src/HOL/Datatype.thy
 author haftmann Tue Feb 26 20:38:10 2008 +0100 (2008-02-26) changeset 26146 61cb176d0385 parent 26072 f65a7fa2da6c child 26339 7825c83c9eff permissions -rw-r--r--
tuned proofs
```     1 (*  Title:      HOL/Datatype.thy
```
```     2     ID:         \$Id\$
```
```     3     Author:     Lawrence C Paulson, Cambridge University Computer Laboratory
```
```     4     Author:     Stefan Berghofer and Markus Wenzel, TU Muenchen
```
```     5
```
```     6 Could <*> be generalized to a general summation (Sigma)?
```
```     7 *)
```
```     8
```
```     9 header {* Analogues of the Cartesian Product and Disjoint Sum for Datatypes *}
```
```    10
```
```    11 theory Datatype
```
```    12 imports Finite_Set
```
```    13 begin
```
```    14
```
```    15 lemma size_bool [code func]:
```
```    16   "size (b\<Colon>bool) = 0" by (cases b) auto
```
```    17
```
```    18 declare "prod.size" [noatp]
```
```    19
```
```    20 typedef (Node)
```
```    21   ('a,'b) node = "{p. EX f x k. p = (f::nat=>'b+nat, x::'a+nat) & f k = Inr 0}"
```
```    22     --{*it is a subtype of @{text "(nat=>'b+nat) * ('a+nat)"}*}
```
```    23   by auto
```
```    24
```
```    25 text{*Datatypes will be represented by sets of type @{text node}*}
```
```    26
```
```    27 types 'a item        = "('a, unit) node set"
```
```    28       ('a, 'b) dtree = "('a, 'b) node set"
```
```    29
```
```    30 consts
```
```    31   apfst     :: "['a=>'c, 'a*'b] => 'c*'b"
```
```    32   Push      :: "[('b + nat), nat => ('b + nat)] => (nat => ('b + nat))"
```
```    33
```
```    34   Push_Node :: "[('b + nat), ('a, 'b) node] => ('a, 'b) node"
```
```    35   ndepth    :: "('a, 'b) node => nat"
```
```    36
```
```    37   Atom      :: "('a + nat) => ('a, 'b) dtree"
```
```    38   Leaf      :: "'a => ('a, 'b) dtree"
```
```    39   Numb      :: "nat => ('a, 'b) dtree"
```
```    40   Scons     :: "[('a, 'b) dtree, ('a, 'b) dtree] => ('a, 'b) dtree"
```
```    41   In0       :: "('a, 'b) dtree => ('a, 'b) dtree"
```
```    42   In1       :: "('a, 'b) dtree => ('a, 'b) dtree"
```
```    43   Lim       :: "('b => ('a, 'b) dtree) => ('a, 'b) dtree"
```
```    44
```
```    45   ntrunc    :: "[nat, ('a, 'b) dtree] => ('a, 'b) dtree"
```
```    46
```
```    47   uprod     :: "[('a, 'b) dtree set, ('a, 'b) dtree set]=> ('a, 'b) dtree set"
```
```    48   usum      :: "[('a, 'b) dtree set, ('a, 'b) dtree set]=> ('a, 'b) dtree set"
```
```    49
```
```    50   Split     :: "[[('a, 'b) dtree, ('a, 'b) dtree]=>'c, ('a, 'b) dtree] => 'c"
```
```    51   Case      :: "[[('a, 'b) dtree]=>'c, [('a, 'b) dtree]=>'c, ('a, 'b) dtree] => 'c"
```
```    52
```
```    53   dprod     :: "[(('a, 'b) dtree * ('a, 'b) dtree)set, (('a, 'b) dtree * ('a, 'b) dtree)set]
```
```    54                 => (('a, 'b) dtree * ('a, 'b) dtree)set"
```
```    55   dsum      :: "[(('a, 'b) dtree * ('a, 'b) dtree)set, (('a, 'b) dtree * ('a, 'b) dtree)set]
```
```    56                 => (('a, 'b) dtree * ('a, 'b) dtree)set"
```
```    57
```
```    58
```
```    59 defs
```
```    60
```
```    61   Push_Node_def:  "Push_Node == (%n x. Abs_Node (apfst (Push n) (Rep_Node x)))"
```
```    62
```
```    63   (*crude "lists" of nats -- needed for the constructions*)
```
```    64   apfst_def:  "apfst == (%f (x,y). (f(x),y))"
```
```    65   Push_def:   "Push == (%b h. nat_case b h)"
```
```    66
```
```    67   (** operations on S-expressions -- sets of nodes **)
```
```    68
```
```    69   (*S-expression constructors*)
```
```    70   Atom_def:   "Atom == (%x. {Abs_Node((%k. Inr 0, x))})"
```
```    71   Scons_def:  "Scons M N == (Push_Node (Inr 1) ` M) Un (Push_Node (Inr (Suc 1)) ` N)"
```
```    72
```
```    73   (*Leaf nodes, with arbitrary or nat labels*)
```
```    74   Leaf_def:   "Leaf == Atom o Inl"
```
```    75   Numb_def:   "Numb == Atom o Inr"
```
```    76
```
```    77   (*Injections of the "disjoint sum"*)
```
```    78   In0_def:    "In0(M) == Scons (Numb 0) M"
```
```    79   In1_def:    "In1(M) == Scons (Numb 1) M"
```
```    80
```
```    81   (*Function spaces*)
```
```    82   Lim_def: "Lim f == Union {z. ? x. z = Push_Node (Inl x) ` (f x)}"
```
```    83
```
```    84   (*the set of nodes with depth less than k*)
```
```    85   ndepth_def: "ndepth(n) == (%(f,x). LEAST k. f k = Inr 0) (Rep_Node n)"
```
```    86   ntrunc_def: "ntrunc k N == {n. n:N & ndepth(n)<k}"
```
```    87
```
```    88   (*products and sums for the "universe"*)
```
```    89   uprod_def:  "uprod A B == UN x:A. UN y:B. { Scons x y }"
```
```    90   usum_def:   "usum A B == In0`A Un In1`B"
```
```    91
```
```    92   (*the corresponding eliminators*)
```
```    93   Split_def:  "Split c M == THE u. EX x y. M = Scons x y & u = c x y"
```
```    94
```
```    95   Case_def:   "Case c d M == THE u.  (EX x . M = In0(x) & u = c(x))
```
```    96                                   | (EX y . M = In1(y) & u = d(y))"
```
```    97
```
```    98
```
```    99   (** equality for the "universe" **)
```
```   100
```
```   101   dprod_def:  "dprod r s == UN (x,x'):r. UN (y,y'):s. {(Scons x y, Scons x' y')}"
```
```   102
```
```   103   dsum_def:   "dsum r s == (UN (x,x'):r. {(In0(x),In0(x'))}) Un
```
```   104                           (UN (y,y'):s. {(In1(y),In1(y'))})"
```
```   105
```
```   106
```
```   107
```
```   108 (** apfst -- can be used in similar type definitions **)
```
```   109
```
```   110 lemma apfst_conv [simp, code]: "apfst f (a, b) = (f a, b)"
```
```   111 by (simp add: apfst_def)
```
```   112
```
```   113
```
```   114 lemma apfst_convE:
```
```   115     "[| q = apfst f p;  !!x y. [| p = (x,y);  q = (f(x),y) |] ==> R
```
```   116      |] ==> R"
```
```   117 by (force simp add: apfst_def)
```
```   118
```
```   119 (** Push -- an injection, analogous to Cons on lists **)
```
```   120
```
```   121 lemma Push_inject1: "Push i f = Push j g  ==> i=j"
```
```   122 apply (simp add: Push_def expand_fun_eq)
```
```   123 apply (drule_tac x=0 in spec, simp)
```
```   124 done
```
```   125
```
```   126 lemma Push_inject2: "Push i f = Push j g  ==> f=g"
```
```   127 apply (auto simp add: Push_def expand_fun_eq)
```
```   128 apply (drule_tac x="Suc x" in spec, simp)
```
```   129 done
```
```   130
```
```   131 lemma Push_inject:
```
```   132     "[| Push i f =Push j g;  [| i=j;  f=g |] ==> P |] ==> P"
```
```   133 by (blast dest: Push_inject1 Push_inject2)
```
```   134
```
```   135 lemma Push_neq_K0: "Push (Inr (Suc k)) f = (%z. Inr 0) ==> P"
```
```   136 by (auto simp add: Push_def expand_fun_eq split: nat.split_asm)
```
```   137
```
```   138 lemmas Abs_Node_inj = Abs_Node_inject [THEN [2] rev_iffD1, standard]
```
```   139
```
```   140
```
```   141 (*** Introduction rules for Node ***)
```
```   142
```
```   143 lemma Node_K0_I: "(%k. Inr 0, a) : Node"
```
```   144 by (simp add: Node_def)
```
```   145
```
```   146 lemma Node_Push_I: "p: Node ==> apfst (Push i) p : Node"
```
```   147 apply (simp add: Node_def Push_def)
```
```   148 apply (fast intro!: apfst_conv nat_case_Suc [THEN trans])
```
```   149 done
```
```   150
```
```   151
```
```   152 subsection{*Freeness: Distinctness of Constructors*}
```
```   153
```
```   154 (** Scons vs Atom **)
```
```   155
```
```   156 lemma Scons_not_Atom [iff]: "Scons M N \<noteq> Atom(a)"
```
```   157 apply (simp add: Atom_def Scons_def Push_Node_def One_nat_def)
