src/Tools/quickcheck.ML
author wenzelm
Mon Mar 12 11:17:59 2018 +0100 (18 months ago)
changeset 67835 c8e4ee2b5482
parent 67149 e61557884799
permissions -rw-r--r--
tuned imports;
     1 (*  Title:      Tools/quickcheck.ML
     2     Author:     Stefan Berghofer, Florian Haftmann, Lukas Bulwahn, TU Muenchen
     3 
     4 Generic counterexample search engine.
     5 *)
     6 
     7 signature QUICKCHECK =
     8 sig
     9   val quickcheckN: string
    10   val genuineN: string
    11   val noneN: string
    12   val unknownN: string
    13   (*configuration*)
    14   val batch_tester : string Config.T
    15   val size : int Config.T
    16   val iterations : int Config.T
    17   val depth : int Config.T
    18   val no_assms : bool Config.T
    19   val report : bool Config.T
    20   val timeout : real Config.T
    21   val timing : bool Config.T
    22   val genuine_only : bool Config.T
    23   val abort_potential : bool Config.T
    24   val quiet : bool Config.T
    25   val verbose : bool Config.T
    26   val use_subtype : bool Config.T
    27   val allow_function_inversion : bool Config.T
    28   val finite_types : bool Config.T
    29   val finite_type_size : int Config.T
    30   val tag : string Config.T
    31   val locale : string Config.T
    32   val set_active_testers: string list -> Context.generic -> Context.generic
    33   datatype expectation = No_Expectation | No_Counterexample | Counterexample;
    34   datatype test_params = Test_Params of {default_type: typ list, expect : expectation};
    35   val test_params_of : Proof.context -> test_params
    36   val map_test_params : (typ list * expectation -> typ list * expectation)
    37     -> Context.generic -> Context.generic
    38   val default_type : Proof.context -> typ list
    39   datatype report = Report of
    40     { iterations : int, raised_match_errors : int,
    41       satisfied_assms : int list, positive_concl_tests : int }
    42   (*quickcheck's result*)
    43   datatype result =
    44     Result of
    45      {counterexample : (bool * (string * term) list) option,
    46       evaluation_terms : (term * term) list option,
    47       timings : (string * int) list,
    48       reports : (int * report) list}
    49   val empty_result : result
    50   val found_counterexample : result -> bool
    51   val add_timing : (string * int) -> result Unsynchronized.ref -> unit
    52   val add_response : string list -> term list -> (bool * term list) option ->
    53     result Unsynchronized.ref -> unit
    54   val add_report : int -> report option -> result Unsynchronized.ref -> unit
    55   val counterexample_of : result -> (bool * (string * term) list) option
    56   val timings_of : result -> (string * int) list
    57   (*registering testers & generators*)
    58   type tester =
    59     Proof.context -> bool -> (string * typ) list -> (term * term list) list -> result list
    60   val add_tester : string * (bool Config.T * tester) -> Context.generic -> Context.generic
    61   val add_batch_generator :
    62     string * (Proof.context -> term list -> (int -> term list option) list)
    63       -> Context.generic -> Context.generic
    64   val add_batch_validator :
    65     string * (Proof.context -> term list -> (int -> bool) list)
    66       -> Context.generic -> Context.generic
    67   (*basic operations*)
    68   val message : Proof.context -> string -> unit
    69   val verbose_message : Proof.context -> string -> unit
    70   val limit : Time.time -> (bool * bool) -> (unit -> 'a) -> (unit -> 'a) -> unit -> 'a
    71   val pretty_counterex : Proof.context -> bool ->
    72     ((bool * (string * term) list) * (term * term) list) option -> Pretty.T
    73   (*testing terms and proof states*)
    74   val mk_batch_validator : Proof.context -> term list -> (int -> bool) list option
    75   val mk_batch_tester : Proof.context -> term list -> (int -> term list option) list option
    76   val active_testers : Proof.context -> tester list
    77   val test_terms : Proof.context -> bool * bool -> (string * typ) list ->
    78     (term * term list) list -> result list option
    79   val quickcheck: (string * string list) list -> int -> Proof.state ->
    80     (bool * (string * term) list) option
    81 end;
    82 
    83 structure Quickcheck : QUICKCHECK =
    84 struct
    85 
    86 val quickcheckN = "quickcheck";
    87 
    88 val genuineN = "genuine";
    89 val noneN = "none";
    90 val unknownN = "unknown";
    91 
    92 
    93 (* quickcheck report *)
    94 
    95 datatype report = Report of
    96  {iterations : int,
    97   raised_match_errors : int,
    98   satisfied_assms : int list,
    99   positive_concl_tests : int};
   100 
   101 
   102 (* Quickcheck Result *)
   103 
   104 datatype result = Result of
   105  {counterexample : (bool * (string * term) list) option,
   106   evaluation_terms : (term * term) list option,
   107   timings : (string * int) list,
   108   reports : (int * report) list};
   109 
   110 val empty_result =
   111   Result {counterexample = NONE, evaluation_terms = NONE, timings = [], reports = []};
   112 
   113 fun counterexample_of (Result r) = #counterexample r;
   114 
   115 fun found_counterexample (Result r) = is_some (#counterexample r);
   116 
   117 fun response_of (Result r) =
   118   (case (#counterexample r, #evaluation_terms r) of
   119     (SOME ts, SOME evals) => SOME (ts, evals)
   120   | (NONE, NONE) => NONE);
   121 
   122 fun timings_of (Result r) = #timings r;
   123 
   124 fun set_response names eval_terms (SOME (genuine, ts)) (Result r) =
   125       let
   126         val (ts1, ts2) = chop (length names) ts
   127         val (eval_terms', _) = chop (length ts2) eval_terms
   128       in
   129         Result {counterexample = SOME (genuine, (names ~~ ts1)),
   130           evaluation_terms = SOME (eval_terms' ~~ ts2),
   131           timings = #timings r, reports = #reports r}
   132       end
   133   | set_response _ _ NONE result = result;
   134 
   135 
   136 fun cons_timing timing (Result r) =
   137   Result {counterexample = #counterexample r, evaluation_terms = #evaluation_terms r,
   138     timings = cons timing (#timings r), reports = #reports r};
   139 
   140 fun cons_report size (SOME report) (Result r) =
   141       Result {counterexample = #counterexample r, evaluation_terms = #evaluation_terms r,
   142         timings = #timings r, reports = cons (size, report) (#reports r)}
   143   | cons_report _ NONE result = result;
   144 
   145 fun add_timing timing result_ref =
   146   Unsynchronized.change result_ref (cons_timing timing);
   147 
   148 fun add_report size report result_ref =
   149   Unsynchronized.change result_ref (cons_report size report);
   150 
   151 fun add_response names eval_terms response result_ref =
   152   Unsynchronized.change result_ref (set_response names eval_terms response);
   153 
   154 
   155 (* expectation *)
   156 
   157 datatype expectation = No_Expectation | No_Counterexample | Counterexample;
   158 
   159 fun merge_expectation (expect1, expect2) =
   160   if expect1 = expect2 then expect1 else No_Expectation;
   161 
   162 (*quickcheck configuration -- default parameters, test generators*)
   163 val batch_tester = Attrib.setup_config_string \<^binding>\<open>quickcheck_batch_tester\<close> (K "");
   164 val size = Attrib.setup_config_int \<^binding>\<open>quickcheck_size\<close> (K 10);
   165 val iterations = Attrib.setup_config_int \<^binding>\<open>quickcheck_iterations\<close> (K 100);
   166 val depth = Attrib.setup_config_int \<^binding>\<open>quickcheck_depth\<close> (K 10);
   167 
   168 val no_assms = Attrib.setup_config_bool \<^binding>\<open>quickcheck_no_assms\<close> (K false);
   169 val locale = Attrib.setup_config_string \<^binding>\<open>quickcheck_locale\<close> (K "interpret expand");
   170 val report = Attrib.setup_config_bool \<^binding>\<open>quickcheck_report\<close> (K true);
   171 val timing = Attrib.setup_config_bool \<^binding>\<open>quickcheck_timing\<close> (K false);
   172 val timeout = Attrib.setup_config_real \<^binding>\<open>quickcheck_timeout\<close> (K 30.0);
   173 
   174 val genuine_only = Attrib.setup_config_bool \<^binding>\<open>quickcheck_genuine_only\<close> (K false);
   175 val abort_potential = Attrib.setup_config_bool \<^binding>\<open>quickcheck_abort_potential\<close> (K false);
   176 
   177 val quiet = Attrib.setup_config_bool \<^binding>\<open>quickcheck_quiet\<close> (K false);
   178 val verbose = Attrib.setup_config_bool \<^binding>\<open>quickcheck_verbose\<close> (K false);
   179 val tag = Attrib.setup_config_string \<^binding>\<open>quickcheck_tag\<close> (K "");
   180 
   181 val use_subtype = Attrib.setup_config_bool \<^binding>\<open>quickcheck_use_subtype\<close> (K false);
   182 
   183 val allow_function_inversion =
   184   Attrib.setup_config_bool \<^binding>\<open>quickcheck_allow_function_inversion\<close> (K false);
   185 val finite_types = Attrib.setup_config_bool \<^binding>\<open>quickcheck_finite_types\<close> (K true);
   186 val finite_type_size = Attrib.setup_config_int \<^binding>\<open>quickcheck_finite_type_size\<close> (K 3);
   187 
   188 datatype test_params = Test_Params of
   189   {default_type: typ list, expect : expectation};
   190 
   191 fun dest_test_params (Test_Params {default_type, expect}) = (default_type, expect);
   192 
   193 fun make_test_params (default_type, expect) =
   194   Test_Params {default_type = default_type, expect = expect};
   195 
   196 fun map_test_params' f (Test_Params {default_type, expect}) =
   197   make_test_params (f (default_type, expect));
   198 
   199 fun merge_test_params
   200   (Test_Params {default_type = default_type1, expect = expect1},
   201     Test_Params {default_type = default_type2, expect = expect2}) =
   202   make_test_params
   203     (merge (op =) (default_type1, default_type2), merge_expectation (expect1, expect2));
   204 
   205 type tester =
   206   Proof.context -> bool -> (string * typ) list -> (term * term list) list -> result list;
   207 
   208 structure Data = Generic_Data
   209 (
   210   type T =
   211     (string * (bool Config.T * tester)) list *
   212     (string * (Proof.context -> term list -> (int -> term list option) list)) list *
   213     (string * (Proof.context -> term list -> (int -> bool) list)) list *
   214     test_params;
   215   val empty = ([], [], [], Test_Params {default_type = [], expect = No_Expectation});
   216   val extend = I;
   217   fun merge
   218    ((testers1, batch_generators1, batch_validators1, params1),
   219     (testers2, batch_generators2, batch_validators2, params2)) : T =
   220     (AList.merge (op =) (K true) (testers1, testers2),
   221      AList.merge (op =) (K true) (batch_generators1, batch_generators2),
   222      AList.merge (op =) (K true) (batch_validators1, batch_validators2),
   223      merge_test_params (params1, params2));
   224 );
   225 
   226 val test_params_of = #4 o Data.get o Context.Proof;
   227 val default_type = fst o dest_test_params o test_params_of;
   228 val expect = snd o dest_test_params o test_params_of;
   229 val map_test_params = Data.map o @{apply 4(4)} o map_test_params';
   230 
   231 val add_tester = Data.map o @{apply 4(1)} o AList.update (op =);
   232 val add_batch_generator = Data.map o @{apply 4(2)} o AList.update (op =);
   233 val add_batch_validator = Data.map o @{apply 4(3)} o AList.update (op =);
   234 
   235 fun active_testers ctxt =
   236   let
   237     val testers = map snd (#1 (Data.get (Context.Proof ctxt)));
   238   in
   239     map snd (filter (fn (active, _) => Config.get ctxt active) testers)
   240   end;
   241 
   242 fun set_active_testers [] context = context
   243   | set_active_testers testers context =
   244       let
   245         val registered_testers = #1 (Data.get context);
   246       in
   247         fold (fn (name, (config, _)) => Config.put_generic config (member (op =) testers name))
   248           registered_testers context
   249       end;
   250 
   251 
   252 (* generating tests *)
   253 
   254 fun gen_mk_tester lookup ctxt v =
   255   let
   256     val name = Config.get ctxt batch_tester
   257     val tester =
   258       (case lookup ctxt name of
   259         NONE => error ("No such quickcheck batch-tester: " ^ name)
   260       | SOME tester => tester ctxt);
   261   in
   262     if Config.get ctxt quiet then
   263       try tester v
   264     else
   265       let (* FIXME !?!? *)
   266         val tester = Exn.interruptible_capture tester v
   267       in
   268         (case Exn.get_res tester of
   269           NONE => SOME (Exn.release tester)
   270         | SOME tester => SOME tester)
   271       end
   272   end;
   273 
   274 val mk_batch_tester = gen_mk_tester (AList.lookup (op =) o #2 o Data.get o Context.Proof);
   275 val mk_batch_validator = gen_mk_tester (AList.lookup (op =) o #3 o Data.get o Context.Proof);
   276 
   277 
   278 (* testing propositions *)
   279 
   280 type compile_generator =
   281   Proof.context -> (term * term list) list -> int list -> term list option * report option;
   282 
   283 fun limit timeout (limit_time, is_interactive) f exc () =
   284   if limit_time then
   285     Timeout.apply timeout f ()
   286       handle timeout_exn as Timeout.TIMEOUT _ =>
   287         if is_interactive then exc () else Exn.reraise timeout_exn
   288   else f ();
   289 
   290 fun message ctxt s = if Config.get ctxt quiet then () else writeln s;
   291 
   292 fun verbose_message ctxt s =
   293   if not (Config.get ctxt quiet) andalso Config.get ctxt verbose
   294   then writeln s else ();
   295 
   296 fun test_terms ctxt0 (limit_time, is_interactive) insts goals =
   297   let val ctxt = Simplifier_Trace.disable ctxt0 in
   298     (case active_testers ctxt of
   299       [] => error "No active testers for quickcheck"
   300     | testers =>
   301         limit (seconds (Config.get ctxt timeout)) (limit_time, is_interactive)
   302           (fn () =>
   303             Par_List.get_some (fn tester =>
   304               tester ctxt (length testers > 1) insts goals |>
   305               (fn result => if exists found_counterexample result then SOME result else NONE))
   306             testers)
   307           (fn () => (message ctxt "Quickcheck ran out of time"; NONE)) ())
   308   end
   309 
   310 fun all_axioms_of ctxt t =
   311   let
   312     val intros = Locale.get_intros ctxt;
   313     val unfolds = Locale.get_unfolds ctxt;
   314     fun retrieve_prems thms t =
   315        (case filter (fn th => Term.could_unify (Thm.concl_of th, t)) thms of
   316          [] => NONE
   317        | [th] =>
   318            let
   319              val (tyenv, tenv) =
   320                Pattern.match (Proof_Context.theory_of ctxt)
   321                 (Thm.concl_of th, t) (Vartab.empty, Vartab.empty)
   322            in SOME (map (Envir.subst_term (tyenv, tenv)) (Thm.prems_of th)) end);
   323     fun all t =
   324       (case retrieve_prems intros t of
   325         NONE => retrieve_prems unfolds t
   326       | SOME ts => SOME (maps (fn t => the_default [t] (all t)) ts));
   327   in
   328     all t
   329   end;
   330 
   331 fun locale_config_of s =
   332   let
   333     val cs = space_explode " " s;
   334   in
   335     if forall (fn c => c = "expand" orelse c = "interpret") cs then cs
   336     else
   337      (warning ("Invalid quickcheck_locale setting: falling back to the default setting.");
   338       ["interpret", "expand"])
   339   end;
   340 
   341 fun test_goal (time_limit, is_interactive) (insts, eval_terms) i state =
   342   let
   343     val ctxt = Proof.context_of state;
   344     val thy = Proof.theory_of state;
   345 
   346     fun strip (Const (\<^const_name>\<open>Pure.all\<close>, _) $ Abs (_, _, t)) = strip t
   347       | strip t = t;
   348     val {goal = st, ...} = Proof.raw_goal state;
   349     val (gi, frees) = Logic.goal_params (Thm.prop_of st) i;
   350     val opt_locale = Named_Target.bottom_locale_of ctxt;
   351     val assms =
   352       if Config.get ctxt no_assms then []
   353       else
   354         (case opt_locale of
   355           NONE => Assumption.all_assms_of ctxt
   356         | SOME locale => Assumption.local_assms_of ctxt (Locale.init locale thy));
   357     val proto_goal = Logic.list_implies (map Thm.term_of assms, subst_bounds (frees, strip gi));
   358     fun axioms_of locale =
   359       (case fst (Locale.specification_of thy locale) of
   360         NONE => []
   361       | SOME t => the_default [] (all_axioms_of ctxt t));
   362     val config = locale_config_of (Config.get ctxt locale);
   363     val goals =
   364       (case opt_locale of
   365         NONE => [(proto_goal, eval_terms)]
   366       | SOME locale =>
   367           fold (fn c =>
   368             if c = "expand" then
   369               cons (Logic.list_implies (axioms_of locale, proto_goal), eval_terms)
   370             else if c = "interpret" then
   371               append (map (fn (_, phi) =>
   372                   (Morphism.term phi proto_goal, map (Morphism.term phi) eval_terms))
   373                 (Locale.registrations_of (Context.Theory thy) (* FIXME !? *) locale))
   374             else I) config []);
   375     val _ =
   376       verbose_message ctxt
   377         (Pretty.string_of
   378           (Pretty.big_list ("Checking goals: ") (map (Syntax.pretty_term ctxt o fst) goals)));
   379   in
   380     test_terms ctxt (time_limit, is_interactive) insts goals
   381   end;
   382 
   383 
   384 (* pretty printing *)
   385 
   386 fun tool_name auto = if auto then "Auto Quickcheck" else "Quickcheck";
   387 
   388 fun pretty_counterex ctxt auto NONE =
   389       Pretty.para (tool_name auto ^ " found no counterexample." ^ Config.get ctxt tag)
   390   | pretty_counterex ctxt auto (SOME ((genuine, cex), eval_terms)) =
   391       let
   392         val header =
   393           Pretty.para
   394             (tool_name auto ^ " found a " ^
   395               (if genuine then "counterexample"
   396                else "potentially spurious counterexample due to underspecified functions") ^
   397               (if null cex then "." else ":") ^
   398               Config.get ctxt tag);
   399         fun pretty_cex (x, t) =
   400           Pretty.block [Pretty.str (x ^ " ="), Pretty.brk 1, Syntax.pretty_term ctxt t];
   401       in
   402         Pretty.chunks (Pretty.block (Pretty.fbreaks (header :: map pretty_cex (rev cex))) ::
   403           (if null eval_terms then []
   404            else
   405             [Pretty.big_list "Evaluated terms:"
   406               (map (fn (t, u) =>
   407                 Pretty.block [Syntax.pretty_term ctxt t, Pretty.str " =", Pretty.brk 1,
   408                   Syntax.pretty_term ctxt u]) (rev eval_terms))]))
   409       end;
   410 
   411 
   412 (* Isar commands *)
   413 
   414 fun read_nat s =
   415   (case Library.read_int (Symbol.explode s) of
   416     (k, []) =>
   417       if k >= 0 then k
   418       else error ("Not a natural number: " ^ s)
   419   | _ => error ("Not a natural number: " ^ s));
   420 
   421 fun read_bool "false" = false
   422   | read_bool "true" = true
   423   | read_bool s = error ("Not a Boolean value: " ^ s);
   424 
   425 fun read_real s =
   426   (case Real.fromString s of
   427     SOME s => s
   428   | NONE => error ("Not a real number: " ^ s));
   429 
   430 fun read_expectation "no_expectation" = No_Expectation
   431   | read_expectation "no_counterexample" = No_Counterexample
   432   | read_expectation "counterexample" = Counterexample
   433   | read_expectation s = error ("Not an expectation value: " ^ s);
   434 
   435 fun valid_tester_name context name =
   436   AList.defined (op =) (#1 (Data.get context)) name;
   437 
   438 fun parse_tester name (testers, context) =
   439   if valid_tester_name context name then
   440     (insert (op =) name testers, context)
   441   else error ("Unknown tester: " ^ name);
   442 
   443 fun parse_test_param ("tester", args) = fold parse_tester args
   444   | parse_test_param ("size", [arg]) = apsnd (Config.put_generic size (read_nat arg))
   445   | parse_test_param ("iterations", [arg]) = apsnd (Config.put_generic iterations (read_nat arg))
   446   | parse_test_param ("depth", [arg]) = apsnd (Config.put_generic depth (read_nat arg))
   447   | parse_test_param ("default_type", arg) =
   448       (fn (testers, context) =>
   449         (testers, map_test_params
   450           (apfst (K (map (Proof_Context.read_typ (Context.proof_of context)) arg))) context))
   451   | parse_test_param ("no_assms", [arg]) = apsnd (Config.put_generic no_assms (read_bool arg))
   452   | parse_test_param ("expect", [arg]) = apsnd (map_test_params (apsnd (K (read_expectation arg))))
   453   | parse_test_param ("report", [arg]) = apsnd (Config.put_generic report (read_bool arg))
   454   | parse_test_param ("genuine_only", [arg]) =
   455       apsnd (Config.put_generic genuine_only (read_bool arg))
   456   | parse_test_param ("abort_potential", [arg]) =
   457       apsnd (Config.put_generic abort_potential (read_bool arg))
   458   | parse_test_param ("quiet", [arg]) = apsnd (Config.put_generic quiet (read_bool arg))
   459   | parse_test_param ("verbose", [arg]) = apsnd (Config.put_generic verbose (read_bool arg))
   460   | parse_test_param ("tag", [arg]) = apsnd (Config.put_generic tag arg)
   461   | parse_test_param ("use_subtype", [arg]) =
   462       apsnd (Config.put_generic use_subtype (read_bool arg))
   463   | parse_test_param ("timeout", [arg]) =
   464       apsnd (Config.put_generic timeout (read_real arg))
   465   | parse_test_param ("finite_types", [arg]) =
   466       apsnd (Config.put_generic finite_types (read_bool arg))
   467   | parse_test_param ("allow_function_inversion", [arg]) =
   468       apsnd (Config.put_generic allow_function_inversion (read_bool arg))
   469   | parse_test_param ("finite_type_size", [arg]) =
   470       apsnd (Config.put_generic finite_type_size (read_nat arg))
   471   | parse_test_param (name, _) =
   472       (fn (testers, context) =>
   473         if valid_tester_name context name then
   474           (insert (op =) name testers, context)
   475         else error ("Unknown tester or test parameter: " ^ name));
   476 
   477 fun parse_test_param_inst (name, arg) ((insts, eval_terms), (testers, ctxt)) =
   478   (case try (Proof_Context.read_typ ctxt) name of
   479     SOME (TFree (v, _)) =>
   480       ((AList.update (op =) (v, Proof_Context.read_typ ctxt (the_single arg)) insts, eval_terms),
   481         (testers, ctxt))
   482   | NONE =>
   483       (case name of
   484         "eval" => ((insts, eval_terms @ map (Syntax.read_term ctxt) arg), (testers, ctxt))
   485       | _ =>
   486         ((insts, eval_terms),
   487           let
   488             val (testers', Context.Proof ctxt') =
   489               parse_test_param (name, arg) (testers, Context.Proof ctxt);
   490           in (testers', ctxt') end)));
   491 
   492 fun quickcheck_params_cmd args =
   493   Context.theory_map
   494     (fn context => uncurry set_active_testers (fold parse_test_param args ([], context)));
   495 
   496 fun check_expectation state results =
   497   if is_some results andalso expect (Proof.context_of state) = No_Counterexample then
   498     error "quickcheck expected to find no counterexample but found one"
   499   else if is_none results andalso expect (Proof.context_of state) = Counterexample then
   500     error "quickcheck expected to find a counterexample but did not find one"
   501   else ();
   502 
   503 fun gen_quickcheck args i state =
   504   state
   505   |> Proof.map_context_result (fn ctxt =>
   506     apsnd (fn (testers, ctxt) => Context.proof_map (set_active_testers testers) ctxt)
   507       (fold parse_test_param_inst args (([], []), ([], ctxt))))
   508   |> (fn ((insts, eval_terms), state') =>
   509       test_goal (true, true) (insts, eval_terms) i state'
   510       |> tap (check_expectation state')
   511       |> rpair state');
   512 
   513 fun quickcheck args i state =
   514   Option.map (the o get_first counterexample_of) (fst (gen_quickcheck args i state));
   515 
   516 fun quickcheck_cmd args i st =
   517   gen_quickcheck args i (Toplevel.proof_of st)
   518   |> apfst (Option.map (the o get_first response_of))
   519   |> (fn (r, state) =>
   520       writeln (Pretty.string_of
   521         (pretty_counterex (Proof.context_of state) false r)));
   522 
   523 val parse_arg =
   524   Parse.name --
   525     (Scan.optional (\<^keyword>\<open>=\<close> |--
   526       (((Parse.name || Parse.float_number) >> single) ||
   527         (\<^keyword>\<open>[\<close> |-- Parse.list1 Parse.name --| \<^keyword>\<open>]\<close>))) ["true"]);
   528 
   529 val parse_args =
   530   \<^keyword>\<open>[\<close> |-- Parse.list1 parse_arg --| \<^keyword>\<open>]\<close> || Scan.succeed [];
   531 
   532 val _ =
   533   Outer_Syntax.command \<^command_keyword>\<open>quickcheck_params\<close> "set parameters for random testing"
   534     (parse_args >> (fn args => Toplevel.theory (quickcheck_params_cmd args)));
   535 
   536 val _ =
   537   Outer_Syntax.command \<^command_keyword>\<open>quickcheck\<close>
   538     "try to find counterexample for subgoal"
   539     (parse_args -- Scan.optional Parse.nat 1 >>
   540       (fn (args, i) => Toplevel.keep_proof (quickcheck_cmd args i)));
   541 
   542 
   543 (* automatic testing *)
   544 
   545 fun try_quickcheck auto state =
   546   let
   547     val ctxt = Proof.context_of state;
   548     val i = 1;
   549     val res =
   550       state
   551       |> Proof.map_context (Config.put report false #> Config.put quiet true)
   552       |> try (test_goal (false, false) ([], []) i);
   553   in
   554     (case res of
   555       NONE => (unknownN, [])
   556     | SOME results =>
   557         let
   558           val msg =
   559             Pretty.string_of
   560               (pretty_counterex ctxt auto (Option.map (the o get_first response_of) results))
   561         in
   562           if is_some results then (genuineN, if auto then [msg] else (writeln msg; []))
   563           else (noneN, [])
   564         end)
   565   end
   566   |> `(fn (outcome_code, _) => outcome_code = genuineN);
   567 
   568 val _ = Try.tool_setup (quickcheckN, (20, \<^system_option>\<open>auto_quickcheck\<close>, try_quickcheck));
   569 
   570 end;
   571