Frama-C-discuss mailing list archives
This page gathers the archives of the old Frama-C-discuss archives, that was hosted by Inria's gforge before its demise at the end of 2020. To search for mails newer than September 2020, please visit the page of the new mailing list on Renater.
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[Frama-c-discuss] [PROVENANCE INTERNET] problems with recognition of the variant
- Subject: [Frama-c-discuss] [PROVENANCE INTERNET] problems with recognition of the variant
- From: loic.correnson at cea.fr (Loïc Correnson)
- Date: Fri, 12 Dec 2014 10:01:35 +0100
- In-reply-to: <12506_1418372019_548AA3B3_12506_291_1_548AA3A9.9000504@cea.fr>
- References: <CAAEWojUFkWjLv9yDjp37=zP0coN1xnFxuuhNc0ER_570HpFpYQ@mail.gmail.com> <548A97AE.7010808@cs.unipr.it> <12506_1418372019_548AA3B3_12506_291_1_548AA3A9.9000504@cea.fr>
You can also add a lemma or axiom asserting the decreasing of the shift, or the equivalence of shifting and dividing for the desired constants. L. Le 12 d?c. 2014 ? 09:13, BAUDIN Patrick <Patrick.Baudin at cea.fr> a ?crit : > Your code was : > void testVariant(unsigned long n) { > unsigned long i= n; > /*@loop variant i;*/ > while (i >= 2UL) { > i >>= 2UL; > } > } > Replacing the shift by integer division is a good idea since it could help to get automatic proof (the use of the shift will require a coq proof). > That will help you in guessing the missing loop invariants. > They are needed for the proof of your loop variant. > Also, perhaps that "i/2" is a better variant. > > Le 12/12/2014 08:22, Roberto Bagnara a ?crit : >> On 20/11/2014 18:03, ALESSIO BORTOLOTTI wrote: >>> While I was trying to prove a while loop containing shifts, I ran into a problem: the program couldn't recognize the variable on which I have done the shift as a variant. >> I stumbled upon the same issue. Apparently the latest version >> of Frama-C is not able to prove that a nonzero unsigned quantity >> shifted to the right by a nonzero number of positions results >> in a strict decrease. Replacing shift by integer division does >> not help. Can someone on this list explain what is going on? >> Is there a workaround for this problem? >> Kind regards, >> >> Roberto >> > > _______________________________________________ > Frama-c-discuss mailing list > Frama-c-discuss at lists.gforge.inria.fr > http://lists.gforge.inria.fr/cgi-bin/mailman/listinfo/frama-c-discuss -------------- next part -------------- An HTML attachment was scrubbed... URL: <http://lists.gforge.inria.fr/pipermail/frama-c-discuss/attachments/20141212/b714a0b8/attachment-0001.html>
- References:
- [Frama-c-discuss] problems with recognition of the variant
- From: bagnara at cs.unipr.it (Roberto Bagnara)
- [Frama-c-discuss] problems with recognition of the variant
- Prev by Date: [Frama-c-discuss] problems with recognition of the variant
- Next by Date: [Frama-c-discuss] Queries regarding WP plugin
- Previous by thread: [Frama-c-discuss] problems with recognition of the variant
- Next by thread: [Frama-c-discuss] Invitation to one day workshop around SMT solvers in Paris
- Index(es):