src/HOL/Tools/SMT/z3_proof_reconstruction.ML
author boehmes
Wed May 12 23:54:02 2010 +0200 (2010-05-12)
changeset 36898 8e55aa1306c5
child 36899 bcd6fce5bf06
permissions -rw-r--r--
integrated SMT into the HOL image
boehmes@36898
     1
(*  Title:      HOL/Tools/SMT/z3_proof_reconstruction.ML
boehmes@36898
     2
    Author:     Sascha Boehme, TU Muenchen
boehmes@36898
     3
boehmes@36898
     4
Proof reconstruction for proofs found by Z3.
boehmes@36898
     5
*)
boehmes@36898
     6
boehmes@36898
     7
signature Z3_PROOF_RECONSTRUCTION =
boehmes@36898
     8
sig
boehmes@36898
     9
  val trace_assms: bool Config.T
boehmes@36898
    10
  val reconstruct: string list * SMT_Translate.recon -> Proof.context ->
boehmes@36898
    11
    thm * Proof.context
boehmes@36898
    12
  val setup: theory -> theory
boehmes@36898
    13
end
boehmes@36898
    14
boehmes@36898
    15
structure Z3_Proof_Reconstruction: Z3_PROOF_RECONSTRUCTION =
boehmes@36898
    16
struct
boehmes@36898
    17
boehmes@36898
    18
structure P = Z3_Proof_Parser
boehmes@36898
    19
structure T = Z3_Proof_Tools
boehmes@36898
    20
structure L = Z3_Proof_Literals
boehmes@36898
    21
boehmes@36898
    22
fun z3_exn msg = raise SMT_Solver.SMT ("Z3 proof reconstruction: " ^ msg)
boehmes@36898
    23
boehmes@36898
    24
boehmes@36898
    25
boehmes@36898
    26
(** net of schematic rules **)
boehmes@36898
    27
boehmes@36898
    28
val z3_ruleN = "z3_rule"
boehmes@36898
    29
boehmes@36898
    30
local
boehmes@36898
    31
  val description = "declaration of Z3 proof rules"
boehmes@36898
    32
boehmes@36898
    33
  val eq = Thm.eq_thm
boehmes@36898
    34
boehmes@36898
    35
  structure Z3_Rules = Generic_Data
boehmes@36898
    36
  (
boehmes@36898
    37
    type T = thm Net.net
boehmes@36898
    38
    val empty = Net.empty
boehmes@36898
    39
    val extend = I
boehmes@36898
    40
    val merge = Net.merge eq
boehmes@36898
    41
  )
boehmes@36898
    42
boehmes@36898
    43
  val prep = `Thm.prop_of o Simplifier.rewrite_rule [L.rewrite_true]
boehmes@36898
    44
boehmes@36898
    45
  fun ins thm net = Net.insert_term eq (prep thm) net handle Net.INSERT => net
boehmes@36898
    46
  fun del thm net = Net.delete_term eq (prep thm) net handle Net.DELETE => net
boehmes@36898
    47
boehmes@36898
    48
  val add = Thm.declaration_attribute (Z3_Rules.map o ins)
boehmes@36898
    49
  val del = Thm.declaration_attribute (Z3_Rules.map o del)
boehmes@36898
    50
in
boehmes@36898
    51
boehmes@36898
    52
fun get_schematic_rules ctxt = Net.content (Z3_Rules.get (Context.Proof ctxt))
boehmes@36898
    53
boehmes@36898
    54
fun by_schematic_rule ctxt ct =
boehmes@36898
    55
  the (T.net_instance (Z3_Rules.get (Context.Proof ctxt)) ct)
boehmes@36898
    56
boehmes@36898
    57
val z3_rules_setup =
boehmes@36898
    58
  Attrib.setup (Binding.name z3_ruleN) (Attrib.add_del add del) description #>
boehmes@36898
    59
  PureThy.add_thms_dynamic (Binding.name z3_ruleN, Net.content o Z3_Rules.get)
boehmes@36898
    60
boehmes@36898
    61
end
boehmes@36898
    62
boehmes@36898
    63
boehmes@36898
    64
boehmes@36898
    65
(** proof tools **)
boehmes@36898
    66
boehmes@36898
    67
fun named ctxt name prover ct =
boehmes@36898
    68
  let val _ = SMT_Solver.trace_msg ctxt I ("Z3: trying " ^ name ^ " ...")
boehmes@36898
    69
  in prover ct end
boehmes@36898
    70
boehmes@36898
    71
fun NAMED ctxt name tac i st =
boehmes@36898
    72
  let val _ = SMT_Solver.trace_msg ctxt I ("Z3: trying " ^ name ^ " ...")
boehmes@36898
    73
  in tac i st end
boehmes@36898
    74
boehmes@36898
    75
fun pretty_goal ctxt thms t =
boehmes@36898
    76
  [Pretty.block [Pretty.str "proposition: ", Syntax.pretty_term ctxt t]]
boehmes@36898
    77
  |> not (null thms) ? cons (Pretty.big_list "assumptions:"
boehmes@36898
    78
       (map (Display.pretty_thm ctxt) thms))
boehmes@36898
    79
boehmes@36898
    80
fun try_apply ctxt thms =
boehmes@36898
    81
  let
boehmes@36898
    82
    fun try_apply_err ct = Pretty.string_of (Pretty.chunks [
boehmes@36898
    83
      Pretty.big_list ("Z3 found a proof," ^
boehmes@36898
    84
        " but proof reconstruction failed at the following subgoal:")
boehmes@36898
    85
        (pretty_goal ctxt thms (Thm.term_of ct)),
boehmes@36898
    86
      Pretty.str ("Adding a rule to the lemma group " ^ quote z3_ruleN ^
boehmes@36898
    87
        " might solve this problem.")])
boehmes@36898
    88
boehmes@36898
    89
    fun apply [] ct = error (try_apply_err ct)
boehmes@36898
    90
      | apply (prover :: provers) ct =
boehmes@36898
    91
          (case try prover ct of
boehmes@36898
    92
            SOME thm => (SMT_Solver.trace_msg ctxt I "Z3: succeeded"; thm)
boehmes@36898
    93
          | NONE => apply provers ct)
boehmes@36898
    94
boehmes@36898
    95
  in apply o cons (named ctxt "schematic rules" (by_schematic_rule ctxt)) end
boehmes@36898
    96
boehmes@36898
    97
boehmes@36898
    98
boehmes@36898
    99
(** theorems and proofs **)
boehmes@36898
   100
boehmes@36898
   101
(* theorem incarnations *)
boehmes@36898
   102
boehmes@36898
   103
datatype theorem =
boehmes@36898
   104
  Thm of thm | (* theorem without special features *)
boehmes@36898
   105
  MetaEq of thm | (* meta equality "t == s" *)
boehmes@36898
   106
  Literals of thm * L.littab
boehmes@36898
   107
    (* "P1 & ... & Pn" and table of all literals P1, ..., Pn *)
boehmes@36898
   108
boehmes@36898
   109
fun thm_of (Thm thm) = thm
boehmes@36898
   110
  | thm_of (MetaEq thm) = thm COMP @{thm meta_eq_to_obj_eq}
boehmes@36898
   111
  | thm_of (Literals (thm, _)) = thm
boehmes@36898
   112
boehmes@36898
   113
fun meta_eq_of (MetaEq thm) = thm
boehmes@36898
   114
  | meta_eq_of p = mk_meta_eq (thm_of p)
boehmes@36898
   115
boehmes@36898
   116
fun literals_of (Literals (_, lits)) = lits
boehmes@36898
   117
  | literals_of p = L.make_littab [thm_of p]
boehmes@36898
   118
boehmes@36898
   119
boehmes@36898
   120
(* proof representation *)
boehmes@36898
   121
boehmes@36898
   122
datatype proof = Unproved of P.proof_step | Proved of theorem
boehmes@36898
   123
boehmes@36898
   124
boehmes@36898
   125
boehmes@36898
   126
(** core proof rules **)
boehmes@36898
   127
boehmes@36898
   128
(* assumption *)
boehmes@36898
   129
boehmes@36898
   130
val (trace_assms, trace_assms_setup) =
boehmes@36898
   131
  Attrib.config_bool "z3_trace_assms" (K false)
boehmes@36898
   132
boehmes@36898
   133
local
boehmes@36898
   134
  val remove_trigger = @{lemma "trigger t p == p"
boehmes@36898
   135
    by (rule eq_reflection, rule trigger_def)}
boehmes@36898
   136
boehmes@36898
   137
  val prep_rules = [@{thm Let_def}, remove_trigger, L.rewrite_true]
boehmes@36898
   138
boehmes@36898
   139
  fun rewrite_conv ctxt eqs = Simplifier.full_rewrite
boehmes@36898
   140
    (Simplifier.context ctxt Simplifier.empty_ss addsimps eqs)
boehmes@36898
   141
boehmes@36898
   142
  fun rewrites ctxt eqs = map (Conv.fconv_rule (rewrite_conv ctxt eqs))
boehmes@36898
   143
boehmes@36898
   144
  fun trace ctxt thm =
boehmes@36898
   145
    if Config.get ctxt trace_assms
boehmes@36898
   146
    then tracing (Display.string_of_thm ctxt thm)
boehmes@36898
   147
    else ()
boehmes@36898
   148
boehmes@36898
   149
  fun lookup_assm ctxt assms ct =
boehmes@36898
   150
    (case T.net_instance assms ct of
boehmes@36898
   151
      SOME thm => (trace ctxt thm; thm)
boehmes@36898
   152
    | _ => z3_exn ("not asserted: " ^
boehmes@36898
   153
        quote (Syntax.string_of_term ctxt (Thm.term_of ct))))
boehmes@36898
   154
in
boehmes@36898
   155
fun prepare_assms ctxt unfolds assms =
boehmes@36898
   156
  let
boehmes@36898
   157
    val unfolds' = rewrites ctxt [L.rewrite_true] unfolds
boehmes@36898
   158
    val assms' = rewrites ctxt (union Thm.eq_thm unfolds' prep_rules) assms
boehmes@36898
   159
  in (unfolds', T.thm_net_of assms') end
boehmes@36898
   160
boehmes@36898
   161
fun asserted _ NONE ct = Thm (Thm.assume ct)
boehmes@36898
   162
  | asserted ctxt (SOME (unfolds, assms)) ct =
boehmes@36898
   163
      let val revert_conv = rewrite_conv ctxt unfolds
boehmes@36898
   164
      in Thm (T.with_conv revert_conv (lookup_assm ctxt assms) ct) end
boehmes@36898
   165
end
boehmes@36898
   166
boehmes@36898
   167
boehmes@36898
   168
boehmes@36898
   169
(* P = Q ==> P ==> Q   or   P --> Q ==> P ==> Q *)
boehmes@36898
   170
local
boehmes@36898
   171
  val meta_iffD1 = @{lemma "P == Q ==> P ==> (Q::bool)" by simp}
boehmes@36898
   172
  val meta_iffD1_c = T.precompose2 Thm.dest_binop meta_iffD1
boehmes@36898
   173
boehmes@36898
   174
  val iffD1_c = T.precompose2 (Thm.dest_binop o Thm.dest_arg) @{thm iffD1}
boehmes@36898
   175
  val mp_c = T.precompose2 (Thm.dest_binop o Thm.dest_arg) @{thm mp}
boehmes@36898
   176
in
boehmes@36898
   177
fun mp (MetaEq thm) p = Thm (Thm.implies_elim (T.compose meta_iffD1_c thm) p)
boehmes@36898
   178
  | mp p_q p = 
boehmes@36898
   179
      let
boehmes@36898
   180
        val pq = thm_of p_q
boehmes@36898
   181
        val thm = T.compose iffD1_c pq handle THM _ => T.compose mp_c pq
boehmes@36898
   182
      in Thm (Thm.implies_elim thm p) end
boehmes@36898
   183
end
boehmes@36898
   184
boehmes@36898
   185
boehmes@36898
   186
boehmes@36898
   187
(* and_elim:     P1 & ... & Pn ==> Pi *)
boehmes@36898
   188
(* not_or_elim:  ~(P1 | ... | Pn) ==> ~Pi *)
boehmes@36898
   189
local
boehmes@36898
   190
  fun is_sublit conj t = L.exists_lit conj (fn u => u aconv t)
boehmes@36898
   191
boehmes@36898
   192
  fun derive conj t lits idx ptab =
boehmes@36898
   193
    let
boehmes@36898
   194
      val lit = the (L.get_first_lit (is_sublit conj t) lits)
boehmes@36898
   195
      val ls = L.explode conj false false [t] lit
boehmes@36898
   196
      val lits' = fold L.insert_lit ls (L.delete_lit lit lits)
boehmes@36898
   197
boehmes@36898
   198
      fun upd (Proved thm) = Proved (Literals (thm_of thm, lits'))
boehmes@36898
   199
        | upd p = p
boehmes@36898
   200
    in (the (L.lookup_lit lits' t), Inttab.map_entry idx upd ptab) end
