This release supports version 13 of mir-json's schema.
New Features
-
SAWScript now supports optional named arguments. These can be passed anywhere in a function application using the syntax
name=val. Ifvalrequires parentheses you can also enclose the name in the parentheses as well. The syntax in a type signature isname?type. The parameter syntax in a function declaration is eithername?=valorname@alt?=val, wherevalis the default value to use when the caller doesn't provide one. By default thenameis both the external call name and the internal variable name for the parameter. Ifaltis present, it can be an identifier or a pattern, and specifies a different name or names for internal use. The alternate name, or parts of it, can be set to_if unused. -
The builtin
str_concatsnow accepts an optional argumentsepto use as a separator between the given strings. For example,str_concats ["a", "b"]will produce"ab"as before, butstr_concats sep=", " ["a", "b"]produces"a, b". -
The SAWScript typechecker will now (sometimes, at least) guess when you forgot a semicolon.
-
The new
subproofbuiltin is similar to "bullets" in Rocq: When there are multiple remaining proof goals, it runs the given inner proof script on the first goal alone, and then checks that the inner script completely proves the goal. -
The SAW proof commands
proveandprove_printnow accept SAWCore terms of typeProp, in addition to predicates returningBool. Previously this required a special proof commandprove_extcore, which is now deprecated in favor ofprove_print. -
The REPL once again accepts pure expressions as well as monadic statements. These are not accepted in monadic contexts in SAWScript files, as should be the case. (That was not, however, the historic behavior.)
-
SAW now includes
map : {a, b} (a -> b) -> [a] -> [b]as a primitive. -
Add new SAWScript commands
timeout_handleandtimeoutfor adding time limits to scripts. -
Add new SAWScript MIR commands
mir_field_valueandmir_field_reffor accessing fields of structs by value and by reference. -
Added the
:llvmdisREPL command. When in the REPL and working with anLLVMModule, this allows examination of the text form of theLLVMModulebitcode. The requested output can be either: (1) a function, (2) the LLVM corresponding to a source file and source line number, or (3) the unnamed Metadata at the requested index. -
Add basic support for Cryptol
Rationalvalues in SAWCore. -
Add support for derived Cryptol instances in SAWCore.
-
Added
llvm_alloc_all_globals,llvm_alloc_constant_globalsandllvm_alloc_no_globalsto determine the automatic allocation globals. Previously, only constant globals were allocated by default. The globals allocation occurs before theLLVMSetupoperation forllvm_verify, so the global allocation disposition must be set as aTopLeveloperation. -
Add
mir_set_exception_context_{none,limited,no_limit}, which configures how much call-stack-related context to include when displaying MIR-related exceptions. The default setting ismir_set_exception_context_limited 10(i.e., 10 call stack frames).
Bug Fixes
-
include_onceno longer gets confused by different../dir/file.sawpathnames starting from different directories. -
The SAWScript typechecker no longer allows
_ <- eas the last statement in a block. Use the plain expression instead. -
The Rocq exporter now generates more or less normal width output instead of cramming everything onto one very long line.
-
Fix bug in the
rmesolver causing the<operator to be treated as<=. -
Avoid exponential blow-up when generating uninterpreted functions.
-
SAW no longer spuriously rejects
mir_array_values that use a signed integer type (e.g.,mir_i32) as an element type. -
Using a fractional Cryptol literal (e.g.,
0.5 : Rational) no longer causes SAW to emit a type error. -
Don't raise spurious type errors when importing Cryptol record or tuple update expressions.
-
Don't raise spurious type errors when importing Cryptol
caseexpressions whose scrutinee types have sophisticated numeric types. -
Fix a panic when importing Cryptol list patterns (e.g.,
(x, y) where [x, y] = [0x1, 0x2]). -
LLVM module importing now supports
DISubrangeType(metadata ID 48) andDIFixedPointType(metadata ID 49) elements. -
SAW no longer panics when defining Cryptol functions using numeric constraint guards in
let {{ ... }}blocks. -
Fix a bug that would cause the
offline_w4_unint_yicesproof script to always throw an error.
Deprecations
-
As noted above,
prove_extcoreis deprecated in favor of just usingprove_print. -
add_prelude_eqsandadd_cryptol_eqsare now deprecated; useadd_core_thmsinstead. -
The
assume_unsatbuiltin has been deprecated, after five years' notice that this was coming. Useadmitinstead. -
The old type names
CrucibleSetupandCrucibleMethodSpechave been deprecated and will now cause warnings. UseLLVMSetupandLLVMSpecinstead respectively.CrucibleSetupremains a reserved word, and will likely remain one until it is finally removed. -
The (less old) name
SetupValueis deprecated and will now cause warnings. USeLLVMValueinstead. -
The deprecated CVC4 builtins are now hidden by default. Use CVC5. Boolector remains for now.
-
The old
crucible_*names that have long been changed tollvm_*names are now hidden by default, except for the ones that never made it pastexperimentaland were already hidden by default; those have now been removed. Exception:crucible_verify_llvm_x86was left off the original deprecation list and is now hidden by default. -
llvm_declare_ghost_stateandcrucible_declare_ghost_state, which are old names fordeclare_ghost_state, are now hidden by default. -
The following other deprecated items are also now hidden by default:
- The
coq-based names for the Rocq exporter. Use therocqversions instead. external_aig_solver(old name forarbitrary_aig)external_cnf_solver(old name forarbitrary_cnf)w4_offline_smtlib2(old name foroffline_w4_smtlib2)
- The
-
The deprecated
envbuiltin has been removed. Use the:envREPL command instead.
Other changes
-
The REPL no longer prints result values you explicitly throw away with
_ <-. -
The way the
:searchREPL command matches function types has been adjusted. It should be more predictable and more useful now. Feedback is welcome. -
crux-mir-comphas been unbundled from the SAW release distribution in preparation for creating a standalone Crux release.