lh-l4v/proof/drefine
Gerwin Klein ba38ae33ab update publications links
The links to nicta.com.au have stopped working, so the publication links
now point to the TS publication pages.

Signed-off-by: Gerwin Klein <gerwin.klein@data61.csiro.au>
2020-11-23 17:06:46 +11:00
..
base ROOT files: file reorg for new ROOT requirements 2020-10-27 15:52:31 +10:00
Arch_DR.thy drefine: Isabelle2020 update 2020-10-27 15:52:31 +10:00
CNode_DR.thy drefine: Isabelle2020 update 2020-10-27 15:52:31 +10:00
Corres_D.thy licenses: convert license tags to SPDX 2020-03-13 14:38:24 +08:00
Finalise_DR.thy drefine: Isabelle2020 update 2020-10-27 15:52:31 +10:00
Intent_DR.thy drefine: Isabelle2020 update 2020-10-27 15:52:31 +10:00
Interrupt_DR.thy licenses: convert license tags to SPDX 2020-03-13 14:38:24 +08:00
Ipc_DR.thy drefine: Isabelle2020 update 2020-10-27 15:52:31 +10:00
KHeap_DR.thy drefine: Isabelle2020 update 2020-10-27 15:52:31 +10:00
Lemmas_D.thy licenses: convert license tags to SPDX 2020-03-13 14:38:24 +08:00
MoreCorres.thy licenses: convert license tags to SPDX 2020-03-13 14:38:24 +08:00
MoreHOL.thy licenses: convert license tags to SPDX 2020-03-13 14:38:24 +08:00
README.md update publications links 2020-11-23 17:06:46 +11:00
Refine_D.thy drefine, infoflow: remove interrupt/irq from p_monad 2020-10-25 13:15:00 +11:00
Schedule_DR.thy drefine: Isabelle2020 update 2020-10-27 15:52:31 +10:00
StateTranslationProofs_DR.thy drefine: Isabelle2020 update 2020-10-27 15:52:31 +10:00
StateTranslation_D.thy drefine: Isabelle2020 update 2020-10-27 15:52:31 +10:00
Syscall_DR.thy drefine: Isabelle2020 update 2020-10-27 15:52:31 +10:00
Tcb_DR.thy drefine: Isabelle2020 update 2020-10-27 15:52:31 +10:00
Untyped_DR.thy drefine: Isabelle2020 update 2020-10-27 15:52:31 +10:00

README.md

CapDL Refinement Proof

This proof establishes that seL4's abstract specification is a formal refinement (i.e. a correct implementation) of its capDL specification. It is described as part of an ICFEM '13 paper.

Building

To build from the l4v/ directory, run:

./isabelle/bin/isabelle build -d . -v -b DRefine

Important Theories

The top-level theory where the refinement statement is established over the entire kernel is Refine_D; the state-relation that relates the state-spaces of the two specifications is defined in StateTranslation_D and the basic correspondence property proved over each kernel function is defined in Corres_D.