Skip to main content

Refined

Struct Refined 

Source
pub struct Refined<Inner, Predicate>(pub Inner, pub Predicate);
Expand description

Value refinement combinator: filters values through a predicate.

§Consistency

inner.consistent(v) && predicate.apply(v).

Tuple Fields§

§0: Inner§1: Predicate

Trait Implementations§

Source§

impl<A, PredFn, T> ByteLen<T> for Refined<A, PredFn>
where T: DeepView, A: ByteLen<T>, PredFn: Pred<T>,

Source§

open spec fn exec_inv(&self) -> bool

{ self.0.exec_inv() }
Source§

exec fn length(&self, v: &T) -> len : usize

Source§

impl<Inner: Clone, Predicate: Clone> Clone for Refined<Inner, Predicate>

Source§

exec fn clone(&self) -> cloned : Self

ensures
call_ensures(Inner::clone, (&self.0,), cloned.0),
call_ensures(Predicate::clone, (&self.1,), cloned.1),
1.0.0 (const: unstable) · Source§

fn clone_from(&mut self, source: &Self)

Performs copy-assignment from source. Read more
Source§

impl<A, Pred> Consistency for Refined<A, Pred>
where A: Consistency, Pred: SpecPred<A::Val>,

Source§

open spec fn consistent(&self, v: Self::Val) -> bool

{ self.0.consistent(v) && self.1.apply(v) }
Source§

type Val = <A as Consistency>::Val

The type of values whose consistency is being checked.
Source§

impl<Inner, P, T> DerOrd<T> for Refined<Inner, P>
where T: DeepView, Inner: DerOrd<T>, P: Pred<T>,

Source§

proof fn lemma_der_serialize_len(&self, value: T::V)

Source§

open spec fn der_remaining(&self, value: T::V, state: Inner::State) -> Seq<u8>

{ self.0.der_remaining(value, state) }
Source§

open spec fn der_state_valid(&self, value: T::V, state: Inner::State) -> bool

{ self.0.der_state_valid(value, state) }
Source§

exec fn der_start(&self, v: &T) -> state : Inner::State

Source§

exec fn der_next(&self, v: &T, state: &mut Inner::State) -> next : Option<u8>

Source§

fn der_leq(&self, left: &T, right: &T) -> bool

Source§

impl<Inner: DerState, P> DerState for Refined<Inner, P>

Source§

type State = <Inner as DerState>::State

Source§

impl<A, Pred> EquivSerializers for Refined<A, Pred>
where A: EquivSerializers, Pred: SpecPred<A::SVal>,

Source§

open spec fn equiv_inv(&self) -> bool

{ self.0.equiv_inv() }
Source§

proof fn lemma_serialize_equiv_on_empty(&self, v: Self::SValue)

Source§

impl<A, Pred> EquivSerializersGeneral for Refined<A, Pred>

Source§

open spec fn equiv_general_inv(&self) -> bool

{ self.0.equiv_general_inv() }
Source§

proof fn lemma_serialize_equiv(&self, v: Self::SValue, obuf: Seq<u8>)

Source§

impl<A, Pred> GoodSerializer for Refined<A, Pred>
where A: GoodSerializer, Pred: SpecPred<A::SVal>,

Source§

open spec fn serialize_inv(&self) -> bool

{ self.0.serialize_inv() }
Source§

proof fn lemma_serialize_len(&self, v: Self::SVal)

Source§

impl<Inner: HasAsn1Start, Predicate: SpecPred<Inner::PVal>> HasAsn1Start for Refined<Inner, Predicate>

Refinement can only narrow an accepted input domain.

Source§

open spec fn asn1_start(&self) -> Asn1StartDomain

{ self.0.asn1_start() }
Source§

proof fn lemma_parse_implies_asn1_start(&self, input: Seq<u8>)

Source§

impl<A, Pred> MinMaxByteLen for Refined<A, Pred>
where A: MinMaxByteLen, Pred: SpecPred<A::T>,

Source§

open spec fn min(&self) -> nat

{ self.0.min() }
Source§

open spec fn max(&self) -> nat

{ self.0.max() }
Source§

proof fn lemma_min_max_byte_len(&self, v: Self::T)

