src/HOL/Tools/inductive_package.ML
author wenzelm
Tue Apr 27 10:50:31 1999 +0200 (1999-04-27)
changeset 6521 16c425fc00cb
parent 6437 9bdfe07ba8e9
child 6556 daa00919502b
permissions -rw-r--r--
intrs attributes;
berghofe@5094
     1
(*  Title:      HOL/Tools/inductive_package.ML
berghofe@5094
     2
    ID:         $Id$
berghofe@5094
     3
    Author:     Lawrence C Paulson, Cambridge University Computer Laboratory
berghofe@5094
     4
                Stefan Berghofer,   TU Muenchen
berghofe@5094
     5
    Copyright   1994  University of Cambridge
berghofe@5094
     6
                1998  TU Muenchen     
berghofe@5094
     7
wenzelm@6424
     8
(Co)Inductive Definition module for HOL.
berghofe@5094
     9
berghofe@5094
    10
Features:
wenzelm@6424
    11
  * least or greatest fixedpoints
wenzelm@6424
    12
  * user-specified product and sum constructions
wenzelm@6424
    13
  * mutually recursive definitions
wenzelm@6424
    14
  * definitions involving arbitrary monotone operators
wenzelm@6424
    15
  * automatically proves introduction and elimination rules
berghofe@5094
    16
wenzelm@6424
    17
The recursive sets must *already* be declared as constants in the
wenzelm@6424
    18
current theory!
berghofe@5094
    19
berghofe@5094
    20
  Introduction rules have the form
berghofe@5094
    21
  [| ti:M(Sj), ..., P(x), ... |] ==> t: Sk |]
berghofe@5094
    22
  where M is some monotone operator (usually the identity)
berghofe@5094
    23
  P(x) is any side condition on the free variables
berghofe@5094
    24
  ti, t are any terms
berghofe@5094
    25
  Sj, Sk are two of the sets being defined in mutual recursion
berghofe@5094
    26
wenzelm@6424
    27
Sums are used only for mutual recursion.  Products are used only to
wenzelm@6424
    28
derive "streamlined" induction rules for relations.
berghofe@5094
    29
*)
berghofe@5094
    30
berghofe@5094
    31
signature INDUCTIVE_PACKAGE =
berghofe@5094
    32
sig
wenzelm@6424
    33
  val quiet_mode: bool ref
wenzelm@6437
    34
  val get_inductive: theory -> string ->
wenzelm@6437
    35
    {names: string list, coind: bool} * {defs: thm list, elims: thm list, raw_induct: thm,
wenzelm@6437
    36
      induct: thm, intrs: thm list, mk_cases: string -> thm, mono: thm, unfold: thm}
wenzelm@6437
    37
  val print_inductives: theory -> unit
wenzelm@6424
    38
  val add_inductive_i: bool -> bool -> bstring -> bool -> bool -> bool -> term list ->
wenzelm@6521
    39
    theory attribute list -> ((bstring * term) * theory attribute list) list ->
wenzelm@6521
    40
      thm list -> thm list -> theory -> theory *
wenzelm@6424
    41
      {defs: thm list, elims: thm list, raw_induct: thm, induct: thm,
wenzelm@6437
    42
       intrs: thm list, mk_cases: string -> thm, mono: thm, unfold: thm}
wenzelm@6521
    43
  val add_inductive: bool -> bool -> string list -> Args.src list ->
wenzelm@6521
    44
    ((bstring * string) * Args.src list) list -> (xstring * Args.src list) list ->
wenzelm@6521
    45
      (xstring * Args.src list) list -> theory -> theory *
wenzelm@6424
    46
      {defs: thm list, elims: thm list, raw_induct: thm, induct: thm,
wenzelm@6437
    47
       intrs: thm list, mk_cases: string -> thm, mono: thm, unfold: thm}
wenzelm@6437
    48
  val setup: (theory -> theory) list
berghofe@5094
    49
end;
berghofe@5094
    50
wenzelm@6424
    51
structure InductivePackage: INDUCTIVE_PACKAGE =
berghofe@5094
    52
struct
berghofe@5094
    53
wenzelm@6424
    54
(** utilities **)
wenzelm@6424
    55
wenzelm@6424
    56
(* messages *)
wenzelm@6424
    57
berghofe@5662
    58
val quiet_mode = ref false;
berghofe@5662
    59
fun message s = if !quiet_mode then () else writeln s;
berghofe@5662
    60
wenzelm@6424
    61
fun coind_prefix true = "co"
wenzelm@6424
    62
  | coind_prefix false = "";
wenzelm@6424
    63
wenzelm@6424
    64
wenzelm@6424
    65
(* misc *)
wenzelm@6424
    66
berghofe@5094
    67
(*For proving monotonicity of recursion operator*)
berghofe@5094
    68
val basic_monos = [subset_refl, imp_refl, disj_mono, conj_mono, 
berghofe@5094
    69
                   ex_mono, Collect_mono, in_mono, vimage_mono];
berghofe@5094
    70
berghofe@5094
    71
val Const _ $ (vimage_f $ _) $ _ = HOLogic.dest_Trueprop (concl_of vimageD);
berghofe@5094
    72
berghofe@5094
    73
(*Delete needless equality assumptions*)
berghofe@5094
    74
val refl_thin = prove_goal HOL.thy "!!P. [| a=a;  P |] ==> P"
berghofe@5094
    75
     (fn _ => [assume_tac 1]);
berghofe@5094
    76
berghofe@5094
    77
(*For simplifying the elimination rule*)
berghofe@5120
    78
val elim_rls = [asm_rl, FalseE, refl_thin, conjE, exE, Pair_inject];
berghofe@5094
    79
wenzelm@6394
    80
val vimage_name = Sign.intern_const (Theory.sign_of Vimage.thy) "op -``";
wenzelm@6394
    81
val mono_name = Sign.intern_const (Theory.sign_of Ord.thy) "mono";
berghofe@5094
    82
berghofe@5094
    83
(* make injections needed in mutually recursive definitions *)
berghofe@5094
    84
berghofe@5094
    85
fun mk_inj cs sumT c x =
berghofe@5094
    86
  let
berghofe@5094
    87
    fun mk_inj' T n i =
berghofe@5094
    88
      if n = 1 then x else
berghofe@5094
    89
      let val n2 = n div 2;
berghofe@5094
    90
          val Type (_, [T1, T2]) = T
berghofe@5094
    91
      in
berghofe@5094
    92
        if i <= n2 then
berghofe@5094
    93
          Const ("Inl", T1 --> T) $ (mk_inj' T1 n2 i)
berghofe@5094
    94
        else
berghofe@5094
    95
          Const ("Inr", T2 --> T) $ (mk_inj' T2 (n - n2) (i - n2))
berghofe@5094
    96
      end
berghofe@5094
    97
  in mk_inj' sumT (length cs) (1 + find_index_eq c cs)
berghofe@5094
    98
  end;
berghofe@5094
    99
berghofe@5094
   100
(* make "vimage" terms for selecting out components of mutually rec.def. *)
berghofe@5094
   101
berghofe@5094
   102
fun mk_vimage cs sumT t c = if length cs < 2 then t else
berghofe@5094
   103
  let
berghofe@5094
   104
    val cT = HOLogic.dest_setT (fastype_of c);
berghofe@5094
   105
    val vimageT = [cT --> sumT, HOLogic.mk_setT sumT] ---> HOLogic.mk_setT cT
berghofe@5094
   106
  in
berghofe@5094
   107
    Const (vimage_name, vimageT) $
berghofe@5094
   108
      Abs ("y", cT, mk_inj cs sumT c (Bound 0)) $ t
berghofe@5094
   109
  end;
berghofe@5094
   110
wenzelm@6424
   111
wenzelm@6424
   112
wenzelm@6424
   113
(** well-formedness checks **)
berghofe@5094
   114
berghofe@5094
   115
fun err_in_rule sign t msg = error ("Ill-formed introduction rule\n" ^
berghofe@5094
   116
  (Sign.string_of_term sign t) ^ "\n" ^ msg);
berghofe@5094
   117
berghofe@5094
   118
fun err_in_prem sign t p msg = error ("Ill-formed premise\n" ^
berghofe@5094
   119
  (Sign.string_of_term sign p) ^ "\nin introduction rule\n" ^
berghofe@5094
   120
  (Sign.string_of_term sign t) ^ "\n" ^ msg);
berghofe@5094
   121
berghofe@5094
   122
val msg1 = "Conclusion of introduction rule must have form\
berghofe@5094
   123
          \ ' t : S_i '";
berghofe@5094
   124
val msg2 = "Premises mentioning recursive sets must have form\
berghofe@5094
   125
          \ ' t : M S_i '";
berghofe@5094
   126
val msg3 = "Recursion term on left of member symbol";
berghofe@5094
   127
berghofe@5094
   128
fun check_rule sign cs r =
berghofe@5094
   129
  let
berghofe@5094
   130
    fun check_prem prem = if exists (Logic.occs o (rpair prem)) cs then
berghofe@5094
   131
         (case prem of
berghofe@5094
   132
           (Const ("op :", _) $ t $ u) =>
berghofe@5094
   133
             if exists (Logic.occs o (rpair t)) cs then
berghofe@5094
   134
               err_in_prem sign r prem msg3 else ()
berghofe@5094
   135
         | _ => err_in_prem sign r prem msg2)
berghofe@5094
   136
        else ()
berghofe@5094
   137
berghofe@5094
   138
  in (case (HOLogic.dest_Trueprop o Logic.strip_imp_concl) r of
berghofe@5094
   139
        (Const ("op :", _) $ _ $ u) =>
wenzelm@6424
   140
          if u mem cs then seq (check_prem o HOLogic.dest_Trueprop)
berghofe@5094
   141
            (Logic.strip_imp_prems r)
berghofe@5094
   142
          else err_in_rule sign r msg1
berghofe@5094
   143
      | _ => err_in_rule sign r msg1)
berghofe@5094
   144
  end;
berghofe@5094
   145
berghofe@5094
   146
fun try' f msg sign t = (f t) handle _ => error (msg ^ Sign.string_of_term sign t);
berghofe@5094
   147
wenzelm@6424
   148
berghofe@5094
   149
wenzelm@6437
   150
(*** theory data ***)
wenzelm@6437
   151
wenzelm@6437
   152
(* data kind 'HOL/inductive' *)
wenzelm@6437
   153
wenzelm@6437
   154
type inductive_info =
wenzelm@6437
   155
  {names: string list, coind: bool} * {defs: thm list, elims: thm list, raw_induct: thm,
wenzelm@6437
   156
    induct: thm, intrs: thm list, mk_cases: string -> thm, mono: thm, unfold: thm};
wenzelm@6437
   157
wenzelm@6437
   158
structure InductiveArgs =
wenzelm@6437
   159
struct
wenzelm@6437
   160
  val name = "HOL/inductive";
wenzelm@6437
   161
  type T = inductive_info Symtab.table;
wenzelm@6437
   162
wenzelm@6437
   163
  val empty = Symtab.empty;
wenzelm@6437
   164
  val prep_ext = I;
wenzelm@6437
   165
  val merge: T * T -> T = Symtab.merge (K true);
wenzelm@6437
   166
wenzelm@6437
   167
  fun print sg tab =
wenzelm@6437
   168
    Pretty.writeln (Pretty.strs ("(co)inductives:" ::
wenzelm@6437
   169
      map (Sign.cond_extern sg Sign.constK o fst) (Symtab.dest tab)));
wenzelm@6437
   170
end;
wenzelm@6437
   171
wenzelm@6437
   172
structure InductiveData = TheoryDataFun(InductiveArgs);
wenzelm@6437
   173
val print_inductives = InductiveData.print;
wenzelm@6437
   174
wenzelm@6437
   175
wenzelm@6437
   176
(* get and put data *)
wenzelm@6437
   177
wenzelm@6437
   178
fun get_inductive thy name =
wenzelm@6437
   179
  (case Symtab.lookup (InductiveData.get thy, name) of
wenzelm@6437
   180
    Some info => info
wenzelm@6437
   181
  | None => error ("Unknown (co)inductive set " ^ quote name));
wenzelm@6437
   182
wenzelm@6437
   183
fun put_inductives names info thy =
wenzelm@6437
   184
  let
wenzelm@6437
   185
    fun upd (tab, name) = Symtab.update_new ((name, info), tab);
wenzelm@6437
   186
    val tab = foldl upd (InductiveData.get thy, names)
wenzelm@6437
   187
      handle Symtab.DUP name => error ("Duplicate definition of (co)inductive set " ^ quote name);
wenzelm@6437
   188
  in InductiveData.put tab thy end;
wenzelm@6437
   189
wenzelm@6437
   190
wenzelm@6437
   191
wenzelm@6424
   192
(*** properties of (co)inductive sets ***)
wenzelm@6424
   193
wenzelm@6424
   194
(** elimination rules **)
berghofe@5094
   195
berghofe@5094
   196
fun mk_elims cs cTs params intr_ts =
berghofe@5094
   197
  let
berghofe@5094
   198
    val used = foldr add_term_names (intr_ts, []);
berghofe@5094
   199
    val [aname, pname] = variantlist (["a", "P"], used);
berghofe@5094
   200
    val P = HOLogic.mk_Trueprop (Free (pname, HOLogic.boolT));
berghofe@5094
   201
berghofe@5094
   202
    fun dest_intr r =
berghofe@5094
   203
      let val Const ("op :", _) $ t $ u =
berghofe@5094
   204
        HOLogic.dest_Trueprop (Logic.strip_imp_concl r)
berghofe@5094
   205
      in (u, t, Logic.strip_imp_prems r) end;
berghofe@5094
   206
berghofe@5094
   207
    val intrs = map dest_intr intr_ts;
berghofe@5094
   208
berghofe@5094
   209
    fun mk_elim (c, T) =
berghofe@5094
   210
      let
berghofe@5094
   211
        val a = Free (aname, T);
berghofe@5094
   212
berghofe@5094
   213
        fun mk_elim_prem (_, t, ts) =
berghofe@5094
   214
          list_all_free (map dest_Free ((foldr add_term_frees (t::ts, [])) \\ params),
berghofe@5094
   215
            Logic.list_implies (HOLogic.mk_Trueprop (HOLogic.mk_eq (a, t)) :: ts, P));
berghofe@5094
   216
      in
berghofe@5094
   217
        Logic.list_implies (HOLogic.mk_Trueprop (HOLogic.mk_mem (a, c)) ::
berghofe@5094
   218
          map mk_elim_prem (filter (equal c o #1) intrs), P)
berghofe@5094
   219
      end
berghofe@5094
   220
  in
berghofe@5094
   221
    map mk_elim (cs ~~ cTs)
berghofe@5094
   222
  end;
berghofe@5094
   223
        
wenzelm@6424
   224
wenzelm@6424
   225
wenzelm@6424
   226
(** premises and conclusions of induction rules **)
berghofe@5094
   227
berghofe@5094
   228
fun mk_indrule cs cTs params intr_ts =
berghofe@5094
   229
  let
berghofe@5094
   230
    val used = foldr add_term_names (intr_ts, []);
berghofe@5094
   231
berghofe@5094
   232
    (* predicates for induction rule *)
berghofe@5094
   233
berghofe@5094
   234
    val preds = map Free (variantlist (if length cs < 2 then ["P"] else
berghofe@5094
   235
      map (fn i => "P" ^ string_of_int i) (1 upto length cs), used) ~~
berghofe@5094
   236
        map (fn T => T --> HOLogic.boolT) cTs);
berghofe@5094
   237
berghofe@5094
   238
    (* transform an introduction rule into a premise for induction rule *)
berghofe@5094
   239
berghofe@5094
   240
    fun mk_ind_prem r =
berghofe@5094
   241
      let
berghofe@5094
   242
        val frees = map dest_Free ((add_term_frees (r, [])) \\ params);
berghofe@5094
   243
berghofe@5094
   244
        fun subst (prem as (Const ("op :", T) $ t $ u), prems) =
berghofe@5094
   245
              let val n = find_index_eq u cs in
berghofe@5094
   246
                if n >= 0 then prem :: (nth_elem (n, preds)) $ t :: prems else
berghofe@5094
   247
                  (subst_free (map (fn (c, P) => (c, HOLogic.mk_binop "op Int"
berghofe@5094
   248
                    (c, HOLogic.Collect_const (HOLogic.dest_setT
berghofe@5094
   249
                      (fastype_of c)) $ P))) (cs ~~ preds)) prem)::prems
berghofe@5094
   250
              end
berghofe@5094
   251
          | subst (prem, prems) = prem::prems;
berghofe@5094
   252
berghofe@5094
   253
        val Const ("op :", _) $ t $ u =
berghofe@5094
   254
          HOLogic.dest_Trueprop (Logic.strip_imp_concl r)
berghofe@5094
   255
berghofe@5094
   256
      in list_all_free (frees,
berghofe@5094
   257
           Logic.list_implies (map HOLogic.mk_Trueprop (foldr subst
berghofe@5094
   258
             (map HOLogic.dest_Trueprop (Logic.strip_imp_prems r), [])),
berghofe@5094
   259
               HOLogic.mk_Trueprop (nth_elem (find_index_eq u cs, preds) $ t)))
berghofe@5094
   260
      end;
berghofe@5094
   261
berghofe@5094
   262
    val ind_prems = map mk_ind_prem intr_ts;
berghofe@5094
   263
berghofe@5094
   264
    (* make conclusions for induction rules *)
berghofe@5094
   265
berghofe@5094
   266
    fun mk_ind_concl ((c, P), (ts, x)) =
berghofe@5094
   267
      let val T = HOLogic.dest_setT (fastype_of c);
berghofe@5094
   268
          val Ts = HOLogic.prodT_factors T;
berghofe@5094
   269
          val (frees, x') = foldr (fn (T', (fs, s)) =>
berghofe@5094
   270
            ((Free (s, T'))::fs, bump_string s)) (Ts, ([], x));
berghofe@5094
   271
          val tuple = HOLogic.mk_tuple T frees;
berghofe@5094
   272
      in ((HOLogic.mk_binop "op -->"
berghofe@5094
   273
        (HOLogic.mk_mem (tuple, c), P $ tuple))::ts, x')
berghofe@5094
   274
      end;
berghofe@5094
   275
berghofe@5094
   276
    val mutual_ind_concl = HOLogic.mk_Trueprop (foldr1 (app HOLogic.conj)
berghofe@5094
   277
        (fst (foldr mk_ind_concl (cs ~~ preds, ([], "xa")))))
berghofe@5094
   278
berghofe@5094
   279
  in (preds, ind_prems, mutual_ind_concl)
berghofe@5094
   280
  end;
berghofe@5094
   281
wenzelm@6424
   282
berghofe@5094
   283
wenzelm@6424
   284
(*** proofs for (co)inductive sets ***)
wenzelm@6424
   285
wenzelm@6424
   286
(** prove monotonicity **)
berghofe@5094
   287
berghofe@5094
   288
fun prove_mono setT fp_fun monos thy =
berghofe@5094
   289
  let
wenzelm@6427
   290
    val _ = message "  Proving monotonicity ...";
berghofe@5094
   291
wenzelm@6394
   292
    val mono = prove_goalw_cterm [] (cterm_of (Theory.sign_of thy) (HOLogic.mk_Trueprop
berghofe@5094
   293
      (Const (mono_name, (setT --> setT) --> HOLogic.boolT) $ fp_fun)))
berghofe@5094
   294
        (fn _ => [rtac monoI 1, REPEAT (ares_tac (basic_monos @ monos) 1)])
berghofe@5094
   295
berghofe@5094
   296
  in mono end;
berghofe@5094
   297
wenzelm@6424
   298
wenzelm@6424
   299
wenzelm@6424
   300
(** prove introduction rules **)
berghofe@5094
   301
berghofe@5094
   302
fun prove_intrs coind mono fp_def intr_ts con_defs rec_sets_defs thy =
berghofe@5094
   303
  let
wenzelm@6427
   304
    val _ = message "  Proving the introduction rules ...";
berghofe@5094
   305
berghofe@5094
   306
    val unfold = standard (mono RS (fp_def RS
berghofe@5094
   307
      (if coind then def_gfp_Tarski else def_lfp_Tarski)));
berghofe@5094
   308
berghofe@5094
   309
    fun select_disj 1 1 = []
berghofe@5094
   310
      | select_disj _ 1 = [rtac disjI1]
berghofe@5094
   311
      | select_disj n i = (rtac disjI2)::(select_disj (n - 1) (i - 1));
berghofe@5094
   312
berghofe@5094
   313
    val intrs = map (fn (i, intr) => prove_goalw_cterm rec_sets_defs
wenzelm@6394
   314
      (cterm_of (Theory.sign_of thy) intr) (fn prems =>
berghofe@5094
   315
       [(*insert prems and underlying sets*)
berghofe@5094
   316
       cut_facts_tac prems 1,
berghofe@5094
   317
       stac unfold 1,
berghofe@5094
   318
       REPEAT (resolve_tac [vimageI2, CollectI] 1),
berghofe@5094
   319
       (*Now 1-2 subgoals: the disjunction, perhaps equality.*)
berghofe@5094
   320
       EVERY1 (select_disj (length intr_ts) i),
berghofe@5094
   321
       (*Not ares_tac, since refl must be tried before any equality assumptions;
berghofe@5094
   322
         backtracking may occur if the premises have extra variables!*)
berghofe@5094
   323
       DEPTH_SOLVE_1 (resolve_tac [refl,exI,conjI] 1 APPEND assume_tac 1),
berghofe@5094
   324
       (*Now solve the equations like Inl 0 = Inl ?b2*)
berghofe@5094
   325
       rewrite_goals_tac con_defs,
berghofe@5094
   326
       REPEAT (rtac refl 1)])) (1 upto (length intr_ts) ~~ intr_ts)
berghofe@5094
   327
berghofe@5094
   328
  in (intrs, unfold) end;
berghofe@5094
   329
wenzelm@6424
   330
wenzelm@6424
   331
wenzelm@6424
   332
(** prove elimination rules **)
berghofe@5094
   333
berghofe@5094
   334
fun prove_elims cs cTs params intr_ts unfold rec_sets_defs thy =
berghofe@5094
   335
  let
wenzelm@6427
   336
    val _ = message "  Proving the elimination rules ...";
berghofe@5094
   337
berghofe@5094
   338
    val rules1 = [CollectE, disjE, make_elim vimageD];
berghofe@5094
   339
    val rules2 = [exE, conjE, Inl_neq_Inr, Inr_neq_Inl] @
berghofe@5094
   340
      map make_elim [Inl_inject, Inr_inject];
berghofe@5094
   341
berghofe@5094
   342
    val elims = map (fn t => prove_goalw_cterm rec_sets_defs
wenzelm@6394
   343
      (cterm_of (Theory.sign_of thy) t) (fn prems =>
berghofe@5094
   344
        [cut_facts_tac [hd prems] 1,
berghofe@5094
   345
         dtac (unfold RS subst) 1,
berghofe@5094
   346
         REPEAT (FIRSTGOAL (eresolve_tac rules1)),
berghofe@5094
   347
         REPEAT (FIRSTGOAL (eresolve_tac rules2)),
berghofe@5094
   348
         EVERY (map (fn prem =>
berghofe@5149
   349
           DEPTH_SOLVE_1 (ares_tac [prem, conjI] 1)) (tl prems))]))
berghofe@5094
   350
      (mk_elims cs cTs params intr_ts)
berghofe@5094
   351
berghofe@5094
   352
  in elims end;
berghofe@5094
   353
wenzelm@6424
   354
berghofe@5094
   355
(** derivation of simplified elimination rules **)
berghofe@5094
   356
berghofe@5094
   357
(*Applies freeness of the given constructors, which *must* be unfolded by
berghofe@5094
   358
  the given defs.  Cannot simply use the local con_defs because con_defs=[] 
berghofe@5094
   359
  for inference systems.
berghofe@5094
   360
 *)
paulson@6141
   361
fun con_elim_tac ss =
berghofe@5094
   362
  let val elim_tac = REPEAT o (eresolve_tac elim_rls)
berghofe@5094
   363
  in ALLGOALS(EVERY'[elim_tac,
paulson@6141
   364
		     asm_full_simp_tac ss,
paulson@6141
   365
		     elim_tac,
paulson@6141
   366
		     REPEAT o bound_hyp_subst_tac])
berghofe@5094
   367
     THEN prune_params_tac
berghofe@5094
   368
  end;
berghofe@5094
   369
berghofe@5094
   370
(*String s should have the form t:Si where Si is an inductive set*)
paulson@6141
   371
fun mk_cases elims s =
wenzelm@6394
   372
  let val prem = assume (read_cterm (Thm.sign_of_thm (hd elims)) (s, propT))
paulson@6141
   373
      fun mk_elim rl = rule_by_tactic (con_elim_tac (simpset())) (prem RS rl) 
paulson@6141
   374
	               |> standard
paulson@6141
   375
  in case find_first is_some (map (try mk_elim) elims) of
berghofe@5094
   376
       Some (Some r) => r
berghofe@5094
   377
     | None => error ("mk_cases: string '" ^ s ^ "' not of form 't : S_i'")
berghofe@5094
   378
  end;
berghofe@5094
   379
wenzelm@6424
   380
wenzelm@6424
   381
wenzelm@6424
   382
(** prove induction rule **)
berghofe@5094
   383
berghofe@5094
   384
fun prove_indrule cs cTs sumT rec_const params intr_ts mono
berghofe@5094
   385
    fp_def rec_sets_defs thy =
berghofe@5094
   386
  let
wenzelm@6427
   387
    val _ = message "  Proving the induction rule ...";
berghofe@5094
   388
wenzelm@6394
   389
    val sign = Theory.sign_of thy;
berghofe@5094
   390
berghofe@5094
   391
    val (preds, ind_prems, mutual_ind_concl) = mk_indrule cs cTs params intr_ts;
berghofe@5094
   392
berghofe@5094
   393
    (* make predicate for instantiation of abstract induction rule *)
berghofe@5094
   394
berghofe@5094
   395
    fun mk_ind_pred _ [P] = P
berghofe@5094
   396
      | mk_ind_pred T Ps =
berghofe@5094
   397
         let val n = (length Ps) div 2;
berghofe@5094
   398
             val Type (_, [T1, T2]) = T
berghofe@5094
   399
         in Const ("sum_case",
berghofe@5094
   400
           [T1 --> HOLogic.boolT, T2 --> HOLogic.boolT, T] ---> HOLogic.boolT) $
berghofe@5094
   401
             mk_ind_pred T1 (take (n, Ps)) $ mk_ind_pred T2 (drop (n, Ps))
berghofe@5094
   402
         end;
berghofe@5094
   403
berghofe@5094
   404
    val ind_pred = mk_ind_pred sumT preds;
berghofe@5094
   405
berghofe@5094
   406
    val ind_concl = HOLogic.mk_Trueprop
berghofe@5094
   407
      (HOLogic.all_const sumT $ Abs ("x", sumT, HOLogic.mk_binop "op -->"
berghofe@5094
   408
        (HOLogic.mk_mem (Bound 0, rec_const), ind_pred $ Bound 0)));
berghofe@5094
   409
berghofe@5094
   410
    (* simplification rules for vimage and Collect *)
berghofe@5094
   411
berghofe@5094
   412
    val vimage_simps = if length cs < 2 then [] else
berghofe@5094
   413
      map (fn c => prove_goalw_cterm [] (cterm_of sign
berghofe@5094
   414
        (HOLogic.mk_Trueprop (HOLogic.mk_eq
berghofe@5094
   415
          (mk_vimage cs sumT (HOLogic.Collect_const sumT $ ind_pred) c,
berghofe@5094
   416
           HOLogic.Collect_const (HOLogic.dest_setT (fastype_of c)) $
berghofe@5094
   417
             nth_elem (find_index_eq c cs, preds)))))
berghofe@5094
   418
        (fn _ => [rtac vimage_Collect 1, rewrite_goals_tac
oheimb@5553
   419
           (map mk_meta_eq [sum_case_Inl, sum_case_Inr]),
berghofe@5094
   420
          rtac refl 1])) cs;
berghofe@5094
   421
berghofe@5094
   422
    val induct = prove_goalw_cterm [] (cterm_of sign
berghofe@5094
   423
      (Logic.list_implies (ind_prems, ind_concl))) (fn prems =>
berghofe@5094
   424
        [rtac (impI RS allI) 1,
berghofe@5094
   425
         DETERM (etac (mono RS (fp_def RS def_induct)) 1),
oheimb@5553
   426
         rewrite_goals_tac (map mk_meta_eq (vimage_Int::vimage_simps)),
berghofe@5094
   427
         fold_goals_tac rec_sets_defs,
berghofe@5094
   428
         (*This CollectE and disjE separates out the introduction rules*)
berghofe@5094
   429
         REPEAT (FIRSTGOAL (eresolve_tac [CollectE, disjE])),
berghofe@5094
   430
         (*Now break down the individual cases.  No disjE here in case
berghofe@5094
   431
           some premise involves disjunction.*)
berghofe@5094
   432
         REPEAT (FIRSTGOAL (eresolve_tac [IntE, CollectE, exE, conjE] 
berghofe@5094
   433
                     ORELSE' hyp_subst_tac)),
oheimb@5553
   434
         rewrite_goals_tac (map mk_meta_eq [sum_case_Inl, sum_case_Inr]),
berghofe@5094
   435
         EVERY (map (fn prem =>
berghofe@5149
   436
           DEPTH_SOLVE_1 (ares_tac [prem, conjI, refl] 1)) prems)]);
berghofe@5094
   437
berghofe@5094
   438
    val lemma = prove_goalw_cterm rec_sets_defs (cterm_of sign
berghofe@5094
   439
      (Logic.mk_implies (ind_concl, mutual_ind_concl))) (fn prems =>
berghofe@5094
   440
        [cut_facts_tac prems 1,
berghofe@5094
   441
         REPEAT (EVERY
berghofe@5094
   442
           [REPEAT (resolve_tac [conjI, impI] 1),
berghofe@5094
   443
            TRY (dtac vimageD 1), etac allE 1, dtac mp 1, atac 1,
oheimb@5553
   444
            rewrite_goals_tac (map mk_meta_eq [sum_case_Inl, sum_case_Inr]),
berghofe@5094
   445
            atac 1])])
berghofe@5094
   446
berghofe@5094
   447
  in standard (split_rule (induct RS lemma))
berghofe@5094
   448
  end;
berghofe@5094
   449
wenzelm@6424
   450
wenzelm@6424
   451
wenzelm@6424
   452
(*** specification of (co)inductive sets ****)
wenzelm@6424
   453
wenzelm@6424
   454
(** definitional introduction of (co)inductive sets **)
berghofe@5094
   455
berghofe@5094
   456
fun add_ind_def verbose declare_consts alt_name coind no_elim no_ind cs
wenzelm@6521
   457
    atts intros monos con_defs thy params paramTs cTs cnames =
berghofe@5094
   458
  let
wenzelm@6424
   459
    val _ = if verbose then message ("Proofs for " ^ coind_prefix coind ^ "inductive set(s) " ^
wenzelm@6424
   460
      commas_quote cnames) else ();
berghofe@5094
   461
berghofe@5094
   462
    val sumT = fold_bal (fn (T, U) => Type ("+", [T, U])) cTs;
berghofe@5094
   463
    val setT = HOLogic.mk_setT sumT;
berghofe@5094
   464
wenzelm@6394
   465
    val fp_name = if coind then Sign.intern_const (Theory.sign_of Gfp.thy) "gfp"
wenzelm@6394
   466
      else Sign.intern_const (Theory.sign_of Lfp.thy) "lfp";
berghofe@5094
   467
wenzelm@6424
   468
    val ((intr_names, intr_ts), intr_atts) = apfst split_list (split_list intros);
wenzelm@6424
   469
berghofe@5149
   470
    val used = foldr add_term_names (intr_ts, []);
berghofe@5149
   471
    val [sname, xname] = variantlist (["S", "x"], used);
berghofe@5149
   472
berghofe@5094
   473
    (* transform an introduction rule into a conjunction  *)
berghofe@5094
   474
    (*   [| t : ... S_i ... ; ... |] ==> u : S_j          *)
berghofe@5094
   475
    (* is transformed into                                *)
berghofe@5094
   476
    (*   x = Inj_j u & t : ... Inj_i -`` S ... & ...      *)
berghofe@5094
   477
berghofe@5094
   478
    fun transform_rule r =
berghofe@5094
   479
      let
berghofe@5094
   480
        val frees = map dest_Free ((add_term_frees (r, [])) \\ params);
berghofe@5149
   481
        val subst = subst_free
berghofe@5149
   482
          (cs ~~ (map (mk_vimage cs sumT (Free (sname, setT))) cs));
berghofe@5094
   483
        val Const ("op :", _) $ t $ u =
berghofe@5094
   484
          HOLogic.dest_Trueprop (Logic.strip_imp_concl r)
berghofe@5094
   485
berghofe@5094
   486
      in foldr (fn ((x, T), P) => HOLogic.mk_exists (x, T, P))
berghofe@5094
   487
        (frees, foldr1 (app HOLogic.conj)
berghofe@5149
   488
          (((HOLogic.eq_const sumT) $ Free (xname, sumT) $ (mk_inj cs sumT u t))::
berghofe@5094
   489
            (map (subst o HOLogic.dest_Trueprop)
berghofe@5094
   490
              (Logic.strip_imp_prems r))))
berghofe@5094
   491
      end
berghofe@5094
   492
berghofe@5094
   493
    (* make a disjunction of all introduction rules *)
berghofe@5094
   494
berghofe@5149
   495
    val fp_fun = absfree (sname, setT, (HOLogic.Collect_const sumT) $
berghofe@5149
   496
      absfree (xname, sumT, foldr1 (app HOLogic.disj) (map transform_rule intr_ts)));
berghofe@5094
   497
berghofe@5094
   498
    (* add definiton of recursive sets to theory *)
berghofe@5094
   499
berghofe@5094
   500
    val rec_name = if alt_name = "" then space_implode "_" cnames else alt_name;
wenzelm@6394
   501
    val full_rec_name = Sign.full_name (Theory.sign_of thy) rec_name;
berghofe@5094
   502
berghofe@5094
   503
    val rec_const = list_comb
berghofe@5094
   504
      (Const (full_rec_name, paramTs ---> setT), params);
berghofe@5094
   505
berghofe@5094
   506
    val fp_def_term = Logic.mk_equals (rec_const,
berghofe@5094
   507
      Const (fp_name, (setT --> setT) --> setT) $ fp_fun)
berghofe@5094
   508
berghofe@5094
   509
    val def_terms = fp_def_term :: (if length cs < 2 then [] else
berghofe@5094
   510
      map (fn c => Logic.mk_equals (c, mk_vimage cs sumT rec_const c)) cs);
berghofe@5094
   511
berghofe@5094
   512
    val thy' = thy |>
berghofe@5094
   513
      (if declare_consts then
berghofe@5094
   514
        Theory.add_consts_i (map (fn (c, n) =>
berghofe@5094
   515
          (n, paramTs ---> fastype_of c, NoSyn)) (cs ~~ cnames))
berghofe@5094
   516
       else I) |>
berghofe@5094
   517
      (if length cs < 2 then I else
berghofe@5094
   518
       Theory.add_consts_i [(rec_name, paramTs ---> setT, NoSyn)]) |>
berghofe@5094
   519
      Theory.add_path rec_name |>
berghofe@5094
   520
      PureThy.add_defss_i [(("defs", def_terms), [])];
berghofe@5094
   521
berghofe@5094
   522
    (* get definitions from theory *)
berghofe@5094
   523
wenzelm@6424
   524
    val fp_def::rec_sets_defs = PureThy.get_thms thy' "defs";
berghofe@5094
   525
berghofe@5094
   526
    (* prove and store theorems *)
berghofe@5094
   527
berghofe@5094
   528
    val mono = prove_mono setT fp_fun monos thy';
berghofe@5094
   529
    val (intrs, unfold) = prove_intrs coind mono fp_def intr_ts con_defs
berghofe@5094
   530
      rec_sets_defs thy';
berghofe@5094
   531
    val elims = if no_elim then [] else
berghofe@5094
   532
      prove_elims cs cTs params intr_ts unfold rec_sets_defs thy';
berghofe@5094
   533
    val raw_induct = if no_ind then TrueI else
berghofe@5094
   534
      if coind then standard (rule_by_tactic
oheimb@5553
   535
        (rewrite_tac [mk_meta_eq vimage_Un] THEN
berghofe@5094
   536
          fold_tac rec_sets_defs) (mono RS (fp_def RS def_Collect_coinduct)))
berghofe@5094
   537
      else
berghofe@5094
   538
        prove_indrule cs cTs sumT rec_const params intr_ts mono fp_def
berghofe@5094
   539
          rec_sets_defs thy';
berghofe@5108
   540
    val induct = if coind orelse no_ind orelse length cs > 1 then raw_induct
berghofe@5094
   541
      else standard (raw_induct RSN (2, rev_mp));
berghofe@5094
   542
wenzelm@6424
   543
    val thy'' = thy'
wenzelm@6521
   544
      |> PureThy.add_thmss [(("intrs", intrs), atts)]
wenzelm@6424
   545
      |> PureThy.add_thms ((intr_names ~~ intrs) ~~ intr_atts)
wenzelm@6424
   546
      |> (if no_elim then I else PureThy.add_thmss [(("elims", elims), [])])
wenzelm@6424
   547
      |> (if no_ind then I else PureThy.add_thms
wenzelm@6424
   548
        [((coind_prefix coind ^ "induct", induct), [])])
wenzelm@6424
   549
      |> Theory.parent_path;
berghofe@5094
   550
berghofe@5094
   551
  in (thy'',
berghofe@5094
   552
    {defs = fp_def::rec_sets_defs,
berghofe@5094
   553
     mono = mono,
berghofe@5094
   554
     unfold = unfold,
berghofe@5094
   555
     intrs = intrs,
berghofe@5094
   556
     elims = elims,
berghofe@5094
   557
     mk_cases = mk_cases elims,
berghofe@5094
   558
     raw_induct = raw_induct,
berghofe@5094
   559
     induct = induct})
berghofe@5094
   560
  end;
berghofe@5094
   561
wenzelm@6424
   562
wenzelm@6424
   563
wenzelm@6424
   564
(** axiomatic introduction of (co)inductive sets **)
berghofe@5094
   565
berghofe@5094
   566
fun add_ind_axm verbose declare_consts alt_name coind no_elim no_ind cs
wenzelm@6521
   567
    atts intros monos con_defs thy params paramTs cTs cnames =
berghofe@5094
   568
  let
wenzelm@6424
   569
    val _ = if verbose then message ("Adding axioms for " ^ coind_prefix coind ^
wenzelm@6424
   570
      "inductive set(s) " ^ commas_quote cnames) else ();
berghofe@5094
   571
berghofe@5094
   572
    val rec_name = if alt_name = "" then space_implode "_" cnames else alt_name;
berghofe@5094
   573
wenzelm@6424
   574
    val ((intr_names, intr_ts), intr_atts) = apfst split_list (split_list intros);
berghofe@5094
   575
    val elim_ts = mk_elims cs cTs params intr_ts;
berghofe@5094
   576
berghofe@5094
   577
    val (_, ind_prems, mutual_ind_concl) = mk_indrule cs cTs params intr_ts;
berghofe@5094
   578
    val ind_t = Logic.list_implies (ind_prems, mutual_ind_concl);
berghofe@5094
   579
    
wenzelm@6424
   580
    val thy' = thy
wenzelm@6424
   581
      |> (if declare_consts then
wenzelm@6424
   582
            Theory.add_consts_i
wenzelm@6424
   583
              (map (fn (c, n) => (n, paramTs ---> fastype_of c, NoSyn)) (cs ~~ cnames))
wenzelm@6424
   584
         else I)
wenzelm@6424
   585
      |> Theory.add_path rec_name
wenzelm@6521
   586
      |> PureThy.add_axiomss_i [(("intrs", intr_ts), atts), (("elims", elim_ts), [])]
wenzelm@6424
   587
      |> (if coind then I else PureThy.add_axioms_i [(("internal_induct", ind_t), [])]);
berghofe@5094
   588
wenzelm@6424
   589
    val intrs = PureThy.get_thms thy' "intrs";
wenzelm@6424
   590
    val elims = PureThy.get_thms thy' "elims";
berghofe@5094
   591
    val raw_induct = if coind then TrueI else
wenzelm@6424
   592
      standard (split_rule (PureThy.get_thm thy' "internal_induct"));
berghofe@5094
   593
    val induct = if coind orelse length cs > 1 then raw_induct
berghofe@5094
   594
      else standard (raw_induct RSN (2, rev_mp));
berghofe@5094
   595
wenzelm@6424
   596
    val thy'' =
wenzelm@6424
   597
      thy'
wenzelm@6424
   598
      |> (if coind then I else PureThy.add_thms [(("induct", induct), [])])
wenzelm@6424
   599
      |> PureThy.add_thms ((intr_names ~~ intrs) ~~ intr_atts)
wenzelm@6424
   600
      |> Theory.parent_path;
berghofe@5094
   601
  in (thy'',
berghofe@5094
   602
    {defs = [],
berghofe@5094
   603
     mono = TrueI,
berghofe@5094
   604
     unfold = TrueI,
berghofe@5094
   605
     intrs = intrs,
berghofe@5094
   606
     elims = elims,
berghofe@5094
   607
     mk_cases = mk_cases elims,
berghofe@5094
   608
     raw_induct = raw_induct,
berghofe@5094
   609
     induct = induct})
berghofe@5094
   610
  end;
berghofe@5094
   611
wenzelm@6424
   612
wenzelm@6424
   613
wenzelm@6424
   614
(** introduction of (co)inductive sets **)
berghofe@5094
   615
berghofe@5094
   616
fun add_inductive_i verbose declare_consts alt_name coind no_elim no_ind cs
wenzelm@6521
   617
    atts intros monos con_defs thy =
berghofe@5094
   618
  let
wenzelm@6424
   619
    val _ = Theory.requires thy "Inductive" (coind_prefix coind ^ "inductive definitions");
wenzelm@6394
   620
    val sign = Theory.sign_of thy;
berghofe@5094
   621
berghofe@5094
   622
    (*parameters should agree for all mutually recursive components*)
berghofe@5094
   623
    val (_, params) = strip_comb (hd cs);
berghofe@5094
   624
    val paramTs = map (try' (snd o dest_Free) "Parameter in recursive\
berghofe@5094
   625
      \ component is not a free variable: " sign) params;
berghofe@5094
   626
berghofe@5094
   627
    val cTs = map (try' (HOLogic.dest_setT o fastype_of)
berghofe@5094
   628
      "Recursive component not of type set: " sign) cs;
berghofe@5094
   629
wenzelm@6437
   630
    val full_cnames = map (try' (fst o dest_Const o head_of)
berghofe@5094
   631
      "Recursive set not previously declared as constant: " sign) cs;
wenzelm@6437
   632
    val cnames = map Sign.base_name full_cnames;
berghofe@5094
   633
wenzelm@6424
   634
    val _ = assert_all Syntax.is_identifier cnames	(* FIXME why? *)
berghofe@5094
   635
       (fn a => "Base name of recursive set not an identifier: " ^ a);
wenzelm@6424
   636
    val _ = seq (check_rule sign cs o snd o fst) intros;
wenzelm@6437
   637
wenzelm@6437
   638
    val (thy1, result) =
wenzelm@6437
   639
      (if ! quick_and_dirty then add_ind_axm else add_ind_def)
wenzelm@6521
   640
        verbose declare_consts alt_name coind no_elim no_ind cs atts intros monos
wenzelm@6437
   641
        con_defs thy params paramTs cTs cnames;
wenzelm@6437
   642
    val thy2 = thy1 |> put_inductives full_cnames ({names = full_cnames, coind = coind}, result);
wenzelm@6437
   643
  in (thy2, result) end;
berghofe@5094
   644
wenzelm@6424
   645
berghofe@5094
   646
wenzelm@6424
   647
(** external interface **)
wenzelm@6424
   648
wenzelm@6521
   649
fun add_inductive verbose coind c_strings srcs intro_srcs raw_monos raw_con_defs thy =
berghofe@5094
   650
  let
wenzelm@6394
   651
    val sign = Theory.sign_of thy;
wenzelm@6394
   652
    val cs = map (readtm (Theory.sign_of thy) HOLogic.termTVar) c_strings;
wenzelm@6424
   653
wenzelm@6521
   654
    val atts = map (Attrib.global_attribute thy) srcs;
wenzelm@6424
   655
    val intr_names = map (fst o fst) intro_srcs;
wenzelm@6424
   656
    val intr_ts = map (readtm (Theory.sign_of thy) propT o snd o fst) intro_srcs;
wenzelm@6424
   657
    val intr_atts = map (map (Attrib.global_attribute thy) o snd) intro_srcs;
berghofe@5094
   658
berghofe@5094
   659
    (* the following code ensures that each recursive set *)
berghofe@5094
   660
    (* always has the same type in all introduction rules *)
berghofe@5094
   661
berghofe@5094
   662
    val {tsig, ...} = Sign.rep_sg sign;
berghofe@5094
   663
    val add_term_consts_2 =
berghofe@5094
   664
      foldl_aterms (fn (cs, Const c) => c ins cs | (cs, _) => cs);
berghofe@5094
   665
    fun varify (t, (i, ts)) =
berghofe@5094
   666
      let val t' = map_term_types (incr_tvar (i + 1)) (Type.varify (t, []))
berghofe@5094
   667
      in (maxidx_of_term t', t'::ts) end;
berghofe@5094
   668
    val (i, cs') = foldr varify (cs, (~1, []));
berghofe@5094
   669
    val (i', intr_ts') = foldr varify (intr_ts, (i, []));
berghofe@5094
   670
    val rec_consts = foldl add_term_consts_2 ([], cs');
berghofe@5094
   671
    val intr_consts = foldl add_term_consts_2 ([], intr_ts');
berghofe@5094
   672
    fun unify (env, (cname, cT)) =
berghofe@5094
   673
      let val consts = map snd (filter (fn c => fst c = cname) intr_consts)
berghofe@5094
   674
      in (foldl (fn ((env', j'), Tp) => Type.unify tsig j' env' Tp)
berghofe@5094
   675
        (env, (replicate (length consts) cT) ~~ consts)) handle _ =>
berghofe@5094
   676
          error ("Occurrences of constant '" ^ cname ^
berghofe@5094
   677
            "' have incompatible types")
berghofe@5094
   678
      end;
berghofe@5094
   679
    val (env, _) = foldl unify (([], i'), rec_consts);
berghofe@5094
   680
    fun typ_subst_TVars_2 env T = let val T' = typ_subst_TVars env T
berghofe@5094
   681
      in if T = T' then T else typ_subst_TVars_2 env T' end;
berghofe@5094
   682
    val subst = fst o Type.freeze_thaw o
berghofe@5094
   683
      (map_term_types (typ_subst_TVars_2 env));
berghofe@5094
   684
    val cs'' = map subst cs';
berghofe@5094
   685
    val intr_ts'' = map subst intr_ts';
berghofe@5094
   686
wenzelm@6424
   687
    val ((thy', con_defs), monos) = thy
wenzelm@6424
   688
      |> IsarThy.apply_theorems raw_monos
wenzelm@6424
   689
      |> apfst (IsarThy.apply_theorems raw_con_defs);
wenzelm@6424
   690
  in
wenzelm@6424
   691
    add_inductive_i verbose false "" coind false false cs''
wenzelm@6521
   692
      atts ((intr_names ~~ intr_ts'') ~~ intr_atts) monos con_defs thy'
berghofe@5094
   693
  end;
berghofe@5094
   694
wenzelm@6424
   695
wenzelm@6424
   696
wenzelm@6437
   697
(** package setup **)
wenzelm@6437
   698
wenzelm@6437
   699
(* setup theory *)
wenzelm@6437
   700
wenzelm@6437
   701
val setup = [InductiveData.init];
wenzelm@6437
   702
wenzelm@6437
   703
wenzelm@6437
   704
(* outer syntax *)
wenzelm@6424
   705
wenzelm@6424
   706
local open OuterParse in
wenzelm@6424
   707
wenzelm@6521
   708
fun mk_ind coind (((sets, (atts, intrs)), monos), con_defs) =
wenzelm@6521
   709
  #1 o add_inductive true coind sets atts (map triple_swap intrs) monos con_defs;
wenzelm@6424
   710
wenzelm@6424
   711
fun ind_decl coind =
wenzelm@6424
   712
  Scan.repeat1 term --
wenzelm@6521
   713
  ($$$ "intrs" |-- !!! (opt_attribs -- Scan.repeat1 (opt_thm_name ":" -- term))) --
wenzelm@6424
   714
  Scan.optional ($$$ "monos" |-- !!! xthms1) [] --
wenzelm@6424
   715
  Scan.optional ($$$ "con_defs" |-- !!! xthms1) []
wenzelm@6424
   716
  >> (Toplevel.theory o mk_ind coind);
wenzelm@6424
   717
wenzelm@6424
   718
val inductiveP = OuterSyntax.command "inductive" "define inductive sets" (ind_decl false);
wenzelm@6424
   719
val coinductiveP = OuterSyntax.command "coinductive" "define coinductive sets" (ind_decl true);
wenzelm@6424
   720
wenzelm@6424
   721
val _ = OuterSyntax.add_keywords ["intrs", "monos", "con_defs"];
wenzelm@6424
   722
val _ = OuterSyntax.add_parsers [inductiveP, coinductiveP];
wenzelm@6424
   723
berghofe@5094
   724
end;
wenzelm@6424
   725
wenzelm@6424
   726
wenzelm@6424
   727
end;