2017-07-06 09:05:05 +00:00
|
|
|
/*
|
|
|
|
This file is part of solidity.
|
|
|
|
|
|
|
|
solidity is free software: you can redistribute it and/or modify
|
|
|
|
it under the terms of the GNU General Public License as published by
|
|
|
|
the Free Software Foundation, either version 3 of the License, or
|
|
|
|
(at your option) any later version.
|
|
|
|
|
|
|
|
solidity is distributed in the hope that it will be useful,
|
|
|
|
but WITHOUT ANY WARRANTY; without even the implied warranty of
|
|
|
|
MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
|
|
|
|
GNU General Public License for more details.
|
|
|
|
|
|
|
|
You should have received a copy of the GNU General Public License
|
|
|
|
along with solidity. If not, see <http://www.gnu.org/licenses/>.
|
|
|
|
*/
|
2020-07-17 14:54:12 +00:00
|
|
|
// SPDX-License-Identifier: GPL-3.0
|
2019-06-25 10:46:17 +00:00
|
|
|
/**
|
|
|
|
* Encodes Solidity into SMT expressions without creating
|
|
|
|
* any verification targets.
|
|
|
|
* Also implements the SSA scheme for branches.
|
|
|
|
*/
|
2017-07-06 09:05:05 +00:00
|
|
|
|
|
|
|
#pragma once
|
|
|
|
|
2017-09-28 13:24:24 +00:00
|
|
|
|
2019-04-17 13:55:46 +00:00
|
|
|
#include <libsolidity/formal/EncodingContext.h>
|
2021-01-19 11:56:22 +00:00
|
|
|
#include <libsolidity/formal/ModelCheckerSettings.h>
|
2018-10-22 08:29:03 +00:00
|
|
|
#include <libsolidity/formal/SymbolicVariables.h>
|
2019-04-01 09:10:28 +00:00
|
|
|
#include <libsolidity/formal/VariableUsage.h>
|
2018-01-17 20:02:23 +00:00
|
|
|
|
2019-11-15 13:48:11 +00:00
|
|
|
#include <libsolidity/ast/AST.h>
|
2017-09-28 13:24:24 +00:00
|
|
|
#include <libsolidity/ast/ASTVisitor.h>
|
2017-07-11 11:26:43 +00:00
|
|
|
#include <libsolidity/interface/ReadFile.h>
|
2021-08-27 09:40:20 +00:00
|
|
|
#include <liblangutil/UniqueErrorReporter.h>
|
2018-11-12 11:21:25 +00:00
|
|
|
|
2017-07-06 09:05:05 +00:00
|
|
|
#include <string>
|
2018-12-17 17:26:10 +00:00
|
|
|
#include <unordered_map>
|
2017-12-11 19:09:17 +00:00
|
|
|
#include <vector>
|
2020-10-14 14:26:50 +00:00
|
|
|
#include <utility>
|
2017-07-06 09:05:05 +00:00
|
|
|
|
2019-12-11 16:31:36 +00:00
|
|
|
namespace solidity::langutil
|
2018-11-14 16:11:55 +00:00
|
|
|
{
|
|
|
|
class ErrorReporter;
|
|
|
|
struct SourceLocation;
|
2021-07-01 15:28:06 +00:00
|
|
|
class CharStreamProvider;
|
2018-11-14 16:11:55 +00:00
|
|
|
}
|
|
|
|
|
2019-12-11 16:31:36 +00:00
|
|
|
namespace solidity::frontend
|
2017-07-06 09:05:05 +00:00
|
|
|
{
|
|
|
|
|
2019-06-25 10:46:17 +00:00
|
|
|
class SMTEncoder: public ASTConstVisitor
|
2017-07-06 09:05:05 +00:00
|
|
|
{
|
|
|
|
public:
|
2021-04-15 10:31:45 +00:00
|
|
|
SMTEncoder(
|
|
|
|
smt::EncodingContext& _context,
|
2022-05-15 15:45:43 +00:00
|
|
|
ModelCheckerSettings _settings,
|
2021-08-27 09:40:20 +00:00
|
|
|
langutil::UniqueErrorReporter& _errorReporter,
|
2021-07-01 15:28:06 +00:00
|
|
|
langutil::CharStreamProvider const& _charStreamProvider
|
2021-04-15 10:31:45 +00:00
|
|
|
);
|
2017-07-06 09:05:05 +00:00
|
|
|
|
2019-05-09 14:06:13 +00:00
|
|
|
/// @returns the leftmost identifier in a multi-d IndexAccess.
|
|
|
|
static Expression const* leftmostBase(IndexAccess const& _indexAccess);
|
2019-03-25 12:58:22 +00:00
|
|
|
|
2020-10-19 20:46:15 +00:00
|
|
|
/// @returns the key type in _type.
|
|
|
|
/// _type must allow IndexAccess, that is,
|
|
|
|
/// it must be either ArrayType or MappingType
|
2021-03-22 16:12:05 +00:00
|
|
|
static Type const* keyType(Type const* _type);
|
2020-10-19 20:46:15 +00:00
|
|
|
|
2020-08-31 10:59:11 +00:00
|
|
|
/// @returns the innermost element in a chain of 1-tuples if applicable,
|
|
|
|
/// otherwise _expr.
|
|
|
|
static Expression const* innermostTuple(Expression const& _expr);
|
2020-07-15 16:56:28 +00:00
|
|
|
|
2021-09-17 19:28:07 +00:00
|
|
|
/// @returns the underlying type if _type is UserDefinedValueType,
|
|
|
|
/// and _type otherwise.
|
|
|
|
static Type const* underlyingType(Type const* _type);
|
|
|
|
|
|
|
|
static TypePointers replaceUserTypes(TypePointers const& _types);
|
|
|
|
|
2021-08-30 16:21:22 +00:00
|
|
|
/// @returns {_funCall.expression(), nullptr} if function call option values are not given, and
|
|
|
|
/// {_funCall.expression().expression(), _funCall.expression()} if they are.
|
|
|
|
static std::pair<Expression const*, FunctionCallOptions const*> functionCallExpression(FunctionCall const& _funCall);
|
|
|
|
|
2021-03-02 17:29:52 +00:00
|
|
|
/// @returns the expression after stripping redundant syntactic sugar.
|
|
|
|
/// Currently supports stripping:
|
|
|
|
/// 1. 1-tuple; i.e. ((x)) -> x
|
|
|
|
/// 2. Explicit cast from string to bytes; i.e. bytes(s) -> s; for s of type string
|
|
|
|
static Expression const* cleanExpression(Expression const& _expr);
|
|
|
|
|
2019-07-17 15:54:48 +00:00
|
|
|
/// @returns the FunctionDefinition of a FunctionCall
|
|
|
|
/// if possible or nullptr.
|
2021-01-25 17:17:56 +00:00
|
|
|
/// @param _scopeContract is the contract that contains the function currently being
|
|
|
|
/// analyzed, if applicable.
|
|
|
|
/// @param _contextContract is the most derived contract currently being analyzed.
|
|
|
|
/// The difference between the two parameters appears in the case of inheritance.
|
|
|
|
/// Let A and B be two contracts so that B derives from A, and A defines a function `f`
|
|
|
|
/// that `B` does not override. Function `f` is visited twice:
|
|
|
|
/// - Once when A is the most derived contract, where both _scopeContract and _contextContract are A.
|
|
|
|
/// - Once when B is the most derived contract, where _scopeContract is A and _contextContract is B.
|
|
|
|
static FunctionDefinition const* functionCallToDefinition(
|
|
|
|
FunctionCall const& _funCall,
|
|
|
|
ContractDefinition const* _scopeContract,
|
|
|
|
ContractDefinition const* _contextContract
|
|
|
|
);
|
2019-07-17 15:54:48 +00:00
|
|
|
|
2020-08-19 11:51:58 +00:00
|
|
|
static std::vector<VariableDeclaration const*> stateVariablesIncludingInheritedAndPrivate(ContractDefinition const& _contract);
|
|
|
|
static std::vector<VariableDeclaration const*> stateVariablesIncludingInheritedAndPrivate(FunctionDefinition const& _function);
|
|
|
|
|
2020-12-15 14:50:02 +00:00
|
|
|
static std::vector<VariableDeclaration const*> localVariablesIncludingModifiers(FunctionDefinition const& _function, ContractDefinition const* _contract);
|
|
|
|
static std::vector<VariableDeclaration const*> modifiersVariables(FunctionDefinition const& _function, ContractDefinition const* _contract);
|
2021-01-04 18:33:07 +00:00
|
|
|
static std::vector<VariableDeclaration const*> tryCatchVariables(FunctionDefinition const& _function);
|
2020-11-04 21:06:30 +00:00
|
|
|
|
2020-12-21 10:41:35 +00:00
|
|
|
/// @returns the ModifierDefinition of a ModifierInvocation if possible, or nullptr.
|
|
|
|
static ModifierDefinition const* resolveModifierInvocation(ModifierInvocation const& _invocation, ContractDefinition const* _contract);
|
|
|
|
|
2020-11-09 15:37:08 +00:00
|
|
|
/// @returns the arguments for each base constructor call in the hierarchy of @a _contract.
|
|
|
|
std::map<ContractDefinition const*, std::vector<ASTPointer<frontend::Expression>>> baseArguments(ContractDefinition const& _contract);
|
|
|
|
|
2020-12-16 10:27:56 +00:00
|
|
|
/// @returns a valid RationalNumberType pointer if _expr has type
|
|
|
|
/// RationalNumberType or can be const evaluated, and nullptr otherwise.
|
2020-12-16 16:58:49 +00:00
|
|
|
static RationalNumberType const* isConstant(Expression const& _expr);
|
2020-12-16 10:27:56 +00:00
|
|
|
|
2021-10-12 09:12:18 +00:00
|
|
|
static std::set<FunctionCall const*, ASTCompareByID<FunctionCall>> collectABICalls(ASTNode const* _node);
|
2020-12-08 20:14:18 +00:00
|
|
|
|
2021-04-07 16:53:56 +00:00
|
|
|
/// @returns all the sources that @param _source depends on,
|
|
|
|
/// including itself.
|
|
|
|
static std::set<SourceUnit const*, ASTNode::CompareByID> sourceDependencies(SourceUnit const& _source);
|
|
|
|
|
2019-06-25 10:46:17 +00:00
|
|
|
protected:
|
2021-08-27 14:45:41 +00:00
|
|
|
void resetSourceAnalysis();
|
|
|
|
|
2017-07-11 11:26:43 +00:00
|
|
|
// TODO: Check that we do not have concurrent reads and writes to a variable,
|
|
|
|
// because the order of expression evaluation is undefined
|
|
|
|
// TODO: or just force a certain order, but people might have a different idea about that.
|
|
|
|
|
2022-03-11 16:01:30 +00:00
|
|
|
bool visit(ImportDirective const& _node) override;
|
2018-11-16 01:09:04 +00:00
|
|
|
bool visit(ContractDefinition const& _node) override;
|
|
|
|
void endVisit(ContractDefinition const& _node) override;
|
|
|
|
void endVisit(VariableDeclaration const& _node) override;
|
2019-03-11 20:06:28 +00:00
|
|
|
bool visit(ModifierDefinition const& _node) override;
|
2018-11-16 01:09:04 +00:00
|
|
|
bool visit(FunctionDefinition const& _node) override;
|
|
|
|
void endVisit(FunctionDefinition const& _node) override;
|
2020-12-16 17:32:34 +00:00
|
|
|
bool visit(Block const& _node) override;
|
|
|
|
void endVisit(Block const& _node) override;
|
2019-03-11 20:06:28 +00:00
|
|
|
bool visit(PlaceholderStatement const& _node) override;
|
2020-11-14 14:42:32 +00:00
|
|
|
bool visit(IfStatement const&) override { return false; }
|
2019-06-25 10:46:17 +00:00
|
|
|
bool visit(WhileStatement const&) override { return false; }
|
|
|
|
bool visit(ForStatement const&) override { return false; }
|
2021-01-21 18:04:34 +00:00
|
|
|
void endVisit(ForStatement const&) override {}
|
2018-11-16 01:09:04 +00:00
|
|
|
void endVisit(VariableDeclarationStatement const& _node) override;
|
2020-10-26 16:16:27 +00:00
|
|
|
bool visit(Assignment const& _node) override;
|
2018-11-16 01:09:04 +00:00
|
|
|
void endVisit(Assignment const& _node) override;
|
|
|
|
void endVisit(TupleExpression const& _node) override;
|
2019-03-11 10:56:08 +00:00
|
|
|
bool visit(UnaryOperation const& _node) override;
|
2018-11-16 01:09:04 +00:00
|
|
|
void endVisit(UnaryOperation const& _node) override;
|
2019-03-11 10:56:08 +00:00
|
|
|
bool visit(BinaryOperation const& _node) override;
|
2018-11-16 01:09:04 +00:00
|
|
|
void endVisit(BinaryOperation const& _node) override;
|
2020-08-18 17:25:36 +00:00
|
|
|
bool visit(Conditional const& _node) override;
|
2021-09-06 21:54:14 +00:00
|
|
|
bool visit(FunctionCall const& _node) override;
|
2018-11-16 01:09:04 +00:00
|
|
|
void endVisit(FunctionCall const& _node) override;
|
2019-11-27 21:34:33 +00:00
|
|
|
bool visit(ModifierInvocation const& _node) override;
|
2018-11-16 01:09:04 +00:00
|
|
|
void endVisit(Identifier const& _node) override;
|
2019-11-15 13:48:11 +00:00
|
|
|
void endVisit(ElementaryTypeNameExpression const& _node) override;
|
2018-11-16 01:09:04 +00:00
|
|
|
void endVisit(Literal const& _node) override;
|
|
|
|
void endVisit(Return const& _node) override;
|
|
|
|
bool visit(MemberAccess const& _node) override;
|
2018-11-09 16:06:30 +00:00
|
|
|
void endVisit(IndexAccess const& _node) override;
|
2019-09-03 16:30:00 +00:00
|
|
|
void endVisit(IndexRangeAccess const& _node) override;
|
2019-04-05 14:41:05 +00:00
|
|
|
bool visit(InlineAssembly const& _node) override;
|
2019-08-20 13:03:45 +00:00
|
|
|
void endVisit(Break const&) override {}
|
|
|
|
void endVisit(Continue const&) override {}
|
2021-01-21 18:04:34 +00:00
|
|
|
bool visit(TryCatchClause const&) override { return true; }
|
|
|
|
void endVisit(TryCatchClause const&) override {}
|
2021-01-04 18:33:07 +00:00
|
|
|
bool visit(TryStatement const&) override { return false; }
|
2017-07-11 11:26:43 +00:00
|
|
|
|
2020-07-27 17:39:17 +00:00
|
|
|
virtual void pushInlineFrame(CallableDeclaration const&);
|
|
|
|
virtual void popInlineFrame(CallableDeclaration const&);
|
|
|
|
|
2019-03-11 10:56:08 +00:00
|
|
|
/// Do not visit subtree if node is a RationalNumber.
|
|
|
|
/// Symbolic _expr is the rational literal.
|
|
|
|
bool shortcutRationalNumber(Expression const& _expr);
|
2017-07-11 11:26:43 +00:00
|
|
|
void arithmeticOperation(BinaryOperation const& _op);
|
2019-06-25 10:46:17 +00:00
|
|
|
/// @returns _op(_left, _right) with and without modular arithmetic.
|
2019-03-28 11:42:32 +00:00
|
|
|
/// Used by the function above, compound assignments and
|
|
|
|
/// unary increment/decrement.
|
2020-05-19 12:14:46 +00:00
|
|
|
virtual std::pair<smtutil::Expression, smtutil::Expression> arithmeticOperation(
|
2019-03-28 11:42:32 +00:00
|
|
|
Token _op,
|
2020-05-19 12:14:46 +00:00
|
|
|
smtutil::Expression const& _left,
|
|
|
|
smtutil::Expression const& _right,
|
2021-03-22 16:12:05 +00:00
|
|
|
Type const* _commonType,
|
2019-06-24 15:37:03 +00:00
|
|
|
Expression const& _expression
|
2019-03-28 11:42:32 +00:00
|
|
|
);
|
2020-09-21 14:54:58 +00:00
|
|
|
|
|
|
|
smtutil::Expression bitwiseOperation(
|
|
|
|
Token _op,
|
|
|
|
smtutil::Expression const& _left,
|
|
|
|
smtutil::Expression const& _right,
|
2021-03-22 16:12:05 +00:00
|
|
|
Type const* _commonType
|
2020-09-21 14:54:58 +00:00
|
|
|
);
|
|
|
|
|
2017-07-11 11:26:43 +00:00
|
|
|
void compareOperation(BinaryOperation const& _op);
|
|
|
|
void booleanOperation(BinaryOperation const& _op);
|
2020-05-13 11:08:48 +00:00
|
|
|
void bitwiseOperation(BinaryOperation const& _op);
|
2020-08-23 19:21:45 +00:00
|
|
|
void bitwiseNotOperation(UnaryOperation const& _op);
|
2017-07-11 11:26:43 +00:00
|
|
|
|
2019-09-28 19:04:49 +00:00
|
|
|
void initContract(ContractDefinition const& _contract);
|
2019-06-25 10:46:17 +00:00
|
|
|
void initFunction(FunctionDefinition const& _function);
|
2018-12-10 16:23:36 +00:00
|
|
|
void visitAssert(FunctionCall const& _funCall);
|
|
|
|
void visitRequire(FunctionCall const& _funCall);
|
2020-12-08 20:14:18 +00:00
|
|
|
void visitABIFunction(FunctionCall const& _funCall);
|
2020-10-13 16:00:26 +00:00
|
|
|
void visitCryptoFunction(FunctionCall const& _funCall);
|
2018-12-10 16:23:36 +00:00
|
|
|
void visitGasLeft(FunctionCall const& _funCall);
|
2020-09-28 10:09:40 +00:00
|
|
|
virtual void visitAddMulMod(FunctionCall const& _funCall);
|
2021-09-17 19:28:07 +00:00
|
|
|
void visitWrapUnwrap(FunctionCall const& _funCall);
|
2020-09-25 12:00:32 +00:00
|
|
|
void visitObjectCreation(FunctionCall const& _funCall);
|
2018-12-20 12:20:07 +00:00
|
|
|
void visitTypeConversion(FunctionCall const& _funCall);
|
2020-11-12 09:09:43 +00:00
|
|
|
void visitStructConstructorCall(FunctionCall const& _funCall);
|
2018-12-10 16:23:36 +00:00
|
|
|
void visitFunctionIdentifier(Identifier const& _identifier);
|
2021-10-12 09:12:18 +00:00
|
|
|
virtual void visitPublicGetter(FunctionCall const& _funCall);
|
2020-11-26 16:14:58 +00:00
|
|
|
|
2021-04-15 10:31:45 +00:00
|
|
|
/// @returns true if @param _contract is set for analysis in the settings
|
|
|
|
/// and it is not abstract.
|
|
|
|
bool shouldAnalyze(ContractDefinition const& _contract) const;
|
2021-12-23 23:44:15 +00:00
|
|
|
/// @returns true if @param _source is set for analysis in the settings.
|
|
|
|
bool shouldAnalyze(SourceUnit const& _source) const;
|
2021-04-15 10:31:45 +00:00
|
|
|
|
2021-10-12 09:12:18 +00:00
|
|
|
/// @returns the state variable returned by a public getter if
|
|
|
|
/// @a _expr is a call to a public getter,
|
|
|
|
/// otherwise nullptr.
|
|
|
|
VariableDeclaration const* publicGetter(Expression const& _expr) const;
|
|
|
|
|
|
|
|
smtutil::Expression contractAddressValue(FunctionCall const& _f);
|
2018-10-10 12:31:49 +00:00
|
|
|
|
2019-03-11 20:06:28 +00:00
|
|
|
/// Encodes a modifier or function body according to the modifier
|
|
|
|
/// visit depth.
|
|
|
|
void visitFunctionOrModifier();
|
|
|
|
|
2019-09-26 14:12:27 +00:00
|
|
|
/// Inlines a modifier or base constructor call.
|
|
|
|
void inlineModifierInvocation(ModifierInvocation const* _invocation, CallableDeclaration const* _definition);
|
|
|
|
|
|
|
|
/// Inlines the constructor hierarchy into a single constructor.
|
|
|
|
void inlineConstructorHierarchy(ContractDefinition const& _contract);
|
|
|
|
|
2019-05-14 16:57:34 +00:00
|
|
|
/// Defines a new global variable or function.
|
2018-12-10 16:23:36 +00:00
|
|
|
void defineGlobalVariable(std::string const& _name, Expression const& _expr, bool _increaseIndex = false);
|
2019-05-14 16:57:34 +00:00
|
|
|
|
2018-12-14 11:21:43 +00:00
|
|
|
/// Handles the side effects of assignment
|
|
|
|
/// to variable of some SMT array type
|
|
|
|
/// while aliasing is not supported.
|
|
|
|
void arrayAssignment();
|
2020-08-25 14:58:09 +00:00
|
|
|
/// Handles assignments to index or member access.
|
|
|
|
void indexOrMemberAssignment(Expression const& _expr, smtutil::Expression const& _rightHandSide);
|
2018-10-18 13:03:52 +00:00
|
|
|
|
2020-05-11 22:39:00 +00:00
|
|
|
void arrayPush(FunctionCall const& _funCall);
|
|
|
|
void arrayPop(FunctionCall const& _funCall);
|
2020-05-17 21:21:08 +00:00
|
|
|
/// Allows BMC and CHC to create verification targets for popping
|
|
|
|
/// an empty array.
|
|
|
|
virtual void makeArrayPopVerificationTarget(FunctionCall const&) {}
|
2021-03-23 18:15:14 +00:00
|
|
|
/// Allows BMC and CHC to create verification targets for out of bounds access.
|
|
|
|
virtual void makeOutOfBoundsVerificationTarget(IndexAccess const&) {}
|
2020-05-11 22:39:00 +00:00
|
|
|
|
2020-10-07 11:28:35 +00:00
|
|
|
void addArrayLiteralAssertions(
|
|
|
|
smt::SymbolicArrayVariable& _symArray,
|
|
|
|
std::vector<smtutil::Expression> const& _elementValues
|
2021-06-01 15:28:41 +00:00
|
|
|
);
|
|
|
|
|
|
|
|
void bytesToFixedBytesAssertions(
|
|
|
|
smt::SymbolicArrayVariable& _symArray,
|
|
|
|
Expression const& _fixedBytes
|
2020-10-07 11:28:35 +00:00
|
|
|
);
|
|
|
|
|
2020-10-14 14:26:50 +00:00
|
|
|
/// @returns a pair of expressions representing _left / _right and _left mod _right, respectively.
|
|
|
|
/// Uses slack variables and additional constraints to express the results using only operations
|
|
|
|
/// more friendly to the SMT solver (multiplication, addition, subtraction and comparison).
|
|
|
|
std::pair<smtutil::Expression, smtutil::Expression> divModWithSlacks(
|
|
|
|
smtutil::Expression _left,
|
|
|
|
smtutil::Expression _right,
|
|
|
|
IntegerType const& _type
|
|
|
|
);
|
2017-10-05 17:20:46 +00:00
|
|
|
|
2020-11-19 16:11:02 +00:00
|
|
|
/// Handles the actual assertion of the new value to the encoding context.
|
|
|
|
/// Other assignment methods should use this one in the end.
|
2020-11-14 14:42:32 +00:00
|
|
|
virtual void assignment(smt::SymbolicVariable& _symVar, smtutil::Expression const& _value);
|
2020-11-19 16:11:02 +00:00
|
|
|
|
2019-06-24 15:58:56 +00:00
|
|
|
void assignment(VariableDeclaration const& _variable, Expression const& _value);
|
2019-04-29 09:39:24 +00:00
|
|
|
/// Handles assignments to variables of different types.
|
2020-05-19 12:14:46 +00:00
|
|
|
void assignment(VariableDeclaration const& _variable, smtutil::Expression const& _value);
|
2019-04-29 09:39:24 +00:00
|
|
|
/// Handles assignments between generic expressions.
|
|
|
|
/// Will also be used for assignments of tuple components.
|
2021-03-26 09:31:58 +00:00
|
|
|
void assignment(Expression const& _left, smtutil::Expression const& _right);
|
2019-04-29 09:39:24 +00:00
|
|
|
void assignment(
|
|
|
|
Expression const& _left,
|
2020-05-27 17:24:48 +00:00
|
|
|
smtutil::Expression const& _right,
|
2021-03-22 16:12:05 +00:00
|
|
|
Type const* _type
|
2019-04-29 09:39:24 +00:00
|
|
|
);
|
2020-05-27 17:24:48 +00:00
|
|
|
/// Handle assignments between tuples.
|
|
|
|
void tupleAssignment(Expression const& _left, Expression const& _right);
|
2019-04-29 09:39:24 +00:00
|
|
|
/// Computes the right hand side of a compound assignment.
|
2020-05-19 12:14:46 +00:00
|
|
|
smtutil::Expression compoundAssignment(Assignment const& _assignment);
|
2021-01-12 14:07:30 +00:00
|
|
|
/// Handles assignment of an expression to a tuple of variables.
|
|
|
|
void expressionToTupleAssignment(std::vector<std::shared_ptr<VariableDeclaration>> const& _variables, Expression const& _rhs);
|
2017-09-28 13:24:24 +00:00
|
|
|
|
2017-12-18 18:43:15 +00:00
|
|
|
/// Maps a variable to an SSA index.
|
2021-03-29 12:44:33 +00:00
|
|
|
using VariableIndices = std::unordered_map<VariableDeclaration const*, unsigned>;
|
2017-12-18 18:43:15 +00:00
|
|
|
|
|
|
|
/// Visits the branch given by the statement, pushes and pops the current path conditions.
|
|
|
|
/// @param _condition if present, asserts that this condition is true within the branch.
|
2020-11-14 14:42:32 +00:00
|
|
|
/// @returns the variable indices after visiting the branch and the expression representing
|
|
|
|
/// the path condition at the end of the branch.
