-
Notifications
You must be signed in to change notification settings - Fork 47
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Proposal: Globals (pre-cursor to Compilation Units) #30
base: master
Are you sure you want to change the base?
Changes from 4 commits
6b118a3
4dd974a
ae9de05
bafffad
c8c1d75
8e9acb2
2ad2788
dd1f540
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,107 @@ | ||
Require Import Coq.Strings.String. | ||
Require Import Coq.ZArith.BinIntDef. | ||
Require Import ExtLib.Data.HList. | ||
Require Import ExtLib.Data.Fin. | ||
Require Import ExtLib.Data.Map.FMapAList. | ||
Require Import bedrock2.Macros bedrock2.Notations bedrock2.Map. | ||
Require Import bedrock2.Syntax. | ||
Require Import bedrock2.Semantics. | ||
|
||
(* Compilation units should be fairly simple | ||
* - the basic idea is that you have "externals", "internals", and "exports" | ||
* - definitions can call externals and internals | ||
* - exports must be a subset of external and internal | ||
* - in the module-level semantics, one type of interaction needs to be | ||
* external call. | ||
* - note(gmm): we don't have to support recursive linking if we want to keep | ||
* the terminating semantics. | ||
*) | ||
|
||
Module module. | ||
Section with_parameters. | ||
Context {p : Syntax.parameters}. | ||
|
||
Variant data : Set := | ||
| Data (_ : list Z). | ||
|
||
Variant definition : Type := | ||
| X (_ : list data) | ||
| Function (_ : list varname * list varname * Syntax.cmd). | ||
|
||
|
||
(* note(gmm): this could be made more uniform with the rest of the development | ||
* if we used `map`. | ||
*) | ||
Record module : Type := | ||
{ imports : list globname | ||
; internal : list globname | ||
; exports : list globname | ||
; definitions : list (globname * definition) | ||
}. | ||
|
||
End with_parameters. | ||
End module. | ||
|
||
(* the meaning of a module is a function of the meaning of the imports to the | ||
* meaning of the outputs. | ||
* note(gmm): an alternative way to represent this to treat calls to imports | ||
* as actions. | ||
*) | ||
|
||
Require Import bedrock2.WeakestPrecondition. | ||
|
||
Section module_semantics. | ||
Variable p : Semantics.parameters. | ||
Variable resolver : globname -> option word. | ||
|
||
Definition func_meaning : Type := | ||
(trace -> Prop) -> | ||
(trace -> Prop) -> | ||
(trace -> trace -> Prop) -> | ||
trace -> | ||
mem -> | ||
list word -> | ||
(trace -> mem -> list word -> Prop) -> Prop. | ||
|
||
Variables (mod : module.module) | ||
(denoteImports : globname -> func_meaning). | ||
|
||
Definition functions : list _ := | ||
(fix functions ls := | ||
match ls with | ||
| nil => nil | ||
| cons (a, module.Function b) ls => | ||
match resolver a with | ||
| Some a => cons (a,b) (functions ls) | ||
| None => functions ls | ||
end | ||
| cons _ ls => functions ls | ||
end) mod.(module.definitions). | ||
|
||
Definition module_definitions (g : globname) | ||
: func_meaning. | ||
refine (fun rely guarantee progress t mem args post => | ||
exists body, List.In (g, body) mod.(module.definitions) /\ | ||
match body with | ||
| module.Function body => | ||
exists n, | ||
WeakestPrecondition.func rely guarantee progress resolver | ||
(fun w t mem args post => | ||
exists g, resolver g = Some w /\ | ||
(List.In g mod.(module.imports) /\ | ||
denoteImports g rely guarantee progress t mem args post) | ||
\/ call_rec rely guarantee progress resolver | ||
functions n w t mem args post) | ||
body | ||
t mem args post | ||
| _ => False | ||
end). | ||
Defined. | ||
|
||
Definition module (g : globname) | ||
: func_meaning := | ||
fun rely guarantee progress t mem args post => | ||
List.In g mod.(module.exports) /\ | ||
module_definitions g rely guarantee progress t mem args post. | ||
|
||
End module_semantics. |
Original file line number | Diff line number | Diff line change |
---|---|---|
|
@@ -5,6 +5,7 @@ Require Import Coq.ZArith.BinIntDef. | |
Section WeakestPrecondition. | ||
Context {p : unique! Semantics.parameters}. | ||
Context (rely guarantee : trace -> Prop) (progress : trace -> trace -> Prop). | ||
Variable resolver : globname -> option word. | ||
|
||
Definition literal v post : Prop := | ||
bind_ex_Some v <- word_of_Z v; post v. | ||
|
@@ -23,6 +24,8 @@ Section WeakestPrecondition. | |
literal v post | ||
| expr.var x => | ||
get l x post | ||
| expr.global g => | ||
bind_ex_Some v <- resolver g ; post v | ||
| expr.op op e1 e2 => | ||
expr e1 (fun v1 => | ||
expr e2 (fun v2 => | ||
|
@@ -46,7 +49,7 @@ Section WeakestPrecondition. | |
End WithF. | ||
|
||
Section WithFunctions. | ||
Context (call : funname -> trace -> mem -> list word -> (trace -> mem -> list word -> Prop) -> Prop). | ||
Context (call : word -> trace -> mem -> list word -> (trace -> mem -> list word -> Prop) -> Prop). | ||
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more.
