• Top
    • Documentation
    • Books
    • Boolean-reasoning
    • Projects
    • Debugging
    • Std
    • Community
    • Proof-automation
    • ACL2
    • Macro-libraries
    • Interfacing-tools
    • Hardware-verification
    • Software-verification
      • Kestrel-books
        • Crypto-hdwallet
        • Apt
        • Error-checking
        • Fty-extensions
        • Isar
        • Kestrel-utilities
        • Set
        • Soft
        • C
          • Syntax-for-tools
          • Atc
            • Atc-implementation
              • Atc-abstract-syntax
              • Atc-pretty-printer
              • Atc-event-and-code-generation
                • Atc-symbolic-computation-states
                • Atc-symbolic-execution-rules
                • Atc-gen-ext-declon-lists
                • Atc-function-and-loop-generation
                  • Atc-gen-cfun-correct-thm
                  • Atc-typed-formals
                  • Atc-gen-outer-bindings-and-hyps
                  • Atc-gen-fundef
                  • Atc-gen-exec-stmt-while-for-loop
                  • Atc-gen-context-preamble
                  • Atc-gen-pop-frame-thm
                  • Atc-gen-loop-correct-thm
                  • Atc-gen-init-scope-thms
                  • Atc-gen-fun-correct-thm
                  • Atc-gen-fn-result-thm
                  • Atc-gen-loop-body-correct-thm
                  • Atc-gen-loop
                  • Atc-gen-loop-test-correct-thm
                  • Atc-check-guard-conjunct
                  • Atc-find-affected
                  • Atc-gen-cfun-final-compustate
                  • Atc-gen-init-inscope-auto
                  • Atc-gen-init-inscope-static
                  • Atc-gen-push-init-thm
                  • Atc-gen-loop-measure-fn
                  • Atc-gen-fun-endstate
                  • Atc-gen-loop-termination-thm
                    • Atc-gen-formal-thm
                    • Atc-gen-loop-final-compustate
                    • Atc-gen-loop-measure-thm
                    • Atc-gen-object-disjoint-hyps
                    • Atc-loop-body-term-subst
                    • Atc-gen-omap-update-formals
                    • Atc-gen-loop-tthm-formula
                    • Atc-gen-init-inscope
                    • Atc-gen-fn-def*
                    • Atc-gen-param-declon-list
                    • Atc-formal-affectablep
                    • Atc-gen-cfun-fun-env-thm
                    • Atc-gen-add-var-formals
                    • Atc-gen-cfun-fun-env-thm-name
                    • Atc-gen-fn-guard
                    • Atc-filter-exec-fun-args
                    • Atc-gen-context-preamble-aux-aux
                    • Atc-typed-formals-to-extobjs
                    • Atc-formal-affectable-listp
                  • Atc-statement-generation
                  • Atc-gen-fileset
                  • Atc-gen-everything
                  • Atc-gen-obj-declon
                  • Atc-gen-fileset-event
                  • Atc-tag-tables
                  • Atc-expression-generation
                  • Atc-generation-contexts
                  • Atc-gen-wf-thm
                  • Term-checkers-atc
                  • Atc-variable-tables
                  • Term-checkers-common
                  • Atc-gen-init-fun-env-thm
                  • Atc-gen-appconds
                  • Read-write-variables
                  • Atc-gen-thm-assert-events
                  • Test*
                  • Atc-gen-prog-const
                  • Atc-gen-expr-bool
                  • Atc-theorem-generation
                  • Atc-tag-generation
                  • Atc-gen-expr-pure
                  • Atc-function-tables
                  • Atc-object-tables
                • Fty-pseudo-term-utilities
                • Atc-term-recognizers
                • Atc-input-processing
                • Atc-shallow-embedding
                • Atc-process-inputs-and-gen-everything
                • Atc-table
                • Atc-fn
                • Atc-pretty-printing-options
                • Atc-types
                • Atc-macro-definition
              • Atc-tutorial
            • Language
            • Representation
            • Transformation-tools
            • Insertion-sort
            • Pack
          • Bv
          • Imp-language
          • Event-macros
          • Java
          • Bitcoin
          • Ethereum
          • Yul
          • Zcash
          • ACL2-programming-language
          • Prime-fields
          • Json
          • Syntheto
          • File-io-light
          • Cryptography
          • Number-theory
          • Lists-light
          • Axe
          • Builtins
          • Solidity
          • Helpers
          • Htclient
          • Typed-lists-light
          • Arithmetic-light
        • X86isa
        • Axe
        • Execloader
      • Math
      • Testing-utilities
    • Atc-function-and-loop-generation

    Atc-gen-loop-termination-thm

    Generate the version of the termination theorem tailored to the limits and measure function.

    Signature
    (atc-gen-loop-termination-thm fn measure-of-fn measure-formals 
                                  natp-of-measure-of-fn-thm 
                                  names-to-avoid state) 
     
      → 
    (mv erp event name updated-names-to-avoid)
    Arguments
    fn — Guard (symbolp fn).
    measure-of-fn — Guard (symbolp measure-of-fn).
    measure-formals — Guard (symbol-listp measure-formals).
    natp-of-measure-of-fn-thm — Guard (symbolp natp-of-measure-of-fn-thm).
    names-to-avoid — Guard (symbol-listp names-to-avoid).
    Returns
    event — Type (pseudo-event-formp event).
    name — Type (symbolp name).
    updated-names-to-avoid — Type (symbol-listp updated-names-to-avoid), given (symbol-listp names-to-avoid).

    We generate a local theorem that is just like the termination theorem of the function except that o< is replaced with <, and that the measure terms are abstracted to calls of the generated measure functions. The theorem is proved using the fact that the measure yields a natural number, which means that o< reduces to < (see above). The purpose of this variant of the termination theorem is to help establish the induction hypothesis in the loop correctness theorem, as explained below.

    Definitions and Theorems

    Function: atc-gen-loop-termination-thm

    (defun atc-gen-loop-termination-thm
           (fn measure-of-fn measure-formals
               natp-of-measure-of-fn-thm
               names-to-avoid state)
     (declare (xargs :stobjs (state)))
     (declare (xargs :guard (and (symbolp fn)
                                 (symbolp measure-of-fn)
                                 (symbol-listp measure-formals)
                                 (symbolp natp-of-measure-of-fn-thm)
                                 (symbol-listp names-to-avoid))))
     (declare (xargs :guard (and (function-symbolp fn (w state))
                                 (logicp fn (w state))
                                 (irecursivep+ fn (w state))
                                 (not (eq measure-of-fn 'quote)))))
     (let ((__function__ 'atc-gen-loop-termination-thm))
      (declare (ignorable __function__))
      (b*
       (((reterr) '(_) nil nil)
        (wrld (w state))
        (termination-of-fn-thm (packn-pos (list 'termination-of- fn)
                                          fn))
        ((mv termination-of-fn-thm names-to-avoid)
         (fresh-logical-name-with-$s-suffix termination-of-fn-thm
                                            nil names-to-avoid wrld))
        (tthm (termination-theorem$ fn state))
        ((when (eq (car tthm) :failed))
         (reterr
          (raise
               "Internal error: cannot find termination theorem of ~x0."
               fn)))
        ((erp tthm-formula)
         (atc-gen-loop-tthm-formula
              tthm
              fn measure-of-fn measure-formals state))
        ((mv termination-of-fn-thm-event &)
         (evmac-generate-defthm
          termination-of-fn-thm
          :formula tthm-formula
          :rule-classes nil
          :hints
          (cons
           (cons
            '"Goal"
            (cons
             ':use
             (cons
              (cons (cons ':termination-theorem
                          (cons fn 'nil))
                    (cons natp-of-measure-of-fn-thm 'nil))
              (cons
               ':in-theory
               (cons
                (cons
                 'quote
                 (cons
                  (cons measure-of-fn
                        '(acl2::natp-compound-recognizer o-p o-finp o<))
                  'nil))
                'nil)))))
           'nil))))
       (retok termination-of-fn-thm-event
              termination-of-fn-thm names-to-avoid))))

    Theorem: pseudo-event-formp-of-atc-gen-loop-termination-thm.event

    (defthm pseudo-event-formp-of-atc-gen-loop-termination-thm.event
      (b*
        (((mv acl2::?erp acl2::?event
              ?name ?updated-names-to-avoid)
          (atc-gen-loop-termination-thm fn measure-of-fn measure-formals
                                        natp-of-measure-of-fn-thm
                                        names-to-avoid state)))
        (pseudo-event-formp event))
      :rule-classes :rewrite)

    Theorem: symbolp-of-atc-gen-loop-termination-thm.name

    (defthm symbolp-of-atc-gen-loop-termination-thm.name
      (b*
        (((mv acl2::?erp acl2::?event
              ?name ?updated-names-to-avoid)
          (atc-gen-loop-termination-thm fn measure-of-fn measure-formals
                                        natp-of-measure-of-fn-thm
                                        names-to-avoid state)))
        (symbolp name))
      :rule-classes :rewrite)

    Theorem: symbol-listp-of-atc-gen-loop-termination-thm.updated-names-to-avoid

    (defthm
     symbol-listp-of-atc-gen-loop-termination-thm.updated-names-to-avoid
     (implies
       (symbol-listp names-to-avoid)
       (b*
        (((mv acl2::?erp acl2::?event
              ?name ?updated-names-to-avoid)
          (atc-gen-loop-termination-thm fn measure-of-fn measure-formals
                                        natp-of-measure-of-fn-thm
                                        names-to-avoid state)))
        (symbol-listp updated-names-to-avoid)))
     :rule-classes :rewrite)