summaryrefslogtreecommitdiff
path: root/Test/og/linear-set.bpl
blob: 1a0cde426b73af6b083c26573d8620d549ec2116 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
function {:inline} Subset(a: [X]bool, b: [X]bool) : bool
{
    MapImp(a, b) == MapConstBool(true)
}

function {:inline} In(a: X, b: [X]bool) : bool
{
    b[a]
}

function {:inline} None() : [X]bool
{
    MapConstBool(false)
}

function {:inline} All() : [X]bool
{
    MapConstBool(true)
}

var x: int;
var l: [X]bool;

procedure Split({:linear "x"} xls: [X]bool) returns ({:linear "x"} xls1: [X]bool, {:linear "x"} xls2: [X]bool);
ensures xls == MapOr(xls1, xls2) && xls1 != None() && xls2 != None();

procedure {:entrypoint} main({:linear "tid"} tidls': [X]bool, {:linear "x"} xls': [X]bool) 
requires tidls' != None() && xls' == All();
{
    var {:linear "tid"} tidls: [X]bool;
    var {:linear "x"} xls: [X]bool;
    var {:linear "tid"} lsChild: [X]bool;
    var {:linear "x"} xls1: [X]bool;
    var {:linear "x"} xls2: [X]bool;

    havoc tidls, xls;
    assume tidls' == tidls && xls' == xls;

    x := 42;
    assert {:yield} xls == All();
    assert x == 42;
    call xls1, xls2 := Split(xls);
    havoc lsChild;
    assume (lsChild != None());
    call {:async} thread(lsChild, xls1);
    havoc lsChild;
    assume (lsChild != None());
    call {:async} thread(lsChild, xls2);
}

procedure thread({:linear "tid"} tidls': [X]bool, {:linear "x"} xls': [X]bool)
requires tidls' != None() && xls' != None();
{
    var {:linear "x"} xls: [X]bool;
    var {:linear "tid"} tidls: [X]bool;

    havoc tidls, xls;
    assume tidls' == tidls && xls' == xls;

    assume l == None();
    l := tidls;
    assert {:yield} tidls != None() && xls != None();
    x := 0;
    assert {:yield} tidls != None() && xls != None();
    assert x == 0;
    assert {:yield} tidls != None() && xls != None();
    l := None();
}