| author | chaieb | 
| Wed, 06 Oct 2004 13:58:08 +0200 | |
| changeset 15231 | 96d5b6e2b6e4 | 
| parent 14095 | a1ba833d6b61 | 
| child 16417 | 9bc16273c2d4 | 
| permissions | -rw-r--r-- | 
| 11479 | 1 | (* Title: ZF/UNITY/Union.thy | 
| 2 | ID: $Id$ | |
| 3 | Author: Sidi O Ehmety, Computer Laboratory | |
| 4 | Copyright 2001 University of Cambridge | |
| 5 | ||
| 6 | Unions of programs | |
| 7 | ||
| 8 | Partly from Misra's Chapter 5: Asynchronous Compositions of Programs | |
| 9 | ||
| 10 | Theory ported form HOL.. | |
| 11 | ||
| 12 | *) | |
| 13 | ||
| 14092 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 14 | theory Union = SubstAx + FP: | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 15 | |
| 11479 | 16 | constdefs | 
| 17 | ||
| 14092 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 18 | (*FIXME: conjoin Init(F) Int Init(G) \<noteq> 0 *) | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 19 | ok :: "[i, i] => o" (infixl "ok" 65) | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 20 | "F ok G == Acts(F) \<subseteq> AllowedActs(G) & | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 21 | Acts(G) \<subseteq> AllowedActs(F)" | 
| 11479 | 22 | |
| 14092 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 23 | (*FIXME: conjoin (\<Inter>i \<in> I. Init(F(i))) \<noteq> 0 *) | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 24 | OK :: "[i, i=>i] => o" | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 25 |     "OK(I,F) == (\<forall>i \<in> I. \<forall>j \<in> I-{i}. Acts(F(i)) \<subseteq> AllowedActs(F(j)))"
 | 
| 11479 | 26 | |
| 14092 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 27 | JOIN :: "[i, i=>i] => i" | 
| 11479 | 28 | "JOIN(I,F) == if I = 0 then SKIP else | 
| 14092 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 29 | mk_program(\<Inter>i \<in> I. Init(F(i)), \<Union>i \<in> I. Acts(F(i)), | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 30 | \<Inter>i \<in> I. AllowedActs(F(i)))" | 
| 11479 | 31 | |
| 14092 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 32 | Join :: "[i, i] => i" (infixl "Join" 65) | 
| 11479 | 33 | "F Join G == mk_program (Init(F) Int Init(G), Acts(F) Un Acts(G), | 
| 34 | AllowedActs(F) Int AllowedActs(G))" | |
| 35 | (*Characterizes safety properties. Used with specifying AllowedActs*) | |
| 36 | safety_prop :: "i => o" | |
| 14092 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 37 | "safety_prop(X) == X\<subseteq>program & | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 38 | SKIP \<in> X & (\<forall>G \<in> program. Acts(G) \<subseteq> (\<Union>F \<in> X. Acts(F)) --> G \<in> X)" | 
| 11479 | 39 | |
| 40 | syntax | |
| 14092 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 41 |   "@JOIN1"     :: "[pttrns, i] => i"         ("(3JN _./ _)" 10)
 | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 42 |   "@JOIN"      :: "[pttrn, i, i] => i"       ("(3JN _:_./ _)" 10)
 | 
| 11479 | 43 | |
| 44 | translations | |
| 45 | "JN x:A. B" == "JOIN(A, (%x. B))" | |
| 46 | "JN x y. B" == "JN x. JN y. B" | |
| 47 | "JN x. B" == "JOIN(state,(%x. B))" | |
| 48 | ||
| 12195 | 49 | syntax (symbols) | 
| 14092 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 50 |    SKIP     :: i                      ("\<bottom>")
 | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 51 | Join :: "[i, i] => i" (infixl "\<squnion>" 65) | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 52 |   "@JOIN1"  :: "[pttrns, i] => i"     ("(3\<Squnion> _./ _)" 10)
 | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 53 |   "@JOIN"   :: "[pttrn, i, i] => i"   ("(3\<Squnion> _ \<in> _./ _)" 10)
 | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 54 | |
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 55 | |
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 56 | subsection{*SKIP*}
 | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 57 | |
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 58 | lemma reachable_SKIP [simp]: "reachable(SKIP) = state" | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 59 | by (force elim: reachable.induct intro: reachable.intros) | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 60 | |
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 61 | text{*Elimination programify from ok and Join*}
 | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 62 | |
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 63 | lemma ok_programify_left [iff]: "programify(F) ok G <-> F ok G" | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 64 | by (simp add: ok_def) | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 65 | |
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 66 | lemma ok_programify_right [iff]: "F ok programify(G) <-> F ok G" | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 67 | by (simp add: ok_def) | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 68 | |
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 69 | lemma Join_programify_left [simp]: "programify(F) Join G = F Join G" | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 70 | by (simp add: Join_def) | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 71 | |
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 72 | lemma Join_programify_right [simp]: "F Join programify(G) = F Join G" | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 73 | by (simp add: Join_def) | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 74 | |
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 75 | subsection{*SKIP and safety properties*}
 | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 76 | |
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 77 | lemma SKIP_in_constrains_iff [iff]: "(SKIP \<in> A co B) <-> (A\<subseteq>B & st_set(A))" | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 78 | by (unfold constrains_def st_set_def, auto) | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 79 | |
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 80 | lemma SKIP_in_Constrains_iff [iff]: "(SKIP \<in> A Co B)<-> (state Int A\<subseteq>B)" | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 81 | by (unfold Constrains_def, auto) | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 82 | |
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 83 | lemma SKIP_in_stable [iff]: "SKIP \<in> stable(A) <-> st_set(A)" | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 84 | by (auto simp add: stable_def) | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 85 | |
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 86 | lemma SKIP_in_Stable [iff]: "SKIP \<in> Stable(A)" | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 87 | by (unfold Stable_def, auto) | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 88 | |
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 89 | subsection{*Join and JOIN types*}
 | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 90 | |
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 91 | lemma Join_in_program [iff,TC]: "F Join G \<in> program" | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 92 | by (unfold Join_def, auto) | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 93 | |
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 94 | lemma JOIN_in_program [iff,TC]: "JOIN(I,F) \<in> program" | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 95 | by (unfold JOIN_def, auto) | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 96 | |
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 97 | subsection{*Init, Acts, and AllowedActs of Join and JOIN*}
 | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 98 | lemma Init_Join [simp]: "Init(F Join G) = Init(F) Int Init(G)" | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 99 | by (simp add: Int_assoc Join_def) | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 100 | |
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 101 | lemma Acts_Join [simp]: "Acts(F Join G) = Acts(F) Un Acts(G)" | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 102 | by (simp add: Int_Un_distrib2 cons_absorb Join_def) | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 103 | |
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 104 | lemma AllowedActs_Join [simp]: "AllowedActs(F Join G) = | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 105 | AllowedActs(F) Int AllowedActs(G)" | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 106 | apply (simp add: Int_assoc cons_absorb Join_def) | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 107 | done | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 108 | |
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 109 | subsection{*Join's algebraic laws*}
 | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 110 | |
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 111 | lemma Join_commute: "F Join G = G Join F" | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 112 | by (simp add: Join_def Un_commute Int_commute) | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 113 | |
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 114 | lemma Join_left_commute: "A Join (B Join C) = B Join (A Join C)" | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 115 | apply (simp add: Join_def Int_Un_distrib2 cons_absorb) | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 116 | apply (simp add: Un_ac Int_ac Int_Un_distrib2 cons_absorb) | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 117 | done | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 118 | |
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 119 | lemma Join_assoc: "(F Join G) Join H = F Join (G Join H)" | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 120 | by (simp add: Un_ac Join_def cons_absorb Int_assoc Int_Un_distrib2) | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 121 | |
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 122 | subsection{*Needed below*}
 | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 123 | lemma cons_id [simp]: "cons(id(state), Pow(state * state)) = Pow(state*state)" | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 124 | by auto | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 125 | |
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 126 | lemma Join_SKIP_left [simp]: "SKIP Join F = programify(F)" | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 127 | apply (unfold Join_def SKIP_def) | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 128 | apply (auto simp add: Int_absorb cons_eq) | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 129 | done | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 130 | |
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 131 | lemma Join_SKIP_right [simp]: "F Join SKIP = programify(F)" | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 132 | apply (subst Join_commute) | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 133 | apply (simp add: Join_SKIP_left) | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 134 | done | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 135 | |
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 136 | lemma Join_absorb [simp]: "F Join F = programify(F)" | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 137 | by (rule program_equalityI, auto) | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 138 | |
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 139 | lemma Join_left_absorb: "F Join (F Join G) = F Join G" | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 140 | by (simp add: Join_assoc [symmetric]) | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 141 | |
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 142 | subsection{*Join is an AC-operator*}
 | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 143 | lemmas Join_ac = Join_assoc Join_left_absorb Join_commute Join_left_commute | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 144 | |
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 145 | subsection{*Eliminating programify form JN and OK expressions*}
 | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 146 | |
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 147 | lemma OK_programify [iff]: "OK(I, %x. programify(F(x))) <-> OK(I, F)" | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 148 | by (simp add: OK_def) | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 149 | |
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 150 | lemma JN_programify [iff]: "JOIN(I, %x. programify(F(x))) = JOIN(I, F)" | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 151 | by (simp add: JOIN_def) | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 152 | |
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 153 | |
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 154 | subsection{*JN*}
 | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 155 | |
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 156 | lemma JN_empty [simp]: "JOIN(0, F) = SKIP" | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 157 | by (unfold JOIN_def, auto) | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 158 | |
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 159 | lemma Init_JN [simp]: | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 160 | "Init(\<Squnion>i \<in> I. F(i)) = (if I=0 then state else (\<Inter>i \<in> I. Init(F(i))))" | 
| 14095 
a1ba833d6b61
Changed many Intersection rules from i:I to I~=0 to avoid introducing a new
 paulson parents: 
14093diff
changeset | 161 | by (simp add: JOIN_def INT_extend_simps del: INT_simps) | 
| 14092 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 162 | |
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 163 | lemma Acts_JN [simp]: | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 164 | "Acts(JOIN(I,F)) = cons(id(state), \<Union>i \<in> I. Acts(F(i)))" | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 165 | apply (unfold JOIN_def) | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 166 | apply (auto simp del: INT_simps UN_simps) | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 167 | apply (rule equalityI) | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 168 | apply (auto dest: Acts_type [THEN subsetD]) | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 169 | done | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 170 | |
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 171 | lemma AllowedActs_JN [simp]: | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 172 | "AllowedActs(\<Squnion>i \<in> I. F(i)) = | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 173 | (if I=0 then Pow(state*state) else (\<Inter>i \<in> I. AllowedActs(F(i))))" | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 174 | apply (unfold JOIN_def, auto) | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 175 | apply (rule equalityI) | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 176 | apply (auto elim!: not_emptyE dest: AllowedActs_type [THEN subsetD]) | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 177 | done | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 178 | |
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 179 | lemma JN_cons [simp]: "(\<Squnion>i \<in> cons(a,I). F(i)) = F(a) Join (\<Squnion>i \<in> I. F(i))" | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 180 | by (rule program_equalityI, auto) | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 181 | |
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 182 | lemma JN_cong [cong]: | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 183 | "[| I=J; !!i. i \<in> J ==> F(i) = G(i) |] ==> | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 184 | (\<Squnion>i \<in> I. F(i)) = (\<Squnion>i \<in> J. G(i))" | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 185 | by (simp add: JOIN_def) | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 186 | |
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 187 | |
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 188 | |
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 189 | subsection{*JN laws*}
 | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 190 | lemma JN_absorb: "k \<in> I ==>F(k) Join (\<Squnion>i \<in> I. F(i)) = (\<Squnion>i \<in> I. F(i))" | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 191 | apply (subst JN_cons [symmetric]) | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 192 | apply (auto simp add: cons_absorb) | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 193 | done | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 194 | |
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 195 | lemma JN_Un: "(\<Squnion>i \<in> I Un J. F(i)) = ((\<Squnion>i \<in> I. F(i)) Join (\<Squnion>i \<in> J. F(i)))" | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 196 | apply (rule program_equalityI) | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 197 | apply (simp_all add: UN_Un INT_Un) | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 198 | apply (simp_all del: INT_simps add: INT_extend_simps, blast) | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 199 | done | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 200 | |
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 201 | lemma JN_constant: "(\<Squnion>i \<in> I. c) = (if I=0 then SKIP else programify(c))" | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 202 | by (rule program_equalityI, auto) | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 203 | |
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 204 | lemma JN_Join_distrib: | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 205 | "(\<Squnion>i \<in> I. F(i) Join G(i)) = (\<Squnion>i \<in> I. F(i)) Join (\<Squnion>i \<in> I. G(i))" | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 206 | apply (rule program_equalityI) | 
| 14095 
a1ba833d6b61
Changed many Intersection rules from i:I to I~=0 to avoid introducing a new
 paulson parents: 
14093diff
changeset | 207 | apply (simp_all add: INT_Int_distrib, blast) | 
| 14092 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 208 | done | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 209 | |
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 210 | lemma JN_Join_miniscope: "(\<Squnion>i \<in> I. F(i) Join G) = ((\<Squnion>i \<in> I. F(i) Join G))" | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 211 | by (simp add: JN_Join_distrib JN_constant) | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 212 | |
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 213 | text{*Used to prove guarantees_JN_I*}
 | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 214 | lemma JN_Join_diff: "i \<in> I==>F(i) Join JOIN(I - {i}, F) = JOIN(I, F)"
 | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 215 | apply (rule program_equalityI) | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 216 | apply (auto elim!: not_emptyE) | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 217 | done | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 218 | |
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 219 | subsection{*Safety: co, stable, FP*}
 | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 220 | |
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 221 | |
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 222 | (*Fails if I=0 because it collapses to SKIP \<in> A co B, i.e. to A\<subseteq>B. So an | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 223 | alternative precondition is A\<subseteq>B, but most proofs using this rule require | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 224 | I to be nonempty for other reasons anyway.*) | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 225 | |
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 226 | lemma JN_constrains: | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 227 | "i \<in> I==>(\<Squnion>i \<in> I. F(i)) \<in> A co B <-> (\<forall>i \<in> I. programify(F(i)) \<in> A co B)" | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 228 | |
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 229 | apply (unfold constrains_def JOIN_def st_set_def, auto) | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 230 | prefer 2 apply blast | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 231 | apply (rename_tac j act y z) | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 232 | apply (cut_tac F = "F (j) " in Acts_type) | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 233 | apply (drule_tac x = act in bspec, auto) | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 234 | done | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 235 | |
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 236 | lemma Join_constrains [iff]: | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 237 | "(F Join G \<in> A co B) <-> (programify(F) \<in> A co B & programify(G) \<in> A co B)" | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 238 | by (auto simp add: constrains_def) | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 239 | |
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 240 | lemma Join_unless [iff]: | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 241 | "(F Join G \<in> A unless B) <-> | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 242 | (programify(F) \<in> A unless B & programify(G) \<in> A unless B)" | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 243 | by (simp add: Join_constrains unless_def) | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 244 | |
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 245 | |
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 246 | (*Analogous weak versions FAIL; see Misra [1994] 5.4.1, Substitution Axiom. | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 247 | reachable (F Join G) could be much bigger than reachable F, reachable G | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 248 | *) | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 249 | |
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 250 | lemma Join_constrains_weaken: | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 251 | "[| F \<in> A co A'; G \<in> B co B' |] | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 252 | ==> F Join G \<in> (A Int B) co (A' Un B')" | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 253 | apply (subgoal_tac "st_set (A) & st_set (B) & F \<in> program & G \<in> program") | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 254 | prefer 2 apply (blast dest: constrainsD2, simp) | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 255 | apply (blast intro: constrains_weaken) | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 256 | done | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 257 | |
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 258 | (*If I=0, it degenerates to SKIP \<in> state co 0, which is false.*) | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 259 | lemma JN_constrains_weaken: | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 260 | assumes major: "(!!i. i \<in> I ==> F(i) \<in> A(i) co A'(i))" | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 261 | and minor: "i \<in> I" | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 262 | shows "(\<Squnion>i \<in> I. F(i)) \<in> (\<Inter>i \<in> I. A(i)) co (\<Union>i \<in> I. A'(i))" | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 263 | apply (cut_tac minor) | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 264 | apply (simp (no_asm_simp) add: JN_constrains) | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 265 | apply clarify | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 266 | apply (rename_tac "j") | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 267 | apply (frule_tac i = j in major) | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 268 | apply (frule constrainsD2, simp) | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 269 | apply (blast intro: constrains_weaken) | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 270 | done | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 271 | |
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 272 | lemma JN_stable: | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 273 | "(\<Squnion>i \<in> I. F(i)) \<in> stable(A) <-> ((\<forall>i \<in> I. programify(F(i)) \<in> stable(A)) & st_set(A))" | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 274 | apply (auto simp add: stable_def constrains_def JOIN_def) | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 275 | apply (cut_tac F = "F (i) " in Acts_type) | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 276 | apply (drule_tac x = act in bspec, auto) | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 277 | done | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 278 | |
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 279 | lemma initially_JN_I: | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 280 | assumes major: "(!!i. i \<in> I ==>F(i) \<in> initially(A))" | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 281 | and minor: "i \<in> I" | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 282 | shows "(\<Squnion>i \<in> I. F(i)) \<in> initially(A)" | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 283 | apply (cut_tac minor) | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 284 | apply (auto elim!: not_emptyE simp add: Inter_iff initially_def) | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 285 | apply (frule_tac i = x in major) | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 286 | apply (auto simp add: initially_def) | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 287 | done | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 288 | |
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 289 | lemma invariant_JN_I: | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 290 | assumes major: "(!!i. i \<in> I ==> F(i) \<in> invariant(A))" | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 291 | and minor: "i \<in> I" | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 292 | shows "(\<Squnion>i \<in> I. F(i)) \<in> invariant(A)" | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 293 | apply (cut_tac minor) | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 294 | apply (auto intro!: initially_JN_I dest: major simp add: invariant_def JN_stable) | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 295 | apply (erule_tac V = "i \<in> I" in thin_rl) | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 296 | apply (frule major) | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 297 | apply (drule_tac [2] major) | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 298 | apply (auto simp add: invariant_def) | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 299 | apply (frule stableD2, force)+ | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 300 | done | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 301 | |
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 302 | lemma Join_stable [iff]: | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 303 | " (F Join G \<in> stable(A)) <-> | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 304 | (programify(F) \<in> stable(A) & programify(G) \<in> stable(A))" | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 305 | by (simp add: stable_def) | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 306 | |
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 307 | lemma initially_JoinI [intro!]: | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 308 | "[| F \<in> initially(A); G \<in> initially(A) |] ==> F Join G \<in> initially(A)" | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 309 | by (unfold initially_def, auto) | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 310 | |
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 311 | lemma invariant_JoinI: | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 312 | "[| F \<in> invariant(A); G \<in> invariant(A) |] | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 313 | ==> F Join G \<in> invariant(A)" | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 314 | apply (subgoal_tac "F \<in> program&G \<in> program") | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 315 | prefer 2 apply (blast dest: invariantD2) | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 316 | apply (simp add: invariant_def) | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 317 | apply (auto intro: Join_in_program) | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 318 | done | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 319 | |
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 320 | |
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 321 | (* Fails if I=0 because \<Inter>i \<in> 0. A(i) = 0 *) | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 322 | lemma FP_JN: "i \<in> I ==> FP(\<Squnion>i \<in> I. F(i)) = (\<Inter>i \<in> I. FP (programify(F(i))))" | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 323 | by (auto simp add: FP_def Inter_def st_set_def JN_stable) | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 324 | |
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 325 | subsection{*Progress: transient, ensures*}
 | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 326 | |
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 327 | lemma JN_transient: | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 328 | "i \<in> I ==> | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 329 | (\<Squnion>i \<in> I. F(i)) \<in> transient(A) <-> (\<exists>i \<in> I. programify(F(i)) \<in> transient(A))" | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 330 | apply (auto simp add: transient_def JOIN_def) | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 331 | apply (unfold st_set_def) | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 332 | apply (drule_tac [2] x = act in bspec) | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 333 | apply (auto dest: Acts_type [THEN subsetD]) | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 334 | done | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 335 | |
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 336 | lemma Join_transient [iff]: | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 337 | "F Join G \<in> transient(A) <-> | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 338 | (programify(F) \<in> transient(A) | programify(G) \<in> transient(A))" | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 339 | apply (auto simp add: transient_def Join_def Int_Un_distrib2) | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 340 | done | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 341 | |
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 342 | lemma Join_transient_I1: "F \<in> transient(A) ==> F Join G \<in> transient(A)" | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 343 | by (simp add: Join_transient transientD2) | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 344 | |
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 345 | |
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 346 | lemma Join_transient_I2: "G \<in> transient(A) ==> F Join G \<in> transient(A)" | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 347 | by (simp add: Join_transient transientD2) | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 348 | |
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 349 | (*If I=0 it degenerates to (SKIP \<in> A ensures B) = False, i.e. to ~(A\<subseteq>B) *) | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 350 | lemma JN_ensures: | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 351 | "i \<in> I ==> | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 352 | (\<Squnion>i \<in> I. F(i)) \<in> A ensures B <-> | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 353 | ((\<forall>i \<in> I. programify(F(i)) \<in> (A-B) co (A Un B)) & | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 354 | (\<exists>i \<in> I. programify(F(i)) \<in> A ensures B))" | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 355 | by (auto simp add: ensures_def JN_constrains JN_transient) | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 356 | |
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 357 | |
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 358 | lemma Join_ensures: | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 359 | "F Join G \<in> A ensures B <-> | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 360 | (programify(F) \<in> (A-B) co (A Un B) & programify(G) \<in> (A-B) co (A Un B) & | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 361 | (programify(F) \<in> transient (A-B) | programify(G) \<in> transient (A-B)))" | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 362 | |
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 363 | apply (unfold ensures_def) | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 364 | apply (auto simp add: Join_transient) | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 365 | done | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 366 | |
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 367 | lemma stable_Join_constrains: | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 368 | "[| F \<in> stable(A); G \<in> A co A' |] | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 369 | ==> F Join G \<in> A co A'" | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 370 | apply (unfold stable_def constrains_def Join_def st_set_def) | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 371 | apply (cut_tac F = F in Acts_type) | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 372 | apply (cut_tac F = G in Acts_type, force) | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 373 | done | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 374 | |
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 375 | (*Premise for G cannot use Always because F \<in> Stable A is | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 376 | weaker than G \<in> stable A *) | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 377 | lemma stable_Join_Always1: | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 378 | "[| F \<in> stable(A); G \<in> invariant(A) |] ==> F Join G \<in> Always(A)" | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 379 | apply (subgoal_tac "F \<in> program & G \<in> program & st_set (A) ") | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 380 | prefer 2 apply (blast dest: invariantD2 stableD2) | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 381 | apply (simp add: Always_def invariant_def initially_def Stable_eq_stable) | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 382 | apply (force intro: stable_Int) | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 383 | done | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 384 | |
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 385 | (*As above, but exchanging the roles of F and G*) | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 386 | lemma stable_Join_Always2: | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 387 | "[| F \<in> invariant(A); G \<in> stable(A) |] ==> F Join G \<in> Always(A)" | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 388 | apply (subst Join_commute) | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 389 | apply (blast intro: stable_Join_Always1) | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 390 | done | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 391 | |
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 392 | |
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 393 | |
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 394 | lemma stable_Join_ensures1: | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 395 | "[| F \<in> stable(A); G \<in> A ensures B |] ==> F Join G \<in> A ensures B" | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 396 | apply (subgoal_tac "F \<in> program & G \<in> program & st_set (A) ") | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 397 | prefer 2 apply (blast dest: stableD2 ensures_type [THEN subsetD]) | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 398 | apply (simp (no_asm_simp) add: Join_ensures) | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 399 | apply (simp add: stable_def ensures_def) | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 400 | apply (erule constrains_weaken, auto) | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 401 | done | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 402 | |
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 403 | |
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 404 | (*As above, but exchanging the roles of F and G*) | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 405 | lemma stable_Join_ensures2: | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 406 | "[| F \<in> A ensures B; G \<in> stable(A) |] ==> F Join G \<in> A ensures B" | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 407 | apply (subst Join_commute) | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 408 | apply (blast intro: stable_Join_ensures1) | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 409 | done | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 410 | |
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 411 | subsection{*The ok and OK relations*}
 | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 412 | |
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 413 | lemma ok_SKIP1 [iff]: "SKIP ok F" | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 414 | by (auto dest: Acts_type [THEN subsetD] simp add: ok_def) | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 415 | |
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 416 | lemma ok_SKIP2 [iff]: "F ok SKIP" | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 417 | by (auto dest: Acts_type [THEN subsetD] simp add: ok_def) | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 418 | |
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 419 | lemma ok_Join_commute: | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 420 | "(F ok G & (F Join G) ok H) <-> (G ok H & F ok (G Join H))" | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 421 | by (auto simp add: ok_def) | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 422 | |
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 423 | lemma ok_commute: "(F ok G) <->(G ok F)" | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 424 | by (auto simp add: ok_def) | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 425 | |
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 426 | lemmas ok_sym = ok_commute [THEN iffD1, standard] | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 427 | |
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 428 | lemma ok_iff_OK: "OK({<0,F>,<1,G>,<2,H>}, snd) <-> (F ok G & (F Join G) ok H)"
 | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 429 | by (simp add: ok_def Join_def OK_def Int_assoc cons_absorb | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 430 | Int_Un_distrib2 Ball_def, safe, force+) | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 431 | |
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 432 | lemma ok_Join_iff1 [iff]: "F ok (G Join H) <-> (F ok G & F ok H)" | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 433 | by (auto simp add: ok_def) | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 434 | |
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 435 | lemma ok_Join_iff2 [iff]: "(G Join H) ok F <-> (G ok F & H ok F)" | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 436 | by (auto simp add: ok_def) | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 437 | |
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 438 | (*useful? Not with the previous two around*) | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 439 | lemma ok_Join_commute_I: "[| F ok G; (F Join G) ok H |] ==> F ok (G Join H)" | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 440 | by (auto simp add: ok_def) | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 441 | |
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 442 | lemma ok_JN_iff1 [iff]: "F ok JOIN(I,G) <-> (\<forall>i \<in> I. F ok G(i))" | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 443 | by (force dest: Acts_type [THEN subsetD] elim!: not_emptyE simp add: ok_def) | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 444 | |
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 445 | lemma ok_JN_iff2 [iff]: "JOIN(I,G) ok F <-> (\<forall>i \<in> I. G(i) ok F)" | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 446 | apply (auto elim!: not_emptyE simp add: ok_def) | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 447 | apply (blast dest: Acts_type [THEN subsetD]) | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 448 | done | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 449 | |
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 450 | lemma OK_iff_ok: "OK(I,F) <-> (\<forall>i \<in> I. \<forall>j \<in> I-{i}. F(i) ok (F(j)))"
 | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 451 | by (auto simp add: ok_def OK_def) | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 452 | |
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 453 | lemma OK_imp_ok: "[| OK(I,F); i \<in> I; j \<in> I; i\<noteq>j|] ==> F(i) ok F(j)" | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 454 | by (auto simp add: OK_iff_ok) | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 455 | |
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 456 | |
| 14093 
24382760fd89
converting more theories to Isar scripts, and tidying
 paulson parents: 
14092diff
changeset | 457 | lemma OK_0 [iff]: "OK(0,F)" | 
| 
24382760fd89
converting more theories to Isar scripts, and tidying
 paulson parents: 
14092diff
changeset | 458 | by (simp add: OK_def) | 
| 
24382760fd89
converting more theories to Isar scripts, and tidying
 paulson parents: 
14092diff
changeset | 459 | |
| 
24382760fd89
converting more theories to Isar scripts, and tidying
 paulson parents: 
14092diff
changeset | 460 | lemma OK_cons_iff: | 
| 
24382760fd89
converting more theories to Isar scripts, and tidying
 paulson parents: 
14092diff
changeset | 461 | "OK(cons(i, I), F) <-> | 
| 
24382760fd89
converting more theories to Isar scripts, and tidying
 paulson parents: 
14092diff
changeset | 462 | (i \<in> I & OK(I, F)) | (i\<notin>I & OK(I, F) & F(i) ok JOIN(I,F))" | 
| 
24382760fd89
converting more theories to Isar scripts, and tidying
 paulson parents: 
14092diff
changeset | 463 | apply (simp add: OK_iff_ok) | 
| 
24382760fd89
converting more theories to Isar scripts, and tidying
 paulson parents: 
14092diff
changeset | 464 | apply (blast intro: ok_sym) | 
| 
24382760fd89
converting more theories to Isar scripts, and tidying
 paulson parents: 
14092diff
changeset | 465 | done | 
| 
24382760fd89
converting more theories to Isar scripts, and tidying
 paulson parents: 
14092diff
changeset | 466 | |
| 
24382760fd89
converting more theories to Isar scripts, and tidying
 paulson parents: 
14092diff
changeset | 467 | |
| 14092 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 468 | subsection{*Allowed*}
 | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 469 | |
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 470 | lemma Allowed_SKIP [simp]: "Allowed(SKIP) = program" | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 471 | by (auto dest: Acts_type [THEN subsetD] simp add: Allowed_def) | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 472 | |
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 473 | lemma Allowed_Join [simp]: | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 474 | "Allowed(F Join G) = | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 475 | Allowed(programify(F)) Int Allowed(programify(G))" | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 476 | apply (auto simp add: Allowed_def) | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 477 | done | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 478 | |
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 479 | lemma Allowed_JN [simp]: | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 480 | "i \<in> I ==> | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 481 | Allowed(JOIN(I,F)) = (\<Inter>i \<in> I. Allowed(programify(F(i))))" | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 482 | apply (auto simp add: Allowed_def, blast) | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 483 | done | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 484 | |
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 485 | lemma ok_iff_Allowed: | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 486 | "F ok G <-> (programify(F) \<in> Allowed(programify(G)) & | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 487 | programify(G) \<in> Allowed(programify(F)))" | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 488 | by (simp add: ok_def Allowed_def) | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 489 | |
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 490 | |
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 491 | lemma OK_iff_Allowed: | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 492 | "OK(I,F) <-> | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 493 |   (\<forall>i \<in> I. \<forall>j \<in> I-{i}. programify(F(i)) \<in> Allowed(programify(F(j))))"
 | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 494 | apply (auto simp add: OK_iff_ok ok_iff_Allowed) | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 495 | done | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 496 | |
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 497 | subsection{*safety_prop, for reasoning about given instances of "ok"*}
 | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 498 | |
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 499 | lemma safety_prop_Acts_iff: | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 500 | "safety_prop(X) ==> (Acts(G) \<subseteq> cons(id(state), (\<Union>F \<in> X. Acts(F)))) <-> (programify(G) \<in> X)" | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 501 | apply (simp (no_asm_use) add: safety_prop_def) | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 502 | apply clarify | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 503 | apply (case_tac "G \<in> program", simp_all, blast, safe) | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 504 | prefer 2 apply force | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 505 | apply (force simp add: programify_def) | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 506 | done | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 507 | |
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 508 | lemma safety_prop_AllowedActs_iff_Allowed: | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 509 | "safety_prop(X) ==> | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 510 | (\<Union>G \<in> X. Acts(G)) \<subseteq> AllowedActs(F) <-> (X \<subseteq> Allowed(programify(F)))" | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 511 | apply (simp add: Allowed_def safety_prop_Acts_iff [THEN iff_sym] | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 512 | safety_prop_def, blast) | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 513 | done | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 514 | |
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 515 | |
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 516 | lemma Allowed_eq: | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 517 | "safety_prop(X) ==> Allowed(mk_program(init, acts, \<Union>F \<in> X. Acts(F))) = X" | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 518 | apply (subgoal_tac "cons (id (state), Union (RepFun (X, Acts)) Int Pow (state * state)) = Union (RepFun (X, Acts))") | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 519 | apply (rule_tac [2] equalityI) | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 520 | apply (simp del: UN_simps add: Allowed_def safety_prop_Acts_iff safety_prop_def, auto) | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 521 | apply (force dest: Acts_type [THEN subsetD] simp add: safety_prop_def)+ | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 522 | done | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 523 | |
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 524 | lemma def_prg_Allowed: | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 525 | "[| F == mk_program (init, acts, \<Union>F \<in> X. Acts(F)); safety_prop(X) |] | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 526 | ==> Allowed(F) = X" | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 527 | by (simp add: Allowed_eq) | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 528 | |
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 529 | (*For safety_prop to hold, the property must be satisfiable!*) | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 530 | lemma safety_prop_constrains [iff]: | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 531 | "safety_prop(A co B) <-> (A \<subseteq> B & st_set(A))" | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 532 | by (simp add: safety_prop_def constrains_def st_set_def, blast) | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 533 | |
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 534 | (* To be used with resolution *) | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 535 | lemma safety_prop_constrainsI [iff]: | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 536 | "[| A\<subseteq>B; st_set(A) |] ==>safety_prop(A co B)" | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 537 | by auto | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 538 | |
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 539 | lemma safety_prop_stable [iff]: "safety_prop(stable(A)) <-> st_set(A)" | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 540 | by (simp add: stable_def) | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 541 | |
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 542 | lemma safety_prop_stableI: "st_set(A) ==> safety_prop(stable(A))" | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 543 | by auto | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 544 | |
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 545 | lemma safety_prop_Int [simp]: | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 546 | "[| safety_prop(X) ; safety_prop(Y) |] ==> safety_prop(X Int Y)" | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 547 | apply (simp add: safety_prop_def, safe, blast) | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 548 | apply (drule_tac [2] B = "Union (RepFun (X Int Y, Acts))" and C = "Union (RepFun (Y, Acts))" in subset_trans) | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 549 | apply (drule_tac B = "Union (RepFun (X Int Y, Acts))" and C = "Union (RepFun (X, Acts))" in subset_trans) | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 550 | apply blast+ | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 551 | done | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 552 | |
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 553 | (* If I=0 the conclusion becomes safety_prop(0) which is false *) | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 554 | lemma safety_prop_Inter: | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 555 | assumes major: "(!!i. i \<in> I ==>safety_prop(X(i)))" | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 556 | and minor: "i \<in> I" | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 557 | shows "safety_prop(\<Inter>i \<in> I. X(i))" | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 558 | apply (simp add: safety_prop_def) | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 559 | apply (cut_tac minor, safe) | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 560 | apply (simp (no_asm_use) add: Inter_iff) | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 561 | apply clarify | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 562 | apply (frule major) | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 563 | apply (drule_tac [2] i = xa in major) | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 564 | apply (frule_tac [4] i = xa in major) | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 565 | apply (auto simp add: safety_prop_def) | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 566 | apply (drule_tac B = "Union (RepFun (Inter (RepFun (I, X)), Acts))" and C = "Union (RepFun (X (xa), Acts))" in subset_trans) | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 567 | apply blast+ | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 568 | done | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 569 | |
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 570 | lemma def_UNION_ok_iff: | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 571 | "[| F == mk_program(init,acts, \<Union>G \<in> X. Acts(G)); safety_prop(X) |] | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 572 | ==> F ok G <-> (programify(G) \<in> X & acts Int Pow(state*state) \<subseteq> AllowedActs(G))" | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 573 | apply (unfold ok_def) | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 574 | apply (drule_tac G = G in safety_prop_Acts_iff) | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 575 | apply (cut_tac F = G in AllowedActs_type) | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 576 | apply (cut_tac F = G in Acts_type, auto) | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 577 | done | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 578 | |
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 579 | |
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 580 | ML | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 581 | {*
 | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 582 | val safety_prop_def = thm "safety_prop_def"; | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 583 | |
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 584 | val reachable_SKIP = thm "reachable_SKIP"; | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 585 | val ok_programify_left = thm "ok_programify_left"; | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 586 | val ok_programify_right = thm "ok_programify_right"; | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 587 | val Join_programify_left = thm "Join_programify_left"; | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 588 | val Join_programify_right = thm "Join_programify_right"; | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 589 | val SKIP_in_constrains_iff = thm "SKIP_in_constrains_iff"; | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 590 | val SKIP_in_Constrains_iff = thm "SKIP_in_Constrains_iff"; | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 591 | val SKIP_in_stable = thm "SKIP_in_stable"; | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 592 | val SKIP_in_Stable = thm "SKIP_in_Stable"; | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 593 | val Join_in_program = thm "Join_in_program"; | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 594 | val JOIN_in_program = thm "JOIN_in_program"; | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 595 | val Init_Join = thm "Init_Join"; | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 596 | val Acts_Join = thm "Acts_Join"; | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 597 | val AllowedActs_Join = thm "AllowedActs_Join"; | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 598 | val Join_commute = thm "Join_commute"; | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 599 | val Join_left_commute = thm "Join_left_commute"; | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 600 | val Join_assoc = thm "Join_assoc"; | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 601 | val cons_id = thm "cons_id"; | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 602 | val Join_SKIP_left = thm "Join_SKIP_left"; | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 603 | val Join_SKIP_right = thm "Join_SKIP_right"; | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 604 | val Join_absorb = thm "Join_absorb"; | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 605 | val Join_left_absorb = thm "Join_left_absorb"; | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 606 | val OK_programify = thm "OK_programify"; | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 607 | val JN_programify = thm "JN_programify"; | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 608 | val JN_empty = thm "JN_empty"; | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 609 | val Init_JN = thm "Init_JN"; | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 610 | val Acts_JN = thm "Acts_JN"; | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 611 | val AllowedActs_JN = thm "AllowedActs_JN"; | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 612 | val JN_cons = thm "JN_cons"; | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 613 | val JN_cong = thm "JN_cong"; | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 614 | val JN_absorb = thm "JN_absorb"; | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 615 | val JN_Un = thm "JN_Un"; | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 616 | val JN_constant = thm "JN_constant"; | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 617 | val JN_Join_distrib = thm "JN_Join_distrib"; | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 618 | val JN_Join_miniscope = thm "JN_Join_miniscope"; | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 619 | val JN_Join_diff = thm "JN_Join_diff"; | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 620 | val JN_constrains = thm "JN_constrains"; | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 621 | val Join_constrains = thm "Join_constrains"; | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 622 | val Join_unless = thm "Join_unless"; | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 623 | val Join_constrains_weaken = thm "Join_constrains_weaken"; | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 624 | val JN_constrains_weaken = thm "JN_constrains_weaken"; | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 625 | val JN_stable = thm "JN_stable"; | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 626 | val initially_JN_I = thm "initially_JN_I"; | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 627 | val invariant_JN_I = thm "invariant_JN_I"; | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 628 | val Join_stable = thm "Join_stable"; | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 629 | val initially_JoinI = thm "initially_JoinI"; | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 630 | val invariant_JoinI = thm "invariant_JoinI"; | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 631 | val FP_JN = thm "FP_JN"; | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 632 | val JN_transient = thm "JN_transient"; | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 633 | val Join_transient = thm "Join_transient"; | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 634 | val Join_transient_I1 = thm "Join_transient_I1"; | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 635 | val Join_transient_I2 = thm "Join_transient_I2"; | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 636 | val JN_ensures = thm "JN_ensures"; | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 637 | val Join_ensures = thm "Join_ensures"; | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 638 | val stable_Join_constrains = thm "stable_Join_constrains"; | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 639 | val stable_Join_Always1 = thm "stable_Join_Always1"; | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 640 | val stable_Join_Always2 = thm "stable_Join_Always2"; | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 641 | val stable_Join_ensures1 = thm "stable_Join_ensures1"; | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 642 | val stable_Join_ensures2 = thm "stable_Join_ensures2"; | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 643 | val ok_SKIP1 = thm "ok_SKIP1"; | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 644 | val ok_SKIP2 = thm "ok_SKIP2"; | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 645 | val ok_Join_commute = thm "ok_Join_commute"; | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 646 | val ok_commute = thm "ok_commute"; | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 647 | val ok_sym = thm "ok_sym"; | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 648 | val ok_iff_OK = thm "ok_iff_OK"; | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 649 | val ok_Join_iff1 = thm "ok_Join_iff1"; | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 650 | val ok_Join_iff2 = thm "ok_Join_iff2"; | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 651 | val ok_Join_commute_I = thm "ok_Join_commute_I"; | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 652 | val ok_JN_iff1 = thm "ok_JN_iff1"; | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 653 | val ok_JN_iff2 = thm "ok_JN_iff2"; | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 654 | val OK_iff_ok = thm "OK_iff_ok"; | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 655 | val OK_imp_ok = thm "OK_imp_ok"; | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 656 | val Allowed_SKIP = thm "Allowed_SKIP"; | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 657 | val Allowed_Join = thm "Allowed_Join"; | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 658 | val Allowed_JN = thm "Allowed_JN"; | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 659 | val ok_iff_Allowed = thm "ok_iff_Allowed"; | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 660 | val OK_iff_Allowed = thm "OK_iff_Allowed"; | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 661 | val safety_prop_Acts_iff = thm "safety_prop_Acts_iff"; | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 662 | val safety_prop_AllowedActs_iff_Allowed = thm "safety_prop_AllowedActs_iff_Allowed"; | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 663 | val Allowed_eq = thm "Allowed_eq"; | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 664 | val def_prg_Allowed = thm "def_prg_Allowed"; | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 665 | val safety_prop_constrains = thm "safety_prop_constrains"; | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 666 | val safety_prop_constrainsI = thm "safety_prop_constrainsI"; | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 667 | val safety_prop_stable = thm "safety_prop_stable"; | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 668 | val safety_prop_stableI = thm "safety_prop_stableI"; | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 669 | val safety_prop_Int = thm "safety_prop_Int"; | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 670 | val safety_prop_Inter = thm "safety_prop_Inter"; | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 671 | val def_UNION_ok_iff = thm "def_UNION_ok_iff"; | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 672 | |
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 673 | val Join_ac = thms "Join_ac"; | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 674 | *} | 
| 
68da54626309
Conversion of ZF/UNITY/{FP,Union} to Isar script.
 paulson parents: 
12195diff
changeset | 675 | |
| 11479 | 676 | |
| 677 | end |