Skip to content

SMT2: tolerate non-constant array indices when parsing array models - #9063

Merged
tautschnig merged 1 commit into
developfrom
strata/smt2-array-model-nonconst-index
Jul 28, 2026
Merged

SMT2: tolerate non-constant array indices when parsing array models#9063
tautschnig merged 1 commit into
developfrom
strata/smt2-array-model-nonconst-index

Conversation

@tautschnig

@tautschnig tautschnig commented Jun 18, 2026

Copy link
Copy Markdown
Collaborator

smt2_convt::walk_array_tree assumes every (store array index value) term in a solver-returned array model has a constant index, calling to_constant_expr on it unconditionally. Models for unbounded or non-integer-keyed arrays can contain a non-constant index, which trips the to_constant_expr precondition. Skip such store entries during model reconstruction instead of aborting.

  • Each commit message has a non-empty body, explaining why the change was made.
  • n/a Methods or procedures I have added are documented, following the guidelines provided in CODING_STANDARD.md.
  • n/a The feature or user visible behaviour I have added or modified has been documented in the User Guide in doc/cprover-manual/
  • Regression or unit tests are included, or existing tests cover the modified code (in this case I have detailed which ones those are in the commit message).
  • n/a My commit message includes data points confirming performance improvements (if claimed).
  • My PR is restricted to a single feature or bugfix.
  • n/a White-space or formatting changes outside the feature-related changed lines are in commits of their own.

@tautschnig tautschnig self-assigned this Jun 18, 2026
Copilot AI review requested due to automatic review settings June 18, 2026 20:01

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Note

Copilot was unable to run its full agentic suite in this review.

Updates SMT2 array model parsing to avoid aborting when encountering store terms with non-constant indices, instead skipping those entries during model reconstruction.

Changes:

  • Detect non-constant store indices during walk_array_tree and skip processing those stores
  • Prevent to_constant_expr precondition violations caused by solver-returned models containing symbolic indices

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment thread src/solvers/smt2/smt2_conv.cpp
Comment thread src/solvers/smt2/smt2_conv.cpp
@codecov

codecov Bot commented Jun 19, 2026

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 96.87500% with 1 line in your changes missing coverage. Please review.
✅ Project coverage is 80.83%. Comparing base (f71fdad) to head (743eb66).
⚠️ Report is 2 commits behind head on develop.

Files with missing lines Patch % Lines
unit/solvers/smt2/smt2_conv.cpp 96.77% 1 Missing ⚠️
Additional details and impacted files
@@           Coverage Diff            @@
##           develop    #9063   +/-   ##
========================================
  Coverage    80.83%   80.83%           
========================================
  Files         1715     1715           
  Lines       189948   189989   +41     
  Branches        73       73           
========================================
+ Hits        153540   153577   +37     
- Misses       36408    36412    +4     

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@tautschnig
tautschnig force-pushed the strata/smt2-array-model-nonconst-index branch from 4cb733b to 69cf780 Compare June 24, 2026 15:42
@tautschnig tautschnig assigned kroening and unassigned tautschnig Jun 24, 2026
@kroening kroening assigned tautschnig and unassigned kroening Jul 6, 2026
@tautschnig
tautschnig force-pushed the strata/smt2-array-model-nonconst-index branch from 69cf780 to 68e69c0 Compare July 28, 2026 13:35
smt2_convt::walk_array_tree assumes every (store array index value) term in
a solver-returned array model has a constant index, calling to_constant_expr
on it unconditionally. Models for unbounded or non-integer-keyed arrays can
contain a non-constant index, which trips the to_constant_expr precondition.
Skip such store entries during model reconstruction instead of aborting.

Add a unit test that drives walk_array_tree directly (via a subclass exposing
the protected method) with a store term whose index is a plain symbol, and
asserts that reconstruction does not abort and drops only the offending entry
while keeping the well-formed default. The test puts invariants into throwing
mode (cbmc_invariants_should_throwt) so that, without the guard, the
to_constant_expr precondition surfaces as a clean test failure rather than
aborting the unit binary.

Note on test shape: parse_rec dispatches on the index type (the array's size
type) and coerces arithmetic types to constants, so a non-constant index can
only be produced by a non-arithmetic index type (which parses to a nil
expression). Such a type is not integer-convertible, so a surviving
constant-integer-indexed store cannot coexist with a dropped non-constant one
in the same model at the irept level; the preserved well-formed entry in the
test is therefore the (as const ...) default, which is collected without going
through index parsing.

The extern6 test declares 'extern int stuff[]' -- an unbounded array whose
SMT array model carries a non-constant store index. Model reconstruction in
smt2_convt::walk_array_tree previously aborted on the to_constant_expr
precondition, which is why the test was tagged broken-smt-backend. With the
non-constant-index guard in place, cbmc --cprover-smt2 (and --smt2 with Z3)
now produces the expected VERIFICATION FAILED / EXIT=10, so the tag no longer
applies; the KNOWNBUG CI job rightly flags the test as fixed. The no-new-smt
tag is retained: the incremental SMT2 backend takes a different code path and
still aborts on this test.

Co-authored-by: Kiro <kiro-agent@users.noreply.github.com>
@tautschnig
tautschnig force-pushed the strata/smt2-array-model-nonconst-index branch from 68e69c0 to 743eb66 Compare July 28, 2026 17:13
@tautschnig
tautschnig merged commit a777c7b into develop Jul 28, 2026
44 checks passed
@tautschnig
tautschnig deleted the strata/smt2-array-model-nonconst-index branch July 28, 2026 19:27
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants