Program verification method, device and equipment and computer readable storage medium
Through the verification of the to-test formula of the iterative program in parallel, multiple verification threads are used to verify multiple candidate values, which solves the problem of inefficient verification of iterative program in the prior art and realizes a more efficient verification process.
Patent Information
- Application Number
- CN202411976040.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-30
- Publication Date
- 2025-05-06
- Estimated Expiration
- 2044-12-30
AI Technical Summary
The prior art is inefficient in the automated verification of iterative programs, making it difficult to perform the solution and verification process in parallel, resulting in a long verification time.
By obtaining the to-test formula of the target program, multiple candidate values of the first type of variable are determined and allocated to multiple verification threads, parallel verification logical expressions are implemented. When verification fails, get the value of the second type of variable that makes the logical expression invalid, and update the current solution rule until the verification is successful.
Parallel verification of iterative programs is realized, which significantly improves verification efficiency and reduces verification time and resource overhead.
Smart Images

Figure CN119938486A_ABST
Abstract
Description
Technical Field
[0001] The present application belongs to the technical field of computer program verification, and in particular, relates to a program verification method, apparatus, device and computer-readable storage medium. Background Art
[0002] In the field of computer program verification, program automated verification has become a key link to ensure program availability and security. In program automated verification, Satisfiablity Module Theories (SMT) is widely used as a powerful formal verification method. However, for complex programs, especially iterative programs, a single SMT problem is difficult to meet the verification requirements. Therefore, Exists-Forall Satisfiabilty Module Theories (EFSMT) was born as an extension method of SMT.
[0003] At present, the automated verification of iterative programs often constructs EFSMT problems (or EFSMT formulas) based on the program source code to accurately describe the program state, and solves the EFSMT problems through solvers. However, solving EFSMT problems often involves first guessing the possible solutions of the formula, then verifying it, and then updating the solution based on the verification results. However, these steps are closely linked, and the subsequent steps are highly dependent on the results of the previous steps, making it difficult to perform this process in parallel. It often takes a lot of time to solve in order to verify the program, and the efficiency of automated program verification is low.
[0004] Therefore, how to improve the verification efficiency of iterative programs has become a technical problem that needs to be solved urgently. Summary of the invention
[0005] The embodiments of the present application provide a program verification method, apparatus, device, and computer-readable storage medium, which can solve the problem of how to improve the verification efficiency of iterative programs.
[0006] In a first aspect, an embodiment of the present application provides a method for verifying a program, including:
[0007] Obtain the formula to be verified corresponding to the target program, the formula to be verified includes the first-category variables, the second-category variables, and a logical expression, the logical expression represents the condition that the second-category variables should satisfy when the first-category variables are known, and the target program corresponds to the current solution rule;
[0008] Based on the current solution rule and the formula to be tested, multiple candidate values corresponding to the first type of variables are determined;
[0009] Assign each candidate value to an idle verification thread in a thread pool, where the thread pool includes multiple verification threads, each verification thread is used to verify the logical expression according to the assigned candidate value;
[0010] Get the verification result of each verification thread on the logical expression;
[0011] When at least one verification result is a verification failure, obtaining a value of at least one second-category variable that makes the logical expression invalid;
[0012] Based on the value of each second-category variable, the current solution rule is updated to update multiple candidate values until at least one verification result is successful, and the target program is verified based on the target candidate value, and the target candidate value is the candidate value whose corresponding verification result is successful among the updated multiple candidate values.
[0013] In some embodiments, obtaining a formula to be verified corresponding to the target program includes:
[0014] Get the source code corresponding to the target program;
[0015] According to the source code, parse the loop invariant corresponding to the target program;
[0016] Construct bit vector constraint formula for loop invariant;
[0017] Based on the bit vector constraint formula, the loop invariant is transformed into an existence-universal satisfiability modulo theory formula, and the existence-universal satisfiability modulo theory formula is used as the formula to be verified.
[0018] In some embodiments, the loop invariant includes a first initial variable and a second initial variable, and constructing a bit vector constraint formula for the loop invariant includes:
[0019] The first initial variable is converted into a bit vector form to obtain a first type variable;
[0020] The second initial variable is converted into a bit vector form to obtain a second type of variable;
[0021] Analyzing the logic operation between the first initial variable and the first initial variable in the target program, the logic operation includes at least one of an arithmetic operation, a bit operation, a conditional judgment operation or a comparison operation;
[0022] A bit vector constraint formula is constructed based on first-class variables, second-class variables, and logical operations.
[0023] In some embodiments, the method further comprises:
[0024] In the case where there is at least one verification result that is successful, the target program is verified based on a candidate value whose corresponding verification result is successful among the multiple candidate values.
[0025] In some embodiments, based on the value of each second-category variable, the current solution rule is updated, including:
[0026] Determine the current value range of the first category variable according to the value of each second category variable and the logical expression;
[0027] Update the current solution rules according to the current value range.
[0028] In some embodiments, the first type of variable is a bit vector including at least one data bit, and based on the current solution rule and the formula to be verified, multiple candidate values of the first type of variable are determined, including:
[0029] Determine the initial value range of the first-category variable according to the total number of data bits in the first-category variable;
[0030] According to the current solution rule and the formula to be tested, multiple candidate values of the first category variables are determined from the initial value range.
[0031] In a second aspect, an embodiment of the present application provides a program verification device, including:
[0032] A first acquisition module is used to acquire a formula to be verified corresponding to the target program, the formula to be verified includes first-category variables, second-category variables, and a logical expression, the logical expression represents a condition that the second-category variables should satisfy when the first-category variables are known, and the target program corresponds to the current solution rule;
[0033] A determination module, used to determine multiple candidate values corresponding to the first type of variables based on the current solution rule and the formula to be verified;
[0034] An allocation module, used to allocate each candidate value to an idle verification thread in a thread pool, wherein the thread pool includes multiple verification threads, and each verification thread is used to verify a logical expression according to the allocated candidate value;
[0035] The second acquisition module is used to obtain the verification result of each verification thread on the logical expression;
[0036] A third acquisition module is used to acquire the value of at least one second-category variable that makes the logical expression invalid when at least one verification result is a verification failure;
[0037] An update module is used to update the current solution rules based on the value of each second-category variable to update multiple candidate values until at least one verification result is successful, and verify the target program based on the target candidate value. The target candidate value is the candidate value whose corresponding verification result is successful among the multiple candidate values after update.
[0038] In a third aspect, an embodiment of the present application provides an electronic device, comprising: a processor, a memory, and a computer program stored in the memory and executable on the processor; when the processor executes the computer program, the electronic device implements a program verification method as in any one of the embodiments in the first aspect.
[0039] In a fourth aspect, an embodiment of the present application provides a computer-readable storage medium, which stores a computer program. When the computer program is executed by a processor, it implements a verification method for the program in any one of the embodiments in the first aspect.
[0040] In a fifth aspect, an embodiment of the present application provides a computer program product, including a computer program. When the computer program is run, the verification method of the program in any one of the embodiments in the first aspect is executed.
[0041] Compared with the prior art, the embodiments of the present invention have the following beneficial effects:
[0042] Based on the current solution rules and the formula to be tested corresponding to the target program, multiple candidate values corresponding to the first type of variables are determined, and each candidate value is assigned to an idle verification thread in the thread pool, so that each verification thread verifies the logical expression in the formula to be tested for each assigned candidate value. The verification of the logical expressions in the formula to be tested in parallel based on multiple verification threads is realized, which speeds up the verification efficiency of the logical expressions. Therefore, the verification results of multiple verification threads for the logical expression can be obtained at one time. In the case where there is at least one verification result that the verification fails, the values of all the second type of variables that make the logical expression invalid under the verified candidate values can be obtained to update the current solution rules. There is no need to verify the candidate values and update the solution rules one by one as in the traditional solution, and the parallelization of the solution process of the formula to be tested corresponding to the target program, such as the EFSMT problem corresponding to the iterative program, is realized, which improves the efficiency of program automatic verification. BRIEF DESCRIPTION OF THE DRAWINGS
[0043] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.
[0044] Figure 1 It is a flowchart of a method for verifying a program provided in an embodiment of the present application;
[0045] Figure 2 It is a schematic diagram of a process for verifying an iterative program in an application scenario of an embodiment of the present application;
[0046] Figure 3 It is a flowchart of verifying an iterative program based on multiple threads in an application scenario of an embodiment of the present application;
[0047] Figure 4 It is a flowchart of another program verification method provided in an embodiment of the present application;
[0048] Figure 5 It is a structural schematic diagram of an electronic device provided in an embodiment of the present application;
[0049] Figure 6 It is a structural diagram of a program verification device provided in one embodiment of the present application. DETAILED DESCRIPTION
[0050] In the following description, specific details such as specific system structures, technologies, etc. are provided for the purpose of illustration rather than limitation, so as to provide a thorough understanding of the embodiments of the present application. However, it should be clear to those skilled in the art that the present application may also be implemented in other embodiments without these specific details. In other cases, detailed descriptions of well-known systems, devices, circuits, and methods are omitted to prevent unnecessary details from obstructing the description of the present application.
[0051] It should be understood that when used in the present specification and the appended claims, the term "comprising" indicates the presence of described features, wholes, steps, operations, elements and / or components, but does not exclude the presence or addition of one or more other features, wholes, steps, operations, elements, components and / or combinations thereof.
[0052] It should also be understood that the term “and / or” used in the specification and appended claims refers to any and all possible combinations of one or more of the associated listed items, and includes these combinations.
[0053] As used in the specification and appended claims of this application, the term "if" can be interpreted as "when" or "uponce" or "in response to determining" or "in response to detecting", depending on the context. Similarly, the phrase "if it is determined" or "if [described condition or event] is detected" can be interpreted as meaning "uponce it is determined" or "in response to determining" or "uponce [described condition or event] is detected" or "in response to detecting [described condition or event]", depending on the context.
[0054] In addition, in the description of the present application specification and the appended claims, the terms "first", "second", "third", etc. are only used to distinguish the descriptions and cannot be understood as indicating or implying relative importance.
[0055] References to "one embodiment" or "some embodiments" etc. described in the specification of this application mean that one or more embodiments of the present application include specific features, structures or characteristics described in conjunction with the embodiment. Therefore, the statements "in one embodiment", "in some embodiments", "in some other embodiments", "in some other embodiments", etc. that appear in different places in this specification do not necessarily refer to the same embodiment, but mean "one or more but not all embodiments", unless otherwise specifically emphasized in other ways. The terms "including", "comprising", "having" and their variations all mean "including but not limited to", unless otherwise specifically emphasized in other ways.
[0056] When automatically verifying a program, an SMT problem can be constructed for the program problem to be verified. The SMT problem can use data types such as integers, floating-point numbers, arrays, bit vectors, and corresponding algebraic operations to form logical formulas to accurately describe the program state, and obtain important information such as the program's running properties or program defects by solving the satisfiability of the logical formula.
[0057] Program problems that need to be verified for complex programs, such as automated planning or multi-objective optimization, can be modeled as EFSMT problems. Program verification for iterative programs often requires verification of loop invariants, which often contain constraints including existential quantifiers and universal quantifiers due to the uncertainty of the number of loops. In this way, EFSMT problems can also be constructed for iterative programs for solution.
[0058] For the EFSMT problem, a relatively novel approach is to use algorithms in the field of program synthesis, such as Counterexample Guilded Inductive Synthesis (CEGIS) to solve it. The CEGIS method decomposes the synthesis process of a specific goal into two stages: generation and verification. In the generation stage, a set of candidate solutions is obtained through certain rules (at the beginning of the algorithm, such rules may not exist temporarily, and at this time, arbitrary solutions are generated). In the verification stage, the correctness of each solution in this set of candidate solutions is verified by finding counterexamples. If it is found that there is no counterexample, the candidate solution obtained in the generation stage is a correct solution, and the program synthesis is successful. Otherwise, we record the counterexample, extract the properties of the problem from the counterexample, integrate them into the rules for generating candidate solutions, and then restart the generation process.
