(* Title: HOL/Extraction.thy 
ID: $Id$ 

Author: Stefan Berghofer, TU Muenchen 

*) 

header {* Program extraction for HOL *} 

theory Extraction 
imports Datatype 
uses "Tools/rewrite_hol_proof.ML" 
begin 
subsection {* Setup *} 

setup {* 
let 

fun realizes_set_proc (Const ("realizes", Type ("fun", [Type ("Null", []), _])) $ r $ 
(Const ("op :", _) $ x $ S)) = (case strip_comb S of 
(Var (ixn, U), ts) => SOME (list_comb (Var (ixn, binder_types U @ 
[HOLogic.dest_setT (body_type U)] > HOLogic.boolT), ts @ [x])) 
 (Free (s, U), ts) => SOME (list_comb (Free (s, binder_types U @ 
[HOLogic.dest_setT (body_type U)] > HOLogic.boolT), ts @ [x])) 
 _ => NONE) 
 realizes_set_proc (Const ("realizes", Type ("fun", [T, _])) $ r $ 
12404b452034
Changed format of realizers / correctness proofs.
berghofe
parents:
13599
diff
changeset

(Const ("op :", _) $ x $ S)) = (case strip_comb S of 
(Var (ixn, U), ts) => SOME (list_comb (Var (ixn, T :: binder_types U @ 
[HOLogic.dest_setT (body_type U)] > HOLogic.boolT), r :: ts @ [x])) 
 (Free (s, U), ts) => SOME (list_comb (Free (s, T :: binder_types U @ 
[HOLogic.dest_setT (body_type U)] > HOLogic.boolT), r :: ts @ [x])) 
 _ => NONE) 
 realizes_set_proc _ = NONE; 

fun mk_realizes_set r rT s (setT as Type ("set", [elT])) = 
Abs ("x", elT, Const ("realizes", rT > HOLogic.boolT > HOLogic.boolT) $ 
incr_boundvars 1 r $ (Const ("op :", elT > setT > HOLogic.boolT) $ 
Bound 0 $ incr_boundvars 1 s)); 
in 
Extraction.add_types 
[("bool", ([], NONE)), 
("set", ([realizes_set_proc], SOME mk_realizes_set))] #> 
Extraction.set_preprocessor (fn thy => 

Proofterm.rewrite_proof_notypes 
([], RewriteHOLProof.elim_cong :: ProofRewriteRules.rprocs true) o 
Proofterm.rewrite_proof thy 
(RewriteHOLProof.rews, ProofRewriteRules.rprocs true) o 
ProofRewriteRules.elim_vars (curry Const @{const_name default})) 
end 
*} 
lemmas [extraction_expand] = 

meta_spec atomize_eq atomize_all atomize_imp atomize_conj 
allE rev_mp conjE Eq_TrueI Eq_FalseI eqTrueI eqTrueE eq_cong2 
beedcae49096
haftmann
notE' impE' impE iffE imp_cong simp_thms eq_True eq_False 
induct_forall_eq induct_implies_eq induct_equal_eq induct_conj_eq 
18511  56 
True_implies_equals TrueE 
59 
61 
62 

extract_type 

"typeof (Trueprop P) \<equiv> typeof P" 

66 
67 
68 

"typeof Q \<equiv> Type (TYPE(Null)) \<Longrightarrow> typeof (P \<longrightarrow> Q) \<equiv> Type (TYPE(Null))" 

71 
72 
73 

"(\<lambda>x. typeof (P x)) \<equiv> (\<lambda>x. Type (TYPE(Null))) \<Longrightarrow> 

typeof (\<forall>x. P x) \<equiv> Type (TYPE(Null))" 

77 
typeof (\<forall>x::'a. P x) \<equiv> Type (TYPE('a \<Rightarrow> 'P))" 

"(\<lambda>x. typeof (P x)) \<equiv> (\<lambda>x. Type (TYPE(Null))) \<Longrightarrow> 

typeof (\<exists>x::'a. P x) \<equiv> Type (TYPE('a))" 

82 

"(\<lambda>x. typeof (P x)) \<equiv> (\<lambda>x. Type (TYPE('P))) \<Longrightarrow> 

84 
85 

86 
87 
typeof (P \<or> Q) \<equiv> Type (TYPE(sumbool))" 

89 
"typeof P \<equiv> Type (TYPE(Null)) \<Longrightarrow> typeof Q \<equiv> Type (TYPE('Q)) \<Longrightarrow> 

typeof (P \<or> Q) \<equiv> Type (TYPE('Q option))" 

92 
"typeof P \<equiv> Type (TYPE('P)) \<Longrightarrow> typeof Q \<equiv> Type (TYPE(Null)) \<Longrightarrow> 

typeof (P \<or> Q) \<equiv> Type (TYPE('P option))" 

94 

"typeof P \<equiv> Type (TYPE('P)) \<Longrightarrow> typeof Q \<equiv> Type (TYPE('Q)) \<Longrightarrow> 

96 
97 

"typeof P \<equiv> Type (TYPE(Null)) \<Longrightarrow> typeof Q \<equiv> Type (TYPE('Q)) \<Longrightarrow> 

99 
100 

101 
102 
typeof (P \<and> Q) \<equiv> Type (TYPE('P))" 

104 
105 
typeof (P \<and> Q) \<equiv> Type (TYPE('P \<times> 'Q))" 

107 
"typeof (P = Q) \<equiv> typeof ((P \<longrightarrow> Q) \<and> (Q \<longrightarrow> P))" 

109 
"typeof (x \<in> P) \<equiv> typeof P" 

111 
subsection {* Realizability *} 

113 
realizability 

"(realizes t (Trueprop P)) \<equiv> (Trueprop (realizes t P))" 

115 

"(typeof P) \<equiv> (Type (TYPE(Null))) \<Longrightarrow> 

117 
118 

119 
120 
121 
(realizes t (P \<longrightarrow> Q)) \<equiv> (\<forall>x::'P. realizes x P \<longrightarrow> realizes Null Q)" 

123 
"(realizes t (P \<longrightarrow> Q)) \<equiv> (\<forall>x. realizes x P \<longrightarrow> realizes (t x) Q)" 

124 

125 
126 
(realizes t (\<forall>x. P x)) \<equiv> (\<forall>x. realizes Null (P x))" 

127 

128 
129 

130 
"(\<lambda>x. typeof (P x)) \<equiv> (\<lambda>x. Type (TYPE(Null))) \<Longrightarrow> 

131 
132 

133 
134 

135 
136 
(typeof Q) \<equiv> (Type (TYPE(Null))) \<Longrightarrow> 

137 
138 
(case t of Left \<Rightarrow> realizes Null P  Right \<Rightarrow> realizes Null Q)" 

140 
"(typeof P) \<equiv> (Type (TYPE(Null))) \<Longrightarrow> 

(realizes t (P \<or> Q)) \<equiv> 

(case t of None \<Rightarrow> realizes Null P  Some q \<Rightarrow> realizes q Q)" 

143 

"(typeof Q) \<equiv> (Type (TYPE(Null))) \<Longrightarrow> 

(realizes t (P \<or> Q)) \<equiv> 

146 
147 

148 
149 
(case t of Inl p \<Rightarrow> realizes p P  Inr q \<Rightarrow> realizes q Q)" 

151 
152 
(realizes t (P \<and> Q)) \<equiv> (realizes Null P \<and> realizes t Q)" 

154 
155 
(realizes t (P \<and> Q)) \<equiv> (realizes t P \<and> realizes Null Q)" 

156 

"(realizes t (P \<and> Q)) \<equiv> (realizes (fst t) P \<and> realizes (snd t) Q)" 

158 

"typeof P \<equiv> Type (TYPE(Null)) \<Longrightarrow> 

160 
realizes t (\<not> P) \<equiv> \<not> realizes Null P" 

162 
163 
realizes t (\<not> P) \<equiv> (\<forall>x::'P. \<not> realizes x P)" 

164 

"typeof (P::bool) \<equiv> Type (TYPE(Null)) \<Longrightarrow> 

166 
167 
realizes t (P = Q) \<equiv> realizes Null P = realizes Null Q" 

168 

"(realizes t (P = Q)) \<equiv> (realizes t ((P \<longrightarrow> Q) \<and> (Q \<longrightarrow> P)))" 

