Thursday, July 9, 2009
Dear LazyMarket
Are you hiring? Do you know someone who is hiring? Well you're in luck! Because none other than yours truly is looking for a job. If you're interested in how great I am, send an email to lunchtimemama@gmail.com and I'll get you a copy of my resume. I look forward to hearing from you...
Tuesday, June 30, 2009
Variance, Thy Name is Ambiguity
"I think there's something you should know about Generic Variance..."
"I can change him!"
And now, the thrilling continuation...
I've just sent my recommendation to the ECMA 335 committee regarding the generic variance problem. I present it here for your reading pleasure:
Quick Recap
The following is an example of an ambiguous circumstance involving generic variance, the very sort over which we have all lost so much sleep:
.class interface abstract I<+T> {
.method public abstract virtual instance !T Foo ()
}
.class A {}
.class B extends A {}
.class C extends A {}
.class X implements I<class B>, I<class C> {
.method virtual instance class B I[B].Foo () { .override I<class B>::Foo }
.method virtual instance class C I[C].Foo () { .override I<class C>::Foo }
}
// Meanwhile, in some unsuspecting method...
I<A> i = new X ();
A a = i.Foo (); // AMBIGUITY!
Give a Runtime A Bone
To disambiguate such situations, we introduce a new custom attribute in the BCL. For the sake of example, let's call it System.PreferredImplementationAttribute. The PreferredImplementationAttribute is applied to a type and indicates which implementation should be selected by the runtime to resolve variance ambiguities. Our above definition of the type X would now look like this:
.class X implements I<class B>, I<class C> {
.custom instance void System.PreferredImplementationAttribute::.ctor (class System.Type) = { type(I<class C>) }
.method virtual instance class B I[B].Foo () { .override I<class B>::Foo }
.method virtual instance class C I[C].Foo () { .override I<class C>::Foo }
}
New Rules
With the addition of this attribute, the runtime requires that any type defined in an assembly targeting the 335 5th edition runtime which implements multiple interfaces that are variants of a common generic interface MUST specify ONE AND ONLY ONE PerferredImplementationAttribute for EACH of the potentially ambiguous common interfaces, and that each such specification of a PerferredImplementationAttribute must reference an interface implemented by the type that is a legal variant of the ambiguous common interface. In other words, all possible ambiguities MUST be disambiguated by the use of PreferredImplementationAttribute custom attributes. If a type does not satisfy these rules, the runtime MUST throw a System.TypeLoadException.
As this rule only applies to assemblies targeting the new version of the runtime, old images will continue to execute without issue. If the committee prefers, the resolution of ambiguities in old types may remain unspecified, or alphabetical priority could be codified in the spec to standardize such behavior. I would be fine leaving it unspecified.
Custom Attributes vs. Metadata
Ideally, I feel disambiguation information belongs in the type metadata structure rather than a custom attribute. If the committee feels that amending the metadata specification is tenable, I would recommend doing so (though I don't have any thoughts at this time on the exact logical or physical nature of such an amendment). If, on the other hand, changing the metadata spec at this point in the game is not feasible, then a custom attribute will just have to do. I see the addition of one custom attribute type to the Base Class Library as entirely justified.
An Aside to Our Friends on the 334 Committee
As a note to language designers targeting the runtime, I personally would consider it obnoxious if developers where burdened with the manual application of such a custom attribute. C# and other languages would do well to prohibit the direct use of the custom attribute, favoring instead a special syntax to denote the preferred implementation (the "default" keyword comes to mind in the case of C#). If this committee changes the type metadata spec to include preferred implementation information (and does not introduce a custom attribute type for that purpose), then special language syntaxes will be necessary.
An Alternative
In the interest of completeness, I will describe an alternate (if similar) approach to the ambiguity resolution problem. Rather than annotate types to indicate which of their interface implementations will satisfy ambiguous calls, the preferred implementation could be denoted on a per-member basis. Referring again to our original type X, this solution would modify that type thusly:
.class X implements I<class B>, I<class C> {
.method virtual instance class B I[B].Foo () { .override I<class B>::Foo }
.method virtual instance class C I[C].Foo () {
.override I<class C>::Foo
.custom instance void System.PreferredImplementationAttribute::.ctor ()
}
}
The member I[C].Foo is annotated with the System.PreferredImplementationAttribute, indicating that it will be selected by the runtime to fulfill otherwise ambiguous calls to I<T>.Foo. Note that in this solution the constructor to the PerferredImplementationAttribute type is parameterless. The runtime ensures that for EACH of the members of an interface which is the common variant of two or more of the interfaces implemented by a type, ONE AND ONLY ONE of the implementations for that member is flagged as "preferred."
