automation.v 15.5 KB
Newer Older
Michael Sammler's avatar
Michael Sammler committed
1
2
3
From iris.proofmode Require Import coq_tactics reduction.
From refinedc.typing Require Export type.
From refinedc.lithium Require Export tactics.
4
From refinedc.typing.automation Require Export normalize solvers simplification proof_state loc_eq.
5
From refinedc.typing Require Import programs function singleton own struct bytes int.
Michael Sammler's avatar
Michael Sammler committed
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
Set Default Proof Using "Type".

(** * Registering extensions *)
(** We use autorewrite for the moment. *)
Ltac normalize_tac ::= normalize_autorewrite.
(* Goal ∀ l i (x : Z), *)
(*     0 < length (<[i:=x]> $ <[i:=x]> (<[length (<[i:=x]>l) :=x]> l ++ <[length (<[i:=x]>l) :=x]> l)). *)
(*   move => ???. normalize_goal. *)
(* Abort. *)

Ltac li_pm_reduce_tac H ::= eval cbv [t2mt mt_type mt_movable] in H.

Ltac custom_exist_tac A protect ::=
    lazymatch A with
    | mtype =>
      lazymatch protect with
      | true => fail 1000 "cannot protect mtype"
      | false =>
      (* it is important that we don't trigger typeclass search here
      as we want to keep Movable as an evar, thus we use notypeclasses
      refine. *)
        notypeclasses refine (ex_intro _ (t2mt _) _)
      end
    | Movable _ => eexists _
    end.

Michael Sammler's avatar
Michael Sammler committed
32
Global Hint Transparent ly_size : solve_protected_eq_db.
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
Ltac solve_protected_eq_unfold_tac ::=
  lazymatch goal with
  (* unfold constants for function types *)
  | |- @eq (_  fn_params) ?a (λ x, _) =>
    lazymatch a with
    | (λ x, _) => idtac
    | _ =>
      let h := get_head a in
      unfold h;
      (* necessary to reduce after unfolding because of the strict
      opaqueness settings for unification *)
      liSimpl
    end
  (* don't fail if nothing matches *)
  | |- _ => idtac
  end.

Michael Sammler's avatar
fix    
Michael Sammler committed
50
Ltac unfold_let_goal_tac H ::=
Michael Sammler's avatar
Michael Sammler committed
51
52
  unfold RETURN_MARKER in H.

Michael Sammler's avatar
Michael Sammler committed
53
54
55
56
Ltac can_solve_tac ::= solve_goal.

Ltac record_destruct_hint hint info ::= add_case_distinction_info hint info.

Michael Sammler's avatar
Michael Sammler committed
57
Ltac convert_to_i2p_tac P bind cont ::=
Michael Sammler's avatar
Michael Sammler committed
58
  lazymatch P with
Michael Sammler's avatar
Michael Sammler committed
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
  | typed_value ?v ?T =>
      bind T ltac:(fun H => uconstr:(typed_value v H));
      cont uconstr:(((_ : TypedValue _) _))
  | typed_bin_op ?v1 ?ty1 ?v2 ?ty2 ?o ?ot1 ?ot2 ?T =>
      bind T ltac:(fun H => uconstr:(typed_bin_op v1 ty1 v2 ty2 o ot1 ot2 H));
      cont uconstr:(((_ : TypedBinOp _ _ _ _ _ _ _) _))
  | typed_un_op ?v ?ty ?o ?ot ?T =>
      bind T ltac:(fun H => uconstr:(typed_un_op ?v ?ty ?o ?ot H));
      cont uconstr:(((_ : TypedUnOp _ _ _ _) _))
  | typed_call ?v ?P ?vl ?tys ?T =>
      bind T ltac:(fun H => uconstr:(typed_call v P vl tys H));
      cont uconstr:(((_ : TypedCall _ _ _ _) _))
  | typed_copy_alloc_id ?v1 ?ty1 ?v2 ?ty2 ?ot ?T =>
      bind T ltac:(fun H => uconstr:(typed_copy_alloc_id v1 ty1 v2 ty2 ot H));
      cont uconstr:(((_ : TypedCopyAllocId _ _ _ _ _) _))
  | typed_place ?P ?l1 ?β1 ?ty1 ?T =>
      bind T ltac:(fun H => uconstr:(typed_place P l1 β1 ty1 H));
      cont uconstr:(((_ : TypedPlace _ _ _ _) _))
  | typed_if ?ot ?v ?P ?T1 ?T2 =>
      cont uconstr:(((_ : TypedIf _ _ _) _ _))
  | typed_switch ?v ?ty ?it ?m ?ss ?def ?fn ?ls ?fr ?Q =>
      cont uconstr:(((_ : TypedSwitch _ _ _) _ _ _ _ _ _ _))
  | typed_assert ?ot ?v ?ty ?s ?fn ?ls ?fr ?Q =>
      cont uconstr:(((_ : TypedAssert _ _ _) _ _ _ _ _))
  | typed_read_end ?a ?E ?l ?β ?ty ?ly ?T =>
      bind T ltac:(fun H => uconstr:(typed_read_end a E l β ty ly H ));
      cont uconstr:(((_ : TypedReadEnd _ _ _ _ _ _) _))
  | typed_write_end ?a ?E ?ot ?v1 ?ty1 ?l2 ?β2 ?ty2 ?T =>
      bind T ltac:(fun H => uconstr:(typed_write_end a E ot v1 ty1 l2 β2 ty2 H ));
      cont uconstr:(((_ : TypedWriteEnd _ _ _ _ _ _ _ _) _))
  | typed_addr_of_end ?l ?β ?ty ?T =>
      bind T ltac:(fun H => uconstr:(typed_addr_of_end l β ty H));
      cont uconstr:(((_ : TypedAddrOfEnd _ _ _) _))
  | typed_cas ?ot ?v1 ?P1 ?v2 ?P2 ?v3 ?P3 ?T =>
      bind T ltac:(fun H => uconstr:(typed_cas ot v1 P1 v2 P2 v3 P3 H ));
      cont uconstr:(((_ : TypedCas _ _ _ _ _ _ _) _))
  | typed_annot_expr ?n ?a ?v ?P ?T =>
      bind T ltac:(fun H => uconstr:(typed_annot_expr n a v P H ));
      cont uconstr:(((_ : TypedAnnotExpr _ _ _ _) _) )
  | typed_annot_stmt ?a ?l ?P ?T =>
      bind T ltac:(fun H => uconstr:(typed_annot_stmt a l P H ));
      cont uconstr:(((_ : TypedAnnotStmt _ _ _) _))
  | typed_macro_expr ?m ?es ?T =>
      bind T ltac:(fun H => uconstr:(typed_macro_expr m es H ));
      cont uconstr:(((_ : TypedMacroExpr _ _) _))
Michael Sammler's avatar
Michael Sammler committed
104
105
106
107
108
109
  end.

(** * Main automation tactics *)
Section automation.
  Context `{!typeG Σ}.

110
111
112
  Lemma tac_simpl_subst xs s fn ls Q R:
    typed_stmt (W.to_stmt (W.subst_stmt xs s)) fn ls R Q -
    typed_stmt (subst_stmt xs (W.to_stmt s)) fn ls R Q.
Michael Sammler's avatar
Michael Sammler committed
113
114
  Proof. by rewrite W.to_stmt_subst. Qed.

115
  Lemma tac_typed_single_block_rec P b Q fn ls R s:
Michael Sammler's avatar
Michael Sammler committed
116
    Q !! b = Some s 
117
118
    (P  accu (λ A, typed_block (P  A) b fn ls R Q - P - A - typed_stmt s fn ls R Q)) -
    typed_stmt (Goto b) fn ls R Q.
Michael Sammler's avatar
Michael Sammler committed
119
120
121
122
123
124
125
126
127
128
129
130
  Proof.
    iIntros (HQ) "[HP Hs]". iIntros (Hls). unfold accu, typed_block.
    iDestruct "Hs" as (A) "[HA #Hs]". iLöb as "Hl".
    iApply wps_goto =>//. iModIntro. iApply ("Hs" with "[] HP HA") => //.
    iIntros "!# [HP HA]". by iApply ("Hl" with "HP HA").
  Qed.
End automation.

Ltac liRIntroduceLetInGoal :=
  lazymatch goal with
  | |- @envs_entails ?PROP ?Δ ?P =>
    lazymatch P with
131
132
    (* | @bi_wand ?PROP ?Q ?T => *)
      (* li_let_bind T (fun H => constr:(@envs_entails PROP Δ (@bi_wand PROP Q H))) *)
Michael Sammler's avatar
Michael Sammler committed
133
    | @typed_val_expr ?Σ ?tG ?e ?T =>
134
      li_let_bind T (fun H => constr:(@envs_entails PROP Δ (@typed_val_expr Σ tG e H)))
Michael Sammler's avatar
Michael Sammler committed
135
    | @typed_write ?Σ ?tG ?b ?e ?ot ?v ?ty ?Mov ?T =>
136
      li_let_bind T (fun H => constr:(@envs_entails PROP Δ (@typed_write Σ tG b e ot v ty Mov H)))
Michael Sammler's avatar
Michael Sammler committed
137
138
139
140
    (* | @typed_place ?Σ ?tG ?P ?l1 ?β1 ?ty1 ?T => *)
    (*   li_let_bind T (fun H => constr:(@envs_entails PROP Δ (@typed_place Σ tG P l1 β1 ty1 H))) *)
    (* | @typed_bin_op ?Σ ?tG ?v1 ?P1 ?v2 ?P2 ?op ?ot1 ?ot2 ?T => *)
    (*   li_let_bind T (fun H => constr:(@envs_entails PROP Δ (@typed_bin_op Σ tG v1 P1 v2 P2 op ot1 ot2 H))) *)
Michael Sammler's avatar
Michael Sammler committed
141
142
143
    end
  end.

Michael Sammler's avatar
Michael Sammler committed
144
Ltac liRInstantiateEvars_hook := idtac.
Michael Sammler's avatar
Michael Sammler committed
145
Ltac liRInstantiateEvars :=
Michael Sammler's avatar
Michael Sammler committed
146
  liRInstantiateEvars_hook;
Michael Sammler's avatar
Michael Sammler committed
147
  lazymatch goal with
Michael Sammler's avatar
Michael Sammler committed
148
149
150
151
152
  | |- (_ < protected ?H)%nat  _ =>
    (* We would like to use [liInst H (S (protected (EVAR_ID _)))],
      but this causes a Error: No such section variable or assumption
      at Qed. time. Maybe this is related to https://github.com/coq/coq/issues/9937 *)
    instantiate_protected (protected H) ltac:(fun H => instantiate (1:=((S (protected (EVAR_ID _))))) in (Value of H))
Michael Sammler's avatar
Michael Sammler committed
153
154
155
156
  (* This is very hard to figure out for unification because of the
  dependent types in with refinement. Unificaiton likes to unfold the
  definition of ty without this. This is the reason why do_instantiate
  evars must come before do_side_cond *)
Michael Sammler's avatar
Michael Sammler committed
157
158
159
160
  | |- protected ?H = ( _ @ ?ty)%I  _ =>
    instantiate_protected (protected H) ltac:(fun H => instantiate (1:=((protected (EVAR_ID _)) @ ty)%I) in (Value of H))
  | |- protected ?H = ty_of_rty (frac_ptr ?β _)%I  _ =>
    instantiate_protected (protected H) ltac:(fun H => instantiate (1:=((frac_ptr β (protected (EVAR_ID _)))%I)) in (Value of H))
Michael Sammler's avatar
Michael Sammler committed
161
162
163
164
165
166
167
168
169
170
  | |- envs_entails _ (subsume (?x ◁ₗ{?β} ?ty) (_ ◁ₗ{_} (protected ?H)) _) => liInst H ty
  | |- envs_entails _ (subsume (?x ◁ₗ{?β} ?ty) (_ ◁ₗ{protected ?H} _) _) => liInst H β
  end.

Ltac liRStmt :=
  lazymatch goal with
  | |- envs_entails ?Δ (typed_stmt ?s ?fn ?ls ?fr ?Q) =>
    lazymatch s with
    | LocInfo ?info ?s2 =>
      update_loc_info (Some info);
171
      change_no_check (envs_entails Δ (typed_stmt s2 fn ls fr Q))
Michael Sammler's avatar
Michael Sammler committed
172
173
174
175
176
177
    | _ => update_loc_info (None : option location_info)
    end
  end;
  lazymatch goal with
  | |- envs_entails ?Δ (typed_stmt ?s ?fn ?ls ?fr ?Q) =>
    lazymatch s with
Michael Sammler's avatar
Michael Sammler committed
178
    | subst_stmt ?xs ?s =>
Michael Sammler's avatar
Michael Sammler committed
179
      let s' := W.of_stmt s in
Michael Sammler's avatar
Michael Sammler committed
180
181
      change (subst_stmt xs s) with (subst_stmt xs (W.to_stmt s'));
      refine (tac_fast_apply (tac_simpl_subst _ _ _ _ _ _) _); simpl; unfold W.to_stmt, W.to_expr
Michael Sammler's avatar
Michael Sammler committed
182
183
184
185
186
    | _ =>
      let s' := W.of_stmt s in
      lazymatch s' with
      | W.Assign _ _ _ _ _ => notypeclasses refine (tac_fast_apply (type_assign _ _ _ _ _ _ _ _ _) _)
      | W.Return _ => notypeclasses refine (tac_fast_apply (type_return _ _ _ _ _) _)
187
      | W.IfS _ _ _ _ => notypeclasses refine (tac_fast_apply (type_if _ _ _ _ _ _ _ _) _)
Michael Sammler's avatar
Michael Sammler committed
188
      | W.Switch _ _ _ _ _ => notypeclasses refine (tac_fast_apply (type_switch _ _ _ _ _ _ _ _ _) _)
189
      | W.Assert _ _ _ => notypeclasses refine (tac_fast_apply (type_assert _ _ _ _ _ _ _) _)
Michael Sammler's avatar
Michael Sammler committed
190
      | W.Goto ?bid => first [
191
         notypeclasses refine (tac_fast_apply (type_goto_precond _ _ _ _ _ _) _); progress liFindHyp FICSyntactic
Michael Sammler's avatar
Michael Sammler committed
192
193
       | lazymatch goal with
         | H : BLOCK_PRECOND bid ?P |- _ =>
194
           notypeclasses refine (tac_fast_apply (tac_typed_single_block_rec P _ _ _ _ _ _ _) _);[unfold_code_marker_and_compute_map_lookup|]
Michael Sammler's avatar
Michael Sammler committed
195
         end
196
       | notypeclasses refine (tac_fast_apply (type_goto _ _ _ _ _ _ _) _); [unfold_code_marker_and_compute_map_lookup|]
Michael Sammler's avatar
Michael Sammler committed
197
198
199
200
201
202
203
204
205
                     ]
      | W.ExprS _ _ => notypeclasses refine (tac_fast_apply (type_exprs _ _ _ _ _ _) _)
      | W.SkipS _ => notypeclasses refine (tac_fast_apply (type_skips' _ _ _ _ _) _)
      | W.AnnotStmt _ ?a _ => notypeclasses refine (tac_fast_apply (type_annot_stmt _ _ _ _ _ _ _) _)
      | _ => fail "do_stmt: unknown stmt" s
      end
    end
  end.

206
207
208
209
210
211
212
213
214
Ltac liRIntroduceTypedStmt :=
  lazymatch goal with
  | |- @envs_entails ?PROP ?Δ (introduce_typed_stmt ?fn ?ls ?R) =>
    iEval (rewrite /introduce_typed_stmt !fmap_insert fmap_empty; simpl_subst);
      lazymatch goal with
      | |- @envs_entails ?PROP ?Δ (@typed_stmt ?Σ ?tG ?s ?fn ?ls ?R ?Q) =>
        let HQ := fresh "Q" in
        let HR := fresh "R" in
        pose (HQ := (CODE_MARKER Q));
Michael Sammler's avatar
Michael Sammler committed
215
        pose (HR := (RETURN_MARKER R));
216
217
218
219
220
        change_no_check (@envs_entails PROP Δ (@typed_stmt Σ tG s fn ls HR HQ));
        iEval (simpl) (* To simplify f_init *)
      end
  end.

Michael Sammler's avatar
Michael Sammler committed
221
222
223
224
225
Ltac liRPopLocationInfo :=
  lazymatch goal with
  (* TODO: don't hardcode this for two arguments *)
  | |- envs_entails ?Δ (pop_location_info ?info ?T ?a1 ?a2) =>
    update_loc_info [info; info];
226
    change_no_check (envs_entails Δ (T a1 a2))
Michael Sammler's avatar
Michael Sammler committed
227
228
229
230
231
232
233
234
  end.

Ltac liRExpr :=
  lazymatch goal with
  | |- envs_entails ?Δ (typed_val_expr ?e ?T) =>
    lazymatch e with
    | LocInfo ?info ?e2 =>
      update_loc_info [info];
235
      change_no_check (envs_entails Δ (typed_val_expr e2 (pop_location_info info T)))
Michael Sammler's avatar
Michael Sammler committed
236
237
238
239
240
241
242
243
244
    | _ => idtac
    end
  end;
  lazymatch goal with
  | |- envs_entails ?Δ (typed_val_expr ?e ?T) =>
    let e' := W.of_expr e in
    lazymatch e' with
    | W.Val _ => notypeclasses refine (tac_fast_apply (type_val _ _) _)
    | W.Loc _ => notypeclasses refine (tac_fast_apply (type_val _ _) _)
245
    | W.Use _ _ _ => notypeclasses refine (tac_fast_apply (type_use _ _ _ _) _)
Michael Sammler's avatar
Michael Sammler committed
246
247
    | W.AddrOf _ => notypeclasses refine (tac_fast_apply (type_addr_of _ _) _)
    | W.BinOp _ _ _ _ _ => notypeclasses refine (tac_fast_apply (type_bin_op _ _ _ _ _ _) _)
248
    | W.CopyAllocId _ _ _ => notypeclasses refine (tac_fast_apply (type_copy_alloc_id _ _ _ _) _)
Michael Sammler's avatar
Michael Sammler committed
249
250
    | W.UnOp _ _ _ => notypeclasses refine (tac_fast_apply (type_un_op _ _ _ _) _)
    | W.CAS _ _ _ _ => notypeclasses refine (tac_fast_apply (type_cas _ _ _ _ _) _)
251
    | W.Call _ _ => notypeclasses refine (tac_fast_apply (type_call _ _ _) _)
252
    | W.OffsetOf _ _ => notypeclasses refine (tac_fast_apply (type_offset_of _ _ _) _)
Michael Sammler's avatar
Michael Sammler committed
253
254
    | W.AnnotExpr _ ?a _ => notypeclasses refine (tac_fast_apply (type_annot_expr _ _ _ _) _)
    | W.StructInit _ _ => notypeclasses refine (tac_fast_apply (type_struct_init _ _ _) _)
Michael Sammler's avatar
Michael Sammler committed
255
    | W.IfE _ _ _ _ => notypeclasses refine (tac_fast_apply (type_ife _ _ _ _ _) _)
256
257
    | W.LogicalAnd _ _ _ _ _ => notypeclasses refine (tac_fast_apply (type_logical_and _ _ _ _ _) _)
    | W.LogicalOr _ _ _ _ _ => notypeclasses refine (tac_fast_apply (type_logical_or _ _ _ _ _) _)
Michael Sammler's avatar
Michael Sammler committed
258
    | W.SkipE _ => notypeclasses refine (tac_fast_apply (type_skipe' _ _) _)
Michael Sammler's avatar
Michael Sammler committed
259
    | W.MacroE _ _ _ => notypeclasses refine (tac_fast_apply (type_macro_expr _ _ _) _)
Michael Sammler's avatar
Michael Sammler committed
260
261
262
263
264
265
    | _ => fail "do_expr: unknown expr" e
    end
  end.

Ltac liRJudgement :=
  lazymatch goal with
266
    | |- envs_entails _ (typed_write _ _ _ _ _ _) => notypeclasses refine (tac_fast_apply (type_write _ _ _ _ _ _ _ _) _); [ solve [refine _ ] |]
267
    | |- envs_entails _ (typed_read _ _ _ _) => notypeclasses refine (tac_fast_apply (type_read _ _ _ _ _ _) _); [ solve [refine _ ] |]
Michael Sammler's avatar
Michael Sammler committed
268
269
270
271
272
    | |- envs_entails _ (typed_addr_of _ _) => notypeclasses refine (tac_fast_apply (type_addr_of_place _ _ _ _) _); [solve [refine _] |]
  end.

(* This does everything *)
Ltac liRStep :=
273
 liEnforceInvariantAndUnfoldInstantiatedEvars;
Michael Sammler's avatar
Michael Sammler committed
274
275
276
277
278
 try liRIntroduceLetInGoal;
 first [
   liRInstantiateEvars (* must be before do_side_cond and do_extensible_judgement *)
 | liRPopLocationInfo
 | liRStmt
279
 | liRIntroduceTypedStmt
Michael Sammler's avatar
Michael Sammler committed
280
281
282
283
284
 | liRExpr
 | liRJudgement
 | liStep
]; liSimpl.

Michael Sammler's avatar
Michael Sammler committed
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
303
304
305
306
307
308
309
310
Tactic Notation "liRStepUntil" open_constr(id) :=
  repeat lazymatch goal with
         | |- @environments.envs_entails _ _ ?P =>
           lazymatch P with
           | id _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ => fail
           | id _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ => fail
           | id _ _ _ _ _ _ _ _ _ _ _ _ _ _ => fail
           | id _ _ _ _ _ _ _ _ _ _ _ _ _ => fail
           | id _ _ _ _ _ _ _ _ _ _ _ _ => fail
           | id _ _ _ _ _ _ _ _ _ _ _ => fail
           | id _ _ _ _ _ _ _ _ _ _ => fail
           | id _ _ _ _ _ _ _ _ _ => fail
           | id _ _ _ _ _ _ _ _ => fail
           | id _ _ _ _ _ _ _ => fail
           | id _ _ _ _ _ _ => fail
           | id _ _ _ _ _ => fail
           | id _ _ _ _ => fail
           | id _ _ => fail
           | id _ => fail
           | id => fail
           | _  => liRStep
           end
         | _ => liRStep
  end; liShow.


Michael Sammler's avatar
Michael Sammler committed
311
312
313
314
315
(** * Tactics for starting a function *)
(* IMPORTANT: We need to make sure to never call simpl while the code
(Q) is part of the goal, because simpl seems to take exponential time
in the number of blocks! *)
(* TODO: don't use i... tactics here *)
Michael Sammler's avatar
Michael Sammler committed
316
Tactic Notation "start_function" constr(fnname) "(" simple_intropattern(x) ")" :=
Michael Sammler's avatar
Michael Sammler committed
317
318
319
320
  intros;
  repeat iIntros "#?";
  rewrite /typed_function;
  iIntros ( x );
Michael Sammler's avatar
Michael Sammler committed
321
  iSplit; [iPureIntro; simpl; by [repeat constructor] || fail "in" fnname "argument types don't match layout of arguments" |];
Michael Sammler's avatar
Michael Sammler committed
322
  let lsa := fresh "lsa" in let lsv := fresh "lsv" in
323
324
325
326
  iIntros "!#" (lsa lsv); inv_vec lsv; inv_vec lsa.

Tactic Notation "prepare_parameters" "(" ident_list(i) ")" :=
  revert i; repeat liForall.
Michael Sammler's avatar
Michael Sammler committed
327
328
329

Ltac liRSplitBlocksIntro :=
  repeat (
330
      liEnforceInvariantAndUnfoldInstantiatedEvars;
Michael Sammler's avatar
Michael Sammler committed
331
332
333
334
335
336
337
338
339
340
341
      first [
          liSep
        | liWand
        | liImpl
        | liForall
        | liExist true
        | liUnfoldLetGoal]; liSimpl);
  liShow.

(* TODO: don't use i... tactics here *)
Ltac split_blocks Pfull Ps :=
Michael Sammler's avatar
Michael Sammler committed
342
  (* cbn in *|- is important here to simplify the types of local
Michael Sammler's avatar
Michael Sammler committed
343
  variables, otherwise unification gets confused later *)
Michael Sammler's avatar
Michael Sammler committed
344
  cbn -[union] in * |-;
Michael Sammler's avatar
Michael Sammler committed
345
346
347
348
349
350
351
352
353
354
355
356
357
358
359
  let rec pose_Ps Ps :=
      lazymatch Ps with
      | <[?bid:=?P]>?m =>
        let Hblock := fresh "Hblock" in
        have Hblock: (BLOCK_PRECOND bid P) by exact: tt;
        pose_Ps m
      | _ => idtac
      end
  in
  pose_Ps Ps;
  let Hfull := fresh "Hfull" in
  (* We must do this pose first since do_split_block_intro might call
  subst and we want to subst in Ps as well. *)
  pose (Hfull := Pfull);
  liRSplitBlocksIntro;
360
  liRIntroduceTypedStmt;
Michael Sammler's avatar
Michael Sammler committed
361
362
  iApply (typed_block_rec Hfull); unfold Hfull; clear Hfull; last first; [|
  repeat (iApply big_sepM_insert; [reflexivity|]; iSplitL); last by [iApply big_sepM_empty];
363
  iExists _; (iSplitR; [iPureIntro; unfold_code_marker_and_compute_map_lookup|]); iModIntro ];
Michael Sammler's avatar
Michael Sammler committed
364
  repeat (iApply tac_split_big_sepM; [reflexivity|]; iIntros "?"); iIntros "_".