2015-09-28 Paul Thomas <pault@gcc.gnu.org>
[official-gcc.git] / gcc / ada / s-rident.ads
blob7b18d2f40892458b8a2d3cf0457b2fc0326c968a
1 ------------------------------------------------------------------------------
2 -- --
3 -- GNAT COMPILER COMPONENTS --
4 -- --
5 -- S Y S T E M . R I D E N T --
6 -- --
7 -- S p e c --
8 -- --
9 -- Copyright (C) 1992-2015, Free Software Foundation, Inc. --
10 -- --
11 -- GNAT is free software; you can redistribute it and/or modify it under --
12 -- terms of the GNU General Public License as published by the Free Soft- --
13 -- ware Foundation; either version 3, or (at your option) any later ver- --
14 -- sion. GNAT is distributed in the hope that it will be useful, but WITH- --
15 -- OUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY --
16 -- or FITNESS FOR A PARTICULAR PURPOSE. --
17 -- --
18 -- As a special exception under Section 7 of GPL version 3, you are granted --
19 -- additional permissions described in the GCC Runtime Library Exception, --
20 -- version 3.1, as published by the Free Software Foundation. --
21 -- --
22 -- You should have received a copy of the GNU General Public License and --
23 -- a copy of the GCC Runtime Library Exception along with this program; --
24 -- see the files COPYING3 and COPYING.RUNTIME respectively. If not, see --
25 -- <http://www.gnu.org/licenses/>. --
26 -- --
27 -- GNAT was originally developed by the GNAT team at New York University. --
28 -- Extensive contributions were provided by Ada Core Technologies Inc. --
29 -- --
30 ------------------------------------------------------------------------------
32 -- This package defines the set of restriction identifiers. It is a generic
33 -- package that is instantiated by the compiler/binder in package Rident, and
34 -- is instantiated in package System.Restrictions for use at run-time.
36 -- The reason that we make this a generic package is so that in the case of
37 -- the instantiation in Rident for use at compile time and bind time, we can
38 -- generate normal image tables for the enumeration types, which are needed
39 -- for diagnostic and informational messages. At run-time we really do not
40 -- want to waste the space for these image tables, and they are not needed,
41 -- so we can do the instantiation under control of Discard_Names to remove
42 -- the tables.
44 ---------------------------------------------------
45 -- Note On Compile/Run-Time Consistency Checking --
46 ---------------------------------------------------
48 -- This unit is with'ed by the run-time (to make System.Restrictions which is
49 -- used for run-time access to restriction information), by the compiler (to
50 -- determine what restrictions are implemented and what their category is) and
51 -- by the binder (in processing ali files, and generating the information used
52 -- at run-time to access restriction information).
54 -- Normally the version of System.Rident referenced in all three contexts
55 -- should be the same. However, problems could arise in certain inconsistent
56 -- builds that used inconsistent versions of the compiler and run-time. This
57 -- sort of thing is not strictly correct, but it does arise when short-cuts
58 -- are taken in build procedures.
60 -- Previously, this kind of inconsistency could cause a significant problem.
61 -- If versions of System.Rident accessed by the compiler and binder differed,
62 -- then the binder could fail to recognize the R (restrictions line) in the
63 -- ali file, leading to bind errors when restrictions were added or removed.
65 -- The latest implementation avoids both this problem by using a named
66 -- scheme for recording restrictions, rather than a positional scheme which
67 -- fails completely if restrictions are added or subtracted. Now the worst
68 -- that happens at bind time in inconsistent builds is that unrecognized
69 -- restrictions are ignored, and the consistency checking for restrictions
70 -- might be incomplete, which is no big deal.
72 pragma Compiler_Unit_Warning;
74 generic
75 package System.Rident is
76 pragma Preelaborate;
78 -- The following enumeration type defines the set of restriction
79 -- identifiers that are implemented in GNAT.
81 -- To add a new restriction identifier, add an entry with the name to be
82 -- used in the pragma, and add calls to the Restrict.Check_Restriction
83 -- routine as appropriate.
85 type Restriction_Id is
87 -- The following cases are checked for consistency in the binder. The
88 -- binder will check that every unit either has the restriction set, or
89 -- does not violate the restriction.
