diff options
author | ckeller <ckeller@users.noreply.github.com> | 2019-01-28 23:19:12 +0100 |
---|---|---|
committer | GitHub <noreply@github.com> | 2019-01-28 23:19:12 +0100 |
commit | 7021c53d4ecf97c82ccebb6bb45f5305d8b482ea (patch) | |
tree | ba7537e1e813cabf9ee0d910f845c71fa5f446e7 /src/euf/Euf.v | |
parent | 36548d6634864a131cc83ce21491c797163de305 (diff) | |
download | smtcoq-7021c53d4ecf97c82ccebb6bb45f5305d8b482ea.tar.gz smtcoq-7021c53d4ecf97c82ccebb6bb45f5305d8b482ea.zip |
Merge from LFSC (#26)
* Showing models as coq counter examples in tactic without constructing coq terms
* also read models when calling cvc4 with a file (deactivated because cvc4 crashes)
* Show counter examples with variables in the order they are quantified in the Coq goal
* Circumvent issue with ocamldep
* fix issue with dependencies
* fix issue with dependencies
* Translation and OCaml support for extract, zero_extend, sign_extend
* Show run times of components
* print time on stdout instead
* Tests now work with new version (master) of CVC4
* fix small printing issue
* look for date on mac os x
* proof of valid_check_bbShl: some cases to prove.
* full proof of "left shift checker".
* full proof of "rigth shift checker".
* Support translation of terms bvlshr, bvshl but LFSC rules do not exists at the moment
Bug fix for bitvector extract (inverted arguments)
* Typo
* More modularity on the format of traces depending on the version of coq
* More straightforward definitions in Int63Native_standard
* Use the Int31 library with coq-8.5
* Use the most efficient operations of Int31
* Improved performance with coq-8.5
* Uniform treatment of sat and smt tactics
* Hopefully solved the problem with universes for the tactic
* Updated the installation instructions
* Holes for unsupported bit blasting rules
* Cherry-picking from smtcoq/smtcoq
* bug fix hole for bitblast
* Predefined arrays are not required anymore
* fix issue with coq bbT and bitof construction from ocaml
* bug fix in smtAtom for uninterpreted functions
fix verit test file
* fix issue with smtlib2 extract parsing
* It looks like we still need the PArray function instances for some examples (see vmcai_bytes.smt2)
* Solver specific reification:
Each solver has a list of supported theories which is passed to Atom.of_coq, this function creates uninterpreted functions / sorts for unsupported features.
* show counter-examples with const_farray instead of const for constant array definitions
* Vernacular commands to debug checkers.
Verit/Lfsc_Checker_Debug will always fail, reporting the first proof step of the certificate that failed be checked
* Update INSTALL.md
* show smtcoq proof when converting
* (Hopefully) repared the universes problems
* Corrected a bug with holes in proofs
* scripts for tests:
create a folder "work" under "lfsc/tests/", locate the benchmarks there.
create a folder "results" under "lfsc/tests/work/" in which you'll find the results of ./cvc4tocoq.
* make sure to give correct path for your benchs...
* Checker for array extensionality modulo symmetry of equality
* fix oversight with bitvectors larger than 63 bits
* some printing functions for smt2 ast
* handle smtlib2 files with more complicated equivalence with (= ... )
* revert: ./cvc4tocoq does not output lfsc proofs...
* bug fix one input was ignored
* Don't show verit translation of LFSC proof if environment variable DONTSHOWVERIT is set
(e.g. put export DONTSHOWVERIT="" in your .bashrc or .bashprofile)
* Also sort names of introduced variables when showing counter-example
* input files for which SMTCoq retuns false.
* input files for which SMTCoq retuns false.
* use debug checker for debug file
* More efficient debug checker
* better approximate number of failing step of certificate in debug checker
* fix mistake in ml4
* very first attempt to support goals in Prop
* bvs: comparison predicates in Prop and their <-> proofs with the ones in bool
farrays: equality predicate in Prop and its <-> proof with the one in bool.
* unit, Bool, Z, Pos: comparison and equality predicates in Prop.
* a typo fixed.
* an example of array equality in Prop (converted into Bool by hand)...
TODO: enhance the search space of cvc4 tactic.
* first version of cvc4' tactic: "solves" the goals in Prop.
WARNING: supports only bv and array goals and might not be complete
TODO: add support for lia goals
* cvc4' support for lia
WARNING: might not be complete!
* small fix in cvc4' and some variations of examples
* small fix + support for goals in Bool and Bool = true + use of solve tactical
WARNING: does not support UF and INT63 goals in Prop
* cvc4': better arrangement
* cvc4': Prop2Bool by context search...
* cvc4': solve tactial added -> do not modify unsolved goals.
* developer documentation for the smtcoq repo
* cvc4': rudimentary support for uninterpreted function goals in Prop.
* cvc4': support for goals with Leibniz equality...
WARNING: necessary use of "Grab Existential Variables." to instantiate variable types for farrays!
* cvc4': Z.lt adapted + better support from verit...
* cvc4': support for Z.le, Z.ge, Z.gt.
* Try arrays with default value (with a constructor for constant arrays), but extensionality is not provable
* cvc4': support for equality over uninterpreted types
* lfsc demo: goals in Coq's Prop.
* lfsc demo: goals in Bool.
* Fix issue with existential variables generated by prop2bool.
- prop2bool tactic exported by SMTCoq
- remove useless stuff
* update usage and installation instructions
* Update INSTALL.md
* highlighting
* the tactic: bool2prop.
* clean up
* the tactic smt: very first version.
* smt: return unsolved goals in Prop.
* Show when a certificate cannot be checked when running the tactic instead of at Qed
* Tactic improvements
- Handle negation/True/False in prop/bool conversions tactic.
- Remove alias for farray (this caused problem for matching on this type in tactics).
- Tactic `smt` that combines cvc4 and veriT.
- return subgoals in prop
* test change header
* smt: support for negated goals + some reorganization.
* conflicts resolved + some reorganization.
* a way to solve the issue with ambiguous coercions.
* reorganization.
* small change.
* another small change.
* developer documentation of the tactics.
* developer guide: some improvements.
* developer guide: some more improvements.
* developer guide: some more improvements.
* developer guide: some more improvements.
* pass correct environment for conversion + better error messages
* cleaning
* ReflectFacts added.
* re-organizing developers' guide.
* re-organizing developers' guide.
* re-organizing developers' guide.
* removing unused maps.
* headers.
* artifact readme getting started...
* first attempt
* second...
* third...
* 4th...
* 5th...
* 6th...
* 7th...
* 8th...
* 9th...
* 10th...
* 11th...
* 12th...
* 13th...
* 14th...
* 15th...
* 16th...
* 17th...
* Update artifact.md
Use links to lfsc repository like in the paper
* 18th...
* 19th...
* 20th...
* 21st...
* 22nd...
* 23rd...
* 24th...
* 25th...
* 26th...
* 27th...
* 28th...
* Update artifact.md
Small reorganization
* minor edits
* More minor edits
* revised description of tactics
* Final pass
* typo
* name changed: artifact-readme.md
* file added...
* passwd chaged...
* links...
* removal
* performance statement...
* typos...
* the link to the artifact image updated...
* suggestions by Guy...
* aux files removed...
* clean-up...
* clean-up...
* some small changes...
* small fix...
* additional information on newly created files after running cvc4tocoq script...
* some small fix...
* another small fix...
* typo...
* small fix...
* another small fix...
* fix...
* link to the artifact image...
* We do not want to force vm_cast for the Theorem commands
* no_check variants of the tactics
* TODO: a veriT test does not work anymore
* Compiles with both versions of Coq
* Test of the tactics in real conditions
* Comment on this case study
* an example for the FroCoS paper.
* Fix smt tactic that doesn't return cvc4's subgoals
* readme modifications
* readme modifications 2
* small typo in readme.
* small changes in readme.
* small changes in readme.
* typo in readme.