[0059] At present, when solving the EFSMT problem using the CEGIS method, it is often necessary to first generate candidate solutions for variables related to the existential quantifier of the EFSMT problem based on the CEGIS method, and then verify whether the variables and conditions related to the universal quantifier in the EFSMT problem are established based on the candidate solutions (that is, verify the satisfiability of the problem). If the verification result is that the problem is unsatisfiable, the generation rules of the candidate solutions are updated based on the counterexamples found, and a candidate solution is regenerated based on the updated generation rules. The above process is repeated until the value of the existential variable that can satisfy the EFSMT problem is found. The existential variable is each variable related to the existential quantifier of the EFSMT problem. However, this method is highly dependent on the results generated between each step, and it is not possible to perform parallel solutions to improve the solution efficiency, resulting in low program verification efficiency.
[0060] In response to the above problems, a program verification method, apparatus, device and computer-readable storage medium are proposed in an embodiment of the present application. By distributing multiple candidate values corresponding to the first type of variables in the formula to be verified (for example, variables related to existential quantifiers in the EFSMT formula) to multiple verification threads, the logical expressions in the formula to be verified are verified in parallel by multiple verification threads based on the candidate values obtained by each of them. When the verification result of each verification thread is a verification failure, the values of the second type of variables generated by all the verification threads that failed the verification (for example, variables related to universal quantifiers in the EFSMT formula) are obtained at one time, and the current solution rules are updated to speed up the convergence speed of the candidate values, so as to realize parallel processing of multiple candidate values, reduce the time and space resource overhead of iterative structure program verification, and help improve the efficiency of program verification.
[0061] The following describes a method for verifying the program in the embodiment of the present application through a specific example.
[0062] Figure 1is a flowchart of a method for verifying a program provided in an embodiment of the present application, such as Figure 1 As shown, the method comprises the following steps:
[0063] Step S101, obtaining a formula to be verified corresponding to the target program.
[0064] The program verification method in the embodiment of the present application can be executed by electronic devices such as servers, desktop computers, laptop computers, ultra-mobile personal computers (UMPCs), personal digital assistants (PDAs), etc. The embodiment of the present application does not impose any restrictions on the specific types of electronic devices.
[0065] In this embodiment, the formula to be tested includes first-category variables, second-category variables, and logical expressions. The logical expressions represent conditions that the second-category variables should satisfy when the first-category variables are known, and the target program corresponds to the current solution rule.
[0066] The formula to be verified can be a formula corresponding to the program problem to be verified (also called program property) of the target program, for example, an EFSMT formula or an EFSMT formula with a bit vector (BV) constraint. In the embodiment of the present application, an EFSMT formula with a BV constraint is used as an example. and universal quantifiers The first type of variable can be the variable in the formula to be tested. The second type of variable can be a variable associated with Associated variables (also called global variables).
[0067] In an example, the formula to be tested may be an EFSMT formula with a BV constraint, which can be expressed as Among them, X is the first type of variable, Y is the second type of variable, is a logical expression, and P(X,Y) represents the constraints modeled by the program properties of the target program. It is worth noting that both the first-class variables and the second-class variables are variables in the form of bit vectors.
[0068] The program problem to be verified of the target program may be a loop invariant of the target program, a program termination verification problem, or a program security verification problem. In the embodiment of the present application, loop invariants are taken as an example. The target program may be an iterative program.
[0069] In an example, the structure of the target program may be as shown in the following code: while(condition(condition)){… / / loop body(code body)}.
[0070] When automatically verifying a target program, an electronic device may convert the source code of the target program into a formula to be verified.
[0071] In one implementation, obtaining the formula to be verified corresponding to the target program includes the following steps (1) to (4):
[0072] Step (1), obtain the source code corresponding to the target program.
[0073] The electronic device may obtain the source code corresponding to the target program input by the user, or when detecting an automatic verification operation on the target program, read the source code corresponding to the target program from a preset storage location. The specific obtaining form is not specifically limited in the embodiments of the present application.
[0074] Step (2), parse out the loop invariant corresponding to the target program according to the source code.
[0075] The electronic device can compile the source code into a formal language through a compiler, and parse out the loop structure (such as for loop or while loop, etc.) in the target program based on the formal language; for the loop structure, parse the variables involved in the loop structure and the logical operations between the variables (such as conditional judgment statements such as if or else, and function calls, etc.), and find the conditions that are always true at the beginning and end of the loop iteration, that is, the loop invariant.
[0076] In an example, a certain loop structure in the target program is a while loop, such as while(i<n){x=x+1;i=i+1;}, the variables involved are i and x. Assuming that initially x==0 and i==0, then the electronic device parses that x==i at the beginning and end of the loop iteration, and it can be determined that the loop invariant is i≤m and x==i.
[0077] Step (3), construct a bit-vector constraint formula for the loop invariant.
[0078] For the variables in the loop invariant, the electronic device can convert each variable into a bit vector according to the data type and value range of each variable, and convert the logical operations between the variables in the loop invariant into bit-vector operations to obtain the bit-vector representation corresponding to the loop invariant, thereby obtaining the bit-vector constraint formula. Referring to the above example, assuming that the variable i is an integer variable and its value range is from 0 to 255, it can be represented as an 8-bit bit vector I=i7i6i5i4i3i2i1i0. The bit-vector representation of the loop invariant x==i is I≤M∧X==I, where "==" is equality in bit-vector operations, "∧" is logical AND in bit-vector operations, X is the bit-vector form of the variable x, and M is the bit-vector form of the variable m. Then the bit-vector constraint formula includes I≤M∧X==I.
[0079] In one implementation, the loop invariant includes a first initial variable and a second initial variable. Constructing a bit-vector constraint formula for the loop invariant includes:
[0080] Convert the first initial variable into the form of a bit vector to obtain a first type of variable;
[0081] Convert the second initial variable into the form of a bit vector to obtain a second type of variable;
[0082] Parse the logical operation between the first initial variable and the first initial variable in the target program. The logical operation includes at least one of arithmetic operations, bit operations, conditional judgment operations, or comparison operations;
[0083] Construct a bit-vector constraint formula according to the first type of variable, the second type of variable, the loop invariant, and the logical operation.
[0084] Combined with the above, after the electronic device converts the variables (the first initial variable and the second initial variable) in the loop invariant into the form of bit vectors, it will also parse out the logical operation, initial value, and post-condition of the variables in the loop invariant in the target program during each loop iteration based on the formal language; convert the corresponding logical operation, initial value, and post-condition of the variables in the target program into the corresponding bit-vector representations respectively. The obtained bit-vector representations after conversion and the bit-vector table corresponding to the loop invariant form a bit-vector constraint formula. It should be noted that the post-condition refers to the condition that should be satisfied when the target program executes to a specific stage (usually the end of execution).
[0085] Continuing to refer to the above example, in while(i<n){x=x+1;i=i+1;}, the logical operations involved in the variables x and i (x and i are the first initial variables) are x=x+1 and i=i+1 respectively. Assuming that initially x==0 and i==0, the loop maintenance condition is i<n, the loop invariant is i≤m and x==i, and the post-condition to be verified is i>=n and x==i. Then, after converting i≤m and x==i, i>=n and x==i, x==0, i==0, x=x+1, i=i+1, and i<n into the corresponding bit-vector representations respectively, we can obtain I<N, I≤M∧X=I, I≥N∧X=I, X==0, I==0, X’=X+1, I’=I+1, and I<N, where X’ is the bit vector after X is incremented by 1, I’ is the bit vector after I is incremented by 1, “+” is the bit-vector addition, M represents the bit vector corresponding to m, and N represents the bit vector corresponding to n. Then, the bit-vector constraint formula corresponding to the loop invariant i≤m and x==i can include I<N, I≤M∧X=I, I≥N∧X=I, X==0, I==0, X’=X+1, I’=I+1, and I<N.
[0086] In the above technical solution, by converting the variables in the loop invariant into the form of bit vectors and parsing the logical operation operations of the variables involved in the loop invariant in the target program, a bit vector constraint formula is constructed based on the first type of variables, the second type of variables, the loop invariant, and the logical operation operations, realizing the construction of the bit vector constraint of the loop invariant of the target program, providing a reliable data basis for the subsequent verification of the target program, and thus improving the accuracy of program verification.
[0087] Step (4), based on the bit vector constraint formula, convert the loop invariant into an existential-universal satisfiability modulo theory (EFSMT) formula, and the existential-universal satisfiability modulo theory formula is used as the formula to be verified.
[0088] Based on the bit vector constraint formula, the electronic device can respectively construct a bit vector formula for the existential quantifier part and a bit vector formula for the universal quantifier part for the loop invariant, and combine the two to obtain an existential-universal satisfiability modulo theory formula. For the bit vector formula of the existential quantifier part, the initial state and the postcondition of the relevant variables in the loop structure of the target program are often represented by combining the bit vector form with the existential quantifier. For the bit vector formula of the universal quantifier part, for the loop result of the target program, the situation of each loop iteration is often represented by combining the bit vector form with the universal quantifier.
[0089] Continuing to refer to the above example, for the bit vector formula of the existential quantifier part, the bit vector formula corresponding to the initial state can be X = 0 ∧ I = 0, and the bit vector formula corresponding to the postcondition can be I ≥ N ∧ X = I. For the bit vector formula of the universal quantifier part, for each iteration sequence, there is Here, it means that in each iteration (as long as i is less than n), the loop invariant I ≤ M ∧ X = I holds, and i and x are updated according to the operations in the loop structure (incremented by 1 each time). The EFSMT formula obtained by combining the two can be:
[0090]
[0091] X’ = X + 1)) → (I’ ≤ M ∧ X’ = I’) ∧ ((I ≤ M ∧ X = I) ∧!(I < N)) → (I ≥ N ∧ X = I)), it can be understood that the first type of variables in this formula includes M, the second type of variables includes X, X’, I, and I’, and the logical expressions include
[0092] In the above technical solution, after obtaining the loop invariant corresponding to the target program, the bit vector is introduced to construct the loop invariant to construct the bit vector constraint formula, and then based on the bit vector constraint formula, the loop invariant is converted into the existence universal satisfiability modulo theory formula to obtain the formula to be verified. The loop inequality problem to be verified by the target program is converted into an EFSMT formula with a bit vector constraint, and the variables in the target program can be accurately represented by the bit vector. The underlying operation of the data in the target program is simulated by the bit vector operation, and the data storage and operation in the target program are finally processed based on the bit vector, so that the final formula to be verified is more in line with the compilation language of the target program. The EFSMT formula can be applied to complex loop structures. The bit vector and the EFSMT formula can accurately reflect the loop invariant and accurately describe the loop behavior of the target program. Thereby improving the accuracy of subsequent verification of the target program.
[0093] Step S102, based on the current solution rule and the formula to be verified, determine multiple candidate values corresponding to the first type of variables.
[0094] The electronic device can analyze the formula to be tested, and generate multiple candidate values corresponding to the first type of variables based on the CEGIS algorithm and the current solution rules.
[0095] Step S103, assigning each candidate value to an idle verification thread in a thread pool, wherein the thread pool includes a plurality of verification threads, and each verification thread is used to verify the logical expression according to the assigned candidate value.
[0096] When the electronic device detects that there are idle verification threads in the thread pool, for each idle verification thread, an unallocated subsequent value is extracted from a plurality of candidate values and allocated to the verification thread.
