FreeRTOS-Kernel/FreeRTOS-Plus/Test/CBMC/proofs/ARP/ARP_OutputARPRequest_buffer_alloc1
markrtuttle cdf6d93cb9
Modify CBMC proofs to make assumptions about malloc explicit. (#312)
Some proofs assume that some pointers returned by malloc are not
NULL. This patch modifies those proofs to make these assumptions
explicit with `__CPROVER_assume(pointer != NULL)` for all such
pointers.

Co-authored-by: Mark R. Tuttle <mrtuttle@amazon.com>
Co-authored-by: Aniruddha Kanhere <60444055+AniruddhaKanhere@users.noreply.github.com>
2020-10-02 18:18:16 -04:00
..
Configurations.json Move CBMC proofs to FreeRTOS+ directory (#64) 2020-05-05 09:57:18 -07:00
OutputARPRequest_harness.c Modify CBMC proofs to make assumptions about malloc explicit. (#312) 2020-10-02 18:18:16 -04:00
README.md Move CBMC proofs to FreeRTOS+ directory (#64) 2020-05-05 09:57:18 -07:00

This is the memory safety proof for FreeRTOS_OutputARPRequest method combined with the BufferAllocation_1.c allocation strategy.

This proof is a work-in-progress. Proof assumptions are described in the harness. The proof also assumes the following functions are memory safe and have no side effects relevant to the memory safety of this function:

  • vPortEnterCritical
  • vPortExitCritical
  • vPortGenerateSimulatedInterrupt
  • vAssertCalled
  • xTaskGetSchedulerState
  • pvTaskIncrementMutexHeldCount
  • xTaskRemoveFromEventList
  • xTaskPriorityDisinherit

This proof checks FreeRTOS_OutputARPRequest in multiple configurations. All assume the memory safety of vNetworkInterfaceAllocateRAMToBuffers.

  • The config_minimal_configuration proof sets ipconfigUSE_LINKED_RX_MESSAGES=0.
  • The config_minimal_configuration_linked_rx_messages proof sets ipconfigUSE_LINKED_RX_MESSAGES=1.
  • The minimal_configuration_minimal_packet_size proof sets ipconfigETHERNET_MINIMUM_PACKET_BYTES to 50.

All harnesses include the queue.c file, but test only for the happy path.