936d209 | Raphaël Cauderlier | 06 February 2021, 22:41:46 UTC | Dexter DFS compat: always call trusted contracts first There are 3 cases where Dexter emits more than an operation at once. In two of them, a potential attacker is called first. If this attacker can produce DFS calls it may be able to access Dextex before the FA1.2 is updated so some invariants might be broken. We haven't managed to use DFS calls to attack Dexter but always calling uncontrolled contracts last in the operation list is always safer. | 07 February 2021, 17:37:21 UTC |
55e0921 | Raphaël Cauderlier | 06 February 2021, 22:05:50 UTC | Dexter DFS compat: assert that `to` and `owner` args are always implicit accounts In order to reduce the attack surface of Dexter in the presence of both BFS and DFS calls, we add assertions that guarantee that: - Dexter is not called by a smart-contract so no BFS operations can be injected before the operations emitted by Dexter. This is checked by (SOURCE = SENDER) which can never hold in internal transactions. - uncontrolled addresses (the `to` and `owner` parameters) are prevented to do any call (DFS or BFS) by requesting them to be implicit accounts. There is unfortunately no instruction in Michelson to check that an address is implicit (see https://gitlab.com/nomadic-labs/tezos/-/merge_requests/93) but we know that the transaction source is always implicit (since Babylon) so we use the over approximation (to = SOURCE) and (owner = SOURCE). | 07 February 2021, 17:37:20 UTC |
3c0ef59 | Raphaël Cauderlier | 07 February 2021, 15:48:49 UTC | Debug: output the Dexter script on stdout A very small edit of the script is still needed to: - remove some garbage before and after the script - replace "" by " - ask Emacs to reindent everything | 07 February 2021, 17:36:37 UTC |
3b57515 | Raphaël Cauderlier | 07 February 2021, 15:47:56 UTC | Dexter string: Add newlines to help Emacs indent the script correctly | 07 February 2021, 17:36:36 UTC |
b710817 | Raphaël Cauderlier | 07 February 2021, 15:46:00 UTC | Dexter string: Edo compat In Edo FAILWITH cannot raise a big map anymore. This commit adds UNIT before the FAILWITHs that don't typecheck in Edo. | 07 February 2021, 17:36:36 UTC |
4f96fe5 | Arvid Jakobsson | 10 October 2020, 14:23:15 UTC | [dexter] functional certification of Dexter Dexter version: 4e24123. The formal specification is based on the informal specification dated September 31, 2020. This is a joint work by: - Arvid Jakobsson, Nomadic Labs - Kristina Sojakova, INRIA - Colin González, Nomadic Labs | 10 October 2020, 15:02:05 UTC |
a11bfa4 | Arvid Jakobsson | 10 October 2020, 14:21:50 UTC | [dexter] add utility lemmas for Dexter | 10 October 2020, 14:24:51 UTC |
c05e6b0 | Arvid Jakobsson | 09 October 2020, 16:44:52 UTC | [mi-cho-coq] add compare_gt_lt to comparable.v | 10 October 2020, 13:56:02 UTC |
bc20d90 | Arvid Jakobsson | 09 October 2020, 16:17:51 UTC | [mi-cho-coq] move fold_eval_precond to semantics.v | 10 October 2020, 13:56:02 UTC |
62f2621 | Arvid Jakobsson | 21 September 2020, 19:36:05 UTC | [mi-cho-coq] prove injectivity of tez.to_Z | 10 October 2020, 13:56:00 UTC |
f75dd14 | Arvid Jakobsson | 18 September 2020, 13:30:41 UTC | [mi-cho-coq] prove lower bound on tez.to_Z | 10 October 2020, 13:55:56 UTC |
