src/HOL/IMP/Live.thy
author blanchet
Tue, 30 Apr 2013 16:29:31 +0200
changeset 51842 cc0a3185406c
parent 51468 0e8012983c4e
child 51975 7bab3fb52e3e
permissions -rw-r--r--
added fields to database
Ignore whitespace changes - Everywhere: Within whitespace: At end of lines:
43158
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
     1
(* Author: Tobias Nipkow *)
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
     2
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
     3
header "Live Variable Analysis"
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
     4
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
     5
theory Live imports Vars Big_Step
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
     6
begin
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
     7
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
     8
subsection "Liveness Analysis"
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
     9
45212
e87feee00a4c renamed name -> vname
nipkow
parents: 45015
diff changeset
    10
fun L :: "com \<Rightarrow> vname set \<Rightarrow> vname set" where
51425
nipkow
parents: 51396
diff changeset
    11
"L SKIP X = X" |
51448
nipkow
parents: 51433
diff changeset
    12
"L (x ::= a) X = vars a \<union> (X - {x})" |
51425
nipkow
parents: 51396
diff changeset
    13
"L (c\<^isub>1; c\<^isub>2) X = L c\<^isub>1 (L c\<^isub>2 X)" |
43158
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
    14
"L (IF b THEN c\<^isub>1 ELSE c\<^isub>2) X = vars b \<union> L c\<^isub>1 X \<union> L c\<^isub>2 X" |
51425
nipkow
parents: 51396
diff changeset
    15
"L (WHILE b DO c) X = vars b \<union> X \<union> L c X"
43158
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
    16
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
    17
value "show (L (''y'' ::= V ''z''; ''x'' ::= Plus (V ''y'') (V ''z'')) {''x''})"
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
    18
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
    19
value "show (L (WHILE Less (V ''x'') (V ''x'') DO ''y'' ::= V ''z'') {''x''})"
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
    20
45212
e87feee00a4c renamed name -> vname
nipkow
parents: 45015
diff changeset
    21
fun "kill" :: "com \<Rightarrow> vname set" where
43158
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
    22
"kill SKIP = {}" |
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
    23
"kill (x ::= a) = {x}" |
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
    24
"kill (c\<^isub>1; c\<^isub>2) = kill c\<^isub>1 \<union> kill c\<^isub>2" |
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
    25
"kill (IF b THEN c\<^isub>1 ELSE c\<^isub>2) = kill c\<^isub>1 \<inter> kill c\<^isub>2" |
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
    26
"kill (WHILE b DO c) = {}"
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
    27
45212
e87feee00a4c renamed name -> vname
nipkow
parents: 45015
diff changeset
    28
fun gen :: "com \<Rightarrow> vname set" where
43158
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
    29
"gen SKIP = {}" |
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
    30
"gen (x ::= a) = vars a" |
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
    31
"gen (c\<^isub>1; c\<^isub>2) = gen c\<^isub>1 \<union> (gen c\<^isub>2 - kill c\<^isub>1)" |
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
    32
"gen (IF b THEN c\<^isub>1 ELSE c\<^isub>2) = vars b \<union> gen c\<^isub>1 \<union> gen c\<^isub>2" |
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
    33
"gen (WHILE b DO c) = vars b \<union> gen c"
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
    34
51433
nipkow
parents: 51425
diff changeset
    35
lemma L_gen_kill: "L c X = gen c \<union> (X - kill c)"
43158
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
    36
by(induct c arbitrary:X) auto
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
    37
45771
a70465244096 added lemmas
nipkow
parents: 45770
diff changeset
    38
lemma L_While_pfp: "L c (L (WHILE b DO c) X) \<subseteq> L (WHILE b DO c) X"
43158
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
    39
by(auto simp add:L_gen_kill)
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
    40
45771
a70465244096 added lemmas
nipkow
