| author | blanchet | 
| Thu, 11 Mar 2010 10:13:24 +0100 | |
| changeset 35710 | 58acd48904bc | 
| parent 35671 | ed2c3830d881 | 
| child 35711 | 548d3f16404b | 
| permissions | -rw-r--r-- | 
| 33197 | 1  | 
(* Title: HOL/Nitpick_Examples/Manual_Nits.thy  | 
2  | 
Author: Jasmin Blanchette, TU Muenchen  | 
|
| 
35076
 
cc19e2aef17e
added hotel key card example for Nitpick, and renumber atoms in Nitpick's output for increased readability
 
blanchet 
parents: 
34982 
diff
changeset
 | 
3  | 
Copyright 2009, 2010  | 
| 33197 | 4  | 
|
5  | 
Examples from the Nitpick manual.  | 
|
6  | 
*)  | 
|
7  | 
||
8  | 
header {* Examples from the Nitpick Manual *}
 | 
|
9  | 
||
10  | 
theory Manual_Nits  | 
|
| 
35665
 
ff2bf50505ab
added "finitize" option to Nitpick + remove dependency on "Coinductive_List"
 
blanchet 
parents: 
35312 
diff
changeset
 | 
11  | 
imports Main Quotient_Product RealDef  | 
| 33197 | 12  | 
begin  | 
13  | 
||
14  | 
chapter {* 3. First Steps *}
 | 
|
15  | 
||
| 35710 | 16  | 
nitpick_params [sat_solver = MiniSat_JNI, max_threads = 1]  | 
| 33197 | 17  | 
|
18  | 
subsection {* 3.1. Propositional Logic *}
 | 
|
19  | 
||
20  | 
lemma "P \<longleftrightarrow> Q"  | 
|
| 
35671
 
ed2c3830d881
improved Nitpick's precision for "card" and "setsum" + fix incorrect outcome code w.r.t. "bisim_depth = -1"
 
blanchet 
parents: 
35665 
diff
changeset
 | 
21  | 
nitpick [expect = genuine]  | 
| 33197 | 22  | 
apply auto  | 
| 
35671
 
ed2c3830d881
improved Nitpick's precision for "card" and "setsum" + fix incorrect outcome code w.r.t. "bisim_depth = -1"
 
blanchet 
parents: 
35665 
diff
changeset
 | 
23  | 
nitpick [expect = genuine] 1  | 
| 
 
ed2c3830d881
improved Nitpick's precision for "card" and "setsum" + fix incorrect outcome code w.r.t. "bisim_depth = -1"
 
blanchet 
parents: 
35665 
diff
changeset
 | 
24  | 
nitpick [expect = genuine] 2  | 
| 33197 | 25  | 
oops  | 
26  | 
||
27  | 
subsection {* 3.2. Type Variables *}
 | 
|
28  | 
||
29  | 
lemma "P x \<Longrightarrow> P (THE y. P y)"  | 
|
| 
35671
 
ed2c3830d881
improved Nitpick's precision for "card" and "setsum" + fix incorrect outcome code w.r.t. "bisim_depth = -1"
 
blanchet 
parents: 
35665 
diff
changeset
 | 
30  | 
nitpick [verbose, expect = genuine]  | 
| 33197 | 31  | 
oops  | 
32  | 
||
33  | 
subsection {* 3.3. Constants *}
 | 
|
34  | 
||
35  | 
lemma "P x \<Longrightarrow> P (THE y. P y)"  | 
|
| 
35671
 
ed2c3830d881
improved Nitpick's precision for "card" and "setsum" + fix incorrect outcome code w.r.t. "bisim_depth = -1"
 
blanchet 
parents: 
35665 
diff
changeset
 | 
36  | 
nitpick [show_consts, expect = genuine]  | 
| 
 
ed2c3830d881
improved Nitpick's precision for "card" and "setsum" + fix incorrect outcome code w.r.t. "bisim_depth = -1"
 
blanchet 
parents: 
35665 
diff
changeset
 | 
37  | 
nitpick [full_descrs, show_consts, expect = genuine]  | 
| 
 
ed2c3830d881
improved Nitpick's precision for "card" and "setsum" + fix incorrect outcome code w.r.t. "bisim_depth = -1"
 
blanchet 
parents: 
35665 
diff
changeset
 | 
38  | 
nitpick [dont_specialize, full_descrs, show_consts, expect = genuine]  | 
| 33197 | 39  | 
oops  | 
40  | 
||
41  | 
lemma "\<exists>!x. P x \<Longrightarrow> P (THE y. P y)"  | 
|
| 
35671
 
ed2c3830d881
improved Nitpick's precision for "card" and "setsum" + fix incorrect outcome code w.r.t. "bisim_depth = -1"
 
blanchet 
parents: 
35665 
diff
changeset
 | 
42  | 
nitpick [expect = none]  | 
| 
 
ed2c3830d881
improved Nitpick's precision for "card" and "setsum" + fix incorrect outcome code w.r.t. "bisim_depth = -1"
 
blanchet 
parents: 
35665 
diff
changeset
 | 
43  | 
nitpick [card 'a = 1\<midarrow>50, expect = none]  | 
| 33197 | 44  | 
(* sledgehammer *)  | 
45  | 
apply (metis the_equality)  | 
|
46  | 
done  | 
|
47  | 
||
48  | 
subsection {* 3.4. Skolemization *}
 | 
|
49  | 
||
50  | 
lemma "\<exists>g. \<forall>x. g (f x) = x \<Longrightarrow> \<forall>y. \<exists>x. y = f x"  | 
|
| 
35671
 
ed2c3830d881
improved Nitpick's precision for "card" and "setsum" + fix incorrect outcome code w.r.t. "bisim_depth = -1"
 
blanchet 
parents: 
35665 
diff
changeset
 | 
51  | 
nitpick [expect = genuine]  | 
| 33197 | 52  | 
oops  | 
53  | 
||
54  | 
lemma "\<exists>x. \<forall>f. f x = x"  | 
|
| 
35671
 
ed2c3830d881
improved Nitpick's precision for "card" and "setsum" + fix incorrect outcome code w.r.t. "bisim_depth = -1"
 
blanchet 
parents: 
35665 
diff
changeset
 | 
55  | 
nitpick [expect = genuine]  | 
| 33197 | 56  | 
oops  | 
57  | 
||
58  | 
lemma "refl r \<Longrightarrow> sym r"  | 
|
| 
35671
 
ed2c3830d881
improved Nitpick's precision for "card" and "setsum" + fix incorrect outcome code w.r.t. "bisim_depth = -1"
 
blanchet 
parents: 
35665 
diff
changeset
 | 
59  | 
nitpick [expect = genuine]  | 
| 33197 | 60  | 
oops  | 
61  | 
||
| 34126 | 62  | 
subsection {* 3.5. Natural Numbers and Integers *}
 | 
| 33197 | 63  | 
|
64  | 
lemma "\<lbrakk>i \<le> j; n \<le> (m\<Colon>int)\<rbrakk> \<Longrightarrow> i * n + j * m \<le> i * m + j * n"  | 
|
| 
35671
 
ed2c3830d881
improved Nitpick's precision for "card" and "setsum" + fix incorrect outcome code w.r.t. "bisim_depth = -1"
 
blanchet 
parents: 
35665 
diff
changeset
 | 
65  | 
nitpick [expect = genuine]  | 
| 33197 | 66  | 
oops  | 
67  | 
||
68  | 
lemma "\<forall>n. Suc n \<noteq> n \<Longrightarrow> P"  | 
|
| 
35671
 
ed2c3830d881
improved Nitpick's precision for "card" and "setsum" + fix incorrect outcome code w.r.t. "bisim_depth = -1"
 
blanchet 
parents: 
35665 
diff
changeset
 | 
69  | 
nitpick [card nat = 100, check_potential, expect = genuine]  | 
| 33197 | 70  | 
oops  | 
71  | 
||
72  | 
lemma "P Suc"  | 
|
| 
35671
 
ed2c3830d881
improved Nitpick's precision for "card" and "setsum" + fix incorrect outcome code w.r.t. "bisim_depth = -1"
 
blanchet 
parents: 
35665 
diff
changeset
 | 
73  | 
nitpick [expect = none]  | 
| 33197 | 74  | 
oops  | 
75  | 
||
76  | 
lemma "P (op +\<Colon>nat\<Rightarrow>nat\<Rightarrow>nat)"  | 
|
| 
35671
 
ed2c3830d881
improved Nitpick's precision for "card" and "setsum" + fix incorrect outcome code w.r.t. "bisim_depth = -1"
 
blanchet 
parents: 
35665 
diff
changeset
 | 
77  | 
nitpick [card nat = 1, expect = genuine]  | 
| 
 
ed2c3830d881
improved Nitpick's precision for "card" and "setsum" + fix incorrect outcome code w.r.t. "bisim_depth = -1"
 
blanchet 
parents: 
35665 
diff
changeset
 | 
78  | 
nitpick [card nat = 2, expect = none]  | 
| 33197 | 79  | 
oops  | 
80  | 
||
81  | 
subsection {* 3.6. Inductive Datatypes *}
 | 
|
82  | 
||
83  | 
lemma "hd (xs @ [y, y]) = hd xs"  | 
|
| 
35671
 
ed2c3830d881
improved Nitpick's precision for "card" and "setsum" + fix incorrect outcome code w.r.t. "bisim_depth = -1"
 
blanchet 
parents: 
35665 
diff
changeset
 | 
84  | 
nitpick [expect = genuine]  | 
| 
 
ed2c3830d881
improved Nitpick's precision for "card" and "setsum" + fix incorrect outcome code w.r.t. "bisim_depth = -1"
 
blanchet 
parents: 
35665 
diff
changeset
 | 
85  | 
nitpick [show_consts, show_datatypes, expect = genuine]  | 
| 33197 | 86  | 
oops  | 
87  | 
||
88  | 
lemma "\<lbrakk>length xs = 1; length ys = 1\<rbrakk> \<Longrightarrow> xs = ys"  | 
|
| 
35671
 
ed2c3830d881
improved Nitpick's precision for "card" and "setsum" + fix incorrect outcome code w.r.t. "bisim_depth = -1"
 
blanchet 
parents: 
35665 
diff
changeset
 | 
89  | 
nitpick [show_datatypes, expect = genuine]  | 
| 33197 | 90  | 
oops  | 
91  | 
||
92  | 
subsection {* 3.7. Typedefs, Records, Rationals, and Reals *}
 | 
|
93  | 
||
94  | 
typedef three = "{0\<Colon>nat, 1, 2}"
 | 
|
95  | 
by blast  | 
|
96  | 
||
97  | 
definition A :: three where "A \<equiv> Abs_three 0"  | 
|
98  | 
definition B :: three where "B \<equiv> Abs_three 1"  | 
|
99  | 
definition C :: three where "C \<equiv> Abs_three 2"  | 
|
100  | 
||
101  | 
lemma "\<lbrakk>P A; P B\<rbrakk> \<Longrightarrow> P x"  | 
|
| 
35671
 
ed2c3830d881
improved Nitpick's precision for "card" and "setsum" + fix incorrect outcome code w.r.t. "bisim_depth = -1"
 
blanchet 
parents: 
35665 
diff
changeset
 | 
102  | 
nitpick [show_datatypes, expect = genuine]  | 
| 33197 | 103  | 
oops  | 
104  | 
||
| 
35284
 
9edc2bd6d2bd
enabled Nitpick's support for quotient types + shortened the Nitpick tests a bit
 
blanchet 
parents: 
35185 
diff
changeset
 | 
105  | 
fun my_int_rel where  | 
| 
 
9edc2bd6d2bd
enabled Nitpick's support for quotient types + shortened the Nitpick tests a bit
 
blanchet 
parents: 
35185 
diff
changeset
 | 
106  | 
"my_int_rel (x, y) (u, v) = (x + v = u + y)"  | 
| 
 
9edc2bd6d2bd
enabled Nitpick's support for quotient types + shortened the Nitpick tests a bit
 
blanchet 
parents: 
35185 
diff
changeset
 | 
107  | 
|
| 
 
9edc2bd6d2bd
enabled Nitpick's support for quotient types + shortened the Nitpick tests a bit
 
blanchet 
parents: 
35185 
diff
changeset
 | 
108  | 
quotient_type my_int = "nat \<times> nat" / my_int_rel  | 
| 
 
9edc2bd6d2bd
enabled Nitpick's support for quotient types + shortened the Nitpick tests a bit
 
blanchet 
parents: 
35185 
diff
changeset
 | 
109  | 
by (auto simp add: equivp_def expand_fun_eq)  | 
| 
 
9edc2bd6d2bd
enabled Nitpick's support for quotient types + shortened the Nitpick tests a bit
 
blanchet 
parents: 
35185 
diff
changeset
 | 
110  | 
|
| 
 
9edc2bd6d2bd
enabled Nitpick's support for quotient types + shortened the Nitpick tests a bit
 
blanchet 
parents: 
35185 
diff
changeset
 | 
111  | 
definition add_raw where  | 
| 
 
9edc2bd6d2bd
enabled Nitpick's support for quotient types + shortened the Nitpick tests a bit
 
blanchet 
parents: 
35185 
diff
changeset
 | 
112  | 
"add_raw \<equiv> \<lambda>(x, y) (u, v). (x + (u\<Colon>nat), y + (v\<Colon>nat))"  | 
| 
 
9edc2bd6d2bd
enabled Nitpick's support for quotient types + shortened the Nitpick tests a bit
 
blanchet 
parents: 
35185 
diff
changeset
 | 
113  | 
|
| 
 
9edc2bd6d2bd
enabled Nitpick's support for quotient types + shortened the Nitpick tests a bit
 
blanchet 
parents: 
35185 
diff
changeset
 | 
114  | 
quotient_definition "add\<Colon>my_int \<Rightarrow> my_int \<Rightarrow> my_int" is add_raw  | 
| 
 
9edc2bd6d2bd
enabled Nitpick's support for quotient types + shortened the Nitpick tests a bit
 
blanchet 
parents: 
35185 
diff
changeset
 | 
115  | 
|
| 
 
9edc2bd6d2bd
enabled Nitpick's support for quotient types + shortened the Nitpick tests a bit
 
blanchet 
parents: 
35185 
diff
changeset
 | 
116  | 
lemma "add x y = add x x"  | 
| 
35671
 
ed2c3830d881
improved Nitpick's precision for "card" and "setsum" + fix incorrect outcome code w.r.t. "bisim_depth = -1"
 
blanchet 
parents: 
35665 
diff
changeset
 | 
117  | 
nitpick [show_datatypes, expect = genuine]  | 
| 
35284
 
9edc2bd6d2bd
enabled Nitpick's support for quotient types + shortened the Nitpick tests a bit
 
blanchet 
parents: 
35185 
diff
changeset
 | 
118  | 
oops  | 
| 
 
9edc2bd6d2bd
enabled Nitpick's support for quotient types + shortened the Nitpick tests a bit
 
blanchet 
parents: 
35185 
diff
changeset
 | 
119  | 
|
| 33197 | 120  | 
record point =  | 
121  | 
Xcoord :: int  | 
|
122  | 
Ycoord :: int  | 
|
123  | 
||
124  | 
lemma "Xcoord (p\<Colon>point) = Xcoord (q\<Colon>point)"  | 
|
| 
35671
 
ed2c3830d881
improved Nitpick's precision for "card" and "setsum" + fix incorrect outcome code w.r.t. "bisim_depth = -1"
 
blanchet 
parents: 
35665 
diff
changeset
 | 
125  | 
nitpick [show_datatypes, expect = genuine]  | 
| 33197 | 126  | 
oops  | 
127  | 
||
128  | 
lemma "4 * x + 3 * (y\<Colon>real) \<noteq> 1 / 2"  | 
|
| 
35671
 
ed2c3830d881
improved Nitpick's precision for "card" and "setsum" + fix incorrect outcome code w.r.t. "bisim_depth = -1"
 
