src/HOL/MicroJava/J/Conform.thy
author nipkow
Thu Feb 14 12:06:07 2002 +0100 (2002-02-14)
changeset 12888 f6c1e7306c40
parent 12517 360e3215f029
child 12911 704713ca07ea
permissions -rw-r--r--
nodups -> distinct
nipkow@8011
     1
(*  Title:      HOL/MicroJava/J/Conform.thy
nipkow@8011
     2
    ID:         $Id$
nipkow@8011
     3
    Author:     David von Oheimb
nipkow@8011
     4
    Copyright   1999 Technische Universitaet Muenchen
oheimb@11070
     5
*)
nipkow@8011
     6
oheimb@11070
     7
header "Conformity Relations for Type Soundness Proof"
nipkow@8011
     8
oheimb@11026
     9
theory Conform = State + WellType:
oheimb@9346
    10
kleing@12517
    11
types 'c env_ = "'c prog \<times> (vname \<leadsto> ty)"  -- "same as @{text env} of @{text WellType.thy}"
nipkow@8011
    12
nipkow@8011
    13
constdefs
nipkow@8011
    14
oheimb@11372
    15
  hext :: "aheap => aheap => bool" ("_ <=| _" [51,51] 50)
oheimb@11372
    16
 "h<=|h' == \<forall>a C fs. h a = Some(C,fs) --> (\<exists>fs'. h' a = Some(C,fs'))"
nipkow@8011
    17
kleing@12517
    18
  conf :: "'c prog => aheap => val => ty => bool" 
oheimb@11372
    19
                                   ("_,_ |- _ ::<= _"  [51,51,51,51] 50)
oheimb@11372
    20
 "G,h|-v::<=T == \<exists>T'. typeof (option_map obj_ty o h) v = Some T' \<and> G\<turnstile>T'\<preceq>T"
nipkow@8011
    21
oheimb@11026
    22
  lconf :: "'c prog => aheap => ('a \<leadsto> val) => ('a \<leadsto> ty) => bool"
oheimb@11372
    23
                                   ("_,_ |- _ [::<=] _" [51,51,51,51] 50)
oheimb@11372
    24
 "G,h|-vs[::<=]Ts == \<forall>n T. Ts n = Some T --> (\<exists>v. vs n = Some v \<and> G,h|-v::<=T)"
nipkow@8011
    25
oheimb@11372
    26
  oconf :: "'c prog => aheap => obj => bool" ("_,_ |- _ [ok]" [51,51,51] 50)
oheimb@11372
    27
 "G,h|-obj [ok] == G,h|-snd obj[::<=]map_of (fields (G,fst obj))"
nipkow@8011
    28
oheimb@11372
    29
  hconf :: "'c prog => aheap => bool" ("_ |-h _ [ok]" [51,51] 50)
oheimb@11372
    30
 "G|-h h [ok]    == \<forall>a obj. h a = Some obj --> G,h|-obj [ok]"
nipkow@8011
    31
kleing@12517
    32
  conforms :: "state => java_mb env_ => bool" ("_ ::<= _" [51,51] 50)
oheimb@11372
    33
 "s::<=E == prg E|-h heap s [ok] \<and> prg E,heap s|-locals s[::<=]localT E"
nipkow@8011
    34
kleing@10061
    35
oheimb@11372
    36
syntax (xsymbols)
kleing@10061
    37
  hext     :: "aheap => aheap => bool"
oheimb@11372
    38
              ("_ \<le>| _" [51,51] 50)
kleing@10061
    39
kleing@10061
    40
  conf     :: "'c prog => aheap => val => ty => bool"
oheimb@11372
    41
              ("_,_ \<turnstile> _ ::\<preceq> _" [51,51,51,51] 50)
kleing@10061
    42
oheimb@11026
    43
  lconf    :: "'c prog => aheap => ('a \<leadsto> val) => ('a \<leadsto> ty) => bool"
