Skip to content

ABI Layer 2: prove linear-pointer memory safety (no use-after-free/double-free) — flagship Idris2 proof#44

Merged
hyperpolymath merged 1 commit into
mainfrom
claude/new-session-znxgm7
Jun 27, 2026
Merged

ABI Layer 2: prove linear-pointer memory safety (no use-after-free/double-free) — flagship Idris2 proof#44
hyperpolymath merged 1 commit into
mainfrom
claude/new-session-znxgm7

Conversation

@hyperpolymath

Copy link
Copy Markdown
Owner

Summary

Raises atsiser's Idris2 ABI to Layer 2 with its first flagship semantic proof. atsiser's headline is wrapping C in ATS linear types for zero-cost memory safety; this proves the defining guarantee: a pointer carries an explicit Live/Freed state, the Accessible permission (to dereference or free) has a constructor only for Live pointers, and free consumes a Live pointer with its witness into a Freed one — so use-after-free and double-free are unrepresentable.

Mirrors the estate flagship-proof pattern: state model, proposition uninhabited on the bad case, sound+complete Dec, certifier proven sound, positive + negative controls.

Changes

  • Adds src/interface/abi/Atsiser/ABI/Semantics.idrPtr/PtrState, Accessible, free, decAccessible, certifyAccessSound, and negative control freedNotAccessible.
  • Registers the module in atsiser-abi.ipkg.

RSR Quality Checklist

Required

  • Tests pass — ABI builds clean (see Testing)
  • Linter clean — zero warnings
  • No banned language patterns
  • No banned functions — genuine proof
  • SPDX headers present
  • No secrets

As Applicable

  • ABI/FFI changes validated — additive proof; FFI untouched

Testing

Verified with Idris2 0.7.0: idris2 --build atsiser-abi.ipkg → exit 0, zero warnings. Adversarial check: a deliberately-false proof (Accessible (MkPtr 4096 Freed)) was rejected. build/ removed.

🤖 Generated with Claude Code

https://claude.ai/code/session_01A6PSzJWpRxtzGDjUCEh7Mx


Generated by Claude Code

Flagship semantic proof: a pointer with explicit Live/Freed state; an
`Accessible` permission with a constructor only for Live pointers, so
use-after-free and double-free are unrepresentable. `free` consumes a
Live pointer (with its witness) into a Freed one. Sound+complete Dec,
certifier soundness, positive + negative controls. Verified with idris2
0.7.0 (build clean, zero warnings) + adversarial false-proof rejection.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01A6PSzJWpRxtzGDjUCEh7Mx
@hyperpolymath hyperpolymath marked this pull request as ready for review June 27, 2026 22:16
@hyperpolymath hyperpolymath merged commit 4ad7cb3 into main Jun 27, 2026
21 of 22 checks passed
@hyperpolymath hyperpolymath deleted the claude/new-session-znxgm7 branch June 27, 2026 22:16
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants