

@2743

7 years 
sacerdot 
Latest version of the compiler, extracted with the latest version of …



@2742

7 years 
sacerdot 
Untrusted register colouring fully branched.



@2741

7 years 
sacerdot 
File used only by untrusted code.
Implemented in Matita to exploit …



@2740

7 years 
sacerdot 
Graph colouring terminated up to Uses that will be implemented
in Matita.



@2739

7 years 
sacerdot 
The graph colouring algorithm takes in input also the function.



@2738

7 years 
sacerdot 
Porting the graph colouring stuff from the untrusted prototype to the …



@2737

7 years 
garnier 
Commit of current proof state for Clight to Cminor translation.



@2736

7 years 
sacerdot 
Untrusted fixpoint computation branched in.



@2735

7 years 
campbell 
Note about loose end in FEMeasurable.



@2734

7 years 
mckinna 
yet another puzzling automation failure, in the repaired case:
"" …



@2733

7 years 
sacerdot 
All axioms in set_adt implemented by hand.



@2732

7 years 
sacerdot 
Unused code removed.



@2731

7 years 
sacerdot 
Minimal set of axioms implemented to make the driver run.



@2730

7 years 
sacerdot 
Exported again.



@2729

7 years 
sacerdot 
More errors recognized



@2728

7 years 
sacerdot 
listb.ma => listb_extra.ma for extraction



@2727

7 years 
campbell 
Remove a couple of redundant hypotheses.



@2726

7 years 
campbell 
Show max stack preserved in FEMeasurable.



@2725

7 years 
campbell 
Add observables to FEMeasurable proof; fix silly typo.



@2724

7 years 
campbell 
Add RTLabs cost labelling checks to compiler.ma.



@2723

7 years 
campbell 
Library name typo fixed.



@2722

7 years 
campbell 
It's easier to keep the real function identifier in frontend …



@2721

7 years 
campbell 
Give the real error in the driver.



@2720

7 years 
tranquil 
implemented back end ops that were still axioms



@2719

7 years 
sacerdot 
More values manually abstracted to functions to avoid failwiths at …



@2718

7 years 
sacerdot 
set_empty turned from a value to a function because it is not …



@2717

7 years 
sacerdot 
Extracted code for the whole compiler.
The space cost model is not …



@2716

7 years 
sacerdot 
utilities/deqsets.ma => utilities/deqsets_extra.ma for extraction



@2715

7 years 
sacerdot 
Policy.ma repaired



@2714

7 years 
sacerdot 
PolicyStep?.ma repaired



@2713

7 years 
sacerdot 
PolicyFront?.ma repaired



@2712

7 years 
tranquil 
changed some fields of joint_internal_function's invariant
fixed linearise



@2711

7 years 
sacerdot 
…



@2710

7 years 
sacerdot 
ASMCosts.ma repaired



@2709

7 years 
sacerdot 
LINToAsm repaired



@2708

7 years 
tranquil 
fixed linearise and LINToASM
LINToASM has now correct transformation …



@2707

7 years 
sacerdot 
Assembly repaired.



@2706

7 years 
mckinna 
repaired contentious broken automation
at end of subgoal 9 of case (* …



@2705

7 years 
sacerdot 
More progress in ASM towards implementing the new pseudoinstructions.



@2704

7 years 
tranquil 
moved JMP from instructions to preinstructions, and added MovSuccessor? …



@2703

7 years 
mckinna 
now includes defn of costlabel_map



@2702

7 years 
sacerdot 
1. proof closed in ASM/UtilBranch
2. more passes integrated in the …



@2701

7 years 
sacerdot 
Automation failure fixed by replacing with hand made proof.



@2700

7 years 
sacerdot 
1. exponential function dropped in favour of standard library
2. …



@2699

7 years 
mckinna 
simplified dependencies somewhat



@2698

7 years 
mckinna 
simplified dependencies



@2697

7 years 
sacerdot 
Compiler fixed to include the ERTLptrToLTL pass.



@2696

7 years 
sacerdot 
I can't get this right... :(



@2695

7 years 
sacerdot 
Renamed again.



