2019-06-25 10:46:17 +00:00
|
|
|
/*
|
|
|
|
This file is part of solidity.
|
|
|
|
|
|
|
|
solidity is free software: you can redistribute it and/or modify
|
|
|
|
it under the terms of the GNU General Public License as published by
|
|
|
|
the Free Software Foundation, either version 3 of the License, or
|
|
|
|
(at your option) any later version.
|
|
|
|
|
|
|
|
solidity is distributed in the hope that it will be useful,
|
|
|
|
but WITHOUT ANY WARRANTY; without even the implied warranty of
|
|
|
|
MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
|
|
|
|
GNU General Public License for more details.
|
|
|
|
|
|
|
|
You should have received a copy of the GNU General Public License
|
|
|
|
along with solidity. If not, see <http://www.gnu.org/licenses/>.
|
|
|
|
*/
|
|
|
|
/**
|
|
|
|
* Class that implements an SMT-based Bounded Model Checker (BMC).
|
|
|
|
* Traverses the AST such that:
|
|
|
|
* - Loops are unrolled
|
|
|
|
* - Internal function calls are inlined
|
|
|
|
* Creates verification targets for:
|
|
|
|
* - Underflow/Overflow
|
|
|
|
* - Constant conditions
|
|
|
|
* - Assertions
|
|
|
|
*/
|
|
|
|
|
|
|
|
#pragma once
|
|
|
|
|
|
|
|
|
|
|
|
#include <libsolidity/formal/EncodingContext.h>
|
|
|
|
#include <libsolidity/formal/SMTEncoder.h>
|
2019-07-02 10:06:52 +00:00
|
|
|
#include <libsolidity/formal/SolverInterface.h>
|
2019-06-25 10:46:17 +00:00
|
|
|
|
|
|
|
#include <libsolidity/interface/ReadFile.h>
|
|
|
|
#include <liblangutil/ErrorReporter.h>
|
|
|
|
|
2019-07-04 12:44:10 +00:00
|
|
|
#include <set>
|
2019-06-25 10:46:17 +00:00
|
|
|
#include <string>
|
|
|
|
#include <vector>
|
|
|
|
|
2019-12-11 16:31:36 +00:00
|
|
|
using solidity::util::h256;
|
|
|
|
|
|
|
|
namespace solidity::langutil
|
2019-06-25 10:46:17 +00:00
|
|
|
{
|
|
|
|
class ErrorReporter;
|
|
|
|
struct SourceLocation;
|
|
|
|
}
|
|
|
|
|
2019-12-11 16:31:36 +00:00
|
|
|
namespace solidity::frontend
|
2019-06-25 10:46:17 +00:00
|
|
|
{
|
|
|
|
|
|
|
|
class BMC: public SMTEncoder
|
|
|
|
{
|
|
|
|
public:
|
2019-09-17 14:06:43 +00:00
|
|
|
BMC(
|
|
|
|
smt::EncodingContext& _context,
|
|
|
|
langutil::ErrorReporter& _errorReporter,
|
|
|
|
std::map<h256, std::string> const& _smtlib2Responses,
|
2019-12-05 15:44:26 +00:00
|
|
|
ReadCallback::Callback const& _smtCallback,
|
2019-12-03 13:39:47 +00:00
|
|
|
smt::SMTSolverChoice _enabledSolvers
|
2019-09-17 14:06:43 +00:00
|
|
|
);
|
2019-06-25 10:46:17 +00:00
|
|
|
|
2019-08-06 14:02:11 +00:00
|
|
|
void analyze(SourceUnit const& _sources, std::set<Expression const*> _safeAssertions);
|
2019-06-25 10:46:17 +00:00
|
|
|
|
|
|
|
/// This is used if the SMT solver is not directly linked into this binary.
|
|
|
|
/// @returns a list of inputs to the SMT solver that were not part of the argument to
|
|
|
|
/// the constructor.
|
|
|
|
std::vector<std::string> unhandledQueries() { return m_interface->unhandledQueries(); }
|
|
|
|
|
2019-07-17 15:54:48 +00:00
|
|
|
/// @returns true if _funCall should be inlined, otherwise false.
|
|
|
|
static bool shouldInlineFunctionCall(FunctionCall const& _funCall);
|
2019-06-25 10:46:17 +00:00
|
|
|
|
|
|
|
private:
|
|
|
|
/// AST visitors.
|
|
|
|
/// Only nodes that lead to verification targets being built
|
|
|
|
/// or checked are visited.
|
|
|
|
//@{
|
|
|
|
bool visit(ContractDefinition const& _node) override;
|
2019-08-02 16:36:26 +00:00
|
|
|
void endVisit(ContractDefinition const& _node) override;
|
2019-06-25 10:46:17 +00:00
|
|
|
bool visit(FunctionDefinition const& _node) override;
|
|
|
|
void endVisit(FunctionDefinition const& _node) override;
|
|
|
|
bool visit(IfStatement const& _node) override;
|
|
|
|
bool visit(WhileStatement const& _node) override;
|
|
|
|
bool visit(ForStatement const& _node) override;
|
|
|
|
void endVisit(UnaryOperation const& _node) override;
|
|
|
|
void endVisit(FunctionCall const& _node) override;
|
|
|
|
//@}
|
|
|
|
|
|
|
|
/// Visitor helpers.
|
|
|
|
//@{
|
|
|
|
void visitAssert(FunctionCall const& _funCall);
|
|
|
|
void visitRequire(FunctionCall const& _funCall);
|
|
|
|
/// Visits the FunctionDefinition of the called function
|
|
|
|
/// if available and inlines the return value.
