Skip to content

SMT2: skip element enumeration for non-integer-keyed array literals#9062

Open
tautschnig wants to merge 1 commit into
diffblue:developfrom
tautschnig:strata/smt2-array-literal-nonint-index
Open

SMT2: skip element enumeration for non-integer-keyed array literals#9062
tautschnig wants to merge 1 commit into
diffblue:developfrom
tautschnig:strata/smt2-array-literal-nonint-index

Conversation

@tautschnig

@tautschnig tautschnig commented Jun 18, 2026

Copy link
Copy Markdown
Collaborator

The array-constructor substitute in find_symbols enumerates element indices via from_integer(i, index_type), which is only valid for integer/bitvector index types. For arrays keyed by a non-scalar type, leave the array unconstrained (a sound over-approximation) rather than constructing an integer constant of a non-integer index type.

  • Each commit message has a non-empty body, explaining why the change was made.
  • Methods or procedures I have added are documented, following the guidelines provided in CODING_STANDARD.md.
  • n/a The feature or user visible behaviour I have added or modified has been documented in the User Guide in doc/cprover-manual/
  • Regression or unit tests are included, or existing tests cover the modified code (in this case I have detailed which ones those are in the commit message).
  • n/a My commit message includes data points confirming performance improvements (if claimed).
  • My PR is restricted to a single feature or bugfix.
  • n/a White-space or formatting changes outside the feature-related changed lines are in commits of their own.

@tautschnig tautschnig self-assigned this Jun 18, 2026
Copilot AI review requested due to automatic review settings June 18, 2026 19:59

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Note

Copilot was unable to run its full agentic suite in this review.

Adjusts SMT2 array-literal handling to avoid generating invalid index constants for arrays whose index type can’t be constructed from integers, by skipping per-element constraints in that case.

Changes:

  • Adds an index-type guard so per-element array constraints are only emitted for integer/bitvector-like index types.
  • Documents the rationale and treats non-integer-keyed arrays as unconstrained (sound over-approximation).

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment thread src/solvers/smt2/smt2_conv.cpp Outdated
Comment thread src/solvers/smt2/smt2_conv.cpp Outdated
@codecov

codecov Bot commented Jun 19, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 80.69%. Comparing base (7483d0d) to head (87d4e17).

Additional details and impacted files
@@           Coverage Diff            @@
##           develop    #9062   +/-   ##
========================================
  Coverage    80.68%   80.69%           
========================================
  Files         1714     1714           
  Lines       189593   189649   +56     
  Branches        73       73           
========================================
+ Hits        152979   153038   +59     
+ Misses       36614    36611    -3     

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

The array-constructor substitute in find_symbols enumerates element indices
via from_integer(i, index_type), which can build a constant only for
integer/bitvector index types and C enums. Restrict the per-element
enumeration to those types:
- integer bitvectors (signed/unsignedbv), ID_bv and ID_integer;
- ID_c_enum, and ID_c_enum_tag followed to its underlying c_enum (from_integer
  has no c_enum_tag branch, so the resolved type is used both for the guard
  and for the from_integer call in the loop).

Arrays keyed by some other domain (e.g. Strata's `Map Ref _`, a struct or
pointer key) are left unconstrained -- a sound over-approximation -- rather
than aborting in from_integer on a non-enumerable index type.

Unit tests in unit/solvers/smt2/smt2_conv.cpp cover the preserved integer
path, the now-supported c_enum_tag path (which aborts without this change),
and the skipped non-scalar (struct) path.

Co-authored-by: Kiro <kiro-agent@users.noreply.github.com>
@tautschnig tautschnig force-pushed the strata/smt2-array-literal-nonint-index branch from 6a0f304 to 87d4e17 Compare June 24, 2026 15:38
@tautschnig tautschnig assigned kroening and unassigned tautschnig Jun 24, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants