Skip to main content

SetOfFmt

Struct SetOfFmt 

Source
pub struct SetOfFmt<C>(pub C);
Expand description

DER SET OF contents whose elements are encoded by C.

C must encode a complete DER element, including its tag and length. The parsed value is a Vec<C::PT> in canonical DER order. Duplicate encodings are permitted.

Tuple Fields§

§0: C

Implementations§

Source§

impl<C: SpecParser> SetOfFmt<C>

Source

pub open spec fn parse_ordered( &self, ibuf: Seq<u8>, previous: Seq<Seq<u8>>, ) -> Option<Seq<C::PVal>>

{
    if !der_encodings_sorted(previous) {
        None
    } else if ibuf.len() == 0 {
        Some(Seq::empty())
    } else {
        match self.0.spec_parse(ibuf) {
            Some(
                (n, v),
            ) if 0 < n <= ibuf.len()
                && der_encodings_sorted(previous.push(ibuf.take(n))) => {
                match self.parse_ordered(ibuf.skip(n), previous.push(ibuf.take(n))) {
                    Some(values) => Some(seq![v] + values),
                    None => None,
                }
            }
            _ => None,
        }
    }
}

Parses all remaining elements while maintaining a canonically sorted encoding prefix.

Trait Implementations§

Source§

impl<C, Elem> ByteLen<[Elem]> for SetOfFmt<C>
where C: SpecByteLen<T = <Elem as DeepView>::V> + ByteLen<Elem> + Copy, Elem: DeepView,

Source§

open spec fn exec_inv(&self) -> bool

{ self.0.exec_inv() }
Source§

exec fn length(&self, v: &[Elem]) -> len : usize

Source§

impl<C, Elem> ByteLen<Vec<Elem>> for SetOfFmt<C>
where C: SpecByteLen<T = <Elem as DeepView>::V> + ByteLen<Elem> + Copy, Elem: DeepView,

Available on crate feature alloc only.
Source§

open spec fn exec_inv(&self) -> bool

{ self.0.exec_inv() }
Source§

exec fn length(&self, values: &Vec<Elem>) -> len : usize

Source§

impl<C: Clone> Clone for SetOfFmt<C>

Source§

exec fn clone(&self) -> cloned : Self

ensures
call_ensures(C::clone, (&self.0,), cloned.0),
1.0.0 (const: unstable) · Source§

fn clone_from(&mut self, source: &Self)

Performs copy-assignment from source. Read more
Source§

impl<C> Consistency for SetOfFmt<C>
where C: Consistency + SpecSerializer<SVal = C::Val>,

Source§

open spec fn consistent(&self, values: Self::Val) -> bool

{
    &&& Star(self.0).consistent(values)
    &&& set_of_values_sorted(self.0, values)

}
Source§

type Val = Seq<<C as Consistency>::Val>

The type of values whose consistency is being checked.
Source§

impl<A, T> DerOrd<Vec<T>> for SetOfFmt<A>
where T: DeepView, A: DerOrd<T> + Copy,

Available on crate feature alloc only.
Source§

proof fn lemma_der_serialize_len(&self, values: Seq<T::V>)

Source§

open spec fn der_remaining( &self, values: Seq<T::V>, state: StarDerState<A::State>, ) -> Seq<u8>

{ Star(self.0).der_remaining(values, state) }
Source§

open spec fn der_state_valid( &self, values: Seq<T::V>, state: StarDerState<A::State>, ) -> bool

{ Star(self.0).der_state_valid(values, state) }
Source§

exec fn der_start(&self, v: &Vec<T>) -> state : StarDerState<A::State>

Source§

exec fn der_next(&self, v: &Vec<T>, state: &mut StarDerState<A::State>) -> next : Option<u8>

Source§

fn der_leq(&self, left: &T, right: &T) -> bool

Source§

impl<A: DerState> DerState for SetOfFmt<A>

Available on crate feature alloc only.
Source§

impl<C: EquivSerializersGeneral> EquivSerializers for SetOfFmt<C>

Source§

open spec fn equiv_inv(&self) -> bool

{ self.0.equiv_general_inv() }
Source§

proof fn lemma_serialize_equiv_on_empty(&self, values: Self::SVal)

Source§

impl<C: GoodSerializer> GoodSerializer for SetOfFmt<C>

Source§

open spec fn serialize_inv(&self) -> bool

{ self.0.serialize_inv() }
Source§

proof fn lemma_serialize_len(&self, values: Self::SVal)

Source§

impl<C: NonMalleable> NonMalleable for SetOfFmt<C>

Source§

open spec fn nonmal_inv(&self) -> bool

{ self.0.nonmal_inv() && self.0.safe_inv() }
Source§

proof fn lemma_parse_non_malleable(&self, buf1: Seq<u8>, buf2: Seq<u8>)

Source§

impl<'i, C> Parser<&'i [u8]> for SetOfFmt<C>
where C: Parser<&'i [u8]> + SafeParser + Productive + Copy,