91 (Simple_Barriers, -- Ada 2012 (D.7 (10.9/3))
92 No_Abort_Statements, -- (RM D.7(5), H.4(3))
93 No_Access_Parameter_Allocators, -- Ada 2012 (RM H.4 (8.3/3))
94 No_Access_Subprograms, -- (RM H.4(17))
95 No_Allocators, -- (RM H.4(7))
96 No_Anonymous_Allocators, -- Ada 2012 (RM H.4(8/1))
97 No_Asynchronous_Control, -- (RM J.13(3/2)
98 No_Calendar, -- GNAT
99 No_Coextensions, -- Ada 2012 (RM H.4(8.2/3))
100 No_Default_Stream_Attributes, -- Ada 2012 (RM 13.12.1(4/2))
101 No_Delay, -- (RM H.4(21))
102 No_Direct_Boolean_Operators, -- GNAT
103 No_Dispatch, -- (RM H.4(19))
104 No_Dispatching_Calls, -- GNAT
105 No_Dynamic_Attachment, -- Ada 2012 (RM E.7(10/3))
106 No_Dynamic_Priorities, -- (RM D.9(9))
107 No_Enumeration_Maps, -- GNAT
108 No_Entry_Calls_In_Elaboration_Code, -- GNAT
109 No_Entry_Queue, -- GNAT (Ravenscar)
110 No_Exception_Handlers, -- GNAT
111 No_Exception_Propagation, -- GNAT
112 No_Exception_Registration, -- GNAT
113 No_Exceptions, -- (RM H.4(12))
114 No_Finalization, -- GNAT
115 No_Fixed_IO, -- GNAT
116 No_Fixed_Point, -- (RM H.4(15))
117 No_Floating_Point, -- (RM H.4(14))
118 No_IO, -- (RM H.4(20))
119 No_Implicit_Conditionals, -- GNAT
120 No_Implicit_Dynamic_Code, -- GNAT
121 No_Implicit_Heap_Allocations, -- (RM D.8(8), H.4(3))
122 No_Implicit_Loops, -- GNAT
123 No_Initialize_Scalars, -- GNAT
124 No_Local_Allocators, -- (RM H.4(8))
125 No_Local_Timing_Events, -- (RM D.7(10.2/2))
126 No_Local_Protected_Objects, -- Ada 2012 (D.7(10/1.3))
127 No_Long_Long_Integers, -- GNAT
128 No_Multiple_Elaboration, -- GNAT
129 No_Nested_Finalization, -- (RM D.7(4))
130 No_Protected_Type_Allocators, -- Ada 2012 (D.7 (10.3/2))
131 No_Protected_Types, -- (RM H.4(5))
132 No_Recursion, -- (RM H.4(22))
133 No_Reentrancy, -- (RM H.4(23))
134 No_Relative_Delay, -- Ada 2012 (D.7 (10.5/3))
135 No_Requeue_Statements, -- Ada 2012 (D.7 (10.6/3))
136 No_Secondary_Stack, -- GNAT
137 No_Select_Statements, -- Ada 2012 (D.7 (10.7/4))
138 No_Specific_Termination_Handlers, -- (RM D.7(10.7/2))
139 No_Standard_Allocators_After_Elaboration, -- Ada 2012 (RM D.7(19.1/2))
140 No_Standard_Storage_Pools, -- GNAT
141 No_Stream_Optimizations, -- GNAT
142 No_Streams, -- GNAT
143 No_Task_Allocators, -- (RM D.7(7))
144 No_Task_Attributes_Package, -- GNAT
145 No_Task_Hierarchy, -- (RM D.7(3), H.4(3))
146 No_Task_Termination, -- GNAT (Ravenscar)
147 No_Tasking, -- GNAT
148 No_Terminate_Alternatives, -- (RM D.7(6))
149 No_Unchecked_Access, -- (RM H.4(18))
150 No_Unchecked_Conversion, -- (RM J.13(4/2))
151 No_Unchecked_Deallocation, -- (RM J.13(5/2))
152 Static_Priorities, -- GNAT
153 Static_Storage_Size, -- GNAT
155 -- The following require consistency checking with special rules. See
156 -- individual routines in unit Bcheck for details of what is required.
158 No_Default_Initialization, -- GNAT
160 -- The following cases do not require consistency checking and if used
161 -- as a configuration pragma within a specific unit, apply only to that
162 -- unit (e.g. if used in the package spec, do not apply to the body)
164 -- Note: No_Elaboration_Code is handled specially. Like the other
165 -- non-partition-wide restrictions, it can only be set in a unit that
166 -- is part of the extended main source unit (body/spec/subunits). But
167 -- it is sticky, in that if it is found anywhere within any of these
168 -- units, it applies to all units in this extended main source.
