no_shm_selinux/Co2sobj_prop.thy
author chunhan
Thu, 09 Jan 2014 14:39:00 +0800
changeset 92 d9dc04c3ea90
parent 88 e832378a2ff2
permissions -rw-r--r--
modify co2sobj/s2ss from object to dobject
Ignore whitespace changes - Everywhere: Within whitespace: At end of lines:
77
chunhan
parents:
diff changeset
     1
(*<*)
chunhan
parents:
diff changeset
     2
theory Co2sobj_prop
chunhan
parents:
diff changeset
     3
imports Main Flask Flask_type Static Static_type Sectxt_prop Init_prop Current_files_prop Current_sockets_prop Delete_prop Proc_fd_of_file_prop Tainted_prop Valid_prop Init_prop Alive_prop
chunhan
parents:
diff changeset
     4
begin
chunhan
parents:
diff changeset
     5
(*<*)
chunhan
parents:
diff changeset
     6
chunhan
parents:
diff changeset
     7
ML {*
chunhan
parents:
diff changeset
     8
fun print_ss ss =
chunhan
parents:
diff changeset
     9
let
chunhan
parents:
diff changeset
    10
val {simps, congs, procs, ...} = Raw_Simplifier.dest_ss ss
chunhan
parents:
diff changeset
    11
in
chunhan
parents:
diff changeset
    12
simps
chunhan
parents:
diff changeset
    13
end
chunhan
parents:
diff changeset
    14
*}
chunhan
parents:
diff changeset
    15
chunhan
parents:
diff changeset
    16
chunhan
parents:
diff changeset
    17
context tainting_s begin
chunhan
parents:
diff changeset
    18
chunhan
parents:
diff changeset
    19
(********************* cm2smsg simpset ***********************)
chunhan
parents:
diff changeset
    20
chunhan
parents:
diff changeset
    21
lemma cm2smsg_other: 
chunhan
parents:
diff changeset
    22
  "\<lbrakk>valid (e # s); \<forall> p q m. e \<noteq> SendMsg p q m; \<forall> p q m. e \<noteq> RecvMsg p q m; \<forall> p q. e \<noteq> RemoveMsgq p q\<rbrakk> 
chunhan
parents:
diff changeset
    23
   \<Longrightarrow> cm2smsg (e # s) = cm2smsg s"
chunhan
parents:
diff changeset
    24
apply (frule vt_grant_os, frule vd_cons, rule ext, rule ext)
chunhan
parents:
diff changeset
    25
unfolding cm2smsg_def
chunhan
parents:
diff changeset
    26
apply (case_tac e)
chunhan
parents:
diff changeset
    27
apply (auto simp:sectxt_of_obj_simps 
chunhan
parents:
diff changeset
    28
           split:t_object.splits option.splits if_splits 
chunhan
parents:
diff changeset
    29
           dest!:current_has_sec')
chunhan
parents:
diff changeset
    30
done
chunhan
parents:
diff changeset
    31
chunhan
parents:
diff changeset
    32
lemma cm2smsg_sendmsg:
chunhan
parents:
diff changeset
    33
  "valid (SendMsg p q m # s) \<Longrightarrow> cm2smsg (SendMsg p q m # s) = (\<lambda> q' m'. 
chunhan
parents:
diff changeset
    34
     if (q' = q \<and> m' = m)
chunhan
parents:
diff changeset
    35
     then (case (sectxt_of_obj (SendMsg p q m # s) (O_msg q m)) of
chunhan
parents:
diff changeset
    36
             Some sec \<Rightarrow> Some (Created, sec, O_msg q m \<in> tainted (SendMsg p q m # s))
chunhan
parents:
diff changeset
    37
           | _ \<Rightarrow> None)
chunhan
parents:
diff changeset
    38
     else cm2smsg s q' m') "
chunhan
parents:
diff changeset
    39
apply (frule vd_cons, frule vt_grant_os, rule ext, rule ext)
chunhan
parents:
diff changeset
    40
apply (auto simp:cm2smsg_def sectxt_of_obj_simps 
88
chunhan
parents: 87
diff changeset
    41
  split:if_splits option.splits dest!:current_has_sec')
77
chunhan
parents:
diff changeset
    42
done
chunhan
parents:
diff changeset
    43
chunhan
parents:
diff changeset
    44
lemma cm2smsg_recvmsg1:
chunhan
parents:
diff changeset
    45
  "\<lbrakk>q' \<noteq> q; valid (RecvMsg p q m # s)\<rbrakk> \<Longrightarrow> cm2smsg (RecvMsg p q m # s) q' = cm2smsg s q'"
chunhan
parents:
diff changeset
    46
apply (frule vd_cons, frule vt_grant_os, rule ext)
chunhan
parents:
diff changeset
    47
apply (auto simp:cm2smsg_def sectxt_of_obj_simps 
chunhan
parents:
diff changeset
    48
  split:if_splits option.splits)
chunhan
parents:
diff changeset
    49
done
chunhan
parents:
diff changeset
    50
chunhan
parents:
diff changeset
    51
lemma cm2smsg_recvmsg2:
chunhan
parents:
diff changeset
    52
  "\<lbrakk>m' \<noteq> m; valid (RecvMsg p q m # s)\<rbrakk> \<Longrightarrow> cm2smsg (RecvMsg p q m # s) q m' = cm2smsg s q m'"
chunhan
parents:
diff changeset
    53
apply (frule vd_cons, frule vt_grant_os)
chunhan
parents:
diff changeset
    54
apply (auto simp:cm2smsg_def sectxt_of_obj_simps 
chunhan
parents:
diff changeset
    55
  split:if_splits option.splits)
chunhan
parents:
diff changeset
    56
done
chunhan
parents:
diff changeset
    57
chunhan
parents:
diff changeset
    58
lemma cm2smsg_recvmsg1':
chunhan
parents:
diff changeset
    59
  "\<lbrakk>valid (RecvMsg p q m # s); q' \<noteq> q\<rbrakk> \<Longrightarrow> cm2smsg (RecvMsg p q m # s) q' = cm2smsg s q'"
chunhan
parents:
diff changeset
    60
apply (frule vd_cons, frule vt_grant_os, rule ext)
chunhan
parents:
diff changeset
    61
apply (auto simp:cm2smsg_def sectxt_of_obj_simps 
chunhan
parents:
diff changeset
    62
  split:if_splits option.splits)
chunhan
parents:
diff changeset
    63
done
chunhan
parents:
diff changeset
    64
chunhan
parents:
diff changeset
    65
lemma cm2smsg_recvmsg2':
chunhan
parents:
diff changeset
    66
  "\<lbrakk>valid (RecvMsg p q m # s); m' \<noteq> m\<rbrakk> \<Longrightarrow> cm2smsg (RecvMsg p q m # s) q m' = cm2smsg s q m'"
chunhan
parents:
diff changeset
    67
apply (frule vd_cons, frule vt_grant_os)
chunhan
parents:
diff changeset
    68
apply (auto simp:cm2smsg_def sectxt_of_obj_simps 
chunhan
parents:
diff changeset
    69
  split:if_splits option.splits)
chunhan
parents:
diff changeset
    70
done
chunhan
parents:
diff changeset
    71
chunhan
parents:
diff changeset
    72
lemma cm2smsg_removemsgq:
chunhan
parents:
diff changeset
    73
  "\<lbrakk>q' \<noteq> q; valid (RemoveMsgq p q # s)\<rbrakk> \<Longrightarrow> cm2smsg (RemoveMsgq p q # s) q' = cm2smsg s q'"
chunhan
parents:
diff changeset
    74
apply (frule vd_cons, frule vt_grant_os, rule ext)
chunhan
parents:
diff changeset
    75
apply (auto simp:cm2smsg_def sectxt_of_obj_simps 
chunhan
parents:
diff changeset
    76
  split:if_splits option.splits)
chunhan
parents:
diff changeset
    77
done
chunhan
parents:
diff changeset
    78
88
chunhan
parents: 87
diff changeset
    79
lemmas cm2smsg_simps = cm2smsg_sendmsg cm2smsg_recvmsg1' cm2smsg_recvmsg2'
77
chunhan
parents:
diff changeset
    80
  cm2smsg_removemsgq cm2smsg_other
chunhan
parents:
diff changeset
    81
87
8d18cfc845dd remove init message queue
chunhan
parents: 85
diff changeset
    82
(*
77
chunhan
parents:
diff changeset
    83
lemma init_cm2smsg_has_smsg:
chunhan
parents:
diff changeset
    84
  "\<lbrakk>m \<in> set (init_msgs_of_queue q); q \<in> init_msgqs\<rbrakk> \<Longrightarrow> \<exists> sm. init_cm2smsg q m = Some sm"
chunhan
parents:
diff changeset
    85
by (auto simp:init_cm2smsg_def split:option.splits dest:init_msg_has_ctxt)
87
8d18cfc845dd remove init message queue
chunhan
parents: 85
diff changeset
    86
*)
77
chunhan
parents:
diff changeset
    87
chunhan
parents:
diff changeset
    88
lemma hd_set_prop1:
chunhan
parents:
diff changeset
    89
  "hd l \<notin> set l \<Longrightarrow> l = []"
chunhan
parents:
diff changeset
    90
by (case_tac l, auto)
chunhan
parents:
diff changeset
    91
chunhan
parents:
diff changeset
    92
lemma tl_set_prop1:
chunhan
parents:
diff changeset
    93
  "a \<in> set (tl l) \<Longrightarrow> a \<in> set l"
chunhan
parents:
diff changeset
    94
by (case_tac l, auto)
chunhan
parents:
diff changeset
    95
chunhan
parents:
diff changeset
    96
lemma current_has_smsg:
chunhan
parents:
diff changeset
    97
  "\<lbrakk>m \<in> set (msgs_of_queue s q); q \<in> current_msgqs s; valid s\<rbrakk> \<Longrightarrow> \<exists> sm. cm2smsg s q m = Some sm"
chunhan
parents:
diff changeset
    98
apply (induct s)
88
chunhan
parents: 87
diff changeset
    99
apply (simp add:msgs_of_queue.simps current_msgqs.simps)
77
chunhan
parents:
diff changeset
   100
chunhan
parents:
diff changeset
   101
apply (frule vt_grant_os, frule vd_cons, case_tac a)
chunhan
parents:
diff changeset
   102
apply (auto simp:cm2smsg_def sectxt_of_obj_simps split:if_splits option.splits
88
chunhan
parents: 87
diff changeset
   103
  dest!:current_has_sec' hd_set_prop1 dest:tl_set_prop1)
77
chunhan
parents:
diff changeset
   104
done 
chunhan
parents:
diff changeset
   105
chunhan
parents:
diff changeset
   106
lemma current_has_smsg':
chunhan
parents:
diff changeset
   107
  "\<lbrakk>cm2smsg s q m = None; q \<in> current_msgqs s; valid s\<rbrakk> \<Longrightarrow> m \<notin> set (msgs_of_queue s q)"
chunhan
parents:
diff changeset
   108
by (auto dest:current_has_smsg)
chunhan
parents:
diff changeset
   109
chunhan
parents:
diff changeset
   110
lemma cqm2sms_has_sms_aux:
chunhan
parents:
diff changeset
   111
  "\<forall> m \<in> set ms. sectxt_of_obj s (O_msg q m) \<noteq> None \<Longrightarrow> (\<exists> sms. cqm2sms s q ms = Some sms)"
chunhan
parents:
diff changeset
   112
by (induct ms, auto split:option.splits simp:cm2smsg_def)
chunhan
parents:
diff changeset
   113
chunhan
parents:
diff changeset
   114
lemma current_has_sms:
chunhan
parents:
diff changeset
   115
  "\<lbrakk>q \<in> current_msgqs s; valid s\<rbrakk> \<Longrightarrow> \<exists> sms. cqm2sms s q (msgs_of_queue s q) = Some sms"
chunhan
parents:
diff changeset
   116
apply (rule cqm2sms_has_sms_aux)
chunhan
parents:
diff changeset
   117
apply (auto dest:current_msg_has_sec)
chunhan
parents:
diff changeset
   118
done
chunhan
parents:
diff changeset
   119
chunhan
parents:
diff changeset
   120
lemma current_has_sms':
chunhan
parents:
diff changeset
   121
  "\<lbrakk>cqm2sms s q (msgs_of_queue s q) = None; valid s\<rbrakk> \<Longrightarrow> q \<notin> current_msgqs s"
chunhan
parents:
diff changeset
   122
by (auto dest:current_has_sms)
chunhan
parents:
diff changeset
   123
chunhan
parents:
diff changeset
   124
(********************* cqm2sms simpset ***********************) 
chunhan
parents:
diff changeset
   125
chunhan
parents:
diff changeset
   126
lemma cqm2sms_other:
chunhan
parents:
diff changeset
   127
  "\<lbrakk>valid (e # s); \<forall> p m. e \<noteq> CreateMsgq p q; \<forall> p q m. e \<noteq> SendMsg p q m; 
chunhan
parents:
diff changeset
   128
    \<forall> p q m. e \<noteq> RecvMsg p q m; \<forall> p q. e \<noteq> RemoveMsgq p q\<rbrakk> 
chunhan
parents:
diff changeset
   129
   \<Longrightarrow> cqm2sms (e # s) = cqm2sms s"
chunhan
parents:
diff changeset
   130
apply (rule ext, rule ext)
chunhan
parents:
diff changeset
   131
apply (induct_tac xa, simp)
chunhan
parents:
diff changeset
   132
apply (frule vt_grant_os, frule vd_cons, case_tac e)
chunhan
parents:
diff changeset
   133
apply (auto split:option.splits dest:cm2smsg_other) 
chunhan
parents:
diff changeset
   134
done
chunhan
parents:
diff changeset
   135
chunhan
parents:
diff changeset
   136
lemma cqm2sms_createmsgq:
chunhan
parents:
diff changeset
   137
  "valid (CreateMsgq p q # s) \<Longrightarrow> cqm2sms (CreateMsgq p q # s) = (\<lambda> q' ms'. 
chunhan
parents:
diff changeset
   138
     if (q' = q \<and> ms' = []) then Some []
chunhan
parents:
diff changeset
   139
     else cqm2sms s q' ms')"
chunhan
parents:
diff changeset
   140
apply (rule ext, rule ext)
chunhan
parents:
diff changeset
   141
apply (frule vt_grant_os, frule vd_cons, induct_tac ms')
chunhan
parents:
diff changeset
   142
apply (auto split:if_splits option.splits dest:cm2smsg_other)
chunhan
parents:
diff changeset
   143
done
chunhan
parents:
diff changeset
   144
chunhan
parents:
diff changeset
   145
lemma cqm2sms_2:
chunhan
parents:
diff changeset
   146
  "cqm2sms s q (ms @ [m]) = 
chunhan
parents:
diff changeset
   147
     (case (cqm2sms s q ms, cm2smsg s q m) of 
chunhan
parents:
diff changeset
   148
       (Some sms, Some sm) \<Rightarrow> Some (sms @ [sm]) 
chunhan
parents:
diff changeset
   149
     | _ \<Rightarrow> None)"
chunhan
parents:
diff changeset
   150
apply (induct ms, simp split:option.splits)
chunhan
parents:
diff changeset
   151
by (auto split:option.splits)
chunhan
parents:
diff changeset
   152
chunhan
parents:
diff changeset
   153
lemmas cqm2sms_simps2 = cqm2sms.simps(1) cqm2sms_2
chunhan
parents:
diff changeset
   154
chunhan
parents:
diff changeset
   155
declare cqm2sms.simps [simp del]
chunhan
parents:
diff changeset
   156
chunhan
parents:
diff changeset
   157
lemma cqm2sms_prop1:
chunhan
parents:
diff changeset
   158
  "cqm2sms s q ms = None \<Longrightarrow> \<exists> m \<in> set ms. cm2smsg s q m = None"
chunhan
parents:
diff changeset
   159
by (induct ms, auto simp:cqm2sms.simps split:option.splits)
chunhan
parents:
diff changeset
   160
chunhan
parents:
diff changeset
   161
lemma cqm2sms_sendmsg1:
chunhan
parents:
diff changeset
   162
  "\<lbrakk>valid (SendMsg p q m # s); m \<notin> set ms\<rbrakk>
chunhan
parents:
diff changeset
   163
   \<Longrightarrow> cqm2sms (SendMsg p q m # s) q' ms = cqm2sms s q' ms"
chunhan
parents:
diff changeset
   164
apply (frule vt_grant_os, frule vd_cons)
chunhan
parents:
diff changeset
   165
apply (frule cm2smsg_sendmsg)
chunhan
parents:
diff changeset
   166
apply (induct ms rule:rev_induct)
chunhan
parents:
diff changeset
   167
apply (auto split:if_splits option.splits  simp:cqm2sms_simps2)
chunhan
parents:
diff changeset
   168
done
chunhan
parents:
diff changeset
   169
chunhan
parents:
diff changeset
   170
lemma cqm2sms_sendmsg2:
chunhan
parents:
diff changeset
   171
  "\<lbrakk>valid (SendMsg p q m # s); q' \<noteq> q\<rbrakk>
chunhan
parents:
diff changeset
   172
   \<Longrightarrow> cqm2sms (SendMsg p q m # s) q' ms = cqm2sms s q' ms"
chunhan
parents:
diff changeset
   173
apply (frule vt_grant_os, frule vd_cons)
chunhan
parents:
diff changeset
   174
apply (frule cm2smsg_sendmsg)
chunhan
parents:
diff changeset
   175
apply (induct ms rule:rev_induct)
chunhan
parents:
diff changeset
   176
apply (auto split:if_splits option.splits  simp:cqm2sms_simps2)
chunhan
parents:
diff changeset
   177
done
chunhan
parents:
diff changeset
   178
chunhan
parents:
diff changeset
   179
lemma cqm2sms_sendmsg3:
chunhan
parents:
diff changeset
   180
  "\<lbrakk>valid (SendMsg p q m # s); ms' = msgs_of_queue (SendMsg p q m # s) q\<rbrakk>
chunhan
parents:
diff changeset
   181
   \<Longrightarrow> cqm2sms (SendMsg p q m # s) q ms' = 
chunhan
parents:
diff changeset
   182
     (case (cqm2sms s q (msgs_of_queue s q), sectxt_of_obj (SendMsg p q m # s) (O_msg q m)) of
chunhan
parents:
diff changeset
   183
       (Some sms, Some sec) \<Rightarrow> Some (sms @ [(Created, sec, O_msg q m \<in> tainted (SendMsg p q m # s))])
chunhan
parents:
diff changeset
   184
     | _ \<Rightarrow> None)"
chunhan
parents:
diff changeset
   185
apply (frule vt_grant_os, frule vd_cons)
chunhan
parents:
diff changeset
   186
apply (frule cm2smsg_sendmsg)
chunhan
parents:
diff changeset
   187
apply (auto split:if_splits option.splits  simp:cqm2sms_simps2 cqm2sms_sendmsg1)
chunhan
parents:
diff changeset
   188
done
chunhan
parents:
diff changeset
   189
chunhan
parents:
diff changeset
   190
lemma cqm2sms_sendmsg:
chunhan
parents:
diff changeset
   191
  "\<lbrakk>valid (SendMsg p q m # s); ms' = msgs_of_queue (SendMsg p q m # s) q'\<rbrakk> 
chunhan
parents:
diff changeset
   192
   \<Longrightarrow> cqm2sms (SendMsg p q m # s) q' ms' = (
chunhan
parents:
diff changeset
   193
     if (q' = q) 
chunhan
parents:
diff changeset
   194
     then (case (cqm2sms s q (msgs_of_queue s q), sectxt_of_obj (SendMsg p q m # s) (O_msg q m)) of
chunhan
parents:
diff changeset
   195
             (Some sms, Some sec) \<Rightarrow> Some (sms @ [(Created, sec, O_msg q m \<in> tainted (SendMsg p q m # s))])
chunhan
parents:
diff changeset
   196
           | _ \<Rightarrow> None)
chunhan
parents:
diff changeset
   197
     else cqm2sms s q' ms' )"
chunhan
parents:
diff changeset
   198
apply (simp split:if_splits add:cqm2sms_sendmsg2 cqm2sms_sendmsg3)
chunhan
parents:
diff changeset
   199
done
chunhan
parents:
diff changeset
   200
chunhan
parents:
diff changeset
   201
lemma cqm2sms_recvmsg1:
chunhan
parents:
diff changeset
   202
  "\<lbrakk>valid (RecvMsg p q m # s); m \<notin> set ms\<rbrakk> 
chunhan
parents:
diff changeset
   203
   \<Longrightarrow> cqm2sms (RecvMsg p q m # s) q ms = cqm2sms s q ms"
chunhan
parents:
diff changeset
   204
apply (frule vt_grant_os, frule vd_cons)
chunhan
parents:
diff changeset
   205
apply (induct ms rule:rev_induct)
chunhan
parents:
diff changeset
   206
apply (auto split:if_splits option.splits simp:cqm2sms_simps2 cm2smsg_recvmsg2')
chunhan
parents:
diff changeset
   207
done
chunhan
parents:
diff changeset
   208
chunhan
parents:
diff changeset
   209
lemma cqm2sms_recvmsg2:
chunhan
parents:
diff changeset
   210
  "\<lbrakk>valid (RecvMsg p q m # s); q' \<noteq> q\<rbrakk>
chunhan
parents:
diff changeset
   211
   \<Longrightarrow> cqm2sms (RecvMsg p q m # s) q' ms = cqm2sms s q' ms"
chunhan
parents:
diff changeset
   212
apply (frule vt_grant_os, frule vd_cons)
chunhan
parents:
diff changeset
   213
apply (induct ms rule:rev_induct)
chunhan
parents:
diff changeset
   214
apply (auto split:if_splits option.splits simp:cqm2sms_simps2 cm2smsg_recvmsg1')
chunhan
parents:
diff changeset
   215
done
chunhan
parents:
diff changeset
   216
chunhan
parents:
diff changeset
   217
lemma cqm2sms_recvmsg:
chunhan
parents:
diff changeset
   218
  "\<lbrakk>valid (RecvMsg p q m # s); ms = msgs_of_queue (RecvMsg p q m # s) q'\<rbrakk>
chunhan
parents:
diff changeset
   219
   \<Longrightarrow> cqm2sms (RecvMsg p q m # s) q' ms = (
chunhan
parents:
diff changeset
   220
     if (q' = q) 
chunhan
parents:
diff changeset
   221
     then (case (cqm2sms s q (msgs_of_queue s q)) of
chunhan
parents:
diff changeset
   222
             Some sms \<Rightarrow> Some (tl sms)
chunhan
parents:
diff changeset
   223
           | _ \<Rightarrow> None)
chunhan
parents:
diff changeset
   224
     else cqm2sms s q' ms)"
chunhan
parents:
diff changeset
   225
apply (frule vt_grant_os, frule vd_cons)
chunhan
parents:
diff changeset
   226
apply (auto split:if_splits option.splits simp:cqm2sms_recvmsg1 cqm2sms_recvmsg2 
chunhan
parents:
diff changeset
   227
     dest!:current_has_sms')
chunhan
parents:
diff changeset
   228
apply (case_tac "msgs_of_queue s q", simp)
chunhan
parents:
diff changeset
   229
apply (frule_tac ms = "tl (msgs_of_queue s q)" in cqm2sms_recvmsg1)
chunhan
parents:
diff changeset
   230
apply (drule_tac q = q in distinct_queue_msgs, simp+)
chunhan
parents:
diff changeset
   231
apply (case_tac a, auto simp:cqm2sms.simps split:option.splits if_splits)
chunhan
parents:
diff changeset
   232
done
chunhan
parents:
diff changeset
   233
chunhan
parents:
diff changeset
   234
lemma cqm2sms_removemsgq:
chunhan
parents:
diff changeset
   235
  "\<lbrakk>valid (RemoveMsgq p q # s); q' \<noteq> q; q' \<in> current_msgqs s\<rbrakk> 
chunhan
parents:
diff changeset
   236
   \<Longrightarrow> cqm2sms (RemoveMsgq p q # s) q' ms = cqm2sms s q' ms"
chunhan
parents:
diff changeset
   237
apply (frule vt_grant_os, frule vd_cons)
chunhan
parents:
diff changeset
   238
apply (induct ms rule:rev_induct)
chunhan
parents:
diff changeset
   239
apply (auto simp:cqm2sms_simps2 cm2smsg_removemsgq split:option.splits if_splits)
chunhan
parents:
diff changeset
   240
done
chunhan
parents:
diff changeset
   241
  
chunhan
parents:
diff changeset
   242
lemmas cqm2sms_simps = cqm2sms_other cqm2sms_createmsgq cqm2sms_sendmsg cqm2sms_recvmsg cqm2sms_removemsgq
chunhan
parents:
diff changeset
   243
chunhan
parents:
diff changeset
   244
(********************* cq2smsgq simpset ***********************) 
chunhan
parents:
diff changeset
   245
 
chunhan
parents:
diff changeset
   246
lemma cq2smsgq_other: 
chunhan
parents:
diff changeset
   247
  "\<lbrakk>valid (e # s); \<forall> p q. e \<noteq> CreateMsgq p q; \<forall> p q m. e \<noteq> SendMsg p q m; 
chunhan
parents:
diff changeset
   248
    \<forall> p q m. e \<noteq> RecvMsg p q m; \<forall> p q. e \<noteq> RemoveMsgq p q\<rbrakk> 
chunhan
parents:
diff changeset
   249
   \<Longrightarrow> cq2smsgq (e # s) = cq2smsgq s" 
chunhan
parents:
diff changeset
   250
apply (frule cqm2sms_other, simp+)
chunhan
parents:
diff changeset
   251
apply (frule vd_cons, frule vt_grant_os, rule ext, case_tac e) 
chunhan
parents:
diff changeset
   252
apply (auto simp:cq2smsgq_def sectxt_of_obj_simps 
88
chunhan
parents: 87
diff changeset
   253
           split:t_object.splits option.splits if_splits)
77
chunhan
parents:
diff changeset
   254
done
chunhan
parents:
diff changeset
   255
chunhan
parents:
diff changeset
   256
lemma cq2smsg_createmsgq:
chunhan
parents:
diff changeset
   257
  "valid (CreateMsgq p q # s)
chunhan
parents:
diff changeset
   258
   \<Longrightarrow> cq2smsgq (CreateMsgq p q # s) = (cq2smsgq s) (q := 
chunhan
parents:
diff changeset
   259
     case (sectxt_of_obj s (O_proc p)) of
chunhan
parents:
diff changeset
   260
       Some psec \<Rightarrow> Some (Created, (fst psec, R_object, (snd o snd) psec), [])
chunhan
parents:
diff changeset
   261
     | None     \<Rightarrow> None)"
chunhan
parents:
diff changeset
   262
apply (frule vd_cons, frule vt_grant_os)
chunhan
parents:
diff changeset
   263
apply (frule cqm2sms_createmsgq)
chunhan
parents:
diff changeset
   264
apply (rule ext, auto simp:cq2smsgq_def sec_createmsgq 
87
8d18cfc845dd remove init message queue
chunhan
parents: 85
diff changeset
   265
  split:option.splits if_splits)
77
chunhan
parents:
diff changeset
   266
done
chunhan
parents:
diff changeset
   267
chunhan
parents:
diff changeset
   268
lemma cq2smsg_sendmsg:
chunhan
parents:
diff changeset
   269
  "valid (SendMsg p q m # s) 
chunhan
parents:
diff changeset
   270
   \<Longrightarrow> cq2smsgq (SendMsg p q m # s) = (cq2smsgq s) (q := 
chunhan
parents:
diff changeset
   271
     case (cq2smsgq s q, sectxt_of_obj (SendMsg p q m # s) (O_msg q m)) of 
chunhan
parents:
diff changeset
   272
       (Some (qi, sec, sms), Some msec) \<Rightarrow> 
chunhan
parents:
diff changeset
   273
          Some (qi, sec, sms @ [(Created, msec, O_msg q m \<in> tainted (SendMsg p q m # s))])
chunhan
parents:
diff changeset
   274
     | _ \<Rightarrow> None)"
chunhan
parents:
diff changeset
   275
apply (frule vd_cons, frule vt_grant_os)
chunhan
parents:
diff changeset
   276
apply (rule ext)
chunhan
parents:
diff changeset
   277
apply (frule_tac q' = x in cqm2sms_sendmsg, simp)
chunhan
parents:
diff changeset
   278
apply (auto simp:cq2smsgq_def sectxt_of_obj_simps  split:option.splits if_splits
chunhan
parents:
diff changeset
   279
  dest!:current_has_sms' current_has_sec')
chunhan
parents:
diff changeset
   280
done
chunhan
parents:
diff changeset
   281
chunhan
parents:
diff changeset
   282
lemma current_has_smsgq:
chunhan
parents:
diff changeset
   283
  "\<lbrakk>q \<in> current_msgqs s; valid s\<rbrakk> \<Longrightarrow> \<exists> sq. cq2smsgq s q = Some sq"
88
chunhan
parents: 87
diff changeset
   284
by (auto simp:cq2smsgq_def split:option.splits 
chunhan
parents: 87
diff changeset
   285
  dest!:current_has_sec' current_has_sms' dest:current_has_sec)
77
chunhan
parents:
diff changeset
   286
chunhan
parents:
diff changeset
   287
lemma current_has_smsgq':
chunhan
parents:
diff changeset
   288
  "\<lbrakk>cq2smsgq s q = None; valid s\<rbrakk> \<Longrightarrow> q \<notin> current_msgqs s"
chunhan
parents:
diff changeset
   289
by (auto dest:current_has_smsgq)
chunhan
parents:
diff changeset
   290
chunhan
parents:
diff changeset
   291
lemma cq2smsg_recvmsg:
chunhan
parents:
diff changeset
   292
  "valid (RecvMsg p q m # s) 
chunhan
parents:
diff changeset
   293
   \<Longrightarrow> cq2smsgq (RecvMsg p q m # s) = (cq2smsgq s) (q := 
chunhan
parents:
diff changeset
   294
    case (cq2smsgq s q) of
chunhan
parents:
diff changeset
   295
      Some (qi, sec, sms) \<Rightarrow> Some (qi, sec, tl sms)
chunhan
parents:
diff changeset
   296
    | _ \<Rightarrow> None)"
chunhan
parents:
diff changeset
   297
apply (frule vd_cons, frule vt_grant_os)
chunhan
parents:
diff changeset
   298
apply (rule ext, frule_tac q' = x in cqm2sms_recvmsg, simp)
chunhan
parents:
diff changeset
   299
apply (auto simp add:cq2smsgq_def sectxt_of_obj_simps split:option.splits if_splits 
chunhan
parents:
diff changeset
   300
  dest!:current_has_sec' current_has_sms' current_has_smsgq')
chunhan
parents:
diff changeset
   301
done
chunhan
parents:
diff changeset
   302
chunhan
parents:
diff changeset
   303
lemma cq2smsg_removemsgq:
chunhan
parents:
diff changeset
   304
  "\<lbrakk>valid (RemoveMsgq p q # s); q' \<noteq> q; q' \<in> current_msgqs s\<rbrakk>
chunhan
parents:
diff changeset
   305
   \<Longrightarrow> cq2smsgq (RemoveMsgq p q # s) q' = cq2smsgq s q'"
chunhan
parents:
diff changeset
   306
apply (frule vd_cons, frule vt_grant_os)
chunhan
parents:
diff changeset
   307
apply (auto simp:cq2smsgq_def sectxt_of_obj_simps cqm2sms_removemsgq split:if_splits option.splits 
chunhan
parents:
diff changeset
   308
  dest!:current_has_sec' current_has_sms' current_has_smsgq')
chunhan
parents:
diff changeset
   309
done
chunhan
parents:
diff changeset
   310
chunhan
parents:
diff changeset
   311
lemmas cq2smsgq_simps = cq2smsgq_other cq2smsg_sendmsg cq2smsg_recvmsg cq2smsg_removemsgq
chunhan
parents:
diff changeset
   312
88
chunhan
parents: 87
diff changeset
   313
(*
77
chunhan
parents:
diff changeset
   314
lemma sm_in_sqsms_init_aux:
chunhan
parents:
diff changeset
   315
  "\<lbrakk>m \<in> set ms; init_cm2smsg q m = Some sm; q \<in> init_msgqs; 
chunhan
parents:
diff changeset
   316
    init_cqm2sms q ms = Some sms\<rbrakk> \<Longrightarrow> sm \<in> set sms"
chunhan
parents:
diff changeset
   317
apply (induct ms arbitrary:m sm sms)
chunhan
parents:
diff changeset
   318
by (auto split:if_splits option.splits)
chunhan
parents:
diff changeset
   319
chunhan
parents:
diff changeset
   320
lemma sm_in_sqsms_init:
chunhan
parents:
diff changeset
   321
  "\<lbrakk>m \<in> set (init_msgs_of_queue q); init_cm2smsg q m = Some sm; q \<in> init_msgqs; 
chunhan
parents:
diff changeset
   322
    init_cqm2sms q (init_msgs_of_queue q) = Some sms\<rbrakk> \<Longrightarrow> sm \<in> set sms"
chunhan
parents:
diff changeset
   323
by (simp add:sm_in_sqsms_init_aux)
88
chunhan
parents: 87
diff changeset
   324
*)
77
chunhan
parents:
diff changeset
   325
chunhan
parents:
diff changeset
   326
lemma cqm2sms_prop0:
chunhan
parents:
diff changeset
   327
  "\<lbrakk>m \<in> set ms; cm2smsg s q m = Some sm; cqm2sms s q ms = Some sms\<rbrakk> \<Longrightarrow> sm \<in> set sms"
chunhan
parents:
diff changeset
   328
apply (induct ms arbitrary:m sm sms)
chunhan
parents:
diff changeset
   329
apply (auto simp:cqm2sms.simps split:option.splits)
chunhan
parents:
diff changeset
   330
done
chunhan
parents:
diff changeset
   331
chunhan
parents:
diff changeset
   332
lemma sm_in_sqsms:
chunhan
parents:
diff changeset
   333
  "\<lbrakk>m \<in> set (msgs_of_queue s q); q \<in> current_msgqs s; valid s; cq2smsgq s q = Some (qi, qsec, sms);
chunhan
parents:
diff changeset
   334
    cm2smsg s q m = Some sm\<rbrakk> \<Longrightarrow> sm \<in> set sms"
chunhan
parents:
diff changeset
   335
proof (induct s arbitrary:m q qi qsec sms sm)
chunhan
parents:
diff changeset
   336
  case Nil
chunhan
parents:
diff changeset
   337
  thus ?case 
88
chunhan
parents: 87
diff changeset
   338
    by (simp split:option.splits)
77
chunhan
parents:
diff changeset
   339
next
chunhan
parents:
diff changeset
   340
  case (Cons e s)
chunhan
parents:
diff changeset
   341
  hence p1:"\<And> m q qi qsec sms sm. \<lbrakk>m \<in> set (msgs_of_queue s q); q \<in> current_msgqs s; valid s; 
chunhan
parents:
diff changeset
   342
    cq2smsgq s q = Some (qi, qsec, sms); cm2smsg s q m = Some sm\<rbrakk>
chunhan
parents:
diff changeset
   343
    \<Longrightarrow> sm \<in> set sms" and p2: "m \<in> set (msgs_of_queue (e # s) q)" 
chunhan
parents:
diff changeset
   344
    and p3: "q \<in> current_msgqs (e # s)" and p4: "valid (e # s)"
chunhan
parents:
diff changeset
   345
    and p5: "cq2smsgq (e # s) q = Some (qi, qsec, sms)"
chunhan
parents:
diff changeset
   346
    and p6: "cm2smsg (e # s) q m = Some sm" by auto
chunhan
parents:
diff changeset
   347
  from p4 have os: "os_grant s e" and vd: "valid s" by (auto dest:vd_cons vt_grant_os)
chunhan
parents:
diff changeset
   348
(*
chunhan
parents:
diff changeset
   349
  from p1 have p1':
chunhan
parents:
diff changeset
   350
    "\<And> m q qi qsec sms sm ms. \<lbrakk>m \<in> set ms; set ms \<subseteq> set (msgs_of_queue s q); q \<in> current_msgqs s;
chunhan
parents:
diff changeset
   351
    valid s; cq2smsgq s q = Some (qi, qsec, sms); cm2smsg s q m = Some sm\<rbrakk>
chunhan
parents:
diff changeset
   352
    \<Longrightarrow> sm \<in> set "
chunhan
parents:
diff changeset
   353
*)
chunhan
parents:
diff changeset
   354
  show ?case using p2 p3 p4 p5 p6 vd os
chunhan
parents:
diff changeset
   355
    apply (case_tac e)
chunhan
parents:
diff changeset
   356
    apply (auto simp:cq2smsgq_simps cm2smsg_simps split:if_splits option.splits intro:p1)
chunhan
parents:
diff changeset
   357
chunhan
parents:
diff changeset
   358
    apply (rule_tac m = m and q = q and qi = qi and qsec = qsec in p1, simp+)
chunhan
parents:
diff changeset
   359
    apply (case_tac "q = nat2", simp)
chunhan
parents:
diff changeset
   360
    apply (drule cq2smsg_createmsgq, simp, simp)
chunhan
parents:
diff changeset
   361
chunhan
parents:
diff changeset
   362
    apply (drule_tac m = m and q = q and qi = qi and qsec = "(aa,ab,b)" in p1, simp+)
chunhan
parents:
diff changeset
   363
    apply (drule_tac m = m and q = q and qi = qi and qsec = "(aa,ab,b)" in p1, simp+)
chunhan
parents:
diff changeset
   364
chunhan
parents:
diff changeset
   365
    apply (simp add:cq2smsgq_def split:option.splits)
chunhan
parents:
diff changeset
   366
    apply (rule_tac m = m and sm = sm in cqm2sms_prop0, simp+)
chunhan
parents:
diff changeset
   367
    apply (simp add:cqm2sms_recvmsg)
chunhan
parents:
diff changeset
   368
    done
chunhan
parents:
diff changeset
   369
qed
chunhan
parents:
diff changeset
   370
chunhan
parents:
diff changeset
   371
(****************** cf2sfile path simpset ***************)
chunhan
parents:
diff changeset
   372
chunhan
parents:
diff changeset
   373
lemma sroot_only:
chunhan
parents:
diff changeset
   374
  "cf2sfile s [] = Some sroot"
chunhan
parents:
diff changeset
   375
by (simp add:cf2sfile_def)
chunhan
parents:
diff changeset
   376
chunhan
parents:
diff changeset
   377
lemma not_file_is_dir:
chunhan
parents:
diff changeset
   378
  "\<lbrakk>\<not> is_file s f; f \<in> current_files s; valid s\<rbrakk> \<Longrightarrow> is_dir s f"
chunhan
parents:
diff changeset
   379
by (auto simp:is_file_def current_files_def is_dir_def 
chunhan
parents:
diff changeset
   380
         dest:finum_has_itag finum_has_ftag' split:t_inode_tag.splits option.splits)
chunhan
parents:
diff changeset
   381
chunhan
parents:
diff changeset
   382
lemma not_dir_is_file:
chunhan
parents:
diff changeset
   383
  "\<lbrakk>\<not> is_dir s f; f \<in> current_files s; valid s\<rbrakk> \<Longrightarrow> is_file s f"
chunhan
parents:
diff changeset
   384
by (auto simp:is_file_def current_files_def is_dir_def 
chunhan
parents:
diff changeset
   385
         dest:finum_has_itag finum_has_ftag' split:t_inode_tag.splits option.splits)
chunhan
parents:
diff changeset
   386
chunhan
parents:
diff changeset
   387
lemma is_file_or_dir:
chunhan
parents:
diff changeset
   388
  "\<lbrakk>f \<in> current_files s; valid s\<rbrakk> \<Longrightarrow> is_file s f \<or> is_dir s f"
chunhan
parents:
diff changeset
   389
by (auto dest:not_dir_is_file)
chunhan
parents:
diff changeset
   390
chunhan
parents:
diff changeset
   391
lemma current_file_has_sfile:
chunhan
parents:
diff changeset
   392
  "\<lbrakk>f \<in> current_files s; valid s\<rbrakk> \<Longrightarrow> \<exists> sf. cf2sfile s f = Some sf"
chunhan
parents:
diff changeset
   393
apply (induct f)
chunhan
parents:
diff changeset
   394
apply (rule_tac x = "sroot" in exI, simp add:sroot_only)
chunhan
parents:
diff changeset
   395
apply (frule parentf_in_current', simp, clarsimp)
chunhan
parents:
diff changeset
   396
apply (frule parentf_is_dir'', simp)
chunhan
parents:
diff changeset
   397
apply (frule is_file_or_dir, simp)
chunhan
parents:
diff changeset
   398
apply (auto dest!:current_has_sec'
chunhan
parents:
diff changeset
   399
            simp:cf2sfile_def split:option.splits if_splits dest!:get_pfs_secs_prop')
chunhan
parents:
diff changeset
   400
done
chunhan
parents:
diff changeset
   401
chunhan
parents:
diff changeset
   402
definition sectxt_of_pf :: "t_state \<Rightarrow> t_file \<Rightarrow> security_context_t option"
chunhan
parents:
diff changeset
   403
where
chunhan
parents:
diff changeset
   404
  "sectxt_of_pf s f = (case f of [] \<Rightarrow> None | (a # pf) \<Rightarrow> sectxt_of_obj s (O_dir pf))"
chunhan
parents:
diff changeset
   405
chunhan
parents:
diff changeset
   406
definition get_parentfs_ctxts' :: "t_state \<Rightarrow> t_file \<Rightarrow> (security_context_t list) option"
chunhan
parents:
diff changeset
   407
where
chunhan
parents:
diff changeset
   408
  "get_parentfs_ctxts' s f = (case f of [] \<Rightarrow> None | (a # pf) \<Rightarrow> get_parentfs_ctxts s pf)"
chunhan
parents:
diff changeset
   409
chunhan
parents:
diff changeset
   410
lemma is_file_has_sfile:
chunhan
parents:
diff changeset
   411
  "\<lbrakk>is_file s f; valid s\<rbrakk> \<Longrightarrow> \<exists> sec psec asecs. cf2sfile s f = Some 
chunhan
parents:
diff changeset
   412
      (if (\<not> died (O_file f) s \<and> is_init_file f) then Init f else Created,
chunhan
parents:
diff changeset
   413
       sec, Some psec, set asecs) \<and> (sectxt_of_obj s (O_file f) = Some sec) \<and>
chunhan
parents:
diff changeset
   414
       (sectxt_of_pf s f = Some psec) \<and> (get_parentfs_ctxts' s f = Some asecs)"
chunhan
parents:
diff changeset
   415
apply (case_tac f, simp, drule root_is_dir', simp, simp)
chunhan
parents:
diff changeset
   416
apply (frule is_file_in_current)
chunhan
parents:
diff changeset
   417
apply (drule current_file_has_sfile, simp)
chunhan
parents:
diff changeset
   418
apply (auto simp:cf2sfile_def sectxt_of_pf_def get_parentfs_ctxts'_def split:if_splits option.splits)
chunhan
parents:
diff changeset
   419
done
chunhan
parents:
diff changeset
   420
chunhan
parents:
diff changeset
   421
lemma is_file_has_sfile':
chunhan
parents:
diff changeset
   422
  "\<lbrakk>is_file s f; valid s\<rbrakk> \<Longrightarrow> \<exists> sf. cf2sfile s f = Some sf"
chunhan
parents:
diff changeset
   423
by (drule is_file_has_sfile, auto)
chunhan
parents:
diff changeset
   424
chunhan
parents:
diff changeset
   425
lemma is_dir_has_sfile:
chunhan
parents:
diff changeset
   426
  "\<lbrakk>is_dir s f; valid s\<rbrakk> \<Longrightarrow> (case f of
chunhan
parents:
diff changeset
   427
      [] \<Rightarrow> cf2sfile s f = Some sroot
chunhan
parents:
diff changeset
   428
    | a # pf \<Rightarrow> (\<exists> sec psec asecs. cf2sfile s f = Some 
chunhan
parents:
diff changeset
   429
      (if (\<not> died (O_dir f) s \<and> is_init_dir f) then Init f else Created,
chunhan
parents:
diff changeset
   430
       sec, Some psec, set asecs) \<and> (sectxt_of_obj s (O_dir f) = Some sec) \<and>
chunhan
parents:
diff changeset
   431
       (sectxt_of_obj s (O_dir pf) = Some psec) \<and> (get_parentfs_ctxts s pf = Some asecs)))"
chunhan
parents:
diff changeset
   432
apply (case_tac f, simp add:sroot_only)
chunhan
parents:
diff changeset
   433
apply (frule is_dir_in_current, frule is_dir_not_file)
chunhan
parents:
diff changeset
   434
apply (drule current_file_has_sfile, simp)
chunhan
parents:
diff changeset
   435
apply (auto simp:cf2sfile_def split:if_splits option.splits)
chunhan
parents:
diff changeset
   436
done
chunhan
parents:
diff changeset
   437
chunhan
parents:
diff changeset
   438
lemma is_dir_has_sdir':
chunhan
parents:
diff changeset
   439
  "\<lbrakk>is_dir s f; valid s\<rbrakk> \<Longrightarrow> \<exists> sf. cf2sfile s f = Some sf"
chunhan
parents:
diff changeset
   440
apply (case_tac f)
chunhan
parents:
diff changeset
   441
apply (rule_tac x = sroot in exI)
chunhan
parents:
diff changeset
   442
apply (simp add:sroot_only)
chunhan
parents:
diff changeset
   443
apply (drule is_dir_has_sfile, auto)
chunhan
parents:
diff changeset
   444
done
chunhan
parents:
diff changeset
   445
chunhan
parents:
diff changeset
   446
lemma sroot_set:
chunhan
parents:
diff changeset
   447
  "valid s \<Longrightarrow> \<exists> sec. sroot = (Init [], sec, None, {}) \<and> sectxt_of_obj s (O_dir []) = Some sec"
chunhan
parents:
diff changeset
   448
apply (frule root_is_dir)
chunhan
parents:
diff changeset
   449
apply (drule is_dir_has_sec, simp)
chunhan
parents:
diff changeset
   450
apply (auto simp:sroot_def sec_of_root_def sectxt_of_obj_def type_of_obj.simps 
chunhan
parents:
diff changeset
   451
                 root_type_remains root_user_remains
chunhan
parents:
diff changeset
   452
           dest!:root_has_type' root_has_user' root_has_init_type' root_has_init_user'
chunhan
parents:
diff changeset
   453
           split:option.splits)
chunhan
parents:
diff changeset
   454
done
chunhan
parents:
diff changeset
   455
chunhan
parents:
diff changeset
   456
lemma cf2sfile_path_file:
chunhan
parents:
diff changeset
   457
  "\<lbrakk>is_file s (f # pf); valid s\<rbrakk>
chunhan
parents:
diff changeset
   458
   \<Longrightarrow> cf2sfile s (f # pf) = (
chunhan
parents:
diff changeset
   459
     case (cf2sfile s pf) of
chunhan
parents:
diff changeset
   460
       Some (pfi, pfsec, psec, asecs) \<Rightarrow> 
chunhan
parents:
diff changeset
   461
          (case (sectxt_of_obj s (O_file (f # pf))) of
chunhan
parents:
diff changeset
   462
              Some fsec \<Rightarrow> Some (if (\<not> died (O_file (f # pf)) s \<and> is_init_file (f # pf)) then Init (f # pf)
chunhan
parents:
diff changeset
   463
                                else Created, fsec, Some pfsec, asecs \<union> {pfsec})
chunhan
parents:
diff changeset
   464
           | None \<Rightarrow> None)
chunhan
parents:
diff changeset
   465
     | _ \<Rightarrow> None)"
chunhan
parents:
diff changeset
   466
apply (frule is_file_in_current, drule parentf_is_dir'', simp)
chunhan
parents:
diff changeset
   467
apply (frule is_dir_has_sfile, simp, frule is_file_has_sfile, simp)
chunhan
parents:
diff changeset
   468
apply (frule sroot_set)
chunhan
parents:
diff changeset
   469
apply (case_tac pf, (clarsimp simp:get_parentfs_ctxts'_def sectxt_of_pf_def)+) 
chunhan
parents:
diff changeset
   470
done
chunhan
parents:
diff changeset
   471
chunhan
parents:
diff changeset
   472
lemma cf2sfile_path_dir:
chunhan
parents:
diff changeset
   473
  "\<lbrakk>is_dir s (f # pf); valid s\<rbrakk>
chunhan
parents:
diff changeset
   474
   \<Longrightarrow> cf2sfile s (f # pf) = (
chunhan
parents:
diff changeset
   475
     case (cf2sfile s pf) of
chunhan
parents:
diff changeset
   476
       Some (pfi, pfsec, psec, asecs) \<Rightarrow> 
chunhan
parents:
diff changeset
   477
          (case (sectxt_of_obj s (O_dir (f # pf))) of
chunhan
parents:
diff changeset
   478
              Some fsec \<Rightarrow> Some (if (\<not> died (O_dir (f # pf)) s \<and> is_init_dir (f # pf)) then Init (f # pf)
chunhan
parents:
diff changeset
   479
                                else Created, fsec, Some pfsec, asecs \<union> {pfsec})
chunhan
parents:
diff changeset
   480
           | None \<Rightarrow> None)
chunhan
parents:
diff changeset
   481
     | _ \<Rightarrow> None)"
chunhan
parents:
diff changeset
   482
apply (frule is_dir_in_current, drule parentf_is_dir'', simp)
chunhan
parents:
diff changeset
   483
apply (frule_tac f = "f # pf" in is_dir_has_sfile, simp)
chunhan
parents:
diff changeset
   484
apply (frule_tac f = "pf" in is_dir_has_sfile, simp)
chunhan
parents:
diff changeset
   485
apply (frule sroot_set)
chunhan
parents:
diff changeset
   486
apply (case_tac pf, (clarsimp simp:get_parentfs_ctxts'_def sectxt_of_pf_def)+) 
chunhan
parents:
diff changeset
   487
done  
chunhan
parents:
diff changeset
   488
chunhan
parents:
diff changeset
   489
lemma cf2sfile_path:
chunhan
parents:
diff changeset
   490
  "\<lbrakk>f # pf \<in> current_files s; valid s\<rbrakk> \<Longrightarrow> cf2sfile s (f # pf) = (
chunhan
parents:
diff changeset
   491
     case (cf2sfile s pf) of
chunhan
parents:
diff changeset
   492
       Some (pfi, pfsec, psec, asecs) \<Rightarrow> (if (is_file s (f # pf))
chunhan
parents:
diff changeset
   493
         then (case (sectxt_of_obj s (O_file (f # pf))) of
chunhan
parents:
diff changeset
   494
                 Some fsec \<Rightarrow> Some (if (\<not> died (O_file (f # pf)) s \<and> is_init_file (f # pf)) then Init (f # pf)
chunhan
parents:
diff changeset
   495
                                   else Created, fsec, Some pfsec, asecs \<union> {pfsec})
chunhan
parents:
diff changeset
   496
               | None \<Rightarrow> None)
chunhan
parents:
diff changeset
   497
         else (case (sectxt_of_obj s (O_dir (f # pf))) of
chunhan
parents:
diff changeset
   498
                 Some fsec \<Rightarrow> Some (if (\<not> died (O_dir (f # pf)) s \<and> is_init_dir (f # pf)) then Init (f # pf)
chunhan
parents:
diff changeset
   499
                                   else Created, fsec, Some pfsec, asecs \<union> {pfsec})
chunhan
parents:
diff changeset
   500
               | None \<Rightarrow> None)           )
chunhan
parents:
diff changeset
   501
     | None \<Rightarrow> None)"
chunhan
parents:
diff changeset
   502
apply (drule is_file_or_dir, simp)
chunhan
parents:
diff changeset
   503
apply (erule disjE)
chunhan
parents:
diff changeset
   504
apply (frule cf2sfile_path_file, simp) defer
chunhan
parents:
diff changeset
   505
apply (frule cf2sfile_path_dir, simp, drule is_dir_not_file)
chunhan
parents:
diff changeset
   506
apply (auto split:option.splits)
chunhan
parents:
diff changeset
   507
done
chunhan
parents:
diff changeset
   508
chunhan
parents:
diff changeset
   509
lemma cf2sfile_path_file_prop1:
chunhan
parents:
diff changeset
   510
  "\<lbrakk>is_file s (f # pf); cf2sfile s pf = Some (pfi, pfsec, psec, asecs); valid s\<rbrakk>
chunhan
parents:
diff changeset
   511
   \<Longrightarrow> \<exists> fsec. cf2sfile s (f # pf) = 
chunhan
parents:
diff changeset
   512
                 Some (if (\<not> died (O_file (f # pf)) s \<and> is_init_file (f # pf)) then Init (f # pf)
chunhan
parents:
diff changeset
   513
                       else Created, fsec, Some pfsec, asecs \<union> {pfsec}) \<and> 
chunhan
parents:
diff changeset
   514
               sectxt_of_obj s (O_file (f # pf)) = Some fsec"
chunhan
parents:
diff changeset
   515
apply (frule is_file_has_sfile, simp)
chunhan
parents:
diff changeset
   516
by (auto simp:cf2sfile_path_file)
chunhan
parents:
diff changeset
   517
chunhan
parents:
diff changeset
   518
lemma cf2sfile_path_file_prop2:
chunhan
parents:
diff changeset
   519
  "\<lbrakk>is_file s (f # pf); cf2sfile s pf = Some (pfi, pfsec, psec, asecs); 
chunhan
parents:
diff changeset
   520
    sectxt_of_obj s (O_file (f # pf)) = Some fsec; valid s\<rbrakk> \<Longrightarrow> cf2sfile s (f # pf) = 
chunhan
parents:
diff changeset
   521
      Some (if (\<not> died (O_file (f # pf)) s \<and> is_init_file (f # pf)) then Init (f # pf)
chunhan
parents:
diff changeset
   522
            else Created, fsec, Some pfsec, asecs \<union> {pfsec})"
chunhan
parents:
diff changeset
   523
by (drule cf2sfile_path_file_prop1, auto)
chunhan
parents:
diff changeset
   524
chunhan
parents:
diff changeset
   525
lemma cf2sfile_path_dir_prop1:
chunhan
parents:
diff changeset
   526
  "\<lbrakk>is_dir s (f # pf); cf2sfile s pf = Some (pfi, pfsec, psec, asecs); valid s\<rbrakk>
chunhan
parents:
diff changeset
   527
   \<Longrightarrow> \<exists> fsec. cf2sfile s (f # pf) = 
chunhan
parents:
diff changeset
   528
                 Some (if (\<not> died (O_dir (f # pf)) s \<and> is_init_dir (f # pf)) then Init (f # pf)
chunhan
parents:
diff changeset
   529
                       else Created, fsec, Some pfsec, asecs \<union> {pfsec}) \<and> 
chunhan
parents:
diff changeset
   530
               sectxt_of_obj s (O_dir (f # pf)) = Some fsec"
chunhan
parents:
diff changeset
   531
apply (frule is_dir_has_sfile, simp)
chunhan
parents:
diff changeset
   532
by (auto simp:cf2sfile_path_dir)
chunhan
parents:
diff changeset
   533
chunhan
parents:
diff changeset
   534
lemma cf2sfile_path_dir_prop2:
chunhan
parents:
diff changeset
   535
  "\<lbrakk>is_dir s (f # pf); cf2sfile s pf = Some (pfi, pfsec, psec, asecs); 
chunhan
parents:
diff changeset
   536
    sectxt_of_obj s (O_dir (f # pf)) = Some fsec; valid s\<rbrakk> \<Longrightarrow> cf2sfile s (f # pf) = 
chunhan
parents:
diff changeset
   537
      Some (if (\<not> died (O_dir (f # pf)) s \<and> is_init_dir (f # pf)) then Init (f # pf)
chunhan
parents:
diff changeset
   538
            else Created, fsec, Some pfsec, asecs \<union> {pfsec})"
chunhan
parents:
diff changeset
   539
by (drule cf2sfile_path_dir_prop1, auto)
chunhan
parents:
diff changeset
   540
chunhan
parents:
diff changeset
   541
(**************** cf2sfile event list simpset ****************)
chunhan
parents:
diff changeset
   542
chunhan
parents:
diff changeset
   543
lemma cf2sfile_open_none':
chunhan
parents:
diff changeset
   544
  "valid (Open p f flag fd None # s) \<Longrightarrow> cf2sfile (Open p f flag fd None # s) f'= cf2sfile s f'"
chunhan
parents:
diff changeset
   545
apply (frule vd_cons, frule vt_grant_os)
chunhan
parents:
diff changeset
   546
apply (induct f', simp add:cf2sfile_def)
chunhan
parents:
diff changeset
   547
apply (simp add:cf2sfile_def is_file_simps is_dir_simps current_files_simps sectxt_of_obj_simps 
chunhan
parents:
diff changeset
   548
               get_parentfs_ctxts_simps)
chunhan
parents:
diff changeset
   549
done
chunhan
parents:
diff changeset
   550
chunhan
parents:
diff changeset
   551
lemma cf2sfile_open_none:
chunhan
parents:
diff changeset
   552
  "valid (Open p f flag fd None # s) \<Longrightarrow> cf2sfile (Open p f flag fd None # s) = cf2sfile s"
chunhan
parents:
diff changeset
   553
apply (rule ext)
chunhan
parents:
diff changeset
   554
by (simp add:cf2sfile_open_none')
chunhan
parents:
diff changeset
   555
chunhan
parents:
diff changeset
   556
lemma cf2sfile_open_some1:
chunhan
parents:
diff changeset
   557
  "\<lbrakk>valid (Open p f flag fd (Some inum) # s); f' \<in> current_files s\<rbrakk>
chunhan
parents:
diff changeset
   558
   \<Longrightarrow> cf2sfile (Open p f flag fd (Some inum) # s) f' = cf2sfile s f'"
chunhan
parents:
diff changeset
   559
apply (frule vd_cons, frule vt_grant_os, frule noroot_events)
chunhan
parents:
diff changeset
   560
apply (case_tac "f = f'", simp)
chunhan
parents:
diff changeset
   561
apply (induct f', simp add:sroot_only, simp)
chunhan
parents:
diff changeset
   562
apply (frule parentf_in_current', simp+)
chunhan
parents:
diff changeset
   563
apply (simp add:cf2sfile_def is_file_simps is_dir_simps current_files_simps sectxt_of_obj_simps 
chunhan
parents:
diff changeset
   564
               get_parentfs_ctxts_simps)
chunhan
parents:
diff changeset
   565
done
chunhan
parents:
diff changeset
   566
chunhan
parents:
diff changeset
   567
lemma cf2sfile_open_some2:
chunhan
parents:
diff changeset
   568
  "\<lbrakk>valid (Open p f flag fd (Some inum) # s); is_file s f'\<rbrakk>
chunhan
parents:
diff changeset
   569
   \<Longrightarrow> cf2sfile (Open p f flag fd (Some inum) # s) f' = cf2sfile s f'"
chunhan
parents:
diff changeset
   570
apply (frule vd_cons, drule is_file_in_current)
chunhan
parents:
diff changeset
   571
by (simp add:cf2sfile_open_some1)
chunhan
parents:
diff changeset
   572
chunhan
parents:
diff changeset
   573
lemma cf2sfile_open_some3:
chunhan
parents:
diff changeset
   574
  "\<lbrakk>valid (Open p f flag fd (Some inum) # s); is_dir s f'\<rbrakk>
chunhan
parents:
diff changeset
   575
   \<Longrightarrow> cf2sfile (Open p f flag fd (Some inum) # s) f' = cf2sfile s f'"
chunhan
parents:
diff changeset
   576
apply (frule vd_cons, drule is_dir_in_current)
chunhan
parents:
diff changeset
   577
by (simp add:cf2sfile_open_some1)
chunhan
parents:
diff changeset
   578
chunhan
parents:
diff changeset
   579
lemma cf2sfile_open_some4:
chunhan
parents:
diff changeset
   580
  "valid (Open p f flag fd (Some inum) # s) \<Longrightarrow> cf2sfile (Open p f flag fd (Some inum) # s) f = (
chunhan
parents:
diff changeset
   581
     case (parent f) of
chunhan
parents:
diff changeset
   582
       Some pf \<Rightarrow> (case (sectxt_of_obj (Open p f flag fd (Some inum) # s) (O_file f), sectxt_of_obj s (O_dir pf), 
chunhan
parents:
diff changeset
   583
                         get_parentfs_ctxts s pf) of
chunhan
parents:
diff changeset
   584
                    (Some sec, Some psec, Some asecs) \<Rightarrow> Some (Created, sec, Some psec, set asecs)
chunhan
parents:
diff changeset
   585
                  | _ \<Rightarrow> None)
chunhan
parents:
diff changeset
   586
     | None \<Rightarrow> None)"
chunhan
parents:
diff changeset
   587
apply (frule vd_cons, frule vt_grant_os, frule noroot_events)
chunhan
parents:
diff changeset
   588
apply (case_tac f, simp)
chunhan
parents:
diff changeset
   589
apply (simp add:cf2sfile_def is_file_simps is_dir_simps current_files_simps sectxt_of_obj_simps 
chunhan
parents:
diff changeset
   590
               get_parentfs_ctxts_simps)
chunhan
parents:
diff changeset
   591
apply (rule impI, (erule conjE)+)
chunhan
parents:
diff changeset
   592
apply (drule not_died_init_file, simp+)
chunhan
parents:
diff changeset
   593
apply (simp add:is_file_in_current)
chunhan
parents:
diff changeset
   594
done
chunhan
parents:
diff changeset
   595
chunhan
parents:
diff changeset
   596
lemma cf2sfile_open:
chunhan
parents:
diff changeset
   597
  "\<lbrakk>valid (Open p f flag fd opt # s); f' \<in> current_files (Open p f flag fd opt # s)\<rbrakk>
chunhan
parents:
diff changeset
   598
   \<Longrightarrow> cf2sfile (Open p f flag fd opt # s) f' = (
chunhan
parents:
diff changeset
   599
     if (opt = None) then cf2sfile s f'
chunhan
parents:
diff changeset
   600
     else if (f' = f) 
chunhan
parents:
diff changeset
   601
     then (case (parent f) of
chunhan
parents:
diff changeset
   602
             Some pf \<Rightarrow> (case (sectxt_of_obj (Open p f flag fd opt # s) (O_file f), sectxt_of_obj s (O_dir pf), 
chunhan
parents:
diff changeset
   603
                 get_parentfs_ctxts s pf) of
chunhan
parents:
diff changeset
   604
                          (Some sec, Some psec, Some asecs) \<Rightarrow> Some (Created, sec, Some psec, set asecs)
chunhan
parents:
diff changeset
   605
                        | _ \<Rightarrow> None)
chunhan
parents:
diff changeset
   606
           | None \<Rightarrow> None)
chunhan
parents:
diff changeset
   607
     else cf2sfile s f')"
chunhan
parents:
diff changeset
   608
apply (case_tac opt)
chunhan
parents:
diff changeset
   609
apply (simp add:cf2sfile_open_none)
chunhan
parents:
diff changeset
   610
apply (case_tac "f = f'")
chunhan
parents:
diff changeset
   611
apply (simp add:cf2sfile_open_some4 split:option.splits)
chunhan
parents:
diff changeset
   612
apply (simp add:cf2sfile_open_some1 current_files_simps)
chunhan
parents:
diff changeset
   613
done
chunhan
parents:
diff changeset
   614
chunhan
parents:
diff changeset
   615
lemma cf2sfile_mkdir1:
chunhan
parents:
diff changeset
   616
  "\<lbrakk>valid (Mkdir p f i # s); f' \<in> current_files s\<rbrakk>
chunhan
parents:
diff changeset
   617
   \<Longrightarrow> cf2sfile (Mkdir p f i # s) f' = cf2sfile s f'"
chunhan
parents:
diff changeset
   618
apply (frule vd_cons, frule vt_grant_os, frule noroot_events)
chunhan
parents:
diff changeset
   619
apply (case_tac "f = f'", simp)
chunhan
parents:
diff changeset
   620
apply (induct f', simp add:sroot_only, simp)
chunhan
parents:
diff changeset
   621
apply (frule parentf_in_current', simp+)
chunhan
parents:
diff changeset
   622
apply (case_tac "f = f'", simp)
chunhan
parents:
diff changeset
   623
apply (simp add:cf2sfile_path is_file_simps is_dir_simps current_files_simps sectxt_of_obj_simps 
chunhan
parents:
diff changeset
   624
               get_parentfs_ctxts_simps split:if_splits option.splits)
chunhan
parents:
diff changeset
   625
done
chunhan
parents:
diff changeset
   626
chunhan
parents:
diff changeset
   627
lemma cf2sfile_mkdir2:
chunhan
parents:
diff changeset
   628
  "\<lbrakk>valid (Mkdir p f i # s); is_file s f'\<rbrakk>
chunhan
parents:
diff changeset
   629
   \<Longrightarrow> cf2sfile (Mkdir p f i # s) f' = cf2sfile s f'"
chunhan
parents:
diff changeset
   630
apply (frule vd_cons, drule is_file_in_current)
chunhan
parents:
diff changeset
   631
by (simp add:cf2sfile_mkdir1)
chunhan
parents:
diff changeset
   632
chunhan
parents:
diff changeset
   633
lemma cf2sfile_mkdir3:
chunhan
parents:
diff changeset
   634
  "\<lbrakk>valid (Mkdir p f i # s); is_dir s f'\<rbrakk>
chunhan
parents:
diff changeset
   635
   \<Longrightarrow> cf2sfile (Mkdir p f i # s) f' = cf2sfile s f'"
chunhan
parents:
diff changeset
   636
apply (frule vd_cons, drule is_dir_in_current)
chunhan
parents:
diff changeset
   637
by (simp add:cf2sfile_mkdir1)
chunhan
parents:
diff changeset
   638
chunhan
parents:
diff changeset
   639
lemma cf2sfile_mkdir4:
chunhan
parents:
diff changeset
   640
  "valid (Mkdir p f i # s)
chunhan
parents:
diff changeset
   641
  \<Longrightarrow> cf2sfile (Mkdir p f i # s) f = (case (parent f) of
chunhan
parents:
diff changeset
   642
         Some pf \<Rightarrow> (case (sectxt_of_obj (Mkdir p f i # s) (O_dir f), sectxt_of_obj s (O_dir pf), 
chunhan
parents:
diff changeset
   643
                           get_parentfs_ctxts s pf) of
chunhan
parents:
diff changeset
   644
                      (Some sec, Some psec, Some asecs) \<Rightarrow> Some (Created, sec, Some psec, set asecs)
chunhan
parents:
diff changeset
   645
                    | _ \<Rightarrow> None)
chunhan
parents:
diff changeset
   646
       | None \<Rightarrow> None)"
chunhan
parents:
diff changeset
   647
apply (frule vd_cons, frule vt_grant_os, frule noroot_events)
chunhan
parents:
diff changeset
   648
apply (case_tac f, simp)
chunhan
parents:
diff changeset
   649
apply (clarsimp simp:os_grant.simps)
chunhan
parents:
diff changeset
   650
apply (simp add:sectxt_of_obj_simps)
chunhan
parents:
diff changeset
   651
apply (frule current_proc_has_sec, simp)
chunhan
parents:
diff changeset
   652
apply (frule is_dir_has_sec, simp)
chunhan
parents:
diff changeset
   653
apply (frule get_pfs_secs_prop, simp)
chunhan
parents:
diff changeset
   654
apply (frule is_dir_not_file)
chunhan
parents:
diff changeset
   655
apply (auto simp add:cf2sfile_def is_file_simps is_dir_simps current_files_simps sectxt_of_obj_simps 
chunhan
parents:
diff changeset
   656
               get_parentfs_ctxts_simps split:option.splits if_splits 
chunhan
parents:
diff changeset
   657
            dest:not_died_init_dir is_dir_in_current not_died_init_file is_file_in_current)
chunhan
parents:
diff changeset
   658
done
chunhan
parents:
diff changeset
   659
chunhan
parents:
diff changeset
   660
lemma cf2sfile_mkdir:
chunhan
parents:
diff changeset
   661
  "\<lbrakk>valid (Mkdir p f i # s); f' \<in> current_files (Mkdir p f i # s)\<rbrakk>
chunhan
parents:
diff changeset
   662
  \<Longrightarrow> cf2sfile (Mkdir p f i # s) f' = (
chunhan
parents:
diff changeset
   663
    if (f' = f) 
chunhan
parents:
diff changeset
   664
    then (case (parent f) of
chunhan
parents:
diff changeset
   665
             Some pf \<Rightarrow> (case (sectxt_of_obj (Mkdir p f i # s) (O_dir f), sectxt_of_obj s (O_dir pf), 
chunhan
parents:
diff changeset
   666
                 get_parentfs_ctxts s pf) of
chunhan
parents:
diff changeset
   667
                          (Some sec, Some psec, Some asecs) \<Rightarrow> Some (Created, sec, Some psec, set asecs)
chunhan
parents:
diff changeset
   668
                        | _ \<Rightarrow> None)
chunhan
parents:
diff changeset
   669
           | None \<Rightarrow> None)
chunhan
parents:
diff changeset
   670
     else cf2sfile s f')"
chunhan
parents:
diff changeset
   671
apply (case_tac "f = f'")
chunhan
parents:
diff changeset
   672
apply (simp add:cf2sfile_mkdir4 split:option.splits)
chunhan
parents:
diff changeset
   673
apply (simp add:cf2sfile_mkdir1 current_files_simps)
chunhan
parents:
diff changeset
   674
done
chunhan
parents:
diff changeset
   675
chunhan
parents:
diff changeset
   676
lemma cf2sfile_linkhard1:
chunhan
parents:
diff changeset
   677
  "\<lbrakk>valid (LinkHard p oldf f # s); f' \<in> current_files s\<rbrakk>
chunhan
parents:
diff changeset
   678
   \<Longrightarrow> cf2sfile (LinkHard p oldf f# s) f' = cf2sfile s f'"
chunhan
parents:
diff changeset
   679
apply (frule vd_cons, frule vt_grant_os, frule noroot_events)
chunhan
parents:
diff changeset
   680
apply (case_tac "f = f'", simp)
chunhan
parents:
diff changeset
   681
apply (induct f', simp add:sroot_only, simp)
chunhan
parents:
diff changeset
   682
apply (frule parentf_in_current', simp+)
chunhan
parents:
diff changeset
   683
apply (simp add:cf2sfile_def is_file_simps is_dir_simps current_files_simps sectxt_of_obj_simps 
chunhan
parents:
diff changeset
   684
               get_parentfs_ctxts_simps split:if_splits option.splits)
chunhan
parents:
diff changeset
   685
done
chunhan
parents:
diff changeset
   686
chunhan
parents:
diff changeset
   687
lemma cf2sfile_linkhard2:
chunhan
parents:
diff changeset
   688
  "\<lbrakk>valid (LinkHard p oldf f # s); is_file s f'\<rbrakk>
chunhan
parents:
diff changeset
   689
   \<Longrightarrow> cf2sfile (LinkHard p oldf f # s) f' = cf2sfile s f'"
chunhan
parents:
diff changeset
   690
apply (frule vd_cons, drule is_file_in_current)
chunhan
parents:
diff changeset
   691
by (simp add:cf2sfile_linkhard1)
chunhan
parents:
diff changeset
   692
chunhan
parents:
diff changeset
   693
lemma cf2sfile_linkhard3:
chunhan
parents:
diff changeset
   694
  "\<lbrakk>valid (LinkHard p oldf f # s); is_dir s f'\<rbrakk>
chunhan
parents:
diff changeset
   695
   \<Longrightarrow> cf2sfile (LinkHard p oldf f # s) f' = cf2sfile s f'"
chunhan
parents:
diff changeset
   696
apply (frule vd_cons, drule is_dir_in_current)
chunhan
parents:
diff changeset
   697
by (simp add:cf2sfile_linkhard1)
chunhan
parents:
diff changeset
   698
chunhan
parents:
diff changeset
   699
lemma cf2sfile_linkhard4:
chunhan
parents:
diff changeset
   700
  "valid (LinkHard p oldf f # s)
chunhan
parents:
diff changeset
   701
  \<Longrightarrow> cf2sfile (LinkHard p oldf f # s) f = (case (parent f) of
chunhan
parents:
diff changeset
   702
         Some pf \<Rightarrow> (case (sectxt_of_obj (LinkHard p oldf f # s) (O_file f), sectxt_of_obj s (O_dir pf), 
chunhan
parents:
diff changeset
   703
                           get_parentfs_ctxts s pf) of
chunhan
parents:
diff changeset
   704
                      (Some sec, Some psec, Some asecs) \<Rightarrow> Some (Created, sec, Some psec, set asecs)
chunhan
parents:
diff changeset
   705
                    | _ \<Rightarrow> None)
chunhan
parents:
diff changeset
   706
       | None \<Rightarrow> None)"
chunhan
parents:
diff changeset
   707
apply (frule vd_cons, frule vt_grant_os, frule noroot_events)
chunhan
parents:
diff changeset
   708
apply (case_tac f, simp)
chunhan
parents:
diff changeset
   709
apply (simp add:cf2sfile_def is_file_simps is_dir_simps current_files_simps sectxt_of_obj_simps 
chunhan
parents:
diff changeset
   710
               get_parentfs_ctxts_simps)
chunhan
parents:
diff changeset
   711
apply (rule impI, (erule conjE)+)
chunhan
parents:
diff changeset
   712
apply (drule not_died_init_file, simp+)
chunhan
parents:
diff changeset
   713
apply (simp add:is_file_in_current)
chunhan
parents:
diff changeset
   714
done
chunhan
parents:
diff changeset
   715
chunhan
parents:
diff changeset
   716
lemma cf2sfile_linkhard:
chunhan
parents:
diff changeset
   717
  "\<lbrakk>valid (LinkHard p oldf f # s); f' \<in> current_files (LinkHard p oldf f # s)\<rbrakk>
chunhan
parents:
diff changeset
   718
  \<Longrightarrow> cf2sfile (LinkHard p oldf f # s) f' = (
chunhan
parents:
diff changeset
   719
    if (f' = f) 
chunhan
parents:
diff changeset
   720
    then (case (parent f) of
chunhan
parents:
diff changeset
   721
             Some pf \<Rightarrow> (case (sectxt_of_obj (LinkHard p oldf f # s) (O_file f), sectxt_of_obj s (O_dir pf), 
chunhan
parents:
diff changeset
   722
                 get_parentfs_ctxts s pf) of
chunhan
parents:
diff changeset
   723
                          (Some sec, Some psec, Some asecs) \<Rightarrow> Some (Created, sec, Some psec, set asecs)
chunhan
parents:
diff changeset
   724
                        | _ \<Rightarrow> None)
chunhan
parents:
diff changeset
   725
           | None \<Rightarrow> None)
chunhan
parents:
diff changeset
   726
     else cf2sfile s f')"
chunhan
parents:
diff changeset
   727
apply (case_tac "f = f'")
chunhan
parents:
diff changeset
   728
apply (simp add:cf2sfile_linkhard4 split:option.splits)
chunhan
parents:
diff changeset
   729
apply (simp add:cf2sfile_linkhard1 current_files_simps)
chunhan
parents:
diff changeset
   730
done
chunhan
parents:
diff changeset
   731
chunhan
parents:
diff changeset
   732
lemma cf2sfile_other:
chunhan
parents:
diff changeset
   733
  "\<lbrakk>ff \<in> current_files s;
chunhan
parents:
diff changeset
   734
    \<forall> p f flag fd opt. e \<noteq> Open p f flag fd opt;
chunhan
parents:
diff changeset
   735
    \<forall> p fd. e \<noteq> CloseFd p fd;
chunhan
parents:
diff changeset
   736
    \<forall> p f. e \<noteq> UnLink p f;
chunhan
parents:
diff changeset
   737
    \<forall> p f. e \<noteq> Rmdir p f;
chunhan
parents:
diff changeset
   738
    \<forall> p f i. e \<noteq> Mkdir p f i;
chunhan
parents:
diff changeset
   739
    \<forall> p f f'. e \<noteq> LinkHard p f f'; 
chunhan
parents:
diff changeset
   740
    valid (e # s)\<rbrakk> \<Longrightarrow> cf2sfile (e # s) ff = cf2sfile s ff"
chunhan
parents:
diff changeset
   741
apply (frule vd_cons, frule vt_grant_os)
chunhan
parents:
diff changeset
   742
apply (induct ff, simp add:sroot_only)
chunhan
parents:
diff changeset
   743
apply (frule parentf_in_current', simp+, case_tac e)
chunhan
parents:
diff changeset
   744
apply (auto simp:current_files_simps is_file_simps is_dir_simps sectxt_of_obj_simps cf2sfile_path 
chunhan
parents:
diff changeset
   745
           split:if_splits option.splits)                     
chunhan
parents:
diff changeset
   746
done     
chunhan
parents:
diff changeset
   747
chunhan
parents:
diff changeset
   748
lemma cf2sfile_other':
chunhan
parents:
diff changeset
   749
  "\<lbrakk>valid (e # s); 
chunhan
parents:
diff changeset
   750
    \<forall> p f flag fd opt. e \<noteq> Open p f flag fd opt;
chunhan
parents:
diff changeset
   751
    \<forall> p fd. e \<noteq> CloseFd p fd;
chunhan
parents:
diff changeset
   752
    \<forall> p f. e \<noteq> UnLink p f;
chunhan
parents:
diff changeset
   753
    \<forall> p f. e \<noteq> Rmdir p f;
chunhan
parents:
diff changeset
   754
    \<forall> p f i. e \<noteq> Mkdir p f i;
chunhan
parents:
diff changeset
   755
    \<forall> p f f'. e \<noteq> LinkHard p f f'; 
chunhan
parents:
diff changeset
   756
    ff \<in> current_files s\<rbrakk> \<Longrightarrow> cf2sfile (e # s) ff = cf2sfile s ff"
chunhan
parents:
diff changeset
   757
by (auto intro!:cf2sfile_other)
chunhan
parents:
diff changeset
   758
  
chunhan
parents:
diff changeset
   759
lemma cf2sfile_unlink:
chunhan
parents:
diff changeset
   760
  "\<lbrakk>valid (UnLink p f # s); f' \<in> current_files (UnLink p f # s)\<rbrakk>
chunhan
parents:
diff changeset
   761
   \<Longrightarrow> cf2sfile (UnLink p f # s) f' = cf2sfile s f'"
chunhan
parents:
diff changeset
   762
apply (frule vd_cons, frule vt_grant_os)
chunhan
parents:
diff changeset
   763
apply (simp add:current_files_simps split:if_splits)
chunhan
parents:
diff changeset
   764
apply (auto simp:cf2sfile_def sectxt_of_obj_simps get_parentfs_ctxts_simps is_file_simps is_dir_simps
chunhan
parents:
diff changeset
   765
           split:if_splits option.splits)
chunhan
parents:
diff changeset
   766
done
chunhan
parents:
diff changeset
   767
chunhan
parents:
diff changeset
   768
lemma cf2sfile_rmdir:
chunhan
parents:
diff changeset
   769
  "\<lbrakk>valid (Rmdir p f # s); f' \<in> current_files (Rmdir p f # s)\<rbrakk>
chunhan
parents:
diff changeset
   770
   \<Longrightarrow> cf2sfile (Rmdir p f # s) f' = cf2sfile s f'"
chunhan
parents:
diff changeset
   771
apply (frule vd_cons, frule vt_grant_os)
chunhan
parents:
diff changeset
   772
apply (simp add:current_files_simps split:if_splits)
chunhan
parents:
diff changeset
   773
apply (auto simp:cf2sfile_def sectxt_of_obj_simps get_parentfs_ctxts_simps is_file_simps is_dir_simps
chunhan
parents:
diff changeset
   774
           split:if_splits option.splits)
chunhan
parents:
diff changeset
   775
done
chunhan
parents:
diff changeset
   776
chunhan
parents:
diff changeset
   777
lemma pfdof_simp5: "\<lbrakk>proc_fd_of_file s f = {(p, fd)}; file_of_proc_fd s p fd = None\<rbrakk> \<Longrightarrow> False"
chunhan
parents:
diff changeset
   778
apply (subgoal_tac "(p, fd) \<in> proc_fd_of_file s f")
chunhan
parents:
diff changeset
   779
by (simp add:pfdof_simp2, simp)
chunhan
parents:
diff changeset
   780
chunhan
parents:
diff changeset
   781
lemma pfdof_simp6: "proc_fd_of_file s f = {(p, fd)} \<Longrightarrow> file_of_proc_fd s p fd = Some f"
chunhan
parents:
diff changeset
   782
apply (subgoal_tac "(p, fd) \<in> proc_fd_of_file s f")
chunhan
parents:
diff changeset
   783
by (simp add:pfdof_simp2, simp)
chunhan
parents:
diff changeset
   784
chunhan
parents:
diff changeset
   785
lemma cf2sfile_closefd:
chunhan
parents:
diff changeset
   786
  "\<lbrakk>valid (CloseFd p fd # s); f \<in> current_files (CloseFd p fd # s)\<rbrakk>
chunhan
parents:
diff changeset
   787
   \<Longrightarrow> cf2sfile (CloseFd p fd # s) f = cf2sfile s f"
chunhan
parents:
diff changeset
   788
apply (frule vd_cons, frule vt_grant_os)
chunhan
parents:
diff changeset
   789
apply (simp add:current_files_simps split:if_splits option.splits) 
chunhan
parents:
diff changeset
   790
(* costs too much time, but solved *)
chunhan
parents:
diff changeset
   791
(*
chunhan
parents:
diff changeset
   792
apply (auto simp:cf2sfile_def sectxt_of_obj_simps get_parentfs_ctxts_simps is_file_simps is_dir_simps 
chunhan
parents:
diff changeset
   793
           split:if_splits option.splits  
chunhan
parents:
diff changeset
   794
            dest:init_file_dir_conflict pfdof_simp5 pfdof_simp6 file_of_pfd_is_file
chunhan
parents:
diff changeset
   795
                 not_died_init_file not_died_init_dir is_file_not_dir is_dir_not_file
chunhan
parents:
diff changeset
   796
            dest!:current_has_sec') 
chunhan
parents:
diff changeset
   797
done
chunhan
parents:
diff changeset
   798
*)
chunhan
parents:
diff changeset
   799
sorry
chunhan
parents:
diff changeset
   800
chunhan
parents:
diff changeset
   801
lemmas cf2sfile_simps = cf2sfile_open cf2sfile_mkdir cf2sfile_linkhard cf2sfile_other
chunhan
parents:
diff changeset
   802
  cf2sfile_unlink cf2sfile_rmdir cf2sfile_closefd
chunhan
parents:
diff changeset
   803
  
chunhan
parents:
diff changeset
   804
(*********** cfd2sfd simpset *********)
chunhan
parents:
diff changeset
   805
chunhan
parents:
diff changeset
   806
lemma cfd2sfd_open1:
chunhan
parents:
diff changeset
   807
  "valid (Open p f flags fd opt # s)
chunhan
parents:
diff changeset
   808
   \<Longrightarrow> cfd2sfd (Open p f flags fd opt # s) p fd = 
chunhan
parents:
diff changeset
   809
     (case (sectxt_of_obj (Open p f flags fd opt # s) (O_fd p fd), cf2sfile (Open p f flags fd opt # s) f) of
85
1d1aa5bdd37d add remove_create_flag to sfd
chunhan
parents: 77
diff changeset
   810
        (Some sec, Some sf) \<Rightarrow> Some (sec, remove_create_flag flags, sf)
77
chunhan
parents:
diff changeset
   811
      | _ \<Rightarrow> None)"
chunhan
parents:
diff changeset
   812
by (simp add:cfd2sfd_def sectxt_of_obj_simps split:if_splits)
chunhan
parents:
diff changeset
   813
chunhan
parents:
diff changeset
   814
lemma cfd2sfd_open_some2:
chunhan
parents:
diff changeset
   815
  "\<lbrakk>valid (Open p f flags fd (Some inum) # s); file_of_proc_fd s p' fd' = Some f'\<rbrakk>
chunhan
parents:
diff changeset
   816
  \<Longrightarrow> cfd2sfd (Open p f flags fd (Some inum) # s) p' fd' = cfd2sfd s p' fd'"
chunhan
parents:
diff changeset
   817
apply (frule vd_cons, frule vt_grant_os)
chunhan
parents:
diff changeset
   818
apply (frule proc_fd_in_fds, simp)
chunhan
parents:
diff changeset
   819
apply (frule file_of_proc_fd_in_curf, simp)
chunhan
parents:
diff changeset
   820
apply (case_tac "f = f'", simp)
chunhan
parents:
diff changeset
   821
apply (simp add:cfd2sfd_def sectxt_of_obj_simps cf2sfile_open_some1)
chunhan
parents:
diff changeset
   822
apply (case_tac "p = p'", simp)
chunhan
parents:
diff changeset
   823
apply (rule conjI, rule impI, simp)
chunhan
parents:
diff changeset
   824
apply (drule cf2sfile_open_some1, simp)
chunhan
parents:
diff changeset
   825
apply (auto split:option.splits)[1]
chunhan
parents:
diff changeset
   826
apply simp
chunhan
parents:
diff changeset
   827
apply (drule cf2sfile_open_some1, simp)
chunhan
parents:
diff changeset
   828
apply (auto split:option.splits)[1]
chunhan
parents:
diff changeset
   829
done
chunhan
parents:
diff changeset
   830
chunhan
parents:
diff changeset
   831
lemma cfd2sfd_open_none2:
chunhan
parents:
diff changeset
   832
  "\<lbrakk>valid (Open p f flags fd None # s); file_of_proc_fd s p' fd' = Some f'\<rbrakk>
chunhan
parents:
diff changeset
   833
  \<Longrightarrow> cfd2sfd (Open p f flags fd None # s) p' fd' = cfd2sfd s p' fd'"
chunhan
parents:
diff changeset
   834
apply (frule vd_cons, frule vt_grant_os)
chunhan
parents:
diff changeset
   835
apply (frule proc_fd_in_fds, simp)
chunhan
parents:
diff changeset
   836
apply (frule file_of_proc_fd_in_curf, simp)
chunhan
parents:
diff changeset
   837
apply (simp add:cfd2sfd_def sectxt_of_obj_simps cf2sfile_open_none)
chunhan
parents:
diff changeset
   838
apply (case_tac "p = p'", simp)
chunhan
parents:
diff changeset
   839
apply (rule conjI, rule impI, simp)
chunhan
parents:
diff changeset
   840
apply (drule cf2sfile_open_none)
chunhan
parents:
diff changeset
   841
apply (auto split:option.splits)[1]
chunhan
parents:
diff changeset
   842
apply simp
chunhan
parents:
diff changeset
   843
apply (drule cf2sfile_open_none)
chunhan
parents:
diff changeset
   844
apply (auto split:option.splits)[1]
chunhan
parents:
diff changeset
   845
done
chunhan
parents:
diff changeset
   846
  
chunhan
parents:
diff changeset
   847
lemma cfd2sfd_open2:
chunhan
parents:
diff changeset
   848
  "\<lbrakk>valid (Open p f flags fd opt # s); file_of_proc_fd s p' fd' = Some f'\<rbrakk>
chunhan
parents:
diff changeset
   849
  \<Longrightarrow> cfd2sfd (Open p f flags fd opt # s) p' fd' = cfd2sfd s p' fd'"
chunhan
parents:
diff changeset
   850
apply (case_tac opt)
chunhan
parents:
diff changeset
   851
apply (simp add:cfd2sfd_open_none2)
chunhan
parents:
diff changeset
   852
apply (simp add:cfd2sfd_open_some2)
chunhan
parents:
diff changeset
   853
done
chunhan
parents:
diff changeset
   854
chunhan
parents:
diff changeset
   855
lemma cfd2sfd_open:
chunhan
parents:
diff changeset
   856
  "\<lbrakk>valid (Open p f flags fd opt # s); file_of_proc_fd (Open p f flags fd opt # s) p' fd' = Some f'\<rbrakk>
chunhan
parents:
diff changeset
   857
   \<Longrightarrow> cfd2sfd (Open p f flags fd opt # s) p' fd' = (if (p' = p \<and> fd' = fd) then 
chunhan
parents:
diff changeset
   858
     (case (sectxt_of_obj (Open p f flags fd opt # s) (O_fd p fd), cf2sfile (Open p f flags fd opt # s) f) of
85
1d1aa5bdd37d add remove_create_flag to sfd
chunhan
parents: 77
diff changeset
   859
        (Some sec, Some sf) \<Rightarrow> Some (sec, remove_create_flag flags, sf)
77
chunhan
parents:
diff changeset
   860
      | _ \<Rightarrow> None)         else cfd2sfd s p' fd')"
chunhan
parents:
diff changeset
   861
apply (simp split:if_splits)
chunhan
parents:
diff changeset
   862
apply (simp add:cfd2sfd_open1 split:option.splits)
chunhan
parents:
diff changeset
   863
apply (simp add:cfd2sfd_open2)
chunhan
parents:
diff changeset
   864
apply (rule impI, simp)
chunhan
parents:
diff changeset
   865
done
chunhan
parents:
diff changeset
   866
chunhan
parents:
diff changeset
   867
lemma cfd2sfd_closefd:
chunhan
parents:
diff changeset
   868
  "\<lbrakk>valid (CloseFd p fd # s); file_of_proc_fd (CloseFd p fd # s) p' fd' = Some f\<rbrakk>
chunhan
parents:
diff changeset
   869
   \<Longrightarrow> cfd2sfd (CloseFd p fd # s) p' fd' = cfd2sfd  s p' fd'"
chunhan
parents:
diff changeset
   870
apply (frule vd_cons, frule vt_grant_os)
chunhan
parents:
diff changeset
   871
apply (frule proc_fd_in_fds, simp)
chunhan
parents:
diff changeset
   872
apply (frule file_of_proc_fd_in_curf, simp)
chunhan
parents:
diff changeset
   873
apply (frule cf2sfile_closefd, simp)
chunhan
parents:
diff changeset
   874
apply (simp add:cfd2sfd_def sectxt_of_obj_simps)
chunhan
parents:
diff changeset
   875
apply (auto split:option.splits if_splits)
chunhan
parents:
diff changeset
   876
done
chunhan
parents:
diff changeset
   877
chunhan
parents:
diff changeset
   878
lemma cfd2sfd_clone:
chunhan
parents:
diff changeset
   879
  "\<lbrakk>valid (Clone p p' fds # s); file_of_proc_fd (Clone p p' fds # s) p'' fd' = Some f\<rbrakk>
chunhan
parents:
diff changeset
   880
   \<Longrightarrow> cfd2sfd (Clone p p' fds # s) p'' fd' = (
chunhan
parents:
diff changeset
   881
     if (p'' = p') then cfd2sfd s p fd'
chunhan
parents:
diff changeset
   882
     else cfd2sfd s p'' fd')"
chunhan
parents:
diff changeset
   883
apply (frule vd_cons, frule vt_grant_os)
chunhan
parents:
diff changeset
   884
apply (frule proc_fd_in_fds, simp)
chunhan
parents:
diff changeset
   885
apply (frule file_of_proc_fd_in_curf, simp, simp add:current_files_simps)
chunhan
parents:
diff changeset
   886
apply (frule_tac cf2sfile_other', simp+)
chunhan
parents:
diff changeset
   887
apply (simp add:cfd2sfd_def sectxt_of_obj_simps)
chunhan
parents:
diff changeset
   888
apply (case_tac "p'' = p'", simp)
chunhan
parents:
diff changeset
   889
apply (auto split:option.splits if_splits)[1]
chunhan
parents:
diff changeset
   890
apply (simp)
chunhan
parents:
diff changeset
   891
apply (auto split:option.splits if_splits)[1]
chunhan
parents:
diff changeset
   892
done
chunhan
parents:
diff changeset
   893
chunhan
parents:
diff changeset
   894
lemma cfd2sfd_execve:
chunhan
parents:
diff changeset
   895
  "\<lbrakk>valid (Execve p f fds # s); file_of_proc_fd (Execve p f fds # s) p' fd' = Some f'\<rbrakk>
chunhan
parents:
diff changeset
   896
   \<Longrightarrow> cfd2sfd (Execve p f fds # s) p' fd' = cfd2sfd s p' fd'"
chunhan
parents:
diff changeset
   897
apply (frule vd_cons, frule vt_grant_os)
chunhan
parents:
diff changeset
   898
apply (frule proc_fd_in_fds, simp)
chunhan
parents:
diff changeset
   899
apply (frule file_of_proc_fd_in_curf, simp, simp add:current_files_simps)
chunhan
parents:
diff changeset
   900
apply (frule_tac cf2sfile_other', simp+)
chunhan
parents:
diff changeset
   901
apply (simp add:cfd2sfd_def sectxt_of_obj_simps)
chunhan
parents:
diff changeset
   902
apply (case_tac "p' = p", simp)
chunhan
parents:
diff changeset
   903
apply (auto split:option.splits if_splits)[1]
chunhan
parents:
diff changeset
   904
apply (simp)
chunhan
parents:
diff changeset
   905
apply (auto split:option.splits if_splits)[1]
chunhan
parents:
diff changeset
   906
done
chunhan
parents:
diff changeset
   907
chunhan
parents:
diff changeset
   908
lemma cfd2sfd_kill:
chunhan
parents:
diff changeset
   909
  "\<lbrakk>valid (Kill p p'' # s); file_of_proc_fd (Kill p p'' # s) p' fd' = Some f'\<rbrakk>
chunhan
parents:
diff changeset
   910
   \<Longrightarrow> cfd2sfd (Kill p p'' # s) p' fd' = cfd2sfd s p' fd'"
chunhan
parents:
diff changeset
   911
apply (frule vd_cons, frule vt_grant_os)
chunhan
parents:
diff changeset
   912
apply (frule proc_fd_in_fds, simp)
chunhan
parents:
diff changeset
   913
apply (frule proc_fd_in_procs, simp)
chunhan
parents:
diff changeset
   914
apply (frule file_of_proc_fd_in_curf, simp, simp add:current_files_simps)
chunhan
parents:
diff changeset
   915
apply (frule_tac cf2sfile_other', simp+)
chunhan
parents:
diff changeset
   916
apply (simp add:cfd2sfd_def sectxt_of_obj_simps)
chunhan
parents:
diff changeset
   917
apply (auto split:option.splits if_splits)
chunhan
parents:
diff changeset
   918
done
chunhan
parents:
diff changeset
   919
chunhan
parents:
diff changeset
   920
lemma cfd2sfd_exit:
chunhan
parents:
diff changeset
   921
  "\<lbrakk>valid (Exit p # s); file_of_proc_fd (Exit p # s) p' fd' = Some f'\<rbrakk>
chunhan
parents:
diff changeset
   922
   \<Longrightarrow> cfd2sfd (Exit p # s) p' fd' = cfd2sfd s p' fd'"
chunhan
parents:
diff changeset
   923
apply (frule vd_cons, frule vt_grant_os)
chunhan
parents:
diff changeset
   924
apply (frule proc_fd_in_fds, simp)
chunhan
parents:
diff changeset
   925
apply (frule proc_fd_in_procs, simp)
chunhan
parents:
diff changeset
   926
apply (frule file_of_proc_fd_in_curf, simp, simp add:current_files_simps)
chunhan
parents:
diff changeset
   927
apply (frule_tac cf2sfile_other', simp+)
chunhan
parents:
diff changeset
   928
apply (simp add:cfd2sfd_def sectxt_of_obj_simps)
chunhan
parents:
diff changeset
   929
apply (auto split:option.splits if_splits)
chunhan
parents:
diff changeset
   930
done
chunhan
parents:
diff changeset
   931
chunhan
parents:
diff changeset
   932
lemma cfd2sfd_other:
chunhan
parents:
diff changeset
   933
  "\<lbrakk>valid (e # s); file_of_proc_fd (e # s) p' fd' = Some f';
chunhan
parents:
diff changeset
   934
    \<forall> p f flags fd opt. e \<noteq> Open p f flags fd opt;
chunhan
parents:
diff changeset
   935
    \<forall> p p'' fds. e \<noteq> Clone p p'' fds\<rbrakk>
chunhan
parents:
diff changeset
   936
   \<Longrightarrow> cfd2sfd (e # s) p' fd' = cfd2sfd s p' fd'"
chunhan
parents:
diff changeset
   937
apply (frule vd_cons, frule vt_grant_os)
chunhan
parents:
diff changeset
   938
apply (frule proc_fd_in_fds, simp)
chunhan
parents:
diff changeset
   939
apply (frule proc_fd_in_procs, simp)
chunhan
parents:
diff changeset
   940
apply (frule file_of_proc_fd_in_curf, simp)
chunhan
parents:
diff changeset
   941
apply (case_tac e)
chunhan
parents:
diff changeset
   942
apply (auto intro!:cfd2sfd_execve cfd2sfd_closefd cfd2sfd_kill cfd2sfd_exit)
chunhan
parents:
diff changeset
   943
apply (auto simp:cfd2sfd_def sectxt_of_obj_simps current_files_simps cf2sfile_simps split:option.splits)
chunhan
parents:
diff changeset
   944
apply (auto dest!:current_has_sec' dest:file_of_proc_fd_in_curf proc_fd_in_fds)
chunhan
parents:
diff changeset
   945
done
chunhan
parents:
diff changeset
   946
chunhan
parents:
diff changeset
   947
lemmas cfd2sfd_simps = cfd2sfd_open cfd2sfd_clone cfd2sfd_other
chunhan
parents:
diff changeset
   948
chunhan
parents:
diff changeset
   949
(********** cpfd2sfds simpset **********)
chunhan
parents:
diff changeset
   950
chunhan
parents:
diff changeset
   951
lemma current_filefd_has_flags:
chunhan
parents:
diff changeset
   952
  "\<lbrakk>file_of_proc_fd s p fd = Some f; valid s\<rbrakk> \<Longrightarrow> \<exists> flags. flags_of_proc_fd s p fd = Some flags"
chunhan
parents:
diff changeset
   953
apply (induct s arbitrary:p)
chunhan
parents:
diff changeset
   954
apply (simp only:flags_of_proc_fd.simps file_of_proc_fd.simps init_filefd_prop4)
chunhan
parents:
diff changeset
   955
apply (frule vd_cons, frule vt_grant_os, case_tac a)
chunhan
parents:
diff changeset
   956
apply (auto split:if_splits option.splits dest:proc_fd_in_fds)
chunhan
parents:
diff changeset
   957
done
chunhan
parents:
diff changeset
   958
chunhan
parents:
diff changeset
   959
lemma current_filefd_has_flags':
chunhan
parents:
diff changeset
   960
  "\<lbrakk>flags_of_proc_fd s p fd = None; valid s\<rbrakk> \<Longrightarrow> file_of_proc_fd s p fd = None"
chunhan
parents:
diff changeset
   961
apply (case_tac "file_of_proc_fd s p fd")
chunhan
parents:
diff changeset
   962
apply (simp, drule current_filefd_has_flags, simp+)
chunhan
parents:
diff changeset
   963
done
chunhan
parents:
diff changeset
   964
chunhan
parents:
diff changeset
   965
lemma current_file_has_sfile':
chunhan
parents:
diff changeset
   966
  "\<lbrakk>cf2sfile s f = None; valid s\<rbrakk> \<Longrightarrow> f \<notin> current_files s"
chunhan
parents:
diff changeset
   967
by (rule notI, drule current_file_has_sfile, simp+)
chunhan
parents:
diff changeset
   968
chunhan
parents:
diff changeset
   969
lemma current_filefd_has_sfd:
chunhan
parents:
diff changeset
   970
  "\<lbrakk>file_of_proc_fd s p fd = Some f; valid s\<rbrakk> \<Longrightarrow> \<exists>sfd. cfd2sfd s p fd = Some sfd"
chunhan
parents:
diff changeset
   971
by (auto simp:cfd2sfd_def split:option.splits dest!:current_has_sec' current_file_has_sfile' 
chunhan
parents:
diff changeset
   972
         dest:file_of_proc_fd_in_curf proc_fd_in_fds current_filefd_has_flags)
chunhan
parents:
diff changeset
   973
chunhan
parents:
diff changeset
   974
lemma current_filefd_has_sfd':
chunhan
parents:
diff changeset
   975
  "\<lbrakk>cfd2sfd s p fd = None; valid s\<rbrakk> \<Longrightarrow> file_of_proc_fd s p fd = None"
chunhan
parents:
diff changeset
   976
by (case_tac "file_of_proc_fd s p fd", auto dest:current_filefd_has_sfd)
chunhan
parents:
diff changeset
   977
chunhan
parents:
diff changeset
   978
lemma cpfd2sfds_open1:
chunhan
parents:
diff changeset
   979
  "valid (Open p f flags fd opt # s) \<Longrightarrow>
chunhan
parents:
diff changeset
   980
   cpfd2sfds (Open p f flags fd opt # s) p = (
chunhan
parents:
diff changeset
   981
    case (cfd2sfd (Open p f flags fd opt # s) p fd) of
chunhan
parents:
diff changeset
   982
        Some sfd \<Rightarrow> (cpfd2sfds s p) \<union> {sfd}
chunhan
parents:
diff changeset
   983
      | _ \<Rightarrow> cpfd2sfds s p)"
chunhan
parents:
diff changeset
   984
apply (frule vd_cons, frule vt_grant_os)
chunhan
parents:
diff changeset
   985
apply (split option.splits)
chunhan
parents:
diff changeset
   986
apply (rule conjI, rule impI, drule current_filefd_has_sfd', simp, simp)
chunhan
parents:
diff changeset
   987
apply (rule allI, rule impI)
chunhan
parents:
diff changeset
   988
apply (rule set_eqI, rule iffI)
chunhan
parents:
diff changeset
   989
apply (case_tac "x = a", simp)
chunhan
parents:
diff changeset
   990
unfolding cpfd2sfds_def
chunhan
parents:
diff changeset
   991
apply (erule CollectE, (erule conjE|erule bexE)+)
chunhan
parents:
diff changeset
   992
apply (simp add:proc_file_fds_def split:if_splits)
chunhan
parents:
diff changeset
   993
apply (erule exE, rule_tac x = fda in exI)
chunhan
parents:
diff changeset
   994
apply (simp add:cfd2sfd_open2)
chunhan
parents:
diff changeset
   995
apply (case_tac "x = a", simp add:proc_file_fds_def)
chunhan
parents:
diff changeset
   996
apply (rule_tac x = fd in exI, simp+)
chunhan
parents:
diff changeset
   997
apply (erule conjE|erule bexE)+
chunhan
parents:
diff changeset
   998
apply (rule_tac x = fda in bexI)
chunhan
parents:
diff changeset
   999
apply (simp add:proc_file_fds_def, erule exE)
chunhan
parents:
diff changeset
  1000
apply (simp add:cfd2sfd_open2)
chunhan
parents:
diff changeset
  1001
apply (simp add:proc_file_fds_def)
chunhan
parents:
diff changeset
  1002
done
chunhan
parents:
diff changeset
  1003
chunhan
parents:
diff changeset
  1004
lemma cpfd2sfds_open1':
chunhan
parents:
diff changeset
  1005
  "valid (Open p f flags fd opt # s) \<Longrightarrow>
chunhan
parents:
diff changeset
  1006
   cpfd2sfds (Open p f flags fd opt # s) p = (
chunhan
parents:
diff changeset
  1007
    case (sectxt_of_obj (Open p f flags fd opt # s) (O_fd p fd), cf2sfile (Open p f flags fd opt # s) f) of
85
1d1aa5bdd37d add remove_create_flag to sfd
chunhan
parents: 77
diff changeset
  1008
        (Some sec, Some sf) \<Rightarrow> (cpfd2sfds s p) \<union> {(sec, remove_create_flag flags, sf)}
77
chunhan
parents:
diff changeset
  1009
      | _ \<Rightarrow> cpfd2sfds s p)"
chunhan
parents:
diff changeset
  1010
apply (frule cfd2sfd_open1)
chunhan
parents:
diff changeset
  1011
apply (auto dest:cpfd2sfds_open1 split:option.splits)
chunhan
parents:
diff changeset
  1012
done
chunhan
parents:
diff changeset
  1013
chunhan
parents:
diff changeset
  1014
lemma cpfd2sfds_open2:
chunhan
parents:
diff changeset
  1015
  "\<lbrakk>valid (Open p f flags fd opt # s); p' \<noteq> p\<rbrakk> \<Longrightarrow> cpfd2sfds (Open p f flags fd opt # s) p' = cpfd2sfds s p'"
chunhan
parents:
diff changeset
  1016
apply (frule vt_grant_os, frule vd_cons)
chunhan
parents:
diff changeset
  1017
unfolding cpfd2sfds_def
chunhan
parents:
diff changeset
  1018
apply (rule set_eqI, rule iffI)
chunhan
parents:
diff changeset
  1019
apply (simp add:proc_file_fds_def)
chunhan
parents:
diff changeset
  1020
apply (erule exE|erule conjE)+
chunhan
parents:
diff changeset
  1021
apply (simp only:file_of_proc_fd.simps cfd2sfd_open2 split:if_splits)
chunhan
parents:
diff changeset
  1022
apply (rule_tac x = fda in exI, simp)
chunhan
parents:
diff changeset
  1023
apply (simp add:proc_file_fds_def)
chunhan
parents:
diff changeset
  1024
apply (erule exE|erule conjE)+
chunhan
parents:
diff changeset
  1025
apply (rule_tac x = fda in exI, simp add:cfd2sfd_open2)
chunhan
parents:
diff changeset
  1026
done
chunhan
parents:
diff changeset
  1027
chunhan
parents:
diff changeset
  1028
lemma cpfd2sfds_open:
chunhan
parents:
diff changeset
  1029
  "valid (Open p f flags fd opt # s)
chunhan
parents:
diff changeset
  1030
   \<Longrightarrow> cpfd2sfds (Open p f flags fd opt # s) = (cpfd2sfds s) (p := (
chunhan
parents:
diff changeset
  1031
    case (sectxt_of_obj (Open p f flags fd opt # s) (O_fd p fd), cf2sfile (Open p f flags fd opt # s) f) of
85
1d1aa5bdd37d add remove_create_flag to sfd
chunhan
parents: 77
diff changeset
  1032
        (Some sec, Some sf) \<Rightarrow> (cpfd2sfds s p) \<union> {(sec, remove_create_flag flags, sf)}
77
chunhan
parents:
diff changeset
  1033
      | _ \<Rightarrow> cpfd2sfds s p))"
chunhan
parents:
diff changeset
  1034
apply (rule ext)
chunhan
parents:
diff changeset
  1035
apply (case_tac "x \<noteq> p")
chunhan
parents:
diff changeset
  1036
apply (simp add:cpfd2sfds_open2)
chunhan
parents:
diff changeset
  1037
apply (simp add:cpfd2sfds_open1')
chunhan
parents:
diff changeset
  1038
done
chunhan
parents:
diff changeset
  1039
chunhan
parents:
diff changeset
  1040
lemma cpfd2sfds_execve:
chunhan
parents:
diff changeset
  1041
  "valid (Execve p f fds # s) 
chunhan
parents:
diff changeset
  1042
   \<Longrightarrow> cpfd2sfds (Execve p f fds # s) = (cpfd2sfds s) (p := {sfd. \<exists> fd \<in> fds. \<exists> f. file_of_proc_fd s p fd = Some f \<and> cfd2sfd s p fd = Some sfd})"
chunhan
parents:
diff changeset
  1043
apply (frule vd_cons, frule vt_grant_os)
chunhan
parents:
diff changeset
  1044
apply (rule ext)
chunhan
parents:
diff changeset
  1045
apply (rule set_eqI, rule iffI)
chunhan
parents:
diff changeset
  1046
unfolding cpfd2sfds_def proc_file_fds_def
chunhan
parents:
diff changeset
  1047
apply (erule CollectE| erule bexE| erule conjE| erule exE| rule conjI)+
chunhan
parents:
diff changeset
  1048
apply (simp split:if_splits)
chunhan
parents:
diff changeset
  1049
apply (frule_tac p' = p and fd' = fd in cfd2sfd_other, simp+)
chunhan
parents:
diff changeset
  1050
apply (rule_tac x = fd in bexI, simp+)
chunhan
parents:
diff changeset
  1051
apply (simp add:cpfd2sfds_def proc_file_fds_def)
chunhan
parents:
diff changeset
  1052
apply (frule_tac p' = x and fd' = fd in cfd2sfd_other, simp+)
chunhan
parents:
diff changeset
  1053
apply (rule_tac x = fd in exI, simp)
chunhan
parents:
diff changeset
  1054
apply (simp split:if_splits)
chunhan
parents:
diff changeset
  1055
apply (erule CollectE| erule bexE| erule conjE| erule exE| rule conjI)+
chunhan
parents:
diff changeset
  1056
apply (rule_tac x = fd in exI, simp)
chunhan
parents:
diff changeset
  1057
apply (frule_tac p' = x and fd' = fd in cfd2sfd_other, simp+)
chunhan
parents:
diff changeset
  1058
apply (simp add:cpfd2sfds_def proc_file_fds_def)
chunhan
parents:
diff changeset
  1059
apply (erule CollectE| erule bexE| erule conjE| erule exE| rule conjI)+
chunhan
parents:
diff changeset
  1060
apply (rule_tac x = fd in exI, simp)
chunhan
parents:
diff changeset
  1061
apply (frule_tac p' = x and fd' = fd in cfd2sfd_other, simp+)
chunhan
parents:
diff changeset
  1062
done
chunhan
parents:
diff changeset
  1063
chunhan
parents:
diff changeset
  1064
lemma cpfd2sfds_clone:
chunhan
parents:
diff changeset
  1065
  "valid (Clone p p' fds # s) 
chunhan
parents:
diff changeset
  1066
   \<Longrightarrow> cpfd2sfds (Clone p p' fds # s) = (cpfd2sfds s) (p' := {sfd. \<exists> fd \<in> fds. \<exists> f. file_of_proc_fd s p fd = Some f \<and> cfd2sfd s p fd = Some sfd})"
chunhan
parents:
diff changeset
  1067
apply (frule vd_cons, frule vt_grant_os)
chunhan
parents:
diff changeset
  1068
apply (rule ext)
chunhan
parents:
diff changeset
  1069
apply (rule set_eqI, rule iffI)
chunhan
parents:
diff changeset
  1070
unfolding cpfd2sfds_def proc_file_fds_def
chunhan
parents:
diff changeset
  1071
apply (erule CollectE| erule bexE| erule conjE| erule exE| rule conjI)+
chunhan
parents:
diff changeset
  1072
apply (simp split:if_splits)
chunhan
parents:
diff changeset
  1073
apply (frule_tac p'' = p' and fd' = fd in cfd2sfd_clone, simp+)
chunhan
parents:
diff changeset
  1074
apply (rule_tac x = fd in bexI, simp+)
chunhan
parents:
diff changeset
  1075
apply (simp add:cpfd2sfds_def proc_file_fds_def)
chunhan
parents:
diff changeset
  1076
apply (frule_tac p'' = x and fd' = fd in cfd2sfd_clone, simp+)
chunhan
parents:
diff changeset
  1077
apply (rule_tac x = fd in exI, simp)
chunhan
parents:
diff changeset
  1078
apply (simp split:if_splits)
chunhan
parents:
diff changeset
  1079
apply (erule CollectE| erule bexE| erule conjE| erule exE| rule conjI)+
chunhan
parents:
diff changeset
  1080
apply (rule_tac x = fd in exI, simp)
chunhan
parents:
diff changeset
  1081
apply (frule_tac p'' = p' and fd' = fd in cfd2sfd_clone, simp+)
chunhan
parents:
diff changeset
  1082
apply (simp add:cpfd2sfds_def proc_file_fds_def)
chunhan
parents:
diff changeset
  1083
apply (erule CollectE| erule bexE| erule conjE| erule exE| rule conjI)+
chunhan
parents:
diff changeset
  1084
apply (rule_tac x = fd in exI, simp)
chunhan
parents:
diff changeset
  1085
apply (frule_tac p'' = x and fd' = fd in cfd2sfd_clone, simp+)
chunhan
parents:
diff changeset
  1086
done
chunhan
parents:
diff changeset
  1087
chunhan
parents:
diff changeset
  1088
lemma cpfd2sfds_other:
chunhan
parents:
diff changeset
  1089
  "\<lbrakk>valid (e # s);
chunhan
parents:
diff changeset
  1090
    \<forall> p f flags fd opt. e \<noteq> Open p f flags fd opt;
chunhan
parents:
diff changeset
  1091
    \<forall> p f fds. e \<noteq> Execve p f fds;
chunhan
parents:
diff changeset
  1092
    \<forall> p p'. e \<noteq> Kill p p';
chunhan
parents:
diff changeset
  1093
    \<forall> p. e \<noteq> Exit p;
chunhan
parents:
diff changeset
  1094
    \<forall> p fd. e \<noteq> CloseFd p fd;
chunhan
parents:
diff changeset
  1095
    \<forall> p p' fds. e \<noteq> Clone p p' fds\<rbrakk> \<Longrightarrow> cpfd2sfds (e # s) = cpfd2sfds s"
chunhan
parents:
diff changeset
  1096
apply (frule vd_cons, frule vt_grant_os)
chunhan
parents:
diff changeset
  1097
apply (rule ext)
chunhan
parents:
diff changeset
  1098
unfolding cpfd2sfds_def proc_file_fds_def
chunhan
parents:
diff changeset
  1099
apply (case_tac e)
chunhan
parents:
diff changeset
  1100
using cfd2sfd_other
chunhan
parents:
diff changeset
  1101
by auto
chunhan
parents:
diff changeset
  1102
chunhan
parents:
diff changeset
  1103
lemma cpfd2sfds_kill:
chunhan
parents:
diff changeset
  1104
  "valid (Kill p p' # s) \<Longrightarrow> cpfd2sfds (Kill p p' # s) = (cpfd2sfds s) (p' := {})"
chunhan
parents:
diff changeset
  1105
apply (frule vd_cons, frule vt_grant_os)
chunhan
parents:
diff changeset
  1106
apply (rule ext, rule set_eqI)
chunhan
parents:
diff changeset
  1107
unfolding cpfd2sfds_def proc_file_fds_def
chunhan
parents:
diff changeset
  1108
apply (rule iffI)
chunhan
parents:
diff changeset
  1109
apply (erule CollectE| erule bexE| erule conjE| erule exE| rule conjI)+
chunhan
parents:
diff changeset
  1110
apply (simp split:if_splits add: cpfd2sfds_def proc_file_fds_def)
chunhan
parents:
diff changeset
  1111
apply (rule_tac x = fd in exI, simp)
chunhan
parents:
diff changeset
  1112
apply (drule_tac p' = x and fd' = fd in cfd2sfd_other, simp+)
chunhan
parents:
diff changeset
  1113
apply (simp split:if_splits add: cpfd2sfds_def proc_file_fds_def)
chunhan
parents:
diff changeset
  1114
apply (erule CollectE| erule bexE| erule conjE| erule exE| rule conjI)+
chunhan
parents:
diff changeset
  1115
apply (rule_tac x = fd in exI, simp)
chunhan
parents:
diff changeset
  1116
apply (drule_tac p' = x and fd' = fd in cfd2sfd_other, simp+)
chunhan
parents:
diff changeset
  1117
done
chunhan
parents:
diff changeset
  1118
chunhan
parents:
diff changeset
  1119
lemma cpfd2sfds_exit:
chunhan
parents:
diff changeset
  1120
  "valid (Exit p # s) \<Longrightarrow> cpfd2sfds (Exit p # s) = (cpfd2sfds s) (p := {})"
chunhan
parents:
diff changeset
  1121
apply (frule vd_cons, frule vt_grant_os)
chunhan
parents:
diff changeset
  1122
apply (rule ext, rule set_eqI)
chunhan
parents:
diff changeset
  1123
unfolding cpfd2sfds_def proc_file_fds_def
chunhan
parents:
diff changeset
  1124
apply (rule iffI)
chunhan
parents:
diff changeset
  1125
apply (erule CollectE| erule bexE| erule conjE| erule exE| rule conjI)+
chunhan
parents:
diff changeset
  1126
apply (simp split:if_splits add: cpfd2sfds_def proc_file_fds_def)
chunhan
parents:
diff changeset
  1127
apply (rule_tac x = fd in exI, simp)
chunhan
parents:
diff changeset
  1128
apply (drule_tac p' = x and fd' = fd in cfd2sfd_other, simp+)
chunhan
parents:
diff changeset
  1129
apply (simp split:if_splits add: cpfd2sfds_def proc_file_fds_def)
chunhan
parents:
diff changeset
  1130
apply (erule CollectE| erule bexE| erule conjE| erule exE| rule conjI)+
chunhan
parents:
diff changeset
  1131
apply (rule_tac x = fd in exI, simp)
chunhan
parents:
diff changeset
  1132
apply (drule_tac p' = x and fd' = fd in cfd2sfd_other, simp+)
chunhan
parents:
diff changeset
  1133
done
chunhan
parents:
diff changeset
  1134
chunhan
parents:
diff changeset
  1135
lemma cpfd2sfds_closefd:
chunhan
parents:
diff changeset
  1136
  "valid (CloseFd p fd # s) \<Longrightarrow> cpfd2sfds (CloseFd p fd # s) = (cpfd2sfds s) (p := 
chunhan
parents:
diff changeset
  1137
     if (fd \<in> proc_file_fds s p)
chunhan
parents:
diff changeset
  1138
     then (case (cfd2sfd s p fd) of 
chunhan
parents:
diff changeset
  1139
             Some sfd \<Rightarrow> (if (\<exists> fd' f'. fd' \<noteq> fd \<and> file_of_proc_fd s p fd' = Some f' \<and> cfd2sfd s p fd' = Some sfd)
chunhan
parents:
diff changeset
  1140
                          then cpfd2sfds s p else cpfd2sfds s p - {sfd})
chunhan
parents:
diff changeset
  1141
           | _        \<Rightarrow> cpfd2sfds s p)
chunhan
parents:
diff changeset
  1142
     else cpfd2sfds s p)"
chunhan
parents:
diff changeset
  1143
apply (frule vd_cons)
chunhan
parents:
diff changeset
  1144
apply (rule ext, rule set_eqI, rule iffI)
chunhan
parents:
diff changeset
  1145
unfolding cpfd2sfds_def proc_file_fds_def
chunhan
parents:
diff changeset
  1146
apply (erule CollectE| erule bexE| erule conjE| erule exE| rule conjI)+
chunhan
parents:
diff changeset
  1147
apply (simp split:if_splits)
chunhan
parents:
diff changeset
  1148
apply (rule conjI, rule impI, rule conjI, rule impI, erule exE)
chunhan
parents:
diff changeset
  1149
apply (frule_tac p = p and fd = fd in current_filefd_has_sfd, simp)
chunhan
parents:
diff changeset
  1150
apply (erule exE, simp)
chunhan
parents:
diff changeset
  1151
apply (rule conjI, rule impI, (erule exE|erule conjE)+)
chunhan
parents:
diff changeset
  1152
apply (rule_tac x = fda in exI, simp, simp add:cfd2sfd_closefd)
chunhan
parents:
diff changeset
  1153
chunhan
parents:
diff changeset
  1154
apply (rule impI, rule conjI)
chunhan
parents:
diff changeset
  1155
apply (rule_tac x = fda in exI, simp, simp add:cfd2sfd_closefd)
chunhan
parents:
diff changeset
  1156
apply (rule notI, simp)
chunhan
parents:
diff changeset
  1157
apply (erule_tac x = fda in allE, simp add:cfd2sfd_closefd)
chunhan
parents:
diff changeset
  1158
chunhan
parents:
diff changeset
  1159
apply (rule impI, simp add:cpfd2sfds_def proc_file_fds_def)
chunhan
parents:
diff changeset
  1160
apply (erule exE, rule_tac x = fda in exI, simp add:cfd2sfd_closefd)
chunhan
parents:
diff changeset
  1161
chunhan
parents:
diff changeset
  1162
apply (rule impI| rule conjI)+
chunhan
parents:
diff changeset
  1163
apply (rule_tac x = fda in exI, simp add:cfd2sfd_closefd)
chunhan
parents:
diff changeset
  1164
chunhan
parents:
diff changeset
  1165
apply (rule impI, simp add:cpfd2sfds_def proc_file_fds_def)
chunhan
parents:
diff changeset
  1166
apply (rule_tac x = fda in exI, simp add:cfd2sfd_closefd)
chunhan
parents:
diff changeset
  1167
chunhan
parents:
diff changeset
  1168
apply (simp split:if_splits)
chunhan
parents:
diff changeset
  1169
apply (frule_tac p = p and fd = fd in current_filefd_has_sfd, simp)
chunhan
parents:
diff changeset
  1170
apply (erule exE, simp)
chunhan
parents:
diff changeset
  1171
apply (case_tac "\<exists>fd'. fd' \<noteq> fd \<and> (\<exists>f'. file_of_proc_fd s p fd' = Some f') \<and> cfd2sfd s p fd' = Some sfd")
chunhan
parents:
diff changeset
  1172
apply simp
chunhan
parents:
diff changeset
  1173
apply (case_tac "xa = sfd")
chunhan
parents:
diff changeset
  1174
apply (erule exE|erule conjE)+
chunhan
parents:
diff changeset
  1175
apply (rule_tac x = fd' in exI, simp add:cfd2sfd_closefd)
chunhan
parents:
diff changeset
  1176
apply (erule exE|erule conjE)+
chunhan
parents:
diff changeset
  1177
apply (rule_tac x = fda in exI, simp add:cfd2sfd_closefd)
chunhan
parents:
diff changeset
  1178
apply (rule notI, simp)
chunhan
parents:
diff changeset
  1179
apply (simp, (erule exE|erule conjE)+)
chunhan
parents:
diff changeset
  1180
apply (rule_tac x = fda in exI, simp add:cfd2sfd_closefd)
chunhan
parents:
diff changeset
  1181
apply (rule notI, simp)
chunhan
parents:
diff changeset
  1182
apply (erule exE|erule conjE)+
chunhan
parents:
diff changeset
  1183
apply (rule_tac x = fda in exI, simp add:cfd2sfd_closefd)
chunhan
parents:
diff changeset
  1184
apply (rule notI, simp)
chunhan
parents:
diff changeset
  1185
apply (simp add:cpfd2sfds_def proc_file_fds_def)
chunhan
parents:
diff changeset
  1186
apply (erule exE|erule conjE)+
chunhan
parents:
diff changeset
  1187
apply (rule_tac x = fda in exI, simp add:cfd2sfd_closefd)
chunhan
parents:
diff changeset
  1188
done
chunhan
parents:
diff changeset
  1189
chunhan
parents:
diff changeset
  1190
lemmas cpfd2sfds_simps = cpfd2sfds_open cpfd2sfds_execve cpfd2sfds_clone cpfd2sfds_kill cpfd2sfds_exit
chunhan
parents:
diff changeset
  1191
  cpfd2sfds_closefd cpfd2sfds_other
chunhan
parents:
diff changeset
  1192
chunhan
parents:
diff changeset
  1193
(********* ch2sshm simpset ********)
chunhan
parents:
diff changeset
  1194
(*
chunhan
parents:
diff changeset
  1195
lemma ch2sshm_createshm:
chunhan
parents:
diff changeset
  1196
  "valid (CreateShM p h # s) 
chunhan
parents:
diff changeset
  1197
   \<Longrightarrow> ch2sshm (CreateShM p h # s) = (ch2sshm s) (h := 
chunhan
parents:
diff changeset
  1198
     (case (sectxt_of_obj (CreateShM p h # s) (O_shm h)) of
chunhan
parents:
diff changeset
  1199
                    Some sec \<Rightarrow> 
chunhan
parents:
diff changeset
  1200
 Some (if (\<not> died (O_shm h) s \<and> h \<in> init_shms) then Init h else Created, sec)
chunhan
parents:
diff changeset
  1201
                  | _ \<Rightarrow> None))"
chunhan
parents:
diff changeset
  1202
apply (frule vd_cons, frule vt_grant_os)
chunhan
parents:
diff changeset
  1203
apply (auto simp:ch2sshm_def sectxt_of_obj_simps dest!:current_has_sec' split:option.splits if_splits)
chunhan
parents:
diff changeset
  1204
done
chunhan
parents:
diff changeset
  1205
chunhan
parents:
diff changeset
  1206
lemma ch2sshm_other:
chunhan
parents:
diff changeset
  1207
  "\<lbrakk>valid (e # s); 
chunhan
parents:
diff changeset
  1208
    \<forall> p h. e \<noteq> CreateShM p h; 
chunhan
parents:
diff changeset
  1209
    h' \<in> current_shms (e # s)\<rbrakk> \<Longrightarrow> ch2sshm (e # s) h' = ch2sshm s h'"
chunhan
parents:
diff changeset
  1210
apply (frule vd_cons, frule vt_grant_os)
chunhan
parents:
diff changeset
  1211
apply (case_tac e)
chunhan
parents:
diff changeset
  1212
apply (auto simp:ch2sshm_def sectxt_of_obj_simps dest!:current_has_sec' split:option.splits if_splits)
chunhan
parents:
diff changeset
  1213
done
chunhan
parents:
diff changeset
  1214
chunhan
parents:
diff changeset
  1215
lemmas ch2sshm_simps = ch2sshm_createshm ch2sshm_other
chunhan
parents:
diff changeset
  1216
chunhan
parents:
diff changeset
  1217
lemma current_shm_has_sh:
chunhan
parents:
diff changeset
  1218
  "\<lbrakk>h \<in> current_shms s; valid s\<rbrakk> \<Longrightarrow> \<exists> sh. ch2sshm s h = Some sh"
chunhan
parents:
diff changeset
  1219
by (auto simp:ch2sshm_def split:option.splits dest!:current_has_sec')
chunhan
parents:
diff changeset
  1220
chunhan
parents:
diff changeset
  1221
lemma current_shm_has_sh':
chunhan
parents:
diff changeset
  1222
  "\<lbrakk>ch2sshm s h = None; valid s\<rbrakk> \<Longrightarrow> h \<notin> current_shms s"
chunhan
parents:
diff changeset
  1223
by (auto dest:current_shm_has_sh)
chunhan
parents:
diff changeset
  1224
chunhan
parents:
diff changeset
  1225
(********** cph2spshs simpset **********)
chunhan
parents:
diff changeset
  1226
chunhan
parents:
diff changeset
  1227
lemma cph2spshs_attach:
chunhan
parents:
diff changeset
  1228
  "valid (Attach p h flag # s) \<Longrightarrow> 
chunhan
parents:
diff changeset
  1229
   cph2spshs (Attach p h flag # s) = (cph2spshs s) (p := 
chunhan
parents:
diff changeset
  1230
     (case (ch2sshm s h) of 
chunhan
parents:
diff changeset
  1231
        Some sh \<Rightarrow> cph2spshs s p \<union> {(sh, flag)}
chunhan
parents:
diff changeset
  1232
      | _       \<Rightarrow> cph2spshs s p) )"
chunhan
parents:
diff changeset
  1233
apply (frule vd_cons, frule vt_grant_os, rule ext)
chunhan
parents:
diff changeset
  1234
using ch2sshm_other[where e = "Attach p h flag" and s = s]
chunhan
parents:
diff changeset
  1235
apply (auto split del:t_open_must_flag.splits t_open_option_flag.splits split add:if_splits option.splits
chunhan
parents:
diff changeset
  1236
dest!:current_shm_has_sh' dest: procs_of_shm_prop1 simp:cph2spshs_def)
chunhan
parents:
diff changeset
  1237
apply (erule_tac x = ha in allE, frule procs_of_shm_prop1, simp, simp)
chunhan
parents:
diff changeset
  1238
apply (erule_tac x = ha in allE, frule procs_of_shm_prop1, simp, simp)
chunhan
parents:
diff changeset
  1239
apply (erule_tac x = ha in allE, frule procs_of_shm_prop1, simp, simp)
chunhan
parents:
diff changeset
  1240
apply (erule_tac x = ha in allE, frule procs_of_shm_prop1, simp, simp)
chunhan
parents:
diff changeset
  1241
apply (erule_tac x = ha in allE, frule procs_of_shm_prop1, simp, simp)
chunhan
parents:
diff changeset
  1242
apply (case_tac "ha = h", simp, frule procs_of_shm_prop1, simp)
chunhan
parents:
diff changeset
  1243
apply (rule_tac x = ha in exI, simp)
chunhan
parents:
diff changeset
  1244
apply (rule_tac x = ha in exI, simp, drule procs_of_shm_prop1, simp, simp)
chunhan
parents:
diff changeset
  1245
apply (rule_tac x = ha in exI, simp)
chunhan
parents:
diff changeset
  1246
apply (frule procs_of_shm_prop1, simp, simp)
chunhan
parents:
diff changeset
  1247
apply (rule impI, simp)
chunhan
parents:
diff changeset
  1248
done
chunhan
parents:
diff changeset
  1249
chunhan
parents:
diff changeset
  1250
lemma cph2spshs_detach: "valid (Detach p h # s) \<Longrightarrow> 
chunhan
parents:
diff changeset
  1251
  cph2spshs (Detach p h # s) = (cph2spshs s) (p := 
chunhan
parents:
diff changeset
  1252
    (case (ch2sshm s h, flag_of_proc_shm s p h) of 
chunhan
parents:
diff changeset
  1253
       (Some sh, Some flag) \<Rightarrow> if (\<exists> h'. h' \<noteq> h \<and> (p,flag) \<in> procs_of_shm s h' \<and> ch2sshm s h' = Some sh)
chunhan
parents:
diff changeset
  1254
                  then cph2spshs s p else cph2spshs s p - {(sh, flag)}
chunhan
parents:
diff changeset
  1255
     | _       \<Rightarrow> cph2spshs s p)             )"
chunhan
parents:
diff changeset
  1256
apply (frule vd_cons, frule vt_grant_os, rule ext)
chunhan
parents:
diff changeset
  1257
apply (case_tac "x = p")  defer
chunhan
parents:
diff changeset
  1258
using ch2sshm_other[where e = "Detach p h" and s = s] 
chunhan
parents:
diff changeset
  1259
apply (auto split del:t_open_must_flag.splits t_open_option_flag.splits split add:if_splits option.splits
chunhan
parents:
diff changeset
  1260
dest!:current_shm_has_sh' procs_of_shm_prop4' dest:procs_of_shm_prop1 procs_of_shm_prop3 simp:cph2spshs_def) [1]
chunhan
parents:
diff changeset
  1261
apply (rule_tac x = ha in exI, frule_tac h = ha in procs_of_shm_prop1, simp, simp)
chunhan
parents:
diff changeset
  1262
apply (rule_tac x = ha in exI, frule_tac h = ha in procs_of_shm_prop1, simp, simp)
chunhan
parents:
diff changeset
  1263
apply (rule impI, simp)
chunhan
parents:
diff changeset
  1264
chunhan
parents:
diff changeset
  1265
apply (clarsimp)
chunhan
parents:
diff changeset
  1266
apply (frule current_shm_has_sh, simp, erule exE)
chunhan
parents:
diff changeset
  1267
apply (frule procs_of_shm_prop4, simp, simp)
chunhan
parents:
diff changeset
  1268
apply (rule allI | rule conjI| erule conjE | erule exE | rule impI)+
chunhan
parents:
diff changeset
  1269
chunhan
parents:
diff changeset
  1270
apply (simp only:cph2spshs_def, rule set_eqI, rule iffI)
chunhan
parents:
diff changeset
  1271
apply (erule CollectE | erule exE| erule conjE| rule CollectI)+
chunhan
parents:
diff changeset
  1272
apply (case_tac "ha = h", simp)
chunhan
parents:
diff changeset
  1273
apply (rule_tac x = sha in exI, rule_tac x = flaga in exI, rule_tac x = ha in exI, simp)
chunhan
parents:
diff changeset
  1274
using ch2sshm_other[where e = "Detach p h" and s = s] apply (simp add:procs_of_shm_prop1)
chunhan
parents:
diff changeset
  1275
chunhan
parents:
diff changeset
  1276
apply (erule CollectE | erule exE| erule conjE| rule CollectI)+
chunhan
parents:
diff changeset
  1277
apply (case_tac "ha = h", simp)
chunhan
parents:
diff changeset
  1278
apply (rule_tac x = h' in exI, simp)
chunhan
parents:
diff changeset
  1279
apply (frule_tac flag = flag and flag' = flaga in procs_of_shm_prop3, simp+)
chunhan
parents:
diff changeset
  1280
apply (frule_tac flag = flaga in procs_of_shm_prop4, simp+)
chunhan
parents:
diff changeset
  1281
using ch2sshm_other[where e = "Detach p h" and s = s] apply (simp add:procs_of_shm_prop1)
chunhan
parents:
diff changeset
  1282
apply (frule_tac h = h' in procs_of_shm_prop1, simp, simp)
chunhan
parents:
diff changeset
  1283
apply (rule_tac x = ha in exI, simp, frule_tac h = ha in procs_of_shm_prop1, simp+)
chunhan
parents:
diff changeset
  1284
using ch2sshm_other[where e = "Detach p h" and s = s] apply (simp add:procs_of_shm_prop1)
chunhan
parents:
diff changeset
  1285
chunhan
parents:
diff changeset
  1286
apply (rule allI | rule conjI| erule conjE | erule exE | rule impI)+
chunhan
parents:
diff changeset
  1287
apply (simp only:cph2spshs_def, rule set_eqI, rule iffI)
chunhan
parents:
diff changeset
  1288
apply (erule CollectE | erule exE| erule conjE| rule DiffI |rule CollectI)+
chunhan
parents:
diff changeset
  1289
apply (simp split:if_splits)
chunhan
parents:
diff changeset
  1290
apply (rule_tac x = ha in exI, simp, frule_tac h = ha in procs_of_shm_prop1, simp+)
chunhan
parents:
diff changeset
  1291
using ch2sshm_other[where e = "Detach p h" and s = s] apply (simp add:procs_of_shm_prop1)
chunhan
parents:
diff changeset
  1292
apply (rule notI, simp split:if_splits)
chunhan
parents:
diff changeset
  1293
apply (erule_tac x = ha in allE, simp, frule_tac h = ha in procs_of_shm_prop1, simp+)
chunhan
parents:
diff changeset
  1294
using ch2sshm_other[where e = "Detach p h" and s = s] apply (simp add:procs_of_shm_prop1)
chunhan
parents:
diff changeset
  1295
apply (erule CollectE | erule exE| erule conjE| erule DiffE |rule CollectI)+
chunhan
parents:
diff changeset
  1296
apply (simp split:if_splits)
chunhan
parents:
diff changeset
  1297
apply (erule_tac x = ha in allE, simp, rule_tac x = ha in exI, simp)
chunhan
parents:
diff changeset
  1298
apply (case_tac "ha = h", simp add:procs_of_shm_prop3, frule_tac h = ha in procs_of_shm_prop1, simp+)
chunhan
parents:
diff changeset
  1299
using ch2sshm_other[where e = "Detach p h" and s = s] apply (simp add:procs_of_shm_prop1)
chunhan
parents:
diff changeset
  1300
done
chunhan
parents:
diff changeset
  1301
chunhan
parents:
diff changeset
  1302
lemma cph2spshs_deleteshm:
chunhan
parents:
diff changeset
  1303
  "valid (DeleteShM p h # s) \<Longrightarrow>     
chunhan
parents:
diff changeset
  1304
   cph2spshs (DeleteShM p h # s) = (\<lambda> p'. 
chunhan
parents:
diff changeset
  1305
    (case (ch2sshm s h, flag_of_proc_shm s p' h) of 
chunhan
parents:
diff changeset
  1306
       (Some sh, Some flag) \<Rightarrow> if (\<exists> h'. h' \<noteq> h \<and> (p', flag) \<in> procs_of_shm s h' \<and> ch2sshm s h' = Some sh)
chunhan
parents:
diff changeset
  1307
                  then cph2spshs s p' else cph2spshs s p' - {(sh, flag)}
chunhan
parents:
diff changeset
  1308
     | _       \<Rightarrow> cph2spshs s p')   )"
chunhan
parents:
diff changeset
  1309
apply (frule vd_cons, frule vt_grant_os, rule ext)
chunhan
parents:
diff changeset
  1310
chunhan
parents:
diff changeset
  1311
apply (clarsimp)
chunhan
parents:
diff changeset
  1312
apply (frule current_shm_has_sh, simp, erule exE, simp, simp split:option.splits)
chunhan
parents:
diff changeset
  1313
apply (rule conjI, rule impI)
chunhan
parents:
diff changeset
  1314
using ch2sshm_other[where e = "DeleteShM p h" and s = s] 
chunhan
parents:
diff changeset
  1315
apply (auto split del:t_open_must_flag.splits t_open_option_flag.splits split add:if_splits option.splits
chunhan
parents:
diff changeset
  1316
dest!:current_shm_has_sh' procs_of_shm_prop4' dest:procs_of_shm_prop1 procs_of_shm_prop3 simp:cph2spshs_def) [1]
chunhan
parents:
diff changeset
  1317
apply (rule_tac x = ha in exI, frule_tac h = ha in procs_of_shm_prop1, simp+)
chunhan
parents:
diff changeset
  1318
apply (rule_tac x = ha in exI, simp)
chunhan
parents:
diff changeset
  1319
apply (case_tac "ha = h", simp+, frule_tac h = ha in procs_of_shm_prop1, simp+)
chunhan
parents:
diff changeset
  1320
chunhan
parents:
diff changeset
  1321
apply (rule allI | rule conjI| erule conjE | erule exE | rule impI)+
chunhan
parents:
diff changeset
  1322
chunhan
parents:
diff changeset
  1323
apply (simp only:cph2spshs_def, rule set_eqI, rule iffI)
chunhan
parents:
diff changeset
  1324
apply (erule CollectE | erule exE| erule conjE| rule CollectI)+
chunhan
parents:
diff changeset
  1325
apply (case_tac "ha = h", simp)
chunhan
parents:
diff changeset
  1326
apply (rule_tac x = sha in exI, rule_tac x = flag in exI, rule_tac x = ha in exI, simp)
chunhan
parents:
diff changeset
  1327
using ch2sshm_other[where e = "DeleteShM p h" and s = s] apply (simp add:procs_of_shm_prop1)
chunhan
parents:
diff changeset
  1328
chunhan
parents:
diff changeset
  1329
apply (erule CollectE | erule exE| erule conjE| rule CollectI)+
chunhan
parents:
diff changeset
  1330
apply (case_tac "ha = h", simp)
chunhan
parents:
diff changeset
  1331
apply (rule_tac x = h' in exI, simp)
chunhan
parents:
diff changeset
  1332
apply (frule_tac flag = flag in procs_of_shm_prop4, simp+)
chunhan
parents:
diff changeset
  1333
using ch2sshm_other[where e = "DeleteShM p h" and s = s] apply (simp add:procs_of_shm_prop1)
chunhan
parents:
diff changeset
  1334
apply (frule_tac h = h' in procs_of_shm_prop1, simp, simp)
chunhan
parents:
diff changeset
  1335
apply (rule_tac x = ha in exI, simp, frule_tac h = ha in procs_of_shm_prop1, simp+)
chunhan
parents:
diff changeset
  1336
using ch2sshm_other[where e = "DeleteShM p h" and s = s] apply (simp add:procs_of_shm_prop1)
chunhan
parents:
diff changeset
  1337
chunhan
parents:
diff changeset
  1338
apply (rule allI | rule conjI| erule conjE | erule exE | rule impI)+
chunhan
parents:
diff changeset
  1339
apply (simp only:cph2spshs_def, rule set_eqI, rule iffI)
chunhan
parents:
diff changeset
  1340
apply (erule CollectE | erule exE| erule conjE| rule DiffI |rule CollectI)+
chunhan
parents:
diff changeset
  1341
apply (simp split:if_splits)
chunhan
parents:
diff changeset
  1342
apply (rule_tac x = ha in exI, simp, frule_tac h = ha in procs_of_shm_prop1, simp+)
chunhan
parents:
diff changeset
  1343
using ch2sshm_other[where e = "DeleteShM p h" and s = s] apply (simp add:procs_of_shm_prop1)
chunhan
parents:
diff changeset
  1344
apply (rule notI, simp split:if_splits)
chunhan
parents:
diff changeset
  1345
apply (erule_tac x = ha in allE, simp, frule_tac h = ha in procs_of_shm_prop1, simp+)
chunhan
parents:
diff changeset
  1346
using ch2sshm_other[where e = "DeleteShM p h" and s = s] apply (simp add:procs_of_shm_prop1)
chunhan
parents:
diff changeset
  1347
apply (erule CollectE | erule exE| erule conjE| erule DiffE |rule CollectI)+
chunhan
parents:
diff changeset
  1348
apply (simp split:if_splits)
chunhan
parents:
diff changeset
  1349
apply (erule_tac x = ha in allE, simp, rule_tac x = ha in exI, simp)
chunhan
parents:
diff changeset
  1350
apply (case_tac "ha = h", simp add:procs_of_shm_prop4)
chunhan
parents:
diff changeset
  1351
apply (frule_tac h = ha in procs_of_shm_prop1, simp+)
chunhan
parents:
diff changeset
  1352
using ch2sshm_other[where e = "DeleteShM p h" and s = s] apply (simp add:procs_of_shm_prop1)
chunhan
parents:
diff changeset
  1353
done
chunhan
parents:
diff changeset
  1354
chunhan
parents:
diff changeset
  1355
lemma flag_of_proc_shm_prop1:
chunhan
parents:
diff changeset
  1356
  "\<lbrakk>flag_of_proc_shm s p h = Some flag; valid s\<rbrakk> \<Longrightarrow> (p, flag) \<in> procs_of_shm s h"
chunhan
parents:
diff changeset
  1357
apply (induct s arbitrary:p)
chunhan
parents:
diff changeset
  1358
apply (simp add:init_shmflag_has_proc)
chunhan
parents:
diff changeset
  1359
apply (frule vt_grant_os, frule vd_cons, case_tac a, auto split:if_splits option.splits)
chunhan
parents:
diff changeset
  1360
done
chunhan
parents:
diff changeset
  1361
chunhan
parents:
diff changeset
  1362
lemma cph2spshs_clone:
chunhan
parents:
diff changeset
  1363
  "valid (Clone p p' fds shms # s) \<Longrightarrow> 
chunhan
parents:
diff changeset
  1364
   cph2spshs (Clone p p' fds shms # s) = (cph2spshs s) (p' := 
chunhan
parents:
diff changeset
  1365
     {(sh, flag) | h sh flag. h \<in> shms \<and> ch2sshm s h = Some sh \<and> flag_of_proc_shm s p h = Some flag} )"
chunhan
parents:
diff changeset
  1366
apply (frule vd_cons, frule vt_grant_os, rule ext)
chunhan
parents:
diff changeset
  1367
using ch2sshm_other[where e = "Clone p p' fds shms" and s = s]
chunhan
parents:
diff changeset
  1368
apply (auto split del:t_open_must_flag.splits t_open_option_flag.splits split add:if_splits option.splits
chunhan
parents:
diff changeset
  1369
dest!:current_shm_has_sh' dest: procs_of_shm_prop1 procs_of_shm_prop2 procs_of_shm_prop3 simp:cph2spshs_def)
chunhan
parents:
diff changeset
  1370
apply (erule_tac x = h in allE, frule procs_of_shm_prop1, simp, simp add:procs_of_shm_prop4)
chunhan
parents:
diff changeset
  1371
apply (rule_tac x = h in exI, simp, frule flag_of_proc_shm_prop1, simp+, simp add:procs_of_shm_prop1)
chunhan
parents:
diff changeset
  1372
apply (rule_tac x = h in exI, simp, frule procs_of_shm_prop1, simp+)+
chunhan
parents:
diff changeset
  1373
done
chunhan
parents:
diff changeset
  1374
chunhan
parents:
diff changeset
  1375
lemma cph2spshs_execve:
chunhan
parents:
diff changeset
  1376
  "valid (Execve p f fds # s) \<Longrightarrow>
chunhan
parents:
diff changeset
  1377
  cph2spshs (Execve p f fds # s) = (cph2spshs s) (p := {})"
chunhan
parents:
diff changeset
  1378
apply (frule vd_cons, frule vt_grant_os, rule ext)
chunhan
parents:
diff changeset
  1379
using ch2sshm_other[where e = "Execve p f fds" and s = s]
chunhan
parents:
diff changeset
  1380
apply (auto split del:t_open_must_flag.splits t_open_option_flag.splits split add:if_splits option.splits
chunhan
parents:
diff changeset
  1381
dest!:current_shm_has_sh' dest: procs_of_shm_prop1 procs_of_shm_prop2 procs_of_shm_prop3 simp:cph2spshs_def)
chunhan
parents:
diff changeset
  1382
apply (rule_tac x = h in exI, simp add:procs_of_shm_prop1)+
chunhan
parents:
diff changeset
  1383
done
chunhan
parents:
diff changeset
  1384
chunhan
parents:
diff changeset
  1385
lemma cph2spshs_kill:
chunhan
parents:
diff changeset
  1386
  "valid (Kill p p' # s) \<Longrightarrow> cph2spshs (Kill p p' # s) = (cph2spshs s) (p' := {})"
chunhan
parents:
diff changeset
  1387
apply (frule vd_cons, frule vt_grant_os, rule ext)
chunhan
parents:
diff changeset
  1388
using ch2sshm_other[where e = "Kill p p'" and s = s]
chunhan
parents:
diff changeset
  1389
apply (auto split del:t_open_must_flag.splits t_open_option_flag.splits split add:if_splits option.splits
chunhan
parents:
diff changeset
  1390
dest!:current_shm_has_sh' dest: procs_of_shm_prop1 procs_of_shm_prop2 procs_of_shm_prop3 simp:cph2spshs_def)
chunhan
parents:
diff changeset
  1391
apply (rule_tac x = h in exI, simp add:procs_of_shm_prop1)+
chunhan
parents:
diff changeset
  1392
done
chunhan
parents:
diff changeset
  1393
chunhan
parents:
diff changeset
  1394
lemma cph2spshs_exit:
chunhan
parents:
diff changeset
  1395
  "valid (Exit p # s) \<Longrightarrow> cph2spshs (Exit p # s) = (cph2spshs s) (p := {})"
chunhan
parents:
diff changeset
  1396
apply (frule vd_cons, frule vt_grant_os, rule ext)
chunhan
parents:
diff changeset
  1397
using ch2sshm_other[where e = "Exit p" and s = s]
chunhan
parents:
diff changeset
  1398
apply (auto split del:t_open_must_flag.splits t_open_option_flag.splits split add:if_splits option.splits
chunhan
parents:
diff changeset
  1399
dest!:current_shm_has_sh' dest: procs_of_shm_prop1 procs_of_shm_prop2 procs_of_shm_prop3 simp:cph2spshs_def)
chunhan
parents:
diff changeset
  1400
apply (rule_tac x = h in exI, simp add:procs_of_shm_prop1)+
chunhan
parents:
diff changeset
  1401
done
chunhan
parents:
diff changeset
  1402
chunhan
parents:
diff changeset
  1403
lemma cph2spshs_createshm:
chunhan
parents:
diff changeset
  1404
  "valid (CreateShM p h # s) \<Longrightarrow> cph2spshs (CreateShM p h # s) = cph2spshs s"
chunhan
parents:
diff changeset
  1405
apply (frule vt_grant_os, frule vd_cons, rule ext)
chunhan
parents:
diff changeset
  1406
apply (auto simp:cph2spshs_def)
chunhan
parents:
diff changeset
  1407
using ch2sshm_createshm
chunhan
parents:
diff changeset
  1408
apply (auto split del:t_open_must_flag.splits t_open_option_flag.splits split add:if_splits option.splits
chunhan
parents:
diff changeset
  1409
dest!:current_shm_has_sh' dest: procs_of_shm_prop1 procs_of_shm_prop2 procs_of_shm_prop3 simp:cph2spshs_def)
chunhan
parents:
diff changeset
  1410
apply (rule_tac x = ha in exI, auto simp:procs_of_shm_prop1)
chunhan
parents:
diff changeset
  1411
done
chunhan
parents:
diff changeset
  1412
chunhan
parents:
diff changeset
  1413
lemma cph2spshs_other:
chunhan
parents:
diff changeset
  1414
  "\<lbrakk>valid (e # s); 
chunhan
parents:
diff changeset
  1415
    \<forall> p h flag. e \<noteq> Attach p h flag;
chunhan
parents:
diff changeset
  1416
    \<forall> p h. e \<noteq> Detach p h;
chunhan
parents:
diff changeset
  1417
    \<forall> p h. e \<noteq> DeleteShM p h;
chunhan
parents:
diff changeset
  1418
    \<forall> p p' fds shms. e \<noteq> Clone p p' fds shms;
chunhan
parents:
diff changeset
  1419
    \<forall> p f fds. e \<noteq> Execve p f fds;
chunhan
parents:
diff changeset
  1420
    \<forall> p p'. e \<noteq> Kill p p';
chunhan
parents:
diff changeset
  1421
    \<forall> p. e \<noteq> Exit p\<rbrakk> \<Longrightarrow> cph2spshs (e # s) = cph2spshs s"
chunhan
parents:
diff changeset
  1422
apply (frule vt_grant_os, frule vd_cons, rule ext)
chunhan
parents:
diff changeset
  1423
unfolding cph2spshs_def 
chunhan
parents:
diff changeset
  1424
apply (rule set_eqI, rule iffI)
chunhan
parents:
diff changeset
  1425
apply (erule CollectE | erule conjE| erule exE| rule conjI| rule impI| rule CollectI)+
chunhan
parents:
diff changeset
  1426
apply (frule procs_of_shm_prop1, simp, rule_tac x= sh in exI, rule_tac x = flag in exI, rule_tac x = h in exI)
chunhan
parents:
diff changeset
  1427
apply (case_tac e)
chunhan
parents:
diff changeset
  1428
using ch2sshm_other[where e = e and s = s] 
chunhan
parents:
diff changeset
  1429
apply (auto split del:t_open_must_flag.splits t_open_option_flag.splits split add:if_splits option.splits
chunhan
parents:
diff changeset
  1430
dest!:current_shm_has_sh' dest: procs_of_shm_prop1 procs_of_shm_prop2 procs_of_shm_prop3
chunhan
parents:
diff changeset
  1431
 simp:ch2sshm_createshm)
chunhan
parents:
diff changeset
  1432
apply (rule_tac x = h in exI, case_tac e)
chunhan
parents:
diff changeset
  1433
using ch2sshm_other[where e = e and s = s] 
chunhan
parents:
diff changeset
  1434
apply (auto split del:t_open_must_flag.splits t_open_option_flag.splits split add:if_splits option.splits
chunhan
parents:
diff changeset
  1435
dest!:current_shm_has_sh' dest: procs_of_shm_prop1 procs_of_shm_prop2 procs_of_shm_prop3 
chunhan
parents:
diff changeset
  1436
 simp:ch2sshm_createshm)
chunhan
parents:
diff changeset
  1437
done
chunhan
parents:
diff changeset
  1438
chunhan
parents:
diff changeset
  1439
lemmas cph2spshs_simps = cph2spshs_attach cph2spshs_detach cph2spshs_deleteshm cph2spshs_clone cph2spshs_execve
chunhan
parents:
diff changeset
  1440
  cph2spshs_exit cph2spshs_kill cph2spshs_other
chunhan
parents:
diff changeset
  1441
*)
chunhan
parents:
diff changeset
  1442
(******** cp2sproc simpset *********)
chunhan
parents:
diff changeset
  1443
chunhan
parents:
diff changeset
  1444
lemma cp2sproc_clone:
chunhan
parents:
diff changeset
  1445
  "valid (Clone p p' fds # s) \<Longrightarrow> cp2sproc (Clone p p' fds # s) = (cp2sproc s) (p' := 
chunhan
parents:
diff changeset
  1446
     case (sectxt_of_obj s (O_proc p)) of 
chunhan
parents:
diff changeset
  1447
       Some sec \<Rightarrow> Some (Created, sec, 
chunhan
parents:
diff changeset
  1448
  {sfd. \<exists> fd \<in> fds. \<exists> f. file_of_proc_fd s p fd = Some f \<and> cfd2sfd s p fd = Some sfd})
chunhan
parents:
diff changeset
  1449
     | _        \<Rightarrow> None)" (* ,
chunhan
parents:
diff changeset
  1450
  {(sh, flag) | h sh flag. h \<in> shms \<and> ch2sshm s h = Some sh \<and> flag_of_proc_shm s p h = Some flag} *)
chunhan
parents:
diff changeset
  1451
apply (frule cpfd2sfds_clone) (*
chunhan
parents:
diff changeset
  1452
apply (frule cph2spshs_clone, frule cpfd2sfds_clone) *)
chunhan
parents:
diff changeset
  1453
apply (frule vd_cons, frule vt_grant_os, simp only:os_grant.simps)
chunhan
parents:
diff changeset
  1454
apply ((erule exE| erule conjE)+, frule not_init_intro_proc, simp, rule ext, case_tac "x = p'", simp)
chunhan
parents:
diff changeset
  1455
apply (auto simp:cp2sproc_def sectxt_of_obj_simps dest!:current_has_sec' 
chunhan
parents:
diff changeset
  1456
            dest:current_proc_has_sec split:option.splits if_splits)
chunhan
parents:
diff changeset
  1457
done
chunhan
parents:
diff changeset
  1458
chunhan
parents:
diff changeset
  1459
lemma cp2sproc_other:
chunhan
parents:
diff changeset
  1460
  "\<lbrakk>valid (e # s); 
chunhan
parents:
diff changeset
  1461
    \<forall> p f flags fd opt. e \<noteq> Open p f flags fd opt;
chunhan
parents:
diff changeset
  1462
    \<forall> p fd. e \<noteq> CloseFd p fd;
chunhan
parents:
diff changeset
  1463
    \<forall> p p' fds. e \<noteq> Clone p p' fds;
chunhan
parents:
diff changeset
  1464
    \<forall> p f fds. e \<noteq> Execve p f fds;
chunhan
parents:
diff changeset
  1465
    \<forall> p p'. e \<noteq> Kill p p';
chunhan
parents:
diff changeset
  1466
    \<forall> p. e \<noteq> Exit p\<rbrakk> \<Longrightarrow> cp2sproc (e # s) = cp2sproc s" (*
chunhan
parents:
diff changeset
  1467
    \<forall> p h flag. e \<noteq> Attach p h flag;
chunhan
parents:
diff changeset
  1468
    \<forall> p h. e \<noteq> Detach p h;
chunhan
parents:
diff changeset
  1469
    \<forall> p h. e \<noteq> DeleteShM p h;*)
chunhan
parents:
diff changeset
  1470
apply (frule cpfd2sfds_other, simp+)(*
chunhan
parents:
diff changeset
  1471
apply (frule cph2spshs_other, simp+, frule cpfd2sfds_other, simp+)*)
chunhan
parents:
diff changeset
  1472
apply (frule vt_grant_os, frule vd_cons, rule ext, case_tac e, simp_all) 
chunhan
parents:
diff changeset
  1473
apply (auto simp:cp2sproc_def sectxt_of_obj_simps dest!:current_has_sec' 
chunhan
parents:
diff changeset
  1474
            dest:current_proc_has_sec not_died_init_proc split:option.splits if_splits)
chunhan
parents:
diff changeset
  1475
done
chunhan
parents:
diff changeset
  1476
chunhan
parents:
diff changeset
  1477
lemma cp2sproc_open:
chunhan
parents:
diff changeset
  1478
  "valid (Open p f flags fd opt # s) \<Longrightarrow> 
chunhan
parents:
diff changeset
  1479
   cp2sproc (Open p f flags fd opt # s) = (cp2sproc s) (p :=      
chunhan
parents:
diff changeset
  1480
     case (sectxt_of_obj s (O_proc p), sectxt_of_obj (Open p f flags fd opt # s) (O_fd p fd), 
chunhan
parents:
diff changeset
  1481
           cf2sfile (Open p f flags fd opt # s) f) of 
chunhan
parents:
diff changeset
  1482
       (Some sec, Some fdsec, Some sf) \<Rightarrow> Some (if (\<not> died (O_proc p) s \<and> p \<in> init_procs) 
chunhan
parents:
diff changeset
  1483
                                               then Init p else Created, sec, 
85
1d1aa5bdd37d add remove_create_flag to sfd
chunhan
parents: 77
diff changeset
  1484
                                                (cpfd2sfds s p) \<union> {(fdsec, remove_create_flag flags, sf)})
77
chunhan
parents:
diff changeset
  1485
     | _        \<Rightarrow> None)" (*, cph2spshs s p 
chunhan
parents:
diff changeset
  1486
apply (frule cph2spshs_other, simp, simp, simp, simp, simp, simp, simp) *)
chunhan
parents:
diff changeset
  1487
apply (frule cpfd2sfds_open, frule vt_grant_os, frule vd_cons, rule ext)
chunhan
parents:
diff changeset
  1488
apply (case_tac "x = p") 
chunhan
parents:
diff changeset
  1489
apply (auto simp:cp2sproc_def sectxt_of_obj_simps current_files_simps 
chunhan
parents:
diff changeset
  1490
           dest!:current_has_sec' dest!:current_file_has_sfile' dest:is_file_in_current is_dir_in_current
chunhan
parents:
diff changeset
  1491
            dest:current_proc_has_sec not_died_init_proc split:option.splits if_splits)
chunhan
parents:
diff changeset
  1492
done
chunhan
parents:
diff changeset
  1493
chunhan
parents:
diff changeset
  1494
lemma cp2sproc_closefd:
chunhan
parents:
diff changeset
  1495
  "valid (CloseFd p fd # s) \<Longrightarrow> 
chunhan
parents:
diff changeset
  1496
   cp2sproc (CloseFd p fd # s) = (cp2sproc s) (p := 
chunhan
parents:
diff changeset
  1497
     if (fd \<in> proc_file_fds s p)
chunhan
parents:
diff changeset
  1498
     then (case (cfd2sfd s p fd) of 
chunhan
parents:
diff changeset
  1499
             Some sfd \<Rightarrow> (if (\<exists> fd' f'. fd' \<noteq> fd \<and> file_of_proc_fd s p fd' = Some f' \<and> cfd2sfd s p fd' = Some sfd)
chunhan
parents:
diff changeset
  1500
                          then cp2sproc s p 
chunhan
parents:
diff changeset
  1501
                          else (case (sectxt_of_obj s (O_proc p)) of
chunhan
parents:
diff changeset
  1502
                                  Some sec \<Rightarrow> Some (if (\<not> died (O_proc p) s \<and> p \<in> init_procs) 
chunhan
parents:
diff changeset
  1503
                                                    then Init p else Created, 
chunhan
parents:
diff changeset
  1504
                                                    sec, cpfd2sfds s p - {sfd})
chunhan
parents:
diff changeset
  1505
                                | _        \<Rightarrow> None))
chunhan
parents:
diff changeset
  1506
           | _        \<Rightarrow> cp2sproc s p)
chunhan
parents:
diff changeset
  1507
     else cp2sproc s p)"(*, cph2spshs s p *)
chunhan
parents:
diff changeset
  1508
apply (frule cpfd2sfds_closefd) (*
chunhan
parents:
diff changeset
  1509
apply (frule cpfd2sfds_closefd, frule cph2spshs_other, simp, simp, simp, simp, simp, simp, simp) *)
chunhan
parents:
diff changeset
  1510
apply (frule vt_grant_os, frule vd_cons, rule ext)
chunhan
parents:
diff changeset
  1511
apply (case_tac "x = p") 
chunhan
parents:
diff changeset
  1512
apply (auto simp:cp2sproc_def sectxt_of_obj_simps current_files_simps 
chunhan
parents:
diff changeset
  1513
           dest!:current_has_sec' dest!:current_file_has_sfile' dest:is_file_in_current is_dir_in_current
chunhan
parents:
diff changeset
  1514
            dest:current_proc_has_sec not_died_init_proc split:option.splits if_splits)
chunhan
parents:
diff changeset
  1515
done
chunhan
parents:
diff changeset
  1516
chunhan
parents:
diff changeset
  1517
(*
chunhan
parents:
diff changeset
  1518
lemma cp2sproc_attach:
chunhan
parents:
diff changeset
  1519
  "valid (Attach p h flag # s) \<Longrightarrow> 
chunhan
parents:
diff changeset
  1520
   cp2sproc (Attach p h flag # s) = (cp2sproc s) (p := 
chunhan
parents:
diff changeset
  1521
     (case (ch2sshm s h) of 
chunhan
parents:
diff changeset
  1522
        Some sh \<Rightarrow> (case (sectxt_of_obj s (O_proc p)) of
chunhan
parents:
diff changeset
  1523
                      Some sec \<Rightarrow> Some (if (\<not> died (O_proc p) s \<and> p \<in> init_procs) 
chunhan
parents:
diff changeset
  1524
                                        then Init p else Created, 
chunhan
parents:
diff changeset
  1525
                                        sec, cpfd2sfds s p, cph2spshs s p \<union> {(sh, flag)})
chunhan
parents:
diff changeset
  1526
                    | _        \<Rightarrow> None)
chunhan
parents:
diff changeset
  1527
      | _       \<Rightarrow> cp2sproc s p) )"
chunhan
parents:
diff changeset
  1528
apply (frule cph2spshs_attach, frule cpfd2sfds_other, simp, simp, simp, simp, simp, simp)
chunhan
parents:
diff changeset
  1529
apply (frule vt_grant_os, frule vd_cons, rule ext)
chunhan
parents:
diff changeset
  1530
apply (case_tac "x = p") 
chunhan
parents:
diff changeset
  1531
apply (auto simp:cp2sproc_def sectxt_of_obj_simps current_files_simps 
chunhan
parents:
diff changeset
  1532
           dest!:current_has_sec' dest!:current_file_has_sfile' dest:is_file_in_current is_dir_in_current
chunhan
parents:
diff changeset
  1533
            dest:current_proc_has_sec not_died_init_proc split:option.splits if_splits)
chunhan
parents:
diff changeset
  1534
done
chunhan
parents:
diff changeset
  1535
chunhan
parents:
diff changeset
  1536
lemma cp2sproc_detach:
chunhan
parents:
diff changeset
  1537
  "valid (Detach p h # s) \<Longrightarrow> 
chunhan
parents:
diff changeset
  1538
   cp2sproc (Detach p h # s) = (cp2sproc s) (p := 
chunhan
parents:
diff changeset
  1539
    (case (ch2sshm s h, flag_of_proc_shm s p h) of 
chunhan
parents:
diff changeset
  1540
       (Some sh, Some flag) \<Rightarrow> if (\<exists> h'. h' \<noteq> h \<and> (p,flag) \<in> procs_of_shm s h' \<and> ch2sshm s h' = Some sh)
chunhan
parents:
diff changeset
  1541
                              then cp2sproc s p 
chunhan
parents:
diff changeset
  1542
                              else (case (sectxt_of_obj s (O_proc p)) of
chunhan
parents:
diff changeset
  1543
                                      Some sec \<Rightarrow> Some (if (\<not> died (O_proc p) s \<and> p \<in> init_procs) 
chunhan
parents:
diff changeset
  1544
                                                       then Init p else Created, sec,
chunhan
parents:
diff changeset
  1545
                                                       cpfd2sfds s p, cph2spshs s p - {(sh, flag)})
chunhan
parents:
diff changeset
  1546
                                    | None     \<Rightarrow> None)                   
chunhan
parents:
diff changeset
  1547
     | _       \<Rightarrow> cp2sproc s p)             )"
chunhan
parents:
diff changeset
  1548
apply (frule cph2spshs_detach, frule cpfd2sfds_other, simp, simp, simp, simp, simp, simp)
chunhan
parents:
diff changeset
  1549
apply (frule vt_grant_os, frule vd_cons, rule ext)
chunhan
parents:
diff changeset
  1550
apply (case_tac "x = p") 
chunhan
parents:
diff changeset
  1551
apply (auto simp:cp2sproc_def sectxt_of_obj_simps current_files_simps 
chunhan
parents:
diff changeset
  1552
           dest!:current_has_sec' dest!:current_file_has_sfile' dest:is_file_in_current is_dir_in_current
chunhan
parents:
diff changeset
  1553
            dest:current_proc_has_sec not_died_init_proc split:option.splits if_splits)
chunhan
parents:
diff changeset
  1554
done
chunhan
parents:
diff changeset
  1555
chunhan
parents:
diff changeset
  1556
lemma cp2sproc_deleteshm:
chunhan
parents:
diff changeset
  1557
  "valid (DeleteShM p h # s) \<Longrightarrow> 
chunhan
parents:
diff changeset
  1558
   cp2sproc (DeleteShM p h # s) = (\<lambda> p'. 
chunhan
parents:
diff changeset
  1559
    (case (ch2sshm s h, flag_of_proc_shm s p' h) of 
chunhan
parents:
diff changeset
  1560
       (Some sh, Some flag) \<Rightarrow> if (\<exists> h'. h' \<noteq> h \<and> (p', flag) \<in> procs_of_shm s h' \<and> ch2sshm s h' = Some sh)
chunhan
parents:
diff changeset
  1561
                              then cp2sproc s p' 
chunhan
parents:
diff changeset
  1562
                              else (case (sectxt_of_obj s (O_proc p')) of
chunhan
parents:
diff changeset
  1563
                                      Some sec \<Rightarrow> Some (if (\<not> died (O_proc p') s \<and> p' \<in> init_procs) 
chunhan
parents:
diff changeset
  1564
                                                       then Init p' else Created, sec,
chunhan
parents:
diff changeset
  1565
                                                       cpfd2sfds s p', cph2spshs s p' - {(sh, flag)})
chunhan
parents:
diff changeset
  1566
                                    | None     \<Rightarrow> None)                   
chunhan
parents:
diff changeset
  1567
     | _       \<Rightarrow> cp2sproc s p')             )"
chunhan
parents:
diff changeset
  1568
apply (frule cph2spshs_deleteshm, frule cpfd2sfds_other, simp, simp, simp, simp, simp, simp)
chunhan
parents:
diff changeset
  1569
apply (frule vt_grant_os, frule vd_cons, rule ext)
chunhan
parents:
diff changeset
  1570
apply (auto simp:cp2sproc_def sectxt_of_obj_simps current_files_simps 
chunhan
parents:
diff changeset
  1571
           dest!:current_has_sec' dest!:current_file_has_sfile' dest:is_file_in_current is_dir_in_current
chunhan
parents:
diff changeset
  1572
            dest:current_proc_has_sec not_died_init_proc split:option.splits if_splits)
chunhan
parents:
diff changeset
  1573
done
chunhan
parents:
diff changeset
  1574
*)
chunhan
parents:
diff changeset
  1575
chunhan
parents:
diff changeset
  1576
lemma cp2sproc_execve:
chunhan
parents:
diff changeset
  1577
  "valid (Execve p f fds # s) \<Longrightarrow> 
chunhan
parents:
diff changeset
  1578
   cp2sproc (Execve p f fds # s) = (cp2sproc s) (p := 
chunhan
parents:
diff changeset
  1579
     (case (sectxt_of_obj (Execve p f fds # s) (O_proc p)) of
chunhan
parents:
diff changeset
  1580
        Some sec \<Rightarrow> Some (if (\<not> died (O_proc p) s \<and> p \<in> init_procs) then Init p else Created, sec, 
chunhan
parents:
diff changeset
  1581
                         {sfd. \<exists> fd \<in> fds. \<exists> f. file_of_proc_fd s p fd = Some f \<and> cfd2sfd s p fd = Some sfd})
chunhan
parents:
diff changeset
  1582
      | _        \<Rightarrow> None)                        )" (*, {}
chunhan
parents:
diff changeset
  1583
apply (frule cph2spshs_execve, frule cpfd2sfds_execve) *)
chunhan
parents:
diff changeset
  1584
apply (frule cpfd2sfds_execve)
chunhan
parents:
diff changeset
  1585
apply (frule vt_grant_os, frule vd_cons, rule ext)
chunhan
parents:
diff changeset
  1586
apply (auto simp:cp2sproc_def sectxt_of_obj_simps current_files_simps 
chunhan
parents:
diff changeset
  1587
           dest!:current_has_sec' dest!:current_file_has_sfile' dest:is_file_in_current is_dir_in_current
chunhan
parents:
diff changeset
  1588
            dest:current_proc_has_sec not_died_init_proc split:option.splits if_splits)
chunhan
parents:
diff changeset
  1589
done
chunhan
parents:
diff changeset
  1590
chunhan
parents:
diff changeset
  1591
lemma cp2sproc_kill:
chunhan
parents:
diff changeset
  1592
  "\<lbrakk>valid (Kill p p' # s); p'' \<noteq> p'\<rbrakk> \<Longrightarrow> 
chunhan
parents:
diff changeset
  1593
   cp2sproc (Kill p p' # s) p'' = (cp2sproc s) p''" (*
chunhan
parents:
diff changeset
  1594
apply (frule cph2spshs_kill, frule cpfd2sfds_kill) *)
chunhan
parents:
diff changeset
  1595
apply (frule cpfd2sfds_kill)
chunhan
parents:
diff changeset
  1596
apply (frule vt_grant_os, frule vd_cons)
chunhan
parents:
diff changeset
  1597
apply (auto simp:cp2sproc_def sectxt_of_obj_simps current_files_simps 
chunhan
parents:
diff changeset
  1598
           dest!:current_has_sec' dest!:current_file_has_sfile' dest:is_file_in_current is_dir_in_current
chunhan
parents:
diff changeset
  1599
            dest:current_proc_has_sec not_died_init_proc split:option.splits if_splits)
chunhan
parents:
diff changeset
  1600
done
chunhan
parents:
diff changeset
  1601
chunhan
parents:
diff changeset
  1602
lemma cp2sproc_kill':
chunhan
parents:
diff changeset
  1603
  "\<lbrakk>valid (Kill p p' # s); p'' \<in> current_procs (Kill p p' # s)\<rbrakk> \<Longrightarrow> 
chunhan
parents:
diff changeset
  1604
   cp2sproc (Kill p p' # s) p'' = (cp2sproc s) p''"
chunhan
parents:
diff changeset
  1605
by (drule_tac p'' = p'' in cp2sproc_kill, simp+)
chunhan
parents:
diff changeset
  1606
chunhan
parents:
diff changeset
  1607
lemma cp2sproc_exit:
chunhan
parents:
diff changeset
  1608
  "\<lbrakk>valid (Exit p # s); p' \<noteq> p\<rbrakk> \<Longrightarrow> 
chunhan
parents:
diff changeset
  1609
   cp2sproc (Exit p # s) p' = (cp2sproc s) p'" (*
chunhan
parents:
diff changeset
  1610
apply (frule cph2spshs_exit, frule cpfd2sfds_exit) *)
chunhan
parents:
diff changeset
  1611
apply (frule cpfd2sfds_exit)
chunhan
parents:
diff changeset
  1612
apply (frule vt_grant_os, frule vd_cons)
chunhan
parents:
diff changeset
  1613
apply (auto simp:cp2sproc_def sectxt_of_obj_simps current_files_simps 
chunhan
parents:
diff changeset
  1614
           dest!:current_has_sec' dest!:current_file_has_sfile' dest:is_file_in_current is_dir_in_current
chunhan
parents:
diff changeset
  1615
            dest:current_proc_has_sec not_died_init_proc split:option.splits if_splits)
chunhan
parents:
diff changeset
  1616
done
chunhan
parents:
diff changeset
  1617
chunhan
parents:
diff changeset
  1618
lemma cp2sproc_exit':
chunhan
parents:
diff changeset
  1619
  "\<lbrakk>valid (Exit p # s); p' \<in> current_procs (Exit p # s)\<rbrakk> \<Longrightarrow> 
chunhan
parents:
diff changeset
  1620
   cp2sproc (Exit p # s) p' = (cp2sproc s) p'"
chunhan
parents:
diff changeset
  1621
by (drule_tac p'= p' in cp2sproc_exit, simp+)
chunhan
parents:
diff changeset
  1622
chunhan
parents:
diff changeset
  1623
lemmas cp2sproc_simps = cp2sproc_open cp2sproc_closefd (* cp2sproc_attach cp2sproc_detach cp2sproc_deleteshm *)
chunhan
parents:
diff changeset
  1624
  cp2sproc_clone cp2sproc_execve cp2sproc_kill cp2sproc_exit cp2sproc_other 
chunhan
parents:
diff changeset
  1625
chunhan
parents:
diff changeset
  1626
lemma current_proc_has_sp:
chunhan
parents:
diff changeset
  1627
  "\<lbrakk>p \<in> current_procs s; valid s\<rbrakk> \<Longrightarrow> \<exists> sp. cp2sproc s p = Some sp"
chunhan
parents:
diff changeset
  1628
by (auto simp:cp2sproc_def split:option.splits dest!:current_has_sec')
chunhan
parents:
diff changeset
  1629
chunhan
parents:
diff changeset
  1630
lemma current_proc_has_sp':
chunhan
parents:
diff changeset
  1631
  "\<lbrakk>cp2sproc s p = None; valid s\<rbrakk> \<Longrightarrow> p \<notin> current_procs s"
chunhan
parents:
diff changeset
  1632
by (auto dest:current_proc_has_sp)
chunhan
parents:
diff changeset
  1633
chunhan
parents:
diff changeset
  1634
(* simpset for cf2sfiles *)
chunhan
parents:
diff changeset
  1635
chunhan
parents:
diff changeset
  1636
lemma cf2sfiles_open:
chunhan
parents:
diff changeset
  1637
  "\<lbrakk>valid (Open p f flag fd opt # s); f' \<in> current_files (Open p f flag fd opt # s)\<rbrakk>
chunhan
parents:
diff changeset
  1638
   \<Longrightarrow> cf2sfiles (Open p f flag fd opt # s) f' = (
chunhan
parents:
diff changeset
  1639
     if (f' = f \<and> opt \<noteq> None) 
chunhan
parents:
diff changeset
  1640
     then (case cf2sfile (Open p f flag fd opt # s) f of 
chunhan
parents:
diff changeset
  1641
             Some sf \<Rightarrow> {sf}  
chunhan
parents:
diff changeset
  1642
           | _       \<Rightarrow> {} )
chunhan
parents:
diff changeset
  1643
     else cf2sfiles s f')"
chunhan
parents:
diff changeset
  1644
apply (frule vt_grant_os, frule vd_cons)
chunhan
parents:
diff changeset
  1645
apply (auto simp:cf2sfiles_def cf2sfile_open_none cf2sfile_simps same_inode_files_open
chunhan
parents:
diff changeset
  1646
  split:if_splits option.splits dest!:current_file_has_sfile' dest:cf2sfile_open)
chunhan
parents:
diff changeset
  1647
apply (rule_tac x = "f'a" in bexI, drule same_inode_files_prop1, simp add:cf2sfile_open_some1, simp)+
chunhan
parents:
diff changeset
  1648
done
chunhan
parents:
diff changeset
  1649
chunhan
parents:
diff changeset
  1650
lemma cf2sfiles_other:
chunhan
parents:
diff changeset
  1651
  "\<lbrakk>valid (e # s);
chunhan
parents:
diff changeset
  1652
    \<forall> p f flag fd opt. e \<noteq> Open p f flag fd opt;
chunhan
parents:
diff changeset
  1653
    \<forall> p fd. e \<noteq> CloseFd p fd;
chunhan
parents:
diff changeset
  1654
    \<forall> p f. e \<noteq> UnLink p f;
chunhan
parents:
diff changeset
  1655
    \<forall> p f f'. e \<noteq> LinkHard p f f'\<rbrakk> \<Longrightarrow> cf2sfiles (e # s) = cf2sfiles s"
chunhan
parents:
diff changeset
  1656
apply (frule vt_grant_os, frule vd_cons, rule ext)
chunhan
parents:
diff changeset
  1657
apply (simp add:cf2sfiles_def, rule set_eqI, rule iffI)
chunhan
parents:
diff changeset
  1658
apply (drule Set.CollectD, erule bexE, rule CollectI)
chunhan
parents:
diff changeset
  1659
apply (rule_tac x = f' in bexI, case_tac e)
chunhan
parents:
diff changeset
  1660
apply (auto simp:cf2sfiles_def cf2sfile_simps same_inode_files_simps current_files_simps
chunhan
parents:
diff changeset
  1661
  split:if_splits option.splits dest!:current_file_has_sfile' dest:same_inode_files_prop1 cf2sfile_other')
chunhan
parents:
diff changeset
  1662
apply (drule_tac f' = f' in cf2sfile_rmdir)
chunhan
parents:
diff changeset
  1663
apply (simp add:current_files_simps same_inode_files_prop1 same_inode_files_prop3 dir_is_empty_def)+
chunhan
parents:
diff changeset
  1664
chunhan
parents:
diff changeset
  1665
apply (rule_tac x = f' in bexI, case_tac e)
chunhan
parents:
diff changeset
  1666
apply (auto simp:cf2sfiles_def cf2sfile_simps same_inode_files_simps current_files_simps
chunhan
parents:
diff changeset
  1667
  split:if_splits option.splits dest!:current_file_has_sfile' dest:same_inode_files_prop1 cf2sfile_other')
chunhan
parents:
diff changeset
  1668
apply (drule_tac f' = f' in cf2sfile_rmdir)
chunhan
parents:
diff changeset
  1669
apply (simp add:current_files_simps same_inode_files_prop1 same_inode_files_prop3 dir_is_empty_def)+
chunhan
parents:
diff changeset
  1670
done
chunhan
parents:
diff changeset
  1671
chunhan
parents:
diff changeset
  1672
lemma cf2sfile_linkhard1':
chunhan
parents:
diff changeset
  1673
  "\<lbrakk>valid (LinkHard p oldf f # s); f' \<in> same_inode_files s f''\<rbrakk>
chunhan
parents:
diff changeset
  1674
   \<Longrightarrow> cf2sfile (LinkHard p oldf f# s) f' = cf2sfile s f'"
chunhan
parents:
diff changeset
  1675
apply (drule same_inode_files_prop1)
chunhan
parents:
diff changeset
  1676
by (simp add:cf2sfile_linkhard1)
chunhan
parents:
diff changeset
  1677
chunhan
parents:
diff changeset
  1678
lemma cf2sfiles_linkhard:
chunhan
parents:
diff changeset
  1679
  "valid (LinkHard p oldf f # s) \<Longrightarrow> cf2sfiles (LinkHard p oldf f # s) = (\<lambda> f'. 
chunhan
parents:
diff changeset
  1680
     if (f' = f \<or> f' \<in> same_inode_files s oldf)
chunhan
parents:
diff changeset
  1681
     then (case (cf2sfile (LinkHard p oldf f # s) f) of
chunhan
parents:
diff changeset
  1682
             Some sf \<Rightarrow> cf2sfiles s oldf \<union> {sf}
chunhan
parents:
diff changeset
  1683
           | _       \<Rightarrow> {})
chunhan
parents:
diff changeset
  1684
     else cf2sfiles s f')"
chunhan
parents:
diff changeset
  1685
apply (frule vt_grant_os, frule vd_cons, rule ext)
chunhan
parents:
diff changeset
  1686
apply (auto simp:cf2sfiles_def cf2sfile_linkhard1' same_inode_files_linkhard current_files_linkhard 
chunhan
parents:
diff changeset
  1687
  split:if_splits option.splits dest!:current_file_has_sfile' current_has_sec' dest:same_inode_files_prop1)
chunhan
parents:
diff changeset
  1688
done
chunhan
parents:
diff changeset
  1689
chunhan
parents:
diff changeset
  1690
lemma cf2sfile_unlink':
chunhan
parents:
diff changeset
  1691
  "\<lbrakk>valid (UnLink p f # s); f' \<in> same_inode_files (UnLink p f # s) f''\<rbrakk>
chunhan
parents:
diff changeset
  1692
   \<Longrightarrow> cf2sfile (UnLink p f # s) f' = cf2sfile s f'"
chunhan
parents:
diff changeset
  1693
apply (drule same_inode_files_prop1)
chunhan
parents:
diff changeset
  1694
by (simp add:cf2sfile_unlink)
chunhan
parents:
diff changeset
  1695
chunhan
parents:
diff changeset
  1696
lemma cf2sfiles_unlink:
chunhan
parents:
diff changeset
  1697
  "\<lbrakk>valid (UnLink p f # s); f' \<in> current_files (UnLink p f # s)\<rbrakk> \<Longrightarrow> cf2sfiles (UnLink p f # s) f' = ( 
chunhan
parents:
diff changeset
  1698
     if (f' \<in> same_inode_files s f \<and> proc_fd_of_file s f = {} \<and> 
chunhan
parents:
diff changeset
  1699
         (\<forall> f'' \<in> same_inode_files s f. f'' \<noteq> f \<longrightarrow> cf2sfile s f'' \<noteq> cf2sfile s f)) then 
chunhan
parents:
diff changeset
  1700
        (case (cf2sfile s f) of 
chunhan
parents:
diff changeset
  1701
           Some sf \<Rightarrow> cf2sfiles s f' - {sf}
chunhan
parents:
diff changeset
  1702
         | _       \<Rightarrow> {})
chunhan
parents:
diff changeset
  1703
     else cf2sfiles s f')"
chunhan
parents:
diff changeset
  1704
apply (frule vt_grant_os, frule vd_cons, simp add:current_files_simps split:if_splits)
chunhan
parents:
diff changeset
  1705
apply (rule conjI, clarify, frule is_file_has_sfile', simp, erule exE, simp)
chunhan
parents:
diff changeset
  1706
apply (simp add:cf2sfiles_def, rule set_eqI, rule iffI, drule CollectD)
chunhan
parents:
diff changeset
  1707
apply (erule bexE, frule_tac f' = f' in same_inode_files_unlink)
chunhan
parents:
diff changeset
  1708
apply (simp add:current_files_unlink, simp, erule conjE)
chunhan
parents:
diff changeset
  1709
apply (erule_tac x = f'a in ballE, frule_tac f' = "f'a" in cf2sfile_unlink)
chunhan
parents:
diff changeset
  1710
apply (simp add:current_files_unlink same_inode_files_prop1, simp)
chunhan
parents:
diff changeset
  1711
apply (rule_tac x = f'a in bexI, simp, simp)
chunhan
parents:
diff changeset
  1712
apply (drule_tac f = f and f' = f' and f'' = f'a in same_inode_files_prop4, simp+)
chunhan
parents:
diff changeset
  1713
apply (erule conjE|erule exE|erule bexE)+
chunhan
parents:
diff changeset
  1714
apply (case_tac "f'a = f", simp)
chunhan
parents:
diff changeset
  1715
apply (frule_tac f' = f' in same_inode_files_unlink, simp add:current_files_unlink)
chunhan
parents:
diff changeset
  1716
apply (frule_tac f' = f'a in cf2sfile_unlink, simp add:current_files_unlink same_inode_files_prop1)
chunhan
parents:
diff changeset
  1717
apply (rule_tac x = f'a in bexI, simp, simp)
chunhan
parents:
diff changeset
  1718
chunhan
parents:
diff changeset
  1719
apply (rule impI)+
chunhan
parents:
diff changeset
  1720
apply (simp add:cf2sfiles_def, rule set_eqI, rule iffI, drule CollectD)
chunhan
parents:
diff changeset
  1721
apply (erule bexE, frule_tac f' = f' in same_inode_files_unlink)
chunhan
parents:
diff changeset
  1722
apply (simp add:current_files_unlink, simp, (erule conjE)+)
chunhan
parents:
diff changeset
  1723
apply (rule_tac x = f'a in bexI, frule_tac f' = "f'a" in cf2sfile_unlink)
chunhan
parents:
diff changeset
  1724
apply (simp add:current_files_unlink same_inode_files_prop1, simp, simp)
chunhan
parents:
diff changeset
  1725
apply (drule CollectD, erule bexE, frule_tac f' = f' in same_inode_files_unlink)
chunhan
parents:
diff changeset
  1726
apply (simp add:current_files_unlink, simp)
chunhan
parents:
diff changeset
  1727
apply (case_tac "f'a = f", simp)
chunhan
parents:
diff changeset
  1728
apply (frule_tac f = f' and f' = f in same_inode_files_prop5, simp)
chunhan
parents:
diff changeset
  1729
apply (erule bexE, erule conjE)
chunhan
parents:
diff changeset
  1730
apply (rule_tac x = f'' in bexI)
chunhan
parents:
diff changeset
  1731
apply (drule_tac f' = f'' in cf2sfile_unlink, simp add:current_files_unlink same_inode_files_prop1)
chunhan
parents:
diff changeset
  1732
apply (simp, simp, erule same_inode_files_prop4, simp)
chunhan
parents:
diff changeset
  1733
apply (rule_tac x = f'a in bexI)
chunhan
parents:
diff changeset
  1734
apply (drule_tac f' = f'a in cf2sfile_unlink, simp add:current_files_unlink same_inode_files_prop1)
chunhan
parents:
diff changeset
  1735
apply (simp, simp)
chunhan
parents:
diff changeset
  1736
chunhan
parents:
diff changeset
  1737
chunhan
parents:
diff changeset
  1738
apply (simp add:cf2sfiles_def, rule set_eqI, rule iffI, drule CollectD)
chunhan
parents:
diff changeset
  1739
apply (erule bexE, frule_tac f' = f' in same_inode_files_unlink)
chunhan
parents:
diff changeset
  1740
apply (simp add:current_files_unlink, simp)
chunhan
parents:
diff changeset
  1741
apply (rule_tac x = f'a in bexI)
chunhan
parents:
diff changeset
  1742
apply (frule_tac f' = f'a in cf2sfile_unlink)
chunhan
parents:
diff changeset
  1743
apply (simp add:same_inode_files_prop1 current_files_unlink, simp, simp)
chunhan
parents:
diff changeset
  1744
apply (drule CollectD, erule bexE, frule_tac f' = f' in same_inode_files_unlink)
chunhan
parents:
diff changeset
  1745
apply (simp add:current_files_unlink, simp)
chunhan
parents:
diff changeset
  1746
apply (rule_tac x = f'a in bexI)
chunhan
parents:
diff changeset
  1747
apply (frule_tac f' = f'a in cf2sfile_unlink)
chunhan
parents:
diff changeset
  1748
apply (simp add:same_inode_files_prop1 current_files_unlink, simp, simp)
chunhan
parents:
diff changeset
  1749
done
chunhan
parents:
diff changeset
  1750
chunhan
parents:
diff changeset
  1751
lemma cf2sfiles_closefd:
chunhan
parents:
diff changeset
  1752
  "\<lbrakk>valid (CloseFd p fd # s); f' \<in> current_files (CloseFd p fd # s)\<rbrakk> \<Longrightarrow> cf2sfiles (CloseFd p fd # s) f' = (
chunhan
parents:
diff changeset
  1753
     case (file_of_proc_fd s p fd) of
chunhan
parents:
diff changeset
  1754
       Some f \<Rightarrow> if (f' \<in> same_inode_files s f \<and> proc_fd_of_file s f = {(p, fd)} \<and> f \<in> files_hung_by_del s \<and> 
chunhan
parents:
diff changeset
  1755
                    (\<forall> f'' \<in> same_inode_files s f. f'' \<noteq> f \<longrightarrow> cf2sfile s f'' \<noteq> cf2sfile s f)) 
chunhan
parents:
diff changeset
  1756
                 then (case (cf2sfile s f) of 
chunhan
parents:
diff changeset
  1757
                         Some sf \<Rightarrow> cf2sfiles s f' - {sf}
chunhan
parents:
diff changeset
  1758
                       | _       \<Rightarrow> {})
chunhan
parents:
diff changeset
  1759
                 else cf2sfiles s f'
chunhan
parents:
diff changeset
  1760
     | _       \<Rightarrow> cf2sfiles s f')"
chunhan
parents:
diff changeset
  1761
chunhan
parents:
diff changeset
  1762
apply (frule vt_grant_os, frule vd_cons, case_tac "file_of_proc_fd s p fd")
chunhan
parents:
diff changeset
  1763
apply (simp_all add:current_files_simps split:if_splits)
chunhan
parents:
diff changeset
  1764
chunhan
parents:
diff changeset
  1765
apply (simp add:cf2sfiles_def, rule set_eqI, rule iffI, drule CollectD)
chunhan
parents:
diff changeset
  1766
apply (erule bexE, frule_tac f' = f' in same_inode_files_closefd)
chunhan
parents:
diff changeset
  1767
apply (simp add:current_files_closefd, simp)
chunhan
parents:
diff changeset
  1768
apply (rule_tac x = f'a in bexI)
chunhan
parents:
diff changeset
  1769
apply (frule_tac f = f'a in cf2sfile_closefd)
chunhan
parents:
diff changeset
  1770
apply (simp add:same_inode_files_prop1 current_files_closefd, simp, simp)
chunhan
parents:
diff changeset
  1771
apply (drule CollectD, erule bexE, frule_tac f' = f' in same_inode_files_closefd)
chunhan
parents:
diff changeset
  1772
apply (simp add:current_files_closefd, simp)
chunhan
parents:
diff changeset
  1773
apply (rule_tac x = f'a in bexI)
chunhan
parents:
diff changeset
  1774
apply (frule_tac f = f'a in cf2sfile_closefd)
chunhan
parents:
diff changeset
  1775
apply (simp add:same_inode_files_prop1 current_files_closefd, simp, simp)
chunhan
parents:
diff changeset
  1776
chunhan
parents:
diff changeset
  1777
apply (rule conjI, clarify, frule file_of_pfd_is_file, simp)
chunhan
parents:
diff changeset
  1778
apply (frule is_file_has_sfile', simp, erule exE, simp)
chunhan
parents:
diff changeset
  1779
apply (simp add:cf2sfiles_def, rule set_eqI, rule iffI, drule CollectD)
chunhan
parents:
diff changeset
  1780
apply (erule bexE, frule_tac f' = f' in same_inode_files_closefd)
chunhan
parents:
diff changeset
  1781
apply (simp add:current_files_closefd, simp, erule conjE)
chunhan
parents:
diff changeset
  1782
apply (erule_tac x = f'a in ballE, frule_tac f = "f'a" in cf2sfile_closefd)
chunhan
parents:
diff changeset
  1783
apply (simp add:current_files_closefd same_inode_files_prop1, simp)
chunhan
parents:
diff changeset
  1784
apply (rule_tac x = f'a in bexI, simp, simp)
chunhan
parents:
diff changeset
  1785
apply (drule_tac f = a and f' = f' and f'' = f'a in same_inode_files_prop4, simp+)
chunhan
parents:
diff changeset
  1786
apply (erule conjE|erule exE|erule bexE)+
chunhan
parents:
diff changeset
  1787
apply (case_tac "f'a = a", simp)
chunhan
parents:
diff changeset
  1788
apply (frule_tac f' = f' in same_inode_files_closefd, simp add:current_files_closefd, simp)
chunhan
parents:
diff changeset
  1789
apply (frule_tac f = f'a in cf2sfile_closefd, simp add:current_files_closefd same_inode_files_prop1)
chunhan
parents:
diff changeset
  1790
apply (rule_tac x = f'a in bexI, simp, simp)
chunhan
parents:
diff changeset
  1791
chunhan
parents:
diff changeset
  1792
apply (rule impI)+
chunhan
parents:
diff changeset
  1793
apply (simp add:cf2sfiles_def, rule set_eqI, rule iffI, drule CollectD)
chunhan
parents:
diff changeset
  1794
apply (erule bexE, frule_tac f' = f' in same_inode_files_closefd)
chunhan
parents:
diff changeset
  1795
apply (simp add:current_files_closefd, simp, (erule conjE)+)
chunhan
parents:
diff changeset
  1796
apply (rule_tac x = f'a in bexI, frule_tac f = f'a in cf2sfile_closefd)
chunhan
parents:
diff changeset
  1797
apply (simp add:current_files_closefd same_inode_files_prop1, simp, simp)
chunhan
parents:
diff changeset
  1798
apply (drule CollectD, erule bexE, frule_tac f' = f' in same_inode_files_closefd)
chunhan
parents:
diff changeset
  1799
apply (simp add:current_files_closefd, simp)
chunhan
parents:
diff changeset
  1800
apply (case_tac "f'a = a", simp)
chunhan
parents:
diff changeset
  1801
apply (frule_tac f = f' and f' = a in same_inode_files_prop5, simp)
chunhan
parents:
diff changeset
  1802
apply (erule bexE, erule conjE)
chunhan
parents:
diff changeset
  1803
apply (rule_tac x = f'' in bexI)
chunhan
parents:
diff changeset
  1804
apply (drule_tac f = f'' in cf2sfile_closefd, simp add:current_files_closefd same_inode_files_prop1)
chunhan
parents:
diff changeset
  1805
apply (simp, simp, erule same_inode_files_prop4, simp)
chunhan
parents:
diff changeset
  1806
apply (rule_tac x = f'a in bexI)
chunhan
parents:
diff changeset
  1807
apply (drule_tac f = f'a in cf2sfile_closefd, simp add:current_files_closefd same_inode_files_prop1)
chunhan
parents:
diff changeset
  1808
apply (simp, simp)
chunhan
parents:
diff changeset
  1809
chunhan
parents:
diff changeset
  1810
apply (rule conjI, clarify)
chunhan
parents:
diff changeset
  1811
chunhan
parents:
diff changeset
  1812
apply (rule impI)
chunhan
parents:
diff changeset
  1813
apply (case_tac "a \<in> files_hung_by_del s", simp_all)
chunhan
parents:
diff changeset
  1814
apply (simp add:cf2sfiles_def, rule set_eqI, rule iffI, drule CollectD)
chunhan
parents:
diff changeset
  1815
apply (erule bexE, frule_tac f' = f' in same_inode_files_closefd)
chunhan
parents:
diff changeset
  1816
apply (simp add:current_files_closefd, simp)
chunhan
parents:
diff changeset
  1817
apply (rule_tac x = f'a in bexI)
chunhan
parents:
diff changeset
  1818
apply (frule_tac f = f'a in cf2sfile_closefd)
chunhan
parents:
diff changeset
  1819
apply (simp add:same_inode_files_prop1 current_files_closefd, simp, simp)
chunhan
parents:
diff changeset
  1820
apply (drule CollectD, erule bexE, frule_tac f' = f' in same_inode_files_closefd)
chunhan
parents:
diff changeset
  1821
apply (simp add:current_files_closefd, simp)
chunhan
parents:
diff changeset
  1822
apply (rule_tac x = f'a in bexI)
chunhan
parents:
diff changeset
  1823
apply (frule_tac f = f'a in cf2sfile_closefd)
chunhan
parents:
diff changeset
  1824
apply (simp add:same_inode_files_prop1 current_files_closefd, simp, simp)
chunhan
parents:
diff changeset
  1825
apply (simp add:cf2sfiles_def, rule set_eqI, rule iffI, drule CollectD)
chunhan
parents:
diff changeset
  1826
apply (erule bexE, frule_tac f' = f' in same_inode_files_closefd)
chunhan
parents:
diff changeset
  1827
apply (simp add:current_files_closefd, simp)
chunhan
parents:
diff changeset
  1828
apply (rule_tac x = f'a in bexI)
chunhan
parents:
diff changeset
  1829
apply (frule_tac f = f'a in cf2sfile_closefd)
chunhan
parents:
diff changeset
  1830
apply (simp add:same_inode_files_prop1 current_files_closefd, simp, simp)
chunhan
parents:
diff changeset
  1831
apply (drule CollectD, erule bexE, frule_tac f' = f' in same_inode_files_closefd)
chunhan
parents:
diff changeset
  1832
apply (simp add:current_files_closefd, simp)
chunhan
parents:
diff changeset
  1833
apply (rule_tac x = f'a in bexI)
chunhan
parents:
diff changeset
  1834
apply (frule_tac f = f'a in cf2sfile_closefd)
chunhan
parents:
diff changeset
  1835
apply (simp add:same_inode_files_prop1 current_files_closefd, simp, simp)
chunhan
parents:
diff changeset
  1836
done
chunhan
parents:
diff changeset
  1837
chunhan
parents:
diff changeset
  1838
lemmas cf2sfiles_simps = cf2sfiles_open cf2sfiles_linkhard cf2sfiles_other
chunhan
parents:
diff changeset
  1839
  cf2sfiles_unlink cf2sfiles_closefd
chunhan
parents:
diff changeset
  1840
  
chunhan
parents:
diff changeset
  1841
chunhan
parents:
diff changeset
  1842
(* simpset for co2sobj *)
chunhan
parents:
diff changeset
  1843
chunhan
parents:
diff changeset
  1844
lemma co2sobj_execve:
92
d9dc04c3ea90 modify co2sobj/s2ss from object to dobject
chunhan
parents: 88
diff changeset
  1845
  "\<lbrakk>valid (Execve p f fds # s); dalive (Execve p f fds # s) obj\<rbrakk> \<Longrightarrow> co2sobj (Execve p f fds # s) obj = (
d9dc04c3ea90 modify co2sobj/s2ss from object to dobject
chunhan
parents: 88
diff changeset
  1846
      if (obj = D_proc p)
77
chunhan
parents:
diff changeset
  1847
      then (case (cp2sproc (Execve p f fds # s) p) of
chunhan
parents:
diff changeset
  1848
              Some sp \<Rightarrow> Some (S_proc sp (O_proc p \<in> tainted s \<or> O_file f \<in> tainted s))
chunhan
parents:
diff changeset
  1849
            | _       \<Rightarrow> None) 
chunhan
parents:
diff changeset
  1850
      else co2sobj s obj )"
chunhan
parents:
diff changeset
  1851
apply (frule vt_grant_os, frule vd_cons, case_tac obj)
chunhan
parents:
diff changeset
  1852
apply (simp_all add:current_files_simps cf2sfiles_other (* ch2sshm_other *) cq2smsgq_other)
chunhan
parents:
diff changeset
  1853
apply (case_tac "cp2sproc (Execve p f fds # s) p")
chunhan
parents:
diff changeset
  1854
apply (drule current_proc_has_sp', simp, simp)
chunhan
parents:
diff changeset
  1855
apply (simp (no_asm_simp) add:cp2sproc_execve split:option.splits)
chunhan
parents:
diff changeset
  1856
apply (simp add:is_dir_simps, frule_tac s = s in is_dir_has_sdir', simp, erule exE, simp)
chunhan
parents:
diff changeset
  1857
apply (frule_tac ff = list in cf2sfile_other', simp_all)
chunhan
parents:
diff changeset
  1858
apply (simp add:is_dir_in_current)
chunhan
parents:
diff changeset
  1859
done
chunhan
parents:
diff changeset
  1860
chunhan
parents:
diff changeset
  1861
lemma co2sobj_execve':
92
d9dc04c3ea90 modify co2sobj/s2ss from object to dobject
chunhan
parents: 88
diff changeset
  1862
  "\<lbrakk>valid (Execve p f fds # s); dalive s obj\<rbrakk> \<Longrightarrow> co2sobj (Execve p f fds # s) obj = (
d9dc04c3ea90 modify co2sobj/s2ss from object to dobject
chunhan
parents: 88
diff changeset
  1863
      if (obj = D_proc p)
77
chunhan
parents:
diff changeset
  1864
      then (case (cp2sproc (Execve p f fds # s) p) of
chunhan
parents:
diff changeset
  1865
              Some sp \<Rightarrow> Some (S_proc sp (O_proc p \<in> tainted s \<or> O_file f \<in> tainted s))
chunhan
parents:
diff changeset
  1866
            | _       \<Rightarrow> None) 
chunhan
parents:
diff changeset
  1867
      else co2sobj s obj )"
chunhan
parents:
diff changeset
  1868
apply (frule vt_grant_os, frule vd_cons, case_tac obj)
chunhan
parents:
diff changeset
  1869
apply (simp_all add:current_files_simps cf2sfiles_other (* ch2sshm_other *) cq2smsgq_other)
chunhan
parents:
diff changeset
  1870
apply (case_tac "cp2sproc (Execve p f fds # s) p")
chunhan
parents:
diff changeset
  1871
apply (drule current_proc_has_sp', simp, simp)
chunhan
parents:
diff changeset
  1872
apply (simp (no_asm_simp) add:cp2sproc_execve split:option.splits)
chunhan
parents:
diff changeset
  1873
apply (frule_tac s = s in is_dir_has_sdir', simp, erule exE, simp)
chunhan
parents:
diff changeset
  1874
apply (frule_tac ff = list in cf2sfile_other', simp_all)
chunhan
parents:
diff changeset
  1875
apply (simp add:is_dir_in_current)
chunhan
parents:
diff changeset
  1876
done
chunhan
parents:
diff changeset
  1877
chunhan
parents:
diff changeset
  1878
lemma co2sobj_clone':
92
d9dc04c3ea90 modify co2sobj/s2ss from object to dobject
chunhan
parents: 88
diff changeset
  1879
  "\<lbrakk>valid (Clone p p' fds # s); dalive s obj\<rbrakk> \<Longrightarrow> co2sobj (Clone p p' fds # s) obj = (
d9dc04c3ea90 modify co2sobj/s2ss from object to dobject
chunhan
parents: 88
diff changeset
  1880
      if (obj = D_proc p')
77
chunhan
parents:
diff changeset
  1881
      then (case (cp2sproc (Clone p p' fds # s) p') of
chunhan
parents:
diff changeset
  1882
              Some sp \<Rightarrow> Some (S_proc sp (O_proc p \<in> tainted s))
chunhan
parents:
diff changeset
  1883
            | _       \<Rightarrow> None)
chunhan
parents:
diff changeset
  1884
      else co2sobj s obj )"
chunhan
parents:
diff changeset
  1885
apply (frule vt_grant_os, frule vd_cons, case_tac obj)
chunhan
parents:
diff changeset
  1886
apply (simp_all add:current_files_simps cf2sfiles_other (* ch2sshm_other *) cq2smsgq_other)
chunhan
parents:
diff changeset
  1887
apply (case_tac "cp2sproc (Clone p p' fds # s) p'")
chunhan
parents:
diff changeset
  1888
apply (drule current_proc_has_sp', simp, simp)
chunhan
parents:
diff changeset
  1889
apply ((erule conjE)+, frule_tac p = p in current_proc_has_sec, simp, erule exE, simp)
chunhan
parents:
diff changeset
  1890
apply (simp (no_asm_simp) add:cp2sproc_clone split:option.splits)
chunhan
parents:
diff changeset
  1891
apply (case_tac "nat = p'", simp, simp)
chunhan
parents:
diff changeset
  1892
apply (frule_tac s = s in is_dir_has_sdir', simp, erule exE, simp)
chunhan
parents:
diff changeset
  1893
apply (frule_tac ff = list in cf2sfile_other', simp_all)
chunhan
parents:
diff changeset
  1894
apply (simp add:is_dir_in_current)
chunhan
parents:
diff changeset
  1895
done
chunhan
parents:
diff changeset
  1896
chunhan
parents:
diff changeset
  1897
lemma co2sobj_clone:
92
d9dc04c3ea90 modify co2sobj/s2ss from object to dobject
chunhan
parents: 88
diff changeset
  1898
  "\<lbrakk>valid (Clone p p' fds # s); dalive (Clone p p' fds # s) obj\<rbrakk> 
77
chunhan
parents:
diff changeset
  1899
   \<Longrightarrow> co2sobj (Clone p p' fds # s) obj = (
92
d9dc04c3ea90 modify co2sobj/s2ss from object to dobject
chunhan
parents: 88
diff changeset
  1900
      if (obj = D_proc p')
77
chunhan
parents:
diff changeset
  1901
      then (case (cp2sproc (Clone p p' fds # s) p') of
chunhan
parents:
diff changeset
  1902
              Some sp \<Rightarrow> Some (S_proc sp (O_proc p \<in> tainted s))
chunhan
parents:
diff changeset
  1903
            | _       \<Rightarrow> None)
chunhan
parents:
diff changeset
  1904
      else co2sobj s obj )"
chunhan
parents:
diff changeset
  1905
apply (frule vt_grant_os, frule vd_cons, case_tac obj)
chunhan
parents:
diff changeset
  1906
apply (simp_all add:current_files_simps cf2sfiles_other (* ch2sshm_other *)  cq2smsgq_other)
chunhan
parents:
diff changeset
  1907
apply (rule conjI, rule impI, simp)
chunhan
parents:
diff changeset
  1908
apply (case_tac "cp2sproc (Clone p p' fds # s) p'")
chunhan
parents:
diff changeset
  1909
apply (drule current_proc_has_sp', simp, simp)
chunhan
parents:
diff changeset
  1910
apply ((erule conjE)+, frule_tac p = p in current_proc_has_sec, simp, erule exE, simp)
chunhan
parents:
diff changeset
  1911
apply (rule impI,rule notI, drule tainted_in_current, simp+)
chunhan
parents:
diff changeset
  1912
apply (rule impI, simp)
chunhan
parents:
diff changeset
  1913
apply (drule current_proc_has_sp, simp, (erule exE|erule conjE)+)
chunhan
parents:
diff changeset
  1914
apply (simp (no_asm_simp) add:cp2sproc_clone tainted_in_current split:option.splits)
chunhan
parents:
diff changeset
  1915
chunhan
parents:
diff changeset
  1916
apply (simp add:is_dir_simps, frule_tac s = s in is_dir_has_sdir', simp, erule exE, simp)
chunhan
parents:
diff changeset
  1917
apply (frule_tac ff = list in cf2sfile_other', simp_all)
chunhan
parents:
diff changeset
  1918
apply (simp add:is_dir_in_current)
chunhan
parents:
diff changeset
  1919
done
chunhan
parents:
diff changeset
  1920
chunhan
parents:
diff changeset
  1921
(*
chunhan
parents:
diff changeset
  1922
lemma co2sobj_ptrace:
92
d9dc04c3ea90 modify co2sobj/s2ss from object to dobject
chunhan
parents: 88
diff changeset
  1923
  "\<lbrakk>valid (Ptrace p p' # s); dalive s obj\<rbrakk>\<Longrightarrow> co2sobj (Ptrace p p' # s) obj = (
77
chunhan
parents:
diff changeset
  1924
     case obj of
chunhan
parents:
diff changeset
  1925
       O_proc p'' \<Rightarrow> if (info_flow_shm s p' p'') 
chunhan
parents:
diff changeset
  1926
                     then (case (cp2sproc s p'') of 
chunhan
parents:
diff changeset
  1927
                             Some sp \<Rightarrow> Some (S_proc sp (O_proc p'' \<in> tainted s \<or> O_proc p \<in> tainted s))
chunhan
parents:
diff changeset
  1928
                           | _       \<Rightarrow> None)
chunhan
parents:
diff changeset
  1929
                     else if (info_flow_shm s p p'')
chunhan
parents:
diff changeset
  1930
                          then (case (cp2sproc s p'') of 
chunhan
parents:
diff changeset
  1931
                                  Some sp \<Rightarrow> Some (S_proc sp (O_proc p'' \<in> tainted s \<or> O_proc p' \<in> tainted s))
chunhan
parents:
diff changeset
  1932
                                | _       \<Rightarrow> None)
chunhan
parents:
diff changeset
  1933
                          else co2sobj s (O_proc p'')
chunhan
parents:
diff changeset
  1934
    | _          \<Rightarrow> co2sobj s obj)"
chunhan
parents:
diff changeset
  1935
apply (frule vt_grant_os, frule vd_cons, case_tac obj)
chunhan
parents:
diff changeset
  1936
apply (simp_all add:current_files_simps ch2sshm_other cq2smsgq_other cf2sfiles_other)
chunhan
parents:
diff changeset
  1937
chunhan
parents:
diff changeset
  1938
apply (auto simp:cp2sproc_other split:option.splits
chunhan
parents:
diff changeset
  1939
  dest!:current_proc_has_sec' current_proc_has_sp' intro:info_flow_shm_tainted)[1]
chunhan
parents:
diff changeset
  1940
chunhan
parents:
diff changeset
  1941
apply (frule_tac s = s in is_dir_has_sdir', simp, erule exE, simp)
chunhan
parents:
diff changeset
  1942
apply (frule_tac ff = list in cf2sfile_other', simp_all)
chunhan
parents:
diff changeset
  1943
apply (simp add:is_dir_in_current)
chunhan
parents:
diff changeset
  1944
done
chunhan
parents:
diff changeset
  1945
*)
chunhan
parents:
diff changeset
  1946
chunhan
parents:
diff changeset
  1947
lemma co2sobj_ptrace:
92
d9dc04c3ea90 modify co2sobj/s2ss from object to dobject
chunhan
parents: 88
diff changeset
  1948
  "\<lbrakk>valid (Ptrace p p' # s); dalive s obj\<rbrakk>\<Longrightarrow> co2sobj (Ptrace p p' # s) obj = (
77
chunhan
parents:
diff changeset
  1949
     case obj of
92
d9dc04c3ea90 modify co2sobj/s2ss from object to dobject
chunhan
parents: 88
diff changeset
  1950
       D_proc p'' \<Rightarrow> if (p'' = p') 
77
chunhan
parents:
diff changeset
  1951
                     then (case (cp2sproc s p'') of 
chunhan
parents:
diff changeset
  1952
                             Some sp \<Rightarrow> Some (S_proc sp (O_proc p'' \<in> tainted s \<or> O_proc p \<in> tainted s))
chunhan
parents:
diff changeset
  1953
                           | _       \<Rightarrow> None)
chunhan
parents:
diff changeset
  1954
                     else if (p'' = p)
chunhan
parents:
diff changeset
  1955
                          then (case (cp2sproc s p'') of 
chunhan
parents:
diff changeset
  1956
                                  Some sp \<Rightarrow> Some (S_proc sp (O_proc p'' \<in> tainted s \<or> O_proc p' \<in> tainted s))
chunhan
parents:
diff changeset
  1957
                                | _       \<Rightarrow> None)
92
d9dc04c3ea90 modify co2sobj/s2ss from object to dobject
chunhan
parents: 88
diff changeset
  1958
                          else co2sobj s (D_proc p'')
77
chunhan
parents:
diff changeset
  1959
    | _          \<Rightarrow> co2sobj s obj)"
chunhan
parents:
diff changeset
  1960
apply (frule vt_grant_os, frule vd_cons, case_tac obj)
chunhan
parents:
diff changeset
  1961
apply (simp_all add:current_files_simps cq2smsgq_other cf2sfiles_other)
chunhan
parents:
diff changeset
  1962
chunhan
parents:
diff changeset
  1963
apply (auto simp:cp2sproc_other split:option.splits
chunhan
parents:
diff changeset
  1964
  dest!:current_proc_has_sec' current_proc_has_sp')[1]
chunhan
parents:
diff changeset
  1965
chunhan
parents:
diff changeset
  1966
apply (frule_tac s = s in is_dir_has_sdir', simp, erule exE, simp)
chunhan
parents:
diff changeset
  1967
apply (frule_tac ff = list in cf2sfile_other', simp_all)
chunhan
parents:
diff changeset
  1968
apply (simp add:is_dir_in_current)
chunhan
parents:
diff changeset
  1969
done
chunhan
parents:
diff changeset
  1970
chunhan
parents:
diff changeset
  1971
chunhan
parents:
diff changeset
  1972
lemma co2sobj_open:
92
d9dc04c3ea90 modify co2sobj/s2ss from object to dobject
chunhan
parents: 88
diff changeset
  1973
  "\<lbrakk>valid (Open p f flag fd opt # s); dalive (Open p f flag fd opt # s) obj\<rbrakk> 
77
chunhan
parents:
diff changeset
  1974
   \<Longrightarrow> co2sobj (Open p f flag fd opt # s) obj = (case obj of 
92
d9dc04c3ea90 modify co2sobj/s2ss from object to dobject
chunhan
parents: 88
diff changeset
  1975
     D_file f' \<Rightarrow> if (f' = f \<and> opt \<noteq> None)
77
chunhan
parents:
diff changeset
  1976
                  then (case (cf2sfile (Open p f flag fd opt # s) f) of
chunhan
parents:
diff changeset
  1977
                          Some sf \<Rightarrow> Some (S_file {sf} (O_proc p \<in> tainted s))
chunhan
parents:
diff changeset
  1978
                        | _       \<Rightarrow> None)
92
d9dc04c3ea90 modify co2sobj/s2ss from object to dobject
chunhan
parents: 88
diff changeset
  1979
                  else co2sobj s (D_file f')
d9dc04c3ea90 modify co2sobj/s2ss from object to dobject
chunhan
parents: 88
diff changeset
  1980
   | D_proc p' \<Rightarrow> if (p' = p) 
77
chunhan
parents:
diff changeset
  1981
                  then (case (cp2sproc (Open p f flag fd opt # s) p) of
chunhan
parents:
diff changeset
  1982
                          Some sp \<Rightarrow> Some (S_proc sp (O_proc p \<in> tainted s))
chunhan
parents:
diff changeset
  1983
                        | _       \<Rightarrow> None)
92
d9dc04c3ea90 modify co2sobj/s2ss from object to dobject
chunhan
parents: 88
diff changeset
  1984
                  else co2sobj s (D_proc p')
77
chunhan
parents:
diff changeset
  1985
   | _         \<Rightarrow> co2sobj s obj )"
chunhan
parents:
diff changeset
  1986
apply (frule vt_grant_os, frule vd_cons, case_tac obj)
chunhan
parents:
diff changeset
  1987
apply (auto simp:cp2sproc_simps split:option.splits
chunhan
parents:
diff changeset
  1988
           dest!:current_proc_has_sp' (* intro:info_flow_shm_tainted *))[1]
chunhan
parents:
diff changeset
  1989
chunhan
parents:
diff changeset
  1990
apply (simp split:if_splits t_object.splits) 
chunhan
parents:
diff changeset
  1991
apply ((rule conjI | rule impI| erule conjE| erule exE)+)
chunhan
parents:
diff changeset
  1992
apply ( simp, (erule exE|erule conjE)+)
chunhan
parents:
diff changeset
  1993
apply (case_tac "cf2sfile (Open p f flag fd (Some y) # s) f")
chunhan
parents:
diff changeset
  1994
apply (drule current_file_has_sfile', simp, simp add:current_files_simps, simp)
chunhan
parents:
diff changeset
  1995
apply (frule_tac f' = f in cf2sfiles_open, simp add:current_files_simps, simp)
chunhan
parents:
diff changeset
  1996
apply (frule_tac f' = list in cf2sfiles_open, simp add:is_file_in_current)
chunhan
parents:
diff changeset
  1997
apply (rule impI)
chunhan
parents:
diff changeset
  1998
apply (case_tac "list = f", simp, simp split:option.splits)
chunhan
parents:
diff changeset
  1999
apply (case_tac "cf2sfile (Open p f flag fd opt # s) f")
chunhan
parents:
diff changeset
  2000
apply (drule current_file_has_sfile', simp)
chunhan
parents:
diff changeset
  2001
apply (simp add:current_files_simps is_file_in_current split:option.splits)
chunhan
parents:
diff changeset
  2002
apply (rule impI, simp add:cf2sfiles_open is_file_in_current split:option.splits)
chunhan
parents:
diff changeset
  2003
apply (rule impI, rule conjI)
chunhan
parents:
diff changeset
  2004
apply (drule_tac f' = f in cf2sfiles_open)
chunhan
parents:
diff changeset
  2005
apply (simp add:current_files_simps, simp)
chunhan
parents:
diff changeset
  2006
apply (rule notI, drule tainted_in_current, simp, simp add:is_file_in_current)
chunhan
parents:
diff changeset
  2007
chunhan
parents:
diff changeset
  2008
apply (simp_all add:current_files_simps is_dir_simps cq2smsgq_other) (* ch2sshm_other *)
chunhan
parents:
diff changeset
  2009
chunhan
parents:
diff changeset
  2010
apply (frule is_dir_in_current)
chunhan
parents:
diff changeset
  2011
apply (frule_tac f' = list in cf2sfile_open)
chunhan
parents:
diff changeset
  2012
apply (simp add:current_files_simps split:option.splits)
chunhan
parents:
diff changeset
  2013
apply (simp split:if_splits option.splits)
chunhan
parents:
diff changeset
  2014
done
chunhan
parents:
diff changeset
  2015
chunhan
parents:
diff changeset
  2016
(*
chunhan
parents:
diff changeset
  2017
lemma co2sobj_readfile:
92
d9dc04c3ea90 modify co2sobj/s2ss from object to dobject
chunhan
parents: 88
diff changeset
  2018
  "\<lbrakk>valid (ReadFile p fd # s); dalive s obj\<rbrakk> \<Longrightarrow> co2sobj (ReadFile p fd # s) obj = (
77
chunhan
parents:
diff changeset
  2019
     case obj of
chunhan
parents:
diff changeset
  2020
       O_proc p' \<Rightarrow> (case (file_of_proc_fd s p fd) of
chunhan
parents:
diff changeset
  2021
                       Some f \<Rightarrow> (if (info_flow_shm s p p' \<and> O_file f \<in> tainted s)
chunhan
parents:
diff changeset
  2022
                                  then (case (cp2sproc s p') of
chunhan
parents:
diff changeset
  2023
                                          Some sp \<Rightarrow> Some (S_proc sp True)
chunhan
parents:
diff changeset
  2024
                                        | _       \<Rightarrow> None)
chunhan
parents:
diff changeset
  2025
                                  else co2sobj s obj)
chunhan
parents:
diff changeset
  2026
                    | _       \<Rightarrow> None)
chunhan
parents:
diff changeset
  2027
     | _         \<Rightarrow> co2sobj s obj)"
chunhan
parents:
diff changeset
  2028
apply (frule vt_grant_os, frule vd_cons, case_tac obj)
chunhan
parents:
diff changeset
  2029
apply (auto simp:cp2sproc_simps split:option.splits
chunhan
parents:
diff changeset
  2030
           dest!:current_proc_has_sp' intro:info_flow_shm_tainted)[1]
chunhan
parents:
diff changeset
  2031
apply (simp_all add:current_files_simps is_dir_simps ch2sshm_other cq2smsgq_other)
chunhan
parents:
diff changeset
  2032
chunhan
parents:
diff changeset
  2033
apply (auto split:if_splits option.splits dest!:current_file_has_sfile' 
chunhan
parents:
diff changeset
  2034
             simp:current_files_simps cf2sfiles_simps cf2sfile_simps 
chunhan
parents:
diff changeset
  2035
             dest:is_file_in_current is_dir_in_current)
chunhan
parents:
diff changeset
  2036
done
chunhan
parents:
diff changeset
  2037
*)
chunhan
parents:
diff changeset
  2038
lemma co2sobj_readfile:
92
d9dc04c3ea90 modify co2sobj/s2ss from object to dobject
chunhan
parents: 88
diff changeset
  2039
  "\<lbrakk>valid (ReadFile p fd # s); dalive s obj\<rbrakk> \<Longrightarrow> co2sobj (ReadFile p fd # s) obj = (
77
chunhan
parents:
diff changeset
  2040
     case obj of
92
d9dc04c3ea90 modify co2sobj/s2ss from object to dobject
chunhan
parents: 88
diff changeset
  2041
       D_proc p' \<Rightarrow> (case (file_of_proc_fd s p fd) of
77
chunhan
parents:
diff changeset
  2042
                       Some f \<Rightarrow> (if (p' = p \<and> O_file f \<in> tainted s)
chunhan
parents:
diff changeset
  2043
                                  then (case (cp2sproc s p') of
chunhan
parents:
diff changeset
  2044
                                          Some sp \<Rightarrow> Some (S_proc sp True)
chunhan
parents:
diff changeset
  2045
                                        | _       \<Rightarrow> None)
chunhan
parents:
diff changeset
  2046
                                  else co2sobj s obj)
chunhan
parents:
diff changeset
  2047
                    | _       \<Rightarrow> None)
chunhan
parents:
diff changeset
  2048
     | _         \<Rightarrow> co2sobj s obj)"
chunhan
parents:
diff changeset
  2049
apply (frule vt_grant_os, frule vd_cons, case_tac obj)
chunhan
parents:
diff changeset
  2050
apply (auto simp:cp2sproc_simps split:option.splits dest!:current_proc_has_sp')[1]
chunhan
parents:
diff changeset
  2051
apply (simp_all add:current_files_simps is_dir_simps cq2smsgq_other)
chunhan
parents:
diff changeset
  2052
chunhan
parents:
diff changeset
  2053
apply (auto split:if_splits option.splits dest!:current_file_has_sfile' 
chunhan
parents:
diff changeset
  2054
             simp:current_files_simps cf2sfile_simps cf2sfiles_simps
chunhan
parents:
diff changeset
  2055
             dest:is_file_in_current is_dir_in_current)
chunhan
parents:
diff changeset
  2056
done
chunhan
parents:
diff changeset
  2057
chunhan
parents:
diff changeset
  2058
lemma co2sobj_writefile:
92
d9dc04c3ea90 modify co2sobj/s2ss from object to dobject
chunhan
parents: 88
diff changeset
  2059
  "\<lbrakk>valid (WriteFile p fd # s); dalive s obj\<rbrakk> \<Longrightarrow> co2sobj (WriteFile p fd # s) obj = (
77
chunhan
parents:
diff changeset
  2060
     case obj of
92
d9dc04c3ea90 modify co2sobj/s2ss from object to dobject
chunhan
parents: 88
diff changeset
  2061
       D_file f' \<Rightarrow> (case (file_of_proc_fd s p fd) of
77
chunhan
parents:
diff changeset
  2062
                       Some f \<Rightarrow> (if (f \<in> same_inode_files s f') 
chunhan
parents:
diff changeset
  2063
                                  then Some (S_file (cf2sfiles s f') 
chunhan
parents:
diff changeset
  2064
                                                    (O_file f' \<in> tainted s \<or> O_proc p \<in> tainted s))
chunhan
parents:
diff changeset
  2065
                                  else co2sobj s obj)
chunhan
parents:
diff changeset
  2066
                    | _       \<Rightarrow> None)
chunhan
parents:
diff changeset
  2067
     | _         \<Rightarrow> co2sobj s obj)"
chunhan
parents:
diff changeset
  2068
apply (frule vt_grant_os, frule vd_cons, case_tac obj)
chunhan
parents:
diff changeset
  2069
apply (simp_all add:current_files_simps is_dir_simps cq2smsgq_other) (* ch2sshm_other*)
chunhan
parents:
diff changeset
  2070
chunhan
parents:
diff changeset
  2071
apply (auto split:if_splits option.splits dest!:current_file_has_sfile' current_proc_has_sp'
chunhan
parents:
diff changeset
  2072
             simp:current_files_simps cf2sfiles_simps cf2sfile_simps cp2sproc_simps
chunhan
parents:
diff changeset
  2073
                  same_inode_files_prop6
chunhan
parents:
diff changeset
  2074
             dest:is_file_in_current is_dir_in_current)
chunhan
parents:
diff changeset
  2075
chunhan
parents:
diff changeset
  2076
(* should delete has_same_inode !?!?*)
chunhan
parents:
diff changeset
  2077
by (auto simp:same_inode_files_def is_file_def has_same_inode_def split:if_splits option.splits)
chunhan
parents:
diff changeset
  2078
chunhan
parents:
diff changeset
  2079
lemma co2sobj_closefd:
92
d9dc04c3ea90 modify co2sobj/s2ss from object to dobject
chunhan
parents: 88
diff changeset
  2080
  "\<lbrakk>valid (CloseFd p fd # s); dalive (CloseFd p fd # s) obj\<rbrakk> \<Longrightarrow> co2sobj (CloseFd p fd # s) obj = (
77
chunhan
parents:
diff changeset
  2081
      case obj of 
92
d9dc04c3ea90 modify co2sobj/s2ss from object to dobject
chunhan
parents: 88
diff changeset
  2082
        D_file f' \<Rightarrow> (case (file_of_proc_fd s p fd) of 
77
chunhan
parents:
diff changeset
  2083
                        Some f \<Rightarrow> (if (f' \<in> same_inode_files s f \<and> proc_fd_of_file s f = {(p, fd)} \<and>
chunhan
parents:
diff changeset
  2084
                                       f \<in> files_hung_by_del s \<and> (\<forall> f'' \<in> same_inode_files s f. 
chunhan
parents:
diff changeset
  2085
                                       f'' \<noteq> f \<longrightarrow> cf2sfile s f'' \<noteq> cf2sfile s f))
92
d9dc04c3ea90 modify co2sobj/s2ss from object to dobject
chunhan
parents: 88
diff changeset
  2086
                                   then (case (cf2sfile s f, co2sobj s (D_file f')) of
77
chunhan
parents:
diff changeset
  2087
                                           (Some sf, Some (S_file sfs b)) \<Rightarrow> Some (S_file (sfs - {sf}) b)
chunhan
parents:
diff changeset
  2088
                                         | _                              \<Rightarrow> None)
chunhan
parents:
diff changeset
  2089
                                   else co2sobj s obj)
chunhan
parents:
diff changeset
  2090
                     | _       \<Rightarrow> co2sobj s obj)
92
d9dc04c3ea90 modify co2sobj/s2ss from object to dobject
chunhan
parents: 88
diff changeset
  2091
      | D_proc p' \<Rightarrow> (if (p = p') 
77
chunhan
parents:
diff changeset
  2092
                      then (case (cp2sproc (CloseFd p fd # s) p) of
chunhan
parents:
diff changeset
  2093
                              Some sp \<Rightarrow> Some (S_proc sp (O_proc p \<in> tainted s))
chunhan
parents:
diff changeset
  2094
                            | _       \<Rightarrow> None)
chunhan
parents:
diff changeset
  2095
                      else co2sobj s obj)
chunhan
parents:
diff changeset
  2096
      | _         \<Rightarrow> co2sobj s obj) "
chunhan
parents:
diff changeset
  2097
apply (frule vt_grant_os, frule vd_cons, case_tac obj)
chunhan
parents:
diff changeset
  2098
apply (simp_all add:current_files_simps cq2smsgq_other) (* ch2sshm_other *)
chunhan
parents:
diff changeset
  2099
apply (auto simp:cp2sproc_simps cf2sfiles_simps split:option.splits if_splits
chunhan
parents:
diff changeset
  2100
           dest!:current_proc_has_sp') [1](* intro:info_flow_shm_tainted)[1] *)
chunhan
parents:
diff changeset
  2101
chunhan
parents:
diff changeset
  2102
apply (frule is_file_in_current)
chunhan
parents:
diff changeset
  2103
apply (case_tac "file_of_proc_fd s p fd")
chunhan
parents:
diff changeset
  2104
apply (simp)
chunhan
parents:
diff changeset
  2105
apply (drule_tac f' = list in cf2sfiles_closefd, simp add:current_files_closefd, simp)
chunhan
parents:
diff changeset
  2106
apply (frule_tac f' = list in cf2sfiles_closefd, simp)
chunhan
parents:
diff changeset
  2107
apply (simp add:is_file_simps current_files_simps)
chunhan
parents:
diff changeset
  2108
apply (auto simp add: cf2sfile_closefd split:if_splits option.splits
chunhan
parents:
diff changeset
  2109
  dest!:current_file_has_sfile' dest:hung_file_in_current)[1]
chunhan
parents:
diff changeset
  2110
chunhan
parents:
diff changeset
  2111
apply (simp add:is_dir_simps, frule is_dir_in_current)
chunhan
parents:
diff changeset
  2112
apply (frule_tac f = list in cf2sfile_closefd)
chunhan
parents:
diff changeset
  2113
apply (clarsimp simp:current_files_closefd split:option.splits)
chunhan
parents:
diff changeset
  2114
apply (drule file_of_pfd_is_file', simp+)
chunhan
parents:
diff changeset
  2115
done
chunhan
parents:
diff changeset
  2116
chunhan
parents:
diff changeset
  2117
lemma co2sobj_unlink:
92
d9dc04c3ea90 modify co2sobj/s2ss from object to dobject
chunhan
parents: 88
diff changeset
  2118
  "\<lbrakk>valid (UnLink p f # s); dalive (UnLink p f # s) obj\<rbrakk> \<Longrightarrow> co2sobj (UnLink p f # s) obj = (
77
chunhan
parents:
diff changeset
  2119
      case obj of
92
d9dc04c3ea90 modify co2sobj/s2ss from object to dobject
chunhan
parents: 88
diff changeset
  2120
        D_file f' \<Rightarrow> if (f' \<in> same_inode_files s f \<and> proc_fd_of_file s f = {} \<and> 
77
chunhan
parents:
diff changeset
  2121
                        (\<forall> f'' \<in> same_inode_files s f. f'' \<noteq> f \<longrightarrow> cf2sfile s f'' \<noteq> cf2sfile s f))
92
d9dc04c3ea90 modify co2sobj/s2ss from object to dobject
chunhan
parents: 88
diff changeset
  2122
                     then (case (cf2sfile s f, co2sobj s (D_file f')) of
77
chunhan
parents:
diff changeset
  2123
                             (Some sf, Some (S_file sfs b)) \<Rightarrow> Some (S_file (sfs - {sf}) b)
chunhan
parents:
diff changeset
  2124
                           | _                              \<Rightarrow> None)
chunhan
parents:
diff changeset
  2125
                     else co2sobj s obj
chunhan
parents:
diff changeset
  2126
      | _         \<Rightarrow> co2sobj s obj)"
chunhan
parents:
diff changeset
  2127
apply (frule vt_grant_os, frule vd_cons, case_tac obj)
chunhan
parents:
diff changeset
  2128
apply (simp_all add:current_files_simps cq2smsgq_other) (* ch2sshm_other*)
chunhan
parents:
diff changeset
  2129
apply (auto simp:cp2sproc_simps split:option.splits if_splits
chunhan
parents:
diff changeset
  2130
           dest!:current_proc_has_sp')[1] (* intro:info_flow_shm_tainted) *)
chunhan
parents:
diff changeset
  2131
apply (frule is_file_in_current)
chunhan
parents:
diff changeset
  2132
apply (frule_tac f' = list in cf2sfile_unlink, simp)
chunhan
parents:
diff changeset
  2133
apply (frule_tac f' = list in cf2sfiles_unlink, simp)
chunhan
parents:
diff changeset
  2134
apply (simp add:is_file_simps current_files_simps)
chunhan
parents:
diff changeset
  2135
apply (auto simp add: is_file_in_current split:if_splits option.splits
chunhan
parents:
diff changeset
  2136
  dest!:current_file_has_sfile')[1]
chunhan
parents:
diff changeset
  2137
chunhan
parents:
diff changeset
  2138
apply (simp add:is_dir_simps, frule is_dir_in_current)
chunhan
parents:
diff changeset
  2139
apply (frule_tac f' = list in cf2sfile_unlink)
chunhan
parents:
diff changeset
  2140
apply (clarsimp simp:current_files_unlink split:option.splits)
chunhan
parents:
diff changeset
  2141
apply (drule file_dir_conflict, simp+)
chunhan
parents:
diff changeset
  2142
done
chunhan
parents:
diff changeset
  2143
chunhan
parents:
diff changeset
  2144
lemma co2sobj_rmdir:
92
d9dc04c3ea90 modify co2sobj/s2ss from object to dobject
chunhan
parents: 88
diff changeset
  2145
  "\<lbrakk>valid (Rmdir p f # s); dalive (Rmdir p f # s) obj\<rbrakk> \<Longrightarrow> co2sobj (Rmdir p f # s) obj = co2sobj s obj"
77
chunhan
parents:
diff changeset
  2146
apply (frule vt_grant_os, frule vd_cons, case_tac obj)
chunhan
parents:
diff changeset
  2147
apply (simp_all add:current_files_simps cq2smsgq_other) (* ch2sshm_other*)
chunhan
parents:
diff changeset
  2148
apply (auto simp:cp2sproc_simps split:option.splits if_splits
chunhan
parents:
diff changeset
  2149
           dest!:current_proc_has_sp')[1] (* intro:info_flow_shm_tainted*)
chunhan
parents:
diff changeset
  2150
apply (simp add:is_file_simps dir_is_empty_def)
chunhan
parents:
diff changeset
  2151
apply (case_tac "f = list", drule file_dir_conflict, simp, simp)
chunhan
parents:
diff changeset
  2152
apply (simp add:cf2sfiles_other)
chunhan
parents:
diff changeset
  2153
apply (auto simp:cf2sfile_simps dest:is_dir_in_current)
chunhan
parents:
diff changeset
  2154
done
chunhan
parents:
diff changeset
  2155
chunhan
parents:
diff changeset
  2156
lemma co2sobj_mkdir:
92
d9dc04c3ea90 modify co2sobj/s2ss from object to dobject
chunhan
parents: 88
diff changeset
  2157
  "\<lbrakk>valid (Mkdir p f i # s); dalive (Mkdir p f i # s) obj\<rbrakk> \<Longrightarrow> co2sobj (Mkdir p f i # s) obj = (
d9dc04c3ea90 modify co2sobj/s2ss from object to dobject
chunhan
parents: 88
diff changeset
  2158
      if (obj = D_dir f) 
77
chunhan
parents:
diff changeset
  2159
      then (case (cf2sfile (Mkdir p f i # s) f) of 
chunhan
parents:
diff changeset
  2160
              Some sf \<Rightarrow> Some (S_dir sf)
chunhan
parents:
diff changeset
  2161
            | _       \<Rightarrow> None)
chunhan
parents:
diff changeset
  2162
      else co2sobj s obj)"
chunhan
parents:
diff changeset
  2163
apply (frule vt_grant_os, frule vd_cons, case_tac obj)
chunhan
parents:
diff changeset
  2164
apply (simp_all add:current_files_simps cq2smsgq_other) (* ch2sshm_other *)
chunhan
parents:
diff changeset
  2165
apply (auto simp:cp2sproc_simps split:option.splits if_splits
chunhan
parents:
diff changeset
  2166
           dest!:current_proc_has_sp')[1] (* intro:info_flow_shm_tainted *)
chunhan
parents:
diff changeset
  2167
apply (frule_tac cf2sfiles_other, simp+)
chunhan
parents:
diff changeset
  2168
apply (frule is_dir_in_current, rule impI, simp add:current_files_mkdir)
chunhan
parents:
diff changeset
  2169
apply (frule current_file_has_sfile, simp, erule exE, simp)
chunhan
parents:
diff changeset
  2170
apply (drule cf2sfile_mkdir1, simp+)
chunhan
parents:
diff changeset
  2171
done
chunhan
parents:
diff changeset
  2172
chunhan
parents:
diff changeset
  2173
lemma co2sobj_linkhard:
92
d9dc04c3ea90 modify co2sobj/s2ss from object to dobject
chunhan
parents: 88
diff changeset
  2174
  "\<lbrakk>valid (LinkHard p oldf f # s); dalive (LinkHard p oldf f # s) obj\<rbrakk> 
77
chunhan
parents:
diff changeset
  2175
   \<Longrightarrow> co2sobj (LinkHard p oldf f # s) obj = (
chunhan
parents:
diff changeset
  2176
    case obj of
92
d9dc04c3ea90 modify co2sobj/s2ss from object to dobject
chunhan
parents: 88
diff changeset
  2177
      D_file f' \<Rightarrow> if (f' = f \<or> f' \<in> same_inode_files s oldf)
77
chunhan
parents:
diff changeset
  2178
                   then (case (cf2sfile (LinkHard p oldf f # s) f) of
chunhan
parents:
diff changeset
  2179
                           Some sf \<Rightarrow> Some (S_file (cf2sfiles s oldf \<union> {sf}) (O_file oldf \<in> tainted s))
chunhan
parents:
diff changeset
  2180
                         | _       \<Rightarrow> None)
chunhan
parents:
diff changeset
  2181
                   else co2sobj s obj
chunhan
parents:
diff changeset
  2182
    | _         \<Rightarrow> co2sobj s obj)"
chunhan
parents:
diff changeset
  2183
apply (frule vt_grant_os, frule vd_cons, case_tac obj)
chunhan
parents:
diff changeset
  2184
apply (simp_all add:current_files_simps cq2smsgq_other) (* ch2sshm_other *)
chunhan
parents:
diff changeset
  2185
apply (auto simp:cp2sproc_simps split:option.splits if_splits
chunhan
parents:
diff changeset
  2186
           dest!:current_proc_has_sp')[1] (* intro:info_flow_shm_tainted *)
chunhan
parents:
diff changeset
  2187
apply (frule_tac cf2sfiles_linkhard, simp+)
chunhan
parents:
diff changeset
  2188
apply (frule_tac f' = f in cf2sfile_linkhard, simp add:current_files_linkhard)
chunhan
parents:
diff changeset
  2189
apply (auto simp:is_file_simps sectxt_of_obj_simps current_files_simps is_file_in_current same_inodes_tainted
chunhan
parents:
diff changeset
  2190
  split:option.splits if_splits dest:tainted_in_current 
chunhan
parents:
diff changeset
  2191
  dest!:current_has_sec' current_file_has_sfile')[1]
chunhan
parents:
diff changeset
  2192
chunhan
parents:
diff changeset
  2193
apply (frule is_dir_in_current, simp add:current_files_linkhard is_dir_simps is_dir_in_current)
chunhan
parents:
diff changeset
  2194
apply (frule is_dir_in_current)
chunhan
parents:
diff changeset
  2195
apply (frule current_file_has_sfile, simp)
chunhan
parents:
diff changeset
  2196
apply (drule cf2sfile_linkhard1, simp+)
chunhan
parents:
diff changeset
  2197
done
chunhan
parents:
diff changeset
  2198
chunhan
parents:
diff changeset
  2199
lemma co2sobj_truncate:
92
d9dc04c3ea90 modify co2sobj/s2ss from object to dobject
chunhan
parents: 88
diff changeset
  2200
  "\<lbrakk>valid (Truncate p f len # s); dalive s obj\<rbrakk> \<Longrightarrow> co2sobj (Truncate p f len # s) obj = (
