1 (* Title: HOL/MicroJava/J/JTypeSafe.ML |
|
2 ID: $Id$ |
|
3 Author: David von Oheimb |
|
4 Copyright 1999 Technische Universitaet Muenchen |
|
5 |
|
6 Type safety proof |
|
7 *) |
|
8 |
|
9 |
|
10 |
|
11 Addsimps [split_beta]; |
|
12 |
|
13 Goal "[|h a = None; (h, l)::\\<preceq>(G, lT); wf_prog wf_mb G; is_class G C|] ==> \ |
|
14 \ (h(a\\<mapsto>(C,(init_vars (fields (G,C))))), l)::\\<preceq>(G, lT)"; |
|
15 by( etac conforms_upd_obj 1); |
|
16 by( rewtac oconf_def); |
|
17 by( auto_tac (claset() addSDs [fields_is_type], simpset())); |
|
18 qed "NewC_conforms"; |
|
19 |
|
20 Goalw [cast_ok_def] |
|
21 "[| wf_prog wf_mb G; G,h\\<turnstile>v::\\<preceq>Class C; G\\<turnstile>C\\<preceq>? D; cast_ok G D h v|] \ |
|
22 \ ==> G,h\\<turnstile>v::\\<preceq>Class D"; |
|
23 by( case_tac "v = Null" 1); |
|
24 by( Asm_full_simp_tac 1); |
|
25 by( dtac widen_RefT 1); |
|
26 by( Clarify_tac 1); |
|
27 by( datac non_npD 1 1); |
|
28 by( auto_tac (claset() addSIs [conf_AddrI], simpset() addsimps [obj_ty_def])); |
|
29 qed "Cast_conf"; |
|
30 |
|
31 Goal "[| wf_prog wf_mb G; field (G,C) fn = Some (fd, ft); (h,l)::\\<preceq>(G,lT); \ |
|
32 \ x' = None --> G,h\\<turnstile>a'::\\<preceq> Class C; np a' x' = None |] ==> \ |
|
33 \ G,h\\<turnstile>the (snd (the (h (the_Addr a'))) (fn, fd))::\\<preceq>ft"; |
|
34 by( dtac np_NoneD 1); |
|
35 by( etac conjE 1); |
|
36 by( mp_tac 1); |
|
37 by( dtac non_np_objD 1); |
|
38 by Auto_tac; |
|
39 by( dtac (conforms_heapD RS hconfD) 1); |
|
40 by( atac 1); |
|
41 by( datac widen_cfs_fields 2 1); |
|
42 by( datac oconf_objD 1 1); |
|
43 by Auto_tac; |
|
44 qed "FAcc_type_sound"; |
|
45 |
|
46 Goal |
|
47 "[| wf_prog wf_mb G; a = the_Addr a'; (c, fs) = the (h a); \ |
|
48 \ (G, lT)\\<turnstile>v::T'; G\\<turnstile>T'\\<preceq>ft; \ |
|
49 \ (G, lT)\\<turnstile>aa::Class C; \ |
|
50 \ field (G,C) fn = Some (fd, ft); h''\\<le>|h'; \ |
|
51 \ x' = None --> G,h'\\<turnstile>a'::\\<preceq> Class C; h'\\<le>|h; \ |
|
52 \ (h, l)::\\<preceq>(G, lT); G,h\\<turnstile>x::\\<preceq>T'; np a' x' = None|] ==> \ |
|
53 \ h''\\<le>|h(a\\<mapsto>(c,(fs((fn,fd)\\<mapsto>x)))) \\<and> \ |
|
54 \ (h(a\\<mapsto>(c,(fs((fn,fd)\\<mapsto>x)))), l)::\\<preceq>(G, lT) \\<and> \ |
|
55 \ G,h(a\\<mapsto>(c,(fs((fn,fd)\\<mapsto>x))))\\<turnstile>x::\\<preceq>T'"; |
|
56 by( dtac np_NoneD 1); |
|
57 by( etac conjE 1); |
|
58 by( Asm_full_simp_tac 1); |
|
59 by( dtac non_np_objD 1); |
|
60 by( atac 1); |
|
61 by( SELECT_GOAL Auto_tac 1); |
|
62 by( Clarify_tac 1); |
|
63 by( Full_simp_tac 1); |
|
64 by( EVERY [ftac hext_objD 1, atac 1]); |
|
65 by( etac exE 1); |
|
66 by( Asm_full_simp_tac 1); |
|
67 by( Clarify_tac 1); |
|
68 by( rtac conjI 1); |
|
69 by( fast_tac (HOL_cs addEs [hext_trans, hext_upd_obj]) 1); |
|
70 by( rtac conjI 1); |
|
71 by( fast_tac (HOL_cs addEs [conf_upd_obj RS iffD2]) 2); |
|
72 |
|
73 by( rtac conforms_upd_obj 1); |
|
74 by Auto_tac; |
|
75 by( rtac hextI 2); |
|
76 by( Force_tac 2); |
|
77 by( rtac oconf_hext 1); |
|
78 by( etac hext_upd_obj 2); |
|
79 by( dtac widen_cfs_fields 1); |
|
80 by( atac 1); |
|
81 by( atac 1); |
|
82 by( rtac (oconf_obj RS iffD2) 1); |
|
83 by( Simp_tac 1); |
|
84 by( strip_tac 1); |
|
85 by( case_tac "(aaa, b) = (fn, fd)" 1); |
|
86 by( Asm_full_simp_tac 1); |
|
87 by( fast_tac (HOL_cs addIs [conf_widen]) 1); |
|
88 by( fast_tac (HOL_cs addDs [conforms_heapD RS hconfD, oconf_objD]) 1); |
|
89 qed "FAss_type_sound"; |
|
90 |
|
91 Goalw [wf_mhead_def] "[| wf_prog wf_mb G; list_all2 (conf G h) pvs pTs; \ |
|
92 \ list_all2 (\\<lambda>T T'. G\\<turnstile>T\\<preceq>T') pTs pTs'; wf_mhead G (mn,pTs') rT; \ |
|
93 \ length pTs' = length pns; nodups pns; \ |
|
94 \ Ball (set lvars) (split (\\<lambda>vn. is_type G)) \ |
|
95 \ |] ==> G,h\\<turnstile>init_vars lvars(pns[\\<mapsto>]pvs)[::\\<preceq>]map_of lvars(pns[\\<mapsto>]pTs')"; |
|
96 by( Clarsimp_tac 1); |
|
97 by( rtac lconf_ext_list 1); |
|
98 by( rtac (Ball_set_table RS lconf_init_vars) 1); |
|
99 by( Force_tac 1); |
|
100 by( atac 1); |
|
101 by( atac 1); |
|
102 by( (etac conf_list_gext_widen THEN_ALL_NEW atac) 1); |
|
103 qed "Call_lemma2"; |
|
104 |
|
105 Goalw [wf_java_prog_def] |
|
106 "[| wf_java_prog G; a' \\<noteq> Null; (h, l)::\\<preceq>(G, lT); class G C = Some y; \ |
|
107 \ max_spec G C (mn,pTsa) = {((mda,rTa),pTs')}; xc\\<le>|xh; xh\\<le>|h; \ |
|
108 \ list_all2 (conf G h) pvs pTsa;\ |
|
109 \ (md, rT, pns, lvars, blk, res) = \ |
|
110 \ the (method (G,fst (the (h (the_Addr a')))) (mn, pTs'));\ |
|
111 \ \\<forall>lT. (h, init_vars lvars(pns[\\<mapsto>]pvs)(This\\<mapsto>a'))::\\<preceq>(G, lT) --> \ |
|
112 \ (G, lT)\\<turnstile>blk\\<surd> --> h\\<le>|xi \\<and> (xi, xl)::\\<preceq>(G, lT); \ |
|
113 \ \\<forall>lT. (xi, xl)::\\<preceq>(G, lT) --> (\\<forall>T. (G, lT)\\<turnstile>res::T --> \ |
|
114 \ xi\\<le>|h' \\<and> (h', xj)::\\<preceq>(G, lT) \\<and> (x' = None --> G,h'\\<turnstile>v::\\<preceq>T)); \ |
|
115 \ G,xh\\<turnstile>a'::\\<preceq> Class C |] ==> \ |
|
116 \ xc\\<le>|h' \\<and> (h', l)::\\<preceq>(G, lT) \\<and> (x' = None --> G,h'\\<turnstile>v::\\<preceq>rTa)"; |
|
117 by( dtac max_spec2mheads 1); |
|
118 by( Clarify_tac 1); |
|
119 by( datac non_np_objD' 2 1); |
|
120 by( Clarsimp_tac 1); |
|
121 by( Clarsimp_tac 1); |
|
122 by( EVERY'[ftac hext_objD, atac] 1); |
|
123 by( Clarsimp_tac 1); |
|
124 by( datac Call_lemma 3 1); |
|
125 by( clarsimp_tac (claset(),simpset() addsimps [wf_java_mdecl_def])1); |
|
126 by( thin_tac "method ?sig ?x = ?y" 1); |
|
127 by( EVERY'[dtac spec, etac impE] 1); |
|
128 by( mp_tac 2); |
|
129 by( rtac conformsI 1); |
|
130 by( etac conforms_heapD 1); |
|
131 by( rtac lconf_ext 1); |
|
132 by( force_tac (claset() addSEs [Call_lemma2],simpset()) 1); |
|
133 by( EVERY'[etac conf_hext, etac conf_obj_AddrI, atac] 1); |
|
134 by( thin_tac "?E\\<turnstile>?blk\\<surd>" 1); |
|
135 by( etac conjE 1); |
|
136 by( EVERY'[dtac spec, mp_tac] 1); |
|
137 (*by( thin_tac "?E::\\<preceq>(G, pT')" 1);*) |
|
138 by( EVERY'[dtac spec, mp_tac] 1); |
|
139 by( thin_tac "?E\\<turnstile>res::?rT" 1); |
|
140 by( Clarify_tac 1); |
|
141 by( rtac conjI 1); |
|
142 by( fast_tac (HOL_cs addIs [hext_trans]) 1); |
|
143 by( rtac conjI 1); |
|
144 by( rtac impI 2); |
|
145 by( mp_tac 2); |
|
146 by( forward_tac [conf_widen] 2); |
|
147 by( atac 4); |
|
148 by( atac 2); |
|
149 by( fast_tac (HOL_cs addSEs [widen_trans]) 2); |
|
150 by( etac conforms_hext 1); |
|
151 by( etac hext_trans 1); |
|
152 by( atac 1); |
|
153 by( etac conforms_heapD 1); |
|
154 qed "Call_type_sound"; |
|
155 |
|
156 |
|
157 |
|
158 Unify.search_bound := 40; |
|
159 Unify.trace_bound := 40; |
|
160 Delsplits[split_if]; |
|
161 Delsimps[fun_upd_apply]; |
|
162 Addsimps[fun_upd_same]; |
|
163 val forward_hyp_tac = ALLGOALS (TRY o (EVERY' [dtac spec, mp_tac, |
|
164 (mp_tac ORELSE' (dtac spec THEN' mp_tac)), REPEAT o (etac conjE)])); |
|
165 Goal |
|
166 "wf_java_prog G ==> \ |
|
167 \ (G\\<turnstile>(x,(h,l)) -e \\<succ>v -> (x', (h',l')) --> \ |
|
168 \ (\\<forall>lT. (h ,l )::\\<preceq>(G,lT) --> (\\<forall>T . (G,lT)\\<turnstile>e :: T --> \ |
|
169 \ h\\<le>|h' \\<and> (h',l')::\\<preceq>(G,lT) \\<and> (x'=None --> G,h'\\<turnstile>v ::\\<preceq> T )))) \\<and> \ |
|
170 \ (G\\<turnstile>(x,(h,l)) -es[\\<succ>]vs-> (x', (h',l')) --> \ |
|
171 \ (\\<forall>lT. (h ,l )::\\<preceq>(G,lT) --> (\\<forall>Ts. (G,lT)\\<turnstile>es[::]Ts --> \ |
|
172 \ h\\<le>|h' \\<and> (h',l')::\\<preceq>(G,lT) \\<and> (x'=None --> list_all2 (\\<lambda>v T. G,h'\\<turnstile>v::\\<preceq>T) vs Ts)))) \\<and> \ |
|
173 \ (G\\<turnstile>(x,(h,l)) -c -> (x', (h',l')) --> \ |
|
174 \ (\\<forall>lT. (h ,l )::\\<preceq>(G,lT) --> (G,lT)\\<turnstile>c \\<surd> --> \ |
|
175 \ h\\<le>|h' \\<and> (h',l')::\\<preceq>(G,lT)))"; |
|
176 by( rtac eval_evals_exec_induct 1); |
|
177 by( rewtac c_hupd_def); |
|
178 |
|
179 (* several simplifications, XcptE, XcptEs, XcptS, Skip, Nil?? *) |
|
180 by( ALLGOALS Asm_full_simp_tac); |
|