boehmes@36898
   201
boehmes@36898
   202
  fun lit_elim conj (p, idx) ct ptab =
boehmes@36898
   203
    let val lits = literals_of p
boehmes@36898
   204
    in
boehmes@36898
   205
      (case L.lookup_lit lits (T.term_of ct) of
boehmes@36898
   206
        SOME lit => (Thm lit, ptab)
boehmes@36898
   207
      | NONE => apfst Thm (derive conj (T.term_of ct) lits idx ptab))
boehmes@36898
   208
    end
boehmes@36898
   209
in
boehmes@36898
   210
val and_elim = lit_elim true
boehmes@36898
   211
val not_or_elim = lit_elim false
boehmes@36898
   212
end
boehmes@36898
   213
boehmes@36898
   214
boehmes@36898
   215
boehmes@36898
   216
(* P1, ..., Pn |- False ==> |- ~P1 | ... | ~Pn *)
boehmes@36898
   217
local
boehmes@36898
   218
  fun step lit thm =
boehmes@36898
   219
    Thm.implies_elim (Thm.implies_intr (Thm.cprop_of lit) thm) lit
boehmes@36898
   220
  val explode_disj = L.explode false false false
boehmes@36898
   221
  fun intro hyps thm th = fold step (explode_disj hyps th) thm
boehmes@36898
   222
boehmes@36898
   223
  fun dest_ccontr ct = [Thm.dest_arg (Thm.dest_arg (Thm.dest_arg1 ct))]
boehmes@36898
   224
  val ccontr = T.precompose dest_ccontr @{thm ccontr}
boehmes@36898
   225
in
boehmes@36898
   226
fun lemma thm ct =
boehmes@36898
   227
  let
boehmes@36898
   228
    val cu = Thm.capply @{cterm Not} (Thm.dest_arg ct)
boehmes@36898
   229
    val hyps = map_filter (try HOLogic.dest_Trueprop) (#hyps (Thm.rep_thm thm))
boehmes@36898
   230
  in Thm (T.compose ccontr (T.under_assumption (intro hyps thm) cu)) end
boehmes@36898
   231
end
boehmes@36898
   232
boehmes@36898
   233
boehmes@36898
   234
boehmes@36898
   235
(* \/{P1, ..., Pn, Q1, ..., Qn}, ~P1, ..., ~Pn ==> \/{Q1, ..., Qn} *)
boehmes@36898
   236
local
boehmes@36898
   237
  val explode_disj = L.explode false true false
boehmes@36898
   238
  val join_disj = L.join false
boehmes@36898
   239
  fun unit thm thms th =
boehmes@36898
   240
    let val t = @{term Not} $ T.prop_of thm and ts = map T.prop_of thms
boehmes@36898
   241
    in join_disj (L.make_littab (thms @ explode_disj ts th)) t end
boehmes@36898
   242
boehmes@36898
   243
  fun dest_arg2 ct = Thm.dest_arg (Thm.dest_arg ct)
boehmes@36898
   244
  fun dest ct = pairself dest_arg2 (Thm.dest_binop ct)
boehmes@36898
   245
  val contrapos = T.precompose2 dest @{lemma "(~P ==> ~Q) ==> Q ==> P" by fast}
boehmes@36898
   246
in
boehmes@36898
   247
fun unit_resolution thm thms ct =
boehmes@36898
   248
  Thm.capply @{cterm Not} (Thm.dest_arg ct)
boehmes@36898
   249
  |> T.under_assumption (unit thm thms)
boehmes@36898
   250
  |> Thm o T.discharge thm o T.compose contrapos
boehmes@36898
   251
end
boehmes@36898
   252
boehmes@36898
   253
boehmes@36898
   254
boehmes@36898
   255
(* P ==> P == True   or   P ==> P == False *)
boehmes@36898
   256
local
boehmes@36898
   257
  val iff1 = @{lemma "P ==> P == (~ False)" by simp}
boehmes@36898
   258
  val iff2 = @{lemma "~P ==> P == False" by simp}
boehmes@36898
   259
in
boehmes@36898
   260
fun iff_true thm = MetaEq (thm COMP iff1)
boehmes@36898
   261
fun iff_false thm = MetaEq (thm COMP iff2)
boehmes@36898
   262
end
boehmes@36898
   263
boehmes@36898
   264
boehmes@36898
   265
boehmes@36898
   266
(* distributivity of | over & *)
boehmes@36898
   267
fun distributivity ctxt = Thm o try_apply ctxt [] [
boehmes@36898
   268
  named ctxt "fast" (T.by_tac (Classical.best_tac HOL_cs))]
boehmes@36898
   269
    (* FIXME: not very well tested *)
boehmes@36898
   270
boehmes@36898
   271
boehmes@36898
   272
boehmes@36898
   273
(* Tseitin-like axioms *)
boehmes@36898
   274
boehmes@36898
   275
local
boehmes@36898
   276
  val disjI1 = @{lemma "(P ==> Q) ==> ~P | Q" by fast}
boehmes@36898
   277
  val disjI2 = @{lemma "(~P ==> Q) ==> P | Q" by fast}
boehmes@36898
   278
  val disjI3 = @{lemma "(~Q ==> P) ==> P | Q" by fast}
boehmes@36898
   279
  val disjI4 = @{lemma "(Q ==> P) ==> P | ~Q" by fast}
boehmes@36898
   280
boehmes@36898
   281
  fun prove' conj1 conj2 ct2 thm =
boehmes@36898
   282
    let val lits = L.true_thm :: L.explode conj1 true (conj1 <> conj2) [] thm
boehmes@36898
   283
    in L.join conj2 (L.make_littab lits) (Thm.term_of ct2) end
boehmes@36898
   284
boehmes@36898
   285
  fun prove rule (ct1, conj1) (ct2, conj2) =
boehmes@36898
   286
    T.under_assumption (prove' conj1 conj2 ct2) ct1 COMP rule
boehmes@36898
   287
boehmes@36898
   288
  fun prove_def_axiom ct =
boehmes@36898
   289
    let val (ct1, ct2) = Thm.dest_binop (Thm.dest_arg ct)
boehmes@36898
   290
    in
boehmes@36898
   291
      (case Thm.term_of ct1 of
boehmes@36898
   292
        @{term Not} $ (@{term "op &"} $ _ $ _) =>
boehmes@36898
   293
          prove disjI1 (Thm.dest_arg ct1, true) (ct2, true)
boehmes@36898
   294
      | @{term "op &"} $ _ $ _ =>
boehmes@36898
   295
          prove disjI3 (Thm.capply @{cterm Not} ct2, false) (ct1, true)
boehmes@36898
   296
      | @{term Not} $ (@{term "op |"} $ _ $ _) =>
boehmes@36898
   297
          prove disjI3 (Thm.capply @{cterm Not} ct2, false) (ct1, false)
boehmes@36898
   298
      | @{term "op |"} $ _ $ _ =>
boehmes@36898
   299
          prove disjI2 (Thm.capply @{cterm Not} ct1, false) (ct2, true)
boehmes@36898
   300
      | Const (@{const_name distinct}, _) $ _ =>
boehmes@36898
   301
          let
boehmes@36898
   302
            fun dis_conv cv = Conv.arg_conv (Conv.arg1_conv cv)
boehmes@36898
   303
            fun prv cu =
boehmes@36898
   304
              let val (cu1, cu2) = Thm.dest_binop (Thm.dest_arg cu)
boehmes@36898
   305
              in prove disjI4 (Thm.dest_arg cu2, true) (cu1, true) end
boehmes@36898
   306
          in T.with_conv (dis_conv T.unfold_distinct_conv) prv ct end
boehmes@36898
   307
      | @{term Not} $ (Const (@{const_name distinct}, _) $ _) =>
boehmes@36898
   308
          let
boehmes@36898
   309
            fun dis_conv cv = Conv.arg_conv (Conv.arg1_conv (Conv.arg_conv cv))
boehmes@36898
   310
            fun prv cu =
boehmes@36898
   311
              let val (cu1, cu2) = Thm.dest_binop (Thm.dest_arg cu)
boehmes@36898
   312
              in prove disjI1 (Thm.dest_arg cu1, true) (cu2, true) end
boehmes@36898
   313
          in T.with_conv (dis_conv T.unfold_distinct_conv) prv ct end
boehmes@36898
   314
      | _ => raise CTERM ("prove_def_axiom", [ct]))
boehmes@36898
   315
    end
boehmes@36898
   316
boehmes@36898
   317
  val rewr_if =
boehmes@36898
   318
    @{lemma "(if P then Q1 else Q2) = ((P --> Q1) & (~P --> Q2))" by simp}
boehmes@36898
   319
in
boehmes@36898
   320
fun def_axiom ctxt = Thm o try_apply ctxt [] [
boehmes@36898
   321
  named ctxt "conj/disj/distinct" prove_def_axiom,
boehmes@36898
   322
  T.by_abstraction ctxt [] (fn ctxt' =>
boehmes@36898
   323
    named ctxt' "simp+fast" (T.by_tac (
boehmes@36898
   324
      Simplifier.simp_tac (HOL_ss addsimps [rewr_if])
boehmes@36898
   325
      THEN_ALL_NEW Classical.best_tac HOL_cs)))]
boehmes@36898
   326
end
boehmes@36898
   327
boehmes@36898
   328
boehmes@36898
   329
boehmes@36898
   330
(* local definitions *)
boehmes@36898
   331
local
boehmes@36898
   332
  val intro_rules = [
boehmes@36898
   333
    @{lemma "n == P ==> (~n | P) & (n | ~P)" by simp},
boehmes@36898
   334
    @{lemma "n == (if P then s else t) ==> (~P | n = s) & (P | n = t)"
boehmes@36898
   335
      by simp},
boehmes@36898
   336
    @{lemma "n == P ==> n = P" by (rule meta_eq_to_obj_eq)} ]
boehmes@36898
   337
boehmes@36898
   338
  val apply_rules = [
boehmes@36898
   339
    @{lemma "(~n | P) & (n | ~P) ==> P == n" by (atomize(full)) fast},
boehmes@36898
   340
    @{lemma "(~P | n = s) & (P | n = t) ==> (if P then s else t) == n"
boehmes@36898
   341
      by (atomize(full)) fastsimp} ]
boehmes@36898
   342
boehmes@36898
   343
  val inst_rule = T.match_instantiate Thm.dest_arg
boehmes@36898
   344
boehmes@36898
   345
  fun apply_rule ct =
boehmes@36898
   346
    (case get_first (try (inst_rule ct)) intro_rules of
boehmes@36898
   347
      SOME thm => thm
boehmes@36898
   348
    | NONE => raise CTERM ("intro_def", [ct]))
boehmes@36898
   349
in
boehmes@36898
   350
fun intro_def ct = T.make_hyp_def (apply_rule ct) #>> Thm
boehmes@36898
   351
boehmes@36898
   352
fun apply_def thm =
boehmes@36898
   353
  get_first (try (fn rule => MetaEq (thm COMP rule))) apply_rules
boehmes@36898
   354
  |> the_default (Thm thm)
boehmes@36898
   355
end
boehmes@36898
   356
boehmes@36898
   357
boehmes@36898
   358
boehmes@36898
   359
(* negation normal form *)
boehmes@36898
   360
boehmes@36898
   361
local
boehmes@36898
   362
  val quant_rules1 = ([
boehmes@36898
   363
    @{lemma "(!!x. P x == Q) ==> ALL x. P x == Q" by simp},
boehmes@36898
   364
    @{lemma "(!!x. P x == Q) ==> EX x. P x == Q" by simp}], [
boehmes@36898
   365
    @{lemma "(!!x. P x == Q x) ==> ALL x. P x == ALL x. Q x" by simp},
boehmes@36898
   366
    @{lemma "(!!x. P x == Q x) ==> EX x. P x == EX x. Q x" by simp}])
boehmes@36898
   367
boehmes@36898
   368
  val quant_rules2 = ([
boehmes@36898
   369
    @{lemma "(!!x. ~P x == Q) ==> ~(ALL x. P x) == Q" by simp},
boehmes@36898
   370
    @{lemma "(!!x. ~P x == Q) ==> ~(EX x. P x) == Q" by simp}], [
boehmes@36898
   371
    @{lemma "(!!x. ~P x == Q x) ==> ~(ALL x. P x) == EX x. Q x" by simp},
boehmes@36898
   372
    @{lemma "(!!x. ~P x == Q x) ==> ~(EX x. P x) == ALL x. Q x" by simp}])
boehmes@36898
   373
boehmes@36898
   374
  fun nnf_quant_tac thm (qs as (qs1, qs2)) i st = (
boehmes@36898
   375
    Tactic.rtac thm ORELSE'
boehmes@36898
   376
    (Tactic.match_tac qs1 THEN' nnf_quant_tac thm qs) ORELSE'
boehmes@36898
   377
    (Tactic.match_tac qs2 THEN' nnf_quant_tac thm qs)) i st
boehmes@36898
   378
boehmes@36898
   379
  fun nnf_quant vars qs p ct =
boehmes@36898
   380
    T.as_meta_eq ct
boehmes@36898
   381
    |> T.by_tac (nnf_quant_tac (T.varify vars (meta_eq_of p)) qs)
boehmes@36898
   382
boehmes@36898
   383
  fun prove_nnf ctxt = try_apply ctxt [] [
boehmes@36898
   384
    named ctxt "conj/disj" L.prove_conj_disj_eq]
boehmes@36898
   385
in
boehmes@36898
   386
fun nnf ctxt vars ps ct =
boehmes@36898
   387
  (case T.term_of ct of
boehmes@36898
   388
    _ $ (l as Const _ $ Abs _) $ (r as Const _ $ Abs _) =>
boehmes@36898
   389
      if l aconv r
boehmes@36898
   390
      then MetaEq (Thm.reflexive (Thm.dest_arg (Thm.dest_arg ct)))
boehmes@36898
   391
      else MetaEq (nnf_quant vars quant_rules1 (hd ps) ct)
boehmes@36898
   392
  | _ $ (@{term Not} $ (Const _ $ Abs _)) $ (Const _ $ Abs _) =>
boehmes@36898
   393
      MetaEq (nnf_quant vars quant_rules2 (hd ps) ct)
boehmes@36898
   394
  | _ =>
boehmes@36898
   395
      let
boehmes@36898
   396
        val nnf_rewr_conv = Conv.arg_conv (Conv.arg_conv
boehmes@36898
   397
          (T.unfold_eqs ctxt (map (Thm.symmetric o meta_eq_of) ps)))
boehmes@36898
   398
      in Thm (T.with_conv nnf_rewr_conv (prove_nnf ctxt) ct) end)
boehmes@36898
   399
end
boehmes@36898
   400
boehmes@36898
   401
boehmes@36898
   402
boehmes@36898
   403
(** equality proof rules **)
boehmes@36898
   404
boehmes@36898
   405
(* |- t = t *)
boehmes@36898
   406
fun refl ct = MetaEq (Thm.reflexive (Thm.dest_arg (Thm.dest_arg ct)))
boehmes@36898
   407
boehmes@36898
   408
boehmes@36898
   409
boehmes@36898
   410
(* s = t ==> t = s *)
boehmes@36898
   411
local
boehmes@36898
   412
  val symm_rule = @{lemma "s = t ==> t == s" by simp}
boehmes@36898
   413
in
boehmes@36898
   414
fun symm (MetaEq thm) = MetaEq (Thm.symmetric thm)
boehmes@36898
   415
  | symm p = MetaEq (thm_of p COMP symm_rule)
boehmes@36898
   416
end
boehmes@36898
   417
boehmes@36898
   418
boehmes@36898
   419
boehmes@36898
   420
(* s = t ==> t = u ==> s = u *)
boehmes@36898
   421
local
boehmes@36898
   422
  val trans1 = @{lemma "s == t ==> t =  u ==> s == u" by simp}
boehmes@36898
   423
  val trans2 = @{lemma "s =  t ==> t == u ==> s == u" by simp}
boehmes@36898
   424
  val trans3 = @{lemma "s =  t ==> t =  u ==> s == u" by simp}
boehmes@36898
   425
in
boehmes@36898
   426
fun trans (MetaEq thm1) (MetaEq thm2) = MetaEq (Thm.transitive thm1 thm2)
boehmes@36898
   427
  | trans (MetaEq thm) q = MetaEq (thm_of q COMP (thm COMP trans1))
boehmes@36898
   428
  | trans p (MetaEq thm) = MetaEq (thm COMP (thm_of p COMP trans2))
boehmes@36898
   429
  | trans p q = MetaEq (thm_of q COMP (thm_of p COMP trans3))
boehmes@36898
   430
end
boehmes@36898
   431
boehmes@36898
   432
boehmes@36898
   433
boehmes@36898
   434
(* t1 = s1 ==> ... ==> tn = sn ==> f t1 ... tn = f s1 .. sn
boehmes@36898
   435
   (reflexive antecendents are droppped) *)
boehmes@36898
   436
local
boehmes@36898
   437
  exception MONO
boehmes@36898
   438
boehmes@36898
   439
  fun prove_refl (ct, _) = Thm.reflexive ct
boehmes@36898
   440
  fun prove_comb f g cp =
boehmes@36898
   441
    let val ((ct1, ct2), (cu1, cu2)) = pairself Thm.dest_comb cp
boehmes@36898
   442
    in Thm.combination (f (ct1, cu1)) (g (ct2, cu2)) end
boehmes@36898
   443
  fun prove_arg f = prove_comb prove_refl f
boehmes@36898
   444
boehmes@36898
   445
  fun prove f cp = prove_comb (prove f) f cp handle CTERM _ => prove_refl cp
boehmes@36898
   446
boehmes@36898
   447
  fun prove_nary is_comb f =
boehmes@36898
   448
    let
boehmes@36898
   449
      fun prove (cp as (ct, _)) = f cp handle MONO =>
boehmes@36898
   450
        if is_comb (Thm.term_of ct)
boehmes@36898
   451
        then prove_comb (prove_arg prove) prove cp
boehmes@36898
   452
        else prove_refl cp
boehmes@36898
   453
    in prove end
boehmes@36898
   454
boehmes@36898
   455
  fun prove_list f n cp =
boehmes@36898
   456
    if n = 0 then prove_refl cp
boehmes@36898
   457
    else prove_comb (prove_arg f) (prove_list f (n-1)) cp
boehmes@36898
   458
boehmes@36898
   459
  fun with_length f (cp as (cl, _)) =
boehmes@36898
   460
    f (length (HOLogic.dest_list (Thm.term_of cl))) cp
boehmes@36898
   461
boehmes@36898
   462
  fun prove_distinct f = prove_arg (with_length (prove_list f))
boehmes@36898
   463
boehmes@36898
   464
  fun prove_eq exn lookup cp =
boehmes@36898
   465
    (case lookup (Logic.mk_equals (pairself Thm.term_of cp)) of
boehmes@36898
   466
      SOME eq => eq
boehmes@36898
   467
    | NONE => if exn then raise MONO else prove_refl cp)
boehmes@36898
   468
  
boehmes@36898
   469
  val prove_eq_exn = prove_eq true
boehmes@36898
   470
  and prove_eq_safe = prove_eq false
boehmes@36898
   471
boehmes@36898
   472
  fun mono f (cp as (cl, _)) =
boehmes@36898
   473
    (case Term.head_of (Thm.term_of cl) of
boehmes@36898
   474
      @{term "op &"} => prove_nary L.is_conj (prove_eq_exn f)
boehmes@36898
   475
    | @{term "op |"} => prove_nary L.is_disj (prove_eq_exn f)
boehmes@36898
   476
    | Const (@{const_name distinct}, _) => prove_distinct (prove_eq_safe f)
boehmes@36898
   477
    | _ => prove (prove_eq_safe f)) cp
boehmes@36898
   478
in
boehmes@36898
   479
fun monotonicity eqs ct =
boehmes@36898
   480
  let
boehmes@36898
   481
    val lookup = AList.lookup (op aconv) (map (`Thm.prop_of o meta_eq_of) eqs)
boehmes@36898
   482
    val cp = Thm.dest_binop (Thm.dest_arg ct)
boehmes@36898
   483
  in MetaEq (prove_eq_exn lookup cp handle MONO => mono lookup cp) end
boehmes@36898
   484
end
boehmes@36898
   485
boehmes@36898
   486
boehmes@36898
   487
boehmes@36898
   488
(* |- f a b = f b a (where f is equality) *)
boehmes@36898
   489
local
boehmes@36898
   490
  val rule = @{lemma "a = b == b = a" by (atomize(full)) (rule eq_commute)}
boehmes@36898
   491
in
boehmes@36898
   492
fun commutativity ct = MetaEq (T.match_instantiate I (T.as_meta_eq ct) rule)
boehmes@36898
   493
end
boehmes@36898
   494
boehmes@36898
   495
boehmes@36898
   496
boehmes@36898
   497
(** quantifier proof rules **)
boehmes@36898
   498
boehmes@36898
   499
(* P ?x = Q ?x ==> (ALL x. P x) = (ALL x. Q x)
boehmes@36898
   500
   P ?x = Q ?x ==> (EX x. P x) = (EX x. Q x)    *)
boehmes@36898
   501
local
boehmes@36898
   502
  val rules = [
boehmes@36898
   503
    @{lemma "(!!x. P x == Q x) ==> (ALL x. P x) == (ALL x. Q x)" by simp},
boehmes@36898
   504
    @{lemma "(!!x. P x == Q x) ==> (EX x. P x) == (EX x. Q x)" by simp}]
boehmes@36898
   505
in
boehmes@36898
   506
fun quant_intro vars p ct =
boehmes@36898
   507
  let
boehmes@36898
   508
    val thm = meta_eq_of p
boehmes@36898
   509
    val rules' = T.varify vars thm :: rules
boehmes@36898
   510
    val cu = T.as_meta_eq ct
boehmes@36898
   511
  in MetaEq (T.by_tac (REPEAT_ALL_NEW (Tactic.match_tac rules')) cu) end
boehmes@36898
   512
end
boehmes@36898
   513
boehmes@36898
   514
boehmes@36898
   515
boehmes@36898
   516
(* |- ((ALL x. P x) | Q) = (ALL x. P x | Q) *)
boehmes@36898
   517
fun pull_quant ctxt = Thm o try_apply ctxt [] [
boehmes@36898
   518
  named ctxt "fast" (T.by_tac (Classical.fast_tac HOL_cs))]
boehmes@36898
   519
    (* FIXME: not very well tested *)
boehmes@36898
   520
boehmes@36898
   521
boehmes@36898
   522
boehmes@36898
   523
(* |- (ALL x. P x & Q x) = ((ALL x. P x) & (ALL x. Q x)) *)
boehmes@36898
   524
fun push_quant ctxt = Thm o try_apply ctxt [] [
boehmes@36898
   525
  named ctxt "fast" (T.by_tac (Classical.fast_tac HOL_cs))]
boehmes@36898
   526
    (* FIXME: not very well tested *)
boehmes@36898
   527
boehmes@36898
   528
boehmes@36898
   529
boehmes@36898
   530
(* |- (ALL x1 ... xn y1 ... yn. P x1 ... xn) = (ALL x1 ... xn. P x1 ... xn) *)
boehmes@36898
   531
local
boehmes@36898
   532
  val elim_all = @{lemma "(ALL x. P) == P" by simp}
boehmes@36898
   533
  val elim_ex = @{lemma "(EX x. P) == P" by simp}
boehmes@36898
   534
boehmes@36898
   535
  fun elim_unused_conv ctxt =
boehmes@36898
   536
    Conv.params_conv ~1 (K (Conv.arg_conv (Conv.arg1_conv
boehmes@36898
   537
      (More_Conv.rewrs_conv [elim_all, elim_ex])))) ctxt
boehmes@36898
   538
boehmes@36898
   539
  fun elim_unused_tac ctxt =
boehmes@36898
   540
    REPEAT_ALL_NEW (
boehmes@36898
   541
      Tactic.match_tac [@{thm refl}, @{thm iff_allI}, @{thm iff_exI}]
boehmes@36898
   542
      ORELSE' CONVERSION (elim_unused_conv ctxt))
boehmes@36898
   543
in
boehmes@36898
   544
fun elim_unused_vars ctxt = Thm o T.by_tac (elim_unused_tac ctxt)
boehmes@36898
   545
end
boehmes@36898
   546
boehmes@36898
   547
boehmes@36898
   548
boehmes@36898
   549
(* |- (ALL x1 ... xn. ~(x1 = t1 & ... xn = tn) | P x1 ... xn) = P t1 ... tn *)
boehmes@36898
   550
fun dest_eq_res ctxt = Thm o try_apply ctxt [] [
boehmes@36898
   551
  named ctxt "fast" (T.by_tac (Classical.fast_tac HOL_cs))]
boehmes@36898
   552
    (* FIXME: not very well tested *)
boehmes@36898
   553
boehmes@36898
   554
boehmes@36898
   555
boehmes@36898
   556
(* |- ~(ALL x1...xn. P x1...xn) | P a1...an *)
boehmes@36898
   557
local
boehmes@36898
   558
  val rule = @{lemma "~ P x | Q ==> ~(ALL x. P x) | Q" by fast}
boehmes@36898
   559
in
boehmes@36898
   560
val quant_inst = Thm o T.by_tac (
boehmes@36898
   561
  REPEAT_ALL_NEW (Tactic.match_tac [rule])
boehmes@36898
   562
  THEN' Tactic.rtac @{thm excluded_middle})
boehmes@36898
   563
end
boehmes@36898
   564
boehmes@36898
   565
boehmes@36898
   566
boehmes@36898
   567
(* c = SOME x. P x |- (EX x. P x) = P c
boehmes@36898
   568
   c = SOME x. ~ P x |- ~(ALL x. P x) = ~ P c *)
boehmes@36898
   569
local
boehmes@36898
   570
  val elim_ex = @{lemma "EX x. P == P" by simp}
boehmes@36898
   571
  val elim_all = @{lemma "~ (ALL x. P) == ~P" by simp}
boehmes@36898
   572
  val sk_ex = @{lemma "c == SOME x. P x ==> EX x. P x == P c"
boehmes@36898
   573
    by simp (intro eq_reflection some_eq_ex[symmetric])}
boehmes@36898
   574
  val sk_all = @{lemma "c == SOME x. ~ P x ==> ~(ALL x. P x) == ~ P c"
boehmes@36898
   575
    by (simp only: not_all) (intro eq_reflection some_eq_ex[symmetric])}
boehmes@36898
   576
  val sk_ex_rule = ((sk_ex, I), elim_ex)
boehmes@36898
   577
  and sk_all_rule = ((sk_all, Thm.dest_arg), elim_all)
boehmes@36898
   578
boehmes@36898
   579
  fun dest f sk_rule = 
boehmes@36898
   580
    Thm.dest_comb (f (Thm.dest_arg (Thm.dest_arg (Thm.cprop_of sk_rule))))
boehmes@36898
   581
  fun type_of f sk_rule = Thm.ctyp_of_term (snd (dest f sk_rule))
boehmes@36898
   582
  fun pair2 (a, b) (c, d) = [(a, c), (b, d)]
boehmes@36898
   583
  fun inst_sk (sk_rule, f) p c =
boehmes@36898
   584
    Thm.instantiate ([(type_of f sk_rule, Thm.ctyp_of_term c)], []) sk_rule
boehmes@36898
   585
    |> (fn sk' => Thm.instantiate ([], (pair2 (dest f sk') (p, c))) sk')
boehmes@36898
   586
    |> Conv.fconv_rule (Thm.beta_conversion true)
boehmes@36898
   587
boehmes@36898
   588
  fun kind (Const (@{const_name Ex}, _) $ _) = (sk_ex_rule, I, I)
boehmes@36898
   589
    | kind (@{term Not} $ (Const (@{const_name All}, _) $ _)) =
boehmes@36898
   590
        (sk_all_rule, Thm.dest_arg, Thm.capply @{cterm Not})
boehmes@36898
   591
    | kind t = raise TERM ("skolemize", [t])
boehmes@36898
   592
boehmes@36898
   593
  fun dest_abs_type (Abs (_, T, _)) = T
boehmes@36898
   594
    | dest_abs_type t = raise TERM ("dest_abs_type", [t])
boehmes@36898
   595
boehmes@36898
   596
  fun bodies_of thy lhs rhs =
boehmes@36898
   597
    let
boehmes@36898
   598
      val (rule, dest, make) = kind (Thm.term_of lhs)
boehmes@36898
   599
boehmes@36898
   600
      fun dest_body idx cbs ct =
boehmes@36898
   601
        let
boehmes@36898
   602
          val cb = Thm.dest_arg (dest ct)
boehmes@36898
   603
          val T = dest_abs_type (Thm.term_of cb)
boehmes@36898
   604
          val cv = Thm.cterm_of thy (Var (("x", idx), T))
boehmes@36898
   605
          val cu = make (Drule.beta_conv cb cv)
boehmes@36898
   606
          val cbs' = (cv, cb) :: cbs
boehmes@36898
   607
        in
boehmes@36898
   608
          (snd (Thm.first_order_match (cu, rhs)), rev cbs')
boehmes@36898
   609
          handle Pattern.MATCH => dest_body (idx+1) cbs' cu
boehmes@36898
   610
        end
boehmes@36898
   611
    in (rule, dest_body 1 [] lhs) end
boehmes@36898
   612
boehmes@36898
   613
  fun transitive f thm = Thm.transitive thm (f (Thm.rhs_of thm))
boehmes@36898
   614
boehmes@36898
   615
  fun sk_step (rule, elim) (cv, mct, cb) ((is, thm), ctxt) =
boehmes@36898
   616
    (case mct of
boehmes@36898
   617
      SOME ct =>
boehmes@36898
   618
        ctxt
boehmes@36898
   619
        |> T.make_hyp_def (inst_sk rule (Thm.instantiate_cterm ([], is) cb) ct)
boehmes@36898
   620
        |>> pair ((cv, ct) :: is) o Thm.transitive thm
boehmes@36898
   621
    | NONE => ((is, transitive (Conv.rewr_conv elim) thm), ctxt))
boehmes@36898
   622
in
boehmes@36898
   623
fun skolemize ct ctxt =
boehmes@36898
   624
  let
boehmes@36898
   625
    val (lhs, rhs) = Thm.dest_binop (Thm.dest_arg ct)
boehmes@36898
   626
    val (rule, (ctab, cbs)) = bodies_of (ProofContext.theory_of ctxt) lhs rhs
boehmes@36898
   627
    fun lookup_var (cv, cb) = (cv, AList.lookup (op aconvc) ctab cv, cb)
boehmes@36898
   628
  in
boehmes@36898
   629
    (([], Thm.reflexive lhs), ctxt)
boehmes@36898
   630
    |> fold (sk_step rule) (map lookup_var cbs)
boehmes@36898
   631
    |>> MetaEq o snd
boehmes@36898
   632
  end
boehmes@36898
   633
end
boehmes@36898
   634
boehmes@36898
   635
boehmes@36898
   636
boehmes@36898
   637
(** theory proof rules **)
boehmes@36898
   638
boehmes@36898
   639
(* theory lemmas: linear arithmetic, arrays *)
boehmes@36898
   640
boehmes@36898
   641
fun th_lemma ctxt simpset thms = Thm o try_apply ctxt thms [
boehmes@36898
   642
  T.by_abstraction ctxt thms (fn ctxt' => T.by_tac (
boehmes@36898
   643
    NAMED ctxt' "arith" (Arith_Data.arith_tac ctxt')
boehmes@36898
   644
    ORELSE' NAMED ctxt' "simp+arith" (Simplifier.simp_tac simpset THEN_ALL_NEW
boehmes@36898
   645
      Arith_Data.arith_tac ctxt')))]
boehmes@36898
   646
boehmes@36898
   647
boehmes@36898
   648
boehmes@36898
   649
(* rewriting: prove equalities:
boehmes@36898
   650
     * ACI of conjunction/disjunction
boehmes@36898
   651
     * contradiction, excluded middle
boehmes@36898
   652
     * logical rewriting rules (for negation, implication, equivalence,
boehmes@36898
   653
         distinct)
boehmes@36898
   654
     * normal forms for polynoms (integer/real arithmetic)
boehmes@36898
   655
     * quantifier elimination over linear arithmetic
boehmes@36898
   656
     * ... ? **)
boehmes@36898
   657
structure Z3_Simps = Named_Thms
boehmes@36898
   658
(
boehmes@36898
   659
  val name = "z3_simp"
boehmes@36898
   660
  val description = "simplification rules for Z3 proof reconstruction"
boehmes@36898
   661
)
boehmes@36898
   662
boehmes@36898
   663
local
boehmes@36898
   664
  fun spec_meta_eq_of thm =
boehmes@36898
   665
    (case try (fn th => th RS @{thm spec}) thm of
boehmes@36898
   666
      SOME thm' => spec_meta_eq_of thm'
boehmes@36898
   667
    | NONE => mk_meta_eq thm)
boehmes@36898
   668
boehmes@36898
   669
  fun prep (Thm thm) = spec_meta_eq_of thm
boehmes@36898
   670
    | prep (MetaEq thm) = thm
boehmes@36898
   671
    | prep (Literals (thm, _)) = spec_meta_eq_of thm
boehmes@36898
   672
boehmes@36898
   673
  fun unfold_conv ctxt ths =
boehmes@36898
   674
    Conv.arg_conv (Conv.binop_conv (T.unfold_eqs ctxt (map prep ths)))
boehmes@36898
   675
boehmes@36898
   676
  fun with_conv _ [] prv = prv
boehmes@36898
   677
    | with_conv ctxt ths prv = T.with_conv (unfold_conv ctxt ths) prv
boehmes@36898
   678
boehmes@36898
   679
  val unfold_conv =
boehmes@36898
   680
    Conv.arg_conv (Conv.binop_conv (Conv.try_conv T.unfold_distinct_conv))
boehmes@36898
   681
  val prove_conj_disj_eq = T.with_conv unfold_conv L.prove_conj_disj_eq
boehmes@36898
   682
in
boehmes@36898
   683
boehmes@36898
   684
fun rewrite ctxt simpset ths = Thm o with_conv ctxt ths (try_apply ctxt [] [
boehmes@36898
   685
  named ctxt "conj/disj/distinct" prove_conj_disj_eq,
boehmes@36898
   686
  T.by_abstraction ctxt [] (fn ctxt' => T.by_tac (
boehmes@36898
   687
    NAMED ctxt' "simp" (Simplifier.simp_tac simpset)
boehmes@36898
   688
    THEN_ALL_NEW (
boehmes@36898
   689
      NAMED ctxt' "fast" (Classical.fast_tac HOL_cs)
boehmes@36898
   690
      ORELSE' NAMED ctxt' "arith" (Arith_Data.arith_tac ctxt'))))])
boehmes@36898
   691
boehmes@36898
   692
end
boehmes@36898
   693
boehmes@36898
   694
boehmes@36898
   695
boehmes@36898
   696
(** proof reconstruction **)
boehmes@36898
   697
boehmes@36898
   698
(* tracing and checking *)
boehmes@36898
   699
boehmes@36898
   700
local
boehmes@36898
   701
  fun count_rules ptab =
boehmes@36898
   702
    let
boehmes@36898
   703
      fun count (_, Unproved _) (solved, total) = (solved, total + 1)
boehmes@36898
   704
        | count (_, Proved _) (solved, total) = (solved + 1, total + 1)
boehmes@36898
   705
    in Inttab.fold count ptab (0, 0) end
boehmes@36898
   706
boehmes@36898
   707
  fun header idx r (solved, total) = 
boehmes@36898
   708
    "Z3: #" ^ string_of_int idx ^ ": " ^ P.string_of_rule r ^ " (goal " ^
boehmes@36898
   709
    string_of_int (solved + 1) ^ " of " ^ string_of_int total ^ ")"
boehmes@36898
   710
boehmes@36898
   711
  fun check ctxt idx r ps ct p =
boehmes@36898
   712
    let val thm = thm_of p |> tap (Thm.join_proofs o single)
boehmes@36898
   713
    in
boehmes@36898
   714
      if (Thm.cprop_of thm) aconvc ct then ()
boehmes@36898
   715
      else z3_exn (Pretty.string_of (Pretty.big_list ("proof step failed: " ^
boehmes@36898
   716
        quote (P.string_of_rule r) ^ " (#" ^ string_of_int idx ^ ")")
boehmes@36898
   717
          (pretty_goal ctxt (map (thm_of o fst) ps) (Thm.prop_of thm) @
boehmes@36898
   718
           [Pretty.block [Pretty.str "expected: ",
boehmes@36898
   719
            Syntax.pretty_term ctxt (Thm.term_of ct)]])))
boehmes@36898
   720
    end
boehmes@36898
   721
in
boehmes@36898
   722
fun trace_rule idx prove r ps ct (cxp as (ctxt, ptab)) =
boehmes@36898
   723
  let
boehmes@36898
   724
    val _ = SMT_Solver.trace_msg ctxt (header idx r o count_rules) ptab
boehmes@36898
   725
    val result as (p, cxp' as (ctxt', _)) = prove r ps ct cxp
boehmes@36898
   726
    val _ = if not (Config.get ctxt' SMT_Solver.trace) then ()
boehmes@36898
   727
      else check ctxt' idx r ps ct p
boehmes@36898
   728
  in result end
boehmes@36898
   729
end
boehmes@36898
   730
boehmes@36898
   731
boehmes@36898
   732
(* overall reconstruction procedure *)
boehmes@36898
   733
boehmes@36898
   734
fun not_supported r =
boehmes@36898
   735
  raise Fail ("Z3: proof rule not implemented: " ^ quote (P.string_of_rule r))
boehmes@36898
   736
boehmes@36898
   737
fun prove ctxt unfolds assms vars =
boehmes@36898
   738
  let
boehmes@36898
   739
    val assms' = Option.map (prepare_assms ctxt unfolds) assms
boehmes@36898
   740
    val simpset = T.make_simpset ctxt (Z3_Simps.get ctxt)
boehmes@36898
   741
boehmes@36898
   742
    fun step r ps ct (cxp as (cx, ptab)) =
boehmes@36898
   743
      (case (r, ps) of
boehmes@36898
   744
        (* core rules *)
boehmes@36898
   745
        (P.TrueAxiom, _) => (Thm L.true_thm, cxp)
boehmes@36898
   746
      | (P.Asserted, _) => (asserted cx assms' ct, cxp)
boehmes@36898
   747
      | (P.Goal, _) => (asserted cx assms' ct, cxp)
boehmes@36898
   748
      | (P.ModusPonens, [(p, _), (q, _)]) => (mp q (thm_of p), cxp)
boehmes@36898
   749
      | (P.ModusPonensOeq, [(p, _), (q, _)]) => (mp q (thm_of p), cxp)
boehmes@36898
   750
      | (P.AndElim, [(p, i)]) => and_elim (p, i) ct ptab ||> pair cx
boehmes@36898
   751
      | (P.NotOrElim, [(p, i)]) => not_or_elim (p, i) ct ptab ||> pair cx
boehmes@36898
   752
      | (P.Hypothesis, _) => (Thm (Thm.assume ct), cxp)
boehmes@36898
   753
      | (P.Lemma, [(p, _)]) => (lemma (thm_of p) ct, cxp)
boehmes@36898
   754
      | (P.UnitResolution, (p, _) :: ps) =>
boehmes@36898
   755
          (unit_resolution (thm_of p) (map (thm_of o fst) ps) ct, cxp)
boehmes@36898
   756
      | (P.IffTrue, [(p, _)]) => (iff_true (thm_of p), cxp)
boehmes@36898
   757
      | (P.IffFalse, [(p, _)]) => (iff_false (thm_of p), cxp)
boehmes@36898
   758
      | (P.Distributivity, _) => (distributivity cx ct, cxp)
boehmes@36898
   759
      | (P.DefAxiom, _) => (def_axiom cx ct, cxp)
boehmes@36898
   760
      | (P.IntroDef, _) => intro_def ct cx ||> rpair ptab
boehmes@36898
   761
      | (P.ApplyDef, [(p, _)]) => (apply_def (thm_of p), cxp)
boehmes@36898
   762
      | (P.IffOeq, [(p, _)]) => (p, cxp)
boehmes@36898
   763
      | (P.NnfPos, _) => (nnf cx vars (map fst ps) ct, cxp)
boehmes@36898
   764
      | (P.NnfNeg, _) => (nnf cx vars (map fst ps) ct, cxp)
boehmes@36898
   765
boehmes@36898
   766
        (* equality rules *)
boehmes@36898
   767
      | (P.Reflexivity, _) => (refl ct, cxp)
boehmes@36898
   768
      | (P.Symmetry, [(p, _)]) => (symm p, cxp)
boehmes@36898
   769
      | (P.Transitivity, [(p, _), (q, _)]) => (trans p q, cxp)
boehmes@36898
   770
      | (P.Monotonicity, _) => (monotonicity (map fst ps) ct, cxp)
boehmes@36898
   771
      | (P.Commutativity, _) => (commutativity ct, cxp)
boehmes@36898
   772
boehmes@36898
   773
        (* quantifier rules *)
boehmes@36898
   774
      | (P.QuantIntro, [(p, _)]) => (quant_intro vars p ct, cxp)
boehmes@36898
   775
      | (P.PullQuant, _) => (pull_quant cx ct, cxp)
boehmes@36898
   776
      | (P.PushQuant, _) => (push_quant cx ct, cxp)
boehmes@36898
   777
      | (P.ElimUnusedVars, _) => (elim_unused_vars cx ct, cxp)
boehmes@36898
   778
      | (P.DestEqRes, _) => (dest_eq_res cx ct, cxp)
boehmes@36898
   779
      | (P.QuantInst, _) => (quant_inst ct, cxp)
boehmes@36898
   780
      | (P.Skolemize, _) => skolemize ct cx ||> rpair ptab
boehmes@36898
   781
boehmes@36898
   782
        (* theory rules *)
boehmes@36898
   783
      | (P.ThLemma, _) =>
boehmes@36898
   784
          (th_lemma cx simpset (map (thm_of o fst) ps) ct, cxp)
boehmes@36898
   785
      | (P.Rewrite, _) => (rewrite cx simpset [] ct, cxp)
boehmes@36898
   786
      | (P.RewriteStar, ps) =>
boehmes@36898
   787
          (rewrite cx simpset (map fst ps) ct, cxp)
boehmes@36898
   788
boehmes@36898
   789
      | (P.NnfStar, _) => not_supported r
boehmes@36898
   790
      | (P.CnfStar, _) => not_supported r
boehmes@36898
   791
      | (P.TransitivityStar, _) => not_supported r
boehmes@36898
   792
      | (P.PullQuantStar, _) => not_supported r
boehmes@36898
   793
boehmes@36898
   794
      | _ => raise Fail ("Z3: proof rule " ^ quote (P.string_of_rule r) ^
boehmes@36898
   795
         " has an unexpected number of arguments."))
boehmes@36898
   796
boehmes@36898
   797
    fun conclude idx rule prop (ps, cxp) =
boehmes@36898
   798
      trace_rule idx step rule ps prop cxp
boehmes@36898
   799
      |-> (fn p => apsnd (Inttab.update (idx, Proved p)) #> pair p)
boehmes@36898
   800
boehmes@36898
   801
    fun lookup idx (cxp as (cx, ptab)) =
boehmes@36898
   802
      (case Inttab.lookup ptab idx of
boehmes@36898
   803
        SOME (Unproved (P.Proof_Step {rule, prems, prop})) =>
boehmes@36898
   804
          fold_map lookup prems cxp
boehmes@36898
   805
          |>> map2 rpair prems
boehmes@36898
   806
          |> conclude idx rule prop
boehmes@36898
   807
      | SOME (Proved p) => (p, cxp)
boehmes@36898
   808
      | NONE => z3_exn ("unknown proof id: " ^ quote (string_of_int idx)))
boehmes@36898
   809
boehmes@36898
   810
    fun result (p, (cx, _)) = (thm_of p, cx)
boehmes@36898
   811
  in
boehmes@36898
   812
    (fn (idx, ptab) => result (lookup idx (ctxt, Inttab.map Unproved ptab)))
boehmes@36898
   813
  end
boehmes@36898
   814
boehmes@36898
   815
fun reconstruct (output, {typs, terms, unfolds, assms}) ctxt =
boehmes@36898
   816
  P.parse ctxt typs terms output
boehmes@36898
   817
  |> (fn (idx, (ptab, vars, cx)) => prove cx unfolds assms vars (idx, ptab))
boehmes@36898
   818
boehmes@36898
   819
val setup = trace_assms_setup #> z3_rules_setup #> Z3_Simps.setup
boehmes@36898
   820
boehmes@36898
   821
end