Module Pulselib.PulseAbductiveDomain
module BaseAddressAttributes = PulseBaseAddressAttributesmodule BaseDomain = PulseBaseDomainmodule BaseMemory = PulseBaseMemorymodule BaseStack = PulseBaseStackmodule type BaseDomainSig = sig ... endsignature common to the "normal"
Domain, representing the post at the current program point, and the invertedPreDomain, representing the inferred pre-condition
module PostDomain : BaseDomainSigThe post abstract state at each program point, or current state.
module PreDomain : BaseDomainSigThe inferred pre-condition at each program point, biabduction style.
type isl_status=|ISLOkok triple: the program executes without error
|ISLErrorError specification: an invalid address recorded in the precondition will cause an error
Execution status, similar to
PulseExecutionDomainbut for ISL (Incorrectness Separation Logic) mode, wherePulseExecutionDomain.base_t.ContinueProgramcan also contain "error specs" that describe what happens when some addresses are invalid explicitly instead of relying onMustBeValidattributes.
val equal_isl_status : isl_status -> isl_status -> bool
type t= private{post : PostDomain.t;state at the current program point
pre : PreDomain.t;inferred procedure pre-condition leading to the current program point
path_condition : PulseBasicInterface.PathCondition.t;arithmetic facts true along the path (holding for both
preandpostsince abstract values are immutable)topl : PulseTopl.state;state at of the Topl monitor at the current program point, when Topl is enabled
skipped_calls : PulseBasicInterface.SkippedCalls.t;metadata: procedure calls for which no summary was found
isl_status : isl_status;}pre/post on a single program path
val leq : lhs:t -> rhs:t -> boolval pp : Stdlib.Format.formatter -> t -> unitval set_isl_status : isl_status -> t -> tval mk_initial : IR.Tenv.t -> IR.Procdesc.t -> tval get_pre : t -> BaseDomain.tval get_post : t -> BaseDomain.t
module Stack : sig ... endstack operations like
BaseStackbut that also take care of propagating facts to the precondition
module Memory : sig ... endmemory operations like
BaseMemorybut that also take care of propagating facts to the precondition
module AddressAttributes : sig ... endattribute operations like
BaseAddressAttributesbut that also take care of propagating facts to the precondition
val is_local : IR.Var.t -> t -> boolval find_post_cell_opt : PulseBasicInterface.AbstractValue.t -> t -> BaseDomain.cell optionval discard_unreachable : t -> t * Pulselib.PulseBasicInterface.AbstractValue.Set.t * PulseBasicInterface.AbstractValue.t listgarbage collect unreachable addresses in the state to make it smaller and return the new state, the live addresses, and the discarded addresses that used to have attributes attached
val add_skipped_call : IR.Procname.t -> PulseBasicInterface.Trace.t -> t -> tval add_skipped_calls : PulseBasicInterface.SkippedCalls.t -> t -> tval set_path_condition : PulseBasicInterface.PathCondition.t -> t -> t
type summary= private tprivate type to make sure
summary_of_postis always called when creating summaries
val summary_of_post : IR.Procdesc.t -> t -> summary PulseBasicInterface.SatUnsat.ttrim the state down to just the procedure's interface (formals and globals), and simplify and normalize the state
val set_post_edges : PulseBasicInterface.AbstractValue.t -> BaseMemory.Edges.t -> t -> tdirectly set the edges for the given address, bypassing abduction altogether
val set_post_cell : (PulseBasicInterface.AbstractValue.t * PulseBasicInterface.ValueHistory.t) -> BaseDomain.cell -> IBase.Location.t -> t -> tdirectly set the edges and attributes for the given address, bypassing abduction altogether
val incorporate_new_eqs : t -> (PulseBasicInterface.PathCondition.t * PulseBasicInterface.PathCondition.new_eqs) -> PulseBasicInterface.PathCondition.tCheck that the new equalities discovered are compatible with the current pre and post heaps, e.g.
x = 0is not compatible withxbeing allocated, andx = yis not compatible withxandybeing allocated separately. In those cases, the resulting path condition isPathCondition.false_.
val initialize : PulseBasicInterface.AbstractValue.t -> t -> tRemove "Uninitialized" attribute of the given address
val set_uninitialized : IR.Tenv.t -> [ `LocalDecl of IR.Pvar.t * PulseBasicInterface.AbstractValue.t option | `Malloc of PulseBasicInterface.AbstractValue.t ] -> IR.Typ.t -> IBase.Location.t -> t -> tAdd "Uninitialized" attributes when a variable is declared or a memory is allocated by malloc.
module Topl : sig ... end