a4d37fa | Raphaël Cauderlier | 24 August 2020, 10:33:05 UTC | [Michocoq] Allow FAILWITH in LOOP, LOOP_LEFT, and ITER Fixes #27. | 17 September 2020, 11:45:12 UTC |
5796046 | Raphaël Cauderlier | 31 May 2020, 13:08:41 UTC | Simplification of the formula produced by eval_precond The following simplifications are applied: - eval_seq_precond immediately returns `False` on instruction sequences ending with a `FAILWITH` (it does so by looking at the tail-fail flag) - `match x with C1 y => phi y | C2 y => False` becomes `exists y, x = C1 y /\ phi y` - the code produced for `IF_ f` depends on the if-family `f` to avoid the previous double pattern matching: for example for options it produces `match o with | Some x -> ... | None -> ... end` instead of `match (match o with Some x -> inl x | None -> inr tt end) with inl x -> ... | inr y -> ... end`. Thanks to these simplifications, the proofs in the contract_coq directory are simpler. | 15 September 2020, 12:28:46 UTC |
1f739de | Raphaël Cauderlier | 08 July 2020, 08:49:35 UTC | [Michocoq] Improve checking time of the SLC proof On my machine, it is now checked in 16s instead of 56s. | 29 August 2020, 15:21:54 UTC |
02388f8 | Raphaël Cauderlier | 22 April 2020, 14:00:01 UTC | [michocoq] Fix typing of chain_id constants (bytes instead of strings) | 24 August 2020, 12:51:55 UTC |
d7cd730 | Raphaël Cauderlier | 16 April 2020, 09:43:55 UTC | [michocoq] Foramlise byte sequences | 24 August 2020, 12:51:55 UTC |
5bf0775 | Raphaël Cauderlier | 15 April 2020, 13:43:50 UTC | [michocoq] Fix the semantics of EDIV | 24 August 2020, 12:51:55 UTC |
83d1e37 | Raphaël Cauderlier | 15 April 2020, 14:01:33 UTC | [michocoq] Big map litterals | 24 August 2020, 12:51:55 UTC |
03244f9 | Raphaël Cauderlier | 14 April 2020, 20:29:53 UTC | [michocoq] Add missing case for the `chain_id` type in the Micheline2michelson parser | 24 August 2020, 12:51:55 UTC |
411a3d3 | Raphaël Cauderlier | 14 April 2020, 20:13:21 UTC | [michocoq] Add the missing case AND :: int : nat : 'S -> nat : 'S | 24 August 2020, 12:51:55 UTC |
13b317b | Raphaël Cauderlier | 08 April 2020, 10:10:55 UTC | [michocoq] Formalize the relation between key_hash, addresses and contracts | 24 August 2020, 12:51:55 UTC |
99b67eb | Raphaël Cauderlier | 08 April 2020, 10:02:49 UTC | [michocoq] remove an unused file | 24 August 2020, 12:51:55 UTC |
3ffee65 | Raphaël Cauderlier | 24 August 2020, 12:01:25 UTC | [SLC] remove unused imports | 24 August 2020, 12:51:54 UTC |
c8a57c8 | Raphaël Cauderlier | 17 July 2020, 12:04:38 UTC | [Optimizer] Optimize `PAIR; UNPAIR` | 17 July 2020, 12:05:04 UTC |
a403a4f | Raphaël Cauderlier | 16 July 2020, 15:19:10 UTC | Optimize `DIP n {}` | 16 July 2020, 15:19:10 UTC |
55af1d7 | Raphaël Cauderlier | 06 July 2020, 19:58:50 UTC | [Michocoq] Improve doc and arg names for precond_iter_bounded | 07 July 2020, 08:25:41 UTC |
12ee2ad | Raphaël Cauderlier | 16 June 2020, 13:12:01 UTC | [SLC] fuel minimization | 07 July 2020, 08:25:41 UTC |
b6580c5 | Raphaël Cauderlier | 09 June 2020, 14:07:28 UTC | [michocoq] Fix curly-brace wrapping of macros | 07 July 2020, 08:25:41 UTC |
