gpu-handle-types 0.2.0

Typed, owned native GPU resource handles (Vulkan, D3D11/12, Metal, OpenGL, CUDA, OpenCL, DMA-BUF, IOSurface, AHardwareBuffer, WebGPU, ...), cross-API sync points and video pixel formats, for passing GPU resources between libraries.
Documentation
// SPDX-License-Identifier: MIT OR Apache-2.0
//
// `wait_deadline` totality (poll-loop deadline computation).
//
// The property under test: a `wait(timeout)` poll loop must never turn a BOUNDED
// wait into an unbounded hang. `Instant + Duration` overflows for a `timeout` near
// `Duration::MAX`, and a raw `Instant::now().checked_add(timeout)` returns `None`
// there — a `None` the poll loops read as "no deadline, wait forever". These pin
// that `None` encodes ONLY the explicit `Duration::MAX` wait-forever sentinel,
// never an accidental overflow.

use std::time::{Duration, Instant};

use gpu_handle_types::wait_deadline;

/// `Duration::MAX` is the `SyncWaiter::wait` contract's "wait forever" sentinel —
/// and the ONLY input that yields `None` (no deadline).
#[test]
fn duration_max_is_the_wait_forever_sentinel() {
    assert_eq!(wait_deadline(Duration::MAX), None, "Duration::MAX must map to the no-deadline (forever) sentinel");
}

/// A normal finite timeout yields a concrete, near-future deadline.
#[test]
fn finite_timeout_is_a_bounded_future_deadline() {
    let before = Instant::now();
    let deadline = wait_deadline(Duration::from_millis(50)).expect("a finite timeout has a deadline");
    assert!(deadline > before, "the deadline must be in the future");
    assert!(deadline <= before + Duration::from_secs(3600), "a 50 ms timeout must not produce a far-future deadline",);
}

/// The overflow case: a huge-but-finite timeout that OVERFLOWS `Instant + Duration`
/// must still yield a bounded `Some(_)` deadline — NOT `None` (which the poll loop
/// would treat as "wait forever") and NOT a panic.
#[test]
fn overflowing_finite_timeout_saturates_to_a_bounded_deadline() {
    // `Duration::from_secs(u64::MAX)` is strictly less than `Duration::MAX`
    // (`Duration::MAX` carries an extra ~1e9 ns), so it is NOT the forever
    // sentinel — yet `now + it` overflows the representable `Instant` range.
    let huge = Duration::from_secs(u64::MAX);
    assert_ne!(huge, Duration::MAX, "precondition: this input is not the forever sentinel");

    let before = Instant::now();
    let deadline =
        wait_deadline(huge).expect("an overflowing finite timeout must still be a bounded deadline, not None");
    assert!(deadline > before, "the saturated deadline is in the future");
    assert!(
        deadline <= before + Duration::from_secs(60 * 60 * 24 * 366),
        "the deadline must be clamped to the bounded saturation cap, not left effectively infinite",
    );
}