Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

Because this "unordered property" is often unexpected, problems can arise when programmers write code that compares floating point values without considering the semantics of NaN. For example, input validation checks that fail to consider the possibility of a NaN value as input may produce unexpected results.

Noncompliant Code Example

This noncompliant code example attempts a direct comparison with NaN. As per the semantics of NaN, all comparisons with NaN yield false (with the exception of the != operator, which returns true). Consequently, the comparison must always return false, and the "result is NaN" message is never printed.

Code Block
bgColor#FFcccc
public class NaNComparison {
  public static void main(String[] args) {
    double x = 0.0;
    double result = Math.cos(1/x); // returns NaN if input is infinity
    if (result == Double.NaN) { // comparison is always false!
      System.out.println("result is NaN");
    }
  }
}

Compliant Solution

This compliant solution uses the method Double.isNaN() to check whether the expression corresponds to a NaN value.

Code Block
bgColor#ccccff
public class NaNComparison {
  public static void main(String[] args) {
    double x = 0.0;	  
    double result = Math.cos(1/x); // returns NaN when input is infinity
    if (Double.isNaN(result)) { 
      System.out.println("result is NaN");
    }
  }
}

Risk Assessment

Comparisons with NaN values can lead to unexpected results.

Guideline

Severity

Likelihood

Remediation Cost

Priority

Level

FLP05-J

low

probable

medium

P4

L3

Automated Detection

Automated detection of floating point comparison operators is straightforward. Sound determination of whether the possibility of an unordered result has been correctly handled is not feasible in the general case. Heuristic checks could be useful.

Findbugs checks for the specific case of comparison with a constant NaN.

Related Vulnerabilities

Search for vulnerabilities resulting from the violation of this guideline on the CERT website.

Bibliography

Wiki Markup
\[[FindBugs 2008|AA. Bibliography#FindBugs 08]\] FE: Doomed test for equality to NaN
\[[JLS 2005|AA. Bibliography#JLS 05]\] [Section 4.2.3, Floating-Point Types, Formats, and Values|http://java.sun.com/docs/books/jls/third_edition/html/typesValues.html#4.2.3]

...