fc_libc.1.res.oracle 246 KB
Newer Older
1 2 3
[kernel] Parsing tests/libc/fc_libc.c (with preprocessing)
/* Generated by Frama-C */
typedef unsigned int size_t;
4
struct __fc_fenv_t {
5 6 7 8 9 10 11 12 13 14 15 16 17 18
   unsigned short __control_word ;
   unsigned short __unused1 ;
   unsigned short __status_word ;
   unsigned short __unused2 ;
   unsigned short __tags ;
   unsigned short __unused3 ;
   unsigned int __eip ;
   unsigned short __cs_selector ;
   unsigned int __opcode : 11 ;
   unsigned int __unused4 : 5 ;
   unsigned int __data_offset ;
   unsigned short __data_selector ;
   unsigned short __unused5 ;
};
19
typedef struct __fc_fenv_t fenv_t;
Andre Maroneze's avatar
Andre Maroneze committed
20 21 22 23 24 25 26
typedef int wchar_t;
typedef int ssize_t;
typedef unsigned int gid_t;
typedef unsigned int uid_t;
typedef long off_t;
typedef int pid_t;
typedef unsigned int useconds_t;
27 28 29 30 31 32
struct option {
   char const *name ;
   int has_arg ;
   int *flag ;
   int val ;
};
33
struct __fc_glob_t {
34 35 36 37 38 39 40
   unsigned int gl_pathc ;
   char **gl_pathv ;
   unsigned int gl_offs ;
   int gl_flags ;
   void (*gl_closedir)(void *) ;
   void *(*gl_readdir)(void *) ;
   void *(*gl_opendir)(char const *) ;
41 42
   int (*gl_lstat)(char const * __restrict , void * __restrict ) ;
   int (*gl_stat)(char const * __restrict , void * __restrict ) ;
43
};
44
typedef struct __fc_glob_t glob_t;
45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62
struct __fc_div_t {
   int quot ;
   int rem ;
};
typedef struct __fc_div_t div_t;
struct __fc_ldiv_t {
   long quot ;
   long rem ;
};
typedef struct __fc_ldiv_t ldiv_t;
struct __fc_lldiv_t {
   long long quot ;
   long long rem ;
};
typedef struct __fc_lldiv_t lldiv_t;
typedef unsigned char uint8_t;
typedef unsigned short uint16_t;
typedef unsigned int uint32_t;
63
typedef unsigned int uintptr_t;
64
typedef long long intmax_t;
65
struct __fc_imaxdiv_t {
66 67 68
   intmax_t quot ;
   intmax_t rem ;
};
69
typedef struct __fc_imaxdiv_t imaxdiv_t;
70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95
struct lconv {
   char *decimal_point ;
   char *thousands_sep ;
   char *grouping ;
   char *int_curr_symbol ;
   char *currency_symbol ;
   char *mon_decimal_point ;
   char *mon_thousands_sep ;
   char *mon_grouping ;
   char *positive_sign ;
   char *negative_sign ;
   char int_frac_digits ;
   char frac_digits ;
   char p_cs_precedes ;
   char p_sep_by_space ;
   char n_cs_precedes ;
   char n_sep_by_space ;
   char p_sign_posn ;
   char n_sign_posn ;
   char int_p_cs_precedes ;
   char int_p_sep_by_space ;
   char int_n_cs_precedes ;
   char int_n_sep_by_space ;
   char int_p_sign_posn ;
   char int_n_sign_posn ;
};
96
union __fc_u_finitef {
97 98 99
   float f ;
   unsigned short w[2] ;
};
100
union __fc_u_finite {
101 102 103
   double d ;
   unsigned short w[4] ;
};
104
struct __fc_pthread_attr_t {
105 106
   int _fc ;
};
107 108
typedef struct __fc_pthread_attr_t pthread_attr_t;
struct __fc_pthread_cond_t {
109 110
   int _fc ;
};
111 112
typedef struct __fc_pthread_cond_t pthread_cond_t;
struct __fc_pthread_condattr_t {
113 114
   int _fc ;
};
115 116
typedef struct __fc_pthread_condattr_t pthread_condattr_t;
struct __fc_pthread_mutex_t {
117 118
   int _fc ;
};
119 120
typedef struct __fc_pthread_mutex_t pthread_mutex_t;
struct __fc_pthread_mutexattr_t {
121 122
   int _fc ;
};
123 124
typedef struct __fc_pthread_mutexattr_t pthread_mutexattr_t;
struct __fc_pthread_t {
125 126
   int _fc ;
};
127
typedef struct __fc_pthread_t pthread_t;
128
typedef unsigned long sigset_t;
Andre Maroneze's avatar
Andre Maroneze committed
129 130 131 132
union sigval {
   int sival_int ;
   void *sival_ptr ;
};
133
struct __fc_siginfo_t {
Andre Maroneze's avatar
Andre Maroneze committed
134 135 136 137 138 139 140 141 142 143
   int si_signo ;
   int si_code ;
   union sigval si_value ;
   int si_errno ;
   pid_t si_pid ;
   uid_t si_uid ;
   void *si_addr ;
   int si_status ;
   int si_band ;
};
144
typedef struct __fc_siginfo_t siginfo_t;
Andre Maroneze's avatar
Andre Maroneze committed
145 146 147 148 149 150
struct sigaction {
   void (*sa_handler)(int ) ;
   void (*sa_sigaction)(int , siginfo_t *, void *) ;
   sigset_t sa_mask ;
   int sa_flags ;
};
151 152 153 154 155 156 157 158 159 160 161 162 163 164 165 166 167 168 169 170 171 172 173 174 175 176 177 178 179
typedef unsigned int socklen_t;
typedef unsigned short sa_family_t;
struct sockaddr {
   sa_family_t sa_family ;
   char sa_data[14] ;
};
struct iovec {
   void *iov_base ;
   size_t iov_len ;
};
struct msghdr {
   void *msg_name ;
   socklen_t msg_namelen ;
   struct iovec *msg_iov ;
   int msg_iovlen ;
   void *msg_control ;
   socklen_t msg_controllen ;
   int msg_flags ;
};
struct __fc_sockfds_type {
   int x ;
};
typedef uint32_t in_addr_t;
struct in_addr {
   in_addr_t s_addr ;
};
struct in6_addr {
   uint8_t s6_addr[16] ;
};
180
enum __fc_ipproto {
181 182 183 184 185 186 187 188 189 190 191 192 193 194 195 196 197 198 199 200 201 202 203 204 205 206 207 208 209 210 211
    IPPROTO_IP = 0,
    IPPROTO_HOPOPTS = 0,
    IPPROTO_ICMP = 1,
    IPPROTO_IGMP = 2,
    IPPROTO_IPIP = 4,
    IPPROTO_TCP = 6,
    IPPROTO_EGP = 8,
    IPPROTO_PUP = 12,
    IPPROTO_UDP = 17,
    IPPROTO_IDP = 22,
    IPPROTO_TP = 29,
    IPPROTO_DCCP = 33,
    IPPROTO_IPV6 = 41,
    IPPROTO_ROUTING = 43,
    IPPROTO_FRAGMENT = 44,
    IPPROTO_RSVP = 46,
    IPPROTO_GRE = 47,
    IPPROTO_ESP = 50,
    IPPROTO_AH = 51,
    IPPROTO_ICMPV6 = 58,
    IPPROTO_NONE = 59,
    IPPROTO_DSTOPTS = 60,
    IPPROTO_MTP = 92,
    IPPROTO_ENCAP = 98,
    IPPROTO_PIM = 103,
    IPPROTO_COMP = 108,
    IPPROTO_SCTP = 132,
    IPPROTO_UDPLITE = 136,
    IPPROTO_RAW = 255,
    IPPROTO_MAX = 256
};
212 213 214 215 216 217 218
struct hostent {
   char *h_name ;
   char **h_aliases ;
   int h_addrtype ;
   int h_length ;
   char **h_addr_list ;
};
219 220 221 222 223 224 225 226 227 228
struct addrinfo {
   int ai_flags ;
   int ai_family ;
   int ai_socktype ;
   int ai_protocol ;
   socklen_t ai_addrlen ;
   struct sockaddr *ai_addr ;
   char *ai_canonname ;
   struct addrinfo *ai_next ;
};
229 230 231 232 233 234 235
struct __fc_gethostbyname {
   struct hostent host ;
   unsigned char host_addr[sizeof(struct in_addr)] ;
   char *h_addr_ptrs[2 + 1] ;
   char *host_aliases[2] ;
   char hostbuf[128] ;
};
236 237 238 239 240 241 242 243 244 245 246 247 248 249 250 251 252 253 254 255 256 257 258 259 260 261 262 263 264 265 266 267 268 269 270 271 272 273 274 275 276 277 278 279 280 281 282 283 284 285 286 287 288 289 290 291 292 293 294 295 296 297 298 299 300
typedef void * const * va_list;
typedef unsigned int ino_t;
typedef long time_t;
typedef unsigned int blkcnt_t;
typedef unsigned int blksize_t;
typedef unsigned int dev_t;
typedef unsigned int mode_t;
typedef unsigned int nlink_t;
struct stat {
   dev_t st_dev ;
   ino_t st_ino ;
   mode_t st_mode ;
   nlink_t st_nlink ;
   uid_t st_uid ;
   gid_t st_gid ;
   dev_t st_rdev ;
   off_t st_size ;
   time_t st_atime ;
   time_t st_mtime ;
   time_t st_ctime ;
   blksize_t st_blksize ;
   blkcnt_t st_blocks ;
};
struct __fc_pos_t {
   unsigned long __fc_stdio_position ;
};
typedef struct __fc_pos_t fpos_t;
struct __fc_FILE {
   unsigned int __fc_FILE_id ;
   unsigned int __fc_FILE_data ;
};
typedef struct __fc_FILE FILE;
typedef unsigned int id_t;
typedef int suseconds_t;
typedef int clockid_t;
typedef unsigned int clock_t;
struct tm {
   int tm_sec ;
   int tm_min ;
   int tm_hour ;
   int tm_mday ;
   int tm_mon ;
   int tm_year ;
   int tm_wday ;
   int tm_yday ;
   int tm_isdst ;
};
struct timespec {
   long tv_sec ;
   long tv_nsec ;
};
struct dirent {
   ino_t d_ino ;
   off_t d_off ;
   unsigned short d_reclen ;
   unsigned char d_type ;
   char d_name[256] ;
};
struct DIR {
   unsigned int __fc_dir_id ;
   unsigned int __fc_dir_position ;
   struct stat *__fc_dir_inode ;
   struct dirent **__fc_dir_entries ;
};
typedef struct DIR DIR;
301
struct __fc_fd_set {
302
   long __fc_fd_set[(unsigned int)1024 / ((unsigned int)8 * sizeof(long))] ;
303
};
304
typedef struct __fc_fd_set fd_set;
305 306 307 308 309 310 311 312 313 314 315 316 317 318 319 320 321 322 323 324 325 326 327 328 329 330 331 332 333 334 335
struct flock {
   short l_type ;
   short l_whence ;
   off_t l_start ;
   off_t l_len ;
   pid_t l_pid ;
};
struct timeval {
   time_t tv_sec ;
   suseconds_t tv_usec ;
};
struct timezone {
   int tz_minuteswest ;
   int tz_dsttime ;
};
struct itimerval {
   struct timeval it_interval ;
   struct timeval it_value ;
};
typedef void * iconv_t;
struct pollfd {
   int fd ;
   short events ;
   short revents ;
};
typedef unsigned long nfds_t;
struct passwd {
   char *pw_name ;
   char *pw_passwd ;
   uid_t pw_uid ;
   gid_t pw_gid ;
336
   char *pw_gecos ;
337 338 339 340
   char *pw_dir ;
   char *pw_shell ;
};
typedef int ( jmp_buf)[5];
341
struct __fc_sigjmp_buf {
342 343 344
   jmp_buf buf ;
   sigset_t sigs ;
};
345
typedef struct __fc_sigjmp_buf sigjmp_buf;
Andre Maroneze's avatar
Andre Maroneze committed
346
struct __fc_code {
347 348 349
   char const *c_name ;
   int c_val ;
};
Andre Maroneze's avatar
Andre Maroneze committed
350
typedef struct __fc_code CODE;
351 352 353 354 355 356 357 358 359 360 361 362 363 364 365 366 367 368 369 370 371 372 373 374 375 376
typedef unsigned long rlim_t;
struct rlimit {
   rlim_t rlim_cur ;
   rlim_t rlim_max ;
};
struct rusage {
   struct timeval ru_utime ;
   struct timeval ru_stime ;
};
struct tms {
   clock_t tms_utime ;
   clock_t tms_stime ;
   clock_t tms_cutime ;
   clock_t tms_cstime ;
};
typedef unsigned int tcflag_t;
typedef unsigned char cc_t;
struct termios {
   tcflag_t c_iflag ;
   tcflag_t c_oflag ;
   tcflag_t c_cflag ;
   tcflag_t c_lflag ;
   cc_t c_cc[32] ;
};
int volatile Frama_C_entropy_source __attribute__((__unused__,
                                                   __FRAMA_C_MODEL__));
377
void Frama_C_make_unknown(char *p, size_t l);
378 379 380 381 382 383 384 385 386 387 388 389 390 391 392 393 394 395 396 397 398 399 400 401