|
|
|
|
std::pair<VariableIndices, smtutil::Expression> visitBranch(ASTNode const* _statement, smtutil::Expression const* _condition = nullptr);
|
|
|
|
std::pair<VariableIndices, smtutil::Expression> visitBranch(ASTNode const* _statement, smtutil::Expression _condition);
|
2017-09-28 11:44:56 +00:00
|
|
|
|
2019-06-24 15:37:03 +00:00
|
|
|
using CallStackEntry = std::pair<CallableDeclaration const*, ASTNode const*>;
|
|
|
|
|
2019-09-26 14:12:27 +00:00
|
|
|
void createStateVariables(ContractDefinition const& _contract);
|
2019-08-02 16:36:26 +00:00
|
|
|
void initializeStateVariables(ContractDefinition const& _contract);
|
2019-09-26 14:12:27 +00:00
|
|
|
void createLocalVariables(FunctionDefinition const& _function);
|
2017-09-28 13:24:24 +00:00
|
|
|
void initializeLocalVariables(FunctionDefinition const& _function);
|
2020-05-19 12:14:46 +00:00
|
|
|
void initializeFunctionCallParameters(CallableDeclaration const& _function, std::vector<smtutil::Expression> const& _callArgs);
|
2018-04-18 21:14:45 +00:00
|
|
|
void resetStateVariables();
|
2021-01-18 09:37:09 +00:00
|
|
|
void resetStorageVariables();
|
|
|
|
void resetMemoryVariables();
|
2021-08-25 09:29:42 +00:00
|
|
|
void resetBalances();
|
2020-06-05 12:54:52 +00:00
|
|
|
/// Resets all references/pointers that have the same type or have
|
|
|
|
/// a subexpression of the same type as _varDecl.
|
|
|
|
void resetReferences(VariableDeclaration const& _varDecl);
|
2020-08-25 17:28:31 +00:00
|
|
|
/// Resets all references/pointers that have type _type.
|
2021-03-22 16:12:05 +00:00
|
|
|
void resetReferences(Type const* _type);
|
2019-02-21 12:01:58 +00:00
|
|
|
/// @returns the type without storage pointer information if it has it.
|
2021-03-22 16:12:05 +00:00
|
|
|
Type const* typeWithoutPointer(Type const* _type);
|
2020-08-25 17:28:31 +00:00
|
|
|
/// @returns whether _a or a subtype of _a is the same as _b.
|
2021-03-22 16:12:05 +00:00
|
|
|
bool sameTypeOrSubtype(Type const* _a, Type const* _b);
|
2019-02-21 12:01:58 +00:00
|
|
|
|
2021-09-17 19:28:07 +00:00
|
|
|
bool isSupportedType(Type const& _type) const;
|
|
|
|
|
2021-03-29 12:44:33 +00:00
|
|
|
/// Given the state of the symbolic variables at the end of two different branches,
|
|
|
|
/// create a merged state using the given branch condition.
|
|
|
|
void mergeVariables(smtutil::Expression const& _condition, VariableIndices const& _indicesEndTrue, VariableIndices const& _indicesEndFalse);
|
2017-10-05 17:31:17 +00:00
|
|
|
/// Tries to create an uninitialized variable and returns true on success.
|
|
|
|
bool createVariable(VariableDeclaration const& _varDecl);
|
2017-07-11 11:26:43 +00:00
|
|
|
|
2017-07-14 09:49:27 +00:00
|
|
|
/// @returns an expression denoting the value of the variable declared in @a _decl
|
|
|
|
/// at the current point.
|
2021-04-27 11:30:19 +00:00
|
|
|
smtutil::Expression currentValue(VariableDeclaration const& _decl) const;
|
2017-07-14 09:49:27 +00:00
|
|
|
/// @returns an expression denoting the value of the variable declared in @a _decl
|
2018-10-17 09:32:01 +00:00
|
|
|
/// at the given index. Does not ensure that this index exists.
|
2021-04-27 11:30:19 +00:00
|
|
|
smtutil::Expression valueAtIndex(VariableDeclaration const& _decl, unsigned _index) const;
|
2019-08-07 08:48:09 +00:00
|
|
|
/// Returns the expression corresponding to the AST node.
|
|
|
|
/// If _targetType is not null apply conversion.
|
|
|
|
/// Throws if the expression does not exist.
|
2021-03-22 16:12:05 +00:00
|
|
|
smtutil::Expression expr(Expression const& _e, Type const* _targetType = nullptr);
|
2017-10-05 13:23:25 +00:00
|
|
|
/// Creates the expression (value can be arbitrary)
|
|
|
|
void createExpr(Expression const& _e);
|
|
|
|
/// Creates the expression and sets its value.
|
2020-05-19 12:14:46 +00:00
|
|
|
void defineExpr(Expression const& _e, smtutil::Expression _value);
|
2021-03-16 12:11:24 +00:00
|
|
|
/// Creates the tuple expression and sets its value.
|
|
|
|
void defineExpr(Expression const& _e, std::vector<std::optional<smtutil::Expression>> const& _values);
|
2020-11-14 14:42:32 +00:00
|
|
|
/// Overwrites the current path condition
|
|
|
|
void setPathCondition(smtutil::Expression const& _e);
|
2017-12-11 19:09:17 +00:00
|
|
|
/// Adds a new path condition
|
2020-05-19 12:14:46 +00:00
|
|
|
void pushPathCondition(smtutil::Expression const& _e);
|
2017-12-11 19:09:17 +00:00
|
|
|
/// Remove the last path condition
|
|
|
|
void popPathCondition();
|
|
|
|
/// Returns the conjunction of all path conditions or True if empty
|
2020-05-19 12:14:46 +00:00
|
|
|
smtutil::Expression currentPathConditions();
|
2019-06-24 15:37:03 +00:00
|
|
|
/// @returns a human-readable call stack. Used for models.
|
|
|
|
langutil::SecondarySourceLocation callStackMessage(std::vector<CallStackEntry> const& _callStack);
|
2019-03-11 20:06:28 +00:00
|
|
|
/// Copies and pops the last called node.
|
2019-05-06 18:03:11 +00:00
|
|
|
CallStackEntry popCallStack();
|
|
|
|
/// Adds (_definition, _node) to the callstack.
