Commit 5cd7305
committed
feat(contracts): Detect and warn about mutual recursion with #[kani::recursion]
The per-function REENTRY mechanism used by #[kani::recursion] only handles
direct recursion (f calls f) soundly. For mutual recursion (f calls g,
g calls f), the REENTRY flag for g is never set, so g's body executes
fully instead of being replaced by its contract. This is a silent
soundness gap — no error or warning was emitted.
This change adds check_mutual_recursion() in the contract transform pass.
When a function with #[kani::recursion] is being processed in
RecursiveCheck mode, we scan its MIR body for calls to other functions
that also have contracts AND #[kani::recursion]. For each such callee,
we check if the callee's body calls back to the original function. If
so, we emit a span_warn pointing at the call site.
We require both has_contract() and has_recursion() on the callee because
if the callee has a contract but no #[kani::recursion], Kani replaces
the call with the contract abstraction — no mutual recursion occurs.
Limitations:
- Only detects one level of indirection (f->g->f), not deeper chains.
- Reports only the first mutual-recursive callee per function.
Includes a test case (mutual_recursion_unsound.rs) with two mutually
recursive functions that triggers the warning.1 parent d2c6dca commit 5cd7305
3 files changed
Lines changed: 108 additions & 0 deletions
File tree
- kani-compiler/src/kani_middle/transform
- tests/expected/function-contract
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
302 | 302 | | |
303 | 303 | | |
304 | 304 | | |
| 305 | + | |
| 306 | + | |
| 307 | + | |
305 | 308 | | |
306 | 309 | | |
307 | 310 | | |
| |||
552 | 555 | | |
553 | 556 | | |
554 | 557 | | |
| 558 | + | |
| 559 | + | |
| 560 | + | |
| 561 | + | |
| 562 | + | |
| 563 | + | |
| 564 | + | |
| 565 | + | |
| 566 | + | |
| 567 | + | |
| 568 | + | |
| 569 | + | |
| 570 | + | |
| 571 | + | |
| 572 | + | |
| 573 | + | |
| 574 | + | |
| 575 | + | |
| 576 | + | |
| 577 | + | |
| 578 | + | |
| 579 | + | |
| 580 | + | |
| 581 | + | |
| 582 | + | |
| 583 | + | |
| 584 | + | |
| 585 | + | |
| 586 | + | |
| 587 | + | |
| 588 | + | |
| 589 | + | |
| 590 | + | |
| 591 | + | |
| 592 | + | |
| 593 | + | |
| 594 | + | |
| 595 | + | |
| 596 | + | |
| 597 | + | |
| 598 | + | |
| 599 | + | |
| 600 | + | |
| 601 | + | |
| 602 | + | |
| 603 | + | |
| 604 | + | |
| 605 | + | |
| 606 | + | |
| 607 | + | |
| 608 | + | |
| 609 | + | |
| 610 | + | |
| 611 | + | |
| 612 | + | |
| 613 | + | |
| 614 | + | |
| 615 | + | |
| 616 | + | |
| 617 | + | |
| 618 | + | |
| 619 | + | |
| 620 | + | |
| 621 | + | |
| 622 | + | |
| 623 | + | |
| 624 | + | |
| 625 | + | |
| 626 | + | |
| 627 | + | |
| 628 | + | |
Lines changed: 2 additions & 0 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
Lines changed: 32 additions & 0 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
| 18 | + | |
| 19 | + | |
| 20 | + | |
| 21 | + | |
| 22 | + | |
| 23 | + | |
| 24 | + | |
| 25 | + | |
| 26 | + | |
| 27 | + | |
| 28 | + | |
| 29 | + | |
| 30 | + | |
| 31 | + | |
| 32 | + | |
0 commit comments