| author | blanchet | 
| Tue, 03 Jan 2012 23:03:49 +0100 | |
| changeset 46105 | 9abb756352a6 | 
| parent 46104 | eb85282db54e | 
| child 46106 | 73e2c70980df | 
| permissions | -rw-r--r-- | 
| 33197 | 1  | 
(* Title: HOL/Nitpick_Examples/Manual_Nits.thy  | 
2  | 
Author: Jasmin Blanchette, TU Muenchen  | 
|
| 45035 | 3  | 
Copyright 2009-2011  | 
| 33197 | 4  | 
|
5  | 
Examples from the Nitpick manual.  | 
|
6  | 
*)  | 
|
7  | 
||
8  | 
header {* Examples from the Nitpick Manual *}
 | 
|
9  | 
||
| 
37477
 
e482320bcbfe
adjusted Nitpick examples to latest changes + make them slightly faster
 
blanchet 
parents: 
36268 
diff
changeset
 | 
10  | 
(* The "expect" arguments to Nitpick in this theory and the other example  | 
| 
 
e482320bcbfe
adjusted Nitpick examples to latest changes + make them slightly faster
 
blanchet 
parents: 
36268 
diff
changeset
 | 
11  | 
theories are there so that the example can also serve as a regression test  | 
| 
 
e482320bcbfe
adjusted Nitpick examples to latest changes + make them slightly faster
 
blanchet 
parents: 
36268 
diff
changeset
 | 
12  | 
suite. *)  | 
| 
 
e482320bcbfe
adjusted Nitpick examples to latest changes + make them slightly faster
 
blanchet 
parents: 
36268 
diff
changeset
 | 
13  | 
|
| 33197 | 14  | 
theory Manual_Nits  | 
| 
41413
 
64cd30d6b0b8
explicit file specifications -- avoid secondary load path;
 
wenzelm 
parents: 
41278 
diff
changeset
 | 
15  | 
imports Main "~~/src/HOL/Library/Quotient_Product" RealDef  | 
| 33197 | 16  | 
begin  | 
17  | 
||
| 45053 | 18  | 
chapter {* 2. First Steps *}
 | 
| 33197 | 19  | 
|
| 46104 | 20  | 
nitpick_params [sat_solver = MiniSat_JNI, max_threads = 1, timeout = 240]  | 
| 33197 | 21  | 
|
| 45053 | 22  | 
subsection {* 2.1. Propositional Logic *}
 | 
| 33197 | 23  | 
|
24  | 
lemma "P \<longleftrightarrow> Q"  | 
|
| 
35671
 
ed2c3830d881
improved Nitpick's precision for "card" and "setsum" + fix incorrect outcome code w.r.t. "bisim_depth = -1"
 
blanchet 
parents: 
35665 
diff
changeset
 | 
25  | 
nitpick [expect = genuine]  | 
| 33197 | 26  | 
apply auto  | 
| 
35671
 
ed2c3830d881
improved Nitpick's precision for "card" and "setsum" + fix incorrect outcome code w.r.t. "bisim_depth = -1"
 
blanchet 
parents: 
35665 
diff
changeset
 | 
27  | 
nitpick [expect = genuine] 1  | 
| 
 
ed2c3830d881
improved Nitpick's precision for "card" and "setsum" + fix incorrect outcome code w.r.t. "bisim_depth = -1"
 
blanchet 
parents: 
35665 
diff
changeset
 | 
28  | 
nitpick [expect = genuine] 2  | 
| 33197 | 29  | 
oops  | 
30  | 
||
| 45053 | 31  | 
subsection {* 2.2. Type Variables *}
 | 
| 33197 | 32  | 
|
| 46104 | 33  | 
lemma "x \<in> A \<Longrightarrow> (THE y. y \<in> A) \<in> A"  | 
| 
35671
 
ed2c3830d881
improved Nitpick's precision for "card" and "setsum" + fix incorrect outcome code w.r.t. "bisim_depth = -1"
 
blanchet 
parents: 
35665 
diff
changeset
 | 
34  | 
nitpick [verbose, expect = genuine]  | 
| 33197 | 35  | 
oops  | 
36  | 
||
| 45053 | 37  | 
subsection {* 2.3. Constants *}
 | 
| 33197 | 38  | 
|
| 46104 | 39  | 
lemma "x \<in> A \<Longrightarrow> (THE y. y \<in> A) \<in> A"  | 
| 
35671
 
ed2c3830d881
improved Nitpick's precision for "card" and "setsum" + fix incorrect outcome code w.r.t. "bisim_depth = -1"
 
blanchet 
parents: 
35665 
diff
changeset
 | 
40  | 
nitpick [show_consts, expect = genuine]  | 
| 
39362
 
ee65900bfced
adapt examples to latest Nitpick changes + speed them up a little bit
 
blanchet 
parents: 
39302 
diff
changeset
 | 
41  | 
nitpick [dont_specialize, show_consts, expect = genuine]  | 
| 33197 | 42  | 
oops  | 
43  | 
||
| 46104 | 44  | 
lemma "\<exists>!x. x \<in> A \<Longrightarrow> (THE y. y \<in> A) \<in> A"  | 
| 
35671
 
ed2c3830d881
improved Nitpick's precision for "card" and "setsum" + fix incorrect outcome code w.r.t. "bisim_depth = -1"
 
blanchet 
parents: 
35665 
diff
changeset
 | 
45  | 
nitpick [expect = none]  | 
| 42959 | 46  | 
nitpick [card 'a = 1\<emdash>50, expect = none]  | 
| 33197 | 47  | 
(* sledgehammer *)  | 
| 46104 | 48  | 
sledgehammer  | 
49  | 
by (metis the_equality)  | 
|
| 33197 | 50  | 
|
| 45053 | 51  | 
subsection {* 2.4. Skolemization *}
 | 
| 33197 | 52  | 
|
53  | 
lemma "\<exists>g. \<forall>x. g (f x) = x \<Longrightarrow> \<forall>y. \<exists>x. y = f x"  | 
|
| 
35671
 
ed2c3830d881
improved Nitpick's precision for "card" and "setsum" + fix incorrect outcome code w.r.t. "bisim_depth = -1"
 
blanchet 
parents: 
35665 
diff
changeset
 | 
54  | 
nitpick [expect = genuine]  | 
| 33197 | 55  | 
oops  | 
56  | 
||
57  | 
lemma "\<exists>x. \<forall>f. f x = x"  | 
|
| 
35671
 
ed2c3830d881
improved Nitpick's precision for "card" and "setsum" + fix incorrect outcome code w.r.t. "bisim_depth = -1"
 
blanchet 
parents: 
35665 
diff
changeset
 | 
58  | 
nitpick [expect = genuine]  | 
| 33197 | 59  | 
oops  | 
60  | 
||
61  | 
lemma "refl r \<Longrightarrow> sym r"  | 
|
| 
35671
 
ed2c3830d881
improved Nitpick's precision for "card" and "setsum" + fix incorrect outcome code w.r.t. "bisim_depth = -1"
 
blanchet 
parents: 
35665 
diff
changeset
 | 
62  | 
nitpick [expect = genuine]  | 
| 33197 | 63  | 
oops  | 
64  | 
||
| 45053 | 65  | 
subsection {* 2.5. Natural Numbers and Integers *}
 | 
| 33197 | 66  | 
|
67  | 
lemma "\<lbrakk>i \<le> j; n \<le> (m\<Colon>int)\<rbrakk> \<Longrightarrow> i * n + j * m \<le> i * m + j * n"  | 
|
| 
35671
 
ed2c3830d881
improved Nitpick's precision for "card" and "setsum" + fix incorrect outcome code w.r.t. "bisim_depth = -1"
 
blanchet 
parents: 
35665 
diff
changeset
 | 
68  | 
nitpick [expect = genuine]  | 
| 46104 | 69  | 
nitpick [binary_ints, bits = 16, expect = genuine]  | 
| 33197 | 70  | 
oops  | 
71  | 
||
72  | 
lemma "\<forall>n. Suc n \<noteq> n \<Longrightarrow> P"  | 
|
| 
42421
 
6bc725d60593
increase "auto"'s timeout in example to help SML/NJ
 
blanchet 
parents: 
42208 
diff
changeset
 | 
73  | 
nitpick [card nat = 100, check_potential, tac_timeout = 5, expect = genuine]  | 
| 33197 | 74  | 
oops  | 
75  | 
||
76  | 
lemma "P Suc"  | 
|
| 
35671
 
ed2c3830d881
improved Nitpick's precision for "card" and "setsum" + fix incorrect outcome code w.r.t. "bisim_depth = -1"
 
blanchet 
parents: 
35665 
diff
changeset
 | 
77  | 
nitpick [expect = none]  | 
| 33197 | 78  | 
oops  | 
79  | 
||
80  | 
lemma "P (op +\<Colon>nat\<Rightarrow>nat\<Rightarrow>nat)"  | 
|
| 
35671
 
ed2c3830d881
improved Nitpick's precision for "card" and "setsum" + fix incorrect outcome code w.r.t. "bisim_depth = -1"
 
blanchet 
parents: 
35665 
diff
changeset
 | 
81  | 
nitpick [card nat = 1, expect = genuine]  | 
| 
 
ed2c3830d881
improved Nitpick's precision for "card" and "setsum" + fix incorrect outcome code w.r.t. "bisim_depth = -1"
 
blanchet 
parents: 
35665 
diff
changeset
 | 
82  | 
nitpick [card nat = 2, expect = none]  | 
| 33197 | 83  | 
oops  | 
84  | 
||
| 45053 | 85  | 
subsection {* 2.6. Inductive Datatypes *}
 | 
| 33197 | 86  | 
|
87  | 
lemma "hd (xs @ [y, y]) = hd xs"  | 
|
| 
35671
 
ed2c3830d881
improved Nitpick's precision for "card" and "setsum" + fix incorrect outcome code w.r.t. "bisim_depth = -1"
 
blanchet 
parents: 
35665 
diff
changeset
 | 
88  | 
nitpick [expect = genuine]  | 
| 
 
ed2c3830d881
improved Nitpick's precision for "card" and "setsum" + fix incorrect outcome code w.r.t. "bisim_depth = -1"
 
blanchet 
parents: 
35665 
diff
changeset
 | 
89  | 
nitpick [show_consts, show_datatypes, expect = genuine]  | 
| 33197 | 90  | 
oops  | 
91  | 
||
92  | 
lemma "\<lbrakk>length xs = 1; length ys = 1\<rbrakk> \<Longrightarrow> xs = ys"  | 
|
| 
35671
 
ed2c3830d881
improved Nitpick's precision for "card" and "setsum" + fix incorrect outcome code w.r.t. "bisim_depth = -1"
 
blanchet 
parents: 
35665 
diff
changeset
 | 
93  | 
nitpick [show_datatypes, expect = genuine]  | 
| 33197 | 94  | 
oops  | 
95  | 
||
| 45053 | 96  | 
subsection {* 2.7. Typedefs, Records, Rationals, and Reals *}
 | 
| 33197 | 97  | 
|
| 46104 | 98  | 
typedef three = "{0\<Colon>nat, 1, 2}"
 | 
99  | 
by blast  | 
|
| 33197 | 100  | 
|
101  | 
definition A :: three where "A \<equiv> Abs_three 0"  | 
|
102  | 
definition B :: three where "B \<equiv> Abs_three 1"  | 
|
103  | 
definition C :: three where "C \<equiv> Abs_three 2"  | 
|
104  | 
||
| 46104 | 105  | 
lemma "\<lbrakk>A \<in> X; B \<in> X\<rbrakk> \<Longrightarrow> c \<in> X"  | 
| 
35671
 
ed2c3830d881
improved Nitpick's precision for "card" and "setsum" + fix incorrect outcome code w.r.t. "bisim_depth = -1"
 
blanchet 
parents: 
35665 
diff
changeset
 | 
106  | 
nitpick [show_datatypes, expect = genuine]  | 
| 33197 | 107  | 
oops  | 
108  | 
||
| 
35284
 
9edc2bd6d2bd
enabled Nitpick's support for quotient types + shortened the Nitpick tests a bit
 
blanchet 
parents: 
35185 
diff
changeset
 | 
109  | 
fun my_int_rel where  | 
| 
 
9edc2bd6d2bd
enabled Nitpick's support for quotient types + shortened the Nitpick tests a bit
 
blanchet 
parents: 
35185 
diff
changeset
 | 
110  | 
"my_int_rel (x, y) (u, v) = (x + v = u + y)"  | 
| 
 
9edc2bd6d2bd
enabled Nitpick's support for quotient types + shortened the Nitpick tests a bit
 
blanchet 
parents: 
35185 
diff
changeset
 | 
111  | 
|
| 
 
9edc2bd6d2bd
enabled Nitpick's support for quotient types + shortened the Nitpick tests a bit
 
blanchet 
parents: 
35185 
diff
changeset
 | 
112  | 
quotient_type my_int = "nat \<times> nat" / my_int_rel  | 
| 
39302
 
d7728f65b353
renamed lemmas: ext_iff -> fun_eq_iff, set_ext_iff -> set_eq_iff, set_ext -> set_eqI
 
nipkow 
parents: 
39198 
diff
changeset
 | 
113  | 
by (auto simp add: equivp_def fun_eq_iff)  | 
| 
35284
 
9edc2bd6d2bd
enabled Nitpick's support for quotient types + shortened the Nitpick tests a bit
 
blanchet 
parents: 
35185 
diff
changeset
 | 
114  | 
|
| 
 
9edc2bd6d2bd
enabled Nitpick's support for quotient types + shortened the Nitpick tests a bit
 
blanchet 
parents: 
35185 
diff
changeset
 | 
115  | 
definition add_raw where  | 
| 
 
9edc2bd6d2bd
enabled Nitpick's support for quotient types + shortened the Nitpick tests a bit
 
blanchet 
parents: 
35185 
diff
changeset
 | 
116  | 
"add_raw \<equiv> \<lambda>(x, y) (u, v). (x + (u\<Colon>nat), y + (v\<Colon>nat))"  | 
| 
 
9edc2bd6d2bd
enabled Nitpick's support for quotient types + shortened the Nitpick tests a bit
 
blanchet 
parents: 
35185 
diff
changeset
 | 
117  | 
|
| 
 
9edc2bd6d2bd
enabled Nitpick's support for quotient types + shortened the Nitpick tests a bit
 
blanchet 
parents: 
35185 
diff
changeset
 | 
118  | 
quotient_definition "add\<Colon>my_int \<Rightarrow> my_int \<Rightarrow> my_int" is add_raw  | 
| 
 
9edc2bd6d2bd
enabled Nitpick's support for quotient types + shortened the Nitpick tests a bit
 
blanchet 
parents: 
35185 
diff
changeset
 | 
119  | 
|
| 
 
9edc2bd6d2bd
enabled Nitpick's support for quotient types + shortened the Nitpick tests a bit
 
blanchet 
parents: 
35185 
diff
changeset
 | 
120  | 
lemma "add x y = add x x"  | 
| 
35671
 
ed2c3830d881
improved Nitpick's precision for "card" and "setsum" + fix incorrect outcome code w.r.t. "bisim_depth = -1"
 
blanchet 
parents: 
35665 
diff
changeset
 | 
121  | 
nitpick [show_datatypes, expect = genuine]  | 
| 
35284
 
9edc2bd6d2bd
enabled Nitpick's support for quotient types + shortened the Nitpick tests a bit
 
blanchet 
parents: 
35185 
diff
changeset
 | 
122  | 
oops  | 
| 
 
9edc2bd6d2bd
enabled Nitpick's support for quotient types + shortened the Nitpick tests a bit
 
blanchet 
parents: 
35185 
diff
changeset
 | 
123  | 
|
| 
35711
 
548d3f16404b
added term postprocessor to Nitpick, to provide custom syntax for typedefs
 
blanchet 
parents: 
35710 
diff
changeset
 | 
124  | 
ML {*
 | 
| 
35712
 
77aa29bf14ee
added a mechanism to Nitpick to support custom rendering of terms, and used it for multisets
 
blanchet 
parents: 
35711 
diff
changeset
 | 
125  | 
fun my_int_postproc _ _ _ T (Const _ $ (Const _ $ t1 $ t2)) =  | 
| 
 
77aa29bf14ee
added a mechanism to Nitpick to support custom rendering of terms, and used it for multisets
 
blanchet 
parents: 
35711 
diff
changeset
 | 
126  | 
HOLogic.mk_number T (snd (HOLogic.dest_number t1)  | 
| 
 
77aa29bf14ee
added a mechanism to Nitpick to support custom rendering of terms, and used it for multisets
 
blanchet 
parents: 
35711 
diff
changeset
 | 
127  | 
- snd (HOLogic.dest_number t2))  | 
| 
 
77aa29bf14ee
added a mechanism to Nitpick to support custom rendering of terms, and used it for multisets
 
blanchet 
parents: 
35711 
diff
changeset
 | 
128  | 
| my_int_postproc _ _ _ _ t = t  | 
| 
35711
 
548d3f16404b
added term postprocessor to Nitpick, to provide custom syntax for typedefs
 
blanchet 
parents: 
35710 
diff
changeset
 | 
129  | 
*}  | 
| 
 
548d3f16404b
added term postprocessor to Nitpick, to provide custom syntax for typedefs
 
blanchet 
parents: 
35710 
diff
changeset
 | 
130  | 
|
| 38288 | 131  | 
declaration {*
 | 
| 
38284
 
9f98107ad8b4
use "declaration" instead of "setup" to register Nitpick extensions
 
blanchet 
parents: 
38242 
diff
changeset
 | 
132  | 
Nitpick_Model.register_term_postprocessor @{typ my_int} my_int_postproc
 | 
| 38242 | 133  | 
*}  | 
| 
35711
 
548d3f16404b
added term postprocessor to Nitpick, to provide custom syntax for typedefs
 
blanchet 
parents: 
35710 
diff
changeset
 | 
134  | 
|
| 
 
548d3f16404b
added term postprocessor to Nitpick, to provide custom syntax for typedefs
 
blanchet 
parents: 
35710 
diff
changeset
 | 
135  | 
lemma "add x y = add x x"  | 
| 
 
548d3f16404b
added term postprocessor to Nitpick, to provide custom syntax for typedefs
 
blanchet 
parents: 
35710 
diff
changeset
 | 
136  | 
nitpick [show_datatypes]  | 
| 
 
548d3f16404b
added term postprocessor to Nitpick, to provide custom syntax for typedefs
 
blanchet 
parents: 
35710 
diff
changeset
 | 
137  | 
oops  | 
| 
 
548d3f16404b
added term postprocessor to Nitpick, to provide custom syntax for typedefs
 
blanchet 
parents: 
35710 
diff
changeset
 | 
138  | 
|
| 33197 | 139  | 
record point =  | 
140  | 
Xcoord :: int  | 
|
141  | 
Ycoord :: int  | 
|
142  | 
||
143  | 
lemma "Xcoord (p\<Colon>point) = Xcoord (q\<Colon>point)"  | 
|
| 
35671
 
ed2c3830d881
improved Nitpick's precision for "card" and "setsum" + fix incorrect outcome code w.r.t. "bisim_depth = -1"
 
blanchet 
parents: 
35665 
diff
changeset
 | 
144  | 
nitpick [show_datatypes, expect = genuine]  | 
| 33197 | 145  | 
oops  | 
146  | 
||
147  | 
lemma "4 * x + 3 * (y\<Colon>real) \<noteq> 1 / 2"  | 
|
| 
35671
 
ed2c3830d881
improved Nitpick's precision for "card" and "setsum" + fix incorrect outcome code w.r.t. "bisim_depth = -1"
 
blanchet 
parents: 
35665 
diff
changeset
 | 
148  | 
nitpick [show_datatypes, expect = genuine]  | 
| 33197 | 149  | 
oops  | 
150  | 
||
| 45053 | 151  | 
subsection {* 2.8. Inductive and Coinductive Predicates *}
 | 
| 33197 | 152  | 
|
153  | 
inductive even where  | 
|
154  | 
"even 0" |  | 
|
155  | 
"even n \<Longrightarrow> even (Suc (Suc n))"  | 
|
156  | 
||
157  | 
lemma "\<exists>n. even n \<and> even (Suc n)"  | 
|
| 35710 | 158  | 
nitpick [card nat = 50, unary_ints, verbose, expect = potential]  | 
| 33197 | 159  | 
oops  | 
160  | 
||
| 35710 | 161  | 
lemma "\<exists>n \<le> 49. even n \<and> even (Suc n)"  | 
| 38184 | 162  | 
nitpick [card nat = 50, unary_ints, expect = genuine]  | 
| 33197 | 163  | 
oops  | 
164  | 
||
165  | 
inductive even' where  | 
|
166  | 
"even' (0\<Colon>nat)" |  | 
|
167  | 
"even' 2" |  | 
|
168  | 
"\<lbrakk>even' m; even' n\<rbrakk> \<Longrightarrow> even' (m + n)"  | 
|
169  | 
||
170  | 
lemma "\<exists>n \<in> {0, 2, 4, 6, 8}. \<not> even' n"
 | 
|
| 
35671
 
ed2c3830d881
improved Nitpick's precision for "card" and "setsum" + fix incorrect outcome code w.r.t. "bisim_depth = -1"
 
blanchet 
parents: 
35665 
diff
changeset
 | 
171  | 
nitpick [card nat = 10, unary_ints, verbose, show_consts, expect = genuine]  | 
| 33197 | 172  | 
oops  | 
173  | 
||
174  | 
lemma "even' (n - 2) \<Longrightarrow> even' n"  | 
|
| 
35671
 
ed2c3830d881
improved Nitpick's precision for "card" and "setsum" + fix incorrect outcome code w.r.t. "bisim_depth = -1"
 
blanchet 
parents: 
35665 
diff
changeset
 | 
175  | 
nitpick [card nat = 10, show_consts, expect = genuine]  | 
| 33197 | 176  | 
oops  | 
177  | 
||
178  | 
coinductive nats where  | 
|
179  | 
"nats (x\<Colon>nat) \<Longrightarrow> nats x"  | 
|
180  | 
||
| 
45970
 
b6d0cff57d96
adjusted to set/pred distinction by means of type constructor `set`
 
haftmann 
parents: 
45694 
diff
changeset
 | 
181  | 
lemma "nats = (\<lambda>n. n \<in> {0, 1, 2, 3, 4})"
 | 
| 
35671
 
ed2c3830d881
improved Nitpick's precision for "card" and "setsum" + fix incorrect outcome code w.r.t. "bisim_depth = -1"
 
blanchet 
parents: 
35665 
diff
changeset
 | 
182  | 
nitpick [card nat = 10, show_consts, expect = genuine]  | 
| 33197 | 183  | 
oops  | 
184  | 
||
185  | 
inductive odd where  | 
|
186  | 
"odd 1" |  | 
|
187  | 
"\<lbrakk>odd m; even n\<rbrakk> \<Longrightarrow> odd (m + n)"  | 
|
188  | 
||
189  | 
lemma "odd n \<Longrightarrow> odd (n - 2)"  | 
|
| 46105 | 190  | 
nitpick [card nat = 4, show_consts, expect = genuine]  | 
| 33197 | 191  | 
oops  | 
192  | 
||
| 45053 | 193  | 
subsection {* 2.9. Coinductive Datatypes *}
 | 
| 33197 | 194  | 
|
| 
35665
 
ff2bf50505ab
added "finitize" option to Nitpick + remove dependency on "Coinductive_List"
 
blanchet 
parents: 
35312 
diff
changeset
 | 
195  | 
(* Lazy lists are defined in Andreas Lochbihler's "Coinductive" AFP entry. Since  | 
| 38184 | 196  | 
we cannot rely on its presence, we expediently provide our own  | 
197  | 
axiomatization. The examples also work unchanged with Lochbihler's  | 
|
198  | 
"Coinductive_List" theory. *)  | 
|
| 
35665
 
ff2bf50505ab
added "finitize" option to Nitpick + remove dependency on "Coinductive_List"
 
blanchet 
parents: 
35312 
diff
changeset
 | 
199  | 
|
| 
45694
 
4a8743618257
prefer typedef without extra definition and alternative name;
 
wenzelm 
parents: 
45053 
diff
changeset
 | 
200  | 
definition "llist = (UNIV\<Colon>('a list + (nat \<Rightarrow> 'a)) set)"
 | 
| 
 
4a8743618257
prefer typedef without extra definition and alternative name;
 
wenzelm 
parents: 
45053 
diff
changeset
 | 
201  | 
|
| 
 
4a8743618257
prefer typedef without extra definition and alternative name;
 
wenzelm 
parents: 
45053 
diff
changeset
 | 
202  | 
typedef (open) 'a llist = "llist\<Colon>('a list + (nat \<Rightarrow> 'a)) set"
 | 
| 
 
4a8743618257
prefer typedef without extra definition and alternative name;
 
wenzelm 
parents: 
45053 
diff
changeset
 | 
203  | 
unfolding llist_def by auto  | 
| 
35665
 
ff2bf50505ab
added "finitize" option to Nitpick + remove dependency on "Coinductive_List"
 
blanchet 
parents: 
35312 
diff
changeset
 | 
204  | 
|
| 
35671
 
ed2c3830d881
improved Nitpick's precision for "card" and "setsum" + fix incorrect outcome code w.r.t. "bisim_depth = -1"
 
blanchet 
parents: 
35665 
diff
changeset
 | 
205  | 
definition LNil where  | 
| 
 
ed2c3830d881
improved Nitpick's precision for "card" and "setsum" + fix incorrect outcome code w.r.t. "bisim_depth = -1"
 
blanchet 
parents: 
35665 
diff
changeset
 | 
206  | 
"LNil = Abs_llist (Inl [])"  | 
| 
35665
 
ff2bf50505ab
added "finitize" option to Nitpick + remove dependency on "Coinductive_List"
 
blanchet 
parents: 
35312 
diff
changeset
 | 
207  | 
definition LCons where  | 
| 
 
ff2bf50505ab
added "finitize" option to Nitpick + remove dependency on "Coinductive_List"
 
blanchet 
parents: 
35312 
diff
changeset
 | 
208  | 
"LCons y ys = Abs_llist (case Rep_llist ys of  | 
| 
 
ff2bf50505ab
added "finitize" option to Nitpick + remove dependency on "Coinductive_List"
 
blanchet 
parents: 
35312 
diff
changeset
 | 
209  | 
Inl ys' \<Rightarrow> Inl (y # ys')  | 
| 
 
ff2bf50505ab
added "finitize" option to Nitpick + remove dependency on "Coinductive_List"
 
blanchet 
parents: 
35312 
diff
changeset
 | 
210  | 
| Inr f \<Rightarrow> Inr (\<lambda>n. case n of 0 \<Rightarrow> y | Suc m \<Rightarrow> f m))"  | 
| 
 
ff2bf50505ab
added "finitize" option to Nitpick + remove dependency on "Coinductive_List"
 
blanchet 
parents: 
35312 
diff
changeset
 | 
211  | 
|
| 
 
ff2bf50505ab
added "finitize" option to Nitpick + remove dependency on "Coinductive_List"
 
blanchet 
parents: 
35312 
diff
changeset
 | 
212  | 
axiomatization iterates :: "('a \<Rightarrow> 'a) \<Rightarrow> 'a \<Rightarrow> 'a llist"
 | 
| 
 
ff2bf50505ab
added "finitize" option to Nitpick + remove dependency on "Coinductive_List"
 
blanchet 
parents: 
35312 
diff
changeset
 | 
213  | 
|
| 
 
ff2bf50505ab
added "finitize" option to Nitpick + remove dependency on "Coinductive_List"
 
blanchet 
parents: 
35312 
diff
changeset
 | 
214  | 
lemma iterates_def [nitpick_simp]:  | 
| 
 
ff2bf50505ab
added "finitize" option to Nitpick + remove dependency on "Coinductive_List"
 
blanchet 
parents: 
35312 
diff
changeset
 | 
215  | 
"iterates f a = LCons a (iterates f (f a))"  | 
| 
 
ff2bf50505ab
added "finitize" option to Nitpick + remove dependency on "Coinductive_List"
 
blanchet 
parents: 
35312 
diff
changeset
 | 
216  | 
sorry  | 
| 
 
ff2bf50505ab
added "finitize" option to Nitpick + remove dependency on "Coinductive_List"
 
blanchet 
parents: 
35312 
diff
changeset
 | 
217  | 
|
| 38288 | 218  | 
declaration {*
 | 
| 
38284
 
9f98107ad8b4
use "declaration" instead of "setup" to register Nitpick extensions
 
blanchet 
parents: 
38242 
diff
changeset
 | 
219  | 
Nitpick_HOL.register_codatatype @{typ "'a llist"} ""
 | 
| 
35665
 
ff2bf50505ab
added "finitize" option to Nitpick + remove dependency on "Coinductive_List"
 
blanchet 
parents: 
35312 
diff
changeset
 | 
220  | 
    (map dest_Const [@{term LNil}, @{term LCons}])
 | 
| 
 
ff2bf50505ab
added "finitize" option to Nitpick + remove dependency on "Coinductive_List"
 
blanchet 
parents: 
35312 
diff
changeset
 | 
221  | 
*}  | 
| 
 
ff2bf50505ab
added "finitize" option to Nitpick + remove dependency on "Coinductive_List"
 
blanchet 
parents: 
35312 
diff
changeset
 | 
222  | 
|
| 33197 | 223  | 
lemma "xs \<noteq> LCons a xs"  | 
| 
35671
 
ed2c3830d881
improved Nitpick's precision for "card" and "setsum" + fix incorrect outcome code w.r.t. "bisim_depth = -1"
 
blanchet 
parents: 
35665 
diff
changeset
 | 
224  | 
nitpick [expect = genuine]  | 
| 33197 | 225  | 
oops  | 
226  | 
||
227  | 
lemma "\<lbrakk>xs = LCons a xs; ys = iterates (\<lambda>b. a) b\<rbrakk> \<Longrightarrow> xs = ys"  | 
|
| 
35671
 
ed2c3830d881
improved Nitpick's precision for "card" and "setsum" + fix incorrect outcome code w.r.t. "bisim_depth = -1"
 
blanchet 
parents: 
35665 
diff
changeset
 | 
228  | 
nitpick [verbose, expect = genuine]  | 
| 33197 | 229  | 
oops  | 
230  | 
||
231  | 
lemma "\<lbrakk>xs = LCons a xs; ys = LCons a ys\<rbrakk> \<Longrightarrow> xs = ys"  | 
|
| 
35671
 
ed2c3830d881
improved Nitpick's precision for "card" and "setsum" + fix incorrect outcome code w.r.t. "bisim_depth = -1"
 
blanchet 
parents: 
35665 
diff
changeset
 | 
232  | 
nitpick [bisim_depth = -1, show_datatypes, expect = quasi_genuine]  | 
| 42959 | 233  | 
nitpick [card = 1\<emdash>5, expect = none]  | 
| 33197 | 234  | 
sorry  | 
235  | 
||
| 45053 | 236  | 
subsection {* 2.10. Boxing *}
 | 
| 33197 | 237  | 
|
238  | 
datatype tm = Var nat | Lam tm | App tm tm  | 
|
239  | 
||
240  | 
primrec lift where  | 
|
241  | 
"lift (Var j) k = Var (if j < k then j else j + 1)" |  | 
|
242  | 
"lift (Lam t) k = Lam (lift t (k + 1))" |  | 
|
243  | 
"lift (App t u) k = App (lift t k) (lift u k)"  | 
|
244  | 
||
245  | 
primrec loose where  | 
|
246  | 
"loose (Var j) k = (j \<ge> k)" |  | 
|
247  | 
"loose (Lam t) k = loose t (Suc k)" |  | 
|
248  | 
"loose (App t u) k = (loose t k \<or> loose u k)"  | 
|
249  | 
||
250  | 
primrec subst\<^isub>1 where  | 
|
251  | 
"subst\<^isub>1 \<sigma> (Var j) = \<sigma> j" |  | 
|
252  | 
"subst\<^isub>1 \<sigma> (Lam t) =  | 
|
253  | 
Lam (subst\<^isub>1 (\<lambda>n. case n of 0 \<Rightarrow> Var 0 | Suc m \<Rightarrow> lift (\<sigma> m) 1) t)" |  | 
|
254  | 
"subst\<^isub>1 \<sigma> (App t u) = App (subst\<^isub>1 \<sigma> t) (subst\<^isub>1 \<sigma> u)"  | 
|
255  | 
||
256  | 
lemma "\<not> loose t 0 \<Longrightarrow> subst\<^isub>1 \<sigma> t = t"  | 
|
| 
35671
 
ed2c3830d881
improved Nitpick's precision for "card" and "setsum" + fix incorrect outcome code w.r.t. "bisim_depth = -1"
 
blanchet 
parents: 
35665 
diff
changeset
 | 
257  | 
nitpick [verbose, expect = genuine]  | 
| 
 
ed2c3830d881
improved Nitpick's precision for "card" and "setsum" + fix incorrect outcome code w.r.t. "bisim_depth = -1"
 
blanchet 
parents: 
35665 
diff
changeset
 | 
258  | 
nitpick [eval = "subst\<^isub>1 \<sigma> t", expect = genuine]  | 
| 
 
ed2c3830d881
improved Nitpick's precision for "card" and "setsum" + fix incorrect outcome code w.r.t. "bisim_depth = -1"
 
blanchet 
parents: 
35665 
diff
changeset
 | 
259  | 
(* nitpick [dont_box, expect = unknown] *)  | 
| 33197 | 260  | 
oops  | 
261  | 
||
262  | 
primrec subst\<^isub>2 where  | 
|
263  | 
"subst\<^isub>2 \<sigma> (Var j) = \<sigma> j" |  | 
|
264  | 
"subst\<^isub>2 \<sigma> (Lam t) =  | 
|
265  | 
Lam (subst\<^isub>2 (\<lambda>n. case n of 0 \<Rightarrow> Var 0 | Suc m \<Rightarrow> lift (\<sigma> m) 0) t)" |  | 
|
266  | 
"subst\<^isub>2 \<sigma> (App t u) = App (subst\<^isub>2 \<sigma> t) (subst\<^isub>2 \<sigma> u)"  | 
|
267  | 
||
268  | 
lemma "\<not> loose t 0 \<Longrightarrow> subst\<^isub>2 \<sigma> t = t"  | 
|
| 42959 | 269  | 
nitpick [card = 1\<emdash>5, expect = none]  | 
| 33197 | 270  | 
sorry  | 
271  | 
||
| 45053 | 272  | 
subsection {* 2.11. Scope Monotonicity *}
 | 
| 33197 | 273  | 
|
274  | 
lemma "length xs = length ys \<Longrightarrow> rev (zip xs ys) = zip xs (rev ys)"  | 
|
| 
35671
 
ed2c3830d881
improved Nitpick's precision for "card" and "setsum" + fix incorrect outcome code w.r.t. "bisim_depth = -1"
 
blanchet 
parents: 
35665 
diff
changeset
 | 
275  | 
nitpick [verbose, expect = genuine]  | 
| 33197 | 276  | 
oops  | 
277  | 
||
278  | 
lemma "\<exists>g. \<forall>x\<Colon>'b. g (f x) = x \<Longrightarrow> \<forall>y\<Colon>'a. \<exists>x. y = f x"  | 
|
| 
35671
 
ed2c3830d881
improved Nitpick's precision for "card" and "setsum" + fix incorrect outcome code w.r.t. "bisim_depth = -1"
 
blanchet 
parents: 
35665 
diff
changeset
 | 
279  | 
nitpick [mono, expect = none]  | 
| 
 
ed2c3830d881
improved Nitpick's precision for "card" and "setsum" + fix incorrect outcome code w.r.t. "bisim_depth = -1"
 
blanchet 
parents: 
35665 
diff
changeset
 | 
280  | 
nitpick [expect = genuine]  | 
| 33197 | 281  | 
oops  | 
282  | 
||
| 45053 | 283  | 
subsection {* 2.12. Inductive Properties *}
 | 
| 
34982
 
7b8c366e34a2
added support for nonstandard models to Nitpick (based on an idea by Koen Claessen) and did other fixes to Nitpick
 
blanchet 
parents: 
34126 
diff
changeset
 | 
284  | 
|
| 
 
7b8c366e34a2
added support for nonstandard models to Nitpick (based on an idea by Koen Claessen) and did other fixes to Nitpick
 
blanchet 
parents: 
34126 
diff
changeset
 | 
285  | 
inductive_set reach where  | 
| 
 
7b8c366e34a2
added support for nonstandard models to Nitpick (based on an idea by Koen Claessen) and did other fixes to Nitpick
 
blanchet 
parents: 
34126 
diff
changeset
 | 
286  | 
"(4\<Colon>nat) \<in> reach" |  | 
| 
 
7b8c366e34a2
added support for nonstandard models to Nitpick (based on an idea by Koen Claessen) and did other fixes to Nitpick
 
blanchet 
parents: 
34126 
diff
changeset
 | 
287  | 
"n \<in> reach \<Longrightarrow> n < 4 \<Longrightarrow> 3 * n + 1 \<in> reach" |  | 
| 
 
7b8c366e34a2
added support for nonstandard models to Nitpick (based on an idea by Koen Claessen) and did other fixes to Nitpick
 
blanchet 
parents: 
34126 
diff
changeset
 | 
288  | 
"n \<in> reach \<Longrightarrow> n + 2 \<in> reach"  | 
| 
 
7b8c366e34a2
added support for nonstandard models to Nitpick (based on an idea by Koen Claessen) and did other fixes to Nitpick
 
blanchet 
parents: 
34126 
diff
changeset
 | 
289  | 
|
| 
 
7b8c366e34a2
added support for nonstandard models to Nitpick (based on an idea by Koen Claessen) and did other fixes to Nitpick
 
blanchet 
parents: 
34126 
diff
changeset
 | 
290  | 
lemma "n \<in> reach \<Longrightarrow> 2 dvd n"  | 
| 38184 | 291  | 
(* nitpick *)  | 
| 
34982
 
7b8c366e34a2
added support for nonstandard models to Nitpick (based on an idea by Koen Claessen) and did other fixes to Nitpick
 
blanchet 
parents: 
34126 
diff
changeset
 | 
292  | 
apply (induct set: reach)  | 
| 
 
7b8c366e34a2
added support for nonstandard models to Nitpick (based on an idea by Koen Claessen) and did other fixes to Nitpick
 
blanchet 
parents: 
34126 
diff
changeset
 | 
293  | 
apply auto  | 
| 42959 | 294  | 
nitpick [card = 1\<emdash>4, bits = 1\<emdash>4, expect = none]  | 
| 
34982
 
7b8c366e34a2
added support for nonstandard models to Nitpick (based on an idea by Koen Claessen) and did other fixes to Nitpick
 
blanchet 
parents: 
34126 
diff
changeset
 | 
295  | 
apply (thin_tac "n \<in> reach")  | 
| 
35671
 
ed2c3830d881
improved Nitpick's precision for "card" and "setsum" + fix incorrect outcome code w.r.t. "bisim_depth = -1"
 
blanchet 
parents: 
35665 
diff
changeset
 | 
296  | 
nitpick [expect = genuine]  | 
| 
34982
 
7b8c366e34a2
added support for nonstandard models to Nitpick (based on an idea by Koen Claessen) and did other fixes to Nitpick
 
blanchet 
parents: 
34126 
diff
changeset
 | 
297  | 
oops  | 
| 
 
7b8c366e34a2
added support for nonstandard models to Nitpick (based on an idea by Koen Claessen) and did other fixes to Nitpick
 
blanchet 
parents: 
34126 
diff
changeset
 | 
298  | 
|
| 
 
7b8c366e34a2
added support for nonstandard models to Nitpick (based on an idea by Koen Claessen) and did other fixes to Nitpick
 
blanchet 
parents: 
34126 
diff
changeset
 | 
299  | 
lemma "n \<in> reach \<Longrightarrow> 2 dvd n \<and> n \<noteq> 0"  | 
| 38184 | 300  | 
(* nitpick *)  | 
| 
34982
 
7b8c366e34a2
added support for nonstandard models to Nitpick (based on an idea by Koen Claessen) and did other fixes to Nitpick
 
blanchet 
parents: 
34126 
diff
changeset
 | 
301  | 
apply (induct set: reach)  | 
| 
 
7b8c366e34a2
added support for nonstandard models to Nitpick (based on an idea by Koen Claessen) and did other fixes to Nitpick
 
blanchet 
parents: 
34126 
diff
changeset
 | 
302  | 
apply auto  | 
| 42959 | 303  | 
nitpick [card = 1\<emdash>4, bits = 1\<emdash>4, expect = none]  | 
| 
34982
 
7b8c366e34a2
added support for nonstandard models to Nitpick (based on an idea by Koen Claessen) and did other fixes to Nitpick
 
blanchet 
parents: 
34126 
diff
changeset
 | 
304  | 
apply (thin_tac "n \<in> reach")  | 
| 
35671
 
ed2c3830d881
improved Nitpick's precision for "card" and "setsum" + fix incorrect outcome code w.r.t. "bisim_depth = -1"
 
blanchet 
parents: 
35665 
diff
changeset
 | 
305  | 
nitpick [expect = genuine]  | 
| 
34982
 
7b8c366e34a2
added support for nonstandard models to Nitpick (based on an idea by Koen Claessen) and did other fixes to Nitpick
 
blanchet 
parents: 
34126 
diff
changeset
 | 
306  | 
oops  | 
| 
 
7b8c366e34a2
added support for nonstandard models to Nitpick (based on an idea by Koen Claessen) and did other fixes to Nitpick
 
blanchet 
parents: 
34126 
diff
changeset
 | 
307  | 
|
| 
 
7b8c366e34a2
added support for nonstandard models to Nitpick (based on an idea by Koen Claessen) and did other fixes to Nitpick
 
blanchet 
parents: 
34126 
diff
changeset
 | 
308  | 
lemma "n \<in> reach \<Longrightarrow> 2 dvd n \<and> n \<ge> 4"  | 
| 
 
7b8c366e34a2
added support for nonstandard models to Nitpick (based on an idea by Koen Claessen) and did other fixes to Nitpick
 
blanchet 
parents: 
34126 
diff
changeset
 | 
309  | 
by (induct set: reach) arith+  | 
| 
 
7b8c366e34a2
added support for nonstandard models to Nitpick (based on an idea by Koen Claessen) and did other fixes to Nitpick
 
blanchet 
parents: 
34126 
diff
changeset
 | 
310  | 
|
| 
 
7b8c366e34a2
added support for nonstandard models to Nitpick (based on an idea by Koen Claessen) and did other fixes to Nitpick
 
blanchet 
parents: 
34126 
diff
changeset
 | 
311  | 
datatype 'a bin_tree = Leaf 'a | Branch "'a bin_tree" "'a bin_tree"  | 
| 
 
7b8c366e34a2
added support for nonstandard models to Nitpick (based on an idea by Koen Claessen) and did other fixes to Nitpick
 
blanchet 
parents: 
34126 
diff
changeset
 | 
312  | 
|
| 
 
7b8c366e34a2
added support for nonstandard models to Nitpick (based on an idea by Koen Claessen) and did other fixes to Nitpick
 
blanchet 
parents: 
34126 
diff
changeset
 | 
313  | 
primrec labels where  | 
| 
 
7b8c366e34a2
added support for nonstandard models to Nitpick (based on an idea by Koen Claessen) and did other fixes to Nitpick
 
blanchet 
parents: 
34126 
diff
changeset
 | 
314  | 
"labels (Leaf a) = {a}" |
 | 
| 
 
7b8c366e34a2
added support for nonstandard models to Nitpick (based on an idea by Koen Claessen) and did other fixes to Nitpick
 
blanchet 
parents: 
34126 
diff
changeset
 | 
315  | 
"labels (Branch t u) = labels t \<union> labels u"  | 
| 
 
7b8c366e34a2
added support for nonstandard models to Nitpick (based on an idea by Koen Claessen) and did other fixes to Nitpick
 
blanchet 
parents: 
34126 
diff
changeset
 | 
316  | 
|
| 
 
7b8c366e34a2
added support for nonstandard models to Nitpick (based on an idea by Koen Claessen) and did other fixes to Nitpick
 
blanchet 
parents: 
34126 
diff
changeset
 | 
317  | 
primrec swap where  | 
| 
 
7b8c366e34a2
added support for nonstandard models to Nitpick (based on an idea by Koen Claessen) and did other fixes to Nitpick
 
blanchet 
parents: 
34126 
diff
changeset
 | 
318  | 
"swap (Leaf c) a b =  | 
| 
 
7b8c366e34a2
added support for nonstandard models to Nitpick (based on an idea by Koen Claessen) and did other fixes to Nitpick
 
blanchet 
parents: 
34126 
diff
changeset
 | 
319  | 
(if c = a then Leaf b else if c = b then Leaf a else Leaf c)" |  | 
| 
 
7b8c366e34a2
added support for nonstandard models to Nitpick (based on an idea by Koen Claessen) and did other fixes to Nitpick
 
blanchet 
parents: 
34126 
diff
changeset
 | 
320  | 
"swap (Branch t u) a b = Branch (swap t a b) (swap u a b)"  | 
| 
 
7b8c366e34a2
added support for nonstandard models to Nitpick (based on an idea by Koen Claessen) and did other fixes to Nitpick
 
blanchet 
parents: 
34126 
diff
changeset
 | 
321  | 
|
| 
35180
 
c57dba973391
more work on Nitpick's support for nonstandard models + fix in model reconstruction
 
blanchet 
parents: 
35078 
diff
changeset
 | 
322  | 
lemma "{a, b} \<subseteq> labels t \<Longrightarrow> labels (swap t a b) = labels t"
 | 
| 
35671
 
ed2c3830d881
improved Nitpick's precision for "card" and "setsum" + fix incorrect outcome code w.r.t. "bisim_depth = -1"
 
blanchet 
parents: 
35665 
diff
changeset
 | 
323  | 
(* nitpick *)  | 
| 
34982
 
7b8c366e34a2
added support for nonstandard models to Nitpick (based on an idea by Koen Claessen) and did other fixes to Nitpick
 
blanchet 
parents: 
34126 
diff
changeset
 | 
324  | 
proof (induct t)  | 
| 
 
7b8c366e34a2
added support for nonstandard models to Nitpick (based on an idea by Koen Claessen) and did other fixes to Nitpick
 
blanchet 
parents: 
34126 
diff
changeset
 | 
325  | 
case Leaf thus ?case by simp  | 
| 
 
7b8c366e34a2
added support for nonstandard models to Nitpick (based on an idea by Koen Claessen) and did other fixes to Nitpick
 
blanchet 
parents: 
34126 
diff
changeset
 | 
326  | 
next  | 
| 
 
7b8c366e34a2
added support for nonstandard models to Nitpick (based on an idea by Koen Claessen) and did other fixes to Nitpick
 
blanchet 
parents: 
34126 
diff
changeset
 | 
327  | 
case (Branch t u) thus ?case  | 
| 
35671
 
ed2c3830d881
improved Nitpick's precision for "card" and "setsum" + fix incorrect outcome code w.r.t. "bisim_depth = -1"
 
blanchet 
parents: 
35665 
diff
changeset
 | 
328  | 
(* nitpick *)  | 
| 
 
ed2c3830d881
improved Nitpick's precision for "card" and "setsum" + fix incorrect outcome code w.r.t. "bisim_depth = -1"
 
blanchet 
parents: 
35665 
diff
changeset
 | 
329  | 
nitpick [non_std, show_all, expect = genuine]  | 
| 
34982
 
7b8c366e34a2
added support for nonstandard models to Nitpick (based on an idea by Koen Claessen) and did other fixes to Nitpick
 
blanchet 
parents: 
34126 
diff
changeset
 | 
330  | 
oops  | 
| 
 
7b8c366e34a2
added support for nonstandard models to Nitpick (based on an idea by Koen Claessen) and did other fixes to Nitpick
 
blanchet 
parents: 
34126 
diff
changeset
 | 
331  | 
|
| 
 
7b8c366e34a2
added support for nonstandard models to Nitpick (based on an idea by Koen Claessen) and did other fixes to Nitpick
 
blanchet 
parents: 
34126 
diff
changeset
 | 
332  | 
lemma "labels (swap t a b) =  | 
| 
 
7b8c366e34a2
added support for nonstandard models to Nitpick (based on an idea by Koen Claessen) and did other fixes to Nitpick
 
blanchet 
parents: 
34126 
diff
changeset
 | 
333  | 
(if a \<in> labels t then  | 
| 
 
7b8c366e34a2
added support for nonstandard models to Nitpick (based on an idea by Koen Claessen) and did other fixes to Nitpick
 
blanchet 
parents: 
34126 
diff
changeset
 | 
334  | 
          if b \<in> labels t then labels t else (labels t - {a}) \<union> {b}
 | 
| 
 
7b8c366e34a2
added support for nonstandard models to Nitpick (based on an idea by Koen Claessen) and did other fixes to Nitpick
 
blanchet 
parents: 
34126 
diff
changeset
 | 
335  | 
else  | 
| 
 
7b8c366e34a2
added support for nonstandard models to Nitpick (based on an idea by Koen Claessen) and did other fixes to Nitpick
 
blanchet 
parents: 
34126 
diff
changeset
 | 
336  | 
          if b \<in> labels t then (labels t - {b}) \<union> {a} else labels t)"
 | 
| 
35309
 
997aa3a3e4bb
catch IO errors in Nitpick's "kodkodi" invocation + shorten execution time of "Manual_Nits" example
 
blanchet 
parents: 
35284 
diff
changeset
 | 
337  | 
(* nitpick *)  | 
| 
34982
 
7b8c366e34a2
added support for nonstandard models to Nitpick (based on an idea by Koen Claessen) and did other fixes to Nitpick
 
blanchet 
parents: 
34126 
diff
changeset
 | 
338  | 
proof (induct t)  | 
| 
 
7b8c366e34a2
added support for nonstandard models to Nitpick (based on an idea by Koen Claessen) and did other fixes to Nitpick
 
blanchet 
parents: 
34126 
diff
changeset
 | 
339  | 
case Leaf thus ?case by simp  | 
| 
 
7b8c366e34a2
added support for nonstandard models to Nitpick (based on an idea by Koen Claessen) and did other fixes to Nitpick
 
blanchet 
parents: 
34126 
diff
changeset
 | 
340  | 
next  | 
| 
 
7b8c366e34a2
added support for nonstandard models to Nitpick (based on an idea by Koen Claessen) and did other fixes to Nitpick
 
blanchet 
parents: 
34126 
diff
changeset
 | 
341  | 
case (Branch t u) thus ?case  | 
| 42959 | 342  | 
nitpick [non_std, card = 1\<emdash>4, expect = none]  | 
| 
34982
 
7b8c366e34a2
added support for nonstandard models to Nitpick (based on an idea by Koen Claessen) and did other fixes to Nitpick
 
blanchet 
parents: 
34126 
diff
changeset
 | 
343  | 
by auto  | 
| 
 
7b8c366e34a2
added support for nonstandard models to Nitpick (based on an idea by Koen Claessen) and did other fixes to Nitpick
 
blanchet 
parents: 
34126 
diff
changeset
 | 
344  | 
qed  | 
| 
 
7b8c366e34a2
added support for nonstandard models to Nitpick (based on an idea by Koen Claessen) and did other fixes to Nitpick
 
blanchet 
parents: 
34126 
diff
changeset
 | 
345  | 
|
| 45053 | 346  | 
section {* 3. Case Studies *}
 | 
| 33197 | 347  | 
|
| 36268 | 348  | 
nitpick_params [max_potential = 0]  | 
| 33197 | 349  | 
|
| 45053 | 350  | 
subsection {* 3.1. A Context-Free Grammar *}
 | 
| 33197 | 351  | 
|
352  | 
datatype alphabet = a | b  | 
|
353  | 
||
354  | 
inductive_set S\<^isub>1 and A\<^isub>1 and B\<^isub>1 where  | 
|
355  | 
"[] \<in> S\<^isub>1"  | 
|
356  | 
| "w \<in> A\<^isub>1 \<Longrightarrow> b # w \<in> S\<^isub>1"  | 
|
357  | 
| "w \<in> B\<^isub>1 \<Longrightarrow> a # w \<in> S\<^isub>1"  | 
|
358  | 
| "w \<in> S\<^isub>1 \<Longrightarrow> a # w \<in> A\<^isub>1"  | 
|
359  | 
| "w \<in> S\<^isub>1 \<Longrightarrow> b # w \<in> S\<^isub>1"  | 
|
360  | 
| "\<lbrakk>v \<in> B\<^isub>1; v \<in> B\<^isub>1\<rbrakk> \<Longrightarrow> a # v @ w \<in> B\<^isub>1"  | 
|
361  | 
||
362  | 
theorem S\<^isub>1_sound:  | 
|
363  | 
"w \<in> S\<^isub>1 \<longrightarrow> length [x \<leftarrow> w. x = a] = length [x \<leftarrow> w. x = b]"  | 
|
| 
35671
 
ed2c3830d881
improved Nitpick's precision for "card" and "setsum" + fix incorrect outcome code w.r.t. "bisim_depth = -1"
 
blanchet 
parents: 
35665 
diff
changeset
 | 
364  | 
nitpick [expect = genuine]  | 
| 33197 | 365  | 
oops  | 
366  | 
||
367  | 
inductive_set S\<^isub>2 and A\<^isub>2 and B\<^isub>2 where  | 
|
368  | 
"[] \<in> S\<^isub>2"  | 
|
369  | 
| "w \<in> A\<^isub>2 \<Longrightarrow> b # w \<in> S\<^isub>2"  | 
|
370  | 
| "w \<in> B\<^isub>2 \<Longrightarrow> a # w \<in> S\<^isub>2"  | 
|
371  | 
| "w \<in> S\<^isub>2 \<Longrightarrow> a # w \<in> A\<^isub>2"  | 
|
372  | 
| "w \<in> S\<^isub>2 \<Longrightarrow> b # w \<in> B\<^isub>2"  | 
|
373  | 
| "\<lbrakk>v \<in> B\<^isub>2; v \<in> B\<^isub>2\<rbrakk> \<Longrightarrow> a # v @ w \<in> B\<^isub>2"  | 
|
374  | 
||
375  | 
theorem S\<^isub>2_sound:  | 
|
376  | 
"w \<in> S\<^isub>2 \<longrightarrow> length [x \<leftarrow> w. x = a] = length [x \<leftarrow> w. x = b]"  | 
|
| 
35671
 
ed2c3830d881
improved Nitpick's precision for "card" and "setsum" + fix incorrect outcome code w.r.t. "bisim_depth = -1"
 
blanchet 
parents: 
35665 
diff
changeset
 | 
377  | 
nitpick [expect = genuine]  | 
| 33197 | 378  | 
oops  | 
379  | 
||
380  | 
inductive_set S\<^isub>3 and A\<^isub>3 and B\<^isub>3 where  | 
|
381  | 
"[] \<in> S\<^isub>3"  | 
|
382  | 
| "w \<in> A\<^isub>3 \<Longrightarrow> b # w \<in> S\<^isub>3"  | 
|
383  | 
| "w \<in> B\<^isub>3 \<Longrightarrow> a # w \<in> S\<^isub>3"  | 
|
384  | 
| "w \<in> S\<^isub>3 \<Longrightarrow> a # w \<in> A\<^isub>3"  | 
|
385  | 
| "w \<in> S\<^isub>3 \<Longrightarrow> b # w \<in> B\<^isub>3"  | 
|
386  | 
| "\<lbrakk>v \<in> B\<^isub>3; w \<in> B\<^isub>3\<rbrakk> \<Longrightarrow> a # v @ w \<in> B\<^isub>3"  | 
|
387  | 
||
388  | 
theorem S\<^isub>3_sound:  | 
|
389  | 
"w \<in> S\<^isub>3 \<longrightarrow> length [x \<leftarrow> w. x = a] = length [x \<leftarrow> w. x = b]"  | 
|
| 42959 | 390  | 
nitpick [card = 1\<emdash>5, expect = none]  | 
| 33197 | 391  | 
sorry  | 
392  | 
||
393  | 
theorem S\<^isub>3_complete:  | 
|
394  | 
"length [x \<leftarrow> w. x = a] = length [x \<leftarrow> w. x = b] \<longrightarrow> w \<in> S\<^isub>3"  | 
|
| 
35671
 
ed2c3830d881
improved Nitpick's precision for "card" and "setsum" + fix incorrect outcome code w.r.t. "bisim_depth = -1"
 
blanchet 
parents: 
35665 
diff
changeset
 | 
395  | 
nitpick [expect = genuine]  | 
| 33197 | 396  | 
oops  | 
397  | 
||
398  | 
inductive_set S\<^isub>4 and A\<^isub>4 and B\<^isub>4 where  | 
|
399  | 
"[] \<in> S\<^isub>4"  | 
|
400  | 
| "w \<in> A\<^isub>4 \<Longrightarrow> b # w \<in> S\<^isub>4"  | 
|
401  | 
| "w \<in> B\<^isub>4 \<Longrightarrow> a # w \<in> S\<^isub>4"  | 
|
402  | 
| "w \<in> S\<^isub>4 \<Longrightarrow> a # w \<in> A\<^isub>4"  | 
|
403  | 
| "\<lbrakk>v \<in> A\<^isub>4; w \<in> A\<^isub>4\<rbrakk> \<Longrightarrow> b # v @ w \<in> A\<^isub>4"  | 
|
404  | 
| "w \<in> S\<^isub>4 \<Longrightarrow> b # w \<in> B\<^isub>4"  | 
|
405  | 
| "\<lbrakk>v \<in> B\<^isub>4; w \<in> B\<^isub>4\<rbrakk> \<Longrightarrow> a # v @ w \<in> B\<^isub>4"  | 
|
406  | 
||
407  | 
theorem S\<^isub>4_sound:  | 
|
408  | 
"w \<in> S\<^isub>4 \<longrightarrow> length [x \<leftarrow> w. x = a] = length [x \<leftarrow> w. x = b]"  | 
|
| 42959 | 409  | 
nitpick [card = 1\<emdash>5, expect = none]  | 
| 33197 | 410  | 
sorry  | 
411  | 
||
412  | 
theorem S\<^isub>4_complete:  | 
|
413  | 
"length [x \<leftarrow> w. x = a] = length [x \<leftarrow> w. x = b] \<longrightarrow> w \<in> S\<^isub>4"  | 
|
| 42959 | 414  | 
nitpick [card = 1\<emdash>5, expect = none]  | 
| 33197 | 415  | 
sorry  | 
416  | 
||
417  | 
theorem S\<^isub>4_A\<^isub>4_B\<^isub>4_sound_and_complete:  | 
|
418  | 
"w \<in> S\<^isub>4 \<longleftrightarrow> length [x \<leftarrow> w. x = a] = length [x \<leftarrow> w. x = b]"  | 
|
419  | 
"w \<in> A\<^isub>4 \<longleftrightarrow> length [x \<leftarrow> w. x = a] = length [x \<leftarrow> w. x = b] + 1"  | 
|
420  | 
"w \<in> B\<^isub>4 \<longleftrightarrow> length [x \<leftarrow> w. x = b] = length [x \<leftarrow> w. x = a] + 1"  | 
|
| 42959 | 421  | 
nitpick [card = 1\<emdash>5, expect = none]  | 
| 33197 | 422  | 
sorry  | 
423  | 
||
| 45053 | 424  | 
subsection {* 3.2. AA Trees *}
 | 
| 33197 | 425  | 
|
| 
34982
 
7b8c366e34a2
added support for nonstandard models to Nitpick (based on an idea by Koen Claessen) and did other fixes to Nitpick
 
blanchet 
parents: 
34126 
diff
changeset
 | 
426  | 
datatype 'a aa_tree = \<Lambda> | N "'a\<Colon>linorder" nat "'a aa_tree" "'a aa_tree"  | 
| 33197 | 427  | 
|
428  | 
primrec data where  | 
|
429  | 
"data \<Lambda> = undefined" |  | 
|
430  | 
"data (N x _ _ _) = x"  | 
|
431  | 
||
432  | 
primrec dataset where  | 
|
433  | 
"dataset \<Lambda> = {}" |
 | 
|
434  | 
"dataset (N x _ t u) = {x} \<union> dataset t \<union> dataset u"
 | 
|
435  | 
||
436  | 
primrec level where  | 
|
437  | 
"level \<Lambda> = 0" |  | 
|
438  | 
"level (N _ k _ _) = k"  | 
|
439  | 
||
440  | 
primrec left where  | 
|
441  | 
"left \<Lambda> = \<Lambda>" |  | 
|
442  | 
"left (N _ _ t\<^isub>1 _) = t\<^isub>1"  | 
|
443  | 
||
444  | 
primrec right where  | 
|
445  | 
"right \<Lambda> = \<Lambda>" |  | 
|
446  | 
"right (N _ _ _ t\<^isub>2) = t\<^isub>2"  | 
|
447  | 
||
448  | 
fun wf where  | 
|
449  | 
"wf \<Lambda> = True" |  | 
|
450  | 
"wf (N _ k t u) =  | 
|
451  | 
(if t = \<Lambda> then  | 
|
452  | 
k = 1 \<and> (u = \<Lambda> \<or> (level u = 1 \<and> left u = \<Lambda> \<and> right u = \<Lambda>))  | 
|
453  | 
else  | 
|
454  | 
wf t \<and> wf u \<and> u \<noteq> \<Lambda> \<and> level t < k \<and> level u \<le> k \<and> level (right u) < k)"  | 
|
455  | 
||
456  | 
fun skew where  | 
|
457  | 
"skew \<Lambda> = \<Lambda>" |  | 
|
458  | 
"skew (N x k t u) =  | 
|
459  | 
(if t \<noteq> \<Lambda> \<and> k = level t then  | 
|
460  | 
N (data t) k (left t) (N x k (right t) u)  | 
|
461  | 
else  | 
|
462  | 
N x k t u)"  | 
|
463  | 
||
464  | 
fun split where  | 
|
465  | 
"split \<Lambda> = \<Lambda>" |  | 
|
466  | 
"split (N x k t u) =  | 
|
467  | 
(if u \<noteq> \<Lambda> \<and> k = level (right u) then  | 
|
468  | 
N (data u) (Suc k) (N x k t (left u)) (right u)  | 
|
469  | 
else  | 
|
470  | 
N x k t u)"  | 
|
471  | 
||
472  | 
theorem dataset_skew_split:  | 
|
473  | 
"dataset (skew t) = dataset t"  | 
|
474  | 
"dataset (split t) = dataset t"  | 
|
| 42959 | 475  | 
nitpick [card = 1\<emdash>5, expect = none]  | 
| 33197 | 476  | 
sorry  | 
477  | 
||
478  | 
theorem wf_skew_split:  | 
|
479  | 
"wf t \<Longrightarrow> skew t = t"  | 
|
480  | 
"wf t \<Longrightarrow> split t = t"  | 
|
| 42959 | 481  | 
nitpick [card = 1\<emdash>5, expect = none]  | 
| 33197 | 482  | 
sorry  | 
483  | 
||
484  | 
primrec insort\<^isub>1 where  | 
|
485  | 
"insort\<^isub>1 \<Lambda> x = N x 1 \<Lambda> \<Lambda>" |  | 
|
486  | 
"insort\<^isub>1 (N y k t u) x =  | 
|
487  | 
(* (split \<circ> skew) *) (N y k (if x < y then insort\<^isub>1 t x else t)  | 
|
488  | 
(if x > y then insort\<^isub>1 u x else u))"  | 
|
489  | 
||
490  | 
theorem wf_insort\<^isub>1: "wf t \<Longrightarrow> wf (insort\<^isub>1 t x)"  | 
|
| 
35671
 
ed2c3830d881
improved Nitpick's precision for "card" and "setsum" + fix incorrect outcome code w.r.t. "bisim_depth = -1"
 
blanchet 
parents: 
35665 
diff
changeset
 | 
491  | 
nitpick [expect = genuine]  | 
| 33197 | 492  | 
oops  | 
493  | 
||
494  | 
theorem wf_insort\<^isub>1_nat: "wf t \<Longrightarrow> wf (insort\<^isub>1 t (x\<Colon>nat))"  | 
|
| 
35671
 
ed2c3830d881
improved Nitpick's precision for "card" and "setsum" + fix incorrect outcome code w.r.t. "bisim_depth = -1"
 
blanchet 
parents: 
35665 
diff
changeset
 | 
495  | 
nitpick [eval = "insort\<^isub>1 t x", expect = genuine]  | 
| 33197 | 496  | 
oops  | 
497  | 
||
498  | 
primrec insort\<^isub>2 where  | 
|
499  | 
"insort\<^isub>2 \<Lambda> x = N x 1 \<Lambda> \<Lambda>" |  | 
|
500  | 
"insort\<^isub>2 (N y k t u) x =  | 
|
501  | 
(split \<circ> skew) (N y k (if x < y then insort\<^isub>2 t x else t)  | 
|
502  | 
(if x > y then insort\<^isub>2 u x else u))"  | 
|
503  | 
||
504  | 
theorem wf_insort\<^isub>2: "wf t \<Longrightarrow> wf (insort\<^isub>2 t x)"  | 
|
| 42959 | 505  | 
nitpick [card = 1\<emdash>5, expect = none]  | 
| 33197 | 506  | 
sorry  | 
507  | 
||
508  | 
theorem dataset_insort\<^isub>2: "dataset (insort\<^isub>2 t x) = {x} \<union> dataset t"
 | 
|
| 42959 | 509  | 
nitpick [card = 1\<emdash>5, expect = none]  | 
| 33197 | 510  | 
sorry  | 
511  | 
||
512  | 
end  |