111
|
1 ------------------------------------------------------------------------------
|
|
2 -- --
|
|
3 -- GNAT COMPILER COMPONENTS --
|
|
4 -- --
|
|
5 -- S Y S T E M . R I D E N T --
|
|
6 -- --
|
|
7 -- S p e c --
|
|
8 -- --
|
|
9 -- Copyright (C) 1992-2017, Free Software Foundation, Inc. --
|
|
10 -- --
|
|
11 -- GNAT is free software; you can redistribute it and/or modify it under --
|
|
12 -- terms of the GNU General Public License as published by the Free Soft- --
|
|
13 -- ware Foundation; either version 3, or (at your option) any later ver- --
|
|
14 -- sion. GNAT is distributed in the hope that it will be useful, but WITH- --
|
|
15 -- OUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY --
|
|
16 -- or FITNESS FOR A PARTICULAR PURPOSE. --
|
|
17 -- --
|
|
18 -- As a special exception under Section 7 of GPL version 3, you are granted --
|
|
19 -- additional permissions described in the GCC Runtime Library Exception, --
|
|
20 -- version 3.1, as published by the Free Software Foundation. --
|
|
21 -- --
|
|
22 -- You should have received a copy of the GNU General Public License and --
|
|
23 -- a copy of the GCC Runtime Library Exception along with this program; --
|
|
24 -- see the files COPYING3 and COPYING.RUNTIME respectively. If not, see --
|
|
25 -- <http://www.gnu.org/licenses/>. --
|
|
26 -- --
|
|
27 -- GNAT was originally developed by the GNAT team at New York University. --
|
|
28 -- Extensive contributions were provided by Ada Core Technologies Inc. --
|
|
29 -- --
|
|
30 ------------------------------------------------------------------------------
|
|
31
|
|
32 -- This package defines the set of restriction identifiers. It is a generic
|
|
33 -- package that is instantiated by the compiler/binder in package Rident, and
|
|
34 -- is instantiated in package System.Restrictions for use at run-time.
|
|
35
|
|
36 -- The reason that we make this a generic package is so that in the case of
|
|
37 -- the instantiation in Rident for use at compile time and bind time, we can
|
|
38 -- generate normal image tables for the enumeration types, which are needed
|
|
39 -- for diagnostic and informational messages. At run-time we really do not
|
|
40 -- want to waste the space for these image tables, and they are not needed,
|
|
41 -- so we can do the instantiation under control of Discard_Names to remove
|
|
42 -- the tables.
|
|
43
|
|
44 ---------------------------------------------------
|
|
45 -- Note On Compile/Run-Time Consistency Checking --
|
|
46 ---------------------------------------------------
|
|
47
|
|
48 -- This unit is with'ed by the run-time (to make System.Restrictions which is
|
|
49 -- used for run-time access to restriction information), by the compiler (to
|
|
50 -- determine what restrictions are implemented and what their category is) and
|
|
51 -- by the binder (in processing ali files, and generating the information used
|
|
52 -- at run-time to access restriction information).
|
|
53
|
|
54 -- Normally the version of System.Rident referenced in all three contexts
|
|
55 -- should be the same. However, problems could arise in certain inconsistent
|
|
56 -- builds that used inconsistent versions of the compiler and run-time. This
|
|
57 -- sort of thing is not strictly correct, but it does arise when short-cuts
|
|
58 -- are taken in build procedures.
|
|
59
|
|
60 -- Previously, this kind of inconsistency could cause a significant problem.
|
|
61 -- If versions of System.Rident accessed by the compiler and binder differed,
|
|
62 -- then the binder could fail to recognize the R (restrictions line) in the
|
|
63 -- ali file, leading to bind errors when restrictions were added or removed.
|
|
64
|
|
65 -- The latest implementation avoids both this problem by using a named
|
|
66 -- scheme for recording restrictions, rather than a positional scheme which
|
|
67 -- fails completely if restrictions are added or subtracted. Now the worst
|
|
68 -- that happens at bind time in inconsistent builds is that unrecognized
|
|
69 -- restrictions are ignored, and the consistency checking for restrictions
|
|
70 -- might be incomplete, which is no big deal.
|
|
71
|
|
72 pragma Compiler_Unit_Warning;
|
|
73
|
|
74 generic
|
|
75 package System.Rident is
|
|
76 pragma Preelaborate;
|
|
77
|
|
78 -- The following enumeration type defines the set of restriction
|
|
79 -- identifiers that are implemented in GNAT.
|
|
80
|
|
81 -- To add a new restriction identifier, add an entry with the name to be
|
|
82 -- used in the pragma, and add calls to the Restrict.Check_Restriction
|
|
83 -- routine as appropriate.
|
|
84
|
|
85 type Restriction_Id is
|
|
86
|
|
87 -- The following cases are checked for consistency in the binder. The
|
|
88 -- binder will check that every unit either has the restriction set, or
|
|
89 -- does not violate the restriction.
|
|
90
|
|
91 (Simple_Barriers, -- Ada 2012 (D.7 (10.9/3))
|
|
92 Pure_Barriers, -- GNAT
|
|
93 No_Abort_Statements, -- (RM D.7(5), H.4(3))
|
|
94 No_Access_Parameter_Allocators, -- Ada 2012 (RM H.4 (8.3/3))
|
|
95 No_Access_Subprograms, -- (RM H.4(17))
|
|
96 No_Allocators, -- (RM H.4(7))
|
|
97 No_Anonymous_Allocators, -- Ada 2012 (RM H.4(8/1))
|
|
98 No_Asynchronous_Control, -- (RM J.13(3/2)
|
|
99 No_Calendar, -- GNAT
|
|
100 No_Coextensions, -- Ada 2012 (RM H.4(8.2/3))
|
|
101 No_Default_Stream_Attributes, -- Ada 2012 (RM 13.12.1(4/2))
|
|
102 No_Delay, -- (RM H.4(21))
|
|
103 No_Direct_Boolean_Operators, -- GNAT
|
|
104 No_Dispatch, -- (RM H.4(19))
|
|
105 No_Dispatching_Calls, -- GNAT
|
|
106 No_Dynamic_Attachment, -- Ada 2012 (RM E.7(10/3))
|
|
107 No_Dynamic_Priorities, -- (RM D.9(9))
|
|
108 No_Enumeration_Maps, -- GNAT
|
|
109 No_Entry_Calls_In_Elaboration_Code, -- GNAT
|
|
110 No_Entry_Queue, -- GNAT (Ravenscar)
|
|
111 No_Exception_Handlers, -- GNAT
|
|
112 No_Exception_Propagation, -- GNAT
|
|
113 No_Exception_Registration, -- GNAT
|
|
114 No_Exceptions, -- (RM H.4(12))
|
|
115 No_Finalization, -- GNAT
|
|
116 No_Fixed_IO, -- GNAT
|
|
117 No_Fixed_Point, -- (RM H.4(15))
|
|
118 No_Floating_Point, -- (RM H.4(14))
|
|
119 No_IO, -- (RM H.4(20))
|
|
120 No_Implicit_Conditionals, -- GNAT
|
|
121 No_Implicit_Dynamic_Code, -- GNAT
|
|
122 No_Implicit_Heap_Allocations, -- (RM D.8(8), H.4(3))
|
|
123 No_Implicit_Task_Allocations, -- GNAT
|
|
124 No_Implicit_Protected_Object_Allocations, -- GNAT
|
|
125 No_Initialize_Scalars, -- GNAT
|
|
126 No_Local_Allocators, -- (RM H.4(8))
|
|
127 No_Local_Timing_Events, -- (RM D.7(10.2/2))
|
|
128 No_Local_Protected_Objects, -- Ada 2012 (D.7(10/1.3))
|
|
129 No_Long_Long_Integers, -- GNAT
|
|
130 No_Multiple_Elaboration, -- GNAT
|
|
131 No_Nested_Finalization, -- (RM D.7(4))
|
|
132 No_Protected_Type_Allocators, -- Ada 2012 (D.7 (10.3/2))
|
|
133 No_Protected_Types, -- (RM H.4(5))
|
|
134 No_Recursion, -- (RM H.4(22))
|
|
135 No_Reentrancy, -- (RM H.4(23))
|
|
136 No_Relative_Delay, -- Ada 2012 (D.7 (10.5/3))
|
|
137 No_Requeue_Statements, -- Ada 2012 (D.7 (10.6/3))
|
|
138 No_Secondary_Stack, -- GNAT
|
|
139 No_Select_Statements, -- Ada 2012 (D.7 (10.7/4))
|
|
140 No_Specific_Termination_Handlers, -- (RM D.7(10.7/2))
|
|
141 No_Standard_Allocators_After_Elaboration, -- Ada 2012 (RM D.7(19.1/2))
|
|
142 No_Standard_Storage_Pools, -- GNAT
|
|
143 No_Stream_Optimizations, -- GNAT
|
|
144 No_Streams, -- GNAT
|
|
145 No_Task_Allocators, -- (RM D.7(7))
|
|
146 No_Task_Attributes_Package, -- GNAT
|
|
147 No_Task_At_Interrupt_Priority, -- GNAT
|
|
148 No_Task_Hierarchy, -- (RM D.7(3), H.4(3))
|
|
149 No_Task_Termination, -- GNAT (Ravenscar)
|
|
150 No_Tasking, -- GNAT
|
|
151 No_Terminate_Alternatives, -- (RM D.7(6))
|
|
152 No_Unchecked_Access, -- (RM H.4(18))
|
|
153 No_Unchecked_Conversion, -- (RM J.13(4/2))
|
|
154 No_Unchecked_Deallocation, -- (RM J.13(5/2))
|
|
155 Static_Priorities, -- GNAT
|
|
156 Static_Storage_Size, -- GNAT
|
|
157
|
|
158 -- The following require consistency checking with special rules. See
|
|
159 -- individual routines in unit Bcheck for details of what is required.
|
|
160
|
|
161 No_Default_Initialization, -- GNAT
|
|
162
|
|
163 -- The following cases do not require consistency checking and if used
|
|
164 -- as a configuration pragma within a specific unit, apply only to that
|
|
165 -- unit (e.g. if used in the package spec, do not apply to the body)
|
|
166
|
|
167 -- Note: No_Elaboration_Code is handled specially. Like the other
|
|
168 -- non-partition-wide restrictions, it can only be set in a unit that
|
|
169 -- is part of the extended main source unit (body/spec/subunits). But
|
|
170 -- it is sticky, in that if it is found anywhere within any of these
|
|
171 -- units, it applies to all units in this extended main source.
|
|
172
|
|
173 Immediate_Reclamation, -- (RM H.4(10))
|
|
174 No_Dynamic_Sized_Objects, -- GNAT
|
|
175 No_Implementation_Aspect_Specifications, -- Ada 2012 AI-241
|
|
176 No_Implementation_Attributes, -- Ada 2005 AI-257
|
|
177 No_Implementation_Identifiers, -- Ada 2012 AI-246
|
|
178 No_Implementation_Pragmas, -- Ada 2005 AI-257
|
|
179 No_Implementation_Restrictions, -- GNAT
|
|
180 No_Implementation_Units, -- Ada 2012 AI-242
|
|
181 No_Implicit_Aliasing, -- GNAT
|
|
182 No_Implicit_Loops, -- GNAT
|
|
183 No_Elaboration_Code, -- GNAT
|
|
184 No_Obsolescent_Features, -- Ada 2005 AI-368
|
|
185 No_Wide_Characters, -- GNAT
|
|
186 SPARK_05, -- GNAT
|
|
187
|
|
188 -- The following cases require a parameter value
|
|
189
|
|
190 No_Specification_Of_Aspect, -- 2012 (RM 13.12.1 (6.1/3))
|
|
191 No_Use_Of_Attribute, -- 2012 (RM 13.12.1 (6.2/3))
|
|
192 No_Use_Of_Pragma, -- 2012 (RM 13.12.1 (6.3/3))
|
|
193
|
|
194 -- The following entries are fully checked at compile/bind time, which
|
|
195 -- means that the compiler can in general tell the minimum value which
|
|
196 -- could be used with a restrictions pragma. The binder can deduce the
|
|
197 -- appropriate minimum value for the partition by taking the maximum
|
|
198 -- value required by any unit.
|
|
199
|
|
200 Max_Protected_Entries, -- (RM D.7(14))
|
|
201 Max_Select_Alternatives, -- (RM D.7(12))
|
|
202 Max_Task_Entries, -- (RM D.7(13), H.4(3))
|
|
203
|
|
204 -- The following entries are also fully checked at compile/bind time,
|
|
205 -- and the compiler can also at least in some cases tell the minimum
|
|
206 -- value which could be used with a restriction pragma. The difference
|
|
207 -- is that the contributions are additive, so the binder deduces this
|
|
208 -- value by adding the unit contributions.
|
|
209
|
|
210 Max_Tasks, -- (RM D.7(19), H.4(3))
|
|
211
|
|
212 -- The following entries are checked at compile time only for zero/
|
|
213 -- nonzero entries. This means that the compiler can tell at compile
|
|
214 -- time if a restriction value of zero is (would be) violated, but that
|
|
215 -- the compiler cannot distinguish between different non-zero values.
|
|
216
|
|
217 Max_Asynchronous_Select_Nesting, -- (RM D.7(18), H.4(3))
|
|
218 Max_Entry_Queue_Length, -- Ada 2012 (RM D.7 (19.1/2))
|
|
219
|
|
220 -- The remaining entries are not checked at compile/bind time
|
|
221
|
|
222 Max_Storage_At_Blocking, -- (RM D.7(17))
|
|
223
|
|
224 Not_A_Restriction_Id);
|
|
225
|
|
226 -- Synonyms permitted for historical purposes of compatibility.
|
|
227 -- Must be coordinated with Restrict.Process_Restriction_Synonym.
|
|
228
|
|
229 Boolean_Entry_Barriers : Restriction_Id renames Simple_Barriers;
|
|
230 Max_Entry_Queue_Depth : Restriction_Id renames Max_Entry_Queue_Length;
|
|
231 No_Dynamic_Interrupts : Restriction_Id renames No_Dynamic_Attachment;
|
|
232 No_Requeue : Restriction_Id renames No_Requeue_Statements;
|
|
233 No_Task_Attributes : Restriction_Id renames No_Task_Attributes_Package;
|
|
234 SPARK : Restriction_Id renames SPARK_05;
|
|
235
|
|
236 subtype All_Restrictions is Restriction_Id range
|
|
237 Simple_Barriers .. Max_Storage_At_Blocking;
|
|
238 -- All restrictions (excluding only Not_A_Restriction_Id)
|
|
239
|
|
240 subtype All_Boolean_Restrictions is Restriction_Id range
|
|
241 Simple_Barriers .. SPARK_05;
|
|
242 -- All restrictions which do not take a parameter
|
|
243
|
|
244 subtype Partition_Boolean_Restrictions is All_Boolean_Restrictions range
|
|
245 Simple_Barriers .. Static_Storage_Size;
|
|
246 -- Boolean restrictions that are checked for partition consistency.
|
|
247 -- Note that all parameter restrictions are checked for partition
|
|
248 -- consistency by default, so this distinction is only needed in the
|
|
249 -- case of Boolean restrictions.
|
|
250
|
|
251 subtype Cunit_Boolean_Restrictions is All_Boolean_Restrictions range
|
|
252 Immediate_Reclamation .. SPARK_05;
|
|
253 -- Boolean restrictions that are not checked for partition consistency
|
|
254 -- and that thus apply only to the current unit. Note that for these
|
|
255 -- restrictions, the compiler does not apply restrictions found in
|
|
256 -- with'ed units, parent specs etc. to the main unit, and vice versa.
|
|
257
|
|
258 subtype All_Parameter_Restrictions is
|
|
259 Restriction_Id range
|
|
260 No_Specification_Of_Aspect .. Max_Storage_At_Blocking;
|
|
261 -- All restrictions that take a parameter
|
|
262
|
|
263 subtype Integer_Parameter_Restrictions is
|
|
264 Restriction_Id range
|
|
265 Max_Protected_Entries .. Max_Storage_At_Blocking;
|
|
266 -- All restrictions taking an integer parameter
|
|
267
|
|
268 subtype Checked_Parameter_Restrictions is
|
|
269 All_Parameter_Restrictions range
|
|
270 Max_Protected_Entries .. Max_Entry_Queue_Length;
|
|
271 -- These are the parameter restrictions that can be at least partially
|
|
272 -- checked at compile/binder time. Minimally, the compiler can detect
|
|
273 -- violations of a restriction pragma with a value of zero reliably.
|
|
274
|
|
275 subtype Checked_Max_Parameter_Restrictions is
|
|
276 Checked_Parameter_Restrictions range
|
|
277 Max_Protected_Entries .. Max_Task_Entries;
|
|
278 -- Restrictions with parameters that can be checked in some cases by
|
|
279 -- maximizing among statically detected instances where the compiler
|
|
280 -- can determine the count.
|
|
281
|
|
282 subtype Checked_Add_Parameter_Restrictions is
|
|
283 Checked_Parameter_Restrictions range
|
|
284 Max_Tasks .. Max_Tasks;
|
|
285 -- Restrictions with parameters that can be checked in some cases by
|
|
286 -- summing the statically detected instances where the compiler can
|
|
287 -- determine the count.
|
|
288
|
|
289 subtype Checked_Val_Parameter_Restrictions is
|
|
290 Checked_Parameter_Restrictions range
|
|
291 Max_Protected_Entries .. Max_Tasks;
|
|
292 -- Restrictions with parameter where the count is known at least in some
|
|
293 -- cases by the compiler/binder.
|
|
294
|
|
295 subtype Checked_Zero_Parameter_Restrictions is
|
|
296 Checked_Parameter_Restrictions range
|
|
297 Max_Asynchronous_Select_Nesting .. Max_Entry_Queue_Length;
|
|
298 -- Restrictions with parameters where the compiler can detect the use of
|
|
299 -- the feature, and hence violations of a restriction specifying a value
|
|
300 -- of zero, but cannot detect specific values other than zero/nonzero.
|
|
301
|
|
302 subtype Unchecked_Parameter_Restrictions is
|
|
303 All_Parameter_Restrictions range
|
|
304 Max_Storage_At_Blocking .. Max_Storage_At_Blocking;
|
|
305 -- Restrictions with parameters where the compiler cannot ever detect
|
|
306 -- corresponding compile time usage, so the binder and compiler never
|
|
307 -- detect violations of any restriction.
|
|
308
|
|
309 -------------------------------------
|
|
310 -- Restriction Status Declarations --
|
|
311 -------------------------------------
|
|
312
|
|
313 -- The following declarations are used to record the current status or
|
|
314 -- restrictions (for the current unit, or related units, at compile time,
|
|
315 -- and for all units in a partition at bind time or run time).
|
|
316
|
|
317 type Restriction_Flags is array (All_Restrictions) of Boolean;
|
|
318 type Restriction_Values is array (All_Parameter_Restrictions) of Natural;
|
|
319 type Parameter_Flags is array (All_Parameter_Restrictions) of Boolean;
|
|
320
|
|
321 type Restrictions_Info is record
|
|
322 Set : Restriction_Flags;
|
|
323 -- An entry is True in the Set array if a restrictions pragma has been
|
|
324 -- encountered for the given restriction. If the value is True for a
|
|
325 -- parameter restriction, then the corresponding entry in the Value
|
|
326 -- array gives the minimum value encountered for any such restriction.
|
|
327
|
|
328 Value : Restriction_Values;
|
|
329 -- If the entry for a parameter restriction in Set is True (i.e. a
|
|
330 -- restrictions pragma for the restriction has been encountered), then
|
|
331 -- the corresponding entry in the Value array is the minimum value
|
|
332 -- specified by any such restrictions pragma. Note that a restrictions
|
|
333 -- pragma specifying a value greater than Int'Last is simply ignored.
|
|
334
|
|
335 Violated : Restriction_Flags;
|
|
336 -- An entry is True in the violations array if the compiler has detected
|
|
337 -- a violation of the restriction. For a parameter restriction, the
|
|
338 -- Count and Unknown arrays have additional information.
|
|
339
|
|
340 Count : Restriction_Values;
|
|
341 -- If an entry for a parameter restriction is True in Violated, the
|
|
342 -- corresponding entry in the Count array may record additional
|
|
343 -- information. If the actual minimum count is known (by taking
|
|
344 -- maximums, or sums, depending on the restriction), it will be
|
|
345 -- recorded in this array. If not, then the value will remain zero.
|
|
346 -- The value is also zero for a non-violated restriction.
|
|
347
|
|
348 Unknown : Parameter_Flags;
|
|
349 -- If an entry for a parameter restriction is True in Violated, the
|
|
350 -- corresponding entry in the Unknown array may record additional
|
|
351 -- information. If the actual count is not known by the compiler (but
|
|
352 -- is known to be non-zero), then the entry in Unknown will be True.
|
|
353 -- This indicates that the value in Count is not known to be exact,
|
|
354 -- and the actual violation count may be higher.
|
|
355
|
|
356 -- Note: If Violated (K) is True, then either Count (K) > 0 or
|
|
357 -- Unknown (K) = True. It is possible for both these to be set.
|
|
358 -- For example, if Count (K) = 3 and Unknown (K) is True, it means
|
|
359 -- that the actual violation count is at least 3 but might be higher.
|
|
360 end record;
|
|
361
|
|
362 No_Restrictions : constant Restrictions_Info :=
|
|
363 (Set => (others => False),
|
|
364 Value => (others => 0),
|
|
365 Violated => (others => False),
|
|
366 Count => (others => 0),
|
|
367 Unknown => (others => False));
|
|
368 -- Used to initialize Restrictions_Info variables
|
|
369
|
|
370 ----------------------------------
|
|
371 -- Profile Definitions and Data --
|
|
372 ----------------------------------
|
|
373
|
|
374 -- Note: to add a profile, modify the following declarations appropriately,
|
|
375 -- add Name_xxx to Snames, and add a branch to the conditions for pragmas
|
|
376 -- Profile and Profile_Warnings in the body of Sem_Prag.
|
|
377
|
|
378 type Profile_Name is
|
|
379 (No_Profile,
|
|
380 No_Implementation_Extensions,
|
|
381 Restricted_Tasking,
|
|
382 Restricted,
|
|
383 Ravenscar,
|
|
384 GNAT_Extended_Ravenscar,
|
|
385 GNAT_Ravenscar_EDF);
|
|
386 -- Names of recognized profiles. No_Profile is used to indicate that a
|
|
387 -- restriction came from pragma Restrictions[_Warning], as opposed to
|
|
388 -- pragma Profile[_Warning]. Restricted_Tasking is a non-user profile that
|
|
389 -- contaings the minimal set of restrictions to trigger the user of the
|
|
390 -- restricted tasking runtime. Restricted is the corresponding user profile
|
|
391 -- that also restrict protected types.
|
|
392
|
|
393 subtype Profile_Name_Actual is Profile_Name
|
|
394 range No_Implementation_Extensions .. Profile_Name'Last;
|
|
395 -- Actual used profile names
|
|
396
|
|
397 type Profile_Data is record
|
|
398 Set : Restriction_Flags;
|
|
399 -- Set to True if given restriction must be set for the profile, and
|
|
400 -- False if it need not be set (False does not mean that it must not be
|
|
401 -- set, just that it need not be set). If the flag is True for a
|
|
402 -- parameter restriction, then the Value array gives the maximum value
|
|
403 -- permitted by the profile.
|
|
404
|
|
405 Value : Restriction_Values;
|
|
406 -- An entry in this array is meaningful only if the corresponding flag
|
|
407 -- in Set is True. In that case, the value in this array is the maximum
|
|
408 -- value of the parameter permitted by the profile.
|
|
409 end record;
|
|
410
|
|
411 Profile_Info : constant array (Profile_Name_Actual) of Profile_Data := (
|
|
412
|
|
413 -- No_Implementation_Extensions profile
|
|
414
|
|
415 No_Implementation_Extensions =>
|
|
416
|
|
417 (Set =>
|
|
418 (No_Implementation_Aspect_Specifications => True,
|
|
419 No_Implementation_Attributes => True,
|
|
420 No_Implementation_Identifiers => True,
|
|
421 No_Implementation_Pragmas => True,
|
|
422 No_Implementation_Units => True,
|
|
423 others => False),
|
|
424
|
|
425 -- Value settings for Restricted profile (none
|
|
426
|
|
427 Value =>
|
|
428 (others => 0)),
|
|
429
|
|
430 -- Restricted_Tasking Profile
|
|
431
|
|
432 Restricted_Tasking =>
|
|
433
|
|
434 -- Restrictions for Restricted_Tasking profile
|
|
435
|
|
436 (Set =>
|
|
437 (No_Abort_Statements => True,
|
|
438 No_Asynchronous_Control => True,
|
|
439 No_Dynamic_Attachment => True,
|
|
440 No_Dynamic_Priorities => True,
|
|
441 No_Local_Protected_Objects => True,
|
|
442 No_Protected_Type_Allocators => True,
|
|
443 No_Requeue_Statements => True,
|
|
444 No_Task_Allocators => True,
|
|
445 No_Task_Attributes_Package => True,
|
|
446 No_Task_Hierarchy => True,
|
|
447 No_Terminate_Alternatives => True,
|
|
448 Max_Asynchronous_Select_Nesting => True,
|
|
449 Max_Select_Alternatives => True,
|
|
450 Max_Task_Entries => True,
|
|
451 others => False),
|
|
452
|
|
453 -- Value settings for Restricted_Tasking profile
|
|
454
|
|
455 Value =>
|
|
456 (Max_Asynchronous_Select_Nesting => 0,
|
|
457 Max_Select_Alternatives => 0,
|
|
458 Max_Task_Entries => 0,
|
|
459 others => 0)),
|
|
460
|
|
461 -- Restricted Profile
|
|
462
|
|
463 Restricted =>
|
|
464
|
|
465 -- Restrictions for Restricted profile
|
|
466
|
|
467 (Set =>
|
|
468 (No_Abort_Statements => True,
|
|
469 No_Asynchronous_Control => True,
|
|
470 No_Dynamic_Attachment => True,
|
|
471 No_Dynamic_Priorities => True,
|
|
472 No_Entry_Queue => True,
|
|
473 No_Local_Protected_Objects => True,
|
|
474 No_Protected_Type_Allocators => True,
|
|
475 No_Requeue_Statements => True,
|
|
476 No_Task_Allocators => True,
|
|
477 No_Task_Attributes_Package => True,
|
|
478 No_Task_Hierarchy => True,
|
|
479 No_Terminate_Alternatives => True,
|
|
480 Max_Asynchronous_Select_Nesting => True,
|
|
481 Max_Protected_Entries => True,
|
|
482 Max_Select_Alternatives => True,
|
|
483 Max_Task_Entries => True,
|
|
484 others => False),
|
|
485
|
|
486 -- Value settings for Restricted profile
|
|
487
|
|
488 Value =>
|
|
489 (Max_Asynchronous_Select_Nesting => 0,
|
|
490 Max_Protected_Entries => 1,
|
|
491 Max_Select_Alternatives => 0,
|
|
492 Max_Task_Entries => 0,
|
|
493 others => 0)),
|
|
494
|
|
495 -- Ravenscar Profile
|
|
496
|
|
497 -- Note: the table entries here only represent the
|
|
498 -- required restriction profile for Ravenscar. The
|
|
499 -- full Ravenscar profile also requires:
|
|
500
|
|
501 -- pragma Dispatching_Policy (FIFO_Within_Priorities);
|
|
502 -- pragma Locking_Policy (Ceiling_Locking);
|
|
503 -- pragma Detect_Blocking;
|
|
504
|
|
505 Ravenscar =>
|
|
506
|
|
507 -- Restrictions for Ravenscar = Restricted profile ..
|
|
508
|
|
509 (Set =>
|
|
510 (No_Abort_Statements => True,
|
|
511 No_Asynchronous_Control => True,
|
|
512 No_Dynamic_Attachment => True,
|
|
513 No_Dynamic_Priorities => True,
|
|
514 No_Entry_Queue => True,
|
|
515 No_Local_Protected_Objects => True,
|
|
516 No_Protected_Type_Allocators => True,
|
|
517 No_Requeue_Statements => True,
|
|
518 No_Task_Allocators => True,
|
|
519 No_Task_Attributes_Package => True,
|
|
520 No_Task_Hierarchy => True,
|
|
521 No_Terminate_Alternatives => True,
|
|
522 Max_Asynchronous_Select_Nesting => True,
|
|
523 Max_Protected_Entries => True,
|
|
524 Max_Select_Alternatives => True,
|
|
525 Max_Task_Entries => True,
|
|
526
|
|
527 -- plus these additional restrictions:
|
|
528
|
|
529 No_Calendar => True,
|
|
530 No_Implicit_Heap_Allocations => True,
|
|
531 No_Local_Timing_Events => True,
|
|
532 No_Relative_Delay => True,
|
|
533 No_Select_Statements => True,
|
|
534 No_Specific_Termination_Handlers => True,
|
|
535 No_Task_Termination => True,
|
|
536 Simple_Barriers => True,
|
|
537 others => False),
|
|
538
|
|
539 -- Value settings for Ravenscar (same as Restricted)
|
|
540
|
|
541 Value =>
|
|
542 (Max_Asynchronous_Select_Nesting => 0,
|
|
543 Max_Protected_Entries => 1,
|
|
544 Max_Select_Alternatives => 0,
|
|
545 Max_Task_Entries => 0,
|
|
546 others => 0)),
|
|
547
|
|
548 GNAT_Extended_Ravenscar =>
|
|
549
|
|
550 -- Restrictions for GNAT_Extended_Ravenscar =
|
|
551 -- Restricted profile ..
