1 (**************************************************************************)
4 (* ||A|| A project by Andrea Asperti *)
6 (* ||I|| Developers: *)
7 (* ||T|| A.Asperti, C.Sacerdoti Coen, *)
8 (* ||A|| E.Tassi, S.Zacchiroli *)
10 (* \ / This file is distributed under the terms of the *)
11 (* v GNU Lesser General Public License Version 2.1 *)
13 (**************************************************************************)
15 (* ********************************************************************** *)
16 (* Progetto FreeScale *)
19 (* Cosimo Oliboni, oliboni@cs.unibo.it *)
21 (* Questo materiale fa parte della tesi: *)
22 (* "Formalizzazione Interattiva dei Microcontroller a 8bit FreeScale" *)
24 (* data ultima modifica 15/11/2007 *)
25 (* ********************************************************************** *)
27 include "freescale/pts.ma".
29 (* ********************************** *)
30 (* SOTTOINSIEME MINIMALE DELLA TEORIA *)
31 (* ********************************** *)
33 (* logic/connectives.ma *)
35 ninductive True: Prop ≝
38 ndefinition True_ind : ΠP:Prop.P → True → P ≝
40 match H with [ I ⇒ p ].
42 ndefinition True_rec : ΠP:Set.P → True → P ≝
44 match H with [ I ⇒ p ].
46 ndefinition True_rect : ΠP:Type.P → True → P ≝
48 match H with [ I ⇒ p ].
50 ninductive False: Prop ≝.
52 ndefinition False_ind : ΠP:Prop.False → P ≝
54 match H in False return λH1:False.P with [].
56 ndefinition False_rec : ΠP:Set.False → P ≝
58 match H in False return λH1:False.P with [].
60 ndefinition False_rect : ΠP:Type.False → P ≝
62 match H in False return λH1:False.P with [].
64 ndefinition Not: Prop → Prop ≝
67 interpretation "logical not" 'not x = (Not x).
69 nlemma absurd : ∀A,C:Prop.A → ¬A → C.
76 nlemma not_to_not : ∀A,B:Prop. (A → B) → ¬B →¬A.
83 ninductive And (A,B:Prop) : Prop ≝
84 conj : A → B → (And A B).
86 ndefinition And_ind : ΠA,B:Prop.ΠP:Prop.(A → B → P) → And A B → P ≝
87 λA,B:Prop.λP:Prop.λf:A → B → P.λH:And A B.
88 match H with [conj H1 H2 ⇒ f H1 H2 ].
90 ndefinition And_rec : ΠA,B:Prop.ΠP:Set.(A → B → P) → And A B → P ≝
91 λA,B:Prop.λP:Set.λf:A → B → P.λH:And A B.
92 match H with [conj H1 H2 ⇒ f H1 H2 ].
94 ndefinition And_rect : ΠA,B:Prop.ΠP:Type.(A → B → P) → And A B → P ≝
95 λA,B:Prop.λP:Type.λf:A → B → P.λH:And A B.
96 match H with [conj H1 H2 ⇒ f H1 H2 ].
98 interpretation "logical and" 'and x y = (And x y).
100 nlemma proj1: ∀A,B:Prop.A ∧ B → A.
102 napply (And_ind A B ?? H);
107 nlemma proj2: ∀A,B:Prop.A ∧ B → B.
109 napply (And_ind A B ?? H);
114 ninductive Or (A,B:Prop) : Prop ≝
115 or_introl : A → (Or A B)
116 | or_intror : B → (Or A B).
118 ndefinition Or_ind : ΠA,B:Prop.ΠP:Prop.(A → P) → (B → P) → Or A B → P ≝
119 λA,B:Prop.λP:Prop.λf1:A → P.λf2:B → P.λH:Or A B.
120 match H with [ or_introl H1 ⇒ f1 H1 | or_intror H1 ⇒ f2 H1 ].
122 interpretation "logical or" 'or x y = (Or x y).
124 ndefinition decidable : Prop → Prop ≝ λA:Prop.A ∨ ¬A.
126 ninductive ex (A:Type) (Q:A → Prop) : Prop ≝
127 ex_intro: ∀x:A.Q x → ex A Q.
129 ndefinition ex_ind : ΠA:Type.ΠQ:A → Prop.ΠP:Prop.(Πa:A.Q a → P) → ex A Q → P ≝
130 λA:Type.λQ:A → Prop.λP:Prop.λf:(Πa:A.Q a → P).λH:ex A Q.
131 match H with [ ex_intro H1 H2 ⇒ f H1 H2 ].
133 interpretation "exists" 'exists x = (ex ? x).
135 ninductive ex2 (A:Type) (Q,R:A → Prop) : Prop ≝
136 ex_intro2: ∀x:A.Q x → R x → ex2 A Q R.
138 ndefinition ex2_ind : ΠA:Type.ΠQ,R:A → Prop.ΠP:Prop.(Πa:A.Q a → R a → P) → ex2 A Q R → P ≝
139 λA:Type.λQ,R:A → Prop.λP:Prop.λf:(Πa:A.Q a → R a → P).λH:ex2 A Q R.
140 match H with [ ex_intro2 H1 H2 H3 ⇒ f H1 H2 H3 ].
143 λA,B.(A -> B) ∧ (B -> A).
145 (* higher_order_defs/relations *)
147 ndefinition relation : Type → Type ≝
148 λA:Type.A → A → Prop.
150 ndefinition reflexive : ∀A:Type.∀R:relation A.Prop ≝
153 ndefinition symmetric : ∀A:Type.∀R:relation A.Prop ≝
154 λA.λR.∀x,y:A.R x y → R y x.
156 ndefinition transitive : ∀A:Type.∀R:relation A.Prop ≝
157 λA.λR.∀x,y,z:A.R x y → R y z → R x z.
159 ndefinition irreflexive : ∀A:Type.∀R:relation A.Prop ≝
160 λA.λR.∀x:A.¬ (R x x).
162 ndefinition cotransitive : ∀A:Type.∀R:relation A.Prop ≝
163 λA.λR.∀x,y:A.R x y → ∀z:A. R x z ∨ R z y.
165 ndefinition tight_apart : ∀A:Type.∀eq,ap:relation A.Prop ≝
166 λA.λeq,ap.∀x,y:A. (¬ (ap x y) → eq x y) ∧ (eq x y → ¬ (ap x y)).
168 ndefinition antisymmetric : ∀A:Type.∀R:relation A.Prop ≝
169 λA.λR.∀x,y:A.R x y → ¬ (R y x).
171 (* logic/equality.ma *)
173 ninductive eq (A:Type) (x:A) : A → Prop ≝
176 ndefinition eq_ind : ΠA:Type.Πx:A.ΠP:A → Prop.P x → Πa:A.eq A x a → P a ≝
177 λA:Type.λx:A.λP:A → Prop.λp:P x.λa:A.λH:eq A x a.
178 match H with [refl_eq ⇒ p ].
180 ndefinition eq_rec : ΠA:Type.Πx:A.ΠP:A → Set.P x → Πa:A.eq A x a → P a ≝
181 λA:Type.λx:A.λP:A → Set.λp:P x.λa:A.λH:eq A x a.
182 match H with [refl_eq ⇒ p ].
184 ndefinition eq_rect : ΠA:Type.Πx:A.ΠP:A → Type.P x → Πa:A.eq A x a → P a ≝
185 λA:Type.λx:A.λP:A → Type.λp:P x.λa:A.λH:eq A x a.
186 match H with [refl_eq ⇒ p ].
188 interpretation "leibnitz's equality" 'eq t x y = (eq t x y).
190 interpretation "leibnitz's non-equality" 'neq t x y = (Not (eq t x y)).
192 nlemma symmetric_eq: ∀A:Type. symmetric A (eq A).
200 nlemma eq_elim_r: ∀A:Type.∀x:A.∀P:A → Prop.P x → ∀y:A.y=x → P y.
