|
6297
|
1 |
(* Title: HOL/UNITY/Extend.ML
|
|
|
2 |
ID: $Id$
|
|
|
3 |
Author: Lawrence C Paulson, Cambridge University Computer Laboratory
|
|
|
4 |
Copyright 1999 University of Cambridge
|
|
|
5 |
|
|
|
6 |
Extending of state sets
|
|
|
7 |
function f (forget) maps the extended state to the original state
|
|
|
8 |
function g (forgotten) maps the extended state to the "extending part"
|
|
|
9 |
*)
|
|
|
10 |
|
|
|
11 |
Open_locale "Extend";
|
|
|
12 |
|
|
|
13 |
val slice_def = thm "slice_def";
|
|
|
14 |
val f_act_def = thm "f_act_def";
|
|
|
15 |
|
|
|
16 |
(*** Trivial properties of f, g, h ***)
|
|
|
17 |
|
|
|
18 |
val inj_h = thm "inj_h";
|
|
|
19 |
val surj_h = thm "surj_h";
|
|
|
20 |
Addsimps [inj_h, inj_h RS inj_eq, surj_h];
|
|
|
21 |
|
|
|
22 |
val f_def = thm "f_def";
|
|
|
23 |
val g_def = thm "g_def";
|
|
|
24 |
|
|
|
25 |
Goal "f(h(x,y)) = x";
|
|
|
26 |
by (simp_tac (simpset() addsimps [f_def]) 1);
|
|
|
27 |
qed "f_h_eq";
|
|
|
28 |
Addsimps [f_h_eq];
|
|
|
29 |
|
|
|
30 |
Goal "g(h(x,y)) = y";
|
|
|
31 |
by (simp_tac (simpset() addsimps [g_def]) 1);
|
|
|
32 |
qed "g_h_eq";
|
|
|
33 |
Addsimps [g_h_eq];
|
|
|
34 |
|
|
|
35 |
Goal "h(f z, g z) = z";
|
|
|
36 |
by (cut_inst_tac [("y", "z")] (surj_h RS surjD) 1);
|
|
|
37 |
by Auto_tac;
|
|
|
38 |
qed "h_f_g_eq";
|
|
|
39 |
|
|
|
40 |
|
|
|
41 |
(*** extend_set: basic properties ***)
|
|
|
42 |
|
|
|
43 |
Goalw [extend_set_def]
|
|
|
44 |
"(h(x,y)) : extend_set h A = (x : A)";
|
|
|
45 |
by Auto_tac;
|
|
|
46 |
qed "mem_extend_set_iff";
|
|
|
47 |
AddIffs [mem_extend_set_iff];
|
|
|
48 |
|
|
|
49 |
Goal "inj (extend_set h)";
|
|
|
50 |
by (rtac injI 1);
|
|
|
51 |
by (rewtac extend_set_def);
|
|
|
52 |
by (etac equalityE 1);
|
|
|
53 |
by (blast_tac (claset() addSDs [inj_h RS inj_image_mem_iff RS iffD1]) 1);
|
|
|
54 |
qed "inj_extend_set";
|
|
|
55 |
|
|
|
56 |
Goalw [extend_set_def]
|
|
|
57 |
"extend_set h (A Un B) = extend_set h A Un extend_set h B";
|
|
|
58 |
by Auto_tac;
|
|
|
59 |
qed "extend_set_Un_distrib";
|
|
|
60 |
|
|
|
61 |
Goalw [extend_set_def]
|
|
|
62 |
"extend_set h (A Int B) = extend_set h A Int extend_set h B";
|
|
|
63 |
by Auto_tac;
|
|
|
64 |
qed "extend_set_Int_distrib";
|
|
|
65 |
|
|
|
66 |
Goalw [extend_set_def]
|
|
|
67 |
"extend_set h (A - B) = extend_set h A - extend_set h B";
|
|
|
68 |
by Auto_tac;
|
|
|
69 |
qed "extend_set_Diff_distrib";
|
|
|
70 |
|
|
|
71 |
Goalw [extend_set_def] "extend_set h (Union A) = (UN X:A. extend_set h X)";
|
|
|
72 |
by (Blast_tac 1);
|
|
|
73 |
qed "extend_set_Union";
|
|
|
74 |
|
|
|
75 |
Goalw [extend_set_def]
|
|
|
76 |
"(extend_set h A <= - extend_set h B) = (A <= - B)";
|
|
|
77 |
by Auto_tac;
|
|
|
78 |
qed "extend_set_subset_Compl_eq";
|
|
|
79 |
|
|
|
80 |
|
|
|
81 |
Goalw [extend_set_def] "f `` extend_set h A = A";
|
|
|
82 |
by Auto_tac;
|
|
|
83 |
by (blast_tac (claset() addIs [f_h_eq RS sym]) 1);
|
|
|
84 |
qed "f_image_extend_set";
|
|
|
85 |
Addsimps [f_image_extend_set];
|
|
|
86 |
|
|
|
87 |
|
|
|
88 |
(*** extend_act ***)
|
|
|
89 |
|
|
|
90 |
Goalw [extend_act_def]
|
|
|
91 |
"((h(s,y), h(s',y)) : extend_act h act) = ((s, s') : act)";
|
|
|
92 |
by Auto_tac;
|
|
|
93 |
qed "mem_extend_act_iff";
|
|
|
94 |
AddIffs [mem_extend_act_iff];
|
|
|
95 |
|
|
|
96 |
Goal "inj (extend_act h)";
|
|
|
97 |
by (rtac injI 1);
|
|
|
98 |
by (rewtac extend_act_def);
|
|
|
99 |
by (force_tac (claset() addSEs [equalityE]
|
|
|
100 |
addIs [h_f_g_eq RS sym],
|
|
|
101 |
simpset()) 1);
|
|
|
102 |
qed "inj_extend_act";
|
|
|
103 |
|
|
|
104 |
Goalw [extend_set_def, extend_act_def]
|
|
|
105 |
"extend_act h act ^^ (extend_set h A) = extend_set h (act ^^ A)";
|
|
|
106 |
by (Force_tac 1);
|
|
|
107 |
qed "extend_act_Image";
|
|
|
108 |
Addsimps [extend_act_Image];
|
|
|
109 |
|
|
|
110 |
Goalw [extend_set_def, extend_act_def]
|
|
|
111 |
"(extend_set h A <= extend_set h B) = (A <= B)";
|
|
|
112 |
by (Force_tac 1);
|
|
|
113 |
qed "extend_set_strict_mono";
|
|
|
114 |
Addsimps [extend_set_strict_mono];
|
|
|
115 |
|
|
|
116 |
Goalw [extend_set_def, extend_act_def]
|
|
|
117 |
"Domain (extend_act h act) = extend_set h (Domain act)";
|
|
|
118 |
by (Force_tac 1);
|
|
|
119 |
qed "Domain_extend_act";
|
|
|
120 |
|
|
|
121 |
Goalw [extend_set_def, extend_act_def]
|
|
|
122 |
"extend_act h Id = Id";
|
|
|
123 |
by (force_tac (claset() addIs [h_f_g_eq RS sym], simpset()) 1);
|
|
|
124 |
qed "extend_act_Id";
|
|
|
125 |
Addsimps [extend_act_Id];
|
|
|
126 |
|
|
|
127 |
Goal "Id : extend_act h `` Acts F";
|
|
|
128 |
by (auto_tac (claset() addSIs [extend_act_Id RS sym],
|
|
|
129 |
simpset() addsimps [image_iff]));
|
|
|
130 |
qed "Id_mem_extend_act";
|
|
|
131 |
|
|
|
132 |
|
|
|
133 |
(**** extend ****)
|
|
|
134 |
|
|
|
135 |
(*** Basic properties ***)
|
|
|
136 |
|
|
|
137 |
Goalw [extend_set_def, extend_def]
|
|
|
138 |
"Init (extend h F) = extend_set h (Init F)";
|
|
|
139 |
by Auto_tac;
|
|
|
140 |
qed "Init_extend";
|
|
|
141 |
|
|
|
142 |
Goal "Acts (extend h F) = (extend_act h `` Acts F)";
|
|
|
143 |
by (auto_tac (claset() addSIs [extend_act_Id RS sym],
|
|
|
144 |
simpset() addsimps [extend_def, image_iff]));
|
|
|
145 |
qed "Acts_extend";
|
|
|
146 |
|
|
|
147 |
Addsimps [Init_extend, Acts_extend];
|
|
|
148 |
|
|
|
149 |
Goalw [SKIP_def] "extend h SKIP = SKIP";
|
|
|
150 |
by (rtac program_equalityI 1);
|
|
|
151 |
by (auto_tac (claset() addIs [h_f_g_eq RS sym],
|
|
|
152 |
simpset() addsimps [extend_set_def]));
|
|
|
153 |
qed "extend_SKIP";
|
|
|
154 |
Addsimps [extend_SKIP];
|
|
|
155 |
|
|
|
156 |
Goal "inj (extend h)";
|
|
|
157 |
by (rtac injI 1);
|
|
|
158 |
by (rewtac extend_def);
|
|
|
159 |
by (etac program_equalityE 1);
|
|
|
160 |
by (full_simp_tac
|
|
|
161 |
(simpset() addsimps [inj_extend_set RS inj_eq,
|
|
|
162 |
inj_extend_act RS inj_image_eq_iff,
|
|
|
163 |
Id_mem_extend_act RS insert_absorb]) 1);
|
|
|
164 |
by (blast_tac (claset() addIs [program_equalityI]) 1);
|
|
|
165 |
qed "inj_extend";
|
|
|
166 |
|
|
|
167 |
Goal "extend h (F Join G) = extend h F Join extend h G";
|
|
|
168 |
by (rtac program_equalityI 1);
|
|
|
169 |
by (simp_tac (simpset() addsimps [image_Un, Acts_Join]) 2);
|
|
|
170 |
by (simp_tac (simpset() addsimps [extend_set_Int_distrib]) 1);
|
|
|
171 |
qed "extend_Join";
|
|
|
172 |
Addsimps [extend_Join];
|
|
|
173 |
|
|
|
174 |
|
|
|
175 |
(*** Safety: constrains, stable ***)
|
|
|
176 |
|
|
|
177 |
Goal "(extend h F : constrains (extend_set h A) (extend_set h B)) = \
|
|
|
178 |
\ (F : constrains A B)";
|
|
|
179 |
by (simp_tac (simpset() addsimps [constrains_def]) 1);
|
|
|
180 |
qed "extend_constrains";
|
|
|
181 |
|
|
|
182 |
Goal "(extend h F : stable (extend_set h A)) = (F : stable A)";
|
|
|
183 |
by (asm_simp_tac (simpset() addsimps [stable_def, extend_constrains]) 1);
|
|
|
184 |
qed "extend_stable";
|
|
|
185 |
|
|
|
186 |
Goal "(extend h F : invariant (extend_set h A)) = (F : invariant A)";
|
|
|
187 |
by (asm_simp_tac (simpset() addsimps [invariant_def, extend_stable]) 1);
|
|
|
188 |
qed "extend_invariant";
|
|
|
189 |
|
|
|
190 |
(** Substitution Axiom versions: Constrains, Stable **)
|
|
|
191 |
|
|
|
192 |
Goal "p : reachable (extend h F) ==> f p : reachable F";
|
|
|
193 |
by (etac reachable.induct 1);
|
|
|
194 |
by (auto_tac
|
|
|
195 |
(claset() addIs reachable.intrs,
|
|
|
196 |
simpset() addsimps [extend_set_def, extend_act_def, image_iff]));
|
|
|
197 |
qed "reachable_extend_f";
|
|
|
198 |
|
|
|
199 |
Goal "h(s,y) : reachable (extend h F) ==> s : reachable F";
|
|
|
200 |
by (force_tac (claset() addSDs [reachable_extend_f], simpset()) 1);
|
|
|
201 |
qed "h_reachable_extend";
|
|
|
202 |
|
|
|
203 |
Goalw [extend_set_def]
|
|
|
204 |
"reachable (extend h F) = extend_set h (reachable F)";
|
|
|
205 |
by (rtac equalityI 1);
|
|
|
206 |
by (force_tac (claset() addIs [h_f_g_eq RS sym]
|
|
|
207 |
addSDs [reachable_extend_f],
|
|
|
208 |
simpset()) 1);
|
|
|
209 |
by (Clarify_tac 1);
|
|
|
210 |
by (etac reachable.induct 1);
|
|
|
211 |
by (ALLGOALS (force_tac (claset() addIs reachable.intrs,
|
|
|
212 |
simpset())));
|
|
|
213 |
qed "reachable_extend_eq";
|
|
|
214 |
|
|
|
215 |
Goal "(extend h F : Constrains (extend_set h A) (extend_set h B)) = \
|
|
|
216 |
\ (F : Constrains A B)";
|
|
|
217 |
by (simp_tac
|
|
|
218 |
(simpset() addsimps [Constrains_def, reachable_extend_eq,
|
|
|
219 |
extend_constrains, extend_set_Int_distrib RS sym]) 1);
|
|
|
220 |
qed "extend_Constrains";
|
|
|
221 |
|
|
|
222 |
Goal "(extend h F : Stable (extend_set h A)) = (F : Stable A)";
|
|
|
223 |
by (simp_tac (simpset() addsimps [Stable_def, extend_Constrains]) 1);
|
|
|
224 |
qed "extend_Stable";
|
|
|
225 |
|
|
|
226 |
|
|
|
227 |
(*** Progress: transient, ensures ***)
|
|
|
228 |
|
|
|
229 |
Goal "(extend h F : transient (extend_set h A)) = (F : transient A)";
|
|
|
230 |
by (auto_tac (claset(),
|
|
|
231 |
simpset() addsimps [transient_def, extend_set_subset_Compl_eq,
|
|
|
232 |
Domain_extend_act]));
|
|
|
233 |
qed "extend_transient";
|
|
|
234 |
|
|
|
235 |
Goal "(extend h F : ensures (extend_set h A) (extend_set h B)) = \
|
|
|
236 |
\ (F : ensures A B)";
|
|
|
237 |
by (simp_tac
|
|
|
238 |
(simpset() addsimps [ensures_def, extend_constrains, extend_transient,
|
|
|
239 |
extend_set_Un_distrib RS sym,
|
|
|
240 |
extend_set_Diff_distrib RS sym]) 1);
|
|
|
241 |
qed "extend_ensures";
|
|
|
242 |
|
|
|
243 |
Goal "F : leadsTo A B \
|
|
|
244 |
\ ==> extend h F : leadsTo (extend_set h A) (extend_set h B)";
|
|
|
245 |
by (etac leadsTo_induct 1);
|
|
|
246 |
by (asm_simp_tac (simpset() addsimps [leadsTo_UN, extend_set_Union]) 3);
|
|
|
247 |
by (blast_tac (claset() addIs [leadsTo_Trans]) 2);
|
|
|
248 |
by (asm_simp_tac (simpset() addsimps [leadsTo_Basis, extend_ensures]) 1);
|
|
|
249 |
qed "leadsTo_imp_extend_leadsTo";
|
|
|
250 |
|
|
|
251 |
(*** Proving the converse takes some doing! ***)
|
|
|
252 |
|
|
|
253 |
Goalw [slice_def] "slice (Union S) y = (UN x:S. slice x y)";
|
|
|
254 |
by Auto_tac;
|
|
|
255 |
qed "slice_Union";
|
|
|
256 |
|
|
|
257 |
Goalw [slice_def] "slice (extend_set h A) y = A";
|
|
|
258 |
by Auto_tac;
|
|
|
259 |
qed "slice_extend_set";
|
|
|
260 |
|
|
|
261 |
Goalw [slice_def] "f``A = (UN y. slice A y)";
|
|
|
262 |
by Auto_tac;
|
|
|
263 |
by (blast_tac (claset() addIs [f_h_eq RS sym]) 2);
|
|
|
264 |
by (best_tac (claset() addIs [h_f_g_eq RS ssubst]) 1);
|
|
|
265 |
qed "image_is_UN_slice";
|
|
|
266 |
|
|
|
267 |
Goalw [slice_def, transient_def]
|
|
|
268 |
"extend h F : transient A ==> F : transient (slice A y)";
|
|
|
269 |
by Auto_tac;
|
|
|
270 |
by (rtac bexI 1);
|
|
|
271 |
by Auto_tac;
|
|
|
272 |
by (force_tac (claset(), simpset() addsimps [extend_act_def]) 1);
|
|
|
273 |
qed "extend_transient_slice";
|
|
|
274 |
|
|
|
275 |
Goal "extend h F : ensures A B ==> F : ensures (slice A y) (f `` B)";
|
|
|
276 |
by (full_simp_tac
|
|
|
277 |
(simpset() addsimps [ensures_def, extend_constrains, extend_transient,
|
|
|
278 |
image_Un RS sym,
|
|
|
279 |
extend_set_Un_distrib RS sym,
|
|
|
280 |
extend_set_Diff_distrib RS sym]) 1);
|
|
|
281 |
by Safe_tac;
|
|
|
282 |
by (full_simp_tac (simpset() addsimps [constrains_def, extend_act_def,
|
|
|
283 |
extend_set_def]) 1);
|
|
|
284 |
by (Clarify_tac 1);
|
|
|
285 |
by (ball_tac 1);
|
|
|
286 |
by (full_simp_tac (simpset() addsimps [slice_def, image_iff, Image_iff]) 1);
|
|
|
287 |
by (force_tac (claset() addSIs [h_f_g_eq RS sym], simpset()) 1);
|
|
|
288 |
(*transient*)
|
|
|
289 |
by (dtac extend_transient_slice 1);
|
|
|
290 |
by (etac transient_strengthen 1);
|
|
|
291 |
by (force_tac (claset() addIs [f_h_eq RS sym],
|
|
|
292 |
simpset() addsimps [slice_def]) 1);
|
|
|
293 |
qed "extend_ensures_slice";
|
|
|
294 |
|
|
|
295 |
Goal "ALL y. F : leadsTo (slice B y) CU ==> F : leadsTo (f `` B) CU";
|
|
|
296 |
by (simp_tac (simpset() addsimps [image_is_UN_slice]) 1);
|
|
|
297 |
by (blast_tac (claset() addIs [leadsTo_UN]) 1);
|
|
|
298 |
qed "leadsTo_slice_image";
|
|
|
299 |
|
|
|
300 |
|
|
|
301 |
Goal "extend h F : leadsTo AU BU \
|
|
|
302 |
\ ==> ALL y. F : leadsTo (slice AU y) (f `` BU)";
|
|
|
303 |
by (etac leadsTo_induct 1);
|
|
|
304 |
by (full_simp_tac (simpset() addsimps [slice_Union]) 3);
|
|
|
305 |
by (blast_tac (claset() addIs [leadsTo_UN]) 3);
|
|
|
306 |
by (blast_tac (claset() addIs [leadsTo_slice_image, leadsTo_Trans]) 2);
|
|
|
307 |
by (blast_tac (claset() addIs [extend_ensures_slice, leadsTo_Basis]) 1);
|
|
|
308 |
qed_spec_mp "extend_leadsTo_slice";
|
|
|
309 |
|
|
|
310 |
Goal "(extend h F : leadsTo (extend_set h A) (extend_set h B)) = \
|
|
|
311 |
\ (F : leadsTo A B)";
|
|
|
312 |
by Safe_tac;
|
|
|
313 |
by (etac leadsTo_imp_extend_leadsTo 2);
|
|
|
314 |
by (dtac extend_leadsTo_slice 1);
|
|
|
315 |
by (full_simp_tac (simpset() addsimps [slice_extend_set]) 1);
|
|
|
316 |
qed "extend_leadsto_eq";
|
|
|
317 |
