src/HOL/HoareParallel/Gar_Coll.thy
author wenzelm
Tue Mar 18 20:33:31 2008 +0100 (2008-03-18)
changeset 26316 9e9e67e33557
parent 24742 73b8b42a36b6
child 26342 0f65fa163304
permissions -rw-r--r--
removed redundant less_trans, less_linear, le_imp_less_or_eq, le_less_trans, less_le_trans (cf. Orderings.thy);
prensani@13020
     1
prensani@13020
     2
header {* \section{The Single Mutator Case} *}
prensani@13020
     3
haftmann@16417
     4
theory Gar_Coll imports Graph OG_Syntax begin
prensani@13020
     5
paulson@13624
     6
declare psubsetE [rule del]
paulson@13624
     7
prensani@13020
     8
text {* Declaration of variables: *}
prensani@13020
     9
prensani@13020
    10
record gar_coll_state =
prensani@13020
    11
  M :: nodes
prensani@13020
    12
  E :: edges
prensani@13020
    13
  bc :: "nat set"
prensani@13020
    14
  obc :: "nat set"
prensani@13020
    15
  Ma :: nodes
prensani@13020
    16
  ind :: nat 
prensani@13020
    17
  k :: nat
prensani@13020
    18
  z :: bool
prensani@13020
    19
prensani@13020
    20
subsection {* The Mutator *}
prensani@13020
    21
prensani@13020
    22
text {* The mutator first redirects an arbitrary edge @{text "R"} from
prensani@13020
    23
an arbitrary accessible node towards an arbitrary accessible node
prensani@13020
    24
@{text "T"}.  It then colors the new target @{text "T"} black. 
prensani@13020
    25
prensani@13020
    26
We declare the arbitrarily selected node and edge as constants:*}
prensani@13020
    27
prensani@13020
    28
consts R :: nat  T :: nat
prensani@13020
    29
prensani@13020
    30
text {* \noindent The following predicate states, given a list of
prensani@13020
    31
nodes @{text "m"} and a list of edges @{text "e"}, the conditions
prensani@13020
    32
under which the selected edge @{text "R"} and node @{text "T"} are
prensani@13020
    33
valid: *}
prensani@13020
    34
prensani@13020
    35
constdefs
prensani@13020
    36
  Mut_init :: "gar_coll_state \<Rightarrow> bool"
prensani@13020
    37
  "Mut_init \<equiv> \<guillemotleft> T \<in> Reach \<acute>E \<and> R < length \<acute>E \<and> T < length \<acute>M \<guillemotright>"
prensani@13020
    38
prensani@13020
    39
text {* \noindent For the mutator we
prensani@13020
    40
consider two modules, one for each action.  An auxiliary variable
prensani@13020
    41
@{text "\<acute>z"} is set to false if the mutator has already redirected an
prensani@13020
    42
edge but has not yet colored the new target.   *}
prensani@13020
    43
prensani@13020
    44
constdefs
prensani@13020
    45
  Redirect_Edge :: "gar_coll_state ann_com"
prensani@13020
    46
  "Redirect_Edge \<equiv> .{\<acute>Mut_init \<and> \<acute>z}. \<langle>\<acute>E:=\<acute>E[R:=(fst(\<acute>E!R), T)],, \<acute>z:= (\<not>\<acute>z)\<rangle>"
prensani@13020
    47
prensani@13020
    48
  Color_Target :: "gar_coll_state ann_com"
prensani@13020
    49
  "Color_Target \<equiv> .{\<acute>Mut_init \<and> \<not>\<acute>z}. \<langle>\<acute>M:=\<acute>M[T:=Black],, \<acute>z:= (\<not>\<acute>z)\<rangle>"
prensani@13020
    50
prensani@13020
    51
  Mutator :: "gar_coll_state ann_com"
prensani@13020
    52
  "Mutator \<equiv>
prensani@13020
    53
  .{\<acute>Mut_init \<and> \<acute>z}. 
prensani@13020
    54
  WHILE True INV .{\<acute>Mut_init \<and> \<acute>z}. 
prensani@13020
    55
  DO  Redirect_Edge ;; Color_Target  OD"
prensani@13020
    56
prensani@13020
    57
subsubsection {* Correctness of the mutator *}
prensani@13020
    58
prensani@13020
    59
lemmas mutator_defs = Mut_init_def Redirect_Edge_def Color_Target_def
prensani@13020
    60
prensani@13020
    61
lemma Redirect_Edge: 
prensani@13020
    62
  "\<turnstile> Redirect_Edge pre(Color_Target)"
prensani@13020
    63
apply (unfold mutator_defs)
prensani@13020
    64
apply annhoare
prensani@13020
    65
apply(simp_all)
prensani@13020
    66
apply(force elim:Graph2)
prensani@13020
    67
done
prensani@13020
    68
prensani@13020
    69
lemma Color_Target:
prensani@13020
    70
  "\<turnstile> Color_Target .{\<acute>Mut_init \<and> \<acute>z}."
prensani@13020
    71
apply (unfold mutator_defs)
prensani@13020
    72
apply annhoare
prensani@13020
    73
apply(simp_all)
prensani@13020
    74
done
prensani@13020
    75
prensani@13020
    76
lemma Mutator: 
prensani@13020
    77
 "\<turnstile> Mutator .{False}."
prensani@13020
    78
apply(unfold Mutator_def)
prensani@13020
    79
apply annhoare
prensani@13020
    80
apply(simp_all add:Redirect_Edge Color_Target)
prensani@13020
    81
apply(simp add:mutator_defs Redirect_Edge_def)
prensani@13020
    82
done
prensani@13020
    83
prensani@13020
    84
subsection {* The Collector *}
prensani@13020
    85
prensani@13020
    86
text {* \noindent A constant @{text "M_init"} is used to give @{text "\<acute>Ma"} a
prensani@13020
    87
suitable first value, defined as a list of nodes where only the @{text
prensani@13020
    88
"Roots"} are black. *}
prensani@13020
    89
prensani@13020
    90
consts  M_init :: nodes
prensani@13020
    91
prensani@13020
    92
constdefs
prensani@13020
    93
  Proper_M_init :: "gar_coll_state \<Rightarrow> bool"
prensani@13020
    94
  "Proper_M_init \<equiv>  \<guillemotleft> Blacks M_init=Roots \<and> length M_init=length \<acute>M \<guillemotright>"
prensani@13020
    95
 
prensani@13020
    96
  Proper :: "gar_coll_state \<Rightarrow> bool"
prensani@13020
    97
  "Proper \<equiv> \<guillemotleft> Proper_Roots \<acute>M \<and> Proper_Edges(\<acute>M, \<acute>E) \<and> \<acute>Proper_M_init \<guillemotright>"
prensani@13020
    98
prensani@13020
    99
  Safe :: "gar_coll_state \<Rightarrow> bool"
prensani@13020
   100
  "Safe \<equiv> \<guillemotleft> Reach \<acute>E \<subseteq> Blacks \<acute>M \<guillemotright>"
prensani@13020
   101
prensani@13020
   102
lemmas collector_defs = Proper_M_init_def Proper_def Safe_def
prensani@13020
   103
prensani@13020
   104
subsubsection {* Blackening the roots *}
prensani@13020
   105
prensani@13020
   106
constdefs
prensani@13020
   107
  Blacken_Roots :: " gar_coll_state ann_com"
prensani@13020
   108
  "Blacken_Roots \<equiv> 
prensani@13020
   109
  .{\<acute>Proper}.
prensani@13020
   110
  \<acute>ind:=0;;
prensani@13020
   111
  .{\<acute>Proper \<and> \<acute>ind=0}.
prensani@13020
   112
  WHILE \<acute>ind<length \<acute>M 
prensani@13020
   113
   INV .{\<acute>Proper \<and> (\<forall>i<\<acute>ind. i \<in> Roots \<longrightarrow> \<acute>M!i=Black) \<and> \<acute>ind\<le>length \<acute>M}.
prensani@13020
   114
  DO .{\<acute>Proper \<and> (\<forall>i<\<acute>ind. i \<in> Roots \<longrightarrow> \<acute>M!i=Black) \<and> \<acute>ind<length \<acute>M}.
prensani@13020
   115
   IF \<acute>ind\<in>Roots THEN 
prensani@13020
   116
   .{\<acute>Proper \<and> (\<forall>i<\<acute>ind. i \<in> Roots \<longrightarrow> \<acute>M!i=Black) \<and> \<acute>ind<length \<acute>M \<and> \<acute>ind\<in>Roots}. 
prensani@13020
   117
    \<acute>M:=\<acute>M[\<acute>ind:=Black] FI;;
prensani@13020
   118
   .{\<acute>Proper \<and> (\<forall>i<\<acute>ind+1. i \<in> Roots \<longrightarrow> \<acute>M!i=Black) \<and> \<acute>ind<length \<acute>M}.
prensani@13020
   119
    \<acute>ind:=\<acute>ind+1 
prensani@13020
   120
  OD"
prensani@13020
   121
prensani@13020
   122
lemma Blacken_Roots: 
prensani@13020
   123
 "\<turnstile> Blacken_Roots .{\<acute>Proper \<and> Roots\<subseteq>Blacks \<acute>M}."
prensani@13020
   124
apply (unfold Blacken_Roots_def)
prensani@13020
   125
apply annhoare
prensani@13020
   126
apply(simp_all add:collector_defs Graph_defs)
prensani@13020
   127
apply safe
prensani@13020
   128
apply(simp_all add:nth_list_update)
prensani@13020
   129
  apply (erule less_SucE)
prensani@13020
   130
   apply simp+
prensani@13020
   131
 apply force
prensani@13020
   132
apply force
prensani@13020
   133
done
prensani@13020
   134
prensani@13020
   135
subsubsection {* Propagating black *}
prensani@13020
   136
prensani@13020
   137
constdefs
prensani@13020
   138
  PBInv :: "gar_coll_state \<Rightarrow> nat \<Rightarrow> bool"
prensani@13020
   139
  "PBInv \<equiv> \<guillemotleft> \<lambda>ind. \<acute>obc < Blacks \<acute>M \<or> (\<forall>i <ind. \<not>BtoW (\<acute>E!i, \<acute>M) \<or>
prensani@13020
   140
   (\<not>\<acute>z \<and> i=R \<and> (snd(\<acute>E!R)) = T \<and> (\<exists>r. ind \<le> r \<and> r < length \<acute>E \<and> BtoW(\<acute>E!r,\<acute>M))))\<guillemotright>"
prensani@13020
   141
prensani@13020
   142
constdefs  
prensani@13020
   143
  Propagate_Black_aux :: "gar_coll_state ann_com"
prensani@13020
   144
  "Propagate_Black_aux \<equiv>
prensani@13020
   145
  .{\<acute>Proper \<and> Roots\<subseteq>Blacks \<acute>M \<and> \<acute>obc\<subseteq>Blacks \<acute>M \<and> \<acute>bc\<subseteq>Blacks \<acute>M}.
prensani@13020
   146
  \<acute>ind:=0;;
prensani@13020
   147
  .{\<acute>Proper \<and> Roots\<subseteq>Blacks \<acute>M \<and> \<acute>obc\<subseteq>Blacks \<acute>M \<and> \<acute>bc\<subseteq>Blacks \<acute>M \<and> \<acute>ind=0}. 
prensani@13020
   148
  WHILE \<acute>ind<length \<acute>E 
prensani@13020
   149
   INV .{\<acute>Proper \<and> Roots\<subseteq>Blacks \<acute>M \<and> \<acute>obc\<subseteq>Blacks \<acute>M \<and> \<acute>bc\<subseteq>Blacks \<acute>M 
prensani@13020
   150
         \<and> \<acute>PBInv \<acute>ind \<and> \<acute>ind\<le>length \<acute>E}.
prensani@13020
   151
  DO .{\<acute>Proper \<and> Roots\<subseteq>Blacks \<acute>M \<and> \<acute>obc\<subseteq>Blacks \<acute>M \<and> \<acute>bc\<subseteq>Blacks \<acute>M 
prensani@13020
   152
       \<and> \<acute>PBInv \<acute>ind \<and> \<acute>ind<length \<acute>E}. 
prensani@13020
   153
   IF \<acute>M!(fst (\<acute>E!\<acute>ind)) = Black THEN 
prensani@13020
   154
    .{\<acute>Proper \<and> Roots\<subseteq>Blacks \<acute>M \<and> \<acute>obc\<subseteq>Blacks \<acute>M \<and> \<acute>bc\<subseteq>Blacks \<acute>M 
prensani@13020
   155
       \<and> \<acute>PBInv \<acute>ind \<and> \<acute>ind<length \<acute>E \<and> \<acute>M!fst(\<acute>E!\<acute>ind)=Black}.
prensani@13020
   156
     \<acute>M:=\<acute>M[snd(\<acute>E!\<acute>ind):=Black];;
prensani@13020
   157
    .{\<acute>Proper \<and> Roots\<subseteq>Blacks \<acute>M \<and> \<acute>obc\<subseteq>Blacks \<acute>M \<and> \<acute>bc\<subseteq>Blacks \<acute>M 
prensani@13020
   158
       \<and> \<acute>PBInv (\<acute>ind + 1) \<and> \<acute>ind<length \<acute>E}.
prensani@13020
   159
     \<acute>ind:=\<acute>ind+1
prensani@13020
   160
   FI
prensani@13020
   161
  OD"
prensani@13020
   162
prensani@13020
   163
lemma Propagate_Black_aux: 
prensani@13020
   164
  "\<turnstile>  Propagate_Black_aux
prensani@13020
   165
  .{\<acute>Proper \<and> Roots\<subseteq>Blacks \<acute>M \<and> \<acute>obc\<subseteq>Blacks \<acute>M \<and> \<acute>bc\<subseteq>Blacks \<acute>M 
prensani@13020
   166
    \<and> ( \<acute>obc < Blacks \<acute>M \<or> \<acute>Safe)}."
prensani@13020
   167
apply (unfold Propagate_Black_aux_def  PBInv_def collector_defs)
prensani@13020
   168
apply annhoare
prensani@13020
   169
apply(simp_all add:Graph6 Graph7 Graph8 Graph12)
prensani@13020
   170
      apply force
prensani@13020
   171
     apply force
prensani@13020
   172
    apply force
prensani@13020
   173
--{* 4 subgoals left *}
prensani@13020
   174
apply clarify
prensani@13020
   175
apply(simp add:Proper_Edges_def Proper_Roots_def Graph6 Graph7 Graph8 Graph12)
prensani@13020
   176
apply (erule disjE)
prensani@13020
   177
 apply(rule disjI1)
prensani@13020
   178
 apply(erule Graph13)
prensani@13020
   179
 apply force
prensani@13020
   180
apply (case_tac "M x ! snd (E x ! ind x)=Black")
prensani@13020
   181
 apply (simp add: Graph10 BtoW_def)
prensani@13020
   182
 apply (rule disjI2)
prensani@13020
   183
 apply clarify
prensani@13020
   184
 apply (erule less_SucE)
prensani@13020
   185
  apply (erule_tac x=i in allE , erule (1) notE impE)
prensani@13020
   186
  apply simp
prensani@13020
   187
  apply clarify
wenzelm@26316
   188
  apply (drule_tac y = r in le_imp_less_or_eq)
prensani@13020
   189
  apply (erule disjE)
prensani@13020
   190
   apply (subgoal_tac "Suc (ind x)\<le>r")
prensani@13020
   191
    apply fast
prensani@13020
   192
   apply arith
prensani@13020
   193
  apply fast
prensani@13020
   194
 apply fast
prensani@13020
   195
apply(rule disjI1)
prensani@13020
   196
apply(erule subset_psubset_trans)
prensani@13020
   197
apply(erule Graph11)
prensani@13020
   198
apply fast
prensani@13020
   199
--{* 3 subgoals left *}
prensani@13020
   200
apply force
prensani@13020
   201
apply force
prensani@13020
   202
--{* last *}
prensani@13020
   203
apply clarify
prensani@13020
   204
apply simp
prensani@13020
   205
apply(subgoal_tac "ind x = length (E x)")
prensani@13020
   206
 apply (rotate_tac -1)
berghofe@13601
   207
 apply (simp (asm_lr))
prensani@13020
   208
 apply(drule Graph1)
prensani@13020
   209
   apply simp
prensani@13020
   210
  apply clarify  
prensani@13020
   211
 apply(erule allE, erule impE, assumption)
prensani@13020
   212
  apply force
prensani@13020
   213
 apply force
prensani@13020
   214
apply arith
prensani@13020
   215
done
prensani@13020
   216
prensani@13020
   217
subsubsection {* Refining propagating black *}
prensani@13020
   218
prensani@13020
   219
constdefs
prensani@13020
   220
  Auxk :: "gar_coll_state \<Rightarrow> bool"
prensani@13020
   221
  "Auxk \<equiv> \<guillemotleft>\<acute>k<length \<acute>M \<and> (\<acute>M!\<acute>k\<noteq>Black \<or> \<not>BtoW(\<acute>E!\<acute>ind, \<acute>M) \<or> 
prensani@13020
   222
          \<acute>obc<Blacks \<acute>M \<or> (\<not>\<acute>z \<and> \<acute>ind=R \<and> snd(\<acute>E!R)=T  
prensani@13020
   223
          \<and> (\<exists>r. \<acute>ind<r \<and> r<length \<acute>E \<and> BtoW(\<acute>E!r, \<acute>M))))\<guillemotright>"
prensani@13020
   224
prensani@13020
   225
constdefs  
prensani@13020
   226
  Propagate_Black :: " gar_coll_state ann_com"
prensani@13020
   227
  "Propagate_Black \<equiv>
prensani@13020
   228
  .{\<acute>Proper \<and> Roots\<subseteq>Blacks \<acute>M \<and> \<acute>obc\<subseteq>Blacks \<acute>M \<and> \<acute>bc\<subseteq>Blacks \<acute>M}.
prensani@13020
   229
  \<acute>ind:=0;;
prensani@13020
   230
  .{\<acute>Proper \<and> Roots\<subseteq>Blacks \<acute>M \<and> \<acute>obc\<subseteq>Blacks \<acute>M \<and> \<acute>bc\<subseteq>Blacks \<acute>M \<and> \<acute>ind=0}.
prensani@13020
   231
  WHILE \<acute>ind<length \<acute>E 
prensani@13020
   232
   INV .{\<acute>Proper \<and> Roots\<subseteq>Blacks \<acute>M \<and> \<acute>obc\<subseteq>Blacks \<acute>M \<and> \<acute>bc\<subseteq>Blacks \<acute>M 
prensani@13020
   233
         \<and> \<acute>PBInv \<acute>ind \<and> \<acute>ind\<le>length \<acute>E}.
prensani@13020
   234
  DO .{\<acute>Proper \<and> Roots\<subseteq>Blacks \<acute>M \<and> \<acute>obc\<subseteq>Blacks \<acute>M \<and> \<acute>bc\<subseteq>Blacks \<acute>M 
prensani@13020
   235
       \<and> \<acute>PBInv \<acute>ind \<and> \<acute>ind<length \<acute>E}. 
prensani@13020
   236
   IF (\<acute>M!(fst (\<acute>E!\<acute>ind)))=Black THEN 
prensani@13020
   237
    .{\<acute>Proper \<and> Roots\<subseteq>Blacks \<acute>M \<and> \<acute>obc\<subseteq>Blacks \<acute>M \<and> \<acute>bc\<subseteq>Blacks \<acute>M 
prensani@13020
   238
      \<and> \<acute>PBInv \<acute>ind \<and> \<acute>ind<length \<acute>E \<and> (\<acute>M!fst(\<acute>E!\<acute>ind))=Black}.
prensani@13020
   239
     \<acute>k:=(snd(\<acute>E!\<acute>ind));;
prensani@13020
   240
    .{\<acute>Proper \<and> Roots\<subseteq>Blacks \<acute>M \<and> \<acute>obc\<subseteq>Blacks \<acute>M \<and> \<acute>bc\<subseteq>Blacks \<acute>M 
prensani@13020
   241
      \<and> \<acute>PBInv \<acute>ind \<and> \<acute>ind<length \<acute>E \<and> (\<acute>M!fst(\<acute>E!\<acute>ind))=Black 
prensani@13020
   242
      \<and> \<acute>Auxk}.
prensani@13020
   243
     \<langle>\<acute>M:=\<acute>M[\<acute>k:=Black],, \<acute>ind:=\<acute>ind+1\<rangle>
prensani@13020
   244
   ELSE .{\<acute>Proper \<and> Roots\<subseteq>Blacks \<acute>M \<and> \<acute>obc\<subseteq>Blacks \<acute>M \<and> \<acute>bc\<subseteq>Blacks \<acute>M 
prensani@13020
   245
          \<and> \<acute>PBInv \<acute>ind \<and> \<acute>ind<length \<acute>E}. 
prensani@13020
   246
         \<langle>IF (\<acute>M!(fst (\<acute>E!\<acute>ind)))\<noteq>Black THEN \<acute>ind:=\<acute>ind+1 FI\<rangle> 
prensani@13020
   247
   FI
prensani@13020
   248
  OD"
prensani@13020
   249
prensani@13020
   250
lemma Propagate_Black: 
prensani@13020
   251
  "\<turnstile>  Propagate_Black
prensani@13020
   252
  .{\<acute>Proper \<and> Roots\<subseteq>Blacks \<acute>M \<and> \<acute>obc\<subseteq>Blacks \<acute>M \<and> \<acute>bc\<subseteq>Blacks \<acute>M 
prensani@13020
   253
    \<and> ( \<acute>obc < Blacks \<acute>M \<or> \<acute>Safe)}."
prensani@13020
   254
apply (unfold Propagate_Black_def  PBInv_def Auxk_def collector_defs)
prensani@13020
   255
apply annhoare
prensani@13020
   256
apply(simp_all add:Graph6 Graph7 Graph8 Graph12)
prensani@13020
   257
       apply force
prensani@13020
   258
      apply force
prensani@13020
   259
     apply force
prensani@13020
   260
--{* 5 subgoals left *}
prensani@13020
   261
apply clarify
prensani@13020
   262
apply(simp add:BtoW_def Proper_Edges_def)
prensani@13020
   263
--{* 4 subgoals left *}
prensani@13020
   264
apply clarify
prensani@13020
   265
apply(simp add:Proper_Edges_def Graph6 Graph7 Graph8 Graph12)
prensani@13020
   266
apply (erule disjE)
prensani@13020
   267
 apply (rule disjI1)
prensani@13020
   268
 apply (erule psubset_subset_trans)
prensani@13020
   269
 apply (erule Graph9)
prensani@13020
   270
apply (case_tac "M x!k x=Black")
prensani@13020
   271
 apply (case_tac "M x ! snd (E x ! ind x)=Black")
prensani@13020
   272
  apply (simp add: Graph10 BtoW_def)
prensani@13020
   273
  apply (rule disjI2)
prensani@13020
   274
  apply clarify
prensani@13020
   275
  apply (erule less_SucE)
prensani@13020
   276
   apply (erule_tac x=i in allE , erule (1) notE impE)
prensani@13020
   277
   apply simp
prensani@13020
   278
   apply clarify
wenzelm@26316
   279
   apply (drule_tac y = r in le_imp_less_or_eq)
prensani@13020
   280
   apply (erule disjE)
prensani@13020
   281
    apply (subgoal_tac "Suc (ind x)\<le>r")
prensani@13020
   282
     apply fast
prensani@13020
   283
    apply arith
prensani@13020
   284
   apply fast
prensani@13020
   285
  apply fast
prensani@13020
   286
 apply (simp add: Graph10 BtoW_def)
prensani@13020
   287
 apply (erule disjE)
prensani@13020
   288
  apply (erule disjI1)
prensani@13020
   289
 apply clarify
prensani@13020
   290
 apply (erule less_SucE)
prensani@13020
   291
  apply force
prensani@13020
   292
 apply simp
prensani@13020
   293
 apply (subgoal_tac "Suc R\<le>r")
prensani@13020
   294
  apply fast
prensani@13020
   295
 apply arith
prensani@13020
   296
apply(rule disjI1)
prensani@13020
   297
apply(erule subset_psubset_trans)
prensani@13020
   298
apply(erule Graph11)
prensani@13020
   299
apply fast
prensani@13020
   300
--{* 3 subgoals left *}
prensani@13020
   301
apply force
prensani@13020
   302
--{* 2 subgoals left *}
prensani@13020
   303
apply clarify
prensani@13020
   304
apply(simp add:Proper_Edges_def Graph6 Graph7 Graph8 Graph12)
prensani@13020
   305
apply (erule disjE)
prensani@13020
   306
 apply fast
prensani@13020
   307
apply clarify
prensani@13020
   308
apply (erule less_SucE)
prensani@13020
   309
 apply (erule_tac x=i in allE , erule (1) notE impE)
prensani@13020
   310
 apply simp
prensani@13020
   311
 apply clarify
wenzelm@26316
   312
 apply (drule_tac y = r in le_imp_less_or_eq)
prensani@13020
   313
 apply (erule disjE)
prensani@13020
   314
  apply (subgoal_tac "Suc (ind x)\<le>r")
prensani@13020
   315
   apply fast
prensani@13020
   316
  apply arith
prensani@13020
   317
 apply (simp add: BtoW_def)
prensani@13020
   318
apply (simp add: BtoW_def)
prensani@13020
   319
--{* last *}
prensani@13020
   320
apply clarify
prensani@13020
   321
apply simp
prensani@13020
   322
apply(subgoal_tac "ind x = length (E x)")
prensani@13020
   323
 apply (rotate_tac -1)
berghofe@13601
   324
 apply (simp (asm_lr))
prensani@13020
   325
 apply(drule Graph1)
prensani@13020
   326
   apply simp
prensani@13020
   327
  apply clarify  
prensani@13020
   328
 apply(erule allE, erule impE, assumption)
prensani@13020
   329
  apply force
prensani@13020
   330
 apply force
prensani@13020
   331
apply arith
prensani@13020
   332
done
prensani@13020
   333
prensani@13020
   334
subsubsection {* Counting black nodes *}
prensani@13020
   335
prensani@13020
   336
constdefs
prensani@13020
   337
  CountInv :: "gar_coll_state \<Rightarrow> nat \<Rightarrow> bool"
prensani@13020
   338
  "CountInv \<equiv> \<guillemotleft> \<lambda>ind. {i. i<ind \<and> \<acute>Ma!i=Black}\<subseteq>\<acute>bc \<guillemotright>"
prensani@13020
   339
prensani@13020
   340
constdefs
prensani@13020
   341
  Count :: " gar_coll_state ann_com"
prensani@13020
   342
  "Count \<equiv>
prensani@13020
   343
  .{\<acute>Proper \<and> Roots\<subseteq>Blacks \<acute>M 
prensani@13020
   344
    \<and> \<acute>obc\<subseteq>Blacks \<acute>Ma \<and> Blacks \<acute>Ma\<subseteq>Blacks \<acute>M \<and> \<acute>bc\<subseteq>Blacks \<acute>M 
prensani@13020
   345
    \<and> length \<acute>Ma=length \<acute>M \<and> (\<acute>obc < Blacks \<acute>Ma \<or> \<acute>Safe) \<and> \<acute>bc={}}.
prensani@13020
   346
  \<acute>ind:=0;;
prensani@13020
   347
  .{\<acute>Proper \<and> Roots\<subseteq>Blacks \<acute>M 
prensani@13020
   348
    \<and> \<acute>obc\<subseteq>Blacks \<acute>Ma \<and> Blacks \<acute>Ma\<subseteq>Blacks \<acute>M \<and> \<acute>bc\<subseteq>Blacks \<acute>M 
prensani@13020
   349
   \<and> length \<acute>Ma=length \<acute>M \<and> (\<acute>obc < Blacks \<acute>Ma \<or> \<acute>Safe) \<and> \<acute>bc={} 
prensani@13020
   350
   \<and> \<acute>ind=0}.
prensani@13020
   351
   WHILE \<acute>ind<length \<acute>M 
prensani@13020
   352
     INV .{\<acute>Proper \<and> Roots\<subseteq>Blacks \<acute>M 
prensani@13020
   353
           \<and> \<acute>obc\<subseteq>Blacks \<acute>Ma \<and> Blacks \<acute>Ma\<subseteq>Blacks \<acute>M \<and> \<acute>bc\<subseteq>Blacks \<acute>M 
prensani@13020
   354
           \<and> length \<acute>Ma=length \<acute>M \<and> \<acute>CountInv \<acute>ind
prensani@13020
   355
           \<and> ( \<acute>obc < Blacks \<acute>Ma \<or> \<acute>Safe) \<and> \<acute>ind\<le>length \<acute>M}.
prensani@13020
   356
   DO .{\<acute>Proper \<and> Roots\<subseteq>Blacks \<acute>M 
prensani@13020
   357
         \<and> \<acute>obc\<subseteq>Blacks \<acute>Ma \<and> Blacks \<acute>Ma\<subseteq>Blacks \<acute>M \<and> \<acute>bc\<subseteq>Blacks \<acute>M 
prensani@13020
   358
         \<and> length \<acute>Ma=length \<acute>M \<and> \<acute>CountInv \<acute>ind 
prensani@13020
   359
         \<and> ( \<acute>obc < Blacks \<acute>Ma \<or> \<acute>Safe) \<and> \<acute>ind<length \<acute>M}. 
prensani@13020
   360
       IF \<acute>M!\<acute>ind=Black 
prensani@13020
   361
          THEN .{\<acute>Proper \<and> Roots\<subseteq>Blacks \<acute>M 
prensani@13020
   362
                 \<and> \<acute>obc\<subseteq>Blacks \<acute>Ma \<and> Blacks \<acute>Ma\<subseteq>Blacks \<acute>M \<and> \<acute>bc\<subseteq>Blacks \<acute>M 
prensani@13020
   363
                 \<and> length \<acute>Ma=length \<acute>M \<and> \<acute>CountInv \<acute>ind
prensani@13020
   364
                 \<and> ( \<acute>obc < Blacks \<acute>Ma \<or> \<acute>Safe) \<and> \<acute>ind<length \<acute>M \<and> \<acute>M!\<acute>ind=Black}.
prensani@13020
   365
          \<acute>bc:=insert \<acute>ind \<acute>bc
prensani@13020
   366
       FI;;
prensani@13020
   367
      .{\<acute>Proper \<and> Roots\<subseteq>Blacks \<acute>M 
prensani@13020
   368
        \<and> \<acute>obc\<subseteq>Blacks \<acute>Ma \<and> Blacks \<acute>Ma\<subseteq>Blacks \<acute>M \<and> \<acute>bc\<subseteq>Blacks \<acute>M 
prensani@13020
   369
        \<and> length \<acute>Ma=length \<acute>M \<and> \<acute>CountInv (\<acute>ind+1)
prensani@13020
   370
        \<and> ( \<acute>obc < Blacks \<acute>Ma \<or> \<acute>Safe) \<and> \<acute>ind<length \<acute>M}.
prensani@13020
   371
      \<acute>ind:=\<acute>ind+1
prensani@13020
   372
   OD"
prensani@13020
   373
prensani@13020
   374
lemma Count: 
prensani@13020
   375
  "\<turnstile> Count 
prensani@13020
   376
  .{\<acute>Proper \<and> Roots\<subseteq>Blacks \<acute>M 
prensani@13020
   377
   \<and> \<acute>obc\<subseteq>Blacks \<acute>Ma \<and> Blacks \<acute>Ma\<subseteq>\<acute>bc \<and> \<acute>bc\<subseteq>Blacks \<acute>M \<and> length \<acute>Ma=length \<acute>M
prensani@13020
   378
   \<and> (\<acute>obc < Blacks \<acute>Ma \<or> \<acute>Safe)}."
prensani@13020
   379
apply(unfold Count_def)
prensani@13020
   380
apply annhoare
prensani@13020
   381
apply(simp_all add:CountInv_def Graph6 Graph7 Graph8 Graph12 Blacks_def collector_defs)
prensani@13020
   382
      apply force
prensani@13020
   383
     apply force
prensani@13020
   384
    apply force
prensani@13020
   385
   apply clarify
prensani@13020
   386
   apply simp
prensani@13020
   387
   apply(fast elim:less_SucE)
prensani@13020
   388
  apply clarify
prensani@13020
   389
  apply simp
prensani@13020
   390
  apply(fast elim:less_SucE)
prensani@13020
   391
 apply force
prensani@13020
   392
apply force
prensani@13020
   393
done
prensani@13020
   394
prensani@13020
   395
subsubsection {* Appending garbage nodes to the free list *}
prensani@13020
   396
prensani@13020
   397
consts Append_to_free :: "nat \<times> edges \<Rightarrow> edges"
prensani@13020
   398
prensani@13020
   399
axioms
prensani@13020
   400
  Append_to_free0: "length (Append_to_free (i, e)) = length e"
prensani@13020
   401
  Append_to_free1: "Proper_Edges (m, e) 
prensani@13020
   402
                   \<Longrightarrow> Proper_Edges (m, Append_to_free(i, e))"
prensani@13020
   403
  Append_to_free2: "i \<notin> Reach e 
prensani@13020
   404
     \<Longrightarrow> n \<in> Reach (Append_to_free(i, e)) = ( n = i \<or> n \<in> Reach e)"
prensani@13020
   405
prensani@13020
   406
constdefs
prensani@13020
   407
  AppendInv :: "gar_coll_state \<Rightarrow> nat \<Rightarrow> bool"
prensani@13020
   408
  "AppendInv \<equiv> \<guillemotleft>\<lambda>ind. \<forall>i<length \<acute>M. ind\<le>i \<longrightarrow> i\<in>Reach \<acute>E \<longrightarrow> \<acute>M!i=Black\<guillemotright>"
prensani@13020
   409
prensani@13020
   410
constdefs
prensani@13020
   411
  Append :: " gar_coll_state ann_com"
prensani@13020
   412
   "Append \<equiv>
prensani@13020
   413
  .{\<acute>Proper \<and> Roots\<subseteq>Blacks \<acute>M \<and> \<acute>Safe}.
prensani@13020
   414
  \<acute>ind:=0;;
prensani@13020
   415
  .{\<acute>Proper \<and> Roots\<subseteq>Blacks \<acute>M \<and> \<acute>Safe \<and> \<acute>ind=0}.
prensani@13020
   416
    WHILE \<acute>ind<length \<acute>M 
prensani@13020
   417
      INV .{\<acute>Proper \<and> \<acute>AppendInv \<acute>ind \<and> \<acute>ind\<le>length \<acute>M}.
prensani@13020
   418
    DO .{\<acute>Proper \<and> \<acute>AppendInv \<acute>ind \<and> \<acute>ind<length \<acute>M}.
prensani@13020
   419
       IF \<acute>M!\<acute>ind=Black THEN 
prensani@13020
   420
          .{\<acute>Proper \<and> \<acute>AppendInv \<acute>ind \<and> \<acute>ind<length \<acute>M \<and> \<acute>M!\<acute>ind=Black}. 
prensani@13020
   421
          \<acute>M:=\<acute>M[\<acute>ind:=White] 
prensani@13020
   422
       ELSE .{\<acute>Proper \<and> \<acute>AppendInv \<acute>ind \<and> \<acute>ind<length \<acute>M \<and> \<acute>ind\<notin>Reach \<acute>E}.
prensani@13020
   423
              \<acute>E:=Append_to_free(\<acute>ind,\<acute>E)
prensani@13020
   424
       FI;;
prensani@13020
   425
     .{\<acute>Proper \<and> \<acute>AppendInv (\<acute>ind+1) \<and> \<acute>ind<length \<acute>M}. 
prensani@13020
   426
       \<acute>ind:=\<acute>ind+1
prensani@13020
   427
    OD"
prensani@13020
   428
prensani@13020
   429
lemma Append: 
prensani@13020
   430
  "\<turnstile> Append .{\<acute>Proper}."
prensani@13020
   431
apply(unfold Append_def AppendInv_def)
prensani@13020
   432
apply annhoare
prensani@13020
   433
apply(simp_all add:collector_defs Graph6 Graph7 Graph8 Append_to_free0 Append_to_free1 Graph12)
prensani@13020
   434
       apply(force simp:Blacks_def nth_list_update)
prensani@13020
   435
      apply force
prensani@13020
   436
     apply force
prensani@13020
   437
    apply(force simp add:Graph_defs)
prensani@13020
   438
   apply force
prensani@13020
   439
  apply clarify
prensani@13020
   440
  apply simp
prensani@13020
   441
  apply(rule conjI)
prensani@13020
   442
   apply (erule Append_to_free1)
prensani@13020
   443
  apply clarify
prensani@13020
   444
  apply (drule_tac n = "i" in Append_to_free2)
prensani@13020
   445
  apply force
prensani@13020
   446
 apply force
prensani@13020
   447
apply force
prensani@13020
   448
done
prensani@13020
   449
prensani@13020
   450
subsubsection {* Correctness of the Collector *}
prensani@13020
   451
prensani@13020
   452
constdefs 
prensani@13020
   453
  Collector :: " gar_coll_state ann_com"
prensani@13020
   454
  "Collector \<equiv>
prensani@13020
   455
.{\<acute>Proper}.  
prensani@13020
   456
 WHILE True INV .{\<acute>Proper}. 
prensani@13020
   457
 DO  
prensani@13020
   458
  Blacken_Roots;; 
prensani@13020
   459
  .{\<acute>Proper \<and> Roots\<subseteq>Blacks \<acute>M}.  
prensani@13020
   460
   \<acute>obc:={};; 
prensani@13020
   461
  .{\<acute>Proper \<and> Roots\<subseteq>Blacks \<acute>M \<and> \<acute>obc={}}. 
prensani@13020
   462
   \<acute>bc:=Roots;; 
prensani@13020
   463
  .{\<acute>Proper \<and> Roots\<subseteq>Blacks \<acute>M \<and> \<acute>obc={} \<and> \<acute>bc=Roots}. 
prensani@13020
   464
   \<acute>Ma:=M_init;;  
prensani@13020
   465
  .{\<acute>Proper \<and> Roots\<subseteq>Blacks \<acute>M \<and> \<acute>obc={} \<and> \<acute>bc=Roots \<and> \<acute>Ma=M_init}. 
prensani@13020
   466
   WHILE \<acute>obc\<noteq>\<acute>bc  
prensani@13020
   467
     INV .{\<acute>Proper \<and> Roots\<subseteq>Blacks \<acute>M 
prensani@13020
   468
           \<and> \<acute>obc\<subseteq>Blacks \<acute>Ma \<and> Blacks \<acute>Ma\<subseteq>\<acute>bc \<and> \<acute>bc\<subseteq>Blacks \<acute>M 
prensani@13020
   469
           \<and> length \<acute>Ma=length \<acute>M \<and> (\<acute>obc < Blacks \<acute>Ma \<or> \<acute>Safe)}. 
prensani@13020
   470
   DO .{\<acute>Proper \<and> Roots\<subseteq>Blacks \<acute>M \<and> \<acute>bc\<subseteq>Blacks \<acute>M}.
prensani@13020
   471
       \<acute>obc:=\<acute>bc;;
prensani@13020
   472
       Propagate_Black;; 
prensani@13020
   473
      .{\<acute>Proper \<and> Roots\<subseteq>Blacks \<acute>M \<and> \<acute>obc\<subseteq>Blacks \<acute>M \<and> \<acute>bc\<subseteq>Blacks \<acute>M 
prensani@13020
   474
        \<and> (\<acute>obc < Blacks \<acute>M \<or> \<acute>Safe)}. 
prensani@13020
   475
       \<acute>Ma:=\<acute>M;;
prensani@13020
   476
      .{\<acute>Proper \<and> Roots\<subseteq>Blacks \<acute>M \<and> \<acute>obc\<subseteq>Blacks \<acute>Ma 
prensani@13020
   477
        \<and> Blacks \<acute>Ma\<subseteq>Blacks \<acute>M \<and> \<acute>bc\<subseteq>Blacks \<acute>M \<and> length \<acute>Ma=length \<acute>M 
prensani@13020
   478
        \<and> ( \<acute>obc < Blacks \<acute>Ma \<or> \<acute>Safe)}.
prensani@13020
   479
       \<acute>bc:={};;
prensani@13020
   480
       Count 
prensani@13020
   481
   OD;; 
prensani@13020
   482
  Append  
prensani@13020
   483
 OD"
prensani@13020
   484
prensani@13020
   485
lemma Collector: 
prensani@13020
   486
  "\<turnstile> Collector .{False}."
prensani@13020
   487
apply(unfold Collector_def)
prensani@13020
   488
apply annhoare
prensani@13020
   489
apply(simp_all add: Blacken_Roots Propagate_Black Count Append)
prensani@13020
   490
apply(simp_all add:Blacken_Roots_def Propagate_Black_def Count_def Append_def collector_defs)
prensani@13020
   491
   apply (force simp add: Proper_Roots_def)
prensani@13020
   492
  apply force
prensani@13020
   493
 apply force
prensani@13020
   494
apply clarify
prensani@13020
   495
apply (erule disjE)
prensani@13020
   496
apply(simp add:psubsetI)
prensani@13020
   497
 apply(force dest:subset_antisym)
prensani@13020
   498
done
prensani@13020
   499
prensani@13020
   500
subsection {* Interference Freedom *}
prensani@13020
   501
prensani@13020
   502
lemmas modules = Redirect_Edge_def Color_Target_def Blacken_Roots_def 
prensani@13020
   503
                 Propagate_Black_def Count_def Append_def
prensani@13020
   504
lemmas Invariants = PBInv_def Auxk_def CountInv_def AppendInv_def
prensani@13020
   505
lemmas abbrev = collector_defs mutator_defs Invariants
prensani@13020
   506
prensani@13020
   507
lemma interfree_Blacken_Roots_Redirect_Edge: 
prensani@13020
   508
 "interfree_aux (Some Blacken_Roots, {}, Some Redirect_Edge)"
prensani@13020
   509
apply (unfold modules)
prensani@13020
   510
apply interfree_aux
prensani@13020
   511
apply safe
prensani@13020
   512
apply (simp_all add:Graph6 Graph12 abbrev)
prensani@13020
   513
done
prensani@13020
   514
prensani@13020
   515
lemma interfree_Redirect_Edge_Blacken_Roots: 
prensani@13020
   516
  "interfree_aux (Some Redirect_Edge, {}, Some Blacken_Roots)"
prensani@13020
   517
apply (unfold modules)
prensani@13020
   518
apply interfree_aux
prensani@13020
   519
apply safe
prensani@13020
   520
apply(simp add:abbrev)+
prensani@13020
   521
done
prensani@13020
   522
prensani@13020
   523
lemma interfree_Blacken_Roots_Color_Target: 
prensani@13020
   524
  "interfree_aux (Some Blacken_Roots, {}, Some Color_Target)"
prensani@13020
   525
apply (unfold modules)
prensani@13020
   526
apply interfree_aux
prensani@13020
   527
apply safe
prensani@13020
   528
apply(simp_all add:Graph7 Graph8 nth_list_update abbrev)
prensani@13020
   529
done
prensani@13020
   530
prensani@13020
   531
lemma interfree_Color_Target_Blacken_Roots: 
prensani@13020
   532
  "interfree_aux (Some Color_Target, {}, Some Blacken_Roots)"
prensani@13020
   533
apply (unfold modules )
prensani@13020
   534
apply interfree_aux
prensani@13020
   535
apply safe
prensani@13020
   536
apply(simp add:abbrev)+
prensani@13020
   537
done
prensani@13020
   538
prensani@13020
   539
lemma interfree_Propagate_Black_Redirect_Edge: 
prensani@13020
   540
  "interfree_aux (Some Propagate_Black, {}, Some Redirect_Edge)"
prensani@13020
   541
apply (unfold modules )
prensani@13020
   542
apply interfree_aux
prensani@13020
   543
--{* 11 subgoals left *}
prensani@13020
   544
apply(clarify, simp add:abbrev Graph6 Graph12)
prensani@13020
   545
apply(clarify, simp add:abbrev Graph6 Graph12)
prensani@13020
   546
apply(clarify, simp add:abbrev Graph6 Graph12)
prensani@13020
   547
apply(clarify, simp add:abbrev Graph6 Graph12)
prensani@13020
   548
apply(erule conjE)+
prensani@13020
   549
apply(erule disjE, erule disjI1, rule disjI2, rule allI, (rule impI)+, case_tac "R=i", rule conjI, erule sym)
prensani@13020
   550
 apply(erule Graph4) 
prensani@13020
   551
   apply(simp)+
prensani@13020
   552
  apply (simp add:BtoW_def)
prensani@13020
   553
 apply (simp add:BtoW_def)
prensani@13020
   554
apply(rule conjI)
prensani@13020
   555
 apply (force simp add:BtoW_def)
prensani@13020
   556
apply(erule Graph4)
prensani@13020
   557
   apply simp+
prensani@13020
   558
--{* 7 subgoals left *}
prensani@13020
   559
apply(clarify, simp add:abbrev Graph6 Graph12)
prensani@13020
   560
apply(erule conjE)+
prensani@13020
   561
apply(erule disjE, erule disjI1, rule disjI2, rule allI, (rule impI)+, case_tac "R=i", rule conjI, erule sym)
prensani@13020
   562
 apply(erule Graph4) 
prensani@13020
   563
   apply(simp)+
prensani@13020
   564
  apply (simp add:BtoW_def)
prensani@13020
   565
 apply (simp add:BtoW_def)
prensani@13020
   566
apply(rule conjI)
prensani@13020
   567
 apply (force simp add:BtoW_def)
prensani@13020
   568
apply(erule Graph4)
prensani@13020
   569
   apply simp+
prensani@13020
   570
--{* 6 subgoals left *}
prensani@13020
   571
apply(clarify, simp add:abbrev Graph6 Graph12)
prensani@13020
   572
apply(erule conjE)+
prensani@13020
   573
apply(rule conjI)
prensani@13020
   574
 apply(erule disjE, erule disjI1, rule disjI2, rule allI, (rule impI)+, case_tac "R=i", rule conjI, erule sym)
prensani@13020
   575
  apply(erule Graph4) 
prensani@13020
   576
    apply(simp)+
prensani@13020
   577
   apply (simp add:BtoW_def)
prensani@13020
   578
  apply (simp add:BtoW_def)
prensani@13020
   579
 apply(rule conjI)
prensani@13020
   580
  apply (force simp add:BtoW_def)
prensani@13020
   581
 apply(erule Graph4)
prensani@13020
   582
    apply simp+
prensani@13020
   583
apply(simp add:BtoW_def nth_list_update) 
prensani@13020
   584
apply force
prensani@13020
   585
--{* 5 subgoals left *}
prensani@13020
   586
apply(clarify, simp add:abbrev Graph6 Graph12)
prensani@13020
   587
--{* 4 subgoals left *}
prensani@13020
   588
apply(clarify, simp add:abbrev Graph6 Graph12)
prensani@13020
   589
apply(rule conjI)
prensani@13020
   590
 apply(erule disjE, erule disjI1, rule disjI2, rule allI, (rule impI)+, case_tac "R=i", rule conjI, erule sym)
prensani@13020
   591
  apply(erule Graph4) 
prensani@13020
   592
    apply(simp)+
prensani@13020
   593
   apply (simp add:BtoW_def)
prensani@13020
   594
  apply (simp add:BtoW_def)
prensani@13020
   595
 apply(rule conjI)
prensani@13020
   596
  apply (force simp add:BtoW_def)
prensani@13020
   597
 apply(erule Graph4)
prensani@13020
   598
    apply simp+
prensani@13020
   599
apply(rule conjI)
prensani@13020
   600
 apply(simp add:nth_list_update)
prensani@13020
   601
 apply force
prensani@13020
   602
apply(rule impI, rule impI, erule disjE, erule disjI1, case_tac "R = (ind x)" ,case_tac "M x ! T = Black")
prensani@13020
   603
  apply(force simp add:BtoW_def)
prensani@13020
   604
 apply(case_tac "M x !snd (E x ! ind x)=Black")
prensani@13020
   605
  apply(rule disjI2)
prensani@13020
   606
  apply simp
prensani@13020
   607
  apply (erule Graph5)
prensani@13020
   608
  apply simp+
prensani@13020
   609
 apply(force simp add:BtoW_def)
prensani@13020
   610
apply(force simp add:BtoW_def)
prensani@13020
   611
--{* 3 subgoals left *}
prensani@13020
   612
apply(clarify, simp add:abbrev Graph6 Graph12)
prensani@13020
   613
--{* 2 subgoals left *}
prensani@13020
   614
apply(clarify, simp add:abbrev Graph6 Graph12)
prensani@13020
   615
apply(erule disjE, erule disjI1, rule disjI2, rule allI, (rule impI)+, case_tac "R=i", rule conjI, erule sym)
