doc-src/TutorialI/todo.tobias
author nipkow
Wed, 18 Oct 2000 17:19:18 +0200
changeset 10242 028f54cd2cc9
parent 10237 875bf54b5d74
child 10281 9554ce1c2e54
permissions -rw-r--r--
*** empty log message ***
Ignore whitespace changes - Everywhere: Within whitespace: At end of lines:
10177
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
     1
General questions
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
     2
=================
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
     3
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
     4
Here is an initial list:
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
     5
clarify, clarsimp, hyp_subst_tac, rename_tac, rotate_tac, split
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
     6
single step tactics: (e/d/f)rule, insert
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
     7
with instantiation: (e/d/f)rule_tac, insert_tac
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
     8
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
     9
Hide global names like Node.
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
    10
Why is comp needed in addition to op O?
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
    11
Explain in syntax section!
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
    12
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
    13
Implementation
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
    14
==============
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
    15
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
    16
swap in classical.ML has ugly name Pa in it. Rename.
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
    17
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
    18
Induction rules for int: int_le/ge_induct?
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
    19
Needed for ifak example. But is that example worth it?
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
    20
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
    21
Add map_cong?? (upto 10% slower)
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
    22
But we should install UN_cong and INT_cong too.
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
    23
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
    24
defs with = and pattern matching
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
    25
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
    26
use arith_tac in recdef to solve termination conditions?
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
    27
-> new example in Recdef/termination
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
    28
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
    29
a tactic for replacing a specific occurrence:
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
    30
apply(substitute [2] thm)
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
    31
10186
499637e8f2c6 *** empty log message ***
nipkow
parents: 10177
diff changeset
    32
it would be nice if @term could deal with ?-vars.
499637e8f2c6 *** empty log message ***
nipkow
parents: 10177
diff changeset
    33
then a number of (unchecked!) @texts could be converted to @terms.
499637e8f2c6 *** empty log message ***
nipkow
parents: 10177
diff changeset
    34
10189
865918597b63 *** empty log message ***
nipkow
parents: 10186
diff changeset
    35
it would be nice if one could get id to the enclosing quotes in the [source] option.
865918597b63 *** empty log message ***
nipkow
parents: 10186
diff changeset
    36
10236
7626cb4e1407 *** empty log message ***
nipkow
parents: 10217
diff changeset
    37
arithmetic: allow mixed nat/int formulae
7626cb4e1407 *** empty log message ***
nipkow
parents: 10217
diff changeset
    38
-> simplify proof of part1 in Inductive/AB.thy
10186
499637e8f2c6 *** empty log message ***
nipkow
parents: 10177
diff changeset
    39
10177
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
    40
Minor fixes in the tutorial
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
    41
===========================
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
    42
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
    43
replace simp only split by split_tac.
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
    44
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
    45
get rid of use_thy?
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
    46
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
    47
Explain typographic conventions?
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
    48
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
    49
an example of induction: !y. A --> B --> C ??
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
    50
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
    51
Appendix: Lexical: long ids.
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
    52
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
    53
Warning: infixes automatically become reserved words!
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
    54
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
    55
Forward ref from blast proof of Puzzle (AdvancedInd) to Isar proof?
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
    56
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
    57
mention split_split in advanced pair section.
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
    58
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
    59
recdef with nested recursion: either an example or at least a pointer to the
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
    60
literature. In Recdef/termination.thy, at the end.
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
    61
%FIXME, with one exception: nested recursion.
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
    62
10186
499637e8f2c6 *** empty log message ***
nipkow
parents: 10177
diff changeset
    63
Syntax section: syntax annotations nor just for consts but also for constdefs and datatype.
499637e8f2c6 *** empty log message ***
nipkow
parents: 10177
diff changeset
    64
499637e8f2c6 *** empty log message ***
nipkow
parents: 10177
diff changeset
    65
Prove EU exercise in CTL.
10177
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
    66
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
    67
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
    68
Minor additions to the tutorial, unclear where
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
    69
==============================================
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
    70
10186
499637e8f2c6 *** empty log message ***
nipkow
parents: 10177
diff changeset
    71
Tacticals: , ? +
10177
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
    72
10186
499637e8f2c6 *** empty log message ***
nipkow
parents: 10177
diff changeset
    73
"typedecl" is used in CTL/Base, but where is it introduced?
499637e8f2c6 *** empty log message ***
nipkow
parents: 10177
diff changeset
    74
In More Types chapter? Rephrase the CTL bit accordingly.
10177
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
    75
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
    76
print_simpset (-> print_simps?)
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
    77
(Another subsection Useful theorems, methods, and commands?)
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
    78
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
    79
Mention that simp etc (big step tactics) insist on change?
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
    80
10237
875bf54b5d74 *** empty log message ***
nipkow
parents: 10236
diff changeset
    81
Rules: Introduce "by" (as a kind of shorthand for apply+done, except that it
875bf54b5d74 *** empty log message ***
nipkow
parents: 10236
diff changeset
    82
does more.)
10177
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
    83
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
    84
A list of further useful commands (rules? tricks?)
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
    85
prefer, defer
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
    86
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
    87
An overview of the automatic methods: simp, auto, fast, blast, force,
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
    88
clarify, clarsimp (intro, elim?)
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
    89
10237
875bf54b5d74 *** empty log message ***
nipkow
parents: 10236
diff changeset
    90
Advanced Ind expects rule_format incl (no_asm) (which it currently explains!)
10242
028f54cd2cc9 *** empty log message ***
nipkow
parents: 10237
diff changeset
    91
Where explained? Should go into a separate section as Inductive needs it as
028f54cd2cc9 *** empty log message ***
nipkow
parents: 10237
diff changeset
    92
well.
10237
875bf54b5d74 *** empty log message ***
nipkow
parents: 10236
diff changeset
    93
875bf54b5d74 *** empty log message ***
nipkow
parents: 10236
diff changeset
    94
Where is "simplified" explained? Needed by Inductive/AB.thy
10177
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
    95
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
    96
demonstrate x : set xs in Sets. Or Tricks chapter?
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
    97
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
    98
Appendix with HOL keywords. Say something about other keywords.
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
    99
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   100
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   101
Possible exercises
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   102
==================
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   103
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   104
Exercises
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   105
%\begin{exercise}
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   106
%Extend expressions by conditional expressions.
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   107
braucht wfrec!
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   108
%\end{exercise}
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   109
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   110
Nested inductive datatypes: another example/exercise:
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   111
 size(t) <= size(subst s t)?
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   112
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   113
insertion sort: primrec, later recdef
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   114
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   115
OTree:
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   116
 first version only for non-empty trees:
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   117
 Tip 'a | Node tree tree
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   118
 Then real version?
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   119
 First primrec, then recdef?
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   120
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   121
Ind. sets: define ABC inductively and prove
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   122
ABC = {rep A n @ rep B n @ rep C n. True}
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   123
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   124
Possible examples/case studies
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   125
==============================
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   126
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   127
Trie: Define functional version
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   128
datatype ('a,'b)trie = Trie ('b option) ('a => ('a,'b)trie option)
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   129
lookup t [] = value t
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   130
lookup t (a#as) = case tries t a of None => None | Some s => lookup s as
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   131
Maybe as an exercise?
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   132
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   133
Trie: function for partial matches (prefixes). Needs sets for spec/proof.
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   134
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   135
Sets via ordered list of intervals. (Isa/Interval(2))
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   136
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   137
Sets: PDL and CTL
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   138
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   139
Ind. defs: Grammar (for same number of as and bs),
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   140
propositional logic (soundness and completeness?),
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   141
predicate logic (soundness?),
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   142
CTL proof.
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   143
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   144
Tautology checker. Based on Ifexpr or prop.logic?
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   145
Include forward reference in relevant section.
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   146
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   147
Sorting with comp-parameter and with type class (<)
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   148
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   149
New book by Bird?
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   150
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   151
Steps Towards Mechanizing Program Transformations Using PVS by N. Shankar,
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   152
      Science of Computer Programming, 26(1-3):33-57, 1996. 
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   153
You can get it from http://www.csl.sri.com/scp95.html
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   154
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   155
J Moore article Towards a ...
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   156
Mergesort, JVM
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   157
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   158
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   159
Additional topics
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   160
=================
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   161
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   162
Beef up recdef (see below).
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   163
Nested recursion? Mutual recursion?
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   164
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   165
Nested inductive datatypes: better recursion and induction
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   166
(see below)
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   167
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   168
Extensionality: applications in
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   169
- boolean expressions: valif o bool2if = value
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   170
- Advanced datatypes exercise subst (f o g) = subst f o subst g
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   171
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   172
A look at the library?
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   173
Functions. Relations. Lfp/Gfp. Map.
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   174
If WF is discussed, make a link to it from AdvancedInd.
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   175
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   176
Prototyping?
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   177
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   178
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   179
Isabelle
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   180
========
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   181
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   182
Get rid of function name in recdef header
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   183
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   184
More predefined functions for datatypes: map?
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   185
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   186
1 and 2 on nat?
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   187
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   188
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   189
==============================================================
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   190
Recdef:
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   191
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   192
nested recursion
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   193
more example proofs:
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   194
 if-normalization with measure function,
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   195
 nested if-normalization,
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   196
 quicksort
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   197
 Trie?
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   198
a case study?
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   199
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   200
----------
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   201
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   202
Partial rekursive functions / Nontermination
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   203
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   204
What appears to be the problem:
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   205
axiom f n = f n + 1
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   206
lemma False
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   207
apply(cut_facts_tac axiom, simp).
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   208
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   209
1. Guarded recursion
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   210
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   211
Scheme:
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   212
f x = if $x \in dom(f)$ then ... else arbitrary
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   213
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   214
Example: sum/fact: int -> int (for no good reason because we have nat)
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   215
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   216
Exercise: ?! f. !i. f i = if i=0 then 1 else i*f(i-1)
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   217
(What about sum? Is there one, a unique one?)
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   218
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   219
[Alternative: include argument that is counted down
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   220
 f x n = if n=0 then None else ...
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   221
Refer to Boyer and Moore]
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   222
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   223
More complex: same_fst
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   224
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   225
chase(f,x) = if wf{(f x,x) . f x ~= x}
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   226
             then if f x = x then x else chase(f,f x)
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   227
             else arb
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   228
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   229
Prove wf ==> f(chase(f,x)) = chase(f,x)
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   230
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   231
2. While / Tail recursion
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   232
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   233
chase f x = fst(while (%(x,fx). x=fx) (%(x,fx). (fx,f fx)) (x,f x))
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   234
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   235
==> unfold eqn for chase? Prove fixpoint property?
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   236
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   237
Better(?) sum i = fst(while (%(s,i). i=0) (%(s,i). (s+i,i-1)) (0,i))
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   238
Prove 0 <= i ==> sum i = i*(i+1) via while-rule
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   239
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   240
Mention prototyping?
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   241
==============================================================