simple_selinux/Init_prop.thy
changeset 74 271e9818b6f6
equal deleted inserted replaced
73:924ab7a4e7fa 74:271e9818b6f6
       
     1 (*<*)
       
     2 theory Init_prop
       
     3 imports Main OS_type_def Flask Flask_type Static_type Static
       
     4 begin
       
     5 (*>*)
       
     6 
       
     7 context init begin
       
     8 
       
     9 lemma init_files_prop1: "init_inum_of_file f = Some im \<Longrightarrow> f \<in> init_files"
       
    10 by (simp add:inof_has_file_tag)
       
    11 
       
    12 lemma init_files_prop2: "finite init_files" 
       
    13 by (simp add:init_finite_sets)
       
    14 
       
    15 lemma init_files_prop3: "f \<in> init_files \<Longrightarrow> init_inum_of_file f \<noteq> None"
       
    16 by (auto dest:init_file_has_inum)
       
    17 
       
    18 lemma init_files_prop4: "(f \<in> init_files) = (f \<in> current_files [])"
       
    19 apply (simp add:current_files_def, rule iffI)
       
    20 using init_files_prop1 init_files_prop3 by auto
       
    21 
       
    22 lemmas init_files_props = init_file_has_inum init_files_prop1 init_files_prop2 init_files_prop3 init_files_prop4
       
    23 
       
    24 lemma init_inumof_prop1: "init_inum_of_file f = Some im \<Longrightarrow> \<exists> tag. init_itag_of_inum im = Some tag"
       
    25 by (auto dest:inof_has_file_tag)
       
    26 
       
    27 lemma init_inumof_prop2:  "init_inum_of_file f = Some im \<Longrightarrow> init_itag_of_inum im \<noteq> None"
       
    28 by (auto dest:inof_has_file_tag)
       
    29 
       
    30 lemma init_inumof_prop3: "\<lbrakk>init_inum_of_file f = Some im; init_itag_of_inum im = Some tag\<rbrakk> \<Longrightarrow> is_file_dir_itag tag"
       
    31 by (auto dest:inof_has_file_tag)
       
    32 
       
    33 lemmas init_inum_of_file_props = init_files_prop1 init_inumof_prop1 init_inumof_prop2 init_inumof_prop3
       
    34 
       
    35 lemma init_inumos_prop1: "init_inum_of_socket s = Some im \<Longrightarrow> s \<in> init_sockets"
       
    36 by (auto dest:inos_has_sock_tag)
       
    37 
       
    38 lemma init_inumos_prop2: "init_inum_of_socket s = Some im \<Longrightarrow> init_itag_of_inum im = Some Tag_TCP_SOCK \<or> init_itag_of_inum im = Some Tag_UDP_SOCK"
       
    39 apply (auto dest!:inos_has_sock_tag) 
       
    40 apply (case_tac tag, simp+)
       
    41 done
       
    42 
       
    43 lemma init_inumos_prop3: "init_inum_of_socket s = Some im \<Longrightarrow> init_itag_of_inum im \<noteq> None"
       
    44 by (auto dest:inos_has_sock_tag)
       
    45 
       
    46 lemma init_inumos_prop4: "init_inum_of_socket s = Some im \<Longrightarrow> \<exists> tag. init_itag_of_inum im = Some tag \<and> is_sock_itag tag"
       
    47 by (auto dest!:inos_has_sock_tag) 
       
    48 
       
    49 lemmas init_inum_of_socket_props = init_inumos_prop1 init_inumos_prop2 init_inumos_prop3 init_inumos_prop4
       
    50 
       
    51 lemma init_sockets_prop1: "(p, fd) \<in> init_sockets \<Longrightarrow> p \<in> init_procs"
       
    52 by (auto dest: init_socket_has_inode)
       
    53 
       
    54 lemma init_sockets_prop2: "(p, fd) \<in> init_sockets \<Longrightarrow> fd \<in> init_fds_of_proc p"
       
    55 by (auto dest:init_socket_has_inode)
       
    56 
       
    57 lemma init_sockets_prop3: "s \<in> init_sockets \<Longrightarrow> \<exists> im. init_inum_of_socket s = Some im"
       
    58 by (case_tac s, auto dest:init_socket_has_inode)
       
    59 
       
    60 lemma init_sockets_prop4: "s \<in> init_sockets \<Longrightarrow> init_inum_of_socket s \<noteq> None"
       
    61 by (simp add:init_sockets_prop3)
       
    62 
       
    63 lemma init_sockets_prop5: "s \<in> init_sockets = (s \<in> current_sockets [])"
       
    64 apply (simp add:current_sockets_def, rule iffI)
       
    65 using init_sockets_prop4 inos_has_sock_tag apply auto
       
    66 apply (case_tac s, auto)
       
    67 done
       
    68 
       
    69 lemma init_socket_prop6: "(p, fd) \<in> init_sockets \<Longrightarrow> init_file_of_proc_fd p fd = None"
       
    70 by (auto dest: init_socket_has_inode)
       
    71 
       
    72 lemmas init_sockets_props = init_sockets_prop1 init_sockets_prop2 init_sockets_prop3 init_sockets_prop4 init_sockets_prop5
       
    73 
       
    74 lemma is_init_file_prop1: "is_init_file f \<Longrightarrow> f \<in> init_files"
       
    75 by (auto simp add:is_init_file_def init_inum_of_file_props split:option.splits)
       
    76 
       
    77 lemma is_init_file_prop2: "is_init_file f \<Longrightarrow> \<not> is_init_dir f"
       
    78 by (auto simp add:is_init_file_def is_init_dir_def split:option.splits t_inode_tag.splits)
       
    79 
       
    80 lemmas is_init_file_props = is_init_file_prop1 is_init_file_prop2
       
    81 
       
    82 lemma is_init_dir_prop1: "is_init_dir f \<Longrightarrow> f \<in> init_files"
       
    83 by (auto simp add:is_init_dir_def is_dir_def init_inum_of_file_props split:option.splits)
       
    84 
       
    85 lemma is_init_dir_prop2: "is_init_dir f \<Longrightarrow> \<not> is_init_file f"
       
    86 by (auto simp add:is_init_dir_def is_init_file_def split:option.splits t_inode_tag.splits)
       
    87 
       
    88 lemmas is_init_dir_props = is_init_dir_prop1 is_init_dir_prop2
       
    89 
       
    90 lemma is_file_nil: "is_file [] = is_init_file"
       
    91 by (auto simp:is_init_file_def is_file_def init_inum_of_file_props intro!:ext split:option.splits)
       
    92 
       
    93 lemma is_dir_nil: "is_dir [] = is_init_dir"
       
    94 by (auto simp:is_init_dir_def is_dir_def init_inum_of_file_props intro!:ext split:option.splits)
       
    95 
       
    96 lemma is_udp_sock_nil:
       
    97   "is_udp_sock [] k = is_init_udp_sock k"
       
    98 by (auto simp:is_udp_sock_def is_init_udp_sock_def split:option.splits)
       
    99 
       
   100 lemma is_init_udp_sock_prop1: "is_init_udp_sock s \<Longrightarrow> s \<in> init_sockets"
       
   101 apply (auto simp add:is_init_udp_sock_def is_udp_sock_def init_inum_of_socket_props 
       
   102                 dest:init_socket_has_inode split:option.splits)       
       
   103 done
       
   104 
       
   105 lemma is_init_udp_sock_prop2: "is_init_udp_sock s \<Longrightarrow> \<not> is_init_tcp_sock s"
       
   106 apply (auto simp add:is_init_udp_sock_def is_init_tcp_sock_def  
       
   107                 dest:init_socket_has_inode split:option.splits t_inode_tag.splits)       
       
   108 done
       
   109 
       
   110 lemma is_init_udp_sock_prop3:
       
   111   "is_init_udp_sock (p, fd) \<Longrightarrow> p \<in> init_procs"
       
   112 by (auto simp:is_init_udp_sock_def split:option.splits t_inode_tag.splits
       
   113          dest:init_socket_has_inode inos_has_sock_tag)
       
   114 
       
   115 lemma is_init_udp_sock_prop4:
       
   116   "is_init_udp_sock (p, fd) \<Longrightarrow> fd \<in> init_fds_of_proc p"
       
   117 by (auto simp:is_init_udp_sock_def split:option.splits t_inode_tag.splits
       
   118          dest:init_socket_has_inode inos_has_sock_tag)
       
   119 
       
   120 lemma is_init_udp_sock_prop5:
       
   121   "is_init_udp_sock (p, fd) \<Longrightarrow> init_file_of_proc_fd p fd = None"
       
   122 by (auto dest:is_init_udp_sock_prop1 intro:init_socket_prop6)
       
   123 
       
   124 lemmas is_init_udp_sock_props = is_init_udp_sock_prop1 is_init_udp_sock_prop2 is_init_udp_sock_prop3
       
   125   is_init_udp_sock_prop4 is_init_udp_sock_prop5
       
   126 
       
   127 lemma is_tcp_sock_nil:
       
   128   "is_tcp_sock [] k = is_init_tcp_sock k"
       
   129 by (auto simp:is_tcp_sock_def is_init_tcp_sock_def split:option.splits)
       
   130 
       
   131 lemma is_init_tcp_sock_prop1: "is_init_tcp_sock s \<Longrightarrow> s \<in> init_sockets"
       
   132 apply (auto simp add:is_init_tcp_sock_def is_tcp_sock_def init_inum_of_socket_props 
       
   133                 dest:init_socket_has_inode split:option.splits)       
       
   134 done
       
   135 
       
   136 lemma is_init_tcp_sock_prop2: "is_init_tcp_sock s \<Longrightarrow> \<not> is_init_udp_sock s"
       
   137 apply (auto simp add:is_init_tcp_sock_def is_init_udp_sock_def  
       
   138                 dest:init_socket_has_inode split:option.splits t_inode_tag.splits)       
       
   139 done
       
   140 
       
   141 lemma is_init_tcp_sock_prop3:
       
   142   "is_init_tcp_sock (p, fd) \<Longrightarrow> p \<in> init_procs"
       
   143 by (auto simp:is_init_tcp_sock_def split:option.splits t_inode_tag.splits
       
   144          dest:init_socket_has_inode inos_has_sock_tag)
       
   145 
       
   146 lemma is_init_tcp_sock_prop4:
       
   147   "is_init_tcp_sock (p, fd) \<Longrightarrow> fd \<in> init_fds_of_proc p"
       
   148 by (auto simp:is_init_tcp_sock_def split:option.splits t_inode_tag.splits
       
   149          dest:init_socket_has_inode inos_has_sock_tag)
       
   150 
       
   151 lemma is_init_tcp_sock_prop5:
       
   152   "is_init_tcp_sock (p, fd) \<Longrightarrow> init_file_of_proc_fd p fd = None"
       
   153 by (auto dest:is_init_tcp_sock_prop1 intro:init_socket_prop6)
       
   154 
       
   155 lemmas is_init_tcp_sock_props = is_init_tcp_sock_prop1 is_init_tcp_sock_prop2 is_init_tcp_sock_prop3
       
   156   is_init_tcp_sock_prop4 is_init_tcp_sock_prop5
       
   157 
       
   158 lemma init_parent_file_prop1: 
       
   159   "\<lbrakk>parent f = Some pf; f \<in> init_files\<rbrakk> \<Longrightarrow> is_init_dir pf"
       
   160 apply (frule parent_file_in_init, simp, frule_tac f = pf in init_files_prop3)
       
   161 apply (clarsimp, drule_tac im = y in init_parentf_is_dir, simp+)
       
   162 by (simp add:is_init_dir_def)
       
   163 
       
   164 lemma init_parent_file_prop1': 
       
   165   "a # f \<in> init_files \<Longrightarrow> is_init_dir f"
       
   166 by (rule_tac pf = f in init_parent_file_prop1, auto)
       
   167 
       
   168 lemma init_parent_file_prop2:
       
   169   "\<lbrakk>parent f = Some pf; is_init_file f\<rbrakk> \<Longrightarrow> is_init_dir pf"
       
   170 by (rule init_parent_file_prop1, simp, simp add: is_init_file_props)
       
   171 
       
   172 lemma init_parent_file_prop2':
       
   173   "is_init_file (f#pf) \<Longrightarrow> is_init_dir pf"
       
   174 apply (rule init_parent_file_prop2)
       
   175 by auto
       
   176 
       
   177 lemma init_parent_file_prop3:
       
   178   "\<lbrakk>parent f = Some pf; is_init_dir f\<rbrakk> \<Longrightarrow> is_init_dir pf"
       
   179 by (rule init_parent_file_prop1, simp, simp add: is_init_dir_props)
       
   180 
       
   181 lemma init_parent_file_prop3':
       
   182   "is_init_dir (f#pf) \<Longrightarrow> is_init_dir pf"
       
   183 apply (rule init_parent_file_prop3)
       
   184 by auto
       
   185 
       
   186 lemma parent_file_in_init': "a # f \<in> init_files \<Longrightarrow> f \<in> init_files"
       
   187 by (subgoal_tac "parent (a # f) = Some f", drule parent_file_in_init, auto)
       
   188 
       
   189 lemmas init_parent_file_props = parent_file_in_init init_parent_file_prop1 parent_file_in_init' init_parent_file_prop1' init_parent_file_prop2 init_parent_file_prop2' init_parent_file_prop3 init_parent_file_prop3'
       
