doc-src/TutorialI/todo.tobias
author nipkow
Fri, 24 Nov 2000 16:49:27 +0100
changeset 10519 ade64af4c57c
parent 10509 ff24ac6678dd
child 10520 bb9dfcc87951
permissions -rw-r--r--
hide many names from Datatype_Universe.
Ignore whitespace changes - Everywhere: Within whitespace: At end of lines:
10281
9554ce1c2e54 *** empty log message ***
nipkow
parents: 10242
diff changeset
     1
Implementation
9554ce1c2e54 *** empty log message ***
nipkow
parents: 10242
diff changeset
     2
==============
10177
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
     3
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
     4
Hide global names like Node.
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
     5
Why is comp needed in addition to op O?
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
     6
Explain in syntax section!
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
     7
10281
9554ce1c2e54 *** empty log message ***
nipkow
parents: 10242
diff changeset
     8
replace "simp only split" by "split_tac".
10177
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
     9
10281
9554ce1c2e54 *** empty log message ***
nipkow
parents: 10242
diff changeset
    10
arithmetic: allow mixed nat/int formulae
9554ce1c2e54 *** empty log message ***
nipkow
parents: 10242
diff changeset
    11
-> simplify proof of part1 in Inductive/AB.thy
10177
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
    12
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
    13
Add map_cong?? (upto 10% slower)
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
    14
10281
9554ce1c2e54 *** empty log message ***
nipkow
parents: 10242
diff changeset
    15
Recdef: Get rid of function name in header.
9554ce1c2e54 *** empty log message ***
nipkow
parents: 10242
diff changeset
    16
Support mutual recursion (Konrad?)
10177
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
    17
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
    18
use arith_tac in recdef to solve termination conditions?
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
    19
-> new example in Recdef/termination
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
    20
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
    21
a tactic for replacing a specific occurrence:
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
    22
apply(substitute [2] thm)
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
    23
10186
499637e8f2c6 *** empty log message ***
nipkow
parents: 10177
diff changeset
    24
it would be nice if @term could deal with ?-vars.
499637e8f2c6 *** empty log message ***
nipkow
parents: 10177
diff changeset
    25
then a number of (unchecked!) @texts could be converted to @terms.
499637e8f2c6 *** empty log message ***
nipkow
parents: 10177
diff changeset
    26
10189
865918597b63 *** empty log message ***
nipkow
parents: 10186
diff changeset
    27
it would be nice if one could get id to the enclosing quotes in the [source] option.
865918597b63 *** empty log message ***
nipkow
parents: 10186
diff changeset
    28
10281
9554ce1c2e54 *** empty log message ***
nipkow
parents: 10242
diff changeset
    29
More predefined functions for datatypes: map?
9554ce1c2e54 *** empty log message ***
nipkow
parents: 10242
diff changeset
    30
9554ce1c2e54 *** empty log message ***
nipkow
parents: 10242
diff changeset
    31
Induction rules for int: int_le/ge_induct?
9554ce1c2e54 *** empty log message ***
nipkow
parents: 10242
diff changeset
    32
Needed for ifak example. But is that example worth it?
9554ce1c2e54 *** empty log message ***
nipkow
parents: 10242
diff changeset
    33
10340
0a380ac80e7d *** empty log message ***
nipkow
parents: 10283
diff changeset
    34
defs with = and pattern matching
0a380ac80e7d *** empty log message ***
nipkow
parents: 10283
diff changeset
    35
10186
499637e8f2c6 *** empty log message ***
nipkow
parents: 10177
diff changeset
    36
10177
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
    37
Minor fixes in the tutorial
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
    38
===========================
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
    39
10340
0a380ac80e7d *** empty log message ***
nipkow
parents: 10283
diff changeset
    40
explanation of term "contrapositive"/contraposition in Rules?
0a380ac80e7d *** empty log message ***
nipkow
parents: 10283
diff changeset
    41
Index the notion and maybe the rules contrapos_xy
0a380ac80e7d *** empty log message ***
nipkow
parents: 10283
diff changeset
    42
0a380ac80e7d *** empty log message ***
nipkow
parents: 10283
diff changeset
    43
Even: forward ref from problem with "Suc(Suc n) : even" to general solution in
0a380ac80e7d *** empty log message ***
nipkow
parents: 10283
diff changeset
    44
AdvancedInd section.
10177
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
    45
10281
9554ce1c2e54 *** empty log message ***
nipkow
parents: 10242
diff changeset
    46
get rid of use_thy in tutorial?
10177
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
    47
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
    48
Explain typographic conventions?
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
    49
10509
ff24ac6678dd *** empty log message ***
nipkow
parents: 10340
diff changeset
    50
Orderings on numbers (with hint that it is overloaded):
ff24ac6678dd *** empty log message ***
nipkow
parents: 10340
diff changeset
    51
>, >=, and bounded quantifers ALL x<y, <=, todo: x>y, x>=y.
ff24ac6678dd *** empty log message ***
nipkow
parents: 10340
diff changeset
    52
10177
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
    53
an example of induction: !y. A --> B --> C ??
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
    54
10509
ff24ac6678dd *** empty log message ***
nipkow
parents: 10340
diff changeset
    55
Explain type_definition and mention pre-proved thms in subset.thy?
ff24ac6678dd *** empty log message ***
nipkow
parents: 10340
diff changeset
    56
-> Types/typedef
ff24ac6678dd *** empty log message ***
nipkow
parents: 10340
diff changeset
    57
10177
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
    58
Appendix: Lexical: long ids.
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
    59
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
    60
Warning: infixes automatically become reserved words!
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
    61
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
    62
Forward ref from blast proof of Puzzle (AdvancedInd) to Isar proof?
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
    63
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
    64
mention split_split in advanced pair section.
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
    65
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
    66
recdef with nested recursion: either an example or at least a pointer to the
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
    67
literature. In Recdef/termination.thy, at the end.
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
    68
%FIXME, with one exception: nested recursion.
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
    69
10186
499637e8f2c6 *** empty log message ***
nipkow
parents: 10177
diff changeset
    70
Syntax section: syntax annotations nor just for consts but also for constdefs and datatype.
499637e8f2c6 *** empty log message ***
nipkow
parents: 10177
diff changeset
    71
10283
ff003e2b790c *** empty log message ***
nipkow
parents: 10281
diff changeset
    72
Appendix with list functions.
ff003e2b790c *** empty log message ***
nipkow
parents: 10281
diff changeset
    73
10177
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
    74
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
    75
Minor additions to the tutorial, unclear where
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
    76
==============================================
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
    77
10186
499637e8f2c6 *** empty log message ***
nipkow
parents: 10177
diff changeset
    78
Tacticals: , ? +
10177
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
    79
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
    80
Mention that simp etc (big step tactics) insist on change?
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
    81
10237
875bf54b5d74 *** empty log message ***
nipkow
parents: 10236
diff changeset
    82
Rules: Introduce "by" (as a kind of shorthand for apply+done, except that it
875bf54b5d74 *** empty log message ***
nipkow
parents: 10236
diff changeset
    83
does more.)
10177
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
    84
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
    85
A list of further useful commands (rules? tricks?)
10281
9554ce1c2e54 *** empty log message ***
nipkow
parents: 10242
diff changeset
    86
prefer, defer, print_simpset (-> print_simps?)
10177
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
    87
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
    88
An overview of the automatic methods: simp, auto, fast, blast, force,
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
    89
clarify, clarsimp (intro, elim?)
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
    90
10237
875bf54b5d74 *** empty log message ***
nipkow
parents: 10236
diff changeset
    91
Advanced Ind expects rule_format incl (no_asm) (which it currently explains!)
10242
028f54cd2cc9 *** empty log message ***
nipkow
parents: 10237
diff changeset
    92
Where explained? Should go into a separate section as Inductive needs it as
028f54cd2cc9 *** empty log message ***
nipkow
parents: 10237
diff changeset
    93
well.
10237
875bf54b5d74 *** empty log message ***
nipkow
parents: 10236
diff changeset
    94
875bf54b5d74 *** empty log message ***
nipkow
parents: 10236
diff changeset
    95
Where is "simplified" explained? Needed by Inductive/AB.thy
10177
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
    96
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
    97
demonstrate x : set xs in Sets. Or Tricks chapter?
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
    98
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
    99
Appendix with HOL keywords. Say something about other keywords.
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   100
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   101
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   102
Possible exercises
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   103
==================
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   104
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   105
Exercises
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   106
%\begin{exercise}
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   107
%Extend expressions by conditional expressions.
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   108
braucht wfrec!
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   109
%\end{exercise}
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   110
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   111
Nested inductive datatypes: another example/exercise:
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   112
 size(t) <= size(subst s t)?
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   113
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   114
insertion sort: primrec, later recdef
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   115
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   116
OTree:
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   117
 first version only for non-empty trees:
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   118
 Tip 'a | Node tree tree
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   119
 Then real version?
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   120
 First primrec, then recdef?
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   121
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   122
Ind. sets: define ABC inductively and prove
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   123
ABC = {rep A n @ rep B n @ rep C n. True}
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   124
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   125
Possible examples/case studies
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   126
==============================
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   127
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   128
Trie: Define functional version
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   129
datatype ('a,'b)trie = Trie ('b option) ('a => ('a,'b)trie option)
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   130
lookup t [] = value t
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   131
lookup t (a#as) = case tries t a of None => None | Some s => lookup s as
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   132
Maybe as an exercise?
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   133
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   134
Trie: function for partial matches (prefixes). Needs sets for spec/proof.
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   135
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   136
Sets via ordered list of intervals. (Isa/Interval(2))
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   137
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   138
propositional logic (soundness and completeness?),
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   139
predicate logic (soundness?),
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   140
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   141
Tautology checker. Based on Ifexpr or prop.logic?
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   142
Include forward reference in relevant section.
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   143
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   144
Sorting with comp-parameter and with type class (<)
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   145
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   146
New book by Bird?
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   147
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   148
Steps Towards Mechanizing Program Transformations Using PVS by N. Shankar,
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   149
      Science of Computer Programming, 26(1-3):33-57, 1996. 
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   150
You can get it from http://www.csl.sri.com/scp95.html
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   151
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   152
J Moore article Towards a ...
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   153
Mergesort, JVM
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   154
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   155
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   156
Additional topics
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   157
=================
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   158
10281
9554ce1c2e54 *** empty log message ***
nipkow
parents: 10242
diff changeset
   159
Recdef with nested recursion?
10177
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   160
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   161
Extensionality: applications in
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   162
- boolean expressions: valif o bool2if = value
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   163
- Advanced datatypes exercise subst (f o g) = subst f o subst g
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   164
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   165
A look at the library?
10281
9554ce1c2e54 *** empty log message ***
nipkow
parents: 10242
diff changeset
   166
Map.
10177
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   167
If WF is discussed, make a link to it from AdvancedInd.
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   168
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   169
Prototyping?
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   170
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   171
==============================================================
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   172
Recdef:
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   173
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   174
nested recursion
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   175
more example proofs:
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   176
 if-normalization with measure function,
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   177
 nested if-normalization,
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   178
 quicksort
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   179
 Trie?
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   180
a case study?
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   181
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   182
----------
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   183
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   184
Partial rekursive functions / Nontermination
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   185
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   186
What appears to be the problem:
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   187
axiom f n = f n + 1
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   188
lemma False
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   189
apply(cut_facts_tac axiom, simp).
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   190
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   191
1. Guarded recursion
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   192
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   193
Scheme:
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   194
f x = if $x \in dom(f)$ then ... else arbitrary
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   195
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   196
Example: sum/fact: int -> int (for no good reason because we have nat)
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   197
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   198
Exercise: ?! f. !i. f i = if i=0 then 1 else i*f(i-1)
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   199
(What about sum? Is there one, a unique one?)
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   200
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   201
[Alternative: include argument that is counted down
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   202
 f x n = if n=0 then None else ...
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   203
Refer to Boyer and Moore]
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   204
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   205
More complex: same_fst
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   206
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   207
chase(f,x) = if wf{(f x,x) . f x ~= x}
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   208
             then if f x = x then x else chase(f,f x)
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   209
             else arb
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   210
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   211
Prove wf ==> f(chase(f,x)) = chase(f,x)
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   212
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   213
2. While / Tail recursion
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   214
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   215
chase f x = fst(while (%(x,fx). x=fx) (%(x,fx). (fx,f fx)) (x,f x))
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   216
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   217
==> unfold eqn for chase? Prove fixpoint property?
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   218
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   219
Better(?) sum i = fst(while (%(s,i). i=0) (%(s,i). (s+i,i-1)) (0,i))
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   220
Prove 0 <= i ==> sum i = i*(i+1) via while-rule
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   221
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   222
Mention prototyping?
383b0a1837a9 *** empty log message ***
nipkow
parents:
diff changeset
   223
==============================================================