Source§

impl<A: NoLookAhead, Pred: SpecPred<A::PVal>> NoLookAhead for Refined<A, Pred>

Source§

open spec fn no_lookahead_inv(&self) -> bool

{ self.0.no_lookahead_inv() }
Source§

proof fn lemma_no_lookahead(&self, i1: Seq<u8>, i2: Seq<u8>)

Source§

fn corollary_non_extensible(&self, i1: Seq<u8>, i2: Seq<u8>)

Source§

impl<A: NonMalleable, Pred: SpecPred<A::PVal>> NonMalleable for Refined<A, Pred>

Source§

open spec fn nonmal_inv(&self) -> bool

{ self.0.nonmal_inv() }
Source§

proof fn lemma_parse_non_malleable(&self, buf1: Seq<u8>, buf2: Seq<u8>)

Source§

impl<A, Pred> NonTailFmt for Refined<A, Pred>
where A: NonTailFmt, Pred: SpecPred<A::SValue>,

Source§

open spec fn serialize_dps_inv(&self) -> bool

{ self.0.serialize_dps_inv() }
Source§

proof fn lemma_serialize_dps_prepend(&self, v: Self::SValue, obuf: Seq<u8>)

Source§

proof fn lemma_serialize_dps_len(&self, v: Self::SValue, obuf: Seq<u8>)

Source§

impl<I, A, PredFn> Parser<I> for Refined<A, PredFn>
where I: View<V = Seq<u8>>, A: Parser<I>, PredFn: Pred<A::PT>,

Source§

open spec fn exec_inv(&self) -> bool

{ self.0.exec_inv() }
Source§

exec fn parse(&self, ibuf: &I) -> PResult<Self::PT>

Source§

type PT = <A as Parser<I>>::PT

Executable value returned by this parser.
Source§

impl<A, PredFn, T> Prepare<T> for Refined<A, PredFn>
where T: DeepView, A: Prepare<T>, PredFn: Pred<T>,

Source§

open spec fn exec_inv(&self) -> bool

{ self.0.exec_inv() }
Source§

exec fn prepare(&self, v: &T) -> checked : Result<usize, PreSerializeError>

Source§

impl<A: Productive, Pred: SpecPred<A::PVal>> Productive for Refined<A, Pred>

Source§

open spec fn productive_inv(&self) -> bool

{ self.0.productive_inv() }
Source§

proof fn lemma_productive(&self, s: Seq<u8>)

Source§

impl<F, P> Retaggable for Refined<F, P>
where F: Retaggable, P: Copy,

Allows a value constraint to remain attached when its underlying ASN.1 format is retagged.

Retagging is delegated to the inner format and the refinement predicate is preserved.

Source§

open spec fn spec_retagged(&self, tag: Tag) -> Self

{ Refined(self.0.spec_retagged(tag), self.1) }
Source§

exec fn retagged(&self, tag: Tag) -> Self

Source§

impl<A, Pred> SPRoundTripDps for Refined<A, Pred>
where A: SPRoundTripDps, Pred: SpecPred<A::PVal>,

Source§

open spec fn unambiguous(&self) -> bool

{ self.0.unambiguous() }
Source§

proof fn theorem_serialize_dps_parse_roundtrip(&self, v: Self::T, obuf: Seq<u8>)

Source§

impl<A, Pred> SafeParser for Refined<A, Pred>
where A: SafeParser, Pred: SpecPred<A::PVal>,

Source§

open spec fn safe_inv(&self) -> bool

{ self.0.safe_inv() }
Source§

proof fn lemma_parse_safe(&self, ibuf: Seq<u8>)

Source§

impl<Output: OutputBuf, A, PredFn, T> Serializer<Output, T> for Refined<A, PredFn>
where T: DeepView, A: Serializer<Output, T>, PredFn: SpecPred<T::V>,

Source§

open spec fn exec_inv(&self) -> bool

{ self.0.exec_inv() }
Source§

exec fn serialize_into(&self, v: &T, obuf: &mut Output)

Source§

impl<A, Pred> SoundParser for Refined<A, Pred>
where A: SoundParser, Pred: SpecPred<A::PVal>,

Source§

open spec fn sound_inv(&self) -> bool

{ self.0.sound_inv() }
Source§

proof fn lemma_parse_sound_consumption(&self, ibuf: Seq<u8>)