170 Immediate_Reclamation, -- (RM H.4(10))
171 No_Implementation_Aspect_Specifications, -- Ada 2012 AI-241
172 No_Implementation_Attributes, -- Ada 2005 AI-257
173 No_Implementation_Identifiers, -- Ada 2012 AI-246
174 No_Implementation_Pragmas, -- Ada 2005 AI-257
175 No_Implementation_Restrictions, -- GNAT
176 No_Implementation_Units, -- Ada 2012 AI-242
177 No_Implicit_Aliasing, -- GNAT
178 No_Elaboration_Code, -- GNAT
179 No_Obsolescent_Features, -- Ada 2005 AI-368
180 No_Wide_Characters, -- GNAT
181 SPARK_05, -- GNAT
183 -- The following cases require a parameter value
185 No_Specification_Of_Aspect, -- 2012 (RM 13.12.1 (6.1/3))
186 No_Use_Of_Attribute, -- 2012 (RM 13.12.1 (6.2/3))
187 No_Use_Of_Pragma, -- 2012 (RM 13.12.1 (6.3/3))
189 -- The following entries are fully checked at compile/bind time, which
190 -- means that the compiler can in general tell the minimum value which
191 -- could be used with a restrictions pragma. The binder can deduce the
192 -- appropriate minimum value for the partition by taking the maximum
193 -- value required by any unit.
195 Max_Protected_Entries, -- (RM D.7(14))
196 Max_Select_Alternatives, -- (RM D.7(12))
197 Max_Task_Entries, -- (RM D.7(13), H.4(3))
199 -- The following entries are also fully checked at compile/bind time,
200 -- and the compiler can also at least in some cases tell the minimum
201 -- value which could be used with a restriction pragma. The difference
202 -- is that the contributions are additive, so the binder deduces this
203 -- value by adding the unit contributions.
205 Max_Tasks, -- (RM D.7(19), H.4(3))
207 -- The following entries are checked at compile time only for zero/
208 -- nonzero entries. This means that the compiler can tell at compile
209 -- time if a restriction value of zero is (would be) violated, but that
210 -- the compiler cannot distinguish between different non-zero values.
212 Max_Asynchronous_Select_Nesting, -- (RM D.7(18), H.4(3))
213 Max_Entry_Queue_Length, -- Ada 2012 (RM D.7 (19.1/2))
215 -- The remaining entries are not checked at compile/bind time
217 Max_Storage_At_Blocking, -- (RM D.7(17))
219 Not_A_Restriction_Id);
221 -- Synonyms permitted for historical purposes of compatibility.
222 -- Must be coordinated with Restrict.Process_Restriction_Synonym.
224 Boolean_Entry_Barriers : Restriction_Id renames Simple_Barriers;
225 Max_Entry_Queue_Depth : Restriction_Id renames Max_Entry_Queue_Length;
226 No_Dynamic_Interrupts : Restriction_Id renames No_Dynamic_Attachment;
227 No_Requeue : Restriction_Id renames No_Requeue_Statements;
228 No_Task_Attributes : Restriction_Id renames No_Task_Attributes_Package;
229 SPARK : Restriction_Id renames SPARK_05;
231 subtype All_Restrictions is Restriction_Id range
232 Simple_Barriers .. Max_Storage_At_Blocking;
233 -- All restrictions (excluding only Not_A_Restriction_Id)
235 subtype All_Boolean_Restrictions is Restriction_Id range
236 Simple_Barriers .. SPARK_05;
237 -- All restrictions which do not take a parameter
239 subtype Partition_Boolean_Restrictions is All_Boolean_Restrictions range
240 Simple_Barriers .. Static_Storage_Size;
241 -- Boolean restrictions that are checked for partition consistency.
242 -- Note that all parameter restrictions are checked for partition
243 -- consistency by default, so this distinction is only needed in the
244 -- case of Boolean restrictions.
246 subtype Cunit_Boolean_Restrictions is All_Boolean_Restrictions range
247 Immediate_Reclamation .. SPARK_05;
248 -- Boolean restrictions that are not checked for partition consistency
249 -- and that thus apply only to the current unit. Note that for these
250 -- restrictions, the compiler does not apply restrictions found in
251 -- with'ed units, parent specs etc. to the main unit, and vice versa.
253 subtype All_Parameter_Restrictions is
254 Restriction_Id range
255 No_Specification_Of_Aspect .. Max_Storage_At_Blocking;
256 -- All restrictions that take a parameter
258 subtype Integer_Parameter_Restrictions is
259 Restriction_Id range
260 Max_Protected_Entries .. Max_Storage_At_Blocking;
261 -- All restrictions taking an integer parameter
263 subtype Checked_Parameter_Restrictions is
264 All_Parameter_Restrictions range
265 Max_Protected_Entries .. Max_Entry_Queue_Length;
266 -- These are the parameter restrictions that can be at least partially
267 -- checked at compile/binder time. Minimally, the compiler can detect
268 -- violations of a restriction pragma with a value of zero reliably.