171 
subsection {* Computational content of basic inference rules *} 

172 

173 
theorem disjE_realizer: 

174 
175 
and r1: "\<And>p. P p \<Longrightarrow> R (f p)" and r2: "\<And>q. Q q \<Longrightarrow> R (g q)" 

176 
shows "R (case x of Inl p \<Rightarrow> f p  Inr q \<Rightarrow> g q)" 

proof (cases x) 

178 
case Inl 

179 
180 
181 
case Inr 

182 
with r show ?thesis by simp (rule r2) 

qed 

184 

185 
assumes r: "case x of None \<Rightarrow> P  Some q \<Rightarrow> Q q" 

187 
and r1: "P \<Longrightarrow> R f" and r2: "\<And>q. Q q \<Longrightarrow> R (g q)" 

188 
shows "R (case x of None \<Rightarrow> f  Some q \<Rightarrow> g q)" 

189 
proof (cases x) 

190 
case None 

191 
with r show ?thesis by simp (rule r1) 

192 
next 

193 
case Some 

194 
with r show ?thesis by simp (rule r2) 

195 
qed 

196 

197 
theorem disjE_realizer3: 

198 
assumes r: "case x of Left \<Rightarrow> P  Right \<Rightarrow> Q" 

199 
and r1: "P \<Longrightarrow> R f" and r2: "Q \<Longrightarrow> R g" 

200 
shows "R (case x of Left \<Rightarrow> f  Right \<Rightarrow> g)" 

201 
proof (cases x) 

202 
case Left 

203 
with r show ?thesis by simp (rule r1) 

204 
next 

205 
case Right 

206 
with r show ?thesis by simp (rule r2) 

207 
qed 

208 

209 
theorem conjI_realizer: 

210 
"P p \<Longrightarrow> Q q \<Longrightarrow> P (fst (p, q)) \<and> Q (snd (p, q))" 

211 
by simp 

212 

213 
theorem exI_realizer: 

"P y x \<Longrightarrow> P (snd (x, y)) (fst (x, y))" by simp 
theorem exE_realizer: "P (snd p) (fst p) \<Longrightarrow> 
15393  217 
(\<And>x y. P y x \<Longrightarrow> Q (f x y)) \<Longrightarrow> Q (let (x, y) = p in f x y)" 
218 
by (cases p) (simp add: Let_def) 

theorem exE_realizer': "P (snd p) (fst p) \<Longrightarrow> 
2134ed516b1b
Tuned realizer for exE rule, to avoid blowup of extracted program.
berghofe
parents:
13725
diff
changeset

221 
13403  222 

setup {* 
224 
Sign.add_const_constraint (@{const_name "default"}, SOME @{typ "'a::type"}) 

225 
*} 

226 

13403  227 
realizers 
impI (P, Q): "\<lambda>pq. pq" 
"\<Lambda> P Q pq (h: _). allI \<cdot> _ \<bullet> (\<Lambda> x. impI \<cdot> _ \<cdot> _ \<bullet> (h \<cdot> x))" 
231 
impI (P): "Null" 

"\<Lambda> P Q (h: _). allI \<cdot> _ \<bullet> (\<Lambda> x. impI \<cdot> _ \<cdot> _ \<bullet> (h \<cdot> x))" 
impI (Q): "\<lambda>q. q" "\<Lambda> P Q q. impI \<cdot> _ \<cdot> _" 
impI: "Null" "impI" 
mp (P, Q): "\<lambda>pq. pq" 
"\<Lambda> P Q pq (h: _) p. mp \<cdot> _ \<cdot> _ \<bullet> (spec \<cdot> _ \<cdot> p \<bullet> h)" 
241 
mp (P): "Null" 

"\<Lambda> P Q (h: _) p. mp \<cdot> _ \<cdot> _ \<bullet> (spec \<cdot> _ \<cdot> p \<bullet> h)" 
mp (Q): "\<lambda>q. q" "\<Lambda> P Q q. mp \<cdot> _ \<cdot> _" 
mp: "Null" "mp" 
allI (P): "\<lambda>p. p" "\<Lambda> P p. allI \<cdot> _" 
allI: "Null" "allI" 
spec (P): "\<lambda>x p. p x" "\<Lambda> P x p. spec \<cdot> _ \<cdot> x" 
spec: "Null" "spec" 
exI (P): "\<lambda>x p. (x, p)" "\<Lambda> P x p. exI_realizer \<cdot> P \<cdot> p \<cdot> x" 
exI: "\<lambda>x. x" "\<Lambda> P x (h: _). h" 
exE (P, Q): "\<lambda>p pq. let (x, y) = p in pq x y" 
"\<Lambda> P Q p (h: _) pq. exE_realizer \<cdot> P \<cdot> p \<cdot> Q \<cdot> pq \<bullet> h" 
263 
exE (P): "Null" 

"\<Lambda> P Q p. exE_realizer' \<cdot> _ \<cdot> _ \<cdot> _" 
exE (Q): "\<lambda>x pq. pq x" 
"\<Lambda> P Q x (h1: _) pq (h2: _). h2 \<cdot> x \<bullet> h1" 
269 
exE: "Null" 

"\<Lambda> P Q x (h1: _) (h2: _). h2 \<cdot> x \<bullet> h1" 
conjI (P, Q): "Pair" 
"\<Lambda> P Q p (h: _) q. conjI_realizer \<cdot> P \<cdot> p \<cdot> Q \<cdot> q \<bullet> h" 
conjI (P): "\<lambda>p. p" 
"\<Lambda> P Q p. conjI \<cdot> _ \<cdot> _" 
conjI (Q): "\<lambda>q. q" 
"\<Lambda> P Q (h: _) q. conjI \<cdot> _ \<cdot> _ \<bullet> h" 
conjI: "Null" "conjI" 
conjunct1 (P, Q): "fst" 
"\<Lambda> P Q pq. conjunct1 \<cdot> _ \<cdot> _" 
conjunct1 (P): "\<lambda>p. p" 
"\<Lambda> P Q p. conjunct1 \<cdot> _ \<cdot> _" 
289 
conjunct1 (Q): "Null" 

"\<Lambda> P Q q. conjunct1 \<cdot> _ \<cdot> _" 
conjunct1: "Null" "conjunct1" 
conjunct2 (P, Q): "snd" 
"\<Lambda> P Q pq. conjunct2 \<cdot> _ \<cdot> _" 
297 
conjunct2 (P): "Null" 

"\<Lambda> P Q p. conjunct2 \<cdot> _ \<cdot> _" 
conjunct2 (Q): "\<lambda>p. p" 
"\<Lambda> P Q p. conjunct2 \<cdot> _ \<cdot> _" 
conjunct2: "Null" "conjunct2" 
disjI1 (P, Q): "Inl" 
"\<Lambda> P Q p. iffD2 \<cdot> _ \<cdot> _ \<bullet> (sum.cases_1 \<cdot> P \<cdot> _ \<cdot> p)" 
disjI1 (P): "Some" 
"\<Lambda> P Q p. iffD2 \<cdot> _ \<cdot> _ \<bullet> (option.cases_2 \<cdot> _ \<cdot> P \<cdot> p)" 
disjI1 (Q): "None" 
"\<Lambda> P Q. iffD2 \<cdot> _ \<cdot> _ \<bullet> (option.cases_1 \<cdot> _ \<cdot> _)" 
disjI1: "Left" 
"\<Lambda> P Q. iffD2 \<cdot> _ \<cdot> _ \<bullet> (sumbool.cases_1 \<cdot> _ \<cdot> _)" 
disjI2 (P, Q): "Inr" 
"\<Lambda> Q P q. iffD2 \<cdot> _ \<cdot> _ \<bullet> (sum.cases_2 \<cdot> _ \<cdot> Q \<cdot> q)" 
disjI2 (P): "None" 
"\<Lambda> Q P. iffD2 \<cdot> _ \<cdot> _ \<bullet> (option.cases_1 \<cdot> _ \<cdot> _)" 
disjI2 (Q): "Some" 
"\<Lambda> Q P q. iffD2 \<cdot> _ \<cdot> _ \<bullet> (option.cases_2 \<cdot> _ \<cdot> Q \<cdot> q)" 
disjI2: "Right" 
"\<Lambda> Q P. iffD2 \<cdot> _ \<cdot> _ \<bullet> (sumbool.cases_2 \<cdot> _ \<cdot> _)" 
disjE (P, Q, R): "\<lambda>pq pr qr. 
(case pq of Inl p \<Rightarrow> pr p  Inr q \<Rightarrow> qr q)" 
"\<Lambda> P Q R pq (h1: _) pr (h2: _) qr. 
12404b452034
Changed format of realizers / correctness proofs.
berghofe
parents:
13599
diff
changeset

332 
disjE_realizer \<cdot> _ \<cdot> _ \<cdot> pq \<cdot> R \<cdot> pr \<cdot> qr \<bullet> h1 \<bullet> h2" 
disjE (Q, R): "\<lambda>pq pr qr. 
(case pq of None \<Rightarrow> pr  Some q \<Rightarrow> qr q)" 
"\<Lambda> P Q R pq (h1: _) pr (h2: _) qr. 
12404b452034
Changed format of realizers / correctness proofs.
berghofe
parents:
13599
diff
changeset

337 
disjE_realizer2 \<cdot> _ \<cdot> _ \<cdot> pq \<cdot> R \<cdot> pr \<cdot> qr \<bullet> h1 \<bullet> h2" 
disjE (P, R): "\<lambda>pq pr qr. 
(case pq of None \<Rightarrow> qr  Some p \<Rightarrow> pr p)" 
"\<Lambda> P Q R pq (h1: _) pr (h2: _) qr (h3: _). 
12404b452034
Changed format of realizers / correctness proofs.
berghofe
parents:
13599
diff
changeset

342 
disjE_realizer2 \<cdot> _ \<cdot> _ \<cdot> pq \<cdot> R \<cdot> qr \<cdot> pr \<bullet> h1 \<bullet> h3 \<bullet> h2" 
disjE (R): "\<lambda>pq pr qr. 
(case pq of Left \<Rightarrow> pr  Right \<Rightarrow> qr)" 
"\<Lambda> P Q R pq (h1: _) pr (h2: _) qr. 
12404b452034
Changed format of realizers / correctness proofs.
berghofe
parents:
13599
diff
changeset

347 
disjE_realizer3 \<cdot> _ \<cdot> _ \<cdot> pq \<cdot> R \<cdot> pr \<cdot> qr \<bullet> h1 \<bullet> h2" 
349 
disjE (P, Q): "Null" 

"\<Lambda> P Q R pq. disjE_realizer \<cdot> _ \<cdot> _ \<cdot> pq \<cdot> (\<lambda>x. R) \<cdot> _ \<cdot> _" 
352 
disjE (Q): "Null" 

"\<Lambda> P Q R pq. disjE_realizer2 \<cdot> _ \<cdot> _ \<cdot> pq \<cdot> (\<lambda>x. R) \<cdot> _ \<cdot> _" 
355 
disjE (P): "Null" 

"\<Lambda> P Q R pq (h1: _) (h2: _) (h3: _). 
disjE_realizer2 \<cdot> _ \<cdot> _ \<cdot> pq \<cdot> (\<lambda>x. R) \<cdot> _ \<cdot> _ \<bullet> h1 \<bullet> h3 \<bullet> h2" 
359 
disjE: "Null" 

"\<Lambda> P Q R pq. disjE_realizer3 \<cdot> _ \<cdot> _ \<cdot> pq \<cdot> (\<lambda>x. R) \<cdot> _ \<cdot> _" 
27982  362 
FalseE (P): "default" 
"\<Lambda> P. FalseE \<cdot> _" 
FalseE: "Null" "FalseE" 
367 
notI (P): "Null" 

"\<Lambda> P (h: _). allI \<cdot> _ \<bullet> (\<Lambda> x. notI \<cdot> _ \<bullet> (h \<cdot> x))" 
notI: "Null" "notI" 
27982  372 
notE (P, R): "\<lambda>p. default" 
"\<Lambda> P R (h: _) p. notE \<cdot> _ \<cdot> _ \<bullet> (spec \<cdot> _ \<cdot> p \<bullet> h)" 
375 
notE (P): "Null" 

"\<Lambda> P R (h: _) p. notE \<cdot> _ \<cdot> _ \<bullet> (spec \<cdot> _ \<cdot> p \<bullet> h)" 
27982  378 
notE (R): "default" 
"\<Lambda> P R. notE \<cdot> _ \<cdot> _" 
notE: "Null" "notE" 
subst (P): "\<lambda>s t ps. ps" 
"\<Lambda> s t P (h: _) ps. subst \<cdot> s \<cdot> t \<cdot> P ps \<bullet> h" 
subst: "Null" "subst" 
iffD1 (P, Q): "fst" 
"\<Lambda> Q P pq (h: _) p. 
mp \<cdot> _ \<cdot> _ \<bullet> (spec \<cdot> _ \<cdot> p \<bullet> (conjunct1 \<cdot> _ \<cdot> _ \<bullet> h))" 
iffD1 (P): "\<lambda>p. p" 
"\<Lambda> Q P p (h: _). mp \<cdot> _ \<cdot> _ \<bullet> (conjunct1 \<cdot> _ \<cdot> _ \<bullet> h)" 
395 
iffD1 (Q): "Null" 

"\<Lambda> Q P q1 (h: _) q2. 
mp \<cdot> _ \<cdot> _ \<bullet> (spec \<cdot> _ \<cdot> q2 \<bullet> (conjunct1 \<cdot> _ \<cdot> _ \<bullet> h))" 
iffD1: "Null" "iffD1" 
iffD2 (P, Q): "snd" 
"\<Lambda> P Q pq (h: _) q. 
mp \<cdot> _ \<cdot> _ \<bullet> (spec \<cdot> _ \<cdot> q \<bullet> (conjunct2 \<cdot> _ \<cdot> _ \<bullet> h))" 
iffD2 (P): "\<lambda>p. p" 
"\<Lambda> P Q p (h: _). mp \<cdot> _ \<cdot> _ \<bullet> (conjunct2 \<cdot> _ \<cdot> _ \<bullet> h)" 
408 
iffD2 (Q): "Null" 

"\<Lambda> P Q q1 (h: _) q2. 
mp \<cdot> _ \<cdot> _ \<bullet> (spec \<cdot> _ \<cdot> q2 \<bullet> (conjunct2 \<cdot> _ \<cdot> _ \<bullet> h))" 
iffD2: "Null" "iffD2" 
iffI (P, Q): "Pair" 
"\<Lambda> P Q pq (h1 : _) qp (h2 : _). conjI_realizer \<cdot> 
(\<lambda>pq. \<forall>x. P x \<longrightarrow> Q (pq x)) \<cdot> pq \<cdot> 
(\<lambda>qp. \<forall>x. Q x \<longrightarrow> P (qp x)) \<cdot> qp \<bullet> 
(allI \<cdot> _ \<bullet> (\<Lambda> x. impI \<cdot> _ \<cdot> _ \<bullet> (h1 \<cdot> x))) \<bullet> 
(allI \<cdot> _ \<bullet> (\<Lambda> x. impI \<cdot> _ \<cdot> _ \<bullet> (h2 \<cdot> x)))" 
iffI (P): "\<lambda>p. p" 
"\<Lambda> P Q (h1 : _) p (h2 : _). conjI \<cdot> _ \<cdot> _ \<bullet> 
(allI \<cdot> _ \<bullet> (\<Lambda> x. impI \<cdot> _ \<cdot> _ \<bullet> (h1 \<cdot> x))) \<bullet> 
(impI \<cdot> _ \<cdot> _ \<bullet> h2)" 
iffI (Q): "\<lambda>q. q" 
"\<Lambda> P Q q (h1 : _) (h2 : _). conjI \<cdot> _ \<cdot> _ \<bullet> 
(impI \<cdot> _ \<cdot> _ \<bullet> h1) \<bullet> 
(allI \<cdot> _ \<bullet> (\<Lambda> x. impI \<cdot> _ \<cdot> _ \<bullet> (h2 \<cdot> x)))" 
iffI: "Null" "iffI" 
(* 
classical: "Null" 
"\<Lambda> P. classical \<cdot> _" 
*) 
setup {* 
439 
Sign.add_const_constraint (@{const_name "default"}, SOME @{typ "'a::default"}) 

440 
*} 

13403  442 
end 