   190 
       
   191 lemma root_in_filesystem:  "[] \<in> init_files" 
       
   192 using init_files_prop1 root_is_dir by auto
       
   193 
       
   194 lemma root_is_init_dir: "is_init_dir []"
       
   195 using root_is_dir
       
   196 by (auto simp add:is_init_dir_def split:option.splits)
       
   197 
       
   198 lemma root_is_init_dir': "is_init_file [] \<Longrightarrow> False"
       
   199 using root_is_dir
       
   200 by (auto simp:is_init_file_def split:option.splits)
       
   201 
       
   202 
       
   203 lemma init_files_hung_prop1: "f \<in> init_files_hung_by_del \<Longrightarrow> f \<in> init_files"
       
   204 by (auto dest:init_files_hung_valid)
       
   205 
       
   206 lemma init_files_hung_prop2: "f \<in> init_files_hung_by_del \<Longrightarrow> \<exists> p fd. init_file_of_proc_fd p fd = Some f"
       
   207 by (auto dest:init_files_hung_valid)
       
   208 
       
   209 lemmas init_files_hung_by_del_props = init_files_hung_prop1 init_files_hung_prop2 init_files_hung_valid'
       
   210 
       
   211 
       
   212 lemma init_fds_of_proc_prop1: "fd \<in> init_fds_of_proc p \<Longrightarrow> p \<in> init_procs"
       
   213 by (auto dest!:init_procfds_valid)
       
   214 
       
   215 lemma init_fds_of_proc_prop2: "fd \<in> init_fds_of_proc p \<Longrightarrow> (\<exists> f \<in> init_files. init_file_of_proc_fd p fd = Some f) \<or> (p, fd) \<in> init_sockets"
       
   216 by (auto dest:init_procfds_valid)
       
   217 
       
   218 lemmas init_fds_of_proc_props = init_fds_of_proc_prop1 init_fds_of_proc_prop2
       
   219 
       
   220 lemma init_filefd_prop1: "init_file_of_proc_fd p fd = Some f \<Longrightarrow> f \<in> init_files"
       
   221 by (auto dest!:init_filefd_valid intro:init_files_prop1)
       
   222 
       
   223 lemma init_filefd_prop2: "init_file_of_proc_fd p fd = Some f \<Longrightarrow> p \<in> init_procs"
       
   224 by (auto dest:init_filefd_valid)
       
   225 
       
   226 lemma init_filefd_prop3: "init_file_of_proc_fd p fd = Some f \<Longrightarrow> fd \<in> init_fds_of_proc p"
       
   227 by (auto dest:init_filefd_valid)
       
   228 
       
   229 lemma init_filefd_prop4: "init_file_of_proc_fd p fd = Some f \<Longrightarrow> \<exists> flags. init_oflags_of_proc_fd p fd = Some flags"
       
   230 by (auto dest:init_filefd_valid)
       
   231 
       
   232 lemma init_filefd_prop5: "init_file_of_proc_fd p fd = Some f \<Longrightarrow> is_init_file f"
       
   233 by (auto dest:init_filefd_valid simp:is_init_file_def)
       
   234 
       
   235 lemma init_filefd_prop6: "init_file_of_proc_fd p fd = Some f \<Longrightarrow> \<not> is_init_tcp_sock (p, fd)"
       
   236 by (auto dest!:init_filefd_valid is_init_tcp_sock_prop1)
       
   237 
       
   238 lemma init_filefd_prop7: "init_file_of_proc_fd p fd = Some f \<Longrightarrow> \<not> is_init_udp_sock (p, fd)"
       
   239 by (auto dest!:init_filefd_valid is_init_udp_sock_prop1)
       
   240 
       
   241 lemma init_filefd_prop8: "init_file_of_proc_fd p fd = Some f \<Longrightarrow> (p, fd) \<notin> init_sockets"
       
   242 by (auto dest!:init_filefd_valid)
       
   243 
       
   244 lemmas init_file_of_proc_fd_props = init_filefd_prop1 init_filefd_prop2 init_filefd_prop3 init_filefd_prop4 init_filefd_prop5 init_filefd_prop6 init_filefd_prop7 init_filefd_prop8
       
   245 
       
   246 lemma init_oflags_prop1: "init_oflags_of_proc_fd p fd = Some flags \<Longrightarrow> p \<in> init_procs"
       
   247 by (auto dest:init_fileflag_valid init_file_of_proc_fd_props)
       
   248 
       
   249 lemma init_oflags_prop2: "init_oflags_of_proc_fd p fd = Some flags \<Longrightarrow> fd \<in> init_fds_of_proc p"
       
   250 by (auto dest:init_fileflag_valid init_file_of_proc_fd_props)
       
   251 
       
   252 lemmas init_oflags_of_proc_fd_props = init_oflags_prop1 init_oflags_prop2 init_fileflag_valid
       
   253 
       
   254 (*
       
   255 lemma init_socketstate_prop1: "s \<in> init_sockets \<Longrightarrow> init_socket_state s \<noteq> None"
       
   256 using init_socket_has_state
       
   257 by (case_tac s, simp add:bidirect_in_init_def)
       
   258 
       
   259 lemma init_socketstate_prop2: "s \<in> init_sockets \<Longrightarrow> \<exists> t. init_socket_state s = Some t"
       
   260 using init_socket_has_state
       
   261 by (case_tac s, simp add:bidirect_in_init_def)
       
   262 
       
   263 lemma init_socketstate_prop3: "init_socket_state s = Some t \<Longrightarrow> s \<in> init_sockets"
       
   264 using init_socket_has_state
       
   265 by (case_tac s, simp add:bidirect_in_init_def)
       
   266 
       
   267 lemmas init_socket_state_props = init_socketstate_prop1 init_socketstate_prop2 init_socketstate_prop3
       
   268 *)
       
   269 
       
   270 lemma init_inum_sock_file_noninter: "\<lbrakk>init_inum_of_socket s = Some im; init_inum_of_file f = Some im\<rbrakk> \<Longrightarrow> False"
       
   271 apply (frule init_inumof_prop1, erule exE, drule init_inumof_prop3, simp)
       
   272 apply (frule init_inumos_prop2)
       
   273 apply (case_tac tag, simp+)
       
   274 done
       
   275 
       
   276 lemma init_parent_file_has_inum: "\<lbrakk>parent f = Some pf; init_inum_of_file f = Some im\<rbrakk> \<Longrightarrow> \<exists> im. init_inum_of_file pf = Some im"
       
   277 by (drule init_files_prop1, drule parent_file_in_init, simp, simp add:init_files_props)
       
   278 
       
   279 lemma init_file_has_no_son': "\<lbrakk>init_itag_of_inum im = Some Tag_FILE; init_inum_of_file f = Some im; parent f' = Some f\<rbrakk> \<Longrightarrow> init_inum_of_file f' = None"
       
   280 apply (drule init_file_no_son, simp)
       
   281 by (case_tac "init_inum_of_file f'", auto dest:init_files_prop1)
       
   282 
       
   283 lemma init_parent_file_is_dir': "\<lbrakk>parent f = Some pf; init_inum_of_file f = Some im; init_inum_of_file pf = Some ipm\<rbrakk> \<Longrightarrow> init_itag_of_inum ipm = Some Tag_DIR"
       
   284 by (drule init_parentf_is_dir, auto dest:init_files_prop1)
       
   285 
       
   286 lemma init_file_hung_has_no_son: "\<lbrakk>f \<in> init_files_hung_by_del; parent f' = Some f; init_inum_of_file f' = Some im\<rbrakk> \<Longrightarrow> False"
       
   287 apply (frule init_files_hung_prop1, drule init_file_has_inum, erule exE)
       
   288 apply (drule init_files_hung_valid', simp)
       
   289 apply (frule init_parent_file_is_dir', simp+)
       
   290 apply (drule init_files_prop1)
       
   291 apply (erule_tac x = f' in allE, simp)
       
   292 by (case_tac f', simp_all add:no_junior_def)
       
   293 
       
   294 (*
       
   295 lemma same_inode_nil_prop:
       
   296   "same_inode_files [] f = init_same_inode_files f"
       
   297 by (simp add:same_inode_files_def init_same_inode_files_def is_file_nil)
       
   298 
       
   299 lemma init_same_inode_prop1:
       
   300   "f \<in> init_files \<Longrightarrow> \<forall> f' \<in> init_same_inode_files f. f' \<in> init_files"
       
   301 apply (simp add:init_same_inode_files_def)
       
   302 apply (drule init_files_prop3)
       
   303 apply (auto simp:init_files_prop1)
       
   304 done
       
   305 
       
   306 lemma init_same_inode_prop2:
       
   307   "\<lbrakk>f' \<in> init_same_inode_files f; f \<in> init_files\<rbrakk> \<Longrightarrow> f' \<in> init_files"
       
   308 by (drule init_same_inode_prop1, simp)
       
   309 
       
   310 lemma init_same_inode_prop3:
       
   311   "f' \<in> init_same_inode_files f \<Longrightarrow> f \<in> init_same_inode_files f'"
       
   312 by (auto simp add:init_same_inode_files_def is_init_file_def split:if_splits)
       
   313 
       
   314 lemma init_same_inode_prop4:
       
   315   "\<lbrakk>f' \<in> init_same_inode_files f; f' \<in> init_files\<rbrakk> \<Longrightarrow> f \<in> init_files"
       
   316 apply (drule init_same_inode_prop3)
       
   317 by (simp add:init_same_inode_prop2)
       
   318 *)
       
   319 
       
   320 end
       
   321 
       
   322 context flask begin
       
   323 
       
   324 lemma init_alive_prop: "init_alive obj = alive [] obj"
       
   325 apply (case_tac obj, simp_all add:is_init_file_props is_init_dir_props is_init_tcp_sock_props
       
   326          is_init_udp_sock_props init_files_props init_sockets_props is_file_nil is_dir_nil
       
   327          is_tcp_sock_nil is_udp_sock_nil)
       
   328 done
       
   329 
       
   330 lemma init_alive_proc: "p \<in> init_procs \<Longrightarrow> init_alive (O_proc p)" by simp
       
   331 lemma init_alive_file: "is_init_file f \<Longrightarrow> init_alive (O_file f)" by simp
       
   332 lemma init_alive_dir: "is_init_dir f \<Longrightarrow> init_alive (O_dir f)" by simp
       
   333 lemma init_alive_fd: "fd \<in> init_fds_of_proc p \<Longrightarrow> init_alive (O_fd p fd)" by simp
       
   334 lemma init_alive_tcp: "is_init_tcp_sock s \<Longrightarrow> init_alive (O_tcp_sock s)" by simp
       
   335 lemma init_alive_udp: "is_init_udp_sock s \<Longrightarrow> init_alive (O_udp_sock s)" by simp
       
   336 lemma init_alive_node: "n \<in> init_nodes \<Longrightarrow> init_alive (O_node n)" by simp
       
   337 lemma init_alive_msgq: "q \<in> init_msgqs \<Longrightarrow> init_alive (O_msgq q)" by simp
       
   338 lemma init_alive_msg: "\<lbrakk>m \<in> set (init_msgs_of_queue q); q \<in> init_msgqs\<rbrakk>
       
   339   \<Longrightarrow> init_alive (O_msg q m)" by simp
       
   340 
       
   341 lemmas init_alive_intros = init_alive_proc init_alive_file init_alive_dir init_alive_fd 
       
   342   init_alive_tcp init_alive_udp init_alive_node init_alive_msgq init_alive_msg
       
   343 
       
   344 lemma init_file_type_prop1: "is_init_file f \<Longrightarrow> \<exists> t. init_type_of_obj (O_file f) = Some t"
       
   345 using init_obj_has_type
       
   346 by (auto simp:is_init_file_def split:option.splits)
       
   347 
       
   348 lemma init_file_type_prop2: "is_init_file f \<Longrightarrow> init_type_of_obj (O_file f) \<noteq> None"
       
   349 by (simp add:init_file_type_prop1)
       
   350 
       
   351 lemma init_file_type_prop3: "init_type_of_obj (O_file f) = Some t \<Longrightarrow> f \<in> init_files"
       
   352 apply (drule init_type_has_obj) 
       
   353 by (simp add:is_init_file_def init_inum_of_file_props split:option.splits)
       
   354 
       
   355 lemma init_file_type_prop4: "init_type_of_obj (O_file f) = Some t \<Longrightarrow> is_init_file f"
       
   356 apply (drule init_type_has_obj) 
       
   357 by (simp add:is_init_file_def init_inum_of_file_props split:option.splits)
       
   358 
       
   359 lemmas init_file_types_props = init_file_type_prop1 init_file_type_prop2 init_file_type_prop3 init_file_type_prop4
       
   360 
       
   361 lemma init_dir_type_prop1: "is_init_dir f \<Longrightarrow> \<exists> t. init_type_of_obj (O_dir f) = Some t"
       
   362 using init_obj_has_type
       
   363 by (auto simp:is_init_dir_def split:option.splits)
       
   364 
       
   365 lemma init_dir_type_prop2: "is_init_dir f \<Longrightarrow> init_type_of_obj (O_dir f) \<noteq> None"
       
   366 by (simp add:init_dir_type_prop1)
       
   367 
       
   368 lemma init_dir_type_prop3: "init_type_of_obj (O_dir f) = Some t \<Longrightarrow> f \<in> init_files"
       
   369 apply (drule init_type_has_obj) 
       
   370 by (simp add:is_init_dir_def init_inum_of_file_props split:option.splits)
       
   371 
       
   372 lemma init_dir_type_prop4: "init_type_of_obj (O_dir f) = Some t \<Longrightarrow> is_init_dir f"
       
   373 apply (drule init_type_has_obj) 
       
   374 by (simp add:is_init_dir_def init_inum_of_file_props split:option.splits)
       
   375 
       
   376 lemmas init_dir_types_props = init_dir_type_prop1 init_dir_type_prop2 init_dir_type_prop3 init_dir_type_prop4
       
   377 
       
   378 lemma init_procrole_prop1: "init_role_of_proc p = Some r \<Longrightarrow> p \<in> init_procs"
       
   379 using init_proc_has_role
       
   380 by (auto simp:bidirect_in_init_def)
       
   381 
       
   382 lemma init_procrole_prop2: "p \<in> init_procs \<Longrightarrow> \<exists> r. init_role_of_proc p = Some r"
       
   383 using init_proc_has_role
       
   384 by (auto simp:bidirect_in_init_def)
       
   385 
       
   386 lemma init_procrole_prop3: "p \<in> init_procs \<Longrightarrow> init_role_of_proc p \<noteq> None"
       
   387 using init_proc_has_role
       
   388 by (auto simp:bidirect_in_init_def)
       
   389 
       
   390 lemmas init_role_of_proc_props = init_procrole_prop1 init_procrole_prop2 init_procrole_prop3
       
   391 
       
   392 lemma init_file_user_prop1: "is_init_file f \<Longrightarrow> \<exists> t. init_user_of_obj (O_file f) = Some t"
       
   393 apply (drule init_alive_file)
       
   394 by (drule init_obj_has_user, auto)
       
   395 
       
   396 lemma init_file_user_prop2: "is_init_file f \<Longrightarrow> init_user_of_obj (O_file f) \<noteq> None"
       
   397 by (simp add:init_file_user_prop1)
       
   398 
       
   399 lemma init_file_user_prop3: "init_user_of_obj (O_file f) = Some t \<Longrightarrow> f \<in> init_files"
       
   400 apply (drule init_user_has_obj) 
       
   401 by (simp add:is_init_file_def init_inum_of_file_props split:option.splits)
       
   402 
       
   403 lemma init_file_user_prop4: "init_user_of_obj (O_file f) = Some t \<Longrightarrow> is_init_file f"
       
   404 apply (drule init_user_has_obj) 
       
   405 by (simp add:is_init_file_def init_inum_of_file_props split:option.splits)
       
   406 
       
   407 lemma init_file_user_prop5: "init_user_of_obj (O_file f) = Some u \<Longrightarrow> u \<in> init_users"
       
   408 by (simp add:init_user_has_obj)
       
   409 
       
   410 lemmas init_file_users_props = init_file_user_prop1 init_file_user_prop2 init_file_user_prop3 init_file_user_prop4 init_file_user_prop5
       
   411 
       
   412 lemma init_dir_user_prop1: "is_init_dir f \<Longrightarrow> \<exists> t. init_user_of_obj (O_dir f) = Some t"
       
   413 apply (drule init_alive_dir)
       
   414 by (drule init_obj_has_user, auto)
       
   415 
       
   416 lemma init_dir_user_prop2: "is_init_dir f \<Longrightarrow> init_user_of_obj (O_dir f) \<noteq> None"
       
   417 by (simp add:init_dir_user_prop1)
       
   418 
       
   419 lemma init_dir_user_prop3: "init_user_of_obj (O_dir f) = Some t \<Longrightarrow> f \<in> init_files"
       
   420 apply (drule init_user_has_obj) 
       
   421 by (simp add:is_init_dir_def init_inum_of_file_props split:option.splits)
       
   422 
       
   423 lemma init_dir_user_prop4: "init_user_of_obj (O_dir f) = Some t \<Longrightarrow> is_init_dir f"
       
   424 apply (drule init_user_has_obj) 
       
   425 by (simp add:is_init_dir_def init_inum_of_file_props split:option.splits)
       
   426 
       
   427 lemma init_dir_user_prop5: "init_user_of_obj (O_dir f) = Some u \<Longrightarrow> u \<in> init_users"
       
   428 by (simp add:init_user_has_obj)
       
   429 
       
   430 lemmas init_dir_users_props = init_dir_user_prop1 init_dir_user_prop2 init_dir_user_prop3 init_dir_user_prop4 init_dir_user_prop5
       
   431 
       
   432 lemma init_file_dir_conflict: "\<lbrakk>is_init_file f; is_init_dir f\<rbrakk> \<Longrightarrow> False"
       
   433 by (auto simp:is_init_file_def is_init_dir_def split:option.splits t_inode_tag.splits)
       
   434 
       
   435 lemma init_file_dir_conflict1: "is_init_file f \<Longrightarrow> \<not> is_init_dir f"
       
   436 by (auto simp:is_init_file_def is_init_dir_def split:option.splits t_inode_tag.splits)
       
   437 
       
   438 lemma init_file_dir_conflict2: "is_init_dir f \<Longrightarrow> \<not> is_init_file f"
       
   439 by (auto simp:is_init_file_def is_init_dir_def split:option.splits t_inode_tag.splits)
       
   440 
       
   441 end
       
   442 
       
   443 context tainting begin
       
   444 
       
   445 lemma tainted_nil_prop:
       
   446   "(x \<in> tainted []) = (x \<in> seeds)"
       
   447 by auto
       
   448 
       
   449 end
       
   450 
       
   451 context tainting_s begin
       
   452 
       
   453 lemma init_file_has_ctxt:
       
   454   "is_init_file f \<Longrightarrow> \<exists> sec. init_sectxt_of_obj (O_file f) = Some sec"
       
   455 apply (simp add:init_sectxt_of_obj_def split:option.splits)
       
   456 apply (rule conjI, rule init_obj_has_user, simp add:is_init_file_props)
       
   457 by (simp add:init_file_types_props)
       
   458 
       
   459 lemma init_file_has_ctxt':
       
   460   "init_sectxt_of_obj (O_file f) = None \<Longrightarrow> \<not> is_init_file f"
       
   461 by (rule notI, drule init_file_has_ctxt, simp)
       
   462 
       
   463 lemma init_dir_has_ctxt:
       
   464   "is_init_dir f \<Longrightarrow> \<exists> sec. init_sectxt_of_obj (O_dir f) = Some sec"
       
   465 apply (simp add:init_sectxt_of_obj_def split:option.splits)
       
   466 apply (rule conjI, rule init_obj_has_user, simp add:is_init_dir_props)
       
   467 by (simp add:init_dir_types_props)
       
   468 
       
   469 lemma init_dir_has_ctxt':
       
   470   "init_sectxt_of_obj (O_dir f) = None \<Longrightarrow> \<not> is_init_dir f"
       
   471 by (rule notI, drule init_dir_has_ctxt, simp)
       
   472 
       
   473 lemma init_proc_has_ctxt:
       
   474   "p \<in> init_procs \<Longrightarrow> \<exists> sec. init_sectxt_of_obj (O_proc p) = Some sec"
       
   475 apply (simp add:init_sectxt_of_obj_def split:option.splits)
       
   476 apply (rule conjI, rule init_obj_has_user, simp)
       
   477 apply (frule init_alive_proc, drule init_obj_has_type)
       
   478 by (drule init_procrole_prop2, auto)
       
   479 
       
   480 lemma init_proc_has_ctxt':
       
   481   "init_sectxt_of_obj (O_proc p) = None \<Longrightarrow> p \<notin> init_procs"
       
   482 by (rule notI, drule init_proc_has_ctxt, simp)
       
   483 
       
   484 lemma init_fd_has_ctxt:
       
   485   "fd \<in> init_fds_of_proc p \<Longrightarrow> \<exists> sec. init_sectxt_of_obj (O_fd p fd) = Some sec"
       
   486 apply (simp add:init_sectxt_of_obj_def split:option.splits)
       
   487 apply (rule conjI, rule init_obj_has_user, simp add:is_init_dir_props)
       
   488 apply (drule init_alive_intros)
       
   489 apply (drule init_obj_has_type, clarsimp)
       
   490 done
       
   491 
       
   492 lemma init_fd_has_ctxt':
       
   493   "init_sectxt_of_obj (O_fd p fd) = None \<Longrightarrow> fd \<notin> init_fds_of_proc p"
       
   494 by (rule notI, drule init_fd_has_ctxt, simp)
       
   495 
       
   496 lemma init_node_has_ctxt:
       
   497   "n \<in> init_nodes \<Longrightarrow> \<exists> sec. init_sectxt_of_obj (O_node n) = Some sec"
       
   498 apply (simp add:init_sectxt_of_obj_def split:option.splits)
       
   499 apply (rule conjI, rule init_obj_has_user, simp add:is_init_dir_props)
       
   500 apply (drule init_alive_intros)
       
   501 apply (drule init_obj_has_type, clarsimp)
       
   502 done
       
   503 
       
   504 lemma init_node_has_ctxt':
       
   505   "init_sectxt_of_obj (O_node n) = None \<Longrightarrow> n \<notin> init_nodes"
       
   506 by (rule notI, drule init_node_has_ctxt, simp)
       
   507 
       
   508 lemma init_tcp_has_ctxt:
       
   509   "is_init_tcp_sock s \<Longrightarrow> \<exists> sec. init_sectxt_of_obj (O_tcp_sock s) = Some sec"
       
   510 apply (simp add:init_sectxt_of_obj_def split:option.splits)
       
   511 apply (rule conjI, rule init_obj_has_user, simp add:is_init_dir_props)
       
   512 apply (drule init_alive_intros)
       
   513 apply (drule init_obj_has_type, clarsimp)
       
   514 done
       
   515 
       
   516 lemma init_tcp_has_ctxt':
       
   517   "init_sectxt_of_obj (O_tcp_sock s) = None \<Longrightarrow> \<not> is_init_tcp_sock s"
       
   518 by (rule notI, drule init_tcp_has_ctxt, simp)
       
   519 
       
   520 lemma init_udp_has_ctxt:
       
   521   "is_init_udp_sock s \<Longrightarrow> \<exists> sec. init_sectxt_of_obj (O_udp_sock s) = Some sec"
       
   522 apply (simp add:init_sectxt_of_obj_def split:option.splits)
       
   523 apply (rule conjI, rule init_obj_has_user, simp add:is_init_dir_props)
       
   524 by (drule init_alive_intros, drule init_obj_has_type, clarsimp)
       
   525 
       
   526 lemma init_udp_has_ctxt':
       
   527   "init_sectxt_of_obj (O_udp_sock s) = None \<Longrightarrow> \<not> is_init_udp_sock s"
       
   528 by (rule notI, drule init_udp_has_ctxt, simp)
       
   529 
       
   530 lemma init_msgq_has_ctxt:
       
   531   "q \<in> init_msgqs \<Longrightarrow> \<exists> sec. init_sectxt_of_obj (O_msgq q) = Some sec"
       
   532 apply (simp add:init_sectxt_of_obj_def split:option.splits)
       
   533 apply (rule conjI, rule init_obj_has_user, simp add:is_init_dir_props)
       
   534 by (drule init_alive_intros, drule init_obj_has_type, clarsimp)
       
   535 
       
   536 lemma init_msgq_has_ctxt':
       
   537   "init_sectxt_of_obj (O_msgq q) = None \<Longrightarrow> q \<notin> init_msgqs"
       
   538 by (rule notI, drule init_msgq_has_ctxt, simp)
       
   539 
       
   540 lemma init_msg_has_ctxt:
       
   541   "\<lbrakk>m \<in> set (init_msgs_of_queue q); q \<in> init_msgqs\<rbrakk> \<Longrightarrow> \<exists> sec. init_sectxt_of_obj (O_msg q m) = Some sec"
       
   542 apply (simp add:init_sectxt_of_obj_def split:option.splits)
       
   543 apply (rule conjI, rule init_obj_has_user, simp add:is_init_dir_props)
       
   544 by (drule init_alive_intros, simp, drule init_obj_has_type, clarsimp)
       
   545 
       
   546 lemma init_msg_has_ctxt':
       
   547   "init_sectxt_of_obj (O_msg q m) = None \<Longrightarrow> m \<notin> set (init_msgs_of_queue q) \<or> q \<notin> init_msgqs"
       
   548 by (auto dest:init_msg_has_ctxt)
       
   549 
       
   550 lemma init_rootf_has_ctxt:
       
   551   "\<exists> sec. init_sectxt_of_obj (O_dir []) = Some sec"
       
   552 apply (rule init_dir_has_ctxt, simp add:is_init_dir_def split:option.splits)
       
   553 using root_is_dir by auto
       
   554 
       
   555 lemma init_rootf_has_ctxt':
       
   556   "init_sectxt_of_obj (O_dir []) = None \<Longrightarrow> False" 
       
   557 using init_rootf_has_ctxt by auto
       
   558 
       
   559 lemmas init_has_ctxt = init_file_has_ctxt init_dir_has_ctxt init_proc_has_ctxt init_fd_has_ctxt
       
   560   init_node_has_ctxt init_tcp_has_ctxt init_udp_has_ctxt init_msgq_has_ctxt
       
   561   init_msg_has_ctxt init_rootf_has_ctxt
       
   562 
       
   563 lemmas init_has_ctxt' = init_file_has_ctxt' init_dir_has_ctxt' init_proc_has_ctxt' init_fd_has_ctxt'
       
   564   init_node_has_ctxt' init_tcp_has_ctxt' init_udp_has_ctxt' init_msgq_has_ctxt'
       
   565   init_msg_has_ctxt' init_rootf_has_ctxt'
       
   566 
       
   567 lemma sec_of_root_valid:
       
   568   "init_sectxt_of_obj (O_dir []) = Some sec_of_root"
       
   569 using init_rootf_has_ctxt
       
   570 by (auto simp:init_sectxt_of_obj_def sec_of_root_def split:option.splits)
       
   571 
       
   572 lemma sec_of_root_is_tuple:
       
   573   "\<exists> u t. sec_of_root = (u, R_object, t)"
       
   574 using sec_of_root_valid
       
   575 by (auto simp:sec_of_root_def init_sectxt_of_obj_def split:option.splits)
       
   576 
       
   577 lemma sroot_valid:
       
   578   "init_cf2sfile [] = Some sroot"
       
   579 by (simp add:init_cf2sfile_def)
       
   580 
       
   581 lemma sroot_valid':
       
   582   "cf2sfile s [] = Some sroot"
       
   583 by (simp add:cf2sfile_def)  
       
   584 
       
   585 lemma init_sectxt_prop:
       
   586   "sectxt_of_obj [] obj = init_sectxt_of_obj obj"
       
   587 apply (auto simp:init_sectxt_of_obj_def sectxt_of_obj_def split:option.splits)
       
   588 apply (case_tac [!] obj, simp+)
       
   589 done
       
   590 
       
   591 lemma init_sectxt_prop2:
       
   592   "init_sectxt_of_obj obj = Some sec \<Longrightarrow> init_alive obj"
       
   593 by (case_tac obj, auto simp:init_sectxt_of_obj_def split:option.splits dest:init_type_has_obj)
       
   594 
       
   595 lemma init_dir_has_seclist:
       
   596   "is_init_dir f \<Longrightarrow> \<exists> seclist. get_parentfs_ctxts [] f = Some seclist"
       
   597 apply (induct f)
       
   598 apply (simp only:get_parentfs_ctxts.simps init_sectxt_prop)
       
   599 using init_rootf_has_ctxt apply (auto)[1]
       
   600 apply (frule init_parent_file_prop3', simp del:get_parentfs_ctxts.simps)
       
   601 apply (erule exE, drule init_dir_has_ctxt)
       
   602 by (auto simp add:init_sectxt_prop)
       
   603 
       
   604 lemma is_init_file_dir_prop1:
       
   605   "is_init_dir f \<Longrightarrow> \<not> is_init_file f"
       
   606 by (auto simp:is_init_dir_def is_init_file_def split:option.splits t_inode_tag.splits)
       
   607 
       
   608 lemma is_init_file_dir_prop2:
       
   609   "is_init_file f \<Longrightarrow> \<not> is_init_dir f"
       
   610 by (auto simp:is_init_dir_def is_init_file_def split:option.splits t_inode_tag.splits)
       
   611 
       
   612 lemma is_init_file_dir_prop3:
       
   613   "\<lbrakk>is_init_dir f; is_init_file f\<rbrakk> \<Longrightarrow> False"
       
   614 by (auto simp:is_init_dir_def is_init_file_def split:option.splits t_inode_tag.splits)
       
   615 
       
   616 lemma is_init_file_dir_prop4:
       
   617   "\<lbrakk>is_init_file f; is_init_dir f\<rbrakk> \<Longrightarrow> False"
       
   618 by (auto simp:is_init_dir_def is_init_file_def split:option.splits t_inode_tag.splits)
       
   619 
       
   620 lemmas is_init_file_dir_props = is_init_file_dir_prop1 is_init_file_dir_prop2 is_init_file_dir_prop3 is_init_file_dir_prop4
       
   621 
       
   622 lemma init_dir_has_sfile:
       
   623   "is_init_dir f \<Longrightarrow> \<exists> sf. init_cf2sfile f = Some sf"
       
   624 apply (case_tac f)
       
   625 using init_rootf_has_ctxt apply (auto)[1]
       
   626 apply (simp add:sec_of_root_valid sroot_valid sroot_def)
       
   627 apply (simp, frule init_parent_file_prop3')
       
   628 apply (frule_tac f = list in init_dir_has_seclist)
       
   629 apply (frule_tac f = list in init_dir_has_ctxt)
       
   630 apply (frule_tac f = "a # list" in init_dir_has_ctxt)
       
   631 apply ((erule exE)+, case_tac sec, auto simp:init_cf2sfile_def split:option.splits)
       
   632 by (auto simp:is_init_file_def is_init_dir_def split:option.splits t_inode_tag.splits)
       
   633 
       
   634 lemma init_file_has_sfile:
       
   635   "is_init_file f \<Longrightarrow> \<exists> sf. init_cf2sfile f = Some sf"
       
   636 apply (case_tac f)
       
   637 apply (simp, drule root_is_init_dir', simp)
       
   638 apply (simp, frule init_parent_file_prop2')
       
   639 apply (frule_tac f = list in init_dir_has_seclist)
       
   640 apply (frule_tac f = list in init_dir_has_ctxt)
       
   641 apply (frule_tac f = "a # list" in init_file_has_ctxt)
       
   642 by ((erule exE)+, case_tac sec, auto simp:init_cf2sfile_def)
       
   643 
       
   644 lemma init_proc_has_sproc:
       
   645   "p \<in> init_procs \<Longrightarrow> \<exists> sp. init_cp2sproc p = Some sp"
       
   646 apply (frule init_proc_has_ctxt, erule exE)
       
   647 apply (simp add:init_cp2sproc_def)
       
   648 by (case_tac sec, simp+)
       
   649 
       
   650 lemma init_cqm2sms_has_sms_aux:
       
   651   "\<forall> m \<in> set ms. init_sectxt_of_obj (O_msg q m) \<noteq> None \<Longrightarrow> (\<exists> sms. init_cqm2sms q ms = Some sms)"
       
   652 by (induct ms, auto split:option.splits simp:init_cm2smsg_def)
       
   653 
       
   654 lemma init_cqm2sms_has_sms: 
       
   655   "q \<in> init_msgqs \<Longrightarrow> \<exists> sms. init_cqm2sms q (init_msgs_of_queue q) = Some sms"
       
   656 apply (rule init_cqm2sms_has_sms_aux)
       
