author  paulson 
Wed, 07 May 1997 12:50:26 +0200  
changeset 3120  c58423c20740 
child 3144  04b0d8941365 
permissions  rwrr 
3120
c58423c20740
New directory to contain examples of (co)inductive definitions
paulson
parents:
diff
changeset

1 
(* Title: HOL/Induct/Exp 
2 
ID: $Id$ 
3 
Author: Lawrence C Paulson, Cambridge University Computer Laboratory 
4 
Copyright 1997 University of Cambridge 
5 

6 
Example of Mutual Induction via Iteratived Inductive Definitions: Expressions 
7 
*) 
8 

9 
open Exp; 
10 

11 
val eval_elim_cases = map (eval.mk_cases exp.simps) 
12 
["(N(n),sigma) > (n',s')", "(X(x),sigma) > (n,s')", 
13 
"(Op f a1 a2,sigma) > (n,s')", 
14 
"(VALOF c RESULTIS e, s) > (n, s1)" 
15 
]; 
16 

17 
AddSEs eval_elim_cases; 
18 

19 

20 
(** Make the induction rule look nicer  though eta_contract makes the new 
21 
version look worse than it is...**) 
22 

23 
goal thy "{((e,s),(n,s')). P e s n s'} = \ 
24 
\ Collect (split (%v. split (split P v)))"; 
25 
by (rtac Collect_cong 1); 
26 
by (split_all_tac 1); 
27 
by (Simp_tac 1); 
28 
val split_lemma = result(); 
29 

30 
(*New induction rule. Note the form of the VALOF induction hypothesis*) 
31 
val major::prems = goal thy 
32 
"[ (e,s) > (n,s'); \ 
33 
\ !!n s. P (N n) s n s; \ 
34 
\ !!s x. P (X x) s (s x) s; \ 
35 
\ !!e0 e1 f n0 n1 s s0 s1. \ 
36 
\ [ (e0,s) > (n0,s0); P e0 s n0 s0; \ 
37 
\ (e1,s0) > (n1,s1); P e1 s0 n1 s1 \ 
38 
\ ] ==> P (Op f e0 e1) s (f n0 n1) s1; \ 
39 
\ !!c e n s s0 s1. \ 
40 
\ [ (c,s) [eval Int {((e,s),(n,s')). P e s n s'}]> s0; \ 
41 
\ (e,s0) > (n,s1); P e s0 n s1 ] \ 
42 
\ ==> P (VALOF c RESULTIS e) s n s1 \ 
43 
\ ] ==> P e s n s'"; 
44 
by (rtac (major RS eval.induct) 1); 
45 
by (blast_tac (!claset addIs prems) 1); 
46 
by (blast_tac (!claset addIs prems) 1); 
47 
by (blast_tac (!claset addIs prems) 1); 
48 
by (fast_tac (!claset addIs prems addss (!simpset addsimps [split_lemma])) 1); 
49 
qed "eval_induct"; 
50 

51 

52 
(*Lemma for Function_eval. The major premise is that (c,s) executes to s1 
53 
using eval restricted to its functional part. Note that the execution 
54 
(c,s) [eval]> s2 can use unrestricted eval! The reason is that 
55 
the execution (c,s) [eval Int {...}]> s1 assures us that execution is 
56 
functional on the argument (c,s). 
57 
*) 
58 
goal thy 
59 
"!!x. (c,s) [eval Int {((e,s),(n,s')). Unique (e,s) (n,s') eval}]> s1 \ 
60 
\ ==> (ALL s2. (c,s) [eval]> s2 > s2=s1)"; 
61 
by (etac exec.induct 1); 
62 
by (ALLGOALS Full_simp_tac); 
63 
by (Blast_tac 3); 
64 
by (Blast_tac 1); 
65 
by (rewtac Unique_def); 
66 
by (Blast_tac 1); 
67 
by (Blast_tac 1); 
68 
by (Blast_tac 1); 
69 
by (blast_tac (!claset addEs [exec_WHILE_case]) 1); 
70 
by (thin_tac "(?c,s2) [?ev]> s3" 1); 
71 
by (Step_tac 1); 
72 
by (etac exec_WHILE_case 1); 
73 
by (ALLGOALS Fast_tac); (*Blast_tac: proof fails*) 
74 
qed "com_Unique"; 
75 

76 

77 
(*Expression evaluation is functional, or deterministic*) 
78 
goal thy "Function eval"; 
79 
by (simp_tac (!simpset addsimps [Function_def]) 1); 
80 
by (REPEAT (rtac allI 1)); 
81 
by (rtac impI 1); 
82 
by (etac eval_induct 1); 
83 
by (dtac com_Unique 4); 
84 
by (ALLGOALS (full_simp_tac (!simpset addsimps [Unique_def]))); 
85 
by (ALLGOALS Blast_tac); 
86 
qed "Function_eval"; 