object ODELiveness
Implements ODE tactics for liveness.
Created by yongkiat on 24 Feb 2020.
- Alphabetic
- By Inheritance
- ODELiveness
- AnyRef
- Any
- Hide All
- Show All
- Public
- All
Value Members
-
final
def
!=(arg0: Any): Boolean
- Definition Classes
- AnyRef → Any
-
final
def
##(): Int
- Definition Classes
- AnyRef → Any
-
final
def
==(arg0: Any): Boolean
- Definition Classes
- AnyRef → Any
-
def
affine_form(odes: DifferentialProgram): (List[List[Term]], List[Term], List[Term])
Computes the affine form for ODEs
Computes the affine form for ODEs
- odes
the ODEs to put into affine form
- returns
A (matrix of terms), b (list of terms), x (list of variables) such that x'=Ax+b
-
final
def
asInstanceOf[T0]: T0
- Definition Classes
- Any
-
def
bDG(ghost: Expression, p: Term): DependentPositionWithAppliedInputTactic
Wrapper around bDG for display.
Wrapper around bDG for display.
- Annotations
- @Tactic( x$13 , x$19 , x$14 , x$15 , x$16 , x$20 , x$21 , x$17 , x$22 , x$23 , x$18 , x$24 )
-
def
bDG(ghost: DifferentialProgram, p: Term): DependentPositionTactic
Implements bDG rule that adds ghosts to box ODEs on the right of the turnstile
Implements bDG rule that adds ghosts to box ODEs on the right of the turnstile
G |- [ghosts, ODE] (||ghosts||)^2 <= p G |- [ghosts, ODE]P ---- dDG G |- [ODE]P
- ghost
the ghost ODEs, L, M as above
-
def
clone(): AnyRef
- Attributes
- protected[java.lang]
- Definition Classes
- AnyRef
- Annotations
- @native() @throws( ... )
-
def
closedRef(R: Formula): DependentPositionWithAppliedInputTactic
Refinement for a closed domain constraint (e.g.
Refinement for a closed domain constraint (e.g. Q = p>=0)
G |- <ODE & R> P G |- p>0 //must start in interior of domain G |-[ODE & R & p>=0 & !P] p>0 //must stay in interior of domain except by possibly exiting exactly at the end ---- (closedRefine) G |- <ODE & p>=0> P
- Annotations
- @Tactic( x$73 , x$74 , x$75 , x$76 , x$77 , x$79 , x$80 , x$78 , x$81 , x$82 , x$83 , x$84 )
-
def
compatCut(R: Formula): DependentPositionWithAppliedInputTactic
A tiny wrapper around cut.
A tiny wrapper around cut. This introduces a cut that is compatible for the ODE at a given position (regardless of modality and position, although most useful for diamond ODEs)
G, [x'=f(x)&Q]R |- C([x'=f(x)&Q]P) G|-[x'=f(x)&Q]R --- compatCut G |- C([x'=f(x)&Q]P)
- Annotations
- @Tactic( x$37 , x$38 , x$39 , x$40 , x$41 , x$44 , x$45 , x$42 , x$46 , x$47 , x$43 , x$48 )
-
def
dBDG(p: Term): DependentPositionWithAppliedInputTactic
- Annotations
- @Tactic( x$85 , x$86 , x$87 , x$88 , x$89 , x$91 , x$92 , x$90 , x$93 , x$94 , x$95 , x$96 )
- def dBDG(p: Term, dim: Int): DependentPositionTactic
-
def
dDDG(L: Term, M: Term): DependentPositionWithAppliedInputTactic
- Annotations
- @Tactic( x$97 , x$98 , x$99 , x$100 , x$101 , x$103 , x$104 , x$102 , x$105 , x$106 , x$107 , x$108 )
- def dDDG(L: Term, M: Term, dim: Int): DependentPositionTactic
-
def
dDG(ghost: DifferentialProgram, L: Term, M: Term): DependentPositionTactic
Implements dDG rule that adds ghosts to box ODEs on the right of the turnstile
Implements dDG rule that adds ghosts to box ODEs on the right of the turnstile
G |- [ghosts, ODE] (||ghosts||)' <= L ||ghosts|| + M G |- [ghosts, ODE]P ---- dDG G |- [ODE]P
- ghost
the ghost ODEs, L, M as above
-
def
dDR(R: Formula): DependentPositionWithAppliedInputTactic
Implements DR<.> rule Note: uses auto cuts for the later premise
Implements DR<.> rule Note: uses auto cuts for the later premise
G |- <ODE & R> P G |- [ODE & R] Q ---- (dDR) G |- <ODE & Q> P
- R
the formula R to refine the domain constraint
- returns
two premises, as shown above when applied to a top-level succedent diamond
- Annotations
- @Tactic( x$61 , x$62 , x$63 , x$64 , x$65 , x$67 , x$68 , x$66 , x$69 , x$70 , x$71 , x$72 )
-
def
dDX: BuiltInPositionTactic
ODE diamond is true if domain and postcondition was already true initially
ODE diamond is true if domain and postcondition was already true initially
G |- Q & P ---- G |- <x'=f(x)&Q>P
- returns
see rule above
-
def
dV(eps: Option[Term]): DependentPositionWithAppliedInputTactic
- Annotations
- @Tactic( x$121 , x$122 , x$123 , x$124 , x$125 , x$128 , x$129 , x$126 , x$130 , x$131 , x$127 , x$132 )
-
def
dV(bnd: Term, manual: Boolean = false): DependentPositionTactic
Implements dV rule for atomic postconditions The bottom two premises are auto-closed because of the need to Dconstify The first one is partially auto-closed if odeReduce is able to prove global existence e.g.
