846710a | Benjamin Gregoire | 14 July 2019, 06:50:07 UTC | Start restructuration of the code to be able to avant mutual dependency between type and mpath | 14 July 2019, 06:50:07 UTC |
a9666b1 | Pierre-Yves Strub | 06 July 2019, 22:07:08 UTC | user error message for FXE_CtorInvalidArity [fix #17387] | 06 July 2019, 22:07:21 UTC |
af25c22 | Benjamin Gregoire | 19 June 2019, 13:28:03 UTC | Bug fixing in phl ([closes #17380]) | 19 June 2019, 13:28:03 UTC |
fc8d388 | Pierre-Yves Strub | 11 June 2019, 09:59:50 UTC | Move to Why3 1.x | 11 June 2019, 09:59:50 UTC |
679f333 | Pierre-Yves Strub | 17 May 2019, 05:46:17 UTC | run-test: add a -timing option | 17 May 2019, 05:46:17 UTC |
a79235c | Pierre-Yves Strub | 17 May 2019, 05:34:41 UTC | add an option [-tstats FILE] for recording timing statistics | 17 May 2019, 05:34:41 UTC |
e522b67 | Pierre-Yves Strub | 01 May 2019, 07:37:32 UTC | runtest: python2 -> python3 | 01 May 2019, 07:37:32 UTC |
f293e76 | François Dupressoir | 16 April 2019, 15:21:17 UTC | Towards fixing XDG-based config | 16 April 2019, 16:18:33 UTC |
27c1df3 | Pierre-Yves Strub | 28 March 2019, 05:41:39 UTC | Allow : t1 || t2 || ... || tn | 28 March 2019, 05:41:39 UTC |
41219ef | Pierre-Yves Strub | 26 March 2019, 13:42:33 UTC | add reduction of Int div/mod by reduction of edivz + bind symbol to Why3 | 26 March 2019, 13:42:33 UTC |
a041441 | Pierre-Yves Strub | 26 March 2019, 13:32:42 UTC | Add congruence rule for projections | 26 March 2019, 13:32:42 UTC |
5e9f955 | Pierre-Yves Strub | 26 March 2019, 10:46:03 UTC | Extend matching (projections) | 26 March 2019, 10:46:03 UTC |
8a0c097 | Pierre-Yves Strub | 26 March 2019, 09:59:05 UTC | Bind auto-conseq in eqobsin | 26 March 2019, 09:59:05 UTC |
b481f98 | Pierre-Yves Strub | 25 March 2019, 12:03:45 UTC | "call L" automatically applies "L" to "_" when needed. | 25 March 2019, 12:03:45 UTC |
1fb57b6 | Pierre-Yves Strub | 25 March 2019, 08:07:17 UTC | fix reduction of fixpoints with extra arguments | 25 March 2019, 08:07:17 UTC |
4387903 | Pierre-Yves Strub | 28 January 2019, 13:48:44 UTC | Fix pretty printing of records projectors (when applied) | 28 January 2019, 13:48:44 UTC |
9c1fdfb | Pierre-Yves Strub | 28 January 2019, 13:40:40 UTC | Reduction fix: reduces record projections when applied. | 28 January 2019, 13:40:40 UTC |
a893051 | Benjamin Gregoire | 17 January 2019, 17:22:08 UTC | add missing quantification over memory in async while | 17 January 2019, 17:22:08 UTC |
337a8ab | Cécile BARITEL-RUET | 20 December 2018, 14:25:05 UTC | fix a smt call | 20 December 2018, 14:25:05 UTC |
b2b7e5b | Cécile BARITEL-RUET | 20 December 2018, 13:13:35 UTC | fix List.ec | 20 December 2018, 13:13:35 UTC |
532e12b | Cécile BARITEL-RUET | 20 December 2018, 12:28:06 UTC | fix types of an operator when its definition is a match, where its type was only its return type inside its body. | 20 December 2018, 12:28:06 UTC |
192a23f | Cécile BARITEL-RUET | 19 December 2018, 17:24:55 UTC | fix type of pred1 from 'a -> bool to 'a -> 'a -> bool | 19 December 2018, 17:24:55 UTC |
0b59cac | Pierre-Yves Strub | 18 December 2018, 14:34:23 UTC | fix bug in LDecl where the type of the operator was not correct. | 18 December 2018, 14:35:55 UTC |
88a87da | Cécile BARITEL-RUET | 17 December 2018, 14:33:18 UTC | Merge branch '1.0' of https://github.com/EasyCrypt/easycrypt into 1.0 | 17 December 2018, 14:33:18 UTC |
dfe37eb | Cécile BARITEL-RUET | 17 December 2018, 14:32:33 UTC | fix bug where the type of pred1 was bool instead of 'a -> bool | 17 December 2018, 14:32:33 UTC |
5a31709 | Benjamin Gregoire | 12 December 2018, 17:00:34 UTC | simplify proof | 12 December 2018, 17:00:34 UTC |
17eced8 | Pierre-Yves Strub | 11 December 2018, 16:29:13 UTC | Simplifying async-while examples | 11 December 2018, 16:29:13 UTC |
2d05f8b | Pierre-Yves Strub | 11 December 2018, 16:24:53 UTC | async-while: example for nested loops | 11 December 2018, 16:24:53 UTC |
ed7bf6c | Pierre-Yves Strub | 03 December 2018, 12:40:04 UTC | (internal API) - typed application soft-constructor for forms | 03 December 2018, 12:40:04 UTC |
f120f53 | Benjamin Gregoire | 13 November 2018, 08:12:18 UTC | fix error message | 13 November 2018, 08:12:18 UTC |
9959602 | Pierre-Yves Strub | 07 November 2018, 21:51:34 UTC | More results in ZModP | 07 November 2018, 21:51:34 UTC |
5c95527 | Pierre-Yves Strub | 07 November 2018, 21:45:42 UTC | New tactic: - exlim (shorthand for exists*; elim*) - ecall (seq + exlim + call with inference) | 07 November 2018, 21:47:02 UTC |
28c5228 | Pierre-Yves Strub | 25 October 2018, 15:21:38 UTC | Fix Cramer Shoup | 25 October 2018, 15:21:38 UTC |
672c36d | Benjamin Gregoire | 25 October 2018, 14:38:06 UTC | weaken axiom | 25 October 2018, 14:38:06 UTC |
5b694ae | Benjamin Gregoire | 25 October 2018, 07:14:05 UTC | add some lemma | 25 October 2018, 07:14:05 UTC |
9d34c3b | Jorden Whitefield | 25 September 2018, 16:48:02 UTC | README | 25 September 2018, 16:48:02 UTC |
6b07f83 | Pierre-Yves Strub | 20 September 2018, 09:37:23 UTC | Extend SmtMap theory with new results. Co-authored-by: Alley Stoughton <alley.stoughton@icloud.com> | 20 September 2018, 09:37:23 UTC |
92effbe | Ruette | 18 September 2018, 16:03:04 UTC | adding joint operator (+) and its lemmas (#21) | 18 September 2018, 16:03:04 UTC |
5cbf6f1 | Pierre-Yves Strub | 17 September 2018, 11:33:37 UTC | better simplification of int/real addition Expressions of the form (x + c1) + c2 are now simplified to (x + [c1+c2]) (modulo commutativity of (+). | 17 September 2018, 11:33:37 UTC |
1b7e5bb | Ruette | 17 September 2018, 10:58:49 UTC | refining bound on Strong_RP_RF (#20) | 17 September 2018, 10:58:49 UTC |
c997f51 | Pierre-Yves Strub | 12 September 2018, 11:42:14 UTC | fix parsing of codeposition Syntax for offset is now: &+n and &-n. | 12 September 2018, 11:42:33 UTC |
978d985 | Pierre-Yves Strub | 12 September 2018, 11:42:02 UTC | fix handling of negative code positions | 12 September 2018, 11:42:02 UTC |
d3a650a | Benjamin Gregoire | 24 July 2018, 05:53:40 UTC | fix condition in the rule for asynchrone while | 24 July 2018, 05:53:40 UTC |
7a4cb50 | Pierre-Yves Strub | 14 July 2018, 05:48:00 UTC | Add an option for setting the printing width. Option can be given using: - a command line option (-pp-width) - an easycrypt.conf entry (general/pp-width) - a pervasive option (pragma PP:width = ...) | 14 July 2018, 05:58:10 UTC |
a52f327 | Pierre-Yves Strub | 13 July 2018, 18:34:30 UTC | New tactic: lossless. This tactic tries to prove goal of the form "islossless M.f". It uses random/lossless solve DB for pruning goals related to the losslessness of samplings or call to abstract procs. | 13 July 2018, 18:35:17 UTC |
de5cd4a | Pierre-Yves Strub | 13 July 2018, 10:56:47 UTC | Extend syntax for code position. Syntax is : codepos1 [.?] codepos1 [.?] ... [.?] codepos1 where codepos1 is of the form basepos [+-] offset and basepos is either an absolute position or of the form ^kw{n} where kw is amon if, while, <-, <@, <$ and {n} (which is optional) is a signed integer. | 13 July 2018, 10:57:06 UTC |
71f975a | Benjamin Gregoire | 12 July 2018, 23:57:01 UTC | fix the checking of generated name in TheoryReplay | 12 July 2018, 23:57:01 UTC |
97e5b1d | Benjamin Gregoire | 10 July 2018, 22:33:36 UTC | fix error in"unroll for" tactic in case of hoare and phoare | 10 July 2018, 22:33:36 UTC |
fecd089 | Pierre-Yves Strub | 09 July 2018, 06:47:56 UTC | apply: tactic now takes a clear/revert list as parameter | 09 July 2018, 06:47:56 UTC |
b75dc92 | Pierre-Yves Strub | 07 July 2018, 21:11:06 UTC | Add syntax for cast in expr/form: (e :~ ty) | 07 July 2018, 21:11:06 UTC |
85eabe3 | Pierre-Yves Strub | 27 June 2018, 03:27:30 UTC | Add [lossless / uniform / full] tags for operators These tags can be apply to operators whose co-domain is a distribution. It adds the relevant lossless / uniform / full axiom (named w.r.t the convention in Distr.ec) and add these axioms to the relevant lossless/random database. | 27 June 2018, 03:27:30 UTC |
e50b7a7 | Benjamin Gregoire | 21 June 2018, 13:50:55 UTC | add nix | 21 June 2018, 13:51:13 UTC |
fb7a987 | Pierre-Yves Strub | 19 June 2018, 13:25:10 UTC | More lemmas on List.take | 19 June 2018, 13:25:10 UTC |
ba545a9 | Benjamin Grégoire | 12 June 2018, 05:31:11 UTC | New tactic for static unrolling of "for-loops" The tactic statically unroll while loops of the form x <- int-constant while (guard) { body (does not write x); x <- f(x); } where "guard" and "f" can be statically evaluated at each iteration. The code is then replaced by the while loop fully unrolled. The tactic does not terminate if the unrolling leads to a infinite process. | 12 June 2018, 05:34:41 UTC |
43fd7aa | Francois Dupressoir | 03 June 2018, 23:18:05 UTC | Deploy smt blacklist (#19) Black-list all versions of Alt-Ergo < 2.2.0 + change default provers to : CVC4, Z3 & Alt-Ergo + fix relevant theories | 03 June 2018, 23:18:05 UTC |
4cf3582 | Pierre-Yves Strub | 31 May 2018, 13:00:17 UTC | Docker image: bump OCaml version to 4.04.0 | 31 May 2018, 13:00:17 UTC |
6da5cf4 | Pierre-Yves Strub | 25 May 2018, 20:12:54 UTC | Docker: install Z3 & CVC4 via apt-get | 25 May 2018, 20:12:54 UTC |
1b9269a | Pierre-Yves Strub | 21 May 2018, 20:36:27 UTC | New tactic: 'conseq ?>' where '?>' is a crush mode. Simplifies *HL post-condition from the pre using a crush-like simplication. Co-authored-by: Benjamin Grégoire <benjamin.gregoire@inria.fr> | 21 May 2018, 20:36:27 UTC |
165ee99 | Pierre-Yves Strub | 20 May 2018, 06:18:32 UTC | `rnd` (in equiv mode) now tries to simplify the post. For instance, it removes all losslessness requirements when the distribution is known to be lossless. Co-authored-by: Benjamin Grégoire <benjamin.gregoire@inria.fr> | 20 May 2018, 06:31:40 UTC |
7c6d40e | Pierre-Yves Strub | 28 April 2018, 15:09:18 UTC | characterization lemmas for <=> and \proper [closes #17377] | 29 April 2018, 09:34:36 UTC |
aa75b1d | Pierre-Yves Strub | 27 April 2018, 12:06:12 UTC | Move the contents of process_trivial down in the API. This makes 'seq' rules independent of hi-level tactics. | 27 April 2018, 12:06:12 UTC |
dcb1f2f | Pierre-Yves Strub | 27 April 2018, 11:38:08 UTC | Docker : allow the use of any branch for building a Docker image | 27 April 2018, 11:38:53 UTC |
64c24ed | Benjamin Gregoire | 26 April 2018, 18:31:53 UTC | improve "include" in module type and module. The following is now possible: type t, t', u, u', v, v'. module type OT = { proc f(_: t): t' proc g1(_: t): t' }. module type MT (O : OT) = { include OT proc g(_: u): u' }. module type MT1 (O : OT) = { include OT [f] proc g(_: u): u' }. module type MT2 (O : OT) = { include OT [f] {O.f} proc g(_: u): u' }. module type MT3 (O : OT) = { include OT [f] {O.g1} proc g(_: u): u' }. module ((M : MT1):MT2) (O : OT) = { proc f = O.f proc g(x: u): u' = { return witness; } }. module M1 = { proc f () : unit = { } proc g () : unit = { } }. module M2 = { include M1 }. module M3 = { include M1 [f] }. module M4 = { include M1 [+f] }. module M5 = { include M1 [-f] }. module F (O:OT) = { proc f1 () = {} }. module G (O:OT) = { include O include F(O) }. module G1 (O:OT) = { include O [-f] include F(O) }. | 26 April 2018, 18:31:53 UTC |
7f33e2a | Benjamin Grégoire | 26 April 2018, 06:13:35 UTC | Module type include & bulk proc aliasing - 'include I' in module type allows the include of the contents of I - proc f1, f2, f3, ... = M imports f1, f2, f3 from M into the current module definition. [closes #17375] | 26 April 2018, 06:18:29 UTC |
4395a7e | François Dupressoir | 25 April 2018, 15:40:02 UTC | including mee-cbc in examples target | 25 April 2018, 16:27:44 UTC |
d30050d | Pierre-Yves Strub | 25 April 2018, 09:05:52 UTC | Induction principle for fmap | 25 April 2018, 09:05:52 UTC |
1845635 | Pierre-Yves Strub | 24 April 2018, 12:47:18 UTC | eta-conversion should only be triggered on terms with compatible types [fix #17306] | 24 April 2018, 13:13:19 UTC |
728c306 | Benjamin Gregoire | 24 April 2018, 09:11:29 UTC | prove the equivalence between two versions of CPA LR and b. | 24 April 2018, 09:11:41 UTC |
a27bd48 | Francois Dupressoir | 24 April 2018, 06:25:41 UTC | Extending SmtMap with new facts (eq_except, map) + adapting lib/examples | 24 April 2018, 06:25:41 UTC |
9ae0786 | Pierre-Yves Strub | 23 April 2018, 13:55:19 UTC | New revert pattern: `@x` This revert pattern revert a local-binding as a let-in construct. [closes #17291] | 23 April 2018, 14:06:48 UTC |
a18abdf | Pierre-Yves Strub | 23 April 2018, 13:37:01 UTC | Deploy multi args eta ticket 17278 (#12) * Reduction for multi-arg eta rule. [fix #17278] | 23 April 2018, 13:37:01 UTC |
d7510b9 | Pierre-Yves Strub | 23 April 2018, 12:04:04 UTC | is_finite : provide a weaker characterization | 23 April 2018, 12:16:30 UTC |
de0e240 | Pierre-Yves Strub | 20 April 2018, 05:14:36 UTC | New smt option: quorum This option expects an integer argument. It indicates the number of smt provers that must solve a goal before being accepted. A value of 0 set the quorum to its default value (1). Note that if provers do not agree while waiting to reach a quorum, the goal is rejected. [closes #17371] | 21 April 2018, 20:20:39 UTC |
6ffe960 | Pierre-Yves Strub | 20 April 2018, 05:20:48 UTC | Swap the semantic of `` and `!` for smt provers option. [closes #17372] | 21 April 2018, 20:06:23 UTC |
e8b4835 | François Dupressoir | 19 April 2018, 14:54:07 UTC | moving OldDistr to oldlibs to mark deprecation | 21 April 2018, 20:05:37 UTC |