prensani@13020
   616
 apply clarify
prensani@13020
   617
 apply(erule Graph4) 
prensani@13020
   618
   apply(simp)+
prensani@13020
   619
  apply (simp add:BtoW_def)
prensani@13020
   620
 apply (simp add:BtoW_def)
prensani@13020
   621
apply(rule conjI)
prensani@13020
   622
 apply (force simp add:BtoW_def)
prensani@13020
   623
apply(erule Graph4)
prensani@13020
   624
   apply simp+
prensani@13020
   625
done
prensani@13020
   626
prensani@13020
   627
lemma interfree_Redirect_Edge_Propagate_Black: 
prensani@13020
   628
  "interfree_aux (Some Redirect_Edge, {}, Some Propagate_Black)"
prensani@13020
   629
apply (unfold modules )
prensani@13020
   630
apply interfree_aux
prensani@13020
   631
apply(clarify, simp add:abbrev)+
prensani@13020
   632
done
prensani@13020
   633
prensani@13020
   634
lemma interfree_Propagate_Black_Color_Target: 
prensani@13020
   635
  "interfree_aux (Some Propagate_Black, {}, Some Color_Target)"
prensani@13020
   636
apply (unfold modules )
prensani@13020
   637
apply interfree_aux
prensani@13020
   638
--{* 11 subgoals left *}
prensani@13020
   639
apply(clarify, simp add:abbrev Graph7 Graph8 Graph12)+
prensani@13020
   640
apply(erule conjE)+
prensani@13020
   641
apply(erule disjE,rule disjI1,erule psubset_subset_trans,erule Graph9, 
prensani@13020
   642
      case_tac "M x!T=Black", rule disjI2,rotate_tac -1, simp add: Graph10, clarify,
prensani@13020
   643
      erule allE, erule impE, assumption, erule impE, assumption, 
prensani@13020
   644
      simp add:BtoW_def, rule disjI1, erule subset_psubset_trans, erule Graph11, force) 
prensani@13020
   645
--{* 7 subgoals left *}
prensani@13020
   646
apply(clarify, simp add:abbrev Graph7 Graph8 Graph12)
prensani@13020
   647
apply(erule conjE)+
prensani@13020
   648
apply(erule disjE,rule disjI1,erule psubset_subset_trans,erule Graph9, 
prensani@13020
   649
      case_tac "M x!T=Black", rule disjI2,rotate_tac -1, simp add: Graph10, clarify,
prensani@13020
   650
      erule allE, erule impE, assumption, erule impE, assumption, 
prensani@13020
   651
      simp add:BtoW_def, rule disjI1, erule subset_psubset_trans, erule Graph11, force) 
prensani@13020
   652
--{* 6 subgoals left *}
prensani@13020
   653
apply(clarify, simp add:abbrev Graph7 Graph8 Graph12)
prensani@13020
   654
apply clarify
prensani@13020
   655
apply (rule conjI)
prensani@13020
   656
 apply(erule disjE,rule disjI1,erule psubset_subset_trans,erule Graph9, 
prensani@13020
   657
      case_tac "M x!T=Black", rule disjI2,rotate_tac -1, simp add: Graph10, clarify,
prensani@13020
   658
      erule allE, erule impE, assumption, erule impE, assumption, 
prensani@13020
   659
      simp add:BtoW_def, rule disjI1, erule subset_psubset_trans, erule Graph11, force) 
prensani@13020
   660
apply(simp add:nth_list_update)
prensani@13020
   661
--{* 5 subgoals left *}
prensani@13020
   662
apply(clarify, simp add:abbrev Graph7 Graph8 Graph12)
prensani@13020
   663
--{* 4 subgoals left *}
prensani@13020
   664
apply(clarify, simp add:abbrev Graph7 Graph8 Graph12)
prensani@13020
   665
apply (rule conjI)
prensani@13020
   666
 apply(erule disjE,rule disjI1,erule psubset_subset_trans,erule Graph9, 
prensani@13020
   667
      case_tac "M x!T=Black", rule disjI2,rotate_tac -1, simp add: Graph10, clarify,
prensani@13020
   668
      erule allE, erule impE, assumption, erule impE, assumption, 
prensani@13020
   669
      simp add:BtoW_def, rule disjI1, erule subset_psubset_trans, erule Graph11, force) 
prensani@13020
   670
apply(rule conjI)
prensani@13020
   671
apply(simp add:nth_list_update)
prensani@13020
   672
apply(rule impI,rule impI, case_tac "M x!T=Black",rotate_tac -1, force simp add: BtoW_def Graph10, 
prensani@13020
   673
      erule subset_psubset_trans, erule Graph11, force)
prensani@13020
   674
--{* 3 subgoals left *}
prensani@13020
   675
apply(clarify, simp add:abbrev Graph7 Graph8 Graph12)
prensani@13020
   676
--{* 2 subgoals left *}
prensani@13020
   677
apply(clarify, simp add:abbrev Graph7 Graph8 Graph12)
prensani@13020
   678
apply(erule disjE,rule disjI1,erule psubset_subset_trans,erule Graph9, 
prensani@13020
   679
      case_tac "M x!T=Black", rule disjI2,rotate_tac -1, simp add: Graph10, clarify,
prensani@13020
   680
      erule allE, erule impE, assumption, erule impE, assumption, 
prensani@13020
   681
      simp add:BtoW_def, rule disjI1, erule subset_psubset_trans, erule Graph11, force) 
prensani@13020
   682
--{* 3 subgoals left *}
prensani@13020
   683
apply(simp add:abbrev)
prensani@13020
   684
done
prensani@13020
   685
prensani@13020
   686
lemma interfree_Color_Target_Propagate_Black: 
prensani@13020
   687
  "interfree_aux (Some Color_Target, {}, Some Propagate_Black)"
prensani@13020
   688
apply (unfold modules )
prensani@13020
   689
apply interfree_aux
prensani@13020
   690
apply(clarify, simp add:abbrev)+
prensani@13020
   691
done
prensani@13020
   692
prensani@13020
   693
lemma interfree_Count_Redirect_Edge: 
prensani@13020
   694
  "interfree_aux (Some Count, {}, Some Redirect_Edge)"
prensani@13020
   695
apply (unfold modules)
prensani@13020
   696
apply interfree_aux
prensani@13020
   697
--{* 9 subgoals left *}
prensani@13020
   698
apply(simp_all add:abbrev Graph6 Graph12)
prensani@13020
   699
--{* 6 subgoals left *}
prensani@13020
   700
apply(clarify, simp add:abbrev Graph6 Graph12,
prensani@13020
   701
      erule disjE,erule disjI1,rule disjI2,rule subset_trans, erule Graph3,force,force)+
prensani@13020
   702
done
prensani@13020
   703
prensani@13020
   704
lemma interfree_Redirect_Edge_Count: 
prensani@13020
   705
  "interfree_aux (Some Redirect_Edge, {}, Some Count)"
prensani@13020
   706
apply (unfold modules )
prensani@13020
   707
apply interfree_aux
prensani@13020
   708
apply(clarify,simp add:abbrev)+
prensani@13020
   709
apply(simp add:abbrev)
prensani@13020
   710
done
prensani@13020
   711
prensani@13020
   712
lemma interfree_Count_Color_Target: 
prensani@13020
   713
  "interfree_aux (Some Count, {}, Some Color_Target)"
prensani@13020
   714
apply (unfold modules )
prensani@13020
   715
apply interfree_aux
prensani@13020
   716
--{* 9 subgoals left *}
prensani@13020
   717
apply(simp_all add:abbrev Graph7 Graph8 Graph12)
prensani@13020
   718
--{* 6 subgoals left *}
prensani@13020
   719
apply(clarify,simp add:abbrev Graph7 Graph8 Graph12,
prensani@13020
   720
      erule disjE, erule disjI1, rule disjI2,erule subset_trans, erule Graph9)+
prensani@13020
   721
--{* 2 subgoals left *}
prensani@13020
   722
apply(clarify, simp add:abbrev Graph7 Graph8 Graph12)
prensani@13020
   723
apply(rule conjI)
prensani@13020
   724
 apply(erule disjE, erule disjI1, rule disjI2,erule subset_trans, erule Graph9) 
prensani@13020
   725
apply(simp add:nth_list_update)
prensani@13022
   726
--{* 1 subgoal left *}
prensani@13020
   727
apply(clarify, simp add:abbrev Graph7 Graph8 Graph12,