Implements dV rule for atomic postconditions The bottom two premises are auto-closed because of the need to Dconstify The first one is partially auto-closed if odeReduce is able to prove global existence e.g. (similarly for dV >),
Note: autonormalizes to >= and > (but provided e_() must be for the normalized shape!)
G, t=0 |- <t'=1, ODE & Q> t > const G, t=0 |- e_() > 0 G, t=0 |- [t'=1, ODE & Q & p-q < 0] p'-q' >= e () (this uses compatible cuts ) ---- (dV >=) G |- <ODE & Q> p >= q
Note that domain constraint Q is kept around!
- bnd
the lower bound on derivatives
- manual
whether to try closing automatically
- returns
closes (or partially so)
- def dVAuto(autoqe: Boolean = true): DependentPositionTactic
-
def
deriveGlobalExistence(ode: DifferentialProgram): Option[ProvableSig]
Given ODE, returns the global existence axiom <t'=1,x'=f(x)>t>p() (if it proves)
Given ODE, returns the global existence axiom <t'=1,x'=f(x)>t>p() (if it proves)
- returns
(optional) ProvableSig proving the global existence axiom, None if failed
-
final
def
eq(arg0: AnyRef): Boolean
- Definition Classes
- AnyRef
-
def
equals(arg0: Any): Boolean
- Definition Classes
- AnyRef → Any
-
def
finalize(): Unit
- Attributes
- protected[java.lang]
- Definition Classes
- AnyRef
- Annotations
- @throws( classOf[java.lang.Throwable] )
-
def
gEx(hint: Option[Formula]): DependentPositionWithAppliedInputTactic
- Annotations
- @Tactic( x$109 , x$110 , x$111 , x$112 , x$113 , x$115 , x$116 , x$114 , x$117 , x$118 , x$119 , x$120 )
- def gEx(hints: List[Formula]): DependentPositionTactic
-
final
def
getClass(): Class[_]
- Definition Classes
- AnyRef → Any
- Annotations
- @native()
- def getDDG(dim: Int): ProvableSig
-
def
getDDGinst(ghostODEs: DifferentialProgram): ProvableSig
Helper that gets the appropriate DDG instance (already instantiated for the ghosts by renaming and friends) This helps simplify the (y^2)' term away
Helper that gets the appropriate DDG instance (already instantiated for the ghosts by renaming and friends) This helps simplify the (y^2)' term away
- ghostODEs
the ghosts to add to the ODE
- returns
DDG instantiated for the particular boxode question
-
def
getVDGinst(ghostODEs: DifferentialProgram): (ProvableSig, ProvableSig)
Helper that gets the appropriate VDG instance (already instantiated for the ghosts and ODE by renaming and friends)
Helper that gets the appropriate VDG instance (already instantiated for the ghosts and ODE by renaming and friends)
- ghostODEs
the ghost ODEs
- returns
both directions of VDG instantiated for the ghost ODEs (everything else is left uninstantiated)
-
def
hashCode(): Int
- Definition Classes
- AnyRef → Any
- Annotations
- @native()
-
def
higherdV(bnds: List[Term]): DependentPositionTactic
Implements higher dV series rule for atomic postconditions with less automation Given a series a_0, a_1, ...
Implements higher dV series rule for atomic postconditions with less automation Given a series a_0, a_1, ... , a_n :
G |- [t'=1, ODE&Q & p<0] p >= a_0 + a_1 t + a_2 t2 + ... + a_n tn G |- <t'=1, ODE & Q> a_0 + a_1 t + a_2 t2 + ... + a_n tn > 0 ---- (higherdV >=) G |- <ODE & Q> p >= 0
Note that domain constraint Q is kept around!