270 subtype Checked_Max_Parameter_Restrictions is
271 Checked_Parameter_Restrictions range
272 Max_Protected_Entries .. Max_Task_Entries;
273 -- Restrictions with parameters that can be checked in some cases by
274 -- maximizing among statically detected instances where the compiler
275 -- can determine the count.
277 subtype Checked_Add_Parameter_Restrictions is
278 Checked_Parameter_Restrictions range
279 Max_Tasks .. Max_Tasks;
280 -- Restrictions with parameters that can be checked in some cases by
281 -- summing the statically detected instances where the compiler can
282 -- determine the count.
284 subtype Checked_Val_Parameter_Restrictions is
285 Checked_Parameter_Restrictions range
286 Max_Protected_Entries .. Max_Tasks;
287 -- Restrictions with parameter where the count is known at least in some
288 -- cases by the compiler/binder.
290 subtype Checked_Zero_Parameter_Restrictions is
291 Checked_Parameter_Restrictions range
292 Max_Asynchronous_Select_Nesting .. Max_Entry_Queue_Length;
293 -- Restrictions with parameters where the compiler can detect the use of
294 -- the feature, and hence violations of a restriction specifying a value
295 -- of zero, but cannot detect specific values other than zero/nonzero.
297 subtype Unchecked_Parameter_Restrictions is
298 All_Parameter_Restrictions range
299 Max_Storage_At_Blocking .. Max_Storage_At_Blocking;
300 -- Restrictions with parameters where the compiler cannot ever detect
301 -- corresponding compile time usage, so the binder and compiler never
302 -- detect violations of any restriction.
304 -------------------------------------
305 -- Restriction Status Declarations --
306 -------------------------------------
308 -- The following declarations are used to record the current status or
309 -- restrictions (for the current unit, or related units, at compile time,
310 -- and for all units in a partition at bind time or run time).
312 type Restriction_Flags is array (All_Restrictions) of Boolean;
313 type Restriction_Values is array (All_Parameter_Restrictions) of Natural;
314 type Parameter_Flags is array (All_Parameter_Restrictions) of Boolean;
316 type Restrictions_Info is record
317 Set : Restriction_Flags;
318 -- An entry is True in the Set array if a restrictions pragma has been
319 -- encountered for the given restriction. If the value is True for a
320 -- parameter restriction, then the corresponding entry in the Value
321 -- array gives the minimum value encountered for any such restriction.
323 Value : Restriction_Values;
324 -- If the entry for a parameter restriction in Set is True (i.e. a
325 -- restrictions pragma for the restriction has been encountered), then
326 -- the corresponding entry in the Value array is the minimum value
327 -- specified by any such restrictions pragma. Note that a restrictions
328 -- pragma specifying a value greater than Int'Last is simply ignored.
330 Violated : Restriction_Flags;
331 -- An entry is True in the violations array if the compiler has detected
332 -- a violation of the restriction. For a parameter restriction, the
333 -- Count and Unknown arrays have additional information.
335 Count : Restriction_Values;
336 -- If an entry for a parameter restriction is True in Violated, the
337 -- corresponding entry in the Count array may record additional
338 -- information. If the actual minimum count is known (by taking
339 -- maximums, or sums, depending on the restriction), it will be
340 -- recorded in this array. If not, then the value will remain zero.
341 -- The value is also zero for a non-violated restriction.
343 Unknown : Parameter_Flags;
344 -- If an entry for a parameter restriction is True in Violated, the
345 -- corresponding entry in the Unknown array may record additional
346 -- information. If the actual count is not known by the compiler (but
347 -- is known to be non-zero), then the entry in Unknown will be True.
348 -- This indicates that the value in Count is not known to be exact,
349 -- and the actual violation count may be higher.
351 -- Note: If Violated (K) is True, then either Count (K) > 0 or
352 -- Unknown (K) = True. It is possible for both these to be set.
353 -- For example, if Count (K) = 3 and Unknown (K) is True, it means
354 -- that the actual violation count is at least 3 but might be higher.
355 end record;
357 No_Restrictions : constant Restrictions_Info :=
358 (Set => (others => False),
359 Value => (others => 0),
360 Violated => (others => False),
361 Count => (others => 0),
362 Unknown => (others => False));
363 -- Used to initialize Restrictions_Info variables
365 ----------------------------------
366 -- Profile Definitions and Data --
367 ----------------------------------
369 -- Note: to add a profile, modify the following declarations appropriately,
370 -- add Name_xxx to Snames, and add a branch to the conditions for pragmas
371 -- Profile and Profile_Warnings in the body of Sem_Prag.
