https://github.com/EasyCrypt/easycrypt
Tip revision: 8f8c2317070b8c8d0946bdc28ed75a0606f11d12 authored by Pierre-Yves Strub on 19 July 2022, 13:48:12 UTC
Internal: EcSubst does not rely anymore on the low-level substitutions
Internal: EcSubst does not rely anymore on the low-level substitutions
Tip revision: 8f8c231
WhileSampling.ec
require import Real Distr.
type t.
op sample: t distr.
axiom sample_ll: is_lossless sample.
op test: t -> bool.
axiom pr_ntest: 0%r < mu sample (predC test).
module Sample = {
proc sample () : t = {
var r : t;
r <$ sample;
while (test r) {
r <$ sample;
}
return r;
}
}.
lemma Sample_lossless: islossless Sample.sample.
proof.
proc; seq 1: true=> //.
+ by auto=> />; exact/sample_ll.
while true (if test r then 1 else 0) 1 (mu sample (predC test))=> //.
+ by move=> _ r; case: (test r).
+ move=> ih; seq 1: true=> //.
by auto; rewrite sample_ll.
+ by auto; rewrite sample_ll.
rewrite pr_ntest=> /= z; conseq (: true ==> !test r).
+ smt().
by rnd; auto=> />.
qed.