|
| 1 | +module integer_library_specs_bv::i128; |
| 2 | + |
| 3 | +#[spec_only] |
| 4 | +use prover::prover::{ensures, asserts, invariant}; |
| 5 | + |
| 6 | +public struct I128 has copy, drop, store { |
| 7 | + bits: u128, |
| 8 | +} |
| 9 | + |
| 10 | +public fun wrapping_add(num1: I128, num2: I128): I128 { |
| 11 | + let mut sum = num1.bits ^ num2.bits; |
| 12 | + let mut carry = (num1.bits & num2.bits) << 1; |
| 13 | + invariant!(|| { |
| 14 | + ensures( |
| 15 | + ((num1.bits as u256) + (num2.bits as u256)) % (1 << 128) == ((sum as u256) + (carry as u256)) % (1 << 128), |
| 16 | + ); |
| 17 | + }); |
| 18 | + while (carry != 0) { |
| 19 | + let a = sum; |
| 20 | + let b = carry; |
| 21 | + sum = a ^ b; |
| 22 | + carry = (a & b) << 1; |
| 23 | + }; |
| 24 | + I128 { |
| 25 | + bits: sum, |
| 26 | + } |
| 27 | +} |
| 28 | + |
| 29 | +/* |
| 30 | + ✅ Computes `num1 + num2` with wrapping overflow. |
| 31 | + ⏮️ The function does not abort. |
| 32 | +*/ |
| 33 | +#[spec(prove, target = wrapping_add)] |
| 34 | +public fun wrapping_add_spec(num1: I128, num2: I128): I128 { |
| 35 | + let result = wrapping_add(num1, num2); |
| 36 | + ensures(result.bits == (((num1.bits as u256) + (num2.bits as u256)) % (1 << 128)) as u128); |
| 37 | + result |
| 38 | +} |
| 39 | + |
| 40 | +public fun shr(v: I128, shift: u8): I128 { |
| 41 | + if (shift == 0) { |
| 42 | + return v |
| 43 | + }; |
| 44 | + let mask = 0xffffffffffffffffffffffffffffffff << (128 - shift); |
| 45 | + if (sign(v) == 1) { |
| 46 | + return I128 { |
| 47 | + bits: (v.bits >> shift) | mask, |
| 48 | + } |
| 49 | + }; |
| 50 | + I128 { |
| 51 | + bits: v.bits >> shift, |
| 52 | + } |
| 53 | +} |
| 54 | + |
| 55 | +public fun sign(v: I128): u8 { |
| 56 | + ((v.bits >> 127) as u8) |
| 57 | +} |
| 58 | + |
| 59 | +public native fun ashr(x: u128, y: u128): u128; |
| 60 | + |
| 61 | +/* |
| 62 | + ✅ Computes arithmetic right shift `v >> shift`. |
| 63 | + ⏮️ The function aborts unless `shift < 128`. |
| 64 | +*/ |
| 65 | +#[spec(prove, target = shr)] |
| 66 | +public fun shr_spec(v: I128, shift: u8): I128 { |
| 67 | + asserts(shift < 128); |
| 68 | + let result = shr(v, shift); |
| 69 | + ensures(result.bits == ashr(v.bits, shift as u128)); |
| 70 | + result |
| 71 | +} |
0 commit comments