```
```   158 apply (blast intro: Node_K0_I Rep_Node [THEN Node_Push_I]
```
```   159          dest!: Abs_Node_inj
```
```   160          elim!: apfst_convE sym [THEN Push_neq_K0])
```
```   161 done
```
```   162
```
```   163 lemmas Atom_not_Scons [iff] = Scons_not_Atom [THEN not_sym, standard]
```
```   164
```
```   165
```
```   166 (*** Injectiveness ***)
```
```   167
```
```   168 (** Atomic nodes **)
```
```   169
```
```   170 lemma inj_Atom: "inj(Atom)"
```
```   171 apply (simp add: Atom_def)
```
```   172 apply (blast intro!: inj_onI Node_K0_I dest!: Abs_Node_inj)
```
```   173 done
```
```   174 lemmas Atom_inject = inj_Atom [THEN injD, standard]
```
```   175
```
```   176 lemma Atom_Atom_eq [iff]: "(Atom(a)=Atom(b)) = (a=b)"
```
```   177 by (blast dest!: Atom_inject)
```
```   178
```
```   179 lemma inj_Leaf: "inj(Leaf)"
```
```   180 apply (simp add: Leaf_def o_def)
```
```   181 apply (rule inj_onI)
```
```   182 apply (erule Atom_inject [THEN Inl_inject])
```
```   183 done
```
```   184
```
```   185 lemmas Leaf_inject [dest!] = inj_Leaf [THEN injD, standard]
```
```   186
```
```   187 lemma inj_Numb: "inj(Numb)"
```
```   188 apply (simp add: Numb_def o_def)
```
```   189 apply (rule inj_onI)
```
```   190 apply (erule Atom_inject [THEN Inr_inject])
```
```   191 done
```
```   192
```
```   193 lemmas Numb_inject [dest!] = inj_Numb [THEN injD, standard]
```
```   194
```
```   195
```
```   196 (** Injectiveness of Push_Node **)
```
```   197
```
```   198 lemma Push_Node_inject:
```
```   199     "[| Push_Node i m =Push_Node j n;  [| i=j;  m=n |] ==> P
```
```   200      |] ==> P"
```
```   201 apply (simp add: Push_Node_def)
```
```   202 apply (erule Abs_Node_inj [THEN apfst_convE])
```
```   203 apply (rule Rep_Node [THEN Node_Push_I])+
```
```   204 apply (erule sym [THEN apfst_convE])
```
```   205 apply (blast intro: Rep_Node_inject [THEN iffD1] trans sym elim!: Push_inject)
```
```   206 done
```
```   207
```
```   208
```
```   209 (** Injectiveness of Scons **)
```
```   210
```
```   211 lemma Scons_inject_lemma1: "Scons M N <= Scons M' N' ==> M<=M'"
```
```   212 apply (simp add: Scons_def One_nat_def)
```
```   213 apply (blast dest!: Push_Node_inject)
```
```   214 done
```
```   215
```
```   216 lemma Scons_inject_lemma2: "Scons M N <= Scons M' N' ==> N<=N'"
```
```   217 apply (simp add: Scons_def One_nat_def)
```
```   218 apply (blast dest!: Push_Node_inject)
```
```   219 done
```
```   220
```
```   221 lemma Scons_inject1: "Scons M N = Scons M' N' ==> M=M'"
```
```   222 apply (erule equalityE)
```
```   223 apply (iprover intro: equalityI Scons_inject_lemma1)
```
```   224 done
```
```   225
```
```   226 lemma Scons_inject2: "Scons M N = Scons M' N' ==> N=N'"
```
```   227 apply (erule equalityE)
```
```   228 apply (iprover intro: equalityI Scons_inject_lemma2)
```
```   229 done
```
```   230
```
```   231 lemma Scons_inject:
```
```   232     "[| Scons M N = Scons M' N';  [| M=M';  N=N' |] ==> P |] ==> P"
```
```   233 by (iprover dest: Scons_inject1 Scons_inject2)
```
```   234
```
```   235 lemma Scons_Scons_eq [iff]: "(Scons M N = Scons M' N') = (M=M' & N=N')"
```
```   236 by (blast elim!: Scons_inject)
```
```   237
```
```   238 (*** Distinctness involving Leaf and Numb ***)
```
```   239
```
```   240 (** Scons vs Leaf **)
```
```   241
```
```   242 lemma Scons_not_Leaf [iff]: "Scons M N \<noteq> Leaf(a)"
```
```   243 by (simp add: Leaf_def o_def Scons_not_Atom)
```
```   244
```
```   245 lemmas Leaf_not_Scons  [iff] = Scons_not_Leaf [THEN not_sym, standard]
```
```   246
```
```   247 (** Scons vs Numb **)
```
```   248
```
```   249 lemma Scons_not_Numb [iff]: "Scons M N \<noteq> Numb(k)"
