Simple normalizations for +1/-1 bounds scenarios#1128
Merged
Conversation
added 21 commits
July 7, 2021 15:53
…dths methods from BaseRange and call utility methods instead
… already in the output form
…into plus-one-minus-one-bounds-widening
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR implements some transformation functions to enable the bounds checker to validate some additional bounds.
These normalization functions attempt to express a given upper bound expression as
((E1 + E2) +/- A) +/- B, whereE1has pointer type andAandBare integer constants. The bounds checker can use the variable partE1 + E2and the constant partA + Bto compare bounds expressions.This enables the bounds checker to validate certain bounds that can arise in bounds widening scenarios. For example:
The bounds checker can express the inferred upper bound
(p + (len - 1)) + 1)as ((p + len) - 1) + 1and extract the variable partp + lenand the constant part-1 + 1 == 0. The bounds checker can then use these to prove that the inferred upper bound is equivalent to the declared upper boundp + len`.