[framework] BigOrderedMap iterator validity specs - #20311
Conversation
|
Warning This pull request is not mergeable via GitHub because a downstack PR is open. Once all requirements are satisfied, merge this PR as a stack on Graphite.
This stack of pull requests is managed by Graphite. Learn more about stacking. |
650cd94 to
003eee2
Compare
0779564 to
39135c5
Compare
39135c5 to
cc99280
Compare
003eee2 to
6eca8b5
Compare
cc99280 to
3d45f54
Compare
6eca8b5 to
c7cb46b
Compare
3d45f54 to
d23ef9d
Compare
c7cb46b to
7ec756e
Compare
There was a problem hiding this comment.
Aptos Security Bugbot has reviewed your changes, there are still 2 issues that need to be addressed from previous scan.
Open findings:
- Iterator-advancing loops cannot satisfy the new contract
- Preallocation invalidates valid iterators in the model
Sent by Cursor Automation: Security Review Bot
7ec756e to
0b9ded7
Compare
d23ef9d to
7c38a6f
Compare
7c38a6f to
de0d964
Compare
0b9ded7 to
23cab00
Compare
There was a problem hiding this comment.
Aptos Security Bugbot has reviewed your changes, there are still 2 issues that need to be addressed from previous scan.
Open findings:
- Preallocation invalidates valid iterators in the model
- Conditional non-structural updates discard iterator validity
Sent by Cursor Automation: Security Review Bot
de0d964 to
83d084c
Compare
23cab00 to
9fa8a48
Compare
There was a problem hiding this comment.
Aptos Security Bugbot has reviewed your changes, there are still 2 issues that need to be addressed from previous scan.
Open findings:
- Preallocation invalidates valid iterators in the model
- Conditional non-structural updates discard iterator validity
Sent by Cursor Automation: Security Review Bot
There was a problem hiding this comment.
Aptos Security Bugbot has reviewed your changes, there are still 2 issues that need to be addressed from previous scan.
Open findings:
- Preallocation invalidates valid iterators in the model
- Conditional non-structural updates discard iterator validity
Sent by Cursor Automation: Security Review Bot
d73658c to
082d39f
Compare
There was a problem hiding this comment.
Aptos Security Bugbot has reviewed your changes, there are still 5 issues that need to be addressed from previous scan.
Open findings:
- Preallocation invalidates valid iterators in the model
- Conditional non-structural updates discard iterator validity
- Misplaced-invariant validation is quadratic in function size
- Iterator validity is not preserved across the intersection leaf loop
- Unreachable loop-unrolling marks still fail validation
Sent by Cursor Automation: Security Review Bot
There was a problem hiding this comment.
Aptos Security Bugbot has reviewed your changes, there are still 5 issues that need to be addressed from previous scan.
Open findings:
- Preallocation invalidates valid iterators in the model
- Conditional non-structural updates discard iterator validity
- Misplaced-invariant validation is quadratic in function size
- Iterator validity is not preserved across the intersection leaf loop
- Unreachable loop-unrolling marks still fail validation
Sent by Cursor Automation: Security Review Bot
b620228 to
a3b0b06
Compare
082d39f to
dcf154c
Compare
There was a problem hiding this comment.
Aptos Security Bugbot has reviewed your changes, there are still 5 issues that need to be addressed from previous scan.
Open findings:
- Preallocation invalidates valid iterators in the model
- Conditional non-structural updates discard iterator validity
- Misplaced-invariant validation is quadratic in function size
- Iterator validity is not preserved across the intersection leaf loop
- Unreachable loop-unrolling marks still fail validation
Sent by Cursor Automation: Security Review Bot
a3b0b06 to
23f624a
Compare
dcf154c to
124d78c
Compare
There was a problem hiding this comment.
Aptos Security Bugbot has reviewed your changes and found 1 potential issue.
Open findings:
- Preallocation invalidates valid iterators in the model
- Conditional non-structural updates discard iterator validity
- Misplaced-invariant validation is quadratic in function size
- Iterator validity is not preserved across the intersection leaf loop
- Unreachable loop-unrolling marks still fail validation
Sent by Cursor Automation: Security Review Bot
There was a problem hiding this comment.
Aptos Security Bugbot has reviewed your changes and found 1 potential issue.