int Frama_C_nondet(int a, int b);

void *Frama_C_nondet_ptr(void *a, void *b);

int Frama_C_interval(int min, int max);

/*@ requires order: min ≤ max;
    ensures result_bounded: \old(min) ≤ \result ≤ \old(max);
    assigns \result, Frama_C_entropy_source;
    assigns \result \from min, max, Frama_C_entropy_source;
    assigns Frama_C_entropy_source \from Frama_C_entropy_source;
 */
extern int Frama_C_interval_split(int min, int max);

/*@ requires order: min ≤ max;
    ensures result_bounded: \old(min) ≤ \result ≤ \old(max);
    assigns \result, Frama_C_entropy_source;
    assigns \result \from min, max, Frama_C_entropy_source;
    assigns Frama_C_entropy_source \from Frama_C_entropy_source;
 */
extern unsigned char Frama_C_unsigned_char_interval(unsigned char min,
                                                    unsigned char max);

402
char Frama_C_char_interval(char min, char max);
403 404 405 406 407 408 409 410 411 412 413 414 415 416 417 418 419 420 421 422 423 424 425 426 427 428 429 430 431 432 433 434 435 436 437 438 439 440 441 442 443 444 445 446 447 448 449 450 451 452 453 454 455 456 457 458 459 460 461 462 463 464 465 466 467 468 469 470 471 472 473 474 475 476 477 478 479 480 481 482 483 484 485 486 487 488 489 490 491 492 493 494

/*@ requires order: min ≤ max;
    ensures result_bounded: \old(min) ≤ \result ≤ \old(max);
    assigns \result, Frama_C_entropy_source;
    assigns \result \from min, max, Frama_C_entropy_source;
    assigns Frama_C_entropy_source \from Frama_C_entropy_source;
 */
extern unsigned short Frama_C_unsigned_short_interval(unsigned short min,
                                                      unsigned short max);

/*@ requires order: min ≤ max;
    ensures result_bounded: \old(min) ≤ \result ≤ \old(max);
    assigns \result, Frama_C_entropy_source;
    assigns \result \from min, max, Frama_C_entropy_source;
    assigns Frama_C_entropy_source \from Frama_C_entropy_source;
 */
extern short Frama_C_short_interval(short min, short max);

/*@ requires order: min ≤ max;
    ensures result_bounded: \old(min) ≤ \result ≤ \old(max);
    assigns \result, Frama_C_entropy_source;
    assigns \result \from min, max, Frama_C_entropy_source;
    assigns Frama_C_entropy_source \from Frama_C_entropy_source;
 */
extern unsigned int Frama_C_unsigned_int_interval(unsigned int min,
                                                  unsigned int max);

/*@ requires order: min ≤ max;
    ensures result_bounded: \old(min) ≤ \result ≤ \old(max);
    assigns \result, Frama_C_entropy_source;
    assigns \result \from min, max, Frama_C_entropy_source;
    assigns Frama_C_entropy_source \from Frama_C_entropy_source;
 */
extern int Frama_C_int_interval(int min, int max);

/*@ requires order: min ≤ max;
    ensures result_bounded: \old(min) ≤ \result ≤ \old(max);
    assigns \result, Frama_C_entropy_source;
    assigns \result \from min, max, Frama_C_entropy_source;
    assigns Frama_C_entropy_source \from Frama_C_entropy_source;
 */
extern unsigned long Frama_C_unsigned_long_interval(unsigned long min,
                                                    unsigned long max);

/*@ requires order: min ≤ max;
    ensures result_bounded: \old(min) ≤ \result ≤ \old(max);
    assigns \result, Frama_C_entropy_source;
    assigns \result \from min, max, Frama_C_entropy_source;
    assigns Frama_C_entropy_source \from Frama_C_entropy_source;
 */
extern long Frama_C_long_interval(long min, long max);

/*@ requires order: min ≤ max;
    ensures result_bounded: \old(min) ≤ \result ≤ \old(max);
    assigns \result, Frama_C_entropy_source;
    assigns \result \from min, max, Frama_C_entropy_source;
    assigns Frama_C_entropy_source \from Frama_C_entropy_source;
 */
extern unsigned long long Frama_C_unsigned_long_long_interval(unsigned long long min,
                                                              unsigned long long max);

/*@ requires order: min ≤ max;
    ensures result_bounded: \old(min) ≤ \result ≤ \old(max);
    assigns \result, Frama_C_entropy_source;
    assigns \result \from min, max, Frama_C_entropy_source;
    assigns Frama_C_entropy_source \from Frama_C_entropy_source;
 */
extern long long Frama_C_long_long_interval(long long min, long long max);

/*@ requires order: min ≤ max;
    ensures result_bounded: \old(min) ≤ \result ≤ \old(max);
    assigns \result, Frama_C_entropy_source;
    assigns \result \from min, max, Frama_C_entropy_source;
    assigns Frama_C_entropy_source \from Frama_C_entropy_source;
 */
extern size_t Frama_C_size_t_interval(size_t min, size_t max);

float Frama_C_float_interval(float min, float max);

double Frama_C_double_interval(double min, double max);

/*@ requires finite: \is_finite(min) ∧ \is_finite(max);
    requires order: min ≤ max;
    ensures
      result_bounded:
        \is_finite(\result) ∧ \old(min) ≤ \result ≤ \old(max);
    assigns \result, Frama_C_entropy_source;
    assigns \result \from min, max, Frama_C_entropy_source;
    assigns Frama_C_entropy_source \from Frama_C_entropy_source;
 */
extern double Frama_C_real_interval_as_double(double min, double max);

495
 __attribute__((__noreturn__)) void Frama_C_abort(void);
496 497 498 499 500 501 502 503 504 505 506 507 508 509 510 511 512

/*@ assigns \result;
    assigns \result \from p; */
extern size_t Frama_C_offset(void const *p);

/*@ assigns \result;
    assigns \result \from i; */
extern long long Frama_C_abstract_cardinal(long long i);

/*@ assigns \result;
    assigns \result \from i; */
extern long long Frama_C_abstract_max(long long i);

/*@ assigns \result;
    assigns \result \from i; */
extern long long Frama_C_abstract_min(long long i);

513 514 515 516 517 518 519 520 521 522 523 524 525 526 527 528 529 530 531 532 533 534 535 536 537 538 539 540 541 542 543 544 545 546 547 548 549 550 551 552 553 554 555 556 557 558 559 560 561 562 563 564 565 566 567 568 569 570 571 572 573 574 575 576 577 578 579 580 581 582 583 584 585 586 587 588 589 590 591 592 593 594 595 596 597 598 599 600 601 602 603 604 605 606 607 608 609 610 611 612 613 614 615 616 617 618 619 620 621 622 623 624 625 626 627 628 629 630 631 632 633 634 635 636 637 638 639 640 641 642 643 644 645 646 647 648 649 650
/*@ assigns Frama_C_entropy_source;
    assigns Frama_C_entropy_source \from Frama_C_entropy_source;
 */
void Frama_C_update_entropy(void)
{
  Frama_C_entropy_source = Frama_C_entropy_source;
  return;
}

/*@ requires valid_p: \valid(p + (0 .. l - 1));
    ensures initialization: \initialized(\old(p) + (0 .. \old(l) - 1));
    assigns *(p + (0 .. l - 1)), Frama_C_entropy_source;
    assigns *(p + (0 .. l - 1)) \from Frama_C_entropy_source;
    assigns Frama_C_entropy_source \from Frama_C_entropy_source;
 */
void Frama_C_make_unknown(char *p, size_t l)
{
  Frama_C_update_entropy();
  {
    size_t i = (unsigned int)0;
    while (i < l) {
      *(p + i) = (char)Frama_C_entropy_source;
      i += (size_t)1;
    }
  }
  return;
}

