| Version 39 (modified by , 10 years ago) ( diff ) |
|---|
The CIVL-IR language. A program in this language is also known as a "CIVL model".
Properties of the language:
- the language is not intended to be written by humans; it is an intermediate form constructed by CIVL. However it should be readable to help debug things
- the language (and grammar) are subsets of CIVL-C
- a CIVL-IR program represents a guarded-transition system explicitly
- as in CIVL-C, there are functions, scopes, and functions can be defined in any scope
- all blocks (including a function body) consist of the following elements:
- a sequence of type definitions
- a sequence of variable declarations with no initializers
- a sequence of function definitions
- a sequence of labeled
$choosestatements. Each clause in the choose statement is a$whenstatement with some guard and a primitive statement, followed by agotostatement
- an array is declared without any length expression. When it is initialized it can specify length.
Can we specify that elements must appear in the order above? Or would that create a problem in something like
{
$integer x=3*y;
$integer a[x+1];
}
Example:
$integer f() {
$real x;
$real y;
$float(16,23) z;
L1 :
$choose {
$when (g1) stmt1; goto L2;
$when (g2) stmt2; goto L3;
}
{ // begin new scope
$real x;
L2 :
$choose {
$when (g3) stmt3; goto L4;
...
}
} // end new scope
...
}
// etc.
Types
The types are:
$bool: boolean type, values are$trueand$false$proc: process type$scope: scope type$char: character type. Alternatively, get rid of this and just use an integer type.$mem: type representing set of memory units$bundle: type representing some un-typed chunk of data$heap: heap type$range: ordered set of integers$domain: ordered set of tuples of integers$domain(n), n is an integer at least 1; subtype of above in which all tuples have arity n.
enumtypes.- different from integers or like C?
$integer: the mathematical integers$int(lo,hi,wrap)- lo, hi are integers, wrap is boolean
- finite interval of integers [lo,hi]. If
wrapis true then all operations "wrap", otherwise, any operation resulting in a value outside of the interval results in an exception being thrown. - Do we want to allow
loandhito be any values of type$integer, which means they are dynamic types, like complete array types?
$hint: Herbrand integers. Values are unsimplified symbolic expressions.$real: the mathematical real numbers$float(e,f), e, f are integers, each at least 1. Same question for e and f as for lo and hi.- IEEE754 floating point numbers
$hreal: Herbrand real numbers. Values are unsimplified symbolic expressions.struct(T1,...,Tn)- structure type with named fields. Names may not seem necessary but if you want a subset of CIVL-C...
- What about bit-widths?
union(T1,...,Tn): similar to structT[]: array-of-T- Function<S1,...,Sn;T>
- function consuming S1,...,Sn and returning T. T can be void. The actual notation is the horrible C notation.
void*: all pointersT*: pointer-to-T, subtype of above
Type facts:
Pure types contain no values anywhere in the type tree. That is, there is no array length expression in the type. The pure types are the static types of the CIVL-IR. Each variable is declared to have some pure type.
Augmented types include all the pure types plus possible length expressions.
A type name is a syntactic element that names a (pure or augmented) type Examples include int[] and int[n*m]. This is the same as in C.
The expression $initval(T) takes a type name and returns the initial value for an object of that type. The initial value of $integer and other primitive (non-compound) types is "undefined". The initial value of $integer[] is an array of length 0 of $integer. The initial value of $real* is the undefined pointer to $real. The initial value of $real[10] is the array of length 10 in which each element is undefined. In general, the initial value of an array of length n is the sequence of length n in which every element is the initial value of the element type of the array. The initial value of a structure is the tuple in which each component is assigned the initial value for its type.
Example:
// type definitions
struct S { int a[];}
// variable decls
int n;
struct S _S_init;
struct S x1;
struct S x2;
// statements (leaving out the chooses and whens for brevity)
n=10;
_S_init=$initval(struct S { int a[n]; };
x1=_S_init;
n=20;
x2=_S_init;
is semantically equivalent to the C code
int n = 10;
struct S { int a[n]; };
struct S x1;
n=20;
struct S x2;
Declarations
Declarations follow the C notation. Function prototypes are considered to be declarations similar to variable declarations.
Example of declaration of a function:
$integer f($real x, $bool y);
Additional modifiers that may be placed on any of above:
$pure: the function has no side effects, but may be nondeterministic$abstract: function is a pure, mathematical function: deterministic function of inputs$atomic_f: function definition is atomic, and there is it is never blocked
System functions:
- A function declaration which is not abstract and for which no definition is provided is a system function.
- If the system function is called anywhere in the program, it must be defined by providing Java code in an Enabler and Executor. Failure to do so will result in an exception.
- A system function may modify any memory it can reach. This includes allocating new data on heaps it can reach.
- A system function may have a guard.
Example of a declaration of a system function with guard.
$bool g($real x, $bool y) { ... }
$integer f($real x, $bool y) $guard {g};
Expressions
In the following list of expressions, e, e0, e1, etc., are expressions. T is a type name. t is an expression of type $type.
- literals
$true,$false: values of type$bool- 123, -123, 3.1415, etc. : values of type
$integer,$int,$real,$float- what particular notations for floating values?
- 'a', 'b', ... UNICODE?
