solidity/libsmtutil/SMTLib2Interface.cpp

376 lines
11 KiB
C++
Raw Permalink Normal View History

2017-07-10 16:13:38 +00:00
/*
This file is part of solidity.
solidity is free software: you can redistribute it and/or modify
it under the terms of the GNU General Public License as published by
the Free Software Foundation, either version 3 of the License, or
(at your option) any later version.
solidity is distributed in the hope that it will be useful,
but WITHOUT ANY WARRANTY; without even the implied warranty of
MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
GNU General Public License for more details.
You should have received a copy of the GNU General Public License
along with solidity. If not, see <http://www.gnu.org/licenses/>.
*/
// SPDX-License-Identifier: GPL-3.0
2017-07-10 16:13:38 +00:00
2020-05-18 15:42:24 +00:00
#include <libsmtutil/SMTLib2Interface.h>
2017-07-10 16:13:38 +00:00
2023-08-11 16:00:22 +00:00
#include <libsmtutil/SMTLibParser.h>
#include <libsolutil/Keccak256.h>
2017-07-10 19:21:11 +00:00
#include <boost/algorithm/string/join.hpp>
2018-12-17 17:26:10 +00:00
#include <boost/algorithm/string/predicate.hpp>
2017-07-10 19:21:11 +00:00
2021-05-18 17:12:06 +00:00
#include <range/v3/algorithm/find_if.hpp>
2018-12-17 17:26:10 +00:00
#include <array>
2017-07-10 19:21:11 +00:00
#include <fstream>
#include <iostream>
#include <memory>
#include <stdexcept>
2020-04-03 13:10:16 +00:00
#include <string>
2020-04-01 03:04:29 +00:00
#include <utility>
2017-07-10 19:21:11 +00:00
2019-12-11 16:31:36 +00:00
using namespace solidity;
using namespace solidity::util;
using namespace solidity::frontend;
2020-05-19 12:14:46 +00:00
using namespace solidity::smtutil;
2017-07-10 16:13:38 +00:00
SMTLib2Interface::SMTLib2Interface(
2023-07-15 12:56:18 +00:00
[[maybe_unused]] std::map<h256, std::string> _queryResponses,
2020-11-02 20:20:20 +00:00
ReadCallback::Callback _smtCallback,
2023-06-26 08:31:02 +00:00
SMTSolverChoice _enabledSolvers,
std::optional<unsigned> _queryTimeout
):
2020-11-02 20:20:20 +00:00
SolverInterface(_queryTimeout),
2023-06-26 08:31:02 +00:00
m_smtCallback(std::move(_smtCallback)),
m_enabledSolvers(_enabledSolvers)
2017-07-10 19:21:11 +00:00
{
reset();
}
void SMTLib2Interface::reset()
{
m_accumulatedOutput.clear();
m_accumulatedOutput.emplace_back();
m_variables.clear();
2020-04-03 13:10:16 +00:00
m_userSorts.clear();
m_sortNames.clear();
2017-07-11 11:26:43 +00:00
write("(set-option :produce-models true)");
2020-11-02 20:20:20 +00:00
if (m_queryTimeout)
write("(set-option :timeout " + std::to_string(*m_queryTimeout) + ")");
write("(set-logic ALL)");
2017-07-10 19:21:11 +00:00
}
void SMTLib2Interface::push()
{
m_accumulatedOutput.emplace_back();
}
void SMTLib2Interface::pop()
{
2020-05-19 12:52:31 +00:00
smtAssert(!m_accumulatedOutput.empty(), "");
2017-07-10 19:21:11 +00:00
m_accumulatedOutput.pop_back();
}
void SMTLib2Interface::declareVariable(std::string const& _name, SortPointer const& _sort)
2017-07-10 19:21:11 +00:00
{
2020-05-19 12:52:31 +00:00
smtAssert(_sort, "");
2019-09-24 15:35:31 +00:00
if (_sort->kind == Kind::Function)
declareFunction(_name, _sort);
else if (!m_variables.count(_name))
{
2019-09-24 15:35:31 +00:00
m_variables.emplace(_name, _sort);
write("(declare-fun |" + _name + "| () " + toSmtLibSort(_sort) + ')');
}
}
void SMTLib2Interface::declareFunction(std::string const& _name, SortPointer const& _sort)
{
2020-05-19 12:52:31 +00:00
smtAssert(_sort, "");
smtAssert(_sort->kind == Kind::Function, "");
2018-04-17 21:46:53 +00:00
// TODO Use domain and codomain as key as well
if (!m_variables.count(_name))
2018-04-17 21:46:53 +00:00
{
auto const& fSort = std::dynamic_pointer_cast<FunctionSort>(_sort);
std::string domain = toSmtLibSort(fSort->domain);
std::string codomain = toSmtLibSort(fSort->codomain);
2019-09-24 15:35:31 +00:00
m_variables.emplace(_name, _sort);
2018-04-17 21:46:53 +00:00
