A.18.22 The Generic Package Containers.Bounded_Ordered_Maps
The language-defined generic package Containers.Bounded_Ordered_Maps
provides a private type Map and a set of operations. It provides the
same operations as the package Containers.Ordered_Maps (see A.18.6
with the difference that the maximum storage is bounded.
The declaration of the generic library package Containers.Bounded_Ordered_Maps
has the same contents and semantics as Containers.Ordered_Maps except:
The type Map is declared
with a discriminant that specifies the capacity (maximum number of elements)
Map (Capacity : Count_Type) is tagged private...;
The type Map needs finalization if and only if
type Key_Type or type Element_Type needs finalization.
The type Map cannot depend on package Ada.Finalization unless the element
type depends on that package. The objects returned from the Iterator
and Reference functions probably do depend on package Ada.Finalization.
Restricted environments may need to avoid use of those functions and
their associated types.
function Empty (Capacity : Count_Type := implementation-defined)
with Post =>
Empty'Result.Capacity = Capacity and then
not Tampering_With_Elements_Prohibited (Empty'Result) and then
not Tampering_With_Cursors_Prohibited (Empty'Result) and then
Length (Empty'Result) = 0;
For procedures Insert
and Include, the part of the precondition reading: The
allocation of internal storage includes a check that the capacity is
not exceeded, and Capacity_Error is raised if this check fails.
(<some length> <= Count_Type'Last - <some other length>
or else raise Constraint_Error)
(<some length> <= Count_Type'Last - <some other length>
or else raise Constraint_Error) and then
(<some length> <= Container.Capacity - <some other length>
or else raise Capacity_Error)
In procedure Assign, the
precondition is altered to: if Source length
is greater than Target capacity, then Capacity_Error is propagated.
Pre => (not Tampering_With_Cursors_Prohibited (Target)
or else raise Program_Error) and then
(Length (Source) <= Target.Capacity
or else raise Capacity_Error),
The function Copy
is replaced with:
Copy (Source : Map;
Capacity : Count_Type := 0) return
with Pre => Capacity = 0 or else Capacity >= Length (Source)
or else raise Capacity_Error,
Length (Copy'Result) = Length (Source) and then
not Tampering_With_Elements_Prohibited (Copy'Result) and then
not Tampering_With_Cursors_Prohibited (Copy'Result) and then
Copy'Result.Capacity = (if Capacity = 0 then
Length (Source) else Capacity)
Returns a map with key/element pairs initialized from the values in Source. If Capacity is 0, then the map capacity is the length of Source; if Capacity
is equal to or greater than the length of Source, the map capacity is
the specified value; otherwise, the operation propagates Capacity_Error.
Bounded (Run-Time) Errors
It is a bounded error to assign from a bounded map
object while tampering with elements [or cursors] of that object is prohibited.
Either Program_Error is raised by the assignment, execution proceeds
with the target object prohibiting tampering with elements [or cursors],
or execution proceeds normally.
Proof: Tampering with elements includes
tampering with cursors, so we only really need to talk about tampering
with elements here; we mention cursors for clarity.
When a bounded map object M
is finalized, if tampering with cursors
is prohibited for M
other than due to an assignment from another
map, then execution is erroneous.
Reason: This is a tampering event, but
since the implementation is not allowed to use Ada.Finalization, it is
not possible in a pure Ada implementation to detect this error. (There
is no Finalize routine that will be called that could make the check.)
Since the check probably cannot be made, the bad effects that could occur
(such as an iterator going into an infinite loop or accessing a nonexistent
element) cannot be prevented and we have to allow anything. We do allow
re-assigning an object that only prohibits tampering because it was copied
from another object as that cannot cause any negative effects.
For each instance of Containers.Ordered_Maps and each instance of Containers.Bounded_Ordered_Maps,
if the two instances meet the following conditions, then the output generated
by the Map'Output or Map'Write subprograms of either instance shall be
readable by the Map'Input or Map'Read of the other instance, respectively:
the Element_Type parameters of the two instances are statically matching
subtypes of the same type; and
the output generated by Element_Type'Output or Element_Type'Write is
readable by Element_Type'Input or Element_Type'Read, respectively (where
Element_Type denotes the type of the two actual Element_Type parameters);
the preceding two conditions also hold for the Key_Type parameters of
Bounded ordered map objects should be implemented without implicit pointers
or dynamic allocation.
Implementation Advice: Bounded ordered
map objects should be implemented without implicit pointers or dynamic
The implementation advice for procedure Move to minimize copying does
Implementation Advice: The implementation
advice for procedure Move to minimize copying does not apply to bounded
Extensions to Ada 2005
Inconsistencies With Ada 2012
with elements is now defined to be equivalent to tampering with cursors
for bounded containers. If a program requires tampering detection to
work, it might fail in Ada 202x. Needless to say, this shouldn't happen
outside of test programs. See Inconsistencies With Ada 2012 in A.18.2
for more details.
Ada 2005 and 2012 Editions sponsored in part by Ada-Europe