(T[]){e0, e1, ...}: values of typeT[](S){e0, ...}: values of typeS(struct literal)e1..e2,e1..e2#e3: values of type$range($domain){r1,...,rn}: value of type$domain(n)"abc": string literals: value of type$char[]$root,$here: values of type$scope$self,$proc_null: values of type$procNULL: value of typevoid*
- variables
$sizeof(T): the size of the named type$sizeof(e): the size of the value of expressione$initval(T): initial value of the named type$defined(e): isedefined? Type is$bool$hasNextIn((i, j, k…), dom): an expression of boolean type, testing if the domaindomcontains any element after(i, j, k, ...)e1+e2: addition. One of the following must hold:e1ande2have the same numeric type. Note that there are no "automatic conversions" as there are in C. If the original expressions have different types, explicit casts must be inserted.e1has pointer type ande2has an integer type. (Alternatively, we could define a separate function$pointer_add(p,n).)
e1-e2: subtractione1*e2: multiplicatione1/e2: division- If both are integer types, the result is integer division. Otherwise it is real division. Need to define what happens for negative integers.
e1%e2: moduluse1[e2]: array subscript expression. Note thate1must have array type, not pointer type. (This is different from C.) Ife1has pointer type, use*(e1+e2)instead.*e: pointer dereference&e: address-of!e: logical not-e: negative- (T)e : casts
eto a value of the named type- need to list all of the legal casts and what they mean exactly
- cast of integer to array-of-boolean, and vice-versa?
e1==e2,e1!=e2e1&&e2,e1||e2e1?e2:e3e1<e2,e1<=e2e0(e1,...,en): pure function call?$forall,$exists: FILL INe1.i, some natural number i (tuple read)e1&e2,e1|e2,e1^e2,~e1: bit-wise operations: arguments are arrays of booleans- Memory set expressions: are these literal values of type
$mem?- could we use Frama-C notation
p+(e1..e2)for example? - are there conversions between pointers and mems?
- could we use Frama-C notation
Pointers: unlike C, there is no "array-pointer pun". If an array a needs to be converted to a pointer, you must use &a[0].
The Primitive Statements
- Assign:
e1=e2; - Call:
e0(e1,...,en);ande=e0(e1,...,en);- regular function (one with flow graph)
- function can be system, pure, abstract?
- Spawn:
$spawn e0(e1,...,en);ande=$spawn e0(e1,...,en); - Wait:
$wait(e); - Wailtall:
$waitall(e, n)whereeis the pointer to an array element andnis the number of processes to be waited for; - Allocation
e=$allocate(h,t,e);, wherehas type$heapthas type$typeehas integer type.
- Allocates
eobjects of typeton heaph - To translate the C
mallocyou first need to figure out the type of the elements being malloced. If the argument to malloc isn, then you first need to insert an assertionn%$sizeof(t)==0, and then$allocate(h,t,n/$sizeof(t)).
- Free:
free(p); - Expression statement:
e;, whereeis side effect free except that it might contain error/exception (e.g., array index out of bound, division by zero); - Noop:
;- Is there a need to add annotations for "true" or "false" branch, etc.? If so, we can just make these parameters to the Noop.
- Return:
return;andreturn e; - Atomic_enter:
$atomic_enter - Atomic_exit:
$atomic_exit - Parfor_spawn:
$parfor_spawn(int i,j,..: dom) f(i,j,...) - For_dom_enter (for domains):
$for_enter(i,j,k..: dom)
Contracts of Functions
- event set expressions:
EventSetExpression : $read(MemorySetExpression) | $write(MemorySetExpression) | $access(MemorySetExpression) | $calls(FunctionCallExpression) | $nothing | $everything | ‘(’ EventSetExpression ‘)’ | EventSetExpression + EventSetExpression | EventSetExpression - EventSetExpression | EventSetExpression & EventSetExpression
- depends clause:
$depends [condition] { event1, event2, ...}- Example:
$depends { $access(n) - ($calls(inc(MemorySetExpression)) + $calls(dec(MemorySetExpression))) } - absence of $depends clause:
- Example:
- assigns-or-reads clause
- assigns clause:
$assigns [condition] {memory-list} - reads clause:
$reads [condition] {memory-list} $reads {$nothing}implies$assigns {$nothing}$reads {$nothing}is equivalent to:$reads {$nothing} $assigns {$nothing}$assigns {X}whereX != $nothing, implies$reads {X}$assigns {X}is equivalent to:$assigns{X} $reads{X}- absence:
- absence of
$readsclause: there is no assumption about the read access of the function, i.e., the function could read anything - absence of
$assignsclause: similar to the absence of$readsclause
- absence of
$reads/$assigns {$nothing}doesn’t necessarily means that the function never reads or assigns any variable. The function could still reads/assigns its “local” variables, including function parameters and any variable declared inside the function body.
- assigns clause:
- For an independent function which has
$depends {$nothing}, usually we also need to specify$reads{nothing}, for the purpose of reachability analysis.
e.g.,
/* Returns the size of the given bundle b. */
int $bundle_size($bundle b)
$depends {$nothing}
$reads {$nothing}
;
- Example of a function declaration with contracts:
$atomic_f void sendRecv(int cmd, void*buf) $depends [cmd==SEND] {$write(buf)} $depends [cmd==RECV] {$access(*buf)} $assigns [cmd==SEND] {$nothing} $assigns [cmd==RECV] {*buf} $reads {*buf} { if(cmd == SEND){ send(*buf, ...); }else if(cmd==RECV){ *buf=recv(...); } }
Program Graph
Model
Semantics
Semantics issues
- define every possible cast
- define every possible +, etc.
- define every kind of pointer value and casts between pointer types
- casts between pointer and integer types?
