This repository has been archived by the owner on Aug 2, 2022. It is now read-only.
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Prove the runtime packages in the minimal runtime. For those packages that require code that is not SPARK compatible SPARK has been turned off with a comment.
System.Parameters
cannot be SPARK but SPARK also cannot be turned off explicitly as its types could not be used in SPARK code then. InInterfaces.C
the long double has been disabled as it is not supported in SPARK.The
System.Arith64
has been proven forAdd_With_Ovflo_Check
andSubtract_With_Ovflo_Check
for the absence of runtime errors. The missing functions and the two unproven lemmas are handled in #50. Since the properties of the conversion functions rest on assumptions about the binary integer representation they have been moved to a separate package to support unit tests.