```
```   250 by (simp add: Numb_def o_def Scons_not_Atom)
```
```   251
```
```   252 lemmas Numb_not_Scons [iff] = Scons_not_Numb [THEN not_sym, standard]
```
```   253
```
```   254
```
```   255 (** Leaf vs Numb **)
```
```   256
```
```   257 lemma Leaf_not_Numb [iff]: "Leaf(a) \<noteq> Numb(k)"
```
```   258 by (simp add: Leaf_def Numb_def)
```
```   259
```
```   260 lemmas Numb_not_Leaf [iff] = Leaf_not_Numb [THEN not_sym, standard]
```
```   261
```
```   262
```
```   263 (*** ndepth -- the depth of a node ***)
```
```   264
```
```   265 lemma ndepth_K0: "ndepth (Abs_Node(%k. Inr 0, x)) = 0"
```
```   266 by (simp add: ndepth_def  Node_K0_I [THEN Abs_Node_inverse] Least_equality)
```
```   267
```
```   268 lemma ndepth_Push_Node_aux:
```
```   269      "nat_case (Inr (Suc i)) f k = Inr 0 --> Suc(LEAST x. f x = Inr 0) <= k"
```
```   270 apply (induct_tac "k", auto)
```
```   271 apply (erule Least_le)
```
```   272 done
```
```   273
```
```   274 lemma ndepth_Push_Node:
```
```   275     "ndepth (Push_Node (Inr (Suc i)) n) = Suc(ndepth(n))"
```
```   276 apply (insert Rep_Node [of n, unfolded Node_def])
```
```   277 apply (auto simp add: ndepth_def Push_Node_def
```
```   278                  Rep_Node [THEN Node_Push_I, THEN Abs_Node_inverse])
```
```   279 apply (rule Least_equality)
```
```   280 apply (auto simp add: Push_def ndepth_Push_Node_aux)
```
```   281 apply (erule LeastI)
```
```   282 done
```
```   283
```
```   284
```
```   285 (*** ntrunc applied to the various node sets ***)
```
```   286
```
```   287 lemma ntrunc_0 [simp]: "ntrunc 0 M = {}"
```
```   288 by (simp add: ntrunc_def)
```
```   289
```
```   290 lemma ntrunc_Atom [simp]: "ntrunc (Suc k) (Atom a) = Atom(a)"
```
```   291 by (auto simp add: Atom_def ntrunc_def ndepth_K0)
```
```   292
```
```   293 lemma ntrunc_Leaf [simp]: "ntrunc (Suc k) (Leaf a) = Leaf(a)"
```
```   294 by (simp add: Leaf_def o_def ntrunc_Atom)
```
```   295
```
```   296 lemma ntrunc_Numb [simp]: "ntrunc (Suc k) (Numb i) = Numb(i)"
```
```   297 by (simp add: Numb_def o_def ntrunc_Atom)
```
```   298
```
```   299 lemma ntrunc_Scons [simp]:
```
```   300     "ntrunc (Suc k) (Scons M N) = Scons (ntrunc k M) (ntrunc k N)"
```
```   301 by (auto simp add: Scons_def ntrunc_def One_nat_def ndepth_Push_Node)
```
```   302
```
```   303
```
```   304
```
```   305 (** Injection nodes **)
```
```   306
```
```   307 lemma ntrunc_one_In0 [simp]: "ntrunc (Suc 0) (In0 M) = {}"
```
```   308 apply (simp add: In0_def)
```
```   309 apply (simp add: Scons_def)
```
```   310 done
```
```   311
```
```   312 lemma ntrunc_In0 [simp]: "ntrunc (Suc(Suc k)) (In0 M) = In0 (ntrunc (Suc k) M)"
```
```   313 by (simp add: In0_def)
```
```   314
```
```   315 lemma ntrunc_one_In1 [simp]: "ntrunc (Suc 0) (In1 M) = {}"
```
```   316 apply (simp add: In1_def)
```
```   317 apply (simp add: Scons_def)
```
```   318 done
```
```   319
```
```   320 lemma ntrunc_In1 [simp]: "ntrunc (Suc(Suc k)) (In1 M) = In1 (ntrunc (Suc k) M)"
```
```   321 by (simp add: In1_def)
```
```   322
```
```   323
```
```   324 subsection{*Set Constructions*}
```
```   325
```
```   326
```
```   327 (*** Cartesian Product ***)
```
```   328
```
```   329 lemma uprodI [intro!]: "[| M:A;  N:B |] ==> Scons M N : uprod A B"
```
```   330 by (simp add: uprod_def)
```
```   331
```
```   332 (*The general elimination rule*)
```
```   333 lemma uprodE [elim!]:
```
```   334     "[| c : uprod A B;
```
```   335         !!x y. [| x:A;  y:B;  c = Scons x y |] ==> P
```
```   336      |] ==> P"
```
```   337 by (auto simp add: uprod_def)
```
```   338
```
```   339
```
```   340 (*Elimination of a pair -- introduces no eigenvariables*)
```
```   341 lemma uprodE2: "[| Scons M N : uprod A B;  [| M:A;  N:B |] ==> P |] ==> P"
```
```   342 by (auto simp add: uprod_def)
```
```   343
```
```   344
```
```   345 (*** Disjoint Sum ***)
```
```   346
```
```   347 lemma usum_In0I [intro]: "M:A ==> In0(M) : usum A B"
```
```   348 by (simp add: usum_def)
```
```   349
```
```   350 lemma usum_In1I [intro]: "N:B ==> In1(N) : usum A B"
```
```   351 by (simp add: usum_def)
```
```   352
```
```   353 lemma usumE [elim!]:
```
```   354     "[| u : usum A B;
```
```   355         !!x. [| x:A;  u=In0(x) |] ==> P;
```
```   356         !!y. [| y:B;  u=In1(y) |] ==> P
```
```   357      |] ==> P"
```
```   358 by (auto simp add: usum_def)
```
```   359
```
```   360
```
```   361 (** Injection **)
```
```   362
```
```   363 lemma In0_not_In1 [iff]: "In0(M) \<noteq> In1(N)"
```
```   364 by (auto simp add: In0_def In1_def One_nat_def)
```
```   365
```
```   366 lemmas In1_not_In0 [iff] = In0_not_In1 [THEN not_sym, standard]
```
```   367
```
```   368 lemma In0_inject: "In0(M) = In0(N) ==>  M=N"
```
```   369 by (simp add: In0_def)
```
```   370
```
```   371 lemma In1_inject: "In1(M) = In1(N) ==>  M=N"
```
```   372 by (simp add: In1_def)
```
```   373
```
```   374 lemma In0_eq [iff]: "(In0 M = In0 N) = (M=N)"
```
```   375 by (blast dest!: In0_inject)
```
```   376
```
```   377 lemma In1_eq [iff]: "(In1 M = In1 N) = (M=N)"
```
```   378 by (blast dest!: In1_inject)
```
```   379
```
```   380 lemma inj_In0: "inj In0"
```
```   381 by (blast intro!: inj_onI)
```
```   382
```
```   383 lemma inj_In1: "inj In1"
```
```   384 by (blast intro!: inj_onI)
```
```   385
```
```   386
```
```   387 (*** Function spaces ***)
```
```   388
```
```   389 lemma Lim_inject: "Lim f = Lim g ==> f = g"
```
```   390 apply (simp add: Lim_def)
```
```   391 apply (rule ext)
```
```   392 apply (blast elim!: Push_Node_inject)
```
```   393 done
```
```   394
```
```   395
```
```   396 (*** proving equality of sets and functions using ntrunc ***)
```
```   397
```
```   398 lemma ntrunc_subsetI: "ntrunc k M <= M"
```
```   399 by (auto simp add: ntrunc_def)
```
```   400
```
```   401 lemma ntrunc_subsetD: "(!!k. ntrunc k M <= N) ==> M<=N"
```
```   402 by (auto simp add: ntrunc_def)
```
```   403
```
```   404 (*A generalized form of the take-lemma*)
```
```   405 lemma ntrunc_equality: "(!!k. ntrunc k M = ntrunc k N) ==> M=N"
```
```   406 apply (rule equalityI)
```
```   407 apply (rule_tac [!] ntrunc_subsetD)
```
```   408 apply (rule_tac [!] ntrunc_subsetI [THEN [2] subset_trans], auto)
```
```   409 done
```
```   410
```
```   411 lemma ntrunc_o_equality:
```
```   412     "[| !!k. (ntrunc(k) o h1) = (ntrunc(k) o h2) |] ==> h1=h2"
```
```   413 apply (rule ntrunc_equality [THEN ext])
```
```   414 apply (simp add: expand_fun_eq)
```
```   415 done
```
```   416
```
```   417
```
```   418 (*** Monotonicity ***)
```
```   419
```
```   420 lemma uprod_mono: "[| A<=A';  B<=B' |] ==> uprod A B <= uprod A' B'"
```
```   421 by (simp add: uprod_def, blast)
```
```   422
```
```   423 lemma usum_mono: "[| A<=A';  B<=B' |] ==> usum A B <= usum A' B'"
```
```   424 by (simp add: usum_def, blast)
```
```   425
```
```   426 lemma Scons_mono: "[| M<=M';  N<=N' |] ==> Scons M N <= Scons M' N'"
```
```   427 by (simp add: Scons_def, blast)
```
```   428
```
```   429 lemma In0_mono: "M<=N ==> In0(M) <= In0(N)"
```
```   430 by (simp add: In0_def subset_refl Scons_mono)
```
```   431
```
```   432 lemma In1_mono: "M<=N ==> In1(M) <= In1(N)"
```
```   433 by (simp add: In1_def subset_refl Scons_mono)
```
```   434
```
```   435
```
```   436 (*** Split and Case ***)
```
```   437
```
```   438 lemma Split [simp]: "Split c (Scons M N) = c M N"
```
```   439 by (simp add: Split_def)
```
```   440
```
```   441 lemma Case_In0 [simp]: "Case c d (In0 M) = c(M)"
```
```   442 by (simp add: Case_def)
```
```   443
```
```   444 lemma Case_In1 [simp]: "Case c d (In1 N) = d(N)"
```
```   445 by (simp add: Case_def)
```
```   446
```
```   447
```
```   448
```
```   449 (**** UN x. B(x) rules ****)
```
```   450
```
```   451 lemma ntrunc_UN1: "ntrunc k (UN x. f(x)) = (UN x. ntrunc k (f x))"
```
```   452 by (simp add: ntrunc_def, blast)
```
```   453
```
```   454 lemma Scons_UN1_x: "Scons (UN x. f x) M = (UN x. Scons (f x) M)"
```
```   455 by (simp add: Scons_def, blast)
```
```   456
```
```   457 lemma Scons_UN1_y: "Scons M (UN x. f x) = (UN x. Scons M (f x))"
```
```   458 by (simp add: Scons_def, blast)
```
```   459
```
```   460 lemma In0_UN1: "In0(UN x. f(x)) = (UN x. In0(f(x)))"
```
```   461 by (simp add: In0_def Scons_UN1_y)
```
```   462
```
```   463 lemma In1_UN1: "In1(UN x. f(x)) = (UN x. In1(f(x)))"
```
```   464 by (simp add: In1_def Scons_UN1_y)
```
```   465
```
```   466
```
```   467 (*** Equality for Cartesian Product ***)
```
```   468
```
```   469 lemma dprodI [intro!]:
```
```   470     "[| (M,M'):r;  (N,N'):s |] ==> (Scons M N, Scons M' N') : dprod r s"
```
```   471 by (auto simp add: dprod_def)
```
```   472
```
```   473 (*The general elimination rule*)
```
```   474 lemma dprodE [elim!]:
```
```   475     "[| c : dprod r s;
```
```   476         !!x y x' y'. [| (x,x') : r;  (y,y') : s;
```
```   477                         c = (Scons x y, Scons x' y') |] ==> P
```
```   478      |] ==> P"
```
```   479 by (auto simp add: dprod_def)
```
```   480
```
```   481
```
```   482 (*** Equality for Disjoint Sum ***)
```
```   483
```
```   484 lemma dsum_In0I [intro]: "(M,M'):r ==> (In0(M), In0(M')) : dsum r s"
```
```   485 by (auto simp add: dsum_def)
```
```   486
```
```   487 lemma dsum_In1I [intro]: "(N,N'):s ==> (In1(N), In1(N')) : dsum r s"
```
```   488 by (auto simp add: dsum_def)
```
```   489
```
```   490 lemma dsumE [elim!]:
```
```   491     "[| w : dsum r s;
```
```   492         !!x x'. [| (x,x') : r;  w = (In0(x), In0(x')) |] ==> P;
```
```   493         !!y y'. [| (y,y') : s;  w = (In1(y), In1(y')) |] ==> P
```
```   494      |] ==> P"
```
```   495 by (auto simp add: dsum_def)
```
```   496
```
```   497
```
```   498 (*** Monotonicity ***)
```
```   499
```
```   500 lemma dprod_mono: "[| r<=r';  s<=s' |] ==> dprod r s <= dprod r' s'"
```
```   501 by blast
```
```   502
```
```   503 lemma dsum_mono: "[| r<=r';  s<=s' |] ==> dsum r s <= dsum r' s'"
```
```   504 by blast
```
```   505
```
```   506
```
```   507 (*** Bounding theorems ***)
```
```   508
```
```   509 lemma dprod_Sigma: "(dprod (A <*> B) (C <*> D)) <= (uprod A C) <*> (uprod B D)"
```
```   510 by blast
```
```   511
```
```   512 lemmas dprod_subset_Sigma = subset_trans [OF dprod_mono dprod_Sigma, standard]
```
```   513
```
```   514 (*Dependent version*)
```
```   515 lemma dprod_subset_Sigma2:
```
```   516      "(dprod (Sigma A B) (Sigma C D)) <=
```
```   517       Sigma (uprod A C) (Split (%x y. uprod (B x) (D y)))"
```
```   518 by auto
```
```   519
```
```   520 lemma dsum_Sigma: "(dsum (A <*> B) (C <*> D)) <= (usum A C) <*> (usum B D)"
```
```   521 by blast
```
```   522
```
```   523 lemmas dsum_subset_Sigma = subset_trans [OF dsum_mono dsum_Sigma, standard]
```
```   524
```
```   525
```
```   526 (*** Domain ***)
```
```   527
```
```   528 lemma Domain_dprod [simp]: "Domain (dprod r s) = uprod (Domain r) (Domain s)"
```
```   529 by auto
```
```   530
```
