Analysis of invariants for efficient bounded verification

  • Authors:
  • Juan Pablo Galeotti;Nicolás Rosner;Carlos Gustavo López Pombo;Marcelo Fabian Frias

  • Affiliations:
  • Universidad de Buenos Aires, Buenos Aires, Argentina;Universidad de Buenos Aires, Buenos Aires, Argentina;Universidad de Buenos Aires, Buenos Aires, Argentina;Buenos Aires Institute of Technology, Buenos Aires, Argentina

  • Venue:
  • Proceedings of the 19th international symposium on Software testing and analysis
  • Year:
  • 2010

Quantified Score

Hi-index 0.00

Visualization

Abstract

SAT-based bounded verification of annotated code consists of translating the code together with the annotations to a propositional formula, and analyzing the formula for specification violations using a SAT-solver. If a violation is found, an execution trace exposing the error is exhibited. Code involving linked data structures with intricate invariants is particularly hard to analyze using these techniques. In this article we present TACO, a prototype tool which implements a novel, general and fully automated technique for the SAT-based analysis of JML-annotated Java sequential programs dealing with complex linked data structures. We instrument code analysis with a symmetry-breaking predicate that allows for the parallel, automated computation of tight bounds for Java fields. Experiments show that the translations to propositional formulas require significantly less propositional variables, leading in the experiments we have carried out to an improvement on the efficiency of the analysis of orders of magnitude, compared to the non-instrumented SAT-based analysis. We show that, in some cases, our tool can uncover bugs that cannot be detected by state-of-the-art tools based on SAT-solving, model checking or SMT-solving.