Mercurial > hg > Members > ryokka > HoareLogic
annotate whileTestGears.agda @ 31:600b4e914071
fix loop
author | Shinji KONO <kono@ie.u-ryukyu.ac.jp> |
---|---|
date | Tue, 10 Dec 2019 09:19:14 +0900 |
parents | dd66b94bf365 |
children | bf7c7bd69e35 |
rev | line source |
---|---|
4 | 1 module whileTestGears where |
2 | |
3 open import Function | |
4 open import Data.Nat | |
27 | 5 open import Data.Bool hiding ( _≟_ ; _≤?_ ; _≤_) |
4 | 6 open import Level renaming ( suc to succ ; zero to Zero ) |
7 open import Relation.Nullary using (¬_; Dec; yes; no) | |
8 open import Relation.Binary.PropositionalEquality | |
9 | |
10 | 10 open import utilities |
11 open _/\_ | |
4 | 12 |
6 | 13 record Env : Set where |
14 field | |
15 varn : ℕ | |
16 vari : ℕ | |
17 open Env | |
18 | |
14 | 19 whileTest : {l : Level} {t : Set l} -> (c10 : ℕ) → (Code : Env -> t) -> t |
20 whileTest c10 next = next (record {varn = c10 ; vari = 0} ) | |
4 | 21 |
22 {-# TERMINATING #-} | |
23 whileLoop : {l : Level} {t : Set l} -> Env -> (Code : Env -> t) -> t | |
24 whileLoop env next with lt 0 (varn env) | |
25 whileLoop env next | false = next env | |
26 whileLoop env next | true = | |
27 whileLoop (record {varn = (varn env) - 1 ; vari = (vari env) + 1}) next | |
28 | |
29 test1 : Env | |
14 | 30 test1 = whileTest 10 (λ env → whileLoop env (λ env1 → env1 )) |
4 | 31 |
32 | |
14 | 33 proof1 : whileTest 10 (λ env → whileLoop env (λ e → (vari e) ≡ 10 )) |
4 | 34 proof1 = refl |
35 | |
16 | 36 -- ↓PostCondition |
14 | 37 whileTest' : {l : Level} {t : Set l} -> {c10 : ℕ } → (Code : (env : Env) -> ((vari env) ≡ 0) /\ ((varn env) ≡ c10) -> t) -> t |
38 whileTest' {_} {_} {c10} next = next env proof2 | |
4 | 39 where |
40 env : Env | |
14 | 41 env = record {vari = 0 ; varn = c10} |
16 | 42 proof2 : ((vari env) ≡ 0) /\ ((varn env) ≡ c10) -- PostCondition |
4 | 43 proof2 = record {pi1 = refl ; pi2 = refl} |
11 | 44 |
45 open import Data.Empty | |
46 open import Data.Nat.Properties | |
47 | |
48 | |
16 | 49 {-# TERMINATING #-} -- ↓PreCondition(Invaliant) |
14 | 50 whileLoop' : {l : Level} {t : Set l} -> (env : Env) -> {c10 : ℕ } → ((varn env) + (vari env) ≡ c10) -> (Code : Env -> t) -> t |
9 | 51 whileLoop' env proof next with ( suc zero ≤? (varn env) ) |
52 whileLoop' env proof next | no p = next env | |
14 | 53 whileLoop' env {c10} proof next | yes p = whileLoop' env1 (proof3 p ) next |
4 | 54 where |
55 env1 = record {varn = (varn env) - 1 ; vari = (vari env) + 1} | |
11 | 56 1<0 : 1 ≤ zero → ⊥ |
57 1<0 () | |
14 | 58 proof3 : (suc zero ≤ (varn env)) → varn env1 + vari env1 ≡ c10 |
9 | 59 proof3 (s≤s lt) with varn env |
11 | 60 proof3 (s≤s z≤n) | zero = ⊥-elim (1<0 p) |
61 proof3 (s≤s (z≤n {n'}) ) | suc n = let open ≡-Reasoning in | |
62 begin | |
63 n' + (vari env + 1) | |
64 ≡⟨ cong ( λ z → n' + z ) ( +-sym {vari env} {1} ) ⟩ | |
65 n' + (1 + vari env ) | |
66 ≡⟨ sym ( +-assoc (n') 1 (vari env) ) ⟩ | |
13 | 67 (n' + 1) + vari env |
11 | 68 ≡⟨ cong ( λ z → z + vari env ) +1≡suc ⟩ |
69 (suc n' ) + vari env | |
70 ≡⟨⟩ | |
71 varn env + vari env | |
72 ≡⟨ proof ⟩ | |
14 | 73 c10 |
11 | 74 ∎ |
6 | 75 |
16 | 76 -- Condition to Invaliant |
14 | 77 conversion1 : {l : Level} {t : Set l } → (env : Env) -> {c10 : ℕ } → ((vari env) ≡ 0) /\ ((varn env) ≡ c10) |
78 -> (Code : (env1 : Env) -> (varn env1 + vari env1 ≡ c10) -> t) -> t | |
79 conversion1 env {c10} p1 next = next env proof4 | |
6 | 80 where |
14 | 81 proof4 : varn env + vari env ≡ c10 |
6 | 82 proof4 = let open ≡-Reasoning in |
83 begin | |
84 varn env + vari env | |
85 ≡⟨ cong ( λ n → n + vari env ) (pi2 p1 ) ⟩ | |
14 | 86 c10 + vari env |
87 ≡⟨ cong ( λ n → c10 + n ) (pi1 p1 ) ⟩ | |
88 c10 + 0 | |
89 ≡⟨ +-sym {c10} {0} ⟩ | |
90 c10 | |
6 | 91 ∎ |
4 | 92 |
6 | 93 |
14 | 94 proofGears : {c10 : ℕ } → Set |
95 proofGears {c10} = whileTest' {_} {_} {c10} (λ n p1 → conversion1 n p1 (λ n1 p2 → whileLoop' n1 p2 (λ n2 → ( vari n2 ≡ c10 )))) | |
9 | 96 |
30
dd66b94bf365
loop causes agda inifinite loop
Shinji KONO <kono@ie.u-ryukyu.ac.jp>
parents:
29
diff
changeset
|
97 -- proofGearsMeta : {c10 : ℕ } → whileTest' {_} {_} {c10} (λ n p1 → conversion1 n p1 (λ n1 p2 → whileLoop' n1 p2 (λ n2 → ( vari n2 ≡ c10 )))) |
dd66b94bf365
loop causes agda inifinite loop
Shinji KONO <kono@ie.u-ryukyu.ac.jp>
parents:
29
diff
changeset
|
98 -- proofGearsMeta {c10} = {!!} |
dd66b94bf365
loop causes agda inifinite loop
Shinji KONO <kono@ie.u-ryukyu.ac.jp>
parents:
29
diff
changeset
|
99 |
dd66b94bf365
loop causes agda inifinite loop
Shinji KONO <kono@ie.u-ryukyu.ac.jp>
parents:
29
diff
changeset
|
100 data whileTestState (c10 : ℕ ) : Set where |
dd66b94bf365
loop causes agda inifinite loop
Shinji KONO <kono@ie.u-ryukyu.ac.jp>
parents:
29
diff
changeset
|
101 error : whileTestState c10 |
dd66b94bf365
loop causes agda inifinite loop
Shinji KONO <kono@ie.u-ryukyu.ac.jp>
parents:
29
diff
changeset
|
102 state1 : (env : Env) → ((vari env) ≡ 0) /\ ((varn env) ≡ c10) → whileTestState c10 |
dd66b94bf365
loop causes agda inifinite loop
Shinji KONO <kono@ie.u-ryukyu.ac.jp>
parents:
29
diff
changeset
|
103 state2 : (env : Env) → (varn env + vari env ≡ c10) → whileTestState c10 |
dd66b94bf365
loop causes agda inifinite loop
Shinji KONO <kono@ie.u-ryukyu.ac.jp>
parents:
29
diff
changeset
|
104 finstate : (env : Env) → ((vari env) ≡ c10 ) → whileTestState c10 |
dd66b94bf365
loop causes agda inifinite loop
Shinji KONO <kono@ie.u-ryukyu.ac.jp>
parents:
29
diff
changeset
|
105 |
dd66b94bf365
loop causes agda inifinite loop
Shinji KONO <kono@ie.u-ryukyu.ac.jp>
parents:
29
diff
changeset
|
106 whileLoopProof0 : {c10 : ℕ } → Set |
dd66b94bf365
loop causes agda inifinite loop
Shinji KONO <kono@ie.u-ryukyu.ac.jp>
parents:
29
diff
changeset
|
107 whileLoopProof0 {c10 } = Env /\ whileTestState c10 → whileLoop {!!} ( λ env → vari env ≡ c10 ) |
dd66b94bf365
loop causes agda inifinite loop
Shinji KONO <kono@ie.u-ryukyu.ac.jp>
parents:
29
diff
changeset
|
108 whileTestProof0 : {c10 : ℕ } → Set |
dd66b94bf365
loop causes agda inifinite loop
Shinji KONO <kono@ie.u-ryukyu.ac.jp>
parents:
29
diff
changeset
|
109 whileTestProof0 {c10} = Env /\ whileTestState c10 → whileTest c10 (λ env → {!!} ) |
dd66b94bf365
loop causes agda inifinite loop
Shinji KONO <kono@ie.u-ryukyu.ac.jp>
parents:
29
diff
changeset
|
110 |
dd66b94bf365
loop causes agda inifinite loop
Shinji KONO <kono@ie.u-ryukyu.ac.jp>
parents:
29
diff
changeset
|
111 proofGearsState : {c10 : ℕ } → whileTestProof0 |
dd66b94bf365
loop causes agda inifinite loop
Shinji KONO <kono@ie.u-ryukyu.ac.jp>
parents:
29
diff
changeset
|
112 proofGearsState {c10} = {!!} where |
dd66b94bf365
loop causes agda inifinite loop
Shinji KONO <kono@ie.u-ryukyu.ac.jp>
parents:
29
diff
changeset
|
113 lemma1 : (env : Env ) → vari env ≡ c10 |
dd66b94bf365
loop causes agda inifinite loop
Shinji KONO <kono@ie.u-ryukyu.ac.jp>
parents:
29
diff
changeset
|
114 lemma1 = {!!} |
27 | 115 |
30
dd66b94bf365
loop causes agda inifinite loop
Shinji KONO <kono@ie.u-ryukyu.ac.jp>
parents:
29
diff
changeset
|
116 record Context : Set where |
dd66b94bf365
loop causes agda inifinite loop
Shinji KONO <kono@ie.u-ryukyu.ac.jp>
parents:
29
diff
changeset
|
117 field |
dd66b94bf365
loop causes agda inifinite loop
Shinji KONO <kono@ie.u-ryukyu.ac.jp>
parents:
29
diff
changeset
|
118 c10 : ℕ |
dd66b94bf365
loop causes agda inifinite loop
Shinji KONO <kono@ie.u-ryukyu.ac.jp>
parents:
29
diff
changeset
|
119 whileDG : Env |
dd66b94bf365
loop causes agda inifinite loop
Shinji KONO <kono@ie.u-ryukyu.ac.jp>
parents:
29
diff
changeset
|
120 whileCond : whileTestState c10 |
dd66b94bf365
loop causes agda inifinite loop
Shinji KONO <kono@ie.u-ryukyu.ac.jp>
parents:
29
diff
changeset
|
121 |
dd66b94bf365
loop causes agda inifinite loop
Shinji KONO <kono@ie.u-ryukyu.ac.jp>
parents:
29
diff
changeset
|
122 open Context |
dd66b94bf365
loop causes agda inifinite loop
Shinji KONO <kono@ie.u-ryukyu.ac.jp>
parents:
29
diff
changeset
|
123 |
dd66b94bf365
loop causes agda inifinite loop
Shinji KONO <kono@ie.u-ryukyu.ac.jp>
parents:
29
diff
changeset
|
124 whileTestContext : {l : Level} {t : Set l} -> Context → (Code : Context -> t) -> t |
dd66b94bf365
loop causes agda inifinite loop
Shinji KONO <kono@ie.u-ryukyu.ac.jp>
parents:
29
diff
changeset
|
125 whileTestContext cxt next = next (record cxt { whileDG = record (whileDG cxt) {varn = c10 cxt ; vari = 0}} ) |
dd66b94bf365
loop causes agda inifinite loop
Shinji KONO <kono@ie.u-ryukyu.ac.jp>
parents:
29
diff
changeset
|
126 |
dd66b94bf365
loop causes agda inifinite loop
Shinji KONO <kono@ie.u-ryukyu.ac.jp>
parents:
29
diff
changeset
|
127 {-# TERMINATING #-} |
dd66b94bf365
loop causes agda inifinite loop
Shinji KONO <kono@ie.u-ryukyu.ac.jp>
parents:
29
diff
changeset
|
128 whileLoopContext : {l : Level} {t : Set l} -> Context -> (Code : Context -> t) -> t |
dd66b94bf365
loop causes agda inifinite loop
Shinji KONO <kono@ie.u-ryukyu.ac.jp>
parents:
29
diff
changeset
|
129 whileLoopContext cxt next with lt 0 (varn (whileDG cxt) ) |
