src/HOL/Fun_Def.thy
 author blanchet Wed Sep 24 15:45:55 2014 +0200 (2014-09-24) changeset 58425 246985c6b20b parent 58377 c6f93b8d2d8e child 58819 aa43c6f05bca permissions -rw-r--r--
simpler proof
 blanchet@55085 ` 1` ```(* Title: HOL/Fun_Def.thy ``` wenzelm@20324 ` 2` ``` Author: Alexander Krauss, TU Muenchen ``` wenzelm@22816 ` 3` ```*) ``` wenzelm@20324 ` 4` krauss@29125 ` 5` ```header {* Function Definitions and Termination Proofs *} ``` wenzelm@20324 ` 6` blanchet@55085 ` 7` ```theory Fun_Def ``` blanchet@58377 ` 8` ```imports Basic_BNF_Least_Fixpoints Partial_Function SAT ``` Manuel@53603 ` 9` ```keywords "function" "termination" :: thy_goal and "fun" "fun_cases" :: thy_decl ``` krauss@19564 ` 10` ```begin ``` krauss@19564 ` 11` blanchet@55085 ` 12` ```subsection {* Definitions with default value *} ``` krauss@20536 ` 13` krauss@20536 ` 14` ```definition ``` wenzelm@21404 ` 15` ``` THE_default :: "'a \ ('a \ bool) \ 'a" where ``` krauss@20536 ` 16` ``` "THE_default d P = (if (\!x. P x) then (THE x. P x) else d)" ``` krauss@20536 ` 17` krauss@20536 ` 18` ```lemma THE_defaultI': "\!x. P x \ P (THE_default d P)" ``` wenzelm@22816 ` 19` ``` by (simp add: theI' THE_default_def) ``` krauss@20536 ` 20` wenzelm@22816 ` 21` ```lemma THE_default1_equality: ``` wenzelm@22816 ` 22` ``` "\\!x. P x; P a\ \ THE_default d P = a" ``` wenzelm@22816 ` 23` ``` by (simp add: the1_equality THE_default_def) ``` krauss@20536 ` 24` krauss@20536 ` 25` ```lemma THE_default_none: ``` wenzelm@22816 ` 26` ``` "\(\!x. P x) \ THE_default d P = d" ``` wenzelm@22816 ` 27` ``` by (simp add:THE_default_def) ``` krauss@20536 ` 28` krauss@20536 ` 29` krauss@19564 ` 30` ```lemma fundef_ex1_existence: ``` wenzelm@22816 ` 31` ``` assumes f_def: "f == (\x::'a. THE_default (d x) (\y. G x y))" ``` wenzelm@22816 ` 32` ``` assumes ex1: "\!y. G x y" ``` wenzelm@22816 ` 33` ``` shows "G x (f x)" ``` wenzelm@22816 ` 34` ``` apply (simp only: f_def) ``` wenzelm@22816 ` 35` ``` apply (rule THE_defaultI') ``` wenzelm@22816 ` 36` ``` apply (rule ex1) ``` wenzelm@22816 ` 37` ``` done ``` krauss@21051 ` 38` krauss@19564 ` 39` ```lemma fundef_ex1_uniqueness: ``` wenzelm@22816 ` 40` ``` assumes f_def: "f == (\x::'a. THE_default (d x) (\y. G x y))" ``` wenzelm@22816 ` 41` ``` assumes ex1: "\!y. G x y" ``` wenzelm@22816 ` 42` ``` assumes elm: "G x (h x)" ``` wenzelm@22816 ` 43` ``` shows "h x = f x" ``` wenzelm@22816 ` 44` ``` apply (simp only: f_def) ``` wenzelm@22816 ` 45` ``` apply (rule THE_default1_equality [symmetric]) ``` wenzelm@22816 ` 46` ``` apply (rule ex1) ``` wenzelm@22816 ` 47` ``` apply (rule elm) ``` wenzelm@22816 ` 48` ``` done ``` krauss@19564 ` 49` krauss@19564 ` 50` ```lemma fundef_ex1_iff: ``` wenzelm@22816 ` 51` ``` assumes f_def: "f == (\x::'a. THE_default (d x) (\y. G x y))" ``` wenzelm@22816 ` 52` ``` assumes ex1: "\!y. G x y" ``` wenzelm@22816 ` 53` ``` shows "(G x y) = (f x = y)" ``` krauss@20536 ` 54` ``` apply (auto simp:ex1 f_def THE_default1_equality) ``` wenzelm@22816 ` 55` ``` apply (rule THE_defaultI') ``` wenzelm@22816 ` 56` ``` apply (rule ex1) ``` wenzelm@22816 ` 57` ``` done ``` krauss@19564 ` 58` krauss@20654 ` 59` ```lemma fundef_default_value: ``` wenzelm@22816 ` 60` ``` assumes f_def: "f == (\x::'a. THE_default (d x) (\y. G x y))" ``` wenzelm@22816 ` 61` ``` assumes graph: "\x y. G x y \ D x" ``` wenzelm@22816 ` 62` ``` assumes "\ D x" ``` wenzelm@22816 ` 63` ``` shows "f x = d x" ``` krauss@20654 ` 64` ```proof - ``` krauss@21051 ` 65` ``` have "\(\y. G x y)" ``` krauss@20654 ` 66` ``` proof ``` krauss@21512 ` 67` ``` assume "\y. G x y" ``` krauss@21512 ` 68` ``` hence "D x" using graph .. ``` krauss@21512 ` 69` ``` with `\ D x` show False .. ``` krauss@20654 ` 70` ``` qed ``` krauss@21051 ` 71` ``` hence "\(\!y. G x y)" by blast ``` wenzelm@22816 ` 72` krauss@20654 ` 73` ``` thus ?thesis ``` krauss@20654 ` 74` ``` unfolding f_def ``` krauss@20654 ` 75` ``` by (rule THE_default_none) ``` krauss@20654 ` 76` ```qed ``` krauss@20654 ` 77` berghofe@23739 ` 78` ```definition in_rel_def[simp]: ``` berghofe@23739 ` 79` ``` "in_rel R x y == (x, y) \ R" ``` berghofe@23739 ` 80` berghofe@23739 ` 81` ```lemma wf_in_rel: ``` berghofe@23739 ` 82` ``` "wf R \ wfP (in_rel R)" ``` berghofe@23739 ` 83` ``` by (simp add: wfP_def) ``` berghofe@23739 ` 84` wenzelm@48891 ` 85` ```ML_file "Tools/Function/function_core.ML" ``` wenzelm@48891 ` 86` ```ML_file "Tools/Function/mutual.ML" ``` wenzelm@48891 ` 87` ```ML_file "Tools/Function/pattern_split.ML" ``` wenzelm@48891 ` 88` ```ML_file "Tools/Function/relation.ML" ``` Manuel@53603 ` 89` ```ML_file "Tools/Function/function_elims.ML" ``` wenzelm@47701 ` 90` wenzelm@47701 ` 91` ```method_setup relation = {* ``` wenzelm@47701 ` 92` ``` Args.term >> (fn t => fn ctxt => SIMPLE_METHOD' (Function_Relation.relation_infer_tac ctxt t)) ``` wenzelm@47701 ` 93` ```*} "prove termination using a user-specified wellfounded relation" ``` wenzelm@47701 ` 94` wenzelm@48891 ` 95` ```ML_file "Tools/Function/function.ML" ``` wenzelm@48891 ` 96` ```ML_file "Tools/Function/pat_completeness.ML" ``` wenzelm@47432 ` 97` wenzelm@47432 ` 98` ```method_setup pat_completeness = {* ``` wenzelm@47432 ` 99` ``` Scan.succeed (SIMPLE_METHOD' o Pat_Completeness.pat_completeness_tac) ``` blanchet@58305 ` 100` ```*} "prove completeness of (co)datatype patterns" ``` wenzelm@47432 ` 101` wenzelm@48891 ` 102` ```ML_file "Tools/Function/fun.ML" ``` wenzelm@48891 ` 103` ```ML_file "Tools/Function/induction_schema.ML" ``` krauss@19564 ` 104` wenzelm@47432 ` 105` ```method_setup induction_schema = {* ``` wenzelm@58002 ` 106` ``` Scan.succeed (NO_CASES oo Induction_Schema.induction_schema_tac) ``` wenzelm@47432 ` 107` ```*} "prove an induction