|
|
|
|
void pushCallStack(CallStackEntry _entry);
|
2017-12-13 16:59:36 +00:00
|
|
|
/// Add to the solver: the given expression implied by the current path conditions
|
2020-05-19 12:14:46 +00:00
|
|
|
void addPathImpliedExpression(smtutil::Expression const& _e);
|
2017-12-11 19:09:17 +00:00
|
|
|
|
2018-10-15 15:32:17 +00:00
|
|
|
/// Copy the SSA indices of m_variables.
|
2018-10-17 09:32:01 +00:00
|
|
|
VariableIndices copyVariableIndices();
|
|
|
|
/// Resets the variable indices.
|
|
|
|
void resetVariableIndices(VariableIndices const& _indices);
|
2019-09-26 14:12:27 +00:00
|
|
|
/// Used when starting a new block.
|
2020-02-12 01:12:42 +00:00
|
|
|
virtual void clearIndices(ContractDefinition const* _contract, FunctionDefinition const* _function = nullptr);
|
2019-09-26 14:12:27 +00:00
|
|
|
|
2018-10-15 15:32:17 +00:00
|
|
|
|
2019-04-01 09:10:28 +00:00
|
|
|
/// @returns variables that are touched in _node's subtree.
|
|
|
|
std::set<VariableDeclaration const*> touchedVariables(ASTNode const& _node);
|
|
|
|
|
2020-10-23 10:44:04 +00:00
|
|
|
/// @returns the declaration referenced by _expr, if any,
|
|
|
|
/// and nullptr otherwise.
|
2020-10-26 16:16:27 +00:00
|
|
|
Declaration const* expressionToDeclaration(Expression const& _expr) const;
|
2020-10-23 10:44:04 +00:00
|
|
|
|
|
|
|
/// @returns the VariableDeclaration referenced by an Expression or nullptr.
|
2020-10-26 16:16:27 +00:00
|
|
|
VariableDeclaration const* identifierToVariable(Expression const& _expr) const;
|
|
|
|
|
|
|
|
/// @returns the MemberAccess <expression>.push if _expr is an empty array push call,
|
|
|
|
/// otherwise nullptr.
|
|
|
|
MemberAccess const* isEmptyPush(Expression const& _expr) const;
|
2019-04-29 09:39:24 +00:00
|
|
|
|
2021-10-12 09:12:18 +00:00
|
|
|
/// @returns true if the given expression is `this`.
|
2020-11-09 13:50:41 +00:00
|
|
|
/// This means we don't have to abstract away effects of external function calls to this contract.
|
2021-10-12 09:12:18 +00:00
|
|
|
static bool isExternalCallToThis(Expression const* _expr);
|
2020-11-09 13:50:41 +00:00
|
|
|
|
2019-08-02 18:43:54 +00:00
|
|
|
/// Creates symbolic expressions for the returned values
|
|
|
|
/// and set them as the components of the symbolic tuple.
|
2021-01-25 17:17:56 +00:00
|
|
|
void createReturnedExpressions(FunctionCall const& _funCall, ContractDefinition const* _contextContract);
|
2019-08-02 18:43:54 +00:00
|
|
|
|
2020-02-12 01:11:28 +00:00
|
|
|
/// @returns the symbolic arguments for a function call,
|
2022-08-30 09:53:02 +00:00
|
|
|
/// taking into account attached functions and
|
2020-02-12 01:11:28 +00:00
|
|
|
/// type conversion.
|
2021-01-25 17:17:56 +00:00
|
|
|
std::vector<smtutil::Expression> symbolicArguments(FunctionCall const& _funCall, ContractDefinition const* _contextContract);
|
2020-02-12 01:11:28 +00:00
|
|
|
|
2021-09-13 11:57:14 +00:00
|
|
|
smtutil::Expression constantExpr(Expression const& _expr, VariableDeclaration const& _var);
|
|
|
|
|
2021-04-07 12:52:56 +00:00
|
|
|
/// Traverses all source units available collecting free functions
|
|
|
|
/// and internal library functions in m_freeFunctions.
|
|
|
|
void collectFreeFunctions(std::set<SourceUnit const*, ASTNode::CompareByID> const& _sources);
|
|
|
|
std::set<FunctionDefinition const*, ASTNode::CompareByID> const& allFreeFunctions() const { return m_freeFunctions; }
|
2021-04-07 16:53:56 +00:00
|
|
|
/// Create symbolic variables for the free constants in all @param _sources.
|
|
|
|
void createFreeConstants(std::set<SourceUnit const*, ASTNode::CompareByID> const& _sources);
|
2021-04-07 12:52:56 +00:00
|
|
|
|
2019-06-25 10:46:17 +00:00
|
|
|
/// @returns a note to be added to warnings.
|
|
|
|
std::string extraComment();
|
|
|
|
|
2020-02-12 01:09:45 +00:00
|
|
|
struct VerificationTarget
|
|
|
|
{
|
2021-01-19 11:56:22 +00:00
|
|
|
VerificationTargetType type;
|
2020-05-19 12:14:46 +00:00
|
|
|
smtutil::Expression value;
|
|
|
|
smtutil::Expression constraints;
|
2020-02-12 01:09:45 +00:00
|
|
|
};
|
|
|
|
|
2019-05-09 10:16:52 +00:00
|
|
|
smt::VariableUsage m_variableUsage;
|
2018-12-14 11:21:43 +00:00
|
|
|
bool m_arrayAssignmentHappened = false;
|
2019-05-13 14:53:38 +00:00
|
|
|
|
2018-10-25 14:00:09 +00:00
|
|
|
/// Stores the instances of an Uninterpreted Function applied to arguments.
