Challenge 10: Kani contracts for String memory safety - #645
Open
sankalpsthakur wants to merge 7 commits into
Open
Challenge 10: Kani contracts for String memory safety#645sankalpsthakur wants to merge 7 commits into
sankalpsthakur wants to merge 7 commits into
Conversation
Kani contracts and harnesses for verify-rust-std challenge. Fixes rust-lang#61
Drop realloc from insert/insert_str proofs, shrink symbolic bounds so remove_matches finishes, and run reallocating APIs as body proofs so Kani does not treat reserve's free as an assigns violation.
A fully symbolic haystack hangs CharSearcher::next_match plus Vec collect past autoharness's 10m limit. Use a concrete ASCII prefix of symbolic length 0..=2 so the real ptr::copy / set_len path still runs.
Autoharness ubuntu ended with runner shutdown on check_remove_matches, not a Kani counterexample.
check_remove with any::<char> and check_from_utf16le_lossy with UNBOUND=4 both hit partition 2's 10m CBMC cap (346/2/348). Use ASCII length 1..=2 for remove and a 2-byte slice for lossy decode.
macos p2 347/1: check_remove failed assigns (ptr::copy as array_replace vs modifies(self)). macos p1 345/3: remove_matches OOM, retain havoc. Use body proofs and ASCII length 0..=1/2.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Kani safety contracts and proof harnesses for this challenge. Runtime stdlib logic is unchanged; annotations are cfg(kani) / contract attributes.
String allocation/mutation safety contracts.
Validation
challenge/10-stringscripts/run-kani.sh)Fixes #61
AI/LLM disclosure