dcbc9de | François Dupressoir | 16 April 2018, 16:02:44 UTC | forgotten example (not included in CI) | 21 April 2018, 20:05:37 UTC |
6124ea4 | François Dupressoir | 13 April 2018, 16:26:38 UTC | pruning some deprecated theories | 21 April 2018, 20:05:37 UTC |
cefe872 | François Dupressoir | 20 April 2018, 09:50:15 UTC | porting example Upto | 20 April 2018, 16:27:35 UTC |
61fef31 | François Dupressoir | 20 April 2018, 09:25:38 UTC | porting example Fundamental Lemma | 20 April 2018, 16:27:35 UTC |
f027390 | François Dupressoir | 20 April 2018, 09:03:45 UTC | removing old WhileSampling | 20 April 2018, 16:27:35 UTC |
55d12be | François Dupressoir | 20 April 2018, 09:03:10 UTC | porting example WhileSampling | 20 April 2018, 16:27:35 UTC |
a7ed76c | François Dupressoir | 19 April 2018, 16:27:33 UTC | porting example Dice4_6 | 20 April 2018, 16:27:35 UTC |
526d0c0 | Benjamin Gregoire | 20 April 2018, 14:36:26 UTC | fix [#17369] : bug in printing of module application | 20 April 2018, 14:36:26 UTC |
1a54e95 | Pierre-Yves Strub | 16 April 2018, 22:51:35 UTC | Squashed commit of the following: commit 8a24a7237a36b7dda929a03eeaf70be1058d1e10 Author: Benjamin Gregoire <Benjamin.Gregoire@inria.fr> Date: Mon Apr 16 13:37:55 2018 +0200 fix glob bug by normalising glob in axioms/lemmas fix #17132 | 16 April 2018, 22:52:00 UTC |
e5969ba | Pierre-Yves Strub | 05 April 2018, 13:22:23 UTC | | 05 April 2018, 13:22:23 UTC |
81d62ac | Pierre-Yves Strub | 03 April 2018, 16:48:08 UTC | pretty printer with {| ... with ... |} | 03 April 2018, 16:48:08 UTC |
79c3916 | Pierre-Yves Strub | 03 April 2018, 08:09:24 UTC | Add new construction for records: { x with f1 = v1; ...; fn = vn; } | 03 April 2018, 08:09:24 UTC |
dd158c9 | Pierre-Yves Strub | 21 March 2018, 09:30:54 UTC | Why3config: only try user configuration file | 21 March 2018, 09:30:54 UTC |
6453d5f | Pierre-Yves Strub | 21 March 2018, 09:29:50 UTC | Do not load Why3 config files when executing why3config cmd | 21 March 2018, 09:29:50 UTC |
bd4c706 | Pierre-Yves Strub | 21 March 2018, 09:06:16 UTC | New command: why3config | 21 March 2018, 09:06:16 UTC |
0c76343 | Pierre-Yves Strub | 20 March 2018, 09:11:32 UTC | Put configuration files under $XDG | 20 March 2018, 09:11:32 UTC |
9867134 | Alley Stoughton | 28 February 2018, 06:58:30 UTC | Fixed bug in SMT option matching The third stage of filtering in the definition of option_matching had a bug, meaning that attempts to rely on it resulted in assertion failures. But that last stage - disambiguating from right to left - was arguably hard for users to predict, anyway. So, fixed the third stage, but left it out of algorithm. (If it's really desired, easy to put it back in, as now it'll work. But do we really think users will understand why, e.g., [prover x=1] means [prover maxlemmas=1] - because the x in maxlemmas comes earlier when working backward as opposed to the x in maxprovers?) This is how option disambiguation works: First filter-in those option names having the letters of the abbreviation abv in the correct order. Then work through the letters of abv in order, keeping only those option names in which each successive letter appears as early as possible | 28 February 2018, 06:58:30 UTC |
8ab4986 | Alley Stoughton | 22 February 2018, 18:54:57 UTC | Fixed mistake wrt oiter. | 26 February 2018, 15:04:53 UTC |
