source: C-semantics/IOMonad.ma @ 252

Last change on this file since 252 was 252, checked in by campbell, 9 years ago

Separate out soundness of exec_step from definition.

File size: 8.3 KB
Line 
1include "Plogic/russell_support.ma".
2include "extralib.ma".
3include "Errors.ma".
4
5(* IO monad *)
6
7ninductive IO (input,output:Type) (T:Type) : Type ≝
8| Interact : output → (input → IO input output T) → IO input output T
9| Value : T → IO input output T
10| Wrong : IO input output T.
11
12nlet rec bindIO (I,O,T,T':Type) (v:IO I O T) (f:T → IO I O T') on v : IO I O T' ≝
13match v with
14[ Interact out k ⇒ (Interact ??? out (λres. bindIO I O T T' (k res) f))
15| Value v' ⇒ (f v')
16| Wrong ⇒ Wrong I O T'
17].
18
19nlet rec bindIO2 (I,O,T1,T2,T':Type) (v:IO I O (T1×T2)) (f:T1 → T2 → IO I O T') on v : IO I O T' ≝
20match v with
21[ Interact out k ⇒ (Interact ??? out (λres. bindIO2 ?? T1 T2 T' (k res) f))
22| Value v' ⇒ match v' with [ mk_pair v1 v2 ⇒ f v1 v2 ]
23| Wrong ⇒ Wrong ?? T'
24].
25
26ndefinition err_to_io : ∀I,O,T. res T → IO I O T ≝
27λI,O,T,v. match v with [ OK v' ⇒ Value I O T v' | Error ⇒ Wrong I O T ].
28ncoercion err_to_io : ∀I,O,A.∀c:res A.IO I O A ≝ err_to_io on _c:res ? to IO ???.
29ndefinition err_to_io_sig : ∀I,O,T.∀P:T → Prop. res (sigma T P) → IO I O (sigma T P) ≝
30λI,O,T,P,v. match v with [ OK v' ⇒ Value I O (sigma T P) v' | Error ⇒ Wrong I O (sigma T P) ].
31(*ncoercion err_to_io_sig : ∀I,O,A.∀P:A → Prop.∀c:res (sigma A P).IO I O (sigma A P) ≝ err_to_io_sig on _c:res (sigma ??) to IO ?? (sigma ??).*)
32
33
34(* If the original definitions are vague enough, do I need to do this? *)
35notation > "! ident v ← e; e'" with precedence 40 for @{'bindIO ${e} (λ${ident v}.${e'})}.
36notation > "! ident v : ty ← e; e'" with precedence 40 for @{'bindIO ${e} (λ${ident v} : ${ty}.${e'})}.
37notation < "vbox(! \nbsp ident v ← e; break e')" with precedence 40 for @{'bindIO ${e} (λ${ident v}.${e'})}.
38notation < "vbox(! \nbsp ident v : ty ← e; break e')" with precedence 40 for @{'bindIO ${e} (λ${ident v} : ${ty}.${e'})}.
39notation > "! 〈ident v1, ident v2〉 ← e; e'" with precedence 40 for @{'bindIO2 ${e} (λ${ident v1}.λ${ident v2}.${e'})}.
40notation > "! 〈ident v1 : ty1, ident v2 : ty2〉 ← e; e'" with precedence 40 for @{'bindIO2 ${e} (λ${ident v1} : ${ty1}.λ${ident v2} : ${ty2}.${e'})}.
41notation < "vbox(! \nbsp 〈ident v1, ident v2〉 ← e; break e')" with precedence 40 for @{'bindIO2 ${e} (λ${ident v1}.λ${ident v2}.${e'})}.
42notation < "vbox(! \nbsp 〈ident v1 : ty1, ident v2 : ty2〉 ← e; break e')" with precedence 40 for @{'bindIO2 ${e} (λ${ident v1} : ${ty1}.λ${ident v2} : ${ty2}.${e'})}.
43interpretation "IO monad bind" 'bindIO e f = (bindIO ???? e f).
44interpretation "IO monad pair bind" 'bindIO2 e f = (bindIO2 ????? e f).
45(**)
46nlet rec P_io (I,O,A:Type) (P:A → Prop) (v:IO I O A) on v : Prop ≝
47match v return λ_.Prop with
48[ Wrong ⇒ True
49| Value z ⇒ P z
50| Interact out k ⇒ ∀v'.P_io I O A P (k v')
51].
52
53nlet rec P_io' (I,O,A:Type) (P:A → Prop) (v:IO I O A) on v : Prop ≝
54match v return λ_.Prop with
55[ Wrong ⇒ False
56| Value z ⇒ P z
57| Interact out k ⇒ ∀v'.P_io' I O A P (k v')
58].
59
60ndefinition P_to_P_option_io : ∀I,O,A.∀P:A → Prop.option (IO I O A) → Prop ≝
61  λI,O,A,P,a.match a with
62   [ None ⇒ False
63   | Some y ⇒ P_io I O A P y
64   ].
65
66nlet rec io_inject_0 (I,O,A:Type) (P:A → Prop) (a:IO I O A) (p:P_io I O A P a) on a : IO I O (sigma A P) ≝
67(match a return λa'.P_io I O A P a' → ? with
68 [ Wrong ⇒ λ_. Wrong I O ?
69 | Value c ⇒ λp'. Value ??? (sig_intro A P c p')
70 | Interact out k ⇒ λp'. Interact ??? out (λv. io_inject_0 I O A P (k v) (p' v))
71 ]) p.
72
73ndefinition io_inject : ∀I,O,A.∀P:A → Prop.∀a:option (IO I O A).∀p:P_to_P_option_io I O A P a.IO I O (sigma A P) ≝
74  λI,O,A.λP:A → Prop.λa:option (IO I O A).λp:P_to_P_option_io I O A P a.
75  (match a return λa'.P_to_P_option_io I O A P a' → IO I O (sigma A P) with
76   [ None ⇒ λp'.?
77   | Some b ⇒ λp'. io_inject_0 I O A P b p'
78   ]) p.
79nelim p'; nqed.
80
81nlet rec io_eject (I,O,A:Type) (P: A → Prop) (a:IO I O (sigma A P)) on a : IO I O A ≝
82match a with
83[ Wrong ⇒ Wrong ???
84| Value b ⇒ match b with [ sig_intro w p ⇒ Value ??? w]
85| Interact out k ⇒ Interact ??? out (λv. io_eject ?? A P (k v))
86].
87
88ncoercion io_inject :
89  ∀I,O,A.∀P:A → Prop.∀a.∀p:P_to_P_option_io I O ? P a.IO I O (sigma A P) ≝ io_inject
90  on a:option (IO ???) to IO ?? (sigma ? ?).
91ncoercion io_eject : ∀I,O,A.∀P:A → Prop.∀c:IO I O (sigma A P).IO I O A ≝ io_eject
92  on _c:IO ?? (sigma ? ?) to IO ???.
93
94ndefinition opt_to_io : ∀I,O,T.option T → IO I O T ≝
95λI,O,T,v. match v with [ None ⇒ Wrong I O T | Some v' ⇒ Value I O T v' ].
96ncoercion opt_to_io : ∀I,O,T.∀v:option T. IO I O T ≝ opt_to_io on _v:option ? to IO ???.
97
98nlemma sig_bindIO_OK: ∀I,O,A,B. ∀P:A → Prop. ∀P':B → Prop. ∀e:IO I O (sigma A P). ∀f:sigma A P → IO I O B.
99  (∀v:A. ∀p:P v. P_io I O ? P' (f (sig_intro A P v p))) →
100  P_io I O ? P' (bindIO I O (sigma A P) B e f).
101#I O A B P P' e f; nelim e;
102##[ #out k IH; #IH'; nwhd; #res; napply IH; //;
103##| #v0; nelim v0; #v Hv IH; nwhd; napply IH;
104##| //;
105##] nqed.
106
107nlemma sig_bindIO2_OK: ∀I,O,A,B,C. ∀P:(A×B) → Prop. ∀P':C → Prop. ∀e:IO I O (sigma (A×B) P). ∀f: A → B → IO I O C.
108  (∀vA:A.∀vB:B. ∀p:P 〈vA,vB〉. P_io I O ? P' (f vA vB)) →
109  P_io I O ? P' (bindIO2 I O A B C e f).
110#I O A B C P P' e f; nelim e;
111##[ #out k IH; #IH'; nwhd; #res; napply IH; napply IH';
112##| #v0; nelim v0; #v; nelim v; #vA vB Hv IH; napply IH; //;
113##| //;
114##] nqed.
115
116nlemma opt_bindIO_OK: ∀I,O,A,B. ∀P:B → Prop. ∀e:option A. ∀f: A → IO I O B.
117  (∀v:A. e = Some A v → P_io I O ? P (f v)) →
118  P_io I O ? P (bindIO I O A B e f).
119#I O A B P e; nelim e; //; #v f H; napply H; //;
120nqed.
121
122nlemma opt_bindIO2_OK: ∀I,O,A,B,C. ∀P:C → Prop. ∀e:option (A×B). ∀f: A → B → IO I O C.
