• Top
    • Documentation
    • Books
    • Boolean-reasoning
    • Projects
    • Debugging
    • Std
    • Proof-automation
    • Macro-libraries
    • ACL2
    • Interfacing-tools
    • Hardware-verification
      • Gl
      • Esim
      • Vl2014
      • Sv
      • Fgl
      • Vwsim
      • Vl
      • X86isa
        • Program-execution
        • Sdm-instruction-set-summary
        • Tlb
        • Running-linux
        • Introduction
        • Asmtest
        • X86isa-build-instructions
        • Publications
        • Contributors
        • Machine
          • X86isa-state
          • Syscalls
          • Cpuid
          • Linear-memory
            • Reasoning-about-memory-reads-and-writes
            • Wml256
            • Rml256
            • Wml512
            • Rml512
            • Rml128
            • Rml80
            • Program-location
            • Rml64
            • Wml128
            • Rml48
            • Rml32
            • Rml08
            • Rml16
              • Wml80
              • Wml64
              • Wml08
              • Byte-listp
              • Wml48
              • Parametric-memory-reads-and-writes
              • Combine-n-bytes
              • Wml32
              • Program-at
              • Wml16
              • Combine-bytes
              • Write-canonical-address-to-memory-user-exec
              • Write-canonical-address-to-memory
              • Riml64
              • Wml-size
              • Rml-size
              • Riml32
              • Riml16
              • Riml08
              • Wiml64
              • Wiml32
              • Wiml16
              • Wiml08
              • Wiml-size
              • Generate-xr-over-write-thms
              • Generate-write-fn-over-xw-thms
              • Generate-read-fn-over-xw-thms
              • Riml-size
            • Rflag-specifications
            • Characterizing-undefined-behavior
            • Top-level-memory
            • App-view
            • X86-decoder
            • Physical-memory
            • Decoding-and-spec-utils
            • Instructions
            • Register-readers-and-writers
            • X86-modes
            • Segmentation
            • Other-non-deterministic-computations
            • Environment
            • Paging
          • Implemented-opcodes
          • To-do
          • Proof-utilities
          • Peripherals
          • Model-validation
          • Modelcalls
          • Concrete-simulation-examples
          • Utils
          • Debugging-code-proofs
        • Svl
        • Rtl
      • Software-verification
      • Math
      • Testing-utilities
    • Linear-memory

    Rml16

    Signature
    (rml16 lin-addr r-x x86) → (mv * * x86)

    Definitions and Theorems

    Theorem: rb-and-rvm16

    (defthm rb-and-rvm16
      (implies (and (app-view x86)
                    (canonical-address-p lin-addr)
                    (canonical-address-p (1+ lin-addr))
                    (x86p x86))
               (equal (rvm16 lin-addr x86)
                      (rb 2 lin-addr r-x x86))))

    Function: rml16

    (defun rml16 (lin-addr r-x x86)
     (declare (xargs :stobjs (x86)))
     (declare (type (signed-byte 48) lin-addr)
              (type (member :r :x) r-x))
     (declare (xargs :split-types t
                     :guard (and (canonical-address-p lin-addr)
                                 (member-eq r-x '(:r :x)))))
     (let ((__function__ 'rml16))
      (declare (ignorable __function__))
      (let* ((1+lin-addr (the (signed-byte 49)
                              (1+ (the (signed-byte 48) lin-addr)))))
       (if
        (mbe :logic (canonical-address-p 1+lin-addr)
             :exec (< (the (signed-byte 49) 1+lin-addr)
                      140737488355328))
        (mbe
         :logic (rb 2 lin-addr r-x x86)
         :exec
         (if (app-view x86)
             (rvm16 lin-addr x86)
          (b* (((mv flag (the (unsigned-byte 52) p-addr0)
                    x86)
                (la-to-pa lin-addr r-x x86))
               ((when flag) (mv flag 0 x86))
               (1+lin-addr (the (signed-byte 49)
                                (1+ (the (signed-byte 48) lin-addr))))
               ((mv flag (the (unsigned-byte 52) ?p-addr1)
                    x86)
                (la-to-pa 1+lin-addr r-x x86))
               ((when flag) (mv flag 0 x86))
               (byte0 (the (unsigned-byte 8)
                           (memi p-addr0 x86)))
               (byte1 (the (unsigned-byte 8)
                           (memi p-addr1 x86)))
               (word (the (unsigned-byte 16)
                          (logior (the (unsigned-byte 16) (ash byte1 8))
                                  byte0))))
            (mv nil word x86))))
        (mv 'rml16 0 x86)))))