8cdd957 | Arvid Jakobsson | 29 November 2019, 14:36:45 UTC | [SLC] Proof of the Spending Limit Contract This is joint work with Zaynah Dargaye <zaynah.dargaye@nomadic-labs.com>. See https://blog.nomadic-labs.com/formally-verifying-a-critical-smart-contract.html | 07 July 2020, 08:25:41 UTC |
98cd2c9 | Raphaël Cauderlier | 10 March 2020, 15:16:23 UTC | Add a lemma precond_iter on precond for ITER | 06 July 2020, 19:17:24 UTC |
50b5400 | Raphaël Cauderlier | 18 June 2020, 20:27:29 UTC | [michocoq] Propagation of annotations | 22 June 2020, 09:30:53 UTC |
83f6208 | Arvid Jakobsson | 18 June 2020, 13:35:44 UTC | [michocoq] WIP lexing and parsing of micheline annotations This does not compile because the definition of the syntax of Micheline nodes has been changed without changing the Micheline pretty-printer nor the converter from and to Michelson. | 22 June 2020, 09:30:36 UTC |
5d3d290 | Arvid Jakobsson | 18 June 2020, 13:35:44 UTC | [michocoq] Avoid using `Check` for unit tests Writing unit tests as `Check (eq_refl : f x = y).` works but dumps unnecessary output on stdout that can be confusing when compiling the project. The equivalent `Goal (f x = y). reflexivity. Qed.` does the same check without producing any output. | 19 June 2020, 20:08:22 UTC |
9eaab97 | Raphaël Cauderlier | 19 June 2020, 13:38:54 UTC | [michocoq] Fix the behaviour of `get_entrypoint_opt (Some "%default")` | 19 June 2020, 20:08:15 UTC |
2e8d5a3 | Raphaël Cauderlier | 16 December 2019, 08:18:47 UTC | [optimizer] Define and certify a Michelson optimizer The optimizer was initially designed for the backend of the Albert compiler, it has been slightly generalized and certified. The main theorem is the last one in file typed_optimizer.v: If the untyped instruction sequence i can be typechecked from stack type A to stack type B and then run successfully on stack sA, then (optimizer.optimize i) can also be typechecked from stack type A to stack type B and run successfully on stack sA yielding the same result. | 19 May 2020, 13:55:03 UTC |
11de7d7 | Raphaël Cauderlier | 10 May 2020, 14:48:32 UTC | Untyped macros in `instruction` | 19 May 2020, 13:55:02 UTC |
2415691 | Raphaël Cauderlier | 26 April 2020, 20:07:01 UTC | [michocoq] Simplification of tez.v This uses `Bool.Is_true (negb ...)` instead of `... = false` in the definition of the `mutez` type which simplifies a bit reasoning about the implementation of mutez. | 14 May 2020, 19:39:36 UTC |
93912f6 | Raphaël Cauderlier | 21 December 2019, 22:12:06 UTC | [michocoq] Prove second half of typer correctness This completes the correctness proof of the typer in Optimized mode. Before this, only the typed -> untyped -> typed round-trip was certified. | 14 May 2020, 19:39:36 UTC |
daec052 | Raphaël Cauderlier | 25 April 2020, 13:33:49 UTC | [michocoq] Typing and untyping mode (Readable or Optimized) Since the introduction of timestamp literals, the typer is not injective anymore so the converse of untyper.untype_type is not true. By introducing a typing and an untyping mode, we get back injectivity at least in optimized mode. | 14 May 2020, 19:39:36 UTC |
8591d76 | Raphaël Cauderlier | 21 December 2019, 21:53:16 UTC | [michocoq] Fix a bug in the typer Type-checking a mutez literal now fails in case of overflow. | 14 May 2020, 19:39:36 UTC |
