX
>>>>
>>>> which is the same as
>>>>
>>>>       r * 10 <= UINT64_MAX - c
>>>>
>>>> which is the same as
>>>>
>>>>       r <= (UINT64_MAX - c) / 10
>>>>
>>>> which is the same as
>>>>
>>>>       (UINT64_MAX - c) / 10 >= r
>>>>
>>>> giving the expression in the if() test.  Done.
>>>
>>> Doesn't help because c isn't a constant.
>>
>> It's hard to know what to say to such an obviously
>> inapplicable comment.
>
> If your exchanges would result in a constant instead of a
> calucaltion they would be favourable.  But the overhead for
> your swapped calculation is exactly the same and the code isn't
> more readable than before.

Apparently you don't understand that your comment has no bearing
on what I was talking about.

[toc] | [prev] | [next] | [standalone]


#164703

FromMeredith Montgomery <mmontgomery@levado.to>
Date2022-01-28 22:25 -0300
Message-ID<86k0ej8hai.fsf@levado.to>
In reply to#164499
Tim Rentsch <tr.17687@z991.linuxsc.com> writes:

> Meredith Montgomery <mmontgomery@levado.to> writes:
>
>> I've been trying to think of an analogy for the verification
>>
>>       if( ((UINT64_MAX - c) / 10) >= r)
>>         r = r * 10 + c;
>>       else return -1; /* doesn't fit */
>>
>> in the procedure below.  [...]
>
> No analogy needed.  The condition that needs to be
> satisfied is
>
>     r * 10 + c <= UINT64_MAX
>
> which is the same as
>
>     r * 10 <= UINT64_MAX - c
>
> which is the same as
>
>     r <= (UINT64_MAX - c) / 10
>
> which is the same as
>
>     (UINT64_MAX - c) / 10 >= r
>
> giving the expression in the if() test.  Done.

That's a brilliant explanation!

[toc] | [prev] | [standalone]


Page 4 of 4 — ← Prev page 1 2 3 [4]

Back to top | Article view | comp.lang.c


csiph-web