principle" ``` wenzelm@47432 ` 108` wenzelm@47701 ` 109` ```setup {* ``` krauss@33099 ` 110` ``` Function.setup ``` krauss@33098 ` 111` ``` #> Function_Fun.setup ``` krauss@25567 ` 112` ```*} ``` krauss@19770 ` 113` blanchet@56643 ` 114` blanchet@56643 ` 115` ```subsection {* Measure functions *} ``` krauss@29125 ` 116` krauss@29125 ` 117` ```inductive is_measure :: "('a \ nat) \ bool" ``` krauss@29125 ` 118` ```where is_measure_trivial: "is_measure f" ``` krauss@29125 ` 119` wenzelm@57959 ` 120` ```named_theorems measure_function "rules that guide the heuristic generation of measure functions" ``` wenzelm@48891 ` 121` ```ML_file "Tools/Function/measure_functions.ML" ``` krauss@29125 ` 122` krauss@29125 ` 123` ```lemma measure_size[measure_function]: "is_measure size" ``` krauss@29125 ` 124` ```by (rule is_measure_trivial) ``` krauss@29125 ` 125` krauss@29125 ` 126` ```lemma measure_fst[measure_function]: "is_measure f \ is_measure (\p. f (fst p))" ``` krauss@29125 ` 127` ```by (rule is_measure_trivial) ``` krauss@29125 ` 128` ```lemma measure_snd[measure_function]: "is_measure f \ is_measure (\p. f (snd p))" ``` krauss@29125 ` 129` ```by (rule is_measure_trivial) ``` krauss@29125 ` 130` wenzelm@48891 ` 131` ```ML_file "Tools/Function/lexicographic_order.ML" ``` wenzelm@47432 ` 132` wenzelm@47432 ` 133` ```method_setup lexicographic_order = {* ``` wenzelm@47432 ` 134` ``` Method.sections clasimp_modifiers >> ``` wenzelm@47432 ` 135` ``` (K (SIMPLE_METHOD o Lexicographic_Order.lexicographic_order_tac false)) ``` wenzelm@47432 ` 136` ```*} "termination prover for lexicographic orderings" ``` wenzelm@47432 ` 137` wenzelm@47701 ` 138` ```setup Lexicographic_Order.setup ``` krauss@29125 ` 139` krauss@29125 ` 140` blanchet@56643 ` 141` ```subsection {* Congruence rules *} ``` krauss@29125 ` 142` haftmann@22838 ` 143` ```lemma let_cong [fundef_cong]: ``` haftmann@22838 ` 144` ``` "M = N \ (\x. x = N \ f x = g x) \ Let M f = Let N g" ``` wenzelm@22816 ` 145` ``` unfolding Let_def by blast ``` krauss@22622 ` 146` wenzelm@22816 ` 147` ```lemmas [fundef_cong] = ``` haftmann@56248 ` 148` ``` if_cong image_cong INF_cong SUP_cong ``` blanchet@55466 ` 149` ``` bex_cong ball_cong imp_cong map_option_cong Option.bind_cong ``` krauss@19564 ` 150` wenzelm@22816 ` 151` ```lemma split_cong [fundef_cong]: ``` haftmann@22838 ` 152` ``` "(\x y. (x, y) = q \ f x y = g x y) \ p = q ``` wenzelm@22816 ` 153` ``` \ split f p = split g q" ``` wenzelm@22816 ` 154` ``` by (auto simp: split_def) ``` krauss@19934 ` 155` wenzelm@22816 ` 156` ```lemma comp_cong [fundef_cong]: ``` haftmann@22838 ` 157` ``` "f (g x) = f' (g' x') \ (f o g) x = (f' o g') x'" ``` wenzelm@22816 ` 158` ``` unfolding o_apply . ``` krauss@19934 ` 159` blanchet@56643 ` 160` krauss@29125 ` 161` ```subsection {* Simp rules for termination proofs *} ``` krauss@26875 ` 162` blanchet@56643 ` 163` ```declare ``` blanchet@56643 ` 164` ``` trans_less_add1[termination_simp] ``` blanchet@56643 ` 165` ``` trans_less_add2[termination_simp] ``` blanchet@56643 ` 166` ``` trans_le_add1[termination_simp] ``` blanchet@56643 ` 167` ``` trans_le_add2[termination_simp] ``` blanchet@56643 ` 168` ``` less_imp_le_nat[termination_simp] ``` blanchet@56643 ` 169` ``` le_imp_less_Suc[termination_simp] ``` krauss@26875 ` 170` blanchet@56846 ` 171` ```lemma size_prod_simp[termination_simp]: ``` blanchet@56846 ` 172` ``` "size_prod f g p = f (fst p) + g (snd p) + Suc 0" ``` krauss@26875 ` 173` ```by (induct p) auto ``` krauss@26875 ` 174` blanchet@56643 ` 175` krauss@29125 ` 176` ```subsection {* Decomposition *} ``` krauss@29125 ` 177` wenzelm@47701 ` 178` ```lemma less_by_empty: ``` krauss@29125 ` 179` ``` "A = {} \ A \ B" ``` krauss@29125 ` 180` ```and union_comp_emptyL: ``` krauss@29125 ` 181` ``` "\ A O C = {}; B O C = {} \ \ (A \ B) O C = {}" ``` krauss@29125 ` 182` ```and union_comp_emptyR: ``` krauss@29125 ` 183` ``` "\ A O B = {}; A O C = {} \ \ A O (B \ C) = {}" ``` wenzelm@47701 ` 184` ```and wf_no_loop: ``` krauss@29125 ` 185` ``` "R O R = {} \ wf R" ``` krauss@29125 ` 186` ```by (auto simp add: wf_comp_self[of R]) ``` krauss@29125 ` 187` krauss@29125 ` 188` blanchet@56643 ` 189` ```subsection {* Reduction pairs *} ``` krauss@29125 ` 190` krauss@29125 ` 191` ```definition ``` krauss@32235 ` 192` ``` "reduction_pair P = (wf (fst P) \ fst P O snd P \ fst P)" ``` krauss@29125 ` 193` krauss@32235 ` 194` ```lemma reduction_pairI[intro]: "wf R \ R O S \ R \ reduction_pair (R, S)" ``` krauss@29125 ` 195` ```unfolding reduction_pair_def by auto ``` krauss@29125 ` 196` krauss@29125 ` 197` ```lemma reduction_pair_lemma: ``` krauss@29125 ` 198` ``` assumes rp: "reduction_pair P" ``` krauss@29125 ` 199` ``` assumes "R \ fst P" ``` krauss@29125 ` 200` ``` assumes "S \ snd P" ``` krauss@29125 ` 201` ``` assumes "wf S" ``` krauss@29125 ` 202` ``` shows "wf (R \ S)" ``` krauss@29125 ` 203` ```proof - ``` krauss@32235 ` 204` ``` from rp `S \ snd P` have "wf (fst P)" "fst P O S \ fst P" ``` krauss@29125 ` 205` ``` unfolding reduction_pair_def by auto ``` wenzelm@47701 ` 206` ``` with `wf S` have "wf (fst P \ S)" ``` krauss@29125 ` 207` ``` by (auto intro: wf_union_compatible) ``` krauss@29125 ` 208` ``` moreover from `R \ fst P` have "R \ S \ fst P \ S" by auto ``` wenzelm@47701 ` 209` ``` ultimately show ?thesis by (rule wf_subset) ``` krauss@29125 ` 210` ```qed ``` krauss@29125 ` 211` krauss@29125 ` 212` ```definition ``` krauss@29125 ` 213` ``` "rp_inv_image = (\(R,S) f. (inv_image R f, inv_image S f))" ``` krauss@29125 ` 214` krauss@29125 ` 215` ```lemma rp_inv_image_rp: ``` krauss@29125 ` 216` ``` "reduction_pair P \ reduction_pair (rp_inv_image P f)" ``` krauss@29125 ` 217` ``` unfolding reduction_pair_def