State in C-132 that a mut-param callee sees the pre-call value of the global its argument is rooted at - #120
Merged
Merged
Conversation
…ooted at sees the pre-call value, and pin it with two fixtures Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Amends C-132 for the ruling on almide/almide#3103 (A): a
mutargument is copied in and written back.The amendment
A callee that reads the module-level
varits argument is rooted at sees the global's pre-call value until the call returns, on every leg. This holds however the callee reaches the global:When the call returns, the write-back stores the callee's buffer into the place. That overwrites a write the callee made to the same place. A write to another part of the global is kept.
Before this, the structural wasm leg handed the callee the global's own block, so a read inside the call printed the callee's in-progress push. Native and the interpreter printed the pre-call value. The wasm leg now pays the copy only when the callee can reach the global, a compile-time over-approximation over the call graph. A callee that cannot reach it keeps the in-place call.
Evidence (paths verbatim with almide)
spec/wasm_cross/mut_param_global_callee_sees_precall.almdcovers a bare global, a field, a nested field, a reach through another fn, and a reach through a closure. Each list has spare capacity before the call, so an in-place push would be visible.spec/wasm_cross/mut_param_global_no_reach_in_place.almdcovers a callee, direct or through another fn, that cannot reach the global.Checks
ref/target/release/als-ref run … --jsongives the same stdout and exit 0 on both fixtures.fix-3103-mut-global-precall) prints identical bytes on native and wasm. Its interp oracle reports2 interp==native==wasm.check-contracts,check-contract-provenance,check-als-element-coverage,check-als-style,check-als-validation,check-links,check-gate-verificationandcheck-ratchet-separationpass.Next
Once this merges, almide advances
proofs/als-pin.txtin its own commit, then lands the implementation PR carrying the same statement.