prensani@13020
   728
      erule disjE, erule disjI1, rule disjI2,erule subset_trans, erule Graph9)
prensani@13020
   729
done
prensani@13020
   730
prensani@13020
   731
lemma interfree_Color_Target_Count: 
prensani@13020
   732
  "interfree_aux (Some Color_Target, {}, Some Count)"
prensani@13020
   733
apply (unfold modules )
prensani@13020
   734
apply interfree_aux
prensani@13020
   735
apply(clarify, simp add:abbrev)+
prensani@13020
   736
apply(simp add:abbrev)
prensani@13020
   737
done
prensani@13020
   738
prensani@13020
   739
lemma interfree_Append_Redirect_Edge: 
prensani@13020
   740
  "interfree_aux (Some Append, {}, Some Redirect_Edge)"
prensani@13020
   741
apply (unfold modules )
prensani@13020
   742
apply interfree_aux
prensani@13020
   743
apply( simp_all add:abbrev Graph6 Append_to_free0 Append_to_free1 Graph12)
prensani@13020
   744
apply(clarify, simp add:abbrev Graph6 Append_to_free0 Append_to_free1 Graph12, force dest:Graph3)+
prensani@13020
   745
done
prensani@13020
   746
prensani@13020
   747
lemma interfree_Redirect_Edge_Append: 
prensani@13020
   748
  "interfree_aux (Some Redirect_Edge, {}, Some Append)"
prensani@13020
   749
apply (unfold modules )
prensani@13020
   750
apply interfree_aux
prensani@13020
   751
apply(clarify, simp add:abbrev Append_to_free0)+
prensani@13020
   752
apply (force simp add: Append_to_free2)
prensani@13020
   753
apply(clarify, simp add:abbrev Append_to_free0)+
prensani@13020
   754
done
prensani@13020
   755
prensani@13020
   756
lemma interfree_Append_Color_Target: 
prensani@13020
   757
  "interfree_aux (Some Append, {}, Some Color_Target)"
prensani@13020
   758
apply (unfold modules )
prensani@13020
   759
apply interfree_aux
prensani@13020
   760
apply(clarify, simp add:abbrev Graph7 Graph8 Append_to_free0 Append_to_free1 Graph12 nth_list_update)+
prensani@13020
   761
apply(simp add:abbrev Graph7 Graph8 Append_to_free0 Append_to_free1 Graph12 nth_list_update)
prensani@13020
   762
done
prensani@13020
   763
prensani@13020
   764
lemma interfree_Color_Target_Append: 
prensani@13020
   765
  "interfree_aux (Some Color_Target, {}, Some Append)"
prensani@13020
   766
apply (unfold modules )
prensani@13020
   767
apply interfree_aux
prensani@13020
   768
apply(clarify, simp add:abbrev Append_to_free0)+
prensani@13020
   769
apply (force simp add: Append_to_free2)
prensani@13020
   770
apply(clarify,simp add:abbrev Append_to_free0)+
prensani@13020
   771
done
prensani@13020
   772
prensani@13020
   773
lemmas collector_mutator_interfree = 
prensani@13020
   774
 interfree_Blacken_Roots_Redirect_Edge interfree_Blacken_Roots_Color_Target 
prensani@13020
   775
 interfree_Propagate_Black_Redirect_Edge interfree_Propagate_Black_Color_Target  
prensani@13020
   776
 interfree_Count_Redirect_Edge interfree_Count_Color_Target 
prensani@13020
   777
 interfree_Append_Redirect_Edge interfree_Append_Color_Target 
prensani@13020
   778
 interfree_Redirect_Edge_Blacken_Roots interfree_Color_Target_Blacken_Roots 
prensani@13020
   779
 interfree_Redirect_Edge_Propagate_Black interfree_Color_Target_Propagate_Black  
prensani@13020
   780
 interfree_Redirect_Edge_Count interfree_Color_Target_Count 
prensani@13020
   781
 interfree_Redirect_Edge_Append interfree_Color_Target_Append
prensani@13020
   782
prensani@13020
   783
subsubsection {* Interference freedom Collector-Mutator *}
prensani@13020
   784
prensani@13020
   785
lemma interfree_Collector_Mutator:
prensani@13020
   786
 "interfree_aux (Some Collector, {}, Some Mutator)"
prensani@13020
   787
apply(unfold Collector_def Mutator_def)
prensani@13020
   788
apply interfree_aux
prensani@13020
   789
apply(simp_all add:collector_mutator_interfree)
prensani@13020
   790
apply(unfold modules collector_defs mutator_defs)
prensani@13020
   791
apply(tactic  {* TRYALL (interfree_aux_tac) *})
prensani@13020
   792
--{* 32 subgoals left *}
prensani@13020
   793
apply(simp_all add:Graph6 Graph7 Graph8 Append_to_free0 Append_to_free1 Graph12)
prensani@13020
   794
--{* 20 subgoals left *}
wenzelm@23894
   795
apply(tactic{* TRYALL (clarify_tac @{claset}) *})
prensani@13020
   796
apply(simp_all add:Graph6 Graph7 Graph8 Append_to_free0 Append_to_free1 Graph12)
prensani@13020
   797
apply(tactic {* TRYALL (etac disjE) *})
prensani@13020
   798
apply simp_all
wenzelm@20050
   799
apply(tactic {* TRYALL(EVERY'[rtac disjI2,rtac subset_trans,etac (thm "Graph3"),force_tac (clasimpset ()), assume_tac]) *})
wenzelm@20050
   800
apply(tactic {* TRYALL(EVERY'[rtac disjI2,etac subset_trans,rtac (thm "Graph9"),force_tac (clasimpset ())]) *})
wenzelm@21669
   801
apply(tactic {* TRYALL(EVERY'[rtac disjI1,etac (thm "psubset_subset_trans"),rtac (thm "Graph9"),force_tac (clasimpset ())]) *})
prensani@13020
   802
done
prensani@13020
   803
prensani@13020
   804
subsubsection {* Interference freedom Mutator-Collector *}
prensani@13020
   805
prensani@13020
   806
lemma interfree_Mutator_Collector:
prensani@13020
   807
 "interfree_aux (Some Mutator, {}, Some Collector)"
prensani@13020
   808
apply(unfold Collector_def Mutator_def)
prensani@13020
   809
apply interfree_aux
prensani@13020
   810
apply(simp_all add:collector_mutator_interfree)
prensani@13020
   811
apply(unfold modules collector_defs mutator_defs)
prensani@13020
   812
apply(tactic  {* TRYALL (interfree_aux_tac) *})
prensani@13020
   813
--{* 64 subgoals left *}
prensani@13020
   814
apply(simp_all add:nth_list_update Invariants Append_to_free0)+
wenzelm@23894
   815
apply(tactic{* TRYALL (clarify_tac @{claset}) *})
prensani@13020
   816
--{* 4 subgoals left *}
prensani@13020
   817
apply force
prensani@13020
   818
apply(simp add:Append_to_free2)
prensani@13020
   819
apply force
prensani@13020
   820
apply(simp add:Append_to_free2)
prensani@13020
   821
done
prensani@13020
   822
prensani@13020
   823
subsubsection {* The Garbage Collection algorithm *}
prensani@13020
   824
prensani@13020
   825
text {* In total there are 289 verification conditions.  *}
prensani@13020
   826
prensani@13020
   827
lemma Gar_Coll: 
prensani@13020
   828
  "\<parallel>- .{\<acute>Proper \<and> \<acute>Mut_init \<and> \<acute>z}.  
prensani@13020
   829
  COBEGIN  
prensani@13020
   830
   Collector
prensani@13020
   831
  .{False}.
prensani@13020
   832
 \<parallel>  
prensani@13020
   833
   Mutator
prensani@13020
   834
  .{False}. 
prensani@13020
   835
 COEND 
prensani@13020
   836
  .{False}."
prensani@13020
   837
apply oghoare
prensani@13020
   838
apply(force simp add: Mutator_def Collector_def modules)
prensani@13020
   839
apply(rule Collector)
prensani@13020
   840
apply(rule Mutator)
prensani@13020
   841
apply(simp add:interfree_Collector_Mutator)
prensani@13020
   842
apply(simp add:interfree_Mutator_Collector)
prensani@13020
   843
apply force
prensani@13020
   844
done
prensani@13020
   845
prensani@13020
   846
end