src/HOL/Real.thy
changeset 51523 97b5e8a1291c
child 51539 625d2ec0bbff
     1.1 --- /dev/null	Thu Jan 01 00:00:00 1970 +0000
     1.2 +++ b/src/HOL/Real.thy	Tue Mar 26 12:20:56 2013 +0100
     1.3 @@ -0,0 +1,2229 @@
     1.4 +(*  Title:      HOL/Real.thy
     1.5 +    Author:     Jacques D. Fleuriot, University of Edinburgh, 1998
     1.6 +    Author:     Larry Paulson, University of Cambridge
     1.7 +    Author:     Jeremy Avigad, Carnegie Mellon University
     1.8 +    Author:     Florian Zuleger, Johannes Hoelzl, and Simon Funke, TU Muenchen
     1.9 +    Conversion to Isar and new proofs by Lawrence C Paulson, 2003/4
    1.10 +    Construction of Cauchy Reals by Brian Huffman, 2010
    1.11 +*)
    1.12 +
    1.13 +header {* Development of the Reals using Cauchy Sequences *}
    1.14 +
    1.15 +theory Real
    1.16 +imports Rat Conditional_Complete_Lattices
    1.17 +begin
    1.18 +
    1.19 +text {*
    1.20 +  This theory contains a formalization of the real numbers as
    1.21 +  equivalence classes of Cauchy sequences of rationals.  See
    1.22 +  @{file "~~/src/HOL/ex/Dedekind_Real.thy"} for an alternative
    1.23 +  construction using Dedekind cuts.
    1.24 +*}
    1.25 +
    1.26 +subsection {* Preliminary lemmas *}
    1.27 +
    1.28 +lemma add_diff_add:
    1.29 +  fixes a b c d :: "'a::ab_group_add"
    1.30 +  shows "(a + c) - (b + d) = (a - b) + (c - d)"
    1.31 +  by simp
    1.32 +
    1.33 +lemma minus_diff_minus:
    1.34 +  fixes a b :: "'a::ab_group_add"
    1.35 +  shows "- a - - b = - (a - b)"
    1.36 +  by simp
    1.37 +
    1.38 +lemma mult_diff_mult:
    1.39 +  fixes x y a b :: "'a::ring"
    1.40 +  shows "(x * y - a * b) = x * (y - b) + (x - a) * b"
    1.41 +  by (simp add: algebra_simps)
    1.42 +
    1.43 +lemma inverse_diff_inverse:
    1.44 +  fixes a b :: "'a::division_ring"
    1.45 +  assumes "a \<noteq> 0" and "b \<noteq> 0"
    1.46 +  shows "inverse a - inverse b = - (inverse a * (a - b) * inverse b)"
    1.47 +  using assms by (simp add: algebra_simps)
    1.48 +
    1.49 +lemma obtain_pos_sum:
    1.50 +  fixes r :: rat assumes r: "0 < r"
    1.51 +  obtains s t where "0 < s" and "0 < t" and "r = s + t"
    1.52 +proof
    1.53 +    from r show "0 < r/2" by simp
    1.54 +    from r show "0 < r/2" by simp
    1.55 +    show "r = r/2 + r/2" by simp
    1.56 +qed
    1.57 +
    1.58 +subsection {* Sequences that converge to zero *}
    1.59 +
    1.60 +definition
    1.61 +  vanishes :: "(nat \<Rightarrow> rat) \<Rightarrow> bool"
    1.62 +where
    1.63 +  "vanishes X = (\<forall>r>0. \<exists>k. \<forall>n\<ge>k. \<bar>X n\<bar> < r)"
    1.64 +
    1.65 +lemma vanishesI: "(\<And>r. 0 < r \<Longrightarrow> \<exists>k. \<forall>n\<ge>k. \<bar>X n\<bar> < r) \<Longrightarrow> vanishes X"
    1.66 +  unfolding vanishes_def by simp
    1.67 +
    1.68 +lemma vanishesD: "\<lbrakk>vanishes X; 0 < r\<rbrakk> \<Longrightarrow> \<exists>k. \<forall>n\<ge>k. \<bar>X n\<bar> < r"
    1.69 +  unfolding vanishes_def by simp
    1.70 +
    1.71 +lemma vanishes_const [simp]: "vanishes (\<lambda>n. c) \<longleftrightarrow> c = 0"
    1.72 +  unfolding vanishes_def
    1.73 +  apply (cases "c = 0", auto)
    1.74 +  apply (rule exI [where x="\<bar>c\<bar>"], auto)
    1.75 +  done
    1.76 +
    1.77 +lemma vanishes_minus: "vanishes X \<Longrightarrow> vanishes (\<lambda>n. - X n)"
    1.78 +  unfolding vanishes_def by simp
    1.79 +
    1.80 +lemma vanishes_add:
    1.81 +  assumes X: "vanishes X" and Y: "vanishes Y"
    1.82 +  shows "vanishes (\<lambda>n. X n + Y n)"
    1.83 +proof (rule vanishesI)
    1.84 +  fix r :: rat assume "0 < r"
    1.85 +  then obtain s t where s: "0 < s" and t: "0 < t" and r: "r = s + t"
    1.86 +    by (rule obtain_pos_sum)
    1.87 +  obtain i where i: "\<forall>n\<ge>i. \<bar>X n\<bar> < s"
    1.88 +    using vanishesD [OF X s] ..
    1.89 +  obtain j where j: "\<forall>n\<ge>j. \<bar>Y n\<bar> < t"
    1.90 +    using vanishesD [OF Y t] ..
    1.91 +  have "\<forall>n\<ge>max i j. \<bar>X n + Y n\<bar> < r"
    1.92 +  proof (clarsimp)
    1.93 +    fix n assume n: "i \<le> n" "j \<le> n"
    1.94 +    have "\<bar>X n + Y n\<bar> \<le> \<bar>X n\<bar> + \<bar>Y n\<bar>" by (rule abs_triangle_ineq)
    1.95 +    also have "\<dots> < s + t" by (simp add: add_strict_mono i j n)
    1.96 +    finally show "\<bar>X n + Y n\<bar> < r" unfolding r .
    1.97 +  qed
    1.98 +  thus "\<exists>k. \<forall>n\<ge>k. \<bar>X n + Y n\<bar> < r" ..
    1.99 +qed
   1.100 +
   1.101 +lemma vanishes_diff:
   1.102 +  assumes X: "vanishes X" and Y: "vanishes Y"
   1.103 +  shows "vanishes (\<lambda>n. X n - Y n)"
   1.104 +unfolding diff_minus by (intro vanishes_add vanishes_minus X Y)
   1.105 +
   1.106 +lemma vanishes_mult_bounded:
   1.107 +  assumes X: "\<exists>a>0. \<forall>n. \<bar>X n\<bar> < a"
   1.108 +  assumes Y: "vanishes (\<lambda>n. Y n)"
   1.109 +  shows "vanishes (\<lambda>n. X n * Y n)"
   1.110 +proof (rule vanishesI)
   1.111 +  fix r :: rat assume r: "0 < r"
   1.112 +  obtain a where a: "0 < a" "\<forall>n. \<bar>X n\<bar> < a"
   1.113 +    using X by fast
   1.114 +  obtain b where b: "0 < b" "r = a * b"
   1.115 +  proof
   1.116 +    show "0 < r / a" using r a by (simp add: divide_pos_pos)
   1.117 +    show "r = a * (r / a)" using a by simp
   1.118 +  qed
   1.119 +  obtain k where k: "\<forall>n\<ge>k. \<bar>Y n\<bar> < b"
   1.120 +    using vanishesD [OF Y b(1)] ..
   1.121 +  have "\<forall>n\<ge>k. \<bar>X n * Y n\<bar> < r"
   1.122 +    by (simp add: b(2) abs_mult mult_strict_mono' a k)
   1.123 +  thus "\<exists>k. \<forall>n\<ge>k. \<bar>X n * Y n\<bar> < r" ..
   1.124 +qed
   1.125 +
   1.126 +subsection {* Cauchy sequences *}
   1.127 +
   1.128 +definition
   1.129 +  cauchy :: "(nat \<Rightarrow> rat) \<Rightarrow> bool"
   1.130 +where
   1.131 +  "cauchy X \<longleftrightarrow> (\<forall>r>0. \<exists>k. \<forall>m\<ge>k. \<forall>n\<ge>k. \<bar>X m - X n\<bar> < r)"
   1.132 +
   1.133 +lemma cauchyI:
   1.134 +  "(\<And>r. 0 < r \<Longrightarrow> \<exists>k. \<forall>m\<ge>k. \<forall>n\<ge>k. \<bar>X m - X n\<bar> < r) \<Longrightarrow> cauchy X"
   1.135 +  unfolding cauchy_def by simp
   1.136 +
   1.137 +lemma cauchyD:
   1.138 +  "\<lbrakk>cauchy X; 0 < r\<rbrakk> \<Longrightarrow> \<exists>k. \<forall>m\<ge>k. \<forall>n\<ge>k. \<bar>X m - X n\<bar> < r"
   1.139 +  unfolding cauchy_def by simp
   1.140 +
   1.141 +lemma cauchy_const [simp]: "cauchy (\<lambda>n. x)"
   1.142 +  unfolding cauchy_def by simp
   1.143 +
   1.144 +lemma cauchy_add [simp]:
   1.145 +  assumes X: "cauchy X" and Y: "cauchy Y"
   1.146 +  shows "cauchy (\<lambda>n. X n + Y n)"
   1.147 +proof (rule cauchyI)
   1.148 +  fix r :: rat assume "0 < r"
   1.149 +  then obtain s t where s: "0 < s" and t: "0 < t" and r: "r = s + t"
   1.150 +    by (rule obtain_pos_sum)
   1.151 +  obtain i where i: "\<forall>m\<ge>i. \<forall>n\<ge>i. \<bar>X m - X n\<bar> < s"
   1.152 +    using cauchyD [OF X s] ..
   1.153 +  obtain j where j: "\<forall>m\<ge>j. \<forall>n\<ge>j. \<bar>Y m - Y n\<bar> < t"
   1.154 +    using cauchyD [OF Y t] ..
   1.155 +  have "\<forall>m\<ge>max i j. \<forall>n\<ge>max i j. \<bar>(X m + Y m) - (X n + Y n)\<bar> < r"
   1.156 +  proof (clarsimp)
   1.157 +    fix m n assume *: "i \<le> m" "j \<le> m" "i \<le> n" "j \<le> n"
   1.158 +    have "\<bar>(X m + Y m) - (X n + Y n)\<bar> \<le> \<bar>X m - X n\<bar> + \<bar>Y m - Y n\<bar>"
   1.159 +      unfolding add_diff_add by (rule abs_triangle_ineq)
   1.160 +    also have "\<dots> < s + t"
   1.161 +      by (rule add_strict_mono, simp_all add: i j *)
   1.162 +    finally show "\<bar>(X m + Y m) - (X n + Y n)\<bar> < r" unfolding r .
   1.163 +  qed
   1.164 +  thus "\<exists>k. \<forall>m\<ge>k. \<forall>n\<ge>k. \<bar>(X m + Y m) - (X n + Y n)\<bar> < r" ..
   1.165 +qed
   1.166 +
   1.167 +lemma cauchy_minus [simp]:
   1.168 +  assumes X: "cauchy X"
   1.169 +  shows "cauchy (\<lambda>n. - X n)"
   1.170 +using assms unfolding cauchy_def
   1.171 +unfolding minus_diff_minus abs_minus_cancel .
   1.172 +
   1.173 +lemma cauchy_diff [simp]:
   1.174 +  assumes X: "cauchy X" and Y: "cauchy Y"
   1.175 +  shows "cauchy (\<lambda>n. X n - Y n)"
   1.176 +using assms unfolding diff_minus by simp
   1.177 +
   1.178 +lemma cauchy_imp_bounded:
   1.179 +  assumes "cauchy X" shows "\<exists>b>0. \<forall>n. \<bar>X n\<bar> < b"
   1.180 +proof -
   1.181 +  obtain k where k: "\<forall>m\<ge>k. \<forall>n\<ge>k. \<bar>X m - X n\<bar> < 1"
   1.182 +    using cauchyD [OF assms zero_less_one] ..
   1.183 +  show "\<exists>b>0. \<forall>n. \<bar>X n\<bar> < b"
   1.184 +  proof (intro exI conjI allI)
   1.185 +    have "0 \<le> \<bar>X 0\<bar>" by simp
   1.186 +    also have "\<bar>X 0\<bar> \<le> Max (abs ` X ` {..k})" by simp
   1.187 +    finally have "0 \<le> Max (abs ` X ` {..k})" .
   1.188 +    thus "0 < Max (abs ` X ` {..k}) + 1" by simp
   1.189 +  next
   1.190 +    fix n :: nat
   1.191 +    show "\<bar>X n\<bar> < Max (abs ` X ` {..k}) + 1"
   1.192 +    proof (rule linorder_le_cases)
   1.193 +      assume "n \<le> k"
   1.194 +      hence "\<bar>X n\<bar> \<le> Max (abs ` X ` {..k})" by simp
   1.195 +      thus "\<bar>X n\<bar> < Max (abs ` X ` {..k}) + 1" by simp
   1.196 +    next
   1.197 +      assume "k \<le> n"
   1.198 +      have "\<bar>X n\<bar> = \<bar>X k + (X n - X k)\<bar>" by simp
   1.199 +      also have "\<bar>X k + (X n - X k)\<bar> \<le> \<bar>X k\<bar> + \<bar>X n - X k\<bar>"
   1.200 +        by (rule abs_triangle_ineq)
   1.201 +      also have "\<dots> < Max (abs ` X ` {..k}) + 1"
   1.202 +        by (rule add_le_less_mono, simp, simp add: k `k \<le> n`)
   1.203 +      finally show "\<bar>X n\<bar> < Max (abs ` X ` {..k}) + 1" .
   1.204 +    qed
   1.205 +  qed
   1.206 +qed
   1.207 +
   1.208 +lemma cauchy_mult [simp]:
   1.209 +  assumes X: "cauchy X" and Y: "cauchy Y"
   1.210 +  shows "cauchy (\<lambda>n. X n * Y n)"
   1.211 +proof (rule cauchyI)
   1.212 +  fix r :: rat assume "0 < r"
   1.213 +  then obtain u v where u: "0 < u" and v: "0 < v" and "r = u + v"
   1.214 +    by (rule obtain_pos_sum)
   1.215 +  obtain a where a: "0 < a" "\<forall>n. \<bar>X n\<bar> < a"
   1.216 +    using cauchy_imp_bounded [OF X] by fast
   1.217 +  obtain b where b: "0 < b" "\<forall>n. \<bar>Y n\<bar> < b"
   1.218 +    using cauchy_imp_bounded [OF Y] by fast
   1.219 +  obtain s t where s: "0 < s" and t: "0 < t" and r: "r = a * t + s * b"
   1.220 +  proof
   1.221 +    show "0 < v/b" using v b(1) by (rule divide_pos_pos)
   1.222 +    show "0 < u/a" using u a(1) by (rule divide_pos_pos)
   1.223 +    show "r = a * (u/a) + (v/b) * b"
   1.224 +      using a(1) b(1) `r = u + v` by simp
   1.225 +  qed
   1.226 +  obtain i where i: "\<forall>m\<ge>i. \<forall>n\<ge>i. \<bar>X m - X n\<bar> < s"
   1.227 +    using cauchyD [OF X s] ..
   1.228 +  obtain j where j: "\<forall>m\<ge>j. \<forall>n\<ge>j. \<bar>Y m - Y n\<bar> < t"
   1.229 +    using cauchyD [OF Y t] ..
   1.230 +  have "\<forall>m\<ge>max i j. \<forall>n\<ge>max i j. \<bar>X m * Y m - X n * Y n\<bar> < r"
   1.231 +  proof (clarsimp)
   1.232 +    fix m n assume *: "i \<le> m" "j \<le> m" "i \<le> n" "j \<le> n"
   1.233 +    have "\<bar>X m * Y m - X n * Y n\<bar> = \<bar>X m * (Y m - Y n) + (X m - X n) * Y n\<bar>"
   1.234 +      unfolding mult_diff_mult ..
   1.235 +    also have "\<dots> \<le> \<bar>X m * (Y m - Y n)\<bar> + \<bar>(X m - X n) * Y n\<bar>"
   1.236 +      by (rule abs_triangle_ineq)
   1.237 +    also have "\<dots> = \<bar>X m\<bar> * \<bar>Y m - Y n\<bar> + \<bar>X m - X n\<bar> * \<bar>Y n\<bar>"
   1.238 +      unfolding abs_mult ..
   1.239 +    also have "\<dots> < a * t + s * b"
   1.240 +      by (simp_all add: add_strict_mono mult_strict_mono' a b i j *)
   1.241 +    finally show "\<bar>X m * Y m - X n * Y n\<bar> < r" unfolding r .
   1.242 +  qed
   1.243 +  thus "\<exists>k. \<forall>m\<ge>k. \<forall>n\<ge>k. \<bar>X m * Y m - X n * Y n\<bar> < r" ..
   1.244 +qed
   1.245 +
   1.246 +lemma cauchy_not_vanishes_cases:
   1.247 +  assumes X: "cauchy X"
   1.248 +  assumes nz: "\<not> vanishes X"
   1.249 +  shows "\<exists>b>0. \<exists>k. (\<forall>n\<ge>k. b < - X n) \<or> (\<forall>n\<ge>k. b < X n)"
   1.250 +proof -
   1.251 +  obtain r where "0 < r" and r: "\<forall>k. \<exists>n\<ge>k. r \<le> \<bar>X n\<bar>"
   1.252 +    using nz unfolding vanishes_def by (auto simp add: not_less)
   1.253 +  obtain s t where s: "0 < s" and t: "0 < t" and "r = s + t"
   1.254 +    using `0 < r` by (rule obtain_pos_sum)
   1.255 +  obtain i where i: "\<forall>m\<ge>i. \<forall>n\<ge>i. \<bar>X m - X n\<bar> < s"
   1.256 +    using cauchyD [OF X s] ..
   1.257 +  obtain k where "i \<le> k" and "r \<le> \<bar>X k\<bar>"
   1.258 +    using r by fast
   1.259 +  have k: "\<forall>n\<ge>k. \<bar>X n - X k\<bar> < s"
   1.260 +    using i `i \<le> k` by auto
   1.261 +  have "X k \<le> - r \<or> r \<le> X k"
   1.262 +    using `r \<le> \<bar>X k\<bar>` by auto
   1.263 +  hence "(\<forall>n\<ge>k. t < - X n) \<or> (\<forall>n\<ge>k. t < X n)"
   1.264 +    unfolding `r = s + t` using k by auto
   1.265 +  hence "\<exists>k. (\<forall>n\<ge>k. t < - X n) \<or> (\<forall>n\<ge>k. t < X n)" ..
   1.266 +  thus "\<exists>t>0. \<exists>k. (\<forall>n\<ge>k. t < - X n) \<or> (\<forall>n\<ge>k. t < X n)"
   1.267 +    using t by auto
   1.268 +qed
   1.269 +
   1.270 +lemma cauchy_not_vanishes:
   1.271 +  assumes X: "cauchy X"
   1.272 +  assumes nz: "\<not> vanishes X"
   1.273 +  shows "\<exists>b>0. \<exists>k. \<forall>n\<ge>k. b < \<bar>X n\<bar>"
   1.274 +using cauchy_not_vanishes_cases [OF assms]
   1.275 +by clarify (rule exI, erule conjI, rule_tac x=k in exI, auto)
   1.276 +
   1.277 +lemma cauchy_inverse [simp]:
   1.278 +  assumes X: "cauchy X"
   1.279 +  assumes nz: "\<not> vanishes X"
   1.280 +  shows "cauchy (\<lambda>n. inverse (X n))"
   1.281 +proof (rule cauchyI)
   1.282 +  fix r :: rat assume "0 < r"
   1.283 +  obtain b i where b: "0 < b" and i: "\<forall>n\<ge>i. b < \<bar>X n\<bar>"
   1.284 +    using cauchy_not_vanishes [OF X nz] by fast
   1.285 +  from b i have nz: "\<forall>n\<ge>i. X n \<noteq> 0" by auto
   1.286 +  obtain s where s: "0 < s" and r: "r = inverse b * s * inverse b"
   1.287 +  proof
   1.288 +    show "0 < b * r * b"
   1.289 +      by (simp add: `0 < r` b mult_pos_pos)
   1.290 +    show "r = inverse b * (b * r * b) * inverse b"
   1.291 +      using b by simp
   1.292 +  qed
   1.293 +  obtain j where j: "\<forall>m\<ge>j. \<forall>n\<ge>j. \<bar>X m - X n\<bar> < s"
   1.294 +    using cauchyD [OF X s] ..
   1.295 +  have "\<forall>m\<ge>max i j. \<forall>n\<ge>max i j. \<bar>inverse (X m) - inverse (X n)\<bar> < r"
   1.296 +  proof (clarsimp)
   1.297 +    fix m n assume *: "i \<le> m" "j \<le> m" "i \<le> n" "j \<le> n"
   1.298 +    have "\<bar>inverse (X m) - inverse (X n)\<bar> =
   1.299 +          inverse \<bar>X m\<bar> * \<bar>X m - X n\<bar> * inverse \<bar>X n\<bar>"
   1.300 +      by (simp add: inverse_diff_inverse nz * abs_mult)
   1.301 +    also have "\<dots> < inverse b * s * inverse b"
   1.302 +      by (simp add: mult_strict_mono less_imp_inverse_less
   1.303 +                    mult_pos_pos i j b * s)
   1.304 +    finally show "\<bar>inverse (X m) - inverse (X n)\<bar> < r" unfolding r .
   1.305 +  qed
   1.306 +  thus "\<exists>k. \<forall>m\<ge>k. \<forall>n\<ge>k. \<bar>inverse (X m) - inverse (X n)\<bar> < r" ..
   1.307 +qed
   1.308 +
   1.309 +lemma vanishes_diff_inverse:
   1.310 +  assumes X: "cauchy X" "\<not> vanishes X"
   1.311 +  assumes Y: "cauchy Y" "\<not> vanishes Y"
   1.312 +  assumes XY: "vanishes (\<lambda>n. X n - Y n)"
   1.313 +  shows "vanishes (\<lambda>n. inverse (X n) - inverse (Y n))"
   1.314 +proof (rule vanishesI)
   1.315 +  fix r :: rat assume r: "0 < r"
   1.316 +  obtain a i where a: "0 < a" and i: "\<forall>n\<ge>i. a < \<bar>X n\<bar>"
   1.317 +    using cauchy_not_vanishes [OF X] by fast
   1.318 +  obtain b j where b: "0 < b" and j: "\<forall>n\<ge>j. b < \<bar>Y n\<bar>"
   1.319 +    using cauchy_not_vanishes [OF Y] by fast
   1.320 +  obtain s where s: "0 < s" and "inverse a * s * inverse b = r"
   1.321 +  proof
   1.322 +    show "0 < a * r * b"
   1.323 +      using a r b by (simp add: mult_pos_pos)
   1.324 +    show "inverse a * (a * r * b) * inverse b = r"
   1.325 +      using a r b by simp
   1.326 +  qed
   1.327 +  obtain k where k: "\<forall>n\<ge>k. \<bar>X n - Y n\<bar> < s"
   1.328 +    using vanishesD [OF XY s] ..
   1.329 +  have "\<forall>n\<ge>max (max i j) k. \<bar>inverse (X n) - inverse (Y n)\<bar> < r"
   1.330 +  proof (clarsimp)
   1.331 +    fix n assume n: "i \<le> n" "j \<le> n" "k \<le> n"
   1.332 +    have "X n \<noteq> 0" and "Y n \<noteq> 0"
   1.333 +      using i j a b n by auto
   1.334 +    hence "\<bar>inverse (X n) - inverse (Y n)\<bar> =
   1.335 +        inverse \<bar>X n\<bar> * \<bar>X n - Y n\<bar> * inverse \<bar>Y n\<bar>"
   1.336 +      by (simp add: inverse_diff_inverse abs_mult)
   1.337 +    also have "\<dots> < inverse a * s * inverse b"
   1.338 +      apply (intro mult_strict_mono' less_imp_inverse_less)
   1.339 +      apply (simp_all add: a b i j k n mult_nonneg_nonneg)
   1.340 +      done
   1.341 +    also note `inverse a * s * inverse b = r`
   1.342 +    finally show "\<bar>inverse (X n) - inverse (Y n)\<bar> < r" .
   1.343 +  qed
   1.344 +  thus "\<exists>k. \<forall>n\<ge>k. \<bar>inverse (X n) - inverse (Y n)\<bar> < r" ..
   1.345 +qed
   1.346 +
   1.347 +subsection {* Equivalence relation on Cauchy sequences *}
   1.348 +
   1.349 +definition realrel :: "(nat \<Rightarrow> rat) \<Rightarrow> (nat \<Rightarrow> rat) \<Rightarrow> bool"
   1.350 +  where "realrel = (\<lambda>X Y. cauchy X \<and> cauchy Y \<and> vanishes (\<lambda>n. X n - Y n))"
   1.351 +
   1.352 +lemma realrelI [intro?]:
   1.353 +  assumes "cauchy X" and "cauchy Y" and "vanishes (\<lambda>n. X n - Y n)"
   1.354 +  shows "realrel X Y"
   1.355 +  using assms unfolding realrel_def by simp
   1.356 +
   1.357 +lemma realrel_refl: "cauchy X \<Longrightarrow> realrel X X"
   1.358 +  unfolding realrel_def by simp
   1.359 +
   1.360 +lemma symp_realrel: "symp realrel"
   1.361 +  unfolding realrel_def
   1.362 +  by (rule sympI, clarify, drule vanishes_minus, simp)
   1.363 +
   1.364 +lemma transp_realrel: "transp realrel"
   1.365 +  unfolding realrel_def
   1.366 +  apply (rule transpI, clarify)
   1.367 +  apply (drule (1) vanishes_add)
   1.368 +  apply (simp add: algebra_simps)
   1.369 +  done
   1.370 +
   1.371 +lemma part_equivp_realrel: "part_equivp realrel"
   1.372 +  by (fast intro: part_equivpI symp_realrel transp_realrel
   1.373 +    realrel_refl cauchy_const)
   1.374 +
   1.375 +subsection {* The field of real numbers *}
   1.376 +
   1.377 +quotient_type real = "nat \<Rightarrow> rat" / partial: realrel
   1.378 +  morphisms rep_real Real
   1.379 +  by (rule part_equivp_realrel)
   1.380 +
   1.381 +lemma cr_real_eq: "pcr_real = (\<lambda>x y. cauchy x \<and> Real x = y)"
   1.382 +  unfolding real.pcr_cr_eq cr_real_def realrel_def by auto
   1.383 +
   1.384 +lemma Real_induct [induct type: real]: (* TODO: generate automatically *)
   1.385 +  assumes "\<And>X. cauchy X \<Longrightarrow> P (Real X)" shows "P x"
   1.386 +proof (induct x)
   1.387 +  case (1 X)
   1.388 +  hence "cauchy X" by (simp add: realrel_def)
   1.389 +  thus "P (Real X)" by (rule assms)
   1.390 +qed
   1.391 +
   1.392 +lemma eq_Real:
   1.393 +  "cauchy X \<Longrightarrow> cauchy Y \<Longrightarrow> Real X = Real Y \<longleftrightarrow> vanishes (\<lambda>n. X n - Y n)"
   1.394 +  using real.rel_eq_transfer
   1.395 +  unfolding real.pcr_cr_eq cr_real_def fun_rel_def realrel_def by simp
   1.396 +
   1.397 +declare real.forall_transfer [transfer_rule del]
   1.398 +
   1.399 +lemma forall_real_transfer [transfer_rule]: (* TODO: generate automatically *)
   1.400 +  "(fun_rel (fun_rel pcr_real op =) op =)
   1.401 +    (transfer_bforall cauchy) transfer_forall"
   1.402 +  using real.forall_transfer
   1.403 +  by (simp add: realrel_def)
   1.404 +
   1.405 +instantiation real :: field_inverse_zero
   1.406 +begin
   1.407 +
   1.408 +lift_definition zero_real :: "real" is "\<lambda>n. 0"
   1.409 +  by (simp add: realrel_refl)
   1.410 +
   1.411 +lift_definition one_real :: "real" is "\<lambda>n. 1"
   1.412 +  by (simp add: realrel_refl)
   1.413 +
   1.414 +lift_definition plus_real :: "real \<Rightarrow> real \<Rightarrow> real" is "\<lambda>X Y n. X n + Y n"
   1.415 +  unfolding realrel_def add_diff_add
   1.416 +  by (simp only: cauchy_add vanishes_add simp_thms)
   1.417 +
   1.418 +lift_definition uminus_real :: "real \<Rightarrow> real" is "\<lambda>X n. - X n"
   1.419 +  unfolding realrel_def minus_diff_minus
   1.420 +  by (simp only: cauchy_minus vanishes_minus simp_thms)
   1.421 +
   1.422 +lift_definition times_real :: "real \<Rightarrow> real \<Rightarrow> real" is "\<lambda>X Y n. X n * Y n"
   1.423 +  unfolding realrel_def mult_diff_mult
   1.424 +  by (subst (4) mult_commute, simp only: cauchy_mult vanishes_add
   1.425 +    vanishes_mult_bounded cauchy_imp_bounded simp_thms)
   1.426 +
   1.427 +lift_definition inverse_real :: "real \<Rightarrow> real"
   1.428 +  is "\<lambda>X. if vanishes X then (\<lambda>n. 0) else (\<lambda>n. inverse (X n))"
   1.429 +proof -
   1.430 +  fix X Y assume "realrel X Y"
   1.431 +  hence X: "cauchy X" and Y: "cauchy Y" and XY: "vanishes (\<lambda>n. X n - Y n)"
   1.432 +    unfolding realrel_def by simp_all
   1.433 +  have "vanishes X \<longleftrightarrow> vanishes Y"
   1.434 +  proof
   1.435 +    assume "vanishes X"
   1.436 +    from vanishes_diff [OF this XY] show "vanishes Y" by simp
   1.437 +  next
   1.438 +    assume "vanishes Y"
   1.439 +    from vanishes_add [OF this XY] show "vanishes X" by simp
   1.440 +  qed
   1.441 +  thus "?thesis X Y"
   1.442 +    unfolding realrel_def
   1.443 +    by (simp add: vanishes_diff_inverse X Y XY)
   1.444 +qed
   1.445 +
   1.446 +definition
   1.447 +  "x - y = (x::real) + - y"
   1.448 +
   1.449 +definition
   1.450 +  "x / y = (x::real) * inverse y"
   1.451 +
   1.452 +lemma add_Real:
   1.453 +  assumes X: "cauchy X" and Y: "cauchy Y"
   1.454 +  shows "Real X + Real Y = Real (\<lambda>n. X n + Y n)"
   1.455 +  using assms plus_real.transfer
   1.456 +  unfolding cr_real_eq fun_rel_def by simp
   1.457 +
   1.458 +lemma minus_Real:
   1.459 +  assumes X: "cauchy X"
   1.460 +  shows "- Real X = Real (\<lambda>n. - X n)"
   1.461 +  using assms uminus_real.transfer
   1.462 +  unfolding cr_real_eq fun_rel_def by simp
   1.463 +
   1.464 +lemma diff_Real:
   1.465 +  assumes X: "cauchy X" and Y: "cauchy Y"
   1.466 +  shows "Real X - Real Y = Real (\<lambda>n. X n - Y n)"
   1.467 +  unfolding minus_real_def diff_minus
   1.468 +  by (simp add: minus_Real add_Real X Y)
   1.469 +
   1.470 +lemma mult_Real:
   1.471 +  assumes X: "cauchy X" and Y: "cauchy Y"
   1.472 +  shows "Real X * Real Y = Real (\<lambda>n. X n * Y n)"
   1.473 +  using assms times_real.transfer
   1.474 +  unfolding cr_real_eq fun_rel_def by simp
   1.475 +
   1.476 +lemma inverse_Real:
   1.477 +  assumes X: "cauchy X"
   1.478 +  shows "inverse (Real X) =
   1.479 +    (if vanishes X then 0 else Real (\<lambda>n. inverse (X n)))"
   1.480 +  using assms inverse_real.transfer zero_real.transfer
   1.481 +  unfolding cr_real_eq fun_rel_def by (simp split: split_if_asm, metis)
   1.482 +
   1.483 +instance proof
   1.484 +  fix a b c :: real
   1.485 +  show "a + b = b + a"
   1.486 +    by transfer (simp add: add_ac realrel_def)
   1.487 +  show "(a + b) + c = a + (b + c)"
   1.488 +    by transfer (simp add: add_ac realrel_def)
   1.489 +  show "0 + a = a"
   1.490 +    by transfer (simp add: realrel_def)
   1.491 +  show "- a + a = 0"
   1.492 +    by transfer (simp add: realrel_def)
   1.493 +  show "a - b = a + - b"
   1.494 +    by (rule minus_real_def)
   1.495 +  show "(a * b) * c = a * (b * c)"
   1.496 +    by transfer (simp add: mult_ac realrel_def)
   1.497 +  show "a * b = b * a"
   1.498 +    by transfer (simp add: mult_ac realrel_def)
   1.499 +  show "1 * a = a"
   1.500 +    by transfer (simp add: mult_ac realrel_def)
   1.501 +  show "(a + b) * c = a * c + b * c"
   1.502 +    by transfer (simp add: distrib_right realrel_def)
   1.503 +  show "(0\<Colon>real) \<noteq> (1\<Colon>real)"
   1.504 +    by transfer (simp add: realrel_def)
   1.505 +  show "a \<noteq> 0 \<Longrightarrow> inverse a * a = 1"
   1.506 +    apply transfer
   1.507 +    apply (simp add: realrel_def)
   1.508 +    apply (rule vanishesI)
   1.509 +    apply (frule (1) cauchy_not_vanishes, clarify)
   1.510 +    apply (rule_tac x=k in exI, clarify)
   1.511 +    apply (drule_tac x=n in spec, simp)
   1.512 +    done
   1.513 +  show "a / b = a * inverse b"
   1.514 +    by (rule divide_real_def)
   1.515 +  show "inverse (0::real) = 0"
   1.516 +    by transfer (simp add: realrel_def)
   1.517 +qed
   1.518 +
   1.519 +end
   1.520 +
   1.521 +subsection {* Positive reals *}
   1.522 +
   1.523 +lift_definition positive :: "real \<Rightarrow> bool"
   1.524 +  is "\<lambda>X. \<exists>r>0. \<exists>k. \<forall>n\<ge>k. r < X n"
   1.525 +proof -
   1.526 +  { fix X Y
   1.527 +    assume "realrel X Y"
   1.528 +    hence XY: "vanishes (\<lambda>n. X n - Y n)"
   1.529 +      unfolding realrel_def by simp_all
   1.530 +    assume "\<exists>r>0. \<exists>k. \<forall>n\<ge>k. r < X n"
   1.531 +    then obtain r i where "0 < r" and i: "\<forall>n\<ge>i. r < X n"
   1.532 +      by fast
   1.533 +    obtain s t where s: "0 < s" and t: "0 < t" and r: "r = s + t"
   1.534 +      using `0 < r` by (rule obtain_pos_sum)
   1.535 +    obtain j where j: "\<forall>n\<ge>j. \<bar>X n - Y n\<bar> < s"
   1.536 +      using vanishesD [OF XY s] ..
   1.537 +    have "\<forall>n\<ge>max i j. t < Y n"
   1.538 +    proof (clarsimp)
   1.539 +      fix n assume n: "i \<le> n" "j \<le> n"
   1.540 +      have "\<bar>X n - Y n\<bar> < s" and "r < X n"
   1.541 +        using i j n by simp_all
   1.542 +      thus "t < Y n" unfolding r by simp
   1.543 +    qed
   1.544 +    hence "\<exists>r>0. \<exists>k. \<forall>n\<ge>k. r < Y n" using t by fast
   1.545 +  } note 1 = this
   1.546 +  fix X Y assume "realrel X Y"
   1.547 +  hence "realrel X Y" and "realrel Y X"
   1.548 +    using symp_realrel unfolding symp_def by auto
   1.549 +  thus "?thesis X Y"
   1.550 +    by (safe elim!: 1)
   1.551 +qed
   1.552 +
   1.553 +lemma positive_Real:
   1.554 +  assumes X: "cauchy X"
   1.555 +  shows "positive (Real X) \<longleftrightarrow> (\<exists>r>0. \<exists>k. \<forall>n\<ge>k. r < X n)"
   1.556 +  using assms positive.transfer
   1.557 +  unfolding cr_real_eq fun_rel_def by simp
   1.558 +
   1.559 +lemma positive_zero: "\<not> positive 0"
   1.560 +  by transfer auto
   1.561 +
   1.562 +lemma positive_add:
   1.563 +  "positive x \<Longrightarrow> positive y \<Longrightarrow> positive (x + y)"
   1.564 +apply transfer
   1.565 +apply (clarify, rename_tac a b i j)
   1.566 +apply (rule_tac x="a + b" in exI, simp)
   1.567 +apply (rule_tac x="max i j" in exI, clarsimp)
   1.568 +apply (simp add: add_strict_mono)
   1.569 +done
   1.570 +
   1.571 +lemma positive_mult:
   1.572 +  "positive x \<Longrightarrow> positive y \<Longrightarrow> positive (x * y)"
   1.573 +apply transfer
   1.574 +apply (clarify, rename_tac a b i j)
   1.575 +apply (rule_tac x="a * b" in exI, simp add: mult_pos_pos)
   1.576 +apply (rule_tac x="max i j" in exI, clarsimp)
   1.577 +apply (rule mult_strict_mono, auto)
   1.578 +done
   1.579 +
   1.580 +lemma positive_minus:
   1.581 +  "\<not> positive x \<Longrightarrow> x \<noteq> 0 \<Longrightarrow> positive (- x)"
   1.582 +apply transfer
   1.583 +apply (simp add: realrel_def)
   1.584 +apply (drule (1) cauchy_not_vanishes_cases, safe, fast, fast)
   1.585 +done
   1.586 +
   1.587 +instantiation real :: linordered_field_inverse_zero
   1.588 +begin
   1.589 +
   1.590 +definition
   1.591 +  "x < y \<longleftrightarrow> positive (y - x)"
   1.592 +
   1.593 +definition
   1.594 +  "x \<le> (y::real) \<longleftrightarrow> x < y \<or> x = y"
   1.595 +
   1.596 +definition
   1.597 +  "abs (a::real) = (if a < 0 then - a else a)"
   1.598 +
   1.599 +definition
   1.600 +  "sgn (a::real) = (if a = 0 then 0 else if 0 < a then 1 else - 1)"
   1.601 +
   1.602 +instance proof
   1.603 +  fix a b c :: real
   1.604 +  show "\<bar>a\<bar> = (if a < 0 then - a else a)"
   1.605 +    by (rule abs_real_def)
   1.606 +  show "a < b \<longleftrightarrow> a \<le> b \<and> \<not> b \<le> a"
   1.607 +    unfolding less_eq_real_def less_real_def
   1.608 +    by (auto, drule (1) positive_add, simp_all add: positive_zero)
   1.609 +  show "a \<le> a"
   1.610 +    unfolding less_eq_real_def by simp
   1.611 +  show "a \<le> b \<Longrightarrow> b \<le> c \<Longrightarrow> a \<le> c"
   1.612 +    unfolding less_eq_real_def less_real_def
   1.613 +    by (auto, drule (1) positive_add, simp add: algebra_simps)
   1.614 +  show "a \<le> b \<Longrightarrow> b \<le> a \<Longrightarrow> a = b"
   1.615 +    unfolding less_eq_real_def less_real_def
   1.616 +    by (auto, drule (1) positive_add, simp add: positive_zero)
   1.617 +  show "a \<le> b \<Longrightarrow> c + a \<le> c + b"
   1.618 +    unfolding less_eq_real_def less_real_def by (auto simp: diff_minus) (* by auto *)
   1.619 +    (* FIXME: Procedure int_combine_numerals: c + b - (c + a) \<equiv> b + - a *)
   1.620 +    (* Should produce c + b - (c + a) \<equiv> b - a *)
   1.621 +  show "sgn a = (if a = 0 then 0 else if 0 < a then 1 else - 1)"
   1.622 +    by (rule sgn_real_def)
   1.623 +  show "a \<le> b \<or> b \<le> a"
   1.624 +    unfolding less_eq_real_def less_real_def
   1.625 +    by (auto dest!: positive_minus)
   1.626 +  show "a < b \<Longrightarrow> 0 < c \<Longrightarrow> c * a < c * b"
   1.627 +    unfolding less_real_def
   1.628 +    by (drule (1) positive_mult, simp add: algebra_simps)
   1.629 +qed
   1.630 +
   1.631 +end
   1.632 +
   1.633 +instantiation real :: distrib_lattice
   1.634 +begin
   1.635 +
   1.636 +definition
   1.637 +  "(inf :: real \<Rightarrow> real \<Rightarrow> real) = min"
   1.638 +
   1.639 +definition
   1.640 +  "(sup :: real \<Rightarrow> real \<Rightarrow> real) = max"
   1.641 +
   1.642 +instance proof
   1.643 +qed (auto simp add: inf_real_def sup_real_def min_max.sup_inf_distrib1)
   1.644 +
   1.645 +end
   1.646 +
   1.647 +lemma of_nat_Real: "of_nat x = Real (\<lambda>n. of_nat x)"
   1.648 +apply (induct x)
   1.649 +apply (simp add: zero_real_def)
   1.650 +apply (simp add: one_real_def add_Real)
   1.651 +done
   1.652 +
   1.653 +lemma of_int_Real: "of_int x = Real (\<lambda>n. of_int x)"
   1.654 +apply (cases x rule: int_diff_cases)
   1.655 +apply (simp add: of_nat_Real diff_Real)
   1.656 +done
   1.657 +
   1.658 +lemma of_rat_Real: "of_rat x = Real (\<lambda>n. x)"
   1.659 +apply (induct x)
   1.660 +apply (simp add: Fract_of_int_quotient of_rat_divide)
   1.661 +apply (simp add: of_int_Real divide_inverse)
   1.662 +apply (simp add: inverse_Real mult_Real)
   1.663 +done
   1.664 +
   1.665 +instance real :: archimedean_field
   1.666 +proof
   1.667 +  fix x :: real
   1.668 +  show "\<exists>z. x \<le> of_int z"
   1.669 +    apply (induct x)
   1.670 +    apply (frule cauchy_imp_bounded, clarify)
   1.671 +    apply (rule_tac x="ceiling b + 1" in exI)
   1.672 +    apply (rule less_imp_le)
   1.673 +    apply (simp add: of_int_Real less_real_def diff_Real positive_Real)
   1.674 +    apply (rule_tac x=1 in exI, simp add: algebra_simps)
   1.675 +    apply (rule_tac x=0 in exI, clarsimp)
   1.676 +    apply (rule le_less_trans [OF abs_ge_self])
   1.677 +    apply (rule less_le_trans [OF _ le_of_int_ceiling])
   1.678 +    apply simp
   1.679 +    done
   1.680 +qed
   1.681 +
   1.682 +instantiation real :: floor_ceiling
   1.683 +begin
   1.684 +
   1.685 +definition [code del]:
   1.686 +  "floor (x::real) = (THE z. of_int z \<le> x \<and> x < of_int (z + 1))"
   1.687 +
   1.688 +instance proof
   1.689 +  fix x :: real
   1.690 +  show "of_int (floor x) \<le> x \<and> x < of_int (floor x + 1)"
   1.691 +    unfolding floor_real_def using floor_exists1 by (rule theI')
   1.692 +qed
   1.693 +
   1.694 +end
   1.695 +
   1.696 +subsection {* Completeness *}
   1.697 +
   1.698 +lemma not_positive_Real:
   1.699 +  assumes X: "cauchy X"
   1.700 +  shows "\<not> positive (Real X) \<longleftrightarrow> (\<forall>r>0. \<exists>k. \<forall>n\<ge>k. X n \<le> r)"
   1.701 +unfolding positive_Real [OF X]
   1.702 +apply (auto, unfold not_less)
   1.703 +apply (erule obtain_pos_sum)
   1.704 +apply (drule_tac x=s in spec, simp)
   1.705 +apply (drule_tac r=t in cauchyD [OF X], clarify)
   1.706 +apply (drule_tac x=k in spec, clarsimp)
   1.707 +apply (rule_tac x=n in exI, clarify, rename_tac m)
   1.708 +apply (drule_tac x=m in spec, simp)
   1.709 +apply (drule_tac x=n in spec, simp)
   1.710 +apply (drule spec, drule (1) mp, clarify, rename_tac i)
   1.711 +apply (rule_tac x="max i k" in exI, simp)
   1.712 +done
   1.713 +
   1.714 +lemma le_Real:
   1.715 +  assumes X: "cauchy X" and Y: "cauchy Y"
   1.716 +  shows "Real X \<le> Real Y = (\<forall>r>0. \<exists>k. \<forall>n\<ge>k. X n \<le> Y n + r)"
   1.717 +unfolding not_less [symmetric, where 'a=real] less_real_def
   1.718 +apply (simp add: diff_Real not_positive_Real X Y)
   1.719 +apply (simp add: diff_le_eq add_ac)
   1.720 +done
   1.721 +
   1.722 +lemma le_RealI:
   1.723 +  assumes Y: "cauchy Y"
   1.724 +  shows "\<forall>n. x \<le> of_rat (Y n) \<Longrightarrow> x \<le> Real Y"
   1.725 +proof (induct x)
   1.726 +  fix X assume X: "cauchy X" and "\<forall>n. Real X \<le> of_rat (Y n)"
   1.727 +  hence le: "\<And>m r. 0 < r \<Longrightarrow> \<exists>k. \<forall>n\<ge>k. X n \<le> Y m + r"
   1.728 +    by (simp add: of_rat_Real le_Real)
   1.729 +  {
   1.730 +    fix r :: rat assume "0 < r"
   1.731 +    then obtain s t where s: "0 < s" and t: "0 < t" and r: "r = s + t"
   1.732 +      by (rule obtain_pos_sum)
   1.733 +    obtain i where i: "\<forall>m\<ge>i. \<forall>n\<ge>i. \<bar>Y m - Y n\<bar> < s"
   1.734 +      using cauchyD [OF Y s] ..
   1.735 +    obtain j where j: "\<forall>n\<ge>j. X n \<le> Y i + t"
   1.736 +      using le [OF t] ..
   1.737 +    have "\<forall>n\<ge>max i j. X n \<le> Y n + r"
   1.738 +    proof (clarsimp)
   1.739 +      fix n assume n: "i \<le> n" "j \<le> n"
   1.740 +      have "X n \<le> Y i + t" using n j by simp
   1.741 +      moreover have "\<bar>Y i - Y n\<bar> < s" using n i by simp
   1.742 +      ultimately show "X n \<le> Y n + r" unfolding r by simp
   1.743 +    qed
   1.744 +    hence "\<exists>k. \<forall>n\<ge>k. X n \<le> Y n + r" ..
   1.745 +  }
   1.746 +  thus "Real X \<le> Real Y"
   1.747 +    by (simp add: of_rat_Real le_Real X Y)
   1.748 +qed
   1.749 +
   1.750 +lemma Real_leI:
   1.751 +  assumes X: "cauchy X"
   1.752 +  assumes le: "\<forall>n. of_rat (X n) \<le> y"
   1.753 +  shows "Real X \<le> y"
   1.754 +proof -
   1.755 +  have "- y \<le> - Real X"
   1.756 +    by (simp add: minus_Real X le_RealI of_rat_minus le)
   1.757 +  thus ?thesis by simp
   1.758 +qed
   1.759 +
   1.760 +lemma less_RealD:
   1.761 +  assumes Y: "cauchy Y"
   1.762 +  shows "x < Real Y \<Longrightarrow> \<exists>n. x < of_rat (Y n)"
   1.763 +by (erule contrapos_pp, simp add: not_less, erule Real_leI [OF Y])
   1.764 +
   1.765 +lemma of_nat_less_two_power:
   1.766 +  "of_nat n < (2::'a::linordered_idom) ^ n"
   1.767 +apply (induct n)
   1.768 +apply simp
   1.769 +apply (subgoal_tac "(1::'a) \<le> 2 ^ n")
   1.770 +apply (drule (1) add_le_less_mono, simp)
   1.771 +apply simp
   1.772 +done
   1.773 +
   1.774 +lemma complete_real:
   1.775 +  fixes S :: "real set"
   1.776 +  assumes "\<exists>x. x \<in> S" and "\<exists>z. \<forall>x\<in>S. x \<le> z"
   1.777 +  shows "\<exists>y. (\<forall>x\<in>S. x \<le> y) \<and> (\<forall>z. (\<forall>x\<in>S. x \<le> z) \<longrightarrow> y \<le> z)"
   1.778 +proof -
   1.779 +  obtain x where x: "x \<in> S" using assms(1) ..
   1.780 +  obtain z where z: "\<forall>x\<in>S. x \<le> z" using assms(2) ..
   1.781 +
   1.782 +  def P \<equiv> "\<lambda>x. \<forall>y\<in>S. y \<le> of_rat x"
   1.783 +  obtain a where a: "\<not> P a"
   1.784 +  proof
   1.785 +    have "of_int (floor (x - 1)) \<le> x - 1" by (rule of_int_floor_le)
   1.786 +    also have "x - 1 < x" by simp
   1.787 +    finally have "of_int (floor (x - 1)) < x" .
   1.788 +    hence "\<not> x \<le> of_int (floor (x - 1))" by (simp only: not_le)
   1.789 +    then show "\<not> P (of_int (floor (x - 1)))"
   1.790 +      unfolding P_def of_rat_of_int_eq using x by fast
   1.791 +  qed
   1.792 +  obtain b where b: "P b"
   1.793 +  proof
   1.794 +    show "P (of_int (ceiling z))"
   1.795 +    unfolding P_def of_rat_of_int_eq
   1.796 +    proof
   1.797 +      fix y assume "y \<in> S"
   1.798 +      hence "y \<le> z" using z by simp
   1.799 +      also have "z \<le> of_int (ceiling z)" by (rule le_of_int_ceiling)
   1.800 +      finally show "y \<le> of_int (ceiling z)" .
