solidity/libsolidity/formal/SMTEncoder.h

380 lines
16 KiB
C
Raw Normal View History

2017-07-06 09:05:05 +00:00
/*
This file is part of solidity.
solidity is free software: you can redistribute it and/or modify
it under the terms of the GNU General Public License as published by
the Free Software Foundation, either version 3 of the License, or
(at your option) any later version.
solidity is distributed in the hope that it will be useful,
but WITHOUT ANY WARRANTY; without even the implied warranty of
MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
GNU General Public License for more details.
You should have received a copy of the GNU General Public License
along with solidity. If not, see <http://www.gnu.org/licenses/>.
*/
// SPDX-License-Identifier: GPL-3.0
/**
* Encodes Solidity into SMT expressions without creating
* any verification targets.
* Also implements the SSA scheme for branches.
*/
2017-07-06 09:05:05 +00:00
#pragma once
2017-09-28 13:24:24 +00:00
2019-04-17 13:55:46 +00:00
#include <libsolidity/formal/EncodingContext.h>
#include <libsolidity/formal/SymbolicVariables.h>
2019-04-01 09:10:28 +00:00
#include <libsolidity/formal/VariableUsage.h>
2019-11-15 13:48:11 +00:00
#include <libsolidity/ast/AST.h>
2017-09-28 13:24:24 +00:00
#include <libsolidity/ast/ASTVisitor.h>
2017-07-11 11:26:43 +00:00
#include <libsolidity/interface/ReadFile.h>
#include <liblangutil/ErrorReporter.h>
2017-07-06 09:05:05 +00:00
#include <string>
2018-12-17 17:26:10 +00:00
#include <unordered_map>
#include <vector>
#include <utility>
2017-07-06 09:05:05 +00:00
2019-12-11 16:31:36 +00:00
namespace solidity::langutil
{
class ErrorReporter;
struct SourceLocation;
}
2019-12-11 16:31:36 +00:00
namespace solidity::frontend
2017-07-06 09:05:05 +00:00
{
class SMTEncoder: public ASTConstVisitor
2017-07-06 09:05:05 +00:00
{
public:
SMTEncoder(smt::EncodingContext& _context);
2017-07-06 09:05:05 +00:00
/// @returns true if engine should proceed with analysis.
bool analyze(SourceUnit const& _sources);
/// @returns the leftmost identifier in a multi-d IndexAccess.
static Expression const* leftmostBase(IndexAccess const& _indexAccess);
/// @returns the key type in _type.
/// _type must allow IndexAccess, that is,
/// it must be either ArrayType or MappingType
static TypePointer keyType(TypePointer _type);
/// @returns the innermost element in a chain of 1-tuples if applicable,
/// otherwise _expr.
static Expression const* innermostTuple(Expression const& _expr);
2020-07-15 16:56:28 +00:00
/// @returns the FunctionDefinition of a FunctionCall
/// if possible or nullptr.
static FunctionDefinition const* functionCallToDefinition(FunctionCall const& _funCall);
static std::vector<VariableDeclaration const*> stateVariablesIncludingInheritedAndPrivate(ContractDefinition const& _contract);
static std::vector<VariableDeclaration const*> stateVariablesIncludingInheritedAndPrivate(FunctionDefinition const& _function);
static std::vector<VariableDeclaration const*> localVariablesIncludingModifiers(FunctionDefinition const& _function);
static std::vector<VariableDeclaration const*> modifiersVariables(FunctionDefinition const& _function);
2020-09-02 08:45:47 +00:00
/// @returns the SourceUnit that contains _scopable.
static SourceUnit const* sourceUnitContaining(Scopable const& _scopable);
/// @returns the arguments for each base constructor call in the hierarchy of @a _contract.
std::map<ContractDefinition const*, std::vector<ASTPointer<frontend::Expression>>> baseArguments(ContractDefinition const& _contract);
protected:
2017-07-11 11:26:43 +00:00
// TODO: Check that we do not have concurrent reads and writes to a variable,
// because the order of expression evaluation is undefined
// TODO: or just force a certain order, but people might have a different idea about that.