ac659ab | Raphaël Cauderlier | 07 May 2020, 19:22:44 UTC | [build|ignore] Also ignore the cache of the `nia` tactic | 14 May 2020, 19:39:35 UTC |
34a1022 | Raphaël Cauderlier | 05 December 2019, 11:08:19 UTC | [michocoq] Use frienly notations in all verified scripts | 14 May 2020, 19:37:32 UTC |
5bd8859 | Raphaël Cauderlier | 03 December 2019, 12:19:06 UTC | [michocoq] Add a distinction between instructions and instruction sequences | 14 May 2020, 19:37:32 UTC |
980a820 | Raphaël Cauderlier | 29 November 2019, 14:27:04 UTC | [michocoq] Also separate IF_ and LOOP_ instructions from the other ones | 07 May 2020, 21:55:22 UTC |
95b18b8 | Raphaël Cauderlier | 17 March 2020, 17:40:39 UTC | [michocoq] Stratify opcodes and instructions. We call opcodes the instructions that do not take subprograms as argument nor have special treatment in the type-checker or evaluator. Most of the instructions in Michelson fall into this category, putting them aside makes the number of constructors of the instruction ASTs much smaller which is needed when reasoning on the syntax. In particular, many optimisations at the Michelson level require to reason about several terms in these ASTs by nesting destructs which was not tractable with more than 80 constructors. | 07 May 2020, 21:55:12 UTC |
ab60300 | Raphaël Cauderlier | 07 May 2020, 21:15:25 UTC | Remove syntax_equiv.v This is incomplete and broken. | 07 May 2020, 21:54:55 UTC |
ba48cdf | Raphaël Cauderlier | 24 January 2020, 10:26:23 UTC | Remove the return_to_sender contract This is a duplicate of the boomerang contract. | 07 May 2020, 21:54:42 UTC |
30ec384 | Guillaume Claret | 10 March 2020, 21:16:49 UTC | [Michocoq] Add parsing of timestamps | 18 April 2020, 12:34:45 UTC |
75ba1ed | Raphaël Cauderlier | 13 March 2020, 16:48:52 UTC | [CI|Tests] Run the tests in the CI | 18 April 2020, 12:34:45 UTC |
b6d740a | Raphaël Cauderlier | 13 March 2020, 16:46:47 UTC | [Build|Tests]: add a build-test target for Opam | 18 April 2020, 12:34:45 UTC |
2eeac09 | Raphaël Cauderlier | 13 March 2020, 16:35:42 UTC | [Tests] Regression traces | 18 April 2020, 12:34:44 UTC |
123c097 | Raphaël Cauderlier | 13 March 2020, 16:48:13 UTC | [Tests] Regression testing Tests are run with `make test` and regression traces are reset with `make RESET_REGRESSION=true test`. | 18 April 2020, 12:34:44 UTC |
3ae9aaf | Raphaël Cauderlier | 13 March 2020, 15:54:06 UTC | [Tests] Update the test suite | 18 April 2020, 12:34:44 UTC |
1c4fb62 | Raphaël Cauderlier | 16 July 2019, 08:57:17 UTC | [Michocoq] Formalize %-annotations and entrypoints Annotations are still ignored at lexing time but the semantically meaningful ones are supported in the untyped syntax. | 18 April 2020, 12:34:44 UTC |
c578eba | Guillaume Claret | 27 February 2020, 17:45:18 UTC | [build] Add support for Coq 8.11 | 18 April 2020, 12:03:13 UTC |
94071da | Guillaume Claret | 06 December 2019, 18:59:32 UTC | [of_ocaml] Add a README for the of_ocaml folder | 18 April 2020, 12:03:13 UTC |
a35ea8c | Guillaume Claret | 06 December 2019, 18:04:18 UTC | [of_ocaml] Beginning of injection of the syntax of Mi-Cho-Coq to OCaml | 18 April 2020, 12:03:13 UTC |
