InvariantChecker.scala 4.98 KB
Newer Older
Christian Müller's avatar
Christian Müller committed
1 2 3 4 5 6 7 8 9
package de.tum.workflows.toz3

import de.tum.workflows.blocks._
import de.tum.workflows.foltl.FOLTL._
import de.tum.workflows.ltl.LTL
import de.tum.workflows.Implicits._
import de.tum.workflows.WorkflowParser
import de.tum.workflows.Encoding
import de.tum.workflows.Preconditions
Christian Müller's avatar
Christian Müller committed
10 11
import de.tum.workflows.foltl.Properties.T1
import de.tum.workflows.foltl.Properties.T2
Christian Müller's avatar
Christian Müller committed
12 13 14 15 16 17 18

import scalax.collection.edge.LDiEdge // labeled directed edge
import com.microsoft.z3.Context
import java.util.HashMap
import org.omg.CORBA.TIMEOUT
import com.microsoft.z3.Status
import com.typesafe.scalalogging.LazyLogging
Christian Müller's avatar
Christian Müller committed
19
import de.tum.workflows.foltl.Properties
Christian Müller's avatar
Christian Müller committed
20 21

object InvariantChecker extends LazyLogging {
Christian Müller's avatar
Christian Müller committed
22

Christian Müller's avatar
Christian Müller committed
23
  val TIMEOUT = 60000 // in milliseconds
Christian Müller's avatar
Christian Müller committed
24 25 26 27 28 29

  def checkOnZ3(f: Formula) = {
    // Set up Z3
    val cfg = new HashMap[String, String]()
    cfg.put("timeout", TIMEOUT.toString())
    val ctx = new Context(cfg)
30 31 32 33 34 35

    val qe = ctx.mkTactic("qe")
    val default = ctx.mkTactic("smt")
    val t = ctx.andThen(qe, default)

    val s = ctx.mkSolver(t)
Christian Müller's avatar
Christian Müller committed
36 37 38 39 40 41 42 43 44 45 46 47

    s.add(toZ3.translate(f, ctx))

    // Send to z3
    val c = s.check()
    if (c == Status.UNKNOWN) {
      logger.info(s"Z3 status unknown: ${s.getReasonUnknown()}")
    }
    if (c == Status.SATISFIABLE) {
      logger.info(s"Z3 model:\n${s.getModel()}")
    }
    (c, s)
Christian Müller's avatar
Christian Müller committed
48
  }
Christian Müller's avatar
Christian Müller committed
49 50 51

  def checkInvariant(w: Workflow, inv: Formula, stubborn: Boolean) = {

Christian Müller's avatar
Christian Müller committed
52 53
    // Build graph
    val graph = Encoding.toGraph(w)
Christian Müller's avatar
Christian Müller committed
54

Christian Müller's avatar
Christian Müller committed
55
    val msg = new StringBuilder()
56
    msg ++= s"Trying to prove safe with invariant:\n\n${inv.pretty()}\n\n"
Christian Müller's avatar
Christian Müller committed
57

Christian Müller's avatar
Christian Müller committed
58 59
    // Check all edges 
    val list = for (e <- graph.edges) yield {
Christian Müller's avatar
Christian Müller committed
60

Christian Müller's avatar
Christian Müller committed
61
      // Check I -> WP[w](inv)
Christian Müller's avatar
Christian Müller committed
62
      val b: SimpleBlock = e
Christian Müller's avatar
Christian Müller committed
63
      val precond = Preconditions.weakestPrecondition(inv, b)
Christian Müller's avatar
Christian Müller committed
64

Christian Müller's avatar
Christian Müller committed
65
      // Stubborn agents -> remove trace variable from choice predicate
Christian Müller's avatar
Christian Müller committed
66 67 68 69 70
      val stubprecond = if (stubborn) {
        precond.everywhere {
          case Fun(f, i, p) if b.may && f == b.pred.get => Fun(f, p)
        }
      } else precond
71 72 73

      //      val test1 = inv.toPrenex()
      //      val test2 = stubprecond.toPrenex()
Christian Müller's avatar
Christian Müller committed
74

Christian Müller's avatar
Christian Müller committed
75
      val f = Implies(inv, stubprecond)
Christian Müller's avatar
Christian Müller committed
76

Christian Müller's avatar
Christian Müller committed
77 78
      logger.info(s"Checking invariant implication for ${e.label}")
      val tocheck = Neg(f).simplify()
Christian Müller's avatar
Christian Müller committed
79

80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97
      //      val test3 = tocheck.toPrenex()

      // Transform to existential
      if (!tocheck.isBS()) {
        logger.error(s"Invariant implication $tocheck is not in BS fragment!")
      }
      
      val negnf = tocheck.toNegNf()
    
      val (agents, inner) = LTL.eliminateExistentials(negnf)
      val existbound = Exists(agents, inner)
      val univfree = LTL.eliminateUniversals(existbound, agents)
      
//      val test3 = univfree.pretty()
//      println(test3)

      val (res, solver) = checkOnZ3(univfree)
      
Christian Müller's avatar
Christian Müller committed
98
      if (res != Status.UNSATISFIABLE) {
Christian Müller's avatar
Christian Müller committed
99 100 101
        msg ++= s"Possibly unsafe: Block may not uphold invariant:\n\n${e.label}\n\n"
        if (res == Status.SATISFIABLE) {
          msg ++= "Satisfying model:\n"
Christian Müller's avatar
Christian Müller committed
102
          msg ++= toZ3.printModel(solver.getModel()).lines.map("  " + _).mkString("\n")
Christian Müller's avatar
Christian Müller committed
103 104
        } else if (res == Status.UNKNOWN) {
          msg ++= s"Z3 result: $res (${solver.getReasonUnknown()})\n"
Christian Müller's avatar
Christian Müller committed
105 106
        }
        msg ++= "\n"
Christian Müller's avatar
Christian Müller committed
107 108 109 110 111 112
        logger.info(s"Could not prove invariant $inv")
        logger.info(s"Z3 status $res")
        logger.info(s"Block ${e.label} may not uphold it")
      }
      res == Status.UNSATISFIABLE
    }
Christian Müller's avatar
Christian Müller committed
113

Christian Müller's avatar
Christian Müller committed
114 115
    val safe = list.reduceLeft(_ && _)
    if (safe) {
116
      msg ++= s"Proven safe.\n"
Christian Müller's avatar
Christian Müller committed
117
      logger.info(s"Workflow $w\n proven safe for invariant:\n${inv.pretty()}")
Christian Müller's avatar
Christian Müller committed
118
    }
Christian Müller's avatar
Christian Müller committed
119
    (safe, msg)
Christian Müller's avatar
Christian Müller committed
120
  }
Christian Müller's avatar
Christian Müller committed
121 122

  def genEq(f: Fun, p: List[Var]) = {
Christian Müller's avatar
Christian Müller committed
123 124 125
    val newf = f.parallelRename(f.params, p)
    Eq(newf.in(T1), newf.in(T2))
  }
Christian Müller's avatar
Christian Müller committed
126 127

  def invariantNoninterStubborn(spec: Spec) = {
Christian Müller's avatar
Christian Müller committed
128
    val agent = spec.target.params(0)
Christian Müller's avatar
Christian Müller committed
129 130

    val premise = And.make(for ((o, t) <- spec.declass) yield {
Christian Müller's avatar
Christian Müller committed
131 132
      // Forall fv(o). (t_T1 or t_t2) -> G (o_T1 <-> o_T2) 
      Forall(o.freeVars().toList, Implies(Or(t.in(T1), t.in(T2)), Eq(o.in(T1), o.in(T2))))
Christian Müller's avatar
Christian Müller committed
133
    })
Christian Müller's avatar
Christian Müller committed
134

Christian Müller's avatar
Christian Müller committed
135 136
    val conclusion = And.make(for (r <- spec.w.sig.preds.toList if r.params.head.typ == agent.typ) yield {
      val quant = r.params.drop(1)
Christian Müller's avatar
Christian Müller committed
137
      Forall(quant, genEq(r, agent :: quant))
Christian Müller's avatar
Christian Müller committed
138
    })
Christian Müller's avatar
Christian Müller committed
139

Christian Müller's avatar
Christian Müller committed
140
    Forall(agent, premise  conclusion).simplify()
Christian Müller's avatar
Christian Müller committed
141
  }
Christian Müller's avatar
Christian Müller committed
142

143 144 145 146 147 148 149 150 151 152 153 154 155 156 157 158 159
  def invariantNoninterStubbornBS(spec: Spec) = {
    val agent = spec.target.params(0)

    val premise = for ((o, t) <- spec.declass) yield {
      // Forall fv(o). (t_T1 or t_t2) -> G (o_T1 <-> o_T2) 
      (o.freeVars().toList, Implies(Or(t.in(T1), t.in(T2)), Eq(o.in(T1), o.in(T2))))
    }
    val quants = premise.flatMap(_._1).toSet.toList // eliminate doubles

    val conclusion = And.make(for (r <- spec.w.sig.preds.toList if r.params.head.typ == agent.typ) yield {
      val quant = r.params.drop(1)
      Forall(quant, genEq(r, agent :: quant))
    })

    Forall(agent, Forall(quants, Implies(And.make(premise.map(_._2)), conclusion))).simplify()
  }

Christian Müller's avatar
Christian Müller committed
160 161 162 163 164 165
  def invariantAllEqual(spec: Spec) = {
    And.make(for (r <- spec.w.sig.preds.toList) yield {
      Forall(r.params, genEq(r, r.params))
    })
  }

Christian Müller's avatar
Christian Müller committed
166
}