201 #A; #x; #P; #H; #y; #H1;
202 napply (eq_ind ? x ? H y ?);
207 ndefinition relationT : Type → Type → Type ≝
210 ndefinition symmetricT: ∀A,T:Type.∀R:relationT A T.Prop ≝
211 λA,T.λR.∀x,y:A.R x y = R y x.
213 ndefinition associative : ∀A:Type.∀R:relationT A A.Prop ≝
214 λA.λR.∀x,y,z:A.R (R x y) z = R x (R y z).
218 ninductive list (A:Type) : Type ≝
220 | cons: A -> list A -> list A.
222 nlet rec list_ind (A:Type) (P:list A → Prop) (p:P (nil A)) (f:(Πa:A.Πl':list A.P l' → P (cons A a l'))) (l:list A) on l ≝
223 match l with [ nil ⇒ p | cons h t ⇒ f h t (list_ind A P p f t) ].
225 nlet rec list_rec (A:Type) (P:list A → Set) (p:P (nil A)) (f:Πa:A.Πl':list A.P l' → P (cons A a l')) (l:list A) on l ≝
226 match l with [ nil ⇒ p | cons h t ⇒ f h t (list_rec A P p f t) ].
228 nlet rec list_rect (A:Type) (P:list A → Type) (p:P (nil A)) (f:Πa:A.Πl':list A.P l' → P (cons A a l')) (l:list A) on l ≝
229 match l with [ nil ⇒ p | cons h t ⇒ f h t (list_rect A P p f t) ].
231 nlet rec append A (l1: list A) l2 on l1 ≝
234 | (cons hd tl) => cons A hd (append A tl l2) ].
236 notation "hvbox(hd break :: tl)"
237 right associative with precedence 47
238 for @{'cons $hd $tl}.
240 notation "[ list0 x sep ; ]"
241 non associative with precedence 90
242 for ${fold right @'nil rec acc @{'cons $x $acc}}.
244 notation "hvbox(l1 break @ l2)"
245 right associative with precedence 47
246 for @{'append $l1 $l2 }.
248 interpretation "nil" 'nil = (nil ?).
249 interpretation "cons" 'cons hd tl = (cons ? hd tl).
250 interpretation "append" 'append l1 l2 = (append ? l1 l2).
252 nlemma list_destruct_1 : ∀T.∀x1,x2:T.∀y1,y2:list T.cons T x1 y1 = cons T x2 y2 → x1 = x2.
253 #T; #x1; #x2; #y1; #y2; #H;
254 nchange with (match cons T x2 y2 with [ nil ⇒ False | cons a _ ⇒ x1 = a ]);
260 nlemma list_destruct_2 : ∀T.∀x1,x2:T.∀y1,y2:list T.cons T x1 y1 = cons T x2 y2 → y1 = y2.
261 #T; #x1; #x2; #y1; #y2; #H;
262 nchange with (match cons T x2 y2 with [ nil ⇒ False | cons _ b ⇒ y1 = b ]);
268 nlemma list_destruct_cons_nil : ∀T.∀x:T.∀y:list T.cons T x y = nil T → False.
270 nchange with (match cons T x y with [ nil ⇒ True | cons a b ⇒ False ]);
276 nlemma list_destruct_nil_cons : ∀T.∀x:T.∀y:list T.nil T = cons T x y → False.
278 nchange with (match cons T x y with [ nil ⇒ True | cons a b ⇒ False ]);
284 nlemma append_nil : ∀T:Type.∀l:list T.(l@[]) = l.
286 napply (list_ind T ??? l);
288 ##[ ##1: napply (refl_eq ??)
295 nlemma associative_list : ∀T.associative (list T) (append T).
297 napply (list_ind T ??? x);
299 ##[ ##1: napply (refl_eq ??)
306 nlemma cons_append_commute : ∀T:Type.∀l1,l2:list T.∀a:T.a :: (l1 @ l2) = (a :: l1) @ l2.
312 nlemma append_cons_commute : ∀T:Type.∀a:T.∀l,l1:list T.l @ (a::l1) = (l@[a]) @ l1.
314 nrewrite > (associative_list T l [a] l1);