Skip to content
Snippets Groups Projects
Commit 59ea0fe4 authored by Thomas Sewell's avatar Thomas Sewell
Browse files

Assertions to lean on abstract refinement.

We can't prove that the caller cap must be a reply cap or that
the frames mapped in an arbitrary address space are backed by caps
without appealing to the abstract invariants, which means yet more
assertions in haskell and work in the abstract/haskell refinement.
parent dcf9707a
No related branches found
No related tags found
No related merge requests found
Loading
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment