author | kleing |
Thu, 21 Sep 2000 10:42:49 +0200 | |
changeset 10042 | 7164dc0d24d8 |
parent 9385 | 6e1ac1629ac7 |
child 10613 | 78b1d6c3ee9c |
permissions | -rw-r--r-- |
8011 | 1 |
(* Title: HOL/MicroJava/J/JTypeSafe.ML |
2 |
ID: $Id$ |
|
3 |
Author: David von Oheimb |
|
4 |
Copyright 1999 Technische Universitaet Muenchen |
|
5 |
||
6 |
Type safety proof |
|
7 |
*) |
|
8 |
||
9240 | 9 |
|
8011 | 10 |
Addsimps [split_beta]; |
11 |
||
10042 | 12 |
Goal "[|h a = None; (h, l)::\\<preceq>(G, lT); wf_prog wf_mb G; is_class G C|] ==> \ |
13 |
\ (h(a\\<mapsto>(C,(init_vars (fields (G,C))))), l)::\\<preceq>(G, lT)"; |
|
8011 | 14 |
by( etac conforms_upd_obj 1); |
15 |
by( rewtac oconf_def); |
|
16 |
by( auto_tac (claset() addSDs [is_type_fields, map_of_SomeD], simpset())); |
|
17 |
qed "NewC_conforms"; |
|
18 |
||
19 |
Goalw [cast_ok_def] |
|
10042 | 20 |
"[| wf_prog wf_mb G; G,h\\<turnstile>v::\\<preceq>Class C; G\\<turnstile>C\\<preceq>? D; cast_ok G D h v|] \ |
21 |
\ ==> G,h\\<turnstile>v::\\<preceq>Class D"; |
|
8011 | 22 |
by( case_tac1 "v = Null" 1); |
23 |
by( Asm_full_simp_tac 1); |
|
24 |
by( dtac widen_RefT 1); |
|
25 |
by( Clarify_tac 1); |
|
26 |
by( rtac widen.null 1); |
|
9348 | 27 |
by( datac non_npD 1 1); |
28 |
by( auto_tac (claset() addSIs [conf_AddrI], simpset() addsimps [obj_ty_def])); |
|
8011 | 29 |
qed "Cast_conf"; |
30 |
||
10042 | 31 |
Goal "[| wf_prog wf_mb G; field (G,C) fn = Some (fd, ft); (h,l)::\\<preceq>(G,lT); \ |
32 |
\ x' = None --> G,h\\<turnstile>a'::\\<preceq> Class C; np a' x' = None |] ==> \ |
|
33 |
\ G,h\\<turnstile>the (snd (the (h (the_Addr a'))) (fn, fd))::\\<preceq>ft"; |
|
8011 | 34 |
by( dtac np_NoneD 1); |
35 |
by( etac conjE 1); |
|
36 |
by( mp_tac 1); |
|
37 |
by( dtac non_np_objD 1); |
|
38 |
by Auto_tac; |
|
39 |
by( dtac (conforms_heapD RS hconfD) 1); |
|
40 |
by( atac 1); |
|
41 |
by( dtac widen_cfs_fields 1); |
|
42 |
by( atac 1); |
|
43 |
by( atac 1); |
|
44 |
by( dtac oconf_objD 1); |
|
45 |
by( atac 1); |
|
46 |
by Auto_tac; |
|
8082 | 47 |
qed "FAcc_type_sound"; |
8011 | 48 |
|
49 |
Goal |
|
10042 | 50 |
"[| wf_prog wf_mb G; a = the_Addr a'; (c, fs) = the (h a); \ |
51 |
\ (G, lT)\\<turnstile>v::T'; G\\<turnstile>T'\\<preceq>ft; \ |
|
52 |
\ (G, lT)\\<turnstile>aa::Class C; \ |
|
8034
6fc37b5c5e98
Various little changes like cmethd -> method and cfield -> field.
nipkow
parents:
8011
diff
changeset
|
53 |
\ field (G,C) fn = Some (fd, ft); h''\\<le>|h'; \ |
10042 | 54 |
\ x' = None --> G,h'\\<turnstile>a'::\\<preceq> Class C; h'\\<le>|h; \ |
55 |
\ (h, l)::\\<preceq>(G, lT); G,h\\<turnstile>x::\\<preceq>T'; np a' x' = None|] ==> \ |
|
8011 | 56 |
\ h''\\<le>|h(a\\<mapsto>(c,(fs((fn,fd)\\<mapsto>x)))) \\<and> \ |
10042 | 57 |
\ (h(a\\<mapsto>(c,(fs((fn,fd)\\<mapsto>x)))), l)::\\<preceq>(G, lT) \\<and> \ |
58 |
\ G,h(a\\<mapsto>(c,(fs((fn,fd)\\<mapsto>x))))\\<turnstile>x::\\<preceq>T'"; |
|
8011 | 59 |
by( dtac np_NoneD 1); |
60 |
by( etac conjE 1); |
|
61 |
by( Asm_full_simp_tac 1); |
|
62 |
by( dtac non_np_objD 1); |
|
63 |
by( atac 1); |
|
64 |
by( SELECT_GOAL Auto_tac 1); |
|
65 |
by( strip_tac1 1); |
|
66 |
by( Full_simp_tac 1); |
|
67 |
by( EVERY [forward_tac [hext_objD] 1, atac 1]); |
|
68 |
by( etac exE 1); |
|
69 |
by( Asm_full_simp_tac 1); |
|
70 |
by( strip_tac1 1); |
|
71 |
by( rtac conjI 1); |
|
72 |
by( fast_tac (HOL_cs addEs [hext_trans, hext_upd_obj]) 1); |
|
73 |
by( rtac conjI 1); |
|
74 |
by( fast_tac (HOL_cs addEs [conf_upd_obj RS iffD2]) 2); |
|
75 |
||
76 |
by( rtac conforms_upd_obj 1); |
|
77 |
by Auto_tac; |
|
78 |
by( rtac hextI 2); |
|
79 |
by( Force_tac 2); |
|
80 |
by( rtac oconf_hext 1); |
|
81 |
by( etac hext_upd_obj 2); |
|
82 |
by( dtac widen_cfs_fields 1); |
|
83 |
by( atac 1); |
|
84 |
by( atac 1); |
|
85 |
by( rtac (oconf_obj RS iffD2) 1); |
|
86 |
by( Simp_tac 1); |
|
87 |
by( strip_tac 1); |
|
88 |
by( case_tac1 "(aaa, b) = (fn, fd)" 1); |
|
89 |
by( Asm_full_simp_tac 1); |
|
90 |
by( fast_tac (HOL_cs addIs [conf_widen]) 1); |
|
91 |
by( fast_tac (HOL_cs addDs [conforms_heapD RS hconfD, oconf_objD]) 1); |
|
8082 | 92 |
qed "FAss_type_sound"; |
8011 | 93 |
|
10042 | 94 |
Goalw [wf_mhead_def] "[| wf_prog wf_mb G; list_all2 (conf G h) pvs pTs; \ |
8011 | 95 |
\ list_all2 (\\<lambda>T T'. G\\<turnstile>T\\<preceq>T') pTs pTs'; wf_mhead G (mn,pTs') rT; \ |
96 |
\ length pTs' = length pns; nodups pns; \ |
|
97 |
\ Ball (set lvars) (split (\\<lambda>vn. is_type G)) \ |
|
10042 | 98 |
\ |] ==> G,h\\<turnstile>init_vars lvars(pns[\\<mapsto>]pvs)[::\\<preceq>]map_of lvars(pns[\\<mapsto>]pTs')"; |
8011 | 99 |
by( Clarsimp_tac 1); |
100 |
by( rtac lconf_ext_list 1); |
|
101 |
by( rtac (Ball_set_table RS lconf_init_vars) 1); |
|
102 |
by( Force_tac 1); |
|
103 |
by( atac 1); |
|
104 |
by( atac 1); |
|
105 |
by( (etac conf_list_gext_widen THEN_ALL_NEW atac) 1); |
|
106 |
qed "Call_lemma2"; |
|
107 |
||
108 |
Goalw [wf_java_prog_def] |
|
10042 | 109 |
"[| wf_java_prog G; a' \\<noteq> Null; (h, l)::\\<preceq>(G, lT); \ |
8085 | 110 |
\ max_spec G C (mn,pTsa) = {((mda,rTa),pTs')}; xc\\<le>|xh; xh\\<le>|h; \ |
8011 | 111 |
\ list_all2 (conf G h) pvs pTsa;\ |
112 |
\ (md, rT, pns, lvars, blk, res) = \ |
|
8034
6fc37b5c5e98
Various little changes like cmethd -> method and cfield -> field.