[0097] The electronic device can monitor the idle verification threads in the thread pool through the thread pool, and issue verification tasks to each idle verification thread, so that each idle verification thread can extract the remaining candidate values from multiple candidate values based on the verification task to verify the logical expression. While verifying the logical expression through multiple candidate values in parallel, it also realizes the timely calling of idle verification threads, dynamically adjusts task allocation, and makes full use of computing resources.
[0098] In one implementation, the electronic device may store multiple candidate values corresponding to the first category of variables in a shared message queue, and start multiple verification threads, uniformly manage the verification threads through a thread pool, and set each verification thread to independently extract different candidate values from the shared message queue, and verify the logical expression in the formula to be verified based on the candidate values.
[0099] In one implementation, each verification thread verifies the logical expression according to each assigned candidate value, including that each verification thread substitutes the assigned candidate value into the logical expression, calls a Boolean Satisfiability Problem (SAT) solver to verify whether the logical expression holds; if so, determines that the verification result of the logical expression is a successful verification; if not, determines that the verification result of the logical expression is a failed verification, and outputs the value of the second-category variable that makes the logical expression invalid.
[0100] Step S104, obtaining the verification result of each verification thread on the logical expression.
[0101] After each verification thread completes the verification of the logical expression, it will store the corresponding verification result in the shared memory, and the electronic device can read the verification result of the logical expression of each verification thread from the shared content.
[0102] Step S105 : when there is at least one verification result indicating that the verification fails, obtaining the value of at least one second-category variable that makes the logical expression invalid.
[0103] After each verification thread completes the verification of the logical expression, if it determines that the verification result is a verification failure, it will generate a value of the second-category variable that makes the logical expression invalid, and associate the value with the verification result and the current candidate value and store it in a shared memory. The electronic device can read the values of all second-category variables that make the logical expression invalid from the shared memory.
[0104] Step S106, based on the value of each second-category variable, update the current solution rule to update multiple candidate values until there is at least one verification result that is successful, and verify the target program based on the target candidate value.
[0105] In this embodiment, the target candidate value is a candidate value whose corresponding verification result is a successfully verified candidate value among the updated multiple candidate values.
[0106] The electronic device can obtain the candidate values corresponding to each verification result that fails verification and the values of the second type of variables, use the candidate values and the values of the second type of variables as counterexamples, analyze the characteristics of the counterexamples, and update the current solution rules according to the properties of the bit vector constraints. For example, if the counterexample shows that when certain bits of are specific values, the logical expression does not hold, then when updating the assignment of, you can consider changing the corresponding bits to avoid this situation.
[0107] For another example, the formula to be tested is The multiple candidate values corresponding to J include J=1 and J=2. The two verification threads verify the logical expressions for J=1 and J=2 respectively. When it is found that the logical expression is not true when Q=0 and Q=1 respectively, the electronic device can obtain counterexamples (J=1, Q=0) and (J=2, Q=1). The electronic device can adopt certain generalization steps to obtain constraints on J. For example, directly substitute two counterexamples to obtain J<=0 and J<=1, and then perform a logical AND operation to obtain the generalized constraint J<=0. The current solution rule can be updated to J<=0. When generating candidate values later, the electronic device determines the candidate value of J from the range of J<=0.
[0108] After updating the current solution rule, the electronic device will return to step S102, except that at this time the electronic device determines multiple candidate values corresponding to the first type of variable based on the updated current solution rule, thereby updating multiple candidate values, and repeating the above steps until at least one verification result is successful. At this time, for the updated multiple candidate values, the electronic device will find the candidate value whose corresponding verification result is successful, and analyze the candidate value to complete the verification of the program problem to be verified for the target program. It can be understood that when there is at least one verification result that is successful, it means that the candidate value that satisfies the formula to be verified has been found, and at this time the electronic device can control all verification threads to suspend the verification of the logical expression.
[0109] In one implementation, the method further includes: when at least one verification result is successful verification, verifying the target program based on a candidate value whose corresponding verification result is successful verification among multiple candidate values. When at least one verification result is successful verification, it means that at this time, all the second-category variables under a certain candidate value make the logical expression valid. The electronic device can find the candidate value among multiple candidate values and verify the target program based on the candidate value.
[0110] In one implementation, based on the value of each second-category variable, updating the current solution rule includes: determining the current value range of the first-category variable based on the value of each second-category variable and the logical expression; and updating the current solution rule based on the current value range. After the electronic device determines the current value range of the first-category variable based on the value of each second-category variable and the logical expression, it can update the current solution rule based on the current value range, so that subsequent candidate values are determined and limited within the current value range.
[0111] In one application scenario, combined with Figure 2 as well as Figure 3, taking the target program as an iterative program as an example, the electronic device obtains the program problem to be verified of the iterative program (that is, the program verification problem of the iterative structure) and converts it into a loop invariant. The loop invariant verification aims to determine whether a certain logical property φ is always established before entering the loop and after each loop iteration. This problem is modeled as an EFSMT problem with a bit vector (BV) constraint. The specific steps are as follows:
[0112] Determine the storage units (such as variables and memory states) involved in the loop structure of the iterative program and their update rules;
[0113] The bit vector (BV) theory is used to model the numerical state of variables. For example, the change of variable x in the loop is represented as BV(x)→BV(x'), and the loop condition and state transformation relationship are defined based on the update rule using the bit vector theory; the loop invariant verification problem is formalized as an EFSMT problem based on the bit vector, and the EFSMT problem with BV constraints is obtained, that is, Figure 2 The satisfiability of existential-universal quantifier constraints in modulo theory.
[0114] Electronic devices can be Figure 3 The daemon thread in the CEGIS method solves the existing variable (an example of the first type of variable) in the EFSMT problem (that is, based on the current solution rule and the formula to be verified, multiple candidate values corresponding to the first type of variable are determined), and the candidate solution of the existing variable is obtained based on the candidate solution generation rule, and it is checked whether it satisfies the relevant constraints in the EFSMT problem. If it is unsatisfiable (UNSAT), the candidate solution is re-obtained. If it is satisfied ( Figure 3 denoted by SAT in the example), a set of candidate solutions can be obtained (an example of multiple candidate values of the first type of variables), and multiple independent verification threads can be started ( Figure 3 Each verification thread independently extracts different candidate solutions (an example of a candidate value of the first type of variable) from the candidate solution set to verify the universal quantifier part of the EFSMT problem. An example of a logical expression) is the satisfiability of
[0115] When a verification thread determines that there is a counterexample y′, which makes P(s,y′) invalid (not valid means Figure 3 , then y′ is recorded as a counterexample (an example of the value of the second type variable that makes the logical expression invalid), and the verification is determined to have failed. The recorded counterexample will be shared with other threads (i.e., the daemon thread), so that when each verification thread fails to verify, other threads can extract the properties of multiple counterexamples through logical formula operations and dynamically update the candidate solution generation rules. Thus, the candidate solution set (i.e., Figure 3Update shared solution set in the above formula) to reduce the size of candidate solution set and achieve Figure 2 The steps of solving the solution in parallel are solved to improve the overall iteration efficiency and accelerate the convergence speed of the candidate solution set. Thus, the solution in the final candidate solution set is analyzed, the iterative program is verified, and the verification result of the original problem of the iterative program (circular inequality in this application scenario) is obtained.
[0116] A multi-threaded parallel solution strategy is implemented, which significantly reduces the time required to solve the EFSMT problem. The BV theory is used to model the EFSMT problem with BV constraints, which can more accurately describe the program state and properties and reduce misjudgments in verification. The solution set sharing and synchronization mechanism is adopted to reduce redundant calculations between threads, reduce memory usage and computing resource consumption.
[0117] In an embodiment of the present application, based on the current solution rules and the formula to be tested corresponding to the target program, multiple candidate values corresponding to the first type of variables are determined, and the multiple candidate values are assigned to multiple verification threads, so that each verification thread verifies the logical expression in the formula to be tested for each candidate value assigned. The purpose of verifying each candidate value of the first type of variables in the formula to be tested in parallel is achieved, and the efficiency of verifying the logical expression is accelerated. Thus, the verification results of multiple verification threads for the logical expression can be obtained at one time. In the case where there is at least one verification result that the verification fails, the values of all the second type of variables that make the logical expression invalid under the verified candidate values can be obtained to update the current solution rules. There is no need to verify the candidate values one by one and update the solution rules as in the traditional solution, and the parallelization of the formula to be tested corresponding to the target program, such as the EFSMT problem solving process corresponding to the iterative program, is achieved, thereby improving the efficiency of program automation verification.
[0118] Figure 4 is a flow chart of another method for verifying a program provided in an embodiment of the present application, such as Figure 4 The method shown comprises the following steps:
[0119] Step S201, obtaining the formula to be verified corresponding to the target program.
[0120] Step S201 can be found in detail. Figure 1 Step S101 in the illustrated embodiment is not described in detail here.
[0121] In one implementation, based on the current solution rule and the formula to be verified, multiple candidate values corresponding to the first type of variables are determined, including the following steps S202 to S203:
[0122] Step S202, determining the initial value range of the first category variables according to the total number of data bits in the first category variables.
[0123] In this embodiment, the first type of variable is a bit vector including at least one data bit. For example, if the first type of variable is a 4-bit bit vector, its initial value range is 0 to 15.
[0124] Step S203, determining multiple candidate values of the first type of variables from the initial value range according to the current solution rule and the formula to be verified.
[0125] The electronic device can select multiple candidate values of the first category variables from the initial value range according to the current solution rule and the formula to be verified.
[0126] Step S204, assigning each candidate value to an idle verification thread in a thread pool, wherein the thread pool includes a plurality of verification threads, and each verification thread is used to verify the logical expression according to the assigned candidate value.
[0127] Step S205, obtaining the verification result of each verification thread on the logical expression.
[0128] Step S206: when there is at least one verification result indicating verification failure, obtaining a value of at least one second-category variable that makes the logical expression invalid.
[0129] Step S207, based on the value of each second-category variable, update the current solution rule to update multiple candidate values until at least one verification result is successful, verify the target program based on the target candidate value, and the target candidate value is the candidate value whose corresponding verification result is successful among the updated multiple candidate values.
[0130] For details of steps S204 to S207, see Figure 1 Steps S103 to S106 in the illustrated embodiment are not described in detail here.
[0131] In the embodiment of the present application, the first-class variable is represented by a bit vector, and its initial value range can be determined based on the total number of data bits in the first-class variable, so as to determine multiple candidate values in the initial value range. By limiting the value range of the variable through the finite field of the bit vector, the reliability of the candidate values can be improved, thereby improving the efficiency of subsequent verification. In addition, by verifying the logical expression in parallel through multiple verification threads, the current solution rule can be updated based on the values of multiple second-class variables that make the logical expression invalid at one time, which can speed up the convergence speed of multiple candidate values of the first-class variable, thereby improving the efficiency of program automation verification.
[0132] Figure 5 This is a schematic diagram of the structure of an electronic device provided by an embodiment of the present application. Figure 5 As shown, the electronic device 6 of this embodiment includes: at least one processor 60 ( Figure 5Only one is shown in the figure) a processor, a memory 61, and a computer program 62 stored in the memory 61 and executable on the at least one processor 60, and when the processor 60 executes the computer program 62, the steps in any of the above-mentioned method embodiments are implemented.
[0133] The electronic device 6 may be a computing device such as a desktop computer, a notebook, a PDA, or a cloud server. The electronic device may include, but is not limited to, a processor 60 and a memory 61. Those skilled in the art will appreciate that Figure 5 It is only an example of the electronic device 6 and does not constitute a limitation on the electronic device 6. It may include more or fewer components than shown in the figure, or a combination of certain components, or different components. For example, it may also include input and output devices, network access devices, etc.
[0134] The processor 60 may be a central processing unit (CPU), or other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), field-programmable gate arrays (FPGA) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. A general-purpose processor may be a microprocessor or any conventional processor, etc.
