Commit c048971
Do not assert dependency contracts for calls made by contract clauses
Contracts of dependencies are asserted by default (#3802) as an aid for
detecting API misuse in user code. Calls made while evaluating
*contract clauses*, however, are specification-level plumbing: clause
expressions compute a predicate over pre-/post-states, and the
functions they call are best executed with their exact semantics.
Re-asserting dependency contracts inside every clause evaluation
multiplies verification cost - clauses of contract-dense code (e.g. the
Rust standard library in model-checking/verify-rust-std) routinely call
contracted functions like NonNull::as_ptr, paying the assert-closure
overhead per clause instance - without checking any user code.
Extend the clause-context dispatch introduced for check modes to assert
mode: calls to a contracted dependency that occur during clause
evaluation now execute the original body (mode 0). The body remains
fully inlined and UB-checked; only the requires/ensures assertions of
the *callee's* contract are skipped in this context.
The new regression test checks both halves: a clause calling a
contracted function with precondition-violating (but well-defined)
arguments verifies successfully, while the same misuse in user code is
still caught.
Co-authored-by: Kiro <kiro-agent@users.noreply.github.com>1 parent fe4eef9 commit c048971
3 files changed
Lines changed: 68 additions & 14 deletions
File tree
- kani-compiler/src/kani_middle/transform
- tests/expected/function-contract
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
453 | 453 | | |
454 | 454 | | |
455 | 455 | | |
456 | | - | |
457 | | - | |
458 | | - | |
459 | | - | |
460 | | - | |
461 | | - | |
462 | | - | |
463 | | - | |
464 | | - | |
465 | | - | |
466 | | - | |
467 | | - | |
468 | | - | |
469 | | - | |
| 456 | + | |
| 457 | + | |
| 458 | + | |
| 459 | + | |
| 460 | + | |
| 461 | + | |
| 462 | + | |
| 463 | + | |
| 464 | + | |
| 465 | + | |
| 466 | + | |
| 467 | + | |
| 468 | + | |
| 469 | + | |
| 470 | + | |
| 471 | + | |
| 472 | + | |
| 473 | + | |
| 474 | + | |
| 475 | + | |
| 476 | + | |
| 477 | + | |
| 478 | + | |
| 479 | + | |
| 480 | + | |
| 481 | + | |
| 482 | + | |
| 483 | + | |
| 484 | + | |
470 | 485 | | |
471 | 486 | | |
472 | 487 | | |
| |||
Lines changed: 4 additions & 0 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
Lines changed: 35 additions & 0 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
| 18 | + | |
| 19 | + | |
| 20 | + | |
| 21 | + | |
| 22 | + | |
| 23 | + | |
| 24 | + | |
| 25 | + | |
| 26 | + | |
| 27 | + | |
| 28 | + | |
| 29 | + | |
| 30 | + | |
| 31 | + | |
| 32 | + | |
| 33 | + | |
| 34 | + | |
| 35 | + | |
0 commit comments