dd66b94bf365
loop causes agda inifinite loop
Shinji KONO <kono@ie.u-ryukyu.ac.jp>
parents:
29
diff
changeset
|
130 whileLoopContext cxt next | false = next cxt |
dd66b94bf365
loop causes agda inifinite loop
Shinji KONO <kono@ie.u-ryukyu.ac.jp>
parents:
29
diff
changeset
|
131 whileLoopContext cxt next | true = |
dd66b94bf365
loop causes agda inifinite loop
Shinji KONO <kono@ie.u-ryukyu.ac.jp>
parents:
29
diff
changeset
|
132 whileLoopContext (record cxt { whileDG = record {varn = (varn (whileDG cxt)) - 1 ; vari = (vari (whileDG cxt)) + 1} } ) next |
dd66b94bf365
loop causes agda inifinite loop
Shinji KONO <kono@ie.u-ryukyu.ac.jp>
parents:
29
diff
changeset
|
133 |
dd66b94bf365
loop causes agda inifinite loop
Shinji KONO <kono@ie.u-ryukyu.ac.jp>
parents:
29
diff
changeset
|
134 {-# TERMINATING #-} |
dd66b94bf365
loop causes agda inifinite loop
Shinji KONO <kono@ie.u-ryukyu.ac.jp>
parents:
29
diff
changeset
|
135 whileLoopStep : {l : Level} {t : Set l} -> Env -> (Code : Env -> t) (Code : Env -> t) -> t |
dd66b94bf365
loop causes agda inifinite loop
Shinji KONO <kono@ie.u-ryukyu.ac.jp>
parents:
29
diff
changeset
|
136 whileLoopStep env next exit with lt 0 (varn env) |
dd66b94bf365
loop causes agda inifinite loop
Shinji KONO <kono@ie.u-ryukyu.ac.jp>
parents:
29
diff
changeset
|
137 whileLoopStep env next exit | false = exit env |
dd66b94bf365
loop causes agda inifinite loop
Shinji KONO <kono@ie.u-ryukyu.ac.jp>
parents:
29
diff
changeset
|
138 whileLoopStep env next exit | true = |
dd66b94bf365
loop causes agda inifinite loop
Shinji KONO <kono@ie.u-ryukyu.ac.jp>
parents:
29
diff
changeset
|
139 next (record {varn = (varn env) - 1 ; vari = (vari env) + 1}) |
27 | 140 |
30
dd66b94bf365
loop causes agda inifinite loop
Shinji KONO <kono@ie.u-ryukyu.ac.jp>
parents:
29
diff
changeset
|
141 whileTestProof : {l : Level} {t : Set l} -> Context → (Code : Context -> t) -> t |
dd66b94bf365
loop causes agda inifinite loop
Shinji KONO <kono@ie.u-ryukyu.ac.jp>
parents:
29
diff
changeset
|
142 whileTestProof cxt next = next record cxt { whileDG = out ; whileCond = init } where |
dd66b94bf365
loop causes agda inifinite loop
Shinji KONO <kono@ie.u-ryukyu.ac.jp>
parents:
29
diff
changeset
|
143 out : Env |
dd66b94bf365
loop causes agda inifinite loop
Shinji KONO <kono@ie.u-ryukyu.ac.jp>
parents:
29
diff
changeset
|
144 out = whileTest (c10 cxt) ( λ e → e ) |
dd66b94bf365
loop causes agda inifinite loop
Shinji KONO <kono@ie.u-ryukyu.ac.jp>
parents:
29
diff
changeset
|
145 init : whileTestState (c10 cxt) |
dd66b94bf365
loop causes agda inifinite loop
Shinji KONO <kono@ie.u-ryukyu.ac.jp>
parents:
29
diff
changeset
|
146 init = state1 out record { pi1 = refl ; pi2 = refl } |
27 | 147 |
30
dd66b94bf365
loop causes agda inifinite loop
Shinji KONO <kono@ie.u-ryukyu.ac.jp>
parents:
29
diff
changeset
|
148 {-# TERMINATING #-} |
dd66b94bf365
loop causes agda inifinite loop
Shinji KONO <kono@ie.u-ryukyu.ac.jp>
parents:
29
diff
changeset
|
