Skip to content
Snippets Groups Projects
  1. Mar 24, 2017
    • Robbert Krebbers's avatar
      Generic big operators that are no longer tied to CMRAs. · 6fbff46e
      Robbert Krebbers authored
      Instead, I have introduced a type class `Monoid` that is used by the big operators:
      
          Class Monoid {M : ofeT} (o : M → M → M) := {
            monoid_unit : M;
            monoid_ne : NonExpansive2 o;
            monoid_assoc : Assoc (≡) o;
            monoid_comm : Comm (≡) o;
            monoid_left_id : LeftId (≡) monoid_unit o;
            monoid_right_id : RightId (≡) monoid_unit o;
          }.
      
      Note that the operation is an argument because we want to have multiple monoids over
      the same type (for example, on `uPred`s we have monoids for `∗`, `∧`, and `∨`). However,
      we do bundle the unit because:
      
      - If we would not, the unit would appear explicitly in an implicit argument of the
        big operators, which confuses rewrite. By bundling the unit in the `Monoid` class
        it is hidden, and hence rewrite won't even see it.
      - The unit is unique.
      
      We could in principle have big ops over setoids instead of OFEs. However, since we do
      not have a canonical structure for bundled setoids, I did not go that way.
      6fbff46e
  2. Feb 09, 2017
  3. Jan 27, 2017
  4. Jan 05, 2017
  5. Jan 03, 2017
  6. Dec 09, 2016
  7. Nov 29, 2016
  8. Nov 28, 2016
    • Robbert Krebbers's avatar
      Simplify proof of auth_local_update. · ce32b224
      Robbert Krebbers authored
      Also, use explicit unfolding lemmas for auth_valid and auth_validN.
      The `Arguments valid _ _ !_ /` hack did not really work when one
      has to deal with the valid instance of the cmra, which underneath also
      includes a `cmra_valid`. Declaring a similar Arguments for `cmra_valid`
      is a bad idea, it will also end up unfold stuff for the exclusive and
      option CMRA.
      ce32b224
    • Ralf Jung's avatar
      Add a local update for auth (needed for nested auth) · 692b8570
      Ralf Jung authored
      Proof was done by Hai & me
      692b8570
  9. Nov 25, 2016
  10. Nov 22, 2016
  11. Oct 25, 2016
  12. Oct 06, 2016
  13. Oct 05, 2016
  14. Oct 03, 2016
  15. Sep 28, 2016
  16. Sep 20, 2016
  17. Sep 09, 2016
  18. Sep 01, 2016
  19. Aug 20, 2016
    • Robbert Krebbers's avatar
      Remove the requirement that the unit of a CMRA is timeless. · 7975f872
      Robbert Krebbers authored
      This requirement was useful in Iris 2.0: in order to ensure that ownership of
      the physical state was timeless, we required the ghost CMRA to have a timeless
      unit. To avoid having additional type class parameters, or having to extend the
      algebraic hierarchy, we required the units of any CMRA to be timeless.
      
      In Iris 3.0, this issue no longer applies: ownership of the physical state is
      ghost ownership in the global CMRA, whose unit is always timeless.
      
      Thanks to Jeehoon Kang for spotting this unnecessary requirement.
      7975f872
  20. Aug 14, 2016
  21. Aug 04, 2016
  22. Jul 28, 2016
  23. Jul 27, 2016
  24. Jul 25, 2016
  25. Jul 03, 2016
  26. Jun 16, 2016
  27. Jun 15, 2016
  28. May 31, 2016
  29. May 30, 2016
  30. May 28, 2016
    • Robbert Krebbers's avatar
      CMRAs with partial cores. · cfb00b3e
      Robbert Krebbers authored
      Based on an idea and WIP commits of J-H. Jourdan: the core of a CMRA
      A is now a partial function A → option A.
      
      TODO: define sum CMRA
      TODO: remove one shot CMRA and define it in terms of sum
      cfb00b3e
  31. May 27, 2016
  32. May 25, 2016
    • Robbert Krebbers's avatar
      Tweak the algebraic hierarchy. · a3d0a338
      Robbert Krebbers authored
      - Make the carrier argument of the constructors for the canonical structures
        cofeT and cmraT explicit. This way we make sure the carrier is properly
        exposed, instead of some alias of the carrier.
      - Make derived constructions (such as discreteC and discreteR) notations
        instead of definitions. This is yet again to make sure that the carrier is
        properly exposed.
      - Turn DRA into a canonical structure (it used to be a type class).
      
      This fixes some issues, notably it fixes some broken rewrites in algebra/sts
      and it makes canonical structures work properly with dec_agree.
      a3d0a338
  33. Mar 11, 2016
Loading