annotate src/Hoare.agda @ 1:73127e0ab57c

(none)
author soto@cr.ie.u-ryukyu.ac.jp
date Tue, 08 Sep 2020 18:38:08 +0900
parents
children
Ignore whitespace changes - Everywhere: Within whitespace: At end of lines:
rev   line source
1
soto@cr.ie.u-ryukyu.ac.jp
parents:
diff changeset
1 module Hoare
soto@cr.ie.u-ryukyu.ac.jp
parents:
diff changeset
2 (PrimComm : Set)
soto@cr.ie.u-ryukyu.ac.jp
parents:
diff changeset
3 (Cond : Set)
soto@cr.ie.u-ryukyu.ac.jp
parents:
diff changeset
4 (Axiom : Cond -> PrimComm -> Cond -> Set)
soto@cr.ie.u-ryukyu.ac.jp
parents:
diff changeset
5 (Tautology : Cond -> Cond -> Set)
soto@cr.ie.u-ryukyu.ac.jp
parents:
diff changeset
6 (_and_ : Cond -> Cond -> Cond)
soto@cr.ie.u-ryukyu.ac.jp
parents:
diff changeset
7 (neg : Cond -> Cond )
soto@cr.ie.u-ryukyu.ac.jp
parents:
diff changeset
8 where
soto@cr.ie.u-ryukyu.ac.jp
parents:
diff changeset
9
soto@cr.ie.u-ryukyu.ac.jp
parents:
diff changeset
10 data Comm : Set where
soto@cr.ie.u-ryukyu.ac.jp
parents:
diff changeset
11 Skip : Comm
soto@cr.ie.u-ryukyu.ac.jp
parents:
diff changeset
12 Abort : Comm
soto@cr.ie.u-ryukyu.ac.jp
parents:
diff changeset
13 PComm : PrimComm -> Comm
soto@cr.ie.u-ryukyu.ac.jp
parents:
diff changeset
14 Seq : Comm -> Comm -> Comm
soto@cr.ie.u-ryukyu.ac.jp
parents:
diff changeset
15 If : Cond -> Comm -> Comm -> Comm
soto@cr.ie.u-ryukyu.ac.jp
parents:
diff changeset
16 While : Cond -> Comm -> Comm
soto@cr.ie.u-ryukyu.ac.jp
parents:
diff changeset
17
soto@cr.ie.u-ryukyu.ac.jp
parents:
diff changeset
18 -- Hoare Triple
soto@cr.ie.u-ryukyu.ac.jp
parents:
diff changeset
19 data HT : Set where
soto@cr.ie.u-ryukyu.ac.jp
parents:
diff changeset
20 ht : Cond -> Comm -> Cond -> HT
soto@cr.ie.u-ryukyu.ac.jp
parents:
diff changeset
21
soto@cr.ie.u-ryukyu.ac.jp
parents:
diff changeset
22 {-
soto@cr.ie.u-ryukyu.ac.jp
parents:
diff changeset
23 prPre pr prPost
soto@cr.ie.u-ryukyu.ac.jp
parents:
diff changeset
24 ------------- ------------------ ----------------
soto@cr.ie.u-ryukyu.ac.jp
parents:
diff changeset
25 bPre => bPre' {bPre'} c {bPost'} bPost' => bPost
soto@cr.ie.u-ryukyu.ac.jp
parents:
diff changeset
26 Weakening : ----------------------------------------------------
soto@cr.ie.u-ryukyu.ac.jp
parents:
diff changeset
27 {bPre} c {bPost}
soto@cr.ie.u-ryukyu.ac.jp
parents:
diff changeset
28
soto@cr.ie.u-ryukyu.ac.jp
parents:
diff changeset
29 Assign: ----------------------------
soto@cr.ie.u-ryukyu.ac.jp
parents:
diff changeset
30 {bPost[v<-e]} v:=e {bPost}
soto@cr.ie.u-ryukyu.ac.jp
parents:
diff changeset
31
soto@cr.ie.u-ryukyu.ac.jp
parents:
diff changeset
32 pr1 pr2
soto@cr.ie.u-ryukyu.ac.jp
parents:
diff changeset
33 ----------------- ------------------
soto@cr.ie.u-ryukyu.ac.jp
parents:
diff changeset
34 {bPre} cm1 {bMid} {bMid} cm2 {bPost}
soto@cr.ie.u-ryukyu.ac.jp
parents:
diff changeset
35 Seq: ---------------------------------------
soto@cr.ie.u-ryukyu.ac.jp
parents:
diff changeset
36 {bPre} cm1 ; cm2 {bPost}
soto@cr.ie.u-ryukyu.ac.jp
parents:
diff changeset
37
soto@cr.ie.u-ryukyu.ac.jp
parents:
diff changeset
38 pr1 pr2
soto@cr.ie.u-ryukyu.ac.jp
parents:
diff changeset
39 ----------------------- ---------------------------
soto@cr.ie.u-ryukyu.ac.jp
parents:
diff changeset
40 {bPre /\ c} cm1 {bPost} {bPre /\ neg c} cm2 {bPost}
soto@cr.ie.u-ryukyu.ac.jp
parents:
diff changeset
41 If: ------------------------------------------------------
soto@cr.ie.u-ryukyu.ac.jp
parents:
diff changeset
42 {bPre} If c then cm1 else cm2 fi {bPost}
soto@cr.ie.u-ryukyu.ac.jp
parents:
diff changeset
43
soto@cr.ie.u-ryukyu.ac.jp
parents:
diff changeset
44 pr
soto@cr.ie.u-ryukyu.ac.jp
parents:
diff changeset
45 -------------------
soto@cr.ie.u-ryukyu.ac.jp
parents:
diff changeset
46 {inv /\ c} cm {inv}
soto@cr.ie.u-ryukyu.ac.jp
parents:
diff changeset
47 While: ---------------------------------------
soto@cr.ie.u-ryukyu.ac.jp
parents:
diff changeset
48 {inv} while c do cm od {inv /\ neg c}
soto@cr.ie.u-ryukyu.ac.jp
parents:
diff changeset
49 -}
soto@cr.ie.u-ryukyu.ac.jp
parents:
diff changeset
50
soto@cr.ie.u-ryukyu.ac.jp
parents:
diff changeset
51
soto@cr.ie.u-ryukyu.ac.jp
parents:
diff changeset
52 data HTProof : Cond -> Comm -> Cond -> Set where
soto@cr.ie.u-ryukyu.ac.jp
parents:
diff changeset
53 PrimRule : {bPre : Cond} -> {pcm : PrimComm} -> {bPost : Cond} ->
soto@cr.ie.u-ryukyu.ac.jp
parents:
diff changeset
54 (pr : Axiom bPre pcm bPost) ->
soto@cr.ie.u-ryukyu.ac.jp
parents:
diff changeset
55 HTProof bPre (PComm pcm) bPost
soto@cr.ie.u-ryukyu.ac.jp
parents:
diff changeset
56 SkipRule : (b : Cond) -> HTProof b Skip b
soto@cr.ie.u-ryukyu.ac.jp
parents:
diff changeset
57 AbortRule : (bPre : Cond) -> (bPost : Cond) ->
soto@cr.ie.u-ryukyu.ac.jp
parents:
diff changeset
58 HTProof bPre Abort bPost
soto@cr.ie.u-ryukyu.ac.jp
parents:
diff changeset
59 WeakeningRule : {bPre : Cond} -> {bPre' : Cond} -> {cm : Comm} ->
soto@cr.ie.u-ryukyu.ac.jp
parents:
diff changeset
60 {bPost' : Cond} -> {bPost : Cond} ->
soto@cr.ie.u-ryukyu.ac.jp
parents:
diff changeset
61 Tautology bPre bPre' ->
soto@cr.ie.u-ryukyu.ac.jp
parents:
diff changeset
62 HTProof bPre' cm bPost' ->
soto@cr.ie.u-ryukyu.ac.jp
parents:
diff changeset
63 Tautology bPost' bPost ->
soto@cr.ie.u-ryukyu.ac.jp
parents:
diff changeset
64 HTProof bPre cm bPost
soto@cr.ie.u-ryukyu.ac.jp
parents:
diff changeset
65 SeqRule : {bPre : Cond} -> {cm1 : Comm} -> {bMid : Cond} ->
soto@cr.ie.u-ryukyu.ac.jp
parents:
diff changeset
66 {cm2 : Comm} -> {bPost : Cond} ->
soto@cr.ie.u-ryukyu.ac.jp
parents:
diff changeset
67 HTProof bPre cm1 bMid ->
soto@cr.ie.u-ryukyu.ac.jp
parents:
diff changeset
68 HTProof bMid cm2 bPost ->
soto@cr.ie.u-ryukyu.ac.jp
parents:
diff changeset
69 HTProof bPre (Seq cm1 cm2) bPost
soto@cr.ie.u-ryukyu.ac.jp
parents:
diff changeset
70 IfRule : {cmThen : Comm} -> {cmElse : Comm} ->
soto@cr.ie.u-ryukyu.ac.jp
parents:
diff changeset
71 {bPre : Cond} -> {bPost : Cond} ->
soto@cr.ie.u-ryukyu.ac.jp
parents:
diff changeset
72 {b : Cond} ->
soto@cr.ie.u-ryukyu.ac.jp
parents:
diff changeset
73 HTProof (bPre and b) cmThen bPost ->
soto@cr.ie.u-ryukyu.ac.jp
parents:
diff changeset
74 HTProof (bPre and neg b) cmElse bPost ->
soto@cr.ie.u-ryukyu.ac.jp
parents:
diff changeset
75 HTProof bPre (If b cmThen cmElse) bPost
soto@cr.ie.u-ryukyu.ac.jp
parents:
diff changeset
76 WhileRule : {cm : Comm} -> {bInv : Cond} -> {b : Cond} ->
soto@cr.ie.u-ryukyu.ac.jp
parents:
diff changeset
77 HTProof (bInv and b) cm bInv ->
soto@cr.ie.u-ryukyu.ac.jp
parents:
diff changeset
78 HTProof bInv (While b cm) (bInv and neg b)
soto@cr.ie.u-ryukyu.ac.jp
parents:
diff changeset
79