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. It is abstract, in this version of the semantics you don't call a There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Further clarification. The There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. It wouldn't be difficult to remove this functionality (just don't allow calling expressions), if that is truly desireable. This seems like an easy way to support function pointers within the "be concrete" mantra of bedrock2. There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. I'd like to be able to use the file |
||
Fixpoint cmd (c : cmd) (t : trace) (m : mem) (l : locals) | ||
(post : trace -> mem -> locals -> Prop) {struct c} : Prop := | ||
match c with | ||
|
@@ -67,19 +70,20 @@ Section WeakestPrecondition. | |
| cmd.seq c1 c2 => | ||
cmd c1 t m l (fun t m l => cmd c2 t m l post) | ||
| cmd.while e c => | ||
exists measure (lt:measure->measure->Prop) (inv:measure->trace->mem->locals->Prop), | ||
exists measure (lt:measure->measure->Prop) (inv:measure->trace->mem->locals->Prop), | ||
Coq.Init.Wf.well_founded lt /\ | ||
(exists v, inv v t m l) /\ | ||
(forall v t m l, inv v t m l -> | ||
expr m l e (fun b => | ||
(word_test b = true -> cmd c t m l (fun t' m l => | ||
exists v', inv v' t' m l /\ (progress t' t \/ lt v' v))) /\ | ||
(word_test b = false -> post t m l))) | ||
| cmd.call binds fname arges => | ||
| cmd.call binds f arges => | ||
list_map (expr m l) arges (fun args => | ||
expr m l f (fun fname => | ||
call fname t m args (fun t m rets => | ||
bind_ex_Some l <- map.putmany binds rets l; | ||
post t m l)) | ||
post t m l))) | ||
| cmd.interact binds action arges => | ||
list_map (expr m l) arges (fun args => | ||
let output := (m, action, args) in | ||
|
@@ -89,22 +93,66 @@ Section WeakestPrecondition. | |
end. | ||
End WithFunctions. | ||
|
||
Definition func call '(innames, outnames, c) (t : trace) (m : mem) (args : list word) (post : trace -> mem -> list word -> Prop) := | ||
Section list_lookup. | ||
Context {A B : Type} (eqA : A -> A -> bool) (key : A). | ||
Fixpoint list_lookup (ls : list (A * B)) : option B := | ||
match ls with | ||
| nil => None | ||
| cons (key', val) ls => | ||
if eqA key key' then Some val | ||
else list_lookup ls | ||
end. | ||
End list_lookup. | ||
|
||
Definition func call '(innames, outnames, c) | ||
(t : trace) (m : mem) (args : list word) | ||
(post : trace -> mem -> list word -> Prop) := | ||
bind_ex_Some l <- map.putmany innames args map.empty; | ||
cmd call c t m l (fun t m l => | ||
list_map (get l) outnames (fun rets => | ||
post t m rets)). | ||
|
||
Fixpoint call (functions : list (funname * (list varname * list varname * cmd.cmd))) | ||
(fname : funname) (t : trace) (m : mem) (args : list word) | ||
(post : trace -> mem -> list word -> Prop) {struct functions} : Prop := | ||
|
||
Section rec. | ||
Variable (functions : list (word * (list varname * list varname * cmd.cmd))). | ||
|
||
(* This definition allows for recursive functions using step-indexing. | ||
* | ||
* note(gmm): using this definition, you would likely write something like: | ||
* `forall n, func (call_rec (3 + n)) ...` which would allow you to make | ||
* calls to functions that have a call depth of at most 3. | ||
* This is equivalent to the previous definition is you use the length | ||
* of the rest of the list. | ||
* in general, the `n` could be dependent (relationally or functionally) | ||
* on both the arguments to the function and the heap. | ||
*) | ||
Fixpoint call_rec (n : nat) | ||
(fname : word) (t : trace) (m : mem) (args : list word) | ||
(post : trace -> mem -> list word -> Prop) {struct n} : Prop := | ||
match n with | ||
| 0 => False | ||
| S n => | ||
match list_lookup word_eqb fname functions with | ||
| None => False | ||
| Some decl => func (call_rec n) decl t m args post | ||
end | ||
end. | ||
|
||
(* note(gmm): `call_rec` is monotone in `n` *) | ||
|
||
End rec. | ||
|
||
Fixpoint call | ||
(functions : list (word * (list varname * list varname * cmd.cmd))) | ||
(fname : word) (t : trace) (m : mem) (args : list word) | ||
(post : trace -> mem -> list word -> Prop) {struct functions} : Prop := | ||
match functions with | ||
| nil => False | ||
| cons (f, decl) functions => | ||
if funname_eqb f fname | ||
if word_eqb f fname | ||
then func (call functions) decl t m args post | ||
else call functions fname t m args post | ||
end. | ||
|
||
Definition program funcs main t m l post : Prop := cmd (call funcs) main t m l post. | ||
Definition program funcs main t m l post : Prop := | ||
cmd (call funcs) main t m l post. | ||
End WeakestPrecondition. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
looks like these
ExtLib
dependencies are not needed (but make the build fail)