    Theorem: n16p-mv-nth-1-rml16

    (defthm n16p-mv-nth-1-rml16
     (unsigned-byte-p 16 (mv-nth 1 (rml16 lin-addr r-x x86)))
     :rule-classes
     (:rewrite
      (:type-prescription
          :corollary (natp (mv-nth 1 (rml16 lin-addr r-x x86)))
          :hints
          (("Goal" :in-theory '(unsigned-byte-p integer-range-p natp))))
      (:linear
       :corollary (and (<= 0 (mv-nth 1 (rml16 lin-addr r-x x86)))
                       (< (mv-nth 1 (rml16 lin-addr r-x x86))
                          65536))
       :hints
       (("Goal"
            :in-theory '(unsigned-byte-p integer-range-p (:e expt)))))))

    Theorem: x86p-rml16

    (defthm x86p-rml16
      (implies (force (x86p x86))
               (x86p (mv-nth 2 (rml16 lin-addr r-x x86))))
      :rule-classes (:rewrite :type-prescription))

    Theorem: rml16-value-when-error

    (defthm rml16-value-when-error
      (implies (mv-nth 0 (rml16 lin-addr r-x x86))
               (equal (mv-nth 1 (rml16 lin-addr r-x x86))
                      0)))

    Theorem: rml16-x86-unmodified-in-app-view

    (defthm rml16-x86-unmodified-in-app-view
      (implies (app-view x86)
               (equal (mv-nth 2 (rml16 lin-addr r-x x86))
                      x86)))

    Theorem: xr-rml16-state-sys-view

    (defthm xr-rml16-state-sys-view
      (implies (and (not (equal fld :mem))
                    (not (equal fld :fault))
                    (not (equal fld :tlb)))
               (equal (xr fld index
                          (mv-nth 2 (rml16 lin-addr r-x x86)))
                      (xr fld index x86))))

    Theorem: rml16-xw-app-view

    (defthm rml16-xw-app-view
     (implies
      (and (app-view x86)
           (not (equal fld :mem))
           (not (equal fld :app-view)))
      (and (equal (mv-nth 0
                          (rml16 lin-addr r-x (xw fld index value x86)))
                  (mv-nth 0 (rml16 lin-addr r-x x86)))
           (equal (mv-nth 1
                          (rml16 lin-addr r-x (xw fld index value x86)))
                  (mv-nth 1 (rml16 lin-addr r-x x86))))))

    Theorem: rml16-xw-sys-view

    (defthm rml16-xw-sys-view
     (implies
      (and (not (app-view x86))
           (not (equal fld :fault))
           (not (equal fld :seg-visible))
           (not (equal fld :seg-hidden-base))
           (not (equal fld :seg-hidden-limit))
           (not (equal fld :seg-hidden-attr))
           (not (equal fld :mem))
           (not (equal fld :ctr))
           (not (equal fld :msr))
           (not (equal fld :rflags))
           (not (equal fld :app-view))
           (not (equal fld :marking-view))
           (not (equal fld :tlb))
           (not (equal fld :implicit-supervisor-access))
           (member-equal fld *x86-field-names-as-keywords*))
      (and (equal (mv-nth 0
                          (rml16 lin-addr r-x (xw fld index value x86)))
                  (mv-nth 0 (rml16 lin-addr r-x x86)))
           (equal (mv-nth 1
                          (rml16 lin-addr r-x (xw fld index value x86)))
                  (mv-nth 1 (rml16 lin-addr r-x x86)))
           (equal (mv-nth 2
                          (rml16 lin-addr r-x (xw fld index value x86)))
                  (xw fld index value
                      (mv-nth 2 (rml16 lin-addr r-x x86)))))))

    Theorem: rml16-xw-sys-view-rflags-not-ac

    (defthm rml16-xw-sys-view-rflags-not-ac
      (implies
           (and (not (app-view x86))
                (equal (rflagsbits->ac value)
                       (rflagsbits->ac (rflags x86))))
           (and (equal (mv-nth 0
                               (rml16 lin-addr
                                      r-x (xw :rflags nil value x86)))
                       (mv-nth 0 (rml16 lin-addr r-x x86)))
                (equal (mv-nth 1
                               (rml16 lin-addr
                                      r-x (xw :rflags nil value x86)))
                       (mv-nth 1 (rml16 lin-addr r-x x86)))
                (equal (mv-nth 2
                               (rml16 lin-addr
                                      r-x (xw :rflags nil value x86)))
                       (xw :rflags nil value
                           (mv-nth 2 (rml16 lin-addr r-x x86)))))))