Open findings:
- Preallocation invalidates valid iterators in the model
- Conditional non-structural updates discard iterator validity
- Misplaced-invariant validation is quadratic in function size
- Iterator validity is not preserved across the intersection leaf loop
- Unreachable loop-unrolling marks still fail validation
Sent by Cursor Automation: Security Review Bot
124d78c to
9863883
Compare
There was a problem hiding this comment.
Aptos Security Bugbot has reviewed your changes, there are still 5 issues that need to be addressed from previous scan.
Open findings:
- Preallocation invalidates valid iterators in the model
- Conditional non-structural updates discard iterator validity
- Misplaced-invariant validation is quadratic in function size
- Iterator validity is not preserved across the intersection leaf loop
- Unreachable loop-unrolling marks still fail validation
Sent by Cursor Automation: Security Review Bot
9863883 to
e8c2957
Compare
23f624a to
07b3826
Compare
There was a problem hiding this comment.
Aptos Security Bugbot has reviewed your changes, there are still 5 issues that need to be addressed from previous scan.
Open findings:
- Preallocation invalidates valid iterators in the model
- Conditional non-structural updates discard iterator validity
- Misplaced-invariant validation is quadratic in function size
- Iterator validity is not preserved across the intersection leaf loop
- Unreachable loop-unrolling marks still fail validation
Sent by Cursor Automation: Security Review Bot
There was a problem hiding this comment.
Aptos Security Bugbot has reviewed your changes, there are still 5 issues that need to be addressed from previous scan.
Open findings:
- Preallocation invalidates valid iterators in the model
- Conditional non-structural updates discard iterator validity
- Misplaced-invariant validation is quadratic in function size
- Iterator validity is not preserved across the intersection leaf loop
- Unreachable loop-unrolling marks still fail validation
Sent by Cursor Automation: Security Review Bot
07b3826 to
5a375c7
Compare
e8c2957 to
97dce1c
Compare
There was a problem hiding this comment.
Aptos Security Bugbot has reviewed your changes and found no new issue.
Open findings:
- Preallocation invalidates valid iterators in the model
- Conditional non-structural updates discard iterator validity
- Misplaced-invariant validation is quadratic in function size
- Iterator validity is not preserved across the intersection leaf loop
- Unreachable loop-unrolling marks still fail validation
Sent by Cursor Automation: Security Review Bot
There was a problem hiding this comment.
Aptos Security Bugbot has reviewed your changes, there are still 5 issues that need to be addressed from previous scan.
Open findings:
- Preallocation invalidates valid iterators in the model
- Conditional non-structural updates discard iterator validity
- Misplaced-invariant validation is quadratic in function size
- Iterator validity is not preserved across the intersection leaf loop
- Unreachable loop-unrolling marks still fail validation
Sent by Cursor Automation: Security Review Bot
5a375c7 to
0f9c064
Compare
97dce1c to
e3ec1bd
Compare
There was a problem hiding this comment.
Aptos Security Bugbot has reviewed your changes, there are still 5 issues that need to be addressed from previous scan.
Open findings:
- Preallocation invalidates valid iterators in the model
- Conditional non-structural updates discard iterator validity
- Misplaced-invariant validation is quadratic in function size
- Iterator validity is not preserved across the intersection leaf loop
- Unreachable loop-unrolling marks still fail validation
Sent by Cursor Automation: Security Review Bot
There was a problem hiding this comment.
Aptos Security Bugbot has reviewed your changes, there are still 5 issues that need to be addressed from previous scan.