Source§

proof fn lemma_parse_sound_value(&self, ibuf: Seq<u8>)

Source§

impl<A, Pred> SpecByteLen for Refined<A, Pred>
where A: SpecByteLen, Pred: SpecPred<A::T>,

Source§

open spec fn byte_len(&self, v: Self::T) -> nat

{ self.0.byte_len(v) }
Source§

type T = <A as SpecByteLen>::T

The type of values whose byte length is being computed.
Source§

impl<A, Pred> SpecParser for Refined<A, Pred>
where A: SpecParser, Pred: SpecPred<A::PVal>,

Source§

open spec fn spec_parse(&self, ibuf: Seq<u8>) -> Option<(int, Self::PVal)>

{
    match self.0.spec_parse(ibuf) {
        Some((n, v)) if self.1.apply(v) => Some((n, v)),
        _ => None,
    }
}
Source§

type PVal = <A as SpecParser>::PVal

The type of parsed values.
Source§

impl<A, Pred> SpecSerializer for Refined<A, Pred>
where A: SpecSerializer, Pred: SpecPred<A::SVal>,

Source§

open spec fn spec_serialize(&self, v: Self::SVal) -> Seq<u8>

{ self.0.spec_serialize(v) }
Source§

type SVal = <A as SpecSerializer>::SVal

The type of values to be serialized.
Source§

impl<A, Pred> SpecSerializerDps for Refined<A, Pred>
where A: SpecSerializerDps, Pred: SpecPred<A::SValue>,

Source§

open spec fn spec_serialize_dps(&self, v: Self::SValue, obuf: Seq<u8>) -> Seq<u8>

{ self.0.spec_serialize_dps(v, obuf) }
Source§

type SValue = <A as SpecSerializerDps>::SValue

The type of values to be serialized.
Source§

impl<A, Pred> StaticByteLen for Refined<A, Pred>
where A: StaticByteLen, Pred: SpecPred<A::T>,

Source§

open spec fn static_byte_len() -> nat

{ A::static_byte_len() }
Source§

proof fn lemma_static_len_matches_byte_len(&self, v: Self::T)

Source§

impl<A, Pred> ValueByteLen for Refined<A, Pred>
where A: ValueByteLen, Pred: SpecPred<A::T>,

Source§

open spec fn value_byte_len(v: Self::T) -> nat

{ A::value_byte_len(v) }
Source§

proof fn lemma_value_len_matches_byte_len(&self, v: Self::T)

Source§

impl<Inner: Copy, Predicate: Copy> Copy for Refined<Inner, Predicate>

Auto Trait Implementations§

§

impl<Inner, Predicate> Freeze for Refined<Inner, Predicate>
where Inner: Freeze, Predicate: Freeze,

§

impl<Inner, Predicate> RefUnwindSafe for Refined<Inner, Predicate>
where Inner: RefUnwindSafe, Predicate: RefUnwindSafe,

§

impl<Inner, Predicate> Send for Refined<Inner, Predicate>
where Inner: Send, Predicate: Send,

§

impl<Inner, Predicate> Sync for Refined<Inner, Predicate>
where Inner: Sync, Predicate: Sync,

§

impl<Inner, Predicate> Unpin for Refined<Inner, Predicate>
where Inner: Unpin, Predicate: Unpin,

§

impl<Inner, Predicate> UnsafeUnpin for Refined<Inner, Predicate>
where Inner: UnsafeUnpin, Predicate: UnsafeUnpin,

§

impl<Inner, Predicate> UnwindSafe for Refined<Inner, Predicate>
where Inner: UnwindSafe, Predicate: UnwindSafe,

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<T> CloneToUninit for T
where T: Clone,

Source§

unsafe fn clone_to_uninit(&self, dest: *mut u8)

🔬This is a nightly-only experimental API. (clone_to_uninit)
Performs copy-assignment from self to dest. Read more
Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

§

impl<T, VERUS_SPEC__A> FromSpec<T> for VERUS_SPEC__A
where VERUS_SPEC__A: From<T>,

§

fn obeys_from_spec() -> bool

§

fn from_spec(v: T) -> VERUS_SPEC__A

Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

§

impl<T, VERUS_SPEC__A> IntoSpec<T> for VERUS_SPEC__A
where VERUS_SPEC__A: Into<T>,

