File: main.c

package info (click to toggle)
cbmc 6.6.0-4
  • links: PTS
  • area: main
  • in suites: forky, sid, trixie
  • size: 153,852 kB
  • sloc: cpp: 386,459; ansic: 114,466; java: 28,405; python: 6,003; yacc: 4,552; makefile: 4,041; lex: 2,487; xml: 2,388; sh: 2,050; perl: 557; pascal: 184; javascript: 163; ada: 36
file content (36 lines) | stat: -rw-r--r-- 945 bytes parent folder | download
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
#include <stdlib.h>

void foo(int *a, int *b)
  // clang-format off
__CPROVER_requires(__CPROVER_is_fresh(a, 3*sizeof(int)))
__CPROVER_requires(__CPROVER_is_fresh(b, 3*sizeof(int)))
__CPROVER_assigns(__CPROVER_object_upto(a, 3*sizeof(int)))
__CPROVER_ensures(a[0] == b[0])
__CPROVER_ensures(a[1] == b[1])
__CPROVER_ensures(a[2] == b[2])
;

int nondet_int();

void bar()
{
  int a[6];
  int b[3];
  // c is either either a slice of `a` disjoint from a[0..2] or `b`
  int *c = nondet_int() ? &a[0] + 3: &b[0];
  int old_c0 = c[0];
  int old_c1 = c[1];
  int old_c2 = c[2];
  foo(a, c); // success of preconditions
  __CPROVER_assert(a[0] == c[0], "same value 0");
  __CPROVER_assert(a[1] == c[1], "same value 1");
  __CPROVER_assert(a[2] == c[2], "same value 2");
  __CPROVER_assert(old_c0 == c[0], "unmodified 0");
  __CPROVER_assert(old_c1 == c[1], "unmodified 1");
  __CPROVER_assert(old_c2 == c[2], "unmodified 2");
}

int main()
{
  bar();
}