pub struct Tree<T: TreeNodeValue<L>, const N: usize, const L: usize> {
pub root: TreeNode<T, N, L>,
}Fields§
§root: TreeNode<T, N, L>Implementations§
Source§impl<T: TreeNodeValue<L>, const N: usize, const L: usize> Tree<T, N, L>
impl<T: TreeNodeValue<L>, const N: usize, const L: usize> Tree<T, N, L>
Sourcepub open spec fn inv(self) -> bool
pub open spec fn inv(self) -> bool
{
&&& L > 0
&&& N > 0
&&& self.root.inv()
&&& self.root.level() == 0
}Sourcepub broadcast proof fn lemma_new_preserves_inv()
pub broadcast proof fn lemma_new_preserves_inv()
requires
N > 0,L > 0,forall |i: int| 0 <= i < N ==> #[trigger] T::default(0).rel_children(i, None),ensures(#[trigger] Self::new()).inv(),Sourcepub open spec fn insert(self, path: TreePath<N>, node: TreeNode<T, N, L>) -> Self
pub open spec fn insert(self, path: TreePath<N>, node: TreeNode<T, N, L>) -> Self
recommends
self.inv(),path.inv(),node.inv(),path.len() < L,node.level() == path.len() as nat,{
Tree {
root: self.root.recursive_insert(path, node),
..self
}
}Sourcepub open spec fn remove(self, path: TreePath<N>) -> Self
pub open spec fn remove(self, path: TreePath<N>) -> Self
recommends
self.inv(),path.inv(),path.len() < L,{
Tree {
root: self.root.recursive_remove(path),
..self
}
}Sourcepub open spec fn visit(self, path: TreePath<N>) -> Seq<TreeNode<T, N, L>>
pub open spec fn visit(self, path: TreePath<N>) -> Seq<TreeNode<T, N, L>>
recommends
self.inv(),path.inv(),path.len() < L,{ self.root.recursive_visit(path) }Sourcepub open spec fn trace(self, path: TreePath<N>) -> Seq<T>
pub open spec fn trace(self, path: TreePath<N>) -> Seq<T>
recommends
self.inv(),path.inv(),path.len() < L,{ self.root.recursive_trace(path) }Sourcepub broadcast proof fn lemma_trace_empty_is_head(self, path: TreePath<N>)
pub broadcast proof fn lemma_trace_empty_is_head(self, path: TreePath<N>)
requires
path.len() == 0,ensures#[trigger] self.trace(path) == seq![self.root.value()],Sourcepub proof fn lemma_trace_up_to(self, path1: TreePath<N>, path2: TreePath<N>, n: int)
pub proof fn lemma_trace_up_to(self, path1: TreePath<N>, path2: TreePath<N>, n: int)
requires
self.inv(),path1.inv(),path2.inv(),n <= path1.len(),n <= path2.len(),forall |i: int| 0 <= i < n ==> path1.0[i] == path2.0[i],self.trace(path1).len() > n,ensuresself.trace(path2).len() > n,forall |i: int| 0 <= i <= n ==> self.trace(path1)[i] == self.trace(path2)[i],Sourcepub broadcast proof fn lemma_trace_length(self, path: TreePath<N>)
pub broadcast proof fn lemma_trace_length(self, path: TreePath<N>)
requires
self.inv(),path.inv(),ensures#[trigger] self.trace(path).len() <= path.len() + 1,Sourcepub open spec fn seek(self, path: TreePath<N>) -> Option<TreeNode<T, N, L>>
pub open spec fn seek(self, path: TreePath<N>) -> Option<TreeNode<T, N, L>>
{ self.root.recursive_seek(path) }Sourcepub proof fn lemma_seek_trace_length(self, path: TreePath<N>)
pub proof fn lemma_seek_trace_length(self, path: TreePath<N>)
requires
self.inv(),path.inv(),path.len() < L,self.seek(path) is Some,ensuresself.trace(path).len() == path.len() + 1,Sourcepub proof fn lemma_seek_trace_next(self, path: TreePath<N>, idx: usize)
pub proof fn lemma_seek_trace_next(self, path: TreePath<N>, idx: usize)
requires
self.seek(path) is Some,self.seek(path)->0.has_child(idx as int),self.inv(),path.inv(),path.len() < L,0 <= idx < N,ensuresself.trace(path.push_tail(idx as int)).len() == path.len() + 2,self.seek(path)->0.child(idx as int).value()
== self.trace(path.push_tail(idx as int))[path.len() as int + 1],Sourcepub broadcast proof fn lemma_insert_preserves_inv(
self,
path: TreePath<N>,
node: TreeNode<T, N, L>,
)
pub broadcast proof fn lemma_insert_preserves_inv( self, path: TreePath<N>, node: TreeNode<T, N, L>, )
requires
self.inv(),path.inv(),node.inv(),path.len() < L,node.level() == path.len() as nat,self.seek(path.pop_tail().1) is Some
==> self.seek(path.pop_tail().1)->0
.value()
.rel_children(path[path.len() - 1] as int, Some(node.value())),self.seek(path.pop_tail().1) is None
==> T::default((path.len() - 1) as nat)
.rel_children(path[path.len() - 1] as int, Some(node.value())),forall |lv: nat, i: int| {
lv < L ==> (0 <= i < N ==> #[trigger] T::default(lv).rel_children(i, None))
},ensures(#[trigger] self.insert(path, node)).inv(),Sourcepub broadcast proof fn lemma_remove_preserves_inv(self, path: TreePath<N>)
pub broadcast proof fn lemma_remove_preserves_inv(self, path: TreePath<N>)
requires
self.inv(),path.inv(),path.len() < L,path.len() > 0
==> (self.seek(path.pop_tail().1) is Some
==> self.seek(path.pop_tail().1)->0.children()[path.pop_tail().0 as int] is None
|| self.seek(path.pop_tail().1)->0
.value()
.rel_children(path[path.len() - 1] as int, None)),ensures(#[trigger] self.remove(path)).inv(),Sourcepub broadcast proof fn lemma_visited_nodes_inv(self, path: TreePath<N>)
pub broadcast proof fn lemma_visited_nodes_inv(self, path: TreePath<N>)
requires
self.inv(),path.inv(),path.len() < L,ensuresforall |i: int| 0 <= i < self.visit(path).len() ==> #[trigger] self.visit(path)[i].inv(),Sourcepub open spec fn on_tree(self, node: TreeNode<T, N, L>) -> bool
pub open spec fn on_tree(self, node: TreeNode<T, N, L>) -> bool
recommends
self.inv(),node.inv(),{ self.root.on_subtree(node) }Sourcepub broadcast proof fn lemma_on_tree_property(self, node: TreeNode<T, N, L>)
pub broadcast proof fn lemma_on_tree_property(self, node: TreeNode<T, N, L>)
requires
self.inv(),node.inv(),#[trigger] self.on_tree(node),ensuresnode.level() == 0 ==> self.root == node,node.level() > 0
==> exists |path: TreePath<N>| {
#[trigger] path.inv() && path.len() == node.level()
&& self.visit(path).last() == node
},Sourcepub broadcast proof fn lemma_not_on_tree_property(self, node: TreeNode<T, N, L>)
pub broadcast proof fn lemma_not_on_tree_property(self, node: TreeNode<T, N, L>)
requires
self.inv(),node.inv(),!#[trigger] self.on_tree(node),ensuresnode != self.root,node.level() > 0
==> forall |path: TreePath<N>| {
#[trigger] path.inv() && path.len() == node.level()
==> self.visit(path).last() != node
},Sourcepub open spec fn get_path(self, node: TreeNode<T, N, L>) -> TreePath<N>
pub open spec fn get_path(self, node: TreeNode<T, N, L>) -> TreePath<N>
recommends
self.inv(),node.inv(),self.on_tree(node),{ path_between::<T, N, L>(self.root, node) }Sourcepub broadcast proof fn lemma_get_path_properties(self, node: TreeNode<T, N, L>)
pub broadcast proof fn lemma_get_path_properties(self, node: TreeNode<T, N, L>)
requires
self.inv(),node.inv(),self.on_tree(node),ensures(#[trigger] self.get_path(node)).inv(),self.get_path(node).len() == node.level(),node.level() == 0 ==> self.get_path(node).is_empty(),node.level() > 0 ==> self.visit(self.get_path(node)).last() == node,Auto Trait Implementations§
impl<T, const N: usize, const L: usize> Freeze for Tree<T, N, L>where
T: Freeze,
impl<T, const N: usize, const L: usize> RefUnwindSafe for Tree<T, N, L>where
T: RefUnwindSafe,
impl<T, const N: usize, const L: usize> Send for Tree<T, N, L>where
T: Send,
impl<T, const N: usize, const L: usize> Sync for Tree<T, N, L>where
T: Sync,
impl<T, const N: usize, const L: usize> Unpin for Tree<T, N, L>where
T: Unpin,
impl<T, const N: usize, const L: usize> UnsafeUnpin for Tree<T, N, L>where
T: UnsafeUnpin,
impl<T, const N: usize, const L: usize> UnwindSafe for Tree<T, N, L>where
T: UnwindSafe,
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
Mutably borrows from an owned value. Read more
§impl<T> Conv for T
impl<T> Conv for T
§impl<T> FmtForward for T
impl<T> FmtForward for T
§fn fmt_binary(self) -> FmtBinary<Self>where
Self: Binary,
fn fmt_binary(self) -> FmtBinary<Self>where
Self: Binary,
Causes
self to use its Binary implementation when Debug-formatted.§fn fmt_display(self) -> FmtDisplay<Self>where
Self: Display,
fn fmt_display(self) -> FmtDisplay<Self>where
Self: Display,
Causes
self to use its Display implementation when
Debug-formatted.§fn fmt_lower_exp(self) -> FmtLowerExp<Self>where
Self: LowerExp,
fn fmt_lower_exp(self) -> FmtLowerExp<Self>where
Self: LowerExp,
Causes
self to use its LowerExp implementation when
Debug-formatted.§fn fmt_lower_hex(self) -> FmtLowerHex<Self>where
Self: LowerHex,
fn fmt_lower_hex(self) -> FmtLowerHex<Self>where
Self: LowerHex,
Causes
self to use its LowerHex implementation when
Debug-formatted.§fn fmt_octal(self) -> FmtOctal<Self>where
Self: Octal,
fn fmt_octal(self) -> FmtOctal<Self>where
Self: Octal,
Causes
self to use its Octal implementation when Debug-formatted.§fn fmt_pointer(self) -> FmtPointer<Self>where
Self: Pointer,
fn fmt_pointer(self) -> FmtPointer<Self>where
Self: Pointer,
Causes
self to use its Pointer implementation when
Debug-formatted.§fn fmt_upper_exp(self) -> FmtUpperExp<Self>where
Self: UpperExp,
fn fmt_upper_exp(self) -> FmtUpperExp<Self>where
Self: UpperExp,
Causes
self to use its UpperExp implementation when
Debug-formatted.§fn fmt_upper_hex(self) -> FmtUpperHex<Self>where
Self: UpperHex,
fn fmt_upper_hex(self) -> FmtUpperHex<Self>where
Self: UpperHex,
Causes
self to use its UpperHex implementation when
Debug-formatted.§fn fmt_list(self) -> FmtList<Self>where
&'a Self: for<'a> IntoIterator,
fn fmt_list(self) -> FmtList<Self>where
&'a Self: for<'a> IntoIterator,
Formats each item in a sequence. Read more
§impl<T, VERUS_SPEC__A> FromSpec<T> for VERUS_SPEC__Awhere
VERUS_SPEC__A: From<T>,
impl<T, VERUS_SPEC__A> FromSpec<T> for VERUS_SPEC__Awhere
VERUS_SPEC__A: From<T>,
fn obeys_from_spec() -> bool
fn from_spec(v: T) -> VERUS_SPEC__A
§impl<T, VERUS_SPEC__A> IntoSpec<T> for VERUS_SPEC__Awhere
VERUS_SPEC__A: Into<T>,
impl<T, VERUS_SPEC__A> IntoSpec<T> for VERUS_SPEC__Awhere
VERUS_SPEC__A: Into<T>,
fn obeys_into_spec() -> bool
fn into_spec(self) -> T
§impl<T, U> IntoSpecImpl<U> for Twhere
U: From<T>,
impl<T, U> IntoSpecImpl<U> for Twhere
U: From<T>,
fn obeys_into_spec() -> bool
fn into_spec(self) -> U
§impl<T> Pipe for Twhere
T: ?Sized,
impl<T> Pipe for Twhere
T: ?Sized,
§fn pipe<R>(self, func: impl FnOnce(Self) -> R) -> Rwhere
Self: Sized,
fn pipe<R>(self, func: impl FnOnce(Self) -> R) -> Rwhere
Self: Sized,
Pipes by value. This is generally the method you want to use. Read more
§fn pipe_ref<'a, R>(&'a self, func: impl FnOnce(&'a Self) -> R) -> Rwhere
R: 'a,
fn pipe_ref<'a, R>(&'a self, func: impl FnOnce(&'a Self) -> R) -> Rwhere
R: 'a,
Borrows
self and passes that borrow into the pipe function. Read more§fn pipe_ref_mut<'a, R>(&'a mut self, func: impl FnOnce(&'a mut Self) -> R) -> Rwhere
R: 'a,
fn pipe_ref_mut<'a, R>(&'a mut self, func: impl FnOnce(&'a mut Self) -> R) -> Rwhere
R: 'a,
Mutably borrows
self and passes that borrow into the pipe function. Read more§fn pipe_borrow<'a, B, R>(&'a self, func: impl FnOnce(&'a B) -> R) -> R