/*@ ensures result_a_or_b: \result ≡ \old(a) ∨ \result ≡ \old(b);
    assigns \result, Frama_C_entropy_source;
    assigns \result \from a, b, Frama_C_entropy_source;
    assigns Frama_C_entropy_source \from Frama_C_entropy_source;
 */
int Frama_C_nondet(int a, int b)
{
  int tmp;
  Frama_C_update_entropy();
  if (Frama_C_entropy_source) tmp = a; else tmp = b;
  return tmp;
}

/*@ ensures result_a_or_b: \result ≡ \old(a) ∨ \result ≡ \old(b);
    assigns \result, Frama_C_entropy_source;
    assigns \result \from a, b, Frama_C_entropy_source;
    assigns Frama_C_entropy_source \from Frama_C_entropy_source;
 */
void *Frama_C_nondet_ptr(void *a, void *b)
{
  void *tmp;
  Frama_C_update_entropy();
  if (Frama_C_entropy_source) tmp = a; else tmp = b;
  return tmp;
}

/*@ requires order: min ≤ max;
    ensures result_bounded: \old(min) ≤ \result ≤ \old(max);
    assigns \result, Frama_C_entropy_source;
    assigns \result \from min, max, Frama_C_entropy_source;
    assigns Frama_C_entropy_source \from Frama_C_entropy_source;
 */
int Frama_C_interval(int min, int max)
{
  int r;
  int aux;
  Frama_C_update_entropy();
  aux = Frama_C_entropy_source;
  if (aux >= min) 
    if (aux <= max) r = aux; else r = min;
  else r = min;
  return r;
}

/*@ requires order: min ≤ max;
    ensures result_bounded: \old(min) ≤ \result ≤ \old(max);
    assigns \result, Frama_C_entropy_source;
    assigns \result \from min, max, Frama_C_entropy_source;
    assigns Frama_C_entropy_source \from Frama_C_entropy_source;
 */
char Frama_C_char_interval(char min, char max)
{
  char __retres;
  int r;
  char aux;
  Frama_C_update_entropy();
  aux = (char)Frama_C_entropy_source;
  if ((int)aux >= (int)min) 
    if ((int)aux <= (int)max) r = (int)aux; else r = (int)min;
  else r = (int)min;
  __retres = (char)r;
  return __retres;
}

/*@ requires finite: \is_finite(min) ∧ \is_finite(max);
    requires order: min ≤ max;
    ensures
      result_bounded:
        \is_finite(\result) ∧ \old(min) ≤ \result ≤ \old(max);
    assigns \result, Frama_C_entropy_source;
    assigns \result \from min, max, Frama_C_entropy_source;
    assigns Frama_C_entropy_source \from Frama_C_entropy_source;
 */
float Frama_C_float_interval(float min, float max)
{
  float tmp;
  Frama_C_update_entropy();
  if (Frama_C_entropy_source) tmp = min; else tmp = max;
  return tmp;
}

/*@ requires finite: \is_finite(min) ∧ \is_finite(max);
    requires order: min ≤ max;
    ensures
      result_bounded:
        \is_finite(\result) ∧ \old(min) ≤ \result ≤ \old(max);
    assigns \result, Frama_C_entropy_source;
    assigns \result \from min, max, Frama_C_entropy_source;
    assigns Frama_C_entropy_source \from Frama_C_entropy_source;
 */
double Frama_C_double_interval(double min, double max)
{
  double tmp;
  Frama_C_update_entropy();
  if (Frama_C_entropy_source) tmp = min; else tmp = max;
  return tmp;
}

extern  __attribute__((__noreturn__)) void __builtin_abort(void);

/*@ terminates \false;
    ensures never_terminates: \false;
    assigns \nothing; */
 __attribute__((__noreturn__)) void Frama_C_abort(void);
void Frama_C_abort(void)
{
  __builtin_abort();
  return;
}

651 652 653 654 655 656 657 658 659 660 661 662 663 664 665 666 667 668 669 670 671 672 673 674 675 676 677 678 679 680 681 682 683 684 685 686 687 688 689 690 691 692 693 694 695 696 697 698 699 700 701 702 703 704 705 706 707 708 709 710 711 712 713 714 715 716 717 718 719 720 721 722 723 724 725 726 727 728 729 730 731 732 733 734 735 736 737 738 739 740 741 742 743 744 745 746 747 748 749 750 751 752 753 754 755 756 757 758 759 760 761 762 763 764 765 766 767 768 769 770 771 772 773 774 775 776 777 778 779 780 781 782 783 784 785 786 787 788 789 790 791 792 793 794 795 796 797 798 799 800 801 802 803 804 805 806 807 808 809 810 811 812 813 814 815 816 817 818 819 820 821 822 823 824 825 826 827 828 829 830 831 832 833 834 835 836 837 838 839 840 841 842 843 844 845 846 847 848 849 850 851 852 853 854 855 856 857 858 859 860 861 862 863 864 865 866 867 868 869 870 871 872 873 874 875 876 877 878 879 880 881 882 883 884 885 886 887 888 889 890 891 892 893 894 895 896 897 898 899 900 901 902 903 904 905 906 907 908 909 910 911 912 913 914 915 916 917 918 919 920 921 922 923 924 925 926 927 928 929 930 931 932 933 934 935 936 937 938 939 940 941 942 943 944 945 946 947 948 949 950 951 952 953 954 955 956 957 958 959 960 961 962 963 964 965 966 967 968 969 970 971 972 973 974 975 976 977 978 979 980 981 982 983 984 985 986 987 988 989 990 991 992 993 994 995 996 997 998 999 1000 1001 1002 1003 1004 1005 1006 1007 1008 1009 1010 1011 1012 1013 1014 1015 1016 1017 1018 1019 1020 1021 1022 1023 1024 1025 1026 1027 1028 1029 1030 1031 1032 1033 1034 1035 1036 1037 1038 1039 1040 1041 1042 1043 1044 1045 1046 1047 1048 1049 1050 1051 1052 1053 1054 1055 1056 1057 1058 1059 1060 1061 1062 1063 1064 1065 1066 1067 1068 1069 1070 1071 1072 1073 1074 1075 1076 1077 1078 1079 1080 1081 1082 1083 1084 1085 1086 1087 1088 1089 1090 1091 1092 1093 1094 1095 1096 1097 1098 1099 1100 1101 1102 1103 1104 1105 1106 1107 1108 1109 1110 1111 1112 1113 1114 1115 1116 1117 1118 1119 1120 1121
void __FC_assert(int c, char const *file, int line, char const *expr);

/*@ assigns \nothing; */
extern void Frama_C_show_each_warning();

/*@ requires nonnull_c: c ≢ 0;
    terminates c ≢ 0;
    assigns \nothing; */
void __FC_assert(int c, char const *file, int line, char const *expr)
{
  if (! c) {
    Frama_C_show_each_warning("Assertion may fail",file,line,expr);
    Frama_C_abort();
  }
  return;
}

int isalnum(int c);

int isalpha(int c);

int isblank(int c);

int iscntrl(int c);

int isdigit(int c);

int isgraph(int c);

int islower(int c);

int isprint(int c);

int ispunct(int c);

int isspace(int c);

int isupper(int c);

int isxdigit(int c);

int tolower(int c);

int toupper(int c);

/*@ requires c_uchar_or_eof: (0 ≤ c ≤ 255) ∨ c ≡ -1;
    assigns \result;
    assigns \result \from c;
    
    behavior match:
      assumes c_ascii: 0 ≤ c ≤ 127;
      ensures nonzero_result: \result < 0 ∨ \result > 0;
    
    behavior no_match:
      assumes c_non_ascii: ¬(0 ≤ c ≤ 127);
      ensures zero_result: \result ≡ 0;
    
    complete behaviors no_match, match;
    disjoint behaviors no_match, match;
 */
extern int isascii(int c);

/*@ requires c_uchar_or_eof_or_EOF: (0 ≤ c ≤ 255) ∨ c ≡ -1;
    assigns \result;
    assigns \result \from c;
    
    behavior definitely_match:
      assumes
        c_alnum:
          ('A' ≤ c ≤ 'Z') ∨ ('a' ≤ c ≤ 'z') ∨ ('0' ≤ c ≤ '9');
      ensures nonzero_result: \result < 0 ∨ \result > 0;
    
    behavior definitely_not_match:
      assumes
        c_non_alnum:
          c ≡ -1 ∨ (0 ≤ c ≤ 47) ∨ (58 ≤ c ≤ 64) ∨
          (91 ≤ c ≤ 96) ∨ (123 ≤ c ≤ 127);
      ensures zero_result: \result ≡ 0;
    
    disjoint behaviors definitely_not_match, definitely_match;
 */
int isalnum(int c)
{
  int tmp;
  if (c >= 'A') {
    if (c <= 'Z') tmp = 1; else goto _LAND_0;
  }
  else {
    _LAND_0: ;
    if (c >= 'a') {
      if (c <= 'z') tmp = 1; else goto _LAND;
    }
    else {
      _LAND: ;
      if (c >= '0') 
        if (c <= '9') tmp = 1; else tmp = 0;
      else tmp = 0;
    }
  }
  return tmp;
}

/*@ requires c_uchar_or_eof: (0 ≤ c ≤ 255) ∨ c ≡ -1;
    assigns \result;
    assigns \result \from c;
    
    behavior definitely_match:
      assumes c_alpha: ('A' ≤ c ≤ 'Z') ∨ ('a' ≤ c ≤ 'z');
      ensures nonzero_result: \result < 0 ∨ \result > 0;
    
    behavior definitely_not_match:
      assumes
        c_non_alpha:
          c ≡ -1 ∨ (0 ≤ c ≤ 64) ∨ (91 ≤ c ≤ 96) ∨
          (123 ≤ c ≤ 127);
      ensures zero_result: \result ≡ 0;
    
    disjoint behaviors definitely_not_match, definitely_match;
 */
int isalpha(int c)
{
  int tmp;
  if (c >= 'A') {
    if (c <= 'Z') tmp = 1; else goto _LAND;
  }
  else {
    _LAND: ;
    if (c >= 'a') 
      if (c <= 'z') tmp = 1; else tmp = 0;
    else tmp = 0;
  }
  return tmp;
}

