-
Notifications
You must be signed in to change notification settings - Fork 1.9k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
kani: fix infinite loop unwinding in dumbo harnesses #5083
Merged
roypat
merged 4 commits into
firecracker-microvm:main
from
roypat:kani-deprecation-cleanup
Mar 13, 2025
Merged
kani: fix infinite loop unwinding in dumbo harnesses #5083
roypat
merged 4 commits into
firecracker-microvm:main
from
roypat:kani-deprecation-cleanup
Mar 13, 2025
Conversation
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
--enable-unstable and --restrict-vtable got deprecated in kani 0.59.0 in favor of variants based on -Z flags. So use the -Z flags instead Signed-off-by: Patrick Roy <roypat@amazon.co.uk>
rebuilding the docker container can upgrade kani, and we'd like to know at the PR stage if that causes issues (such as timeouts). Signed-off-by: Patrick Roy <roypat@amazon.co.uk>
Codecov ReportAll modified and coverable lines are covered by tests ✅
Additional details and impacted files@@ Coverage Diff @@
## main #5083 +/- ##
==========================================
- Coverage 83.15% 83.15% -0.01%
==========================================
Files 248 248
Lines 26901 26896 -5
==========================================
- Hits 22370 22365 -5
Misses 4531 4531
Flags with carried forward coverage won't be shown. Click here to find out more. ☔ View full report in Codecov by Sentry. 🚀 New features to boost your workflow:
|
Manciukic
reviewed
Mar 13, 2025
00fd35c
to
275003a
Compare
JackThomson2
previously approved these changes
Mar 13, 2025
Instead of copying the buffers byte-by-byte in a loop, just use copy_from_slice, which compiles to a memcpy. While we're at it, drop some unused function definitions. Also remove the special snowflake functions for dealing with i8 slices, and instead just use zerocopy to safely transmute these into u8 slices, on which the normal functions work. Signed-off-by: Patrick Roy <roypat@amazon.co.uk>
with the byte_order modules no longer using loops, this is no longer needed. Signed-off-by: Patrick Roy <roypat@amazon.co.uk>
275003a
to
b606d1b
Compare
Manciukic
approved these changes
Mar 13, 2025
JackThomson2
approved these changes
Mar 13, 2025
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Since 0.58.0 kani gets stuck unwinding loops in the dumbo proofs. The exact loops were the ones in the
byte_order
module. We've previously seen this with a subset of thebyte_order
functions, which is why some of them were already stubbed out in kani. However, instead of just doing more stubbing, let's just eliminate the loops. The were just a handrolled memcpy (the reason we need these convoluted byte_order functions in the first place is that the stdlib functions cannot deal with buffers that are "too small", while we for some reason want to support that).Signed-off-by: Patrick Roy roypat@amazon.co.uk## Changes
...
Reason
...
License Acceptance
By submitting this pull request, I confirm that my contribution is made under
the terms of the Apache 2.0 license. For more information on following Developer
Certificate of Origin and signing off your commits, please check
CONTRIBUTING.md
.PR Checklist
tools/devtool checkstyle
to verify that the PR passes theautomated style checks.
how they are solving the problem in a clear and encompassing way.
in the PR.
CHANGELOG.md
.Runbook for Firecracker API changes.
integration tests.
TODO
.rust-vmm
.