Skip to content

DFCC instrumentation: skip unused functions #8628

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Open
wants to merge 1 commit into
base: develop
Choose a base branch
from

Conversation

tautschnig
Copy link
Collaborator

Do not attempt to instrument functions that will never be used anyway. As we eventually use remove_unused_functions there is no point in trying to instrument them, and there is a scenario where the function may not have been compiled (see included test).

  • Each commit message has a non-empty body, explaining why the change was made.
  • n/a Methods or procedures I have added are documented, following the guidelines provided in CODING_STANDARD.md.
  • n/a The feature or user visible behaviour I have added or modified has been documented in the User Guide in doc/cprover-manual/
  • Regression or unit tests are included, or existing tests cover the modified code (in this case I have detailed which ones those are in the commit message).
  • n/a My commit message includes data points confirming performance improvements (if claimed).
  • My PR is restricted to a single feature or bugfix.
  • n/a White-space or formatting changes outside the feature-related changed lines are in commits of their own.

Do not attempt to instrument functions that will never be used anyway.
As we eventually use `remove_unused_functions` there is no point in
trying to instrument them, and there is a scenario where the function
may not have been compiled (see included test).
Copy link

codecov bot commented Apr 16, 2025

Codecov Report

Attention: Patch coverage is 80.00000% with 1 line in your changes missing coverage. Please review.

Project coverage is 80.37%. Comparing base (5dc709d) to head (fa4a51c).

Files with missing lines Patch % Lines
.../goto-instrument/contracts/dynamic-frames/dfcc.cpp 80.00% 1 Missing ⚠️
Additional details and impacted files
@@           Coverage Diff            @@
##           develop    #8628   +/-   ##
========================================
  Coverage    80.37%   80.37%           
========================================
  Files         1686     1686           
  Lines       206872   206877    +5     
  Branches        73       73           
========================================
+ Hits        166265   166271    +6     
+ Misses       40607    40606    -1     

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@@ -272,7 +278,7 @@ void dfcct::partition_function_symbols(
{
contract_symbols.insert(sym_name);
}
else
else if(called_functions.find(sym_name) != called_functions.end())
Copy link
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

When the program uses function pointers find_used_functions is not guaranteed to discover all reachable functions. Moreover users can expand function pointer calls after contract instrumentation, so we should at least inject assert(false);assume(false) sentinel instructions in the functions we skip.

Copy link
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

But then we use use remove_unused_functions afterwards, which itself uses find_used_functions` to determine which functions to remove, so I wouldn't know how users would do something after contract instrumentation?

Copy link
Collaborator

@remi-delmas-3000 remi-delmas-3000 Apr 16, 2025

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Still not convinced we are totally sound. CBMC removes function pointers very late, right before the analysis, so if we remove functions that we think are unused, but could have been used as a target due to their signature, wouldn't we create a change in semantics for function pointers between contracts and basic symex ?

What about a case like this one ? Would intfun_contract still be considered used ?
Does find_used_functions consider a function used if its address is taken and assigned to a function pointer variable (e.g. intfun bar = baz;)?

typedef int (*intfun)(int);

intfun __VERIFIER_nondet_intfun();

int intfun_contract(int x)
__CPROVER_requires(-12 <= x && x <= 12)
__CPROVER_ensures(__CPROVER_return_value == 2*x)
;

int foo(intfun bar)
__CPROVER_requires(__CPROVER_obeys_contract(bar, intfun_contract))
__CPROVER_ensures(__CPROVER_return_value == 24)
{
  return bar(12);
}

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants