Skip to content

Contracts & Harnesses for byte_add, byte_offset, and byte_offset_from - #103

Merged
tautschnig merged 27 commits into
model-checking:mainfrom
danielhumanmod:daniel/byte_operation
Dec 3, 2024
Merged

tautschnig merged 27 commits into
model-checking:mainfrom
danielhumanmod:daniel/byte_operation

Conversation

@danielhumanmod

@danielhumanmod danielhumanmod commented Oct 5, 2024 •

Copy link
Copy Markdown

Description:

This PR introduces function contracts and proof harness for the NonNull pointer in the Rust core library. Specifically, it verifies three new APIs—byte_offset, byte_add, and byte_offset_from with Kani. These changes enhance the functionality of pointer arithmetic and verification for NonNull pointers.

Changes Overview:

Covered APIs:

  1. NonNull::byte_add: Adds a specified byte offset to a pointer.
  2. NonNull::byte_offset: Allows calculating an offset from a pointer in bytes.
  3. NonNull::byte_offset_from: Calculates the distance between two pointers in bytes.

Proof harness:

  1. non_null_byte_add_proof
  2. non_null_byte_offset_proof
  3. non_null_byte_offset_from_proof

Towards #53

By submitting this pull request, I confirm that my contribution is made under the terms of the Apache 2.0 and MIT licenses.

@danielhumanmod danielhumanmod changed the title Contracts & Harnesses for byte_add, byte_offset, and byte_offset_from Contracts & Harnesses for byte_add, byte_offset, and byte_offset_from Oct 6, 2024
@danielhumanmod
danielhumanmod marked this pull request as ready for review October 9, 2024 23:48
@danielhumanmod
danielhumanmod requested a review from a team as a code owner October 9, 2024 23:48
Comment thread library/core/src/ptr/non_null.rs Outdated
Comment thread library/core/src/ptr/non_null.rs Outdated
Comment thread library/core/src/ptr/non_null.rs Outdated
Comment thread library/core/src/ptr/non_null.rs Outdated
Comment thread library/core/src/ptr/non_null.rs Outdated
Comment thread library/core/src/ptr/non_null.rs Outdated
Comment thread library/core/src/ptr/non_null.rs Outdated
Comment thread library/core/src/ptr/non_null.rs Outdated
Comment thread library/core/src/ptr/non_null.rs Outdated
@danielhumanmod

Copy link
Copy Markdown
Author

Thanks for your suggestion @zhassan-aws! I've updated the code in the latest commit based on your comments. I’d appreciate it if you could take a look when you have a chance.

Comment thread library/core/src/ptr/non_null.rs Outdated
Comment thread library/core/src/ptr/non_null.rs Outdated
Comment thread library/core/src/ptr/non_null.rs Outdated
Comment thread library/core/src/ptr/non_null.rs
Comment thread library/core/src/ptr/non_null.rs Outdated
Comment thread library/core/src/ptr/non_null.rs Outdated
Comment thread library/core/src/ptr/non_null.rs Outdated
Comment thread library/core/src/ptr/non_null.rs Outdated
@danielhumanmod

Copy link
Copy Markdown
Author

Hi @zhassan-aws , thanks for the review and suggestions. I have updated the code based on the comments, fix the unnecessary assume proof harness, using addr, and add unchecked_add to avoid overflow, appreciate if any further suggestion!

@zhassan-aws zhassan-aws left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Nice. Thanks!

Comment thread library/core/src/ptr/non_null.rs Outdated
Comment thread library/core/src/ptr/non_null.rs Outdated

@celinval celinval left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Please replace kani::requires and kani::ensures by safety::requires and safety::ensures. Thanks!

Comment thread library/core/src/ptr/non_null.rs Outdated
Comment thread library/core/src/ptr/non_null.rs Outdated
Comment thread library/core/src/ptr/non_null.rs Outdated
Comment thread library/core/src/ptr/non_null.rs Outdated
Comment thread library/core/src/ptr/non_null.rs Outdated
Comment thread library/core/src/ptr/non_null.rs Outdated
Comment thread library/core/src/ptr/non_null.rs Outdated

@celinval celinval left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks good. Can you please add harnesses for the dangling pointers cases?

Comment thread library/core/src/ptr/non_null.rs
Comment thread library/core/src/ptr/non_null.rs Outdated
Comment thread library/core/src/ptr/non_null.rs Outdated
@feliperodri

Copy link
Copy Markdown
Member

@danielhumanmod could you resolve the conflicts?

@danielhumanmod

Copy link
Copy Markdown
Author

@danielhumanmod could you resolve the conflicts?

Hi @feliperodri , I have solved the conflicts in latest commit, thanks for reminding that

@danielhumanmod

Copy link
Copy Markdown
Author

Thanks for the clarification @zhassan-aws ! I have updated the code based on the comments, appreciate any further or review that might need @zhassan-aws @celinval

@zhassan-aws zhassan-aws left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks!

Comment thread library/core/src/ptr/non_null.rs
@tautschnig
tautschnig merged commit 892ee59 into model-checking:main Dec 3, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants