

@3342

6 years 
boender 
 completed reworking of proofs



@3341

6 years 
boender 
 more notation stuff (still needs work!)



@3338

6 years 
boender 
 updated statement of main correctness statement (still needs work)



@3304

6 years 
boender 
 added 2012 reviews
 updated affiliation



@3265

6 years 
tranquil 
added validate_pointer filter
in Interference added that intereference …



@3263

6 years 
tranquil 
moved callee saved saving and restoring to ERTL > LTL pass (untrusted …



@3262

6 years 
piccolo 
reverted status_simulation_utils



@3261

6 years 
piccolo 
reverted joint_semantics rtl_semantics and ltl_semantics



@3259

6 years 
piccolo 
changed ERTL semantics:
1) added manipulation of stack pointer …



@3257

6 years 
tranquil 
fixed uses in ERTL



@3256

6 years 
tranquil 
fixed compilation



@3255

6 years 
tranquil 
* dropped newframe and delframe (to be integrated in calls and returns …



@3254

6 years 
sacerdot 
Code I always forgot to commit.
To be ported to ERTLtoLTLProof.ma.



@3253

6 years 
piccolo 
some proof obbligation closed of ERTL to LTL proof



@3252

6 years 
piccolo 
proof obbligation added on ERTL to LTL proof



@3237

6 years 
campbell 
Some incomplete work on Clight > Cminor call steps.



@3217

6 years 
piccolo 
Correctness of ERTL to LTL in place



@3178

6 years 
campbell 
Some progress on Callstate steps in Clight to Cminor.
Note that some …



@3176

6 years 
mckinna 
simplified dependencies



@3171

6 years 
mckinna 
removed redundant dependencies



@3170

6 years 
mckinna 
removed redundant dependencies



@3165

6 years 
campbell 
A little bit of progress on Callstate case.



@3156

6 years 
campbell 
Rebuild prefix traces in backend's preferred form.



@3155

6 years 
campbell 
Now have proof that the initial states are in simulation for clight to …



@3154

6 years 
piccolo 
1) changed block_of_call in order to prevent premain calls
2) …



@3145

7 years 
tranquil 
* removed sigma types from traces of intensional events
* completed …



@3118

7 years 
piccolo 
1) finished return case in StatusSimulationHelper?
2) started to write …



@3115

7 years 
campbell 
Clean up some leftover lemmas and move comment back into place.



@3112

7 years 
tranquil 
added invariant that costlabels are only assigned to NOPs (not proved …



@3104

7 years 
sacerdot 
Performance improvement.



@3103

7 years 
mckinna 
Simplified "include" dependencies



@3102

7 years 
mckinna 
Removed redundant refs to current_instruction0,
which itself has been …



@3101

7 years 
mckinna 
Removed redundant lemma execute_1_technical,
which is covered by …



@3100

7 years 
mckinna 
Removed redundant defn of current_instruction0,
which only appears in …



@3099

7 years 
mckinna 
Simplified preliminaries:
inefficient_address_of_word_labels, and …



@3098

7 years 
sacerdot 
Performance improvement.



@3097

7 years 
sacerdot 
Performance improvement in policy computation.



@3096

7 years 
tranquil 
preliminary work on closing correctness.ma



@3095

7 years 
sacerdot 
Some performance improvement: an heavy computation was done again and …



@3083

7 years 
sacerdot 
The cost and stack* variables are now initialized with the cost of …



@3082

7 years 
mckinna 
Tidying up: the long comment about preamble/renamed_symbols in the …



@3081

7 years 
campbell 
Tidy up recent work a little.



@3078

7 years 
tranquil 
fixed change of Mov



@3076

7 years 
mckinna 
simplified include dependencies



@3075

7 years 
mckinna 
Apologies for late folding in of old changes which were left over from …



@3074

7 years 
campbell 
Put some kind of high level proof in for frontend.



@3072

7 years 
tranquil 
corrected a bug (translate_store was wrong)



@3066

7 years 
tranquil 
* implemented get_arg_16 for ACC_DPTR
* LINToASM is now agnostic as to …



@3065

7 years 
sacerdot 
Efficiency of semantics of assembled improved: ticks_of was …



@3064

7 years 
sacerdot 
Efficiency of the semantics of assembly improved by avoiding the …



@3063

7 years 
campbell 
Remove measure function from FEMeasurable because we're not using it …



@3062

7 years 
sacerdot 
Bug fixed in the semantics of Mov: the offset was ignored.
Now all …



@3060

7 years 
sacerdot 
Bug fixed in the semantics of JMP.
The bug was due to a bug in the …



@3057

7 years 
tranquil 
lookup of function identifiers was not corrected with sigma



@3056

7 years 
tranquil 
fixed a merge gone wrong



@3055

7 years 
campbell 
Start getting partial Clight to Cminor proof in shape for …



@3054

7 years 
campbell 
Put missing typ check in; adjust proof because I did it a little …



@3053

7 years 
campbell 
Cast simplification preserves measurable subtraces.



@3051

7 years 
tranquil 
fixed order of global initialization in LINToASM. For the moment …



@3050

7 years 
piccolo 
1) Added general commutation theorem for monads.
2) Added some …



@3049

7 years 
campbell 
Globalenvs and initial states for cast simplification.



@3048

7 years 
campbell 
Improve dependency for cast simplification.



@3047

7 years 
campbell 
Switch removal and labelling combined.



@3046

7 years 
campbell 
Main part of combined switch removal and labelling proof.



@3045

7 years 
tranquil 
fixed what made test3 fail. However it involves a different notion of …



@3044

7 years 
campbell 
Start showing combination of switch removal and labelling is OK.
Fix …



@3042

7 years 
sacerdot 
Repaired.



@3041

7 years 
sacerdot 
Repaired



@3040

7 years 
tranquil 
fixed LINToASM



@3039

7 years 
tranquil 
* merged and extended MovSuccessor? and Mov in one instruction (Mov dst …



@3037

7 years 
tranquil 
* ADDRESS joint instruction now has also an offset
* corrected call to …



@3036

7 years 
garnier 
Fixing some problems, progress, etc



@3035

7 years 
mckinna 
Tweak: tidied up ?/\ldots
Conceptual: better monadic threading of …



@3034

7 years 
sacerdot 
Bug fixed: COST instructions are now assembled as NOP to prevent the …



@3033

7 years 
sacerdot 
Bug fixed: sign_extension was extending according to the _second_ bit, …



@3032

7 years 
campbell 
Remind myself why ms_rel_normal is reasonable.



@3031

7 years 
campbell 
Tidy up RTLabs preclassified_system definitions.



@3030

7 years 
campbell 
Break up frontend for correctness proof.
Use let rec to prevent …



@3028

7 years 
sacerdot 
Bug fixed: 82 and 83 (intended to be the addresses of DPH/DPL) should …



@3024

7 years 
sacerdot 
Bug fixed: set_flags was ignoring the cy and ov flags.



@3023

7 years 
sacerdot 
Typo fixed. It made all GOTOs jump to random positions in the ASM code.



@3022

7 years 
campbell 
Make a couple of tests monadic for easier inversion.



@3021

7 years 
campbell 
Replace clight_clock_after with a more sensible definition that uses …



@3018

7 years 
sacerdot 
1) some files repaired
2) all stuff related to the aborted pass …



@3017

7 years 
sacerdot 
Repaired.



@3016

7 years 
tranquil 
fixed after previous commit



@3014

7 years 
tranquil 
ERTL to ERTLptr pass suppressed (it introduced a bug in the later …



@3010

7 years 
tranquil 
same bug as was in liveness is now fixed



@3008

7 years 
tranquil 
corrected bug where the address of pointer calls was not defined as used



@3007

7 years 
campbell 
Sketch out how Cminor to RTLabs correctness would fit into the …



@3004

7 years 
tranquil 
fixed a bug where when doing an asymetrical op, cast initialization …



@3003

7 years 
sacerdot 
Correctness.ma "repaired"



@2999

7 years 
sacerdot 
code_memory added to labelled_object_code to avoid recomputing it …



@2996

7 years 
sacerdot 
Printing of graphs now starts from the entry point.



@2994

7 years 
sacerdot 
The LIN printer.



@2993

7 years 
sacerdot 
1. performance improved: the type inference was inferring
…



@2992

7 years 
campbell 
Add "only one return" invariant to RTLabs functions.



@2991

7 years 
piccolo 
Fixed cond and seq case in StatusSimulationHelper?
Added cost case in …



@2990

7 years 
campbell 
Replace dodgy hypothesis by nice ones, clean up a little.



@2989

7 years 
campbell 
Make frontend measurability preservation proof cope with moving the …