   657 using init_msg_has_ctxt by auto
       
   658 
       
   659 lemma init_msgq_has_smsgq:
       
   660   "q \<in> init_msgqs \<Longrightarrow> \<exists> sq. init_cq2smsgq q = Some sq"
       
   661 apply (frule init_msgq_has_ctxt, erule exE, drule init_cqm2sms_has_sms, erule exE)
       
   662 apply (simp add:init_cq2smsgq_def)
       
   663 by (case_tac sec, simp+)
       
   664 
       
   665 lemma cf2sfile_nil_prop:
       
   666   "f \<in> init_files \<Longrightarrow> cf2sfile [] f = init_cf2sfile f"
       
   667 apply (case_tac f)
       
   668 apply (simp add:init_sectxt_prop cf2sfile_def init_cf2sfile_def)
       
   669 apply (auto simp:init_sectxt_prop cf2sfile_def init_cf2sfile_def split:option.splits dest!:init_has_ctxt')
       
   670 apply (auto simp:is_init_file_def is_init_dir_def is_file_nil split:option.splits t_inode_tag.splits 
       
   671             dest:init_file_has_inum inof_has_file_tag)
       
   672 done
       
   673 
       
   674 lemma init_sec_file_dir:
       
   675   "\<lbrakk>init_sectxt_of_obj (O_file f) = Some x; init_sectxt_of_obj (O_dir f) = Some y\<rbrakk> \<Longrightarrow> False"
       
   676 apply (drule init_sectxt_prop2)+
       
   677 apply (auto intro:init_file_dir_conflict)
       
   678 done
       
   679 
       
   680 lemma cf2sfile_nil_prop3:
       
   681   "is_init_file f \<Longrightarrow> cf2sfile [] f = init_cf2sfile f"
       
   682 by (simp add:is_init_file_prop1 cf2sfile_nil_prop)
       
   683 
       
   684 lemma cf2sfile_nil_prop4:
       
   685   "is_init_dir f \<Longrightarrow> cf2sfile [] f = init_cf2sfile f"
       
   686 apply (frule init_file_dir_conflict2)
       
   687 by (simp add:is_init_file_prop1 is_init_dir_prop1 cf2sfile_nil_prop)
       
   688 
       
   689 lemma cfd2sfd_nil_prop:
       
   690   "init_file_of_proc_fd p fd = Some f \<Longrightarrow> cfd2sfd [] p fd = init_cfd2sfd p fd"
       
   691 apply (simp add:cfd2sfd_def init_sectxt_prop init_cfd2sfd_def)
       
   692 apply (frule init_filefd_prop5, drule init_filefd_prop1, drule cf2sfile_nil_prop)
       
   693 by (auto split:option.splits)
       
   694 
       
   695 lemma cpfd2sfds_nil_prop:
       
   696   "cpfd2sfds [] p = init_cfds2sfds p"
       
   697 apply (simp only:cpfd2sfds_def init_cfds2sfds_def proc_file_fds_def init_proc_file_fds_def)
       
   698 apply (rule set_eqI, rule iffI)
       
   699 apply (drule CollectD, erule bexE, drule CollectD, erule exE)
       
   700 apply (rule CollectI, rule_tac x = fd in bexI) defer
       
   701 apply (rule CollectI, rule_tac x = f in exI, simp)
       
   702 apply (drule CollectD, erule bexE, drule CollectD, erule exE)
       
   703 apply (rule CollectI, rule_tac x = fd in bexI) defer
       
   704 apply (rule CollectI, rule_tac x = f in exI)
       
   705 using cfd2sfd_nil_prop 
       
   706 by auto
       
   707 
       
   708 lemma cp2sproc_nil_prop:
       
   709   "p \<in> init_procs \<Longrightarrow> cp2sproc [] p = init_cp2sproc p"
       
   710 by (auto simp add:init_cp2sproc_def cp2sproc_def init_sectxt_prop cpfd2sfds_nil_prop
       
   711          split:option.splits)
       
   712 
       
   713 lemma msg_has_sec_imp_init: 
       
   714   "init_sectxt_of_obj (O_msg q m) = Some sec \<Longrightarrow> q \<in> init_msgqs \<and> m \<in> set (init_msgs_of_queue q)"
       
   715 apply (simp add:init_sectxt_of_obj_def split:option.splits)
       
   716 by (drule init_type_has_obj, simp)
       
   717 
       
   718 lemma msgq_has_sec_imp_init:
       
   719   "init_sectxt_of_obj (O_msgq q) = Some sec \<Longrightarrow> q \<in> init_msgqs"
       
   720 apply (simp add:init_sectxt_of_obj_def split:option.splits)
       
   721 by (drule init_type_has_obj, simp)
       
   722 
       
   723 lemma cm2smsg_nil_prop:
       
   724   "cm2smsg [] q m = init_cm2smsg q m"
       
   725 by (auto simp add:init_sectxt_prop cm2smsg_def init_cm2smsg_def split:option.splits
       
   726              dest: msg_has_sec_imp_init elim:tainted.cases)
       
   727 
       
   728 lemma cqm2sms_nil_prop:
       
   729   "cqm2sms [] q ms = init_cqm2sms q ms"
       
   730 apply (induct ms, simp)
       
   731 by (auto simp add:cm2smsg_def init_sectxt_prop tainted_nil_prop msg_has_sec_imp_init init_cm2smsg_def
       
   732          split:option.splits)
       
   733 
       
   734 lemma cq2smsga_nil_prop:
       
   735   "cq2smsgq [] q = init_cq2smsgq q"
       
   736 by (auto simp add:cq2smsgq_def init_cq2smsgq_def init_sectxt_prop cqm2sms_nil_prop
       
   737             intro:msgq_has_sec_imp_init split:option.splits)
       
   738 
       
   739 lemma co2sobj_nil_prop:
       
   740   "init_alive obj \<Longrightarrow> co2sobj [] obj = init_obj2sobj obj"
       
   741 apply (case_tac obj)
       
   742 apply (auto simp add:cf2sfile_nil_prop cq2smsga_nil_prop cqm2sms_nil_prop tainted_nil_prop 
       
   743                      cp2sproc_nil_prop is_init_dir_prop1 is_init_file_prop1
       
   744                      is_init_udp_sock_prop1 is_init_tcp_sock_prop1 
       
   745                        cm2smsg_nil_prop 
       
   746                split:option.splits)
       
   747 done
       
   748 
       
   749 lemma s2ss_nil_prop:
       
   750   "s2ss [] = init_static_state"
       
   751 using co2sobj_nil_prop init_alive_prop
       
   752 by (auto simp add:s2ss_def init_static_state_def)
       
   753 
       
   754 end
       
   755 
       
   756 (*<*)
       
   757 end
       
   758 (*>*)