Commit b9c06fd
feat(spark): Stage 8c-M2 — live compute contract + pure dominates + inner invariant
Unlocks the deferred compute contract by solving the two blockers:
1. dominates marked #[pure] — Creusot can now call it inside ensures/
requires/invariant clauses; without pure the verifier cannot unfold
dominates into the compute postcondition.
2. compute ensures (^candidates) — four postconditions now live:
• length preserved
• objectives read-only
• is_pareto_optimal == ¬(∃ j≠i: dominates(j,i)) (correctness)
• return value ⊆ optimal indices (frontier membership)
Uses ^candidates (Creusot mutable-borrow sigil) for the final state.
3. Inner-loop invariant for dominated:
dominated ⟺ ∃ k < j, k ≠ i: dominates(candidates[k], candidates[i])
Written as cfg_attr(feature = "creusot", invariant(...)) so it is a
no-op on stable Rust and a real Creusot invariant under --features creusot.
CREUSOT-SETUP.md: updated stage table (M1 done, M2 done, M3 pending);
documents the remaining outer-loop invariant deferred to Stage 8c-M3.
51 tests passing. Stable build unaffected.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>1 parent 7c02c2e commit b9c06fd
2 files changed
Lines changed: 80 additions & 21 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
21 | 21 | | |
22 | 22 | | |
23 | 23 | | |
24 | | - | |
25 | | - | |
| 24 | + | |
| 25 | + | |
| 26 | + | |
| 27 | + | |
26 | 28 | | |
27 | 29 | | |
28 | 30 | | |
| |||
86 | 88 | | |
87 | 89 | | |
88 | 90 | | |
89 | | - | |
90 | | - | |
91 | | - | |
| 91 | + | |
| 92 | + | |
| 93 | + | |
| 94 | + | |
92 | 95 | | |
93 | 96 | | |
94 | 97 | | |
| |||
97 | 100 | | |
98 | 101 | | |
99 | 102 | | |
100 | | - | |
101 | | - | |
| 103 | + | |
| 104 | + | |
| 105 | + | |
| 106 | + | |
| 107 | + | |
| 108 | + | |
| 109 | + | |
| 110 | + | |
| 111 | + | |
| 112 | + | |
| 113 | + | |
| 114 | + | |
| 115 | + | |
| 116 | + | |
| 117 | + | |
102 | 118 | | |
103 | 119 | | |
104 | 120 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
114 | 114 | | |
115 | 115 | | |
116 | 116 | | |
| 117 | + | |
| 118 | + | |
| 119 | + | |
| 120 | + | |
117 | 121 | | |
118 | 122 | | |
119 | 123 | | |
| |||
165 | 169 | | |
166 | 170 | | |
167 | 171 | | |
168 | | - | |
169 | | - | |
170 | | - | |
171 | | - | |
172 | | - | |
173 | | - | |
174 | | - | |
175 | | - | |
176 | | - | |
177 | | - | |
178 | | - | |
179 | | - | |
180 | | - | |
181 | | - | |
| 172 | + | |
| 173 | + | |
| 174 | + | |
| 175 | + | |
| 176 | + | |
| 177 | + | |
| 178 | + | |
| 179 | + | |
| 180 | + | |
| 181 | + | |
| 182 | + | |
| 183 | + | |
| 184 | + | |
| 185 | + | |
| 186 | + | |
| 187 | + | |
| 188 | + | |
| 189 | + | |
| 190 | + | |
| 191 | + | |
| 192 | + | |
| 193 | + | |
| 194 | + | |
| 195 | + | |
| 196 | + | |
| 197 | + | |
| 198 | + | |
| 199 | + | |
| 200 | + | |
| 201 | + | |
| 202 | + | |
| 203 | + | |
| 204 | + | |
| 205 | + | |
| 206 | + | |
| 207 | + | |
| 208 | + | |
| 209 | + | |
| 210 | + | |
| 211 | + | |
| 212 | + | |
182 | 213 | | |
183 | 214 | | |
184 | 215 | | |
185 | 216 | | |
186 | 217 | | |
187 | 218 | | |
188 | 219 | | |
| 220 | + | |
| 221 | + | |
| 222 | + | |
| 223 | + | |
| 224 | + | |
| 225 | + | |
| 226 | + | |
| 227 | + | |
| 228 | + | |
| 229 | + | |
| 230 | + | |
| 231 | + | |
189 | 232 | | |
190 | 233 | | |
191 | 234 | | |
| |||
0 commit comments