Commit 45d1de0
feat(spark): Stage 8c-M3 — outer-loop invariant, CI hard gate
Completes Stage 8c. All three milestones done.
pareto.rs — outer-loop invariant for compute:
• Ghost snapshot `init = snapshot!(candidates)` at function entry.
On stable Rust this declaration compiles away (cfg-gated). With
--features creusot it creates a Snapshot<&mut [ProofCandidate]>
capturing *candidates at call time.
• #[cfg_attr(feature = "creusot", invariant(...))] at the top of the
outer for-i loop with two conjuncts:
(a) Objectives read-only: candidates[k].objectives == (*init)[k].objectives
for all k < n. Gives Creusot the framing fact it cannot auto-derive
from a mutable-borrow slice without an explicit statement.
(b) Prefix classification: for all k < i, is_pareto_optimal[k] equals
¬(∃ j ≠ k, j < n : dominates(j, k)). Together with (a) this closes
the induction and lets Creusot propagate the ensures postconditions
through the loop.
Inner-loop invariant (M2) preserved unchanged.
All existing comments updated: M2 note → M3 note.
formal-verification.yml — hard gate:
• Removed `continue-on-error: true` from the creusot-verify job.
• Added `why3 config detect` step + alt-ergo as fallback solver.
• Updated job name and comments to reflect hard-gate status.
CREUSOT-SETUP.md:
• Stage table: M3 marked done.
• CI section updated: both jobs are hard gates.
• Outer-loop invariant structure documented (snapshot + two conjuncts).
51 spark tests passing. Stable build unaffected.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>1 parent b9c06fd commit 45d1de0
3 files changed
Lines changed: 110 additions & 46 deletions
File tree
- .github/workflows
- crates/echidna-core-spark
- src
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
3 | 3 | | |
4 | 4 | | |
5 | 5 | | |
6 | | - | |
7 | | - | |
8 | | - | |
| 6 | + | |
9 | 7 | | |
10 | 8 | | |
11 | | - | |
12 | | - | |
| 9 | + | |
| 10 | + | |
13 | 11 | | |
14 | | - | |
15 | | - | |
16 | | - | |
17 | | - | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
18 | 17 | | |
19 | 18 | | |
20 | 19 | | |
| |||
34 | 33 | | |
35 | 34 | | |
36 | 35 | | |
37 | | - | |
| 36 | + | |
38 | 37 | | |
39 | 38 | | |
40 | 39 | | |
| |||
58 | 57 | | |
59 | 58 | | |
60 | 59 | | |
61 | | - | |
| 60 | + | |
62 | 61 | | |
63 | | - | |
| 62 | + | |
64 | 63 | | |
65 | | - | |
66 | | - | |
| 64 | + | |
| 65 | + | |
| 66 | + | |
| 67 | + | |
| 68 | + | |
| 69 | + | |
67 | 70 | | |
68 | 71 | | |
69 | 72 | | |
| |||
80 | 83 | | |
81 | 84 | | |
82 | 85 | | |
83 | | - | |
84 | | - | |
| 86 | + | |
| 87 | + | |
| 88 | + | |
| 89 | + | |
| 90 | + | |
| 91 | + | |
| 92 | + | |
| 93 | + | |
| 94 | + | |
85 | 95 | | |
86 | 96 | | |
87 | 97 | | |
88 | | - | |
89 | | - | |
90 | | - | |
| 98 | + | |
| 99 | + | |
91 | 100 | | |
92 | | - | |
| 101 | + | |
93 | 102 | | |
94 | 103 | | |
95 | 104 | | |
96 | 105 | | |
97 | 106 | | |
98 | | - | |
99 | | - | |
100 | | - | |
| 107 | + | |
| 108 | + | |
| 109 | + | |
| 110 | + | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
88 | 88 | | |
89 | 89 | | |
90 | 90 | | |
91 | | - | |
92 | | - | |
93 | | - | |
94 | | - | |
| 91 | + | |
| 92 | + | |
| 93 | + | |
| 94 | + | |
| 95 | + | |
| 96 | + | |
| 97 | + | |
95 | 98 | | |
96 | 99 | | |
97 | 100 | | |
| |||
108 | 111 | | |
109 | 112 | | |
110 | 113 | | |
111 | | - | |
| 114 | + | |
| 115 | + | |
| 116 | + | |
| 117 | + | |
| 118 | + | |
| 119 | + | |
| 120 | + | |
| 121 | + | |
| 122 | + | |
112 | 123 | | |
113 | | - | |
114 | | - | |
115 | | - | |
116 | | - | |
117 | | - | |
| 124 | + | |
| 125 | + | |
| 126 | + | |
| 127 | + | |
118 | 128 | | |
119 | 129 | | |
120 | 130 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
183 | 183 | | |
184 | 184 | | |
185 | 185 | | |
186 | | - | |
187 | | - | |
188 | | - | |
189 | | - | |
190 | | - | |
191 | | - | |
192 | | - | |
| 186 | + | |
| 187 | + | |
| 188 | + | |
| 189 | + | |
193 | 190 | | |
194 | 191 | | |
195 | 192 | | |
| |||
214 | 211 | | |
215 | 212 | | |
216 | 213 | | |
| 214 | + | |
| 215 | + | |
| 216 | + | |
| 217 | + | |
| 218 | + | |
| 219 | + | |
| 220 | + | |
| 221 | + | |
| 222 | + | |
| 223 | + | |
| 224 | + | |
| 225 | + | |
| 226 | + | |
| 227 | + | |
| 228 | + | |
217 | 229 | | |
| 230 | + | |
| 231 | + | |
| 232 | + | |
| 233 | + | |
| 234 | + | |
| 235 | + | |
| 236 | + | |
| 237 | + | |
| 238 | + | |
| 239 | + | |
| 240 | + | |
| 241 | + | |
| 242 | + | |
| 243 | + | |
| 244 | + | |
| 245 | + | |
| 246 | + | |
| 247 | + | |
| 248 | + | |
| 249 | + | |
| 250 | + | |
| 251 | + | |
| 252 | + | |
| 253 | + | |
| 254 | + | |
| 255 | + | |
| 256 | + | |
| 257 | + | |
| 258 | + | |
| 259 | + | |
| 260 | + | |
| 261 | + | |
218 | 262 | | |
219 | 263 | | |
220 | | - | |
221 | | - | |
| 264 | + | |
| 265 | + | |
222 | 266 | | |
223 | | - | |
224 | | - | |
225 | | - | |
226 | | - | |
| 267 | + | |
| 268 | + | |
| 269 | + | |
| 270 | + | |
227 | 271 | | |
228 | 272 | | |
229 | 273 | | |
| |||
0 commit comments