Per-member preference definition affords developers more control but costs runtime implementers time, effort, and simplicity. I also don't envision many scenarios when developers would desire per-member control over implementation preference. I personally find this approach less tasteful than the per-interface solution but I mention it here, as I said, for completeness.
One More Thing...
There remains a situation on which there are varied opinions:
.class interface abstract I<+T> {
.method public abstract virtual instance !T Foo ()
}
.class A {}
.class B extends A {}
.class X implements I<class A> {
.method virtual instance class A I[A].Foo () { .override I<class A>::Foo }
}
.class Y extends X implements I<class B> {
.method virtual instance class B I[B].Foo () { .override I<class B>::Foo }
}
// Meanwhile, in some unsuspecting method...
I<A> i = new Y ();
A a = i.Foo ();
In this situation I<A>::Foo is called on an object of type Y. There is an implementation of I<A>::Foo in Y's type hierarchy (X::I[A].Foo), but there is also an available implementation which is a legal variant of I<A> in Y itself (Y:I[B].Foo). Does the runtime favor the exact implementation, or the more derived variant implementation? I don't have strong feelings on the matter, but my slight preference is for favoring the exact implementation.
The runtime is deciding on behalf of the developer which implementation is most appropriate. It could be argued that an exact implementation, wherever it is to be found the type hierarchy, is more appropriate than a variant implementation.
Also - and this is an implementation detail which should not outweigh other considerations but may be useful to keep in mind if all other things are equal - Mono stores a type's implemented interfaces in a binary tree, meaning that finding an exact implementation is an O(log n) worst-case operation, whereas finding a legal variant interface among a type's implemented interfaces is an O(n) worst-case operation (all interfaces must be examined to see if a legal variant exists among them). I haven't heard of any way to do O(log n) (or better) lookup of variants. With such popular types as IEnumerable`1 becoming variant, the superior time complexity could make a difference.
Saturday, May 16, 2009
Further Generic Variance Thoughts
I was writing a type today that implements both IDictionary<TKey, TValue> and ICollection<TValue>. These interfaces require the implementation of both IEnumerable<TValue> and IEnumerable<KeyValuePair<TKey, TValue>>. In .NET 4, the IEnumerable<T> type will be covariant. This exposes my type to potential ambiguity if it is assigned to a location of type IEnumerable<object> (see the previous post for details). If I were to follow my own advice and forbid the implementation of multiple interfaces which are variants of a single common interface, this type would be illegal. So on further reflection, I have decided to amend my opinion thusly: If there are multiple interface implementations which are variants of a common interface, then there must be implicit implementations of all of the potentially ambiguous members. These public members are then selected by the runtime to satisfy otherwise ambiguous calls. The implicit member implementations need not all be for the same interface. For example, if we have some interface IFoo<out T> with members T Bar(); and T Bat(); and we have some type with implements both IFoo<string> and IFoo<Uri>, it could have the members public string Bar(){} and public Uri Bat(){}. Any call to IFoo<object>.Bar() on an object of this type will execute the IFoo<string> implementation, and IFoo<object>.Bat() will execute the Uri implementation.
I believe that this restriction should be enforced at least at the language level (for all variant-capable languages targeting .NET), if not at the runtime level: all potentially ambiguous members must have public implementations. This resolves the ambiguity in a logical way, allows for more complex type design (which, as in the case of my type today, is desirable), and gives developers the ability to control which implementation will be selected. I think it is a Good Thing.
I believe that this restriction should be enforced at least at the language level (for all variant-capable languages targeting .NET), if not at the runtime level: all potentially ambiguous members must have public implementations. This resolves the ambiguity in a logical way, allows for more complex type design (which, as in the case of my type today, is desirable), and gives developers the ability to control which implementation will be selected. I think it is a Good Thing.
Thursday, April 9, 2009
Who's Afraid of Generic Variance?
Abstract
This post is an in-depth exploration of generic variance in the ECMA 335 standard and the REALLY BIG PROBLEM therewith. See the previous post on generic variance for an introduction to the topic.
The Punchline
The ECMA 335 Standard, 4th Edition, allows for nondeterministic execution. This means that in certain situations involving generic variance, the specification does not provide sufficient guidance to resolve ambiguities. As you may imagine, nondeterminism is a Very Bad Thing in computing (usually). It means that your program may run one way on .NET 3.5 and another way on .NET 4 and a third way if Richard Stallman saw his shadow in the morning.
