source: LTS/Lang_meas.ma @ 3550

Last change on this file since 3550 was 3550, checked in by piccolo, 5 years ago

chiusi dei demoni

File size: 32.9 KB
Line 
1(**************************************************************************)
2(*       ___                                                              *)
3(*      ||M||                                                             *)
4(*      ||A||       A project by Andrea Asperti                           *)
5(*      ||T||                                                             *)
6(*      ||I||       Developers:                                           *)
7(*      ||T||         The HELM team.                                      *)
8(*      ||A||         http://helm.cs.unibo.it                             *)
9(*      \   /                                                             *)
10(*       \ /        This file is distributed under the terms of the       *)
11(*        v         GNU General Public License Version 2                  *)
12(*                                                                        *)
13(**************************************************************************)
14
15include "Lang_corr.ma".
16
17
18lemma top_move_source_is_empty : ∀p,p',prog.
19let 〈t_prog,m,keep〉 ≝ trans_prog … prog in
20∀l.
21∀s1,s2,s1' : state p.∀abs_top,abs_tail.
22execute_l … p' (env … prog) l s1 s2 →
23is_costlabelled_act p l →
24(is_call_act p l → is_call_post_label p (operational_semantics p p' prog) … s1) →
25state_rel … m keep abs_top abs_tail s1 s1' → abs_top = nil ? ∧
26(is_call_act p l → is_call_post_label p (operational_semantics p p' t_prog) … s1').
27#p #p' #prog @pair_elim * #t_prog #m #keep #EQt_prog normalize nodelta
28#l #s1 #s2 #s1' #abs_top #abs_tail #H elim H -s1 -s2 -l
29[ #s1 #s2 * #lab #code_cont #stack #EQcode #EQcont #EQ1 #EQ2 destruct #EQstore
30  #Hio1 #Hio2 #no_ret_lab #cost_lab whd in match state_rel; normalize nodelta
31  inversion(check_continuations ?????) [ #_ #_ *] ** #Hcont #a_top #a_tail #EQcheck #_
32  normalize nodelta **** #HHcont #EQcall_post #EQstore #EQio #EQ destruct
33  >EQcont in EQcheck; whd in ⊢ (??%? → ?); inversion(cont … s1') normalize nodelta
34  [ #_ #EQ destruct] * #lab' #code_cont' #stack' #_ #EQcont'
35    change with (check_continuations ??????) in match (foldr2 ???????);
36    inversion(check_continuations ?????) [ #_ normalize #EQ destruct]
37    ** #H2 #a_top1 #a_tail1 #EQcheck >m_return_bind normalize nodelta
38    inversion(call_post_clean ?????) normalize nodelta [ #_ whd in ⊢ (??%% → ?); #EQ destruct cases HHcont]
39    * #labels #code_cleaned #EQclean normalize nodelta
40    >EQcode in EQcall_post; inversion(code ? s1')
41        [2,3,4,5,6,7:
42          [ #ret | #seq #opt_l #instr #_ | #cond #ltrue #i_true #lfalse #i_false #instr #_ #_ #_|
43            #cond #ltrue #itrue #lfalse #ifalse #_ #_| #f #pars #opt_l #instr #_ | #lin #io #lout #instr #_ ]
44          #_ whd in ⊢ (??%% → ?);
45          [ | cases(call_post_clean ?????); normalize nodelta [2: #x cases opt_l normalize nodelta [| #label cases(?==?) normalize nodelta]]
46          | cases(call_post_clean ?????); normalize nodelta
47            [2: #x whd in ⊢ (??%? → ?); cases(call_post_clean ?????) normalize nodelta
48               [|#y whd in ⊢ (??%? → ?); cases(call_post_clean ?????) normalize nodelta
49                 [| #z cases(?∧?) normalize nodelta
50                 ]
51               ]
52            ]
53          | cases(call_post_clean ?????) normalize nodelta
54            [| #x whd in ⊢ (??%? → ?); cases(call_post_clean ?????) normalize nodelta
55               [| #y cases(?∧?) normalize nodelta
56               ]
57            ]
58          | cases(call_post_clean ?????) normalize nodelta
59             [| #x cases opt_l normalize nodelta [| #lbls cases(memb ???) normalize nodelta
60                [ cases (?==?) normalize nodelta ]
61             ]]
62          | cases(call_post_clean ?????) normalize nodelta
63             [| #x cases(? ∧ ?) normalize nodelta ]
64          ]
65          whd in ⊢ (??%% → ?); #EQ lapply(eq_to_jmeq ??? EQ) -EQ #EQ destruct
66        | #EQcode_s1' whd in ⊢ (??%% → ?); #EQ destruct cases lab' normalize nodelta
67          [ #f #c whd in ⊢ (??%% → ?); #EQ destruct %{(refl …)} cases HHcont
68          | * normalize nodelta [| #Lab cases(ret_costed_abs ??) normalize nodelta [| #xxx]] whd in ⊢ (??%% → ?);
69            #EQ destruct %{(refl …)} cases HHcont * [3: *] #EQ destruct #_ #_ [ #_] * #f * #c #EQ destruct
70          | * [|#LAB] normalize nodelta whd in ⊢ (??%% → ?); #EQ destruct % // cases HHcont * #EQ destruct
71            try cases cost_lab #_ #_ cases EQ -EQ #EQ destruct #_ * #f * #c #EQ destruct
72          ]
73        ]
74| #s1 #s2 #i #instr #st * [|#lbl] #EQcode_s1 #EQst #EQ destruct #EQcont #EQ destruct #Hios1 #Hios2 *
75  whd in match state_rel; normalize nodelta cases(check_continuations ?????) normalize nodelta [ #_ *] **
76  #H1 #a_top #a_tail normalize nodelta #_ **** #HH1 >EQcode_s1 inversion(code ? s1')
77  [1,2,4,5,6,7:
78    [ | #ret | #cond #ltrue #i_true #lfalse #i_false #instr #_ #_ #_|
79            #cond #ltrue #itrue #lfalse #ifalse #_ #_| #f #pars #opt_l #instr #_ | #lin #io #lout #instr #_ ]
80          #_ whd in ⊢ (??%% → ?);
81          [ |
82          | cases(call_post_clean ?????); normalize nodelta
83            [2: #x whd in ⊢ (??%? → ?); cases(call_post_clean ?????) normalize nodelta
84               [|#y whd in ⊢ (??%? → ?); cases(call_post_clean ?????) normalize nodelta
85                 [| #z cases(?∧?) normalize nodelta
86                 ]
87               ]
88            ]
89          | cases(call_post_clean ?????) normalize nodelta
90            [| #x whd in ⊢ (??%? → ?); cases(call_post_clean ?????) normalize nodelta
91               [| #y cases(?∧?) normalize nodelta
92               ]
93            ]
94          | cases(call_post_clean ?????) normalize nodelta
95             [| #x cases opt_l normalize nodelta [| #lbls cases(memb ???) normalize nodelta
96                [ cases (?==?) normalize nodelta ]
97             ]]
98          | cases(call_post_clean ?????) normalize nodelta
99             [| #x cases(? ∧ ?) normalize nodelta ]
100          ]
101          whd in ⊢ (??%% → ?); #EQ lapply(eq_to_jmeq ??? EQ) -EQ #EQ destruct
102  | #i' * [|#lb] #instr' #_ #EQcode_s1' whd in ⊢ (??%% → ?); cases(call_post_clean ?????) normalize nodelta
103    [1,3: #EQ destruct] #x whd in ⊢ (??%% → ?); [ #EQ lapply(eq_to_jmeq ??? EQ) -EQ #EQ destruct ]
104    cases(get_element ???) normalize nodelta [#EQ destruct] #LAB #ll normalize nodelta cases(?==?) normalize nodelta
105    [2:  #EQ destruct] whd in ⊢ (??%% → ?); #EQ lapply(eq_to_jmeq ??? EQ) -EQ #EQ destruct #_ #_ #_ % // * #f * #c #EQ4 destruct
106 ]
107| #s1 #s2 #exp #ltrue #i_true #lfalse #i_false #instrs #new_m #EQcode_s1 #EQeval #EQcont_s2 #EQ destruct #EQ destruct
108  #Hio1 #Hio2 #_ #_ whd in match state_rel; normalize nodelta inversion(check_continuations ?????) normalize nodelta
109  [ #_ *] ** #H1 #a_top #a_tail #EQcheck normalize nodelta **** #HH1 >EQcode_s1 inversion(code ? s1')
110  [1,2,3,5,6,7:
111    [ | #ret | #seq #opt_l #instr #_ | #cond #ltrue #itrue #lfalse #ifalse #_ #_| #f #pars #opt_l #instr #_
112       | #lin #io #lout #instr #_ ]
113          #_ whd in ⊢ (??%% → ?);
114          [ |
115          | cases(call_post_clean ?????); normalize nodelta [2: #x cases opt_l normalize nodelta [| #label cases(?==?) normalize nodelta]]
116          | cases(call_post_clean ?????) normalize nodelta
117            [| #x whd in ⊢ (??%? → ?); cases(call_post_clean ?????) normalize nodelta
118               [| #y cases(?∧?) normalize nodelta
119               ]
120            ]
121          | cases(call_post_clean ?????) normalize nodelta
122             [| #x cases opt_l normalize nodelta [| #lbls cases(memb ???) normalize nodelta
123                [ cases (?==?) normalize nodelta ]
124             ]]
125          | cases(call_post_clean ?????) normalize nodelta
126             [| #x cases(? ∧ ?) normalize nodelta ]
127          ]
128          whd in ⊢ (??%% → ?); #EQ lapply(eq_to_jmeq ??? EQ) -EQ #EQ destruct
129  ]
130  #exp' #ltrue' #i_true' #lfalse' #i_false' #instrs'  #_ #_ #_ #EQcode_s1' whd in ⊢ (??%% → ?);
131  inversion(call_post_clean ?????) normalize nodelta [#_ #EQ destruct] * #a_top1 #istr1 #EQinstr'
132  whd in ⊢ (??%%→ ?); inversion(call_post_clean ?????) normalize nodelta [ #_ #EQ destruct] * #a_top2 #istr2
133  #EQi_false' whd in ⊢ (??%% → ?); inversion(call_post_clean ?????) normalize nodelta [#_ #EQ destruct] *
134  #a_top3 #istr3 #EQi_true' inversion(?==?) #EQget1 inversion(?==?) #EQget2 normalize nodelta
135  whd in ⊢ (??%% → ?); #EQ lapply(eq_to_jmeq ??? EQ) -EQ #EQ destruct #_ #_ #EQ destruct % // * #f * #c #EQ destruct
136| #s1 #s2 #exp #ltrue #i_true #lfalse #i_false #instrs #new_m #EQcode_s1 #EQeval #EQcont_s2 #EQ1 #EQ2 destruct
137  #Hio1 #Hio2 * #_ whd in match state_rel; normalize nodelta inversion(check_continuations ?????) normalize nodelta
138  [ #_ *] ** #H1 #a_top #a_tail #EQcheck normalize nodelta **** #HH1 >EQcode_s1  inversion(code ? s1')
139  [1,2,3,5,6,7:
140    [ | #ret | #seq #opt_l #instr #_ | #cond #ltrue #itrue #lfalse #ifalse #_ #_| #f #pars #opt_l #instr #_
141       | #lin #io #lout #instr #_ ]
142          #_ whd in ⊢ (??%% → ?);
143          [ |
144          | cases(call_post_clean ?????); normalize nodelta [2: #x cases opt_l normalize nodelta [| #label cases(?==?) normalize nodelta]]
145          | cases(call_post_clean ?????) normalize nodelta
146            [| #x whd in ⊢ (??%? → ?); cases(call_post_clean ?????) normalize nodelta
147               [| #y cases(?∧?) normalize nodelta
148               ]
149            ]
150          | cases(call_post_clean ?????) normalize nodelta
151             [| #x cases opt_l normalize nodelta [| #lbls cases(memb ???) normalize nodelta
152                [ cases (?==?) normalize nodelta ]
153             ]]
154          | cases(call_post_clean ?????) normalize nodelta
155             [| #x cases(? ∧ ?) normalize nodelta ]
156          ]
157          whd in ⊢ (??%% → ?); #EQ lapply(eq_to_jmeq ??? EQ) -EQ #EQ destruct
158  ]
159  #exp' #ltrue' #i_true' #lfalse' #i_false' #instrs' #_ #_ #_ #EQcode_s1' whd in ⊢ (??%% → ?);
160  inversion(call_post_clean ?????) normalize nodelta [#_ #EQ destruct] * #a_top1 #istr1 #EQinstr'
161  whd in ⊢ (??%%→ ?); inversion(call_post_clean ?????) normalize nodelta [ #_ #EQ destruct] * #a_top2 #istr2
162  #EQi_false' whd in ⊢ (??%% → ?); inversion(call_post_clean ?????) normalize nodelta [#_ #EQ destruct] *
163  #a_top3 #istr3 #EQi_true' inversion(?==?) #EQget1 inversion(?==?) #EQget2 normalize nodelta
164  whd in ⊢ (??%% → ?); #EQ lapply(eq_to_jmeq ??? EQ) -EQ #EQ destruct #_ #_ #EQ destruct % // * #f * #c #EQ destruct
165| #s1 #s2 #exp #ltrue #i_true #lfalse #i_false #m #EQcode_s1 #EQeval #EQcont_s2 #EQ1 #EQ2 destruct #Hio1 #Hio2
166  #_ #_ whd in match state_rel; normalize nodelta inversion(check_continuations …) normalize nodelta
167  [ #_ *] ** #H1 #a_top #a_tail #EQcheck normalize nodelta **** #HH1 >EQcode_s1 inversion(code … s1')
168  [1,2,3,4,6,7:
169    [ | #ret | #seq #opt_l #instr #_ | #cond #ltrue #i_true #lfalse #i_false #instr #_ #_ #_| #f #pars #opt_l #instr #_
170       | #lin #io #lout #instr #_ ]
171          #_ whd in ⊢ (??%% → ?);
172          [ |
173          | cases(call_post_clean ?????); normalize nodelta [2: #x cases opt_l normalize nodelta [| #label cases(?==?) normalize nodelta]]
174          | cases(call_post_clean ?????); normalize nodelta
175            [2: #x whd in ⊢ (??%? → ?); cases(call_post_clean ?????) normalize nodelta
176               [|#y whd in ⊢ (??%? → ?); cases(call_post_clean ?????) normalize nodelta
177                 [| #z cases(?∧?) normalize nodelta
178                 ]
179               ]
180            ]
181          | cases(call_post_clean ?????) normalize nodelta
182             [| #x cases opt_l normalize nodelta [| #lbls cases(memb ???) normalize nodelta
183                [ cases (?==?) normalize nodelta ]
184             ]]
185          | cases(call_post_clean ?????) normalize nodelta
186             [| #x cases(? ∧ ?) normalize nodelta ]
187          ]
188          whd in ⊢ (??%% → ?); #EQ lapply(eq_to_jmeq ??? EQ) -EQ #EQ destruct
189   ]
190   #exp' #ltrue' #i_true' #lfalse' #i_false' #_ #_ #EQcode_s1' whd in ⊢ (??%% → ?);
191   cases(call_post_clean …) normalize nodelta [ #EQ destruct] * #a_top1 #i_false''
192   cases(call_post_clean …) [ whd in ⊢ (??%% → ?); #EQ destruct] * #a_top2 #i_true'' >m_return_bind
193   cases(?∧?) normalize nodelta whd in ⊢ (??%% → ?); #EQ lapply(eq_to_jmeq ??? EQ) -EQ #EQ destruct
194   #_ #_ #EQ destruct % // * #f * #lab #EQ destruct
195| #s1 #s2 #exp #ltrue #i_true #lfalse #i_false #m #EQcode_s1 #EQeval #EQcont_s2 #EQ1 #EQ2 destruct #Hio1 #Hio2
196  #_ #_ whd in match state_rel; normalize nodelta inversion(check_continuations …) normalize nodelta
197  [ #_ *] ** #H1 #a_top #a_tail #EQcheck normalize nodelta **** #HH1 >EQcode_s1 inversion(code … s1')
198  [1,2,3,4,6,7:
199    [ | #ret | #seq #opt_l #instr #_ | #cond #ltrue #i_true #lfalse #i_false #instr #_ #_ #_| #f #pars #opt_l #instr #_
200       | #lin #io #lout #instr #_ ]
201          #_ whd in ⊢ (??%% → ?);
202          [ |
203          | cases(call_post_clean ?????); normalize nodelta [2: #x cases opt_l normalize nodelta [| #label cases(?==?) normalize nodelta]]
204          | cases(call_post_clean ?????); normalize nodelta
205            [2: #x whd in ⊢ (??%? → ?); cases(call_post_clean ?????) normalize nodelta
206               [|#y whd in ⊢ (??%? → ?); cases(call_post_clean ?????) normalize nodelta
207                 [| #z cases(?∧?) normalize nodelta
208                 ]
209               ]
210            ]
211          | cases(call_post_clean ?????) normalize nodelta
212             [| #x cases opt_l normalize nodelta [| #lbls cases(memb ???) normalize nodelta
213                [ cases (?==?) normalize nodelta ]
214             ]]
215          | cases(call_post_clean ?????) normalize nodelta
216             [| #x cases(? ∧ ?) normalize nodelta ]
217          ]
218          whd in ⊢ (??%% → ?); #EQ lapply(eq_to_jmeq ??? EQ) -EQ #EQ destruct
219   ]
220   #exp' #ltrue' #i_true' #lfalse' #i_false' #_ #_ #EQcode_s1' whd in ⊢ (??%% → ?);
221   cases(call_post_clean …) normalize nodelta [ #EQ destruct] * #a_top1 #i_false''
222   cases(call_post_clean …) [ whd in ⊢ (??%% → ?); #EQ destruct] * #a_top2 #i_true'' >m_return_bind
223   cases(?∧?) normalize nodelta whd in ⊢ (??%% → ?); #EQ lapply(eq_to_jmeq ??? EQ) -EQ #EQ destruct
224   #_ #_ #EQ destruct % // * #f * #lab #EQ destruct
225| #s1 #s2 #lin #io #lout #instr #men #EQcode  #EQeval #EQcodes2 #EQcont_s2 #EQ destruct #Hio * whd in match state_rel;
226  normalize nodelta cases(check_continuations ?????) normalize nodelta [ #_ *] **
227  #H1 #a_top #a_tail normalize nodelta #_ **** #HH1 >EQcode inversion(code ? s1')
228  [1,2,3,4,5,6:
229    [ | #ret | #seq #opt_l #instr #_ | #cond #ltrue #i_true #lfalse #i_false #instr #_ #_ #_|
230        #cond #ltrue #itrue #lfalse #ifalse #_ #_ | #f #pars #opt_l #instr #_ ]
231          #_ whd in ⊢ (??%% → ?);
232          [ |
233          | cases(call_post_clean ?????); normalize nodelta [2: #x cases opt_l normalize nodelta [| #label cases(?==?) normalize nodelta]]
234          | cases(call_post_clean ?????); normalize nodelta
235            [2: #x whd in ⊢ (??%? → ?); cases(call_post_clean ?????) normalize nodelta
236               [|#y whd in ⊢ (??%? → ?); cases(call_post_clean ?????) normalize nodelta
237                 [| #z cases(?∧?) normalize nodelta
238                 ]
239               ]
240            ]
241          | cases(call_post_clean ?????) normalize nodelta
242            [| #x whd in ⊢ (??%? → ?); cases(call_post_clean ?????) normalize nodelta
243               [| #y cases(?∧?) normalize nodelta
244               ]
245            ]
246          | cases(call_post_clean ?????) normalize nodelta
247             [| #x cases opt_l normalize nodelta [| #lbls cases(memb ???) normalize nodelta
248                [ cases (?==?) normalize nodelta ]
249             ]]
250          ]
251          whd in ⊢ (??%% → ?); #EQ lapply(eq_to_jmeq ??? EQ) -EQ #EQ destruct
252  | #lin' #io' #lout' #i' #_ #EQcode_s1' whd in ⊢ (??%% → ?); cases(call_post_clean ?????) normalize nodelta
253    [ #EQ destruct] #x
254    cases(get_element ???) normalize nodelta [#EQ destruct] #LAB #ll normalize nodelta cases(?∧?) normalize nodelta
255    [2:  #EQ destruct] whd in ⊢ (??%% → ?); #EQ lapply(eq_to_jmeq ??? EQ) -EQ #EQ destruct #_ #_ #_ % // * #f * #c #EQ destruct
256 ]
257| #s1 #s2 #f #act_p #lbl #instr #men #env_it #EQcode #EQenv_it  #EQeval #EQ destruct #EQcodes2 #EQ destruct #_ #_ *
258  whd in match state_rel; normalize nodelta cases(check_continuations ?????) normalize nodelta [ #_ *] **
259  #H1 #a_top #a_tail normalize nodelta #Hcall **** #HH1 >EQcode inversion(code ? s1')
260  [1,2,3,4,5,7:
261    [ | #ret | #seq #opt_l #instr #_ | #cond #ltrue #i_true #lfalse #i_false #instr #_ #_ #_|
262        #cond #ltrue #itrue #lfalse #ifalse #_ #_ | #lin #io #lout #instr #_  ]
263          #_ whd in ⊢ (??%% → ?);
264          [ |
265          | cases(call_post_clean ?????); normalize nodelta [2: #x cases opt_l normalize nodelta [| #label cases(?==?) normalize nodelta]]
266          | cases(call_post_clean ?????); normalize nodelta
267            [2: #x whd in ⊢ (??%? → ?); cases(call_post_clean ?????) normalize nodelta
268               [|#y whd in ⊢ (??%? → ?); cases(call_post_clean ?????) normalize nodelta