* Sync with https://github.com/LFSC/smtcoq
* Port to Coq 8.6
* README
* README
* INSTALL
* Missing file
* Yves' proposition for installation instructions
* Updated link to CVC4
* Compiles again with native-coq
* Compiles with both versions of Coq
* Command to bypass typechecking when generating a zchaff theorem
* Solved bug on cuts from Hole
* Counter-models for uninterpreted sorts (improves issue #13)
* OCaml version note (#15)
* update .gitignore
* needs OCaml 4.04.0
* Solving merge issues (under progress)
* Make SmtBtype compile
* Compilation of SmtForm under progress
* Make SmtForm compile
* Make SmtCertif compile
* Make SmtTrace compile
* Make SatAtom compile
* Make smtAtom compile
* Make CnfParser compile
* Make Zchaff compile
* Make VeritSyntax compile
* Make VeritParser compile
* Make lfsc/tosmtcoq compile
* Make smtlib2_genconstr compile
* smtCommand under progress
* smtCommands and verit compile again
* lfsc compiles
* ml4 compiles
* Everything compiles
* All ZChaff unit tests and most verit unit tests (but taut5 and un_menteur) go through
* Most LFSC tests ok; some fail due to the problem of verit; a few fail due to an error "Not_found" to investigate
* Authors and headings
* Compiles with native-coq
* Typo
Diffstat (limited to 'src/euf/Euf.v')
-rw-r--r-- | src/euf/Euf.v | 62 |
1 files changed, 35 insertions, 27 deletions
diff --git a/src/euf/Euf.v b/src/euf/Euf.v index 70b23da..7818246 100644 --- a/src/euf/Euf.v +++ b/src/euf/Euf.v @@ -1,13 +1,9 @@ (**************************************************************************) (* *) (* SMTCoq *) -(* Copyright (C) 2011 - 2016 *) +(* Copyright (C) 2011 - 2019 *) (* *) -(* Michaël Armand *) -(* Benjamin Grégoire *) -(* Chantal Keller *) -(* *) -(* Inria - École Polytechnique - Université Paris-Sud *) +(* See file "AUTHORS" for the list of authors *) (* *) (* This file is distributed under the terms of the CeCILL-C licence *) (* *) @@ -16,7 +12,6 @@ Require Import Bool List Int63 PArray. Require Import State SMT_terms. - Local Open Scope array_scope. Local Open Scope int63_scope. @@ -141,7 +136,7 @@ Section certif. Section Proof. - Variables (t_i : array typ_eqb) + Variables (t_i : array SMT_classes.typ_compdec) (t_func : array (Atom.tval t_i)) (ch_atom : Atom.check_atom t_atom) (ch_form : Form.check_form t_form) @@ -153,8 +148,11 @@ Section certif. Local Notation interp_form_hatom := (Atom.interp_form_hatom t_i t_func t_atom). + Local Notation interp_form_hatom_bv := + (Atom.interp_form_hatom_bv t_i t_func t_atom). + Local Notation rho := - (Form.interp_state_var interp_form_hatom t_form). + (Form.interp_state_var interp_form_hatom interp_form_hatom_bv t_form). Let wf_t_atom : Atom.wf t_atom. Proof. destruct (Atom.check_atom_correct _ ch_atom); auto. Qed. @@ -164,32 +162,32 @@ Section certif. Let def_t_form : default t_form = Form.Ftrue. Proof. - destruct (Form.check_form_correct interp_form_hatom _ ch_form) as [H _]; destruct H; auto. + destruct (Form.check_form_correct interp_form_hatom interp_form_hatom_bv _ ch_form) as [H _]; destruct H; auto. Qed. Let wf_t_form : Form.wf t_form. Proof. - destruct (Form.check_form_correct interp_form_hatom _ ch_form) as [H _]; destruct H; auto. + destruct (Form.check_form_correct interp_form_hatom interp_form_hatom_bv _ ch_form) as [H _]; destruct H; auto. Qed. Let wf_rho : Valuation.wf rho. Proof. - destruct (Form.check_form_correct interp_form_hatom _ ch_form); auto. + destruct (Form.check_form_correct interp_form_hatom interp_form_hatom_bv _ ch_form); auto. Qed. Lemma valid_C_true : C.interp rho C._true. Proof. apply C.interp_true. - destruct (Form.check_form_correct interp_form_hatom _ ch_form);trivial. + destruct (Form.check_form_correct interp_form_hatom interp_form_hatom_bv _ ch_form);trivial. Qed. Hint Resolve valid_C_true. Local Notation interp := (Atom.interp t_i t_func t_atom). Lemma wf_interp_form : forall x, - rho x = Form.interp interp_form_hatom t_form (t_form.