The Solution
The ECMA 335 committee is hoping to resolve this problem in the 5th edition. Unfortunately, no clear solutions have revealed themselves. There are a number of possible approaches, all of which have pros and cons. I will be describing the problems and their possible solutions in this post. Feel free to weigh in on the matter. A robust discussion will aid the 335 group in their decision.
The Implementation Selection Problem
There are a number of increasingly pointy corner cases, all variations on the same theme: which of multiple implementation does the runtime select for execution? I will describe these corner cases in order of ascending pointiness. For each case, I will propose a deterministic solution and then demonstrate how that solution fails to address the next corner case. (Note: the deterministic solutions I propose are merely examples. Other solutions could be used.)
Overview
Before getting into the corner cases, I will provide a broad overview of the problem. Ambiguous situations arise when there are multiple implementations of one generic interface (with different type arguments). The generic interface must have some variant generic type parameter.
Vocab
The implemented types are the closed generic interface types that are actually implemented in the type hierarchy of the object in question.The execution type is the closed generic interface type of the location to which the object is assigned. Calls made to members of this type must be resolved to an implementation among the implemented types.
An exact implementation is the implementation of an implemented type whose generic type arguments precisely match those of the execution type. For example, if type A implements the generic interface I<String>, and we assign some A to an I<String> location, then its implementation for that interface is exact.
A variant implementation is the implementation of an implemented type whose generic type arguments do not precisely match those of the execution type, but are legal variants thereof. For example, if type A implements the covariant generic interface I<String>, and we assign some A to an I<Object> location, then its implementation for that interface is variant.
Case 0
Nothing to See Here
As a starting point, let us consider the following non-variant scenario which is NOT ambiguous.interface I<T> {
T Next();
}
class A {}
class X : I<A> {
A I<A>.Next() {...}
}
class Y : X, I<A> {
A I<A>.Next() {...}
}
// Test code
I<A> i = new Y();
A someA = i.Next();
Problem
There are two implementations of I<A>: one in X and one in Y. Which is used for the call to I<A>.Next()?
Solution
The implementation in type Y is used. As I said, this is not actually a problematic situation. I illustrate this case to demonstrate one of the ways the spec currently resolves potential ambiguities. In this case, the implementation in the most derived class is used. Y is more derived than X, therefore its implementation is used.
Case 1
Easy Pickins
interface I<out T> {
T Next();
}
class A {}
class B : A {}
class X : I<A> {
A I<A>.Next() {...}
}
class Y : X, I<B> {
B I<B>.Next() {...}
}
// Test code
I<A> i = new Y();
A someA = i.Next();
T Next();
}
class A {}
class B : A {}
class X : I<A> {
A I<A>.Next() {...}
}
class Y : X, I<B> {
B I<B>.Next() {...}
}
// Test code
I<A> i = new Y();
A someA = i.Next();
Problem
There are two implementations which suffice for I<A>: the I<A> exact implementation in X, and the I<B> variant implementation in Y. Which does the runtime select?
Solution
There are two possible solutions. We could adopt the aforementioned "most derived implementation wins" rule, in which case the runtime would pick the variant implementation in Y.
The other solution is to favor exact implementations over variant implementations, in which case the runtime would pick the exact but less derived implementation in X.
For the sake of argument, let's adopt the second solution: the runtime will select the most-derived exact implementation if one exists.
Case 2
The Decider
interface I<out T> {
T Next();
}
class A {}
class B : A {}
class C : B {}
class X : I<B> {
B I<B>.Next();
}
class Y : I<C> {
C I<C>.Next();
}
// Test code
I<A> i = new Y();
T Next();
}
class A {}
class B : A {}
class C : B {}
class X : I<B> {
B I<B>.Next();
}
class Y : I<C> {
C I<C>.Next();
}
// Test code
I<A> i = new Y();
Problem
There is no exact implementation of I<A>. There are two variant implementations: I<B> in X and I<C> in Y. Which does the runtime select?
Solution
As before, there are two options. We could choose the most derived implementation, in which case the runtime would select the I<C> implementation in Y.
The other option is to select the variant implementation with the least "distance" to the execution type. We are attempting to select an implementation for I<A>. We have variant implementations I<B> and I<C>. B is nearer to A in the inheritance chain than is C. Therefore we say that I<B> has less "distance" to I<A> than does I<C>. It may therefore be the case that the I<B> implementation is a more relevant substitute for I<A> since B is nearer to A than is C. By this rule, we would select the less distant but less derived I<B> implementation in X.
There are problems with the second option. What if there are multiple type parameters, each with different distances? How do we calculate the total distance of the type? Such a solution could require a rather complex set of rules, complicating the specification and compliant runtimes. And at the end of the day, it is dubious whether "distance" is a meaningful selection criteria.
For the sake of argument, let us go with the first option: the runtime will select the most derived variant implementation in the absence of an exact implementation.
Case 3
Ambiguity is Scary
interface I<out T> {
T Next();
}
class A {}
class B : A {}
class C : B {}
class X : I<B>, I<C> {
B I<B>.Next () {...}
C I<C>.Next() {...}
}
// Test code
I<A> i = new X();
A someA = i.Next();
T Next();
}
class A {}
class B : A {}
class C : B {}
class X : I<B>, I<C> {
B I<B>.Next () {...}
C I<C>.Next() {...}
}
// Test code
I<A> i = new X();
A someA = i.Next();
Problem
There is no exact implementation for I<A> and there are two variant implementations, I<B> and I<C>, both defined in the same type: X. Which does the runtime select?
Solution
We are now approaching the point at which any selection rule is largely arbitrary. We can revisit the "least distant" option though its problems are no fewer. It is also unclear whether such a selection behavior is obvious to the user. The user may not have taken "distance" into consideration when designing their types. On the other hand, the user who wrote this code clearly failed to take a number of things into consideration and it's now the runtime's job to make the best possible choice. Anything is better than nondeterminism.
For the sake of argument, let us say that we select the variant implementation with the least distant type argument. If there are multiple type parameters, we take the distance from the first non-identical set of arguments.
Case 4
Sophie's Choice
interface I<out T> {
T Next();
}
class A {}
class B : A {}
class C : A {}
class X : I<B>, I<C> {
B I<B>.Next() {...}
C I<C>.Next() {...}
}
// Test code
I<A> i = new X();
A someA = i.Next();
T Next();
}
class A {}
class B : A {}
class C : A {}
class X : I<B>, I<C> {
B I<B>.Next() {...}
C I<C>.Next() {...}
}
// Test code
I<A> i = new X();
A someA = i.Next();
Problem
There is no exact implementation of I<A>. There are two variant implementations: I<B> and I<C>, both defined in type X. B and C are equidistant from A. What would Jesus do?
Solution
Select I<B>. Because B comes before C in the alphabet.
If you think that's heinously arbitrary, you're right! But remember our motto: anything is better than nondeterminism.
[UPDATE]
Several people have proposed selecting based on the order in which the implementations appear in the code. This would select I<B> because it is defined first. As I said, my solutions are merely example rules.
Recap
To review, our selection rules are:
- The most derived exact implementation wins
- Failing an exact implementation, the most derived variant implementation wins
- If there are multiple equally-derived variant implementations and no exact implementation, the implementation with the least "distance" wins. If there are multiple type parameters, the distance is taken from the first non-identical set of arguments.
- If there are multiple equally-derived equidistant variant implementations and no exact implementation, the implementation with alphabetical priority wins. If there are multiple type parameters, the alphabetical priority is taken from the first non-identical set of arguments.
How Arbitrary Is Too Arbitrary?
As the cases get cornerier, the solutions get arbitrarier. Somewhere around case 3, the arbitrariness begins to offend the delicate sensibilities. There are alternatives to arbitrary selection which I will describe in a moment but I would like to first emphasize the virtue of arbitrariness: it is better than nondeterminism. ANYTHING is better than nondeterminism. Eeny meeny miny moe is a step up from the current spec. If no other solution can be decided upon, egregious arbitrariness is still better than what we have.
As we consider alternatives to arbitrary selection, consider the question, "how arbitrary is too arbitrary?" For which of the above cases is one of the below alternatives a superior option? Bear it in mind as we press ahead...
Exceptions
Runtime exceptions are an alternative to arbitrary implementation selection. If an ambiguous situation arises, an exception pops up. The benefit of exceptions is that they let the developer know that there is an ambiguous situation, whereas arbitrary selection may simply lead to unexpected and difficult-to-debug behavior. There are two exceptional approaches:
Exception On Call
When an ambiguous call is made, throw a runtime exception. For example:interface I<out T> {
T Next();
}
class A {}
class B : A {}
class C : A {}
class X : I<B>, I<C> {
B I<B>.Next();
C I<C>.Next();
}
// Test code
I<A> i = new X();
A someA = i.Next(); // AMBIGUOUS CALL EXCEPTION HAPPENS HERE
This has the benefit of only throwing an exception if the ambiguity is actually going to be a problem. The major issue is, exceptions can be thrown from innocent code. If you pass an X to some library function which takes an I<A>, that library will blissfully call I<A>.Next() and trigger the exception. The stack trace will implicate the library, but the culprit is the X type definition.
Exception On Assignment
When an object is assigned to an ambiguous interface, throw a runtime exception. For example:interface I<out T> {
T Next();
}
class A {}
class B : A {}
class C : A {}
class X : I<B>, I<C> {
B I<B>.Next();
C I<C>.Next();
}
// Test code
I<A> i = new X(); // AMBIGUOUS ASSIGNMENT EXCEPTION HAPPENS HERE
A someA = i.Next();
This approach runs the risk of unnecessary exceptions. If an ambiguous call is never made, an ambiguous assignment is not dangerous. This approach also allows exceptions to be thrown from innocent code. If some library takes an I<B>, an X can be passed without ambiguity. The library is then at liberty to assign the I<B> to an I<A>, resulting in an exception. The library is not at fault, but the stack trace implies otherwise.
Invalid Ambiguity
Once you have answered the question "how arbitrary is too arbitrary," take everything on the "too arbitrary" side of the fence and make it against the rules. For example, if you conclude that there is no reasonable way of selecting between two variant implementations defined in the same type, then it would be invalid to define a type which implements multiple interfaces that are variants of a common interface.
This has the downside of invaliding currently valid CLI images. I don't know to what degree forward compatibility is a goal for the ECMA 335 spec.
Language-Level Enforcement
Irrespective of the runtime's solution to this problem, languages can impose independent restrictions on ambiguous type design. For example, C# could make it a compilation error for a type to implement multiple interfaces that are variants of a common interface, even if such a type is valid for the runtime. If all major languages enforce unambiguous type design, the pressure on the runtime to avoid arbitrariness is lessened since the dangerously arbitrary rules will not affect any code written in a major language. The only people vulnerable to the arbitrary rules are ostensibly savvy enough to be trusted with understanding obscure runtime behaviors.
The Least Worst Solution
There is clearly no silver bullet for the problem. The least worst solution will be a blend of several approaches. The appropriate blend will depend upon a number of things such as the importance of the forward compatibility of CLI images. The ultimate solution must address two concerns: the elimination of nondeterminism and the prevention of developer confusion. The same implementation must deterministically execute every time, and it must be clear to developers which implementation that will be.
My Thoughts
The implementation selections rules should begin as follows:
- The most derived exact implementation wins.
- In the absence of an exact implementation, the most derived variant implementation wins.
Situations not addressed by these rules are considered "ambiguous."
As a solution to ambiguous situations, exceptions serve neither of the stated goals. They achieve deterministic failure rather than deterministic execution and their stack traces obfuscate the root of the problem. A sufficiently descriptive error message could aid developer comprehension but it would be far too easy for a stack trace from "someone else's code" to become a bug report to the wrong people or an ignored problem. I think exceptions are the worst worst solution.
Language-level ambiguity preclusion is an very good idea but adding a compiler error for ambiguous type design could break existing code when existing interfaces are made variant. For example, consider this C#:
class A {}
class B : A {}
class C : A {}
class X : IEnumerable<B>, IEnumerable<C> {...}
This is currently a legal C# class definition. However with the release of .NET 4 the IEnumerable<T> interface will be made covariant, making the above class vulnerable to ambiguity. Making ambiguous type design a warning rather than an error would solve this problem but I think it is worth breaking existing code in the interest of drawing developers' attention to the new ambiguity.
All variance-capable .NET languages should add errors for ambiguous type design.
Which brings us to the question of the runtime's ambiguity handling mechanism. The two best options are:
- Make ambiguities illegal.
- Add an arbitrary implementation selection rule: alphabetical priority of type arguments.
Option 1 achieves both objectives of a solution: it guarantees deterministic execution and ensures developer comprehension by proscribing ambiguous circumstances altogether. However it also breaks the forward compatibility of existing binaries.
Option 2 guarantees deterministic execution but does not serve developer comprehension (no developer wants to consider the alphabetical priority of type arguments when designing their types). In conjunction with language-level enforcement, however, no developer should ever suffer this confusion. And this option affords all currently valid CLI images continued validity.
So the key question is, how important is compatibility?
I am tending toward option 1, but I think there is room for debate.
What Do You Think?