```   531 lemma Domain_dsum [simp]: "Domain (dsum r s) = usum (Domain r) (Domain s)"
```
```   532 by auto
```
```   533
```
```   534
```
```   535 text {* hides popular names *}
```
```   536 hide (open) type node item
```
```   537 hide (open) const Push Node Atom Leaf Numb Lim Split Case
```
```   538
```
```   539
```
```   540 section {* Datatypes *}
```
```   541
```
```   542 subsection {* Representing sums *}
```
```   543
```
```   544 rep_datatype sum
```
```   545   distinct Inl_not_Inr Inr_not_Inl
```
```   546   inject Inl_eq Inr_eq
```
```   547   induction sum_induct
```
```   548
```
```   549 lemma sum_case_KK[simp]: "sum_case (%x. a) (%x. a) = (%x. a)"
```
```   550   by (rule ext) (simp split: sum.split)
```
```   551
```
```   552 lemma surjective_sum: "sum_case (%x::'a. f (Inl x)) (%y::'b. f (Inr y)) s = f(s)"
```
```   553   apply (rule_tac s = s in sumE)
```
```   554    apply (erule ssubst)
```
```   555    apply (rule sum.cases(1))
```
```   556   apply (erule ssubst)
```
```   557   apply (rule sum.cases(2))
```
```   558   done
```
```   559
```
```   560 lemma sum_case_weak_cong: "s = t ==> sum_case f g s = sum_case f g t"
```
```   561   -- {* Prevents simplification of @{text f} and @{text g}: much faster. *}
```
```   562   by simp
```
```   563
```
```   564 lemma sum_case_inject:
```
```   565   "sum_case f1 f2 = sum_case g1 g2 ==> (f1 = g1 ==> f2 = g2 ==> P) ==> P"
```
```   566 proof -
```
```   567   assume a: "sum_case f1 f2 = sum_case g1 g2"
```
```   568   assume r: "f1 = g1 ==> f2 = g2 ==> P"
```
```   569   show P
```
```   570     apply (rule r)
```
```   571      apply (rule ext)
```
```   572      apply (cut_tac x = "Inl x" in a [THEN fun_cong], simp)
```
```   573     apply (rule ext)
```
```   574     apply (cut_tac x = "Inr x" in a [THEN fun_cong], simp)
```
```   575     done
```
```   576 qed
```
```   577
```
```   578 constdefs
```
```   579   Suml :: "('a => 'c) => 'a + 'b => 'c"
```
```   580   "Suml == (%f. sum_case f arbitrary)"
```
```   581
```
```   582   Sumr :: "('b => 'c) => 'a + 'b => 'c"
```
```   583   "Sumr == sum_case arbitrary"
```
```   584
```
```   585 lemma Suml_inject: "Suml f = Suml g ==> f = g"
```
```   586   by (unfold Suml_def) (erule sum_case_inject)
```
```   587
```
```   588 lemma Sumr_inject: "Sumr f = Sumr g ==> f = g"
```
```   589   by (unfold Sumr_def) (erule sum_case_inject)
```
```   590
```
```   591 hide (open) const Suml Sumr
```
```   592
```
```   593
```
```   594 subsection {* The option datatype *}
```
```   595
```
```   596 datatype 'a option = None | Some 'a
```
```   597
```
```   598 lemma not_None_eq [iff]: "(x ~= None) = (EX y. x = Some y)"
```
```   599   by (induct x) auto
```
```   600
```
```   601 lemma not_Some_eq [iff]: "(ALL y. x ~= Some y) = (x = None)"
```
```   602   by (induct x) auto
```
```   603
```
```   604 text{*Although it may appear that both of these equalities are helpful
```
```   605 only when applied to assumptions, in practice it seems better to give
```
```   606 them the uniform iff attribute. *}
```
```   607
```
```   608 lemma option_caseE:
```
```   609   assumes c: "(case x of None => P | Some y => Q y)"
```
```   610   obtains
```
```   611     (None) "x = None" and P
```
```   612   | (Some) y where "x = Some y" and "Q y"
```
```   613   using c by (cases x) simp_all
```
```   614
```
```   615 lemma insert_None_conv_UNIV: "insert None (range Some) = UNIV"
```
```   616   by (rule set_ext, case_tac x) auto
```
```   617
```
```   618 instance option :: (finite) finite
```
```   619   by default (simp add: insert_None_conv_UNIV [symmetric])
```
```   620
```
```   621
```
```   622 subsubsection {* Operations *}
```
```   623
```
