Clone or download
Fetching latest commit…
Cannot retrieve the latest commit at this time.
Type Name Latest commit message Commit time
Failed to load latest commit information.
c-refinement proof: relicense the c-refinement proofs under BSD Dec 16, 2018
cogent proof: relicense the core proofs under BSD Dec 16, 2018
impl proof: bilby proof work Dec 13, 2018
isa-parser compiler: deps := deps - {haskell-src-exts} (*) Nov 29, 2018
isabelle @ 5ea4195 proof: bump isabelle submodule and update README Nov 8, 2018
l4v @ 5e51fa0 proof: move to properly licensed l4v Dec 16, 2018
regression Initial Release May 1, 2016
z3 @ b79440a add z3 submodule May 7, 2018
.gitignore proof: actually add ML_Old and fix gitignore Aug 14, 2018
.gitmodules compiler: upstream packages are updated. remove local May 21, 2018
.regression-noclean add missing config file May 6, 2016
.travis.yml compiler: now support ghc-8.6.[12] Dec 9, 2018
BilbyFs_CorresProof.patch bilby: rename CorresProof patch and update README Nov 10, 2016 add contributing file Jun 19, 2016 [CI] Use travis on github for build and sanity. Jan 11, 2017
LICENSE_BSD2.txt fix corrupted LICENSE files May 3, 2016
LICENSE_GPLv2.txt fix corrupted LICENSE files May 3, 2016 proof: bump isabelle submodule and update README Nov 8, 2018 regression: lemma and travis cover most tests (minus huge proofs) Apr 3, 2017 regression: lemma and travis cover most tests (minus huge proofs) Apr 3, 2017 build: Update stack.yml and dependencies Feb 15, 2018
run_tests Initial Release May 1, 2016

Build Status

Cogent: Code and Proof Co-Generation

Project homepage

For general context of this project, motivation, an overview, and published papers, see our project homepage.


Instructions tested on Debian GNU/Linux 8.2 ("jessie") and Ubuntu 16.04 ("xenial"). May need to be adapted for other systems.

Install dependencies from the Debian repository.

sudo apt-get install git # git
sudo apt-get install python-lxml python-psutil python-pycparser # regression tester

To install the Cogent compiler, consult file cogent/ for details.

l4v, isabelle and z3 are submodules that the Cogent framework depends on. To get them: git submodule update --init --recursive.

If you already have them on your machine, you can use your local copies, by checking out the compatible revisions:

  • l4v: ecc84ffc6ead5a4d80aac7dabacf4b010c05dfca
  • isabelle: any Isabelle2018 revision
  • z3: see cogent/ for more information

Add isabelle/bin to your PATH: export PATH="$(pwd)/isabelle/bin:$PATH" If you have an existing Isabelle install, you may want to set ISABELLE_IDENTIFIER instead of PATH.

Initialise Isabelle and install components:

isabelle components -I
isabelle components -a

Consult Isabelle manual for more information.

For more customised settings to run proofs and regression tests, modify

Note: also see Proofs and Regression tests below.

Regression tests

Run build system and regression tests. (ETA: 2–3 CPU hours) This also builds the Cogent compiler and Isabelle theories. If this works, your install is probably ok. Run ./run_tests.

For C-refinement proofs, which are excluded from the regression tests because of their size, follow instructions in Proofs section.


To build the proofs, it is recommended that your machine (or virtual machine) provides 32G of memory and 4–8 CPU threads.

# Build compilation correctness proof for ext2. (ETA: 120 CPU hours)
(cd impl/fs/ext2/cogent;
 make verification;
 isabelle build -d plat/verification -d ../../../../cogent/isa -d ../../../../l4v -b Ext2_AllRefine)

# Build compilation correctness proof for BilbyFs. (ETA: 120 CPU hours)
(cd impl/fs/bilby/cogent;
 make verification;
 patch -d plat/verification < ../../../../BilbyFs_CorresProof.patch;
 isabelle build -d . -d ../../../../cogent/isa -d ../../../../l4v -b -o process_output_limit=999 BilbyFs_AllRefine)

# View end-to-end theorems. Each theory has a "print_theorems" command for this.
# For ext2:
isabelle jedit -d impl/ext2/cogent/plat/verification -d cogent/isa -d l4v -l Ext2_CorresProof impl/fs/ext2/cogent/plat/verification/Ext2_AllRefine.thy
# For BilbyFs:
isabelle jedit -d impl/fs/bilby/cogent/plat/verification -d cogent/isa -d l4v -l BilbyFs_CorresProof impl/fs/bilby/cogent/plat/verification/BilbyFs_AllRefine.thy

The functional correctness proofs for BilbyFs's sync and iget operations are in impl/fs/bilby/proof/. They are built as part of the regression tests, and can be rebuilt with

regression/ -x l4v -x isabelle -v sync iget

File systems

See impl/fs/ext2/README and impl/fs/bilby/README for more information on how to build the kernel modules


  • cogent: Cogent compiler
  • c-refinement: Isabelle/HOL theories and proof procedures for Cogent-C refinement
    • tests: Cogent test programs for proof procedures
  • isa-parser: Haskell library for parsing and pretty-printing Isabelle/HOL
  • impl: Systems implemented in Cogent
    • fs: File systems
      • bilby: Bilby file system
        • cogent: Cogent code for BilbyFs
        • c: C implementation for BilbyFs
        • proof: Functional correctness specs and proofs for BilbyFs
      • ext2: ext2 file system
        • cogent: Cogent code for ext2
  • regression: Regression test script