Comment away.
Next Time...
If all that weren't enough, there is a problem with variancifying existing types (such as turning IEnumerable<T> into IEnumerable<out T>) but I will save that for another post.
Thanks
Thanks goes to Dr. Nigel Perry on the ECMA 334 and 335 standards committee for working with me on this.
Saturday, April 4, 2009
Exceptional APIs
Axioms for public API design:
Axiom 1
NullReferenceExceptions that come out of your code ARE YOUR FAULT!
Axiom 2
The fewer exceptions your code can possibly throw, the better!
Applications of these axioms:
Let's say we're writing a public API, you and I. In it, let's say we have the following awesome method:
Lemma 1
From axiom 1 it follows: Null-check EVERYTHING YOU DEREFERENCE unless you know where it came from.
We could do a conditional dereference:
Let's say that we decide on argument verification. Now let's say that we want to add a convenience overload:
Lemma 2
From axiom 2 it follows: Use 'null' as a sentinel between overloads for the default value when null is not an otherwise permissible value.
My favorite non-fiction book of all time, Framework Design Guidelines, specifically says not to do this. It is wrong. Well, sort of. FDG advises against using null as a "magic" sentinel, period. I argue that sentinel null is correct for parameters which are omitted in convenience overloads. Here is why:
To recap, our API currently looks like this:
Foo(); // This is fine
Foo("How the hell do I use this API?"); // This too is just fine
But if misguided user passes null to Foo(string), or passes a variable which may be null, things aren't so rosey:
Foo(null); // Exception city!
Foo(someString); // It depends...
How is our misguided user to know what is and is not a safe call? They could look at our documentation. Assuming we wrote any. And assuming we correctly documented all of the parameters which need to be non-null. Or they could test passing null and see if it throws.
(As a side note, I wonder all the time about whether I can pass null to an API. Documentation is usually no help and if I see a parameterless overload, I generally assume that I can)
More likely, they will do none of the above and just write something resembling the last example call, passing a variable. A variable which is usually not null. A variable which is never null during testing. But a variable which, when released into the wild may, under some unforeseen circumstance, be null. Then all the kids would cry.
The solution:
Some may complain about semantics purity or somesuch. They are wrong.
So, if you have some public API which takes a parameter that a) is not allowed to be null, and b) has a default value for the purpose of convenience overloads, use the sentinel null. Just do it.
Axiom 1
NullReferenceExceptions that come out of your code ARE YOUR FAULT!
Axiom 2
The fewer exceptions your code can possibly throw, the better!
Applications of these axioms:
Let's say we're writing a public API, you and I. In it, let's say we have the following awesome method:
public void Foo(string s) {You will notice that we dereference s to get its Length property. If some misguided user of ours were to pass null to Foo, an NRE would pop out of our code like an overweight stripper out of a wedding cake. Awkward! And then the stack trace would get passed all over school and all the kids would laugh at us.
Bar(s.Length);
}
Lemma 1
From axiom 1 it follows: Null-check EVERYTHING YOU DEREFERENCE unless you know where it came from.
We could do a conditional dereference:
public void Foo(string s) {Or we could verify the argument:
if (s != null) Bar(s.Length);
}
public void Foo(string s) {If our method absolutely needs to dereference the object in order to do its job, then argument verification is the way to go. This may seem like trading one exception type for another, but it's really not. Argument exception types are perfectly acceptable - they inform our misguided user what went wrong and how to make it right. On the other hand, NREs mean that we didn't verify the argument or null-check before dereferencing. And they mean that all the kids will laugh at us.
if (s == null) throw new ArgumentNullException("s");
Bar(s.Length);
}
Let's say that we decide on argument verification. Now let's say that we want to add a convenience overload:
public void Foo() {Looks good, right? WRONG!
Foo("");
}
Lemma 2
From axiom 2 it follows: Use 'null' as a sentinel between overloads for the default value when null is not an otherwise permissible value.
My favorite non-fiction book of all time, Framework Design Guidelines, specifically says not to do this. It is wrong. Well, sort of. FDG advises against using null as a "magic" sentinel, period. I argue that sentinel null is correct for parameters which are omitted in convenience overloads. Here is why:
To recap, our API currently looks like this:
public void Foo() {Let's consider the possible ways our misguided user can use this API. If he or she calls the convenience overload, or passes a string literal, everything's honkey dorey:
Foo("");
}
public void Foo(string s) {
if (s == null) throw new ArgumentNullException("s");
Bar(s.Length);
}
Foo(); // This is fine
Foo("How the hell do I use this API?"); // This too is just fine
But if misguided user passes null to Foo(string), or passes a variable which may be null, things aren't so rosey:
Foo(null); // Exception city!