oheimb@11372
    44
              ("_,_ \<turnstile> _ [::\<preceq>] _" [51,51,51,51] 50)
kleing@10061
    45
kleing@10061
    46
  oconf    :: "'c prog => aheap => obj => bool"
oheimb@11372
    47
              ("_,_ \<turnstile> _ \<surd>" [51,51,51] 50)
kleing@10061
    48
kleing@10061
    49
  hconf    :: "'c prog => aheap => bool"
oheimb@11372
    50
              ("_ \<turnstile>h _ \<surd>" [51,51] 50)
kleing@10061
    51
kleing@10061
    52
  conforms :: "state => java_mb env_ => bool"
oheimb@11372
    53
              ("_ ::\<preceq> _" [51,51] 50)
kleing@10061
    54
oheimb@11026
    55
oheimb@11026
    56
section "hext"
oheimb@11026
    57
oheimb@11026
    58
lemma hextI: 
oheimb@11026
    59
" \<forall>a C fs . h  a = Some (C,fs) -->   
oheimb@11026
    60
      (\<exists>fs'. h' a = Some (C,fs')) ==> h\<le>|h'"
oheimb@11026
    61
apply (unfold hext_def)
oheimb@11026
    62
apply auto
oheimb@11026
    63
done
oheimb@11026
    64
oheimb@11026
    65
lemma hext_objD: "[|h\<le>|h'; h a = Some (C,fs) |] ==> \<exists>fs'. h' a = Some (C,fs')"
oheimb@11026
    66
apply (unfold hext_def)
oheimb@11026
    67
apply (force)
oheimb@11026
    68
done
oheimb@11026
    69
oheimb@11026
    70
lemma hext_refl [simp]: "h\<le>|h"
oheimb@11026
    71
apply (rule hextI)
oheimb@11026
    72
apply (fast)
oheimb@11026
    73
done
oheimb@11026
    74
oheimb@11026
    75
lemma hext_new [simp]: "h a = None ==> h\<le>|h(a\<mapsto>x)"
oheimb@11026
    76
apply (rule hextI)
oheimb@11026
    77
apply auto
oheimb@11026
    78
done
oheimb@11026
    79
oheimb@11026
    80
lemma hext_trans: "[|h\<le>|h'; h'\<le>|h''|] ==> h\<le>|h''"
oheimb@11026
    81
apply (rule hextI)
oheimb@11026
    82
apply (fast dest: hext_objD)
oheimb@11026
    83
done
oheimb@11026
    84
oheimb@11026
    85
lemma hext_upd_obj: "h a = Some (C,fs) ==> h\<le>|h(a\<mapsto>(C,fs'))"
oheimb@11026
    86
apply (rule hextI)
oheimb@11026
    87
apply auto
oheimb@11026
    88
done
oheimb@11026
    89
oheimb@11026
    90
oheimb@11026
    91
section "conf"
oheimb@11026
    92
oheimb@11026
    93
lemma conf_Null [simp]: "G,h\<turnstile>Null::\<preceq>T = G\<turnstile>RefT NullT\<preceq>T"
oheimb@11026
    94
apply (unfold conf_def)
oheimb@11026
    95
apply (simp (no_asm))
oheimb@11026
    96
done
oheimb@11026
    97
oheimb@11026
    98
lemma conf_litval [rule_format (no_asm), simp]: 
oheimb@11026
    99
  "typeof (\<lambda>v. None) v = Some T --> G,h\<turnstile>v::\<preceq>T"
oheimb@11026
   100
apply (unfold conf_def)
oheimb@11026
   101
apply (rule val.induct)
oheimb@11026
   102
apply auto
oheimb@11026
   103
done
oheimb@11026
   104
oheimb@11026
   105
lemma conf_AddrI: "[|h a = Some obj; G\<turnstile>obj_ty obj\<preceq>T|] ==> G,h\<turnstile>Addr a::\<preceq>T"