|
2018-11-09 16:06:30 +00:00
|
|
|
/// These may be direct application of UFs or Array index access.
|
2018-10-25 14:00:09 +00:00
|
|
|
/// Used to retrieve models.
|
2018-11-09 16:06:30 +00:00
|
|
|
std::set<Expression const*> m_uninterpretedTerms;
|
2020-05-19 12:14:46 +00:00
|
|
|
std::vector<smtutil::Expression> m_pathConditions;
|
2020-12-16 17:32:34 +00:00
|
|
|
|
|
|
|
/// Whether the currently visited block uses checked
|
|
|
|
/// or unchecked arithmetic.
|
|
|
|
bool m_checked = true;
|
|
|
|
|
2021-08-27 09:40:20 +00:00
|
|
|
langutil::UniqueErrorReporter& m_errorReporter;
|
2017-07-11 11:26:43 +00:00
|
|
|
|
2019-05-06 18:03:11 +00:00
|
|
|
/// Stores the current function/modifier call/invocation path.
|
|
|
|
std::vector<CallStackEntry> m_callStack;
|
2021-01-21 18:04:34 +00:00
|
|
|
|
|
|
|
/// Stack of scopes.
|
|
|
|
std::vector<ScopeOpener const*> m_scopes;
|
|
|
|
|
2018-10-10 12:31:49 +00:00
|
|
|
/// Returns true if the current function was not visited by
|
|
|
|
/// a function call.
|
|
|
|
bool isRootFunction();
|
|
|
|
/// Returns true if _funDef was already visited.
|
|
|
|
bool visitedFunction(FunctionDefinition const* _funDef);
|
2021-01-25 17:17:56 +00:00
|
|
|
/// @returns the contract that contains the current FunctionDefinition that is being visited,
|
|
|
|
/// or nullptr if the analysis is not inside a FunctionDefinition.
|
|
|
|
ContractDefinition const* currentScopeContract();
|
2019-02-06 10:12:02 +00:00
|
|
|
|
2020-12-21 17:17:56 +00:00
|
|
|
/// @returns FunctionDefinitions of the given contract (including its constructor and inherited methods),
|
|
|
|
/// taking into account overriding of the virtual functions.
|
2021-01-25 17:17:56 +00:00
|
|
|
std::set<FunctionDefinition const*, ASTNode::CompareByID> const& contractFunctions(ContractDefinition const& _contract);
|
2020-12-21 17:17:56 +00:00
|
|
|
/// Cache for the method contractFunctions.
|
2021-01-25 17:17:56 +00:00
|
|
|
std::map<ContractDefinition const*, std::set<FunctionDefinition const*, ASTNode::CompareByID>> m_contractFunctions;
|
|
|
|
|
|
|
|
/// @returns FunctionDefinitions of the given contract (including its constructor and methods of bases),
|
|
|
|
/// without taking into account overriding of the virtual functions.
|
|
|
|
std::set<FunctionDefinition const*, ASTNode::CompareByID> const& contractFunctionsWithoutVirtual(ContractDefinition const& _contract);
|
|
|
|
/// Cache for the method contractFunctionsWithoutVirtual.
|
|
|
|
std::map<ContractDefinition const*, std::set<FunctionDefinition const*, ASTNode::CompareByID>> m_contractFunctionsWithoutVirtual;
|
2020-12-21 17:17:56 +00:00
|
|
|
|
2019-03-11 20:06:28 +00:00
|
|
|
/// Depth of visit to modifiers.
|
|
|
|
/// When m_modifierDepth == #modifiers the function can be visited
|
|
|
|
/// when placeholder is visited.
|
|
|
|
/// Needs to be a stack because of function calls.
|
|
|
|
std::vector<int> m_modifierDepthStack;
|
2019-04-17 13:55:46 +00:00
|
|
|
|
2019-09-26 14:12:27 +00:00
|
|
|
std::map<ContractDefinition const*, ModifierInvocation const*> m_baseConstructorCalls;
|
|
|
|
|
2019-08-02 16:36:26 +00:00
|
|
|
ContractDefinition const* m_currentContract = nullptr;
|
|
|
|
|
2021-04-07 12:52:56 +00:00
|
|
|
/// Stores the free functions and internal library functions.
|
|
|
|
/// Those need to be encoded repeatedely for every analyzed contract.
|
|
|
|
std::set<FunctionDefinition const*, ASTNode::CompareByID> m_freeFunctions;
|
|
|
|
|
2019-04-17 13:55:46 +00:00
|
|
|
/// Stores the context of the encoding.
|
2019-06-25 10:46:17 +00:00
|
|
|
smt::EncodingContext& m_context;
|
2021-02-03 10:31:17 +00:00
|
|
|
|
2022-05-15 15:45:43 +00:00
|
|
|
ModelCheckerSettings m_settings;
|
2021-04-15 10:31:45 +00:00
|
|
|
|
2021-07-01 15:28:06 +00:00
|
|
|
/// Character stream for each source,
|
|
|
|
/// used for retrieving source text of expressions for e.g. counter-examples.
|
|
|
|
langutil::CharStreamProvider const& m_charStreamProvider;
|
|
|
|
|
2021-02-03 10:31:17 +00:00
|
|
|
smt::SymbolicState& state();
|
2017-07-06 09:05:05 +00:00
|
|
|
};
|
|
|
|
|
|
|
|
}
|