181 by( ALLGOALS strip_tac); |
|
182 by( ALLGOALS (eresolve_tac ty_expr_ty_exprs_wt_stmt.elims |
|
183 THEN_ALL_NEW Full_simp_tac)); |
|
184 by( ALLGOALS (EVERY' [REPEAT o (etac conjE), REPEAT o hyp_subst_tac])); |
|
185 by( rewtac wf_java_prog_def); |
|
186 |
|
187 (* Level 7 *) |
|
188 |
|
189 (* 15 NewC *) |
|
190 by( dtac new_AddrD 1); |
|
191 by( etac disjE 1); |
|
192 by( Asm_simp_tac 2); |
|
193 by( Clarsimp_tac 1); |
|
194 by( rtac conjI 1); |
|
195 by( force_tac (claset() addSEs [NewC_conforms],simpset()) 1); |
|
196 by( rtac conf_obj_AddrI 1); |
|
197 by( rtac rtrancl_refl 2); |
|
198 by( Simp_tac 1); |
|
199 |
|
200 (* for Cast *) |
|
201 by( defer_tac 1); |
|
202 |
|
203 (* 14 Lit *) |
|
204 by( etac conf_litval 1); |
|
205 |
|
206 (* 13 BinOp *) |
|
207 by forward_hyp_tac; |
|
208 by forward_hyp_tac; |
|
209 by( EVERY'[rtac conjI, eatac hext_trans 1] 1); |
|
210 by( etac conjI 1); |
|
211 by( Clarsimp_tac 1); |
|
212 by( dtac eval_no_xcpt 1); |
|
213 by( asm_full_simp_tac (simpset() addsplits [binop.split]) 1); |
|
214 |
|
215 (* 12 LAcc *) |
|
216 by( fast_tac (claset() addEs [conforms_localD RS lconfD]) 1); |
|
217 |
|
218 (* for FAss *) |
|
219 by( EVERY'[eresolve_tac ty_expr_ty_exprs_wt_stmt.elims THEN_ALL_NEW Full_simp_tac, |
|
220 REPEAT o (etac conjE), hyp_subst_tac] 3); |
|
221 |
|
222 (* for if *) |
|
223 by( (case_tac "the_Bool v" THEN_ALL_NEW Asm_full_simp_tac) 8); |
|
224 |
|
225 by forward_hyp_tac; |
|
226 |
|
227 (* 11+1 if *) |
|
228 by( fast_tac (HOL_cs addIs [hext_trans]) 8); |
|
229 by( fast_tac (HOL_cs addIs [hext_trans]) 8); |
|
230 |
|
231 (* 10 Expr *) |
|
232 by( Fast_tac 6); |
|
233 |
|
234 (* 9 ??? *) |
|
235 by( ALLGOALS Asm_full_simp_tac); |
|
236 |
|
237 (* 8 Cast *) |
|
238 by( EVERY'[rtac impI, dtac raise_if_NoneD, Clarsimp_tac, |
|
239 fast_tac (claset() addEs [Cast_conf])] 8); |
|
240 |
|
241 (* 7 LAss *) |
|
242 by( asm_simp_tac (simpset() addsplits [split_if]) 1); |
|
243 by( EVERY'[eresolve_tac ty_expr_ty_exprs_wt_stmt.elims THEN_ALL_NEW Full_simp_tac] 1); |
|
244 by( blast_tac (claset() addIs [conforms_upd_local, conf_widen]) 1); |
|
245 |
|
246 (* 6 FAcc *) |
|
247 by( fast_tac (claset() addSEs [FAcc_type_sound]) 1); |
|
248 |
|
249 (* 5 While *) |
|
250 by(thin_tac "?a \\<longrightarrow> ?b" 5); |
|
251 by(datac ty_expr_ty_exprs_wt_stmt.Loop 1 5); |
|
252 by(force_tac (claset() addEs [hext_trans], simpset()) 5); |
|
253 |
|
254 by forward_hyp_tac; |
|
255 |
|
256 (* 4 Cons *) |
|
257 by( fast_tac (claset() addDs [evals_no_xcpt] addIs [conf_hext,hext_trans]) 3); |
|
258 |
|
259 (* 3 ;; *) |
|
260 by( fast_tac (claset() addIs [hext_trans]) 3); |
|
261 |
|
262 (* 2 FAss *) |
|
263 by( case_tac "x2 = None" 1); |
|
264 by( Asm_simp_tac 2); |
|
265 by( fast_tac (claset() addIs [hext_trans]) 2); |
|
266 by( Asm_full_simp_tac 1); |
|
267 by( dtac eval_no_xcpt 1); |
|
268 by( SELECT_GOAL (etac FAss_type_sound 1 THEN rtac refl 1 THEN ALLGOALS atac) 1); |
|
269 |
|
270 by prune_params_tac; |
|
271 (* Level 52 *) |
|
272 |
|
273 (* 1 Call *) |
|
274 by( case_tac "x" 1); |
|
275 by( Clarsimp_tac 2); |
|
276 by( dtac exec_xcpt 2); |
|
277 by( Asm_full_simp_tac 2); |
|
278 by( dtac eval_xcpt 2); |
|
279 by( Asm_full_simp_tac 2); |
|
280 by( fast_tac (HOL_cs addEs [hext_trans]) 2); |
|
281 by( Clarify_tac 1); |
|
282 by( dtac evals_no_xcpt 1); |
|
283 by( Asm_full_simp_tac 1); |
|
284 by( case_tac "a' = Null" 1); |
|
285 by( Asm_full_simp_tac 1); |
|
286 by( dtac exec_xcpt 1); |
|
287 by( Asm_full_simp_tac 1); |
|
288 by( dtac eval_xcpt 1); |
|
289 by( Asm_full_simp_tac 1); |
|
290 by( fast_tac (HOL_cs addEs [hext_trans]) 1); |
|
291 by( datac ty_expr_is_type 1 1); |
|
292 by(Clarsimp_tac 1); |
|
293 by(rewtac is_class_def); |
|
294 by(Clarsimp_tac 1); |
|
295 by( (rtac (rewrite_rule [wf_java_prog_def] Call_type_sound) |
|
296 THEN_ALL_NEW Asm_simp_tac) 1); |
|
297 qed "eval_evals_exec_type_sound"; |
|
298 |
|
299 Goal "!!E s s'. \ |
|
300 \ [| G=prg E; wf_java_prog G; G\\<turnstile>(x,s) -e\\<succ>v -> (x',s'); s::\\<preceq>E; E\\<turnstile>e::T |] \ |
|
301 \ ==> s'::\\<preceq>E \\<and> (x'=None --> G,heap s'\\<turnstile>v::\\<preceq>T)"; |
|
302 by( split_all_tac 1); |
|
303 bd (eval_evals_exec_type_sound RS conjunct1 RS mp RS spec RS mp) 1; |
|
304 by Auto_tac; |
|
305 qed "eval_type_sound"; |
|
306 |
|
307 Goal "!!E s s'. \ |
|
308 \ [| G=prg E; wf_java_prog G; G\\<turnstile>(x,s) -s0-> (x',s'); s::\\<preceq>E; E\\<turnstile>s0\\<surd> |] \ |
|
309 \ ==> s'::\\<preceq>E"; |
|
310 by( split_all_tac 1); |
|
311 bd (eval_evals_exec_type_sound RS conjunct2 RS conjunct2 RS mp RS spec RS mp) 1; |
|
312 by Auto_tac; |
|
313 qed "exec_type_sound"; |
|
314 |
|
315 Goal "[|G=prg E; wf_java_prog G; G\\<turnstile>(x,s) -e\\<succ>a'-> Norm s'; a' \\<noteq> Null;\ |
|
316 \ s::\\<preceq>E; E\\<turnstile>e::Class C; method (G,C) sig \\<noteq> None|] ==> \ |
|
317 \ method (G,fst (the (heap s' (the_Addr a')))) sig \\<noteq> None"; |
|
318 by( datac eval_type_sound 4 1); |
|
319 by(Clarsimp_tac 1); |
|
320 by(rewtac wf_java_prog_def); |
|
321 by( forward_tac [widen_methd] 1); |
|
322 by( atac 1); |
|
323 by( Fast_tac 2); |
|
324 by( dtac non_npD 1); |
|
325 by Auto_tac; |
|
326 qed "all_methods_understood"; |
|
327 |
|
328 Delsimps [split_beta]; |
|
329 Addsimps[fun_upd_apply]; |
|
330 |
|