| author | nipkow | 
| Thu, 01 Apr 2010 09:31:58 +0200 | |
| changeset 36070 | d80e5d3c8fe1 | 
| parent 35807 | e4d1b5cbd429 | 
| child 36176 | 3fe7e97ccca8 | 
| permissions | -rw-r--r-- | 
| 33192 | 1 | (* Title: HOL/Nitpick.thy | 
| 2 | Author: Jasmin Blanchette, TU Muenchen | |
| 35807 
e4d1b5cbd429
added support for "specification" and "ax_specification" constructs to Nitpick
 blanchet parents: 
35699diff
changeset | 3 | Copyright 2008, 2009, 2010 | 
| 33192 | 4 | |
| 5 | Nitpick: Yet another counterexample generator for Isabelle/HOL. | |
| 6 | *) | |
| 7 | ||
| 8 | header {* Nitpick: Yet Another Counterexample Generator for Isabelle/HOL *}
 | |
| 9 | ||
| 10 | theory Nitpick | |
| 35284 
9edc2bd6d2bd
enabled Nitpick's support for quotient types + shortened the Nitpick tests a bit
 blanchet parents: 
35220diff
changeset | 11 | imports Map Quotient SAT | 
| 33192 | 12 | uses ("Tools/Nitpick/kodkod.ML")
 | 
| 13 |      ("Tools/Nitpick/kodkod_sat.ML")
 | |
| 14 |      ("Tools/Nitpick/nitpick_util.ML")
 | |
| 15 |      ("Tools/Nitpick/nitpick_hol.ML")
 | |
| 35070 
96136eb6218f
split "nitpick_hol.ML" into two files to make it more manageable;
 blanchet parents: 
34982diff
changeset | 16 |      ("Tools/Nitpick/nitpick_preproc.ML")
 | 
| 33192 | 17 |      ("Tools/Nitpick/nitpick_mono.ML")
 | 
| 18 |      ("Tools/Nitpick/nitpick_scope.ML")
 | |
| 19 |      ("Tools/Nitpick/nitpick_peephole.ML")
 | |
| 20 |      ("Tools/Nitpick/nitpick_rep.ML")
 | |
| 21 |      ("Tools/Nitpick/nitpick_nut.ML")
 | |
| 22 |      ("Tools/Nitpick/nitpick_kodkod.ML")
 | |
| 23 |      ("Tools/Nitpick/nitpick_model.ML")
 | |
| 24 |      ("Tools/Nitpick/nitpick.ML")
 | |
| 25 |      ("Tools/Nitpick/nitpick_isar.ML")
 | |
| 26 |      ("Tools/Nitpick/nitpick_tests.ML")
 | |
| 27 |      ("Tools/Nitpick/minipick.ML")
 | |
| 28 | begin | |
| 29 | ||
| 30 | typedecl bisim_iterator | |
| 31 | ||
| 32 | axiomatization unknown :: 'a | |
| 34938 | 33 | and is_unknown :: "'a \<Rightarrow> bool" | 
| 33192 | 34 | and undefined_fast_The :: 'a | 
| 35 | and undefined_fast_Eps :: 'a | |
| 36 | and bisim :: "bisim_iterator \<Rightarrow> 'a \<Rightarrow> 'a \<Rightarrow> bool" | |
| 37 | and bisim_iterator_max :: bisim_iterator | |
| 34938 | 38 | and Quot :: "'a \<Rightarrow> 'b" | 
| 35671 
ed2c3830d881
improved Nitpick's precision for "card" and "setsum" + fix incorrect outcome code w.r.t. "bisim_depth = -1"
 blanchet parents: 
35665diff
changeset | 39 |            and safe_The :: "('a \<Rightarrow> bool) \<Rightarrow> 'a"
 | 
| 
ed2c3830d881
improved Nitpick's precision for "card" and "setsum" + fix incorrect outcome code w.r.t. "bisim_depth = -1"
 blanchet parents: 
35665diff
changeset | 40 |            and safe_Eps :: "('a \<Rightarrow> bool) \<Rightarrow> 'a"
 | 
| 33192 | 41 | |
| 35665 
ff2bf50505ab
added "finitize" option to Nitpick + remove dependency on "Coinductive_List"
 blanchet parents: 
35311diff