bool visit(ContractDefinition const& _node) override;
void endVisit(ContractDefinition const& _node) override;
void endVisit(VariableDeclaration const& _node) override;
2019-03-11 20:06:28 +00:00
bool visit(ModifierDefinition const& _node) override;
bool visit(FunctionDefinition const& _node) override;
void endVisit(FunctionDefinition const& _node) override;
2019-03-11 20:06:28 +00:00
bool visit(PlaceholderStatement const& _node) override;
bool visit(IfStatement const&) override { return false; }
bool visit(WhileStatement const&) override { return false; }
bool visit(ForStatement const&) override { return false; }
void endVisit(VariableDeclarationStatement const& _node) override;
bool visit(Assignment const& _node) override;
void endVisit(Assignment const& _node) override;
void endVisit(TupleExpression const& _node) override;
bool visit(UnaryOperation const& _node) override;
void endVisit(UnaryOperation const& _node) override;
bool visit(BinaryOperation const& _node) override;
void endVisit(BinaryOperation const& _node) override;
bool visit(Conditional const& _node) override;
void endVisit(FunctionCall const& _node) override;
bool visit(ModifierInvocation const& _node) override;
void endVisit(Identifier const& _node) override;
2019-11-15 13:48:11 +00:00
void endVisit(ElementaryTypeNameExpression const& _node) override;
void endVisit(Literal const& _node) override;
void endVisit(Return const& _node) override;
bool visit(MemberAccess const& _node) override;
2018-11-09 16:06:30 +00:00
void endVisit(IndexAccess const& _node) override;
void endVisit(IndexRangeAccess const& _node) override;
bool visit(InlineAssembly const& _node) override;
2019-08-20 13:03:45 +00:00
void endVisit(Break const&) override {}
void endVisit(Continue const&) override {}
bool visit(TryCatchClause const& _node) override;
2017-07-11 11:26:43 +00:00
2020-07-27 17:39:17 +00:00
virtual void pushInlineFrame(CallableDeclaration const&);
virtual void popInlineFrame(CallableDeclaration const&);
/// Do not visit subtree if node is a RationalNumber.
/// Symbolic _expr is the rational literal.
bool shortcutRationalNumber(Expression const& _expr);
2017-07-11 11:26:43 +00:00
void arithmeticOperation(BinaryOperation const& _op);
/// @returns _op(_left, _right) with and without modular arithmetic.
/// Used by the function above, compound assignments and
/// unary increment/decrement.
2020-05-19 12:14:46 +00:00
virtual std::pair<smtutil::Expression, smtutil::Expression> arithmeticOperation(
Token _op,
2020-05-19 12:14:46 +00:00
smtutil::Expression const& _left,
smtutil::Expression const& _right,
TypePointer const& _commonType,
Expression const& _expression
);
smtutil::Expression bitwiseOperation(
Token _op,
smtutil::Expression const& _left,
smtutil::Expression const& _right,
TypePointer const& _commonType
);
2017-07-11 11:26:43 +00:00
void compareOperation(BinaryOperation const& _op);
void booleanOperation(BinaryOperation const& _op);
2020-05-13 11:08:48 +00:00
void bitwiseOperation(BinaryOperation const& _op);
void bitwiseNotOperation(UnaryOperation const& _op);
2017-07-11 11:26:43 +00:00
void initContract(ContractDefinition const& _contract);
void initFunction(FunctionDefinition const& _function);
void visitAssert(FunctionCall const& _funCall);
void visitRequire(FunctionCall const& _funCall);
void visitCryptoFunction(FunctionCall const& _funCall);
void visitGasLeft(FunctionCall const& _funCall);
virtual void visitAddMulMod(FunctionCall const& _funCall);
void visitObjectCreation(FunctionCall const& _funCall);
2018-12-20 12:20:07 +00:00
void visitTypeConversion(FunctionCall const& _funCall);
void visitStructConstructorCall(FunctionCall const& _funCall);
void visitFunctionIdentifier(Identifier const& _identifier);
void visitPublicGetter(FunctionCall const& _funCall);
bool isPublicGetter(Expression const& _expr);
2019-03-11 20:06:28 +00:00
/// Encodes a modifier or function body according to the modifier
/// visit depth.
