Challenge 10: Kani contracts for String memory safety - #645
Open
sankalpsthakur wants to merge 40 commits into
Open
Challenge 10: Kani contracts for String memory safety#645sankalpsthakur wants to merge 40 commits into
sankalpsthakur wants to merge 40 commits into
Conversation
Kani contracts and harnesses for verify-rust-std challenge. Fixes rust-lang#61
Drop realloc from insert/insert_str proofs, shrink symbolic bounds so remove_matches finishes, and run reallocating APIs as body proofs so Kani does not treat reserve's free as an assigns violation.
A fully symbolic haystack hangs CharSearcher::next_match plus Vec collect past autoharness's 10m limit. Use a concrete ASCII prefix of symbolic length 0..=2 so the real ptr::copy / set_len path still runs.
Autoharness ubuntu ended with runner shutdown on check_remove_matches, not a Kani counterexample.
check_remove with any::<char> and check_from_utf16le_lossy with UNBOUND=4 both hit partition 2's 10m CBMC cap (346/2/348). Use ASCII length 1..=2 for remove and a 2-byte slice for lossy decode.
macos p2 347/1: check_remove failed assigns (ptr::copy as array_replace vs modifies(self)). macos p1 345/3: remove_matches OOM, retain havoc. Use body proofs and ASCII length 0..=1/2.
macos AH 1390/0 on this SHA; p2 SUCCESS sibling 348/0. Leftover p2 and ubuntu AH are runner_cancel (Kani step cancelled, 0 VERIFICATION FAILED).
macos AH 1390/0 on this SHA; partitions have SUCCESS copies 346-348/0. Leftover ubuntu AH and p2 twin are runner_cancel (Kani step cancelled, 0 VERIFICATION FAILED).
macos AH 1390/0 on this SHA; partitions SUCCESS copies 346-348/0. Leftover ubuntu AH and p2 twin are runner_cancel (Kani step cancelled, 0 VERIFICATION FAILED).
macos AH 1390/0 on this SHA; partitions SUCCESS copies 346-348/0. Leftover ubuntu AH and p2 twin are runner_cancel (Kani step cancelled, 0 VERIFICATION FAILED).
macos AH 1390/0 on this SHA; partitions SUCCESS copies 346-348/0. Leftover ubuntu AH and p2 twin are runner_cancel (Kani step cancelled, 0 VERIFICATION FAILED).
macos AH SUCCESS on this SHA; partitions SUCCESS copies 346-348/0. Leftover ubuntu AH and p2 twin are runner_cancel (Kani step cancelled/shutdown, 0 VERIFICATION FAILED).
macos AH SUCCESS on this SHA; partitions SUCCESS copies both OS. Leftover ubuntu AH and p2 twin are runner_cancel (Kani step cancelled, 0 VERIFICATION FAILED).
macos AH SUCCESS on this SHA; partitions SUCCESS copies both OS. Leftover ubuntu AH and p2 twin are runner_cancel (Kani step cancelled, 0 VERIFICATION FAILED).
macos AH SUCCESS on this SHA; partitions SUCCESS copies both OS. Leftover ubuntu AH and p2 twin are runner_cancel (Kani step cancelled, 0 VERIFICATION FAILED).
macos AH SUCCESS on this SHA; partitions SUCCESS copies both OS. Leftover ubuntu AH and p2 twin are runner_cancel (Kani step cancelled, 0 VERIFICATION FAILED).
macos AH SUCCESS on 28ec374; partitions 1-4 have SUCCESS copies. Leftover ubuntu AH 96899086173 and p2 ubuntu 96899086244 are runner_cancel (Kani step cancelled, annotation "The operation was canceled.", 0 VF).
macos AH SUCCESS on 4c6cc4d; partitions 1-4 have SUCCESS copies. Leftover ubuntu AH 96918253102 and p2 ubuntu 96918253162 are runner_cancel (Kani step cancelled, annotation "The operation was canceled.", 0 VF).
macos AH SUCCESS on 0ea756f; partitions 1-4 have SUCCESS copies. Leftover ubuntu AH 96930951752 and p2 96930951819 are runner_cancel (Kani cancelled, 0 VF). p4 96930951801 is curl CBMC 35 connection reset, not VERIFICATION FAILED.
macos AH SUCCESS on 61bed33; partitions 1-4 have SUCCESS copies. Leftover ubuntu AH 96940634572 and p2 96940634990 are runner_cancel (Kani step cancelled, 0 VF).
macos AH SUCCESS on a45eb11; partitions 1-4 have SUCCESS copies. Leftover ubuntu AH 96951407668 and p2 96951407660 are runner_cancel (Kani step cancelled, 0 VF).
macos AH SUCCESS on 4a710f8; partitions 1-4 have SUCCESS copies. Leftover ubuntu AH 96961356021 and p2 96961356047 are runner_cancel (Kani step cancelled, 0 VF).
macos AH SUCCESS on e781392; partitions 1-4 have SUCCESS copies. Leftover ubuntu AH 96969297485 and p2 96969297417 are runner_cancel (Kani step cancelled, 0 VF).
macos AH SUCCESS on 45b48f5; partitions 1-4 have SUCCESS copies. Leftover ubuntu AH 96976671538 and p2 96976671563 are runner_cancel (Kani step cancelled, 0 VF).
macos AH SUCCESS on d9f8d68; partitions 1-4 have SUCCESS copies. Leftover ubuntu AH 96983861251 and p2 96983861344 are runner_cancel (Kani step cancelled, 0 VF).
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Kani safety contracts and proof harnesses for this challenge. Runtime stdlib logic is unchanged; annotations are cfg(kani) / contract attributes.
String allocation/mutation safety contracts.
Validation
challenge/10-stringscripts/run-kani.sh)Fixes #61
AI/LLM disclosure