/*@ requires c_uchar_or_eof: (0 ≤ c ≤ 255) ∨ c ≡ -1;
    assigns \result;
    assigns \result \from c;
    
    behavior match:
      assumes c_tab_or_space: c ≡ ' ' ∨ c ≡ '\t';
      ensures nonzero_result: \result < 0 ∨ \result > 0;
    
    behavior no_match:
      assumes c_non_blank: c ≢ ' ' ∧ c ≢ '\t';
      ensures zero_result: \result ≡ 0;
    
    complete behaviors no_match, match;
    disjoint behaviors no_match, match;
 */
int isblank(int c)
{
  int tmp;
  if (c == ' ') tmp = 1;
  else 
    if (c == '\t') tmp = 1;
    else 
      if (c == ' ') tmp = 1;
      else 
        if (c == '\f') tmp = 1;
        else 
          if (c == '\n') tmp = 1;
          else 
            if (c == '\r') tmp = 1;
            else 
              if (c == '\t') tmp = 1;
              else 
                if (c == '\v') tmp = 1; else tmp = 0;
  return tmp;
}

/*@ requires c_uchar_or_eof: (0 ≤ c ≤ 255) ∨ c ≡ -1;
    assigns \result;
    assigns \result \from c;
    
    behavior definitely_match:
      assumes c_control_char: (0 ≤ c ≤ 31) ∨ c ≡ 127;
      ensures nonzero_result: \result < 0 ∨ \result > 0;
    
    behavior definitely_not_match:
      assumes c_non_control_char: c ≡ -1 ∨ (32 ≤ c ≤ 126);
      ensures zero_result: \result ≡ 0;
    
    disjoint behaviors definitely_not_match, definitely_match;
 */
int iscntrl(int c)
{
  int tmp;
  tmp = Frama_C_nondet(0,1);
  return tmp;
}

/*@ requires c_uchar_or_eof: (0 ≤ c ≤ 255) ∨ c ≡ -1;
    assigns \result;
    assigns \result \from c;
    
    behavior match:
      assumes c_digit: '0' ≤ c ≤ '9';
      ensures nonzero_result: \result < 0 ∨ \result > 0;
    
    behavior no_match:
      assumes c_non_digit: c < '0' ∨ c > '9';
      ensures zero_result: \result ≡ 0;
    
    complete behaviors no_match, match;
    disjoint behaviors no_match, match;
 */
int isdigit(int c)
{
  int tmp;
  if (c >= '0') 
    if (c <= '9') tmp = 1; else tmp = 0;
  else tmp = 0;
  return tmp;
}

/*@ requires c_uchar_or_eof: (0 ≤ c ≤ 255) ∨ c ≡ -1;
    assigns \result;
    assigns \result \from c;
    
    behavior definitely_match:
      assumes c_graphical: 33 ≤ c ≤ 126;
      ensures nonzero_result: \result < 0 ∨ \result > 0;
    
    behavior definitely_not_match:
      assumes c_non_graphical: c ≡ -1 ∨ (0 ≤ c ≤ 32) ∨ c ≡ 127;
      ensures zero_result: \result ≡ 0;
    
    disjoint behaviors definitely_not_match, definitely_match;
 */
int isgraph(int c)
{
  int tmp;
  tmp = Frama_C_nondet(0,1);
  return tmp;
}

/*@ requires c_uchar_or_eof: (0 ≤ c ≤ 255) ∨ c ≡ -1;
    assigns \result;
    assigns \result \from c;
    
    behavior definitely_match:
      assumes c_lower: 'a' ≤ c ≤ 'z';
      ensures nonzero_result: \result < 0 ∨ \result > 0;
    
    behavior definitely_not_match:
      assumes c_non_lower: c ≡ -1 ∨ (0 ≤ c < 'a') ∨ ('z' < c < 127);
      ensures zero_result: \result ≡ 0;
    
    disjoint behaviors definitely_not_match, definitely_match;
 */
int islower(int c)
{
  int tmp;
  if (c >= 'a') 
    if (c <= 'z') tmp = 1; else tmp = 0;
  else tmp = 0;
  return tmp;
}

/*@ requires c_uchar_or_eof: (0 ≤ c ≤ 255) ∨ c ≡ -1;
    assigns \result;
    assigns \result \from c;
    
    behavior definitely_match:
      assumes c_printable: 32 ≤ c ≤ 126;
      ensures nonzero_result: \result < 0 ∨ \result > 0;
    
    behavior definitely_not_match:
      assumes c_non_printable: c ≡ -1 ∨ (0 ≤ c ≤ 31) ∨ c ≡ 127;
      ensures zero_result: \result ≡ 0;
    
    disjoint behaviors definitely_not_match, definitely_match;
 */
int isprint(int c)
{
  int tmp;
  tmp = Frama_C_nondet(0,1);
  return tmp;
}

/*@ requires c_uchar_or_eof: (0 ≤ c ≤ 255) ∨ c ≡ -1;
    assigns \result;
    assigns \result \from c;
    
    behavior definitely_match:
      assumes
        c_punct:
          (33 ≤ c ≤ 47) ∨ (58 ≤ c ≤ 64) ∨ (91 ≤ c ≤ 96) ∨
          (123 ≤ c ≤ 126);
      ensures nonzero_result: \result < 0 ∨ \result > 0;
    
    behavior definitely_not_match:
      assumes
        c_non_punct:
          c ≡ -1 ∨ (0 ≤ c ≤ 32) ∨ (48 ≤ c ≤ 57) ∨
          (65 ≤ c ≤ 90) ∨ (97 ≤ c ≤ 122) ∨ c ≡ 127;
      ensures zero_result: \result ≡ 0;
    
    disjoint behaviors definitely_not_match, definitely_match;
 */
int ispunct(int c)
{
  int tmp;
  tmp = Frama_C_nondet(0,1);
  return tmp;
}

/*@ requires c_uchar_or_eof: (0 ≤ c ≤ 255) ∨ c ≡ -1;
    assigns \result;
    assigns \result \from c;
    
    behavior definitely_match:
      assumes c_space: (9 ≤ c ≤ 13) ∨ c ≡ ' ';
      ensures nonzero_result: \result < 0 ∨ \result > 0;
    
    behavior definitely_not_match:
      assumes
        c_non_space:
          c ≡ -1 ∨ (0 ≤ c ≤ 8) ∨ (14 ≤ c < ' ') ∨
          (' ' < c ≤ 127);
      ensures zero_result: \result ≡ 0;
    
    disjoint behaviors definitely_not_match, definitely_match;
 */
int isspace(int c)
{
  int tmp;
  if (c == ' ') tmp = 1;
  else 
    if (c == '\f') tmp = 1;
    else 
      if (c == '\n') tmp = 1;
      else 
        if (c == '\r') tmp = 1;
        else 
          if (c == '\t') tmp = 1;
          else 
            if (c == '\v') tmp = 1; else tmp = 0;
  return tmp;
}

/*@ requires c_uchar_or_eof: (0 ≤ c ≤ 255) ∨ c ≡ -1;
    assigns \result;
    assigns \result \from c;
    
    behavior definitely_match:
      assumes c_upper: 'A' ≤ c ≤ 'Z';
      ensures nonzero_result: \result < 0 ∨ \result > 0;
    
    behavior definitely_not_match:
      assumes
        c_non_upper: c ≡ -1 ∨ (0 ≤ c < 'A') ∨ ('Z' < c ≤ 127);
      ensures zero_result: \result ≡ 0;
    
    disjoint behaviors definitely_not_match, definitely_match;
 */
int isupper(int c)
{
  int tmp;
  if (c >= 'A') 
    if (c <= 'Z') tmp = 1; else tmp = 0;
  else tmp = 0;
  return tmp;
}

/*@ requires c_uchar_or_eof: (0 ≤ c ≤ 255) ∨ c ≡ -1;
    assigns \result;
    assigns \result \from c;
    
    behavior match:
      assumes
        c_hexa_digit:
          ('0' ≤ c ≤ '9') ∨ ('A' ≤ c ≤ 'F') ∨ ('a' ≤ c ≤ 'f');
      ensures nonzero_result: \result < 0 ∨ \result > 0;
    
    behavior no_match:
      assumes
        c_non_hexa_digit:
          ¬(('0' ≤ c ≤ '9') ∨ ('A' ≤ c ≤ 'F') ∨
             ('a' ≤ c ≤ 'f'));
      ensures zero_result: \result ≡ 0;
    
    complete behaviors no_match, match;
    disjoint behaviors no_match, match;
 */
int isxdigit(int c)
{
  int tmp;
  if (c >= '0') {
    if (c <= '9') tmp = 1; else goto _LAND_0;
  }
  else {
    _LAND_0: ;
    if (c >= 'a') {
      if (c <= 'f') tmp = 1; else goto _LAND;
    }
    else {
      _LAND: ;
      if (c >= 'A') 
        if (c <= 'F') tmp = 1; else tmp = 0;
      else tmp = 0;
    }
  }
  return tmp;
}

/*@ requires c_uchar_or_eof: (0 ≤ c ≤ 255) ∨ c ≡ -1;
    ensures result_uchar_of_eof: (0 ≤ \result ≤ 255) ∨ \result ≡ -1;
    assigns \result;
    assigns \result \from c;
    
    behavior definitely_changed:
      assumes c_ascii_upper: 'A' ≤ c ≤ 'Z';
      ensures result_ascii_lower: \result ≡ \old(c) + 32;
    
    behavior definitely_not_changed:
      assumes
        c_ascii_but_non_upper:
          c ≡ -1 ∨ (0 ≤ c < 'A') ∨ ('Z' < c ≤ 127);
      ensures result_unchanged: \result ≡ \old(c);
    
    disjoint behaviors definitely_not_changed, definitely_changed;
 */
int tolower(int c)
{
  int __retres;
  if (c >= 'A') 
    if (c <= 'Z') {
      __retres = c + 0x20;
      goto return_label;
    }
  __retres = c;
  return_label: return __retres;
}

/*@ requires c_uchar_of_eof: (0 ≤ c ≤ 255) ∨ c ≡ -1;
    ensures result_uchar_of_eof: (0 ≤ \result ≤ 255) ∨ \result ≡ -1;
    assigns \result;
    assigns \result \from c;
    
    behavior definitely_changed:
      assumes c_ascii_lower: 'a' ≤ c ≤ 'z';
      ensures result_ascii_upper: \result ≡ \old(c) - 32;
    
    behavior definitely_not_changed:
      assumes
        c_ascii_but_non_lower:
          c ≡ -1 ∨ (0 ≤ c < 'a') ∨ ('z' < c ≤ 127);
      ensures result_unchanged: \result ≡ \old(c);
    
    disjoint behaviors definitely_not_changed, definitely_changed;
 */
int toupper(int c)
{
  int __retres;
  if (c >= 'a') 
    if (c <= 'z') {
      __retres = c - 0x20;
      goto return_label;
    }
  __retres = c;
  return_label: return __retres;
}

int __fc_errno;

int __fc_errno = 0;
int fetestexcept(int excepts);

int feholdexcept(fenv_t *envp);

1122
int fesetenv(fenv_t const *envp);
1123 1124 1125 1126 1127 1128 1129 1130 1131 1132 1133 1134 1135 1136 1137 1138 1139 1140 1141

static int volatile fetestexcept___fc_random_fetestexcept __attribute__((
  __FRAMA_C_MODEL__));
int fetestexcept(int excepts)
{
  int __retres;
  __retres = 0x00FF & fetestexcept___fc_random_fetestexcept;
  return __retres;
}

fenv_t volatile __fc_fenv_state __attribute__((__FRAMA_C_MODEL__));
int feholdexcept(fenv_t *envp)
{
  int __retres;
  *envp = __fc_fenv_state;
  __retres = 0;
  return __retres;
}

1142
int fesetenv(fenv_t const *envp)
1143
{
1144
  int __retres;
1145
  __fc_fenv_state = *envp;
1146 1147
  __retres = 0;
  return __retres;
1148 1149 1150 1151 1152 1153 1154 1155 1156 1157 1158 1159 1160 1161 1162 1163 1164 1165 1166 1167 1168 1169 1170 1171 1172 1173 1174 1175 1176 1177 1178 1179 1180 1181 1182 1183 1184 1185 1186 1187 1188 1189 1190 1191 1192 1193 1194 1195 1196 1197 1198 1199 1200 1201 1202 1203 1204 1205 1206 1207 1208 1209 1210 1211 1212 1213 1214 1215 1216 1217 1218 1219 1220 1221 1222 1223 1224 1225 1226 1227 1228 1229 1230 1231 1232 1233 1234 1235 1236 1237 1238 1239 1240 1241 1242 1243 1244 1245 1246 1247 1248 1249 1250 1251 1252 1253 1254 1255 1256 1257 1258 1259 1260 1261 1262 1263 1264 1265 1266 1267 1268 1269 1270 1271 1272 1273 1274 1275 1276 1277 1278 1279 1280 1281 1282 1283 1284 1285 1286 1287 1288 1289 1290 1291 1292 1293 1294 1295 1296 1297 1298 1299 1300 1301 1302 1303 1304 1305 1306 1307 1308 1309 1310
}

/*@
axiomatic MemCmp {
  logic ℤ memcmp{L1, L2}(char *s1, char *s2, ℤ n) 
    reads \at(*(s1 + (0 .. n - 1)),L1), \at(*(s2 + (0 .. n - 1)),L2);
  
  axiom memcmp_zero{L1, L2}:
    ∀ char *s1, char *s2;
    ∀ ℤ n;
      memcmp{L1, L2}(s1, s2, n) ≡ 0 ⇔
      (∀ ℤ i; 0 ≤ i < n ⇒ \at(*(s1 + i),L1) ≡ \at(*(s2 + i),L2));
  
  }
 */
/*@
axiomatic MemChr {
  logic 𝔹 memchr{L}(char *s, ℤ c, ℤ n) 
    reads *(s + (0 .. n - 1));
  
  logic ℤ memchr_off{L}(char *s, ℤ c, ℤ n) 
    reads *(s + (0 .. n - 1));
  
  axiom memchr_def{L}:
    ∀ char *s;
    ∀ ℤ c;
    ∀ ℤ n;
      memchr(s, c, n) ≡ \true ⇔
      (∃ int i; 0 ≤ i < n ∧ *(s + i) ≡ c);
  
  }
 */
/*@
axiomatic MemSet {
  logic 𝔹 memset{L}(char *s, ℤ c, ℤ n) 
    reads *(s + (0 .. n - 1));
  
  axiom memset_def{L}:
    ∀ char *s;
    ∀ ℤ c;
    ∀ ℤ n;
      memset(s, c, n) ≡ \true ⇔
      (∀ ℤ i; 0 ≤ i < n ⇒ *(s + i) ≡ c);
  
  }
 */
/*@
axiomatic StrLen {
  logic ℤ strlen{L}(char *s) 
    reads *(s + (0 ..));
  
  axiom strlen_pos_or_null{L}:
    ∀ char *s;
    ∀ ℤ i;
      0 ≤ i ∧ (∀ ℤ j; 0 ≤ j < i ⇒ *(s + j) ≢ '\000') ∧
      *(s + i) ≡ '\000' ⇒ strlen(s) ≡ i;
  
  axiom strlen_neg{L}:
    ∀ char *s;
      (∀ ℤ i; 0 ≤ i ⇒ *(s + i) ≢ '\000') ⇒ strlen(s) < 0;
  
  axiom strlen_before_null{L}:
    ∀ char *s;
    ∀ ℤ i; 0 ≤ i < strlen(s) ⇒ *(s + i) ≢ '\000';
  
  axiom strlen_at_null{L}:
    ∀ char *s; 0 ≤ strlen(s) ⇒ *(s + strlen(s)) ≡ '\000';
  
  axiom strlen_not_zero{L}:
    ∀ char *s;
    ∀ ℤ i;
      0 ≤ i ≤ strlen(s) ∧ *(s + i) ≢ '\000' ⇒ i < strlen(s);
  
  axiom strlen_zero{L}:
    ∀ char *s;
    ∀ ℤ i;
      0 ≤ i ≤ strlen(s) ∧ *(s + i) ≡ '\000' ⇒ i ≡ strlen(s);
  
  axiom strlen_sup{L}:
    ∀ char *s;
    ∀ ℤ i; 0 ≤ i ∧ *(s + i) ≡ '\000' ⇒ 0 ≤ strlen(s) ≤ i;
  
  axiom strlen_shift{L}:
    ∀ char *s;
    ∀ ℤ i; 0 ≤ i ≤ strlen(s) ⇒ strlen(s + i) ≡ strlen(s) - i;
  
  axiom strlen_create{L}:
    ∀ char *s;
    ∀ ℤ i; 0 ≤ i ∧ *(s + i) ≡ '\000' ⇒ 0 ≤ strlen(s) ≤ i;
  
  axiom strlen_create_shift{L}:
    ∀ char *s;
    ∀ ℤ i;
    ∀ ℤ k;
      0 ≤ k ≤ i ∧ *(s + i) ≡ '\000' ⇒ 0 ≤ strlen(s + k) ≤ i - k;
  
  axiom memcmp_strlen_left{L}:
    ∀ char *s1, char *s2;
    ∀ ℤ n;
      memcmp{L, L}(s1, s2, n) ≡ 0 ∧ strlen(s1) < n ⇒
      strlen(s1) ≡ strlen(s2);
  
  axiom memcmp_strlen_right{L}:
    ∀ char *s1, char *s2;
    ∀ ℤ n;
      memcmp{L, L}(s1, s2, n) ≡ 0 ∧ strlen(s2) < n ⇒
      strlen(s1) ≡ strlen(s2);
  
  axiom memcmp_strlen_shift_left{L}:
    ∀ char *s1, char *s2;
    ∀ ℤ k, ℤ n;
      memcmp{L, L}(s1, s2 + k, n) ≡ 0 ≤ k ∧ strlen(s1) < n ⇒
      0 ≤ strlen(s2) ≤ k + strlen(s1);
  
  axiom memcmp_strlen_shift_right{L}:
    ∀ char *s1, char *s2;
    ∀ ℤ k, ℤ n;
      memcmp{L, L}(s1 + k, s2, n) ≡ 0 ≤ k ∧ strlen(s2) < n ⇒
      0 ≤ strlen(s1) ≤ k + strlen(s2);
  
  }
 */
/*@
axiomatic StrCmp {
  logic ℤ strcmp{L}(char *s1, char *s2) 
    reads *(s1 + (0 .. strlen(s1))), *(s2 + (0 .. strlen(s2)));
  
  axiom strcmp_zero{L}:
    ∀ char *s1, char *s2;
      strcmp(s1, s2) ≡ 0 ⇔
      strlen(s1) ≡ strlen(s2) ∧
      (∀ ℤ i; 0 ≤ i ≤ strlen(s1) ⇒ *(s1 + i) ≡ *(s2 + i));
  
  }
 */
/*@
axiomatic StrNCmp {
  logic ℤ strncmp{L}(char *s1, char *s2, ℤ n) 
    reads *(s1 + (0 .. n - 1)), *(s2 + (0 .. n - 1));
  
  axiom strncmp_zero{L}:
    ∀ char *s1, char *s2;
    ∀ ℤ n;
      strncmp(s1, s2, n) ≡ 0 ⇔
      (strlen(s1) < n ∧ strcmp(s1, s2) ≡ 0) ∨
      (∀ ℤ i; 0 ≤ i < n ⇒ *(s1 + i) ≡ *(s2 + i));
  
  }
 */
/*@
axiomatic StrChr {
  logic 𝔹 strchr{L}(char *s, ℤ c) 
    reads *(s + (0 .. strlen(s)));
  
  axiom strchr_def{L}:
    ∀ char *s;
    ∀ ℤ c;
      strchr(s, c) ≡ \true ⇔
      (∃ ℤ i; 0 ≤ i ≤ strlen(s) ∧ *(s + i) ≡ (char)c);
  
  }
 */
/*@
Andre Maroneze's avatar
Andre Maroneze committed
1311 1312 1313 1314 1315 1316 1317 1318 1319 1320 1321 1322 1323 1324 1325 1326 1327
axiomatic WMemChr {
  logic 𝔹 wmemchr{L}(wchar_t *s, wchar_t c, ℤ n) 
    reads *(s + (0 .. n - 1));
  
  logic ℤ wmemchr_off{L}(wchar_t *s, wchar_t c, ℤ n) 
    reads *(s + (0 .. n - 1));
  
  axiom wmemchr_def{L}:
    ∀ wchar_t *s;
    ∀ int c;
    ∀ ℤ n;
      wmemchr(s, c, n) ≡ \true ⇔
      (∃ int i; 0 ≤ i < n ∧ *(s + i) ≡ c);
  