41fed52 | Guillaume Claret | 03 December 2019, 15:35:40 UTC | [of_ocaml] Bijection for the comparable types | 18 April 2020, 12:03:13 UTC |
e94f138 | Guillaume Claret | 02 December 2019, 14:54:09 UTC | [of_ocaml] Explicit definition of coq_to_ocaml_typ | 18 April 2020, 12:03:13 UTC |
bbb0057 | Guillaume Claret | 16 November 2019, 16:28:49 UTC | [of_ocaml] Extend one side on the equivalence of the types with comparable types | 18 April 2020, 12:03:13 UTC |
e432e03 | Guillaume Claret | 16 November 2019, 13:29:15 UTC | [of_ocaml] Add one side of the equivalence with the Coq AST | 18 April 2020, 12:03:12 UTC |
80978ee | Guillaume Claret | 16 November 2019, 13:28:16 UTC | [of_ocaml] Add imported syntax definition from the OCaml code | 18 April 2020, 12:03:12 UTC |
fdfa10d | Raphaël Cauderlier | 04 December 2019, 20:50:34 UTC | [Michocoq] Remove superfluous functors | 18 April 2020, 12:03:12 UTC |
ae11043 | Raphaël Cauderlier | 04 December 2019, 14:19:10 UTC | [Michocoq] Remove contract literals | 18 April 2020, 11:49:22 UTC |
5b40d03 | Raphaël Cauderlier | 18 April 2020, 11:40:18 UTC | [CI] fix shellcheck URL | 18 April 2020, 11:43:19 UTC |
3fb4ceb | Arvid Jakobsson | 10 March 2020, 14:23:46 UTC | [generic_multisig] Add CHAIN_ID to signature Related to #21 | 11 March 2020, 13:52:45 UTC |
00e403d | Raphaël Cauderlier | 13 February 2020, 17:07:39 UTC | [SC verif] Deposit contract | 13 February 2020, 17:07:39 UTC |
90abcb0 | Raphaël Cauderlier | 23 January 2020, 22:29:22 UTC | [build] Add missing dependency to ocamlbuild | 13 February 2020, 10:07:44 UTC |
9b308f4 | Raphaël Cauderlier | 12 February 2020, 13:15:58 UTC | [doc] slides for WTSC | 12 February 2020, 13:23:16 UTC |
949a7a4 | Raphaël Cauderlier | 12 February 2020, 13:15:36 UTC | [doc] slides of past talks | 12 February 2020, 13:23:16 UTC |
a0ebbfd | Raphaël Cauderlier | 27 January 2020, 09:47:43 UTC | [doc] More explicit names for the talk directories | 27 January 2020, 09:48:13 UTC |
f65e22e | Raphaël Cauderlier | 13 January 2020, 12:33:51 UTC | [doc] slides for the workshop at Cobra in Aarhus | 13 January 2020, 12:34:38 UTC |
dc275c8 | Guillaume Claret | 04 December 2019, 09:27:10 UTC | Fix the install of the michocoq binary | 04 December 2019, 09:39:27 UTC |
9aa10a2 | Arvid Jakobsson | 29 November 2019, 14:39:11 UTC | [ott] remove the original michocott formalization | 29 November 2019, 14:39:11 UTC |
ceb487e | Raphaël Cauderlier | 11 September 2019, 07:54:20 UTC | Michocott: Update michelson.ott to ease documentation generation | 29 November 2019, 13:41:28 UTC |
8733671 | Basile Pesin | 31 May 2019, 13:43:15 UTC | Corrected the 'a's that were changed in 'ty2's | 29 November 2019, 13:41:24 UTC |
3098cf5 | Basile Pesin | 30 May 2019, 17:27:17 UTC | All the way to extraction | 29 November 2019, 13:41:11 UTC |
f2939c1 | Basile Pesin | 30 May 2019, 16:01:51 UTC | Removed ambiguity by adding explicit annotations | 29 November 2019, 13:40:31 UTC |
eb1c38f | Basile Pesin | 29 May 2019, 23:02:55 UTC | Every rule is good with doc but multiple parses on compilation to coq for list set map | 29 November 2019, 13:40:31 UTC |
609a9c5 | Basile Pesin | 29 May 2019, 19:06:58 UTC | ott spec OK except for list and map | 29 November 2019, 13:40:31 UTC |