nipkow
parents:
8011
diff
changeset
|
113 |
\ the (method (G,fst (the (h (the_Addr a')))) (mn, pTs'));\ |
10042 | 114 |
\ \\<forall>lT. (h, init_vars lvars(pns[\\<mapsto>]pvs)(This\\<mapsto>a'))::\\<preceq>(G, lT) --> \ |
115 |
\ (G, lT)\\<turnstile>blk\\<surd> --> h\\<le>|xi \\<and> (xi, xl)::\\<preceq>(G, lT); \ |
|
116 |
\ \\<forall>lT. (xi, xl)::\\<preceq>(G, lT) --> (\\<forall>T. (G, lT)\\<turnstile>res::T --> \ |
|
117 |
\ xi\\<le>|h' \\<and> (h', xj)::\\<preceq>(G, lT) \\<and> (x' = None --> G,h'\\<turnstile>v::\\<preceq>T)); \ |
|
118 |
\ G,xh\\<turnstile>a'::\\<preceq> Class C |] ==> \ |
|
119 |
\ xc\\<le>|h' \\<and> (h', l)::\\<preceq>(G, lT) \\<and> (x' = None --> G,h'\\<turnstile>v::\\<preceq>rTa)"; |
|
8011 | 120 |
by( dtac (insertI1 RSN (2,(equalityD2 RS subsetD))) 1); |
121 |
by( dtac (max_spec2appl_meths RS appl_methsD) 1); |
|
8105
2dda3e88d23f
simplified definition of appl_methds, removing m_head
oheimb
parents:
8085
diff
changeset
|
122 |
by( Clarify_tac 1); |
2dda3e88d23f
simplified definition of appl_methds, removing m_head
oheimb
parents:
8085
diff
changeset
|
123 |
by( datac non_np_objD' 2 1); |
8011 | 124 |
by( strip_tac1 1); |
125 |
by( Asm_full_simp_tac 1); |
|
126 |
by( Clarsimp_tac 1); |
|
127 |
by( EVERY'[forward_tac [hext_objD], atac] 1); |
|
128 |
by( Clarsimp_tac 1); |
|
129 |
by( EVERY'[dtac Call_lemma, atac, atac] 1); |
|
8082 | 130 |
by( clarsimp_tac (claset(),simpset() addsimps [wf_java_mdecl_def])1); |
8034
6fc37b5c5e98
Various little changes like cmethd -> method and cfield -> field.
nipkow
parents:
8011
diff
changeset
|
131 |
by( thin_tac "method ?sig ?x = ?y" 1); |
8011 | 132 |
by( EVERY'[dtac spec, etac impE] 1); |
133 |
by( mp_tac 2); |
|
134 |
by( rtac conformsI 1); |
|
135 |
by( etac conforms_heapD 1); |
|
136 |
by( rtac lconf_ext 1); |
|
137 |
by( force_tac (claset() addSEs [Call_lemma2],simpset()) 1); |
|
138 |
by( EVERY'[etac conf_hext, etac conf_obj_AddrI, atac] 1); |
|
139 |
by( thin_tac "?E\\<turnstile>?blk\\<surd>" 1); |
|
140 |
by( etac conjE 1); |
|
141 |
by( EVERY'[dtac spec, mp_tac] 1); |
|
10042 | 142 |
(*by( thin_tac "?E::\\<preceq>(G, pT')" 1);*) |
8011 | 143 |
by( EVERY'[dtac spec, mp_tac] 1); |
10042 | 144 |
by( thin_tac "?E\\<turnstile>res::?rT" 1); |
8011 | 145 |
by( strip_tac1 1); |
146 |
by( rtac conjI 1); |
|
147 |
by( fast_tac (HOL_cs addIs [hext_trans]) 1); |
|
148 |
by( rtac conjI 1); |
|
149 |
by( rtac impI 2); |
|
150 |
by( mp_tac 2); |
|
151 |
by( forward_tac [conf_widen] 2); |
|
152 |
by( atac 4); |
|
153 |
by( atac 2); |
|
154 |
by( fast_tac (HOL_cs addSEs [widen_trans]) 2); |
|
155 |
by( etac conforms_hext 1); |
|
156 |
by( etac hext_trans 1); |
|
157 |
by( atac 1); |
|
158 |
by( etac conforms_heapD 1); |
|
159 |
qed "Call_type_sound"; |
|
160 |
||
161 |
||
162 |
||
163 |
Unify.search_bound := 40; |
|
164 |
Unify.trace_bound := 40; |
|
165 |
Delsplits[split_if]; |
|
166 |
Delsimps[fun_upd_apply];(*###*) |
|
9240 | 167 |
val forward_hyp_tac = ALLGOALS (TRY o (EVERY' [dtac spec, mp_tac, |
168 |
(mp_tac ORELSE' (dtac spec THEN' mp_tac)), REPEAT o (etac conjE)])); |
|
8011 | 169 |
Goal |
10042 | 170 |
"wf_java_prog G ==> \ |
171 |
\ (G\\<turnstile>(x,(h,l)) -e \\<succ>v -> (x', (h',l')) --> \ |
|
172 |
\ (\\<forall>lT. (h ,l )::\\<preceq>(G,lT) --> (\\<forall>T . (G,lT)\\<turnstile>e :: T --> \ |
|
173 |
\ h\\<le>|h' \\<and> (h',l')::\\<preceq>(G,lT) \\<and> (x'=None --> G,h'\\<turnstile>v ::\\<preceq> T )))) \\<and> \ |
|
174 |
\ (G\\<turnstile>(x,(h,l)) -es[\\<succ>]vs-> (x', (h',l')) --> \ |
|
175 |
\ (\\<forall>lT. (h ,l )::\\<preceq>(G,lT) --> (\\<forall>Ts. (G,lT)\\<turnstile>es[::]Ts --> \ |
|
176 |
\ h\\<le>|h' \\<and> (h',l')::\\<preceq>(G,lT) \\<and> (x'=None --> list_all2 (\\<lambda>v T. G,h'\\<turnstile>v::\\<preceq>T) vs Ts)))) \\<and> \ |
|
177 |
\ (G\\<turnstile>(x,(h,l)) -c -> (x', (h',l')) --> \ |
|
178 |
\ (\\<forall>lT. (h ,l )::\\<preceq>(G,lT) --> (G,lT)\\<turnstile>c \\<surd> --> \ |
|
179 |
\ h\\<le>|h' \\<and> (h',l')::\\<preceq>(G,lT)))"; |
|
8011 | 180 |
by( rtac eval_evals_exec.induct 1); |
181 |
by( rewtac c_hupd_def); |
|
182 |
||
183 |
(* several simplifications, XcptE, XcptEs, XcptS, Skip *) |
|
184 |
by( ALLGOALS Asm_full_simp_tac); |
|
185 |
by( ALLGOALS strip_tac); |
|
186 |
by( ALLGOALS (eresolve_tac ty_expr_ty_exprs_wt_stmt.elims |
|
187 |
THEN_ALL_NEW Full_simp_tac)); |
|
188 |
by( ALLGOALS (EVERY' [REPEAT o (etac conjE), REPEAT o hyp_subst_tac])); |
|
189 |
by( rewtac wf_java_prog_def); |
|
190 |
||
191 |
(* Level 7 *) |
|
192 |
||
9240 | 193 |
(* 14 NewC *) |
8011 | 194 |
by( dtac new_AddrD 1); |
195 |
by( etac disjE 1); |
|
196 |
by( Asm_simp_tac 2); |
|
197 |
by( etac conjE 1); |
|
198 |
by( Asm_simp_tac 1); |
|
199 |
by( rtac conjI 1); |
|
200 |
by( fast_tac (HOL_cs addSEs [NewC_conforms]) 1); |
|
201 |
by( rtac conf_obj_AddrI 1); |
|
8185 | 202 |
by( rtac rtrancl_refl 2); |
8011 | 203 |
by( Simp_tac 1); |
204 |
||
205 |
(* for Cast *) |
|
206 |
by( defer_tac 1); |
|
207 |
||
9240 | 208 |
(* 13 Lit *) |
8011 | 209 |
by( etac conf_litval 1); |
210 |
||
9240 | 211 |
(* 12 BinOp *) |
212 |
by forward_hyp_tac; |
|
213 |
by forward_hyp_tac; |
|
214 |
by( EVERY'[rtac conjI, eatac hext_trans 1] 1); |
|
215 |
by( etac conjI 1); |
|
216 |
by( Clarsimp_tac 1); |
|
217 |
by( dtac eval_no_xcpt 1); |
|
218 |
by( asm_full_simp_tac (simpset() addsplits [binop.split]) 1); |
|
219 |
||
8185 | 220 |
(* 11 LAcc *) |
8011 | 221 |
by( fast_tac (claset() addEs [conforms_localD RS lconfD]) 1); |
222 |
||
8185 | 223 |
(* 10 Nil *) |
8011 | 224 |
by( Simp_tac 5); |
225 |
||
226 |
(* for FAss *) |
|
227 |
by( EVERY'[eresolve_tac ty_expr_ty_exprs_wt_stmt.elims THEN_ALL_NEW Full_simp_tac, |
|
228 |
REPEAT o (etac conjE), hyp_subst_tac] 3); |
|
229 |
||
230 |
(* for if *) |
|
231 |
by( (case_tac1 "the_Bool v" THEN_ALL_NEW Asm_full_simp_tac) 8); |
|
232 |
||
233 |
by forward_hyp_tac; |
|
234 |
||
235 |
(* 10+1 if *) |
|
236 |
by( fast_tac (HOL_cs addIs [hext_trans]) 8); |
|
237 |
by( fast_tac (HOL_cs addIs [hext_trans]) 8); |
|
238 |
||
239 |
(* 9 Expr *) |
|
240 |
by( Fast_tac 6); |
|
241 |
||
242 |
by( ALLGOALS Asm_full_simp_tac); |
|
243 |
||
244 |
(* 8 Cast *) |
|
245 |
by( EVERY'[rtac impI, dtac raise_if_NoneD, Clarsimp_tac, |
|
246 |
fast_tac (claset() addEs [Cast_conf])] 8); |
|
247 |
||
248 |
(* 7 LAss *) |
|
9385 | 249 |
by( asm_simp_tac (simpset() addsplits [split_if]) 1); |
8011 | 250 |
by( EVERY'[eresolve_tac ty_expr_ty_exprs_wt_stmt.elims THEN_ALL_NEW Full_simp_tac] 1); |
251 |
by( blast_tac (claset() addIs [conforms_upd_local, conf_widen]) 1); |
|
252 |
||
253 |
(* 6 FAcc *) |
|
254 |
by( fast_tac (claset() addSEs [FAcc_type_sound]) 1); |
|
255 |
||
256 |
(* 5 While *) |
|
257 |
by( fast_tac (claset() addIs [ty_expr_ty_exprs_wt_stmt.Cond, ty_expr_ty_exprs_wt_stmt.Comp, ty_expr_ty_exprs_wt_stmt.Skip] |
|
258 |
addEs [ty_expr_ty_exprs_wt_stmt.Loop]) 5); |
|
259 |
||
260 |
by forward_hyp_tac; |
|
261 |
||
262 |
(* 4 Cons *) |
|
263 |
by( fast_tac (claset() addDs [evals_no_xcpt] addIs [conf_hext,hext_trans]) 3); |
|
264 |
||
265 |
(* 3 ;; *) |
|
266 |
by( fast_tac (claset() addIs [hext_trans]) 3); |
|
267 |
||
268 |
(* 2 FAss *) |
|
269 |
by( case_tac1 "x2 = None" 1); |
|
270 |
by( Asm_simp_tac 2); |
|
271 |
by( fast_tac (claset() addIs [hext_trans]) 2); |
|
272 |
by( Asm_full_simp_tac 1); |
|
273 |
by( dtac eval_no_xcpt 1); |
|
274 |
by( SELECT_GOAL (etac FAss_type_sound 1 THEN rtac refl 1 THEN ALLGOALS atac) 1); |
|
275 |
||
276 |
by prune_params_tac; |
|
9348 | 277 |
(* Level 51 *) |
8011 | 278 |
|
279 |
(* 1 Call *) |
|
8442
96023903c2df
case_tac now subsumes both boolean and datatype cases;
wenzelm
parents:
8423
diff
changeset
|
280 |
by( case_tac "x" 1); |
8011 | 281 |
by( Clarsimp_tac 2); |
282 |
by( dtac exec_xcpt 2); |
|
283 |
by( Asm_full_simp_tac 2); |
|
284 |
by( dtac eval_xcpt 2); |
|
285 |
by( Asm_full_simp_tac 2); |
|
286 |
by( fast_tac (HOL_cs addEs [hext_trans]) 2); |
|
287 |
by( Clarify_tac 1); |
|
288 |
by( dtac evals_no_xcpt 1); |
|
289 |
by( Asm_full_simp_tac 1); |
|
290 |
by( case_tac1 "a' = Null" 1); |
|
291 |
by( Asm_full_simp_tac 1); |
|
292 |
by( dtac exec_xcpt 1); |
|
293 |
by( Asm_full_simp_tac 1); |
|
294 |
by( dtac eval_xcpt 1); |
|
295 |
by( Asm_full_simp_tac 1); |
|
296 |
by( fast_tac (HOL_cs addEs [hext_trans]) 1); |
|
9348 | 297 |
by( (rtac (rewrite_rule[wf_java_prog_def]Call_type_sound) |
298 |
THEN_ALL_NEW Asm_simp_tac) 1); |
|
8011 | 299 |
qed "eval_evals_exec_type_sound"; |
300 |
||
10042 | 301 |
Goal "!!E s s'. \ |
302 |
\ [| G=prg E; wf_java_prog G; G\\<turnstile>(x,s) -e\\<succ>v -> (x',s'); s::\\<preceq>E; E\\<turnstile>e::T |] \ |
|
303 |
\ ==> s'::\\<preceq>E \\<and> (x'=None --> G,heap s'\\<turnstile>v::\\<preceq>T)"; |
|
8011 | 304 |
by( split_all_tac 1); |
305 |
bd (eval_evals_exec_type_sound RS conjunct1 RS mp RS spec RS mp) 1; |
|
306 |
by Auto_tac; |
|
307 |
qed "eval_type_sound"; |
|
308 |
||
10042 | 309 |
Goal "!!E s s'. \ |
310 |
\ [| G=prg E; wf_java_prog G; G\\<turnstile>(x,s) -s0-> (x',s'); s::\\<preceq>E; E\\<turnstile>s0\\<surd> |] \ |
|
311 |
\ ==> s'::\\<preceq>E"; |
|
8011 | 312 |
by( split_all_tac 1); |
313 |
bd (eval_evals_exec_type_sound RS conjunct2 RS conjunct2 RS mp RS spec RS mp) 1; |
|
314 |
by Auto_tac; |
|
315 |
qed "exec_type_sound"; |
|
316 |
||
10042 | 317 |
Goal "[|G=prg E; wf_java_prog G; G\\<turnstile>(x,s) -e\\<succ>a'-> Norm s'; a' \\<noteq> Null;\ |
318 |
\ s::\\<preceq>E; E\\<turnstile>e::Class C; method (G,C) sig \\<noteq> None|] ==> \ |
|
8034
6fc37b5c5e98
Various little changes like cmethd -> method and cfield -> field.
nipkow
parents:
8011
diff
changeset
|
319 |
\ method (G,fst (the (heap s' (the_Addr a')))) sig \\<noteq> None"; |
8105
2dda3e88d23f
simplified definition of appl_methds, removing m_head
oheimb
parents:
8085
diff
changeset
|
320 |
by( datac eval_type_sound 4 1); |
8011 | 321 |
by( not_None_tac 1); |
322 |
by( split_all_tac 1); |
|
323 |
by(rewtac wf_java_prog_def); |
|
324 |
by( forward_tac [widen_methd] 1); |
|
325 |
by( atac 1); |
|
326 |
by( rtac (not_None_eq RS iffD1) 2); |
|
327 |
by( Fast_tac 2); |
|
328 |
by( etac conjE 1); |
|
329 |
by( dtac non_npD 1); |
|
330 |
by Auto_tac; |
|
331 |
qed "all_methods_understood"; |
|
332 |
||
333 |
Delsimps [split_beta]; |
|
334 |
Addsimps[fun_upd_apply];(*###*) |
|
335 |