Skip to content
GitLab
Projects
Groups
Snippets
Help
Loading...
Help
Help
Support
Community forum
Keyboard shortcuts
?
Submit feedback
Contribute to GitLab
Sign in
Toggle navigation
Open sidebar
Why3
why3
Commits
7e0d3658
Commit
7e0d3658
authored
Mar 10, 2011
by
Jean-Christophe
Browse files
new program examples from Pierce's book
parent
5d121853
Changes
2
Hide whitespace changes
Inline
Side-by-side
Showing
2 changed files
with
80 additions
and
0 deletions
+80
-0
examples/programs/sf.mlw
examples/programs/sf.mlw
+76
-0
src/programs/TODO
src/programs/TODO
+4
-0
No files found.
examples/programs/sf.mlw
0 → 100644
View file @
7e0d3658
(* Program verification examples from the book "Software Foundations"
http://www.cis.upenn.edu/~bcpierce/sf/
Note: we are using int (not nat), so we need extra precondition (e.g. x >= 0)
Note: we are also proving termination
*)
module SF
use import int.Int
use import module stdlib.Ref
(* Example: Slow Subtraction *)
let slow_subtraction x z =
{ x >= 0 }
label L:
while !x <> 0 do
invariant { 0 <= x and z - x = at z L - at x L } variant { x }
z := !z - 1;
x := !x - 1
done
{ z = old z - old x }
(* Example: Reduce to Zero *)
let reduce_to_zero x =
{ x >= 0 }
while !x <> 0 do invariant { x >= 0 } variant { x } x := !x - 1 done
{ x = 0 }
(* Exercise: Slow Addition *)
let slow_addition x z =
{ x >= 0 }
label L:
while !x <> 0 do
invariant { 0 <= x and z + x = at z L + at x L } variant { x }
z := !z + 1;
x := !x - 1
done
{ z = old z + old x }
(* Example: Parity *)
inductive even int =
| even_0 : even 0
| even_odd : forall x:int. even x -> even (x+2)
lemma even_not_odd : forall x:int. even x -> even (x+1) -> false
let parity x y =
{ x >= 0 }
y := 0;
label L:
while !x <> 0 do
invariant { 0 <= x and (y=0 and even (at x L - x) or
y=1 and even (at x L - x + 1)) }
variant { x }
y := 1 - !y;
x := !x - 1
done
{ y=0 <-> even (old x) }
(* Example: Finding Square Roots *)
(* Exercise: Factorial *)
end
(*
Local Variables:
compile-command: "unset LANG; make -C ../.. examples/programs/sf.gui"
End:
*)
src/programs/TODO
View file @
7e0d3658
o use of old in loop invariant should be reported as an error (correctly)
o automatically add a label Init at the beginning of each function body
o what about pervasives old, at, label, unit = ()
in particular, how to prevent old and at from being used in programs?
can we get rid of theories/programs.why?
...
...
Write
Preview
Markdown
is supported
0%
Try again
or
attach a new file
.
Attach a file
Cancel
You are about to add
0
people
to the discussion. Proceed with caution.
Finish editing this message first!
Cancel
Please
register
or
sign in
to comment