src/HOL/UNITY/Mutex.ML
author paulson
Fri, 07 May 1999 11:02:00 +0200
changeset 6615 f72f560af0a1
parent 6570 a7d7985050a9
child 6678 d83f27b03529
permissions -rw-r--r--
tidied
Ignore whitespace changes - Everywhere: Within whitespace: At end of lines:
5111
8f4b72f0c15d Uncurried functions LeadsTo and reach
paulson
parents: 5069
diff changeset
     1
(*  Title:      HOL/UNITY/Mutex
4776
1f9362e769c1 New UNITY theory
paulson
parents:
diff changeset
     2
    ID:         $Id$
1f9362e769c1 New UNITY theory
paulson
parents:
diff changeset
     3
    Author:     Lawrence C Paulson, Cambridge University Computer Laboratory
1f9362e769c1 New UNITY theory
paulson
parents:
diff changeset
     4
    Copyright   1998  University of Cambridge
1f9362e769c1 New UNITY theory
paulson
parents:
diff changeset
     5
1f9362e769c1 New UNITY theory
paulson
parents:
diff changeset
     6
Based on "A Family of 2-Process Mutual Exclusion Algorithms" by J Misra
1f9362e769c1 New UNITY theory
paulson
parents:
diff changeset
     7
*)
1f9362e769c1 New UNITY theory
paulson
parents:
diff changeset
     8
5232
e5a7cdd07ea5 Tidied; uses records
paulson
parents: 5111
diff changeset
     9
(*split_all_tac causes a big blow-up*)
5706
21706a735c8d record_split_name;
wenzelm
parents: 5701
diff changeset
    10
claset_ref() := claset() delSWrapper record_split_name;
4776
1f9362e769c1 New UNITY theory
paulson
parents:
diff changeset
    11
6565
de4acf4449fa renamed state variables
paulson
parents: 6536
diff changeset
    12
Addsimps [Mutex_def RS def_prg_Init];
de4acf4449fa renamed state variables
paulson
parents: 6536
diff changeset
    13
program_defs_ref := [Mutex_def];
4776
1f9362e769c1 New UNITY theory
paulson
parents:
diff changeset
    14
5426
566f47250bd0 A new approach, using simp_of_act and simp_of_set to activate definitions when
paulson
parents: 5424
diff changeset
    15
Addsimps (map simp_of_act
6565
de4acf4449fa renamed state variables
paulson
parents: 6536
diff changeset
    16
	  [U0_def, U1_def, U2_def, U3_def, U4_def, 
de4acf4449fa renamed state variables
paulson
parents: 6536
diff changeset
    17
	   V0_def, V1_def, V2_def, V3_def, V4_def]);
4776
1f9362e769c1 New UNITY theory
paulson
parents:
diff changeset
    18
6570
a7d7985050a9 Invariant -> Always and other tidying
paulson
parents: 6565
diff changeset
    19
Addsimps (map simp_of_set [IU_def, IV_def, bad_IU_def]);
4776
1f9362e769c1 New UNITY theory
paulson
parents:
diff changeset
    20
5232
e5a7cdd07ea5 Tidied; uses records
paulson
parents: 5111
diff changeset
    21
(*Simplification for records*)
5426
566f47250bd0 A new approach, using simp_of_act and simp_of_set to activate definitions when
paulson
parents: 5424
diff changeset
    22
Addsimps (thms"state.update_defs");
5232
e5a7cdd07ea5 Tidied; uses records
paulson
parents: 5111
diff changeset
    23
6570
a7d7985050a9 Invariant -> Always and other tidying
paulson
parents: 6565
diff changeset
    24
Goal "Mutex : Always IU";
a7d7985050a9 Invariant -> Always and other tidying
paulson
parents: 6565
diff changeset
    25
by (rtac AlwaysI 1);
5426
566f47250bd0 A new approach, using simp_of_act and simp_of_set to activate definitions when
paulson
parents: 5424
diff changeset
    26
by (constrains_tac 2);
5232
e5a7cdd07ea5 Tidied; uses records
paulson
parents: 5111
diff changeset
    27
by Auto_tac;
6570
a7d7985050a9 Invariant -> Always and other tidying
paulson
parents: 6565
diff changeset
    28
qed "IU";
4776
1f9362e769c1 New UNITY theory
paulson
parents:
diff changeset
    29
6570
a7d7985050a9 Invariant -> Always and other tidying
paulson
parents: 6565
diff changeset
    30
Goal "Mutex : Always IV";
a7d7985050a9 Invariant -> Always and other tidying
paulson
parents: 6565
diff changeset
    31
by (rtac AlwaysI 1);
5426
566f47250bd0 A new approach, using simp_of_act and simp_of_set to activate definitions when
paulson
parents: 5424
diff changeset
    32
by (constrains_tac 2);
4776
1f9362e769c1 New UNITY theory
paulson
parents:
diff changeset
    33
by Auto_tac;
6570
a7d7985050a9 Invariant -> Always and other tidying
paulson
parents: 6565
diff changeset
    34
qed "IV";
4776
1f9362e769c1 New UNITY theory
paulson
parents:
diff changeset
    35
5240
bbcd79ef7cf2 Constant "invariant" and new constrains_tac, ensures_tac
paulson
parents: 5232
diff changeset
    36
(*The safety property: mutual exclusion*)
6570
a7d7985050a9 Invariant -> Always and other tidying
paulson
parents: 6565
diff changeset
    37
Goal "Mutex : Always {s. ~ (m s = #3 & n s = #3)}";
a7d7985050a9 Invariant -> Always and other tidying
paulson
parents: 6565
diff changeset
    38
by (rtac Always_weaken 1);
a7d7985050a9 Invariant -> Always and other tidying
paulson
parents: 6565
diff changeset
    39
by (rtac ([IU, IV] MRS Always_Int) 1);
4776
1f9362e769c1 New UNITY theory
paulson
parents:
diff changeset
    40
by Auto_tac;
1f9362e769c1 New UNITY theory
paulson
parents:
diff changeset
    41
qed "mutual_exclusion";
1f9362e769c1 New UNITY theory
paulson
parents:
diff changeset
    42
1f9362e769c1 New UNITY theory
paulson
parents:
diff changeset
    43
6565
de4acf4449fa renamed state variables
paulson
parents: 6536
diff changeset
    44
(*The bad invariant FAILS in V1*)
6570
a7d7985050a9 Invariant -> Always and other tidying
paulson
parents: 6565
diff changeset
    45
Goal "Mutex : Always bad_IU";
a7d7985050a9 Invariant -> Always and other tidying
paulson
parents: 6565
diff changeset
    46
by (rtac AlwaysI 1);
5426
566f47250bd0 A new approach, using simp_of_act and simp_of_set to activate definitions when
paulson
parents: 5424
diff changeset
    47
by (constrains_tac 2);
6615
paulson
parents: 6570
diff changeset
    48
by Auto_tac;
4776
1f9362e769c1 New UNITY theory
paulson
parents:
diff changeset
    49
(*Resulting state: n=1, p=false, m=4, u=false.  
6565
de4acf4449fa renamed state variables
paulson
parents: 6536
diff changeset
    50
  Execution of V1 (the command of process v guarded by n=1) sets p:=true,
4776
1f9362e769c1 New UNITY theory
paulson
parents:
diff changeset
    51
  violating the invariant!*)
1f9362e769c1 New UNITY theory
paulson
parents:
diff changeset
    52
(*Check that subgoals remain: proof failed.*)
1f9362e769c1 New UNITY theory
paulson
parents:
diff changeset
    53
getgoal 1;  
1f9362e769c1 New UNITY theory
paulson
parents:
diff changeset
    54
1f9362e769c1 New UNITY theory
paulson
parents:
diff changeset
    55
6565
de4acf4449fa renamed state variables
paulson
parents: 6536
diff changeset
    56
Goal "(#1 <= i & i <= #3) = (i = #1 | i = #2 | i = #3)";
6615
paulson
parents: 6570
diff changeset
    57
by (arith_tac 1);
5596
b29d18d8c4d2 abstype of programs
paulson
parents: 5426
diff changeset
    58
qed "eq_123";
b29d18d8c4d2 abstype of programs
paulson
parents: 5426
diff changeset
    59
b29d18d8c4d2 abstype of programs
paulson
parents: 5426
diff changeset
    60
4776
1f9362e769c1 New UNITY theory
paulson
parents:
diff changeset
    61
(*** Progress for U ***)
1f9362e769c1 New UNITY theory
paulson
parents:
diff changeset
    62
6565
de4acf4449fa renamed state variables
paulson
parents: 6536
diff changeset
    63
Goalw [Unless_def] "Mutex : {s. m s=#2} Unless {s. m s=#3}";
5426
566f47250bd0 A new approach, using simp_of_act and simp_of_set to activate definitions when
paulson
parents: 5424
diff changeset
    64
by (constrains_tac 1);
4776
1f9362e769c1 New UNITY theory
paulson
parents:
diff changeset
    65
qed "U_F0";
1f9362e769c1 New UNITY theory
paulson
parents:
diff changeset
    66
6565
de4acf4449fa renamed state variables
paulson
parents: 6536
diff changeset
    67
Goal "Mutex : {s. m s=#1} LeadsTo {s. p s = v s & m s = #2}";
de4acf4449fa renamed state variables
paulson
parents: 6536
diff changeset
    68
by (ensures_tac "U1" 1);
4776
1f9362e769c1 New UNITY theory
paulson
parents:
diff changeset
    69
qed "U_F1";
1f9362e769c1 New UNITY theory
paulson
parents:
diff changeset
    70
6565
de4acf4449fa renamed state variables
paulson
parents: 6536
diff changeset
    71
Goal "Mutex : {s. ~ p s & m s = #2} LeadsTo {s. m s = #3}";
6570
a7d7985050a9 Invariant -> Always and other tidying
paulson
parents: 6565
diff changeset
    72
by (cut_facts_tac [IU] 1);
6565
de4acf4449fa renamed state variables
paulson
parents: 6536
diff changeset
    73
by (ensures_tac "U2" 1);
4776
1f9362e769c1 New UNITY theory
paulson
parents:
diff changeset
    74
qed "U_F2";
1f9362e769c1 New UNITY theory
paulson
parents:
diff changeset
    75
6565
de4acf4449fa renamed state variables
paulson
parents: 6536
diff changeset
    76
Goal "Mutex : {s. m s = #3} LeadsTo {s. p s}";
de4acf4449fa renamed state variables
paulson
parents: 6536
diff changeset
    77
by (res_inst_tac [("B", "{s. m s = #4}")] LeadsTo_Trans 1);
de4acf4449fa renamed state variables
paulson
parents: 6536
diff changeset
    78
by (ensures_tac "U4" 2);
de4acf4449fa renamed state variables
paulson
parents: 6536
diff changeset
    79
by (ensures_tac "U3" 1);
4776
1f9362e769c1 New UNITY theory
paulson
parents:
diff changeset
    80
qed "U_F3";
1f9362e769c1 New UNITY theory
paulson
parents:
diff changeset
    81
6565
de4acf4449fa renamed state variables
paulson
parents: 6536
diff changeset
    82
Goal "Mutex : {s. m s = #2} LeadsTo {s. p s}";
5340
d75c03cf77b5 Misc changes
paulson
parents: 5320
diff changeset
    83
by (rtac ([LeadsTo_weaken_L, Int_lower2 RS subset_imp_LeadsTo] 
4776
1f9362e769c1 New UNITY theory
paulson
parents:
diff changeset
    84
	  MRS LeadsTo_Diff) 1);
1f9362e769c1 New UNITY theory
paulson
parents:
diff changeset
    85
by (rtac ([U_F2, U_F3] MRS LeadsTo_Trans) 1);
1f9362e769c1 New UNITY theory
paulson
parents:
diff changeset
    86
by (auto_tac (claset() addSEs [less_SucE], simpset()));
5240
bbcd79ef7cf2 Constant "invariant" and new constrains_tac, ensures_tac
paulson
parents: 5232
diff changeset
    87
val U_lemma2 = result();
4776
1f9362e769c1 New UNITY theory
paulson
parents:
diff changeset
    88
6565
de4acf4449fa renamed state variables
paulson
parents: 6536
diff changeset
    89
Goal "Mutex : {s. m s = #1} LeadsTo {s. p s}";
5240
bbcd79ef7cf2 Constant "invariant" and new constrains_tac, ensures_tac
paulson
parents: 5232
diff changeset
    90
by (rtac ([U_F1 RS LeadsTo_weaken_R, U_lemma2] MRS LeadsTo_Trans) 1);
4776
1f9362e769c1 New UNITY theory
paulson
parents:
diff changeset
    91
by (Blast_tac 1);
5240
bbcd79ef7cf2 Constant "invariant" and new constrains_tac, ensures_tac
paulson
parents: 5232
diff changeset
    92
val U_lemma1 = result();
4776
1f9362e769c1 New UNITY theory
paulson
parents:
diff changeset
    93
6565
de4acf4449fa renamed state variables
paulson
parents: 6536
diff changeset
    94
Goal "Mutex : {s. #1 <= m s & m s <= #3} LeadsTo {s. p s}";
5596
b29d18d8c4d2 abstype of programs
paulson
parents: 5426
diff changeset
    95
by (simp_tac (simpset() addsimps [eq_123, Collect_disj_eq, LeadsTo_Un_distrib,
5240
bbcd79ef7cf2 Constant "invariant" and new constrains_tac, ensures_tac
paulson
parents: 5232
diff changeset
    96
				  U_lemma1, U_lemma2, U_F3] ) 1);
bbcd79ef7cf2 Constant "invariant" and new constrains_tac, ensures_tac
paulson
parents: 5232
diff changeset
    97
val U_lemma123 = result();
4776
1f9362e769c1 New UNITY theory
paulson
parents:
diff changeset
    98
1f9362e769c1 New UNITY theory
paulson
parents:
diff changeset
    99
(*Misra's F4*)
6565
de4acf4449fa renamed state variables
paulson
parents: 6536
diff changeset
   100
Goal "Mutex : {s. u s} LeadsTo {s. p s}";
6570
a7d7985050a9 Invariant -> Always and other tidying
paulson
parents: 6565
diff changeset
   101
by (rtac ([IU, U_lemma123] MRS Always_LeadsTo_weaken) 1);
4776
1f9362e769c1 New UNITY theory
paulson
parents:
diff changeset
   102
by Auto_tac;
5313
1861a564d7e2 Constrains, Stable, Invariant...more of the substitution axiom, but Union
paulson
parents: 5277
diff changeset
   103
qed "u_Leadsto_p";
4776
1f9362e769c1 New UNITY theory
paulson
parents:
diff changeset
   104
1f9362e769c1 New UNITY theory
paulson
parents:
diff changeset
   105
1f9362e769c1 New UNITY theory
paulson
parents:
diff changeset
   106
(*** Progress for V ***)
1f9362e769c1 New UNITY theory
paulson
parents:
diff changeset
   107
1f9362e769c1 New UNITY theory
paulson
parents:
diff changeset
   108
6565
de4acf4449fa renamed state variables
paulson
parents: 6536
diff changeset
   109
Goalw [Unless_def] "Mutex : {s. n s=#2} Unless {s. n s=#3}";
5426
566f47250bd0 A new approach, using simp_of_act and simp_of_set to activate definitions when
paulson
parents: 5424
diff changeset
   110
by (constrains_tac 1);
4776
1f9362e769c1 New UNITY theory
paulson
parents:
diff changeset
   111
qed "V_F0";
1f9362e769c1 New UNITY theory
paulson
parents:
diff changeset
   112
6565
de4acf4449fa renamed state variables
paulson
parents: 6536
diff changeset
   113
Goal "Mutex : {s. n s=#1} LeadsTo {s. p s = (~ u s) & n s = #2}";
de4acf4449fa renamed state variables
paulson
parents: 6536
diff changeset
   114
by (ensures_tac "V1" 1);
4776
1f9362e769c1 New UNITY theory
paulson
parents:
diff changeset
   115
qed "V_F1";
1f9362e769c1 New UNITY theory
paulson
parents:
diff changeset
   116
6565
de4acf4449fa renamed state variables
paulson
parents: 6536
diff changeset
   117
Goal "Mutex : {s. p s & n s = #2} LeadsTo {s. n s = #3}";
6570
a7d7985050a9 Invariant -> Always and other tidying
paulson
parents: 6565
diff changeset
   118
by (cut_facts_tac [IV] 1);
6565
de4acf4449fa renamed state variables
paulson
parents: 6536
diff changeset
   119
by (ensures_tac "V2" 1);
4776
1f9362e769c1 New UNITY theory
paulson
parents:
diff changeset
   120
qed "V_F2";
1f9362e769c1 New UNITY theory
paulson
parents:
diff changeset
   121
6565
de4acf4449fa renamed state variables
paulson
parents: 6536
diff changeset
   122
Goal "Mutex : {s. n s = #3} LeadsTo {s. ~ p s}";
de4acf4449fa renamed state variables
paulson
parents: 6536
diff changeset
   123
by (res_inst_tac [("B", "{s. n s = #4}")] LeadsTo_Trans 1);
de4acf4449fa renamed state variables
paulson
parents: 6536
diff changeset
   124
by (ensures_tac "V4" 2);
de4acf4449fa renamed state variables
paulson
parents: 6536
diff changeset
   125
by (ensures_tac "V3" 1);
4776
1f9362e769c1 New UNITY theory
paulson
parents:
diff changeset
   126
qed "V_F3";
1f9362e769c1 New UNITY theory
paulson
parents:
diff changeset
   127
6565
de4acf4449fa renamed state variables
paulson
parents: 6536
diff changeset
   128
Goal "Mutex : {s. n s = #2} LeadsTo {s. ~ p s}";
5340
d75c03cf77b5 Misc changes
paulson
parents: 5320
diff changeset
   129
by (rtac ([LeadsTo_weaken_L, Int_lower2 RS subset_imp_LeadsTo] 
4776
1f9362e769c1 New UNITY theory
paulson
parents:
diff changeset
   130
	  MRS LeadsTo_Diff) 1);
1f9362e769c1 New UNITY theory
paulson
parents:
diff changeset
   131
by (rtac ([V_F2, V_F3] MRS LeadsTo_Trans) 1);
1f9362e769c1 New UNITY theory
paulson
parents:
diff changeset
   132
by (auto_tac (claset() addSEs [less_SucE], simpset()));
5240
bbcd79ef7cf2 Constant "invariant" and new constrains_tac, ensures_tac
paulson
parents: 5232
diff changeset
   133
val V_lemma2 = result();
4776
1f9362e769c1 New UNITY theory
paulson
parents:
diff changeset
   134
6565
de4acf4449fa renamed state variables
paulson
parents: 6536
diff changeset
   135
Goal "Mutex : {s. n s = #1} LeadsTo {s. ~ p s}";
5240
bbcd79ef7cf2 Constant "invariant" and new constrains_tac, ensures_tac
paulson
parents: 5232
diff changeset
   136
by (rtac ([V_F1 RS LeadsTo_weaken_R, V_lemma2] MRS LeadsTo_Trans) 1);
4776
1f9362e769c1 New UNITY theory
paulson
parents:
diff changeset
   137
by (Blast_tac 1);
5240
bbcd79ef7cf2 Constant "invariant" and new constrains_tac, ensures_tac
paulson
parents: 5232
diff changeset
   138
val V_lemma1 = result();
4776
1f9362e769c1 New UNITY theory
paulson
parents:
diff changeset
   139
6565
de4acf4449fa renamed state variables
paulson
parents: 6536
diff changeset
   140
Goal "Mutex : {s. #1 <= n s & n s <= #3} LeadsTo {s. ~ p s}";
5596
b29d18d8c4d2 abstype of programs
paulson
parents: 5426
diff changeset
   141
by (simp_tac (simpset() addsimps [eq_123, Collect_disj_eq, LeadsTo_Un_distrib,
5240
bbcd79ef7cf2 Constant "invariant" and new constrains_tac, ensures_tac
paulson
parents: 5232
diff changeset
   142
				  V_lemma1, V_lemma2, V_F3] ) 1);
bbcd79ef7cf2 Constant "invariant" and new constrains_tac, ensures_tac
paulson
parents: 5232
diff changeset
   143
val V_lemma123 = result();
4776
1f9362e769c1 New UNITY theory
paulson
parents:
diff changeset
   144
1f9362e769c1 New UNITY theory
paulson
parents:
diff changeset
   145
1f9362e769c1 New UNITY theory
paulson
parents:
diff changeset
   146
(*Misra's F4*)
6565
de4acf4449fa renamed state variables
paulson
parents: 6536
diff changeset
   147
Goal "Mutex : {s. v s} LeadsTo {s. ~ p s}";
6570
a7d7985050a9 Invariant -> Always and other tidying
paulson
parents: 6565
diff changeset
   148
by (rtac ([IV, V_lemma123] MRS Always_LeadsTo_weaken) 1);
4776
1f9362e769c1 New UNITY theory
paulson
parents:
diff changeset
   149
by Auto_tac;
5313
1861a564d7e2 Constrains, Stable, Invariant...more of the substitution axiom, but Union
paulson
parents: 5277
diff changeset
   150
qed "v_Leadsto_not_p";
4776
1f9362e769c1 New UNITY theory
paulson
parents:
diff changeset
   151
1f9362e769c1 New UNITY theory
paulson
parents:
diff changeset
   152
1f9362e769c1 New UNITY theory
paulson
parents:
diff changeset
   153
(** Absence of starvation **)
1f9362e769c1 New UNITY theory
paulson
parents:
diff changeset
   154
1f9362e769c1 New UNITY theory
paulson
parents:
diff changeset
   155
(*Misra's F6*)
6565
de4acf4449fa renamed state variables
paulson
parents: 6536
diff changeset
   156
Goal "Mutex : {s. m s = #1} LeadsTo {s. m s = #3}";
6615
paulson
parents: 6570
diff changeset
   157
by (rtac (LeadsTo_cancel2 RS LeadsTo_Un_duplicate) 1);
4776
1f9362e769c1 New UNITY theory
paulson
parents:
diff changeset
   158
by (rtac U_F2 2);
1f9362e769c1 New UNITY theory
paulson
parents:
diff changeset
   159
by (simp_tac (simpset() addsimps [Collect_conj_eq] ) 1);
1f9362e769c1 New UNITY theory
paulson
parents:
diff changeset
   160
by (stac Un_commute 1);
6615
paulson
parents: 6570
diff changeset
   161
by (rtac (LeadsTo_cancel2 RS LeadsTo_Un_duplicate) 1);
paulson
parents: 6570
diff changeset
   162
by (rtac ([v_Leadsto_not_p, U_F0] MRS PSP_Unless) 2);
4776
1f9362e769c1 New UNITY theory
paulson
parents:
diff changeset
   163
by (rtac (U_F1 RS LeadsTo_weaken_R) 1);
6615
paulson
parents: 6570
diff changeset
   164
by Auto_tac;
5313
1861a564d7e2 Constrains, Stable, Invariant...more of the substitution axiom, but Union
paulson
parents: 5277
diff changeset
   165
qed "m1_Leadsto_3";
4776
1f9362e769c1 New UNITY theory
paulson
parents:
diff changeset
   166
1f9362e769c1 New UNITY theory
paulson
parents:
diff changeset
   167
(*The same for V*)
6565
de4acf4449fa renamed state variables
paulson
parents: 6536
diff changeset
   168
Goal "Mutex : {s. n s = #1} LeadsTo {s. n s = #3}";
6615
paulson
parents: 6570
diff changeset
   169
by (rtac (LeadsTo_cancel2 RS LeadsTo_Un_duplicate) 1);
4776
1f9362e769c1 New UNITY theory
paulson
parents:
diff changeset
   170
by (rtac V_F2 2);
1f9362e769c1 New UNITY theory
paulson
parents:
diff changeset
   171
by (simp_tac (simpset() addsimps [Collect_conj_eq] ) 1);
1f9362e769c1 New UNITY theory
paulson
parents:
diff changeset
   172
by (stac Un_commute 1);
6615
paulson
parents: 6570
diff changeset
   173
by (rtac (LeadsTo_cancel2 RS LeadsTo_Un_duplicate) 1);
paulson
parents: 6570
diff changeset
   174
by (rtac ([u_Leadsto_p, V_F0] MRS PSP_Unless) 2);
4776
1f9362e769c1 New UNITY theory
paulson
parents:
diff changeset
   175
by (rtac (V_F1 RS LeadsTo_weaken_R) 1);
6615
paulson
parents: 6570
diff changeset
   176
by Auto_tac;
5313
1861a564d7e2 Constrains, Stable, Invariant...more of the substitution axiom, but Union
paulson
parents: 5277
diff changeset
   177
qed "n1_Leadsto_3";