rp_inv_image_def split_def ``` krauss@29125 ` 218` ``` by force ``` krauss@29125 ` 219` krauss@29125 ` 220` krauss@29125 ` 221` ```subsection {* Concrete orders for SCNP termination proofs *} ``` krauss@29125 ` 222` krauss@29125 ` 223` ```definition "pair_less = less_than <*lex*> less_than" ``` haftmann@37767 ` 224` ```definition "pair_leq = pair_less^=" ``` krauss@29125 ` 225` ```definition "max_strict = max_ext pair_less" ``` haftmann@37767 ` 226` ```definition "max_weak = max_ext pair_leq \ {({}, {})}" ``` haftmann@37767 ` 227` ```definition "min_strict = min_ext pair_less" ``` haftmann@37767 ` 228` ```definition "min_weak = min_ext pair_leq \ {({}, {})}" ``` krauss@29125 ` 229` krauss@29125 ` 230` ```lemma wf_pair_less[simp]: "wf pair_less" ``` krauss@29125 ` 231` ``` by (auto simp: pair_less_def) ``` krauss@29125 ` 232` wenzelm@29127 ` 233` ```text {* Introduction rules for @{text pair_less}/@{text pair_leq} *} ``` krauss@29125 ` 234` ```lemma pair_leqI1: "a < b \ ((a, s), (b, t)) \ pair_leq" ``` krauss@29125 ` 235` ``` and pair_leqI2: "a \ b \ s \ t \ ((a, s), (b, t)) \ pair_leq" ``` krauss@29125 ` 236` ``` and pair_lessI1: "a < b \ ((a, s), (b, t)) \ pair_less" ``` krauss@29125 ` 237` ``` and pair_lessI2: "a \ b \ s < t \ ((a, s), (b, t)) \ pair_less" ``` krauss@29125 ` 238` ``` unfolding pair_leq_def pair_less_def by auto ``` krauss@29125 ` 239` krauss@29125 ` 240` ```text {* Introduction rules for max *} ``` wenzelm@47701 ` 241` ```lemma smax_emptyI: ``` wenzelm@47701 ` 242` ``` "finite Y \ Y \ {} \ ({}, Y) \ max_strict" ``` wenzelm@47701 ` 243` ``` and smax_insertI: ``` krauss@29125 ` 244` ``` "\y \ Y; (x, y) \ pair_less; (X, Y) \ max_strict\ \ (insert x X, Y) \ max_strict" ``` wenzelm@47701 ` 245` ``` and wmax_emptyI: ``` wenzelm@47701 ` 246` ``` "finite X \ ({}, X) \ max_weak" ``` krauss@29125 ` 247` ``` and wmax_insertI: ``` wenzelm@47701 ` 248` ``` "\y \ YS; (x, y) \ pair_leq; (XS, YS) \ max_weak\ \ (insert x XS, YS) \ max_weak" ``` krauss@29125 ` 249` ```unfolding max_strict_def max_weak_def by (auto elim!: max_ext.cases) ``` krauss@29125 ` 250` krauss@29125 ` 251` ```text {* Introduction rules for min *} ``` wenzelm@47701 ` 252` ```lemma smin_emptyI: ``` wenzelm@47701 ` 253` ``` "X \ {} \ (X, {}) \ min_strict" ``` wenzelm@47701 ` 254` ``` and smin_insertI: ``` krauss@29125 ` 255` ``` "\x \ XS; (x, y) \ pair_less; (XS, YS) \ min_strict\ \ (XS, insert y YS) \ min_strict" ``` wenzelm@47701 ` 256` ``` and wmin_emptyI: ``` wenzelm@47701 ` 257` ``` "(X, {}) \ min_weak" ``` wenzelm@47701 ` 258` ``` and wmin_insertI: ``` wenzelm@47701 ` 259` ``` "\x \ XS; (x, y) \ pair_leq; (XS, YS) \ min_weak\ \ (XS, insert y YS) \ min_weak" ``` krauss@29125 ` 260` ```by (auto simp: min_strict_def min_weak_def min_ext_def) ``` krauss@29125 ` 261` krauss@29125 ` 262` ```text {* Reduction Pairs *} ``` krauss@29125 ` 263` wenzelm@47701 ` 264` ```lemma max_ext_compat: ``` krauss@32235 ` 265` ``` assumes "R O S \ R" ``` krauss@32235 ` 266` ``` shows "max_ext R O (max_ext S \ {({},{})}) \ max_ext R" ``` wenzelm@47701 ` 267` ```using assms ``` krauss@29125 ` 268` ```apply auto ``` krauss@29125 ` 269` ```apply (elim max_ext.cases) ``` krauss@29125 ` 270` ```apply rule ``` krauss@29125 ` 271` ```apply auto[3] ``` krauss@29125 ` 272` ```apply (drule_tac x=xa in meta_spec) ``` krauss@29125 ` 273` ```apply simp ``` krauss@29125 ` 274` ```apply (erule bexE) ``` krauss@29125 ` 275` ```apply (drule_tac x=xb in meta_spec) ``` krauss@29125 ` 276` ```by auto ``` krauss@29125 ` 277` krauss@29125 ` 278` ```lemma max_rpair_set: "reduction_pair (max_strict, max_weak)" ``` wenzelm@47701 ` 279` ``` unfolding max_strict_def max_weak_def ``` krauss@29125 ` 280` ```apply (intro reduction_pairI max_ext_wf) ``` krauss@29125 ` 281` ```apply simp ``` krauss@29125 ` 282` ```apply (rule max_ext_compat) ``` krauss@29125 ` 283` ```by (auto simp: pair_less_def pair_leq_def) ``` krauss@29125 ` 284` wenzelm@47701 ` 285` ```lemma min_ext_compat: ``` krauss@32235 ` 286` ``` assumes "R O S \ R" ``` krauss@32235 ` 287` ``` shows "min_ext R O (min_ext S \ {({},{})}) \ min_ext R" ``` wenzelm@47701 ` 288` ```using assms ``` krauss@29125 ` 289` ```apply (auto simp: min_ext_def) ``` krauss@29125 ` 290` ```apply (drule_tac x=ya in bspec, assumption) ``` krauss@29125 ` 291` ```apply (erule bexE) ``` krauss@29125 ` 292` ```apply (drule_tac x=xc in bspec) ``` krauss@29125 ` 293` ```apply assumption ``` krauss@29125 ` 294` ```by auto ``` krauss@29125 ` 295` krauss@29125 ` 296` ```lemma min_rpair_set: "reduction_pair (min_strict, min_weak)" ``` wenzelm@47701 ` 297` ``` unfolding min_strict_def min_weak_def ``` krauss@29125 ` 298` ```apply (intro reduction_pairI min_ext_wf) ``` krauss@29125 ` 299` ```apply simp ``` krauss@29125 ` 300` ```apply (rule min_ext_compat) ``` krauss@29125 ` 301` ```by (auto simp: pair_less_def pair_leq_def) ``` krauss@29125 ` 302` krauss@29125 ` 303` krauss@29125 ` 304` ```subsection {* Tool setup *} ``` krauss@29125 ` 305` wenzelm@48891 ` 306` ```ML_file "Tools/Function/termination.ML" ``` wenzelm@48891 ` 307` ```ML_file "Tools/Function/scnp_solve.ML" ``` wenzelm@48891 ` 308` ```ML_file "Tools/Function/scnp_reconstruct.ML" ``` Manuel@53603 ` 309` ```ML_file "Tools/Function/fun_cases.ML" ``` krauss@29125 ` 310` blanchet@54407 ` 311` ```setup ScnpReconstruct.setup ``` wenzelm@30480 ` 312` wenzelm@30480 ` 313` ```ML_val -- "setup inactive" ``` wenzelm@30480 ` 314` ```{* ``` krauss@36521 ` 315` ``` Context.theory_map (Function_Common.set_termination_prover ``` krauss@36521 ` 316` ``` (ScnpReconstruct.decomp_scnp_tac [ScnpSolve.MAX, ScnpSolve.MIN, ScnpSolve.MS])) ``` krauss@29125 ` 317` ```*} ``` krauss@26875 ` 318` krauss@19564 ` 319` ```end ```