blanchet 
parents: 
35665 
diff
changeset
 | 
129  | 
nitpick [show_datatypes, expect = genuine]  | 
| 33197 | 130  | 
oops  | 
131  | 
||
132  | 
subsection {* 3.8. Inductive and Coinductive Predicates *}
 | 
|
133  | 
||
134  | 
inductive even where  | 
|
135  | 
"even 0" |  | 
|
136  | 
"even n \<Longrightarrow> even (Suc (Suc n))"  | 
|
137  | 
||
138  | 
lemma "\<exists>n. even n \<and> even (Suc n)"  | 
|
| 35710 | 139  | 
nitpick [card nat = 50, unary_ints, verbose, expect = potential]  | 
| 33197 | 140  | 
oops  | 
141  | 
||
| 35710 | 142  | 
lemma "\<exists>n \<le> 49. even n \<and> even (Suc n)"  | 
143  | 
nitpick [card nat = 50, unary_ints, verbose, expect = genuine]  | 
|
| 33197 | 144  | 
oops  | 
145  | 
||
146  | 
inductive even' where  | 
|
147  | 
"even' (0\<Colon>nat)" |  | 
|
148  | 
"even' 2" |  | 
|
149  | 
"\<lbrakk>even' m; even' n\<rbrakk> \<Longrightarrow> even' (m + n)"  | 
|
150  | 
||
151  | 
lemma "\<exists>n \<in> {0, 2, 4, 6, 8}. \<not> even' n"
 | 
|
| 
35671
 
ed2c3830d881
improved Nitpick's precision for "card" and "setsum" + fix incorrect outcome code w.r.t. "bisim_depth = -1"
 
blanchet 
parents: 
35665 
diff
changeset
 | 
152  | 
nitpick [card nat = 10, unary_ints, verbose, show_consts, expect = genuine]  | 
| 33197 | 153  | 
oops  | 
154  | 
||
155  | 
lemma "even' (n - 2) \<Longrightarrow> even' n"  | 
|
| 
35671
 
ed2c3830d881
improved Nitpick's precision for "card" and "setsum" + fix incorrect outcome code w.r.t. "bisim_depth = -1"
 
blanchet 
parents: 
35665 
diff
changeset
 | 
156  | 
nitpick [card nat = 10, show_consts, expect = genuine]  | 
| 33197 | 157  | 
oops  | 
158  | 
||
159  | 
coinductive nats where  | 
|
160  | 
"nats (x\<Colon>nat) \<Longrightarrow> nats x"  | 
|
161  | 
||
162  | 
lemma "nats = {0, 1, 2, 3, 4}"
 | 
|
| 
35671
 
ed2c3830d881
improved Nitpick's precision for "card" and "setsum" + fix incorrect outcome code w.r.t. "bisim_depth = -1"
 
blanchet 
parents: 
35665 
diff
changeset
 | 
163  | 
nitpick [card nat = 10, show_consts, expect = genuine]  | 
| 33197 | 164  | 
oops  | 
165  | 
||
166  | 
inductive odd where  | 
|
167  | 
"odd 1" |  | 
|
168  | 
"\<lbrakk>odd m; even n\<rbrakk> \<Longrightarrow> odd (m + n)"  | 
|
169  | 
||
170  | 
lemma "odd n \<Longrightarrow> odd (n - 2)"  | 
|
| 
35671
 
ed2c3830d881
improved Nitpick's precision for "card" and "setsum" + fix incorrect outcome code w.r.t. "bisim_depth = -1"
 
blanchet 
parents: 
35665 
diff
changeset
 | 
171  | 
nitpick [card nat = 10, show_consts, expect = genuine]  | 
| 33197 | 172  | 
oops  | 
173  | 
||
174  | 
subsection {* 3.9. Coinductive Datatypes *}
 | 
|
175  | 
||
| 
35665
 
ff2bf50505ab
added "finitize" option to Nitpick + remove dependency on "Coinductive_List"
 
blanchet 
parents: 
35312 
diff
changeset
 | 
176  | 
(* Lazy lists are defined in Andreas Lochbihler's "Coinductive" AFP entry. Since  | 
| 
 
ff2bf50505ab
added "finitize" option to Nitpick + remove dependency on "Coinductive_List"
 
blanchet 
parents: 
35312 
diff
changeset
 | 
177  | 
we cannot rely on its presence, we expediently provide our own axiomatization.  | 
| 
 
ff2bf50505ab
added "finitize" option to Nitpick + remove dependency on "Coinductive_List"
 
blanchet 
parents: 
35312 
diff
changeset
 | 
178  | 
The examples also work unchanged with Lochbihler's "Coinductive_List" theory. *)  | 
| 
 
ff2bf50505ab
added "finitize" option to Nitpick + remove dependency on "Coinductive_List"
 
blanchet 
parents: 
35312 
diff
changeset
 | 
179  | 
|
| 
 
ff2bf50505ab
added "finitize" option to Nitpick + remove dependency on "Coinductive_List"
 
blanchet 
parents: 
35312 
diff
changeset
 | 
180  | 
typedef 'a llist = "UNIV\<Colon>('a list + (nat \<Rightarrow> 'a)) set" by auto
 | 
| 
 
ff2bf50505ab
added "finitize" option to Nitpick + remove dependency on "Coinductive_List"
 
blanchet 
parents: 
35312 
diff
changeset
 | 
181  | 
|
| 
35671
 
ed2c3830d881
improved Nitpick's precision for "card" and "setsum" + fix incorrect outcome code w.r.t. "bisim_depth = -1"
 
blanchet 
parents: 
35665 
diff
changeset
 | 
182  | 
definition LNil where  | 
| 
 
ed2c3830d881
improved Nitpick's precision for "card" and "setsum" + fix incorrect outcome code w.r.t. "bisim_depth = -1"
 
blanchet 
parents: 
35665 
diff
changeset
 | 
183  | 
"LNil = Abs_llist (Inl [])"  | 
| 
35665
 
ff2bf50505ab
added "finitize" option to Nitpick + remove dependency on "Coinductive_List"
 
blanchet 
parents: 
35312 
diff
changeset
 | 
184  | 
definition LCons where  | 
| 
 
ff2bf50505ab
added "finitize" option to Nitpick + remove dependency on "Coinductive_List"
 
blanchet 
parents: 
35312 
diff
changeset
 | 
185  | 
"LCons y ys = Abs_llist (case Rep_llist ys of  | 
| 
 
ff2bf50505ab
added "finitize" option to Nitpick + remove dependency on "Coinductive_List"
 
blanchet 
parents: 
35312 
diff
changeset
 | 
186  | 
Inl ys' \<Rightarrow> Inl (y # ys')  | 
| 
 
ff2bf50505ab
added "finitize" option to Nitpick + remove dependency on "Coinductive_List"
 
blanchet 
parents: 
35312 
diff
changeset
 | 
187  | 
| Inr f \<Rightarrow> Inr (\<lambda>n. case n of 0 \<Rightarrow> y | Suc m \<Rightarrow> f m))"  | 
| 
 
ff2bf50505ab
added "finitize" option to Nitpick + remove dependency on "Coinductive_List"
 
blanchet 
parents: 
35312 
diff
changeset
 | 
188  | 
|
| 
 
ff2bf50505ab
added "finitize" option to Nitpick + remove dependency on "Coinductive_List"
 
blanchet 
parents: 
35312 
diff
changeset
 | 
189  | 
axiomatization iterates :: "('a \<Rightarrow> 'a) \<Rightarrow> 'a \<Rightarrow> 'a llist"
 | 
| 
 
ff2bf50505ab
added "finitize" option to Nitpick + remove dependency on "Coinductive_List"
 
blanchet 
parents: 
35312 
diff
changeset
 | 
190  | 
|
| 
 
ff2bf50505ab
added "finitize" option to Nitpick + remove dependency on "Coinductive_List"
 
blanchet 
parents: 
35312 
diff
changeset
 | 
191  | 
lemma iterates_def [nitpick_simp]:  | 
| 
 
ff2bf50505ab
added "finitize" option to Nitpick + remove dependency on "Coinductive_List"
 