269                 [| #z cases(?∧?) normalize nodelta
270                 ]
271               ]
272            ]
273          | cases(call_post_clean ?????) normalize nodelta
274            [| #x whd in ⊢ (??%? → ?); cases(call_post_clean ?????) normalize nodelta
275               [| #y cases(?∧?) normalize nodelta
276               ]
277            ]
278         | cases(call_post_clean ?????) normalize nodelta
279             [| #x cases(? ∧ ?) normalize nodelta ]
280         ]
281         whd in ⊢ (??%% → ?); #EQ lapply(eq_to_jmeq ??? EQ) -EQ #EQ destruct
282  |*: #f' #act_p' #lbl' #instr' #_ #EQcode_s1' whd in ⊢ (??%% → ?); cases(call_post_clean ?????) normalize nodelta
283    [ #EQ destruct] #x cases lbl' in EQcode_s1'; normalize nodelta [ #_ #EQ destruct] #lbl'' #EQcode_s1'
284    inversion(?∈?) normalize nodelta
285    [#_ cases(get_element ???) normalize nodelta [#EQ destruct] #LAB #ll normalize nodelta
286      cases(?==?) normalize nodelta
287    [2:  #EQ destruct] whd in ⊢ (??%% → ?); #EQ1 lapply(eq_to_jmeq ??? EQ1) -EQ1 #EQ1 destruct #_#_ #EQ1 destruct % //
288    #_ whd in match (is_call_post_label ???); >EQcode_s1' %
289    ]
290    #ABS whd in ⊢ (??%% → ?);  #EQ1 lapply(eq_to_jmeq ??? EQ1) -EQ1 #EQ1 destruct lapply(Hcall ?) [ %{f} %{(f_lab … env_it)} %]
291    whd in ⊢ (% → ?); whd in match (is_call_post_label ???); normalize nodelta >EQcode *
292 ]
293| #s1 #s2 #r_t #mem #stack * [|#lbl] #i #EQcode #EQcont #EQ destruct #_ #_ #EQeval #EQ1 #EQ2 destruct * #_
294  whd in match state_rel; normalize nodelta inversion(check_continuations ?????) normalize nodelta [ #_ *]
295  ** #H1 #a_top #a_tail #EQcheck normalize nodelta **** #HH1 >EQcode inversion(code … s1')
296  [1,3,4,5,6,7:
297       [ | #seq #opt_l #instr #_ | #cond #ltrue #i_true #lfalse #i_false #instr #_ #_ #_|
298        #cond #ltrue #itrue #lfalse #ifalse #_ #_ | #f #pars #opt_l #instr #_ | #lin #io #lout #instr #_  ]
299          #_ whd in ⊢ (??%% → ?);
300          [
301          | cases(call_post_clean ?????); normalize nodelta [2: #x cases opt_l normalize nodelta [| #label cases(?==?) normalize nodelta]]
302          | cases(call_post_clean ?????); normalize nodelta
303            [2: #x whd in ⊢ (??%? → ?); cases(call_post_clean ?????) normalize nodelta
304               [|#y whd in ⊢ (??%? → ?); cases(call_post_clean ?????) normalize nodelta
305                 [| #z cases(?∧?) normalize nodelta
306                 ]
307               ]
308            ]
309          | cases(call_post_clean ?????) normalize nodelta
310            [| #x whd in ⊢ (??%? → ?); cases(call_post_clean ?????) normalize nodelta
311               [| #y cases(?∧?) normalize nodelta
312               ]
313            ]
314         | cases(call_post_clean ?????) normalize nodelta
315             [| #x cases opt_l normalize nodelta [| #lbls cases(memb ???) normalize nodelta
316                [ cases (?==?) normalize nodelta ]
317             ]]
318         | cases(call_post_clean ?????) normalize nodelta
319             [| #x cases(? ∧ ?) normalize nodelta ]
320         ]
321         whd in ⊢ (??%% → ?); #EQ lapply(eq_to_jmeq ??? EQ) -EQ #EQ destruct
322  | #r_t' #EQcode_s1' whd in ⊢ (??%% → ?); #EQ1 lapply(eq_to_jmeq ??? EQ1) -EQ1 #EQ1 destruct
323    >EQcont in EQcheck; inversion (cont ? s1') [ #_ whd in ⊢ (??%% → ?); #EQ destruct]
324    * #LAB #instrs #stack' #_ #EQcont_s1' whd in match check_continuations; normalize nodelta
325    whd in match (foldr2 ???????); change with (check_continuations ??????) in match (foldr2 ???????);
326    cases(check_continuations ?????) normalize nodelta [#EQ destruct] ** #H2 #a_top1 #a_tail1
327    normalize nodelta   whd in ⊢ (??%? → ?); cases(call_post_clean ?????) normalize nodelta [ #EQ destruct cases HH1]
328    * #ret_top #cleaned cases LAB in EQcont_s1';
329    [ #f #c #_ normalize nodelta #EQ destruct cases HH1
330    | *
331      [ #EQcont_s1' normalize nodelta #EQ destruct cases HH1 * #EQ destruct
332      | #lbl1 #EQcont_s1' whd in match ret_costed_abs; normalize nodelta inversion(? ∈ ?) normalize nodelta
333        [ #EQkeep #EQ destruct cases HH1 ** #EQ destruct #HH2 #EQ destruct #_ #_ #_ #_ % // * #f * #c #EQ destruct
334        | #EQkeep #EQ destruct #_ #_ #_ % // * #f * #c #EQ destruct
335        ]
336      ]
337    | * [|#lbl] #EQcont_s1' normalize nodelta  #EQ destruct cases HH1 *  #EQ destruct cases EQ -EQ #EQ destruct
338    ]
339  ]
340]
341qed.
342
343lemma bool_true : ∀b : bool.b=true → b. * // #EQ destruct qed.
344
345lemma labelled_action_is_correct :
346∀p,p',prog.
347no_duplicates_labels … prog →
348let 〈t_prog,m,keep〉 ≝ trans_prog … prog in
349∀s1,s2,s1' : state p.∀abs_top,abs_tail.
350∀l.is_costlabelled_act p l →
351∀prf :execute_l p p' (env … prog) l s1 s2.
352state_rel … m keep abs_top abs_tail s1 s1' →
353∃abs_top'.∃s2'.
354execute_l p p' (env … t_prog) l s1' s2' ∧
355state_rel  … m keep abs_top' abs_tail s2 s2' ∧
356map_labels_on_trace … m … (actionlabel_to_costlabel p l) =
357actionlabel_to_costlabel p l @ abs_top'.
358#p #p' #prog  #no_dup @pair_elim * #t_prog #m #keep #EQt_prog normalize nodelta
359#s1 #s2 #s1' #abs_top #abs_tail #l #Hl #H lapply Hl -Hl elim H -s1 -s2 -l
360[ #s1 #s2 * #lbl #i #stack #EQcode_s1 #EQcont_s1 #EQ destruct #EQ destruct #EQstore #Hio1 #Hio2
361  #Hlbl #cost_lbl whd in match state_rel in ⊢ (% → ?); normalize nodelta inversion(check_continuations ?????)
362  normalize nodelta [ #_ *] ** #H1 #a_top #a_tail >EQcont_s1 inversion(cont … s1') [ #_ whd in ⊢ (??%% → ?); #EQ destruct]
363  * #lbl' #i' #stack' #_ #EQcont_s1' whd in ⊢ (??%% → ?); change with (check_continuations ??????) in match (foldr2 ???????);
364  inversion(check_continuations ?????) normalize nodelta [ #_ #EQ destruct] ** #H2 #a_top1 #a_tail1 #EQcheck
365  normalize nodelta inversion(call_post_clean ?????) normalize nodelta [#_ whd in ⊢ (??%% → ?); #EQ destruct ***** ]
366  * #gen_labels #cleaned_i' #EQclean cases lbl' in EQcont_s1'; -lbl' normalize nodelta
367  [ #f #c #_ whd in ⊢ (??%% → ?); #EQ destruct *****
368  | * [|#lbl'] normalize nodelta #_ whd in ⊢ (??%% → ?); [2: cases(ret_costed_abs ??) normalize nodelta [|#lbl'']]
369    #EQ destruct ****** [2: *] #EQ destruct @⊥ cases Hlbl #H @H %
370  | * [|#lbl'] #EQcont_s1' normalize nodelta whd in ⊢ (??%% → ?); #EQ destruct ****** [2: *] #EQ destruct
371    cases cost_lbl #HH2 #EQ destruct #EQget #EQ_cleaned #EQstore #EQio #EQ destruct
372    >EQcode_s1 in EQ_cleaned; inversion(code ? s1')
373    [2,3,4,5,6,7: [ #ret | #seq #opt_l #instr #_ | #cond #ltrue #i_true #lfalse #i_false #instr #_ #_ #_|
374            #cond #ltrue #itrue #lfalse #ifalse #_ #_| #f #pars #opt_l #instr #_ | #lin #io #lout #instr #_ ]
375          #_ whd in ⊢ (??%% → ?);
376          [ | cases(call_post_clean ?????); normalize nodelta [2: #x cases opt_l normalize nodelta [| #label cases(?==?) normalize nodelta]]
377          | cases(call_post_clean ?????); normalize nodelta
378            [2: #x whd in ⊢ (??%? → ?); cases(call_post_clean ?????) normalize nodelta
379               [|#y whd in ⊢ (??%? → ?); cases(call_post_clean ?????) normalize nodelta
380                 [| #z cases(?∧?) normalize nodelta
381                 ]
382               ]
383            ]
384          | cases(call_post_clean ?????) normalize nodelta
385            [| #x whd in ⊢ (??%? → ?); cases(call_post_clean ?????) normalize nodelta
386               [| #y cases(?∧?) normalize nodelta
387               ]
388            ]
389          | cases(call_post_clean ?????) normalize nodelta
390             [| #x cases opt_l normalize nodelta [| #lbls cases(memb ???) normalize nodelta
391                [ cases (?==?) normalize nodelta ]
392             ]]
393          | cases(call_post_clean ?????) normalize nodelta
394             [| #x cases(? ∧ ?) normalize nodelta ]
395          ]
396          whd in ⊢ (??%% → ?); #EQ lapply(eq_to_jmeq ??? EQ) -EQ #EQ destruct] #EQcode_s1' whd in ⊢ (??%% → ?); #EQ destruct
397    %{gen_labels} %{(mk_state … i' stack' (store … s1') false)} %
398    [% [ @(empty … EQcode_s1' EQcont_s1') // #_ %{lbl'} %]
399       whd >EQcheck in ⊢ (match % with [_ ⇒ ? | _ ⇒ ?]); normalize nodelta % // % // % // % // >EQclean %]
400   whd in match actionlabel_to_costlabel; normalize nodelta whd in ⊢ (??%%); >EQget >append_nil %
401 ]
402| #s1 #s2 #seq #i #store * [|#lbl] #EQcode_s1 #EQeval #EQ destruct #EQcont #EQ destruct #Hio1 #Hio2 *
403  whd in match state_rel in ⊢ (% → ?); normalize nodelta inversion(check_continuations ?????) normalize nodelta
404  [#_ *] ** #H1 #a_top #a_tail #EQcheck normalize nodelta **** #HH1 >EQcode_s1 inversion(code ? s1')
405  [1,2,4,5,6,7: [ | #ret | #cond #ltrue #i_true #lfalse #i_false #instr #_ #_ #_|
406            #cond #ltrue #itrue #lfalse #ifalse #_ #_| #f #pars #opt_l #instr #_ | #lin #io #lout #instr #_ ]
407          #_ whd in ⊢ (??%% → ?);
408          [ |