Open findings:
- Preallocation invalidates valid iterators in the model
- Conditional non-structural updates discard iterator validity
- Misplaced-invariant validation is quadratic in function size
- Iterator validity is not preserved across the intersection leaf loop
- Unreachable loop-unrolling marks still fail validation
Sent by Cursor Automation: Security Review Bot
Declare a ghost brand on BigOrderedMap and replace the opaque iterator pragma placements with explicit spec conditions: creation functions ensure the result's stamp matches the map's brand, use sites require spec_iter_valid, and iter_modify preserves the brand. Structural mutations havoc the brand, invalidating outstanding iterators of that map object only. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
e3ec1bd to
a18ecf6
Compare



Description
Activate iterator-validity checking for
BigOrderedMapusing the hidden-slot machinery from #20310: iterator staleness becomes a machine-checked precondition instead of a documented presumption, per map object.The spec binds the three validity roles and declares their native predicates — no ghost state, no new fields, nothing nameable beyond the predicates themselves:
Binding the roles gives the map and both iterator types hidden version slots (fresh at creation, havocked by every structural mutation, preserved by value writes); the natives are defined by the prover as slot equality. The contracts then say the obvious things:
internal_lower_bound,internal_find,internal_new_begin_iter,internal_find_with_path,internal_leaf_new_begin_iter):ensures spec_iter_current(result, self)— a fresh iterator is valid for its map.iter_borrow,iter_borrow_mut,iter_next,iter_prev,iter_is_begin,iter_modify,iter_remove):requires spec_iter_valid(self, map). Advancing (iter_next/iter_prev) re-ensures validity of the result.iter_modify,allocate_spare_slots):ensures spec_iter_preserved(map, old(map))— modifying a value through an iterator, or preallocating storage slots, is not a structural mutation.spec_iter_validis a thin public wrapper adding the End disjunct: End iterators carry no position, so they are valid regardless of mutation (iter_prevfrom End legitimately finds the largest key of the current map). The leaf walker has no End variant distinct from itsNULL_INDEXsentinel and binds its native directly.Structural mutations havoc the map's slot, so they invalidate outstanding iterators of that map object only — same-type sibling maps, other elements of a
vector<BigOrderedMap>, and copies that have since diverged are unaffected, while stale or cross-map iterator use fails verification. One refinement lives in the intrinsic model itself: an existing-keyupsertreplaces the value in place (add_atoverwrites before ever splitting), so theupsert/add_override_if_existstemplates preserve the slot on that branch — iterators survive value-only upserts with no annotation.Supporting changes:
iter_with_path_get_iterbecomes transparent (it is a plain projection): an opaqueensures result == self.iteratorwould not carry the projected iterator's hidden slot (equality excludes it), while inlined value flow does.fat_loop.rs: loop-invariant and unrolling-mark placement validation now ignores declarations in unreachable code — inline expansion (e.g. offor_each_mut) leaves dead copies of the spec block behind, which are never verified and must not be flagged as misplaced. The reachability check is a single pass collecting reachablePropattr ids, so validation stays linear in function size.for_each_mut,for_each_leaf_node_children_ref,intersection_zip_for_each_ref) carryspec_iter_valid/spec_leaf_iter_validinvariants so advanced iterators survive the loop-head havoc; the intersection walk needs them for both maps' leaf iterators.How Has This Been Tested?
aptos-move-cli prove -f big_ordered_map: the module verifies, including the transparent projection, the three invariant-carrying loops, and the new witnesstest_verify_iter_across_upsert(an iterator survives an existing-key upsert and reads through afterwards).move_stdlib,aptos_stdlib,framework,token) green — all existing framework specs verify unchanged with validity active.&mut, loops, wrappers) is pinned in [move prover] ghost carrier and iterator validity for intrinsic maps #20310'sverify_iterator_validity.moveagainst a mock map.Type of Change
Which Components or Systems Does This Change Impact?
Checklist
🤖 Generated with Claude Code
Note
Medium Risk
Touches Move prover map intrinsics, Boogie mutation semantics, and framework verification contracts; runtime map behavior is unchanged but proof obligations and prover diagnostics shift.
Overview
Turns BigOrderedMap iterator staleness from a documented presumption into prover-enforced preconditions via intrinsic map roles (
map_spec_iter_valid,map_spec_leaf_iter_valid,map_spec_iter_preserved) and native predicates tied to hidden validity slots.Iterator create/use/advance specs now require or ensure validity; value-only paths (
iter_modify,allocate_spare_slots) ensurespec_iter_preserved.iter_with_path_get_iteris no longer opaque so projected iterators keep validity through equality.for_each_mut, leaf walks, andintersection_zip_for_each_refadd loop **invariant**s for iterator validity.Boogie map templates treat existing-key
upsert/add_override_if_existsas in-place value updates ($UpdateMutationwithout ghost havoc) so iterators can survive those updates;test_verify_iter_across_upsertwitnesses that behavior.fat_loop.rsskips “misplaced” loop invariant / unrolling diagnostics when the specProplives only in unreachable bytecode (e.g. dead copies after inline expansion).Reviewed by Cursor Bugbot for commit a18ecf6. Bugbot is set up for automated code reviews on this repo. Configure here.