  }
 */
/*@
1328 1329 1330 1331 1332 1333 1334 1335 1336 1337 1338 1339 1340 1341 1342 1343 1344 1345 1346 1347 1348 1349 1350 1351 1352 1353 1354 1355 1356 1357 1358 1359 1360 1361 1362 1363 1364 1365 1366 1367 1368 1369 1370 1371 1372 1373 1374 1375 1376 1377 1378 1379 1380 1381 1382 1383 1384 1385 1386 1387 1388 1389 1390 1391 1392 1393 1394 1395 1396 1397 1398 1399 1400 1401 1402 1403 1404 1405 1406 1407 1408 1409 1410 1411 1412 1413 1414 1415 1416 1417 1418 1419 1420 1421 1422 1423 1424 1425 1426 1427 1428 1429 1430 1431 1432 1433 1434 1435 1436 1437 1438 1439 1440 1441 1442 1443 1444 1445 1446 1447 1448 1449 1450 1451 1452 1453
axiomatic WcsLen {
  logic ℤ wcslen{L}(wchar_t *s) 
    reads *(s + (0 ..));
  
  axiom wcslen_pos_or_null{L}:
    ∀ wchar_t *s;
    ∀ ℤ i;
      0 ≤ i ∧ (∀ ℤ j; 0 ≤ j < i ⇒ *(s + j) ≢ 0) ∧
      *(s + i) ≡ 0 ⇒ wcslen(s) ≡ i;
  
  axiom wcslen_neg{L}:
    ∀ wchar_t *s; (∀ ℤ i; 0 ≤ i ⇒ *(s + i) ≢ 0) ⇒ wcslen(s) < 0;
  
  axiom wcslen_before_null{L}:
    ∀ wchar_t *s;
    ∀ int i; 0 ≤ i < wcslen(s) ⇒ *(s + i) ≢ 0;
  
  axiom wcslen_at_null{L}:
    ∀ wchar_t *s; 0 ≤ wcslen(s) ⇒ *(s + wcslen(s)) ≡ 0;
  
  axiom wcslen_not_zero{L}:
    ∀ wchar_t *s;
    ∀ int i; 0 ≤ i ≤ wcslen(s) ∧ *(s + i) ≢ 0 ⇒ i < wcslen(s);
  
  axiom wcslen_zero{L}:
    ∀ wchar_t *s;
    ∀ int i; 0 ≤ i ≤ wcslen(s) ∧ *(s + i) ≡ 0 ⇒ i ≡ wcslen(s);
  
  axiom wcslen_sup{L}:
    ∀ wchar_t *s;
    ∀ int i; 0 ≤ i ∧ *(s + i) ≡ 0 ⇒ 0 ≤ wcslen(s) ≤ i;
  
  axiom wcslen_shift{L}:
    ∀ wchar_t *s;
    ∀ int i; 0 ≤ i ≤ wcslen(s) ⇒ wcslen(s + i) ≡ wcslen(s) - i;
  
  axiom wcslen_create{L}:
    ∀ wchar_t *s;
    ∀ int i; 0 ≤ i ∧ *(s + i) ≡ 0 ⇒ 0 ≤ wcslen(s) ≤ i;
  
  axiom wcslen_create_shift{L}:
    ∀ wchar_t *s;
    ∀ int i;
    ∀ int k;
      0 ≤ k ≤ i ∧ *(s + i) ≡ 0 ⇒ 0 ≤ wcslen(s + k) ≤ i - k;
  
  }
 */
/*@
axiomatic WcsCmp {
  logic ℤ wcscmp{L}(wchar_t *s1, wchar_t *s2) 
    reads *(s1 + (0 .. wcslen(s1))), *(s2 + (0 .. wcslen(s2)));
  
  axiom wcscmp_zero{L}:
    ∀ wchar_t *s1, wchar_t *s2;
      wcscmp(s1, s2) ≡ 0 ⇔
      wcslen(s1) ≡ wcslen(s2) ∧
      (∀ ℤ i; 0 ≤ i ≤ wcslen(s1) ⇒ *(s1 + i) ≡ *(s2 + i));
  
  }
 */
/*@
axiomatic WcsNCmp {
  logic ℤ wcsncmp{L}(wchar_t *s1, wchar_t *s2, ℤ n) 
    reads *(s1 + (0 .. n - 1)), *(s2 + (0 .. n - 1));
  
  axiom wcsncmp_zero{L}:
    ∀ wchar_t *s1, wchar_t *s2;
    ∀ ℤ n;
      wcsncmp(s1, s2, n) ≡ 0 ⇔
      (wcslen(s1) < n ∧ wcscmp(s1, s2) ≡ 0) ∨
      (∀ ℤ i; 0 ≤ i < n ⇒ *(s1 + i) ≡ *(s2 + i));
  
  }
 */
/*@
axiomatic WcsChr {
  logic 𝔹 wcschr{L}(wchar_t *wcs, ℤ wc) 
    reads *(wcs + (0 .. wcslen(wcs)));
  
  axiom wcschr_def{L}:
    ∀ wchar_t *wcs;
    ∀ ℤ wc;
      wcschr(wcs, wc) ≡ \true ⇔
      (∃ ℤ i; 0 ≤ i ≤ wcslen(wcs) ∧ *(wcs + i) ≡ (int)wc);
  
  }
 */
/*@ logic ℤ minimum(ℤ i, ℤ j) = i < j? i: j;
 */
/*@ logic ℤ maximum(ℤ i, ℤ j) = i < j? j: i;
 */
/*@
predicate valid_string{L}(char *s) =
  0 ≤ strlen(s) ∧ \valid(s + (0 .. strlen(s)));
 */
/*@
predicate valid_read_string{L}(char *s) =
  0 ≤ strlen(s) ∧ \valid_read(s + (0 .. strlen(s)));
 */
/*@
predicate valid_read_nstring{L}(char *s, ℤ n) =
  (\valid_read(s + (0 .. n - 1)) ∧ \initialized(s + (0 .. n - 1))) ∨
  valid_read_string(s);
 */
/*@
predicate valid_string_or_null{L}(char *s) = s ≡ \null ∨ valid_string(s);
 */
/*@
predicate valid_wstring{L}(wchar_t *s) =
  0 ≤ wcslen(s) ∧ \valid(s + (0 .. wcslen(s)));
 */
/*@
predicate valid_read_wstring{L}(wchar_t *s) =
  0 ≤ wcslen(s) ∧ \valid_read(s + (0 .. wcslen(s)));
 */
/*@
predicate valid_read_nwstring{L}(wchar_t *s, ℤ n) =
  (\valid_read(s + (0 .. n - 1)) ∧ \initialized(s + (0 .. n - 1))) ∨
  valid_read_wstring(s);
 */
/*@
predicate valid_wstring_or_null{L}(wchar_t *s) =
  s ≡ \null ∨ valid_wstring(s);

*/
Andre Maroneze's avatar
Andre Maroneze committed
1454 1455 1456 1457
/*@ ghost int __fc_fds[1024]; */
/*@ requires valid_string_path: valid_read_string(path);
    requires valid_amode: (amode & ~((4 | 2) | 1)) ≡ 0 ∨ amode ≡ 0;
    ensures result_ok_or_error: \result ≡ 0 ∨ \result ≡ -1;
1458
    assigns \result;
Andre Maroneze's avatar
Andre Maroneze committed
1459 1460
    assigns \result
      \from (indirect: path), (indirect: *(path + (0 ..))), (indirect: amode);
1461
 */
Andre Maroneze's avatar
Andre Maroneze committed
1462
extern int access(char const *path, int amode);
1463

Andre Maroneze's avatar
Andre Maroneze committed
1464 1465
/*@ requires valid_string_path: valid_read_string(path);
    ensures result_ok_or_error: \result ≡ 0 ∨ \result ≡ -1;
1466
    assigns \result;
Andre Maroneze's avatar
Andre Maroneze committed
1467
    assigns \result \from (indirect: path), (indirect: *(path + (0 ..)));
1468
 */
Andre Maroneze's avatar
Andre Maroneze committed
1469
extern int chdir(char const *path);
1470

Andre Maroneze's avatar
Andre Maroneze committed
1471 1472
/*@ requires valid_string_path: valid_read_string(path);
    ensures result_ok_or_error: \result ≡ 0 ∨ \result ≡ -1;
1473
    assigns \result;
Andre Maroneze's avatar
Andre Maroneze committed
1474
    assigns \result \from (indirect: path), (indirect: *(path + (0 ..)));
1475
 */
Andre Maroneze's avatar
Andre Maroneze committed
1476
extern int chroot(char const *path);
1477

Andre Maroneze's avatar
Andre Maroneze committed
1478 1479 1480 1481 1482 1483
/*@ requires valid_string_path: valid_read_string(path);
    ensures result_ok_or_error: \result ≡ 0 ∨ \result ≡ -1;
    assigns \result;
    assigns \result
      \from (indirect: path), (indirect: *(path + (0 ..))),
            (indirect: owner), (indirect: group);
1484
 */
Andre Maroneze's avatar
Andre Maroneze committed
1485
extern int chown(char const *path, uid_t owner, gid_t group);
1486

Andre Maroneze's avatar
Andre Maroneze committed
1487 1488 1489 1490 1491
/*@ requires valid_fd: 0 ≤ fd < 1024;
    ensures result_ok_or_error: \result ≡ 0 ∨ \result ≡ -1;
    assigns __fc_fds[fd], \result;
    assigns __fc_fds[fd] \from fd, __fc_fds[fd];
    assigns \result \from (indirect: fd), (indirect: __fc_fds[fd]);
1492
 */
Andre Maroneze's avatar
Andre Maroneze committed
1493
extern int close(int fd);
1494

Andre Maroneze's avatar
Andre Maroneze committed
1495 1496 1497 1498 1499 1500 1501
/*@ requires valid_fildes: 0 ≤ fildes < 1024;
    ensures
      result_valid_fildes_or_error:
        \result ≡ -1 ∨ (\old(fildes) ≤ \result < 1024);
    assigns __fc_fds[fildes ..], \result;
    assigns __fc_fds[fildes ..] \from fildes;
    assigns \result \from fildes;
1502
 */
Andre Maroneze's avatar
Andre Maroneze committed
1503
extern int dup(int fildes);
1504