oheimb@11026
   106
apply (unfold conf_def)
oheimb@11026
   107
apply (simp)
oheimb@11026
   108
done
oheimb@11026
   109
oheimb@11026
   110
lemma conf_obj_AddrI: "[|h a = Some (C,fs); G\<turnstile>C\<preceq>C D|] ==> G,h\<turnstile>Addr a::\<preceq> Class D"
oheimb@11026
   111
apply (unfold conf_def)
oheimb@11026
   112
apply (simp)
oheimb@11026
   113
done
oheimb@11026
   114
kleing@12517
   115
lemma defval_conf [rule_format (no_asm)]: 
kleing@12517
   116
  "is_type G T --> G,h\<turnstile>default_val T::\<preceq>T"
oheimb@11026
   117
apply (unfold conf_def)
oheimb@11026
   118
apply (rule_tac "y" = "T" in ty.exhaust)
oheimb@11026
   119
apply  (erule ssubst)
oheimb@11026
   120
apply  (rule_tac "y" = "prim_ty" in prim_ty.exhaust)
oheimb@11026
   121
apply    (auto simp add: widen.null)
oheimb@11026
   122
done
oheimb@11026
   123
oheimb@11026
   124
lemma conf_upd_obj: 
oheimb@11026
   125
"h a = Some (C,fs) ==> (G,h(a\<mapsto>(C,fs'))\<turnstile>x::\<preceq>T) = (G,h\<turnstile>x::\<preceq>T)"
oheimb@11026
   126
apply (unfold conf_def)
oheimb@11026
   127
apply (rule val.induct)
oheimb@11026
   128
apply auto
oheimb@11026
   129
done
oheimb@11026
   130
kleing@12517
   131
lemma conf_widen [rule_format (no_asm)]: 
kleing@12517
   132
  "wf_prog wf_mb G ==> G,h\<turnstile>x::\<preceq>T --> G\<turnstile>T\<preceq>T' --> G,h\<turnstile>x::\<preceq>T'"
oheimb@11026
   133
apply (unfold conf_def)
oheimb@11026
   134
apply (rule val.induct)
oheimb@11026
   135
apply (auto intro: widen_trans)
oheimb@11026
   136
done
oheimb@11026
   137
oheimb@11026
   138
lemma conf_hext [rule_format (no_asm)]: "h\<le>|h' ==> G,h\<turnstile>v::\<preceq>T --> G,h'\<turnstile>v::\<preceq>T"
oheimb@11026
   139
apply (unfold conf_def)
oheimb@11026
   140
apply (rule val.induct)
oheimb@11026
   141
apply (auto dest: hext_objD)
oheimb@11026
   142
done
oheimb@11026
   143
oheimb@11026
   144
lemma new_locD: "[|h a = None; G,h\<turnstile>Addr t::\<preceq>T|] ==> t\<noteq>a"
oheimb@11026
   145
apply (unfold conf_def)
oheimb@11026
   146
apply auto
oheimb@11026
   147
done
oheimb@11026
   148
oheimb@11026
   149
lemma conf_RefTD [rule_format (no_asm)]: 
oheimb@11026
   150
 "G,h\<turnstile>a'::\<preceq>RefT T --> a' = Null |   
oheimb@11026
   151
  (\<exists>a obj T'. a' = Addr a \<and>  h a = Some obj \<and>  obj_ty obj = T' \<and>  G\<turnstile>T'\<preceq>RefT T)"
oheimb@11026
   152
apply (unfold conf_def)
oheimb@11026
   153
apply(induct_tac "a'")
oheimb@11026
   154
apply(auto)
oheimb@11026
   155
done
oheimb@11026
   156
oheimb@11026
   157
lemma conf_NullTD: "G,h\<turnstile>a'::\<preceq>RefT NullT ==> a' = Null"
oheimb@11026
   158
apply (drule conf_RefTD)
oheimb@11026
   159
apply auto
oheimb@11026
   160
done
oheimb@11026