blanchet 
parents: 
35312 
diff
changeset
 | 
192  | 
"iterates f a = LCons a (iterates f (f a))"  | 
| 
 
ff2bf50505ab
added "finitize" option to Nitpick + remove dependency on "Coinductive_List"
 
blanchet 
parents: 
35312 
diff
changeset
 | 
193  | 
sorry  | 
| 
 
ff2bf50505ab
added "finitize" option to Nitpick + remove dependency on "Coinductive_List"
 
blanchet 
parents: 
35312 
diff
changeset
 | 
194  | 
|
| 
 
ff2bf50505ab
added "finitize" option to Nitpick + remove dependency on "Coinductive_List"
 
blanchet 
parents: 
35312 
diff
changeset
 | 
195  | 
setup {*
 | 
| 
 
ff2bf50505ab
added "finitize" option to Nitpick + remove dependency on "Coinductive_List"
 
blanchet 
parents: 
35312 
diff
changeset
 | 
196  | 
Nitpick.register_codatatype @{typ "'a llist"} ""
 | 
| 
 
ff2bf50505ab
added "finitize" option to Nitpick + remove dependency on "Coinductive_List"
 
blanchet 
parents: 
35312 
diff
changeset
 | 
197  | 
    (map dest_Const [@{term LNil}, @{term LCons}])
 | 
| 
 
ff2bf50505ab
added "finitize" option to Nitpick + remove dependency on "Coinductive_List"
 
blanchet 
parents: 
35312 
diff
changeset
 | 
198  | 
*}  | 
| 
 
ff2bf50505ab
added "finitize" option to Nitpick + remove dependency on "Coinductive_List"
 
blanchet 
parents: 
35312 
diff
changeset
 | 
199  | 
|
| 33197 | 200  | 
lemma "xs \<noteq> LCons a xs"  | 
| 
35671
 
ed2c3830d881
improved Nitpick's precision for "card" and "setsum" + fix incorrect outcome code w.r.t. "bisim_depth = -1"
 
blanchet 
parents: 
35665 
diff
changeset
 | 
201  | 
nitpick [expect = genuine]  | 
| 33197 | 202  | 
oops  | 
203  | 
||
204  | 
lemma "\<lbrakk>xs = LCons a xs; ys = iterates (\<lambda>b. a) b\<rbrakk> \<Longrightarrow> xs = ys"  | 
|
| 
35671
 
ed2c3830d881
improved Nitpick's precision for "card" and "setsum" + fix incorrect outcome code w.r.t. "bisim_depth = -1"
 
blanchet 
parents: 
35665 
diff
changeset
 | 
205  | 
nitpick [verbose, expect = genuine]  | 
| 33197 | 206  | 
oops  | 
207  | 
||
208  | 
lemma "\<lbrakk>xs = LCons a xs; ys = LCons a ys\<rbrakk> \<Longrightarrow> xs = ys"  | 
|
| 
35671
 
ed2c3830d881
improved Nitpick's precision for "card" and "setsum" + fix incorrect outcome code w.r.t. "bisim_depth = -1"
 
blanchet 
parents: 
35665 
diff
changeset
 | 
209  | 
nitpick [bisim_depth = -1, show_datatypes, expect = quasi_genuine]  | 
| 
 
ed2c3830d881
improved Nitpick's precision for "card" and "setsum" + fix incorrect outcome code w.r.t. "bisim_depth = -1"
 
blanchet 
parents: 
35665 
diff
changeset
 | 
210  | 
nitpick [expect = none]  | 
| 33197 | 211  | 
sorry  | 
212  | 
||
213  | 
subsection {* 3.10. Boxing *}
 | 
|
214  | 
||
215  | 
datatype tm = Var nat | Lam tm | App tm tm  | 
|
216  | 
||
217  | 
primrec lift where  | 
|
218  | 
"lift (Var j) k = Var (if j < k then j else j + 1)" |  | 
|
219  | 
"lift (Lam t) k = Lam (lift t (k + 1))" |  | 
|
220  | 
"lift (App t u) k = App (lift t k) (lift u k)"  | 
|
221  | 
||
222  | 
primrec loose where  | 
|
223  | 
"loose (Var j) k = (j \<ge> k)" |  | 
|
224  | 
"loose (Lam t) k = loose t (Suc k)" |  | 
|
225  | 
"loose (App t u) k = (loose t k \<or> loose u k)"  | 
|
226  | 
||
227  | 
primrec subst\<^isub>1 where  | 
|
228  | 
"subst\<^isub>1 \<sigma> (Var j) = \<sigma> j" |  | 
|
229  | 
"subst\<^isub>1 \<sigma> (Lam t) =  | 
|
230  | 
Lam (subst\<^isub>1 (\<lambda>n. case n of 0 \<Rightarrow> Var 0 | Suc m \<Rightarrow> lift (\<sigma> m) 1) t)" |  | 
|
231  | 
"subst\<^isub>1 \<sigma> (App t u) = App (subst\<^isub>1 \<sigma> t) (subst\<^isub>1 \<sigma> u)"  | 
|
232  | 
||
233  | 
lemma "\<not> loose t 0 \<Longrightarrow> subst\<^isub>1 \<sigma> t = t"  | 
|
| 
35671
 
ed2c3830d881
improved Nitpick's precision for "card" and "setsum" + fix incorrect outcome code w.r.t. "bisim_depth = -1"
 
blanchet 
parents: 
35665 
diff
changeset
 | 
234  | 
nitpick [verbose, expect = genuine]  | 
| 
 
ed2c3830d881
improved Nitpick's precision for "card" and "setsum" + fix incorrect outcome code w.r.t. "bisim_depth = -1"
 
blanchet 
parents: 
35665 
diff
changeset
 | 
235  | 
nitpick [eval = "subst\<^isub>1 \<sigma> t", expect = genuine]  | 
| 
 
ed2c3830d881
improved Nitpick's precision for "card" and "setsum" + fix incorrect outcome code w.r.t. "bisim_depth = -1"
 
blanchet 
parents: 
35665 
diff
changeset
 | 
236  | 
(* nitpick [dont_box, expect = unknown] *)  | 
| 33197 | 237  | 
oops  | 
238  | 
||
239  | 
primrec subst\<^isub>2 where  | 
|
240  | 
"subst\<^isub>2 \<sigma> (Var j) = \<sigma> j" |  | 
|
241  | 
"subst\<^isub>2 \<sigma> (Lam t) =  | 
|
242  | 
Lam (subst\<^isub>2 (\<lambda>n. case n of 0 \<Rightarrow> Var 0 | Suc m \<Rightarrow> lift (\<sigma> m) 0) t)" |  | 
|
243  | 
"subst\<^isub>2 \<sigma> (App t u) = App (subst\<^isub>2 \<sigma> t) (subst\<^isub>2 \<sigma> u)"  | 
|
244  | 
||
245  | 
lemma "\<not> loose t 0 \<Longrightarrow> subst\<^isub>2 \<sigma> t = t"  | 
|
| 35710 | 246  | 
nitpick [card = 1\<midarrow>5, expect = none]  | 
| 33197 | 247  | 
sorry  | 
248  | 
||
249  | 
subsection {* 3.11. Scope Monotonicity *}
 | 
|
250  | 
||
251  | 
lemma "length xs = length ys \<Longrightarrow> rev (zip xs ys) = zip xs (rev ys)"  | 
|
| 
35671
 
ed2c3830d881
improved Nitpick's precision for "card" and "setsum" + fix incorrect outcome code w.r.t. "bisim_depth = -1"
 
blanchet 
parents: 
35665 
diff
changeset
 | 
252  | 
nitpick [verbose, expect = genuine]  | 
| 
 
ed2c3830d881
improved Nitpick's precision for "card" and "setsum" + fix incorrect outcome code w.r.t. "bisim_depth = -1"
 
blanchet 
parents: 
35665 
diff
changeset
 | 
253  | 
nitpick [card = 8, verbose, expect = genuine]  | 
| 33197 | 254  | 
oops  | 
255  | 
||
256  | 
lemma "\<exists>g. \<forall>x\<Colon>'b. g (f x) = x \<Longrightarrow> \<forall>y\<Colon>'a. \<exists>x. y = f x"  | 
|
| 
35671
 
ed2c3830d881
improved Nitpick's precision for "card" and "setsum" + fix incorrect outcome code w.r.t. "bisim_depth = -1"
 
blanchet 
parents: 
35665 
diff
changeset
 | 
257  | 
nitpick [mono, expect = none]  | 
| 
 
ed2c3830d881
improved Nitpick's precision for "card" and "setsum" + fix incorrect outcome code w.r.t. "bisim_depth = -1"
 
blanchet 
parents: 
35665 
diff
changeset
 | 
258  | 
nitpick [expect = genuine]  | 
| 33197 | 259  | 
oops  | 
260  | 
||
| 
34982
 
7b8c366e34a2
added support for nonstandard models to Nitpick (based on an idea by Koen Claessen) and did other fixes to Nitpick
 
blanchet 
parents: 
34126 
diff
changeset
 | 
261  | 
subsection {* 3.12. Inductive Properties *}
 | 
| 
 
7b8c366e34a2
added support for nonstandard models to Nitpick (based on an idea by Koen Claessen) and did other fixes to Nitpick
 
blanchet 
parents: 
34126 
diff
changeset
 | 
262  | 
|
| 
 
7b8c366e34a2
added support for nonstandard models to Nitpick (based on an idea by Koen Claessen) and did other fixes to Nitpick
 
blanchet 
parents: 
34126 
diff
changeset
 | 
263  | 
inductive_set reach where  | 
| 
 
7b8c366e34a2
added support for nonstandard models to Nitpick (based on an idea by Koen Claessen) and did other fixes to Nitpick
 
blanchet 
parents: 
34126 
diff
changeset
 | 
264  | 
"(4\<Colon>nat) \<in> reach" |  | 
| 
 
7b8c366e34a2
added support for nonstandard models to Nitpick (based on an idea by Koen Claessen) and did other fixes to Nitpick
 
blanchet 
parents: 
34126 
diff
changeset
 | 
265  | 
"n \<in> reach \<Longrightarrow> n < 4 \<Longrightarrow> 3 * n + 1 \<in> reach" |  | 
| 
 
7b8c366e34a2
added support for nonstandard models to Nitpick (based on an idea by Koen Claessen) and did other fixes to Nitpick
 
blanchet 
parents: 
34126 
diff
changeset
 | 
266  | 
"n \<in> reach \<Longrightarrow> n + 2 \<in> reach"  | 
| 
 
7b8c366e34a2
added support for nonstandard models to Nitpick (based on an idea by Koen Claessen) and did other fixes to Nitpick
 
blanchet 
parents: 
34126 
diff
changeset
 | 
267  | 
|
| 
 
7b8c366e34a2
added support for nonstandard models to Nitpick (based on an idea by Koen Claessen) and did other fixes to Nitpick
 
blanchet 
parents: 
34126 
diff
changeset
 | 
268  | 
lemma "n \<in> reach \<Longrightarrow> 2 dvd n"  | 
| 
35671
 
ed2c3830d881
improved Nitpick's precision for "card" and "setsum" + fix incorrect outcome code w.r.t. "bisim_depth = -1"
 
blanchet 
parents: 
35665 
diff
changeset
 | 
269  | 
nitpick [unary_ints, expect = none]  | 
| 
34982
 
7b8c366e34a2
added support for nonstandard models to Nitpick (based on an idea by Koen Claessen) and did other fixes to Nitpick
 
blanchet 
parents: 
34126 
diff
changeset
 | 
270  | 
apply (induct set: reach)  | 
| 
 
7b8c366e34a2
added support for nonstandard models to Nitpick (based on an idea by Koen Claessen) and did other fixes to Nitpick
 
blanchet 
parents: 
34126 
diff
changeset
 | 
271  | 
apply auto  | 
| 
35671
 
ed2c3830d881
improved Nitpick's precision for "card" and "setsum" + fix incorrect outcome code w.r.t. "bisim_depth = -1"
 
blanchet 
parents: 
35665 
diff
changeset
 | 
272  | 
nitpick [expect = none]  | 
| 
34982
 
7b8c366e34a2
added support for nonstandard models to Nitpick (based on an idea by Koen Claessen) and did other fixes to Nitpick
 
blanchet 
parents: 
34126 
diff
changeset
 | 
273  | 
apply (thin_tac "n \<in> reach")  | 
| 
35671
 
ed2c3830d881
improved Nitpick's precision for "card" and "setsum" + fix incorrect outcome code w.r.t. "bisim_depth = -1"
 
blanchet 
parents: 
35665 
diff
changeset
 | 
274  | 
nitpick [expect = genuine]  | 
| 
34982
 
7b8c366e34a2
added support for nonstandard models to Nitpick (based on an idea by Koen Claessen) and did other fixes to Nitpick
 
blanchet 
parents: 
34126 
diff
changeset
 | 
275  | 
oops  | 
| 
 
7b8c366e34a2
added support for nonstandard models to Nitpick (based on an idea by Koen Claessen) and did other fixes to Nitpick
 
blanchet 
parents: 
34126 
diff
changeset
 | 
276  | 
|
| 
 
7b8c366e34a2
added support for nonstandard models to Nitpick (based on an idea by Koen Claessen) and did other fixes to Nitpick
 
blanchet 
parents: 
34126 
diff
changeset
 | 
277  | 
lemma "n \<in> reach \<Longrightarrow> 2 dvd n \<and> n \<noteq> 0"  | 
| 
35671
 
ed2c3830d881
improved Nitpick's precision for "card" and "setsum" + fix incorrect outcome code w.r.t. "bisim_depth = -1"
 
blanchet 
parents: 
35665 
diff
changeset
 | 
278  | 
nitpick [unary_ints, expect = none]  | 
| 
34982
 
7b8c366e34a2
added support for nonstandard models to Nitpick (based on an idea by Koen Claessen) and did other fixes to Nitpick
 
blanchet 
parents: 
34126 
diff
changeset
 | 
279  | 
apply (induct set: reach)  | 
| 
 
7b8c366e34a2
added support for nonstandard models to Nitpick (based on an idea by Koen Claessen) and did other fixes to Nitpick
 
blanchet 
parents: 
34126 
diff
changeset
 | 
280  | 
apply auto  | 
| 
35671
 
ed2c3830d881
improved Nitpick's precision for "card" and "setsum" + fix incorrect outcome code w.r.t. "bisim_depth = -1"
 
blanchet 
parents: 
35665 
diff
changeset
 | 
281  | 
nitpick [expect = none]  | 
| 
34982
 
7b8c366e34a2
added support for nonstandard models to Nitpick (based on an idea by Koen Claessen) and did other fixes to Nitpick
 
blanchet 
parents: 
34126 
diff
changeset
 | 
282  | 
apply (thin_tac "n \<in> reach")  | 
| 
35671
 
ed2c3830d881
improved Nitpick's precision for "card" and "setsum" + fix incorrect outcome code w.r.t. "bisim_depth = -1"
 
blanchet 
parents: 
35665 
diff
changeset
 | 
283  | 
nitpick [expect = genuine]  | 
| 
34982
 
7b8c366e34a2
added support for nonstandard models to Nitpick (based on an idea by Koen Claessen) and did other fixes to Nitpick
 
blanchet 
parents: 
34126 
diff
changeset
 | 
284  | 
oops  | 
| 
 
7b8c366e34a2
added support for nonstandard models to Nitpick (based on an idea by Koen Claessen) and did other fixes to Nitpick
 
blanchet 
parents: 
34126 
diff
changeset
 | 
285  | 
|
| 
 
7b8c366e34a2
added support for nonstandard models to Nitpick (based on an idea by Koen Claessen) and did other fixes to Nitpick
 
blanchet 
parents: 
34126 
diff
changeset
 | 
286  | 
lemma "n \<in> reach \<Longrightarrow> 2 dvd n \<and> n \<ge> 4"  | 
| 
 
7b8c366e34a2
added support for nonstandard models to Nitpick (based on an idea by Koen Claessen) and did other fixes to Nitpick
 
blanchet 
parents: 
34126 
diff
changeset
 | 
287  | 
by (induct set: reach) arith+  | 
| 
 
7b8c366e34a2
added support for nonstandard models to Nitpick (based on an idea by Koen Claessen) and did other fixes to Nitpick
 
blanchet 
parents: 
34126 
diff
changeset
 | 
288  | 
|
| 
 
7b8c366e34a2
added support for nonstandard models to Nitpick (based on an idea by Koen Claessen) and did other fixes to Nitpick
 
blanchet 
parents: 
34126 
diff
changeset
 | 
289  | 
datatype 'a bin_tree = Leaf 'a | Branch "'a bin_tree" "'a bin_tree"  | 
| 
 
7b8c366e34a2
added support for nonstandard models to Nitpick (based on an idea by Koen Claessen) and did other fixes to Nitpick
 
blanchet 
parents: 
34126 
diff
changeset
 | 
290  | 
|
| 
 
7b8c366e34a2
added support for nonstandard models to Nitpick (based on an idea by Koen Claessen) and did other fixes to Nitpick
 
blanchet 
parents: 
34126 
diff
changeset
 | 
291  | 
primrec labels where  | 
| 
 
7b8c366e34a2
added support for nonstandard models to Nitpick (based on an idea by Koen Claessen) and did other fixes to Nitpick
 
blanchet 
parents: 
34126 
diff
changeset
 | 
292  | 
"labels (Leaf a) = {a}" |
 | 
| 
 
7b8c366e34a2
added support for nonstandard models to Nitpick (based on an idea by Koen Claessen) and did other fixes to Nitpick
 
blanchet 
parents: 
34126 
diff
changeset
 | 
293  | 
"labels (Branch t u) = labels t \<union> labels u"  | 
| 
 
7b8c366e34a2
added support for nonstandard models to Nitpick (based on an idea by Koen Claessen) and did other fixes to Nitpick
 
blanchet 
parents: 
34126 
diff
changeset
 | 
294  | 
|
| 
 
7b8c366e34a2
added support for nonstandard models to Nitpick (based on an idea by Koen Claessen) and did other fixes to Nitpick
 
blanchet 
parents: 
34126 
diff
changeset
 | 
295  | 
primrec swap where  | 
| 
 
7b8c366e34a2
added support for nonstandard models to Nitpick (based on an idea by Koen Claessen) and did other fixes to Nitpick
 
blanchet 
parents: 
34126 
diff
changeset
 | 
296  | 
"swap (Leaf c) a b =  | 
| 
 
7b8c366e34a2
added support for nonstandard models to Nitpick (based on an idea by Koen Claessen) and did other fixes to Nitpick
 
blanchet 
parents: 
34126 
diff
changeset
 | 
297  | 
(if c = a then Leaf b else if c = b then Leaf a else Leaf c)" |  | 
| 
 
7b8c366e34a2
added support for nonstandard models to Nitpick (based on an idea by Koen Claessen) and did other fixes to Nitpick
 
blanchet 
parents: 
34126 
diff
changeset
 | 
298  | 
"swap (Branch t u) a b = Branch (swap t a b) (swap u a b)"  | 
| 
 
7b8c366e34a2
added support for nonstandard models to Nitpick (based on an idea by Koen Claessen) and did other fixes to Nitpick
 
blanchet 
parents: 
34126 
diff
changeset
 | 
299  | 
|
| 
35180
 
c57dba973391
more work on Nitpick's support for nonstandard models + fix in model reconstruction
 
blanchet 
parents: 
35078 
diff
changeset
 | 
300  | 
lemma "{a, b} \<subseteq> labels t \<Longrightarrow> labels (swap t a b) = labels t"
 | 
| 
35671
 
ed2c3830d881
improved Nitpick's precision for "card" and "setsum" + fix incorrect outcome code w.r.t. "bisim_depth = -1"
 
blanchet 
parents: 
35665 
diff
changeset
 | 
301  | 
(* nitpick *)  | 
| 
34982
 
7b8c366e34a2
added support for nonstandard models to Nitpick (based on an idea by Koen Claessen) and did other fixes to Nitpick
 
blanchet 
parents: 
34126 
diff
changeset
 | 
302  | 
proof (induct t)  | 
| 
 
7b8c366e34a2
added support for nonstandard models to Nitpick (based on an idea by Koen Claessen) and did other fixes to Nitpick
 
blanchet 
parents: 
34126 
diff
changeset
 | 
303  | 
case Leaf thus ?case by simp  | 
| 
 
7b8c366e34a2
added support for nonstandard models to Nitpick (based on an idea by Koen Claessen) and did other fixes to Nitpick
 
blanchet 
parents: 
34126 
diff
changeset
 | 
304  | 
next  | 
| 
 
7b8c366e34a2
added support for nonstandard models to Nitpick (based on an idea by Koen Claessen) and did other fixes to Nitpick
 
blanchet 
parents: 
34126 
diff
changeset
 | 
305  | 
case (Branch t u) thus ?case  | 
| 
35671
 
ed2c3830d881
improved Nitpick's precision for "card" and "setsum" + fix incorrect outcome code w.r.t. "bisim_depth = -1"
 
blanchet 
parents: 
35665 
diff
changeset
 | 
306  | 
(* nitpick *)  | 
| 
 
ed2c3830d881
improved Nitpick's precision for "card" and "setsum" + fix incorrect outcome code w.r.t. "bisim_depth = -1"
 
blanchet 
parents: 
35665 
diff
changeset
 | 
307  | 
nitpick [non_std, show_all, expect = genuine]  | 
| 
34982
 
7b8c366e34a2
added support for nonstandard models to Nitpick (based on an idea by Koen Claessen) and did other fixes to Nitpick
 
blanchet 
parents: 
34126 
diff
changeset
 | 
308  | 
oops  | 
| 
 
7b8c366e34a2
added support for nonstandard models to Nitpick (based on an idea by Koen Claessen) and did other fixes to Nitpick
 
blanchet 
parents: 
34126 
diff
changeset
 | 
309  | 
|
| 
 
7b8c366e34a2
added support for nonstandard models to Nitpick (based on an idea by Koen Claessen) and did other fixes to Nitpick
 
blanchet 
parents: 
34126 
diff
changeset
 | 
310  | 
lemma "labels (swap t a b) =  | 
| 
 
7b8c366e34a2
added support for nonstandard models to Nitpick (based on an idea by Koen Claessen) and did other fixes to Nitpick
 
blanchet 
parents: 
34126 
diff
changeset
 | 
311  | 
(if a \<in> labels t then  | 
| 
 
7b8c366e34a2
added support for nonstandard models to Nitpick (based on an idea by Koen Claessen) and did other fixes to Nitpick
 
blanchet 
parents: 
34126 
diff
changeset
 | 
312  | 
          if b \<in> labels t then labels t else (labels t - {a}) \<union> {b}
 | 
| 
 
7b8c366e34a2
added support for nonstandard models to Nitpick (based on an idea by Koen Claessen) and did other fixes to Nitpick
 
blanchet 
parents: 
34126 
diff
changeset
 | 
313  | 
else  | 
| 
 
7b8c366e34a2
added support for nonstandard models to Nitpick (based on an idea by Koen Claessen) and did other fixes to Nitpick
 
blanchet 
parents: 
34126 
diff
changeset
 | 
314  | 
          if b \<in> labels t then (labels t - {b}) \<union> {a} else labels t)"
 | 
| 
35309
 
997aa3a3e4bb
catch IO errors in Nitpick's "kodkodi" invocation + shorten execution time of "Manual_Nits" example
 
blanchet 
parents: 
35284 
diff
changeset
 | 
315  | 
(* nitpick *)  | 
| 
34982
 
7b8c366e34a2
added support for nonstandard models to Nitpick (based on an idea by Koen Claessen) and did other fixes to Nitpick
 
blanchet 
parents: 
34126 
diff
changeset
 | 
316  | 
proof (induct t)  | 
| 
 
7b8c366e34a2
added support for nonstandard models to Nitpick (based on an idea by Koen Claessen) and did other fixes to Nitpick
 
blanchet 
parents: 
34126 
diff
changeset
 | 
317  | 
case Leaf thus ?case by simp  | 
| 
 
7b8c366e34a2
added support for nonstandard models to Nitpick (based on an idea by Koen Claessen) and did other fixes to Nitpick
 
blanchet 
parents: 
34126 
diff
changeset
 | 
318  | 
next  | 
| 
 
7b8c366e34a2
added support for nonstandard models to Nitpick (based on an idea by Koen Claessen) and did other fixes to Nitpick
 
blanchet 
parents: 
34126 
diff
changeset
 | 
319  | 
case (Branch t u) thus ?case  | 
| 35710 | 320  | 
nitpick [non_std, card = 1\<midarrow>5, expect = none]  | 
| 
34982
 
7b8c366e34a2
added support for nonstandard models to Nitpick (based on an idea by Koen Claessen) and did other fixes to Nitpick
 
blanchet 
parents: 
34126 
diff
changeset
 | 
321  | 
by auto  | 
| 
 
7b8c366e34a2
added support for nonstandard models to Nitpick (based on an idea by Koen Claessen) and did other fixes to Nitpick
 
blanchet 
parents: 
34126 
diff
changeset
 | 
322  | 
qed  | 
| 
 
7b8c366e34a2
added support for nonstandard models to Nitpick (based on an idea by Koen Claessen) and did other fixes to Nitpick
 
blanchet 
parents: 
34126 
diff
changeset
 | 
323  | 
|
| 33197 | 324  | 
section {* 4. Case Studies *}
 | 
325  | 
||
326  | 
nitpick_params [max_potential = 0, max_threads = 2]  | 
|
327  | 
||
328  | 
subsection {* 4.1. A Context-Free Grammar *}
 | 
|
329  | 
||
330  | 
datatype alphabet = a | b  | 
|
331  | 
||
332  | 
inductive_set S\<^isub>1 and A\<^isub>1 and B\<^isub>1 where  | 
|
333  | 
"[] \<in> S\<^isub>1"  | 
|
334  | 
| "w \<in> A\<^isub>1 \<Longrightarrow> b # w \<in> S\<^isub>1"  | 
|
335  | 
| "w \<in> B\<^isub>1 \<Longrightarrow> a # w \<in> S\<^isub>1"  | 
|
336  | 
| "w \<in> S\<^isub>1 \<Longrightarrow> a # w \<in> A\<^isub>1"  | 
|
337  | 
| "w \<in> S\<^isub>1 \<Longrightarrow> b # w \<in> S\<^isub>1"  | 
|
338  | 
| "\<lbrakk>v \<in> B\<^isub>1; v \<in> B\<^isub>1\<rbrakk> \<Longrightarrow> a # v @ w \<in> B\<^isub>1"  | 
|
339  | 
||
340  | 
theorem S\<^isub>1_sound:  | 
|
341  | 
"w \<in> S\<^isub>1 \<longrightarrow> length [x \<leftarrow> w. x = a] = length [x \<leftarrow> w. x = b]"  | 
|
| 
35671
 
ed2c3830d881
improved Nitpick's precision for "card" and "setsum" + fix incorrect outcome code w.r.t. "bisim_depth = -1"
 
blanchet 
parents: 
35665 
diff
changeset
 | 
342  | 
nitpick [expect = genuine]  | 
| 33197 | 343  | 
oops  | 
344  | 
||
345  | 
inductive_set S\<^isub>2 and A\<^isub>2 and B\<^isub>2 where  | 
|
346  | 
"[] \<in> S\<^isub>2"  | 
|
347  | 
| "w \<in> A\<^isub>2 \<Longrightarrow> b # w \<in> S\<^isub>2"  | 
|
348  | 
| "w \<in> B\<^isub>2 \<Longrightarrow> a # w \<in> S\<^isub>2"  | 
|
349  | 
| "w \<in> S\<^isub>2 \<Longrightarrow> a # w \<in> A\<^isub>2"  | 
|
350  | 
| "w \<in> S\<^isub>2 \<Longrightarrow> b # w \<in> B\<^isub>2"  | 
|
351  | 
| "\<lbrakk>v \<in> B\<^isub>2; v \<in> B\<^isub>2\<rbrakk> \<Longrightarrow> a # v @ w \<in> B\<^isub>2"  | 
|
352  | 
||
353  | 
theorem S\<^isub>2_sound:  | 
|
354  | 
"w \<in> S\<^isub>2 \<longrightarrow> length [x \<leftarrow> w. x = a] = length [x \<leftarrow> w. x = b]"  | 
|
| 
35671
 
ed2c3830d881
improved Nitpick's precision for "card" and "setsum" + fix incorrect outcome code w.r.t. "bisim_depth = -1"
 
blanchet 
parents: 
35665 
diff
changeset
 | 
355  | 
nitpick [expect = genuine]  | 
| 33197 | 356  | 
oops  | 
357  | 
||
358  | 
inductive_set S\<^isub>3 and A\<^isub>3 and B\<^isub>3 where  | 
|
359  | 
"[] \<in> S\<^isub>3"  | 
|
360  | 
| "w \<in> A\<^isub>3 \<Longrightarrow> b # w \<in> S\<^isub>3"  | 
|
361  | 
| "w \<in> B\<^isub>3 \<Longrightarrow> a # w \<in> S\<^isub>3"  | 
|
362  | 
| "w \<in> S\<^isub>3 \<Longrightarrow> a # w \<in> A\<^isub>3"  | 
|
363  | 
| "w \<in> S\<^isub>3 \<Longrightarrow> b # w \<in> B\<^isub>3"  | 
|
364  | 
| "\<lbrakk>v \<in> B\<^isub>3; w \<in> B\<^isub>3\<rbrakk> \<Longrightarrow> a # v @ w \<in> B\<^isub>3"  | 
|
365  | 
||
366  | 
theorem S\<^isub>3_sound:  | 
|
367  | 
"w \<in> S\<^isub>3 \<longrightarrow> length [x \<leftarrow> w. x = a] = length [x \<leftarrow> w. x = b]"  | 
|
| 35710 | 368  | 
nitpick [card = 1\<midarrow>6, expect = none]  | 
| 33197 | 369  | 
sorry  | 
370  | 
||
371  | 
theorem S\<^isub>3_complete:  | 
|
372  | 
"length [x \<leftarrow> w. x = a] = length [x \<leftarrow> w. x = b] \<longrightarrow> w \<in> S\<^isub>3"  | 
|
| 
35671
 
ed2c3830d881
improved Nitpick's precision for "card" and "setsum" + fix incorrect outcome code w.r.t. "bisim_depth = -1"
 
