1 /*
2 * FreeRTOS memory safety proofs with CBMC.
3 * Copyright (C) 2022 Amazon.com, Inc. or its affiliates. All Rights Reserved.
4 *
5 * Permission is hereby granted, free of charge, to any person
6 * obtaining a copy of this software and associated documentation
7 * files (the "Software"), to deal in the Software without
8 * restriction, including without limitation the rights to use, copy,
9 * modify, merge, publish, distribute, sublicense, and/or sell copies
10 * of the Software, and to permit persons to whom the Software is
11 * furnished to do so, subject to the following conditions:
12 *
13 * The above copyright notice and this permission notice shall be
14 * included in all copies or substantial portions of the Software.
15 *
16 * THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND,
17 * EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF
18 * MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND
19 * NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS
20 * BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN
21 * ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN
22 * CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE
23 * SOFTWARE.
24 *
25 * http://aws.amazon.com/freertos
26 * http://www.FreeRTOS.org
27 */
28
29 #include <stdint.h>
30
31 /* FreeRTOS includes. */
32 #include "FreeRTOS.h"
33 #include "task.h"
34
35 /* FreeRTOS+TCP includes. */
36 #include "FreeRTOS_IP.h"
37 #include "FreeRTOS_IP_Private.h"
38
39 #include "cbmc.h"
40
41 /* eARPProcessPacket() is proved separately */
eARPProcessPacket(ARPPacket_t * const pxARPFrame)42 eFrameProcessingResult_t eARPProcessPacket( ARPPacket_t * const pxARPFrame )
43 {
44 __CPROVER_assert( pxARPFrame != NULL, "pxARPFrame != NULL" );
45 eFrameProcessingResult_t retVal;
46 return retVal;
47 }
48
49 /* vReturnEthernetFrame() is proved separately */
vReturnEthernetFrame(NetworkBufferDescriptor_t * pxNetworkBuffer,BaseType_t xReleaseAfterSend)50 void vReturnEthernetFrame( NetworkBufferDescriptor_t * pxNetworkBuffer,
51 BaseType_t xReleaseAfterSend )
52 {
53 __CPROVER_assert( pxNetworkBuffer != NULL, "xNetworkBuffer != NULL" );
54 __CPROVER_assert( pxNetworkBuffer->pucEthernetBuffer != NULL, "pxNetworkBuffer->pucEthernetBuffer != NULL" );
55
56 free( pxNetworkBuffer->pucEthernetBuffer );
57 free( pxNetworkBuffer );
58 }
59
60 /* This function has been proved to be memory safe in another proof (in parsing/ProcessIPPacket). Hence we assume it to be correct here. */
__CPROVER_file_local_FreeRTOS_IP_c_prvProcessIPPacket(IPPacket_t * pxIPPacket,NetworkBufferDescriptor_t * const pxNetworkBuffer)61 eFrameProcessingResult_t __CPROVER_file_local_FreeRTOS_IP_c_prvProcessIPPacket( IPPacket_t * pxIPPacket,
62 NetworkBufferDescriptor_t * const pxNetworkBuffer )
63 {
64 __CPROVER_assert( pxIPPacket != NULL, "pxIPPacket cannot be NULL" );
65 __CPROVER_assert( pxNetworkBuffer != NULL, "pxNetworkBuffer cannot be NULL" );
66
67 eFrameProcessingResult_t result;
68
69 return result;
70 }
71
72
73 void __CPROVER_file_local_FreeRTOS_IP_c_prvProcessEthernetPacket( NetworkBufferDescriptor_t * const pxNetworkBuffer );
74
75 /* The harness test proceeds to call prvProcessEthernetPacket with an unconstrained value */
harness()76 void harness()
77 {
78 /* Needs a valid network buffer to be passed */
79 NetworkBufferDescriptor_t * pxNetworkBuffer = safeMalloc( sizeof( NetworkBufferDescriptor_t ) );
80
81 __CPROVER_assume( pxNetworkBuffer != NULL );
82
83 /* Minimum required length of the pxNetworkBuffer->xDataLength is at least the size of the EthernetHeader_t. */
84 __CPROVER_assume( ( pxNetworkBuffer->xDataLength >= ( sizeof( EthernetHeader_t ) ) ) && ( pxNetworkBuffer->xDataLength <= ipTOTAL_ETHERNET_FRAME_SIZE ) );
85
86 /* Needs a valid ethernet buffer to be passed */
87 pxNetworkBuffer->pucEthernetBuffer = ( ( ( uint8_t * ) safeMalloc( pxNetworkBuffer->xDataLength ) ) );
88 __CPROVER_assume( pxNetworkBuffer->pucEthernetBuffer != NULL );
89
90 __CPROVER_file_local_FreeRTOS_IP_c_prvProcessEthernetPacket( pxNetworkBuffer );
91 }
92