   161
oheimb@11026
   162
lemma non_npD: "[|a' \<noteq> Null; G,h\<turnstile>a'::\<preceq>RefT t|] ==>  
oheimb@11026
   163
  \<exists>a C fs. a' = Addr a \<and>  h a = Some (C,fs) \<and>  G\<turnstile>Class C\<preceq>RefT t"
oheimb@11026
   164
apply (drule conf_RefTD)
oheimb@11026
   165
apply auto
oheimb@11026
   166
done
oheimb@11026
   167
oheimb@11026
   168
lemma non_np_objD: "!!G. [|a' \<noteq> Null; G,h\<turnstile>a'::\<preceq> Class C; C \<noteq> Object|] ==>  
oheimb@11026
   169
  (\<exists>a C' fs. a' = Addr a \<and>  h a = Some (C',fs) \<and>  G\<turnstile>C'\<preceq>C C)"
oheimb@11026
   170
apply (fast dest: non_npD)
oheimb@11026
   171
done
oheimb@11026
   172
kleing@12517
   173
lemma non_np_objD' [rule_format (no_asm)]: 
kleing@12517
   174
  "a' \<noteq> Null ==> wf_prog wf_mb G ==> G,h\<turnstile>a'::\<preceq>RefT t --> 
oheimb@11026
   175
  (\<forall>C. t = ClassT C --> C \<noteq> Object) -->  
oheimb@11026
   176
  (\<exists>a C fs. a' = Addr a \<and>  h a = Some (C,fs) \<and>  G\<turnstile>Class C\<preceq>RefT t)"
oheimb@11026
   177
apply(rule_tac "y" = "t" in ref_ty.exhaust)
oheimb@11026
   178
 apply (fast dest: conf_NullTD)
oheimb@11026
   179
apply (fast dest: non_np_objD)
oheimb@11026
   180
done
oheimb@11026
   181
kleing@12517
   182
lemma conf_list_gext_widen [rule_format (no_asm)]: 
kleing@12517
   183
  "wf_prog wf_mb G ==> \<forall>Ts Ts'. list_all2 (conf G h) vs Ts --> 
kleing@12517
   184
  list_all2 (\<lambda>T T'. G\<turnstile>T\<preceq>T') Ts Ts' -->  list_all2 (conf G h) vs Ts'"
oheimb@11026
   185
apply(induct_tac "vs")
oheimb@11026
   186
 apply(clarsimp)
oheimb@11026
   187
apply(clarsimp)
oheimb@11026
   188
apply(frule list_all2_lengthD [THEN sym])
oheimb@11026
   189
apply(simp (no_asm_use) add: length_Suc_conv)
oheimb@11026
   190
apply(safe)
oheimb@11026
   191
apply(frule list_all2_lengthD [THEN sym])
oheimb@11026
   192
apply(simp (no_asm_use) add: length_Suc_conv)
oheimb@11026
   193
apply(clarify)
oheimb@11026
   194
apply(fast elim: conf_widen)
oheimb@11026
   195
done
oheimb@11026
   196
oheimb@11026
   197
oheimb@11026
   198
section "lconf"
oheimb@11026
   199
oheimb@11026
   200
lemma lconfD: "[| G,h\<turnstile>vs[::\<preceq>]Ts; Ts n = Some T |] ==> G,h\<turnstile>(the (vs n))::\<preceq>T"
oheimb@11026
   201
apply (unfold lconf_def)
oheimb@11026
   202
apply (force)
oheimb@11026
   203
done
oheimb@11026
   204
oheimb@11026
   205
lemma lconf_hext [elim]: "[| G,h\<turnstile>l[::\<preceq>]L; h\<le>|h' |] ==> G,h'\<turnstile>l[::\<preceq>]L"
oheimb@11026
   206
apply (unfold lconf_def)
oheimb@11026
   207
apply  (fast elim: conf_hext)
oheimb@11026
   208
done
oheimb@11026
   209
oheimb@11026
   210
lemma lconf_upd: "!!X. [| G,h\<turnstile>l[::\<preceq>]lT;  