|
|
|
318 |
|
|
|
319 |
(*** guarantees properties ***)
|
|
|
320 |
|
|
|
321 |
Goalw [f_act_def, extend_act_def] "f_act (extend_act h act1) = act1";
|
|
|
322 |
by (force_tac
|
|
|
323 |
(claset() addSIs [rev_bexI],
|
|
|
324 |
simpset() addsimps [image_iff]) 1);
|
|
|
325 |
qed "f_act_extend_act";
|
|
|
326 |
Addsimps [f_act_extend_act];
|
|
|
327 |
|
|
|
328 |
Goalw [extend_set_def]
|
|
|
329 |
"f `` (extend_set h A Int B) = (f `` extend_set h A) Int (f``B)";
|
|
|
330 |
by (force_tac (claset() addIs [h_f_g_eq RS sym], simpset()) 1);
|
|
|
331 |
qed "image_extend_set_Int_eq";
|
|
|
332 |
|
|
|
333 |
Goal "(extend h F) Join G = extend h H ==> EX J. H = F Join J";
|
|
|
334 |
by (etac program_equalityE 1);
|
|
|
335 |
by (auto_tac (claset(), simpset() addsimps [Acts_Join]));
|
|
|
336 |
by (res_inst_tac [("x", "mk_program(f``(Init G), f_act``Acts G)")] exI 1);
|
|
|
337 |
by (rtac program_equalityI 1);
|
|
|
338 |
(*Init*)
|
|
|
339 |
by (REPEAT (dres_inst_tac [("f", "op `` f")] arg_cong 1));
|
|
|
340 |
by (asm_full_simp_tac (simpset() addsimps [image_extend_set_Int_eq]) 1);
|
|
|
341 |
(*Now for the Actions*)
|
|
|
342 |
by (dres_inst_tac [("f", "op `` f_act")] arg_cong 1);
|
|
|
343 |
by (asm_full_simp_tac
|
|
|
344 |
(simpset() addsimps [Acts_Join, image_Un, image_compose RS sym, o_def]) 1);
|
|
|
345 |
qed "extend_Join_eq_extend_D";
|
|
|
346 |
|
|
|
347 |
Goal "F : X guarantees Y \
|
|
|
348 |
\ ==> extend h F : (extend h `` X) guarantees (extend h `` Y)";
|
|
|
349 |
by (rtac guaranteesI 1);
|
|
|
350 |
by Auto_tac;
|
|
|
351 |
by (blast_tac (claset() addDs [extend_Join_eq_extend_D, guaranteesD]) 1);
|
|
|
352 |
qed "guarantees_imp_extend_guarantees";
|
|
|
353 |
|
|
|
354 |
Goal "extend h F : (extend h `` X) guarantees (extend h `` Y) \
|
|
|
355 |
\ ==> F : X guarantees Y";
|
|
|
356 |
by (rtac guaranteesI 1);
|
|
|
357 |
by (rewrite_goals_tac [guarantees_def, component_def]);
|
|
|
358 |
by Auto_tac;
|
|
|
359 |
by (dtac spec 1);
|
|
|
360 |
by (dtac (mp RS mp) 1);
|
|
|
361 |
by (Blast_tac 2);
|
|
|
362 |
by (blast_tac (claset() addSDs [inj_extend RS inj_image_mem_iff RS iffD1]) 2);
|
|
|
363 |
by Auto_tac;
|
|
|
364 |
qed "extend_guarantees_imp_guarantees";
|
|
|
365 |
|
|
|
366 |
Goal "(extend h F : (extend h `` X) guarantees (extend h `` Y)) \
|
|
|
367 |
\ = (F : X guarantees Y)";
|
|
|
368 |
by (blast_tac (claset() addIs [guarantees_imp_extend_guarantees,
|
|
|
369 |
extend_guarantees_imp_guarantees]) 1);
|
|
|
370 |
qed "extend_guarantees_eq";
|
|
|
371 |
|
|
|
372 |
|
|
|
373 |
Close_locale "Extend";
|