automation.v 15.3 KB
Newer Older
Michael Sammler's avatar
Michael Sammler committed
1
2
3
From iris.proofmode Require Import coq_tactics reduction.
From refinedc.typing Require Export type.
From refinedc.lithium Require Export tactics.
4
From refinedc.typing.automation Require Export normalize solvers simplification proof_state loc_eq.
5
From refinedc.typing Require Import programs function singleton own struct bytes int.
Michael Sammler's avatar
Michael Sammler committed
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
Set Default Proof Using "Type".

(** * Registering extensions *)
(** More automation for modular arithmetics. *)
Ltac Zify.zify_post_hook ::= Z.to_euclidean_division_equations.

(** We use autorewrite for the moment. *)
Ltac normalize_tac ::= normalize_autorewrite.
(* Goal ∀ l i (x : Z), *)
(*     0 < length (<[i:=x]> $ <[i:=x]> (<[length (<[i:=x]>l) :=x]> l ++ <[length (<[i:=x]>l) :=x]> l)). *)
(*   move => ???. normalize_goal. *)
(* Abort. *)

Ltac li_pm_reduce_tac H ::= eval cbv [t2mt mt_type mt_movable] in H.

Ltac custom_exist_tac A protect ::=
    lazymatch A with
    | mtype =>
      lazymatch protect with
      | true => fail 1000 "cannot protect mtype"
      | false =>
      (* it is important that we don't trigger typeclass search here
      as we want to keep Movable as an evar, thus we use notypeclasses
      refine. *)
        notypeclasses refine (ex_intro _ (t2mt _) _)
      end
    | Movable _ => eexists _
    end.

35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
Hint Transparent ly_size : solve_protected_eq_db.
Ltac solve_protected_eq_unfold_tac ::=
  lazymatch goal with
  (* unfold constants for function types *)
  | |- @eq (_  fn_params) ?a (λ x, _) =>
    lazymatch a with
    | (λ x, _) => idtac
    | _ =>
      let h := get_head a in
      unfold h;
      (* necessary to reduce after unfolding because of the strict
      opaqueness settings for unification *)
      liSimpl
    end
  (* don't fail if nothing matches *)
  | |- _ => idtac
  end.

Michael Sammler's avatar
Michael Sammler committed
53
54
55
56
57
58
59
60
61
Ltac can_solve_tac ::= solve_goal.

Ltac record_destruct_hint hint info ::= add_case_distinction_info hint info.

Ltac convert_to_i2p_tac P ::=
  lazymatch P with
  | typed_value ?v ?T => uconstr:(((_ : TypedValue _) _).(i2p_proof))
  | typed_bin_op ?v1 ?ty1 ?v2 ?ty2 ?o ?ot1 ?ot2 ?T => uconstr:(((_ : TypedBinOp _ _ _ _ _ _ _) _).(i2p_proof))
  | typed_un_op ?v ?ty ?o ?ot ?T => uconstr:(((_ : TypedUnOp _ _ _ _) _).(i2p_proof))
62
  | typed_call ?v ?P ?vl ?tys ?T => uconstr:(((_ : TypedCall _ _ _ _) _).(i2p_proof))
63
  | typed_copy_alloc_id ?v1 ?ty1 ?v2 ?ty2 ?ot ?T => uconstr:(((_ : TypedCopyAllocId _ _ _ _ _) _).(i2p_proof))
Michael Sammler's avatar
Michael Sammler committed
64
  | typed_place ?P ?l1 ?β1 ?ty1 ?T => uconstr:(((_ : TypedPlace _ _ _ _) _).(i2p_proof))
Michael Sammler's avatar
Michael Sammler committed
65
  | typed_if ?ot ?v ?ty ?T1 ?T2 => uconstr:(((_ : TypedIf _ _ _) _ _).(i2p_proof))
66
  | typed_switch ?v ?ty ?it ?m ?ss ?def ?fn ?ls ?fr ?Q => uconstr:(((_ : TypedSwitch _ _ _) _ _ _ _ _ _ _).(i2p_proof))
67
  | typed_assert ?ot ?v ?ty ?s ?fn ?ls ?fr ?Q => uconstr:(((_ : TypedAssert _ _ _) _ _ _ _ _).(i2p_proof))
68
  | typed_read_end ?a ?l ?β ?ty ?ly ?T => uconstr:(((_ : TypedReadEnd _ _ _ _ _) _).(i2p_proof))
Michael Sammler's avatar
Michael Sammler committed
69
  | typed_write_end ?a ?ot ?v1 ?ty1 ?l2 ?β2 ?ty2 ?T => uconstr:(((_ : TypedWriteEnd _ _ _ _ _ _ _) _).(i2p_proof))
Michael Sammler's avatar
Michael Sammler committed
70
  | typed_addr_of_end ?l ?β ?ty ?T => uconstr:(((_ : TypedAddrOfEnd _ _ _) _).(i2p_proof))
Michael Sammler's avatar
Michael Sammler committed
71
  | typed_cas ?ot ?v1 ?P1 ?v2 ?P2 ?v3 ?P3 ?T => uconstr:(((_ : TypedCas _ _ _ _ _ _ _) _).(i2p_proof))
Michael Sammler's avatar
Michael Sammler committed
72
73
  | typed_annot_expr ?n ?a ?v ?P ?T => uconstr:(((_ : TypedAnnotExpr _ _ _ _) _) .(i2p_proof))
  | typed_annot_stmt ?a ?l ?P ?T => uconstr:(((_ : TypedAnnotStmt _ _ _) _).(i2p_proof))
Michael Sammler's avatar
Michael Sammler committed
74
  | typed_macro_expr ?m ?es ?T => uconstr:(((_ : TypedMacroExpr _ _) _).(i2p_proof))
Michael Sammler's avatar
Michael Sammler committed
75
76
77
78
79
80
  end.

(** * Main automation tactics *)
Section automation.
  Context `{!typeG Σ}.

81
82
83
  Lemma tac_simpl_subst xs s fn ls Q R:
    typed_stmt (W.to_stmt (W.subst_stmt xs s)) fn ls R Q -
    typed_stmt (subst_stmt xs (W.to_stmt s)) fn ls R Q.
Michael Sammler's avatar
Michael Sammler committed
84
85
  Proof. by rewrite W.to_stmt_subst. Qed.

86
  Lemma tac_typed_single_block_rec P b Q fn ls R s:
Michael Sammler's avatar
Michael Sammler committed
87
    Q !! b = Some s 
88
89
    (P  accu (λ A, typed_block (P  A) b fn ls R Q - P - A - typed_stmt s fn ls R Q)) -
    typed_stmt (Goto b) fn ls R Q.
Michael Sammler's avatar
Michael Sammler committed
90
91
92
93
94
95
96
97
98
99
100
101
102
103
  Proof.
    iIntros (HQ) "[HP Hs]". iIntros (Hls). unfold accu, typed_block.
    iDestruct "Hs" as (A) "[HA #Hs]". iLöb as "Hl".
    iApply wps_goto =>//. iModIntro. iApply ("Hs" with "[] HP HA") => //.
    iIntros "!# [HP HA]". by iApply ("Hl" with "HP HA").
  Qed.
End automation.

Ltac liRIntroduceLetInGoal :=
  lazymatch goal with
  | |- @envs_entails ?PROP ?Δ ?P =>
    let H := fresh "GOAL" in
    lazymatch P with
    | @bi_wand ?PROP ?Q ?T =>
104
      pose H := (LET_ID T); change_no_check (@envs_entails PROP Δ (@bi_wand PROP Q H))
Michael Sammler's avatar
Michael Sammler committed
105
    | @typed_val_expr ?Σ ?tG ?e ?T =>
106
      pose (H := LET_ID T); change_no_check (@envs_entails PROP Δ (@typed_val_expr Σ tG e H))
Michael Sammler's avatar
Michael Sammler committed
107
108
    | @typed_write ?Σ ?tG ?b ?e ?ot ?v ?ty ?Mov ?T =>
      pose (H := LET_ID T); change_no_check (@envs_entails PROP Δ (@typed_write Σ tG b e ot v ty Mov H))
Michael Sammler's avatar
Michael Sammler committed
109
    | @typed_place ?Σ ?tG ?P ?l1 ?β1 ?ty1 ?T =>
110
      pose (H := LET_ID T); change_no_check (@envs_entails PROP Δ (@typed_place Σ tG P l1 β1 ty1 H))
Michael Sammler's avatar
Michael Sammler committed
111
    | @typed_bin_op ?Σ ?tG ?v1 ?P1 ?v2 ?P2 ?op ?ot1 ?ot2 ?T =>
112
      pose (H := LET_ID T); change_no_check (@envs_entails PROP Δ (@typed_bin_op Σ tG v1 P1 v2 P2 op ot1 ot2 H))
Michael Sammler's avatar
Michael Sammler committed
113
114
115
    end
  end.

Michael Sammler's avatar
Michael Sammler committed
116
Ltac liRInstantiateEvars_hook := idtac.
Michael Sammler's avatar
Michael Sammler committed
117
Ltac liRInstantiateEvars :=
Michael Sammler's avatar
Michael Sammler committed
118
  liRInstantiateEvars_hook;
Michael Sammler's avatar
Michael Sammler committed
119
  lazymatch goal with
Michael Sammler's avatar
Michael Sammler committed
120
121
122
123
124
  | |- (_ < protected ?H)%nat  _ =>
    (* We would like to use [liInst H (S (protected (EVAR_ID _)))],
      but this causes a Error: No such section variable or assumption
      at Qed. time. Maybe this is related to https://github.com/coq/coq/issues/9937 *)
    instantiate_protected (protected H) ltac:(fun H => instantiate (1:=((S (protected (EVAR_ID _))))) in (Value of H))
Michael Sammler's avatar
Michael Sammler committed
125
126
127
128
  (* This is very hard to figure out for unification because of the
  dependent types in with refinement. Unificaiton likes to unfold the
  definition of ty without this. This is the reason why do_instantiate
  evars must come before do_side_cond *)
Michael Sammler's avatar
Michael Sammler committed
129
130
131
132
  | |- protected ?H = ( _ @ ?ty)%I  _ =>
    instantiate_protected (protected H) ltac:(fun H => instantiate (1:=((protected (EVAR_ID _)) @ ty)%I) in (Value of H))
  | |- protected ?H = ty_of_rty (frac_ptr ?β _)%I  _ =>
    instantiate_protected (protected H) ltac:(fun H => instantiate (1:=((frac_ptr β (protected (EVAR_ID _)))%I)) in (Value of H))
Michael Sammler's avatar
Michael Sammler committed
133
134
135
136
137
138
139
140
141
142
  | |- envs_entails _ (subsume (?x ◁ₗ{?β} ?ty) (_ ◁ₗ{_} (protected ?H)) _) => liInst H ty
  | |- envs_entails _ (subsume (?x ◁ₗ{?β} ?ty) (_ ◁ₗ{protected ?H} _) _) => liInst H β
  end.

Ltac liRStmt :=
  lazymatch goal with
  | |- envs_entails ?Δ (typed_stmt ?s ?fn ?ls ?fr ?Q) =>
    lazymatch s with
    | LocInfo ?info ?s2 =>
      update_loc_info (Some info);
143
      change_no_check (envs_entails Δ (typed_stmt s2 fn ls fr Q))
Michael Sammler's avatar
Michael Sammler committed
144
145
146
147
148
149
    | _ => update_loc_info (None : option location_info)
    end
  end;
  lazymatch goal with
  | |- envs_entails ?Δ (typed_stmt ?s ?fn ?ls ?fr ?Q) =>
    lazymatch s with
Michael Sammler's avatar
Michael Sammler committed
150
    | subst_stmt ?xs ?s =>
Michael Sammler's avatar
Michael Sammler committed
151
      let s' := W.of_stmt s in
Michael Sammler's avatar
Michael Sammler committed
152
153
      change (subst_stmt xs s) with (subst_stmt xs (W.to_stmt s'));
      refine (tac_fast_apply (tac_simpl_subst _ _ _ _ _ _) _); simpl; unfold W.to_stmt, W.to_expr
Michael Sammler's avatar
Michael Sammler committed
154
155
156
157
158
    | _ =>
      let s' := W.of_stmt s in
      lazymatch s' with
      | W.Assign _ _ _ _ _ => notypeclasses refine (tac_fast_apply (type_assign _ _ _ _ _ _ _ _ _) _)
      | W.Return _ => notypeclasses refine (tac_fast_apply (type_return _ _ _ _ _) _)
159
      | W.IfS _ _ _ _ => notypeclasses refine (tac_fast_apply (type_if _ _ _ _ _ _ _ _) _)
Michael Sammler's avatar
Michael Sammler committed
160
      | W.Switch _ _ _ _ _ => notypeclasses refine (tac_fast_apply (type_switch _ _ _ _ _ _ _ _ _) _)
161
      | W.Assert _ _ _ => notypeclasses refine (tac_fast_apply (type_assert _ _ _ _ _ _ _) _)
Michael Sammler's avatar
Michael Sammler committed
162
      | W.Goto ?bid => first [
163
         notypeclasses refine (tac_fast_apply (type_goto_precond _ _ _ _ _ _) _); progress liFindHyp FICSyntactic
Michael Sammler's avatar
Michael Sammler committed
164
165
       | lazymatch goal with
         | H : BLOCK_PRECOND bid ?P |- _ =>
166
           notypeclasses refine (tac_fast_apply (tac_typed_single_block_rec P _ _ _ _ _ _ _) _);[unfold_code_marker_and_compute_map_lookup|]
Michael Sammler's avatar
Michael Sammler committed
167
         end
168
       | notypeclasses refine (tac_fast_apply (type_goto _ _ _ _ _ _ _) _); [unfold_code_marker_and_compute_map_lookup|]
Michael Sammler's avatar
Michael Sammler committed
169
170
171
172
173
174
175
176
177
                     ]
      | W.ExprS _ _ => notypeclasses refine (tac_fast_apply (type_exprs _ _ _ _ _ _) _)
      | W.SkipS _ => notypeclasses refine (tac_fast_apply (type_skips' _ _ _ _ _) _)
      | W.AnnotStmt _ ?a _ => notypeclasses refine (tac_fast_apply (type_annot_stmt _ _ _ _ _ _ _) _)
      | _ => fail "do_stmt: unknown stmt" s
      end
    end
  end.

178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
Ltac liRIntroduceTypedStmt :=
  lazymatch goal with
  | |- @envs_entails ?PROP ?Δ (introduce_typed_stmt ?fn ?ls ?R) =>
    iEval (rewrite /introduce_typed_stmt !fmap_insert fmap_empty; simpl_subst);
      lazymatch goal with
      | |- @envs_entails ?PROP ?Δ (@typed_stmt ?Σ ?tG ?s ?fn ?ls ?R ?Q) =>
        let HQ := fresh "Q" in
        let HR := fresh "R" in
        pose (HQ := (CODE_MARKER Q));
        pose (HR := (RETURN_MARKER R));
        change_no_check (@envs_entails PROP Δ (@typed_stmt Σ tG s fn ls HR HQ));
        iEval (simpl) (* To simplify f_init *)
      end
  end.

Michael Sammler's avatar
Michael Sammler committed
193
194
195
196
197
Ltac liRPopLocationInfo :=
  lazymatch goal with
  (* TODO: don't hardcode this for two arguments *)
  | |- envs_entails ?Δ (pop_location_info ?info ?T ?a1 ?a2) =>
    update_loc_info [info; info];
198
    change_no_check (envs_entails Δ (T a1 a2))
Michael Sammler's avatar
Michael Sammler committed
199
200
201
202
203
204
205
206
  end.

Ltac liRExpr :=
  lazymatch goal with
  | |- envs_entails ?Δ (typed_val_expr ?e ?T) =>
    lazymatch e with
    | LocInfo ?info ?e2 =>
      update_loc_info [info];
207
      change_no_check (envs_entails Δ (typed_val_expr e2 (pop_location_info info T)))
Michael Sammler's avatar
Michael Sammler committed
208
209
210
211
212
213
214
215
216
    | _ => idtac
    end
  end;
  lazymatch goal with
  | |- envs_entails ?Δ (typed_val_expr ?e ?T) =>
    let e' := W.of_expr e in
    lazymatch e' with
    | W.Val _ => notypeclasses refine (tac_fast_apply (type_val _ _) _)
    | W.Loc _ => notypeclasses refine (tac_fast_apply (type_val _ _) _)
217
    | W.Use _ _ _ => notypeclasses refine (tac_fast_apply (type_use _ _ _ _) _)
Michael Sammler's avatar
Michael Sammler committed
218
219
    | W.AddrOf _ => notypeclasses refine (tac_fast_apply (type_addr_of _ _) _)
    | W.BinOp _ _ _ _ _ => notypeclasses refine (tac_fast_apply (type_bin_op _ _ _ _ _ _) _)
220
    | W.CopyAllocId _ _ _ => notypeclasses refine (tac_fast_apply (type_copy_alloc_id _ _ _ _) _)
Michael Sammler's avatar
Michael Sammler committed
221
222
    | W.UnOp _ _ _ => notypeclasses refine (tac_fast_apply (type_un_op _ _ _ _) _)
    | W.CAS _ _ _ _ => notypeclasses refine (tac_fast_apply (type_cas _ _ _ _ _) _)
223
    | W.Call _ _ => notypeclasses refine (tac_fast_apply (type_call _ _ _) _)
224
    | W.OffsetOf _ _ => notypeclasses refine (tac_fast_apply (type_offset_of _ _ _) _)
Michael Sammler's avatar
Michael Sammler committed
225
226
    | W.AnnotExpr _ ?a _ => notypeclasses refine (tac_fast_apply (type_annot_expr _ _ _ _) _)
    | W.StructInit _ _ => notypeclasses refine (tac_fast_apply (type_struct_init _ _ _) _)
Michael Sammler's avatar
Michael Sammler committed
227
    | W.IfE _ _ _ _ => notypeclasses refine (tac_fast_apply (type_ife _ _ _ _ _) _)
228
229
    | W.LogicalAnd _ _ _ _ => notypeclasses refine (tac_fast_apply (type_logical_and _ _ _ _ _) _)
    | W.LogicalOr _ _ _ _ => notypeclasses refine (tac_fast_apply (type_logical_or _ _ _ _ _) _)
Michael Sammler's avatar
Michael Sammler committed
230
    | W.SkipE _ => notypeclasses refine (tac_fast_apply (type_skipe' _ _) _)
Michael Sammler's avatar
Michael Sammler committed
231
    | W.MacroE _ _ _ => notypeclasses refine (tac_fast_apply (type_macro_expr _ _ _) _)
Michael Sammler's avatar
Michael Sammler committed
232
233
234
235
236
237
    | _ => fail "do_expr: unknown expr" e
    end
  end.

Ltac liRJudgement :=
  lazymatch goal with
238
    | |- envs_entails _ (typed_write _ _ _ _ _ _) => notypeclasses refine (tac_fast_apply (type_write _ _ _ _ _ _ _ _) _); [ solve [refine _ ] |]
239
    | |- envs_entails _ (typed_read _ _ _ _) => notypeclasses refine (tac_fast_apply (type_read _ _ _ _ _ _) _); [ solve [refine _ ] |]
Michael Sammler's avatar
Michael Sammler committed
240
241
242
243
244
    | |- envs_entails _ (typed_addr_of _ _) => notypeclasses refine (tac_fast_apply (type_addr_of_place _ _ _ _) _); [solve [refine _] |]
  end.

(* This does everything *)
Ltac liRStep :=
245
 liEnforceInvariantAndUnfoldInstantiatedEvars;
Michael Sammler's avatar
Michael Sammler committed
246
247
248
249
250
 try liRIntroduceLetInGoal;
 first [
   liRInstantiateEvars (* must be before do_side_cond and do_extensible_judgement *)
 | liRPopLocationInfo
 | liRStmt
251
 | liRIntroduceTypedStmt
Michael Sammler's avatar
Michael Sammler committed
252
253
254
255
256
 | liRExpr
 | liRJudgement
 | liStep
]; liSimpl.

Michael Sammler's avatar
Michael Sammler committed
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
Tactic Notation "liRStepUntil" open_constr(id) :=
  repeat lazymatch goal with
         | |- @environments.envs_entails _ _ ?P =>
           lazymatch P with
           | id _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ => fail
           | id _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ => fail
           | id _ _ _ _ _ _ _ _ _ _ _ _ _ _ => fail
           | id _ _ _ _ _ _ _ _ _ _ _ _ _ => fail
           | id _ _ _ _ _ _ _ _ _ _ _ _ => fail
           | id _ _ _ _ _ _ _ _ _ _ _ => fail
           | id _ _ _ _ _ _ _ _ _ _ => fail
           | id _ _ _ _ _ _ _ _ _ => fail
           | id _ _ _ _ _ _ _ _ => fail
           | id _ _ _ _ _ _ _ => fail
           | id _ _ _ _ _ _ => fail
           | id _ _ _ _ _ => fail
           | id _ _ _ _ => fail
           | id _ _ => fail
           | id _ => fail
           | id => fail
           | _  => liRStep
           end
         | _ => liRStep
  end; liShow.


Michael Sammler's avatar
Michael Sammler committed
283
(** * Tactics for starting a function *)
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
(* Recursively destruct a product in hypothesis H, using the given name as template. *)
Ltac destruct_product_hypothesis name H :=
  match goal with
  | H : _ * _ |- _ => let tmp1 := fresh "tmp" in
                      let tmp2 := fresh "tmp" in
                      destruct H as [tmp1 tmp2];
                      destruct_product_hypothesis name tmp1;
                      destruct_product_hypothesis name tmp2
  |           |- _ => let id := fresh name in
                      rename H into id
  end.

Ltac prepare_initial_coq_context :=
  (* The automation assumes that all products in the context are destructed, see liForall *)
  repeat lazymatch goal with
  | H : _ * _ |- _ => destruct_product_hypothesis H H
  | H : unit |- _ => destruct H
  end.

Michael Sammler's avatar
Michael Sammler committed
303
304
305
306
(* IMPORTANT: We need to make sure to never call simpl while the code
(Q) is part of the goal, because simpl seems to take exponential time
in the number of blocks! *)
(* TODO: don't use i... tactics here *)
Michael Sammler's avatar
Michael Sammler committed
307
Tactic Notation "start_function" constr(fnname) "(" simple_intropattern(x) ")" :=
Michael Sammler's avatar
Michael Sammler committed
308
309
310
311
  intros;
  repeat iIntros "#?";
  rewrite /typed_function;
  iIntros ( x );
Michael Sammler's avatar
Michael Sammler committed
312
  iSplit; [iPureIntro; simpl; by [repeat constructor] || fail "in" fnname "argument types don't match layout of arguments" |];
Michael Sammler's avatar
Michael Sammler committed
313
  let lsa := fresh "lsa" in let lsv := fresh "lsv" in
314
  iIntros "!#" (lsa lsv); inv_vec lsv; inv_vec lsa; prepare_initial_coq_context.
Michael Sammler's avatar
Michael Sammler committed
315
316
317

Ltac liRSplitBlocksIntro :=
  repeat (
318
      liEnforceInvariantAndUnfoldInstantiatedEvars;
Michael Sammler's avatar
Michael Sammler committed
319
320
321
322
323
324
325
326
327
328
329
330
331
      first [
          liSep
        | liWand
        | liImpl
        | liForall
        | liExist true
        | liUnfoldLetGoal]; liSimpl);
  liShow.

(* TODO: don't use i... tactics here *)
Ltac split_blocks Pfull Ps :=
  (* cbn in * is important here to simplify the types of local
  variables, otherwise unification gets confused later *)
332
  cbn -[union] in *;
Michael Sammler's avatar
Michael Sammler committed
333
334
335
336
337
338
339
340
341
342
343
344
345
346
347
  let rec pose_Ps Ps :=
      lazymatch Ps with
      | <[?bid:=?P]>?m =>
        let Hblock := fresh "Hblock" in
        have Hblock: (BLOCK_PRECOND bid P) by exact: tt;
        pose_Ps m
      | _ => idtac
      end
  in
  pose_Ps Ps;
  let Hfull := fresh "Hfull" in
  (* We must do this pose first since do_split_block_intro might call
  subst and we want to subst in Ps as well. *)
  pose (Hfull := Pfull);
  liRSplitBlocksIntro;
348
  liRIntroduceTypedStmt;
Michael Sammler's avatar
Michael Sammler committed
349
350
  iApply (typed_block_rec Hfull); unfold Hfull; clear Hfull; last first; [|
  repeat (iApply big_sepM_insert; [reflexivity|]; iSplitL); last by [iApply big_sepM_empty];
351
  iExists _; (iSplitR; [iPureIntro; unfold_code_marker_and_compute_map_lookup|]); iModIntro ];
Michael Sammler's avatar
Michael Sammler committed
352
  repeat (iApply tac_split_big_sepM; [reflexivity|]; iIntros "?"); iIntros "_".