src/HOL/IOA/ABP/Check.ML
author nipkow
Tue, 18 Mar 1997 08:42:18 +0100
changeset 2800 9741c4c6b62b
parent 1465 5d7a7e439cec
permissions -rw-r--r--
Added P&P&Q = P&Q and P|P|Q = P|Q.
Ignore whitespace changes - Everywhere: Within whitespace: At end of lines:
1050
0c36c6a52a1d ABP: Alternating bit protocol example
nipkow
parents:
diff changeset
     1
0c36c6a52a1d ABP: Alternating bit protocol example
nipkow
parents:
diff changeset
     2
1138
mueller
parents: 1050
diff changeset
     3
 
mueller
parents: 1050
diff changeset
     4
(* ----------------------------------------------------------------
mueller
parents: 1050
diff changeset
     5
       P r o t o t y p e   M o d e l   C h e c k e r 
mueller
parents: 1050
diff changeset
     6
   ----------------------------------------------------------------*)
1050
0c36c6a52a1d ABP: Alternating bit protocol example
nipkow
parents:
diff changeset
     7
0c36c6a52a1d ABP: Alternating bit protocol example
nipkow
parents:
diff changeset
     8
fun check(extacts,intacts,string_of_a,startsI,string_of_s,
0c36c6a52a1d ABP: Alternating bit protocol example
nipkow
parents:
diff changeset
     9
          nexts,hom,transA,startsS) =
0c36c6a52a1d ABP: Alternating bit protocol example
nipkow
parents:
diff changeset
    10
  let fun check_s(s,unchecked,checked) =
0c36c6a52a1d ABP: Alternating bit protocol example
nipkow
parents:
diff changeset
    11
        let fun check_sa(unchecked,a) =
0c36c6a52a1d ABP: Alternating bit protocol example
nipkow
parents:
diff changeset
    12
              let fun check_sas(unchecked,t) =
0c36c6a52a1d ABP: Alternating bit protocol example
nipkow
parents:
diff changeset
    13
                    (if a mem extacts then
1138
mueller
parents: 1050
diff changeset
    14
                          (if transA(hom s,a,hom t) then ( )
1050
0c36c6a52a1d ABP: Alternating bit protocol example
nipkow
parents:
diff changeset
    15
                           else (writeln("Error: Mapping of Externals!");
0c36c6a52a1d ABP: Alternating bit protocol example
nipkow
parents:
diff changeset
    16
                                 string_of_s s; writeln"";
0c36c6a52a1d ABP: Alternating bit protocol example
nipkow
parents:
diff changeset
    17
                                 string_of_a a; writeln"";
1138
mueller
parents: 1050
diff changeset
    18
                                 string_of_s t;writeln"";writeln"" ))
mueller
parents: 1050
diff changeset
    19
                     else (if hom(s)=hom(t) then ( )
1050
0c36c6a52a1d ABP: Alternating bit protocol example
nipkow
parents:
diff changeset
    20
                           else (writeln("Error: Mapping of Internals!");
1138
mueller
parents: 1050
diff changeset
    21
                                 string_of_s s; writeln"";
mueller
parents: 1050
diff changeset
    22
                                 string_of_a a; writeln"";
mueller
parents: 1050
diff changeset
    23
                                 string_of_s t;writeln"";writeln"" ));
1050
0c36c6a52a1d ABP: Alternating bit protocol example
nipkow
parents:
diff changeset
    24
                     if t mem checked then unchecked else t ins unchecked)
0c36c6a52a1d ABP: Alternating bit protocol example
nipkow
parents:
diff changeset
    25
              in foldl check_sas (unchecked,nexts s a) end;
0c36c6a52a1d ABP: Alternating bit protocol example
nipkow
parents:
diff changeset
    26
              val unchecked' = foldl check_sa (unchecked,extacts @ intacts)
0c36c6a52a1d ABP: Alternating bit protocol example
nipkow
parents:
diff changeset
    27
        in    (if s mem startsI then 
0c36c6a52a1d ABP: Alternating bit protocol example
nipkow
parents:
diff changeset
    28
                    (if hom(s) mem startsS then ()
0c36c6a52a1d ABP: Alternating bit protocol example
nipkow
parents:
diff changeset
    29
                     else writeln("Error: At start states!"))
0c36c6a52a1d ABP: Alternating bit protocol example
nipkow
parents:
diff changeset
    30
               else ();  
0c36c6a52a1d ABP: Alternating bit protocol example
nipkow
parents:
diff changeset
    31
               checks(unchecked',s::checked)) end
0c36c6a52a1d ABP: Alternating bit protocol example
nipkow
parents:
diff changeset
    32
      and checks([],_) = ()
0c36c6a52a1d ABP: Alternating bit protocol example
nipkow
parents:
diff changeset
    33
        | checks(s::unchecked,checked) = check_s(s,unchecked,checked)
0c36c6a52a1d ABP: Alternating bit protocol example
nipkow
parents:
diff changeset
    34
  in checks(startsI,[]) end;
0c36c6a52a1d ABP: Alternating bit protocol example
nipkow
parents:
diff changeset
    35
0c36c6a52a1d ABP: Alternating bit protocol example
nipkow
parents:
diff changeset
    36
1138
mueller
parents: 1050
diff changeset
    37
(* ------------------------------------------------------
mueller
parents: 1050
diff changeset
    38
                 A B P     E x a m p l e
mueller
parents: 1050
diff changeset
    39
   -------------------------------------------------------*)
1050
0c36c6a52a1d ABP: Alternating bit protocol example
nipkow
parents:
diff changeset
    40
1138
mueller
parents: 1050
diff changeset
    41
datatype msg = m | n | l;
1050
0c36c6a52a1d ABP: Alternating bit protocol example
nipkow
parents:
diff changeset
    42
datatype act = Next | S_msg of msg | R_msg of msg
0c36c6a52a1d ABP: Alternating bit protocol example
nipkow
parents:
diff changeset
    43
                    | S_pkt of bool * msg | R_pkt of bool * msg
0c36c6a52a1d ABP: Alternating bit protocol example
nipkow
parents:
diff changeset
    44
                    | S_ack of bool | R_ack of bool;
0c36c6a52a1d ABP: Alternating bit protocol example
nipkow
parents:
diff changeset
    45
1138
mueller
parents: 1050
diff changeset
    46
(* -------------------- Transition relation of Specification -----------*)
mueller
parents: 1050
diff changeset
    47
1050
0c36c6a52a1d ABP: Alternating bit protocol example
nipkow
parents:
diff changeset
    48
fun transA((u,s),a,(v,t)) = 
0c36c6a52a1d ABP: Alternating bit protocol example
nipkow
parents:
diff changeset
    49
    (case a of 
0c36c6a52a1d ABP: Alternating bit protocol example
nipkow
parents:
diff changeset
    50
       Next       => v andalso t = s |                         
1138
mueller
parents: 1050
diff changeset
    51
       S_msg(q)   => u andalso not(v) andalso t = s@[q]   |    
mueller
parents: 1050
diff changeset
    52
       R_msg(q)   => u = v andalso s = (q::t)  |                    
mueller
parents: 1050
diff changeset
    53
       S_pkt(b,q) => false |                    
mueller
parents: 1050
diff changeset
    54
       R_pkt(b,q) => false |                    
1050
0c36c6a52a1d ABP: Alternating bit protocol example
nipkow
parents:
diff changeset
    55
       S_ack(b)   => false |                      
0c36c6a52a1d ABP: Alternating bit protocol example
nipkow
parents:
diff changeset
    56
       R_ack(b)   => false);
0c36c6a52a1d ABP: Alternating bit protocol example
nipkow
parents:
diff changeset
    57
1138
mueller
parents: 1050
diff changeset
    58
mueller
parents: 1050
diff changeset
    59
(* ---------------------- Abstraction function --------------------------*)
mueller
parents: 1050
diff changeset
    60
1050
0c36c6a52a1d ABP: Alternating bit protocol example
nipkow
parents:
diff changeset
    61
fun hom((env,p,a,q,b,_,_)) = (env,q@(if (a=b) then tl(p) else p));
0c36c6a52a1d ABP: Alternating bit protocol example
nipkow
parents:
diff changeset
    62
1138
mueller
parents: 1050
diff changeset
    63
mueller
parents: 1050
diff changeset
    64
(* --------------------- Transition relation of Implementation ----------*)
mueller
parents: 1050
diff changeset
    65
1050
0c36c6a52a1d ABP: Alternating bit protocol example
nipkow
parents:
diff changeset
    66
fun nexts (s as (env,p,a,q,b,ch1,ch2)) action =
0c36c6a52a1d ABP: Alternating bit protocol example
nipkow
parents:
diff changeset
    67
    (case action of
0c36c6a52a1d ABP: Alternating bit protocol example
nipkow
parents:
diff changeset
    68
       Next       => if p=[] then [(true,p,a,q,b,ch1,ch2)] else [] |                         
1138
mueller
parents: 1050
diff changeset
    69
       S_msg(mornorl)   => if env then [(false,p@[mornorl],a,q,b,ch1,ch2)] else [] |     
mueller
parents: 1050
diff changeset
    70
       R_msg(mornorl)   => if (q<>[] andalso mornorl=hd(q)) 
1050
0c36c6a52a1d ABP: Alternating bit protocol example
nipkow
parents:
diff changeset
    71
                        then [(env,p,a,tl(q),b,ch1,ch2)]
0c36c6a52a1d ABP: Alternating bit protocol example
nipkow
parents:
diff changeset
    72
                        else [] |                    
1138
mueller
parents: 1050
diff changeset
    73
       S_pkt(h,mornorl) => if (p<>[] andalso mornorl=hd(p) andalso h=a)
mueller
parents: 1050
diff changeset
    74
                        then (if (ch1<>[] andalso hd(rev(ch1))=(h,mornorl))
1050
0c36c6a52a1d ABP: Alternating bit protocol example
nipkow
parents:
diff changeset
    75
                              then [s]
1138
mueller
parents: 1050
diff changeset
    76
                              else [s,(env,p,a,q,b,ch1@[(h,mornorl)],ch2)])
1050
0c36c6a52a1d ABP: Alternating bit protocol example
nipkow
parents:
diff changeset
    77
                        else [] |
1138
mueller
parents: 1050
diff changeset
    78
       R_pkt(h,mornorl) => if (ch1<>[] andalso hd(ch1)=(h,mornorl))
1050
0c36c6a52a1d ABP: Alternating bit protocol example
nipkow
parents:
diff changeset
    79
                         then (if (h<>b andalso q=[])
1138
mueller
parents: 1050
diff changeset
    80
                               then [(env,p,a,q@[mornorl],not(b),ch1,ch2),
mueller
parents: 1050
diff changeset
    81
                                     (env,p,a,q@[mornorl],not(b),tl(ch1),ch2)]
1050
0c36c6a52a1d ABP: Alternating bit protocol example
nipkow
parents:
diff changeset
    82
                               else [s,(env,p,a,q,b,tl(ch1),ch2)])
0c36c6a52a1d ABP: Alternating bit protocol example
nipkow
parents:
diff changeset
    83
                          else [] | 
0c36c6a52a1d ABP: Alternating bit protocol example
nipkow
parents:
diff changeset
    84
       S_ack(h)   => if (h=b)
0c36c6a52a1d ABP: Alternating bit protocol example
nipkow
parents:
diff changeset
    85
                        then (if (ch2<>[] andalso h=hd(rev(ch2))) 
0c36c6a52a1d ABP: Alternating bit protocol example
nipkow
parents:
diff changeset
    86
                              then [s]
0c36c6a52a1d ABP: Alternating bit protocol example
nipkow
parents:
diff changeset
    87
                              else [s,(env,p,a,q,b,ch1,ch2@[h])])
0c36c6a52a1d ABP: Alternating bit protocol example
nipkow
parents:
diff changeset
    88
                        else []  |                      
0c36c6a52a1d ABP: Alternating bit protocol example
nipkow
parents:
diff changeset
    89
       R_ack(h)   => if (ch2<>[] andalso hd(ch2)=h)
0c36c6a52a1d ABP: Alternating bit protocol example
nipkow
parents:
diff changeset
    90
                        then (if h=a
0c36c6a52a1d ABP: Alternating bit protocol example
nipkow
parents:
diff changeset
    91
                              then [(env,tl(p),not(a),q,b,ch1,ch2),
0c36c6a52a1d ABP: Alternating bit protocol example
nipkow
parents:
diff changeset
    92
                                    (env,tl(p),not(a),q,b,ch1,tl(ch2))]
0c36c6a52a1d ABP: Alternating bit protocol example
nipkow
parents:
diff changeset
    93
                              else [s,(env,p,a,q,b,ch1,tl(ch2))]) 
0c36c6a52a1d ABP: Alternating bit protocol example
nipkow
parents:
diff changeset
    94
                         else [])
0c36c6a52a1d ABP: Alternating bit protocol example
nipkow
parents:
diff changeset
    95
0c36c6a52a1d ABP: Alternating bit protocol example
nipkow
parents:
diff changeset
    96
1138
mueller
parents: 1050
diff changeset
    97
val extactions = [Next,S_msg(m),R_msg(m),S_msg(n),R_msg(n),S_msg(l),R_msg(l)];
1050
0c36c6a52a1d ABP: Alternating bit protocol example
nipkow
parents:
diff changeset
    98
val intactions = [S_pkt(true,m),R_pkt(true,m),S_ack(true),R_ack(true),
1138
mueller
parents: 1050
diff changeset
    99
                  S_pkt(false,m),R_pkt(false,m),S_ack(false),R_ack(false),
mueller
parents: 1050
diff changeset
   100
                  S_pkt(true,n),R_pkt(true,n),S_pkt(true,l),R_pkt(true,l),
mueller
parents: 1050
diff changeset
   101
               S_pkt(false,n),R_pkt(false,n),S_pkt(false,l),R_pkt(false,l)];
mueller
parents: 1050
diff changeset
   102
1050
0c36c6a52a1d ABP: Alternating bit protocol example
nipkow
parents:
diff changeset
   103
1138
mueller
parents: 1050
diff changeset
   104
(* ------------------------------------
mueller
parents: 1050
diff changeset
   105
           Input / Output utilities 
mueller
parents: 1050
diff changeset
   106
   ------------------------------------*)
1050
0c36c6a52a1d ABP: Alternating bit protocol example
nipkow
parents:
diff changeset
   107
1138
mueller
parents: 1050
diff changeset
   108
fun print_list (lpar, rpar, pre: 'a -> unit) (lll : 'a list) =
1050
0c36c6a52a1d ABP: Alternating bit protocol example
nipkow
parents:
diff changeset
   109
  let fun prec x = (prs ","; pre x)
0c36c6a52a1d ABP: Alternating bit protocol example
nipkow
parents:
diff changeset
   110
  in
1138
mueller
parents: 1050
diff changeset
   111
    (case lll of
1050
0c36c6a52a1d ABP: Alternating bit protocol example
nipkow
parents:
diff changeset
   112
      [] => (prs lpar; prs rpar)
1138
mueller
parents: 1050
diff changeset
   113
    | x::lll => (prs lpar; pre x; seq prec lll; prs rpar))
1050
0c36c6a52a1d ABP: Alternating bit protocol example
nipkow
parents:
diff changeset
   114
   end;
0c36c6a52a1d ABP: Alternating bit protocol example
nipkow
parents:
diff changeset
   115
0c36c6a52a1d ABP: Alternating bit protocol example
nipkow
parents:
diff changeset
   116
fun pr_bool true = output(std_out,"true")
0c36c6a52a1d ABP: Alternating bit protocol example
nipkow
parents:
diff changeset
   117
|   pr_bool false = output(std_out,"false");
0c36c6a52a1d ABP: Alternating bit protocol example
nipkow
parents:
diff changeset
   118
1138
mueller
parents: 1050
diff changeset
   119
fun pr_msg m = output(std_out,"m")
mueller
parents: 1050
diff changeset
   120
|   pr_msg n = output(std_out,"n")
mueller
parents: 1050
diff changeset
   121
|   pr_msg l = output(std_out,"l");
1050
0c36c6a52a1d ABP: Alternating bit protocol example
nipkow
parents:
diff changeset
   122
0c36c6a52a1d ABP: Alternating bit protocol example
nipkow
parents:
diff changeset
   123
fun pr_act a = output(std_out, case a of
0c36c6a52a1d ABP: Alternating bit protocol example
nipkow
parents:
diff changeset
   124
      Next => "Next"|                         
1138
mueller
parents: 1050
diff changeset
   125
      S_msg(ma) => "S_msg(ma)"  |
mueller
parents: 1050
diff changeset
   126
      R_msg(ma) => "R_msg(ma)"  |
mueller
parents: 1050
diff changeset
   127
      S_pkt(b,ma) => "S_pkt(b,ma)" |                    
mueller
parents: 1050
diff changeset
   128
      R_pkt(b,ma) => "R_pkt(b,ma)" |                    
1050
0c36c6a52a1d ABP: Alternating bit protocol example
nipkow
parents:
diff changeset
   129
      S_ack(b)   => "S_ack(b)" |                      
0c36c6a52a1d ABP: Alternating bit protocol example
nipkow
parents:
diff changeset
   130
      R_ack(b)   => "R_ack(b)");
0c36c6a52a1d ABP: Alternating bit protocol example
nipkow
parents:
diff changeset
   131
1138
mueller
parents: 1050
diff changeset
   132
fun pr_pkt (b,ma) = (prs "<"; pr_bool b;prs ", "; pr_msg ma; prs ">");
1050
0c36c6a52a1d ABP: Alternating bit protocol example
nipkow
parents:
diff changeset
   133
0c36c6a52a1d ABP: Alternating bit protocol example
nipkow
parents:
diff changeset
   134
val pr_bool_list  = print_list("[","]",pr_bool);
0c36c6a52a1d ABP: Alternating bit protocol example
nipkow
parents:
diff changeset
   135
val pr_msg_list   = print_list("[","]",pr_msg);
0c36c6a52a1d ABP: Alternating bit protocol example
nipkow
parents:
diff changeset
   136
val pr_pkt_list   = print_list("[","]",pr_pkt);
0c36c6a52a1d ABP: Alternating bit protocol example
nipkow
parents:
diff changeset
   137
0c36c6a52a1d ABP: Alternating bit protocol example
nipkow
parents:
diff changeset
   138
fun pr_tuple (env,p,a,q,b,ch1,ch2) = 
0c36c6a52a1d ABP: Alternating bit protocol example
nipkow
parents:
diff changeset
   139
        (prs "{"; pr_bool env; prs ", "; pr_msg_list p;  prs ", ";
0c36c6a52a1d ABP: Alternating bit protocol example
nipkow
parents:
diff changeset
   140
         pr_bool a;  prs ", "; pr_msg_list q; prs ", ";
0c36c6a52a1d ABP: Alternating bit protocol example
nipkow
parents:
diff changeset
   141
         pr_bool b;  prs ", "; pr_pkt_list ch1;  prs ", ";
0c36c6a52a1d ABP: Alternating bit protocol example
nipkow
parents:
diff changeset
   142
         pr_bool_list ch2; prs "}");
0c36c6a52a1d ABP: Alternating bit protocol example
nipkow
parents:
diff changeset
   143
1138
mueller
parents: 1050
diff changeset
   144
1050
0c36c6a52a1d ABP: Alternating bit protocol example
nipkow
parents:
diff changeset
   145
1138
mueller
parents: 1050
diff changeset
   146
(* ---------------------------------
mueller
parents: 1050
diff changeset
   147
         Main function call
mueller
parents: 1050
diff changeset
   148
   ---------------------------------*)
mueller
parents: 1050
diff changeset
   149
mueller
parents: 1050
diff changeset
   150
(*
1050
0c36c6a52a1d ABP: Alternating bit protocol example
nipkow
parents:
diff changeset
   151
check(extactions,intactions,pr_act, [(true,[],true,[],false,[],[])], 
0c36c6a52a1d ABP: Alternating bit protocol example
nipkow
parents:
diff changeset
   152
      pr_tuple, nexts, hom, transA, [(true,[])]);
1138
mueller
parents: 1050
diff changeset
   153
*)
mueller
parents: 1050
diff changeset
   154
mueller
parents: 1050
diff changeset
   155
mueller
parents: 1050
diff changeset
   156
1050
0c36c6a52a1d ABP: Alternating bit protocol example
nipkow
parents:
diff changeset
   157
0c36c6a52a1d ABP: Alternating bit protocol example
nipkow
parents:
diff changeset
   158
1138
mueller
parents: 1050
diff changeset
   159
(*
mueller
parents: 1050
diff changeset
   160
           Little test example
mueller
parents: 1050
diff changeset
   161
mueller
parents: 1050
diff changeset
   162
datatype act = A;
mueller
parents: 1050
diff changeset
   163
fun transA(s,a,t) = (not(s)=t);
mueller
parents: 1050
diff changeset
   164
fun hom(i) = i mod 2 = 0;
mueller
parents: 1050
diff changeset
   165
fun nexts s A = [(s+1) mod 4];
mueller
parents: 1050
diff changeset
   166
check([A],[],K"A", [0], string_of_int, nexts, hom, transA, [true]);
mueller
parents: 1050
diff changeset
   167
mueller
parents: 1050
diff changeset
   168
fun nexts s A = [(s+1) mod 5];
mueller
parents: 1050
diff changeset
   169
1465
5d7a7e439cec expanded tabs
clasohm
parents: 1138
diff changeset
   170
*)