write(
"(declare-fun |" +
_name +
"| " +
domain +
" " +
codomain +
2018-04-17 21:46:53 +00:00
")"
);
}
2017-07-10 19:21:11 +00:00
}
2020-05-19 12:14:46 +00:00
void SMTLib2Interface::addAssertion(Expression const& _expr)
2017-07-10 19:21:11 +00:00
{
2017-07-13 16:22:51 +00:00
write("(assert " + toSExpr(_expr) + ")");
2017-07-10 19:21:11 +00:00
}
2023-07-21 15:14:29 +00:00
namespace // Helpers for querying solvers using SMT callback
{
auto resultFromSolverResponse (std::string const& response) {
CheckResult result;
// TODO proper parsing
2023-06-26 14:38:59 +00:00
if (boost::starts_with(response, "sat"))
result = CheckResult::SATISFIABLE;
2023-06-26 14:38:59 +00:00
else if (boost::starts_with(response, "unsat"))
result = CheckResult::UNSATISFIABLE;
2023-06-26 14:38:59 +00:00
else if (boost::starts_with(response, "unknown"))
result = CheckResult::UNKNOWN;
else
result = CheckResult::ERROR;
return result;
}
bool solverAnswered(CheckResult result)
{
return result == CheckResult::SATISFIABLE || result == CheckResult::UNSATISFIABLE;
}
2023-08-11 16:00:22 +00:00
std::vector<std::string> parseValues(std::string const& solverAnswer)
{
2023-08-11 16:00:22 +00:00
std::vector<std::string> parsedValues;
std::stringstream ss(solverAnswer);
std::string answer;
ss >> answer;
solAssert(answer == "sat");
SMTLib2Parser parser(ss);
if (parser.isEOF())
return parsedValues;
auto values = parser.parseExpression();
solAssert(!isAtom(values));
auto const& valuesExpr = asSubExpressions(values);
for (auto const& valueExpr: valuesExpr)
{
2023-08-11 16:00:22 +00:00
solAssert(!isAtom(valueExpr));
auto const& nameValuePair = asSubExpressions(valueExpr);
solAssert(nameValuePair.size() == 2);
parsedValues.push_back(nameValuePair[1].toString());
}
2023-08-11 16:00:22 +00:00
return parsedValues;
}
}
std::pair<CheckResult, std::vector<std::string>> SMTLib2Interface::check(std::vector<Expression> const& _expressionsToEvaluate)
2017-07-10 19:21:11 +00:00
{
2023-07-21 15:14:29 +00:00
auto query = boost::algorithm::join(m_accumulatedOutput, "\n") + checkSatAndGetValuesCommand(_expressionsToEvaluate);
std::vector<std::string> solverCommands;
if (m_enabledSolvers.z3)
2023-08-16 22:26:13 +00:00
solverCommands.emplace_back("z3 -in rlimit=1000000");
if (m_enabledSolvers.cvc4)
2023-08-16 22:26:13 +00:00
solverCommands.emplace_back("cvc4 --lang smtlib2.6 --output-lang smtlib2.6");
CheckResult lastResult = CheckResult::ERROR;
2023-07-15 12:56:18 +00:00
std::vector<std::string> finalValues;
smtAssert(m_smtCallback);
for (auto const& s: solverCommands)
{
2023-08-16 22:26:13 +00:00
auto callBackResult = m_smtCallback(ReadCallback::kindString(ReadCallback::Kind::SMTQuery) + ":" + s, query);
if (not callBackResult.success)
continue;
auto const& response = callBackResult.responseOrErrorMessage;
CheckResult result = resultFromSolverResponse(response);
if (solverAnswered(result))
{
if (!solverAnswered(lastResult))
{
lastResult = result;
if (result == CheckResult::SATISFIABLE)
finalValues = parseValues(response);
}
else if (lastResult != result)
{
lastResult = CheckResult::CONFLICTING;
break;
}
}
else if (result == CheckResult::UNKNOWN && lastResult == CheckResult::ERROR)
lastResult = result;
}
2023-07-21 15:14:29 +00:00
if (lastResult == CheckResult::ERROR)
m_unhandledQueries.push_back(query);
return std::make_pair(lastResult, finalValues);
2017-07-10 19:21:11 +00:00
}
std::string SMTLib2Interface::toSExpr(Expression const& _expr)
2017-07-13 16:22:51 +00:00
{
if (_expr.arguments.empty())
return _expr.name;
std::string sexpr = "(";
2020-05-13 11:08:48 +00:00
if (_expr.name == "int2bv")
{
size_t size = std::stoul(_expr.arguments[1].name);
2020-05-13 11:08:48 +00:00
auto arg = toSExpr(_expr.arguments.front());
auto int2bv = "(_ int2bv " + std::to_string(size) + ")";
2020-05-13 11:08:48 +00:00
// Some solvers treat all BVs as unsigned, so we need to manually apply 2's complement if needed.