Foo(someString); // It depends...
How is our misguided user to know what is and is not a safe call? They could look at our documentation. Assuming we wrote any. And assuming we correctly documented all of the parameters which need to be non-null. Or they could test passing null and see if it throws.
(As a side note, I wonder all the time about whether I can pass null to an API. Documentation is usually no help and if I see a parameterless overload, I generally assume that I can)
More likely, they will do none of the above and just write something resembling the last example call, passing a variable. A variable which is usually not null. A variable which is never null during testing. But a variable which, when released into the wild may, under some unforeseen circumstance, be null. Then all the kids would cry.
The solution:
public void Foo() {All possible inputs to this API are valid and there is zero change of an exception. This is better!
Foo(null);
}
public void Foo(string s) {
if (s == null) s = "";
Bar(s.Length);
}
Some may complain about semantics purity or somesuch. They are wrong.
So, if you have some public API which takes a parameter that a) is not allowed to be null, and b) has a default value for the purpose of convenience overloads, use the sentinel null. Just do it.
Sunday, February 22, 2009
Now Is The Winter of Our Optional and Named Parameters
Optional and named method parameters are coming to C# 4. This means you can provide default values for method parameters. When you call the method, you can name only the parameters you want to specify - default values will be used for all other parameters.
The compiler just sprinkles the default values into every callsite. There are a few problems with this approach. Let's suppose I release version 1 of my awesome library with the above Foo method. You compile. All is well. Now let's say I release version 2 of my library, in which the default value "STELLAAAA!" is changed to "KHAAAAN!". But your code still has the old default value baked in. You need to re-compile your code to get the new default value. There is also the problem that injecting the full argument list into every callsite bloats the size of the code. Bigger code means more to JIT and fewer cache hits
Thanks to C# 3's object initialization, you can squint at the call and almost see the named parameter syntax (just ignore "new FooSettings"). This pattern of using a special "settings" type for passing arguments to methods already exists in the framework (see XmlReader.Create and XmlWriter.Create for an example). I am proposing that the compiler auto-generate these types and provide full optional/named parameter sugar. The compiler-generated types would be publicly nested within the type containing the method and named "[MemberName]Settings" by default.
This is better than callsite default value injection because:
This is how C# 4 should do optional and named parameters.
Here's how you use it:
public void Foo (
int doodad = 1,
string humdinger = "",
string wuchacallit = "STELLAAAA!")
{
// Do stuff here
}
void Test ()
{
Foo ();
Foo (humdinger = "Beard Lust");
Foo (doodad = 5,
wuchacallit = "SHAMU!");
Foo (wuchacallit = "Kia",
humdinger = "Ora",
doodad = 42);
}
int doodad = 1,
string humdinger = "",
string wuchacallit = "STELLAAAA!")
{
// Do stuff here
}
void Test ()
{
Foo ();
Foo (humdinger = "Beard Lust");
Foo (doodad = 5,
wuchacallit = "SHAMU!");
Foo (wuchacallit = "Kia",
humdinger = "Ora",
doodad = 42);
}
Here's how it really works:
public void Foo (
[Optional, DefaultParameterValue(1)]
int doodad,
[Optional, DefaultParameterValue("")]
string humdinger,
[Optional, DefaultParameterValue("STELLAAAA!")]
string wuchacallit)
{
// Do stuff here
}
void Test ()
{
Foo (1, "", "STELLAAAA!");
Foo (1, "Beard Lust", "STELLAAAA!");
Foo (5, "", "SHAMU!");
Foo (42, "Ora", "Kia");
}
[Optional, DefaultParameterValue(1)]
int doodad,
[Optional, DefaultParameterValue("")]
string humdinger,
[Optional, DefaultParameterValue("STELLAAAA!")]