123  (∀vA:A.∀vB:B. e = Some (A×B) 〈vA,vB〉 → P_io I O ? P (f vA vB)) →
124  P_io I O ? P (bindIO2 I O A B C e f).
125#I O A B C P e; nelim e; //; #v; ncases v; #vA vB f H; napply H; //;
126nqed.
127
128nlemma res_bindIO_OK: ∀I,O,A,B. ∀P:B → Prop. ∀e:res A. ∀f: A → IO I O B.
129  (∀v:A. e = OK A v → P_io I O ? P (f v)) →
130  P_io I O ? P (bindIO I O A B e f).
131#I O A B P e; nelim e; //; #v f H; napply H; //;
132nqed.
133
134nlemma res_bindIO2_OK: ∀I,O,A,B,C. ∀P:C → Prop. ∀e:res (A×B). ∀f: A → B → IO I O C.
135  (∀vA:A.∀vB:B. e = OK (A×B) 〈vA,vB〉 → P_io I O ? P (f vA vB)) →
136  P_io I O ? P (bindIO2 I O A B C e f).
137#I O A B C P e; nelim e; //; #v; ncases v; #vA vB f H; napply H; //;
138nqed.
139
140nlemma bindIO_OK: ∀I,O,A,B. ∀P:B → Prop. ∀e:IO I O A. ∀f: A → IO I O B.
141  (∀v:A. P_io I O ? P (f v)) →
142  P_io I O ? P (bindIO I O A B e f).
143#I O A B P e; nelim e;
144##[ #out k IH; #f H; nwhd; #res; napply IH; //;
145##| #v f H; napply H;
146##| //;
147##] nqed.
148
149nlemma bindIO2_OK: ∀I,O,A,B,C. ∀P:C → Prop. ∀e:IO I O (A×B). ∀f: A → B → IO I O C.
150  (∀v1:A.∀v2:B. P_io I O ? P (f v1 v2)) →
151  P_io I O ? P (bindIO2 I O A B C e f).
152#I O A B C P e; nelim e;
153##[ #out k IH; #f H; nwhd; #res; napply IH; //;
154##| #v; ncases v; #v1 v2 f H; napply H;
155##| //;
156##] nqed.
157
158nlemma P_bindIO_OK: ∀I,O,A,B. ∀P':A → Prop. ∀P:B → Prop. ∀e:IO I O A. ∀f: A → IO I O B.
159  P_io … P' e →
160  (∀v:A. P' v → P_io I O ? P (f v)) →
161  P_io I O ? P (bindIO I O A B e f).
162#I O A B P' P e; nelim e;
163##[ #out k IH f He H; nwhd in He ⊢ %; #res; napply IH; /2/;
164##| #v f He H; napply H; napply He;
165##| //;
166##] nqed.
167
168nlemma P_bindIO2_OK: ∀I,O,A,B,C. ∀P':A×B → Prop. ∀P:C → Prop. ∀e:IO I O (A×B). ∀f: A → B → IO I O C.
169  P_io … P' e →
170  (∀v1:A.∀v2:B. P' 〈v1,v2〉 → P_io I O ? P (f v1 v2)) →
171  P_io I O ? P (bindIO2 I O A B C e f).
172#I O A B C P' P e; nelim e;
173##[ #out k IH f He H; nwhd in He ⊢ %; #res; napply IH; /2/;
174##| #v; ncases v; #v1 v2 f He H; napply H; napply He;
175##| //;
176##] nqed.
177
178
179(* TODO: is there a way to prove this without extensionality?
180
181nlemma bind_assoc_r: ∀A,B,C,e,f,g.
182  bindIO B C (bindIO A B e f) g = bindIO A C e (λx.bindIO B C (f x) g).
183#A B C e f g; nelim e;
184##[ #fn args k IH; nwhd in ⊢ (???%);
185nnormalize;
186*)
187
188nlemma extract_subset_pair_io: ∀I,O,A,B,C,P. ∀e:{e:A×B | P e}. ∀Q:A→B→IO I O C. ∀R:C→Prop.
189  (∀a,b. eject ?? e = 〈a,b〉 → P 〈a,b〉 → P_io I O ? R (Q a b)) →
190  P_io I O ? R (match eject ?? e with [ mk_pair a b ⇒ Q a b ]).
191#I O A B C P e Q R; ncases e; #e'; ncases e'; nnormalize;
192##[ *;
193##| #e''; ncases e''; #a b Pab H; nnormalize; /2/;
194##] nqed.
195
Note: See TracBrowser for help on using the repository browser.