9e2c45b | Alley Stoughton | 22 February 2018, 17:44:03 UTC | Fixed poor spacing. | 26 February 2018, 15:04:53 UTC |
1ca374d | Alley Stoughton | 22 February 2018, 17:20:48 UTC | Reworking specification of current provers. All use-only instructions must come first. There are two "universal" use-only instructions: "" (all known provers), and "!" (no provers). It is illegal to mix ""/"!" with prover names (no point in doing so). As before, if the use-only part is empty, it means the currently known provers. The include/exclude instructions are processed in order, acting on the result of the use-only part. Examples (assuming "Z3" and "Alt-Ergo" are only known provers): prover []. (* no-op *) prover [-"Z3"]. (* removes "Z3" from current provers *) prover [+"Z3"]. (* adds "Z3" to current provers *) prover [""]. (* results in "Z3", "Alt-Ergo" *) prover ["!"]. (* results in no provers *) prover ["Z3"]. (* results in "Z3" *) prover ["Z3" "Alt-Ergo"]. (* results in "Z3", "Alt-Ergo" *) prover ["!" +"Z3"]. (* results in "Z3" *) prover ["" -"Z3"]. (* results in "Alt-Ergo" *) | 26 February 2018, 15:04:53 UTC |
36f7f5a | Alley Stoughton | 21 February 2018, 22:32:02 UTC | Added clean way to clear the list of current provers. The elements of prover [...] have one of the following forms, where s is a string: s (add s to the use-only list) +s (add include s to the include/exclude list) -s (add exclude s to the include/exclude list) The include/exclude list is ordered, so that later instructions can supersede earlier ones. The use-only list was not ordered, but now is. The relative order of the use-only and include/exclude lists is irrelevant, so that, e.g., prover ["Z3" +"Alt-Ergo"] and prover [+"Alt-Ergo" "Z3"] are equivalent. The semantics is that the use-only list is first interpreted (if it's empty, one starts with the current provers as the base), and only then are the instructions of the include/exclude list applied to it, in order. There was already the special use-only instruction "ALL". Now, there is also the use-only instruction "CLEAR", which clears the use-only list, but may be superseded by the use-only instructions that follow. Examples (assuming "Z3" and "Alt-Ergo" are only known provers): prover []. (* a no-op *) prover [+"Z3"] (* adds just "Z3" to whatever current provers are *) prover [-"Z3"] (* removes just "Z3" from whatever current provers are *) prover ["ALL"] (* results in "Z3", "Alt-Ergo" *) prover ["CLEAR"] (* results in nothing *) prover ["CLEAR" +"Z3"] (* results in just "Z3" *) prover [+"Z3" "CLEAR"] (* results in just "Z3" *) prover ["CLEAR" "Z3"] (* result in just "Z3" *) prover ["Z3" "CLEAR"] (* results in nothing *) prover [-"Z3" "ALL"] (* results in "Alt-Ergo" *) prover [+"Z3" "ALL" -"Z3"] (* results in "Alt-Ergo" *) prover [-"Z3" "ALL" +"Z3"] (* results in "Z3", "Alt-Ergo" *) | 26 February 2018, 15:04:53 UTC |
5115c89 | François Dupressoir | 23 February 2018, 12:20:12 UTC | SmtMap: rng and basic results | 24 February 2018, 08:13:05 UTC |
9f07d02 | Pierre-Yves Strub | 23 February 2018, 08:37:48 UTC | SmtMap : fdom and related results | 24 February 2018, 08:12:44 UTC |
dd27d32 | François Dupressoir | 22 February 2018, 10:57:52 UTC | whitespace | 22 February 2018, 10:57:52 UTC |
850f427 | Pierre-Yves Strub | 21 February 2018, 16:09:18 UTC | SMT backed map/fmap | 21 February 2018, 16:09:18 UTC |