[0135] In some embodiments, the memory 61 may be an internal storage unit of the electronic device 6, such as a hard disk or memory of the electronic device 6. In other embodiments, the memory 61 may also be an external storage device of the electronic device 6, such as a plug-in hard disk, a smart memory card (Smart Media Card, SMC), a secure digital (Secure Digital, SD) card, a flash card (Flash Card), etc. equipped on the electronic device 6. Further, the memory 61 may also include both an internal storage unit of the electronic device 6 and an external storage device. The memory 61 is used to store an operating system, an application program, a boot loader (BootLoader), data, and other programs, such as the program code of the computer program, etc. The memory 61 may also be used to temporarily store data that has been output or is to be output.
[0136] Corresponding to the verification method of the program described in the above embodiment, Figure 6A structural block diagram of a verification device for a program provided in an embodiment of the present application is shown. For ease of explanation, only the portion related to the embodiment of the present application is shown.
[0137] Reference Figure 6 , the device comprises:
[0138] The first acquisition module 100 is used to acquire a formula to be verified corresponding to the target program, the formula to be verified includes first-class variables, second-class variables and a logical expression, the logical expression represents the condition that the second-class variables should satisfy when the first-class variables are known, and the target program corresponds to the current solution rule;
[0139] A determination module 200, for determining a plurality of candidate values corresponding to the first type of variables based on the current solution rule and the formula to be verified;
[0140] An allocation module 300, used to allocate each candidate value to an idle verification thread in a thread pool, wherein the thread pool includes a plurality of verification threads, each verification thread being used to verify a logical expression according to the allocated candidate value;
[0141] The second acquisition module 400 is used to obtain the verification result of each verification thread on the logical expression;
[0142] A third acquisition module 500 is used to acquire the value of at least one second-category variable that makes the logical expression invalid when at least one verification result is a verification failure;
[0143] Update module 600 is used to update the current solution rules based on the value of each second-category variable to update multiple candidate values until at least one verification result is successful, and verify the target program based on the target candidate value. The target candidate value is the candidate value whose corresponding verification result is successful among the multiple candidate values after update.
[0144] In some embodiments, the first acquisition module is further used to:
[0145] Get the source code corresponding to the target program;
[0146] According to the source code, parse the loop invariant corresponding to the target program;
[0147] Construct bit vector constraint formula for loop invariant;
[0148] Based on the bit vector constraint formula, the loop invariant is transformed into an existence-universal satisfiability modulo theory formula, and the existence-universal satisfiability modulo theory formula is used as the formula to be verified.
[0149] In some embodiments, the first acquisition module is further used to:
[0150] The first initial variable is converted into a bit vector form to obtain a first type variable;
[0151] The second initial variable is converted into a bit vector form to obtain a second type of variable;
[0152] Analyzing the logic operation between the first initial variable and the first initial variable in the target program, the logic operation includes at least one of an arithmetic operation, a bit operation, a conditional judgment operation or a comparison operation;
[0153] A bit vector constraint formula is constructed based on first-class variables, second-class variables, and logical operations.
[0154] In some embodiments, the apparatus further comprises:
[0155] The verification module is used to verify the target program based on candidate values corresponding to the verification results of successful verification among multiple candidate values when there is at least one verification result of successful verification.
[0156] In some embodiments, the update module is further configured to:
[0157] Determine the current value range of the first category variable according to the value of each second category variable and the logical expression;
[0158] Update the current solution rules according to the current value range.
[0159] In some embodiments, the first type of variable is a bit vector including at least one data bit, and the determining module is further configured to:
[0160] Determine the initial value range of the first-category variable according to the total number of data bits in the first-category variable;
[0161] According to the current solution rule and the formula to be tested, multiple candidate values of the first category variables are determined from the initial value range.
[0162] It should be noted that the information interaction, execution process, etc. between the above-mentioned devices / units are based on the same concept as the method embodiment of the present application. Their specific functions and technical effects can be found in the method embodiment part and will not be repeated here.
[0163] The technicians in the relevant field can clearly understand that for the convenience and simplicity of description, only the division of the above-mentioned functional units and modules is used as an example for illustration. In practical applications, the above-mentioned function allocation can be completed by different functional units and modules as needed, that is, the internal structure of the device can be divided into different functional units or modules to complete all or part of the functions described above. The functional units and modules in the embodiment can be integrated in a processing unit, or each unit can exist physically separately, or two or more units can be integrated in one unit. The above-mentioned integrated unit can be implemented in the form of hardware or in the form of software functional units. In addition, the specific names of the functional units and modules are only for the convenience of distinguishing each other, and are not used to limit the scope of protection of this application. The specific working process of the units and modules in the above-mentioned system can refer to the corresponding process in the aforementioned method embodiment, which will not be repeated here.
[0164] An embodiment of the present application also provides a network device, which includes: at least one processor, a memory, and a computer program stored in the memory and executable on the at least one processor, wherein the processor implements the steps in any of the above-mentioned method embodiments when executing the computer program.
[0165] An embodiment of the present application further provides a computer-readable storage medium, wherein the computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the steps in the above-mentioned method embodiments can be implemented.
[0166] An embodiment of the present application provides a computer program product. When the computer program product runs on a mobile terminal, the mobile terminal can implement the steps in the above-mentioned method embodiments when executing the computer program product.
[0167] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the present application implements all or part of the processes in the above-mentioned embodiment method, which can be completed by instructing the relevant hardware through a computer program. The computer program can be stored in a computer-readable storage medium, and the computer program can implement the steps of the above-mentioned various method embodiments when executed by the processor. Among them, the computer program includes computer program code, and the computer program code can be in source code form, object code form, executable file or some intermediate form. The computer-readable medium can at least include: any entity or device that can carry the computer program code to the camera / terminal device, recording medium, computer memory, read-only memory (ROM, Read-Only Memory), random access memory (RAM, RandomAccess Memory), electric carrier signal, telecommunication signal and software distribution medium. For example, a USB flash drive, a mobile hard disk, a magnetic disk or an optical disk. In some jurisdictions, according to legislation and patent practice, computer-readable media cannot be electric carrier signals and telecommunication signals.
