• Top
    • Documentation
    • Books
    • Boolean-reasoning
    • Projects
    • Debugging
    • Community
    • Std
    • Proof-automation
    • Macro-libraries
    • ACL2
    • Interfacing-tools
    • Hardware-verification
    • Software-verification
      • Kestrel-books
        • Crypto-hdwallet
        • Apt
        • Error-checking
        • Fty-extensions
        • Isar
        • Kestrel-utilities
        • Set
        • C
          • Syntax-for-tools
          • Atc
          • Transformation-tools
            • Simpadd0
            • Proof-generation
              • Xeq-fundef
              • Xeq-expr-cond
              • Xeq-expr-binary
              • Xeq-block-item-list-cons
              • Xeq-stmt-ifelse
              • Xeq-expr-const
              • Gen-param-thms
              • Gen-from-params
              • Xeq-decl-decl
              • Gout
              • Gen-block-item-list-thm
              • Xeq-stmt-while
              • Xeq-stmt-dowhile
                • Gin
                • Xeq-expr-ident
                • Gen-block-item-thm
                • Xeq-stmt-if
                • Xeq-expr-cast
                • Gen-initer-single-thm
                • Gen-init-scope-thm
                • Gen-expr-thm
                • Xeq-expr-unary
                • Gen-decl-thm
                • Gen-stmt-thm
                • Xeq-stmt-return
                • Xeq-stmt-expr
                • Xeq-block-item-decl
                • Xeq-block-item-stmt
                • Xeq-stmt-compound
                • Xeq-initer-single
                • Gen-thm-name
                • Gin-update
                • Gen-var-assertions
                • Tyspecseq-to-type
                • Xeq-block-item-list-empty
                • Gout-no-thm
                • Irr-gout
              • Split-gso
              • Wrap-fn
              • Constant-propagation
              • Specialize
              • Split-fn
              • Split-fn-when
              • Split-all-gso
              • Copy-fn
              • Variables-in-computation-states
              • Rename
              • Utilities
              • Proof-generation-theorems
              • Input-processing
            • Language
            • Representation
            • Insertion-sort
            • Pack
          • Soft
          • Bv
          • Imp-language
          • Ethereum
          • Event-macros
          • Java
          • Riscv
          • Bitcoin
          • Zcash
          • Yul
          • ACL2-programming-language
          • Prime-fields
          • Json
          • Syntheto
          • File-io-light
          • Cryptography
          • Number-theory
          • Axe
          • Lists-light
          • Builtins
          • Solidity
          • Helpers
          • Htclient
          • Typed-lists-light
          • Arithmetic-light
        • X86isa
        • Axe
        • Execloader
      • Math
      • Testing-utilities
    • Proof-generation

    Xeq-stmt-dowhile

    Equality lifting transformation of a do-while loop.

    Signature
    (xeq-stmt-dowhile body body-new body-thm-name 
                      test test-new test-thm-name gin) 
     
      → 
    (mv stmt gout)
    Arguments
    body — Guard (stmtp body).
    body-new — Guard (stmtp body-new).
    body-thm-name — Guard (symbolp body-thm-name).
    test — Guard (exprp test).
    test-new — Guard (exprp test-new).
    test-thm-name — Guard (symbolp test-thm-name).
    gin — Guard (ginp gin).
    Returns
    stmt — Type (stmtp stmt).
    gout — Type (goutp gout).

    Definitions and Theorems

    Function: xeq-stmt-dowhile

    (defun xeq-stmt-dowhile (body body-new body-thm-name
                                  test test-new test-thm-name gin)
     (declare (xargs :guard (and (stmtp body)
                                 (stmtp body-new)
                                 (symbolp body-thm-name)
                                 (exprp test)
                                 (exprp test-new)
                                 (symbolp test-thm-name)
                                 (ginp gin))))
     (declare (xargs :guard (and (stmt-unambp body)
                                 (stmt-annop body)
                                 (stmt-unambp body-new)
                                 (stmt-annop body-new)
                                 (expr-unambp test)
                                 (expr-annop test)
                                 (expr-unambp test-new)
                                 (expr-annop test-new))))
     (let ((__function__ 'xeq-stmt-dowhile))
      (declare (ignorable __function__))
      (b*
       (((gin gin) gin)
        (stmt (make-stmt-dowhile :body body
                                 :test test))
        (stmt-new (make-stmt-dowhile :body body-new
                                     :test test-new))
        ((unless (and body-thm-name test-thm-name))
         (mv stmt-new (gout-no-thm gin)))
        (types (stmt-types body))
        ((mv & old-body) (ldm-stmt body))
        ((mv & new-body) (ldm-stmt body-new))
        ((mv & old-test) (ldm-expr test))
        ((mv & new-test) (ldm-expr test-new))
        (hints
         (cons
          (cons
           '"Goal"
           (cons
            ':in-theory
            (cons
             ''((:e c::stmt-dowhile)
                (:e c::ident-type-map-fix)
                (:e omap::emptyp)
                (:e omap::head)
                (:e omap::tail)
                (:e insert)
                (:e c::type-nonchar-integerp)
                dowhile-test-hyp dowhile-body-hyp
                c::compustate-has-vars-with-types-p
                stmt-compustate-vars)
             (cons
              ':use
              (cons
               (cons
                (cons
                 ':instance
                 (cons
                  body-thm-name
                  (cons
                   (cons
                    'compst
                    (cons
                     (cons
                      'mv-nth
                      (cons
                       '0
                       (cons
                        (cons
                         'dowhile-body-hyp-witness
                         (cons
                          (cons 'quote (cons old-body 'nil))
                          (cons
                           (cons 'quote (cons new-body 'nil))
                           (cons
                            'old-fenv
                            (cons
                             'new-fenv
                             (cons
                              (cons 'quote (cons types 'nil))
                              (cons (cons 'quote (cons gin.vartys 'nil))
                                    'nil)))))))
                        'nil)))
                     'nil))
                   (cons
                    (cons
                     'limit
                     (cons
                      (cons
                       'mv-nth
                       (cons
                        '1
                        (cons
                         (cons
                          'dowhile-body-hyp-witness
                          (cons
                           (cons 'quote (cons old-body 'nil))
                           (cons
                            (cons 'quote (cons new-body 'nil))
                            (cons
                             'old-fenv
                             (cons
                              'new-fenv
                              (cons
                               (cons 'quote (cons types 'nil))
                               (cons
                                    (cons 'quote (cons gin.vartys 'nil))
                                    'nil)))))))
                         'nil)))
                      'nil))
                    'nil))))
                (cons
                 (cons
                  ':instance
                  (cons
                   test-thm-name
                   (cons
                    (cons
                     'compst
                     (cons
                      (cons
                       'mv-nth
                       (cons
                        '0
                        (cons
                         (cons
                          'dowhile-test-hyp-witness
                          (cons
                           (cons 'quote (cons old-test 'nil))
                           (cons
                            (cons 'quote (cons new-test 'nil))
                            (cons
                             'old-fenv
                             (cons
                              'new-fenv
                              (cons (cons 'quote (cons gin.vartys 'nil))
                                    'nil))))))
                         'nil)))
                      'nil))
                    (cons
                     (cons
                      'limit
                      (cons
                       (cons
                        'mv-nth
                        (cons
                         '1
                         (cons
                          (cons
                           'dowhile-test-hyp-witness
                           (cons
                            (cons 'quote (cons old-test 'nil))
                            (cons
                             (cons 'quote (cons new-test 'nil))
                             (cons
                              'old-fenv
                              (cons
                               'new-fenv
                               (cons
                                    (cons 'quote (cons gin.vartys 'nil))
                                    'nil))))))
                          'nil)))
                       'nil))
                     'nil))))
                 (cons
                  (cons
                   ':instance
                   (cons
                    'stmt-dowhile-theorem
                    (cons
                     (cons 'old-body
                           (cons (cons 'quote (cons old-body 'nil))
                                 'nil))
                     (cons
                      (cons 'new-body
                            (cons (cons 'quote (cons new-body 'nil))
                                  'nil))
                      (cons
                       (cons 'old-test
                             (cons (cons 'quote (cons old-test 'nil))
                                   'nil))
                       (cons
                        (cons 'new-test
                              (cons (cons 'quote (cons new-test 'nil))
                                    'nil))
                        (cons
                         (cons 'types
                               (cons (cons 'quote (cons types 'nil))
                                     'nil))
                         (cons
                          (cons
                              'vartys
                              (cons (cons 'quote (cons gin.vartys 'nil))
                                    'nil))
                          'nil))))))))
                  'nil)))
               'nil)))))
          'nil))
        ((mv thm-event thm-name thm-index)
         (gen-stmt-thm stmt stmt-new gin.vartys
                       gin.const-new gin.thm-index hints)))
       (mv stmt-new
           (make-gout :events (cons thm-event gin.events)
                      :thm-index thm-index
                      :thm-name thm-name
                      :vartys gin.vartys)))))

    Theorem: stmtp-of-xeq-stmt-dowhile.stmt

    (defthm stmtp-of-xeq-stmt-dowhile.stmt
      (b* (((mv ?stmt ?gout)
            (xeq-stmt-dowhile body body-new body-thm-name
                              test test-new test-thm-name gin)))
        (stmtp stmt))
      :rule-classes :rewrite)

    Theorem: goutp-of-xeq-stmt-dowhile.gout

    (defthm goutp-of-xeq-stmt-dowhile.gout
      (b* (((mv ?stmt ?gout)
            (xeq-stmt-dowhile body body-new body-thm-name
                              test test-new test-thm-name gin)))
        (goutp gout))
      :rule-classes :rewrite)

    Theorem: stmt-unambp-of-xeq-stmt-dowhile

    (defthm stmt-unambp-of-xeq-stmt-dowhile
     (implies (and (stmt-unambp body-new)
                   (expr-unambp test-new))
              (b* (((mv ?stmt ?gout)
                    (xeq-stmt-dowhile body body-new body-thm-name
                                      test test-new test-thm-name gin)))
                (stmt-unambp stmt))))

    Theorem: stmt-annop-of-xeq-stmt-dowhile

    (defthm stmt-annop-of-xeq-stmt-dowhile
     (implies (and (stmt-annop body-new)
                   (expr-annop test-new))
              (b* (((mv ?stmt ?gout)
                    (xeq-stmt-dowhile body body-new body-thm-name
                                      test test-new test-thm-name gin)))
                (stmt-annop stmt))))

    Theorem: stmt-aidentp-of-xeq-stmt-dowhile

    (defthm stmt-aidentp-of-xeq-stmt-dowhile
     (implies (and (stmt-aidentp body-new gcc)
                   (expr-aidentp test-new gcc))
              (b* (((mv ?stmt ?gout)
                    (xeq-stmt-dowhile body body-new body-thm-name
                                      test test-new test-thm-name gin)))
                (stmt-aidentp stmt gcc))))