oheimb@11026
   211
  G,h\<turnstile>v::\<preceq>T; lT va = Some T |] ==> G,h\<turnstile>l(va\<mapsto>v)[::\<preceq>]lT"
oheimb@11026
   212
apply (unfold lconf_def)
oheimb@11026
   213
apply auto
oheimb@11026
   214
done
oheimb@11026
   215
kleing@12517
   216
lemma lconf_init_vars_lemma [rule_format (no_asm)]: 
kleing@12517
   217
  "\<forall>x. P x --> R (dv x) x ==> (\<forall>x. map_of fs f = Some x --> P x) -->  
oheimb@11026
   218
  (\<forall>T. map_of fs f = Some T -->  
oheimb@11026
   219
  (\<exists>v. map_of (map (\<lambda>(f,ft). (f, dv ft)) fs) f = Some v \<and>  R v T))"
oheimb@11026
   220
apply( induct_tac "fs")
oheimb@11026
   221
apply auto
oheimb@11026
   222
done
oheimb@11026
   223
oheimb@11026
   224
lemma lconf_init_vars [intro!]: 
oheimb@11026
   225
"\<forall>n. \<forall>T. map_of fs n = Some T --> is_type G T ==> G,h\<turnstile>init_vars fs[::\<preceq>]map_of fs"
oheimb@11026
   226
apply (unfold lconf_def init_vars_def)
oheimb@11026
   227
apply auto
oheimb@11026
   228
apply( rule lconf_init_vars_lemma)
oheimb@11026
   229
apply(   erule_tac [3] asm_rl)
oheimb@11026
   230
apply(  intro strip)
oheimb@11026
   231
apply(  erule defval_conf)
oheimb@11026
   232
apply auto
oheimb@11026
   233
done
oheimb@11026
   234
oheimb@11026
   235
lemma lconf_ext: "[|G,s\<turnstile>l[::\<preceq>]L; G,s\<turnstile>v::\<preceq>T|] ==> G,s\<turnstile>l(vn\<mapsto>v)[::\<preceq>]L(vn\<mapsto>T)"
oheimb@11026
   236
apply (unfold lconf_def)
oheimb@11026
   237
apply auto
oheimb@11026
   238
done
oheimb@11026
   239
kleing@12517
   240
lemma lconf_ext_list [rule_format (no_asm)]: 
nipkow@12888
   241
  "G,h\<turnstile>l[::\<preceq>]L ==> \<forall>vs Ts. distinct vns --> length Ts = length vns --> 
kleing@12517
   242
  list_all2 (\<lambda>v T. G,h\<turnstile>v::\<preceq>T) vs Ts --> G,h\<turnstile>l(vns[\<mapsto>]vs)[::\<preceq>]L(vns[\<mapsto>]Ts)"
oheimb@11026
   243
apply (unfold lconf_def)
oheimb@11026
   244
apply( induct_tac "vns")
oheimb@11026
   245
apply(  clarsimp)
oheimb@11026
   246
apply( clarsimp)
oheimb@11026
   247
apply( frule list_all2_lengthD)
oheimb@11026
   248
apply( auto simp add: length_Suc_conv)
oheimb@11026
   249
done
oheimb@11026
   250
oheimb@11026
   251
oheimb@11026
   252
section "oconf"
oheimb@11026
   253
oheimb@11026
   254
lemma oconf_hext: "G,h\<turnstile>obj\<surd> ==> h\<le>|h' ==> G,h'\<turnstile>obj\<surd>"
oheimb@11026
   255
apply (unfold oconf_def)
oheimb@11026
   256
apply (fast)
oheimb@11026
   257
done
oheimb@11026
   258
oheimb@11026
   259
lemma oconf_obj: "G,h\<turnstile>(C,fs)\<surd> =  
oheimb@11026
   260
  (\<forall>T f. map_of(fields (G,C)) f = Some T --> (\<exists>v. fs f = Some v \<and>  G,h\<turnstile>v::\<preceq>T))"
oheimb@11026
   261