```   624 consts
```
```   625   the :: "'a option => 'a"
```
```   626 primrec
```
```   627   "the (Some x) = x"
```
```   628
```
```   629 consts
```
```   630   o2s :: "'a option => 'a set"
```
```   631 primrec
```
```   632   "o2s None = {}"
```
```   633   "o2s (Some x) = {x}"
```
```   634
```
```   635 lemma ospec [dest]: "(ALL x:o2s A. P x) ==> A = Some x ==> P x"
```
```   636   by simp
```
```   637
```
```   638 ML_setup {* change_claset (fn cs => cs addSD2 ("ospec", thm "ospec")) *}
```
```   639
```
```   640 lemma elem_o2s [iff]: "(x : o2s xo) = (xo = Some x)"
```
```   641   by (cases xo) auto
```
```   642
```
```   643 lemma o2s_empty_eq [simp]: "(o2s xo = {}) = (xo = None)"
```
```   644   by (cases xo) auto
```
```   645
```
```   646 definition
```
```   647   option_map :: "('a \<Rightarrow> 'b) \<Rightarrow> 'a option \<Rightarrow> 'b option"
```
```   648 where
```
```   649   [code func del]: "option_map = (%f y. case y of None => None | Some x => Some (f x))"
```
```   650
```
```   651 lemma option_map_None [simp, code]: "option_map f None = None"
```
```   652   by (simp add: option_map_def)
```
```   653
```
```   654 lemma option_map_Some [simp, code]: "option_map f (Some x) = Some (f x)"
```
```   655   by (simp add: option_map_def)
```
```   656
```
```   657 lemma option_map_is_None [iff]:
```
```   658     "(option_map f opt = None) = (opt = None)"
```
```   659   by (simp add: option_map_def split add: option.split)
```
```   660
```
```   661 lemma option_map_eq_Some [iff]:
```
```   662     "(option_map f xo = Some y) = (EX z. xo = Some z & f z = y)"
```
```   663   by (simp add: option_map_def split add: option.split)
```
```   664
```
```   665 lemma option_map_comp:
```
```   666     "option_map f (option_map g opt) = option_map (f o g) opt"
```
```   667   by (simp add: option_map_def split add: option.split)
```
```   668
```
```   669 lemma option_map_o_sum_case [simp]:
```
```   670     "option_map f o sum_case g h = sum_case (option_map f o g) (option_map f o h)"
```
```   671   by (rule ext) (simp split: sum.split)
```
```   672
```
```   673
```
```   674 subsubsection {* Code generator setup *}
```
```   675
```
```   676 definition
```
```   677   is_none :: "'a option \<Rightarrow> bool" where
```
```   678   is_none_none [code post, symmetric, code inline]: "is_none x \<longleftrightarrow> x = None"
```
```   679
```
```   680 lemma is_none_code [code]:
```
```   681   shows "is_none None \<longleftrightarrow> True"
```
```   682     and "is_none (Some x) \<longleftrightarrow> False"
```
```   683   unfolding is_none_none [symmetric] by simp_all
```
```   684
```
```   685 hide (open) const is_none
```
```   686
```
```   687 code_type option
```
```   688   (SML "_ option")
```
```   689   (OCaml "_ option")
```
```   690   (Haskell "Maybe _")
```
```   691
```
```   692 code_const None and Some
```
```   693   (SML "NONE" and "SOME")
```
```   694   (OCaml "None" and "Some _")
```
```   695   (Haskell "Nothing" and "Just")
```
```   696
```
```   697 code_instance option :: eq
```
```   698   (Haskell -)
```
```   699
```
```   700 code_const "op = \<Colon> 'a\<Colon>eq option \<Rightarrow> 'a option \<Rightarrow> bool"
```
```   701   (Haskell infixl 4 "==")
```
```   702
```
```   703 code_reserved SML
```
```   704   option NONE SOME
```
```   705
```
```   706 code_reserved OCaml
```
```   707   option None Some
```
```   708
```
```   709 code_modulename SML
```
```   710   Datatype Nat
```
```   711
```
```   712 code_modulename OCaml
```
```   713   Datatype Nat
```
```   714
```
```   715 code_modulename Haskell
```
```   716   Datatype Nat
```
```   717
```
```   718 end
```