parents: 45770
diff changeset
    41
lemma L_While_lpfp:
45784
nipkow
parents: 45771
diff changeset
    42
  "vars b \<union> X \<union> L c P \<subseteq> P \<Longrightarrow> L (WHILE b DO c) X \<subseteq> P"
45771
a70465244096 added lemmas
nipkow
parents: 45770
diff changeset
    43
by(simp add: L_gen_kill)
a70465244096 added lemmas
nipkow
parents: 45770
diff changeset
    44
51468
0e8012983c4e proofs depend only on constraints, not on def of L WHILE
nipkow
parents: 51448
diff changeset
    45
lemma L_While_vars: "vars b \<subseteq> L (WHILE b DO c) X"
0e8012983c4e proofs depend only on constraints, not on def of L WHILE
nipkow
parents: 51448
diff changeset
    46
by auto
0e8012983c4e proofs depend only on constraints, not on def of L WHILE
nipkow
parents: 51448
diff changeset
    47
0e8012983c4e proofs depend only on constraints, not on def of L WHILE
nipkow
parents: 51448
diff changeset
    48
lemma L_While_X: "X \<subseteq> L (WHILE b DO c) X"
0e8012983c4e proofs depend only on constraints, not on def of L WHILE
nipkow
parents: 51448
diff changeset
    49
by auto
0e8012983c4e proofs depend only on constraints, not on def of L WHILE
nipkow
parents: 51448
diff changeset
    50
0e8012983c4e proofs depend only on constraints, not on def of L WHILE
nipkow
parents: 51448
diff changeset
    51
text{* Disable L WHILE equation and reason only with L WHILE constraints *}
0e8012983c4e proofs depend only on constraints, not on def of L WHILE
nipkow
parents: 51448
diff changeset
    52
declare L.simps(5)[simp del]
43158
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
    53
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
    54
subsection "Soundness"
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
    55
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
    56
theorem L_sound:
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
    57
  "(c,s) \<Rightarrow> s'  \<Longrightarrow> s = t on L c X \<Longrightarrow>
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
    58
  \<exists> t'. (c,t) \<Rightarrow> t' & s' = t' on X"
45015
fdac1e9880eb Updated IMP to use new induction method
nipkow
parents: 44923
diff changeset
    59
proof (induction arbitrary: X t rule: big_step_induct)
43158
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
    60
  case Skip then show ?case by auto
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
    61
next
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
    62
  case Assign then show ?case
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
    63
    by (auto simp: ball_Un)
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
    64
next
47818
151d137f1095 renamed Semi to Seq
nipkow
parents: 45784
diff changeset
    65
  case (Seq c1 s1 s2 c2 s3 X t1)
151d137f1095 renamed Semi to Seq
nipkow
parents: 45784
diff changeset
    66
  from Seq.IH(1) Seq.prems obtain t2 where
43158
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
    67
    t12: "(c1, t1) \<Rightarrow> t2" and s2t2: "s2 = t2 on L c2 X"
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
    68
    by simp blast
47818
151d137f1095 renamed Semi to Seq
nipkow
parents: 45784
diff changeset
    69
  from Seq.IH(2)[OF s2t2] obtain t3 where
43158
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
    70
    t23: "(c2, t2) \<Rightarrow> t3" and s3t3: "s3 = t3 on X"
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
    71
    by auto
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
    72
  show ?case using t12 t23 s3t3 by auto
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
    73
next
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
    74
  case (IfTrue b s c1 s' c2)
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
    75
  hence "s = t on vars b" "s = t on L c1 X" by auto
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
    76
  from  bval_eq_if_eq_on_vars[OF this(1)] IfTrue(1) have "bval b t" by simp
50009
nipkow
parents: 47818
diff changeset
    77
  from IfTrue.IH[OF `s = t on L c1 X`] obtain t' where
43158
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
    78
    "(c1, t) \<Rightarrow> t'" "s' = t' on X" by auto
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
    79
  thus ?case using `bval b t` by auto
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