§

fn obeys_into_spec() -> bool

§

fn into_spec(self) -> T

§

impl<T, U> IntoSpecImpl<U> for T
where U: From<T>,

§

fn obeys_into_spec() -> bool

§

fn into_spec(self) -> U

Source§

impl<C> NonAmbiguous for C
where C: SPRoundTrip,

Source§

open spec fn nonamb_inv(&self) -> bool

{ self.sp_roundtrip_inv() }
Source§

proof fn lemma_serialize_injective( &self, v1: <C as Consistency>::Val, v2: <C as Consistency>::Val, )

Source§

fn corollary_serialize_injective_contrapositive( &self, v1: Self::Val, v2: Self::Val, )

Source§

impl<C> PSRoundTrip for C

Source§

open spec fn ps_roundtrip_inv(&self) -> bool

{ self.safe_inv() && self.sound_inv() && self.nonmal_inv() && self.sp_roundtrip_inv() }
Source§

proof fn theorem_parse_serialize_roundtrip(&self, ibuf: Seq<u8>)

Source§

fn corollary_parse_non_malleable(&self, buf1: Seq<u8>, buf2: Seq<u8>)

Source§

impl<C> SPRoundTrip for C

Source§

open spec fn sp_roundtrip_inv(&self) -> bool

{ self.serialize_inv() && self.equiv_inv() && self.unambiguous() }
Source§

proof fn theorem_serialize_parse_roundtrip(&self, v: <C as SpecByteLen>::T)

Source§

impl<T, S> SerializerExt<T> for S
where S: SpecByteLen<T = <T as DeepView>::V> + SpecSerializer<SVal = <T as DeepView>::V> + Consistency<Val = <T as DeepView>::V>, T: DeepView + ?Sized,

Source§

fn serialize<'a>(&self, v: &T, obuf: &'a mut [u8])
where Self: Serializer<OutputSlice<'a>, T>,

Source§

fn serialize_with_vec(&self, v: &T, obuf: &mut Vec<u8>)
where Self: Serializer<Vec<u8>, T>,

Source§

impl<T> ToOwned for T
where T: Clone,

Source§

type Owned = T

The resulting type after obtaining ownership.
Source§

fn to_owned(&self) -> T

Creates owned data from borrowed data, usually by cloning. Read more
Source§

fn clone_into(&self, target: &mut T)

Uses borrowed data to replace owned data, usually by cloning. Read more
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = Infallible

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, <T as TryFrom<U>>::Error>

Performs the conversion.
§

impl<T, VERUS_SPEC__A> TryFromSpec<T> for VERUS_SPEC__A
where VERUS_SPEC__A: TryFrom<T>,

§

fn obeys_try_from_spec() -> bool

§

fn try_from_spec( v: T, ) -> Result<VERUS_SPEC__A, <VERUS_SPEC__A as TryFrom<T>>::Error>

Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.
§

impl<T, VERUS_SPEC__A> TryIntoSpec<T> for VERUS_SPEC__A
where VERUS_SPEC__A: TryInto<T>,

§

fn obeys_try_into_spec() -> bool

§

fn try_into_spec(self) -> Result<T, <VERUS_SPEC__A as TryInto<T>>::Error>

§

impl<T, U> TryIntoSpecImpl<U> for T
where U: TryFrom<T>,

§

fn obeys_try_into_spec() -> bool

§

fn try_into_spec(self) -> Result<U, <U as TryFrom<T>>::Error>

Source§

impl<T> SpecCombinator for T
where T: SpecParser<PVal = <T as SpecByteLen>::T> + SpecByteLen + SpecSerializer<SVal = <T as SpecByteLen>::T> + Consistency<Val = <T as SpecByteLen>::T> + SpecSerializerDps<SValue = <T as SpecByteLen>::T>,

§

impl<A> SpecEq<&A> for A
where A: ?Sized,

§

impl<A> SpecEq<&mut A> for A
where A: ?Sized,

§

impl<A> SpecEq<A> for A
where A: ?Sized,

§

impl<A> SpecEq<Ghost<A>> for A

§

impl<A> SpecEq<Tracked<A>> for A

Source§

impl<Body> StrictCombinator for Body