-
Notifications
You must be signed in to change notification settings - Fork 1
/
realm_activate_ops.v
71 lines (56 loc) · 2.86 KB
/
realm_activate_ops.v
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
Require Import CodeProofDeps.
Require Import Ident.
Require Import Constants.
Require Import RData.
Require Import EventReplay.
Require Import MoverTypes.
Require Import CommonLib.
Require Import AbsAccessor.Spec.
Require Import RmiAux2.Layer.
Require Import RmiOps.Code.realm_activate_ops.
Require Import RmiOps.LowSpecs.realm_activate_ops.
Local Open Scope Z_scope.
Section CodeProof.
Context `{real_params: RealParams}.
Context {memb} `{Hmemx: Mem.MemoryModelX memb}.
Context `{Hmwd: UseMemWithData memb}.
Let mem := mwd (cdata RData).
Context `{Hstencil: Stencil}.
Context `{make_program_ops: !MakeProgramOps Clight.function type Clight.fundef type}.
Context `{Hmake_program: !MakeProgram Clight.function type Clight.fundef type}.
Let L : compatlayer (cdata RData) :=
_measurement_finish ↦ gensem measurement_finish_spec
⊕ _set_rd_state ↦ gensem set_rd_state_spec
.
Local Instance: ExternalCallsOps mem := CompatExternalCalls.compatlayer_extcall_ops L.
Local Instance: CompilerConfigOps mem := CompatExternalCalls.compatlayer_compiler_config_ops L.
Section BodyProof.
Context `{Hwb: WritableBlockOps}.
Variable (sc: stencil).
Variables (ge: genv) (STENCIL_MATCHES: stencil_matches sc ge).
Variable b_measurement_finish: block.
Hypothesis h_measurement_finish_s : Genv.find_symbol ge _measurement_finish = Some b_measurement_finish.
Hypothesis h_measurement_finish_p : Genv.find_funct_ptr ge b_measurement_finish
= Some (External (EF_external _measurement_finish
(signature_of_type (Tcons Tptr Tnil) tvoid cc_default))
(Tcons Tptr Tnil) tvoid cc_default).
Local Opaque measurement_finish_spec.
Variable b_set_rd_state: block.
Hypothesis h_set_rd_state_s : Genv.find_symbol ge _set_rd_state = Some b_set_rd_state.
Hypothesis h_set_rd_state_p : Genv.find_funct_ptr ge b_set_rd_state
= Some (External (EF_external _set_rd_state
(signature_of_type (Tcons Tptr (Tcons tuint Tnil)) tvoid cc_default))
(Tcons Tptr (Tcons tuint Tnil)) tvoid cc_default).
Local Opaque set_rd_state_spec.
Lemma realm_activate_ops_body_correct:
forall m d d' env le rd_base rd_offset
(Henv: env = PTree.empty _)
(Hinv: high_level_invariant d)
(HPTrd: PTree.get _rd le = Some (Vptr rd_base (Int.repr rd_offset)))
(Hspec: realm_activate_ops_spec0 (rd_base, rd_offset) d = Some d'),
exists le', (exec_stmt ge env le ((m, d): mem) realm_activate_ops_body E0 le' (m, d') Out_normal).
Proof.
solve_code_proof Hspec realm_activate_ops_body; eexists; solve_proof_low.
Qed.
End BodyProof.
End CodeProof.