InvariantChecker.scala 3.29 KB
Newer Older
Christian Müller's avatar
Christian Müller committed
1 2 3 4 5 6 7 8 9
package de.tum.workflows.toz3

import de.tum.workflows.blocks._
import de.tum.workflows.foltl.FOLTL._
import de.tum.workflows.ltl.LTL
import de.tum.workflows.Implicits._
import de.tum.workflows.WorkflowParser
import de.tum.workflows.Encoding
import de.tum.workflows.Preconditions
Christian Müller's avatar
Christian Müller committed
10 11
import de.tum.workflows.foltl.Properties.T1
import de.tum.workflows.foltl.Properties.T2
Christian Müller's avatar
Christian Müller committed
12 13 14 15 16 17 18

import scalax.collection.edge.LDiEdge // labeled directed edge
import com.microsoft.z3.Context
import java.util.HashMap
import org.omg.CORBA.TIMEOUT
import com.microsoft.z3.Status
import com.typesafe.scalalogging.LazyLogging
Christian Müller's avatar
Christian Müller committed
19
import de.tum.workflows.foltl.Properties
Christian Müller's avatar
Christian Müller committed
20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50

object InvariantChecker extends LazyLogging {
  
  val TIMEOUT = 60000 // in milliseconds
  
  def checkOnZ3(f:Formula) = {
      // Set up Z3
      val cfg = new HashMap[String, String]()
      cfg.put("timeout", TIMEOUT.toString())
      val ctx = new Context(cfg)
//      val t = ctx.andThen(ctx.mkTactic("qe"), ctx.mkTactic("smt"))
      val s = ctx.mkSolver()

      s.add(toZ3.translate(f, ctx))
      
      // Send to z3
      val c = s.check()
      if (c == Status.UNKNOWN) {
        logger.info(s"Z3 status unknown: ${s.getReasonUnknown()}")
      }
      if (c == Status.SATISFIABLE) {
        logger.info(s"Z3 model:\n${s.getModel()}")
      }
      c
  }
  
  def checkStubborn(w:Workflow, inv:Formula) = {
    
    // Build graph
    val graph = Encoding.toGraph(w)
    
Christian Müller's avatar
Christian Müller committed
51
    val msg = new StringBuilder()
52
    msg ++= s"Trying to prove safe with invariant:\n\n${inv.pretty()}\n\n"
Christian Müller's avatar
Christian Müller committed
53
    
Christian Müller's avatar
Christian Müller committed
54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72
    // Check all edges 
    val list = for (e <- graph.edges) yield {
      
      // Check I -> WP[w](inv)
      val b:SimpleBlock = e
      val precond = Preconditions.weakestPrecondition(inv, b)
      
      // Stubborn agents -> remove trace variable from choice predicate
      val stubprecond = precond.everywhere {
        case Fun(f, i, p) if b.may && f == b.pred.get => Fun(f, p)
      }
      
      val f = Implies(inv, stubprecond)
      
      logger.info(s"Checking invariant implication for ${e.label}")
      val tocheck = Neg(f).simplify()
      
      val res = checkOnZ3(tocheck)
      if (res != Status.UNSATISFIABLE) {
73
        msg ++= s"Possibly unsafe: Block\n\n${e.label}\n\nmay not uphold invariant.\n"
Christian Müller's avatar
Christian Müller committed
74 75 76 77 78 79 80 81 82
        logger.info(s"Could not prove invariant $inv")
        logger.info(s"Z3 status $res")
        logger.info(s"Block ${e.label} may not uphold it")
      }
      res == Status.UNSATISFIABLE
    }
    
    val safe = list.reduceLeft(_ && _)
    if (safe) {
83
      msg ++= s"Proven safe.\n"
Christian Müller's avatar
Christian Müller committed
84
      logger.info(s"Workflow $w\n proven safe for invariant:\n${inv.pretty()}")
Christian Müller's avatar
Christian Müller committed
85
    }
Christian Müller's avatar
Christian Müller committed
86
    (safe, msg)
Christian Müller's avatar
Christian Müller committed
87
  }
Christian Müller's avatar
Christian Müller committed
88 89 90 91 92 93 94 95 96 97
  
  def genEq(f:Fun, p:List[Var]) = {
    val newf = f.parallelRename(f.params, p)
    Eq(newf.in(T1), newf.in(T2))
  }
  
  def invariantNoninterStubborn(spec:Spec) = {
    val agent = spec.target.params(0)
    
    val premise = And.make(for ((o,t) <- spec.declass) yield {
Christian Müller's avatar
Christian Müller committed
98 99
      // Forall fv(o). (t_T1 or t_t2) -> G (o_T1 <-> o_T2) 
      Forall(o.freeVars().toList, Implies(Or(t.in(T1), t.in(T2)), Eq(o.in(T1), o.in(T2))))
Christian Müller's avatar
Christian Müller committed
100 101 102 103 104 105 106
    })
    
    val conclusion = And.make(for (r <- spec.w.sig.preds.toList if r.params.head.typ == agent.typ) yield {
      val quant = r.params.drop(1)
      Forall(quant, genEq(r, agent::quant))
    })
    
107
    Forall(agent, Implies(premise, conclusion)).simplify()
Christian Müller's avatar
Christian Müller committed
108
  }
Christian Müller's avatar
Christian Müller committed
109
}