sexpr += std::string("ite ") +
2020-05-13 11:08:48 +00:00
"(>= " + arg + " 0) " +
"(" + int2bv + " " + arg + ") " +
"(bvneg (" + int2bv + " (- " + arg + ")))";
}
else if (_expr.name == "bv2int")
{
auto intSort = std::dynamic_pointer_cast<IntSort>(_expr.sort);
2020-05-13 11:08:48 +00:00
smtAssert(intSort, "");
auto arg = toSExpr(_expr.arguments.front());
auto nat = "(bv2nat " + arg + ")";
if (!intSort->isSigned)
return nat;
auto bvSort = std::dynamic_pointer_cast<BitVectorSort>(_expr.arguments.front().sort);
2020-05-13 11:08:48 +00:00
smtAssert(bvSort, "");
auto size = std::to_string(bvSort->size);
auto pos = std::to_string(bvSort->size - 1);
2020-05-13 11:08:48 +00:00
// Some solvers treat all BVs as unsigned, so we need to manually apply 2's complement if needed.
sexpr += std::string("ite ") +
2020-05-13 11:08:48 +00:00
"(= ((_ extract " + pos + " " + pos + ")" + arg + ") #b0) " +
nat + " " +
2021-05-18 21:01:13 +00:00
"(- (bv2nat (bvneg " + arg + ")))";
2020-05-13 11:08:48 +00:00
}
else if (_expr.name == "const_array")
{
2020-05-19 12:52:31 +00:00
smtAssert(_expr.arguments.size() == 2, "");
auto sortSort = std::dynamic_pointer_cast<SortSort>(_expr.arguments.at(0).sort);
2020-05-19 12:52:31 +00:00
smtAssert(sortSort, "");
auto arraySort = std::dynamic_pointer_cast<ArraySort>(sortSort->inner);
2020-05-19 12:52:31 +00:00
smtAssert(arraySort, "");
sexpr += "(as const " + toSmtLibSort(arraySort) + ") ";
sexpr += toSExpr(_expr.arguments.at(1));
}
2020-04-03 13:10:16 +00:00
else if (_expr.name == "tuple_get")
{
2020-05-19 12:52:31 +00:00
smtAssert(_expr.arguments.size() == 2, "");
auto tupleSort = std::dynamic_pointer_cast<TupleSort>(_expr.arguments.at(0).sort);
size_t index = std::stoul(_expr.arguments.at(1).name);
2020-05-19 12:52:31 +00:00
smtAssert(index < tupleSort->members.size(), "");
2020-04-14 09:09:38 +00:00
sexpr += "|" + tupleSort->members.at(index) + "| " + toSExpr(_expr.arguments.at(0));
}
else if (_expr.name == "tuple_constructor")
{
auto tupleSort = std::dynamic_pointer_cast<TupleSort>(_expr.sort);
2020-05-19 12:52:31 +00:00
smtAssert(tupleSort, "");
2020-04-14 09:09:38 +00:00
sexpr += "|" + tupleSort->name + "|";
for (auto const& arg: _expr.arguments)
sexpr += " " + toSExpr(arg);
2020-04-03 13:10:16 +00:00
}
else
{
sexpr += _expr.name;
for (auto const& arg: _expr.arguments)
sexpr += " " + toSExpr(arg);
}
2017-07-13 16:22:51 +00:00
sexpr += ")";
return sexpr;
}
std::string SMTLib2Interface::toSmtLibSort(SortPointer _sort)
{
if (!m_sortNames.count(_sort))
{
auto smtLibName = sortToString(*_sort);
m_sortNames[_sort] = smtLibName;
}
return m_sortNames.at(_sort);
}
std::string SMTLib2Interface::sortToString(Sort const& _sort)
{
switch (_sort.kind)
{
case Kind::Int:
return "Int";
case Kind::Bool:
return "Bool";
2020-05-11 17:56:29 +00:00
case Kind::BitVector:
return "(_ BitVec " + std::to_string(dynamic_cast<BitVectorSort const&>(_sort).size) + ")";
case Kind::Array:
{
auto const& arraySort = dynamic_cast<ArraySort const&>(_sort);
2020-05-19 12:52:31 +00:00
smtAssert(arraySort.domain && arraySort.range, "");
return "(Array " + toSmtLibSort(arraySort.domain) + ' ' + toSmtLibSort(arraySort.range) + ')';
}
2020-04-03 13:10:16 +00:00
case Kind::Tuple:
{
auto const& tupleSort = dynamic_cast<TupleSort const&>(_sort);
std::string tupleName = "|" + tupleSort.name + "|";
2021-05-18 17:12:06 +00:00
auto isName = [&](auto entry) { return entry.first == tupleName; };
if (ranges::find_if(m_userSorts, isName) == m_userSorts.end())
2020-04-03 13:10:16 +00:00
{
std::string decl("(declare-datatypes ((" + tupleName + " 0)) (((" + tupleName);
2020-05-19 12:52:31 +00:00
smtAssert(tupleSort.members.size() == tupleSort.components.size(), "");
2020-04-03 13:10:16 +00:00
for (unsigned i = 0; i < tupleSort.members.size(); ++i)
decl += " (|" + tupleSort.members.at(i) + "| " + toSmtLibSort(tupleSort.components.at(i)) + ")";
2020-04-03 13:10:16 +00:00
decl += "))))";
2021-05-18 17:12:06 +00:00
m_userSorts.emplace_back(tupleName, decl);
2020-04-03 13:10:16 +00:00
write(decl);
}
2020-04-14 09:09:38 +00:00
return tupleName;
2020-04-03 13:10:16 +00:00
}
default:
2020-05-19 12:52:31 +00:00
smtAssert(false, "Invalid SMT sort");
}
}
std::string SMTLib2Interface::toSmtLibSort(std::vector<SortPointer> const& _sorts)
{
std::string ssort("(");
for (auto const& sort: _sorts)
ssort += toSmtLibSort(sort) + " ";
ssort += ")";
return ssort;
}
void SMTLib2Interface::write(std::string _data)
2017-07-10 19:21:11 +00:00
{
2020-05-19 12:52:31 +00:00
smtAssert(!m_accumulatedOutput.empty(), "");
2022-08-23 17:28:45 +00:00
m_accumulatedOutput.back() += std::move(_data) + "\n";
2017-07-10 19:21:11 +00:00
}
std::string SMTLib2Interface::checkSatAndGetValuesCommand(std::vector<Expression> const& _expressionsToEvaluate)
2017-07-10 19:21:11 +00:00
{
std::string command;
2017-07-11 11:26:43 +00:00
if (_expressionsToEvaluate.empty())
command = "(check-sat)\n";
else
{
// TODO make sure these are unique
for (size_t i = 0; i < _expressionsToEvaluate.size(); i++)
{
auto const& e = _expressionsToEvaluate.at(i);
2020-05-19 12:52:31 +00:00
smtAssert(e.sort->kind == Kind::Int || e.sort->kind == Kind::Bool, "Invalid sort for expression to evaluate.");
command += "(declare-const |EVALEXPR_" + std::to_string(i) + "| " + (e.sort->kind == Kind::Int ? "Int" : "Bool") + ")\n";
command += "(assert (= |EVALEXPR_" + std::to_string(i) + "| " + toSExpr(e) + "))\n";
2017-07-11 11:26:43 +00:00
}
command += "(check-sat)\n";
command += "(get-value (";
for (size_t i = 0; i < _expressionsToEvaluate.size(); i++)
command += "|EVALEXPR_" + std::to_string(i) + "| ";
2017-07-11 11:26:43 +00:00
command += "))\n";
}
return command;
2017-07-10 19:21:11 +00:00
}
std::string SMTLib2Interface::dumpQuery(std::vector<Expression> const& _expressionsToEvaluate)
{
return boost::algorithm::join(m_accumulatedOutput, "\n") +
checkSatAndGetValuesCommand(_expressionsToEvaluate);
}