|
|
|
|
void inlineFunctionCall(FunctionCall const& _funCall);
|
|
|
|
/// Creates an uninterpreted function call.
|
|
|
|
void abstractFunctionCall(FunctionCall const& _funCall);
|
|
|
|
/// Inlines if the function call is internal or external to `this`.
|
|
|
|
/// Erases knowledge about state variables if external.
|
|
|
|
void internalOrExternalFunctionCall(FunctionCall const& _funCall);
|
|
|
|
|
|
|
|
/// Creates underflow/overflow verification targets.
|
|
|
|
std::pair<smt::Expression, smt::Expression> arithmeticOperation(
|
|
|
|
Token _op,
|
|
|
|
smt::Expression const& _left,
|
|
|
|
smt::Expression const& _right,
|
|
|
|
TypePointer const& _commonType,
|
|
|
|
Expression const& _expression
|
|
|
|
) override;
|
|
|
|
|
|
|
|
void resetStorageReferences();
|
|
|
|
void reset();
|
|
|
|
|
|
|
|
std::pair<std::vector<smt::Expression>, std::vector<std::string>> modelExpressions();
|
|
|
|
//@}
|
|
|
|
|
|
|
|
/// Verification targets.
|
|
|
|
//@{
|
2020-02-12 01:09:45 +00:00
|
|
|
struct BMCVerificationTarget: VerificationTarget
|
2019-06-25 10:46:17 +00:00
|
|
|
{
|
|
|
|
Expression const* expression;
|
|
|
|
std::vector<CallStackEntry> callStack;
|
|
|
|
std::pair<std::vector<smt::Expression>, std::vector<std::string>> modelExpressions;
|
|
|
|
};
|
|
|
|
|
|
|
|
void checkVerificationTargets(smt::Expression const& _constraints);
|
2020-02-12 01:09:45 +00:00
|
|
|
void checkVerificationTarget(BMCVerificationTarget& _target, smt::Expression const& _constraints = smt::Expression(true));
|
|
|
|
void checkConstantCondition(BMCVerificationTarget& _target);
|
|
|
|
void checkUnderflow(BMCVerificationTarget& _target, smt::Expression const& _constraints);
|
|
|
|
void checkOverflow(BMCVerificationTarget& _target, smt::Expression const& _constraints);
|
|
|
|
void checkDivByZero(BMCVerificationTarget& _target);
|
|
|
|
void checkBalance(BMCVerificationTarget& _target);
|
|
|
|
void checkAssert(BMCVerificationTarget& _target);
|
2019-06-25 10:46:17 +00:00
|
|
|
void addVerificationTarget(
|
|
|
|
VerificationTarget::Type _type,
|
|
|
|
smt::Expression const& _value,
|
|
|
|
Expression const* _expression
|
|
|
|
);
|
|
|
|
//@}
|
|
|
|
|
|
|
|
/// Solver related.
|
|
|
|
//@{
|
|
|
|
/// Check that a condition can be satisfied.
|
|
|
|
void checkCondition(
|
|
|
|
smt::Expression _condition,
|
|
|
|
std::vector<CallStackEntry> const& callStack,
|
|
|
|
std::pair<std::vector<smt::Expression>, std::vector<std::string>> const& _modelExpressions,
|
|
|
|
langutil::SourceLocation const& _location,
|
|
|
|
std::string const& _description,
|
|
|
|
std::string const& _additionalValueName = "",
|
|
|
|
smt::Expression const* _additionalValue = nullptr
|
|
|
|
);
|
|
|
|
/// Checks that a boolean condition is not constant. Do not warn if the expression
|
|
|
|
/// is a literal constant.
|
|
|
|
/// @param _description the warning string, $VALUE will be replaced by the constant value.
|
|
|
|
void checkBooleanNotConstant(
|
|
|
|
Expression const& _condition,
|
|
|
|
smt::Expression const& _constraints,
|
|
|
|
smt::Expression const& _value,
|
|
|
|
std::vector<CallStackEntry> const& _callStack,
|
|
|
|
std::string const& _description
|
|
|
|
);
|
|
|
|
std::pair<smt::CheckResult, std::vector<std::string>>
|
|
|
|
checkSatisfiableAndGenerateModel(std::vector<smt::Expression> const& _expressionsToEvaluate);
|
|
|
|
|
|
|
|
smt::CheckResult checkSatisfiable();
|
|
|
|
//@}
|
|
|
|
|
2020-01-04 20:45:21 +00:00
|
|
|
std::unique_ptr<smt::SolverInterface> m_interface;
|
|
|
|
|
2019-06-25 10:46:17 +00:00
|
|
|
/// Flags used for better warning messages.
|
|
|
|
bool m_loopExecutionHappened = false;
|
|
|
|
bool m_externalFunctionCallHappened = false;
|
|
|
|
|
|
|
|
/// ErrorReporter that comes from CompilerStack.
|
|
|
|
langutil::ErrorReporter& m_outerErrorReporter;
|
|
|
|
|
2020-02-12 01:09:45 +00:00
|
|
|
std::vector<BMCVerificationTarget> m_verificationTargets;
|
2019-07-02 10:06:52 +00:00
|
|
|
|
2019-07-04 12:44:10 +00:00
|
|
|
/// Assertions that are known to be safe.
|
|
|
|
std::set<Expression const*> m_safeAssertions;
|
2019-06-25 10:46:17 +00:00
|
|
|
};
|
|
|
|
|
|
|
|
}
|