[x]). + rho x = Form.interp interp_form_hatom interp_form_hatom_bv t_form (t_form.[x]). Proof. - destruct (Form.check_form_correct interp_form_hatom _ ch_form). + destruct (Form.check_form_correct interp_form_hatom interp_form_hatom_bv _ ch_form). destruct H; intros x;rewrite Form.wf_interp_form;trivial. Qed. @@ -248,8 +246,8 @@ Section certif. destruct (Typ.cast ta u);destruct (Typ.cast tb u);trivial. apply f_equal; apply eq_true_iff_eq. match goal with |- ?x = _ <-> ?y = _ => - change (is_true x <-> is_true y) end. - rewrite !Typ.i_eqb_spec;split;auto. + change (is_true x <-> is_true y) end. + split; intro; rewrite Typ.i_eqb_sym in H; auto. Qed. Lemma interp_binop_eqb_trans: @@ -270,7 +268,7 @@ Section certif. unfold Atom.interp_hatom. rewrite HHa, HHb, HHc;simpl;rewrite Typ.cast_refl. unfold Atom.interp_bool;simpl. - rewrite !Typ.i_eqb_spec;intros HH;rewrite HH;trivial. + apply Typ.i_eqb_trans. Qed. Lemma check_trans_aux_correct : @@ -291,9 +289,9 @@ Section certif. rewrite eqb_spec in H7. rewrite eqb_spec in H8. subst. tunicity. subst t. rewrite H4, H1;auto. rewrite eqb_spec in H7. rewrite eqb_spec in H8. subst. - tunicity;subst t;rewrite interp_binop_eqb_sym in H1;rewrite H4, H1;auto. + tunicity. subst t;rewrite interp_binop_eqb_sym in H1;rewrite H4, H1;auto. apply get_eq_interp;intros. - destruct (Int63Properties.reflect_eqb t2 b). subst;tunicity; subst t. + destruct (Int63Properties.reflect_eqb t2 b);subst;tunicity; try subst t. apply (IHeqs u);trivial. simpl;unfold is_true;rewrite orb_true_iff. rewrite Lit.interp_nlit;unfold Var.interp. @@ -318,7 +316,7 @@ Section certif. case_eq (rho (Lit.blit a));[rewrite H4; intros | simpl;auto]. destruct H1;[left | auto]. apply interp_binop_eqb_trans with (5:= H1);trivial. - destruct (Int63Properties.reflect_eqb t1 a0);[subst;tunicity; try subst t|auto]. + destruct (Int63Properties.reflect_eqb t1 a0);[subst;tunicity;try subst t|auto]. apply (IHeqs u);trivial. simpl;unfold is_true;rewrite orb_true_iff. rewrite Lit.interp_nlit;unfold Var.interp. @@ -345,7 +343,7 @@ Section certif. generalize (Atom.check_aux_interp_hatom _ t_func _ wf_t_atom b). rewrite Typ.eqb_spec in H3. unfold Atom.get_type in H3. rewrite H3. intros [vb HHb]. unfold Atom.interp_hatom. rewrite HHb;simpl;rewrite Typ.cast_refl;simpl. - rewrite !Typ.i_eqb_spec;trivial. + apply Typ.i_eqb_refl. auto. apply get_eq_interp;intros. apply check_trans_aux_correct with t;trivial. @@ -412,9 +410,10 @@ Section certif. inversion H6;subst. unfold Atom.interp_hatom in H10. rewrite <- HHa; rewrite <- HHb, H10;trivial. - rewrite Typ.i_eqb_spec. - inversion H7. - apply Eqdep_dec.inj_pair2_eq_dec in H9;trivial. + inversion H7. + apply Eqdep_dec.inj_pair2_eq_dec in H9;trivial. + rewrite H9. + apply Typ.i_eqb_refl. intros x y;destruct (Typ.reflect_eqb x y);auto. (* bop *) destruct (Atom.reflect_bop_eqb b0 b1);[subst | auto]. @@ -432,9 +431,10 @@ Section certif. inversion H12;clear H12;subst. unfold Atom.interp_hatom in H10, H8. rewrite <- HHa. rewrite <- HHb, H10, H8;trivial. - rewrite Typ.i_eqb_spec. inversion H7. apply Eqdep_dec.inj_pair2_eq_dec in H9;trivial. + rewrite H9. + apply Typ.i_eqb_refl. intros x y;destruct (Typ.reflect_eqb x y);auto. (* op *) destruct (Int63Properties.reflect_eqb i i0);[subst | auto]. @@ -453,9 +453,10 @@ Section certif. induction H6;simpl;trivial. unfold Atom.interp_hatom in H4. rewrite IHForall2, H4;trivial. - rewrite Typ.i_eqb_spec. inversion H7. apply Eqdep_dec.inj_pair2_eq_dec in H9;trivial. + rewrite H9. + apply Typ.i_eqb_refl. intros x y;destruct (Typ.reflect_eqb x y);auto. Qed. @@ -537,3 +538,10 @@ Section certif. End Proof. End certif. + + +(* + Local Variables: + coq-load-path: ((rec ".." "SMTCoq")) + End: +*) |