array initialization with a function









up vote
1
down vote

favorite












method arrayFromSeq<T(0)> (s: seq<T>) returns (a:array<T>)
ensures a[..] == s
ensures fresh(a)
];
//forall i


I would like to substitute the first two lines in the body by the third one, in order to avoid the qualifier (0) in type T, but it raises an "index out of range" error.










share|improve this question

























    up vote
    1
    down vote

    favorite












    method arrayFromSeq<T(0)> (s: seq<T>) returns (a:array<T>)
    ensures a[..] == s
    ensures fresh(a)
    ];
    //forall i


    I would like to substitute the first two lines in the body by the third one, in order to avoid the qualifier (0) in type T, but it raises an "index out of range" error.










    share|improve this question























      up vote
      1
      down vote

      favorite









      up vote
      1
      down vote

      favorite











      method arrayFromSeq<T(0)> (s: seq<T>) returns (a:array<T>)
      ensures a[..] == s
      ensures fresh(a)
      ];
      //forall i


      I would like to substitute the first two lines in the body by the third one, in order to avoid the qualifier (0) in type T, but it raises an "index out of range" error.










      share|improve this question













      method arrayFromSeq<T(0)> (s: seq<T>) returns (a:array<T>)
      ensures a[..] == s
      ensures fresh(a)
      ];
      //forall i


      I would like to substitute the first two lines in the body by the third one, in order to avoid the qualifier (0) in type T, but it raises an "index out of range" error.







      arrays initialization dafny






      share|improve this question













      share|improve this question











      share|improve this question




      share|improve this question










      asked Nov 9 at 11:50









      Paqui Lucio

      163




      163






















          1 Answer
          1






          active

          oldest

          votes

















          up vote
          0
          down vote













          You can use this modified version of the third line instead



          a := new T[|s|] (i requires 0 <= i < |s| => s[i]);


          The reason that your version of the third line doesn't work is that Dafny verifies anonymous functions separately from their context. By looking at the function i => s[i] in isolation, Dafny is worried that i might be out of bounds.



          The fix is to introduce a precondition to this anonymous function, which is what I showed above. Now, when looking at the function in isolation, the precondition guarantees that the index will be in bounds.



          Separately, Dafny has to check that this precondition is satisfied by the use of the function. This check passes, because Dafny knows that array initialization new T[|s|] will only call the function on arguments that are between 0 and |s|.






          share|improve this answer




















            Your Answer






            StackExchange.ifUsing("editor", function ()
            StackExchange.using("externalEditor", function ()
            StackExchange.using("snippets", function ()
            StackExchange.snippets.init();
            );
            );
            , "code-snippets");

            StackExchange.ready(function()
            var channelOptions =
            tags: "".split(" "),
            id: "1"
            ;
            initTagRenderer("".split(" "), "".split(" "), channelOptions);

            StackExchange.using("externalEditor", function()
            // Have to fire editor after snippets, if snippets enabled
            if (StackExchange.settings.snippets.snippetsEnabled)
            StackExchange.using("snippets", function()
            createEditor();
            );

            else
            createEditor();

            );

            function createEditor()
            StackExchange.prepareEditor(
            heartbeatType: 'answer',
            convertImagesToLinks: true,
            noModals: true,
            showLowRepImageUploadWarning: true,
            reputationToPostImages: 10,
            bindNavPrevention: true,
            postfix: "",
            imageUploader:
            brandingHtml: "Powered by u003ca class="icon-imgur-white" href="https://imgur.com/"u003eu003c/au003e",
            contentPolicyHtml: "User contributions licensed under u003ca href="https://creativecommons.org/licenses/by-sa/3.0/"u003ecc by-sa 3.0 with attribution requiredu003c/au003e u003ca href="https://stackoverflow.com/legal/content-policy"u003e(content policy)u003c/au003e",
            allowUrls: true
            ,
            onDemand: true,
            discardSelector: ".discard-answer"
            ,immediatelyShowMarkdownHelp:true
            );



            );













             

            draft saved


            draft discarded


















            StackExchange.ready(
            function ()
            StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fstackoverflow.com%2fquestions%2f53225213%2farray-initialization-with-a-function%23new-answer', 'question_page');

            );

            Post as a guest















            Required, but never shown

























            1 Answer
            1






            active

            oldest

            votes








            1 Answer
            1






            active

            oldest

            votes









            active

            oldest

            votes






            active

            oldest

            votes








            up vote
            0
            down vote













            You can use this modified version of the third line instead



            a := new T[|s|] (i requires 0 <= i < |s| => s[i]);


            The reason that your version of the third line doesn't work is that Dafny verifies anonymous functions separately from their context. By looking at the function i => s[i] in isolation, Dafny is worried that i might be out of bounds.



            The fix is to introduce a precondition to this anonymous function, which is what I showed above. Now, when looking at the function in isolation, the precondition guarantees that the index will be in bounds.



            Separately, Dafny has to check that this precondition is satisfied by the use of the function. This check passes, because Dafny knows that array initialization new T[|s|] will only call the function on arguments that are between 0 and |s|.






            share|improve this answer
























              up vote
              0
              down vote













              You can use this modified version of the third line instead



              a := new T[|s|] (i requires 0 <= i < |s| => s[i]);


              The reason that your version of the third line doesn't work is that Dafny verifies anonymous functions separately from their context. By looking at the function i => s[i] in isolation, Dafny is worried that i might be out of bounds.



              The fix is to introduce a precondition to this anonymous function, which is what I showed above. Now, when looking at the function in isolation, the precondition guarantees that the index will be in bounds.



              Separately, Dafny has to check that this precondition is satisfied by the use of the function. This check passes, because Dafny knows that array initialization new T[|s|] will only call the function on arguments that are between 0 and |s|.






              share|improve this answer






















                up vote
                0
                down vote










                up vote
                0
                down vote









                You can use this modified version of the third line instead



                a := new T[|s|] (i requires 0 <= i < |s| => s[i]);


                The reason that your version of the third line doesn't work is that Dafny verifies anonymous functions separately from their context. By looking at the function i => s[i] in isolation, Dafny is worried that i might be out of bounds.



                The fix is to introduce a precondition to this anonymous function, which is what I showed above. Now, when looking at the function in isolation, the precondition guarantees that the index will be in bounds.



                Separately, Dafny has to check that this precondition is satisfied by the use of the function. This check passes, because Dafny knows that array initialization new T[|s|] will only call the function on arguments that are between 0 and |s|.






                share|improve this answer












                You can use this modified version of the third line instead



                a := new T[|s|] (i requires 0 <= i < |s| => s[i]);


                The reason that your version of the third line doesn't work is that Dafny verifies anonymous functions separately from their context. By looking at the function i => s[i] in isolation, Dafny is worried that i might be out of bounds.



                The fix is to introduce a precondition to this anonymous function, which is what I showed above. Now, when looking at the function in isolation, the precondition guarantees that the index will be in bounds.



                Separately, Dafny has to check that this precondition is satisfied by the use of the function. This check passes, because Dafny knows that array initialization new T[|s|] will only call the function on arguments that are between 0 and |s|.







                share|improve this answer












                share|improve this answer



                share|improve this answer










                answered Nov 9 at 19:40









                James Wilcox

                2,4901120




                2,4901120



























                     

                    draft saved


                    draft discarded















































                     


                    draft saved


                    draft discarded














                    StackExchange.ready(
                    function ()
                    StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fstackoverflow.com%2fquestions%2f53225213%2farray-initialization-with-a-function%23new-answer', 'question_page');

                    );

                    Post as a guest















                    Required, but never shown





















































                    Required, but never shown














                    Required, but never shown












                    Required, but never shown







                    Required, but never shown

































                    Required, but never shown














                    Required, but never shown












                    Required, but never shown







                    Required, but never shown







                    Popular posts from this blog

                    Use pre created SQLite database for Android project in kotlin

                    Darth Vader #20

                    Ondo