|
|
552
|
|
553 (Set =>
|
|
554 (No_Abort_Statements => True,
|
|
555 No_Asynchronous_Control => True,
|
|
556 No_Dynamic_Attachment => True,
|
|
557 No_Dynamic_Priorities => True,
|
|
558 No_Local_Protected_Objects => True,
|
|
559 No_Protected_Type_Allocators => True,
|
|
560 No_Requeue_Statements => True,
|
|
561 No_Task_Allocators => True,
|
|
562 No_Task_Attributes_Package => True,
|
|
563 No_Task_Hierarchy => True,
|
|
564 No_Terminate_Alternatives => True,
|
|
565 Max_Asynchronous_Select_Nesting => True,
|
|
566 Max_Select_Alternatives => True,
|
|
567 Max_Task_Entries => True,
|
|
568
|
|
569 -- plus these additional restrictions:
|
|
570
|
|
571 No_Implicit_Task_Allocations => True,
|
|
572 No_Implicit_Protected_Object_Allocations
|
|
573 => True,
|
|
574 No_Local_Timing_Events => True,
|
|
575 No_Select_Statements => True,
|
|
576 No_Specific_Termination_Handlers => True,
|
|
577 No_Task_Termination => True,
|
|
578 Pure_Barriers => True,
|
|
579 others => False),
|
|
580
|
|
581 -- Value settings for Ravenscar (same as Restricted)
|
|
582
|
|
583 Value =>
|
|
584 (Max_Asynchronous_Select_Nesting => 0,
|
|
585 Max_Select_Alternatives => 0,
|
|
586 Max_Task_Entries => 0,
|
|
587 others => 0)),
|
|
588
|
|
589 -- GNAT_Ravenscar_EDF Profile
|
|
590
|
|
591 -- Note: the table entries here only represent the
|
|
592 -- required restriction profile for GNAT_Ravenscar_EDF.
|
|
593 -- The full GNAT_Ravenscar_EDF profile also requires:
|
|
594
|
|
595 -- pragma Dispatching_Policy (EDF_Across_Priorities);
|
|
596 -- pragma Locking_Policy (Ceiling_Locking);
|
|
597 -- pragma Detect_Blocking;
|
|
598
|
|
599 GNAT_Ravenscar_EDF =>
|
|
600
|
|
601 -- Restrictions for Ravenscar = Restricted profile ..
|
|
602
|
|
603 (Set =>
|
|
604 (No_Abort_Statements => True,
|
|
605 No_Asynchronous_Control => True,
|
|
606 No_Dynamic_Attachment => True,
|
|
607 No_Dynamic_Priorities => True,
|
|
608 No_Entry_Queue => True,
|
|
609 No_Local_Protected_Objects => True,
|
|
610 No_Protected_Type_Allocators => True,
|
|
611 No_Requeue_Statements => True,
|
|
612 No_Task_Allocators => True,
|
|
613 No_Task_Attributes_Package => True,
|
|
614 No_Task_Hierarchy => True,
|
|
615 No_Terminate_Alternatives => True,
|
|
616 Max_Asynchronous_Select_Nesting => True,
|
|
617 Max_Protected_Entries => True,
|
|
618 Max_Select_Alternatives => True,
|
|
619 Max_Task_Entries => True,
|
|
620
|
|
621 -- plus these additional restrictions:
|
|
622
|
|
623 No_Calendar => True,
|
|
624 No_Implicit_Heap_Allocations => True,
|
|
625 No_Local_Timing_Events => True,
|
|
626 No_Relative_Delay => True,
|
|
627 No_Select_Statements => True,
|
|
628 No_Specific_Termination_Handlers => True,
|
|
629 No_Task_Termination => True,
|
|
630 Simple_Barriers => True,
|
|
631 others => False),
|
|
632
|
|
633 -- Value settings for Ravenscar (same as Restricted)
|
|
634
|
|
635 Value =>
|
|
636 (Max_Asynchronous_Select_Nesting => 0,
|
|
637 Max_Protected_Entries => 1,
|
|
638 Max_Select_Alternatives => 0,
|
|
639 Max_Task_Entries => 0,
|
|
640 others => 0)));
|
|
641
|
|
642 end System.Rident;
|