The first one is the main file, the rest only supply rules for individual theories and modules.

Expr: separate firstorder "expr" and higherorder "cexp" Dexpr: add an "absurd" branch for nonexhaustive matches in programs

Sessions may contain the status "stepslimitexceeded", but this was not actually parsed by the session parser. Now fixed.

characters '. ", <, > and &

this is of course unsafe, yet useful if you have proved absence of overflows independently or if you are happy with a partial correctness proof (that is, if there is no overflow then the postcondition holds) this is work in progress; nothing plugged in yet

p labeled with label "model_projected" for that it exists a projection function f creates declaration of new constant c and axiom stating that c = f p Projection functions are functions tagged with meta "model_projection". Function f is projection function for abstract function and predicate p if f is tagged with meta "model_projection" and has a single argument of the same type as is the type of p. This transformation is needed in situations when we want to display not value of a variable, but value of a projection function applied to a variable. Note that since Why3 supports namespaces (different projection functions can have the same name) and input languages of solvers typically not, Why3 renames projection functions to avoid name clashes. This is why it is not possible to just store the name of the projection function in a label and than query the solver directly for the value of the projection. Also, it means that this transformation should thus be executed before this renaming.

MARCHE Claude authored

