• Top
    • Documentation
    • Books
    • Boolean-reasoning
    • Projects
    • Debugging
    • Std
    • Proof-automation
    • Macro-libraries
    • ACL2
    • Interfacing-tools
    • Hardware-verification
      • Gl
      • Esim
      • Vl2014
      • Sv
      • Fgl
      • Vwsim
      • Vl
      • X86isa
        • Program-execution
        • Sdm-instruction-set-summary
        • Tlb
        • Running-linux
        • Introduction
        • Asmtest
        • X86isa-build-instructions
        • Publications
        • Contributors
        • Machine
          • X86isa-state
          • Syscalls
          • Cpuid
          • Linear-memory
            • Reasoning-about-memory-reads-and-writes
            • Wml256
            • Rml256
            • Wml512
            • Rml512
            • Rml128
            • Rml80
            • Program-location
            • Rml64
            • Wml128
            • Rml48
            • Rml32
              • Rml08
              • Rml16
              • Wml80
              • Wml64
              • Wml08
              • Byte-listp
              • Wml48
              • Parametric-memory-reads-and-writes
              • Combine-n-bytes
              • Wml32
              • Program-at
              • Wml16
              • Combine-bytes
              • Write-canonical-address-to-memory-user-exec
              • Write-canonical-address-to-memory
              • Riml64
              • Wml-size
              • Rml-size
              • Riml32
              • Riml16
              • Riml08
              • Wiml64
              • Wiml32
              • Wiml16
              • Wiml08
              • Wiml-size
              • Generate-xr-over-write-thms
              • Generate-write-fn-over-xw-thms
              • Generate-read-fn-over-xw-thms
              • Riml-size
            • Rflag-specifications
            • Characterizing-undefined-behavior
            • Top-level-memory
            • App-view
            • X86-decoder
            • Physical-memory
            • Decoding-and-spec-utils
            • Instructions
            • Register-readers-and-writers
            • X86-modes
            • Segmentation
            • Other-non-deterministic-computations
            • Environment
            • Paging
          • Implemented-opcodes
          • To-do
          • Proof-utilities
          • Peripherals
          • Model-validation
          • Modelcalls
          • Concrete-simulation-examples
          • Utils
          • Debugging-code-proofs
        • Svl
        • Rtl
      • Software-verification
      • Math
      • Testing-utilities
    • Linear-memory

    Rml32

    Signature
    (rml32 lin-addr r-x x86) → (mv * * x86)

    Definitions and Theorems

    Theorem: rb-and-rvm32

    (defthm rb-and-rvm32
      (implies (and (app-view x86)
                    (x86p x86)
                    (canonical-address-p lin-addr)
                    (canonical-address-p (+ 3 lin-addr)))
               (equal (rvm32 lin-addr x86)
                      (rb 4 lin-addr r-x x86))))

    Function: rml32

    (defun rml32 (lin-addr r-x x86)
     (declare (xargs :stobjs (x86)))
     (declare (type (signed-byte 48) lin-addr)
              (type (member :r :x) r-x))
     (declare (xargs :split-types t
                     :guard (and (canonical-address-p lin-addr)
                                 (member-eq r-x '(:r :x)))))
     (let ((__function__ 'rml32))
      (declare (ignorable __function__))
      (if
       (mbt (canonical-address-p lin-addr))
       (let* ((3+lin-addr (the (signed-byte 49)
                               (+ 3 (the (signed-byte 48) lin-addr)))))
        (if
         (mbe :logic (canonical-address-p 3+lin-addr)
              :exec (< (the (signed-byte 49) 3+lin-addr)
                       140737488355328))
         (mbe
          :logic (rb 4 lin-addr r-x x86)
          :exec
          (if (app-view x86)
              (rvm32 lin-addr x86)
           (b* (((mv flag (the (unsigned-byte 52) p-addr0)
                     x86)
                 (la-to-pa lin-addr r-x x86))
                ((when flag) (mv flag 0 x86))
                (1+lin-addr (the (signed-byte 49)
                                 (+ 1 (the (signed-byte 48) lin-addr))))
                ((mv flag (the (unsigned-byte 52) p-addr1)
                     x86)
                 (la-to-pa 1+lin-addr r-x x86))
                ((when flag) (mv flag 0 x86))
                (2+lin-addr (the (signed-byte 50)
                                 (+ 2 (the (signed-byte 48) lin-addr))))
                ((mv flag (the (unsigned-byte 52) p-addr2)
                     x86)
                 (la-to-pa 2+lin-addr r-x x86))
                ((when flag) (mv flag 0 x86))
                (3+lin-addr (the (signed-byte 51)
                                 (+ 3 (the (signed-byte 48) lin-addr))))
                ((mv flag (the (unsigned-byte 52) p-addr3)
                     x86)
                 (la-to-pa 3+lin-addr r-x x86))
                ((when flag) (mv flag 0 x86))
                (byte0 (the (unsigned-byte 8)
                            (memi p-addr0 x86)))
                (byte1 (the (unsigned-byte 8)
                            (memi p-addr1 x86)))
                (byte2 (the (unsigned-byte 8)
                            (memi p-addr2 x86)))
                (byte3 (the (unsigned-byte 8)
                            (memi p-addr3 x86)))
                ((the (unsigned-byte 16) word1)
                 (logior byte2
                         (the (unsigned-byte 16) (ash byte3 8))))
                ((the (unsigned-byte 24) high-24)
                 (logior byte1
                         (the (unsigned-byte 24) (ash word1 8))))
                ((the (unsigned-byte 32) dword)
                 (logior byte0
                         (the (unsigned-byte 32)
                              (ash high-24 8)))))
             (mv nil dword x86))))
         (mv 'rml32 0 x86)))
       (mv 'rml32 0 x86))))

    Theorem: n32p-mv-nth-1-rml32

    (defthm n32p-mv-nth-1-rml32
     (unsigned-byte-p 32 (mv-nth 1 (rml32 lin-addr r-x x86)))
     :rule-classes
     (:rewrite
      (:type-prescription
          :corollary (natp (mv-nth 1 (rml32 lin-addr r-x x86)))
          :hints
          (("Goal" :in-theory '(unsigned-byte-p integer-range-p natp))))
      (:linear
       :corollary (and (<= 0 (mv-nth 1 (rml32 lin-addr r-x x86)))
                       (< (mv-nth 1 (rml32 lin-addr r-x x86))
                          4294967296))
       :hints
       (("Goal"
            :in-theory '(unsigned-byte-p integer-range-p (:e expt)))))))

    Theorem: x86p-rml32

    (defthm x86p-rml32
      (implies (force (x86p x86))
               (x86p (mv-nth 2 (rml32 lin-addr r-x x86))))
      :rule-classes (:rewrite :type-prescription))

    Theorem: rml32-value-when-error

    (defthm rml32-value-when-error
      (implies (mv-nth 0 (rml32 lin-addr r-x x86))
               (equal (mv-nth 1 (rml32 lin-addr r-x x86))
                      0)))

    Theorem: rml32-x86-unmodified-in-app-view

    (defthm rml32-x86-unmodified-in-app-view
      (implies (app-view x86)
               (equal (mv-nth 2 (rml32 lin-addr r-x x86))
                      x86)))

    Theorem: xr-rml32-state-sys-view

    (defthm xr-rml32-state-sys-view
      (implies (and (not (equal fld :mem))
                    (not (equal fld :fault))
                    (not (equal fld :tlb)))
               (equal (xr fld index
                          (mv-nth 2 (rml32 lin-addr r-x x86)))
                      (xr fld index x86))))

    Theorem: rml32-xw-app-view

    (defthm rml32-xw-app-view
     (implies
      (and (app-view x86)
           (not (equal fld :mem))
           (not (equal fld :app-view)))
      (and (equal (mv-nth 0
                          (rml32 lin-addr r-x (xw fld index value x86)))
                  (mv-nth 0 (rml32 lin-addr r-x x86)))
           (equal (mv-nth 1
                          (rml32 lin-addr r-x (xw fld index value x86)))
                  (mv-nth 1 (rml32 lin-addr r-x x86))))))

    Theorem: rml32-xw-sys-view

    (defthm rml32-xw-sys-view
     (implies
      (and (not (app-view x86))
           (not (equal fld :fault))
           (not (equal fld :seg-visible))
           (not (equal fld :seg-hidden-base))
           (not (equal fld :seg-hidden-limit))
           (not (equal fld :seg-hidden-attr))
           (not (equal fld :mem))
           (not (equal fld :ctr))
           (not (equal fld :msr))
           (not (equal fld :rflags))
           (not (equal fld :app-view))
           (not (equal fld :marking-view))
           (not (equal fld :tlb))
           (not (equal fld :implicit-supervisor-access))
           (member-equal fld *x86-field-names-as-keywords*))
      (and (equal (mv-nth 0
                          (rml32 lin-addr r-x (xw fld index value x86)))
                  (mv-nth 0 (rml32 lin-addr r-x x86)))
           (equal (mv-nth 1
                          (rml32 lin-addr r-x (xw fld index value x86)))
                  (mv-nth 1 (rml32 lin-addr r-x x86)))
           (equal (mv-nth 2
                          (rml32 lin-addr r-x (xw fld index value x86)))
                  (xw fld index value
                      (mv-nth 2 (rml32 lin-addr r-x x86)))))))

    Theorem: rml32-xw-sys-view-rflags-not-ac

    (defthm rml32-xw-sys-view-rflags-not-ac
      (implies
           (and (not (app-view x86))
                (equal (rflagsbits->ac value)
                       (rflagsbits->ac (rflags x86))))
           (and (equal (mv-nth 0
                               (rml32 lin-addr
                                      r-x (xw :rflags nil value x86)))
                       (mv-nth 0 (rml32 lin-addr r-x x86)))
                (equal (mv-nth 1
                               (rml32 lin-addr
                                      r-x (xw :rflags nil value x86)))
                       (mv-nth 1 (rml32 lin-addr r-x x86)))
                (equal (mv-nth 2
                               (rml32 lin-addr
                                      r-x (xw :rflags nil value x86)))
                       (xw :rflags nil value
                           (mv-nth 2 (rml32 lin-addr r-x x86)))))))