changeset | 42 | datatype ('a, 'b) fin_fun = FinFun "('a \<Rightarrow> 'b)"
 | 
| 
ff2bf50505ab
added "finitize" option to Nitpick + remove dependency on "Coinductive_List"
 blanchet parents: 
35311diff
changeset | 43 | datatype ('a, 'b) fun_box = FunBox "('a \<Rightarrow> 'b)"
 | 
| 33192 | 44 | datatype ('a, 'b) pair_box = PairBox 'a 'b
 | 
| 34124 
c4628a1dcf75
added support for binary nat/int representation to Nitpick
 blanchet parents: 
33747diff
changeset | 45 | |
| 
c4628a1dcf75
added support for binary nat/int representation to Nitpick
 blanchet parents: 
33747diff
changeset | 46 | typedecl unsigned_bit | 
| 
c4628a1dcf75
added support for binary nat/int representation to Nitpick
 blanchet parents: 
33747diff
changeset | 47 | typedecl signed_bit | 
| 
c4628a1dcf75
added support for binary nat/int representation to Nitpick
 blanchet parents: 
33747diff
changeset | 48 | |
| 
c4628a1dcf75
added support for binary nat/int representation to Nitpick
 blanchet parents: 
33747diff
changeset | 49 | datatype 'a word = Word "('a set)"
 | 
| 33192 | 50 | |
| 51 | text {*
 | |
| 52 | Alternative definitions. | |
| 53 | *} | |
| 54 | ||
| 55 | lemma If_def [nitpick_def]: | |
| 56 | "(if P then Q else R) \<equiv> (P \<longrightarrow> Q) \<and> (\<not> P \<longrightarrow> R)" | |
| 57 | by (rule eq_reflection) (rule if_bool_eq_conj) | |
| 58 | ||
| 59 | lemma Ex1_def [nitpick_def]: | |
| 60 | "Ex1 P \<equiv> \<exists>x. P = {x}"
 | |
| 61 | apply (rule eq_reflection) | |
| 62 | apply (simp add: Ex1_def expand_set_eq) | |
| 63 | apply (rule iffI) | |
| 64 | apply (erule exE) | |
| 65 | apply (erule conjE) | |
| 66 | apply (rule_tac x = x in exI) | |
| 67 | apply (rule allI) | |
| 68 | apply (rename_tac y) | |
| 69 | apply (erule_tac x = y in allE) | |
| 70 | by (auto simp: mem_def) | |
| 71 | ||
| 72 | lemma rtrancl_def [nitpick_def]: "r\<^sup>* \<equiv> (r\<^sup>+)\<^sup>=" | |
| 73 | by simp | |
| 74 | ||
| 75 | lemma rtranclp_def [nitpick_def]: | |
| 76 | "rtranclp r a b \<equiv> (a = b \<or> tranclp r a b)" | |
| 77 | by (rule eq_reflection) (auto dest: rtranclpD) | |
| 78 | ||
| 79 | lemma tranclp_def [nitpick_def]: | |
| 80 | "tranclp r a b \<equiv> trancl (split r) (a, b)" | |
| 81 | by (simp add: trancl_def Collect_def mem_def) | |
| 82 | ||
| 83 | definition refl' :: "('a \<times> 'a \<Rightarrow> bool) \<Rightarrow> bool" where
 | |
| 84 | "refl' r \<equiv> \<forall>x. (x, x) \<in> r" | |
| 85 | ||
| 86 | definition wf' :: "('a \<times> 'a \<Rightarrow> bool) \<Rightarrow> bool" where
 | |
| 87 | "wf' r \<equiv> acyclic r \<and> (finite r \<or> unknown)" | |
| 88 | ||
| 89 | axiomatization wf_wfrec :: "('a \<times> 'a \<Rightarrow> bool) \<Rightarrow> (('a \<Rightarrow> 'b) \<Rightarrow> 'a \<Rightarrow> 'b) \<Rightarrow> 'a \<Rightarrow> 'b"
 | |
| 90 | ||
| 91 | definition wf_wfrec' :: "('a \<times> 'a \<Rightarrow> bool) \<Rightarrow> (('a \<Rightarrow> 'b) \<Rightarrow> 'a \<Rightarrow> 'b) \<Rightarrow> 'a \<Rightarrow> 'b" where
 | |
| 92 | [nitpick_simp]: "wf_wfrec' R F x = F (Recdef.cut (wf_wfrec R F) R x) x" | |
| 93 | ||
| 94 | definition wfrec' ::  "('a \<times> 'a \<Rightarrow> bool) \<Rightarrow> (('a \<Rightarrow> 'b) \<Rightarrow> 'a \<Rightarrow> 'b) \<Rightarrow> 'a \<Rightarrow> 'b" where
 | |
| 95 | "wfrec' R F x \<equiv> if wf R then wf_wfrec' R F x | |
| 96 | else THE y. wfrec_rel R (%f x. F (Recdef.cut f R x) x) x y" | |
| 97 | ||
| 98 | definition card' :: "('a \<Rightarrow> bool) \<Rightarrow> nat" where
 | |
| 35699 | 99 | "card' A \<equiv> if finite A then length (safe_Eps (\<lambda>xs. set xs = A \<and> distinct xs)) else 0" | 
| 33192 | 100 | |
| 101 | definition setsum' :: "('a \<Rightarrow> 'b\<Colon>comm_monoid_add) \<Rightarrow> ('a \<Rightarrow> bool) \<Rightarrow> 'b" where
 | |
| 35699 | 102 | "setsum' f A \<equiv> if finite A then listsum (map f (safe_Eps (\<lambda>xs. set xs = A \<and> distinct xs))) else 0" | 
| 33192 | 103 | |
| 104 | inductive fold_graph' :: "('a \<Rightarrow> 'b \<Rightarrow> 'b) \<Rightarrow> 'b \<Rightarrow> ('a \<Rightarrow> bool) \<Rightarrow> 'b \<Rightarrow> bool" where
 | |
| 105 | "fold_graph' f z {} z" |
 | |
| 106 | "\<lbrakk>x \<in> A; fold_graph' f z (A - {x}) y\<rbrakk> \<Longrightarrow> fold_graph' f z A (f x y)"
 | |
| 107 | ||
| 108 | text {*
 | |
| 109 | The following lemmas are not strictly necessary but they help the | |
| 110 | \textit{special\_level} optimization.
 | |
| 111 | *} | |
| 112 | ||
| 113 | lemma The_psimp [nitpick_psimp]: | |
| 114 | "P = {x} \<Longrightarrow> The P = x"
 | |
| 115 | by (subgoal_tac "{x} = (\<lambda>y. y = x)") (auto simp: mem_def)
 | |
| 116 | ||
| 117 | lemma Eps_psimp [nitpick_psimp]: | |
| 118 | "\<lbrakk>P x; \<not> P y; Eps P = y\<rbrakk> \<Longrightarrow> Eps P = x" | |
| 119 | apply (case_tac "P (Eps P)") | |
| 120 | apply auto | |
| 121 | apply (erule contrapos_np) | |
| 122 | by (rule someI) | |
| 123 | ||
| 124 | lemma unit_case_def [nitpick_def]: | |
| 125 | "unit_case x u \<equiv> x" | |
| 126 | apply (subgoal_tac "u = ()") | |
| 127 | apply (simp only: unit.cases) | |
| 128 | by simp | |
| 129 | ||
| 33556 
cba22e2999d5
renamed Nitpick option "coalesce_type_vars" to "merge_type_vars" (shorter) and cleaned up old hacks that are no longer necessary
 blanchet parents: 
33192diff
changeset | 130 | declare unit.cases [nitpick_simp del] | 
| 
cba22e2999d5
renamed Nitpick option "coalesce_type_vars" to "merge_type_vars" (shorter) and cleaned up old hacks that are no longer necessary
 blanchet parents: 
33192diff
changeset | 131 | |
| 33192 | 132 | lemma nat_case_def [nitpick_def]: | 
| 133 | "nat_case x f n \<equiv> if n = 0 then x else f (n - 1)" | |
| 134 | apply (rule eq_reflection) | |
| 135 | by (case_tac n) auto | |
| 136 | ||
| 33556 
cba22e2999d5
renamed Nitpick option "coalesce_type_vars" to "merge_type_vars" (shorter) and cleaned up old hacks that are no longer necessary
 blanchet parents: 
33192diff
changeset | 137 | declare nat.cases [nitpick_simp del] | 
| 
cba22e2999d5
renamed Nitpick option "coalesce_type_vars" to "merge_type_vars" (shorter) and cleaned up old hacks that are no longer necessary
 blanchet parents: 
33192diff
changeset | 138 | |
| 33192 | 139 | lemma list_size_simp [nitpick_simp]: | 
| 140 | "list_size f xs = (if xs = [] then 0 | |
| 141 | else Suc (f (hd xs) + list_size f (tl xs)))" | |
| 142 | "size xs = (if xs = [] then 0 else Suc (size (tl xs)))" | |
| 143 | by (case_tac xs) auto | |
| 144 | ||
| 145 | text {*
 | |
| 146 | Auxiliary definitions used to provide an alternative representation for | |
| 147 | @{text rat} and @{text real}.
 | |
| 148 | *} | |
| 149 | ||
| 150 | function nat_gcd :: "nat \<Rightarrow> nat \<Rightarrow> nat" where | |
| 151 | [simp del]: "nat_gcd x y = (if y = 0 then x else nat_gcd y (x mod y))" | |
| 152 | by auto | |
| 153 | termination | |
| 154 | apply (relation "measure (\<lambda>(x, y). x + y + (if y > x then 1 else 0))") | |
| 155 | apply auto | |
| 156 | apply (metis mod_less_divisor xt1(9)) | |
| 157 | by (metis mod_mod_trivial mod_self nat_neq_iff xt1(10)) | |
| 158 | ||
| 159 | definition nat_lcm :: "nat \<Rightarrow> nat \<Rightarrow> nat" where | |
| 160 | "nat_lcm x y = x * y div (nat_gcd x y)" | |
| 161 | ||
| 162 | definition int_gcd :: "int \<Rightarrow> int \<Rightarrow> int" where | |
| 163 | "int_gcd x y = int (nat_gcd (nat (abs x)) (nat (abs y)))" | |
| 164 | ||
| 165 | definition int_lcm :: "int \<Rightarrow> int \<Rightarrow> int" where | |
| 166 | "int_lcm x y = int (nat_lcm (nat (abs x)) (nat (abs y)))" | |
| 167 | ||
| 168 | definition Frac :: "int \<times> int \<Rightarrow> bool" where | |
| 169 | "Frac \<equiv> \<lambda>(a, b). b > 0 \<and> int_gcd a b = 1" | |
| 170 | ||
| 171 | axiomatization Abs_Frac :: "int \<times> int \<Rightarrow> 'a" | |
| 172 | and Rep_Frac :: "'a \<Rightarrow> int \<times> int" | |
| 173 | ||
| 174 | definition zero_frac :: 'a where | |
| 175 | "zero_frac \<equiv> Abs_Frac (0, 1)" | |
| 176 | ||
| 177 | definition one_frac :: 'a where | |
| 178 | "one_frac \<equiv> Abs_Frac (1, 1)" | |
| 179 | ||
| 180 | definition num :: "'a \<Rightarrow> int" where | |
| 181 | "num \<equiv> fst o Rep_Frac" | |
| 182 | ||
| 183 | definition denom :: "'a \<Rightarrow> int" where | |
| 184 | "denom \<equiv> snd o Rep_Frac" | |
| 185 | ||
| 186 | function norm_frac :: "int \<Rightarrow> int \<Rightarrow> int \<times> int" where | |
| 187 | [simp del]: "norm_frac a b = (if b < 0 then norm_frac (- a) (- b) | |
| 188 | else if a = 0 \<or> b = 0 then (0, 1) | |
| 189 | else let c = int_gcd a b in (a div c, b div c))" | |
| 190 | by pat_completeness auto | |
| 191 | termination by (relation "measure (\<lambda>(_, b). if b < 0 then 1 else 0)") auto | |
| 192 | ||
| 193 | definition frac :: "int \<Rightarrow> int \<Rightarrow> 'a" where | |
| 194 | "frac a b \<equiv> Abs_Frac (norm_frac a b)" | |
| 195 | ||
| 196 | definition plus_frac :: "'a \<Rightarrow> 'a \<Rightarrow> 'a" where | |
| 197 | [nitpick_simp]: | |
| 198 | "plus_frac q r = (let d = int_lcm (denom q) (denom r) in | |
| 199 | frac (num q * (d div denom q) + num r * (d div denom r)) d)" | |
| 200 | ||
| 201 | definition times_frac :: "'a \<Rightarrow> 'a \<Rightarrow> 'a" where | |
| 202 | [nitpick_simp]: | |
| 203 | "times_frac q r = frac (num q * num r) (denom q * denom r)" | |
| 204 | ||
| 205 | definition uminus_frac :: "'a \<Rightarrow> 'a" where | |
| 206 | "uminus_frac q \<equiv> Abs_Frac (- num q, denom q)" | |
| 207 | ||
| 208 | definition number_of_frac :: "int \<Rightarrow> 'a" where | |
| 209 | "number_of_frac n \<equiv> Abs_Frac (n, 1)" | |
| 210 | ||
| 211 | definition inverse_frac :: "'a \<Rightarrow> 'a" where | |
| 212 | "inverse_frac q \<equiv> frac (denom q) (num q)" | |
| 213 | ||
| 214 | definition less_eq_frac :: "'a \<Rightarrow> 'a \<Rightarrow> bool" where | |
| 215 | [nitpick_simp]: | |
| 216 | "less_eq_frac q r \<longleftrightarrow> num (plus_frac q (uminus_frac r)) \<le> 0" | |
| 217 | ||
| 218 | definition of_frac :: "'a \<Rightarrow> 'b\<Colon>{inverse,ring_1}" where
 | |
| 219 | "of_frac q \<equiv> of_int (num q) / of_int (denom q)" | |
| 220 | ||
| 221 | use "Tools/Nitpick/kodkod.ML" | |
| 222 | use "Tools/Nitpick/kodkod_sat.ML" | |
| 223 | use "Tools/Nitpick/nitpick_util.ML" | |
| 224 | use "Tools/Nitpick/nitpick_hol.ML" | |
| 35665 
ff2bf50505ab
added "finitize" option to Nitpick + remove dependency on "Coinductive_List"
 blanchet parents: 
35311diff
changeset | 225 | use "Tools/Nitpick/nitpick_mono.ML" | 
| 35070 
96136eb6218f
split "nitpick_hol.ML" into two files to make it more manageable;
 blanchet parents: 
34982diff
changeset | 226 | use "Tools/Nitpick/nitpick_preproc.ML" | 
| 33192 | 227 | use "Tools/Nitpick/nitpick_scope.ML" | 
| 228 | use "Tools/Nitpick/nitpick_peephole.ML" | |
| 229 | use "Tools/Nitpick/nitpick_rep.ML" | |
| 230 | use "Tools/Nitpick/nitpick_nut.ML" | |
| 231 | use "Tools/Nitpick/nitpick_kodkod.ML" | |
| 232 | use "Tools/Nitpick/nitpick_model.ML" | |
| 233 | use "Tools/Nitpick/nitpick.ML" | |
| 234 | use "Tools/Nitpick/nitpick_isar.ML" | |
| 235 | use "Tools/Nitpick/nitpick_tests.ML" | |
| 236 | use "Tools/Nitpick/minipick.ML" | |
| 237 | ||
| 33561 
ab01b72715ef
introduced Auto Nitpick in addition to Auto Quickcheck;
 blanchet parents: 
33556diff
changeset | 238 | setup {* Nitpick_Isar.setup *}
 | 
| 
ab01b72715ef
introduced Auto Nitpick in addition to Auto Quickcheck;
 blanchet parents: 
33556diff
changeset | 239 | |
| 34938 | 240 | hide (open) const unknown is_unknown undefined_fast_The undefined_fast_Eps bisim | 
| 35671 
ed2c3830d881
improved Nitpick's precision for "card" and "setsum" + fix incorrect outcome code w.r.t. "bisim_depth = -1"
 blanchet parents: 
35665diff
changeset | 241 | bisim_iterator_max Quot safe_The safe_Eps FinFun FunBox PairBox Word refl' | 
| 
ed2c3830d881
improved Nitpick's precision for "card" and "setsum" + fix incorrect outcome code w.r.t. "bisim_depth = -1"
 blanchet parents: 
35665diff
changeset | 242 | wf' wf_wfrec wf_wfrec' wfrec' card' setsum' fold_graph' nat_gcd nat_lcm | 
| 
ed2c3830d881
improved Nitpick's precision for "card" and "setsum" + fix incorrect outcome code w.r.t. "bisim_depth = -1"
 blanchet parents: 
35665diff
changeset | 243 | int_gcd int_lcm Frac Abs_Frac Rep_Frac zero_frac one_frac num denom | 
| 
ed2c3830d881
improved Nitpick's precision for "card" and "setsum" + fix incorrect outcome code w.r.t. "bisim_depth = -1"
 blanchet parents: 
35665diff
changeset | 244 | norm_frac frac plus_frac times_frac uminus_frac number_of_frac inverse_frac | 
| 
ed2c3830d881
improved Nitpick's precision for "card" and "setsum" + fix incorrect outcome code w.r.t. "bisim_depth = -1"
 blanchet parents: 
35665diff
changeset | 245 | less_eq_frac of_frac | 
| 35665 
ff2bf50505ab
added "finitize" option to Nitpick + remove dependency on "Coinductive_List"
 blanchet parents: 
35311diff
changeset | 246 | hide (open) type bisim_iterator fin_fun fun_box pair_box unsigned_bit signed_bit | 
| 
ff2bf50505ab
added "finitize" option to Nitpick + remove dependency on "Coinductive_List"
 blanchet parents: 
35311diff
changeset | 247 | word | 
| 33192 | 248 | hide (open) fact If_def Ex1_def rtrancl_def rtranclp_def tranclp_def refl'_def | 
| 249 | wf'_def wf_wfrec'_def wfrec'_def card'_def setsum'_def fold_graph'_def | |
| 33556 
cba22e2999d5
renamed Nitpick option "coalesce_type_vars" to "merge_type_vars" (shorter) and cleaned up old hacks that are no longer necessary
 blanchet parents: 
33192diff
changeset | 250 | The_psimp Eps_psimp unit_case_def nat_case_def list_size_simp nat_gcd_def | 
| 
cba22e2999d5
renamed Nitpick option "coalesce_type_vars" to "merge_type_vars" (shorter) and cleaned up old hacks that are no longer necessary
 blanchet parents: 
33192diff
changeset | 251 | nat_lcm_def int_gcd_def int_lcm_def Frac_def zero_frac_def one_frac_def | 
| 
cba22e2999d5
renamed Nitpick option "coalesce_type_vars" to "merge_type_vars" (shorter) and cleaned up old hacks that are no longer necessary
 blanchet parents: 
33192diff
changeset | 252 | num_def denom_def norm_frac_def frac_def plus_frac_def times_frac_def | 
| 
cba22e2999d5
renamed Nitpick option "coalesce_type_vars" to "merge_type_vars" (shorter) and cleaned up old hacks that are no longer necessary
 blanchet parents: 
33192diff
changeset | 253 | uminus_frac_def number_of_frac_def inverse_frac_def less_eq_frac_def | 
| 
cba22e2999d5
renamed Nitpick option "coalesce_type_vars" to "merge_type_vars" (shorter) and cleaned up old hacks that are no longer necessary
 blanchet parents: 
33192diff
changeset | 254 | of_frac_def | 
| 33192 | 255 | |
| 256 | end |