@2694

7 years 
tranquil 
completed ERTLptrToLTL



@2693

7 years 
sacerdot 
1. Stuff moved to correct places.
2. ERTLptr pass added



@2692

7 years 
garnier 
Add some more constraints in clight_cminor_data.



@2691

7 years 
sacerdot 
ERTLtoERTLptr* moved to the proper place



@2690

7 years 
campbell 
Most of the measurable subtrace preservation proof done.



@2689

7 years 
tranquil 
* fixed passes up to linearisation



@2688

7 years 
tranquil 
* in Arithmeticcs.ma: commented include that breaks script in latest …



@2687

7 years 
tranquil 
* polished some interfaces



@2686

7 years 
mckinna 
two minor modifications to assist disambiguation of "lookup"
file …



@2685

7 years 
campbell 
Progress on measurable trace preservation: prefix preserves observable …



@2684

7 years 
sacerdot 
…



@2683

7 years 
tranquil 
proof of properties of b_graph_program_transform (with an open axiom)



@2682

7 years 
campbell 
Don't apply inv in after_n_steps to last state.



@2681

7 years 
tranquil 
* improvements to the graph translation function
* fixed passes up to LTL



@2680

7 years 
mckinna 
proofs which previously succeeded fail, thanks to fold on positive_map …



@2679

7 years 
mckinna 
Further tweak to Brian's changes: no normalization reqd at all!



@2678

7 years 
campbell 
Switch to single source step simulations for frontend measurable …



@2677

7 years 
campbell 
Retain the pointer for the function called in frontend call states
so …



@2676

7 years 
campbell 
Less aggressive normalisation in ASMCosts to prevent memory blowup.



@2675

7 years 
tranquil 
* a generic graph program transformation



@2674

7 years 
tranquil 
* another change in block definition
* RTLabs > RTL and ERTL > …



@2673

7 years 
tranquil 
corrected some compilation errors (that might depend on some matita update)



@2672

7 years 
sacerdot 
One less axiom on bitvectors.



@2671

7 years 
sacerdot 
simplification



@2670

7 years 
campbell 
Clean up from recent commits.



@2669

7 years 
campbell 
Tweak exec_steps output; show that simulations extend to measurable …



@2668

7 years 
campbell 
Intermediate measurable proof checkin before I change its traces again.



@2667

7 years 
garnier 
Clight to Cminor, statements: some cases down. Subset of the …



@2666

7 years 
piccolo 
bug fixed in blocks.ma



@2665

7 years 
sacerdot 
…



@2664

7 years 
sacerdot 
Tailcall case implemented (it does not happen ATM).



@2663

7 years 
piccolo 
some minor modifications to ERTLtoERTLptr



@2662

7 years 
piccolo 
Towards a very generalized lemma that summarizes all of Paolo's results.



@2661

7 years 
sacerdot 
stacksize "repaired" by "considering" tailcalls
Some daemons added …



@2660

7 years 
sacerdot 
…



@2659

7 years 
sacerdot 
Tailcall elimination no longer necessary:
1. the backend is almost …



@2658

7 years 
sacerdot 
…



@2657

7 years 
sacerdot 
Cost proof fully repaired. It was broken by the definitions used in …



@2656

7 years 
sacerdot 
Ported to tailcalls (currently nothing is classified as a tailcall).



@2655

7 years 
tranquil 
new step in code semantic lemma



@2654

7 years 
garnier 
Memory injections in a coherent state.



@2653

7 years 
sacerdot 
…



@2652

7 years 
sacerdot 
String type changed definition.



@2651

7 years 
sacerdot 
Type String changed.



@2650

7 years 
regisgia 
* Final version of the untrusted software.



@2649

7 years 
sacerdot 
…



@2648

7 years 
sacerdot 
Back in sync with the extracted code.



@2647

7 years 
sacerdot 
Stupid typo fixed.



@2646

7 years 
sacerdot 
A tag was classified as an error message. Fixed.



@2645

7 years 
sacerdot 
1. some broken backend files repaires, several still to go
2. the …



@2644

7 years 
campbell 
Commit some work on FEMeasurable before trying to do something nicer …


