blob: ac4a2e21433efae0b92f7da0381244a6002a0528 (
plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
|
type X;
function {:builtin "MapConst"} MapConstInt(int) : [X]int;
function {:builtin "MapConst"} MapConstBool(bool) : [X]bool;
function {:builtin "MapOr"} MapOr([X]bool, [X]bool) : [X]bool;
function {:inline} None() : [X]bool
{
MapConstBool(false)
}
function {:inline} All() : [X]bool
{
MapConstBool(true)
}
var x: int;
var l: X;
const nil: X;
procedure Split({:linear "x"} xls: [X]bool) returns ({:linear "x"} xls1: [X]bool, {:linear "x"} xls2: [X]bool);
ensures xls == MapOr(xls1, xls2) && xls1 != None() && xls2 != None();
procedure Allocate() returns ({:linear "tid"} xls: X);
ensures xls != nil;
procedure {:entrypoint} main({:linear "tid"} tidls': X, {:linear "x"} xls': [X]bool)
requires tidls' != nil && xls' == All();
{
var {:linear "tid"} tidls: X;
var {:linear "x"} xls: [X]bool;
var {:linear "tid"} lsChild: X;
var {:linear "x"} xls1: [X]bool;
var {:linear "x"} xls2: [X]bool;
tidls := tidls';
xls := xls';
x := 42;
yield;
assert xls == All();
assert x == 42;
call xls1, xls2 := Split(xls);
call lsChild := Allocate();
async call thread(lsChild, xls1);
call lsChild := Allocate();
async call thread(lsChild, xls2);
}
procedure thread({:linear "tid"} tidls': X, {:linear "x"} xls': [X]bool)
requires tidls' != nil && xls' != None();
{
var {:linear "x"} xls: [X]bool;
var {:linear "tid"} tidls: X;
tidls := tidls';
xls := xls';
assume l == nil;
l := tidls;
yield;
assert tidls != nil && xls != None();
x := 0;
yield;
assert tidls != nil && xls != None();
assert x == 0;
yield;
assert tidls != nil && xls != None();
l := nil;
}
|