409          | cases(call_post_clean ?????); normalize nodelta
410            [2: #x whd in ⊢ (??%? → ?); cases(call_post_clean ?????) normalize nodelta
411               [|#y whd in ⊢ (??%? → ?); cases(call_post_clean ?????) normalize nodelta
412                 [| #z cases(?∧?) normalize nodelta
413                 ]
414               ]
415            ]
416          | cases(call_post_clean ?????) normalize nodelta
417            [| #x whd in ⊢ (??%? → ?); cases(call_post_clean ?????) normalize nodelta
418               [| #y cases(?∧?) normalize nodelta
419               ]
420            ]
421          | cases(call_post_clean ?????) normalize nodelta
422             [| #x cases opt_l normalize nodelta [| #lbls cases(memb ???) normalize nodelta
423                [ cases (?==?) normalize nodelta ]
424             ]]
425          | cases(call_post_clean ?????) normalize nodelta
426             [| #x cases(? ∧ ?) normalize nodelta ]
427          ]
428          whd in ⊢ (??%% → ?); #EQ lapply(eq_to_jmeq ??? EQ) -EQ #EQ destruct] #seq' #opt_l' #i' #_ #EQcode_s1' whd in ⊢ (??%% → ?);
429  inversion(call_post_clean ?????) normalize nodelta [ #_ #EQ destruct] * #genlab #cleaned #EQcleaned
430  cases opt_l' in EQcode_s1'; normalize nodelta [|#lbl'] #EQcode_s1' [| inversion(?==?) normalize nodelta #EQget]
431  whd in ⊢ (??%% → ?); #EQ lapply(eq_to_jmeq ??? EQ) -EQ #EQ destruct #EQst #EQioinfo #EQ destruct
432  %{genlab} %{(mk_state … i' (cont … s1') (store … s2) false)} % [ %
433  [ @(seq_sil … EQcode_s1') // ]
434  whd <EQcont >EQcheck normalize nodelta % // % // % // % // >EQcleaned %]
435  whd in match actionlabel_to_costlabel; normalize nodelta whd in ⊢ (??%%); >(\P EQget) >append_nil %
436| cases daemon
437| cases daemon
438| cases daemon
439| cases daemon
440| #s1 #s2 #lin #io #lout #i #store #EQcode_s1 #EQeval #EQcode_s2 #EQcont_s2. #EQ destruct #EQio_s2 *
441  whd in match state_rel in ⊢ (% → ?); normalize nodelta inversion(check_continuations ?????) normalize nodelta [#_ *]
442  ** #H1 #a_top #a_tail #EQcheck normalize nodelta **** #HH1 >EQcode_s1 inversion(code ? s1')
443  [1,2,3,4,5,6:  [ | #ret | #seq #opt_l #instr #_ | #cond #ltrue #i_true #lfalse #i_false #instr #_ #_ #_|
444        #cond #ltrue #itrue #lfalse #ifalse #_ #_ | #f #pars #opt_l #instr #_ ]
445          #_ whd in ⊢ (??%% → ?);
446          [ |
447          | cases(call_post_clean ?????); normalize nodelta [2: #x cases opt_l normalize nodelta [| #label cases(?==?) normalize nodelta]]
448          | cases(call_post_clean ?????); normalize nodelta
449            [2: #x whd in ⊢ (??%? → ?); cases(call_post_clean ?????) normalize nodelta
450               [|#y whd in ⊢ (??%? → ?); cases(call_post_clean ?????) normalize nodelta
451                 [| #z cases(?∧?) normalize nodelta
452                 ]
453               ]
454            ]
455          | cases(call_post_clean ?????) normalize nodelta
456            [| #x whd in ⊢ (??%? → ?); cases(call_post_clean ?????) normalize nodelta
457               [| #y cases(?∧?) normalize nodelta
458               ]
459            ]
460          | cases(call_post_clean ?????) normalize nodelta
461             [| #x cases opt_l normalize nodelta [| #lbls cases(memb ???) normalize nodelta
462                [ cases (?==?) normalize nodelta ]
463             ]]
464          ]
465          whd in ⊢ (??%% → ?); #EQ lapply(eq_to_jmeq ??? EQ) -EQ #EQ destruct ]
466  #lin' #io' #lout' #i' #_ #EQcode_s1' whd in ⊢ (??%% → ?); inversion(call_post_clean ?????) normalize nodelta [ #_ #EQ destruct]
467  * #genlab #cleaned #EQcleaned inversion(?∧?) normalize nodelta #EQget whd in ⊢ (??%% → ?); #EQ lapply(eq_to_jmeq ??? EQ) -EQ
468  #EQ destruct #EQstore_s1_s1' #EQioinfo #EQ destruct %{[]}
469  %{(mk_state … (EMPTY …) (〈cost_act p (Some ? lout),i'〉::(cont … s1')) (store … s2) true)} % [%
470  [ @(io_in … EQcode_s1') // ]
471  whd >EQcont_s2 whd in match (check_continuations ??????); change with (check_continuations ??????) in match (foldr2 ???????);
472  >EQcheck normalize nodelta >EQcleaned normalize nodelta % // % // % // % [2: >EQcode_s2 %] %
473  [2: cases(andb_Prop_true … (bool_true … EQget)) #H #_ >(\P (bool_true … H)) % ] % // % //]
474  cases(andb_Prop_true … (bool_true … EQget)) #_ #EQget'
475  whd in match actionlabel_to_costlabel; normalize nodelta whd in ⊢ (??%%); >append_nil >append_nil inversion(? == ?) in EQget';
476  [2: #_ *] #EQget' #_ >(\P EQget') %
477|*: cases daemon
478]
479qed.