Available on crate feature alloc only.
Source§

open spec fn exec_inv(&self) -> bool

{
    &&& self.0.exec_inv()
    &&& self.0.safe_inv()
    &&& self.0.productive_inv()

}
Source§

exec fn parse(&self, ibuf: &&'i [u8]) -> r : PResult<Self::PT>

Source§

type PT = Vec<<C as Parser<&'i [u8]>>::PT>

Executable value returned by this parser.
Source§

impl<C, Elem> Prepare<[Elem]> for SetOfFmt<C>
where Elem: DeepView, C: SpecCombinator<T = <Elem as DeepView>::V> + Prepare<Elem> + DerOrd<Elem> + Copy,

Source§

open spec fn exec_inv(&self) -> bool

{ self.0.exec_inv() }
Source§

exec fn prepare(&self, values: &[Elem]) -> checked : Result<usize, PreSerializeError>

Source§

impl<C, Elem> Prepare<Vec<Elem>> for SetOfFmt<C>
where Elem: DeepView, C: SpecCombinator<T = <Elem as DeepView>::V> + Prepare<Elem> + DerOrd<Elem> + Copy,

Available on crate feature alloc only.
Source§

open spec fn exec_inv(&self) -> bool

{ self.0.exec_inv() }
Source§

exec fn prepare(&self, values: &Vec<Elem>) -> checked : Result<usize, PreSerializeError>

Source§

impl<C: SafeParser> Productive for SetOfFmt<C>

Source§

open spec fn productive_inv(&self) -> bool

{ false }
Source§

proof fn lemma_productive(&self, _ibuf: Seq<u8>)

Source§

impl<C> SPRoundTripDps for SetOfFmt<C>

Source§

open spec fn unambiguous(&self) -> bool

{
    &&& self.0.unambiguous()
    &&& self.0.serialize_dps_inv()
    &&& self.0.equiv_general_inv()
    &&& self.0.safe_inv()
    &&& self.0.productive_inv()

}
Source§

proof fn theorem_serialize_dps_parse_roundtrip(&self, values: Self::T, _obuf: Seq<u8>)

Source§

impl<C: SafeParser> SafeParser for SetOfFmt<C>

Source§

open spec fn safe_inv(&self) -> bool

{ self.0.safe_inv() }
Source§

proof fn lemma_parse_safe(&self, ibuf: Seq<u8>)

Source§

impl<Output: OutputBuf, C, Elem> Serializer<Output, [Elem]> for SetOfFmt<C>
where Elem: DeepView, C: SpecCombinator<T = <Elem as DeepView>::V> + Serializer<Output, Elem> + Copy,

Source§

open spec fn exec_inv(&self) -> bool

{ self.0.exec_inv() }
Source§

exec fn serialize_into(&self, v: &[Elem], obuf: &mut Output)

Source§

impl<Output: OutputBuf, C, Elem> Serializer<Output, Vec<Elem>> for SetOfFmt<C>
where Elem: DeepView, C: SpecCombinator<T = <Elem as DeepView>::V> + Serializer<Output, Elem> + Copy,

Available on crate feature alloc only.
Source§

open spec fn exec_inv(&self) -> bool

{ self.0.exec_inv() }
Source§

exec fn serialize_into(&self, values: &Vec<Elem>, obuf: &mut Output)

Source§

impl<C: SoundParser + PSRoundTrip> SoundParser for SetOfFmt<C>

Source§

open spec fn sound_inv(&self) -> bool

{ self.0.sound_inv() && self.0.ps_roundtrip_inv() }
Source§

proof fn lemma_parse_sound_consumption(&self, ibuf: Seq<u8>)

Source§

proof fn lemma_parse_sound_value(&self, ibuf: Seq<u8>)

Source§

impl<C: SpecByteLen> SpecByteLen for SetOfFmt<C>

Source§

open spec fn byte_len(&self, v: Self::T) -> nat

{ Star(self.0).byte_len(v) }
Source§

type T = Seq<<C as SpecByteLen>::T>

The type of values whose byte length is being computed.
Source§

impl<C: SpecParser> SpecParser for SetOfFmt<C>

Source§

open spec fn spec_parse(&self, ibuf: Seq<u8>) -> Option<(int, Self::PVal)>

{
    match self.parse_ordered(ibuf, Seq::empty()) {
        Some(values) => Some((ibuf.len() as int, values)),
        _ => None,
    }
}
Source§

type PVal = Seq<<C as SpecParser>::PVal>

The type of parsed values.
Source§

impl<C: SpecSerializer> SpecSerializer for SetOfFmt<C>

Source§

open spec fn spec_serialize(&self, v: Self::SVal) -> Seq<u8>

{ Star(self.0).spec_serialize(v) }
Source§

type SVal = Seq<<C as SpecSerializer>::SVal>

The type of values to be serialized.
Source§

impl<C: SpecSerializerDps> SpecSerializerDps for SetOfFmt<C>

Source§

open spec fn spec_serialize_dps(&self, v: Self::SValue, _obuf: Seq<u8>) -> Seq<u8>

{ Star(self.0).spec_serialize_dps(v, Seq::empty()) }
Source§

type SValue = Seq<<C as SpecSerializerDps>::SValue>

The type of values to be serialized.
Source§

impl<C: Copy> Copy for SetOfFmt<C>

Auto Trait Implementations§

§

impl<C> Freeze for SetOfFmt<C>
where C: Freeze,

§

impl<C> RefUnwindSafe for SetOfFmt<C>
where C: RefUnwindSafe,

§

impl<C> Send for SetOfFmt<C>
where C: Send,

§

impl<C> Sync for SetOfFmt<C>
where C: Sync,

§

impl<C> Unpin for SetOfFmt<C>
where C: Unpin,

§

impl<C> UnsafeUnpin for SetOfFmt<C>
where C: UnsafeUnpin,

§

impl<C> UnwindSafe for SetOfFmt<C>
where C: UnwindSafe,

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<T> CloneToUninit for T
where T: Clone,

Source§

unsafe fn clone_to_uninit(&self, dest: *mut u8)

🔬This is a nightly-only experimental API. (clone_to_uninit)
Performs copy-assignment from self to dest. Read more
Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

§

impl<T, VERUS_SPEC__A> FromSpec<T> for VERUS_SPEC__A
where VERUS_SPEC__A: From<T>,

§

fn obeys_from_spec() -> bool

§

fn from_spec(v: T) -> VERUS_SPEC__A

Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

§

impl<T, VERUS_SPEC__A> IntoSpec<T> for VERUS_SPEC__A
where VERUS_SPEC__A: Into<T>,

§

fn obeys_into_spec() -> bool

§

fn into_spec(self) -> T

§

impl<T, U> IntoSpecImpl<U> for T
where U: From<T>,

§

fn obeys_into_spec() -> bool

§

fn into_spec(self) -> U

Source§

impl<C> NonAmbiguous for C
where C: SPRoundTrip,

Source§

open spec fn nonamb_inv(&self) -> bool

{ self.sp_roundtrip_inv() }
Source§

proof fn lemma_serialize_injective( &self, v1: <C as Consistency>::Val, v2: <C as Consistency>::Val, )

Source§

fn corollary_serialize_injective_contrapositive( &self, v1: Self::Val, v2: Self::Val, )

Source§

impl<C> PSRoundTrip for C

Source§

open spec fn ps_roundtrip_inv(&self) -> bool

{ self.safe_inv() && self.sound_inv() && self.nonmal_inv() && self.sp_roundtrip_inv() }
Source§

proof fn theorem_parse_serialize_roundtrip(&self, ibuf: Seq<u8>)

Source§

fn corollary_parse_non_malleable(&self, buf1: Seq<u8>, buf2: Seq<u8>)

Source§

impl<C> SPRoundTrip for C

Source§

open spec fn sp_roundtrip_inv(&self) -> bool

{ self.serialize_inv() && self.equiv_inv() && self.unambiguous() }
Source§

proof fn theorem_serialize_parse_roundtrip(&self, v: <C as SpecByteLen>::T)

Source§

impl<T> ToOwned for T
where T: Clone,

Source§

type Owned = T

The resulting type after obtaining ownership.
Source§

fn to_owned(&self) -> T

Creates owned data from borrowed data, usually by cloning. Read more
Source§

fn clone_into(&self, target: &mut T)

Uses borrowed data to replace owned data, usually by cloning. Read more
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = Infallible

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, <T as TryFrom<U>>::Error>

Performs the conversion.
§

impl<T, VERUS_SPEC__A> TryFromSpec<T> for VERUS_SPEC__A
where VERUS_SPEC__A: TryFrom<T>,

§

fn obeys_try_from_spec() -> bool

§

fn try_from_spec( v: T, ) -> Result<VERUS_SPEC__A, <VERUS_SPEC__A as TryFrom<T>>::Error>

Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.
§

impl<T, VERUS_SPEC__A> TryIntoSpec<T> for VERUS_SPEC__A
where VERUS_SPEC__A: TryInto<T>,

§

fn obeys_try_into_spec() -> bool

§

fn try_into_spec(self) -> Result<T, <VERUS_SPEC__A as TryInto<T>>::Error>

§

impl<T, U> TryIntoSpecImpl<U> for T
where U: TryFrom<T>,

§

fn obeys_try_into_spec() -> bool

§

fn try_into_spec(self) -> Result<U, <U as TryFrom<T>>::Error>

§

impl<A> SpecEq<&A> for A
where A: ?Sized,

§

impl<A> SpecEq<&mut A> for A
where A: ?Sized,

§

impl<A> SpecEq<A> for A
where A: ?Sized,

§

impl<A> SpecEq<Ghost<A>> for A

§

impl<A> SpecEq<Tracked<A>> for A