218ee17 | Basile Pesin | 29 May 2019, 13:09:06 UTC | Changed symbol for typing to '::' and symbol for cons to ':' in michelson_typing | 29 November 2019, 13:40:31 UTC |
a7ba07f | Raphaël Cauderlier | 29 May 2019, 09:23:37 UTC | [Michocott] Formalize the typing rules of Michelson in OTT TOFIX: Currently the syntax of Michelson is not shared with michelson.ott. Moreover I used `:` for the typing relation and `::` for stack consing whereas the documentation (and michelson.ott) use `:` for consing and `::` for typing. | 29 November 2019, 13:40:31 UTC |
cdc97c1 | Raphaël Cauderlier | 28 November 2019, 15:06:48 UTC | [CI] Add Coq v8.10 | 28 November 2019, 15:06:48 UTC |
ac14acd | Raphaël Cauderlier | 28 November 2019, 10:00:56 UTC | Add the IF_RIGHT macro at the typed syntax level | 28 November 2019, 10:00:56 UTC |
e729117 | Raphaël Cauderlier | 26 November 2019, 21:09:02 UTC | Remove IF_RIGHT The `IF_RIGHT` macro was incorrectly documented as an instruction when the Mi-Cho-Coq effort started. The macro expanser correctly converted ot to its expanded form so all handling of `IF_RIGHT` as an instruction was basically dead code. | 26 November 2019, 21:09:02 UTC |
a7655d8 | Raphaël Cauderlier | 23 November 2019, 08:33:21 UTC | Formatting | 25 November 2019, 10:24:17 UTC |
48f957f | Raphaël Cauderlier | 20 November 2019, 08:13:43 UTC | Printer: simplify Michelson -> Micheline and the Micheline printer | 25 November 2019, 10:23:25 UTC |
474723b | Raphaël Cauderlier | 14 November 2019, 17:33:09 UTC | Make the type argument of error.Return implicit | 14 November 2019, 17:33:09 UTC |
3bebfc4 | Raphaël Cauderlier | 14 November 2019, 17:13:23 UTC | Swap arguments of bind | 14 November 2019, 17:19:07 UTC |
085c7d7 | Guillaume Claret | 23 October 2019, 14:48:57 UTC | Remove all remaining binds without let! notation | 14 November 2019, 17:19:07 UTC |
f7efb6f | Guillaume Claret | 23 October 2019, 13:43:29 UTC | Use the let! notation | 14 November 2019, 17:11:20 UTC |
a0ad40f | Guillaume Claret | 23 October 2019, 13:48:45 UTC | Add a module to namespace the let! notation | 14 November 2019, 17:10:51 UTC |
3993c1c | Guillaume Claret | 23 October 2019, 12:45:53 UTC | Add a let! notation for the bind | 06 November 2019, 15:48:00 UTC |
d18aeba | Guillaume Claret | 23 October 2019, 12:44:24 UTC | Remove unused Eval | 06 November 2019, 15:48:00 UTC |
d45b391 | Guillaume Claret | 23 October 2019, 12:37:56 UTC | Ignore .lia.cache files | 06 November 2019, 15:48:00 UTC |
edb58ee | Arvid Jakobsson | 06 November 2019, 15:08:13 UTC | Update coq-mi-cho-coq.opam: remove duplicate synpopsis | 06 November 2019, 15:08:13 UTC |
ec3f4a8 | Guillaume Claret | 23 October 2019, 15:13:34 UTC | Backport upstream changes to the opam package | 01 November 2019, 16:31:58 UTC |
ab8c856 | Arvid Jakobsson | 23 October 2019, 08:52:16 UTC | Make sure that make clean removes files generated by extraction | 23 October 2019, 08:52:16 UTC |
61e2773 | Raphaël Cauderlier | 18 October 2019, 14:00:51 UTC | PAPAIR and UNPAPAIR macros | 22 October 2019, 14:18:33 UTC |
1b89f58 | Raphaël Cauderlier | 10 October 2019, 11:14:44 UTC | Fix expansion of the DUUUP macro | 22 October 2019, 14:18:33 UTC |