Repository navigation
Fix semantics of onehot0: at most one bit set - #9166
Merged
Merged
Conversation
onehot0_exprt is meant to model SystemVerilog's $onehot0 (IEEE 1800-2017 20.9), which is true iff at most one bit of the operand is set, i.e., the operand is either one-hot or zero. The implementation (both the boolbv flattening and the lowering used by the SMT2 back-end) instead computed "exactly one bit is zero", i.e., onehot of the bitwise negation. Under an assumption $onehot0(x) this let a 4-bit x take the value 4'b1011. Fix the flattening, the lowering, and the class documentation, and correct the unit tests, which encoded the wrong semantics. onehot and onehot0 now differ exactly on the zero vector. Co-authored-by: Kiro <kiro-agent@users.noreply.github.com>
tautschnig
requested review from
kroening,
martin-cs and
peterschrammel
as code owners
September 22, 2026 07:14
There was a problem hiding this comment.
Copilot review overview
🟢 Approval recommended
The semantics, documentation, and regression tests are consistently corrected.
Review effort: Lite
Findings: None
What changed in this PR
Corrects $onehot0 to accept vectors with zero or one set bit.
Changes:
- Fixes expression lowering and BoolBV semantics.
- Updates class documentation.
- Corrects unit tests.
| File | Description |
|---|---|
unit/util/bitvector_expr.cpp |
Updates lowering tests. |
unit/solvers/flattening/boolbv_onehot.cpp |
Updates flattening tests. |
src/util/bitvector_expr.h |
Documents corrected semantics. |
src/util/bitvector_expr.cpp |
Corrects expression lowering. |
src/solvers/flattening/boolbv_onehot.cpp |
Applies at-most-one semantics. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## develop #9166 +/- ##
========================================
Coverage 80.83% 80.84%
========================================
Files 1717 1717
Lines 190069 190084 +15
Branches 73 73
========================================
+ Hits 153647 153678 +31
+ Misses 36422 36406 -16 ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
kroening
approved these changes
Sep 22, 2026
tautschnig
added a commit
to diffblue/hw-cbmc
that referenced
this pull request
Sep 22, 2026
Per IEEE 1800-2017 section 20.9, $onehot0(expr) returns true iff at most one bit of expr is set, i.e., expr is one-hot or zero. Both the Verilog constant folder and CBMC's onehot0_exprt (flattening and SMT2 lowering) instead computed "exactly one bit is zero". As a consequence, an assumption $onehot0(x) permitted, e.g., x == 4'b1011. The constant folder now checks $countones(expr) <= 1. The CBMC submodule is bumped to include the fix of onehot0_exprt (diffblue/cbmc#9166). The existing tests onehot1 and system_verilog_assertion3 encoded the wrong semantics and are corrected; the new test onehot2 uses $onehot0 on a free input in an assumption, which exercises the solver back-ends rather than the constant folder. Co-authored-by: Kiro <kiro-agent@users.noreply.github.com>
kroening
pushed a commit
to diffblue/hw-cbmc
that referenced
this pull request
Sep 27, 2026
Per IEEE 1800-2017 section 20.9, $onehot0(expr) returns true iff at most one bit of expr is set, i.e., expr is one-hot or zero. Both the Verilog constant folder and CBMC's onehot0_exprt (flattening and SMT2 lowering) instead computed "exactly one bit is zero". As a consequence, an assumption $onehot0(x) permitted, e.g., x == 4'b1011. The constant folder now checks $countones(expr) <= 1. The CBMC submodule is bumped to include the fix of onehot0_exprt (diffblue/cbmc#9166). The existing tests onehot1 and system_verilog_assertion3 encoded the wrong semantics and are corrected; the new test onehot2 uses $onehot0 on a free input in an assumption, which exercises the solver back-ends rather than the constant folder. Co-authored-by: Kiro <kiro-agent@users.noreply.github.com>
tautschnig
added a commit
to diffblue/hw-cbmc
that referenced
this pull request
Sep 28, 2026
Per IEEE 1800-2017 section 20.9, $onehot0(expr) returns true iff at most one bit of expr is set, i.e., expr is one-hot or zero. Both the Verilog constant folder and CBMC's onehot0_exprt (flattening and SMT2 lowering) instead computed "exactly one bit is zero". As a consequence, an assumption $onehot0(x) permitted, e.g., x == 4'b1011. The constant folder now checks $countones(expr) <= 1. The CBMC submodule is bumped to include the fix of onehot0_exprt (diffblue/cbmc#9166). The existing tests onehot1 and system_verilog_assertion3 encoded the wrong semantics and are corrected; the new test onehot2 uses $onehot0 on a free input in an assumption, which exercises the solver back-ends rather than the constant folder. Co-authored-by: Kiro <kiro-agent@users.noreply.github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
onehot0_exprt is meant to model SystemVerilog's $onehot0 (IEEE 1800-2017 20.9), which is true iff at most one bit of the operand is set, i.e., the operand is either one-hot or zero. The implementation (both the boolbv flattening and the lowering used by the SMT2 back-end) instead computed "exactly one bit is zero", i.e., onehot of the bitwise negation. Under an assumption $onehot0(x) this let a 4-bit x take the value 4'b1011.
Fix the flattening, the lowering, and the class documentation, and correct the unit tests, which encoded the wrong semantics. onehot and onehot0 now differ exactly on the zero vector.