void visitFunctionOrModifier();
/// Inlines a modifier or base constructor call.
void inlineModifierInvocation(ModifierInvocation const* _invocation, CallableDeclaration const* _definition);
/// Inlines the constructor hierarchy into a single constructor.
void inlineConstructorHierarchy(ContractDefinition const& _contract);
/// Defines a new global variable or function.
void defineGlobalVariable(std::string const& _name, Expression const& _expr, bool _increaseIndex = false);
/// Handles the side effects of assignment
/// to variable of some SMT array type
/// while aliasing is not supported.
void arrayAssignment();
2020-08-25 14:58:09 +00:00
/// Handles assignments to index or member access.
void indexOrMemberAssignment(Expression const& _expr, smtutil::Expression const& _rightHandSide);
2020-05-11 22:39:00 +00:00
void arrayPush(FunctionCall const& _funCall);
void arrayPop(FunctionCall const& _funCall);
2020-05-19 12:14:46 +00:00
void arrayPushPopAssign(Expression const& _expr, smtutil::Expression const& _array);
2020-05-17 21:21:08 +00:00
/// Allows BMC and CHC to create verification targets for popping
/// an empty array.
virtual void makeArrayPopVerificationTarget(FunctionCall const&) {}
2020-05-11 22:39:00 +00:00
2020-10-07 11:28:35 +00:00
void addArrayLiteralAssertions(
smt::SymbolicArrayVariable& _symArray,
std::vector<smtutil::Expression> const& _elementValues
);
/// @returns a pair of expressions representing _left / _right and _left mod _right, respectively.
/// Uses slack variables and additional constraints to express the results using only operations
/// more friendly to the SMT solver (multiplication, addition, subtraction and comparison).
std::pair<smtutil::Expression, smtutil::Expression> divModWithSlacks(
smtutil::Expression _left,
smtutil::Expression _right,
IntegerType const& _type
);
2017-10-05 17:20:46 +00:00
/// Handles the actual assertion of the new value to the encoding context.
/// Other assignment methods should use this one in the end.
virtual void assignment(smt::SymbolicVariable& _symVar, smtutil::Expression const& _value);
void assignment(VariableDeclaration const& _variable, Expression const& _value);
2019-04-29 09:39:24 +00:00
/// Handles assignments to variables of different types.
2020-05-19 12:14:46 +00:00
void assignment(VariableDeclaration const& _variable, smtutil::Expression const& _value);
2019-04-29 09:39:24 +00:00
/// Handles assignments between generic expressions.
/// Will also be used for assignments of tuple components.
void assignment(
Expression const& _left,
smtutil::Expression const& _right,
TypePointer const& _type
2019-04-29 09:39:24 +00:00
);
/// Handle assignments between tuples.
void tupleAssignment(Expression const& _left, Expression const& _right);
2019-04-29 09:39:24 +00:00
/// Computes the right hand side of a compound assignment.
2020-05-19 12:14:46 +00:00
smtutil::Expression compoundAssignment(Assignment const& _assignment);
2017-09-28 13:24:24 +00:00
/// Maps a variable to an SSA index.
using VariableIndices = std::unordered_map<VariableDeclaration const*, int>;
/// Visits the branch given by the statement, pushes and pops the current path conditions.
/// @param _condition if present, asserts that this condition is true within the branch.
