src/HOL/IMP/Hoare.ML
author nipkow
Wed, 07 Feb 1996 12:22:32 +0100
changeset 1481 03f096efa26d
parent 1465 5d7a7e439cec
child 1486 7b95d7b49f7a
permissions -rw-r--r--
Modified datatype com. Added (part of) relative completeness proof for Hoare logic.
Ignore whitespace changes - Everywhere: Within whitespace: At end of lines:
1465
5d7a7e439cec expanded tabs
clasohm
parents: 1447
diff changeset
     1
(*  Title:      HOL/IMP/Hoare.ML
938
621be7ec81d7 *** empty log message ***
nipkow
parents: 936
diff changeset
     2
    ID:         $Id$
1465
5d7a7e439cec expanded tabs
clasohm
parents: 1447
diff changeset
     3
    Author:     Tobias Nipkow
936
a6d7b4084761 Hoare logic
nipkow
parents:
diff changeset
     4
    Copyright   1995 TUM
a6d7b4084761 Hoare logic
nipkow
parents:
diff changeset
     5
1481
03f096efa26d Modified datatype com.
nipkow
parents: 1465
diff changeset
     6
Soundness (and part of) relative completeness of Hoare rules
03f096efa26d Modified datatype com.
nipkow
parents: 1465
diff changeset
     7
wrt denotational semantics
936
a6d7b4084761 Hoare logic
nipkow
parents:
diff changeset
     8
*)
a6d7b4084761 Hoare logic
nipkow
parents:
diff changeset
     9
a6d7b4084761 Hoare logic
nipkow
parents:
diff changeset
    10
open Hoare;
a6d7b4084761 Hoare logic
nipkow
parents:
diff changeset
    11
1481
03f096efa26d Modified datatype com.
nipkow
parents: 1465
diff changeset
    12
goalw Hoare.thy [hoare_valid_def] "!P c Q. ({{P}}c{{Q}}) --> |= {{P}}c{{Q}}";
1465
5d7a7e439cec expanded tabs
clasohm
parents: 1447
diff changeset
    13
by (rtac hoare.mutual_induct 1);
1447
bc2c0acbbf29 Added a verified verification-condition generator.
nipkow
parents: 1266
diff changeset
    14
    by(ALLGOALS Asm_simp_tac);
bc2c0acbbf29 Added a verified verification-condition generator.
nipkow
parents: 1266
diff changeset
    15
  by(fast_tac rel_cs 1);
bc2c0acbbf29 Added a verified verification-condition generator.
nipkow
parents: 1266
diff changeset
    16
 by(fast_tac HOL_cs 1);
1465
5d7a7e439cec expanded tabs
clasohm
parents: 1447
diff changeset
    17
by (rtac allI 1);
5d7a7e439cec expanded tabs
clasohm
parents: 1447
diff changeset
    18
by (rtac allI 1);
5d7a7e439cec expanded tabs
clasohm
parents: 1447
diff changeset
    19
by (rtac impI 1);
5d7a7e439cec expanded tabs
clasohm
parents: 1447
diff changeset
    20
by (etac induct2 1);
1447
bc2c0acbbf29 Added a verified verification-condition generator.
nipkow
parents: 1266
diff changeset
    21
 br Gamma_mono 1;
1465
5d7a7e439cec expanded tabs
clasohm
parents: 1447
diff changeset
    22
by (rewtac Gamma_def);  
936
a6d7b4084761 Hoare logic
nipkow
parents:
diff changeset
    23
by(eres_inst_tac [("x","a")] allE 1);
a6d7b4084761 Hoare logic
nipkow
parents:
diff changeset
    24
by (safe_tac comp_cs);
1447
bc2c0acbbf29 Added a verified verification-condition generator.
nipkow
parents: 1266
diff changeset
    25
  by(ALLGOALS Asm_full_simp_tac);
bc2c0acbbf29 Added a verified verification-condition generator.
nipkow
parents: 1266
diff changeset
    26
qed "hoare_sound";
936
a6d7b4084761 Hoare logic
nipkow
parents:
diff changeset
    27
1481
03f096efa26d Modified datatype com.
nipkow
parents: 1465
diff changeset
    28
goalw Hoare.thy [swp_def] "swp Skip Q = Q";
03f096efa26d Modified datatype com.
nipkow
parents: 1465
diff changeset
    29
by(Simp_tac 1);
03f096efa26d Modified datatype com.
nipkow
parents: 1465
diff changeset
    30
br ext 1;
03f096efa26d Modified datatype com.
nipkow
parents: 1465
diff changeset
    31
by(fast_tac HOL_cs 1);
03f096efa26d Modified datatype com.
nipkow
parents: 1465
diff changeset
    32
qed "swp_Skip";
03f096efa26d Modified datatype com.
nipkow
parents: 1465
diff changeset
    33
03f096efa26d Modified datatype com.
nipkow
parents: 1465
diff changeset
    34
goalw Hoare.thy [swp_def] "swp (x:=a) Q = (%s.Q(s[A a s/x]))";
03f096efa26d Modified datatype com.
nipkow
parents: 1465
diff changeset
    35
by(Simp_tac 1);
03f096efa26d Modified datatype com.
nipkow
parents: 1465
diff changeset
    36
br ext 1;
03f096efa26d Modified datatype com.
nipkow
parents: 1465
diff changeset
    37
by(fast_tac HOL_cs 1);
03f096efa26d Modified datatype com.
nipkow
parents: 1465
diff changeset
    38
qed "swp_Ass";
03f096efa26d Modified datatype com.
nipkow
parents: 1465
diff changeset
    39
03f096efa26d Modified datatype com.
nipkow
parents: 1465
diff changeset
    40
goalw Hoare.thy [swp_def] "swp (c;d) Q = swp c (swp d Q)";
03f096efa26d Modified datatype com.
nipkow
parents: 1465
diff changeset
    41
by(Simp_tac 1);
03f096efa26d Modified datatype com.
nipkow
parents: 1465
diff changeset
    42
br ext 1;
03f096efa26d Modified datatype com.
nipkow
parents: 1465
diff changeset
    43
by(fast_tac comp_cs 1);
03f096efa26d Modified datatype com.
nipkow
parents: 1465
diff changeset
    44
qed "swp_Semi";
936
a6d7b4084761 Hoare logic
nipkow
parents:
diff changeset
    45
1481
03f096efa26d Modified datatype com.
nipkow
parents: 1465
diff changeset
    46
goalw Hoare.thy [swp_def]
03f096efa26d Modified datatype com.
nipkow
parents: 1465
diff changeset
    47
  "swp (IF b THEN c ELSE d) Q = (%s. (B b s --> swp c Q s) & \
03f096efa26d Modified datatype com.
nipkow
parents: 1465
diff changeset
    48
\                                    (~B b s --> swp d Q s))";
03f096efa26d Modified datatype com.
nipkow
parents: 1465
diff changeset
    49
by(Simp_tac 1);
03f096efa26d Modified datatype com.
nipkow
parents: 1465
diff changeset
    50
br ext 1;
03f096efa26d Modified datatype com.
nipkow
parents: 1465
diff changeset
    51
by(fast_tac comp_cs 1);
03f096efa26d Modified datatype com.
nipkow
parents: 1465
diff changeset
    52
qed "swp_If";
936
a6d7b4084761 Hoare logic
nipkow
parents:
diff changeset
    53
1481
03f096efa26d Modified datatype com.
nipkow
parents: 1465
diff changeset
    54
goalw Hoare.thy [swp_def]
03f096efa26d Modified datatype com.
nipkow
parents: 1465
diff changeset
    55
  "!!s. B b s ==> swp (WHILE b DO c) Q s = swp (c;WHILE b DO c) Q s";
03f096efa26d Modified datatype com.
nipkow
parents: 1465
diff changeset
    56
by(stac C_While_If 1);
03f096efa26d Modified datatype com.
nipkow
parents: 1465
diff changeset
    57
by(Asm_simp_tac 1);
03f096efa26d Modified datatype com.
nipkow
parents: 1465
diff changeset
    58
qed "swp_While_True";
03f096efa26d Modified datatype com.
nipkow
parents: 1465
diff changeset
    59
03f096efa26d Modified datatype com.
nipkow
parents: 1465
diff changeset
    60
goalw Hoare.thy [swp_def] "!!s. ~B b s ==> swp (WHILE b DO c) Q s = Q s";
03f096efa26d Modified datatype com.
nipkow
parents: 1465
diff changeset
    61
by(stac C_While_If 1);
03f096efa26d Modified datatype com.
nipkow
parents: 1465
diff changeset
    62
by(Asm_simp_tac 1);
03f096efa26d Modified datatype com.
nipkow
parents: 1465
diff changeset
    63
by(fast_tac HOL_cs 1);
03f096efa26d Modified datatype com.
nipkow
parents: 1465
diff changeset
    64
qed "swp_While_False";
03f096efa26d Modified datatype com.
nipkow
parents: 1465
diff changeset
    65
03f096efa26d Modified datatype com.
nipkow
parents: 1465
diff changeset
    66
Addsimps [swp_Skip,swp_Ass,swp_Semi,swp_If,swp_While_True,swp_While_False];
03f096efa26d Modified datatype com.
nipkow
parents: 1465
diff changeset
    67
03f096efa26d Modified datatype com.
nipkow
parents: 1465
diff changeset
    68
Delsimps [C_while];
936
a6d7b4084761 Hoare logic
nipkow
parents:
diff changeset
    69
1481
03f096efa26d Modified datatype com.
nipkow
parents: 1465
diff changeset
    70
goalw Hoare.thy [hoare_valid_def,swp_def]
03f096efa26d Modified datatype com.
nipkow
parents: 1465
diff changeset
    71
  "!!c. |= {{P}}c{{Q}} ==> !s. P s --> swp c Q s";
03f096efa26d Modified datatype com.
nipkow
parents: 1465
diff changeset
    72
by(fast_tac HOL_cs 1);
03f096efa26d Modified datatype com.
nipkow
parents: 1465
diff changeset
    73
qed "swp_is_weakest";
03f096efa26d Modified datatype com.
nipkow
parents: 1465
diff changeset
    74
03f096efa26d Modified datatype com.
nipkow
parents: 1465
diff changeset
    75
goal Hoare.thy "!Q. {{swp c Q}} c {{Q}}";
03f096efa26d Modified datatype com.
nipkow
parents: 1465
diff changeset
    76
by(com.induct_tac "c" 1);
03f096efa26d Modified datatype com.
nipkow
parents: 1465
diff changeset
    77
by(ALLGOALS Simp_tac);
03f096efa26d Modified datatype com.
nipkow
parents: 1465
diff changeset
    78
    by(fast_tac (HOL_cs addIs [hoare.skip]) 1);
03f096efa26d Modified datatype com.
nipkow
parents: 1465
diff changeset
    79
   by(fast_tac (HOL_cs addIs [hoare.ass]) 1);
03f096efa26d Modified datatype com.
nipkow
parents: 1465
diff changeset
    80
  by(fast_tac (HOL_cs addIs [hoare.semi]) 1);
03f096efa26d Modified datatype com.
nipkow
parents: 1465
diff changeset
    81
 by(safe_tac (HOL_cs addSIs [hoare.If]));
03f096efa26d Modified datatype com.
nipkow
parents: 1465
diff changeset
    82
  br hoare.conseq 1;
03f096efa26d Modified datatype com.
nipkow
parents: 1465
diff changeset
    83
    by(fast_tac HOL_cs 2);
03f096efa26d Modified datatype com.
nipkow
parents: 1465
diff changeset
    84
   by(fast_tac HOL_cs 2);
03f096efa26d Modified datatype com.
nipkow
parents: 1465
diff changeset
    85
  by(fast_tac HOL_cs 1);
03f096efa26d Modified datatype com.
nipkow
parents: 1465
diff changeset
    86
 br hoare.conseq 1;
03f096efa26d Modified datatype com.
nipkow
parents: 1465
diff changeset
    87
   by(fast_tac HOL_cs 2);
03f096efa26d Modified datatype com.
nipkow
parents: 1465
diff changeset
    88
  by(fast_tac HOL_cs 2);
03f096efa26d Modified datatype com.
nipkow
parents: 1465
diff changeset
    89
 by(fast_tac HOL_cs 1);
03f096efa26d Modified datatype com.
nipkow
parents: 1465
diff changeset
    90
br hoare.conseq 1;
03f096efa26d Modified datatype com.
nipkow
parents: 1465
diff changeset
    91
  br hoare.While 2;
03f096efa26d Modified datatype com.
nipkow
parents: 1465
diff changeset
    92
  be thin_rl 1;
03f096efa26d Modified datatype com.
nipkow
parents: 1465
diff changeset
    93
  by(fast_tac HOL_cs 1);
03f096efa26d Modified datatype com.
nipkow
parents: 1465
diff changeset
    94
 br hoare.conseq 1;
03f096efa26d Modified datatype com.
nipkow
parents: 1465
diff changeset
    95
   be thin_rl 3;
03f096efa26d Modified datatype com.
nipkow
parents: 1465
diff changeset
    96
   br allI 3;
03f096efa26d Modified datatype com.
nipkow
parents: 1465
diff changeset
    97
   br impI 3;
03f096efa26d Modified datatype com.
nipkow
parents: 1465
diff changeset
    98
   ba 3;
03f096efa26d Modified datatype com.
nipkow
parents: 1465
diff changeset
    99
  by(fast_tac HOL_cs 2);
03f096efa26d Modified datatype com.
nipkow
parents: 1465
diff changeset
   100
 by(safe_tac HOL_cs);
03f096efa26d Modified datatype com.
nipkow
parents: 1465
diff changeset
   101
 by(rotate_tac ~1 1);
03f096efa26d Modified datatype com.
nipkow
parents: 1465
diff changeset
   102
 by(Asm_full_simp_tac 1);
03f096efa26d Modified datatype com.
nipkow
parents: 1465
diff changeset
   103
by(rotate_tac ~1 1);
03f096efa26d Modified datatype com.
nipkow
parents: 1465
diff changeset
   104
by(Asm_full_simp_tac 1);
03f096efa26d Modified datatype com.
nipkow
parents: 1465
diff changeset
   105
bind_thm("swp_is_pre", result() RS spec);
03f096efa26d Modified datatype com.
nipkow
parents: 1465
diff changeset
   106
03f096efa26d Modified datatype com.
nipkow
parents: 1465
diff changeset
   107
goal Hoare.thy "!!c. |= {{P}}c{{Q}} ==> {{P}}c{{Q}}";
03f096efa26d Modified datatype com.
nipkow
parents: 1465
diff changeset
   108
br (swp_is_pre RSN (2,hoare.conseq)) 1;
03f096efa26d Modified datatype com.
nipkow
parents: 1465
diff changeset
   109
 by(fast_tac HOL_cs 2);
03f096efa26d Modified datatype com.
nipkow
parents: 1465
diff changeset
   110
be swp_is_weakest 1;
03f096efa26d Modified datatype com.
nipkow
parents: 1465
diff changeset
   111
qed "hoare_relative_complete";