-
Notifications
You must be signed in to change notification settings - Fork 260
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
fix: Fix CanCall assumptions for loop invariants (#1813)
The CanCall assumptions generated at the end of a loop body (to support the expressions in the loop invariant to be proved) were not generated correctly. In particular, when there are multiple invariant declarations, the CanCall assumptions were not given the right antecedents. (See issue #1812 for more details.) Fixes #1812
- Loading branch information
1 parent
49836a6
commit d740dc8
Showing
3 changed files
with
50 additions
and
4 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,37 @@ | ||
// RUN: %dafny "%s" > "%t" | ||
// RUN: %diff "%s.expect" "%t" | ||
|
||
function Max(s: set<int>): (m: int) | ||
requires s != {} | ||
{ | ||
var x :| x in s; | ||
if s == {x} then | ||
x | ||
else | ||
var s' := s - {x}; | ||
var y := Max(s'); | ||
y | ||
} | ||
|
||
method IncorrectLoop0(m: int) | ||
{ | ||
var r := {m}; | ||
while r != {} | ||
// Incorrectly generated CanCall assumptions for multiple invariant declarations | ||
// once caused the error on the next line to be omitted. | ||
invariant r != {} // error: loop invariant not maintained | ||
invariant m == Max(r) | ||
{ | ||
r := r - {m}; | ||
} | ||
} | ||
|
||
method IncorrectLoop1(m: int) | ||
{ | ||
var r := {m}; | ||
while r != {} | ||
invariant r != {} && m == Max(r) // error: loop invariant not maintained | ||
{ | ||
r := r - {m}; | ||
} | ||
} |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,6 @@ | ||
git-issue-1812.dfy(22,16): Error: This loop invariant might not be maintained by the loop. | ||
git-issue-1812.dfy(22,16): Related message: loop invariant violation | ||
git-issue-1812.dfy(33,16): Error: This loop invariant might not be maintained by the loop. | ||
git-issue-1812.dfy(33,16): Related message: loop invariant violation | ||
|
||
Dafny program verifier finished with 1 verified, 2 errors |