| 1 | /*
|
|---|
| 2 | Author: Yihao Yan
|
|---|
| 3 |
|
|---|
| 4 | See challenge 1 of: http://etaps2015.verifythis.org/challenges
|
|---|
| 5 |
|
|---|
| 6 | -----------------
|
|---|
| 7 | Problem description:
|
|---|
| 8 |
|
|---|
| 9 | Verify a function isRelaxedPrefix determining if a list _pat_ (for
|
|---|
| 10 | pattern) is a relaxed prefix of another list _a_.
|
|---|
| 11 |
|
|---|
| 12 | The relaxed prefix property holds iff _pat_ is a prefix of _a_ after
|
|---|
| 13 | removing at most one element from _pat_.
|
|---|
| 14 |
|
|---|
| 15 | examples:
|
|---|
| 16 | pat = {1,3} is a relaxed prefix of a = {1,3,2,3} (standard prefix)
|
|---|
| 17 | pat = {1,2,3} is a relaxed prefix of a = {1,3,2,3} (remove 2 from pat)
|
|---|
| 18 | pat = {1,2,4} is not a relaxed prefix of a = {1,3,2,3}.
|
|---|
| 19 |
|
|---|
| 20 | -----------------
|
|---|
| 21 | Verification Task:
|
|---|
| 22 |
|
|---|
| 23 | Implement the isRelaxedPrefix function which takes two arrays and their length
|
|---|
| 24 | as input and verify that it behaves as described.
|
|---|
| 25 |
|
|---|
| 26 | -----------------
|
|---|
| 27 | Result:
|
|---|
| 28 |
|
|---|
| 29 | For any array X1 with length less than 5 and any array X2 with length less than 4,
|
|---|
| 30 | function isRelaxedPrefix will tell if X1 can become a prefix of X2 by removing at
|
|---|
| 31 | most one element. Therefore, the isRelaxedPrefix behaves correctly.
|
|---|
| 32 |
|
|---|
| 33 | -----------------
|
|---|
| 34 | command: civl verify relaxedPrefix.c
|
|---|
| 35 |
|
|---|
| 36 | */
|
|---|
| 37 |
|
|---|
| 38 | #include <stdio.h>
|
|---|
| 39 | #include <stdbool.h>
|
|---|
| 40 | #include <civlc.cvh>
|
|---|
| 41 |
|
|---|
| 42 | $input int N1_BOUND = 4;
|
|---|
| 43 | $input int N2_BOUND = 3;
|
|---|
| 44 | $input int n1;
|
|---|
| 45 | $input int n2;
|
|---|
| 46 | $assume (n2>0 && n2 < N2_BOUND);
|
|---|
| 47 | $assume (n1>0 && n1 < N1_BOUND);
|
|---|
| 48 | $input int X2[n2];
|
|---|
| 49 | $input int X1[n1];
|
|---|
| 50 |
|
|---|
| 51 | bool isRelaxedPrefix(int* pat, int patLen, int* a, int aLen) {
|
|---|
| 52 | int shift = 0;
|
|---|
| 53 | int i;
|
|---|
| 54 |
|
|---|
| 55 | if(patLen > aLen+1) return false;
|
|---|
| 56 |
|
|---|
| 57 | if(aLen == 0) return true;
|
|---|
| 58 |
|
|---|
| 59 | for(i=0; i<patLen; i++) {
|
|---|
| 60 | if(pat[i] != a[i-shift]) {
|
|---|
| 61 | if(shift == 0)
|
|---|
| 62 | shift = 1;
|
|---|
| 63 | else
|
|---|
| 64 | return false;
|
|---|
| 65 | }
|
|---|
| 66 | if(i == aLen - 1 && shift == 0) return true;
|
|---|
| 67 | }
|
|---|
| 68 | return true;
|
|---|
| 69 | }
|
|---|
| 70 |
|
|---|
| 71 | void main() {
|
|---|
| 72 | bool result = isRelaxedPrefix(X1, n1, X2, n2);
|
|---|
| 73 |
|
|---|
| 74 | if(n1 > n2+1) {
|
|---|
| 75 | $assert(!result);
|
|---|
| 76 | } else if(n1 == n2+1) {
|
|---|
| 77 | $assert( result ==
|
|---|
| 78 | ($exists (int k: 0 .. n1-1)
|
|---|
| 79 | (
|
|---|
| 80 | ($forall (int i: 0 .. k-1) X1[i] == X2[i]) &&
|
|---|
| 81 | ($forall (int i: k+1 .. n1-1) X1[i] == X2[i-1])
|
|---|
| 82 | )
|
|---|
| 83 | )
|
|---|
| 84 | );
|
|---|
| 85 | } else {
|
|---|
| 86 | $assert(result ==
|
|---|
| 87 | ($exists (int k: 0 .. n1)
|
|---|
| 88 | (
|
|---|
| 89 | ($forall (int i: 0 .. k-1) X1[i] == X2[i]) &&
|
|---|
| 90 | ($forall (int i: k+1 .. n1-1) X1[i] == X2[i-1])
|
|---|
| 91 | )
|
|---|
| 92 | )
|
|---|
| 93 | );
|
|---|
| 94 | }
|
|---|
| 95 | }
|
|---|