- bnds
the lower bound on derivatives
- returns
two subgoals, shown above
-
final
def
isInstanceOf[T0]: Boolean
- Definition Classes
- Any
-
def
kDomainDiamond(R: Formula): DependentPositionWithAppliedInputTactic
Implements K<&> rule Note: uses auto cuts for the later premise
Implements K<&> rule Note: uses auto cuts for the later premise
G |- <ODE & Q> R G |- [ODE & Q & !P] !R ---- (kDomD) G |- <ODE & Q> P
- R
the formula R to refine the postcondition
- returns
two premises, as shown above when applied to a top-level succedent diamond
- Annotations
- @Tactic( x$49 , x$50 , x$54 , x$51 , x$52 , x$55 , x$56 , x$53 , x$57 , x$58 , x$59 , x$60 )
-
final
def
ne(arg0: AnyRef): Boolean
- Definition Classes
- AnyRef
-
final
def
notify(): Unit
- Definition Classes
- AnyRef
- Annotations
- @native()
-
final
def
notifyAll(): Unit
- Definition Classes
- AnyRef
- Annotations
- @native()
-
def
odeReduce(strict: Boolean = true, hints: List[Formula]): DependentPositionTactic
Applied to a top-level position containing a succedent diamond, this tactic removes irrelevant ODEs
Applied to a top-level position containing a succedent diamond, this tactic removes irrelevant ODEs
- strict
whether to throw an error when it meets a nonlinear ODE that can't be reduced
- hints
a list of
- returns
reduces away all irrelevant ODEs
-
def
odeUnify: DependentPositionTactic
Adds compatible (ODE unifiable) box modalities from the assumptions to the domain constraint e.g.
Adds compatible (ODE unifiable) box modalities from the assumptions to the domain constraint e.g. [x'=f(x)&A]B is compatible for [x'=f(x)&Q]P if A implies Q
[z'=g(z)&Q]P is compatible for [x'=f(x)&Q]P if z'=g(z) contains a subset of ODEs of x'=f(x)
For compatible assumptions, the rule adds them by diff cut, e.g.:
G, [x'=f(x)&A]B |- [x'=f(x)&Q&B]P --- G, [x'=f(x)&A]B |- [x'=f(x)&Q]P
- Annotations
- @Tactic( x$25 , x$26 , x$27 , x$28 , x$29 , x$31 , x$32 , x$30 , x$33 , x$34 , x$35 , x$36 )
-
def
saveBox: DependentPositionTactic
Saves a (negated) box version of the liveness postcondition.
Saves a (negated) box version of the liveness postcondition. This is a helpful pattern because of compat cuts
G, [ODE & Q]!P |- <ODE & Q> P ---- (saveBox) G |- <ODE & Q> P
- def semialgdV(bnd: Term): DependentPositionTactic
- def semialgdVAuto(autoqe: Boolean = true): DependentPositionTactic
-
final
def
synchronized[T0](arg0: ⇒ T0): T0
- Definition Classes
- AnyRef
-
def
toString(): String
- Definition Classes
- AnyRef → Any
-
def
vDG(ghost: Expression): DependentPositionWithAppliedInputTactic
Wrapper around vDG for display.
Wrapper around vDG for display.
- Annotations
- @Tactic( x$1 , x$7 , x$2 , x$3 , x$4 , x$8 , x$9 , x$5 , x$10 , x$11 , x$6 , x$12 )
-
def
vDG(ghost: DifferentialProgram): DependentPositionTactic
Implements linear vDG rule that adds ghosts to an ODE on the left or right, in either modality For boxes on the right and diamonds on the left, the ODE must be affine
Implements linear vDG rule that adds ghosts to an ODE on the left or right, in either modality For boxes on the right and diamonds on the left, the ODE must be affine
G |- [y'=g(x,y),x'=f(x)]P ---- vDG (g affine in y) G |- [x'=f(x)]P [y'=g(x,y),x'=f(x)]P |- D ---- [x'=f(x)]P |- D
- ghost
the ODEs to ghost in
- returns
the sequent with ghosts added in requested position
-
final
def
wait(): Unit
- Definition Classes
- AnyRef
- Annotations
- @throws( ... )
-
final
def
wait(arg0: Long, arg1: Int): Unit
- Definition Classes
- AnyRef
- Annotations
- @throws( ... )
-
final
def
wait(arg0: Long): Unit
- Definition Classes
- AnyRef
- Annotations
- @native() @throws( ... )
KeYmaera X: An aXiomatic Tactical Theorem Prover
KeYmaera X is a theorem prover for differential dynamic logic (dL), a logic for specifying and verifying properties of hybrid systems with mixed discrete and continuous dynamics. Reasoning about complicated hybrid systems requires support for sophisticated proof techniques, efficient computation, and a user interface that crystallizes salient properties of the system. KeYmaera X allows users to specify custom proof search techniques as tactics, execute tactics in parallel, and interface with partial proofs via an extensible user interface.