   1.801 +    qed
   1.802 +  qed
   1.803 +
   1.804 +  def avg \<equiv> "\<lambda>x y :: rat. x/2 + y/2"
   1.805 +  def bisect \<equiv> "\<lambda>(x, y). if P (avg x y) then (x, avg x y) else (avg x y, y)"
   1.806 +  def A \<equiv> "\<lambda>n. fst ((bisect ^^ n) (a, b))"
   1.807 +  def B \<equiv> "\<lambda>n. snd ((bisect ^^ n) (a, b))"
   1.808 +  def C \<equiv> "\<lambda>n. avg (A n) (B n)"
   1.809 +  have A_0 [simp]: "A 0 = a" unfolding A_def by simp
   1.810 +  have B_0 [simp]: "B 0 = b" unfolding B_def by simp
   1.811 +  have A_Suc [simp]: "\<And>n. A (Suc n) = (if P (C n) then A n else C n)"
   1.812 +    unfolding A_def B_def C_def bisect_def split_def by simp
   1.813 +  have B_Suc [simp]: "\<And>n. B (Suc n) = (if P (C n) then C n else B n)"
   1.814 +    unfolding A_def B_def C_def bisect_def split_def by simp
   1.815 +
   1.816 +  have width: "\<And>n. B n - A n = (b - a) / 2^n"
   1.817 +    apply (simp add: eq_divide_eq)
   1.818 +    apply (induct_tac n, simp)
   1.819 +    apply (simp add: C_def avg_def algebra_simps)
   1.820 +    done
   1.821 +
   1.822 +  have twos: "\<And>y r :: rat. 0 < r \<Longrightarrow> \<exists>n. y / 2 ^ n < r"
   1.823 +    apply (simp add: divide_less_eq)
   1.824 +    apply (subst mult_commute)
   1.825 +    apply (frule_tac y=y in ex_less_of_nat_mult)
   1.826 +    apply clarify
   1.827 +    apply (rule_tac x=n in exI)
   1.828 +    apply (erule less_trans)
   1.829 +    apply (rule mult_strict_right_mono)
   1.830 +    apply (rule le_less_trans [OF _ of_nat_less_two_power])
   1.831 +    apply simp
   1.832 +    apply assumption
   1.833 +    done
   1.834 +
   1.835 +  have PA: "\<And>n. \<not> P (A n)"
   1.836 +    by (induct_tac n, simp_all add: a)
   1.837 +  have PB: "\<And>n. P (B n)"
   1.838 +    by (induct_tac n, simp_all add: b)
   1.839 +  have ab: "a < b"
   1.840 +    using a b unfolding P_def
   1.841 +    apply (clarsimp simp add: not_le)
   1.842 +    apply (drule (1) bspec)
   1.843 +    apply (drule (1) less_le_trans)
   1.844 +    apply (simp add: of_rat_less)
   1.845 +    done
   1.846 +  have AB: "\<And>n. A n < B n"
   1.847 +    by (induct_tac n, simp add: ab, simp add: C_def avg_def)
   1.848 +  have A_mono: "\<And>i j. i \<le> j \<Longrightarrow> A i \<le> A j"
   1.849 +    apply (auto simp add: le_less [where 'a=nat])
   1.850 +    apply (erule less_Suc_induct)
   1.851 +    apply (clarsimp simp add: C_def avg_def)
   1.852 +    apply (simp add: add_divide_distrib [symmetric])
   1.853 +    apply (rule AB [THEN less_imp_le])
   1.854 +    apply simp
   1.855 +    done
   1.856 +  have B_mono: "\<And>i j. i \<le> j \<Longrightarrow> B j \<le> B i"
   1.857 +    apply (auto simp add: le_less [where 'a=nat])
   1.858 +    apply (erule less_Suc_induct)
   1.859 +    apply (clarsimp simp add: C_def avg_def)
   1.860 +    apply (simp add: add_divide_distrib [symmetric])
   1.861 +    apply (rule AB [THEN less_imp_le])
   1.862 +    apply simp
   1.863 +    done
   1.864 +  have cauchy_lemma:
   1.865 +    "\<And>X. \<forall>n. \<forall>i\<ge>n. A n \<le> X i \<and> X i \<le> B n \<Longrightarrow> cauchy X"
   1.866 +    apply (rule cauchyI)
   1.867 +    apply (drule twos [where y="b - a"])
   1.868 +    apply (erule exE)
   1.869 +    apply (rule_tac x=n in exI, clarify, rename_tac i j)
   1.870 +    apply (rule_tac y="B n - A n" in le_less_trans) defer
   1.871 +    apply (simp add: width)
   1.872 +    apply (drule_tac x=n in spec)
   1.873 +    apply (frule_tac x=i in spec, drule (1) mp)
   1.874 +    apply (frule_tac x=j in spec, drule (1) mp)
   1.875 +    apply (frule A_mono, drule B_mono)
   1.876 +    apply (frule A_mono, drule B_mono)
   1.877 +    apply arith
   1.878 +    done
   1.879 +  have "cauchy A"
   1.880 +    apply (rule cauchy_lemma [rule_format])
   1.881 +    apply (simp add: A_mono)
   1.882 +    apply (erule order_trans [OF less_imp_le [OF AB] B_mono])
   1.883 +    done
   1.884 +  have "cauchy B"
   1.885 +    apply (rule cauchy_lemma [rule_format])
   1.886 +    apply (simp add: B_mono)
   1.887 +    apply (erule order_trans [OF A_mono less_imp_le [OF AB]])
   1.888 +    done
   1.889 +  have 1: "\<forall>x\<in>S. x \<le> Real B"
   1.890 +  proof
   1.891 +    fix x assume "x \<in> S"
   1.892 +    then show "x \<le> Real B"
   1.893 +      using PB [unfolded P_def] `cauchy B`
   1.894 +      by (simp add: le_RealI)
   1.895 +  qed
   1.896 +  have 2: "\<forall>z. (\<forall>x\<in>S. x \<le> z) \<longrightarrow> Real A \<le> z"
   1.897 +    apply clarify
   1.898 +    apply (erule contrapos_pp)
   1.899 +    apply (simp add: not_le)
   1.900 +    apply (drule less_RealD [OF `cauchy A`], clarify)
   1.901 +    apply (subgoal_tac "\<not> P (A n)")
   1.902 +    apply (simp add: P_def not_le, clarify)
   1.903 +    apply (erule rev_bexI)
   1.904 +    apply (erule (1) less_trans)
   1.905 +    apply (simp add: PA)
   1.906 +    done
   1.907 +  have "vanishes (\<lambda>n. (b - a) / 2 ^ n)"
   1.908 +  proof (rule vanishesI)
   1.909 +    fix r :: rat assume "0 < r"
   1.910 +    then obtain k where k: "\<bar>b - a\<bar> / 2 ^ k < r"
   1.911 +      using twos by fast
   1.912 +    have "\<forall>n\<ge>k. \<bar>(b - a) / 2 ^ n\<bar> < r"
   1.913 +    proof (clarify)
   1.914 +      fix n assume n: "k \<le> n"
   1.915 +      have "\<bar>(b - a) / 2 ^ n\<bar> = \<bar>b - a\<bar> / 2 ^ n"
   1.916 +        by simp
   1.917 +      also have "\<dots> \<le> \<bar>b - a\<bar> / 2 ^ k"
   1.918 +        using n by (simp add: divide_left_mono mult_pos_pos)
   1.919 +      also note k
   1.920 +      finally show "\<bar>(b - a) / 2 ^ n\<bar> < r" .
   1.921 +    qed
   1.922 +    thus "\<exists>k. \<forall>n\<ge>k. \<bar>(b - a) / 2 ^ n\<bar> < r" ..
   1.923 +  qed
   1.924 +  hence 3: "Real B = Real A"
   1.925 +    by (simp add: eq_Real `cauchy A` `cauchy B` width)
   1.926 +  show "\<exists>y. (\<forall>x\<in>S. x \<le> y) \<and> (\<forall>z. (\<forall>x\<in>S. x \<le> z) \<longrightarrow> y \<le> z)"
   1.927 +    using 1 2 3 by (rule_tac x="Real B" in exI, simp)
   1.928 +qed
   1.929 +
   1.930 +
   1.931 +instantiation real :: conditional_complete_linorder
   1.932 +begin
   1.933 +
   1.934 +subsection{*Supremum of a set of reals*}
   1.935 +
   1.936 +definition
   1.937 +  Sup_real_def: "Sup X \<equiv> LEAST z::real. \<forall>x\<in>X. x\<le>z"
   1.938 +
   1.939 +definition
   1.940 +  Inf_real_def: "Inf (X::real set) \<equiv> - Sup (uminus ` X)"
   1.941 +
   1.942 +instance
   1.943 +proof
   1.944 +  { fix z x :: real and X :: "real set"
   1.945 +    assume x: "x \<in> X" and z: "\<And>x. x \<in> X \<Longrightarrow> x \<le> z"
   1.946 +    then obtain s where s: "\<forall>y\<in>X. y \<le> s" "\<And>z. \<forall>y\<in>X. y \<le> z \<Longrightarrow> s \<le> z"
   1.947 +      using complete_real[of X] by blast
   1.948 +    then show "x \<le> Sup X"
   1.949 +      unfolding Sup_real_def by (rule LeastI2_order) (auto simp: x) }
   1.950 +  note Sup_upper = this
   1.951 +
   1.952 +  { fix z :: real and X :: "real set"
   1.953 +    assume x: "X \<noteq> {}" and z: "\<And>x. x \<in> X \<Longrightarrow> x \<le> z"
   1.954 +    then obtain s where s: "\<forall>y\<in>X. y \<le> s" "\<And>z. \<forall>y\<in>X. y \<le> z \<Longrightarrow> s \<le> z"
   1.955 +      using complete_real[of X] by blast
   1.956 +    then have "Sup X = s"
   1.957 +      unfolding Sup_real_def by (best intro: Least_equality)  
   1.958 +    also with s z have "... \<le> z"
   1.959 +      by blast
   1.960 +    finally show "Sup X \<le> z" . }
   1.961 +  note Sup_least = this
   1.962 +
   1.963 +  { fix x z :: real and X :: "real set"
   1.964 +    assume x: "x \<in> X" and z: "\<And>x. x \<in> X \<Longrightarrow> z \<le> x"
   1.965 +    have "-x \<le> Sup (uminus ` X)"
   1.966 +      by (rule Sup_upper[of _ _ "- z"]) (auto simp add: image_iff x z)
   1.967 +    then show "Inf X \<le> x" 
   1.968 +      by (auto simp add: Inf_real_def) }
   1.969 +
   1.970 +  { fix z :: real and X :: "real set"
   1.971 +    assume x: "X \<noteq> {}" and z: "\<And>x. x \<in> X \<Longrightarrow> z \<le> x"
   1.972 +    have "Sup (uminus ` X) \<le> -z"
   1.973 +      using x z by (force intro: Sup_least)
   1.974 +    then show "z \<le> Inf X" 
   1.975 +        by (auto simp add: Inf_real_def) }
   1.976 +qed
   1.977 +end
   1.978 +
   1.979 +text {*
   1.980 +  \medskip Completeness properties using @{text "isUb"}, @{text "isLub"}:
   1.981 +*}
   1.982 +
   1.983 +lemma reals_complete: "\<exists>X. X \<in> S \<Longrightarrow> \<exists>Y. isUb (UNIV::real set) S Y \<Longrightarrow> \<exists>t. isLub (UNIV :: real set) S t"
   1.984 +  by (intro exI[of _ "Sup S"] isLub_cSup) (auto simp: setle_def isUb_def intro: cSup_upper)
   1.985 +
   1.986 +
   1.987 +subsection {* Hiding implementation details *}
   1.988 +
   1.989 +hide_const (open) vanishes cauchy positive Real
   1.990 +
   1.991 +declare Real_induct [induct del]
   1.992 +declare Abs_real_induct [induct del]
   1.993 +declare Abs_real_cases [cases del]
   1.994 +
   1.995 +lemmas [transfer_rule del] =
   1.996 +  real.All_transfer real.Ex_transfer real.rel_eq_transfer forall_real_transfer
   1.997 +  zero_real.transfer one_real.transfer plus_real.transfer uminus_real.transfer
   1.998 +  times_real.transfer inverse_real.transfer positive.transfer real.right_unique
   1.999 +  real.right_total
  1.1000 +
  1.1001 +subsection{*More Lemmas*}
  1.1002 +
  1.1003 +text {* BH: These lemmas should not be necessary; they should be
  1.1004 +covered by existing simp rules and simplification procedures. *}
  1.1005 +
  1.1006 +lemma real_mult_left_cancel: "(c::real) \<noteq> 0 ==> (c*a=c*b) = (a=b)"
  1.1007 +by simp (* redundant with mult_cancel_left *)
  1.1008 +
  1.1009 +lemma real_mult_right_cancel: "(c::real) \<noteq> 0 ==> (a*c=b*c) = (a=b)"
  1.1010 +by simp (* redundant with mult_cancel_right *)
  1.1011 +
  1.1012 +lemma real_mult_less_iff1 [simp]: "(0::real) < z ==> (x*z < y*z) = (x < y)"
  1.1013 +by simp (* solved by linordered_ring_less_cancel_factor simproc *)
  1.1014 +
  1.1015 +lemma real_mult_le_cancel_iff1 [simp]: "(0::real) < z ==> (x*z \<le> y*z) = (x\<le>y)"
  1.1016 +by simp (* solved by linordered_ring_le_cancel_factor simproc *)
  1.1017 +
  1.1018 +lemma real_mult_le_cancel_iff2 [simp]: "(0::real) < z ==> (z*x \<le> z*y) = (x\<le>y)"
  1.1019 +by simp (* solved by linordered_ring_le_cancel_factor simproc *)
  1.1020 +
  1.1021 +
  1.1022 +subsection {* Embedding numbers into the Reals *}
  1.1023 +
  1.1024 +abbreviation
  1.1025 +  real_of_nat :: "nat \<Rightarrow> real"
  1.1026 +where
  1.1027 +  "real_of_nat \<equiv> of_nat"
  1.1028 +
  1.1029 +abbreviation
  1.1030 +  real_of_int :: "int \<Rightarrow> real"
  1.1031 +where
  1.1032 +  "real_of_int \<equiv> of_int"
  1.1033 +
  1.1034 +abbreviation
  1.1035 +  real_of_rat :: "rat \<Rightarrow> real"
  1.1036 +where
  1.1037 +  "real_of_rat \<equiv> of_rat"
  1.1038 +
  1.1039 +consts
  1.1040 +  (*overloaded constant for injecting other types into "real"*)
  1.1041 +  real :: "'a => real"
  1.1042 +
  1.1043 +defs (overloaded)
  1.1044 +  real_of_nat_def [code_unfold]: "real == real_of_nat"
  1.1045 +  real_of_int_def [code_unfold]: "real == real_of_int"
  1.1046 +
  1.1047 +declare [[coercion_enabled]]
  1.1048 +declare [[coercion "real::nat\<Rightarrow>real"]]
  1.1049 +declare [[coercion "real::int\<Rightarrow>real"]]
  1.1050 +declare [[coercion "int"]]
  1.1051 +
  1.1052 +declare [[coercion_map map]]
  1.1053 +declare [[coercion_map "% f g h x. g (h (f x))"]]
  1.1054 +declare [[coercion_map "% f g (x,y) . (f x, g y)"]]
  1.1055 +
  1.1056 +lemma real_eq_of_nat: "real = of_nat"
  1.1057 +  unfolding real_of_nat_def ..
  1.1058 +
  1.1059 +lemma real_eq_of_int: "real = of_int"
  1.1060 +  unfolding real_of_int_def ..
  1.1061 +
  1.1062 +lemma real_of_int_zero [simp]: "real (0::int) = 0"  
  1.1063 +by (simp add: real_of_int_def) 
  1.1064 +
  1.1065 +lemma real_of_one [simp]: "real (1::int) = (1::real)"
  1.1066 +by (simp add: real_of_int_def) 
  1.1067 +
  1.1068 +lemma real_of_int_add [simp]: "real(x + y) = real (x::int) + real y"
  1.1069 +by (simp add: real_of_int_def) 
  1.1070 +
  1.1071 +lemma real_of_int_minus [simp]: "real(-x) = -real (x::int)"
  1.1072 +by (simp add: real_of_int_def) 
  1.1073 +
  1.1074 +lemma real_of_int_diff [simp]: "real(x - y) = real (x::int) - real y"
  1.1075 +by (simp add: real_of_int_def) 
  1.1076 +
  1.1077 +lemma real_of_int_mult [simp]: "real(x * y) = real (x::int) * real y"
  1.1078 +by (simp add: real_of_int_def) 
  1.1079 +
  1.1080 +lemma real_of_int_power [simp]: "real (x ^ n) = real (x::int) ^ n"
  1.1081 +by (simp add: real_of_int_def of_int_power)
  1.1082 +
  1.1083 +lemmas power_real_of_int = real_of_int_power [symmetric]
  1.1084 +
  1.1085 +lemma real_of_int_setsum [simp]: "real ((SUM x:A. f x)::int) = (SUM x:A. real(f x))"
  1.1086 +  apply (subst real_eq_of_int)+
  1.1087 +  apply (rule of_int_setsum)
  1.1088 +done
  1.1089 +
  1.1090 +lemma real_of_int_setprod [simp]: "real ((PROD x:A. f x)::int) = 
  1.1091 +    (PROD x:A. real(f x))"
  1.1092 +  apply (subst real_eq_of_int)+
  1.1093 +  apply (rule of_int_setprod)
  1.1094 +done
  1.1095 +
  1.1096 +lemma real_of_int_zero_cancel [simp, algebra, presburger]: "(real x = 0) = (x = (0::int))"
  1.1097 +by (simp add: real_of_int_def) 
  1.1098 +
  1.1099 +lemma real_of_int_inject [iff, algebra, presburger]: "(real (x::int) = real y) = (x = y)"
  1.1100 +by (simp add: real_of_int_def) 
  1.1101 +
  1.1102 +lemma real_of_int_less_iff [iff, presburger]: "(real (x::int) < real y) = (x < y)"
  1.1103 +by (simp add: real_of_int_def) 
  1.1104 +
  1.1105 +lemma real_of_int_le_iff [simp, presburger]: "(real (x::int) \<le> real y) = (x \<le> y)"
  1.1106 +by (simp add: real_of_int_def) 
  1.1107 +
  1.1108 +lemma real_of_int_gt_zero_cancel_iff [simp, presburger]: "(0 < real (n::int)) = (0 < n)"
  1.1109 +by (simp add: real_of_int_def) 
  1.1110 +
  1.1111 +lemma real_of_int_ge_zero_cancel_iff [simp, presburger]: "(0 <= real (n::int)) = (0 <= n)"
  1.1112 +by (simp add: real_of_int_def) 
  1.1113 +
  1.1114 +lemma real_of_int_lt_zero_cancel_iff [simp, presburger]: "(real (n::int) < 0) = (n < 0)" 
  1.1115 +by (simp add: real_of_int_def)
  1.1116 +
  1.1117 +lemma real_of_int_le_zero_cancel_iff [simp, presburger]: "(real (n::int) <= 0) = (n <= 0)"
  1.1118 +by (simp add: real_of_int_def)
  1.1119 +
  1.1120 +lemma one_less_real_of_int_cancel_iff: "1 < real (i :: int) \<longleftrightarrow> 1 < i"
  1.1121 +  unfolding real_of_one[symmetric] real_of_int_less_iff ..
  1.1122 +
  1.1123 +lemma one_le_real_of_int_cancel_iff: "1 \<le> real (i :: int) \<longleftrightarrow> 1 \<le> i"
  1.1124 +  unfolding real_of_one[symmetric] real_of_int_le_iff ..
  1.1125 +
  1.1126 +lemma real_of_int_less_one_cancel_iff: "real (i :: int) < 1 \<longleftrightarrow> i < 1"
  1.1127 +  unfolding real_of_one[symmetric] real_of_int_less_iff ..
  1.1128 +
  1.1129 +lemma real_of_int_le_one_cancel_iff: "real (i :: int) \<le> 1 \<longleftrightarrow> i \<le> 1"
  1.1130 +  unfolding real_of_one[symmetric] real_of_int_le_iff ..
  1.1131 +
  1.1132 +lemma real_of_int_abs [simp]: "real (abs x) = abs(real (x::int))"
  1.1133 +by (auto simp add: abs_if)
  1.1134 +
  1.1135 +lemma int_less_real_le: "((n::int) < m) = (real n + 1 <= real m)"
  1.1136 +  apply (subgoal_tac "real n + 1 = real (n + 1)")
  1.1137 +  apply (simp del: real_of_int_add)
  1.1138 +  apply auto
  1.1139 +done
  1.1140 +
  1.1141 +lemma int_le_real_less: "((n::int) <= m) = (real n < real m + 1)"
  1.1142 +  apply (subgoal_tac "real m + 1 = real (m + 1)")
  1.1143 +  apply (simp del: real_of_int_add)
  1.1144 +  apply simp
  1.1145 +done
  1.1146 +
  1.1147 +lemma real_of_int_div_aux: "(real (x::int)) / (real d) = 
  1.1148 +    real (x div d) + (real (x mod d)) / (real d)"
  1.1149 +proof -
  1.1150 +  have "x = (x div d) * d + x mod d"
  1.1151 +    by auto
  1.1152 +  then have "real x = real (x div d) * real d + real(x mod d)"
  1.1153 +    by (simp only: real_of_int_mult [THEN sym] real_of_int_add [THEN sym])
  1.1154 +  then have "real x / real d = ... / real d"
  1.1155 +    by simp
  1.1156 +  then show ?thesis
  1.1157 +    by (auto simp add: add_divide_distrib algebra_simps)
  1.1158 +qed
  1.1159 +
  1.1160 +lemma real_of_int_div: "(d :: int) dvd n ==>
  1.1161 +    real(n div d) = real n / real d"
  1.1162 +  apply (subst real_of_int_div_aux)
  1.1163 +  apply simp
  1.1164 +  apply (simp add: dvd_eq_mod_eq_0)
  1.1165 +done
  1.1166 +
  1.1167 +lemma real_of_int_div2:
  1.1168 +  "0 <= real (n::int) / real (x) - real (n div x)"
  1.1169 +  apply (case_tac "x = 0")
  1.1170 +  apply simp
  1.1171 +  apply (case_tac "0 < x")
  1.1172 +  apply (simp add: algebra_simps)
  1.1173 +  apply (subst real_of_int_div_aux)
  1.1174 +  apply simp
  1.1175 +  apply (subst zero_le_divide_iff)
  1.1176 +  apply auto
  1.1177 +  apply (simp add: algebra_simps)
  1.1178 +  apply (subst real_of_int_div_aux)
  1.1179 +  apply simp
  1.1180 +  apply (subst zero_le_divide_iff)
  1.1181 +  apply auto
  1.1182 +done
  1.1183 +
  1.1184 +lemma real_of_int_div3:
  1.1185 +  "real (n::int) / real (x) - real (n div x) <= 1"
  1.1186 +  apply (simp add: algebra_simps)
  1.1187 +  apply (subst real_of_int_div_aux)
  1.1188 +  apply (auto simp add: divide_le_eq intro: order_less_imp_le)
  1.1189 +done
  1.1190 +
  1.1191 +lemma real_of_int_div4: "real (n div x) <= real (n::int) / real x" 
  1.1192 +by (insert real_of_int_div2 [of n x], simp)
  1.1193 +
  1.1194 +lemma Ints_real_of_int [simp]: "real (x::int) \<in> Ints"
  1.1195 +unfolding real_of_int_def by (rule Ints_of_int)
  1.1196 +
  1.1197 +
  1.1198 +subsection{*Embedding the Naturals into the Reals*}
  1.1199 +
  1.1200 +lemma real_of_nat_zero [simp]: "real (0::nat) = 0"
  1.1201 +by (simp add: real_of_nat_def)
  1.1202 +
  1.1203 +lemma real_of_nat_1 [simp]: "real (1::nat) = 1"
  1.1204 +by (simp add: real_of_nat_def)
  1.1205 +
  1.1206 +lemma real_of_nat_one [simp]: "real (Suc 0) = (1::real)"
  1.1207 +by (simp add: real_of_nat_def)
  1.1208 +
  1.1209 +lemma real_of_nat_add [simp]: "real (m + n) = real (m::nat) + real n"
  1.1210 +by (simp add: real_of_nat_def)
  1.1211 +
  1.1212 +(*Not for addsimps: often the LHS is used to represent a positive natural*)
  1.1213 +lemma real_of_nat_Suc: "real (Suc n) = real n + (1::real)"
  1.1214 +by (simp add: real_of_nat_def)
  1.1215 +
  1.1216 +lemma real_of_nat_less_iff [iff]: 
  1.1217 +     "(real (n::nat) < real m) = (n < m)"
  1.1218 +by (simp add: real_of_nat_def)
  1.1219 +
  1.1220 +lemma real_of_nat_le_iff [iff]: "(real (n::nat) \<le> real m) = (n \<le> m)"
  1.1221 +by (simp add: real_of_nat_def)
  1.1222 +
  1.1223 +lemma real_of_nat_ge_zero [iff]: "0 \<le> real (n::nat)"
  1.1224 +by (simp add: real_of_nat_def)
  1.1225 +
  1.1226 +lemma real_of_nat_Suc_gt_zero: "0 < real (Suc n)"
  1.1227 +by (simp add: real_of_nat_def del: of_nat_Suc)
  1.1228 +
  1.1229 +lemma real_of_nat_mult [simp]: "real (m * n) = real (m::nat) * real n"
  1.1230 +by (simp add: real_of_nat_def of_nat_mult)
  1.1231 +
  1.1232 +lemma real_of_nat_power [simp]: "real (m ^ n) = real (m::nat) ^ n"
  1.1233 +by (simp add: real_of_nat_def of_nat_power)
  1.1234 +
  1.1235 +lemmas power_real_of_nat = real_of_nat_power [symmetric]
  1.1236 +
  1.1237 +lemma real_of_nat_setsum [simp]: "real ((SUM x:A. f x)::nat) = 
  1.1238 +    (SUM x:A. real(f x))"
  1.1239 +  apply (subst real_eq_of_nat)+
  1.1240 +  apply (rule of_nat_setsum)
  1.1241 +done
  1.1242 +
  1.1243 +lemma real_of_nat_setprod [simp]: "real ((PROD x:A. f x)::nat) = 
  1.1244 +    (PROD x:A. real(f x))"
  1.1245 +  apply (subst real_eq_of_nat)+
  1.1246 +  apply (rule of_nat_setprod)
  1.1247 +done
  1.1248 +
  1.1249 +lemma real_of_card: "real (card A) = setsum (%x.1) A"
  1.1250 +  apply (subst card_eq_setsum)
  1.1251 +  apply (subst real_of_nat_setsum)
  1.1252 +  apply simp
  1.1253 +done
  1.1254 +
  1.1255 +lemma real_of_nat_inject [iff]: "(real (n::nat) = real m) = (n = m)"
  1.1256 +by (simp add: real_of_nat_def)
  1.1257 +
  1.1258 +lemma real_of_nat_zero_iff [iff]: "(real (n::nat) = 0) = (n = 0)"
  1.1259 +by (simp add: real_of_nat_def)
  1.1260 +
  1.1261 +lemma real_of_nat_diff: "n \<le> m ==> real (m - n) = real (m::nat) - real n"
  1.1262 +by (simp add: add: real_of_nat_def of_nat_diff)
  1.1263 +
  1.1264 +lemma real_of_nat_gt_zero_cancel_iff [simp]: "(0 < real (n::nat)) = (0 < n)"
  1.1265 +by (auto simp: real_of_nat_def)
  1.1266 +
  1.1267 +lemma real_of_nat_le_zero_cancel_iff [simp]: "(real (n::nat) \<le> 0) = (n = 0)"
  1.1268 +by (simp add: add: real_of_nat_def)
  1.1269 +
  1.1270 +lemma not_real_of_nat_less_zero [simp]: "~ real (n::nat) < 0"
  1.1271 +by (simp add: add: real_of_nat_def)
  1.1272 +
  1.1273 +lemma nat_less_real_le: "((n::nat) < m) = (real n + 1 <= real m)"
  1.1274 +  apply (subgoal_tac "real n + 1 = real (Suc n)")
  1.1275 +  apply simp
  1.1276 +  apply (auto simp add: real_of_nat_Suc)
  1.1277 +done
  1.1278 +
  1.1279 +lemma nat_le_real_less: "((n::nat) <= m) = (real n < real m + 1)"
  1.1280 +  apply (subgoal_tac "real m + 1 = real (Suc m)")
  1.1281 +  apply (simp add: less_Suc_eq_le)
  1.1282 +  apply (simp add: real_of_nat_Suc)
  1.1283 +done
  1.1284 +
  1.1285 +lemma real_of_nat_div_aux: "(real (x::nat)) / (real d) = 
  1.1286 +    real (x div d) + (real (x mod d)) / (real d)"
  1.1287 +proof -
  1.1288 +  have "x = (x div d) * d + x mod d"
  1.1289 +    by auto
  1.1290 +  then have "real x = real (x div d) * real d + real(x mod d)"
  1.1291 +    by (simp only: real_of_nat_mult [THEN sym] real_of_nat_add [THEN sym])
  1.1292 +  then have "real x / real d = \<dots> / real d"
  1.1293 +    by simp
  1.1294 +  then show ?thesis
  1.1295 +    by (auto simp add: add_divide_distrib algebra_simps)
  1.1296 +qed
  1.1297 +
  1.1298 +lemma real_of_nat_div: "(d :: nat) dvd n ==>
  1.1299 +    real(n div d) = real n / real d"
  1.1300 +  by (subst real_of_nat_div_aux)
  1.1301 +    (auto simp add: dvd_eq_mod_eq_0 [symmetric])
  1.1302 +
  1.1303 +lemma real_of_nat_div2:
  1.1304 +  "0 <= real (n::nat) / real (x) - real (n div x)"
  1.1305 +apply (simp add: algebra_simps)
  1.1306 +apply (subst real_of_nat_div_aux)
  1.1307 +apply simp
  1.1308 +apply (subst zero_le_divide_iff)
  1.1309 +apply simp
  1.1310 +done
  1.1311 +
  1.1312 +lemma real_of_nat_div3:
  1.1313 +  "real (n::nat) / real (x) - real (n div x) <= 1"
  1.1314 +apply(case_tac "x = 0")
  1.1315 +apply (simp)
  1.1316 +apply (simp add: algebra_simps)
  1.1317 +apply (subst real_of_nat_div_aux)
  1.1318 +apply simp
  1.1319 +done
  1.1320 +
  1.1321 +lemma real_of_nat_div4: "real (n div x) <= real (n::nat) / real x" 
  1.1322 +by (insert real_of_nat_div2 [of n x], simp)
  1.1323 +
  1.1324 +lemma real_of_int_of_nat_eq [simp]: "real (of_nat n :: int) = real n"
  1.1325 +by (simp add: real_of_int_def real_of_nat_def)
  1.1326 +
  1.1327 +lemma real_nat_eq_real [simp]: "0 <= x ==> real(nat x) = real x"
  1.1328 +  apply (subgoal_tac "real(int(nat x)) = real(nat x)")
  1.1329 +  apply force
  1.1330 +  apply (simp only: real_of_int_of_nat_eq)
  1.1331 +done
  1.1332 +
  1.1333 +lemma Nats_real_of_nat [simp]: "real (n::nat) \<in> Nats"
  1.1334 +unfolding real_of_nat_def by (rule of_nat_in_Nats)
  1.1335 +
  1.1336 +lemma Ints_real_of_nat [simp]: "real (n::nat) \<in> Ints"
  1.1337 +unfolding real_of_nat_def by (rule Ints_of_nat)
  1.1338 +
  1.1339 +subsection {* The Archimedean Property of the Reals *}
  1.1340 +
  1.1341 +theorem reals_Archimedean:
  1.1342 +  assumes x_pos: "0 < x"
  1.1343 +  shows "\<exists>n. inverse (real (Suc n)) < x"
  1.1344 +  unfolding real_of_nat_def using x_pos
  1.1345 +  by (rule ex_inverse_of_nat_Suc_less)
  1.1346 +
  1.1347 +lemma reals_Archimedean2: "\<exists>n. (x::real) < real (n::nat)"
  1.1348 +  unfolding real_of_nat_def by (rule ex_less_of_nat)
  1.1349 +
  1.1350 +lemma reals_Archimedean3:
  1.1351 +  assumes x_greater_zero: "0 < x"
  1.1352 +  shows "\<forall>(y::real). \<exists>(n::nat). y < real n * x"
  1.1353 +  unfolding real_of_nat_def using `0 < x`
  1.1354 +  by (auto intro: ex_less_of_nat_mult)
  1.1355 +
  1.1356 +
  1.1357 +subsection{* Rationals *}
  1.1358 +
  1.1359 +lemma Rats_real_nat[simp]: "real(n::nat) \<in> \<rat>"
  1.1360 +by (simp add: real_eq_of_nat)
  1.1361 +
  1.1362 +
  1.1363 +lemma Rats_eq_int_div_int:
  1.1364 +  "\<rat> = { real(i::int)/real(j::int) |i j. j \<noteq> 0}" (is "_ = ?S")
  1.1365 +proof
  1.1366 +  show "\<rat> \<subseteq> ?S"
  1.1367 +  proof
  1.1368 +    fix x::real assume "x : \<rat>"
  1.1369 +    then obtain r where "x = of_rat r" unfolding Rats_def ..
  1.1370 +    have "of_rat r : ?S"
  1.1371 +      by (cases r)(auto simp add:of_rat_rat real_eq_of_int)
  1.1372 +    thus "x : ?S" using `x = of_rat r` by simp
  1.1373 +  qed
  1.1374 +next
  1.1375 +  show "?S \<subseteq> \<rat>"
  1.1376 +  proof(auto simp:Rats_def)
  1.1377 +    fix i j :: int assume "j \<noteq> 0"
  1.1378 +    hence "real i / real j = of_rat(Fract i j)"
  1.1379 +      by (simp add:of_rat_rat real_eq_of_int)
  1.1380 +    thus "real i / real j \<in> range of_rat" by blast
  1.1381 +  qed
  1.1382 +qed
  1.1383 +
  1.1384 +lemma Rats_eq_int_div_nat:
  1.1385 +  "\<rat> = { real(i::int)/real(n::nat) |i n. n \<noteq> 0}"
  1.1386 +proof(auto simp:Rats_eq_int_div_int)
  1.1387 +  fix i j::int assume "j \<noteq> 0"
  1.1388 +  show "EX (i'::int) (n::nat). real i/real j = real i'/real n \<and> 0<n"
  1.1389 +  proof cases
  1.1390 +    assume "j>0"
  1.1391 +    hence "real i/real j = real i/real(nat j) \<and> 0<nat j"
  1.1392 +      by (simp add: real_eq_of_int real_eq_of_nat of_nat_nat)
  1.1393 +    thus ?thesis by blast
  1.1394 +  next
  1.1395 +    assume "~ j>0"
  1.1396 +    hence "real i/real j = real(-i)/real(nat(-j)) \<and> 0<nat(-j)" using `j\<noteq>0`
  1.1397 +      by (simp add: real_eq_of_int real_eq_of_nat of_nat_nat)
  1.1398 +    thus ?thesis by blast
  1.1399 +  qed
  1.1400 +next
  1.1401 +  fix i::int and n::nat assume "0 < n"
  1.1402 +  hence "real i/real n = real i/real(int n) \<and> int n \<noteq> 0" by simp
  1.1403 +  thus "\<exists>(i'::int) j::int. real i/real n = real i'/real j \<and> j \<noteq> 0" by blast
  1.1404 +qed
  1.1405 +
  1.1406 +lemma Rats_abs_nat_div_natE:
  1.1407 +  assumes "x \<in> \<rat>"
  1.1408 +  obtains m n :: nat
  1.1409 +  where "n \<noteq> 0" and "\<bar>x\<bar> = real m / real n" and "gcd m n = 1"
  1.1410 +proof -
  1.1411 +  from `x \<in> \<rat>` obtain i::int and n::nat where "n \<noteq> 0" and "x = real i / real n"
  1.1412 +    by(auto simp add: Rats_eq_int_div_nat)
  1.1413 +  hence "\<bar>x\<bar> = real(nat(abs i)) / real n" by simp
  1.1414 +  then obtain m :: nat where x_rat: "\<bar>x\<bar> = real m / real n" by blast
  1.1415 +  let ?gcd = "gcd m n"
  1.1416 +  from `n\<noteq>0` have gcd: "?gcd \<noteq> 0" by simp
  1.1417 +  let ?k = "m div ?gcd"
  1.1418 +  let ?l = "n div ?gcd"
  1.1419 +  let ?gcd' = "gcd ?k ?l"
  1.1420 +  have "?gcd dvd m" .. then have gcd_k: "?gcd * ?k = m"
  1.1421 +    by (rule dvd_mult_div_cancel)
  1.1422 +  have "?gcd dvd n" .. then have gcd_l: "?gcd * ?l = n"
  1.1423 +    by (rule dvd_mult_div_cancel)
  1.1424 +  from `n\<noteq>0` and gcd_l have "?l \<noteq> 0" by (auto iff del: neq0_conv)
  1.1425 +  moreover
  1.1426 +  have "\<bar>x\<bar> = real ?k / real ?l"
  1.1427 +  proof -
  1.1428 +    from gcd have "real ?k / real ?l =
  1.1429 +        real (?gcd * ?k) / real (?gcd * ?l)" by simp
  1.1430 +    also from gcd_k and gcd_l have "\<dots> = real m / real n" by simp
  1.1431 +    also from x_rat have "\<dots> = \<bar>x\<bar>" ..
  1.1432 +    finally show ?thesis ..
  1.1433 +  qed
  1.1434 +  moreover
  1.1435 +  have "?gcd' = 1"
  1.1436 +  proof -
  1.1437 +    have "?gcd * ?gcd' = gcd (?gcd * ?k) (?gcd * ?l)"
  1.1438 +      by (rule gcd_mult_distrib_nat)
  1.1439 +    with gcd_k gcd_l have "?gcd * ?gcd' = ?gcd" by simp
  1.1440 +    with gcd show ?thesis by auto
  1.1441 +  qed
  1.1442 +  ultimately show ?thesis ..
  1.1443 +qed
  1.1444 +
  1.1445 +subsection{*Density of the Rational Reals in the Reals*}
  1.1446 +
  1.1447 +text{* This density proof is due to Stefan Richter and was ported by TN.  The
  1.1448 +original source is \emph{Real Analysis} by H.L. Royden.
  1.1449 +It employs the Archimedean property of the reals. *}
  1.1450 +
  1.1451 +lemma Rats_dense_in_real:
  1.1452 +  fixes x :: real
  1.1453 +  assumes "x < y" shows "\<exists>r\<in>\<rat>. x < r \<and> r < y"
  1.1454 +proof -
  1.1455 +  from `x<y` have "0 < y-x" by simp
  1.1456 +  with reals_Archimedean obtain q::nat 
  1.1457 +    where q: "inverse (real q) < y-x" and "0 < q" by auto
  1.1458 +  def p \<equiv> "ceiling (y * real q) - 1"
  1.1459 +  def r \<equiv> "of_int p / real q"
  1.1460 +  from q have "x < y - inverse (real q)" by simp
  1.1461 +  also have "y - inverse (real q) \<le> r"
  1.1462 +    unfolding r_def p_def
  1.1463 +    by (simp add: le_divide_eq left_diff_distrib le_of_int_ceiling `0 < q`)
  1.1464 +  finally have "x < r" .
  1.1465 +  moreover have "r < y"
  1.1466 +    unfolding r_def p_def
  1.1467 +    by (simp add: divide_less_eq diff_less_eq `0 < q`
  1.1468 +      less_ceiling_iff [symmetric])
  1.1469 +  moreover from r_def have "r \<in> \<rat>" by simp
  1.1470 +  ultimately show ?thesis by fast
  1.1471 +qed
  1.1472 +
  1.1473 +
  1.1474 +
  1.1475 +subsection{*Numerals and Arithmetic*}
  1.1476 +
  1.1477 +lemma [code_abbrev]:
  1.1478 +  "real_of_int (numeral k) = numeral k"
  1.1479 +  "real_of_int (neg_numeral k) = neg_numeral k"
  1.1480 +  by simp_all
  1.1481 +
  1.1482 +text{*Collapse applications of @{term real} to @{term number_of}*}
  1.1483 +lemma real_numeral [simp]:
  1.1484 +  "real (numeral v :: int) = numeral v"
  1.1485 +  "real (neg_numeral v :: int) = neg_numeral v"
  1.1486 +by (simp_all add: real_of_int_def)
  1.1487 +
  1.1488 +lemma real_of_nat_numeral [simp]:
  1.1489 +  "real (numeral v :: nat) = numeral v"
  1.1490 +by (simp add: real_of_nat_def)
  1.1491 +
  1.1492 +declaration {*
  1.1493 +  K (Lin_Arith.add_inj_thms [@{thm real_of_nat_le_iff} RS iffD2, @{thm real_of_nat_inject} RS iffD2]
  1.1494 +    (* not needed because x < (y::nat) can be rewritten as Suc x <= y: real_of_nat_less_iff RS iffD2 *)
  1.1495 +  #> Lin_Arith.add_inj_thms [@{thm real_of_int_le_iff} RS iffD2, @{thm real_of_int_inject} RS iffD2]
  1.1496 +    (* not needed because x < (y::int) can be rewritten as x + 1 <= y: real_of_int_less_iff RS iffD2 *)
  1.1497 +  #> Lin_Arith.add_simps [@{thm real_of_nat_zero}, @{thm real_of_nat_Suc}, @{thm real_of_nat_add},
  1.1498 +      @{thm real_of_nat_mult}, @{thm real_of_int_zero}, @{thm real_of_one},
  1.1499 +      @{thm real_of_int_add}, @{thm real_of_int_minus}, @{thm real_of_int_diff},
  1.1500 +      @{thm real_of_int_mult}, @{thm real_of_int_of_nat_eq},
  1.1501 +      @{thm real_of_nat_numeral}, @{thm real_numeral(1)}, @{thm real_numeral(2)}]
  1.1502 +  #> Lin_Arith.add_inj_const (@{const_name real}, @{typ "nat \<Rightarrow> real"})
  1.1503 +  #> Lin_Arith.add_inj_const (@{const_name real}, @{typ "int \<Rightarrow> real"}))
  1.1504 +*}
  1.1505 +
  1.1506 +
  1.1507 +subsection{* Simprules combining x+y and 0: ARE THEY NEEDED?*}
  1.1508 +
  1.1509 +lemma real_add_minus_iff [simp]: "(x + - a = (0::real)) = (x=a)" 
  1.1510 +by arith
  1.1511 +
  1.1512 +text {* FIXME: redundant with @{text add_eq_0_iff} below *}
  1.1513 +lemma real_add_eq_0_iff: "(x+y = (0::real)) = (y = -x)"
  1.1514 +by auto
  1.1515 +
  1.1516 +lemma real_add_less_0_iff: "(x+y < (0::real)) = (y < -x)"
  1.1517 +by auto
  1.1518 +
  1.1519 +lemma real_0_less_add_iff: "((0::real) < x+y) = (-x < y)"
  1.1520 +by auto
  1.1521 +
  1.1522 +lemma real_add_le_0_iff: "(x+y \<le> (0::real)) = (y \<le> -x)"
  1.1523 +by auto
  1.1524 +
  1.1525 +lemma real_0_le_add_iff: "((0::real) \<le> x+y) = (-x \<le> y)"
  1.1526 +by auto
  1.1527 +
  1.1528 +subsection {* Lemmas about powers *}
  1.1529 +
  1.1530 +text {* FIXME: declare this in Rings.thy or not at all *}
  1.1531 +declare abs_mult_self [simp]
  1.1532 +
  1.1533 +(* used by Import/HOL/real.imp *)
  1.1534 +lemma two_realpow_ge_one: "(1::real) \<le> 2 ^ n"
  1.1535 +by simp
  1.1536 +
  1.1537 +lemma two_realpow_gt [simp]: "real (n::nat) < 2 ^ n"
  1.1538 +apply (induct "n")
  1.1539 +apply (auto simp add: real_of_nat_Suc)
  1.1540 +apply (subst mult_2)
  1.1541 +apply (erule add_less_le_mono)
  1.1542 +apply (rule two_realpow_ge_one)
  1.1543 +done
  1.1544 +
  1.1545 +text {* TODO: no longer real-specific; rename and move elsewhere *}
  1.1546 +lemma realpow_Suc_le_self:
  1.1547 +  fixes r :: "'a::linordered_semidom"
  1.1548 +  shows "[| 0 \<le> r; r \<le> 1 |] ==> r ^ Suc n \<le> r"
  1.1549 +by (insert power_decreasing [of 1 "Suc n" r], simp)
  1.1550 +
  1.1551 +text {* TODO: no longer real-specific; rename and move elsewhere *}
  1.1552 +lemma realpow_minus_mult:
  1.1553 +  fixes x :: "'a::monoid_mult"
  1.1554 +  shows "0 < n \<Longrightarrow> x ^ (n - 1) * x = x ^ n"
  1.1555 +by (simp add: power_commutes split add: nat_diff_split)
  1.1556 +
  1.1557 +text {* FIXME: declare this [simp] for all types, or not at all *}
  1.1558 +lemma real_two_squares_add_zero_iff [simp]:
  1.1559 +  "(x * x + y * y = 0) = ((x::real) = 0 \<and> y = 0)"
  1.1560 +by (rule sum_squares_eq_zero_iff)
  1.1561 +
  1.1562 +text {* FIXME: declare this [simp] for all types, or not at all *}
  1.1563 +lemma realpow_two_sum_zero_iff [simp]:
  1.1564 +     "(x ^ 2 + y ^ 2 = (0::real)) = (x = 0 & y = 0)"
  1.1565 +by (rule sum_power2_eq_zero_iff)
  1.1566 +
  1.1567 +lemma real_minus_mult_self_le [simp]: "-(u * u) \<le> (x * (x::real))"
  1.1568 +by (rule_tac y = 0 in order_trans, auto)
  1.1569 +
  1.1570 +lemma realpow_square_minus_le [simp]: "-(u ^ 2) \<le> (x::real) ^ 2"
  1.1571 +by (auto simp add: power2_eq_square)
  1.1572 +
  1.1573 +
  1.1574 +lemma numeral_power_le_real_of_nat_cancel_iff[simp]:
  1.1575 +  "(numeral x::real) ^ n \<le> real a \<longleftrightarrow> (numeral x::nat) ^ n \<le> a"
  1.1576 +  unfolding real_of_nat_le_iff[symmetric] by simp
  1.1577 +
  1.1578 +lemma real_of_nat_le_numeral_power_cancel_iff[simp]:
  1.1579 +  "real a \<le> (numeral x::real) ^ n \<longleftrightarrow> a \<le> (numeral x::nat) ^ n"
  1.1580 +  unfolding real_of_nat_le_iff[symmetric] by simp
  1.1581 +
  1.1582 +lemma numeral_power_le_real_of_int_cancel_iff[simp]:
  1.1583 +  "(numeral x::real) ^ n \<le> real a \<longleftrightarrow> (numeral x::int) ^ n \<le> a"
  1.1584 +  unfolding real_of_int_le_iff[symmetric] by simp
  1.1585 +
  1.1586 +lemma real_of_int_le_numeral_power_cancel_iff[simp]:
  1.1587 +  "real a \<le> (numeral x::real) ^ n \<longleftrightarrow> a \<le> (numeral x::int) ^ n"
  1.1588 +  unfolding real_of_int_le_iff[symmetric] by simp
  1.1589 +
  1.1590 +lemma neg_numeral_power_le_real_of_int_cancel_iff[simp]:
  1.1591 +  "(neg_numeral x::real) ^ n \<le> real a \<longleftrightarrow> (neg_numeral x::int) ^ n \<le> a"
  1.1592 +  unfolding real_of_int_le_iff[symmetric] by simp
  1.1593 +
  1.1594 +lemma real_of_int_le_neg_numeral_power_cancel_iff[simp]:
  1.1595 +  "real a \<le> (neg_numeral x::real) ^ n \<longleftrightarrow> a \<le> (neg_numeral x::int) ^ n"
  1.1596 +  unfolding real_of_int_le_iff[symmetric] by simp
  1.1597 +
  1.1598 +subsection{*Density of the Reals*}
  1.1599 +
  1.1600 +lemma real_lbound_gt_zero:
  1.1601 +     "[| (0::real) < d1; 0 < d2 |] ==> \<exists>e. 0 < e & e < d1 & e < d2"
  1.1602 +apply (rule_tac x = " (min d1 d2) /2" in exI)
  1.1603 +apply (simp add: min_def)
  1.1604 +done
  1.1605 +
  1.1606 +
  1.1607 +text{*Similar results are proved in @{text Fields}*}
  1.1608 +lemma real_less_half_sum: "x < y ==> x < (x+y) / (2::real)"
  1.1609 +  by auto
  1.1610 +
  1.1611 +lemma real_gt_half_sum: "x < y ==> (x+y)/(2::real) < y"
  1.1612 +  by auto
  1.1613 +
  1.1614 +lemma real_sum_of_halves: "x/2 + x/2 = (x::real)"
  1.1615 +  by simp
  1.1616 +
  1.1617 +subsection{*Absolute Value Function for the Reals*}
  1.1618 +
  1.1619 +lemma abs_minus_add_cancel: "abs(x + (-y)) = abs (y + (-(x::real)))"
  1.1620 +by (simp add: abs_if)
  1.1621 +
  1.1622 +(* FIXME: redundant, but used by Integration/RealRandVar.thy in AFP *)
  1.1623 +lemma abs_le_interval_iff: "(abs x \<le> r) = (-r\<le>x & x\<le>(r::real))"
  1.1624 +by (force simp add: abs_le_iff)
  1.1625 +
  1.1626 +lemma abs_add_one_gt_zero: "(0::real) < 1 + abs(x)"
  1.1627 +by (simp add: abs_if)
  1.1628 +
  1.1629 +lemma abs_real_of_nat_cancel [simp]: "abs (real x) = real (x::nat)"
  1.1630 +by (rule abs_of_nonneg [OF real_of_nat_ge_zero])
  1.1631 +
  1.1632 +lemma abs_add_one_not_less_self: "~ abs(x) + (1::real) < x"
  1.1633 +by simp
  1.1634 + 
  1.1635 +lemma abs_sum_triangle_ineq: "abs ((x::real) + y + (-l + -m)) \<le> abs(x + -l) + abs(y + -m)"
  1.1636 +by simp
  1.1637 +
  1.1638 +
  1.1639 +subsection{*Floor and Ceiling Functions from the Reals to the Integers*}
  1.1640 +
  1.1641 +(* FIXME: theorems for negative numerals *)
  1.1642 +lemma numeral_less_real_of_int_iff [simp]:
  1.1643 +     "((numeral n) < real (m::int)) = (numeral n < m)"
  1.1644 +apply auto
  1.1645 +apply (rule real_of_int_less_iff [THEN iffD1])
  1.1646 +apply (drule_tac [2] real_of_int_less_iff [THEN iffD2], auto)
  1.1647 +done
  1.1648 +
  1.1649 +lemma numeral_less_real_of_int_iff2 [simp]:
  1.1650 +     "(real (m::int) < (numeral n)) = (m < numeral n)"
  1.1651 +apply auto
  1.1652 +apply (rule real_of_int_less_iff [THEN iffD1])
  1.1653 +apply (drule_tac [2] real_of_int_less_iff [THEN iffD2], auto)
  1.1654 +done
  1.1655 +
  1.1656 +lemma numeral_le_real_of_int_iff [simp]:
  1.1657 +     "((numeral n) \<le> real (m::int)) = (numeral n \<le> m)"
  1.1658 +by (simp add: linorder_not_less [symmetric])
  1.1659 +
  1.1660 +lemma numeral_le_real_of_int_iff2 [simp]:
  1.1661 +     "(real (m::int) \<le> (numeral n)) = (m \<le> numeral n)"
  1.1662 +by (simp add: linorder_not_less [symmetric])
  1.1663 +
  1.1664 +lemma floor_real_of_nat [simp]: "floor (real (n::nat)) = int n"
  1.1665 +unfolding real_of_nat_def by simp
  1.1666 +
  1.1667 +lemma floor_minus_real_of_nat [simp]: "floor (- real (n::nat)) = - int n"
  1.1668 +unfolding real_of_nat_def by (simp add: floor_minus)
  1.1669 +
  1.1670 +lemma floor_real_of_int [simp]: "floor (real (n::int)) = n"
  1.1671 +unfolding real_of_int_def by simp
  1.1672 +
  1.1673 +lemma floor_minus_real_of_int [simp]: "floor (- real (n::int)) = - n"
  1.1674 +unfolding real_of_int_def by (simp add: floor_minus)
  1.1675 +
  1.1676 +lemma real_lb_ub_int: " \<exists>n::int. real n \<le> r & r < real (n+1)"
  1.1677 +unfolding real_of_int_def by (rule floor_exists)
  1.1678 +
  1.1679 +lemma lemma_floor:
  1.1680 +  assumes a1: "real m \<le> r" and a2: "r < real n + 1"
  1.1681 +  shows "m \<le> (n::int)"
  1.1682 +proof -
  1.1683 +  have "real m < real n + 1" using a1 a2 by (rule order_le_less_trans)
  1.1684 +  also have "... = real (n + 1)" by simp
  1.1685 +  finally have "m < n + 1" by (simp only: real_of_int_less_iff)
  1.1686 +  thus ?thesis by arith
  1.1687 +qed
  1.1688 +
  1.1689 +lemma real_of_int_floor_le [simp]: "real (floor r) \<le> r"
  1.1690 +unfolding real_of_int_def by (rule of_int_floor_le)
  1.1691 +
  1.1692 +lemma lemma_floor2: "real n < real (x::int) + 1 ==> n \<le> x"
  1.1693 +by (auto intro: lemma_floor)
  1.1694 +
  1.1695 +lemma real_of_int_floor_cancel [simp]:
  1.1696 +    "(real (floor x) = x) = (\<exists>n::int. x = real n)"
  1.1697 +  using floor_real_of_int by metis
  1.1698 +
  1.1699 +lemma floor_eq: "[| real n < x; x < real n + 1 |] ==> floor x = n"
  1.1700 +  unfolding real_of_int_def using floor_unique [of n x] by simp
  1.1701 +
  1.1702 +lemma floor_eq2: "[| real n \<le> x; x < real n + 1 |] ==> floor x = n"
  1.1703 +  unfolding real_of_int_def by (rule floor_unique)
  1.1704 +
  1.1705 +lemma floor_eq3: "[| real n < x; x < real (Suc n) |] ==> nat(floor x) = n"
  1.1706 +apply (rule inj_int [THEN injD])
  1.1707 +apply (simp add: real_of_nat_Suc)
  1.1708 +apply (simp add: real_of_nat_Suc floor_eq floor_eq [where n = "int n"])
  1.1709 +done
  1.1710 +
  1.1711 +lemma floor_eq4: "[| real n \<le> x; x < real (Suc n) |] ==> nat(floor x) = n"
  1.1712 +apply (drule order_le_imp_less_or_eq)
  1.1713 +apply (auto intro: floor_eq3)
  1.1714 +done
  1.1715 +
  1.1716 +lemma real_of_int_floor_ge_diff_one [simp]: "r - 1 \<le> real(floor r)"
  1.1717 +  unfolding real_of_int_def using floor_correct [of r] by simp
  1.1718 +
  1.1719 +lemma real_of_int_floor_gt_diff_one [simp]: "r - 1 < real(floor r)"
  1.1720 +  unfolding real_of_int_def using floor_correct [of r] by simp
  1.1721 +
  1.1722 +lemma real_of_int_floor_add_one_ge [simp]: "r \<le> real(floor r) + 1"
  1.1723 +  unfolding real_of_int_def using floor_correct [of r] by simp
  1.1724 +
  1.1725 +lemma real_of_int_floor_add_one_gt [simp]: "r < real(floor r) + 1"
  1.1726 +  unfolding real_of_int_def using floor_correct [of r] by simp
  1.1727 +
  1.1728 +lemma le_floor: "real a <= x ==> a <= floor x"
  1.1729 +  unfolding real_of_int_def by (simp add: le_floor_iff)
  1.1730 +
  1.1731 +lemma real_le_floor: "a <= floor x ==> real a <= x"
  1.1732 +  unfolding real_of_int_def by (simp add: le_floor_iff)
  1.1733 +
  1.1734 +lemma le_floor_eq: "(a <= floor x) = (real a <= x)"
  1.1735 +  unfolding real_of_int_def by (rule le_floor_iff)
  1.1736 +
  1.1737 +lemma floor_less_eq: "(floor x < a) = (x < real a)"
  1.1738 +  unfolding real_of_int_def by (rule floor_less_iff)
  1.1739 +
  1.1740 +lemma less_floor_eq: "(a < floor x) = (real a + 1 <= x)"
  1.1741 +  unfolding real_of_int_def by (rule less_floor_iff)
  1.1742 +
  1.1743 +lemma floor_le_eq: "(floor x <= a) = (x < real a + 1)"
  1.1744 +  unfolding real_of_int_def by (rule floor_le_iff)
  1.1745 +
  1.1746 +lemma floor_add [simp]: "floor (x + real a) = floor x + a"
  1.1747 +  unfolding real_of_int_def by (rule floor_add_of_int)
  1.1748 +
  1.1749 +lemma floor_subtract [simp]: "floor (x - real a) = floor x - a"
  1.1750 +  unfolding real_of_int_def by (rule floor_diff_of_int)
  1.1751 +
  1.1752 +lemma le_mult_floor:
  1.1753 +  assumes "0 \<le> (a :: real)" and "0 \<le> b"
  1.1754 +  shows "floor a * floor b \<le> floor (a * b)"
  1.1755 +proof -
  1.1756 +  have "real (floor a) \<le> a"
  1.1757 +    and "real (floor b) \<le> b" by auto
  1.1758 +  hence "real (floor a * floor b) \<le> a * b"
  1.1759 +    using assms by (auto intro!: mult_mono)
  1.1760 +  also have "a * b < real (floor (a * b) + 1)" by auto
  1.1761 +  finally show ?thesis unfolding real_of_int_less_iff by simp
  1.1762 +qed
  1.1763 +
  1.1764 +lemma floor_divide_eq_div:
  1.1765 +  "floor (real a / real b) = a div b"
  1.1766 +proof cases
  1.1767 +  assume "b \<noteq> 0 \<or> b dvd a"
  1.1768 +  with real_of_int_div3[of a b] show ?thesis
  1.1769 +    by (auto simp: real_of_int_div[symmetric] intro!: floor_eq2 real_of_int_div4 neq_le_trans)
  1.1770 +       (metis add_left_cancel zero_neq_one real_of_int_div_aux real_of_int_inject
  1.1771 +              real_of_int_zero_cancel right_inverse_eq div_self mod_div_trivial)
  1.1772 +qed (auto simp: real_of_int_div)
  1.1773 +
  1.1774 +lemma ceiling_real_of_nat [simp]: "ceiling (real (n::nat)) = int n"
  1.1775 +  unfolding real_of_nat_def by simp
  1.1776 +
  1.1777 +lemma real_of_int_ceiling_ge [simp]: "r \<le> real (ceiling r)"
  1.1778 +  unfolding real_of_int_def by (rule le_of_int_ceiling)
  1.1779 +
  1.1780 +lemma ceiling_real_of_int [simp]: "ceiling (real (n::int)) = n"
  1.1781 +  unfolding real_of_int_def by simp
  1.1782 +
  1.1783 +lemma real_of_int_ceiling_cancel [simp]:
  1.1784 +     "(real (ceiling x) = x) = (\<exists>n::int. x = real n)"
  1.1785 +  using ceiling_real_of_int by metis
  1.1786 +
  1.1787 +lemma ceiling_eq: "[| real n < x; x < real n + 1 |] ==> ceiling x = n + 1"
  1.1788 +  unfolding real_of_int_def using ceiling_unique [of "n + 1" x] by simp
  1.1789 +
  1.1790 +lemma ceiling_eq2: "[| real n < x; x \<le> real n + 1 |] ==> ceiling x = n + 1"
  1.1791 +  unfolding real_of_int_def using ceiling_unique [of "n + 1" x] by simp
  1.1792 +
  1.1793 +lemma ceiling_eq3: "[| real n - 1 < x; x \<le> real n  |] ==> ceiling x = n"
  1.1794 +  unfolding real_of_int_def using ceiling_unique [of n x] by simp
  1.1795 +
  1.1796 +lemma real_of_int_ceiling_diff_one_le [simp]: "real (ceiling r) - 1 \<le> r"
  1.1797 +  unfolding real_of_int_def using ceiling_correct [of r] by simp
  1.1798 +
  1.1799 +lemma real_of_int_ceiling_le_add_one [simp]: "real (ceiling r) \<le> r + 1"
  1.1800 +  unfolding real_of_int_def using ceiling_correct [of r] by simp
  1.1801 +
  1.1802 +lemma ceiling_le: "x <= real a ==> ceiling x <= a"
  1.1803 +  unfolding real_of_int_def by (simp add: ceiling_le_iff)
  1.1804 +
  1.1805 +lemma ceiling_le_real: "ceiling x <= a ==> x <= real a"
  1.1806 +  unfolding real_of_int_def by (simp add: ceiling_le_iff)
  1.1807 +
  1.1808 +lemma ceiling_le_eq: "(ceiling x <= a) = (x <= real a)"
  1.1809 +  unfolding real_of_int_def by (rule ceiling_le_iff)
  1.1810 +
  1.1811 +lemma less_ceiling_eq: "(a < ceiling x) = (real a < x)"
  1.1812 +  unfolding real_of_int_def by (rule less_ceiling_iff)
  1.1813 +
  1.1814 +lemma ceiling_less_eq: "(ceiling x < a) = (x <= real a - 1)"
  1.1815 +  unfolding real_of_int_def by (rule ceiling_less_iff)
  1.1816 +
  1.1817 +lemma le_ceiling_eq: "(a <= ceiling x) = (real a - 1 < x)"
  1.1818 +  unfolding real_of_int_def by (rule le_ceiling_iff)
  1.1819 +
  1.1820 +lemma ceiling_add [simp]: "ceiling (x + real a) = ceiling x + a"
  1.1821 +  unfolding real_of_int_def by (rule ceiling_add_of_int)
  1.1822 +
  1.1823 +lemma ceiling_subtract [simp]: "ceiling (x - real a) = ceiling x - a"
  1.1824 +  unfolding real_of_int_def by (rule ceiling_diff_of_int)
  1.1825 +
  1.1826 +
  1.1827 +subsubsection {* Versions for the natural numbers *}
  1.1828 +
  1.1829 +definition
  1.1830 +  natfloor :: "real => nat" where
  1.1831 +  "natfloor x = nat(floor x)"
  1.1832 +
  1.1833 +definition
  1.1834 +  natceiling :: "real => nat" where
  1.1835 +  "natceiling x = nat(ceiling x)"
  1.1836 +
  1.1837 +lemma natfloor_zero [simp]: "natfloor 0 = 0"
  1.1838 +  by (unfold natfloor_def, simp)
  1.1839 +
  1.1840 +lemma natfloor_one [simp]: "natfloor 1 = 1"
  1.1841 +  by (unfold natfloor_def, simp)
  1.1842 +
  1.1843 +lemma zero_le_natfloor [simp]: "0 <= natfloor x"
  1.1844 +  by (unfold natfloor_def, simp)
  1.1845 +
  1.1846 +lemma natfloor_numeral_eq [simp]: "natfloor (numeral n) = numeral n"
  1.1847 +  by (unfold natfloor_def, simp)
  1.1848 +
  1.1849 +lemma natfloor_real_of_nat [simp]: "natfloor(real n) = n"
  1.1850 +  by (unfold natfloor_def, simp)
  1.1851 +
  1.1852 +lemma real_natfloor_le: "0 <= x ==> real(natfloor x) <= x"
  1.1853 +  by (unfold natfloor_def, simp)
  1.1854 +
  1.1855 +lemma natfloor_neg: "x <= 0 ==> natfloor x = 0"
  1.1856 +  unfolding natfloor_def by simp
  1.1857 +
  1.1858 +lemma natfloor_mono: "x <= y ==> natfloor x <= natfloor y"
  1.1859 +  unfolding natfloor_def by (intro nat_mono floor_mono)
  1.1860 +
  1.1861 +lemma le_natfloor: "real x <= a ==> x <= natfloor a"
  1.1862 +  apply (unfold natfloor_def)
  1.1863 +  apply (subst nat_int [THEN sym])
  1.1864 +  apply (rule nat_mono)
  1.1865 +  apply (rule le_floor)
  1.1866 +  apply simp
  1.1867 +done
  1.1868 +
  1.1869 +lemma natfloor_less_iff: "0 \<le> x \<Longrightarrow> natfloor x < n \<longleftrightarrow> x < real n"
  1.1870 +  unfolding natfloor_def real_of_nat_def
  1.1871 +  by (simp add: nat_less_iff floor_less_iff)
  1.1872 +
  1.1873 +lemma less_natfloor:
  1.1874 +  assumes "0 \<le> x" and "x < real (n :: nat)"
  1.1875 +  shows "natfloor x < n"
  1.1876 +  using assms by (simp add: natfloor_less_iff)
  1.1877 +
  1.1878 +lemma le_natfloor_eq: "0 <= x ==> (a <= natfloor x) = (real a <= x)"
  1.1879 +  apply (rule iffI)
  1.1880 +  apply (rule order_trans)
  1.1881 +  prefer 2
  1.1882 +  apply (erule real_natfloor_le)
  1.1883 +  apply (subst real_of_nat_le_iff)
  1.1884 +  apply assumption
  1.1885 +  apply (erule le_natfloor)
  1.1886 +done
  1.1887 +
  1.1888 +lemma le_natfloor_eq_numeral [simp]:
  1.1889 +    "~ neg((numeral n)::int) ==> 0 <= x ==>
  1.1890 +      (numeral n <= natfloor x) = (numeral n <= x)"
  1.1891 +  apply (subst le_natfloor_eq, assumption)
  1.1892 +  apply simp
  1.1893 +done
  1.1894 +
  1.1895 +lemma le_natfloor_eq_one [simp]: "(1 <= natfloor x) = (1 <= x)"
  1.1896 +  apply (case_tac "0 <= x")
  1.1897 +  apply (subst le_natfloor_eq, assumption, simp)
  1.1898 +  apply (rule iffI)
  1.1899 +  apply (subgoal_tac "natfloor x <= natfloor 0")
  1.1900 +  apply simp
  1.1901 +  apply (rule natfloor_mono)
  1.1902 +  apply simp
  1.1903 +  apply simp
  1.1904 +done
  1.1905 +
  1.1906 +lemma natfloor_eq: "real n <= x ==> x < real n + 1 ==> natfloor x = n"
  1.1907 +  unfolding natfloor_def by (simp add: floor_eq2 [where n="int n"])
  1.1908 +
  1.1909 +lemma real_natfloor_add_one_gt: "x < real(natfloor x) + 1"
  1.1910 +  apply (case_tac "0 <= x")
  1.1911 +  apply (unfold natfloor_def)
  1.1912 +  apply simp
  1.1913 +  apply simp_all
  1.1914 +done
  1.1915 +
  1.1916 +lemma real_natfloor_gt_diff_one: "x - 1 < real(natfloor x)"
  1.1917 +using real_natfloor_add_one_gt by (simp add: algebra_simps)
  1.1918 +
  1.1919 +lemma ge_natfloor_plus_one_imp_gt: "natfloor z + 1 <= n ==> z < real n"
  1.1920 +  apply (subgoal_tac "z < real(natfloor z) + 1")
  1.1921 +  apply arith
  1.1922 +  apply (rule real_natfloor_add_one_gt)
  1.1923 +done
  1.1924 +
  1.1925 +lemma natfloor_add [simp]: "0 <= x ==> natfloor (x + real a) = natfloor x + a"
  1.1926 +  unfolding natfloor_def
  1.1927 +  unfolding real_of_int_of_nat_eq [symmetric] floor_add
  1.1928 +  by (simp add: nat_add_distrib)
  1.1929 +
  1.1930 +lemma natfloor_add_numeral [simp]:
  1.1931 +    "~neg ((numeral n)::int) ==> 0 <= x ==>
  1.1932 +      natfloor (x + numeral n) = natfloor x + numeral n"
  1.1933 +  by (simp add: natfloor_add [symmetric])
  1.1934 +
  1.1935 +lemma natfloor_add_one: "0 <= x ==> natfloor(x + 1) = natfloor x + 1"
  1.1936 +  by (simp add: natfloor_add [symmetric] del: One_nat_def)
  1.1937 +
  1.1938 +lemma natfloor_subtract [simp]:
  1.1939 +    "natfloor(x - real a) = natfloor x - a"
  1.1940 +  unfolding natfloor_def real_of_int_of_nat_eq [symmetric] floor_subtract
  1.1941 +  by simp
  1.1942 +
  1.1943 +lemma natfloor_div_nat:
  1.1944 +  assumes "1 <= x" and "y > 0"
  1.1945 +  shows "natfloor (x / real y) = natfloor x div y"
  1.1946 +proof (rule natfloor_eq)
  1.1947 +  have "(natfloor x) div y * y \<le> natfloor x"
  1.1948 +    by (rule add_leD1 [where k="natfloor x mod y"], simp)
  1.1949 +  thus "real (natfloor x div y) \<le> x / real y"
  1.1950 +    using assms by (simp add: le_divide_eq le_natfloor_eq)
  1.1951 +  have "natfloor x < (natfloor x) div y * y + y"
  1.1952 +    apply (subst mod_div_equality [symmetric])
  1.1953 +    apply (rule add_strict_left_mono)
  1.1954 +    apply (rule mod_less_divisor)
  1.1955 +    apply fact
  1.1956 +    done
  1.1957 +  thus "x / real y < real (natfloor x div y) + 1"
  1.1958 +    using assms
  1.1959 +    by (simp add: divide_less_eq natfloor_less_iff distrib_right)
  1.1960 +qed
  1.1961 +
  1.1962 +lemma le_mult_natfloor:
  1.1963 +  shows "natfloor a * natfloor b \<le> natfloor (a * b)"
  1.1964 +  by (cases "0 <= a & 0 <= b")
  1.1965 +    (auto simp add: le_natfloor_eq mult_nonneg_nonneg mult_mono' real_natfloor_le natfloor_neg)
  1.1966 +
  1.1967 +lemma natceiling_zero [simp]: "natceiling 0 = 0"
  1.1968 +  by (unfold natceiling_def, simp)
  1.1969 +
  1.1970 +lemma natceiling_one [simp]: "natceiling 1 = 1"
  1.1971 +  by (unfold natceiling_def, simp)
  1.1972 +
  1.1973 +lemma zero_le_natceiling [simp]: "0 <= natceiling x"
  1.1974 +  by (unfold natceiling_def, simp)
  1.1975 +
  1.1976 +lemma natceiling_numeral_eq [simp]: "natceiling (numeral n) = numeral n"
  1.1977 +  by (unfold natceiling_def, simp)
  1.1978 +
  1.1979 +lemma natceiling_real_of_nat [simp]: "natceiling(real n) = n"
  1.1980 +  by (unfold natceiling_def, simp)
  1.1981 +
  1.1982 +lemma real_natceiling_ge: "x <= real(natceiling x)"
  1.1983 +  unfolding natceiling_def by (cases "x < 0", simp_all)
  1.1984 +
  1.1985 +lemma natceiling_neg: "x <= 0 ==> natceiling x = 0"
  1.1986 +  unfolding natceiling_def by simp
  1.1987 +
  1.1988 +lemma natceiling_mono: "x <= y ==> natceiling x <= natceiling y"
  1.1989 +  unfolding natceiling_def by (intro nat_mono ceiling_mono)
  1.1990 +
  1.1991 +lemma natceiling_le: "x <= real a ==> natceiling x <= a"
  1.1992 +  unfolding natceiling_def real_of_nat_def
  1.1993 +  by (simp add: nat_le_iff ceiling_le_iff)
  1.1994 +
  1.1995 +lemma natceiling_le_eq: "(natceiling x <= a) = (x <= real a)"
  1.1996 +  unfolding natceiling_def real_of_nat_def
  1.1997 +  by (simp add: nat_le_iff ceiling_le_iff)
  1.1998 +
  1.1999 +lemma natceiling_le_eq_numeral [simp]:
  1.2000 +    "~ neg((numeral n)::int) ==>
  1.2001 +      (natceiling x <= numeral n) = (x <= numeral n)"
  1.2002 +  by (simp add: natceiling_le_eq)
  1.2003 +
  1.2004 +lemma natceiling_le_eq_one: "(natceiling x <= 1) = (x <= 1)"
  1.2005 +  unfolding natceiling_def
  1.2006 +  by (simp add: nat_le_iff ceiling_le_iff)
  1.2007 +
  1.2008 +lemma natceiling_eq: "real n < x ==> x <= real n + 1 ==> natceiling x = n + 1"
  1.2009 +  unfolding natceiling_def
  1.2010 +  by (simp add: ceiling_eq2 [where n="int n"])
  1.2011 +
  1.2012 +lemma natceiling_add [simp]: "0 <= x ==>
  1.2013 +    natceiling (x + real a) = natceiling x + a"
  1.2014 +  unfolding natceiling_def
  1.2015 +  unfolding real_of_int_of_nat_eq [symmetric] ceiling_add
  1.2016 +  by (simp add: nat_add_distrib)
  1.2017 +
  1.2018 +lemma natceiling_add_numeral [simp]:
  1.2019 +    "~ neg ((numeral n)::int) ==> 0 <= x ==>
  1.2020 +      natceiling (x + numeral n) = natceiling x + numeral n"
  1.2021 +  by (simp add: natceiling_add [symmetric])
  1.2022 +
  1.2023 +lemma natceiling_add_one: "0 <= x ==> natceiling(x + 1) = natceiling x + 1"
  1.2024 +  by (simp add: natceiling_add [symmetric] del: One_nat_def)
  1.2025 +
  1.2026 +lemma natceiling_subtract [simp]: "natceiling(x - real a) = natceiling x - a"
  1.2027 +  unfolding natceiling_def real_of_int_of_nat_eq [symmetric] ceiling_subtract
  1.2028 +  by simp
  1.2029 +
  1.2030 +subsection {* Exponentiation with floor *}
  1.2031 +
  1.2032 +lemma floor_power:
  1.2033 +  assumes "x = real (floor x)"
  1.2034 +  shows "floor (x ^ n) = floor x ^ n"
  1.2035 +proof -
  1.2036 +  have *: "x ^ n = real (floor x ^ n)"
  1.2037 +    using assms by (induct n arbitrary: x) simp_all
  1.2038 +  show ?thesis unfolding real_of_int_inject[symmetric]
  1.2039 +    unfolding * floor_real_of_int ..
  1.2040 +qed
  1.2041 +
  1.2042 +lemma natfloor_power:
  1.2043 +  assumes "x = real (natfloor x)"
  1.2044 +  shows "natfloor (x ^ n) = natfloor x ^ n"
  1.2045 +proof -
  1.2046 +  from assms have "0 \<le> floor x" by auto
  1.2047 +  note assms[unfolded natfloor_def real_nat_eq_real[OF `0 \<le> floor x`]]
  1.2048 +  from floor_power[OF this]
  1.2049 +  show ?thesis unfolding natfloor_def nat_power_eq[OF `0 \<le> floor x`, symmetric]
  1.2050 +    by simp
  1.2051 +qed
  1.2052 +
  1.2053 +
  1.2054 +subsection {* Implementation of rational real numbers *}
  1.2055 +
  1.2056 +text {* Formal constructor *}
  1.2057 +
  1.2058 +definition Ratreal :: "rat \<Rightarrow> real" where
  1.2059 +  [code_abbrev, simp]: "Ratreal = of_rat"
  1.2060 +
  1.2061 +code_datatype Ratreal
  1.2062 +
  1.2063 +
  1.2064 +text {* Numerals *}
  1.2065 +
  1.2066 +lemma [code_abbrev]:
  1.2067 +  "(of_rat (of_int a) :: real) = of_int a"
  1.2068 +  by simp
  1.2069 +
  1.2070 +lemma [code_abbrev]:
  1.2071 +  "(of_rat 0 :: real) = 0"
  1.2072 +  by simp
  1.2073 +
  1.2074 +lemma [code_abbrev]:
  1.2075 +  "(of_rat 1 :: real) = 1"
  1.2076 +  by simp
  1.2077 +
  1.2078 +lemma [code_abbrev]:
  1.2079 +  "(of_rat (numeral k) :: real) = numeral k"
  1.2080 +  by simp
  1.2081 +
  1.2082 +lemma [code_abbrev]:
  1.2083 +  "(of_rat (neg_numeral k) :: real) = neg_numeral k"
  1.2084 +  by simp
  1.2085 +
  1.2086 +lemma [code_post]:
  1.2087 +  "(of_rat (0 / r)  :: real) = 0"
  1.2088 +  "(of_rat (r / 0)  :: real) = 0"
  1.2089 +  "(of_rat (1 / 1)  :: real) = 1"
  1.2090 +  "(of_rat (numeral k / 1) :: real) = numeral k"
  1.2091 +  "(of_rat (neg_numeral k / 1) :: real) = neg_numeral k"
  1.2092 +  "(of_rat (1 / numeral k) :: real) = 1 / numeral k"
  1.2093 +  "(of_rat (1 / neg_numeral k) :: real) = 1 / neg_numeral k"
  1.2094 +  "(of_rat (numeral k / numeral l)  :: real) = numeral k / numeral l"
  1.2095 +  "(of_rat (numeral k / neg_numeral l)  :: real) = numeral k / neg_numeral l"
  1.2096 +  "(of_rat (neg_numeral k / numeral l)  :: real) = neg_numeral k / numeral l"
  1.2097 +  "(of_rat (neg_numeral k / neg_numeral l)  :: real) = neg_numeral k / neg_numeral l"
  1.2098 +  by (simp_all add: of_rat_divide)
  1.2099 +
  1.2100 +
  1.2101 +text {* Operations *}
  1.2102 +
  1.2103 +lemma zero_real_code [code]:
  1.2104 +  "0 = Ratreal 0"
  1.2105 +by simp
  1.2106 +
  1.2107 +lemma one_real_code [code]:
  1.2108 +  "1 = Ratreal 1"
  1.2109 +by simp
  1.2110 +
  1.2111 +instantiation real :: equal
  1.2112 +begin
  1.2113 +
  1.2114 +definition "HOL.equal (x\<Colon>real) y \<longleftrightarrow> x - y = 0"
  1.2115 +
  1.2116 +instance proof
  1.2117 +qed (simp add: equal_real_def)
  1.2118 +
  1.2119 +lemma real_equal_code [code]:
  1.2120 +  "HOL.equal (Ratreal x) (Ratreal y) \<longleftrightarrow> HOL.equal x y"
  1.2121 +  by (simp add: equal_real_def equal)
  1.2122 +
  1.2123 +lemma [code nbe]:
  1.2124 +  "HOL.equal (x::real) x \<longleftrightarrow> True"
  1.2125 +  by (rule equal_refl)
  1.2126 +
  1.2127 +end
  1.2128 +
  1.2129 +lemma real_less_eq_code [code]: "Ratreal x \<le> Ratreal y \<longleftrightarrow> x \<le> y"
  1.2130 +  by (simp add: of_rat_less_eq)
  1.2131 +
  1.2132 +lemma real_less_code [code]: "Ratreal x < Ratreal y \<longleftrightarrow> x < y"
  1.2133 +  by (simp add: of_rat_less)
  1.2134 +
  1.2135 +lemma real_plus_code [code]: "Ratreal x + Ratreal y = Ratreal (x + y)"
  1.2136 +  by (simp add: of_rat_add)
  1.2137 +
  1.2138 +lemma real_times_code [code]: "Ratreal x * Ratreal y = Ratreal (x * y)"
  1.2139 +  by (simp add: of_rat_mult)
  1.2140 +
  1.2141 +lemma real_uminus_code [code]: "- Ratreal x = Ratreal (- x)"
  1.2142 +  by (simp add: of_rat_minus)
  1.2143 +
  1.2144 +lemma real_minus_code [code]: "Ratreal x - Ratreal y = Ratreal (x - y)"
  1.2145 +  by (simp add: of_rat_diff)
  1.2146 +
  1.2147 +lemma real_inverse_code [code]: "inverse (Ratreal x) = Ratreal (inverse x)"
  1.2148 +  by (simp add: of_rat_inverse)
  1.2149 + 
  1.2150 +lemma real_divide_code [code]: "Ratreal x / Ratreal y = Ratreal (x / y)"
  1.2151 +  by (simp add: of_rat_divide)
  1.2152 +
  1.2153 +lemma real_floor_code [code]: "floor (Ratreal x) = floor x"
  1.2154 +  by (metis Ratreal_def floor_le_iff floor_unique le_floor_iff of_int_floor_le of_rat_of_int_eq real_less_eq_code)
  1.2155 +
  1.2156 +
  1.2157 +text {* Quickcheck *}
  1.2158 +
  1.2159 +definition (in term_syntax)
  1.2160 +  valterm_ratreal :: "rat \<times> (unit \<Rightarrow> Code_Evaluation.term) \<Rightarrow> real \<times> (unit \<Rightarrow> Code_Evaluation.term)" where
  1.2161 +  [code_unfold]: "valterm_ratreal k = Code_Evaluation.valtermify Ratreal {\<cdot>} k"
  1.2162 +
  1.2163 +notation fcomp (infixl "\<circ>>" 60)
  1.2164 +notation scomp (infixl "\<circ>\<rightarrow>" 60)
  1.2165 +
  1.2166 +instantiation real :: random
  1.2167 +begin
  1.2168 +
  1.2169 +definition
  1.2170 +  "Quickcheck_Random.random i = Quickcheck_Random.random i \<circ>\<rightarrow> (\<lambda>r. Pair (valterm_ratreal r))"
  1.2171 +
  1.2172 +instance ..
  1.2173 +
  1.2174 +end
  1.2175 +
  1.2176 +no_notation fcomp (infixl "\<circ>>" 60)
  1.2177 +no_notation scomp (infixl "\<circ>\<rightarrow>" 60)
  1.2178 +
  1.2179 +instantiation real :: exhaustive
  1.2180 +begin
  1.2181 +
  1.2182 +definition
  1.2183 +  "exhaustive_real f d = Quickcheck_Exhaustive.exhaustive (%r. f (Ratreal r)) d"
  1.2184 +
  1.2185 +instance ..
  1.2186 +
  1.2187 +end
  1.2188 +
  1.2189 +instantiation real :: full_exhaustive
  1.2190 +begin
  1.2191 +
  1.2192 +definition
  1.2193 +  "full_exhaustive_real f d = Quickcheck_Exhaustive.full_exhaustive (%r. f (valterm_ratreal r)) d"
  1.2194 +
  1.2195 +instance ..
  1.2196 +
  1.2197 +end
  1.2198 +
  1.2199 +instantiation real :: narrowing
  1.2200 +begin
  1.2201 +
  1.2202 +definition
  1.2203 +  "narrowing = Quickcheck_Narrowing.apply (Quickcheck_Narrowing.cons Ratreal) narrowing"
  1.2204 +
  1.2205 +instance ..
  1.2206 +
  1.2207 +end
  1.2208 +
  1.2209 +
  1.2210 +subsection {* Setup for Nitpick *}
  1.2211 +
  1.2212 +declaration {*
  1.2213 +  Nitpick_HOL.register_frac_type @{type_name real}
  1.2214 +   [(@{const_name zero_real_inst.zero_real}, @{const_name Nitpick.zero_frac}),
  1.2215 +    (@{const_name one_real_inst.one_real}, @{const_name Nitpick.one_frac}),
  1.2216 +    (@{const_name plus_real_inst.plus_real}, @{const_name Nitpick.plus_frac}),
  1.2217 +    (@{const_name times_real_inst.times_real}, @{const_name Nitpick.times_frac}),
  1.2218 +    (@{const_name uminus_real_inst.uminus_real}, @{const_name Nitpick.uminus_frac}),
  1.2219 +    (@{const_name inverse_real_inst.inverse_real}, @{const_name Nitpick.inverse_frac}),
  1.2220 +    (@{const_name ord_real_inst.less_real}, @{const_name Nitpick.less_frac}),
  1.2221 +    (@{const_name ord_real_inst.less_eq_real}, @{const_name Nitpick.less_eq_frac})]
  1.2222 +*}
  1.2223 +
  1.2224 +lemmas [nitpick_unfold] = inverse_real_inst.inverse_real one_real_inst.one_real
  1.2225 +    ord_real_inst.less_real ord_real_inst.less_eq_real plus_real_inst.plus_real
  1.2226 +    times_real_inst.times_real uminus_real_inst.uminus_real
  1.2227 +    zero_real_inst.zero_real
  1.2228 +
  1.2229 +ML_file "Tools/SMT/smt_real.ML"
  1.2230 +setup SMT_Real.setup
  1.2231 +
  1.2232 +end