/// @returns the variable indices after visiting the branch and the expression representing
/// the path condition at the end of the branch.
std::pair<VariableIndices, smtutil::Expression> visitBranch(ASTNode const* _statement, smtutil::Expression const* _condition = nullptr);
std::pair<VariableIndices, smtutil::Expression> visitBranch(ASTNode const* _statement, smtutil::Expression _condition);
2017-09-28 11:44:56 +00:00
using CallStackEntry = std::pair<CallableDeclaration const*, ASTNode const*>;
void createStateVariables(ContractDefinition const& _contract);
void initializeStateVariables(ContractDefinition const& _contract);
void createLocalVariables(FunctionDefinition const& _function);
2017-09-28 13:24:24 +00:00
void initializeLocalVariables(FunctionDefinition const& _function);
2020-05-19 12:14:46 +00:00
void initializeFunctionCallParameters(CallableDeclaration const& _function, std::vector<smtutil::Expression> const& _callArgs);
void resetStateVariables();
/// Resets all references/pointers that have the same type or have
/// a subexpression of the same type as _varDecl.
void resetReferences(VariableDeclaration const& _varDecl);
/// Resets all references/pointers that have type _type.
void resetReferences(TypePointer _type);
2019-02-21 12:01:58 +00:00
/// @returns the type without storage pointer information if it has it.
TypePointer typeWithoutPointer(TypePointer const& _type);
/// @returns whether _a or a subtype of _a is the same as _b.
bool sameTypeOrSubtype(TypePointer _a, TypePointer _b);
2019-02-21 12:01:58 +00:00
/// Given two different branches and the touched variables,
/// merge the touched variables into after-branch ite variables
/// using the branch condition as guard.
2020-05-19 12:14:46 +00:00
void mergeVariables(std::set<VariableDeclaration const*> const& _variables, smtutil::Expression const& _condition, VariableIndices const& _indicesEndTrue, VariableIndices const& _indicesEndFalse);
/// Tries to create an uninitialized variable and returns true on success.
bool createVariable(VariableDeclaration const& _varDecl);
2017-07-11 11:26:43 +00:00
2017-07-14 09:49:27 +00:00
/// @returns an expression denoting the value of the variable declared in @a _decl
/// at the current point.
2020-05-19 12:14:46 +00:00
smtutil::Expression currentValue(VariableDeclaration const& _decl);
2017-07-14 09:49:27 +00:00
/// @returns an expression denoting the value of the variable declared in @a _decl
/// at the given index. Does not ensure that this index exists.
smtutil::Expression valueAtIndex(VariableDeclaration const& _decl, unsigned _index);
/// Returns the expression corresponding to the AST node.
/// If _targetType is not null apply conversion.
/// Throws if the expression does not exist.
2020-05-19 12:14:46 +00:00
smtutil::Expression expr(Expression const& _e, TypePointer _targetType = nullptr);
2017-10-05 13:23:25 +00:00
/// Creates the expression (value can be arbitrary)
void createExpr(Expression const& _e);
/// Creates the expression and sets its value.
2020-05-19 12:14:46 +00:00
void defineExpr(Expression const& _e, smtutil::Expression _value);
2017-07-11 11:26:43 +00:00
/// Overwrites the current path condition
void setPathCondition(smtutil::Expression const& _e);
/// Adds a new path condition
2020-05-19 12:14:46 +00:00
void pushPathCondition(smtutil::Expression const& _e);
/// Remove the last path condition
void popPathCondition();
/// Returns the conjunction of all path conditions or True if empty
2020-05-19 12:14:46 +00:00
smtutil::Expression currentPathConditions();
/// @returns a human-readable call stack. Used for models.
langutil::SecondarySourceLocation callStackMessage(std::vector<CallStackEntry> const& _callStack);
2019-03-11 20:06:28 +00:00
/// Copies and pops the last called node.
CallStackEntry popCallStack();
/// Adds (_definition, _node) to the callstack.
void pushCallStack(CallStackEntry _entry);
/// Add to the solver: the given expression implied by the current path conditions
2020-05-19 12:14:46 +00:00
void addPathImpliedExpression(smtutil::Expression const& _e);
2018-10-15 15:32:17 +00:00
/// Copy the SSA indices of m_variables.
