src/HOLCF/IOA/meta_theory/SimCorrectness.ML
author wenzelm
Fri, 26 May 2006 22:20:02 +0200
changeset 19728 6c47d9295dca
parent 19360 f47412f922ab
permissions -rw-r--r--
freeze_spec: gensym;
Ignore whitespace changes - Everywhere: Within whitespace: At end of lines:
4565
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
     1
(*  Title:      HOLCF/IOA/meta_theory/SimCorrectness.ML
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
     2
    ID:         $Id$
19360
f47412f922ab converted Müller to Mueller to make smlnj 110.58 work
kleing
parents: 17955
diff changeset
     3
    Author:     Olaf Mueller
4565
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
     4
*)
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
     5
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
     6
(* -------------------------------------------------------------------------------- *)
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
     7
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
     8
section "corresp_ex_sim";
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
     9
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
    10
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
    11
(* ---------------------------------------------------------------- *)
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
    12
(*                             corresp_ex_simC                          *)
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
    13
(* ---------------------------------------------------------------- *)
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
    14
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
    15
5068
fb28eaa07e01 isatool fixgoal;
wenzelm
parents: 4833
diff changeset
    16
Goal "corresp_ex_simC A R  = (LAM ex. (%s. case ex of \
4565
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
    17
\      nil =>  nil   \
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
    18
\    | x##xs => (flift1 (%pr. let a = (fst pr); t = (snd pr); \
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
    19
\                                 T' = @t'. ? ex1. (t,t'):R & move A ex1 s a t' \
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
    20
\                             in \
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
    21
\                                (@cex. move A cex s a T')  \
10835
nipkow
parents: 9970
diff changeset
    22
\                              @@ ((corresp_ex_simC A R $xs) T'))   \
nipkow
parents: 9970
diff changeset
    23
\                        $x) ))";
4565
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
    24
by (rtac trans 1);
5132
24f992a25adc isatool expandshort;
wenzelm
parents: 5068
diff changeset
    25
by (rtac fix_eq2 1);
24f992a25adc isatool expandshort;
wenzelm
parents: 5068
diff changeset
    26
by (rtac corresp_ex_simC_def 1);
24f992a25adc isatool expandshort;
wenzelm
parents: 5068
diff changeset
    27
by (rtac beta_cfun 1);
4565
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
    28
by (simp_tac (simpset() addsimps [flift1_def]) 1);
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
    29
qed"corresp_ex_simC_unfold";
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
    30
10835
nipkow
parents: 9970
diff changeset
    31
Goal "(corresp_ex_simC A R$UU) s=UU";
4565
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
    32
by (stac corresp_ex_simC_unfold 1);
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
    33
by (Simp_tac 1);
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
    34
qed"corresp_ex_simC_UU";
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
    35
10835
nipkow
parents: 9970
diff changeset
    36
Goal "(corresp_ex_simC A R$nil) s = nil";
4565
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
    37
by (stac corresp_ex_simC_unfold 1);
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
    38
by (Simp_tac 1);
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
    39
qed"corresp_ex_simC_nil";
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
    40
10835
nipkow
parents: 9970
diff changeset
    41
Goal "(corresp_ex_simC A R$((a,t)>>xs)) s = \
4565
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
    42
\          (let T' = @t'. ? ex1. (t,t'):R & move A ex1 s a t' \
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
    43
\           in  \
17233
41eee2e7b465 converted specifications to Isar theories;
wenzelm
parents: 14981
diff changeset
    44
\            (@cex. move A cex s a T')  \
10835
nipkow
parents: 9970
diff changeset
    45
\             @@ ((corresp_ex_simC A R$xs) T'))";
5132
24f992a25adc isatool expandshort;
wenzelm
parents: 5068
diff changeset
    46
by (rtac trans 1);
4565
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
    47
by (stac corresp_ex_simC_unfold 1);
7229
6773ba0c36d5 renamed Cons to Consq in order to avoid clash with List.Cons;
wenzelm
parents: 6161
diff changeset
    48
by (asm_full_simp_tac (simpset() addsimps [Consq_def,flift1_def]) 1);
4565
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
    49
by (Simp_tac 1);
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
    50
qed"corresp_ex_simC_cons";
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
    51
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
    52
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
    53
Addsimps [corresp_ex_simC_UU,corresp_ex_simC_nil,corresp_ex_simC_cons];
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
    54
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
    55
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
    56
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
    57
(* ------------------------------------------------------------------ *)
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
    58
(*               The following lemmata describe the definition        *)
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
    59
(*                         of move in more detail                     *)
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
    60
(* ------------------------------------------------------------------ *)
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
    61
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
    62
section"properties of move";
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
    63
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
    64
Delsimps [Let_def];
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
    65
5068
fb28eaa07e01 isatool fixgoal;
wenzelm
parents: 4833
diff changeset
    66
Goalw [is_simulation_def]
6161
paulson
parents: 5132
diff changeset
    67
   "[|is_simulation R C A; reachable C s; s -a--C-> t; (s,s'):R|] ==>\
4565
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
    68
\     let T' = @t'. ? ex1. (t,t'):R & move A ex1 s' a t' in \
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
    69
\     (t,T'): R & move A (@ex2. move A ex2 s' a T') s' a T'";
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
    70
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
    71
(* Does not perform conditional rewriting on assumptions automatically as
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
    72
   usual. Instantiate all variables per hand. Ask Tobias?? *)
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
    73
by (subgoal_tac "? t' ex. (t,t'):R & move A ex s' a t'" 1);
17233
41eee2e7b465 converted specifications to Isar theories;
wenzelm
parents: 14981
diff changeset
    74
by (Asm_full_simp_tac 2);
4565
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
    75
by (etac conjE 2);
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
    76
by (eres_inst_tac [("x","s")] allE 2);
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
    77
by (eres_inst_tac [("x","s'")] allE 2);
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
    78
by (eres_inst_tac [("x","t")] allE 2);
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
    79
by (eres_inst_tac [("x","a")] allE 2);
17233
41eee2e7b465 converted specifications to Isar theories;
wenzelm
parents: 14981
diff changeset
    80
by (Asm_full_simp_tac 2);
4565
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
    81
(* Go on as usual *)
5132
24f992a25adc isatool expandshort;
wenzelm
parents: 5068
diff changeset
    82
by (etac exE 1);
4565
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
    83
by (dres_inst_tac [("x","t'"),
9970
dfe4747c8318 the final renaming: selectI -> someI
paulson
parents: 9969
diff changeset
    84
         ("P","%t'. ? ex.(t,t'):R & move A ex s' a t'")] someI 1);
5132
24f992a25adc isatool expandshort;
wenzelm
parents: 5068
diff changeset
    85
by (etac exE 1);
24f992a25adc isatool expandshort;
wenzelm
parents: 5068
diff changeset
    86
by (etac conjE 1);
4565
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
    87
by (asm_full_simp_tac (simpset() addsimps [Let_def]) 1);
9970
dfe4747c8318 the final renaming: selectI -> someI
paulson
parents: 9969
diff changeset
    88
by (res_inst_tac [("x","ex")] someI 1);
5132
24f992a25adc isatool expandshort;
wenzelm
parents: 5068
diff changeset
    89
by (etac conjE 1);
24f992a25adc isatool expandshort;
wenzelm
parents: 5068
diff changeset
    90
by (assume_tac 1);
4565
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
    91
qed"move_is_move_sim";
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
    92
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
    93
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
    94
Addsimps [Let_def];
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
    95
5068
fb28eaa07e01 isatool fixgoal;
wenzelm
parents: 4833
diff changeset
    96
Goal
6161
paulson
parents: 5132
diff changeset
    97
   "[|is_simulation R C A; reachable C s; s-a--C-> t; (s,s'):R|] ==>\
4565
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
    98
\   let T' = @t'. ? ex1. (t,t'):R & move A ex1 s' a t' in \
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
    99
\    is_exec_frag A (s',@x. move A x s' a T')";
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
   100
by (cut_inst_tac [] move_is_move_sim 1);
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
   101
by (REPEAT (assume_tac 1));
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
   102
by (asm_full_simp_tac (simpset() addsimps [move_def,Let_def]) 1);
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
   103
qed"move_subprop1_sim";
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
   104
5068
fb28eaa07e01 isatool fixgoal;
wenzelm
parents: 4833
diff changeset
   105
Goal
6161
paulson
parents: 5132
diff changeset
   106
   "[|is_simulation R C A; reachable C s; s-a--C-> t; (s,s'):R|] ==>\
4565
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
   107
\   let T' = @t'. ? ex1. (t,t'):R & move A ex1 s' a t' in \
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
   108
\   Finite (@x. move A x s' a T')";
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
   109
by (cut_inst_tac [] move_is_move_sim 1);
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
   110
by (REPEAT (assume_tac 1));
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
   111
by (asm_full_simp_tac (simpset() addsimps [move_def,Let_def]) 1);
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
   112
qed"move_subprop2_sim";
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
   113
5068
fb28eaa07e01 isatool fixgoal;
wenzelm
parents: 4833
diff changeset
   114
Goal
6161
paulson
parents: 5132
diff changeset
   115
   "[|is_simulation R C A; reachable C s; s-a--C-> t; (s,s'):R|] ==>\
4565
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
   116
\   let T' = @t'. ? ex1. (t,t'):R & move A ex1 s' a t' in \
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
   117
\    laststate (s',@x. move A x s' a T') = T'";
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
   118
by (cut_inst_tac [] move_is_move_sim 1);
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
   119
by (REPEAT (assume_tac 1));
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
   120
by (asm_full_simp_tac (simpset() addsimps [move_def,Let_def]) 1);
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
   121
qed"move_subprop3_sim";
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
   122
5068
fb28eaa07e01 isatool fixgoal;
wenzelm
parents: 4833
diff changeset
   123
Goal
6161
paulson
parents: 5132
diff changeset
   124
   "[|is_simulation R C A; reachable C s; s-a--C-> t; (s,s'):R|] ==>\
4565
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
   125
\   let T' = @t'. ? ex1. (t,t'):R & move A ex1 s' a t' in \
10835
nipkow
parents: 9970
diff changeset
   126
\     mk_trace A$((@x. move A x s' a T')) = \
4565
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
   127
\       (if a:ext A then a>>nil else nil)";
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
   128
by (cut_inst_tac [] move_is_move_sim 1);
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
   129
by (REPEAT (assume_tac 1));
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
   130
by (asm_full_simp_tac (simpset() addsimps [move_def,Let_def]) 1);
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
   131
qed"move_subprop4_sim";
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
   132
5068
fb28eaa07e01 isatool fixgoal;
wenzelm
parents: 4833
diff changeset
   133
Goal
6161
paulson
parents: 5132
diff changeset
   134
   "[|is_simulation R C A; reachable C s; s-a--C-> t; (s,s'):R|] ==>\
4565
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
   135
\   let T' = @t'. ? ex1. (t,t'):R & move A ex1 s' a t' in \
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
   136
\     (t,T'):R";
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
   137
by (cut_inst_tac [] move_is_move_sim 1);
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
   138
by (REPEAT (assume_tac 1));
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
   139
by (asm_full_simp_tac (simpset() addsimps [move_def,Let_def]) 1);
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
   140
qed"move_subprop5_sim";
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
   141
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
   142
(* ------------------------------------------------------------------ *)
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
   143
(*                   The following lemmata contribute to              *)