373 type Profile_Name is
374 (No_Profile,
375 No_Implementation_Extensions,
376 Ravenscar,
377 Restricted);
378 -- Names of recognized profiles. No_Profile is used to indicate that a
379 -- restriction came from pragma Restrictions[_Warning], as opposed to
380 -- pragma Profile[_Warning].
382 subtype Profile_Name_Actual is Profile_Name
383 range No_Implementation_Extensions .. Restricted;
384 -- Actual used profile names
386 type Profile_Data is record
387 Set : Restriction_Flags;
388 -- Set to True if given restriction must be set for the profile, and
389 -- False if it need not be set (False does not mean that it must not be
390 -- set, just that it need not be set). If the flag is True for a
391 -- parameter restriction, then the Value array gives the maximum value
392 -- permitted by the profile.
394 Value : Restriction_Values;
395 -- An entry in this array is meaningful only if the corresponding flag
396 -- in Set is True. In that case, the value in this array is the maximum
397 -- value of the parameter permitted by the profile.
398 end record;
400 Profile_Info : constant array (Profile_Name_Actual) of Profile_Data := (
402 -- No_Implementation_Extensions profile
404 No_Implementation_Extensions =>
406 (Set =>
407 (No_Implementation_Aspect_Specifications => True,
408 No_Implementation_Attributes => True,
409 No_Implementation_Identifiers => True,
410 No_Implementation_Pragmas => True,
411 No_Implementation_Units => True,
412 others => False),
414 -- Value settings for Restricted profile (none
416 Value =>
417 (others => 0)),
419 -- Restricted Profile
421 Restricted =>
423 -- Restrictions for Restricted profile
425 (Set =>
426 (No_Abort_Statements => True,
427 No_Asynchronous_Control => True,
428 No_Dynamic_Attachment => True,
429 No_Dynamic_Priorities => True,
430 No_Entry_Queue => True,
431 No_Local_Protected_Objects => True,
432 No_Protected_Type_Allocators => True,
433 No_Requeue_Statements => True,
434 No_Task_Allocators => True,
435 No_Task_Attributes_Package => True,
436 No_Task_Hierarchy => True,
437 No_Terminate_Alternatives => True,
438 Max_Asynchronous_Select_Nesting => True,
439 Max_Protected_Entries => True,
440 Max_Select_Alternatives => True,
441 Max_Task_Entries => True,
442 others => False),
444 -- Value settings for Restricted profile
446 Value =>
447 (Max_Asynchronous_Select_Nesting => 0,
448 Max_Protected_Entries => 1,
449 Max_Select_Alternatives => 0,
450 Max_Task_Entries => 0,
451 others => 0)),
453 -- Ravenscar Profile
455 -- Note: the table entries here only represent the
456 -- required restriction profile for Ravenscar. The
457 -- full Ravenscar profile also requires:
459 -- pragma Dispatching_Policy (FIFO_Within_Priorities);
460 -- pragma Locking_Policy (Ceiling_Locking);
461 -- pragma Detect_Blocking
463 Ravenscar =>
465 -- Restrictions for Ravenscar = Restricted profile ..
467 (Set =>
468 (No_Abort_Statements => True,
469 No_Asynchronous_Control => True,
470 No_Dynamic_Attachment => True,
471 No_Dynamic_Priorities => True,
472 No_Entry_Queue => True,
473 No_Local_Protected_Objects => True,
474 No_Protected_Type_Allocators => True,
475 No_Requeue_Statements => True,
476 No_Task_Allocators => True,
477 No_Task_Attributes_Package => True,
478 No_Task_Hierarchy => True,
479 No_Terminate_Alternatives => True,
480 Max_Asynchronous_Select_Nesting => True,
481 Max_Protected_Entries => True,
482 Max_Select_Alternatives => True,
483 Max_Task_Entries => True,
485 -- plus these additional restrictions:
487 No_Calendar => True,
488 No_Implicit_Heap_Allocations => True,
489 No_Local_Timing_Events => True,
490 No_Relative_Delay => True,
491 No_Select_Statements => True,
492 No_Specific_Termination_Handlers => True,
493 No_Task_Termination => True,
494 Simple_Barriers => True,
495 others => False),
497 -- Value settings for Ravenscar (same as Restricted)
499 Value =>
500 (Max_Asynchronous_Select_Nesting => 0,
501 Max_Protected_Entries => 1,
502 Max_Select_Alternatives => 0,
503 Max_Task_Entries => 0,
504 others => 0)));
506 end System.Rident;