149 whileLoopProof : {l : Level} {t : Set l} -> Context -> (Code : Context -> t) (Code : Context -> t) -> t |
31 | 150 whileLoopProof cxt next exit = whileLoopStep (whileDG cxt) |
151 ( λ env → next record cxt { whileDG = env ; whileCond = nextCond env } ) | |
152 ( λ env → exit record cxt { whileDG = env ; whileCond = exitCond env } ) where | |
153 nextCond : Env → whileTestState (c10 cxt) | |
154 nextCond nenv with whileCond cxt | |
155 ... | state2 e inv = state2 (whileDG cxt) {!!} | |
156 ... | _ = error | |
157 exitCond : Env → whileTestState (c10 cxt) | |
158 exitCond nenv with whileCond cxt | |
159 ... | state2 e inv = finstate (whileDG cxt) {!!} | |
160 ... | _ = error | |
27 | 161 |
30
dd66b94bf365
loop causes agda inifinite loop
Shinji KONO <kono@ie.u-ryukyu.ac.jp>
parents:
29
diff
changeset
|
162 whileConvProof : {l : Level} {t : Set l} -> Context -> (Code : Context -> t) -> t |
dd66b94bf365
loop causes agda inifinite loop
Shinji KONO <kono@ie.u-ryukyu.ac.jp>
parents:
29
diff
changeset
|
163 whileConvProof cxt next = next record cxt { whileCond = postCond } where |
dd66b94bf365
loop causes agda inifinite loop
Shinji KONO <kono@ie.u-ryukyu.ac.jp>
parents:
29
diff
changeset
|
164 postCond : whileTestState (c10 cxt) |
dd66b94bf365
loop causes agda inifinite loop
Shinji KONO <kono@ie.u-ryukyu.ac.jp>
parents:
29
diff
changeset
|
165 postCond with whileCond cxt |
31 | 166 ... | state1 e inv = state2 (whileDG cxt) {!!} |
30
dd66b94bf365
loop causes agda inifinite loop
Shinji KONO <kono@ie.u-ryukyu.ac.jp>
parents:
29
diff
changeset
|
167 ... | _ = error |
dd66b94bf365
loop causes agda inifinite loop
Shinji KONO <kono@ie.u-ryukyu.ac.jp>
parents:
29
diff
changeset
|
168 |
dd66b94bf365
loop causes agda inifinite loop
Shinji KONO <kono@ie.u-ryukyu.ac.jp>
parents:
29
diff
changeset
|
169 {-# TERMINATING #-} |
dd66b94bf365
loop causes agda inifinite loop
Shinji KONO <kono@ie.u-ryukyu.ac.jp>
parents:
29
diff
changeset
|
170 loop : {l : Level} {t : Set l} -> Context -> (exit : Context -> t) -> t |
31 | 171 loop cxt exit = whileLoopProof cxt (λ cxt → loop cxt exit ) exit |
30
dd66b94bf365
loop causes agda inifinite loop
Shinji KONO <kono@ie.u-ryukyu.ac.jp>
parents:
29
diff
changeset
|
172 |
dd66b94bf365
loop causes agda inifinite loop
Shinji KONO <kono@ie.u-ryukyu.ac.jp>
parents:
29
diff
changeset
|
173 proofWhileGear : (c : ℕ) (cxt : Context) → whileTestProof (record cxt { c10 = c ; whileCond = error }) |
dd66b94bf365
loop causes agda inifinite loop
Shinji KONO <kono@ie.u-ryukyu.ac.jp>
parents:
29
diff
changeset
|
174 $ λ cxt → whileConvProof cxt |
dd66b94bf365
loop causes agda inifinite loop
Shinji KONO <kono@ie.u-ryukyu.ac.jp>
parents:
29
diff
changeset
|
175 $ λ cxt → loop cxt |
dd66b94bf365
loop causes agda inifinite loop
Shinji KONO <kono@ie.u-ryukyu.ac.jp>
parents:
29
diff
changeset
|
176 $ λ cxt → vari (whileDG cxt) ≡ c10 cxt |
31 | 177 proofWhileGear cxt = {!!} |
30
dd66b94bf365
loop causes agda inifinite loop
Shinji KONO <kono@ie.u-ryukyu.ac.jp>
parents:
29
diff
changeset
|
178 |