3
我在努力學習ACSL,但是試圖編寫一個完整的規範時磕磕絆絆。我的代碼如何在frama-c中調試ACSL?
#include <stdint.h>
#include <stddef.h>
#define NUM_ELEMS (8)
/*@ requires expected != test;
@ requires \let n = NUM_ELEMS;
@ \valid_read(expected + (0.. n-1)) && \valid_read(test + (0.. n-1));
@ assigns \nothing;
@ behavior matches:
@ assumes \let n = NUM_ELEMS;
@ \forall integer i; 0 <= i < n ==> expected[i] == test[i];
@ ensures \result == 1;
@ behavior not_matches:
@ assumes \let n = NUM_ELEMS;
@ \exists integer i; 0 <= i < n && expected[i] != test[i];
@ ensures \result == 0;
@ complete behaviors;
@ disjoint behaviors;
@*/
int array_equals(const uint32_t expected[static NUM_ELEMS], const uint32_t test[static NUM_ELEMS]) {
for (size_t i = 0; i < NUM_ELEMS; i++) {
if (expected[i] != test[i]) {
return 0;
}
}
return 1;
}
我與運行
郵資-C -wp -wp即食test.c的
,我看到下面的日誌
[kernel] Parsing FRAMAC_SHARE/libc/__fc_builtin_for_normalization.i (no preprocessing)
[kernel] Parsing test.c (with preprocessing)
[rte] annotating function array_equals
test.c:22:[wp] warning: Missing assigns clause (assigns 'everything' instead)
[wp] 9 goals scheduled
[wp] [Alt-Ergo] Goal typed_array_equals_assign_part1 : Unknown (Qed:2ms) (67ms)
[wp] [Alt-Ergo] Goal typed_array_equals_assert_rte_mem_access_2 : Unknown (Qed:2ms) (128ms)
[wp] [Alt-Ergo] Goal typed_array_equals_assert_rte_mem_access : Unknown (Qed:2ms) (125ms)
[wp] [Alt-Ergo] Goal typed_array_equals_matches_post : Unknown (Qed:10ms) (175ms)
[wp] [Alt-Ergo] Goal typed_array_equals_not_matches_post : Unknown (Qed:7ms) (109ms)
[wp] Proved goals: 4/9
Qed: 4 (0.56ms-4ms)
Alt-Ergo: 0 (unknown: 5)
所以看起來好像我的兩種行爲和「分配\沒有」無法證明。那麼我怎麼從這裏開始呢?
編輯:所以我想通了問題。我沒有註釋我的循環:
/*@ loop invariant \let n = NUM_ELEMS; 0 <= i <= n;
@ loop invariant \forall integer k; 0 <= k < i ==> expected[k] == test[k];
@ loop assigns i;
@ loop variant \let n = NUM_ELEMS; n-i;
@*/
我的更大的問題仍然是:什麼是調試問題的好方法?我通過更改和刪除代碼並查看證明/未證實的內容來解決此問題。
謝謝,這些都是有益的策略! – Yifan
關於'assert',我們應該注意不要在程序中向下依賴它們,即有人可能會認爲某些事情是由於(有時是錯誤的)'assert'而被證明的。 –
@DavidMENTRÉ的確。這是「假設下的有效性」(GUI中的綠色/黃色項目符號)狀態的作用:依賴於尚未證實的「斷言」的後置條件(或循環不變或另一個斷言)不會被標記爲完全驗證(完全綠色的子彈)。類似地,'-report'將標記「Partial」而不是'Valid'等屬性。 – Virgile