77
chunhan
parents:
diff changeset
  2201
      case obj of
92
d9dc04c3ea90 modify co2sobj/s2ss from object to dobject
chunhan
parents: 88
diff changeset
  2202
        D_file f' \<Rightarrow> if (f' \<in> same_inode_files s f \<and> len > 0)
77
chunhan
parents:
diff changeset
  2203
                     then Some (S_file (cf2sfiles s f') (O_file f' \<in> tainted s \<or> O_proc p \<in> tainted s))
chunhan
parents:
diff changeset
  2204
                     else co2sobj s obj
chunhan
parents:
diff changeset
  2205
      | _         \<Rightarrow> co2sobj s obj)"
chunhan
parents:
diff changeset
  2206
apply (frule vt_grant_os, frule vd_cons, case_tac obj)
chunhan
parents:
diff changeset
  2207
apply (simp_all add:current_files_simps is_dir_simps cq2smsgq_other) (* ch2sshm_other *)
chunhan
parents:
diff changeset
  2208
chunhan
parents:
diff changeset
  2209
apply (auto split:if_splits option.splits dest!:current_file_has_sfile' current_proc_has_sp'
chunhan
parents:
diff changeset
  2210
             simp:current_files_simps cf2sfiles_simps cf2sfile_simps cp2sproc_simps
chunhan
parents:
diff changeset
  2211
                  same_inode_files_prop6
chunhan
parents:
diff changeset
  2212
             dest:is_file_in_current is_dir_in_current)
chunhan
parents:
diff changeset
  2213
done
chunhan
parents:
diff changeset
  2214
chunhan
parents:
diff changeset
  2215
lemma co2sobj_kill:
92
d9dc04c3ea90 modify co2sobj/s2ss from object to dobject
chunhan
parents: 88
diff changeset
  2216
  "\<lbrakk>valid (Kill p p' # s); dalive (Kill p p' # s) obj\<rbrakk> \<Longrightarrow> co2sobj (Kill p p' # s) obj = co2sobj s obj"
77
chunhan
parents:
diff changeset
  2217
apply (frule vt_grant_os, frule vd_cons, case_tac obj)
chunhan
parents:
diff changeset
  2218
apply (simp_all add:current_files_simps is_dir_simps cq2smsgq_other) (* ch2sshm_other *)
chunhan
parents:
diff changeset
  2219
apply (auto split:if_splits option.splits dest!:current_file_has_sfile' current_proc_has_sp'
chunhan
parents:
diff changeset
  2220
             simp:current_files_simps cf2sfiles_simps cf2sfile_simps cp2sproc_simps 
chunhan
parents:
diff changeset
  2221
                  same_inode_files_prop6
chunhan
parents:
diff changeset
  2222
             dest:is_file_in_current is_dir_in_current)
chunhan
parents:
diff changeset
  2223
done
chunhan
parents:
diff changeset
  2224
chunhan
parents:
diff changeset
  2225
lemma co2sobj_exit:
92
d9dc04c3ea90 modify co2sobj/s2ss from object to dobject
chunhan
parents: 88
diff changeset
  2226
  "\<lbrakk>valid (Exit p # s); dalive (Exit p # s) obj\<rbrakk> \<Longrightarrow> co2sobj (Exit p # s) obj = co2sobj s obj"
77
chunhan
parents:
diff changeset
  2227
apply (frule vt_grant_os, frule vd_cons, case_tac obj)
chunhan
parents:
diff changeset
  2228
apply (simp_all add:current_files_simps is_dir_simps cq2smsgq_other)
chunhan
parents:
diff changeset
  2229
apply (auto split:if_splits option.splits dest!:current_file_has_sfile' current_proc_has_sp'
chunhan
parents:
diff changeset
  2230
             simp:current_files_simps cf2sfiles_simps cf2sfile_simps cp2sproc_simps
chunhan
parents:
diff changeset
  2231
                  same_inode_files_prop6
chunhan
parents:
diff changeset
  2232
             dest:is_file_in_current is_dir_in_current)
chunhan
parents:
diff changeset
  2233
done
chunhan
parents:
diff changeset
  2234
chunhan
parents:
diff changeset
  2235
lemma co2sobj_createmsgq:
92
d9dc04c3ea90 modify co2sobj/s2ss from object to dobject
chunhan
parents: 88
diff changeset
  2236
  "\<lbrakk>valid (CreateMsgq p q # s); dalive (CreateMsgq p q # s) obj\<rbrakk> \<Longrightarrow> co2sobj (CreateMsgq p q # s) obj = (
77
chunhan
parents:
diff changeset
  2237
      case obj of
92
d9dc04c3ea90 modify co2sobj/s2ss from object to dobject
chunhan
parents: 88
diff changeset
  2238
        D_msgq q' \<Rightarrow> if (q' = q) then (case (cq2smsgq (CreateMsgq p q # s) q) of
77
chunhan
parents:
diff changeset
  2239
                                         Some sq \<Rightarrow> Some (S_msgq sq)
chunhan
parents:
diff changeset
  2240
                                       | _       \<Rightarrow> None)
chunhan
parents:
diff changeset
  2241
                     else co2sobj s obj
chunhan
parents:
diff changeset
  2242
      | _        \<Rightarrow> co2sobj s obj)"
chunhan
parents:
diff changeset
  2243
apply (frule vt_grant_os, frule vd_cons, case_tac obj)
chunhan
parents:
diff changeset
  2244
apply (simp_all add:current_files_simps is_dir_simps cq2smsgq_other)
chunhan
parents:
diff changeset
  2245
apply (auto split:if_splits option.splits dest!:current_file_has_sfile' current_proc_has_sp'
chunhan
parents:
diff changeset
  2246
             simp:current_files_simps cf2sfiles_simps cf2sfile_simps cp2sproc_simps
chunhan
parents:
diff changeset
  2247
                  same_inode_files_prop6
chunhan
parents:
diff changeset
  2248
             dest!:current_has_smsgq'
chunhan
parents:
diff changeset
  2249
             dest:is_file_in_current is_dir_in_current cq2smsg_createmsgq)
chunhan
parents:
diff changeset
  2250
done
chunhan
parents:
diff changeset
  2251
chunhan
parents:
diff changeset
  2252
lemma co2sobj_sendmsg:
92
d9dc04c3ea90 modify co2sobj/s2ss from object to dobject
chunhan
parents: 88
diff changeset
  2253
  "\<lbrakk>valid (SendMsg p q m # s); dalive (SendMsg p q m # s) obj\<rbrakk> \<Longrightarrow> co2sobj (SendMsg p q m # s) obj = (
77
chunhan
parents:
diff changeset
  2254
      case obj of
92
d9dc04c3ea90 modify co2sobj/s2ss from object to dobject
chunhan
parents: 88
diff changeset
  2255
        D_msgq q' \<Rightarrow> if (q' = q) then (case (cq2smsgq (SendMsg p q m # s) q) of
77
chunhan
parents:
diff changeset
  2256
                                         Some sq \<Rightarrow> Some (S_msgq sq)
chunhan
parents:
diff changeset
  2257
                                       | _       \<Rightarrow> None)
chunhan
parents:
diff changeset
  2258
                     else co2sobj s obj
chunhan
parents:
diff changeset
  2259
      | _        \<Rightarrow> co2sobj s obj)"
chunhan
parents:
diff changeset
  2260
apply (frule vt_grant_os, frule vd_cons, case_tac obj)
chunhan
parents:
diff changeset
  2261
apply (simp_all add:current_files_simps is_dir_simps cq2smsgq_other)
chunhan
parents:
diff changeset
  2262
apply (auto split:if_splits option.splits dest!:current_file_has_sfile' current_proc_has_sp'
chunhan
parents:
diff changeset
  2263
             simp:current_files_simps cf2sfiles_simps cf2sfile_simps cp2sproc_simps
chunhan
parents:
diff changeset
  2264
                  same_inode_files_prop6
chunhan
parents:
diff changeset
  2265
             dest!:current_has_smsgq'
chunhan
parents:
diff changeset
  2266
             dest:is_file_in_current is_dir_in_current cq2smsg_sendmsg)
chunhan
parents:
diff changeset
  2267
done
chunhan
parents:
diff changeset
  2268
chunhan
parents:
diff changeset
  2269
lemma co2sobj_recvmsg:
92
d9dc04c3ea90 modify co2sobj/s2ss from object to dobject
chunhan
parents: 88
diff changeset
  2270
  "\<lbrakk>valid (RecvMsg p q m # s); dalive (RecvMsg p q m # s) obj\<rbrakk> \<Longrightarrow> co2sobj (RecvMsg p q m # s) obj = (
77
chunhan
parents:
diff changeset
  2271
      case obj of
92
d9dc04c3ea90 modify co2sobj/s2ss from object to dobject
chunhan
parents: 88
diff changeset
  2272
        D_msgq q' \<Rightarrow> if (q' = q) then (case (cq2smsgq (RecvMsg p q m # s) q) of
77
chunhan
parents:
diff changeset
  2273
                                         Some sq \<Rightarrow> Some (S_msgq sq)
chunhan
parents:
diff changeset
  2274
                                       | _       \<Rightarrow> None)
chunhan
parents:
diff changeset
  2275
                     else co2sobj s obj
92
d9dc04c3ea90 modify co2sobj/s2ss from object to dobject
chunhan
parents: 88
diff changeset
  2276
      | D_proc p' \<Rightarrow> if (p' = p \<and> O_msg q m \<in> tainted s)
77
chunhan
parents:
diff changeset
  2277
                     then (case (cp2sproc s p') of
chunhan
parents:
diff changeset
  2278
                             Some sp \<Rightarrow> Some (S_proc sp True)
chunhan
parents:
diff changeset
  2279
                           | _       \<Rightarrow> None)
chunhan
parents:
diff changeset
  2280
                     else co2sobj s obj
chunhan
parents:
diff changeset
  2281
      | _         \<Rightarrow> co2sobj s obj)"
chunhan
parents:
diff changeset
  2282
apply (frule vt_grant_os, frule vd_cons, case_tac obj)
chunhan
parents:
diff changeset
  2283
apply (simp_all add:current_files_simps is_dir_simps cq2smsgq_other)
chunhan
parents:
diff changeset
  2284
apply (auto split:if_splits option.splits dest!:current_file_has_sfile' current_proc_has_sp'
chunhan
parents:
diff changeset
  2285
             simp:current_files_simps cf2sfiles_simps cf2sfile_simps cp2sproc_simps
chunhan
parents:
diff changeset
  2286
                  same_inode_files_prop6
chunhan
parents:
diff changeset
  2287
             dest!:current_has_smsgq'
chunhan
parents:
diff changeset
  2288
             dest:is_file_in_current is_dir_in_current cq2smsg_recvmsg)
chunhan
parents:
diff changeset
  2289
done
chunhan
parents:
diff changeset
  2290
(*
chunhan
parents:
diff changeset
  2291
lemma co2sobj_recvmsg:
92
d9dc04c3ea90 modify co2sobj/s2ss from object to dobject
chunhan
parents: 88
diff changeset
  2292
  "\<lbrakk>valid (RecvMsg p q m # s); dalive (RecvMsg p q m # s) obj\<rbrakk> \<Longrightarrow> co2sobj (RecvMsg p q m # s) obj = (
77
chunhan
parents:
diff changeset
  2293
      case obj of
chunhan
parents:
diff changeset
  2294
        O_msgq q' \<Rightarrow> if (q' = q) then (case (cq2smsgq (RecvMsg p q m # s) q) of
chunhan
parents:
diff changeset
  2295
                                         Some sq \<Rightarrow> Some (S_msgq sq)
chunhan
parents:
diff changeset
  2296
                                       | _       \<Rightarrow> None)
chunhan
parents:
diff changeset
  2297
                     else co2sobj s obj
chunhan
parents:
diff changeset
  2298
      | O_proc p' \<Rightarrow> if (info_flow_shm s p p' \<and> O_msg q m \<in> tainted s)
chunhan
parents:
diff changeset
  2299
                     then (case (cp2sproc s p') of
chunhan
parents:
diff changeset
  2300
                             Some sp \<Rightarrow> Some (S_proc sp True)
chunhan
parents:
diff changeset
  2301
                           | _       \<Rightarrow> None)
chunhan
parents:
diff changeset
  2302
                     else co2sobj s obj
chunhan
parents:
diff changeset
  2303
      | _         \<Rightarrow> co2sobj s obj)"
chunhan
parents:
diff changeset
  2304
apply (frule vt_grant_os, frule vd_cons, case_tac obj)
chunhan
parents:
diff changeset
  2305
apply (simp_all add:current_files_simps is_dir_simps cq2smsgq_other)
chunhan
parents:
diff changeset
  2306
apply (auto split:if_splits option.splits dest!:current_file_has_sfile' current_proc_has_sp'
chunhan
parents:
diff changeset
  2307
             simp:current_files_simps cf2sfiles_simps cf2sfile_simps cp2sproc_simps
chunhan
parents:
diff changeset
  2308
                  same_inode_files_prop6
chunhan
parents:
diff changeset
  2309
             dest!:current_has_smsgq'
chunhan
parents:
diff changeset
  2310
             dest:is_file_in_current is_dir_in_current cq2smsg_recvmsg)
chunhan
parents:
diff changeset
  2311
done
chunhan
parents:
diff changeset
  2312
*)
chunhan
parents:
diff changeset
  2313
chunhan
parents:
diff changeset
  2314
lemma co2sobj_removemsgq:
92
d9dc04c3ea90 modify co2sobj/s2ss from object to dobject
chunhan
parents: 88
diff changeset
  2315
  "\<lbrakk>valid (RemoveMsgq p q # s); dalive (RemoveMsgq p q # s) obj\<rbrakk> 
77
chunhan
parents:
diff changeset
  2316
   \<Longrightarrow> co2sobj (RemoveMsgq p q # s) obj = co2sobj s obj"
chunhan
parents:
diff changeset
  2317
apply (frule vt_grant_os, frule vd_cons, case_tac obj)
chunhan
parents:
diff changeset
  2318
apply (simp_all add:current_files_simps is_dir_simps cq2smsgq_other)
chunhan
parents:
diff changeset
  2319
apply (auto split:if_splits option.splits dest!:current_file_has_sfile' current_proc_has_sp'
chunhan
parents:
diff changeset
  2320
             simp:current_files_simps cf2sfiles_simps cf2sfile_simps cp2sproc_simps
chunhan
parents:
diff changeset
  2321
                  same_inode_files_prop6
chunhan
parents:
diff changeset
  2322
             dest!:current_has_smsgq'
chunhan
parents:
diff changeset
  2323
             dest:is_file_in_current is_dir_in_current cq2smsg_removemsgq)
chunhan
parents:
diff changeset
  2324
done
chunhan
parents:
diff changeset
  2325
chunhan
parents:
diff changeset
  2326
(*
chunhan
parents:
diff changeset
  2327
lemma co2sobj_createshm:
92
d9dc04c3ea90 modify co2sobj/s2ss from object to dobject
chunhan
parents: 88
diff changeset
  2328
  "\<lbrakk>valid (CreateShM p h # s); dalive (CreateShM p h # s) obj\<rbrakk> \<Longrightarrow> co2sobj (CreateShM p h # s) obj = (
77
chunhan
parents:
diff changeset
  2329
      case obj of 
chunhan
parents:
diff changeset
  2330
        O_shm h' \<Rightarrow> if (h' = h) then (case (ch2sshm (CreateShM p h # s) h) of
chunhan
parents:
diff changeset
  2331
                                        Some sh \<Rightarrow> Some (S_shm sh)
chunhan
parents:
diff changeset
  2332
                                      | _       \<Rightarrow> None)
chunhan
parents:
diff changeset
  2333
                    else co2sobj s obj
chunhan
parents:
diff changeset
  2334
      | _        \<Rightarrow> co2sobj s obj)"
chunhan
parents:
diff changeset
  2335
apply (frule vt_grant_os, frule vd_cons, case_tac obj)
chunhan
parents:
diff changeset
  2336
apply (simp_all add:current_files_simps is_dir_simps ch2sshm_other cq2smsgq_other)
chunhan
parents:
diff changeset
  2337
apply (auto split:if_splits option.splits dest!:current_file_has_sfile' current_proc_has_sp'
chunhan
parents:
diff changeset
  2338
             simp:current_files_simps cf2sfiles_simps cf2sfile_simps cp2sproc_simps tainted_eq_tainted
chunhan
parents:
diff changeset
  2339
                  same_inode_files_prop6 ch2sshm_simps
chunhan
parents:
diff changeset
  2340
             dest!:current_shm_has_sh'
chunhan
parents:
diff changeset
  2341
             dest:is_file_in_current is_dir_in_current)
chunhan
parents:
diff changeset
  2342
done
chunhan
parents:
diff changeset
  2343
chunhan
parents:
diff changeset
  2344
lemma co2sobj_detach:
92
d9dc04c3ea90 modify co2sobj/s2ss from object to dobject
chunhan
parents: 88
diff changeset
  2345
  "\<lbrakk>valid (Detach p h # s); dalive s obj\<rbrakk> \<Longrightarrow> co2sobj (Detach p h # s) obj = (
77
chunhan
parents:
diff changeset
  2346
      case obj of
chunhan
parents:
diff changeset
  2347
        O_proc p' \<Rightarrow> if (p' = p) then (case (cp2sproc (Detach p h # s) p) of
chunhan
parents:
diff changeset
  2348
                                         Some sp \<Rightarrow> Some (S_proc sp (O_proc p \<in> tainted s))
chunhan
parents:
diff changeset
  2349
                                       | _       \<Rightarrow> None)
chunhan
parents:
diff changeset
  2350
                     else co2sobj s obj
chunhan
parents:
diff changeset
  2351
      | _         \<Rightarrow> co2sobj s obj)"
chunhan
parents:
diff changeset
  2352
apply (frule vt_grant_os, frule vd_cons, case_tac obj)
chunhan
parents:
diff changeset
  2353
apply (simp_all add:current_files_simps is_dir_simps ch2sshm_other cq2smsgq_other)
chunhan
parents:
diff changeset
  2354
chunhan
parents:
diff changeset
  2355
apply (auto split:if_splits option.splits dest!:current_file_has_sfile' current_proc_has_sp'
chunhan
parents:
diff changeset
  2356
             simp:current_files_simps cf2sfiles_simps cf2sfile_simps cp2sproc_simps tainted_eq_tainted
chunhan
parents:
diff changeset
  2357
                  same_inode_files_prop6 ch2sshm_simps
chunhan
parents:
diff changeset
  2358
             dest!:current_shm_has_sh'
chunhan
parents:
diff changeset
  2359
             dest:is_file_in_current is_dir_in_current)
chunhan
parents:
diff changeset
  2360
done
chunhan
parents:
diff changeset
  2361
chunhan
parents:
diff changeset
  2362
lemma co2sobj_deleteshm:
92
d9dc04c3ea90 modify co2sobj/s2ss from object to dobject
chunhan
parents: 88
diff changeset
  2363
  "\<lbrakk>valid (DeleteShM p h # s); dalive (DeleteShM p h # s) obj\<rbrakk> \<Longrightarrow> co2sobj (DeleteShM p h # s) obj = (
77
chunhan
parents:
diff changeset
  2364
      case obj of
chunhan
parents:
diff changeset
  2365
        O_proc p' \<Rightarrow> (case (cp2sproc (DeleteShM p h # s) p') of
chunhan
parents:
diff changeset
  2366
                        Some sp \<Rightarrow> Some (S_proc sp (O_proc p' \<in> tainted s))
chunhan
parents:
diff changeset
  2367
                      | _       \<Rightarrow> None)
chunhan
parents:
diff changeset
  2368
      | _         \<Rightarrow> co2sobj s obj)"
chunhan
parents:
diff changeset
  2369
apply (frule vt_grant_os, frule vd_cons, case_tac obj)
chunhan
parents:
diff changeset
  2370
apply (simp_all add:current_files_simps is_dir_simps ch2sshm_other cq2smsgq_other)
chunhan
parents:
diff changeset
  2371
chunhan
parents:
diff changeset
  2372
apply (auto split:if_splits option.splits dest!:current_file_has_sfile' current_proc_has_sp'
chunhan
parents:
diff changeset
  2373
             simp:current_files_simps cf2sfiles_simps cf2sfile_simps tainted_eq_tainted
chunhan
parents:
diff changeset
  2374
                  same_inode_files_prop6 ch2sshm_simps
chunhan
parents:
diff changeset
  2375
             dest!:current_shm_has_sh' 
chunhan
parents:
diff changeset
  2376
             dest:is_file_in_current is_dir_in_current)
chunhan
parents:
diff changeset
  2377
done
chunhan
parents:
diff changeset
  2378
*)
chunhan
parents:
diff changeset
  2379
chunhan
parents:
diff changeset
  2380
declare Product_Type.split_paired_Ex Product_Type.split_paired_All [simp del]
chunhan
parents:
diff changeset
  2381
chunhan
parents:
diff changeset
  2382
(*
chunhan
parents:
diff changeset
  2383
lemma info_flow_shm_prop1:
chunhan
parents:
diff changeset
  2384
  "p \<in> current_procs s \<Longrightarrow> info_flow_shm s p p"
chunhan
parents:
diff changeset
  2385
by (simp add:info_flow_shm_def)
chunhan
parents:
diff changeset
  2386
chunhan
parents:
diff changeset
  2387
lemma co2sobj_attach:
92
d9dc04c3ea90 modify co2sobj/s2ss from object to dobject
chunhan
parents: 88
diff changeset
  2388
  "\<lbrakk>valid (Attach p h flag # s); dalive s obj\<rbrakk> \<Longrightarrow> co2sobj (Attach p h flag # s) obj = (
77
chunhan
parents:
diff changeset
  2389
      case obj of
chunhan
parents:
diff changeset
  2390
        O_proc p' \<Rightarrow> if (info_flow_shm s p p')
chunhan
parents:
diff changeset
  2391
                     then (case (cp2sproc (Attach p h flag # s) p') of
chunhan
parents:
diff changeset
  2392
                             Some sp \<Rightarrow> Some (S_proc sp (O_proc p' \<in> tainted s \<or> 
chunhan
parents:
diff changeset
  2393
              (\<exists> p''. O_proc p'' \<in> tainted s \<and> (p'', SHM_RDWR) \<in> procs_of_shm s h)))
chunhan
parents:
diff changeset
  2394
                           | _       \<Rightarrow> None)
chunhan
parents:
diff changeset
  2395
                     else if (\<exists> p'' flag'. (p'', flag') \<in> procs_of_shm s h \<and> flag = SHM_RDWR \<and> O_proc p \<in> tainted s \<and>
chunhan
parents:
diff changeset
  2396
  info_flow_shm s p'' p')
chunhan
parents:
diff changeset
  2397
                          then (case (cp2sproc s p') of 
chunhan
parents:
diff changeset
  2398
                                  Some sp \<Rightarrow> Some (S_proc sp True)
chunhan
parents:
diff changeset
  2399
                                | _       \<Rightarrow> None)
chunhan
parents:
diff changeset
  2400
                          else co2sobj s obj
chunhan
parents:
diff changeset
  2401
      | _         \<Rightarrow> co2sobj s obj)"
chunhan
parents:
diff changeset
  2402
apply (frule vt_grant_os, frule vd_cons, case_tac obj)
chunhan
parents:
diff changeset
  2403
apply (simp_all add:current_files_simps is_dir_simps ch2sshm_other cq2smsgq_other)
chunhan
parents:
diff changeset
  2404
chunhan
parents:
diff changeset
  2405
apply (rule conjI|rule impI|erule exE)+
chunhan
parents:
diff changeset
  2406
apply (simp split:option.splits del:split_paired_Ex)
chunhan
parents:
diff changeset
  2407
apply (rule impI, frule current_proc_has_sp, simp)
chunhan
parents:
diff changeset
  2408
apply ((erule exE)+, auto simp:tainted_eq_tainted intro:info_flow_shm_tainted)[1]
chunhan
parents:
diff changeset
  2409
apply (rule impI, simp add:tainted_eq_tainted split:option.splits del:split_paired_Ex)
chunhan
parents:
diff changeset
  2410
apply (auto simp:info_flow_shm_prop1 cp2sproc_attach dest!:current_proc_has_sp')[1]
chunhan
parents:
diff changeset
  2411
chunhan
parents:
diff changeset
  2412
apply (case_tac "cp2sproc (Attach p h flag # s) nat")
chunhan
parents:
diff changeset
  2413
apply (drule current_proc_has_sp', simp+)
chunhan
parents:
diff changeset
  2414
chunhan
parents:
diff changeset
  2415
apply (rule conjI|erule exE|erule conjE|rule impI)+
chunhan
parents:
diff changeset
  2416
apply (simp add:tainted_eq_tainted)
chunhan
parents:
diff changeset
  2417
apply (auto simp:info_flow_shm_prop1 cp2sproc_attach intro:info_flow_shm_tainted dest!:current_proc_has_sp')[1]
chunhan
parents:
diff changeset
  2418
apply (auto simp:info_flow_shm_prop1 cp2sproc_attach intro:info_flow_shm_tainted dest!:current_proc_has_sp'
chunhan
parents:
diff changeset
  2419
split:option.splits if_splits)[1]
chunhan
parents:
diff changeset
  2420
chunhan
parents:
diff changeset
  2421
chunhan
parents:
diff changeset
  2422
apply (auto split:if_splits option.splits dest!:current_file_has_sfile' 
chunhan
parents:
diff changeset
  2423
             simp:current_files_simps cf2sfiles_simps cf2sfile_simps tainted_eq_tainted
chunhan
parents:
diff changeset
  2424
                  same_inode_files_prop6 
chunhan
parents:
diff changeset
  2425
             dest:is_file_in_current is_dir_in_current)
chunhan
parents:
diff changeset
  2426
done
chunhan
parents:
diff changeset
  2427
*)
chunhan
parents:
diff changeset
  2428
92
d9dc04c3ea90 modify co2sobj/s2ss from object to dobject
chunhan
parents: 88
diff changeset
  2429
lemma co2sobj_bind:
d9dc04c3ea90 modify co2sobj/s2ss from object to dobject
chunhan
parents: 88
diff changeset
  2430
  "valid (Bind p fd addr # s) \<Longrightarrow> co2sobj (Bind p fd addr # s) = co2sobj s"
d9dc04c3ea90 modify co2sobj/s2ss from object to dobject
chunhan
parents: 88
diff changeset
  2431
apply (frule vd_cons, frule vt_grant, rule ext, case_tac x)
d9dc04c3ea90 modify co2sobj/s2ss from object to dobject
chunhan
parents: 88
diff changeset
  2432
by auto
d9dc04c3ea90 modify co2sobj/s2ss from object to dobject
chunhan
parents: 88
diff changeset
  2433
d9dc04c3ea90 modify co2sobj/s2ss from object to dobject
chunhan
parents: 88
diff changeset
  2434
lemma co2sobj_connect:
d9dc04c3ea90 modify co2sobj/s2ss from object to dobject
chunhan
parents: 88
diff changeset
  2435
  "valid (Connect p fd addr # s) \<Longrightarrow> co2sobj (Connect p fd addr # s) = co2sobj s"
d9dc04c3ea90 modify co2sobj/s2ss from object to dobject
chunhan
parents: 88
diff changeset
  2436
apply (frule vd_cons, frule vt_grant, rule ext, case_tac x)
d9dc04c3ea90 modify co2sobj/s2ss from object to dobject
chunhan
parents: 88
diff changeset
  2437
by auto
d9dc04c3ea90 modify co2sobj/s2ss from object to dobject
chunhan
parents: 88
diff changeset
  2438
d9dc04c3ea90 modify co2sobj/s2ss from object to dobject
chunhan
parents: 88
diff changeset
  2439
lemma co2sobj_createsock:
d9dc04c3ea90 modify co2sobj/s2ss from object to dobject
chunhan
parents: 88
diff changeset
  2440
  "valid (CreateSock p af st fd inum # s) \<Longrightarrow> co2sobj (CreateSock p af st fd inum # s) = co2sobj s"
d9dc04c3ea90 modify co2sobj/s2ss from object to dobject
chunhan
parents: 88
diff changeset
  2441
apply (frule vd_cons, frule vt_grant, rule ext, case_tac x)
d9dc04c3ea90 modify co2sobj/s2ss from object to dobject
chunhan
parents: 88
diff changeset
  2442
by auto
d9dc04c3ea90 modify co2sobj/s2ss from object to dobject
chunhan
parents: 88
diff changeset
  2443
d9dc04c3ea90 modify co2sobj/s2ss from object to dobject
chunhan
parents: 88
diff changeset
  2444
lemma co2sobj_accept:
d9dc04c3ea90 modify co2sobj/s2ss from object to dobject
chunhan
parents: 88
diff changeset
  2445
  "valid (Accept p fd addr port fd' inum # s) \<Longrightarrow> co2sobj (Accept p fd addr port fd' inum # s) = co2sobj s"
d9dc04c3ea90 modify co2sobj/s2ss from object to dobject
chunhan
parents: 88
diff changeset
  2446
apply (frule vd_cons, frule vt_grant, rule ext, case_tac x)
d9dc04c3ea90 modify co2sobj/s2ss from object to dobject
chunhan
parents: 88
diff changeset
  2447
by auto
d9dc04c3ea90 modify co2sobj/s2ss from object to dobject
chunhan
parents: 88
diff changeset
  2448
d9dc04c3ea90 modify co2sobj/s2ss from object to dobject
chunhan
parents: 88
diff changeset
  2449
lemma co2sobj_listen:
d9dc04c3ea90 modify co2sobj/s2ss from object to dobject
chunhan
parents: 88
diff changeset
  2450
  "valid (Listen p fd # s) \<Longrightarrow> co2sobj (Listen p fd # s) = co2sobj s"
d9dc04c3ea90 modify co2sobj/s2ss from object to dobject
chunhan
parents: 88
diff changeset
  2451
apply (frule vd_cons, frule vt_grant, rule ext, case_tac x)
d9dc04c3ea90 modify co2sobj/s2ss from object to dobject
chunhan
parents: 88
diff changeset
  2452
by auto
d9dc04c3ea90 modify co2sobj/s2ss from object to dobject
chunhan
parents: 88
diff changeset
  2453
lemma co2sobj_sendsock:
d9dc04c3ea90 modify co2sobj/s2ss from object to dobject
chunhan
parents: 88
diff changeset
  2454
  "valid (SendSock p fd # s) \<Longrightarrow> co2sobj (SendSock p fd # s) = co2sobj s"
d9dc04c3ea90 modify co2sobj/s2ss from object to dobject
chunhan
parents: 88
diff changeset
  2455
apply (frule vd_cons, frule vt_grant, rule ext, case_tac x)
d9dc04c3ea90 modify co2sobj/s2ss from object to dobject
chunhan
parents: 88
diff changeset
  2456
by auto
d9dc04c3ea90 modify co2sobj/s2ss from object to dobject
chunhan
parents: 88
diff changeset
  2457
lemma co2sobj_recvsock:
d9dc04c3ea90 modify co2sobj/s2ss from object to dobject
chunhan
parents: 88
diff changeset
  2458
  "valid (RecvSock p fd # s) \<Longrightarrow> co2sobj (RecvSock p fd # s) = co2sobj s"
d9dc04c3ea90 modify co2sobj/s2ss from object to dobject
chunhan
parents: 88
diff changeset
  2459
apply (frule vd_cons, frule vt_grant, rule ext, case_tac x)
d9dc04c3ea90 modify co2sobj/s2ss from object to dobject
chunhan
parents: 88
diff changeset
  2460
by auto
d9dc04c3ea90 modify co2sobj/s2ss from object to dobject
chunhan
parents: 88
diff changeset
  2461
lemma co2sobj_shutdown:
d9dc04c3ea90 modify co2sobj/s2ss from object to dobject
chunhan
parents: 88
diff changeset
  2462
  "valid (Shutdown p fd addr # s) \<Longrightarrow> co2sobj (Shutdown p fd addr # s) = co2sobj s"
d9dc04c3ea90 modify co2sobj/s2ss from object to dobject
chunhan
parents: 88
diff changeset
  2463
apply (frule vd_cons, frule vt_grant, rule ext, case_tac x)
d9dc04c3ea90 modify co2sobj/s2ss from object to dobject
chunhan
parents: 88
diff changeset
  2464
by auto
d9dc04c3ea90 modify co2sobj/s2ss from object to dobject
chunhan
parents: 88
diff changeset
  2465
77
chunhan
parents:
diff changeset
  2466
lemma co2sobj_other:
92
d9dc04c3ea90 modify co2sobj/s2ss from object to dobject
chunhan
parents: 88
diff changeset
  2467
  "\<lbrakk>valid (e # s); dalive (e # s) obj; 
77
chunhan
parents:
diff changeset
  2468
    \<forall> p f fds. e \<noteq> Execve p f fds;
chunhan
parents:
diff changeset
  2469
    \<forall> p p' fds. e \<noteq> Clone p p' fds;
chunhan
parents:
diff changeset
  2470
    \<forall> p p'. e \<noteq> Ptrace p p';
chunhan
parents:
diff changeset
  2471
    \<forall> p f flags fd opt. e \<noteq> Open p f flags fd opt;
chunhan
parents:
diff changeset
  2472
    \<forall> p fd. e \<noteq> ReadFile p fd;
chunhan
parents:
diff changeset
  2473
    \<forall> p fd. e \<noteq> WriteFile p fd;
chunhan
parents:
diff changeset
  2474
    \<forall> p fd. e \<noteq> CloseFd p fd;
chunhan
parents:
diff changeset
  2475
    \<forall> p f. e \<noteq> UnLink p f;
chunhan
parents:
diff changeset
  2476
    \<forall> p f. e \<noteq> Rmdir p f;
chunhan
parents:
diff changeset
  2477
    \<forall> p f i. e \<noteq> Mkdir p f i;
chunhan
parents:
diff changeset
  2478
    \<forall> p f f'. e \<noteq> LinkHard p f f';
chunhan
parents:
diff changeset
  2479
    \<forall> p f len. e \<noteq> Truncate p f len;
chunhan
parents:
diff changeset
  2480
    \<forall> p q. e \<noteq> CreateMsgq p q;
chunhan
parents:
diff changeset
  2481
    \<forall> p q m. e \<noteq> SendMsg p q m;
chunhan
parents:
diff changeset
  2482
    \<forall> p q m. e \<noteq> RecvMsg p q m;
chunhan
parents:
diff changeset
  2483
    \<forall> p q. e \<noteq> RemoveMsgq p q
chunhan
parents:
diff changeset
  2484
   \<rbrakk> \<Longrightarrow> co2sobj (e # s) obj = co2sobj s obj" (*;
chunhan
parents:
diff changeset
  2485
    \<forall> p h flag. e \<noteq> Attach p h flag;
chunhan
parents:
diff changeset
  2486
    \<forall> p h. e \<noteq> Detach p h;
chunhan
parents:
diff changeset
  2487
    \<forall> p h. e \<noteq> DeleteShM p h*)
chunhan
parents:
diff changeset
  2488
apply (frule vt_grant, case_tac e)
chunhan
parents:
diff changeset
  2489
apply (auto intro:co2sobj_kill co2sobj_exit)
chunhan
parents:
diff changeset
  2490
done
chunhan
parents:
diff changeset
  2491
chunhan
parents:
diff changeset
  2492
lemmas co2sobj_simps = co2sobj_execve co2sobj_clone co2sobj_ptrace co2sobj_open co2sobj_readfile
chunhan
parents:
diff changeset
  2493
  co2sobj_writefile co2sobj_closefd co2sobj_unlink co2sobj_rmdir co2sobj_mkdir co2sobj_linkhard
chunhan
parents:
diff changeset
  2494
  co2sobj_truncate co2sobj_kill co2sobj_exit co2sobj_createmsgq co2sobj_sendmsg co2sobj_recvmsg
chunhan
parents:
diff changeset
  2495
  co2sobj_removemsgq (* co2sobj_attach co2sobj_detach co2sobj_createshm co2sobj_deleteshm *)
92
d9dc04c3ea90 modify co2sobj/s2ss from object to dobject
chunhan
parents: 88
diff changeset
  2496
  co2sobj_createsock co2sobj_accept co2sobj_listen co2sobj_sendsock co2sobj_recvsock 
d9dc04c3ea90 modify co2sobj/s2ss from object to dobject
chunhan
parents: 88
diff changeset
  2497
  co2sobj_shutdown co2sobj_bind co2sobj_connect
77
chunhan
parents:
diff changeset
  2498
chunhan
parents:
diff changeset
  2499
end
chunhan
parents:
diff changeset
  2500
chunhan
parents:
diff changeset
  2501
(*<*)
chunhan
parents:
diff changeset
  2502
end
chunhan
parents:
diff changeset
  2503
(*>*)