blanchet 
parents: 
35665 
diff
changeset
 | 
373  | 
nitpick [expect = genuine]  | 
| 33197 | 374  | 
oops  | 
375  | 
||
376  | 
inductive_set S\<^isub>4 and A\<^isub>4 and B\<^isub>4 where  | 
|
377  | 
"[] \<in> S\<^isub>4"  | 
|
378  | 
| "w \<in> A\<^isub>4 \<Longrightarrow> b # w \<in> S\<^isub>4"  | 
|
379  | 
| "w \<in> B\<^isub>4 \<Longrightarrow> a # w \<in> S\<^isub>4"  | 
|
380  | 
| "w \<in> S\<^isub>4 \<Longrightarrow> a # w \<in> A\<^isub>4"  | 
|
381  | 
| "\<lbrakk>v \<in> A\<^isub>4; w \<in> A\<^isub>4\<rbrakk> \<Longrightarrow> b # v @ w \<in> A\<^isub>4"  | 
|
382  | 
| "w \<in> S\<^isub>4 \<Longrightarrow> b # w \<in> B\<^isub>4"  | 
|
383  | 
| "\<lbrakk>v \<in> B\<^isub>4; w \<in> B\<^isub>4\<rbrakk> \<Longrightarrow> a # v @ w \<in> B\<^isub>4"  | 
|
384  | 
||
385  | 
theorem S\<^isub>4_sound:  | 
|
386  | 
"w \<in> S\<^isub>4 \<longrightarrow> length [x \<leftarrow> w. x = a] = length [x \<leftarrow> w. x = b]"  | 
|
| 35710 | 387  | 
nitpick [card = 1\<midarrow>6, expect = none]  | 
| 33197 | 388  | 
sorry  | 
389  | 
||
390  | 
theorem S\<^isub>4_complete:  | 
|
391  | 
"length [x \<leftarrow> w. x = a] = length [x \<leftarrow> w. x = b] \<longrightarrow> w \<in> S\<^isub>4"  | 
|
| 35710 | 392  | 
nitpick [card = 1\<midarrow>6, expect = none]  | 
| 33197 | 393  | 
sorry  | 
394  | 
||
395  | 
theorem S\<^isub>4_A\<^isub>4_B\<^isub>4_sound_and_complete:  | 
|
396  | 
"w \<in> S\<^isub>4 \<longleftrightarrow> length [x \<leftarrow> w. x = a] = length [x \<leftarrow> w. x = b]"  | 
|
397  | 
"w \<in> A\<^isub>4 \<longleftrightarrow> length [x \<leftarrow> w. x = a] = length [x \<leftarrow> w. x = b] + 1"  | 
|
398  | 
"w \<in> B\<^isub>4 \<longleftrightarrow> length [x \<leftarrow> w. x = b] = length [x \<leftarrow> w. x = a] + 1"  | 
|
| 35710 | 399  | 
nitpick [card = 1\<midarrow>6, expect = none]  | 
| 33197 | 400  | 
sorry  | 
401  | 
||
402  | 
subsection {* 4.2. AA Trees *}
 | 
|
403  | 
||
| 
34982
 
7b8c366e34a2
added support for nonstandard models to Nitpick (based on an idea by Koen Claessen) and did other fixes to Nitpick
 
blanchet 
parents: 
34126 
diff
changeset
 | 
404  | 
datatype 'a aa_tree = \<Lambda> | N "'a\<Colon>linorder" nat "'a aa_tree" "'a aa_tree"  | 
| 33197 | 405  | 
|
406  | 
primrec data where  | 
|
407  | 
"data \<Lambda> = undefined" |  | 
|
408  | 
"data (N x _ _ _) = x"  | 
|
409  | 
||
410  | 
primrec dataset where  | 
|
411  | 
"dataset \<Lambda> = {}" |
 | 
|
412  | 
"dataset (N x _ t u) = {x} \<union> dataset t \<union> dataset u"
 | 
|
413  | 
||
414  | 
primrec level where  | 
|
415  | 
"level \<Lambda> = 0" |  | 
|
416  | 
"level (N _ k _ _) = k"  | 
|
417  | 
||
418  | 
primrec left where  | 
|
419  | 
"left \<Lambda> = \<Lambda>" |  | 
|
420  | 
"left (N _ _ t\<^isub>1 _) = t\<^isub>1"  | 
|
421  | 
||
422  | 
primrec right where  | 
|
423  | 
"right \<Lambda> = \<Lambda>" |  | 
|
424  | 
"right (N _ _ _ t\<^isub>2) = t\<^isub>2"  | 
|
425  | 
||
426  | 
fun wf where  | 
|
427  | 
"wf \<Lambda> = True" |  | 
|
428  | 
"wf (N _ k t u) =  | 
|
429  | 
(if t = \<Lambda> then  | 
|
430  | 
k = 1 \<and> (u = \<Lambda> \<or> (level u = 1 \<and> left u = \<Lambda> \<and> right u = \<Lambda>))  | 
|
431  | 
else  | 
|
432  | 
wf t \<and> wf u \<and> u \<noteq> \<Lambda> \<and> level t < k \<and> level u \<le> k \<and> level (right u) < k)"  | 
|
433  | 
||
434  | 
fun skew where  | 
|
435  | 
"skew \<Lambda> = \<Lambda>" |  | 
|
436  | 
"skew (N x k t u) =  | 
|
437  | 
(if t \<noteq> \<Lambda> \<and> k = level t then  | 
|
438  | 
N (data t) k (left t) (N x k (right t) u)  | 
|
439  | 
else  | 
|
440  | 
N x k t u)"  | 
|
441  | 
||
442  | 
fun split where  | 
|
443  | 
"split \<Lambda> = \<Lambda>" |  | 
|
444  | 
"split (N x k t u) =  | 
|
445  | 
(if u \<noteq> \<Lambda> \<and> k = level (right u) then  | 
|
446  | 
N (data u) (Suc k) (N x k t (left u)) (right u)  | 
|
447  | 
else  | 
|
448  | 
N x k t u)"  | 
|
449  | 
||
450  | 
theorem dataset_skew_split:  | 
|
451  | 
"dataset (skew t) = dataset t"  | 
|
452  | 
"dataset (split t) = dataset t"  | 
|
| 35710 | 453  | 
nitpick [card = 1\<midarrow>6, expect = none]  | 
| 33197 | 454  | 
sorry  | 
455  | 
||
456  | 
theorem wf_skew_split:  | 
|
457  | 
"wf t \<Longrightarrow> skew t = t"  | 
|
458  | 
"wf t \<Longrightarrow> split t = t"  | 
|
| 35710 | 459  | 
nitpick [card = 1\<midarrow>6, expect = none]  | 
| 33197 | 460  | 
sorry  | 
461  | 
||
462  | 
primrec insort\<^isub>1 where  | 
|
463  | 
"insort\<^isub>1 \<Lambda> x = N x 1 \<Lambda> \<Lambda>" |  | 
|
464  | 
"insort\<^isub>1 (N y k t u) x =  | 
|
465  | 
(* (split \<circ> skew) *) (N y k (if x < y then insort\<^isub>1 t x else t)  | 
|
466  | 
(if x > y then insort\<^isub>1 u x else u))"  | 
|
467  | 
||
468  | 
theorem wf_insort\<^isub>1: "wf t \<Longrightarrow> wf (insort\<^isub>1 t x)"  | 
|
| 
35671
 
ed2c3830d881
improved Nitpick's precision for "card" and "setsum" + fix incorrect outcome code w.r.t. "bisim_depth = -1"
 
blanchet 
parents: 
35665 
diff
changeset
 | 
469  | 
nitpick [expect = genuine]  | 
| 33197 | 470  | 
oops  | 
471  | 
||
472  | 
theorem wf_insort\<^isub>1_nat: "wf t \<Longrightarrow> wf (insort\<^isub>1 t (x\<Colon>nat))"  | 
|
| 
35671
 
ed2c3830d881
improved Nitpick's precision for "card" and "setsum" + fix incorrect outcome code w.r.t. "bisim_depth = -1"
 
blanchet 
parents: 
35665 
diff
changeset
 | 
473  | 
nitpick [eval = "insort\<^isub>1 t x", expect = genuine]  | 
| 33197 | 474  | 
oops  | 
475  | 
||
476  | 
primrec insort\<^isub>2 where  | 
|
477  | 
"insort\<^isub>2 \<Lambda> x = N x 1 \<Lambda> \<Lambda>" |  | 
|
478  | 
"insort\<^isub>2 (N y k t u) x =  | 
|
479  | 
(split \<circ> skew) (N y k (if x < y then insort\<^isub>2 t x else t)  | 
|
480  | 
(if x > y then insort\<^isub>2 u x else u))"  | 
|
481  | 
||
482  | 
theorem wf_insort\<^isub>2: "wf t \<Longrightarrow> wf (insort\<^isub>2 t x)"  | 
|
| 35710 | 483  | 
nitpick [card = 1\<midarrow>6, expect = none]  | 
| 33197 | 484  | 
sorry  | 
485  | 
||
486  | 
theorem dataset_insort\<^isub>2: "dataset (insort\<^isub>2 t x) = {x} \<union> dataset t"
 | 
|
| 35710 | 487  | 
nitpick [card = 1\<midarrow>6, expect = none]  | 
| 33197 | 488  | 
sorry  | 
489  | 
||
490  | 
end  |