apply (unfold oconf_def lconf_def)
oheimb@11026
   262
apply auto
oheimb@11026
   263
done
oheimb@11026
   264
oheimb@11026
   265
lemmas oconf_objD = oconf_obj [THEN iffD1, THEN spec, THEN spec, THEN mp]
oheimb@11026
   266
oheimb@11026
   267
oheimb@11026
   268
section "hconf"
oheimb@11026
   269
oheimb@11026
   270
lemma hconfD: "[|G\<turnstile>h h\<surd>; h a = Some obj|] ==> G,h\<turnstile>obj\<surd>"
oheimb@11026
   271
apply (unfold hconf_def)
oheimb@11026
   272
apply (fast)
oheimb@11026
   273
done
oheimb@11026
   274
oheimb@11026
   275
lemma hconfI: "\<forall>a obj. h a=Some obj --> G,h\<turnstile>obj\<surd> ==> G\<turnstile>h h\<surd>"
oheimb@11026
   276
apply (unfold hconf_def)
oheimb@11026
   277
apply (fast)
oheimb@11026
   278
done
oheimb@11026
   279
oheimb@11026
   280
oheimb@11026
   281
section "conforms"
oheimb@11026
   282
oheimb@11026
   283
lemma conforms_heapD: "(h, l)::\<preceq>(G, lT) ==> G\<turnstile>h h\<surd>"
oheimb@11026
   284
apply (unfold conforms_def)
oheimb@11026
   285
apply (simp)
oheimb@11026
   286
done
oheimb@11026
   287
oheimb@11026
   288
lemma conforms_localD: "(h, l)::\<preceq>(G, lT) ==> G,h\<turnstile>l[::\<preceq>]lT"
oheimb@11026
   289
apply (unfold conforms_def)
oheimb@11026
   290
apply (simp)
oheimb@11026
   291
done
oheimb@11026
   292
oheimb@11026
   293
lemma conformsI: "[|G\<turnstile>h h\<surd>; G,h\<turnstile>l[::\<preceq>]lT|] ==> (h, l)::\<preceq>(G, lT)"
oheimb@11026
   294
apply (unfold conforms_def)
oheimb@11026
   295
apply auto
oheimb@11026
   296
done
oheimb@11026
   297
oheimb@11026
   298
lemma conforms_hext: "[|(h,l)::\<preceq>(G,lT); h\<le>|h'; G\<turnstile>h h'\<surd> |] ==> (h',l)::\<preceq>(G,lT)"
oheimb@11026
   299
apply( fast dest: conforms_localD elim!: conformsI lconf_hext)
oheimb@11026
   300
done
oheimb@11026
   301
kleing@12517
   302
lemma conforms_upd_obj: 
kleing@12517
   303
  "[|(h,l)::\<preceq>(G, lT); G,h(a\<mapsto>obj)\<turnstile>obj\<surd>; h\<le>|h(a\<mapsto>obj)|] ==> (h(a\<mapsto>obj),l)::\<preceq>(G, lT)"
kleing@12517
   304
apply(rule conforms_hext)
kleing@12517
   305
apply  auto
kleing@12517
   306
apply(rule hconfI)
kleing@12517
   307
apply(drule conforms_heapD)
kleing@12517
   308
apply(tactic {* auto_tac (HOL_cs addEs [thm "oconf_hext"] 
kleing@12517
   309
                addDs [thm "hconfD"], simpset() delsimps [split_paired_All]) *})
oheimb@11026
   310
done
oheimb@11026
   311
oheimb@11026
   312
lemma conforms_upd_local: 
oheimb@11026
   313
"[|(h, l)::\<preceq>(G, lT); G,h\<turnstile>v::\<preceq>T; lT va = Some T|] ==> (h, l(va\<mapsto>v))::\<preceq>(G, lT)"
oheimb@11026
   314
apply (unfold conforms_def)
oheimb@11026
   315
apply( auto elim: lconf_upd)
oheimb@11026
   316
done
oheimb@11026
   317
nipkow@8011
   318
end