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
   144
(*                 TRACE INCLUSION Part 1: Traces coincide            *)
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
   145
(* ------------------------------------------------------------------ *)
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
   146
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
   147
section "Lemmata for <==";
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
   148
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
   149
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
   150
(* ------------------------------------------------------
17233
41eee2e7b465 converted specifications to Isar theories;
wenzelm
parents: 14981
diff changeset
   151
                 Lemma 1 :Traces coincide
4565
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
   152
   ------------------------------------------------------- *)
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
   153
4833
2e53109d4bc8 Renamed expand_const -> split_const
nipkow
parents: 4681
diff changeset
   154
Delsplits[split_if];
17233
41eee2e7b465 converted specifications to Isar theories;
wenzelm
parents: 14981
diff changeset
   155
Goal
41eee2e7b465 converted specifications to Isar theories;
wenzelm
parents: 14981
diff changeset
   156
  "[|is_simulation R C A; ext C = ext A|] ==>  \
4565
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
   157
\        !s s'. reachable C s & is_exec_frag C (s,ex) & (s,s'): R --> \
10835
nipkow
parents: 9970
diff changeset
   158
\            mk_trace C$ex = mk_trace A$((corresp_ex_simC A R$ex) s')";
4565
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
   159
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
   160
by (pair_induct_tac "ex" [is_exec_frag_def] 1);
17233
41eee2e7b465 converted specifications to Isar theories;
wenzelm
parents: 14981
diff changeset
   161
(* cons case *)
41eee2e7b465 converted specifications to Isar theories;
wenzelm
parents: 14981
diff changeset
   162
by (safe_tac set_cs);
17955
3b34516662c6 avoid shortcuts from OldGoals;
wenzelm
parents: 17233
diff changeset
   163
by (rename_tac "ex a t s s'" 1);
4565
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
   164
by (asm_full_simp_tac (simpset() addsimps [mk_traceConc]) 1);
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
   165
by (forward_tac [reachable.reachable_n] 1);
5132
24f992a25adc isatool expandshort;
wenzelm
parents: 5068
diff changeset
   166
by (assume_tac 1);
4565
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
   167
by (eres_inst_tac [("x","t")] allE 1);
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
   168
by (eres_inst_tac [("x",
17233
41eee2e7b465 converted specifications to Isar theories;
wenzelm
parents: 14981
diff changeset
   169
                    "@t'. ? ex1. (t,t'):R & move A ex1 s' a t'")]
4565
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
   170
     allE 1);
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
   171
by (Asm_full_simp_tac 1);
17233
41eee2e7b465 converted specifications to Isar theories;
wenzelm
parents: 14981
diff changeset
   172
by (asm_full_simp_tac (simpset() addsimps
4565
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
   173
      [rewrite_rule [Let_def] move_subprop5_sim,
17233
41eee2e7b465 converted specifications to Isar theories;
wenzelm
parents: 14981
diff changeset
   174
       rewrite_rule [Let_def] move_subprop4_sim]
4833
2e53109d4bc8 Renamed expand_const -> split_const
nipkow
parents: 4681
diff changeset
   175
   addsplits [split_if]) 1);
4565
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
   176
qed_spec_mp"traces_coincide_sim";
4833
2e53109d4bc8 Renamed expand_const -> split_const
nipkow
parents: 4681
diff changeset
   177
Addsplits[split_if];
4565
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
   178
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
   179
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
   180
(* ----------------------------------------------------------- *)
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
   181
(*               Lemma 2 : corresp_ex_sim is execution             *)
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
   182
(* ----------------------------------------------------------- *)
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
   183
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
   184
17233
41eee2e7b465 converted specifications to Isar theories;
wenzelm
parents: 14981
diff changeset
   185
Goal
6161
paulson
parents: 5132
diff changeset
   186
 "[| is_simulation R C A |] ==>\
4565
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
   187
\ !s s'. reachable C s & is_exec_frag C (s,ex) & (s,s'):R  \
17233