fn pipe_borrow<'a, B, R>(&'a self, func: impl FnOnce(&'a B) -> R) -> R
§fn pipe_borrow_mut<'a, B, R>(
&'a mut self,
func: impl FnOnce(&'a mut B) -> R,
) -> R
fn pipe_borrow_mut<'a, B, R>( &'a mut self, func: impl FnOnce(&'a mut B) -> R, ) -> R
§fn pipe_as_ref<'a, U, R>(&'a self, func: impl FnOnce(&'a U) -> R) -> R
fn pipe_as_ref<'a, U, R>(&'a self, func: impl FnOnce(&'a U) -> R) -> R
Borrows
self, then passes self.as_ref() into the pipe function.§fn pipe_as_mut<'a, U, R>(&'a mut self, func: impl FnOnce(&'a mut U) -> R) -> R
fn pipe_as_mut<'a, U, R>(&'a mut self, func: impl FnOnce(&'a mut U) -> R) -> R
Mutably borrows
self, then passes self.as_mut() into the pipe
function.§fn pipe_deref<'a, T, R>(&'a self, func: impl FnOnce(&'a T) -> R) -> R
fn pipe_deref<'a, T, R>(&'a self, func: impl FnOnce(&'a T) -> R) -> R
Borrows
self, then passes self.deref() into the pipe function.impl<A> SpecEq<&A> for Awhere
A: ?Sized,
impl<A> SpecEq<&mut A> for Awhere
A: ?Sized,
impl<A> SpecEq<A> for Awhere
A: ?Sized,
impl<A> SpecEq<Ghost<A>> for A
impl<A> SpecEq<Tracked<A>> for A
§impl<T> Tap for T
impl<T> Tap for T
§fn tap_borrow<B>(self, func: impl FnOnce(&B)) -> Self
fn tap_borrow<B>(self, func: impl FnOnce(&B)) -> Self
Immutable access to the
Borrow<B> of a value. Read more§fn tap_borrow_mut<B>(self, func: impl FnOnce(&mut B)) -> Self
fn tap_borrow_mut<B>(self, func: impl FnOnce(&mut B)) -> Self
Mutable access to the
BorrowMut<B> of a value. Read more§fn tap_ref<R>(self, func: impl FnOnce(&R)) -> Self
fn tap_ref<R>(self, func: impl FnOnce(&R)) -> Self
Immutable access to the
AsRef<R> view of a value. Read more§fn tap_ref_mut<R>(self, func: impl FnOnce(&mut R)) -> Self
fn tap_ref_mut<R>(self, func: impl FnOnce(&mut R)) -> Self
Mutable access to the
AsMut<R> view of a value. Read more§fn tap_deref<T>(self, func: impl FnOnce(&T)) -> Self
fn tap_deref<T>(self, func: impl FnOnce(&T)) -> Self
Immutable access to the
Deref::Target of a value. Read more§fn tap_deref_mut<T>(self, func: impl FnOnce(&mut T)) -> Self
fn tap_deref_mut<T>(self, func: impl FnOnce(&mut T)) -> Self
Mutable access to the
Deref::Target of a value. Read more§fn tap_dbg(self, func: impl FnOnce(&Self)) -> Self
fn tap_dbg(self, func: impl FnOnce(&Self)) -> Self
Calls
.tap() only in debug builds, and is erased in release builds.§fn tap_mut_dbg(self, func: impl FnOnce(&mut Self)) -> Self
fn tap_mut_dbg(self, func: impl FnOnce(&mut Self)) -> Self
Calls
.tap_mut() only in debug builds, and is erased in release
builds.§fn tap_borrow_dbg<B>(self, func: impl FnOnce(&B)) -> Self
fn tap_borrow_dbg<B>(self, func: impl FnOnce(&B)) -> Self
Calls
.tap_borrow() only in debug builds, and is erased in release
builds.§fn tap_borrow_mut_dbg<B>(self, func: impl FnOnce(&mut B)) -> Self
fn tap_borrow_mut_dbg<B>(self, func: impl FnOnce(&mut B)) -> Self
Calls
.tap_borrow_mut() only in debug builds, and is erased in release
builds.§fn tap_ref_dbg<R>(self, func: impl FnOnce(&R)) -> Self
fn tap_ref_dbg<R>(self, func: impl FnOnce(&R)) -> Self
Calls
.tap_ref() only in debug builds, and is erased in release
builds.§fn tap_ref_mut_dbg<R>(self, func: impl FnOnce(&mut R)) -> Self
fn tap_ref_mut_dbg<R>(self, func: impl FnOnce(&mut R)) -> Self
Calls
.tap_ref_mut() only in debug builds, and is erased in release
builds.§fn tap_deref_dbg<T>(self, func: impl FnOnce(&T)) -> Self
fn tap_deref_dbg<T>(self, func: impl FnOnce(&T)) -> Self
Calls
.tap_deref() only in debug builds, and is erased in release
builds.