[0168] In the above embodiments, the description of each embodiment has its own emphasis. For parts that are not described or recorded in detail in a certain embodiment, reference can be made to the relevant descriptions of other embodiments.
[0169] Those of ordinary skill in the art will appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of this application.
[0170] In the embodiments provided in the present application, it should be understood that the disclosed devices / network equipment and methods can be implemented in other ways. For example, the device / network equipment embodiments described above are merely schematic. For example, the division of the modules or units is only a logical function division. There may be other division methods in actual implementation, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.
[0171] The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed on multiple network units. Some or all of the units may be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0172] The embodiments described above are only used to illustrate the technical solutions of the present application, rather than to limit them. Although the present application has been described in detail with reference to the aforementioned embodiments, a person skilled in the art should understand that the technical solutions described in the aforementioned embodiments may still be modified, or some of the technical features may be replaced by equivalents. Such modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the embodiments of the present application, and should all be included in the protection scope of the present application.
Claims
1. A program verification method, characterized in that: include: Obtain a formula to be verified corresponding to the target program, the formula to be verified includes a first-category variable, a second-category variable, and a logical expression, the logical expression represents a condition that the second-category variable should satisfy when the first-category variable is known, and the target program corresponds to a current solution rule; Based on the current solution rule and the formula to be tested, determine multiple candidate values corresponding to the first type of variables; Assign each of the candidate values to an idle verification thread in a thread pool, wherein the thread pool includes a plurality of verification threads, and each verification thread is used to verify the logical expression according to the assigned candidate value; Obtaining the verification result of each verification thread on the logical expression; When at least one of the verification results is a verification failure, obtaining a value of at least one variable of the second category that makes the logical expression invalid; Based on the value of each of the second-category variables, the current solution rule is updated to update the multiple candidate values until at least one of the verification results is successful, and the target program is verified based on the target candidate value, and the target candidate value is the candidate value corresponding to the verification result of successful verification among the multiple candidate values after update.
2. The method according to claim 1, characterized in that The step of obtaining the formula to be verified corresponding to the target program includes: Obtaining source code corresponding to the target program; According to the source code, a loop invariant corresponding to the target program is parsed; constructing a bit vector constraint formula for the loop invariant; Based on the bit vector constraint formula, the loop invariant is converted into an existential-universal satisfiability modulo theory formula, and the existential-universal satisfiability modulo theory formula is used as the formula to be verified.
3. The method according to claim 2, characterized in that The loop invariant includes a first initial variable and a second initial variable, and constructing a bit vector constraint formula for the loop invariant includes: Converting the first initial variable into a bit vector to obtain the first type of variable; Converting the second initial variable into a bit vector to obtain the second type of variable; parsing a logic operation between the first initial variable and the first initial variable in the target program, wherein the logic operation includes at least one of an arithmetic operation, a bit operation, a conditional judgment operation or a comparison operation; The bit vector constraint formula is constructed according to the first-category variables, the second-category variables, and the logical operation.
4. The method according to any one of claims 1 to 3, characterized in that The method further comprises: In the case that there is at least one verification result that is a successful verification, the target program is verified based on the candidate values whose corresponding verification results are successful among the multiple candidate values.
5. The method according to claim 1, characterized in that The updating of the current solution rule based on the value of each of the second-category variables comprises: Determine the current value range of the first category variables according to the value of each of the second category variables and the logical expression; Update the current solution rule according to the current value range.
6. The method according to claim 1, characterized in that The first type of variable is a bit vector including at least one data bit, and the determining of multiple candidate values of the first type of variable based on the current solution rule and the formula to be verified includes: Determining an initial value range of the first type of variables according to the total number of data bits in the first type of variables; According to the current solution rule and the formula to be tested, multiple candidate values of the first type of variables are determined from the initial value range.
7. A program verification device, characterized in that: include: A first acquisition module is used to acquire a formula to be verified corresponding to a target program, wherein the formula to be verified includes a first-category variable, a second-category variable, and a logical expression, wherein the logical expression indicates a condition that the second-category variable should satisfy when the first-category variable is known, and the target program corresponds to a current solution rule; A determination module, configured to determine a plurality of candidate values corresponding to the first type of variables based on the current solution rule and the formula to be verified; An allocation module, used for allocating each candidate value to an idle verification thread in a thread pool, wherein the thread pool includes a plurality of verification threads, and each verification thread is used for verifying the logical expression according to the allocated candidate value; A second acquisition module is used to obtain the verification result of each verification thread on the logical expression; A third acquisition module is used to acquire the value of at least one second-category variable that makes the logical expression invalid when at least one of the verification results is a verification failure; An updating module is used to update the current solution rule based on the value of each of the second-category variables to update the multiple candidate values until at least one of the verification results is successful, and verify the target program based on the target candidate value, wherein the target candidate value is the candidate value corresponding to the verification result of successful verification among the multiple candidate values after update.
8. An electronic device, characterized in that: The electronic device comprises a processor, a memory, and a computer program stored in the memory and executable on the processor, wherein when the processor executes the computer program, the electronic device implements the program verification method as described in any one of claims 1 to 6.
9. A computer-readable storage medium storing a computer program, characterized in that: When the computer program is executed by a processor, the program verification method according to any one of claims 1 to 6 is implemented.
10. A computer program product, characterized in that The invention comprises a computer program, which enables the verification method of the program according to any one of claims 1 to 6 to be executed when the computer program is executed.
Citation Information
Patent Citations
Multithreaded program output uniqueness detection and evidence generation method based on program constraint building
CN104077226A
Taint analysis method for dynamic parallel program based on symbolic computation
CN105955877A
White box verification method, system and equipment for simulating register reading and writing and medium
CN116776783A
Logic verification device, logic verification method and logic verification computer program
US20050229122A1