author | wenzelm |
Mon, 13 Aug 2007 18:10:24 +0200 | |
changeset 24247 | 9d0bb01f6634 |
parent 23767 | 7272a839ccd9 |
child 24345 | 86a3557a9ebb |
permissions | -rw-r--r-- |
13821
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
1 |
(* Title: HOL/UNITY/Transformers |
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
2 |
ID: $Id$ |
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
3 |
Author: Lawrence C Paulson, Cambridge University Computer Laboratory |
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
4 |
Copyright 2003 University of Cambridge |
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
5 |
|
13866 | 6 |
Predicate Transformers. From |
13821
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
7 |
|
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
8 |
David Meier and Beverly Sanders, |
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
9 |
Composing Leads-to Properties |
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
10 |
Theoretical Computer Science 243:1-2 (2000), 339-361. |
13866 | 11 |
|
12 |
David Meier, |
|
13 |
Progress Properties in Program Refinement and Parallel Composition |
|
14 |
Swiss Federal Institute of Technology Zurich (1997) |
|
13821
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
15 |
*) |
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
16 |
|
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
17 |
header{*Predicate Transformers*} |
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
18 |
|
16417 | 19 |
theory Transformers imports Comp begin |
13821
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
20 |
|
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
21 |
subsection{*Defining the Predicate Transformers @{term wp}, |
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
22 |
@{term awp} and @{term wens}*} |
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
23 |
|
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
24 |
constdefs |
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
25 |
wp :: "[('a*'a) set, 'a set] => 'a set" |
13832
e7649436869c
completed proofs for programs consisting of a single assignment
paulson
parents:
13821
diff
changeset
|
26 |
--{*Dijkstra's weakest-precondition operator (for an individual command)*} |
13821
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
27 |
"wp act B == - (act^-1 `` (-B))" |
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
28 |
|
13832
e7649436869c
completed proofs for programs consisting of a single assignment
paulson
parents:
13821
diff
changeset
|
29 |
awp :: "['a program, 'a set] => 'a set" |
e7649436869c
completed proofs for programs consisting of a single assignment
paulson
parents:
13821
diff
changeset
|
30 |
--{*Dijkstra's weakest-precondition operator (for a program)*} |
13821
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
31 |
"awp F B == (\<Inter>act \<in> Acts F. wp act B)" |
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
32 |
|
13832
e7649436869c
completed proofs for programs consisting of a single assignment
paulson
parents:
13821
diff
changeset
|
33 |
wens :: "['a program, ('a*'a) set, 'a set] => 'a set" |
e7649436869c
completed proofs for programs consisting of a single assignment
paulson
parents:
13821
diff
changeset
|
34 |
--{*The weakest-ensures transformer*} |
13821
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
35 |
"wens F act B == gfp(\<lambda>X. (wp act B \<inter> awp F (B \<union> X)) \<union> B)" |
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
36 |
|
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
37 |
text{*The fundamental theorem for wp*} |
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
38 |
theorem wp_iff: "(A <= wp act B) = (act `` A <= B)" |
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
39 |
by (force simp add: wp_def) |
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
40 |
|
13874 | 41 |
text{*This lemma is a good deal more intuitive than the definition!*} |
42 |
lemma in_wp_iff: "(a \<in> wp act B) = (\<forall>x. (a,x) \<in> act --> x \<in> B)" |
|
43 |
by (simp add: wp_def, blast) |
|
44 |
||
13821
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
45 |
lemma Compl_Domain_subset_wp: "- (Domain act) \<subseteq> wp act B" |
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
46 |
by (force simp add: wp_def) |
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
47 |
|
13832
e7649436869c
completed proofs for programs consisting of a single assignment
paulson
parents:
13821
diff
changeset
|
48 |
lemma wp_empty [simp]: "wp act {} = - (Domain act)" |
e7649436869c
completed proofs for programs consisting of a single assignment
paulson
parents:
13821
diff
changeset
|
49 |
by (force simp add: wp_def) |
e7649436869c
completed proofs for programs consisting of a single assignment
paulson
parents:
13821
diff
changeset
|
50 |
|
e7649436869c
completed proofs for programs consisting of a single assignment
paulson
parents:
13821
diff
changeset
|
51 |
text{*The identity relation is the skip action*} |
e7649436869c
completed proofs for programs consisting of a single assignment
paulson
parents:
13821
diff
changeset
|
52 |
lemma wp_Id [simp]: "wp Id B = B" |
e7649436869c
completed proofs for programs consisting of a single assignment
paulson
parents:
13821
diff
changeset
|
53 |
by (simp add: wp_def) |
e7649436869c
completed proofs for programs consisting of a single assignment
paulson
parents:
13821
diff
changeset
|
54 |
|
13851 | 55 |
lemma wp_totalize_act: |
56 |
"wp (totalize_act act) B = (wp act B \<inter> Domain act) \<union> (B - Domain act)" |
|
57 |
by (simp add: wp_def totalize_act_def, blast) |
|
58 |
||
13861 | 59 |
lemma awp_subset: "(awp F A \<subseteq> A)" |
60 |
by (force simp add: awp_def wp_def) |
|
61 |
||
13821
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
62 |
lemma awp_Int_eq: "awp F (A\<inter>B) = awp F A \<inter> awp F B" |
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
63 |
by (simp add: awp_def wp_def, blast) |
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
64 |
|
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
65 |
text{*The fundamental theorem for awp*} |
13861 | 66 |
theorem awp_iff_constrains: "(A <= awp F B) = (F \<in> A co B)" |
13821
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
67 |
by (simp add: awp_def constrains_def wp_iff INT_subset_iff) |
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
68 |
|
13861 | 69 |
lemma awp_iff_stable: "(A \<subseteq> awp F A) = (F \<in> stable A)" |
70 |
by (simp add: awp_iff_constrains stable_def) |
|
71 |
||
72 |
lemma stable_imp_awp_ident: "F \<in> stable A ==> awp F A = A" |
|
73 |
apply (rule equalityI [OF awp_subset]) |
|
74 |
apply (simp add: awp_iff_stable) |
|
75 |
done |
|
13821
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
76 |
|
13874 | 77 |
lemma wp_mono: "(A \<subseteq> B) ==> wp act A \<subseteq> wp act B" |
78 |
by (simp add: wp_def, blast) |
|
79 |
||
13821
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
80 |
lemma awp_mono: "(A \<subseteq> B) ==> awp F A \<subseteq> awp F B" |
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
81 |
by (simp add: awp_def wp_def, blast) |
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
82 |
|
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
83 |
lemma wens_unfold: |
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
84 |
"wens F act B = (wp act B \<inter> awp F (B \<union> wens F act B)) \<union> B" |
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
85 |
apply (simp add: wens_def) |
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
86 |
apply (rule gfp_unfold) |
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
87 |
apply (simp add: mono_def wp_def awp_def, blast) |
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
88 |
done |
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
89 |
|
13832
e7649436869c
completed proofs for programs consisting of a single assignment
paulson
parents:
13821
diff
changeset
|
90 |
lemma wens_Id [simp]: "wens F Id B = B" |
21312 | 91 |
by (simp add: wens_def gfp_def wp_def awp_def Sup_set_eq, blast) |
13832
e7649436869c
completed proofs for programs consisting of a single assignment
paulson
parents:
13821
diff
changeset
|
92 |
|
13821
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
93 |
text{*These two theorems justify the claim that @{term wens} returns the |
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
94 |
weakest assertion satisfying the ensures property*} |
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
95 |
lemma ensures_imp_wens: "F \<in> A ensures B ==> \<exists>act \<in> Acts F. A \<subseteq> wens F act B" |
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
96 |
apply (simp add: wens_def ensures_def transient_def, clarify) |
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
97 |
apply (rule rev_bexI, assumption) |
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
98 |
apply (rule gfp_upperbound) |
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
99 |
apply (simp add: constrains_def awp_def wp_def, blast) |
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
100 |
done |
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
101 |
|
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
102 |
lemma wens_ensures: "act \<in> Acts F ==> F \<in> (wens F act B) ensures B" |
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
103 |
by (simp add: wens_def gfp_def constrains_def awp_def wp_def |
21312 | 104 |
ensures_def transient_def Sup_set_eq, blast) |
13821
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
105 |
|
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
106 |
text{*These two results constitute assertion (4.13) of the thesis*} |
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
107 |
lemma wens_mono: "(A \<subseteq> B) ==> wens F act A \<subseteq> wens F act B" |
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
108 |
apply (simp add: wens_def wp_def awp_def) |
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
109 |
apply (rule gfp_mono, blast) |
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
110 |
done |
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
111 |
|
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
112 |
lemma wens_weakening: "B \<subseteq> wens F act B" |
21312 | 113 |
by (simp add: wens_def gfp_def Sup_set_eq, blast) |
13821
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
114 |
|
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
115 |
text{*Assertion (6), or 4.16 in the thesis*} |
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
116 |
lemma subset_wens: "A-B \<subseteq> wp act B \<inter> awp F (B \<union> A) ==> A \<subseteq> wens F act B" |
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
117 |
apply (simp add: wens_def wp_def awp_def) |
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
118 |
apply (rule gfp_upperbound, blast) |
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
119 |
done |
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
120 |
|
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
121 |
text{*Assertion 4.17 in the thesis*} |
21312 | 122 |
lemma Diff_wens_constrains: "F \<in> (wens F act A - A) co wens F act A" |
123 |
by (simp add: wens_def gfp_def wp_def awp_def constrains_def Sup_set_eq, blast) |
|
15102 | 124 |
--{*Proved instantly, yet remarkably fragile. If @{text Un_subset_iff} |
125 |
is declared as an iff-rule, then it's almost impossible to prove. |
|
126 |
One proof is via @{text meson} after expanding all definitions, but it's |
|
127 |
slow!*} |
|
13821
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
128 |
|
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
129 |
text{*Assertion (7): 4.18 in the thesis. NOTE that many of these results |
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
130 |
hold for an arbitrary action. We often do not require @{term "act \<in> Acts F"}*} |
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
131 |
lemma stable_wens: "F \<in> stable A ==> F \<in> stable (wens F act A)" |
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
132 |
apply (simp add: stable_def) |
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
133 |
apply (drule constrains_Un [OF Diff_wens_constrains [of F act A]]) |
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
134 |
apply (simp add: Un_Int_distrib2 Compl_partition2) |
13832
e7649436869c
completed proofs for programs consisting of a single assignment
paulson
parents:
13821
diff
changeset
|
135 |
apply (erule constrains_weaken, blast) |
13821
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
136 |
apply (simp add: Un_subset_iff wens_weakening) |
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
137 |
done |
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
138 |
|
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
139 |
text{*Assertion 4.20 in the thesis.*} |
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
140 |
lemma wens_Int_eq_lemma: |
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
141 |
"[|T-B \<subseteq> awp F T; act \<in> Acts F|] |
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
142 |
==> T \<inter> wens F act B \<subseteq> wens F act (T\<inter>B)" |
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
143 |
apply (rule subset_wens) |
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
144 |
apply (rule_tac P="\<lambda>x. ?f x \<subseteq> ?b" in ssubst [OF wens_unfold]) |
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
145 |
apply (simp add: wp_def awp_def, blast) |
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
146 |
done |
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
147 |
|
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
148 |
text{*Assertion (8): 4.21 in the thesis. Here we indeed require |
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
149 |
@{term "act \<in> Acts F"}*} |
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
150 |
lemma wens_Int_eq: |
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
151 |
"[|T-B \<subseteq> awp F T; act \<in> Acts F|] |
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
152 |
==> T \<inter> wens F act B = T \<inter> wens F act (T\<inter>B)" |
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
153 |
apply (rule equalityI) |
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
154 |
apply (simp_all add: Int_lower1 Int_subset_iff) |
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
155 |
apply (rule wens_Int_eq_lemma, assumption+) |
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
156 |
apply (rule subset_trans [OF _ wens_mono [of "T\<inter>B" B]], auto) |
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
157 |
done |
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
158 |
|
13832
e7649436869c
completed proofs for programs consisting of a single assignment
paulson
parents:
13821
diff
changeset
|
159 |
|
13821
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
160 |
subsection{*Defining the Weakest Ensures Set*} |
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
161 |
|
23767 | 162 |
inductive_set |
13821
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
163 |
wens_set :: "['a program, 'a set] => 'a set set" |
23767 | 164 |
for F :: "'a program" and B :: "'a set" |
165 |
where |
|
13821
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
166 |
|
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
167 |
Basis: "B \<in> wens_set F B" |
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
168 |
|
23767 | 169 |
| Wens: "[|X \<in> wens_set F B; act \<in> Acts F|] ==> wens F act X \<in> wens_set F B" |
13821
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
170 |
|
23767 | 171 |
| Union: "W \<noteq> {} ==> \<forall>U \<in> W. U \<in> wens_set F B ==> \<Union>W \<in> wens_set F B" |
13821
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
172 |
|
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
173 |
lemma wens_set_imp_co: "A \<in> wens_set F B ==> F \<in> (A-B) co A" |
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
174 |
apply (erule wens_set.induct) |
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
175 |
apply (simp add: constrains_def) |
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
176 |
apply (drule_tac act1=act and A1=X |
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
177 |
in constrains_Un [OF Diff_wens_constrains]) |
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
178 |
apply (erule constrains_weaken, blast) |
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
179 |
apply (simp add: Un_subset_iff wens_weakening) |
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
180 |
apply (rule constrains_weaken) |
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
181 |
apply (rule_tac I=W and A="\<lambda>v. v-B" and A'="\<lambda>v. v" in constrains_UN, blast+) |
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
182 |
done |
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
183 |
|
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
184 |
lemma wens_set_imp_leadsTo: "A \<in> wens_set F B ==> F \<in> A leadsTo B" |
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
185 |
apply (erule wens_set.induct) |
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
186 |
apply (rule leadsTo_refl) |
13832
e7649436869c
completed proofs for programs consisting of a single assignment
paulson
parents:
13821
diff
changeset
|
187 |
apply (blast intro: wens_ensures leadsTo_Trans) |
13821
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
188 |
apply (blast intro: leadsTo_Union) |
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
189 |
done |
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
190 |
|
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
191 |
lemma leadsTo_imp_wens_set: "F \<in> A leadsTo B ==> \<exists>C \<in> wens_set F B. A \<subseteq> C" |
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
192 |
apply (erule leadsTo_induct_pre) |
13861 | 193 |
apply (blast dest!: ensures_imp_wens intro: wens_set.Basis wens_set.Wens) |
194 |
apply (clarify, drule ensures_weaken_R, assumption) |
|
13821
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
195 |
apply (blast dest!: ensures_imp_wens intro: wens_set.Wens) |
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
196 |
apply (case_tac "S={}") |
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
197 |
apply (simp, blast intro: wens_set.Basis) |
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
198 |
apply (clarsimp dest!: bchoice simp: ball_conj_distrib Bex_def) |
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
199 |
apply (rule_tac x = "\<Union>{Z. \<exists>U\<in>S. Z = f U}" in exI) |
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
200 |
apply (blast intro: wens_set.Union) |
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
201 |
done |
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
202 |
|
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
203 |
text{*Assertion (9): 4.27 in the thesis.*} |
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
204 |
lemma leadsTo_iff_wens_set: "(F \<in> A leadsTo B) = (\<exists>C \<in> wens_set F B. A \<subseteq> C)" |
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
205 |
by (blast intro: leadsTo_imp_wens_set leadsTo_weaken_L wens_set_imp_leadsTo) |
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
206 |
|
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
207 |
text{*This is the result that requires the definition of @{term wens_set} to |
13832
e7649436869c
completed proofs for programs consisting of a single assignment
paulson
parents:
13821
diff
changeset
|
208 |
require @{term W} to be non-empty in the Unio case, for otherwise we should |
e7649436869c
completed proofs for programs consisting of a single assignment
paulson
parents:
13821
diff
changeset
|
209 |
always have @{term "{} \<in> wens_set F B"}.*} |
13821
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
210 |
lemma wens_set_imp_subset: "A \<in> wens_set F B ==> B \<subseteq> A" |
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
211 |
apply (erule wens_set.induct) |
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
212 |
apply (blast intro: wens_weakening [THEN subsetD])+ |
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
213 |
done |
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
214 |
|
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
215 |
|
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
216 |
subsection{*Properties Involving Program Union*} |
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
217 |
|
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
218 |
text{*Assertion (4.30) of thesis, reoriented*} |
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
219 |
lemma awp_Join_eq: "awp (F\<squnion>G) B = awp F B \<inter> awp G B" |
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
220 |
by (simp add: awp_def wp_def, blast) |
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
221 |
|
13861 | 222 |
lemma wens_subset: "wens F act B - B \<subseteq> wp act B \<inter> awp F (B \<union> wens F act B)" |
13821
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
223 |
by (subst wens_unfold, fast) |
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
224 |
|
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
225 |
text{*Assertion (4.31)*} |
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
226 |
lemma subset_wens_Join: |
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
227 |
"[|A = T \<inter> wens F act B; T-B \<subseteq> awp F T; A-B \<subseteq> awp G (A \<union> B)|] |
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
228 |
==> A \<subseteq> wens (F\<squnion>G) act B" |
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
229 |
apply (subgoal_tac "(T \<inter> wens F act B) - B \<subseteq> |
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
230 |
wp act B \<inter> awp F (B \<union> wens F act B) \<inter> awp F T") |
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
231 |
apply (rule subset_wens) |
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
232 |
apply (simp add: awp_Join_eq awp_Int_eq Int_subset_iff Un_commute) |
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
233 |
apply (simp add: awp_def wp_def, blast) |
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
234 |
apply (insert wens_subset [of F act B], blast) |
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
235 |
done |
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
236 |
|
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
237 |
text{*Assertion (4.32)*} |
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
238 |
lemma wens_Join_subset: "wens (F\<squnion>G) act B \<subseteq> wens F act B" |
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
239 |
apply (simp add: wens_def) |
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
240 |
apply (rule gfp_mono) |
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
241 |
apply (auto simp add: awp_Join_eq) |
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
242 |
done |
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
243 |
|
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
244 |
text{*Lemma, because the inductive step is just too messy.*} |
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
245 |
lemma wens_Union_inductive_step: |
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
246 |
assumes awpF: "T-B \<subseteq> awp F T" |
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
247 |
and awpG: "!!X. X \<in> wens_set F B ==> (T\<inter>X) - B \<subseteq> awp G (T\<inter>X)" |
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
248 |
shows "[|X \<in> wens_set F B; act \<in> Acts F; Y \<subseteq> X; T\<inter>X = T\<inter>Y|] |
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
249 |
==> wens (F\<squnion>G) act Y \<subseteq> wens F act X \<and> |
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
250 |
T \<inter> wens F act X = T \<inter> wens (F\<squnion>G) act Y" |
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
251 |
apply (subgoal_tac "wens (F\<squnion>G) act Y \<subseteq> wens F act X") |
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
252 |
prefer 2 |
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
253 |
apply (blast dest: wens_mono intro: wens_Join_subset [THEN subsetD], simp) |
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
254 |
apply (rule equalityI) |
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
255 |
prefer 2 apply blast |
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
256 |
apply (simp add: Int_lower1 Int_subset_iff) |
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
257 |
apply (frule wens_set_imp_subset) |
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
258 |
apply (subgoal_tac "T-X \<subseteq> awp F T") |
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
259 |
prefer 2 apply (blast intro: awpF [THEN subsetD]) |
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
260 |
apply (rule_tac B = "wens (F\<squnion>G) act (T\<inter>X)" in subset_trans) |
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
261 |
prefer 2 apply (blast intro!: wens_mono) |
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
262 |
apply (subst wens_Int_eq, assumption+) |
13861 | 263 |
apply (rule subset_wens_Join [of _ T], simp, blast) |
13821
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
264 |
apply (subgoal_tac "T \<inter> wens F act (T\<inter>X) \<union> T\<inter>X = T \<inter> wens F act X") |
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
265 |
prefer 2 |
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
266 |
apply (subst wens_Int_eq [symmetric], assumption+) |
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
267 |
apply (blast intro: wens_weakening [THEN subsetD], simp) |
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
268 |
apply (blast intro: awpG [THEN subsetD] wens_set.Wens) |
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
269 |
done |
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
270 |
|
13832
e7649436869c
completed proofs for programs consisting of a single assignment
paulson
parents:
13821
diff
changeset
|
271 |
theorem wens_Union: |
13821
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
272 |
assumes awpF: "T-B \<subseteq> awp F T" |
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
273 |
and awpG: "!!X. X \<in> wens_set F B ==> (T\<inter>X) - B \<subseteq> awp G (T\<inter>X)" |
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
274 |
and major: "X \<in> wens_set F B" |
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
275 |
shows "\<exists>Y \<in> wens_set (F\<squnion>G) B. Y \<subseteq> X & T\<inter>X = T\<inter>Y" |
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
276 |
apply (rule wens_set.induct [OF major]) |
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
277 |
txt{*Basis: trivial*} |
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
278 |
apply (blast intro: wens_set.Basis) |
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
279 |
txt{*Inductive step*} |
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
280 |
apply clarify |
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
281 |
apply (rule_tac x = "wens (F\<squnion>G) act Y" in rev_bexI) |
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
282 |
apply (force intro: wens_set.Wens) |
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
283 |
apply (simp add: wens_Union_inductive_step [OF awpF awpG]) |
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
284 |
txt{*Union: by Axiom of Choice*} |
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
285 |
apply (simp add: ball_conj_distrib Bex_def) |
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
286 |
apply (clarify dest!: bchoice) |
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
287 |
apply (rule_tac x = "\<Union>{Z. \<exists>U\<in>W. Z = f U}" in exI) |
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
288 |
apply (blast intro: wens_set.Union) |
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
289 |
done |
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
290 |
|
13866 | 291 |
theorem leadsTo_Join: |
292 |
assumes leadsTo: "F \<in> A leadsTo B" |
|
293 |
and awpF: "T-B \<subseteq> awp F T" |
|
13832
e7649436869c
completed proofs for programs consisting of a single assignment
paulson
parents:
13821
diff
changeset
|
294 |
and awpG: "!!X. X \<in> wens_set F B ==> (T\<inter>X) - B \<subseteq> awp G (T\<inter>X)" |
e7649436869c
completed proofs for programs consisting of a single assignment
paulson
parents:
13821
diff
changeset
|
295 |
shows "F\<squnion>G \<in> T\<inter>A leadsTo B" |
e7649436869c
completed proofs for programs consisting of a single assignment
paulson
parents:
13821
diff
changeset
|
296 |
apply (rule leadsTo [THEN leadsTo_imp_wens_set, THEN bexE]) |
e7649436869c
completed proofs for programs consisting of a single assignment
paulson
parents:
13821
diff
changeset
|
297 |
apply (rule wens_Union [THEN bexE]) |
e7649436869c
completed proofs for programs consisting of a single assignment
paulson
parents:
13821
diff
changeset
|
298 |
apply (rule awpF) |
13851 | 299 |
apply (erule awpG, assumption) |
13832
e7649436869c
completed proofs for programs consisting of a single assignment
paulson
parents:
13821
diff
changeset
|
300 |
apply (blast intro: wens_set_imp_leadsTo [THEN leadsTo_weaken_L]) |
e7649436869c
completed proofs for programs consisting of a single assignment
paulson
parents:
13821
diff
changeset
|
301 |
done |
e7649436869c
completed proofs for programs consisting of a single assignment
paulson
parents:
13821
diff
changeset
|
302 |
|
e7649436869c
completed proofs for programs consisting of a single assignment
paulson
parents:
13821
diff
changeset
|
303 |
|
e7649436869c
completed proofs for programs consisting of a single assignment
paulson
parents:
13821
diff
changeset
|
304 |
subsection {*The Set @{term "wens_set F B"} for a Single-Assignment Program*} |
e7649436869c
completed proofs for programs consisting of a single assignment
paulson
parents:
13821
diff
changeset
|
305 |
text{*Thesis Section 4.3.3*} |
e7649436869c
completed proofs for programs consisting of a single assignment
paulson
parents:
13821
diff
changeset
|
306 |
|
e7649436869c
completed proofs for programs consisting of a single assignment
paulson
parents:
13821
diff
changeset
|
307 |
text{*We start by proving laws about single-assignment programs*} |
e7649436869c
completed proofs for programs consisting of a single assignment
paulson
parents:
13821
diff
changeset
|
308 |
lemma awp_single_eq [simp]: |
e7649436869c
completed proofs for programs consisting of a single assignment
paulson
parents:
13821
diff
changeset
|
309 |
"awp (mk_program (init, {act}, allowed)) B = B \<inter> wp act B" |
e7649436869c
completed proofs for programs consisting of a single assignment
paulson
parents:
13821
diff
changeset
|
310 |
by (force simp add: awp_def wp_def) |
e7649436869c
completed proofs for programs consisting of a single assignment
paulson
parents:
13821
diff
changeset
|
311 |
|
e7649436869c
completed proofs for programs consisting of a single assignment
paulson
parents:
13821
diff
changeset
|
312 |
lemma wp_Un_subset: "wp act A \<union> wp act B \<subseteq> wp act (A \<union> B)" |
e7649436869c
completed proofs for programs consisting of a single assignment
paulson
parents:
13821
diff
changeset
|
313 |
by (force simp add: wp_def) |
e7649436869c
completed proofs for programs consisting of a single assignment
paulson
parents:
13821
diff
changeset
|
314 |
|
e7649436869c
completed proofs for programs consisting of a single assignment
paulson
parents:
13821
diff
changeset
|
315 |
lemma wp_Un_eq: "single_valued act ==> wp act (A \<union> B) = wp act A \<union> wp act B" |
e7649436869c
completed proofs for programs consisting of a single assignment
paulson
parents:
13821
diff
changeset
|
316 |
apply (rule equalityI) |
e7649436869c
completed proofs for programs consisting of a single assignment
paulson
parents:
13821
diff
changeset
|
317 |
apply (force simp add: wp_def single_valued_def) |
e7649436869c
completed proofs for programs consisting of a single assignment
paulson
parents:
13821
diff
changeset
|
318 |
apply (rule wp_Un_subset) |
e7649436869c
completed proofs for programs consisting of a single assignment
paulson
parents:
13821
diff
changeset
|
319 |
done |
e7649436869c
completed proofs for programs consisting of a single assignment
paulson
parents:
13821
diff
changeset
|
320 |
|
e7649436869c
completed proofs for programs consisting of a single assignment
paulson
parents:
13821
diff
changeset
|
321 |
lemma wp_UN_subset: "(\<Union>i\<in>I. wp act (A i)) \<subseteq> wp act (\<Union>i\<in>I. A i)" |
e7649436869c
completed proofs for programs consisting of a single assignment
paulson
parents:
13821
diff
changeset
|
322 |
by (force simp add: wp_def) |
e7649436869c
completed proofs for programs consisting of a single assignment
paulson
parents:
13821
diff
changeset
|
323 |
|
e7649436869c
completed proofs for programs consisting of a single assignment
paulson
parents:
13821
diff
changeset
|
324 |
lemma wp_UN_eq: |
e7649436869c
completed proofs for programs consisting of a single assignment
paulson
parents:
13821
diff
changeset
|
325 |
"[|single_valued act; I\<noteq>{}|] |
e7649436869c
completed proofs for programs consisting of a single assignment
paulson
parents:
13821
diff
changeset
|
326 |
==> wp act (\<Union>i\<in>I. A i) = (\<Union>i\<in>I. wp act (A i))" |
e7649436869c
completed proofs for programs consisting of a single assignment
paulson
parents:
13821
diff
changeset
|
327 |
apply (rule equalityI) |
e7649436869c
completed proofs for programs consisting of a single assignment
paulson
parents:
13821
diff
changeset
|
328 |
prefer 2 apply (rule wp_UN_subset) |
e7649436869c
completed proofs for programs consisting of a single assignment
paulson
parents:
13821
diff
changeset
|
329 |
apply (simp add: wp_def Image_INT_eq) |
e7649436869c
completed proofs for programs consisting of a single assignment
paulson
parents:
13821
diff
changeset
|
330 |
done |
e7649436869c
completed proofs for programs consisting of a single assignment
paulson
parents:
13821
diff
changeset
|
331 |
|
e7649436869c
completed proofs for programs consisting of a single assignment
paulson
parents:
13821
diff
changeset
|
332 |
lemma wens_single_eq: |
e7649436869c
completed proofs for programs consisting of a single assignment
paulson
parents:
13821
diff
changeset
|
333 |
"wens (mk_program (init, {act}, allowed)) act B = B \<union> wp act B" |
21312 | 334 |
by (simp add: wens_def gfp_def wp_def Sup_set_eq, blast) |
13832
e7649436869c
completed proofs for programs consisting of a single assignment
paulson
parents:
13821
diff
changeset
|
335 |
|
e7649436869c
completed proofs for programs consisting of a single assignment
paulson
parents:
13821
diff
changeset
|
336 |
|
e7649436869c
completed proofs for programs consisting of a single assignment
paulson
parents:
13821
diff
changeset
|
337 |
text{*Next, we express the @{term "wens_set"} for single-assignment programs*} |
e7649436869c
completed proofs for programs consisting of a single assignment
paulson
parents:
13821
diff
changeset
|
338 |
|
e7649436869c
completed proofs for programs consisting of a single assignment
paulson
parents:
13821
diff
changeset
|
339 |
constdefs |
e7649436869c
completed proofs for programs consisting of a single assignment
paulson
parents:
13821
diff
changeset
|
340 |
wens_single_finite :: "[('a*'a) set, 'a set, nat] => 'a set" |
e7649436869c
completed proofs for programs consisting of a single assignment
paulson
parents:
13821
diff
changeset
|
341 |
"wens_single_finite act B k == \<Union>i \<in> atMost k. ((wp act)^i) B" |
e7649436869c
completed proofs for programs consisting of a single assignment
paulson
parents:
13821
diff
changeset
|
342 |
|
e7649436869c
completed proofs for programs consisting of a single assignment
paulson
parents:
13821
diff
changeset
|
343 |
wens_single :: "[('a*'a) set, 'a set] => 'a set" |
e7649436869c
completed proofs for programs consisting of a single assignment
paulson
parents:
13821
diff
changeset
|
344 |
"wens_single act B == \<Union>i. ((wp act)^i) B" |
e7649436869c
completed proofs for programs consisting of a single assignment
paulson
parents:
13821
diff
changeset
|
345 |
|
e7649436869c
completed proofs for programs consisting of a single assignment
paulson
parents:
13821
diff
changeset
|
346 |
lemma wens_single_Un_eq: |
e7649436869c
completed proofs for programs consisting of a single assignment
paulson
parents:
13821
diff
changeset
|
347 |
"single_valued act |
e7649436869c
completed proofs for programs consisting of a single assignment
paulson
parents:
13821
diff
changeset
|
348 |
==> wens_single act B \<union> wp act (wens_single act B) = wens_single act B" |
e7649436869c
completed proofs for programs consisting of a single assignment
paulson
parents:
13821
diff
changeset
|
349 |
apply (rule equalityI) |
e7649436869c
completed proofs for programs consisting of a single assignment
paulson
parents:
13821
diff
changeset
|
350 |
apply (simp_all add: Un_upper1 Un_subset_iff) |
e7649436869c
completed proofs for programs consisting of a single assignment
paulson
parents:
13821
diff
changeset
|
351 |
apply (simp add: wens_single_def wp_UN_eq, clarify) |
e7649436869c
completed proofs for programs consisting of a single assignment
paulson
parents:
13821
diff
changeset
|
352 |
apply (rule_tac a="Suc(i)" in UN_I, auto) |
e7649436869c
completed proofs for programs consisting of a single assignment
paulson
parents:
13821
diff
changeset
|
353 |
done |
e7649436869c
completed proofs for programs consisting of a single assignment
paulson
parents:
13821
diff
changeset
|
354 |
|
e7649436869c
completed proofs for programs consisting of a single assignment
paulson
parents:
13821
diff
changeset
|
355 |
lemma atMost_nat_nonempty: "atMost (k::nat) \<noteq> {}" |
e7649436869c
completed proofs for programs consisting of a single assignment
paulson
parents:
13821
diff
changeset
|
356 |
by force |
e7649436869c
completed proofs for programs consisting of a single assignment
paulson
parents:
13821
diff
changeset
|
357 |
|
13851 | 358 |
lemma wens_single_finite_0 [simp]: "wens_single_finite act B 0 = B" |
359 |
by (simp add: wens_single_finite_def) |
|
360 |
||
13832
e7649436869c
completed proofs for programs consisting of a single assignment
paulson
parents:
13821
diff
changeset
|
361 |
lemma wens_single_finite_Suc: |
e7649436869c
completed proofs for programs consisting of a single assignment
paulson
parents:
13821
diff
changeset
|
362 |
"single_valued act |
e7649436869c
completed proofs for programs consisting of a single assignment
paulson
parents:
13821
diff
changeset
|
363 |
==> wens_single_finite act B (Suc k) = |
13851 | 364 |
wens_single_finite act B k \<union> wp act (wens_single_finite act B k)" |
13832
e7649436869c
completed proofs for programs consisting of a single assignment
paulson
parents:
13821
diff
changeset
|
365 |
apply (simp add: wens_single_finite_def image_def |
e7649436869c
completed proofs for programs consisting of a single assignment
paulson
parents:
13821
diff
changeset
|
366 |
wp_UN_eq [OF _ atMost_nat_nonempty]) |
e7649436869c
completed proofs for programs consisting of a single assignment
paulson
parents:
13821
diff
changeset
|
367 |
apply (force elim!: le_SucE) |
e7649436869c
completed proofs for programs consisting of a single assignment
paulson
parents:
13821
diff
changeset
|
368 |
done |
e7649436869c
completed proofs for programs consisting of a single assignment
paulson
parents:
13821
diff
changeset
|
369 |
|
e7649436869c
completed proofs for programs consisting of a single assignment
paulson
parents:
13821
diff
changeset
|
370 |
lemma wens_single_finite_Suc_eq_wens: |
e7649436869c
completed proofs for programs consisting of a single assignment
paulson
parents:
13821
diff
changeset
|
371 |
"single_valued act |
e7649436869c
completed proofs for programs consisting of a single assignment
paulson
parents:
13821
diff
changeset
|
372 |
==> wens_single_finite act B (Suc k) = |
e7649436869c
completed proofs for programs consisting of a single assignment
paulson
parents:
13821
diff
changeset
|
373 |
wens (mk_program (init, {act}, allowed)) act |
e7649436869c
completed proofs for programs consisting of a single assignment
paulson
parents:
13821
diff
changeset
|
374 |
(wens_single_finite act B k)" |
e7649436869c
completed proofs for programs consisting of a single assignment
paulson
parents:
13821
diff
changeset
|
375 |
by (simp add: wens_single_finite_Suc wens_single_eq) |
e7649436869c
completed proofs for programs consisting of a single assignment
paulson
parents:
13821
diff
changeset
|
376 |
|
13851 | 377 |
lemma def_wens_single_finite_Suc_eq_wens: |
378 |
"[|F = mk_program (init, {act}, allowed); single_valued act|] |
|
379 |
==> wens_single_finite act B (Suc k) = |
|
380 |
wens F act (wens_single_finite act B k)" |
|
381 |
by (simp add: wens_single_finite_Suc_eq_wens) |
|
382 |
||
13832
e7649436869c
completed proofs for programs consisting of a single assignment
paulson
parents:
13821
diff
changeset
|
383 |
lemma wens_single_finite_Un_eq: |
e7649436869c
completed proofs for programs consisting of a single assignment
paulson
parents:
13821
diff
changeset
|
384 |
"single_valued act |
e7649436869c
completed proofs for programs consisting of a single assignment
paulson
parents:
13821
diff
changeset
|
385 |
==> wens_single_finite act B k \<union> wp act (wens_single_finite act B k) |
e7649436869c
completed proofs for programs consisting of a single assignment
paulson
parents:
13821
diff
changeset
|
386 |
\<in> range (wens_single_finite act B)" |
e7649436869c
completed proofs for programs consisting of a single assignment
paulson
parents:
13821
diff
changeset
|
387 |
by (simp add: wens_single_finite_Suc [symmetric]) |
e7649436869c
completed proofs for programs consisting of a single assignment
paulson
parents:
13821
diff
changeset
|
388 |
|
e7649436869c
completed proofs for programs consisting of a single assignment
paulson
parents:
13821
diff
changeset
|
389 |
lemma wens_single_eq_Union: |
e7649436869c
completed proofs for programs consisting of a single assignment
paulson
parents:
13821
diff
changeset
|
390 |
"wens_single act B = \<Union>range (wens_single_finite act B)" |
e7649436869c
completed proofs for programs consisting of a single assignment
paulson
parents:
13821
diff
changeset
|
391 |
by (simp add: wens_single_finite_def wens_single_def, blast) |
e7649436869c
completed proofs for programs consisting of a single assignment
paulson
parents:
13821
diff
changeset
|
392 |
|
e7649436869c
completed proofs for programs consisting of a single assignment
paulson
parents:
13821
diff
changeset
|
393 |
lemma wens_single_finite_eq_Union: |
e7649436869c
completed proofs for programs consisting of a single assignment
paulson
parents:
13821
diff
changeset
|
394 |
"wens_single_finite act B n = (\<Union>k\<in>atMost n. wens_single_finite act B k)" |
e7649436869c
completed proofs for programs consisting of a single assignment
paulson
parents:
13821
diff
changeset
|
395 |
apply (auto simp add: wens_single_finite_def) |
e7649436869c
completed proofs for programs consisting of a single assignment
paulson
parents:
13821
diff
changeset
|
396 |
apply (blast intro: le_trans) |
e7649436869c
completed proofs for programs consisting of a single assignment
paulson
parents:
13821
diff
changeset
|
397 |
done |
e7649436869c
completed proofs for programs consisting of a single assignment
paulson
parents:
13821
diff
changeset
|
398 |
|
e7649436869c
completed proofs for programs consisting of a single assignment
paulson
parents:
13821
diff
changeset
|
399 |
lemma wens_single_finite_mono: |
e7649436869c
completed proofs for programs consisting of a single assignment
paulson
parents:
13821
diff
changeset
|
400 |
"m \<le> n ==> wens_single_finite act B m \<subseteq> wens_single_finite act B n" |
e7649436869c
completed proofs for programs consisting of a single assignment
paulson
parents:
13821
diff
changeset
|
401 |
by (force simp add: wens_single_finite_eq_Union [of act B n]) |
e7649436869c
completed proofs for programs consisting of a single assignment
paulson
parents:
13821
diff
changeset
|
402 |
|
e7649436869c
completed proofs for programs consisting of a single assignment
paulson
parents:
13821
diff
changeset
|
403 |
lemma wens_single_finite_subset_wens_single: |
e7649436869c
completed proofs for programs consisting of a single assignment
paulson
parents:
13821
diff
changeset
|
404 |
"wens_single_finite act B k \<subseteq> wens_single act B" |
15236
f289e8ba2bb3
Proofs needed to be updated because induction now preserves name of
nipkow
parents:
15102
diff
changeset
|
405 |
by (simp add: wens_single_eq_Union, blast) |
13832
e7649436869c
completed proofs for programs consisting of a single assignment
paulson
parents:
13821
diff
changeset
|
406 |
|
e7649436869c
completed proofs for programs consisting of a single assignment
paulson
parents:
13821
diff
changeset
|
407 |
lemma subset_wens_single_finite: |
e7649436869c
completed proofs for programs consisting of a single assignment
paulson
parents:
13821
diff
changeset
|
408 |
"[|W \<subseteq> wens_single_finite act B ` (atMost k); single_valued act; W\<noteq>{}|] |
e7649436869c
completed proofs for programs consisting of a single assignment
paulson
parents:
13821
diff
changeset
|
409 |
==> \<exists>m. \<Union>W = wens_single_finite act B m" |
13851 | 410 |
apply (induct k) |
15236
f289e8ba2bb3
Proofs needed to be updated because induction now preserves name of
nipkow
parents:
15102
diff
changeset
|
411 |
apply (rule_tac x=0 in exI, simp, blast) |
f289e8ba2bb3
Proofs needed to be updated because induction now preserves name of
nipkow
parents:
15102
diff
changeset
|
412 |
apply (auto simp add: atMost_Suc) |
f289e8ba2bb3
Proofs needed to be updated because induction now preserves name of
nipkow
parents:
15102
diff
changeset
|
413 |
apply (case_tac "wens_single_finite act B (Suc k) \<in> W") |
f289e8ba2bb3
Proofs needed to be updated because induction now preserves name of
nipkow
parents:
15102
diff
changeset
|
414 |
prefer 2 apply blast |
f289e8ba2bb3
Proofs needed to be updated because induction now preserves name of
nipkow
parents:
15102
diff
changeset
|
415 |
apply (drule_tac x="Suc k" in spec) |
13832
e7649436869c
completed proofs for programs consisting of a single assignment
paulson
parents:
13821
diff
changeset
|
416 |
apply (erule notE, rule equalityI) |
15236
f289e8ba2bb3
Proofs needed to be updated because induction now preserves name of
nipkow
parents:
15102
diff
changeset
|
417 |
prefer 2 apply blast |
f289e8ba2bb3
Proofs needed to be updated because induction now preserves name of
nipkow
parents:
15102
diff
changeset
|
418 |
apply (subst wens_single_finite_eq_Union) |
f289e8ba2bb3
Proofs needed to be updated because induction now preserves name of
nipkow
parents:
15102
diff
changeset
|
419 |
apply (simp add: atMost_Suc, blast) |
13832
e7649436869c
completed proofs for programs consisting of a single assignment
paulson
parents:
13821
diff
changeset
|
420 |
done |
e7649436869c
completed proofs for programs consisting of a single assignment
paulson
parents:
13821
diff
changeset
|
421 |
|
e7649436869c
completed proofs for programs consisting of a single assignment
paulson
parents:
13821
diff
changeset
|
422 |
text{*lemma for Union case*} |
e7649436869c
completed proofs for programs consisting of a single assignment
paulson
parents:
13821
diff
changeset
|
423 |
lemma Union_eq_wens_single: |
e7649436869c
completed proofs for programs consisting of a single assignment
paulson
parents:
13821
diff
changeset
|
424 |
"\<lbrakk>\<forall>k. \<not> W \<subseteq> wens_single_finite act B ` {..k}; |
e7649436869c
completed proofs for programs consisting of a single assignment
paulson
parents:
13821
diff
changeset
|
425 |
W \<subseteq> insert (wens_single act B) |
e7649436869c
completed proofs for programs consisting of a single assignment
paulson
parents:
13821
diff
changeset
|
426 |
(range (wens_single_finite act B))\<rbrakk> |
e7649436869c
completed proofs for programs consisting of a single assignment
paulson
parents:
13821
diff
changeset
|
427 |
\<Longrightarrow> \<Union>W = wens_single act B" |
e7649436869c
completed proofs for programs consisting of a single assignment
paulson
parents:
13821
diff
changeset
|
428 |
apply (case_tac "wens_single act B \<in> W") |
e7649436869c
completed proofs for programs consisting of a single assignment
paulson
parents:
13821
diff
changeset
|
429 |
apply (blast dest: wens_single_finite_subset_wens_single [THEN subsetD]) |
e7649436869c
completed proofs for programs consisting of a single assignment
paulson
parents:
13821
diff
changeset
|
430 |
apply (simp add: wens_single_eq_Union) |
13851 | 431 |
apply (rule equalityI, blast) |
13832
e7649436869c
completed proofs for programs consisting of a single assignment
paulson
parents:
13821
diff
changeset
|
432 |
apply (simp add: UN_subset_iff, clarify) |
e7649436869c
completed proofs for programs consisting of a single assignment
paulson
parents:
13821
diff
changeset
|
433 |
apply (subgoal_tac "\<exists>y\<in>W. \<exists>n. y = wens_single_finite act B n & i\<le>n") |
13851 | 434 |
apply (blast intro: wens_single_finite_mono [THEN subsetD]) |
13832
e7649436869c
completed proofs for programs consisting of a single assignment
paulson
parents:
13821
diff
changeset
|
435 |
apply (drule_tac x=i in spec) |
e7649436869c
completed proofs for programs consisting of a single assignment
paulson
parents:
13821
diff
changeset
|
436 |
apply (force simp add: atMost_def) |
e7649436869c
completed proofs for programs consisting of a single assignment
paulson
parents:
13821
diff
changeset
|
437 |
done |
e7649436869c
completed proofs for programs consisting of a single assignment
paulson
parents:
13821
diff
changeset
|
438 |
|
e7649436869c
completed proofs for programs consisting of a single assignment
paulson
parents:
13821
diff
changeset
|
439 |
lemma wens_set_subset_single: |
e7649436869c
completed proofs for programs consisting of a single assignment
paulson
parents:
13821
diff
changeset
|
440 |
"single_valued act |
e7649436869c
completed proofs for programs consisting of a single assignment
paulson
parents:
13821
diff
changeset
|
441 |
==> wens_set (mk_program (init, {act}, allowed)) B \<subseteq> |
e7649436869c
completed proofs for programs consisting of a single assignment
paulson
parents:
13821
diff
changeset
|
442 |
insert (wens_single act B) (range (wens_single_finite act B))" |
e7649436869c
completed proofs for programs consisting of a single assignment
paulson
parents:
13821
diff
changeset
|
443 |
apply (rule subsetI) |
e7649436869c
completed proofs for programs consisting of a single assignment
paulson
parents:
13821
diff
changeset
|
444 |
apply (erule wens_set.induct) |
e7649436869c
completed proofs for programs consisting of a single assignment
paulson
parents:
13821
diff
changeset
|
445 |
txt{*Basis*} |
21733 | 446 |
apply (fastsimp simp add: wens_single_finite_def) |
13832
e7649436869c
completed proofs for programs consisting of a single assignment
paulson
parents:
13821
diff
changeset
|
447 |
txt{*Wens inductive step*} |
21733 | 448 |
apply (case_tac "acta = Id", simp) |
13832
e7649436869c
completed proofs for programs consisting of a single assignment
paulson
parents:
13821
diff
changeset
|
449 |
apply (simp add: wens_single_eq) |
21733 | 450 |
apply (elim disjE) |
13832
e7649436869c
completed proofs for programs consisting of a single assignment
paulson
parents:
13821
diff
changeset
|
451 |
apply (simp add: wens_single_Un_eq) |
e7649436869c
completed proofs for programs consisting of a single assignment
paulson
parents:
13821
diff
changeset
|
452 |
apply (force simp add: wens_single_finite_Un_eq) |
e7649436869c
completed proofs for programs consisting of a single assignment
paulson
parents:
13821
diff
changeset
|
453 |
txt{*Union inductive step*} |
e7649436869c
completed proofs for programs consisting of a single assignment
paulson
parents:
13821
diff
changeset
|
454 |
apply (case_tac "\<exists>k. W \<subseteq> wens_single_finite act B ` (atMost k)") |
e7649436869c
completed proofs for programs consisting of a single assignment
paulson
parents:
13821
diff
changeset
|
455 |
apply (blast dest!: subset_wens_single_finite, simp) |
e7649436869c
completed proofs for programs consisting of a single assignment
paulson
parents:
13821
diff
changeset
|
456 |
apply (rule disjI1 [OF Union_eq_wens_single], blast+) |
e7649436869c
completed proofs for programs consisting of a single assignment
paulson
parents:
13821
diff
changeset
|
457 |
done |
e7649436869c
completed proofs for programs consisting of a single assignment
paulson
parents:
13821
diff
changeset
|
458 |
|
e7649436869c
completed proofs for programs consisting of a single assignment
paulson
parents:
13821
diff
changeset
|
459 |
lemma wens_single_finite_in_wens_set: |
e7649436869c
completed proofs for programs consisting of a single assignment
paulson
parents:
13821
diff
changeset
|
460 |
"single_valued act \<Longrightarrow> |
e7649436869c
completed proofs for programs consisting of a single assignment
paulson
parents:
13821
diff
changeset
|
461 |
wens_single_finite act B k |
e7649436869c
completed proofs for programs consisting of a single assignment
paulson
parents:
13821
diff
changeset
|
462 |
\<in> wens_set (mk_program (init, {act}, allowed)) B" |
e7649436869c
completed proofs for programs consisting of a single assignment
paulson
parents:
13821
diff
changeset
|
463 |
apply (induct_tac k) |
e7649436869c
completed proofs for programs consisting of a single assignment
paulson
parents:
13821
diff
changeset
|
464 |
apply (simp add: wens_single_finite_def wens_set.Basis) |
e7649436869c
completed proofs for programs consisting of a single assignment
paulson
parents:
13821
diff
changeset
|
465 |
apply (simp add: wens_set.Wens |
e7649436869c
completed proofs for programs consisting of a single assignment
paulson
parents:
13821
diff
changeset
|
466 |
wens_single_finite_Suc_eq_wens [of act B _ init allowed]) |
e7649436869c
completed proofs for programs consisting of a single assignment
paulson
parents:
13821
diff
changeset
|
467 |
done |
e7649436869c
completed proofs for programs consisting of a single assignment
paulson
parents:
13821
diff
changeset
|
468 |
|
e7649436869c
completed proofs for programs consisting of a single assignment
paulson
parents:
13821
diff
changeset
|
469 |
lemma single_subset_wens_set: |
e7649436869c
completed proofs for programs consisting of a single assignment
paulson
parents:
13821
diff
changeset
|
470 |
"single_valued act |
e7649436869c
completed proofs for programs consisting of a single assignment
paulson
parents:
13821
diff
changeset
|
471 |
==> insert (wens_single act B) (range (wens_single_finite act B)) \<subseteq> |
e7649436869c
completed proofs for programs consisting of a single assignment
paulson
parents:
13821
diff
changeset
|
472 |
wens_set (mk_program (init, {act}, allowed)) B" |
e7649436869c
completed proofs for programs consisting of a single assignment
paulson
parents:
13821
diff
changeset
|
473 |
apply (simp add: wens_single_eq_Union UN_eq) |
e7649436869c
completed proofs for programs consisting of a single assignment
paulson
parents:
13821
diff
changeset
|
474 |
apply (blast intro: wens_set.Union wens_single_finite_in_wens_set) |
e7649436869c
completed proofs for programs consisting of a single assignment
paulson
parents:
13821
diff
changeset
|
475 |
done |
e7649436869c
completed proofs for programs consisting of a single assignment
paulson
parents:
13821
diff
changeset
|
476 |
|
e7649436869c
completed proofs for programs consisting of a single assignment
paulson
parents:
13821
diff
changeset
|
477 |
text{*Theorem (4.29)*} |
e7649436869c
completed proofs for programs consisting of a single assignment
paulson
parents:
13821
diff
changeset
|
478 |
theorem wens_set_single_eq: |
13851 | 479 |
"[|F = mk_program (init, {act}, allowed); single_valued act|] |
480 |
==> wens_set F B = |
|
481 |
insert (wens_single act B) (range (wens_single_finite act B))" |
|
13832
e7649436869c
completed proofs for programs consisting of a single assignment
paulson
parents:
13821
diff
changeset
|
482 |
apply (rule equalityI) |
13851 | 483 |
apply (simp add: wens_set_subset_single) |
484 |
apply (erule ssubst, erule single_subset_wens_set) |
|
13832
e7649436869c
completed proofs for programs consisting of a single assignment
paulson
parents:
13821
diff
changeset
|
485 |
done |
e7649436869c
completed proofs for programs consisting of a single assignment
paulson
parents:
13821
diff
changeset
|
486 |
|
13853
89131afa9f01
New theory ProgressSets. Definition of closure sets
paulson
parents:
13851
diff
changeset
|
487 |
text{*Generalizing Misra's Fixed Point Union Theorem (4.41)*} |
89131afa9f01
New theory ProgressSets. Definition of closure sets
paulson
parents:
13851
diff
changeset
|
488 |
|
13866 | 489 |
lemma fp_leadsTo_Join: |
13853
89131afa9f01
New theory ProgressSets. Definition of closure sets
paulson
parents:
13851
diff
changeset
|
490 |
"[|T-B \<subseteq> awp F T; T-B \<subseteq> FP G; F \<in> A leadsTo B|] ==> F\<squnion>G \<in> T\<inter>A leadsTo B" |
13866 | 491 |
apply (rule leadsTo_Join, assumption, blast) |
492 |
apply (simp add: FP_def awp_iff_constrains stable_def constrains_def, blast) |
|
13853
89131afa9f01
New theory ProgressSets. Definition of closure sets
paulson
parents:
13851
diff
changeset
|
493 |
done |
89131afa9f01
New theory ProgressSets. Definition of closure sets
paulson
parents:
13851
diff
changeset
|
494 |
|
13821
0fd39aa77095
new theory Transformers: Meier-Sanders non-interference theory
paulson
parents:
diff
changeset
|
495 |
end |