Andre Maroneze's avatar
Andre Maroneze committed
1505 1506 1507 1508 1509 1510
/*@ requires valid_fildes: 0 ≤ fildes < 1024;
    requires valid_fildes2: 0 ≤ fildes2 < 1024;
    ensures
      result_fildes2_or_error: \result ≡ \old(fildes2) ∨ \result ≡ -1;
    assigns __fc_fds[fildes2], \result;
    assigns __fc_fds[fildes2] \from fildes, fildes2, __fc_fds[fildes2];
1511
    assigns \result
Andre Maroneze's avatar
Andre Maroneze committed
1512
      \from fildes, fildes2, __fc_fds[fildes], __fc_fds[fildes2];
1513
 */
Andre Maroneze's avatar
Andre Maroneze committed
1514
extern int dup2(int fildes, int fildes2);
1515

Andre Maroneze's avatar
Andre Maroneze committed
1516 1517 1518 1519
/*@ requires valid_string_path: valid_read_string(path);
    requires valid_string_arg: valid_read_string(arg);
    assigns \result;
    assigns \result \from *(path + (0 ..)), *(arg + (0 ..));
1520
 */
Andre Maroneze's avatar
Andre Maroneze committed
1521
extern int execl(char const *path, char const *arg, void * const *__va_params);
1522

Andre Maroneze's avatar
Andre Maroneze committed
1523 1524 1525 1526
/*@ requires valid_string_path: valid_read_string(path);
    requires valid_string_arg: valid_read_string(arg);
    assigns \result;
    assigns \result \from *(path + (0 ..)), *(arg + (0 ..));
1527
 */
Andre Maroneze's avatar
Andre Maroneze committed
1528 1529
extern int execle(char const *path, char const *arg,
                  void * const *__va_params);
1530

Andre Maroneze's avatar
Andre Maroneze committed
1531 1532 1533 1534
/*@ requires valid_string_path: valid_read_string(path);
    requires valid_string_arg: valid_read_string(arg);
    assigns \result;
    assigns \result \from *(path + (0 ..)), *(arg + (0 ..));
1535
 */
Andre Maroneze's avatar
Andre Maroneze committed
1536 1537
extern int execlp(char const *path, char const *arg,
                  void * const *__va_params);
1538

Andre Maroneze's avatar
Andre Maroneze committed
1539 1540 1541 1542
/*@ requires valid_string_path: valid_read_string(path);
    requires valid_string_argv0: valid_read_string(*(argv + 0));
    assigns \result;
    assigns \result \from *(path + (0 ..)), *(argv + (0 ..));
1543
 */
Andre Maroneze's avatar
Andre Maroneze committed
1544
extern int execv(char const *path, char * const *argv);
1545

Andre Maroneze's avatar
Andre Maroneze committed
1546 1547 1548 1549 1550 1551
/*@ requires valid_path: valid_read_string(path);
    requires valid_argv0: valid_read_string(*(argv + 0));
    assigns \result;
    assigns \result \from *(path + (0 ..)), *(argv + (0 ..));
 */
extern int execve(char const *path, char * const *argv, char * const *env);
1552

Andre Maroneze's avatar
Andre Maroneze committed
1553 1554
/*@ requires valid_string_path: valid_read_string(path);
    requires valid_string_argv0: valid_read_string(*(argv + 0));
1555
    assigns \result;
Andre Maroneze's avatar
Andre Maroneze committed
1556
    assigns \result \from *(path + (0 ..)), *(argv + (0 ..));
1557
 */
Andre Maroneze's avatar
Andre Maroneze committed
1558
extern int execvp(char const *path, char * const *argv);
1559

Andre Maroneze's avatar
Andre Maroneze committed
1560 1561 1562
/*@ ensures never_terminates: \false;
    assigns \nothing; */
extern  __attribute__((__noreturn__)) void _exit(int);
1563

Andre Maroneze's avatar
Andre Maroneze committed
1564 1565 1566 1567 1568
/*@ ensures
      result_ok_child_or_error:
        \result ≡ 0 ∨ \result > 0 ∨ \result ≡ -1;
    assigns \result;
    assigns \result \from \nothing;
1569
 */
Andre Maroneze's avatar
Andre Maroneze committed
1570
extern pid_t fork(void);
1571

Andre Maroneze's avatar
Andre Maroneze committed
1572 1573 1574 1575 1576
/*@ requires valid_buf: \valid(buf + (0 .. size - 1));
    ensures result_ok_or_error: \result ≡ \null ∨ \result ≡ \old(buf);
    assigns *(buf + (0 .. size - 1)), \result;
    assigns *(buf + (0 .. size - 1)) \from (indirect: buf), (indirect: size);
    assigns \result \from buf, (indirect: size);
1577
 */
Andre Maroneze's avatar
Andre Maroneze committed
1578
extern char *getcwd(char *buf, size_t size);
1579

Andre Maroneze's avatar
Andre Maroneze committed
1580 1581 1582
/*@ assigns \result;
    assigns \result \from \nothing; */
extern gid_t getegid(void);
1583

Andre Maroneze's avatar
Andre Maroneze committed
1584 1585 1586
/*@ assigns \result;
    assigns \result \from \nothing; */
extern uid_t geteuid(void);
1587

Andre Maroneze's avatar
Andre Maroneze committed
1588 1589 1590
/*@ assigns \result;
    assigns \result \from \nothing; */
extern gid_t getgid(void);
1591

Andre Maroneze's avatar
Andre Maroneze committed
1592 1593 1594 1595 1596 1597 1598 1599 1600
extern char volatile __fc_hostname[64];

/*@ requires name_has_room: \valid(name + (0 .. len - 1));
    ensures result_ok_or_error: \result ≡ 0 ∨ \result ≡ -1;
    assigns \result, *(name + (0 .. len - 1));
    assigns \result
      \from (indirect: __fc_hostname[0 .. len]), (indirect: len);
    assigns *(name + (0 .. len - 1))
      \from (indirect: __fc_hostname[0 .. len]), (indirect: len);
1601
 */
Andre Maroneze's avatar
Andre Maroneze committed
1602
extern int gethostname(char *name, size_t len);
1603

Andre Maroneze's avatar
Andre Maroneze committed
1604 1605 1606 1607 1608 1609 1610
/*@ requires name_valid_string: valid_read_nstring(name, len);
    requires bounded_len: len ≤ 64;
    ensures result_ok_or_error: \result ≡ 0 ∨ \result ≡ -1;
    assigns __fc_hostname[0 .. len], \result;
    assigns __fc_hostname[0 .. len]
      \from *(name + (0 .. len - 1)), (indirect: len);
    assigns \result \from (indirect: __fc_hostname[0 .. len]);
1611
 */
Andre Maroneze's avatar
Andre Maroneze committed
1612
extern int sethostname(char const *name, size_t len);
1613

Andre Maroneze's avatar
Andre Maroneze committed
1614 1615 1616
/*@ assigns \result;
    assigns \result \from (indirect: pid); */
extern pid_t getpgid(pid_t pid);
1617

Andre Maroneze's avatar
Andre Maroneze committed
1618 1619 1620
/*@ assigns \result;
    assigns \result \from \nothing; */
extern pid_t getpgrp(void);
1621

Andre Maroneze's avatar
Andre Maroneze committed
1622 1623 1624
/*@ assigns \result;
    assigns \result \from \nothing; */
extern pid_t getpid(void);
1625 1626 1627

/*@ assigns \result;
    assigns \result \from \nothing; */
Andre Maroneze's avatar
Andre Maroneze committed
1628
extern pid_t getppid(void);
1629 1630 1631

/*@ assigns \result;
    assigns \result \from \nothing; */
Andre Maroneze's avatar
Andre Maroneze committed
1632
extern pid_t getsid(pid_t);
1633

Andre Maroneze's avatar
Andre Maroneze committed
1634 1635 1636
/*@ assigns \result;
    assigns \result \from \nothing; */
extern uid_t getuid(void);
1637

Andre Maroneze's avatar
Andre Maroneze committed
1638 1639 1640 1641 1642
/*@ ensures result_true_or_false: \result ≡ 0 ∨ \result ≡ 1;
    assigns \result;
    assigns \result \from (indirect: fd), (indirect: __fc_fds[fd]);
 */
extern int isatty(int fd);
1643

Andre Maroneze's avatar
Andre Maroneze committed
1644 1645 1646 1647 1648 1649 1650 1651 1652 1653 1654 1655
/*@ requires valid_fd: 0 ≤ fd < 1024;
    requires valid_whence: whence ≡ 0 ∨ whence ≡ 1 ∨ whence ≡ 2;
    ensures result_error_or_offset: \result ≡ -1 ∨ 0 ≤ \result;
    assigns \result, __fc_fds[fd];
    assigns \result
      \from (indirect: fd), (indirect: __fc_fds[fd]), (indirect: offset),
            (indirect: whence);
    assigns __fc_fds[fd]
      \from (indirect: fd), __fc_fds[fd], (indirect: offset),
            (indirect: whence);
 */
extern off_t lseek(int fd, off_t offset, int whence);
1656

Andre Maroneze's avatar
Andre Maroneze committed
1657 1658 1659 1660 1661
/*@ requires valid_path: valid_read_string(path);
    assigns \result;
    assigns \result \from (indirect: *(path + (0 ..))), (indirect: name);
 */
extern long pathconf(char const *path, int name);
1662

Andre Maroneze's avatar
Andre Maroneze committed
1663 1664
/*@ requires valid_pipefd: \valid(pipefd + (0 .. 1));
    ensures initialization: pipefd: \initialized(\old(pipefd) + (0 .. 1));
Andre Maroneze's avatar
Andre Maroneze committed
1665 1666 1667 1668 1669 1670 1671 1672
    ensures valid_fd0: 0 ≤ *(\old(pipefd) + 0) < 1024;
    ensures valid_fd1: 0 ≤ *(\old(pipefd) + 1) < 1024;
    ensures result_ok_or_error: \result ≡ 0 ∨ \result ≡ -1;
    assigns *(pipefd + (0 .. 1)), \result;
    assigns *(pipefd + (0 .. 1)) \from (indirect: __fc_fds[0 ..]);
    assigns \result \from (indirect: __fc_fds[0 ..]);
 */
extern int pipe(int * /*[2]*/ pipefd);
1673