480
481include "Vm.ma".
482
483theorem correctness_theorem : ∀p,p',prog.
484no_duplicates_labels … prog →
485let 〈t_prog,m,keep〉 ≝ trans_prog … prog in
486∀si,s1,s2,sn,si' : state p.∀abs_top,abs_tail.
487∀t : raw_trace p (operational_semantics … p' prog) si sn.
488measurable p (operational_semantics p p' prog) … s1 s2 … t →
489state_rel … m keep abs_top abs_tail si si' →
490∃abs_top',abs_tail'.∃sn'.∃t' : raw_trace p (operational_semantics … p' t_prog) si' sn'.
491state_rel  … m keep abs_top' abs_tail' sn sn' ∧
492is_permutation ? (map_labels_on_trace … m (chop … (get_costlabels_of_trace … t))) 
493                  (chop … (get_costlabels_of_trace … t')) ∧
494                  ∃s1',s2'.
495measurable p (operational_semantics … p' t_prog)  … s1' s2' … t'.
496#p #p' #prog #no_dup @pair_elim * #t_prog #m #keep #EQt_prog normalize nodelta
497#si #s1 #s3 #sn #si' #abs_top #abs_tail #t *  #s0 * #s2 * #ti0 * #t12 * #t3n * #l1 * #l2
498* #prf1 * #prf2 ******* #pre_t12 #EQ destruct #Hl1 #Hl2 #Hcall_fin #sil_ti0 #sil_t3n #Hcall_init #Rsi_si'
499lapply(silent_in_silent … p' prog no_dup) >EQt_prog normalize nodelta #Hsilent
500cases(Hsilent … sil_ti0 … Rsi_si')
501#abs_top1 * #s0' * #t_i0' * #Rs0_s0' #sil_ti0'
502lapply(labelled_action_is_correct … p' prog no_dup) >EQt_prog normalize nodelta #Hmove
503cases(Hmove … prf1 … Rs0_s0') //
504#abs_top2 * #s1' ** #prf1' #Rs1_s1' #EQmap_l1
505lapply(correctness_lemma … p' prog no_dup) >EQt_prog normalize nodelta #H
506cases(H … pre_t12 … Rs1_s1') -H
507#abs_top3 * #s2' * #t12' ***** #Rs2_s2' #Hperm #_ #_ #pre_t12' #_
508cases(Hmove … prf2 … Rs2_s2') -Hmove //
509#abs_top4 * #s3' ** #prf2' #Rs3_s3' #EQmap_l2
510cases(Hsilent … sil_t3n … Rs3_s3')
511#abs_top5 * #sn' * #t3n' * #Rsn_sn' #sil_t3n'
512%{abs_top5} %{abs_tail} %{sn'}
513%{(t_i0' @ (t_ind … prf1' (t12' @ (t_ind … prf2' t3n'))))} %
514[ %{Rsn_sn'} >get_cost_label_append >get_cost_label_append >(get_cost_label_silent_is_empty … sil_ti0)
515  >(get_cost_label_silent_is_empty … sil_ti0') >(get_cost_label_append … (t_ind … (t_base …)))
516  >(get_cost_label_append … (t_ind … (t_base …))) in ⊢ (???%); >get_cost_label_append
517  >get_cost_label_append whd in match (get_costlabels_of_trace … (t_ind … t3n));
518  whd in match (get_costlabels_of_trace … (t_ind … t3n'));
519  >(get_cost_label_silent_is_empty … sil_t3n) >(get_cost_label_silent_is_empty … sil_t3n')
520  >append_nil cases(actionlabel_ok … Hl2) #c2 #EQc2 >EQc2 <associative_append <associative_append
521  <associative_append >chop_append_singleton <associative_append <associative_append >chop_append_singleton
522  >append_nil whd in match (get_costlabels_of_trace ???? (t_ind ? (operational_semantics p p' t_prog) … prf1' (t_base …)));
523  >append_nil >map_labels_on_trace_append >EQmap_l1 >associative_append @is_permutation_append_left_cancellable
524  lapply(top_move_source_is_empty … p' prog) >EQt_prog normalize nodelta #H
525  >(proj1 … (H … prf2 Hl2 … Rs2_s2')) in Hperm; [2: assumption] >append_nil @permute_equal_right
526| %{s1'} %{s3'} whd %{s0'} %{s2'} %{t_i0'} %{t12'} %{t3n'} %{l1} %{l2} %{prf1'} %{prf2'}
527  % [2: lapply(top_move_source_is_empty … p' prog) >EQt_prog normalize nodelta #H
528  @(proj2 … (H … prf1 Hl1 … Rs0_s0')) assumption ] % // % // %
529  [2: lapply(top_move_source_is_empty … p' prog) >EQt_prog normalize nodelta #H
530  @(proj2 … (H … prf2 Hl2 … Rs2_s2')) assumption ] % // % // % //
531]
532qed.
Note: See TracBrowser for help on using the repository browser.