https://gitlab.com/nomadic-labs/mi-cho-coq
Tip revision: 416793b544257750fdc08474933a5c139fe3e056 authored by Yann Regis-Gianas on 08 March 2021, 10:11:49 UTC
Dexter2/Spec: Take care of division by zero
Dexter2/Spec: Take care of division by zero
Tip revision: 416793b
dexter_verification_ep_addLiquidity.v
(* Open Source License *)
(* Copyright (c) 2019 Nomadic Labs. <contact@nomadic-labs.com> *)
(* Permission is hereby granted, free of charge, to any person obtaining a *)
(* copy of this software and associated documentation files (the "Software"), *)
(* to deal in the Software without restriction, including without limitation *)
(* the rights to use, copy, modify, merge, publish, distribute, sublicense, *)
(* and/or sell copies of the Software, and to permit persons to whom the *)
(* Software is furnished to do so, subject to the following conditions: *)
(* The above copyright notice and this permission notice shall be included *)
(* in all copies or substantial portions of the Software. *)
(* THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR *)
(* IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, *)
(* FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL *)
(* THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER *)
(* LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING *)
(* FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER *)
(* DEALINGS IN THE SOFTWARE. *)
(* Coq *)
Require Import String.
Require Import Michocoq.macros.
Import syntax.
Import comparable.
Require Import NArith.
Require Import ZArith.
Require Import Coq.Setoids.Setoid.
Require Import Coq.micromega.Lia.
From Coq Require Import Program.Tactics.
(* Mi-Cho-Coq *)
Require Import semantics.
Require Import util.
Import error.
Require List.
(* Dexter *)
Require dexter_definition.
Require dexter_spec.
Require Import dexter_util.
Require Import dexter_spec_util.
Module Spec := dexter_spec.
Module Def := dexter_definition.
Import Def.Storage.
Import Tactics.
Require Import contract_semantics.
(* It's better not to unfold compare in this proof,
* this makes it easier to use util.eqb_eq.
*)
Opaque N.mul.
Opaque N.add.
Opaque Z.modulo.
Opaque compare.
Lemma ep_addLiquidity_correct
(env : @proto_env dexter_definition.self_type)
(p : data dexter_definition.parameter_ep_addLiquidity_ty)
(sto : data dexter_definition.storage_ty)
(ret_ops : Datatypes.list (data operation))
(ret_sto : data dexter_definition.storage_ty)
(fuel : Datatypes.nat) :
(* TODO: fuel may have to be adapted to suit the entrypoint *)
400 <= fuel ->
eval_precond fuel env Def.ep_addLiquidity
(fun x => x = (ret_ops, ret_sto, tt))
(p, (sto, tt)) <->
Spec.ep_addLiquidity env p sto ret_ops ret_sto.
Proof.
intros Hfuel.
destruct_sto sto tokenPool xtzPool lqtTotal selfIsUpdatingTokenPool freezeBaker manager tokenAddress lqtAddress.
destruct p as (owner, (min_lqt_minted, (max_tokens_deposited, deadline))).
(*
* unfold Spec.ep_addLiquidity.
* unfold Spec.ep_addLiquidity_header.
*
*
* (*
* * re-order conjuncts to match spec.
* *)
* repeat rewrite and_assoc.
* repeat apply and_both_0_inv.
*
* simpl (Spec.Storage.sto_lqtTotal _).
* destruct lq_total; simpl;
* repeat fold_eval_precond;
* rewrite fold_eval_seq_precond_aux.
*
* - rewrite ep_addLiquidity_no_lqt_correct; [| lia].
*
* unfold Spec.ep_addLiquidity_no_lqt.
* ex_and_comm_intro c.
* ex_and_comm_intro x.
* intuition.
* - rewrite ep_addLiquidity_some_lqt_correct; [| lia].
*
* unfold Spec.ep_addLiquidity_some_lqt.
* ex_and_comm_intro c.
* ex_and_comm_intro x.
* intuition.
* - rewrite <- comparison_to_int_compare_gt_lt.
* apply comparison_to_int_tez_compare_lt_zero.
* - apply comparison_to_int_compare_nat_lt.
* - apply comparison_to_int_compare_nat_lt.
* - apply check_deadline_correct.
* - apply bool_false_not.
* - rewrite eqb_eq.
* reflexivity.
* - rewrite eqb_eq.
* reflexivity.
*)
Admitted.