string wuchacallit)
{
// Do stuff here
}
void Test ()
{
Foo (1, "", "STELLAAAA!");
Foo (1, "Beard Lust", "STELLAAAA!");
Foo (5, "", "SHAMU!");
Foo (42, "Ora", "Kia");
}
The compiler just sprinkles the default values into every callsite. There are a few problems with this approach. Let's suppose I release version 1 of my awesome library with the above Foo method. You compile. All is well. Now let's say I release version 2 of my library, in which the default value "STELLAAAA!" is changed to "KHAAAAN!". But your code still has the old default value baked in. You need to re-compile your code to get the new default value. There is also the problem that injecting the full argument list into every callsite bloats the size of the code. Bigger code means more to JIT and fewer cache hits
How it should work:
struct FooSettings {
int doodad_value = 1;
string humdinger_value = "";
string wuchacallit_value = "STELLAAAA!";
public int doodad {
get { return doodad_value; }
set { doodad_value = value; }
}
public string humdinger {
get { return humdinger_value; }
set { humdinger_value = value; }
}
public string wuchacallit {
get { return wuchacallit_value; }
set { wuchacallit_value = value; }
}
}
public void Foo (FooSettings settings)
{
// Do stuff
}
void Test ()
{
Foo (new FooSettings ());
Foo (new FooSettings { humdinger = "Beard Lust" });
Foo (new FooSettings {
doodad = 5,
wuchacallit = "SHAMU!" });
Foo (new FooSettings {
wuchacallit = "Kia",
humdinger = "Ora",
doodad = 42 });
}
int doodad_value = 1;
string humdinger_value = "";
string wuchacallit_value = "STELLAAAA!";
public int doodad {
get { return doodad_value; }
set { doodad_value = value; }
}
public string humdinger {
get { return humdinger_value; }
set { humdinger_value = value; }
}
public string wuchacallit {
get { return wuchacallit_value; }
set { wuchacallit_value = value; }
}
}
public void Foo (FooSettings settings)
{
// Do stuff
}
void Test ()
{
Foo (new FooSettings ());
Foo (new FooSettings { humdinger = "Beard Lust" });
Foo (new FooSettings {
doodad = 5,
wuchacallit = "SHAMU!" });
Foo (new FooSettings {
wuchacallit = "Kia",
humdinger = "Ora",
doodad = 42 });
}
Thanks to C# 3's object initialization, you can squint at the call and almost see the named parameter syntax (just ignore "new FooSettings"). This pattern of using a special "settings" type for passing arguments to methods already exists in the framework (see XmlReader.Create and XmlWriter.Create for an example). I am proposing that the compiler auto-generate these types and provide full optional/named parameter sugar. The compiler-generated types would be publicly nested within the type containing the method and named "[MemberName]Settings" by default.
This is better than callsite default value injection because:
- It versions well
- It adds a fixed amount of additional code (the type), whereas injection adds more code every time you use it
- It is CLS compliant
This is how C# 4 should do optional and named parameters.
Saturday, February 14, 2009
Generic Type Parameters AS Method Parameters
I have long had an interest in method contracts (pre- and post-conditions). I followed Spec# and I continue to follow the Pex project. I am also a big fan of doing argument verification at the highest possible level of a public API. I was working on a public API today which takes a Type object. My method looked like this:
It then occurred to me that I can do the same thing with a generic type parameter, but get all the checks for free!
Tada! Using generic type parameters as method parameters is nothing new (Aaron has something like this in the Banshee service stack), but the really neat thing is that you can use the generic constraints as a kind of argument pre-condition. If you have a method which takes a Type, consider using a generic type parameter rather than a method parameter. It guarantees that 'null' cannot be passed and it allows you to specify ancestry, interfaces, ref/value types, and the presence of a default constructor.
public string GetClassName (Type type) {
if (type == null) {
throw new ArugmentNullException ("type");
}
if (!type.IsSubclassOf (typeof (UpnpObject)) &&
type != typeof (UpnpObject)) {
throw new ArgumentException (
"The type does not derive from UpnpObject.",
"type");
}
// do stuff with 'type'
}
if (type == null) {
throw new ArugmentNullException ("type");
}
if (!type.IsSubclassOf (typeof (UpnpObject)) &&
type != typeof (UpnpObject)) {
throw new ArgumentException (
"The type does not derive from UpnpObject.",
"type");
}
// do stuff with 'type'
}
It then occurred to me that I can do the same thing with a generic type parameter, but get all the checks for free!
public string GetClassName<T> () where T : UpnpObject {
//do stuff with 'typeof (T)'
}
//do stuff with 'typeof (T)'
}
Tada! Using generic type parameters as method parameters is nothing new (Aaron has something like this in the Banshee service stack), but the really neat thing is that you can use the generic constraints as a kind of argument pre-condition. If you have a method which takes a Type, consider using a generic type parameter rather than a method parameter. It guarantees that 'null' cannot be passed and it allows you to specify ancestry, interfaces, ref/value types, and the presence of a default constructor.
Subscribe to:
Posts (Atom)