http://keymaeraX.org/
Concrete syntax for input language Differential Dynamic Logic
Package Structure
Main documentation entry points for KeYmaera X API:
edu.cmu.cs.ls.keymaerax.core- KeYmaera X kernel, proof certificates, main data structuresExpression- Differential dynamic logic expressions:Term,Formula,ProgramSequent- Sequents of formulasProvable- Proof certificates transformed by rules/axiomsRule- Proof rules as well asUSubstOnefor (one-pass) uniform substitutions and renaming.StaticSemantics- Static semantics with free and bound variable analysisKeYmaeraXParser.edu.cmu.cs.ls.keymaerax.parser- Parser and pretty printer with concrete syntax and notation for differential dynamic logic.KeYmaeraXPrettyPrinter- Pretty printer producing concrete KeYmaera X syntaxKeYmaeraXParser- Parser reading concrete KeYmaera X syntaxKeYmaeraXArchiveParser- Parser reading KeYmaera X model and proof archive.kyxfilesDLParser- Combinator parser reading concrete KeYmaera X syntaxDLArchiveParser- Combinator parser reading KeYmaera X model and proof archive.kyxfilesedu.cmu.cs.ls.keymaerax.infrastruct- Prover infrastructure outside the kernelUnificationMatch- Unification algorithmRenUSubst- Renaming Uniform Substitution quickly combining kernel's renaming and substitution.Context- Representation for contexts of formulas in which they occur.Augmentors- Augmenting formula and expression data structures with additional functionalityExpressionTraversal- Generic traversal functionality for expressionsedu.cmu.cs.ls.keymaerax.bellerophon- Bellerophon tactic language and tactic interpreterBelleExpr- Tactic language expressionsSequentialInterpreter- Sequential tactic interpreter for Bellerophon tacticsedu.cmu.cs.ls.keymaerax.btactics- Bellerophon tactic library for conducting proofs.TactixLibrary- Main KeYmaera X tactic library including many proof tactics.HilbertCalculus- Hilbert Calculus for differential dynamic logicSequentCalculus- Sequent Calculus for propositional and first-order logicHybridProgramCalculus- Hybrid Program Calculus for differential dynamic logicDifferentialEquationCalculus- Differential Equation Calculus for differential dynamic logicUnifyUSCalculus- Unification-based uniform substitution calculus underlying the other calculi[edu.cmu.cs.ls.keymaerax.btactics.UnifyUSCalculus.ForwardTactic ForwardTactic]- Forward tactic framework for conducting proofs from premises to conclusionsedu.cmu.cs.ls.keymaerax.lemma- Lemma mechanismLemma- Lemmas are Provables stored under a name, e.g., in files.LemmaDB- Lemma database stored in files or database etc.edu.cmu.cs.ls.keymaerax.tools.qe- Real arithmetic back-end solversMathematicaQETool- Mathematica interface for real arithmetic.Z3QETool- Z3 interface for real arithmetic.edu.cmu.cs.ls.keymaerax.tools.ext- Extended back-ends for noncritical ODE solving, counterexamples, algebra, simplifiers, etc.Mathematica- Mathematica interface for ODE solving, algebra, simplification, invariant generation, etc.Z3- Z3 interface for real arithmetic including simplifiers.Entry Points
Additional entry points and usage points for KeYmaera X API:
edu.cmu.cs.ls.keymaerax.launcher.KeYmaeraX- Command-line launcher for KeYmaera X supports command-line argument-helpto obtain usage informationedu.cmu.cs.ls.keymaerax.btactics.AxIndex- Axiom indexing data structures with keys and recursors for canonical proof strategies.edu.cmu.cs.ls.keymaerax.btactics.DerivationInfo- Meta-information on all derivation steps (axioms, derived axioms, proof rules, tactics) with user-interface info.edu.cmu.cs.ls.keymaerax.bellerophon.UIIndex- Index determining which canonical reasoning steps to display on the KeYmaera X User Interface.edu.cmu.cs.ls.keymaerax.btactics.Ax- Registry for derived axioms and axiomatic proof rules that are proved from the core.References
Full references on KeYmaera X are provided at http://keymaeraX.org/. The main references are the following:
1. André Platzer. A complete uniform substitution calculus for differential dynamic logic. Journal of Automated Reasoning, 59(2), pp. 219-265, 2017.
2. Nathan Fulton, Stefan Mitsch, Jan-David Quesel, Marcus Völp and André Platzer. KeYmaera X: An axiomatic tactical theorem prover for hybrid systems. In Amy P. Felty and Aart Middeldorp, editors, International Conference on Automated Deduction, CADE'15, Berlin, Germany, Proceedings, volume 9195 of LNCS, pp. 527-538. Springer, 2015.
3. André Platzer. Logical Foundations of Cyber-Physical Systems. Springer, 2018. Videos