Andre Maroneze's avatar
Andre Maroneze committed
1674 1675 1676 1677 1678 1679 1680 1681 1682 1683 1684 1685 1686 1687 1688
/*@ requires valid_fd: 0 ≤ fd < 1024;
    requires buf_has_room: \valid((char *)buf + (0 .. count - 1));
    ensures
      result_error_or_read_length:
        (0 ≤ \result ≤ \old(count)) ∨ \result ≡ -1;
    ensures
      initialization: buf:
        \initialized((char *)\old(buf) + (0 .. \result - 1));
    assigns __fc_fds[fd], \result, *((char *)buf + (0 .. count - 1));
    assigns __fc_fds[fd] \from __fc_fds[fd];
    assigns \result \from (indirect: __fc_fds[fd]), (indirect: count);
    assigns *((char *)buf + (0 .. count - 1))
      \from (indirect: __fc_fds[fd]), (indirect: count);
 */
extern ssize_t read(int fd, void *buf, size_t count);
1689

Andre Maroneze's avatar
Andre Maroneze committed
1690 1691 1692 1693 1694
/*@ ensures result_ok_or_error: \result ≡ 0 ∨ \result ≡ -1;
    assigns \result;
    assigns \result \from (indirect: gid);
 */
extern int setegid(gid_t gid);
1695

Andre Maroneze's avatar
Andre Maroneze committed
1696
/*@ ensures result_ok_or_error: \result ≡ 0 ∨ \result ≡ -1;
1697
    assigns \result;
Andre Maroneze's avatar
Andre Maroneze committed
1698
    assigns \result \from (indirect: uid);
1699
 */
Andre Maroneze's avatar
Andre Maroneze committed
1700
extern int seteuid(uid_t uid);
1701

Andre Maroneze's avatar
Andre Maroneze committed
1702
/*@ ensures result_ok_or_error: \result ≡ 0 ∨ \result ≡ -1;
1703
    assigns \result;
Andre Maroneze's avatar
Andre Maroneze committed
1704
    assigns \result \from (indirect: gid);
1705
 */
Andre Maroneze's avatar
Andre Maroneze committed
1706
extern int setgid(gid_t gid);
1707

Andre Maroneze's avatar
Andre Maroneze committed
1708 1709 1710
/*@ ensures result_ok_or_error: \result ≡ 0 ∨ \result ≡ -1;
    assigns \result;
    assigns \result \from (indirect: pid), (indirect: pgid);
1711
 */
Andre Maroneze's avatar
Andre Maroneze committed
1712
extern int setpgid(pid_t pid, pid_t pgid);
1713

Andre Maroneze's avatar
Andre Maroneze committed
1714 1715 1716 1717 1718
/*@ ensures result_ok_or_error: \result ≡ 0 ∨ \result ≡ -1;
    assigns \result;
    assigns \result \from (indirect: rgid), (indirect: egid);
 */
extern int setregid(gid_t rgid, gid_t egid);
1719

Andre Maroneze's avatar
Andre Maroneze committed
1720
/*@ ensures result_ok_or_error: \result ≡ 0 ∨ \result ≡ -1;
1721
    assigns \result;
Andre Maroneze's avatar
Andre Maroneze committed
1722
    assigns \result \from (indirect: ruid), (indirect: euid);
1723
 */
Andre Maroneze's avatar
Andre Maroneze committed
1724
extern int setreuid(uid_t ruid, uid_t euid);
1725

Andre Maroneze's avatar
Andre Maroneze committed
1726
/*@ ensures result_pgid_or_error: \result ≡ -1 ∨ \result ≥ 0;
1727
    assigns \result;
Andre Maroneze's avatar
Andre Maroneze committed
1728
    assigns \result \from \nothing;
1729
 */
Andre Maroneze's avatar
Andre Maroneze committed
1730
extern pid_t setsid(void);
1731

Andre Maroneze's avatar
Andre Maroneze committed
1732 1733 1734 1735 1736
/*@ ensures result_ok_or_error: \result ≡ 0 ∨ \result ≡ -1;
    assigns \result;
    assigns \result \from (indirect: uid);
 */
extern int setuid(uid_t uid);
1737

Andre Maroneze's avatar
Andre Maroneze committed
1738 1739
/*@ assigns \nothing; */
extern void sync(void);
1740 1741

/*@ assigns \result;
Andre Maroneze's avatar
Andre Maroneze committed
1742 1743
    assigns \result \from (indirect: name); */
extern long sysconf(int name);
1744

1745
char volatile __fc_ttyname[32];
Andre Maroneze's avatar
Andre Maroneze committed
1746
char volatile *__fc_p_ttyname = __fc_ttyname;
Andre Maroneze's avatar
Andre Maroneze committed
1747 1748
/*@ requires valid_fildes: 0 ≤ fildes < 1024;
    ensures
Andre Maroneze's avatar
Andre Maroneze committed
1749 1750 1751
      result_name_or_null: \result ≡ __fc_p_ttyname ∨ \result ≡ \null;
    assigns \result;
    assigns \result \from __fc_p_ttyname, (indirect: fildes);
1752
 */
Andre Maroneze's avatar
Andre Maroneze committed
1753
extern char *ttyname(int fildes);
1754

Andre Maroneze's avatar
Andre Maroneze committed
1755 1756 1757 1758 1759 1760
/*@ requires valid_string_path: valid_read_string(path);
    ensures result_ok_or_error: \result ≡ 0 ∨ \result ≡ -1;
    assigns \result;
    assigns \result \from *(path + (0 ..));
 */
extern int unlink(char const *path);
1761

Andre Maroneze's avatar
Andre Maroneze committed
1762 1763
/*@ ensures result_ok_or_error: \result ≡ 0 ∨ \result ≡ -1;
    assigns \result, Frama_C_entropy_source;
1764
    assigns \result
Andre Maroneze's avatar
Andre Maroneze committed
1765 1766
      \from (indirect: usec), (indirect: Frama_C_entropy_source);
    assigns Frama_C_entropy_source \from Frama_C_entropy_source;
1767
 */
Andre Maroneze's avatar
Andre Maroneze committed
1768
extern int usleep(useconds_t usec);
1769

Andre Maroneze's avatar
Andre Maroneze committed
1770 1771 1772 1773 1774 1775 1776 1777 1778 1779
/*@ requires valid_fd: 0 ≤ fd < 1024;
    requires buf_has_room: \valid_read((char *)buf + (0 .. count - 1));
    ensures
      result_error_or_written_bytes:
        \result ≡ -1 ∨ (0 ≤ \result ≤ \old(count));
    assigns __fc_fds[fd], \result;
    assigns __fc_fds[fd]
      \from (indirect: fd), (indirect: count), __fc_fds[fd];
    assigns \result
      \from (indirect: fd), (indirect: count), (indirect: __fc_fds[fd]);
1780
 */
Andre Maroneze's avatar
Andre Maroneze committed
1781
extern ssize_t write(int fd, void const *buf, size_t count);
1782

Andre Maroneze's avatar
Andre Maroneze committed
1783 1784 1785 1786 1787 1788 1789 1790 1791 1792 1793 1794
/*@ requires valid_ruid: \valid(ruid);
    requires valid_euid: \valid(suid);
    requires valid_suid: \valid(euid);
    ensures
      initialization: result_ok_or_error:
        (\result ≡ 0 ∧ \initialized(\old(ruid)) ∧
         \initialized(\old(euid)) ∧ \initialized(\old(suid))) ∨
        \result ≡ -1;
    assigns *ruid, *euid, *suid, \result;
    assigns *ruid \from \nothing;
    assigns *euid \from \nothing;
    assigns *suid \from \nothing;
1795
    assigns \result
Andre Maroneze's avatar
Andre Maroneze committed
1796
      \from (indirect: ruid), (indirect: euid), (indirect: suid);
1797
 */
Andre Maroneze's avatar
Andre Maroneze committed
1798
int getresuid(uid_t *ruid, uid_t *euid, uid_t *suid);
1799

Andre Maroneze's avatar
Andre Maroneze committed
1800 1801
/*@ ensures result_ok_or_error: \result ≡ 0 ∨ \result ≡ -1;
    assigns \result;
1802
    assigns \result
Andre Maroneze's avatar
Andre Maroneze committed
1803
      \from (indirect: ruid), (indirect: euid), (indirect: suid);
1804
 */
Andre Maroneze's avatar
Andre Maroneze committed
1805
int setresuid(uid_t ruid, uid_t euid, uid_t suid);
1806

Andre Maroneze's avatar
Andre Maroneze committed
1807 1808 1809
/*@ requires valid_rgid: \valid(rgid);
    requires valid_egid: \valid(sgid);
    requires valid_sgid: \valid(egid);
Andre Maroneze's avatar
Andre Maroneze committed
1810
    ensures
Andre Maroneze's avatar
Andre Maroneze committed
1811 1812 1813 1814 1815 1816 1817 1818 1819 1820
      initialization: result_ok_or_error:
        (\result ≡ 0 ∧ \initialized(\old(rgid)) ∧
         \initialized(\old(egid)) ∧ \initialized(\old(sgid))) ∨
        \result ≡ -1;
    assigns *rgid, *egid, *sgid, \result;
    assigns *rgid \from \nothing;
    assigns *egid \from \nothing;
    assigns *sgid \from \nothing;
    assigns \result
      \from (indirect: rgid), (indirect: egid), (indirect: sgid);
Andre Maroneze's avatar
Andre Maroneze committed
1821
 */
Andre Maroneze's avatar
Andre Maroneze committed
1822
int getresgid(gid_t *rgid, gid_t *egid, gid_t *sgid);
Andre Maroneze's avatar
Andre Maroneze committed
1823

Andre Maroneze's avatar
Andre Maroneze committed
1824 1825 1826 1827 1828 1829
/*@ ensures result_ok_or_error: \result ≡ 0 ∨ \result ≡ -1;
    assigns \result;
    assigns \result
      \from (indirect: rgid), (indirect: egid), (indirect: sgid);
 */
int setresgid(gid_t rgid, gid_t egid, gid_t sgid);
1830

Andre Maroneze's avatar
Andre Maroneze committed
1831
extern char *optarg;
1832

Andre Maroneze's avatar
Andre Maroneze committed
1833
int optind;
1834

Andre Maroneze's avatar
Andre Maroneze committed
1835
extern int opterr;
1836

Andre Maroneze's avatar
Andre Maroneze committed
1837
extern int optopt;
1838

Andre Maroneze's avatar
Andre Maroneze committed
1839