    80
next
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
    81
  case (IfFalse b s c2 s' c1)
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
    82
  hence "s = t on vars b" "s = t on L c2 X" by auto
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
    83
  from  bval_eq_if_eq_on_vars[OF this(1)] IfFalse(1) have "~bval b t" by simp
50009
nipkow
parents: 47818
diff changeset
    84
  from IfFalse.IH[OF `s = t on L c2 X`] obtain t' where
43158
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
    85
    "(c2, t) \<Rightarrow> t'" "s' = t' on X" by auto
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
    86
  thus ?case using `~bval b t` by auto
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
    87
next
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
    88
  case (WhileFalse b s c)
51468
0e8012983c4e proofs depend only on constraints, not on def of L WHILE
nipkow
parents: 51448
diff changeset
    89
  hence "~ bval b t"
0e8012983c4e proofs depend only on constraints, not on def of L WHILE
nipkow
parents: 51448
diff changeset
    90
    by (metis L_While_vars bval_eq_if_eq_on_vars set_mp)
0e8012983c4e proofs depend only on constraints, not on def of L WHILE
nipkow
parents: 51448
diff changeset
    91
  thus ?case by(metis WhileFalse.prems L_While_X big_step.WhileFalse set_mp)
43158
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
    92
next
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
    93
  case (WhileTrue b s1 c s2 s3 X t1)
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
    94
  let ?w = "WHILE b DO c"
45770
5d35cb2c0f02 tuned proof
nipkow
parents: 45212
diff changeset
    95
  from `bval b s1` WhileTrue.prems have "bval b t1"
51468
0e8012983c4e proofs depend only on constraints, not on def of L WHILE
nipkow
parents: 51448
diff changeset
    96
    by (metis L_While_vars bval_eq_if_eq_on_vars set_mp)
0e8012983c4e proofs depend only on constraints, not on def of L WHILE
nipkow
parents: 51448
diff changeset
    97
  have "s1 = t1 on L c (L ?w X)" using L_While_pfp WhileTrue.prems
43158
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
    98
    by (blast)
45015
fdac1e9880eb Updated IMP to use new induction method
nipkow
parents: 44923
diff changeset
    99
  from WhileTrue.IH(1)[OF this] obtain t2 where
43158
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
   100
    "(c, t1) \<Rightarrow> t2" "s2 = t2 on L ?w X" by auto
45015
fdac1e9880eb Updated IMP to use new induction method
nipkow
parents: 44923
diff changeset
   101
  from WhileTrue.IH(2)[OF this(2)] obtain t3 where "(?w,t2) \<Rightarrow> t3" "s3 = t3 on X"
43158
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
   102
    by auto
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
   103
  with `bval b t1` `(c, t1) \<Rightarrow> t2` show ?case by auto
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
   104
qed
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
   105
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
   106
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
   107
subsection "Program Optimization"
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
   108
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
   109
text{* Burying assignments to dead variables: *}
45212
e87feee00a4c renamed name -> vname
nipkow
parents: 45015
diff changeset
   110
fun bury :: "com \<Rightarrow> vname set \<Rightarrow> com" where
43158
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
   111
"bury SKIP X = SKIP" |
50009
nipkow
parents: 47818
diff changeset
   112
"bury (x ::= a) X = (if x \<in> X then x ::= a else SKIP)" |
43158
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
   113
"bury (c\<^isub>1; c\<^isub>2) X = (bury c\<^isub>1 (L c\<^isub>2 X); bury c\<^isub>2 X)" |
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
   114
"bury (IF b THEN c\<^isub>1 ELSE c\<^isub>2) X = IF b THEN bury c\<^isub>1 X ELSE bury c\<^isub>2 X" |
51468
0e8012983c4e proofs depend only on constraints, not on def of L WHILE
nipkow
parents: 51448
diff changeset
   115
"bury (WHILE b DO c) X = WHILE b DO bury c (L (WHILE b DO c) X)"
43158
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
   116
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
   117
text{* We could prove the analogous lemma to @{thm[source]L_sound}, and the
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
   118
proof would be very similar. However, we phrase it as a semantics
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
   119
preservation property: *}
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
   120
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
   121
theorem bury_sound:
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
   122
  "(c,s) \<Rightarrow> s'  \<Longrightarrow> s = t on L c X \<Longrightarrow>
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
   123
  \<exists> t'. (bury c X,t) \<Rightarrow> t' & s' = t' on X"
45015
fdac1e9880eb Updated IMP to use new induction method
nipkow
parents: 44923
diff changeset
   124
proof (induction arbitrary: X t rule: big_step_induct)
43158
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
   125
  case Skip then show ?case by auto
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
   126
next
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
   127
  case Assign then show ?case
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
   128
    by (auto simp: ball_Un)
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
   129
next
47818
151d137f1095 renamed Semi to Seq
nipkow
parents: 45784
diff changeset
   130
  case (Seq c1 s1 s2 c2 s3 X t1)
151d137f1095 renamed Semi to Seq
nipkow
parents: 45784
diff changeset
   131
  from Seq.IH(1) Seq.prems obtain t2 where
43158
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
   132
    t12: "(bury c1 (L c2 X), t1) \<Rightarrow> t2" and s2t2: "s2 = t2 on L c2 X"
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
   133
    by simp blast
47818
151d137f1095 renamed Semi to Seq
nipkow
parents: 45784
diff changeset
   134
  from Seq.IH(2)[OF s2t2] obtain t3 where
43158
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
   135
    t23: "(bury c2 X, t2) \<Rightarrow> t3" and s3t3: "s3 = t3 on X"
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
   136
    by auto
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
   137
  show ?case using t12 t23 s3t3 by auto
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
   138
next
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
   139
  case (IfTrue b s c1 s' c2)
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
   140
  hence "s = t on vars b" "s = t on L c1 X" by auto
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
   141
  from  bval_eq_if_eq_on_vars[OF this(1)] IfTrue(1) have "bval b t" by simp
50009
nipkow
parents: 47818
diff changeset
   142
  from IfTrue.IH[OF `s = t on L c1 X`] obtain t' where
43158
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
   143
    "(bury c1 X, t) \<Rightarrow> t'" "s' =t' on X" by auto
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
   144
  thus ?case using `bval b t` by auto
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
   145
next
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
   146
  case (IfFalse b s c2 s' c1)
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
   147
  hence "s = t on vars b" "s = t on L c2 X" by auto
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
   148
  from  bval_eq_if_eq_on_vars[OF this(1)] IfFalse(1) have "~bval b t" by simp
50009
nipkow
parents: 47818
diff changeset
   149
  from IfFalse.IH[OF `s = t on L c2 X`] obtain t' where
43158
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
   150
    "(bury c2 X, t) \<Rightarrow> t'" "s' = t' on X" by auto
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
   151
  thus ?case using `~bval b t` by auto
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
   152
next
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
   153
  case (WhileFalse b s c)
51468
0e8012983c4e proofs depend only on constraints, not on def of L WHILE
nipkow
parents: 51448
diff changeset
   154
  hence "~ bval b t" by (metis L_While_vars bval_eq_if_eq_on_vars set_mp)
0e8012983c4e proofs depend only on constraints, not on def of L WHILE
nipkow
parents: 51448
diff changeset
   155
  thus ?case
0e8012983c4e proofs depend only on constraints, not on def of L WHILE
nipkow
parents: 51448
diff changeset
   156
    by simp (metis L_While_X WhileFalse.prems big_step.WhileFalse set_mp)
43158
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
   157
next
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
   158
  case (WhileTrue b s1 c s2 s3 X t1)
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
   159
  let ?w = "WHILE b DO c"
45770
5d35cb2c0f02 tuned proof
nipkow
parents: 45212
diff changeset
   160
  from `bval b s1` WhileTrue.prems have "bval b t1"
51468
0e8012983c4e proofs depend only on constraints, not on def of L WHILE
nipkow
parents: 51448
diff changeset
   161
    by (metis L_While_vars bval_eq_if_eq_on_vars set_mp)
43158
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
   162
  have "s1 = t1 on L c (L ?w X)"
45771
a70465244096 added lemmas
nipkow
parents: 45770
diff changeset
   163
    using L_While_pfp WhileTrue.prems by blast
45015
fdac1e9880eb Updated IMP to use new induction method
nipkow
parents: 44923
diff changeset
   164
  from WhileTrue.IH(1)[OF this] obtain t2 where
43158
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
   165
    "(bury c (L ?w X), t1) \<Rightarrow> t2" "s2 = t2 on L ?w X" by auto
45015
fdac1e9880eb Updated IMP to use new induction method
nipkow
parents: 44923
diff changeset
   166
  from WhileTrue.IH(2)[OF this(2)] obtain t3
43158
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
   167
    where "(bury ?w X,t2) \<Rightarrow> t3" "s3 = t3 on X"
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
   168
    by auto
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
   169
  with `bval b t1` `(bury c (L ?w X), t1) \<Rightarrow> t2` show ?case by auto
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
   170
qed
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
   171
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
   172
corollary final_bury_sound: "(c,s) \<Rightarrow> s' \<Longrightarrow> (bury c UNIV,s) \<Rightarrow> s'"
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
   173
using bury_sound[of c s s' UNIV]
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
   174
by (auto simp: fun_eq_iff[symmetric])
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
   175
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
   176
text{* Now the opposite direction. *}
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
   177
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
   178
lemma SKIP_bury[simp]:
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
   179
  "SKIP = bury c X \<longleftrightarrow> c = SKIP | (EX x a. c = x::=a & x \<notin> X)"
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
   180
by (cases c) auto
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
   181
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
   182
lemma Assign_bury[simp]: "x::=a = bury c X \<longleftrightarrow> c = x::=a & x : X"
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
   183
by (cases c) auto
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
   184
47818
151d137f1095 renamed Semi to Seq
nipkow
parents: 45784
diff changeset
   185
lemma Seq_bury[simp]: "bc\<^isub>1;bc\<^isub>2 = bury c X \<longleftrightarrow>
43158
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
   186
  (EX c\<^isub>1 c\<^isub>2. c = c\<^isub>1;c\<^isub>2 & bc\<^isub>2 = bury c\<^isub>2 X & bc\<^isub>1 = bury c\<^isub>1 (L c\<^isub>2 X))"
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
   187
by (cases c) auto
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
   188
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
   189
lemma If_bury[simp]: "IF b THEN bc1 ELSE bc2 = bury c X \<longleftrightarrow>
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
   190
  (EX c1 c2. c = IF b THEN c1 ELSE c2 &
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
   191
     bc1 = bury c1 X & bc2 = bury c2 X)"
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
   192
by (cases c) auto
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
   193
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
   194
lemma While_bury[simp]: "WHILE b DO bc' = bury c X \<longleftrightarrow>
51468
0e8012983c4e proofs depend only on constraints, not on def of L WHILE
nipkow
parents: 51448
diff changeset
   195
  (EX c'. c = WHILE b DO c' & bc' = bury c' (L (WHILE b DO c') X))"
43158
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
   196
by (cases c) auto
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
   197
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
   198
theorem bury_sound2:
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
   199
  "(bury c X,s) \<Rightarrow> s'  \<Longrightarrow> s = t on L c X \<Longrightarrow>
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
   200
  \<exists> t'. (c,t) \<Rightarrow> t' & s' = t' on X"
45015
fdac1e9880eb Updated IMP to use new induction method
nipkow
parents: 44923
diff changeset
   201
proof (induction "bury c X" s s' arbitrary: c X t rule: big_step_induct)
43158
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
   202
  case Skip then show ?case by auto
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
   203
next
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
   204
  case Assign then show ?case
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
   205
    by (auto simp: ball_Un)
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
   206
next
47818
151d137f1095 renamed Semi to Seq
nipkow
parents: 45784
diff changeset
   207
  case (Seq bc1 s1 s2 bc2 s3 c X t1)
43158
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
   208
  then obtain c1 c2 where c: "c = c1;c2"
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
   209
    and bc2: "bc2 = bury c2 X" and bc1: "bc1 = bury c1 (L c2 X)" by auto
47818
151d137f1095 renamed Semi to Seq
nipkow
parents: 45784
diff changeset
   210
  note IH = Seq.hyps(2,4)
151d137f1095 renamed Semi to Seq
nipkow
parents: 45784
diff changeset
   211
  from IH(1)[OF bc1, of t1] Seq.prems c obtain t2 where
43158
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
   212
    t12: "(c1, t1) \<Rightarrow> t2" and s2t2: "s2 = t2 on L c2 X" by auto
45015
fdac1e9880eb Updated IMP to use new induction method
nipkow
parents: 44923
diff changeset
   213
  from IH(2)[OF bc2 s2t2] obtain t3 where
43158
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
   214
    t23: "(c2, t2) \<Rightarrow> t3" and s3t3: "s3 = t3 on X"
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
   215
    by auto
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
   216
  show ?case using c t12 t23 s3t3 by auto
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
   217
next
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
   218
  case (IfTrue b s bc1 s' bc2)
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
   219
  then obtain c1 c2 where c: "c = IF b THEN c1 ELSE c2"
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
   220
    and bc1: "bc1 = bury c1 X" and bc2: "bc2 = bury c2 X" by auto
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
   221
  have "s = t on vars b" "s = t on L c1 X" using IfTrue.prems c by auto
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
   222
  from bval_eq_if_eq_on_vars[OF this(1)] IfTrue(1) have "bval b t" by simp
45015
fdac1e9880eb Updated IMP to use new induction method
nipkow
parents: 44923
diff changeset
   223
  note IH = IfTrue.hyps(3)
fdac1e9880eb Updated IMP to use new induction method
nipkow
parents: 44923
diff changeset
   224
  from IH[OF bc1 `s = t on L c1 X`] obtain t' where
43158
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
   225
    "(c1, t) \<Rightarrow> t'" "s' =t' on X" by auto
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
   226
  thus ?case using c `bval b t` by auto
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
   227
next
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
   228
  case (IfFalse b s bc2 s' bc1)
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
   229
  then obtain c1 c2 where c: "c = IF b THEN c1 ELSE c2"
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
   230
    and bc1: "bc1 = bury c1 X" and bc2: "bc2 = bury c2 X" by auto
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
   231
  have "s = t on vars b" "s = t on L c2 X" using IfFalse.prems c by auto
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
   232
  from bval_eq_if_eq_on_vars[OF this(1)] IfFalse(1) have "~bval b t" by simp
45015
fdac1e9880eb Updated IMP to use new induction method
nipkow
parents: 44923
diff changeset
   233
  note IH = IfFalse.hyps(3)
fdac1e9880eb Updated IMP to use new induction method
nipkow
parents: 44923
diff changeset
   234
  from IH[OF bc2 `s = t on L c2 X`] obtain t' where
43158
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
   235
    "(c2, t) \<Rightarrow> t'" "s' =t' on X" by auto
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
   236
  thus ?case using c `~bval b t` by auto
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
   237
next
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
   238
  case (WhileFalse b s c)
51468
0e8012983c4e proofs depend only on constraints, not on def of L WHILE
nipkow
parents: 51448
diff changeset
   239
  hence "~ bval b t"
0e8012983c4e proofs depend only on constraints, not on def of L WHILE
nipkow
parents: 51448
diff changeset
   240
    by auto (metis L_While_vars bval_eq_if_eq_on_vars set_rev_mp)
0e8012983c4e proofs depend only on constraints, not on def of L WHILE
nipkow
parents: 51448
diff changeset
   241
  thus ?case using WhileFalse
0e8012983c4e proofs depend only on constraints, not on def of L WHILE
nipkow
parents: 51448
diff changeset
   242
    by auto (metis L_While_X big_step.WhileFalse set_mp)
43158
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
   243
next
51468
0e8012983c4e proofs depend only on constraints, not on def of L WHILE
nipkow
parents: 51448
diff changeset
   244
  case (WhileTrue b s1 bc' s2 s3 w X t1)
0e8012983c4e proofs depend only on constraints, not on def of L WHILE
nipkow
parents: 51448
diff changeset
   245
  then obtain c' where w: "w = WHILE b DO c'"
0e8012983c4e proofs depend only on constraints, not on def of L WHILE
nipkow
parents: 51448
diff changeset
   246
    and bc': "bc' = bury c' (L (WHILE b DO c') X)" by auto
0e8012983c4e proofs depend only on constraints, not on def of L WHILE
nipkow
parents: 51448
diff changeset
   247
  from `bval b s1` WhileTrue.prems w have "bval b t1"
0e8012983c4e proofs depend only on constraints, not on def of L WHILE
nipkow
parents: 51448
diff changeset
   248
    by auto (metis L_While_vars bval_eq_if_eq_on_vars set_mp)
45015
fdac1e9880eb Updated IMP to use new induction method
nipkow
parents: 44923
diff changeset
   249
  note IH = WhileTrue.hyps(3,5)
51468
0e8012983c4e proofs depend only on constraints, not on def of L WHILE
nipkow
parents: 51448
diff changeset
   250
  have "s1 = t1 on L c' (L w X)"
0e8012983c4e proofs depend only on constraints, not on def of L WHILE
nipkow
parents: 51448
diff changeset
   251
    using L_While_pfp WhileTrue.prems w by blast
0e8012983c4e proofs depend only on constraints, not on def of L WHILE
nipkow
parents: 51448
diff changeset
   252
  with IH(1)[OF bc', of t1] w obtain t2 where
0e8012983c4e proofs depend only on constraints, not on def of L WHILE
nipkow
parents: 51448
diff changeset
   253
    "(c', t1) \<Rightarrow> t2" "s2 = t2 on L w X" by auto
0e8012983c4e proofs depend only on constraints, not on def of L WHILE
nipkow
parents: 51448
diff changeset
   254
  from IH(2)[OF WhileTrue.hyps(6), of t2] w this(2) obtain t3
0e8012983c4e proofs depend only on constraints, not on def of L WHILE
nipkow
parents: 51448
diff changeset
   255
    where "(w,t2) \<Rightarrow> t3" "s3 = t3 on X"
43158
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
   256
    by auto
51468
0e8012983c4e proofs depend only on constraints, not on def of L WHILE
nipkow
parents: 51448
diff changeset
   257
  with `bval b t1` `(c', t1) \<Rightarrow> t2` w show ?case by auto
43158
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
   258
qed
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
   259
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
   260
corollary final_bury_sound2: "(bury c UNIV,s) \<Rightarrow> s' \<Longrightarrow> (c,s) \<Rightarrow> s'"
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
   261
using bury_sound2[of c UNIV]
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
   262
by (auto simp: fun_eq_iff[symmetric])
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
   263
51433
nipkow
parents: 51425
diff changeset
   264
corollary bury_sim: "bury c UNIV \<sim> c"
43158
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
   265
by(metis final_bury_sound final_bury_sound2)
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
   266
686fa0a0696e imported rest of new IMP
kleing
parents:
diff changeset
   267
end