File: main.c

package info (click to toggle)
cbmc 6.6.0-4
  • links: PTS
  • area: main
  • in suites: forky, sid, trixie
  • size: 153,852 kB
  • sloc: cpp: 386,459; ansic: 114,466; java: 28,405; python: 6,003; yacc: 4,552; makefile: 4,041; lex: 2,487; xml: 2,388; sh: 2,050; perl: 557; pascal: 184; javascript: 163; ada: 36
file content (45 lines) | stat: -rw-r--r-- 1,155 bytes parent folder | download
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
#include <stdbool.h>
#include <stdlib.h>

// type of functions that manipulate arrays
typedef void (*arr_fun_t)(char *arr, size_t size);

// A contract for the arr_fun_t type
// requires a fresh array and positive size
// resets the first element to zero
void arr_fun_contract(char *arr, size_t size)
  // clang-format off
__CPROVER_requires(0 < size && __CPROVER_is_fresh(arr, size))
__CPROVER_assigns(arr[0])
__CPROVER_ensures(arr[0] == 0)
  // clang-format on
  ;

// Testing pre-conditions constructs
// Takes a function pointer as input, uses it if its preconditions are met
// to establish post-conditions
int foo(char *arr, size_t size, arr_fun_t arr_fun)
  // clang-format off
__CPROVER_requires(arr == NULL || __CPROVER_is_fresh(arr, size))
__CPROVER_requires(__CPROVER_obeys_contract(arr_fun, arr_fun_contract))
__CPROVER_assigns(arr && size > 0 : arr[0])
__CPROVER_ensures((__CPROVER_return_value == 0) ==> (arr[0] == 0))
// clang-format on
{
  int retval = -1;
  if(arr && size > 0)
  {
  CALL:
    arr_fun(arr, size);
    retval = 0;
  }
  return retval;
}

void main()
{
  size_t size;
  char *arr;
  arr_fun_t fun;
  foo(arr, size, fun);
}