41eee2e7b465 converted specifications to Isar theories;
wenzelm
parents: 14981
diff changeset
   188
\ --> is_exec_frag A (s',(corresp_ex_simC A R$ex) s')";
4565
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
   189
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
   190
by (Asm_full_simp_tac 1);
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
   191
by (pair_induct_tac "ex" [is_exec_frag_def] 1);
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
   192
(* main case *)
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
   193
by (safe_tac set_cs);
17955
3b34516662c6 avoid shortcuts from OldGoals;
wenzelm
parents: 17233
diff changeset
   194
by (rename_tac "ex a t s s'" 1);
4565
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
   195
by (res_inst_tac [("t",
17233
41eee2e7b465 converted specifications to Isar theories;
wenzelm
parents: 14981
diff changeset
   196
                   "@t'. ? ex1. (t,t'):R & move A ex1 s' a t'")]
4565
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
   197
    lemma_2_1 1);
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
   198
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
   199
(* Finite *)
5132
24f992a25adc isatool expandshort;
wenzelm
parents: 5068
diff changeset
   200
by (etac (rewrite_rule [Let_def] move_subprop2_sim) 1);
4565
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
   201
by (REPEAT (atac 1));
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
   202
by (rtac conjI 1);
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
   203
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
   204
(* is_exec_frag *)
5132
24f992a25adc isatool expandshort;
wenzelm
parents: 5068
diff changeset
   205
by (etac (rewrite_rule [Let_def] move_subprop1_sim) 1);
4565
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
   206
by (REPEAT (atac 1));
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
   207
by (rtac conjI 1);
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
   208
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
   209
(* Induction hypothesis  *)
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
   210
(* reachable_n looping, therefore apply it manually *)
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
   211
by (eres_inst_tac [("x","t")] allE 1);
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
   212
by (eres_inst_tac [("x",
17233
41eee2e7b465 converted specifications to Isar theories;
wenzelm
parents: 14981
diff changeset
   213
                    "@t'. ? ex1. (t,t'):R & move A ex1 s' a t'")]
4565
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
   214
     allE 1);
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
   215
by (Asm_full_simp_tac 1);
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
   216
by (forward_tac [reachable.reachable_n] 1);
5132
24f992a25adc isatool expandshort;
wenzelm
parents: 5068
diff changeset
   217
by (assume_tac 1);
17233
41eee2e7b465 converted specifications to Isar theories;
wenzelm
parents: 14981
diff changeset
   218
by (asm_full_simp_tac (simpset() addsimps
4565
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
   219
            [rewrite_rule [Let_def] move_subprop5_sim]) 1);
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
   220
(* laststate *)
5132
24f992a25adc isatool expandshort;
wenzelm
parents: 5068
diff changeset
   221
by (etac ((rewrite_rule [Let_def] move_subprop3_sim) RS sym) 1);
4565
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
   222
by (REPEAT (atac 1));
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
   223
qed_spec_mp"correspsim_is_execution";
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
   224
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
   225
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
   226
(* -------------------------------------------------------------------------------- *)
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
   227
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
   228
section "Main Theorem: T R A C E - I N C L U S I O N";
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
   229
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
   230
(* -------------------------------------------------------------------------------- *)
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
   231
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
   232
  (* generate condition (s,S'):R & S':starts_of A, the first being intereting
17233
41eee2e7b465 converted specifications to Isar theories;
wenzelm
parents: 14981
diff changeset
   233
     for the induction cases concerning the two lemmas correpsim_is_execution and
41eee2e7b465 converted specifications to Isar theories;
wenzelm
parents: 14981
diff changeset
   234
     traces_coincide_sim, the second for the start state case.
4565
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
   235
     S':= @s'. (s,s'):R & s':starts_of A, where s:starts_of C  *)
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
   236
17233
41eee2e7b465 converted specifications to Isar theories;
wenzelm
parents: 14981
diff changeset
   237
Goal
6161
paulson
parents: 5132
diff changeset
   238
"[| is_simulation R C A; s:starts_of C |] \
4565
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
   239
\ ==> let S' = @s'. (s,s'):R & s':starts_of A in \
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
   240
\     (s,S'):R & S':starts_of A";
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
   241
  by (asm_full_simp_tac (simpset() addsimps [is_simulation_def,
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
   242
         corresp_ex_sim_def, Int_non_empty,Image_def]) 1);
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
   243
  by (REPEAT (etac conjE 1));
5132
24f992a25adc isatool expandshort;
wenzelm
parents: 5068
diff changeset
   244
  by (etac ballE 1);
4565
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
   245
  by (Blast_tac 2);
5132
24f992a25adc isatool expandshort;
wenzelm
parents: 5068
diff changeset
   246
  by (etac exE 1);
9969
4753185f1dd2 renamed (most of...) the select rules
paulson
parents: 7229
diff changeset
   247
  by (rtac someI2 1);
5132
24f992a25adc isatool expandshort;
wenzelm
parents: 5068
diff changeset
   248
  by (assume_tac 1);
4565
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
   249
  by (Blast_tac 1);
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
   250
qed"simulation_starts";
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
   251
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
   252
bind_thm("sim_starts1",(rewrite_rule [Let_def] simulation_starts) RS conjunct1);
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
   253
bind_thm("sim_starts2",(rewrite_rule [Let_def] simulation_starts) RS conjunct2);
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
   254
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
   255
5068
fb28eaa07e01 isatool fixgoal;
wenzelm
parents: 4833
diff changeset
   256
Goalw [traces_def]
6161
paulson
parents: 5132
diff changeset
   257
  "[| ext C = ext A; is_simulation R C A |] \
17233
41eee2e7b465 converted specifications to Isar theories;
wenzelm
parents: 14981
diff changeset
   258
\          ==> traces C <= traces A";
4565
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
   259
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
   260
  by (simp_tac(simpset() addsimps [has_trace_def2])1);
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
   261
  by (safe_tac set_cs);
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
   262
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
   263
  (* give execution of abstract automata *)
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
   264
  by (res_inst_tac[("x","corresp_ex_sim A R ex")] bexI 1);
17233
41eee2e7b465 converted specifications to Isar theories;
wenzelm
parents: 14981
diff changeset
   265
4565
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
   266
  (* Traces coincide, Lemma 1 *)
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
   267
  by (pair_tac "ex" 1);
17955
3b34516662c6 avoid shortcuts from OldGoals;
wenzelm
parents: 17233
diff changeset
   268
  by (rename_tac "s ex" 1);
4565
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
   269
  by (simp_tac (simpset() addsimps [corresp_ex_sim_def]) 1);
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
   270
  by (res_inst_tac [("s","s")] traces_coincide_sim 1);
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
   271
  by (REPEAT (atac 1));
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
   272
  by (asm_full_simp_tac (simpset() addsimps [executions_def,
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
   273
          reachable.reachable_0,sim_starts1]) 1);
17233
41eee2e7b465 converted specifications to Isar theories;
wenzelm
parents: 14981
diff changeset
   274
4565
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
   275
  (* corresp_ex_sim is execution, Lemma 2 *)
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
   276
  by (pair_tac "ex" 1);
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
   277
  by (asm_full_simp_tac (simpset() addsimps [executions_def]) 1);
17955
3b34516662c6 avoid shortcuts from OldGoals;
wenzelm
parents: 17233
diff changeset
   278
  by (rename_tac "s ex" 1);
4565
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
   279
17233
41eee2e7b465 converted specifications to Isar theories;
wenzelm
parents: 14981
diff changeset
   280
  (* start state *)
4565
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
   281
  by (rtac conjI 1);
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
   282
  by (asm_full_simp_tac (simpset() addsimps [sim_starts2,
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
   283
         corresp_ex_sim_def]) 1);
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
   284
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
   285
  (* is-execution-fragment *)
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
   286
  by (asm_full_simp_tac (simpset() addsimps [corresp_ex_sim_def]) 1);
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
   287
  by (res_inst_tac [("s","s")] correspsim_is_execution 1);
5132
24f992a25adc isatool expandshort;
wenzelm
parents: 5068
diff changeset
   288
  by (assume_tac 1);
4565
ea467ce15040 added forward simulation correectness;
mueller
parents:
diff changeset
   289
  by (asm_full_simp_tac (simpset() addsimps [reachable.reachable_0,sim_starts1]) 1);
17233
41eee2e7b465 converted specifications to Isar theories;
wenzelm
parents: 14981
diff changeset
   290
qed"trace_inclusion_for_simulations";