VariableIndices copyVariableIndices();
/// Resets the variable indices.
void resetVariableIndices(VariableIndices const& _indices);
/// Used when starting a new block.
virtual void clearIndices(ContractDefinition const* _contract, FunctionDefinition const* _function = nullptr);
2018-10-15 15:32:17 +00:00
2019-04-01 09:10:28 +00:00
/// @returns variables that are touched in _node's subtree.
std::set<VariableDeclaration const*> touchedVariables(ASTNode const& _node);
/// @returns the declaration referenced by _expr, if any,
/// and nullptr otherwise.
Declaration const* expressionToDeclaration(Expression const& _expr) const;
/// @returns the VariableDeclaration referenced by an Expression or nullptr.
VariableDeclaration const* identifierToVariable(Expression const& _expr) const;
/// @returns the MemberAccess <expression>.push if _expr is an empty array push call,
/// otherwise nullptr.
MemberAccess const* isEmptyPush(Expression const& _expr) const;
2019-04-29 09:39:24 +00:00
/// @returns true if the given identifier is a contract which is known and trusted.
/// This means we don't have to abstract away effects of external function calls to this contract.
static bool isTrustedExternalCall(Expression const* _expr);
/// Creates symbolic expressions for the returned values
/// and set them as the components of the symbolic tuple.
void createReturnedExpressions(FunctionCall const& _funCall);
2020-02-12 01:11:28 +00:00
/// @returns the symbolic arguments for a function call,
/// taking into account bound functions and
/// type conversion.
2020-05-19 12:14:46 +00:00
std::vector<smtutil::Expression> symbolicArguments(FunctionCall const& _funCall);
2020-02-12 01:11:28 +00:00
/// @returns a note to be added to warnings.
std::string extraComment();
struct VerificationTarget
{
2020-05-17 21:21:08 +00:00
enum class Type { ConstantCondition, Underflow, Overflow, UnderOverflow, DivByZero, Balance, Assert, PopEmptyArray } type;
2020-05-19 12:14:46 +00:00
smtutil::Expression value;
smtutil::Expression constraints;
};
smt::VariableUsage m_variableUsage;
bool m_arrayAssignmentHappened = false;
// True if the "No SMT solver available" warning was already created.
bool m_noSolverWarning = false;
/// Stores the instances of an Uninterpreted Function applied to arguments.
2018-11-09 16:06:30 +00:00
/// These may be direct application of UFs or Array index access.
/// Used to retrieve models.
2018-11-09 16:06:30 +00:00
std::set<Expression const*> m_uninterpretedTerms;
2020-05-19 12:14:46 +00:00
std::vector<smtutil::Expression> m_pathConditions;
/// Local SMTEncoder ErrorReporter.
/// This is necessary to show the "No SMT solver available"
/// warning before the others in case it's needed.
langutil::ErrorReporter m_errorReporter;
langutil::ErrorList m_smtErrors;
2017-07-11 11:26:43 +00:00
/// Stores the current function/modifier call/invocation path.
std::vector<CallStackEntry> m_callStack;
/// Returns true if the current function was not visited by
/// a function call.
bool isRootFunction();
/// Returns true if _funDef was already visited.
bool visitedFunction(FunctionDefinition const* _funDef);
2019-03-11 20:06:28 +00:00
/// Depth of visit to modifiers.
/// When m_modifierDepth == #modifiers the function can be visited
/// when placeholder is visited.
/// Needs to be a stack because of function calls.
std::vector<int> m_modifierDepthStack;
2019-04-17 13:55:46 +00:00
std::map<ContractDefinition const*, ModifierInvocation const*> m_baseConstructorCalls;
ContractDefinition const* m_currentContract = nullptr;
2019-04-17 13:55:46 +00:00
/// Stores the context of the encoding.
smt::EncodingContext& m_context;
2017-07-06 09:05:05 +00:00
};
}