47269
|
1 |
%
|
|
2 |
\begin{isabellebody}%
|
|
3 |
\def\isabellecontext{Basics}%
|
|
4 |
%
|
|
5 |
\isadelimtheory
|
|
6 |
%
|
|
7 |
\endisadelimtheory
|
|
8 |
%
|
|
9 |
\isatagtheory
|
|
10 |
%
|
|
11 |
\endisatagtheory
|
|
12 |
{\isafoldtheory}%
|
|
13 |
%
|
|
14 |
\isadelimtheory
|
|
15 |
%
|
|
16 |
\endisadelimtheory
|
|
17 |
%
|
|
18 |
\begin{isamarkuptext}%
|
|
19 |
This chapter introduces HOL as a functional programming language and shows
|
|
20 |
how to prove properties of functional programs by induction.
|
|
21 |
|
|
22 |
\section{Basics}
|
|
23 |
|
|
24 |
\subsection{Types, Terms and Formulae}
|
|
25 |
\label{sec:TypesTermsForms}
|
|
26 |
|
|
27 |
HOL is a typed logic whose type system resembles that of functional
|
|
28 |
programming languages. Thus there are
|
|
29 |
\begin{description}
|
|
30 |
\item[base types,]
|
|
31 |
in particular \isa{bool}, the type of truth values,
|
|
32 |
\isa{nat}, the type of natural numbers ($\mathbb{N}$), and \isa{int},
|
|
33 |
the type of mathematical integers ($\mathbb{Z}$).
|
|
34 |
\item[type constructors,]
|
|
35 |
in particular \isa{list}, the type of
|
|
36 |
lists, and \isa{set}, the type of sets. Type constructors are written
|
|
37 |
postfix, e.g.\ \isa{nat\ list} is the type of lists whose elements are
|
|
38 |
natural numbers.
|
|
39 |
\item[function types,]
|
|
40 |
denoted by \isa{{\isaliteral{5C3C52696768746172726F773E}{\isasymRightarrow}}}.
|
|
41 |
\item[type variables,]
|
|
42 |
denoted by \isa{{\isaliteral{27}{\isacharprime}}a}, \isa{{\isaliteral{27}{\isacharprime}}b} etc., just like in ML\@.
|
|
43 |
\end{description}
|
|
44 |
|
|
45 |
\concept{Terms} are formed as in functional programming by
|
|
46 |
applying functions to arguments. If \isa{f} is a function of type
|
|
47 |
\isa{{\isaliteral{5C3C7461753E}{\isasymtau}}\isaliteral{5C3C5E697375623E}{}\isactrlisub {\isadigit{1}}\ {\isaliteral{5C3C52696768746172726F773E}{\isasymRightarrow}}\ {\isaliteral{5C3C7461753E}{\isasymtau}}\isaliteral{5C3C5E697375623E}{}\isactrlisub {\isadigit{2}}} and \isa{t} is a term of type
|
|
48 |
\isa{{\isaliteral{5C3C7461753E}{\isasymtau}}\isaliteral{5C3C5E697375623E}{}\isactrlisub {\isadigit{1}}} then \isa{f\ t} is a term of type \isa{{\isaliteral{5C3C7461753E}{\isasymtau}}\isaliteral{5C3C5E697375623E}{}\isactrlisub {\isadigit{2}}}. We write \isa{t\ {\isaliteral{3A}{\isacharcolon}}{\isaliteral{3A}{\isacharcolon}}\ {\isaliteral{5C3C7461753E}{\isasymtau}}} to mean that term \isa{t} has type \isa{{\isaliteral{5C3C7461753E}{\isasymtau}}}.
|
|
49 |
|
|
50 |
\begin{warn}
|
|
51 |
There are many predefined infix symbols like \isa{{\isaliteral{2B}{\isacharplus}}} and \isa{{\isaliteral{5C3C6C653E}{\isasymle}}}.
|
|
52 |
The name of the corresponding binary function is \isa{op\ {\isaliteral{2B}{\isacharplus}}},
|
|
53 |
not just \isa{{\isaliteral{2B}{\isacharplus}}}. That is, \isa{x\ {\isaliteral{2B}{\isacharplus}}\ y} is syntactic sugar for
|
|
54 |
\noquotes{\isa{{\isaliteral{22}{\isachardoublequote}}op\ {\isaliteral{2B}{\isacharplus}}\ x\ y{\isaliteral{22}{\isachardoublequote}}}}.
|
|
55 |
\end{warn}
|
|
56 |
|
|
57 |
HOL also supports some basic constructs from functional programming:
|
|
58 |
\begin{quote}
|
|
59 |
\isa{{\isaliteral{28}{\isacharparenleft}}if\ b\ then\ t\isaliteral{5C3C5E697375623E}{}\isactrlisub {\isadigit{1}}\ else\ t\isaliteral{5C3C5E697375623E}{}\isactrlisub {\isadigit{2}}{\isaliteral{29}{\isacharparenright}}}\\
|
|
60 |
\isa{{\isaliteral{28}{\isacharparenleft}}let\ x\ {\isaliteral{3D}{\isacharequal}}\ t\ in\ u{\isaliteral{29}{\isacharparenright}}}\\
|
|
61 |
\isa{{\isaliteral{28}{\isacharparenleft}}case\ t\ of\ pat\isaliteral{5C3C5E697375623E}{}\isactrlisub {\isadigit{1}}\ {\isaliteral{5C3C52696768746172726F773E}{\isasymRightarrow}}\ t\isaliteral{5C3C5E697375623E}{}\isactrlisub {\isadigit{1}}\ {\isaliteral{7C}{\isacharbar}}\ {\isaliteral{5C3C646F74733E}{\isasymdots}}\ {\isaliteral{7C}{\isacharbar}}\ pat\isaliteral{5C3C5E697375623E}{}\isactrlisub n\ {\isaliteral{5C3C52696768746172726F773E}{\isasymRightarrow}}\ t\isaliteral{5C3C5E697375623E}{}\isactrlisub n{\isaliteral{29}{\isacharparenright}}}
|
|
62 |
\end{quote}
|
|
63 |
\begin{warn}
|
|
64 |
The above three constructs must always be enclosed in parentheses
|
|
65 |
if they occur inside other constructs.
|
|
66 |
\end{warn}
|
|
67 |
Terms may also contain \isa{{\isaliteral{5C3C6C616D6264613E}{\isasymlambda}}}-abstractions. For example,
|
|
68 |
\isa{{\isaliteral{5C3C6C616D6264613E}{\isasymlambda}}x{\isaliteral{2E}{\isachardot}}\ x} is the identity function.
|
|
69 |
|
|
70 |
\concept{Formulae} are terms of type \isa{bool}.
|
|
71 |
There are the basic constants \isa{True} and \isa{False} and
|
|
72 |
the usual logical connectives (in decreasing order of precedence):
|
|
73 |
\isa{{\isaliteral{5C3C6E6F743E}{\isasymnot}}}, \isa{{\isaliteral{5C3C616E643E}{\isasymand}}}, \isa{{\isaliteral{5C3C6F723E}{\isasymor}}}, \isa{{\isaliteral{5C3C6C6F6E6772696768746172726F773E}{\isasymlongrightarrow}}}.
|
|
74 |
|
|
75 |
\concept{Equality} is available in the form of the infix function \isa{{\isaliteral{3D}{\isacharequal}}}
|
|
76 |
of type \isa{{\isaliteral{27}{\isacharprime}}a\ {\isaliteral{5C3C52696768746172726F773E}{\isasymRightarrow}}\ {\isaliteral{27}{\isacharprime}}a\ {\isaliteral{5C3C52696768746172726F773E}{\isasymRightarrow}}\ bool}. It also works for formulas, where
|
|
77 |
it means ``if and only if''.
|
|
78 |
|
|
79 |
\concept{Quantifiers} are written \isa{{\isaliteral{5C3C666F72616C6C3E}{\isasymforall}}x{\isaliteral{2E}{\isachardot}}\ P} and \isa{{\isaliteral{5C3C6578697374733E}{\isasymexists}}x{\isaliteral{2E}{\isachardot}}\ P}.
|
|
80 |
|
|
81 |
Isabelle automatically computes the type of each variable in a term. This is
|
|
82 |
called \concept{type inference}. Despite type inference, it is sometimes
|
|
83 |
necessary to attach explicit \concept{type constraints} (or \concept{type
|
|
84 |
annotations}) to a variable or term. The syntax is \isa{t\ {\isaliteral{3A}{\isacharcolon}}{\isaliteral{3A}{\isacharcolon}}\ {\isaliteral{5C3C7461753E}{\isasymtau}}} as in
|
|
85 |
\mbox{\noquotes{\isa{{\isaliteral{22}{\isachardoublequote}}m\ {\isaliteral{3C}{\isacharless}}\ {\isaliteral{28}{\isacharparenleft}}n{\isaliteral{3A}{\isacharcolon}}{\isaliteral{3A}{\isacharcolon}}nat{\isaliteral{29}{\isacharparenright}}{\isaliteral{22}{\isachardoublequote}}}}}. Type constraints may be
|
|
86 |
needed to
|
|
87 |
disambiguate terms involving overloaded functions such as \isa{{\isaliteral{2B}{\isacharplus}}}, \isa{{\isaliteral{2A}{\isacharasterisk}}} and \isa{{\isaliteral{5C3C6C653E}{\isasymle}}}.
|
|
88 |
|
|
89 |
Finally there are the universal quantifier \isa{{\isaliteral{5C3C416E643E}{\isasymAnd}}} and the implication
|
|
90 |
\isa{{\isaliteral{5C3C4C6F6E6772696768746172726F773E}{\isasymLongrightarrow}}}. They are part of the Isabelle framework, not the logic
|
|
91 |
HOL. Logically, they agree with their HOL counterparts \isa{{\isaliteral{5C3C666F72616C6C3E}{\isasymforall}}} and
|
|
92 |
\isa{{\isaliteral{5C3C6C6F6E6772696768746172726F773E}{\isasymlongrightarrow}}}, but operationally they behave differently. This will become
|
|
93 |
clearer as we go along.
|
|
94 |
\begin{warn}
|
|
95 |
Right-arrows of all kinds always associate to the right. In particular,
|
|
96 |
the formula
|
|
97 |
\isa{A\isaliteral{5C3C5E697375623E}{}\isactrlisub {\isadigit{1}}\ {\isaliteral{5C3C4C6F6E6772696768746172726F773E}{\isasymLongrightarrow}}\ A\isaliteral{5C3C5E697375623E}{}\isactrlisub {\isadigit{2}}\ {\isaliteral{5C3C4C6F6E6772696768746172726F773E}{\isasymLongrightarrow}}\ A\isaliteral{5C3C5E697375623E}{}\isactrlisub {\isadigit{3}}} means \isa{A\isaliteral{5C3C5E697375623E}{}\isactrlisub {\isadigit{1}}\ {\isaliteral{5C3C4C6F6E6772696768746172726F773E}{\isasymLongrightarrow}}\ {\isaliteral{28}{\isacharparenleft}}A\isaliteral{5C3C5E697375623E}{}\isactrlisub {\isadigit{2}}\ {\isaliteral{5C3C4C6F6E6772696768746172726F773E}{\isasymLongrightarrow}}\ A\isaliteral{5C3C5E697375623E}{}\isactrlisub {\isadigit{3}}{\isaliteral{29}{\isacharparenright}}}.
|
|
98 |
The (Isabelle specific) notation \mbox{\isa{{\isaliteral{5C3C6C6272616B6B3E}{\isasymlbrakk}}\ A\isaliteral{5C3C5E697375623E}{}\isactrlisub {\isadigit{1}}{\isaliteral{3B}{\isacharsemicolon}}\ {\isaliteral{5C3C646F74733E}{\isasymdots}}{\isaliteral{3B}{\isacharsemicolon}}\ A\isaliteral{5C3C5E697375623E}{}\isactrlisub n\ {\isaliteral{5C3C726272616B6B3E}{\isasymrbrakk}}\ {\isaliteral{5C3C4C6F6E6772696768746172726F773E}{\isasymLongrightarrow}}\ A}}
|
|
99 |
is short for the iterated implication \mbox{\isa{A\isaliteral{5C3C5E697375623E}{}\isactrlisub {\isadigit{1}}\ {\isaliteral{5C3C4C6F6E6772696768746172726F773E}{\isasymLongrightarrow}}\ {\isaliteral{5C3C646F74733E}{\isasymdots}}\ {\isaliteral{5C3C4C6F6E6772696768746172726F773E}{\isasymLongrightarrow}}\ A\isaliteral{5C3C5E697375623E}{}\isactrlisub n\ {\isaliteral{5C3C4C6F6E6772696768746172726F773E}{\isasymLongrightarrow}}\ A}}.
|
|
100 |
Sometimes we also employ inference rule notation:
|
|
101 |
\inferrule{\mbox{\isa{A\isaliteral{5C3C5E697375623E}{}\isactrlisub {\isadigit{1}}}}\\ \mbox{\isa{{\isaliteral{5C3C646F74733E}{\isasymdots}}}}\\ \mbox{\isa{A\isaliteral{5C3C5E697375623E}{}\isactrlisub n}}}
|
|
102 |
{\mbox{\isa{A}}}
|
|
103 |
\end{warn}
|
|
104 |
|
|
105 |
|
|
106 |
\subsection{Theories}
|
|
107 |
\label{sec:Basic:Theories}
|
|
108 |
|
|
109 |
Roughly speaking, a \concept{theory} is a named collection of types,
|
|
110 |
functions, and theorems, much like a module in a programming language.
|
|
111 |
All the Isabelle text that you ever type needs to go into a theory.
|
|
112 |
The general format of a theory \isa{T} is
|
|
113 |
\begin{quote}
|
|
114 |
\isacom{theory} \isa{T}\\
|
|
115 |
\isacom{imports} \isa{T\isaliteral{5C3C5E697375623E}{}\isactrlisub {\isadigit{1}}\ {\isaliteral{5C3C646F74733E}{\isasymdots}}\ T\isaliteral{5C3C5E697375623E}{}\isactrlisub n}\\
|
|
116 |
\isacom{begin}\\
|
|
117 |
\emph{definitions, theorems and proofs}\\
|
|
118 |
\isacom{end}
|
|
119 |
\end{quote}
|
|
120 |
where \isa{T\isaliteral{5C3C5E697375623E}{}\isactrlisub {\isadigit{1}}\ {\isaliteral{5C3C646F74733E}{\isasymdots}}\ T\isaliteral{5C3C5E697375623E}{}\isactrlisub n} are the names of existing
|
|
121 |
theories that \isa{T} is based on. The \isa{T\isaliteral{5C3C5E697375623E}{}\isactrlisub i} are the
|
|
122 |
direct \concept{parent theories} of \isa{T}.
|
|
123 |
Everything defined in the parent theories (and their parents, recursively) is
|
|
124 |
automatically visible. Each theory \isa{T} must
|
|
125 |
reside in a \concept{theory file} named \isa{T{\isaliteral{2E}{\isachardot}}thy}.
|
|
126 |
|
|
127 |
\begin{warn}
|
|
128 |
HOL contains a theory \isa{Main}, the union of all the basic
|
|
129 |
predefined theories like arithmetic, lists, sets, etc.
|
|
130 |
Unless you know what you are doing, always include \isa{Main}
|
|
131 |
as a direct or indirect parent of all your theories.
|
|
132 |
\end{warn}
|
|
133 |
|
|
134 |
In addition to the theories that come with the Isabelle/HOL distribution
|
|
135 |
(see \url{http://isabelle.in.tum.de/library/HOL/})
|
|
136 |
there is also the \emph{Archive of Formal Proofs}
|
|
137 |
at \url{http://afp.sourceforge.net}, a growing collection of Isabelle theories
|
|
138 |
that everybody can contribute to.
|
|
139 |
|
|
140 |
\subsection{Quotation Marks}
|
|
141 |
|
|
142 |
The textual definition of a theory follows a fixed syntax with keywords like
|
|
143 |
\isacommand{begin} and \isacommand{datatype}. Embedded in this syntax are
|
|
144 |
the types and formulae of HOL. To distinguish the two levels, everything
|
|
145 |
HOL-specific (terms and types) must be enclosed in quotation marks:
|
|
146 |
\texttt{"}\dots\texttt{"}. To lessen this burden, quotation marks around a
|
|
147 |
single identifier can be dropped. When Isabelle prints a syntax error
|
|
148 |
message, it refers to the HOL syntax as the \concept{inner syntax} and the
|
|
149 |
enclosing theory language as the \concept{outer syntax}.
|
|
150 |
\begin{warn}
|
|
151 |
For reasons of readability, we almost never show the quotation marks in this
|
|
152 |
book. Consult the accompanying theory files to see where they need to go.
|
|
153 |
\end{warn}%
|
|
154 |
\end{isamarkuptext}%
|
|
155 |
\isamarkuptrue%
|
|
156 |
%
|
|
157 |
\isadelimtheory
|
|
158 |
%
|
|
159 |
\endisadelimtheory
|
|
160 |
%
|
|
161 |
\isatagtheory
|
|
162 |
%
|
|
163 |
\endisatagtheory
|
|
164 |
{\isafoldtheory}%
|
|
165 |
%
|
|
166 |
\isadelimtheory
|
|
167 |
%
|
|
168 |
\endisadelimtheory
|
|
169 |
\end{isabellebody}%
|
|
170 |
%%% Local Variables:
|
|
171 |
%%% mode: latex
|
|
172 |
%%% TeX-master: "root"
|
|
173 |
%%% End:
|