InvariantChecker.scala 3.74 KB
Newer Older
Christian Müller's avatar
Christian Müller committed
1
2
3
4
5
6
7
8
9
package de.tum.workflows.toz3

import de.tum.workflows.blocks._
import de.tum.workflows.foltl.FOLTL._
import de.tum.workflows.ltl.LTL
import de.tum.workflows.Implicits._
import de.tum.workflows.WorkflowParser
import de.tum.workflows.Encoding
import de.tum.workflows.Preconditions
Christian Müller's avatar
Christian Müller committed
10
11
import de.tum.workflows.foltl.Properties.T1
import de.tum.workflows.foltl.Properties.T2
Christian Müller's avatar
Christian Müller committed
12
13
14
15
16
17
18

import scalax.collection.edge.LDiEdge // labeled directed edge
import com.microsoft.z3.Context
import java.util.HashMap
import org.omg.CORBA.TIMEOUT
import com.microsoft.z3.Status
import com.typesafe.scalalogging.LazyLogging
Christian Müller's avatar
Christian Müller committed
19
import de.tum.workflows.foltl.Properties
Christian Müller's avatar
Christian Müller committed
20
21

object InvariantChecker extends LazyLogging {
Christian Müller's avatar
checker    
Christian Müller committed
22

Christian Müller's avatar
Christian Müller committed
23
  val TIMEOUT = 60000 // in milliseconds
Christian Müller's avatar
checker    
Christian Müller committed
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42

  def checkOnZ3(f: Formula) = {
    // Set up Z3
    val cfg = new HashMap[String, String]()
    cfg.put("timeout", TIMEOUT.toString())
    val ctx = new Context(cfg)
    val s = ctx.mkSolver()

    s.add(toZ3.translate(f, ctx))

    // Send to z3
    val c = s.check()
    if (c == Status.UNKNOWN) {
      logger.info(s"Z3 status unknown: ${s.getReasonUnknown()}")
    }
    if (c == Status.SATISFIABLE) {
      logger.info(s"Z3 model:\n${s.getModel()}")
    }
    (c, s)
Christian Müller's avatar
Christian Müller committed
43
  }
Christian Müller's avatar
checker    
Christian Müller committed
44
45
46

  def checkInvariant(w: Workflow, inv: Formula, stubborn: Boolean) = {

Christian Müller's avatar
Christian Müller committed
47
48
    // Build graph
    val graph = Encoding.toGraph(w)
Christian Müller's avatar
checker    
Christian Müller committed
49

Christian Müller's avatar
Christian Müller committed
50
    val msg = new StringBuilder()
51
    msg ++= s"Trying to prove safe with invariant:\n\n${inv.pretty()}\n\n"
Christian Müller's avatar
checker    
Christian Müller committed
52

Christian Müller's avatar
Christian Müller committed
53
54
    // Check all edges 
    val list = for (e <- graph.edges) yield {
Christian Müller's avatar
checker    
Christian Müller committed
55

Christian Müller's avatar
Christian Müller committed
56
      // Check I -> WP[w](inv)
Christian Müller's avatar
checker    
Christian Müller committed
57
      val b: SimpleBlock = e
Christian Müller's avatar
Christian Müller committed
58
      val precond = Preconditions.weakestPrecondition(inv, b)
Christian Müller's avatar
checker    
Christian Müller committed
59

Christian Müller's avatar
Christian Müller committed
60
      // Stubborn agents -> remove trace variable from choice predicate
Christian Müller's avatar
checker    
Christian Müller committed
61
62
63
64
65
      val stubprecond = if (stubborn) {
        precond.everywhere {
          case Fun(f, i, p) if b.may && f == b.pred.get => Fun(f, p)
        }
      } else precond
Christian Müller's avatar
Christian Müller committed
66
67
68
      
      val test1 = inv.toPrenex()
      val test2 = stubprecond.toPrenex()
Christian Müller's avatar
checker    
Christian Müller committed
69

Christian Müller's avatar
Christian Müller committed
70
      val f = Implies(inv, stubprecond)
Christian Müller's avatar
checker    
Christian Müller committed
71

Christian Müller's avatar
Christian Müller committed
72
73
      logger.info(s"Checking invariant implication for ${e.label}")
      val tocheck = Neg(f).simplify()
Christian Müller's avatar
checker    
Christian Müller committed
74

Christian Müller's avatar
Christian Müller committed
75
      val (res, solver) = checkOnZ3(tocheck)
Christian Müller's avatar
Christian Müller committed
76
      if (res != Status.UNSATISFIABLE) {
Christian Müller's avatar
Christian Müller committed
77
78
79
        msg ++= s"Possibly unsafe: Block may not uphold invariant:\n\n${e.label}\n\n"
        if (res == Status.SATISFIABLE) {
          msg ++= "Satisfying model:\n"
Christian Müller's avatar
Christian Müller committed
80
          msg ++= toZ3.printModel(solver.getModel()).lines.map("  " + _).mkString("\n")
Christian Müller's avatar
Christian Müller committed
81
82
        } else if (res == Status.UNKNOWN) {
          msg ++= s"Z3 result: $res (${solver.getReasonUnknown()})\n"
Christian Müller's avatar
Christian Müller committed
83
84
        }
        msg ++= "\n"
Christian Müller's avatar
Christian Müller committed
85
86
87
88
89
90
        logger.info(s"Could not prove invariant $inv")
        logger.info(s"Z3 status $res")
        logger.info(s"Block ${e.label} may not uphold it")
      }
      res == Status.UNSATISFIABLE
    }
Christian Müller's avatar
checker    
Christian Müller committed
91

Christian Müller's avatar
Christian Müller committed
92
93
    val safe = list.reduceLeft(_ && _)
    if (safe) {
94
      msg ++= s"Proven safe.\n"
Christian Müller's avatar
Christian Müller committed
95
      logger.info(s"Workflow $w\n proven safe for invariant:\n${inv.pretty()}")
Christian Müller's avatar
Christian Müller committed
96
    }
Christian Müller's avatar
Christian Müller committed
97
    (safe, msg)
Christian Müller's avatar
Christian Müller committed
98
  }
Christian Müller's avatar
checker    
Christian Müller committed
99
100

  def genEq(f: Fun, p: List[Var]) = {
Christian Müller's avatar
Christian Müller committed
101
102
103
    val newf = f.parallelRename(f.params, p)
    Eq(newf.in(T1), newf.in(T2))
  }
Christian Müller's avatar
checker    
Christian Müller committed
104
105

  def invariantNoninterStubborn(spec: Spec) = {
Christian Müller's avatar
Christian Müller committed
106
    val agent = spec.target.params(0)
Christian Müller's avatar
checker    
Christian Müller committed
107
108

    val premise = And.make(for ((o, t) <- spec.declass) yield {
Christian Müller's avatar
Christian Müller committed
109
110
      // Forall fv(o). (t_T1 or t_t2) -> G (o_T1 <-> o_T2) 
      Forall(o.freeVars().toList, Implies(Or(t.in(T1), t.in(T2)), Eq(o.in(T1), o.in(T2))))
Christian Müller's avatar
Christian Müller committed
111
    })
Christian Müller's avatar
checker    
Christian Müller committed
112

Christian Müller's avatar
Christian Müller committed
113
114
    val conclusion = And.make(for (r <- spec.w.sig.preds.toList if r.params.head.typ == agent.typ) yield {
      val quant = r.params.drop(1)
Christian Müller's avatar
checker    
Christian Müller committed
115
      Forall(quant, genEq(r, agent :: quant))
Christian Müller's avatar
Christian Müller committed
116
    })
Christian Müller's avatar
checker    
Christian Müller committed
117

Christian Müller's avatar
Christian Müller committed
118
    Forall(agent, premise  conclusion).simplify()
Christian Müller's avatar
Christian Müller committed
119
  }
Christian Müller's avatar
checker    
Christian Müller committed
120

Christian Müller's avatar
Christian Müller committed
121
122
123
124
125
126
  def invariantAllEqual(spec: Spec) = {
    And.make(for (r <- spec.w.sig.preds.toList) yield {
      Forall(r.params, genEq(r, r.params))
    })
  }

Christian Müller's avatar
Christian Müller committed
127
}