Engineering Formal Metatheory

被引:76
|
作者
Aydemir, Brian [1 ]
Chargueraud, Arthur
Pierce, Benjamin C. [1 ]
Pollack, Randy
Weirich, Stephanie [1 ]
机构
[1] Univ Penn, Philadelphia, PA 19104 USA
关键词
binding; Coq; locally nameless;
D O I
10.1145/1328438.1328443
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Machine-checked proofs of properties of programming languages have become a critical need, both for increased confidence in large and complex designs and as a foundation for technologies such as proof-carrying code. However, constructing these proofs remains a black art, involving many choices in the formulation of definitions and theorems that make a huge cumulative difference in the difficulty of carrying out large formal developments. The representation and manipulation of terms with variable binding is a key issue. We propose a novel style for formalizing metatheory, combining locally, nameless representation of terms and cofinite quantification of free variable names in inductive definitions of relations on terms (typing, reduction,...). The key technical insight is that our use of cofinite quantification obviates the need for reasoning about equivariance (the fact that free names can be renamed in derivations); in particular, the structural induction principles of relations defined using cofinite quantification are strong enough for metatheoretic reasoning, and need not be explicitly strengthened. Strong inversion principles follow (automatically, in Coq) from the induction principles. Although many of the underlying ingredients of our technique have been used before, their combination here yields a significant improvement over other methodologies using first-order representations, leading to developments that are faithful to informal practice, yet require no external tool support and little infrastructure within the proof assistant. We have carried out several large developments in this style using the Coq proof assistant and have made them publicly available. Our developments include type soundness for System F-<: and core ML (with references, exceptions, datatypes, recursion, and patterns) and subject reduction for the Calculus of Constructions. Not only do these developments demonstrate the comprehensiveness of our approach; they have also been optimized for clarity and robustness, making them good templates for future extension.
引用
收藏
页码:3 / 15
页数:13
相关论文
共 50 条
  • [21] Formal Methods and Software Engineering
    Serna Montoya, Edgar
    REVISTA VIRTUAL UNIVERSIDAD CATOLICA DEL NORTE, 2010, 30 : 158 - 184
  • [22] Formal methods in knowledge engineering
    VanHarmelen, F
    Fensel, D
    KNOWLEDGE ENGINEERING REVIEW, 1995, 10 (04): : 345 - 360
  • [23] AN ENGINEERING APPROACH TO FORMAL METHODS
    TURNER, KJ
    PROTOCOL SPECIFICATION, TESTING AND VERIFICATION, XIII, 1993, 16 : 357 - 380
  • [24] Three perspectives in formal engineering
    McDermid, John
    Galloway, Andy
    FORMAL METHODS AND SOFTWARE ENGINEERING, PROCEEDINGS, 2006, 4260 : 35 - +
  • [25] Agile formal method engineering
    Paige, RR
    Brooke, PJ
    INTEGRATED FORMAL METHODS, PROCEEDINGS, 2005, 3771 : 109 - 128
  • [26] FORMAL METHODS IN SOFTWARE ENGINEERING
    LEVESON, NG
    IEEE TRANSACTIONS ON SOFTWARE ENGINEERING, 1990, 16 (09) : 929 - 931
  • [27] Formal methods and traditional engineering
    Jackson, M
    JOURNAL OF SYSTEMS AND SOFTWARE, 1998, 40 (03) : 191 - 194
  • [28] Formal Engineering with Fuzzy Logic
    Lopez, Victoria
    KNOWLEDGE ENGINEERING AND MANAGEMENT, 2011, 123 : 643 - 652
  • [29] FORMAL METHODS AND THE ENGINEERING PARADIGM
    LUTZ, MJ
    LECTURE NOTES IN COMPUTER SCIENCE, 1992, 640 : 121 - 130
  • [30] Meehl on metatheory
    Rozeboom, WW
    JOURNAL OF CLINICAL PSYCHOLOGY, 2005, 61 (10) : 1317 - 1354