Commit 3ce7307
committed
Revamp function contracts interface
This commit adds four new flags to goto-instrument that allow CBMC to
check or take advantage of function contracts in the target codebase.
It prepares for a series of commits that will improve the soundness of
this functionality and add support for loop invariants.
The motivation behind this patch series is to improve scalability of
code verification. Given the following code:
foo()
__CPROVER_ensures(P)
__CPROVER_ensures(Q)
{ ... }
bar()
{
foo();
}
the user can pass `--replace-call-with-contract foo` to goto-instrument,
which will change the body of `bar` so that it can be verified more
scalably:
bar()
{
assert(P);
assume(Q);
}
The user should then separately pass `--enforce-contract foo` to
goto-instrument. This instruments `foo` so that it looks like this:
foo()
{
assume(P);
// original body
assert(Q);
}
Running `cbmc --function foo` on the instrumented binary then checks
that `foo` actually abides by its contract, regardless of its calling
context.
Users can also pass `--enforce-all-contracts` and
`--replace-all-calls-with-contracts` to avoid naming every function.1 parent dbac963 commit 3ce7307
File tree
15 files changed
+384
-87
lines changed- regression/contracts
- function_apply_01
- function_check_01
- function_check_04
- function_no_apply_01
- invar_check_01
- invar_check_02
- invar_check_03
- invar_check_04
- src/goto-instrument
15 files changed
+384
-87
lines changed| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
1 | 1 | | |
2 | | - | |
| 2 | + | |
3 | 3 | | |
4 | | - | |
| 4 | + | |
5 | 5 | | |
6 | 6 | | |
7 | 7 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
6 | 6 | | |
7 | 7 | | |
8 | 8 | | |
9 | | - | |
10 | | - | |
| 9 | + | |
11 | 10 | | |
12 | 11 | | |
13 | 12 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
1 | | - | |
| 1 | + | |
2 | 2 | | |
3 | | - | |
| 3 | + | |
4 | 4 | | |
5 | 5 | | |
6 | 6 | | |
7 | 7 | | |
| 8 | + | |
8 | 9 | | |
9 | | - | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
1 | | - | |
| 1 | + | |
2 | 2 | | |
3 | 3 | | |
4 | 4 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
1 | | - | |
| 1 | + | |
2 | 2 | | |
3 | 3 | | |
4 | 4 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
| 18 | + | |
| 19 | + | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
1 | | - | |
| 1 | + | |
2 | 2 | | |
3 | 3 | | |
4 | 4 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
1 | | - | |
| 1 | + | |
2 | 2 | | |
3 | 3 | | |
4 | 4 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
1 | | - | |
| 1 | + | |
2 | 2 | | |
3 | 3 | | |
4 | 4 | | |
| |||
0 commit comments