 31 Oct, 2018 40 commits


Robbert Krebbers authored

Robbert Krebbers authored

Robbert Krebbers authored

Robbert Krebbers authored
This commit extends the state interpretation with an additional parameter to talk about the number of forkedoff threads, and a fixed postcondition for each forkedoff thread: state_interp : Λstate → list Λobservation → nat → iProp Σ; fork_post : iProp Σ; This way, instead of having `True` as the postcondition of `Fork`, one can have any postcondition, which is then recorded in the state interpretation. The point of keeping track of the postconditions of forkedoff threads, is that we get an (additional) stronger adequacy theorem: Theorem wp_strong_all_adequacy Σ Λ `{invPreG Σ} s e σ1 v vs σ2 φ : (∀ `{Hinv : invG Σ} κs, (={⊤}=> ∃ (stateI : state Λ → list (observation Λ) → nat → iProp Σ) (fork_post : iProp Σ), let _ : irisG Λ Σ := IrisG _ _ _ Hinv stateI fork_post in stateI σ1 κs 0 ∗ WP e @ s; ⊤ {{ v, let m := length vs in stateI σ2 [] m ∗ [∗] replicate m fork_post ={⊤,∅}=∗ ⌜ φ v ⌝ }})%I) → rtc erased_step ([e], σ1) (of_val <$> v :: vs, σ2) → φ v. The difference with the ordinary adequacy theorem is that this one only applies once all threads terminated. In this case, one gets back the postconditions `[∗] replicate m fork_post` of all forkedoff threads. In Iron we showed that we can use this mechanism to make sure that all resources are disposed of properly in the presence of forkbased concurrency.

 18 Oct, 2018 40 commits


Ralf Jung authored

 05 Oct, 2018 40 commits


Ralf Jung authored

Marianna Rapoport authored
 Removing head of list of observations after each reduction step in definition of wp  Adding support for observations to state_interp and world  Applying Ralf's suggestions to previous commit (e.g. replacing /\ and > with unicode characters)

Marianna Rapoport authored

 14 Jun, 2018 40 commits


JacquesHenri Jourdan authored

JacquesHenri Jourdan authored

 24 May, 2018 40 commits


Ralf Jung authored

 07 Dec, 2017 40 commits


Ralf Jung authored

 26 Nov, 2017 40 commits


David Swasey authored

 23 Nov, 2017 40 commits


Robbert Krebbers authored

 09 Nov, 2017 40 commits


David Swasey authored
This reverts commit 913059d2.

David Swasey authored

 08 Nov, 2017 40 commits


David Swasey authored

David Swasey authored

David Swasey authored

David Swasey authored

 25 Sep, 2017 40 commits


Robbert Krebbers authored
Typeclass search gets less confused when this version is used, also, we had the same for `wp_bind` already.

 24 Mar, 2017 40 commits


Robbert Krebbers authored
Instead, I have introduced a type class `Monoid` that is used by the big operators: Class Monoid {M : ofeT} (o : M → M → M) := { monoid_unit : M; monoid_ne : NonExpansive2 o; monoid_assoc : Assoc (≡) o; monoid_comm : Comm (≡) o; monoid_left_id : LeftId (≡) monoid_unit o; monoid_right_id : RightId (≡) monoid_unit o; }. Note that the operation is an argument because we want to have multiple monoids over the same type (for example, on `uPred`s we have monoids for `∗`, `∧`, and `∨`). However, we do bundle the unit because:  If we would not, the unit would appear explicitly in an implicit argument of the big operators, which confuses rewrite. By bundling the unit in the `Monoid` class it is hidden, and hence rewrite won't even see it.  The unit is unique. We could in principle have big ops over setoids instead of OFEs. However, since we do not have a canonical structure for bundled setoids, I did not go that way.

 15 Mar, 2017 40 commits


Robbert Krebbers authored

Robbert Krebbers authored

Ralf Jung authored

 09 Mar, 2017 40 commits


Ralf Jung authored

 05 Jan, 2017 40 commits


Ralf Jung authored

 04 Jan, 2017 40 commits


Ralf Jung authored

 03 Jan, 2017 40 commits


Ralf Jung authored
This patch was created using find name *.v  xargs L 1 awk i inplace '{from = 0} /^From/{ from = 1; ever_from = 1} { if (from == 0 && seen == 0 && ever_from == 1) { print "Set Default Proof Using \"Type*\"."; seen = 1 } }1 ' and some minor manual editing

 09 Dec, 2016 40 commits


Ralf Jung authored

Robbert Krebbers authored
The WP construction now takes an invariant on states as a parameter (part of the irisG class) and no longer builds in the authoritative ownership of the entire state. When instantiating WP with a concrete language on can choose its state invariant. For example, for heap_lang we directly use `auth (gmap loc (frac * dec_agree val))`, and avoid the indirection through invariants entirely. As a result, we no longer have to carry `heap_ctx` around.

 08 Dec, 2016 40 commits


Ralf Jung authored

 06 Dec, 2016 40 commits


Ralf Jung authored

 22 Nov, 2016 40 commits


Ralf Jung authored

 03 Nov, 2016 40 commits


Robbert Krebbers authored
The old choice for ★ was a arbitrary: the precedence of the ASCII asterisk * was fixed at a wrong level in Coq, so we had to pick another symbol. The ★ was a random choice from a unicode chart. The new symbol ∗ (as proposed by David Swasey) corresponds better to conventional practise and matches the symbol we use on paper.

 01 Nov, 2016 40 commits
 28 Oct, 2016 40 commits


Robbert Krebbers authored
