author | wenzelm |
Thu, 15 Feb 2018 12:11:00 +0100 | |
changeset 67613 | ce654b0e6d69 |
parent 62390 | 842917225d56 |
permissions | -rw-r--r-- |
42151 | 1 |
(* Title: HOL/HOLCF/IOA/NTP/Correctness.thy |
3073
88366253a09a
Old NTP files now running under the IOA meta theory based on HOLCF;
mueller
parents:
diff
changeset
|
2 |
Author: Tobias Nipkow & Konrad Slind |
88366253a09a
Old NTP files now running under the IOA meta theory based on HOLCF;
mueller
parents:
diff
changeset
|
3 |
*) |
88366253a09a
Old NTP files now running under the IOA meta theory based on HOLCF;
mueller
parents:
diff
changeset
|
4 |
|
62002 | 5 |
section \<open>The main correctness proof: Impl implements Spec\<close> |
17244 | 6 |
|
7 |
theory Correctness |
|
8 |
imports Impl Spec |
|
9 |
begin |
|
3073
88366253a09a
Old NTP files now running under the IOA meta theory based on HOLCF;
mueller
parents:
diff
changeset
|
10 |
|
25131
2c8caac48ade
modernized specifications ('definition', 'abbreviation', 'notation');
wenzelm
parents:
19739
diff
changeset
|
11 |
definition |
2c8caac48ade
modernized specifications ('definition', 'abbreviation', 'notation');
wenzelm
parents:
19739
diff
changeset
|
12 |
hom :: "'m impl_state => 'm list" where |
2c8caac48ade
modernized specifications ('definition', 'abbreviation', 'notation');
wenzelm
parents:
19739
diff
changeset
|
13 |
"hom s = rq(rec(s)) @ (if rbit(rec s) = sbit(sen s) then sq(sen s) |
2c8caac48ade
modernized specifications ('definition', 'abbreviation', 'notation');
wenzelm
parents:
19739
diff
changeset
|
14 |
else tl(sq(sen s)))" |
3073
88366253a09a
Old NTP files now running under the IOA meta theory based on HOLCF;
mueller
parents:
diff
changeset
|
15 |
|
62002 | 16 |
setup \<open>map_theory_claset (fn ctxt => ctxt delSWrapper "split_all_tac")\<close> |
19739 | 17 |
|
18 |
lemmas hom_ioas = Spec.ioa_def Spec.trans_def sender_trans_def receiver_trans_def impl_ioas |
|
19 |
and impl_asigs = sender_asig_def receiver_asig_def srch_asig_def rsch_asig_def |
|
20 |
||
21 |
declare split_paired_All [simp del] |
|
22 |
||
23 |
||
62002 | 24 |
text \<open> |
19739 | 25 |
A lemma about restricting the action signature of the implementation |
26 |
to that of the specification. |
|
62002 | 27 |
\<close> |
19739 | 28 |
|
29 |
lemma externals_lemma: |
|
67613 | 30 |
"a\<in>externals(asig_of(Automata.restrict impl_ioa (externals spec_sig))) = |
19739 | 31 |
(case a of |
67613 | 32 |
S_msg(m) \<Rightarrow> True |
33 |
| R_msg(m) \<Rightarrow> True |
|
34 |
| S_pkt(pkt) \<Rightarrow> False |
|
35 |
| R_pkt(pkt) \<Rightarrow> False |
|
36 |
| S_ack(b) \<Rightarrow> False |
|
37 |
| R_ack(b) \<Rightarrow> False |
|
38 |
| C_m_s \<Rightarrow> False |
|
39 |
| C_m_r \<Rightarrow> False |
|
40 |
| C_r_s \<Rightarrow> False |
|
41 |
| C_r_r(m) \<Rightarrow> False)" |
|
19739 | 42 |
apply (simp (no_asm) add: externals_def restrict_def restrict_asig_def Spec.sig_def asig_projections) |
43 |
||
44 |
apply (induct_tac "a") |
|
45 |
apply (simp_all (no_asm) add: actions_def asig_projections) |
|
62002 | 46 |
txt \<open>2\<close> |
19739 | 47 |
apply (simp (no_asm) add: impl_ioas) |
48 |
apply (simp (no_asm) add: impl_asigs) |
|
49 |
apply (simp (no_asm) add: asig_of_par asig_comp_def asig_projections) |
|
35215
a03462cbf86f
get rid of warnings about duplicate simp rules in all HOLCF theories
huffman
parents:
35174
diff
changeset
|
50 |
apply (simp (no_asm) add: "transitions"(1) unfold_renaming) |
62002 | 51 |
txt \<open>1\<close> |
19739 | 52 |
apply (simp (no_asm) add: impl_ioas) |
53 |
apply (simp (no_asm) add: impl_asigs) |
|
54 |
apply (simp (no_asm) add: asig_of_par asig_comp_def asig_projections) |
|
55 |
done |
|
56 |
||
57 |
lemmas sels = sbit_def sq_def ssending_def rbit_def rq_def rsending_def |
|
58 |
||
59 |
||
62002 | 60 |
text \<open>Proof of correctness\<close> |
19739 | 61 |
lemma ntp_correct: |
62 |
"is_weak_ref_map hom (Automata.restrict impl_ioa (externals spec_sig)) spec_ioa" |
|
63 |
apply (unfold Spec.ioa_def is_weak_ref_map_def) |
|
62390 | 64 |
apply (simp (no_asm) cong del: if_weak_cong split del: if_split add: Correctness.hom_def |
19739 | 65 |
cancel_restrict externals_lemma) |
66 |
apply (rule conjI) |
|
67 |
apply (simp (no_asm) add: hom_ioas) |
|
68 |
apply (simp (no_asm_simp) add: sels) |
|
69 |
apply (rule allI)+ |
|
70 |
apply (rule imp_conj_lemma) |
|
71 |
||
72 |
apply (induct_tac "a") |
|
73 |
apply (simp_all (no_asm_simp) add: hom_ioas) |
|
74 |
apply (frule inv4) |
|
75 |
apply force |
|
76 |
||
77 |
apply (frule inv4) |
|
78 |
apply (frule inv2) |
|
79 |
apply (erule disjE) |
|
80 |
apply (simp (no_asm_simp)) |
|
81 |
apply force |
|
82 |
||
83 |
apply (frule inv2) |
|
84 |
apply (erule disjE) |
|
85 |
||
86 |
apply (frule inv3) |
|
87 |
apply (case_tac "sq (sen (s))=[]") |
|
88 |
||
89 |
apply (simp add: hom_ioas) |
|
90 |
apply (blast dest!: add_leD1 [THEN leD]) |
|
91 |
||
58270 | 92 |
apply (rename_tac m, case_tac "m = hd (sq (sen (s)))") |
19739 | 93 |
|
94 |
apply force |
|
95 |
||
96 |
apply simp |
|
97 |
apply (blast dest!: add_leD1 [THEN leD]) |
|
98 |
||
99 |
apply simp |
|
100 |
done |
|
17244 | 101 |
|
3073
88366253a09a
Old NTP files now running under the IOA meta theory based on HOLCF;
mueller
parents:
diff
changeset
|
102 |
end |