From: Piotr Trojanek <troja...@adacore.com> The existing precondition guarded against exception Dereference_Error, but not against Constraint_Error.
The RM rule B.3.1(36/3) only mentions Constraint_Error for the Value function which returns char_array, but the one which returns String has the same restriction, because it is equivalent to calling the variant which returns char_array and then converted. gcc/ada/ * libgnat/i-cstrin.ads (Value): Extend preconditions; adapt comment for the package. Tested on x86_64-pc-linux-gnu, committed on master. --- gcc/ada/libgnat/i-cstrin.ads | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/gcc/ada/libgnat/i-cstrin.ads b/gcc/ada/libgnat/i-cstrin.ads index e486f03a585..9f1577f5e14 100644 --- a/gcc/ada/libgnat/i-cstrin.ads +++ b/gcc/ada/libgnat/i-cstrin.ads @@ -36,8 +36,8 @@ -- Preconditions in this unit are meant for analysis only, not for run-time -- checking, so that the expected exceptions are raised. This is enforced by -- setting the corresponding assertion policy to Ignore. These preconditions --- protect from Dereference_Error and Update_Error, but not from --- Storage_Error. +-- protect from Constraint_Error, Dereference_Error and Update_Error, but not +-- from Storage_Error. pragma Assertion_Policy (Pre => Ignore); @@ -95,7 +95,7 @@ is (Item : chars_ptr; Length : size_t) return char_array with - Pre => Item /= Null_Ptr, + Pre => Item /= Null_Ptr and then Length /= 0, Global => (Input => C_Memory); function Value (Item : chars_ptr) return String with @@ -106,7 +106,7 @@ is (Item : chars_ptr; Length : size_t) return String with - Pre => Item /= Null_Ptr, + Pre => Item /= Null_Ptr and then Length /= 0, Global => (Input => C_Memory); function Strlen (Item : chars_ptr) return size_t with -- 2.40.0