array initialization with a function










1














method arrayFromSeq<T(0)> (s: seq<T>) returns (a:array<T>)
ensures a[..] == s
ensures fresh(a)
s


I would like to substitute the first two lines in the body by the third one, in order to avoid the qualifier (0) in type T, but it raises an "index out of range" error.










share|improve this question


























    1














    method arrayFromSeq<T(0)> (s: seq<T>) returns (a:array<T>)
    ensures a[..] == s
    ensures fresh(a)
    s


    I would like to substitute the first two lines in the body by the third one, in order to avoid the qualifier (0) in type T, but it raises an "index out of range" error.










    share|improve this question
























      1












      1








      1


      1





      method arrayFromSeq<T(0)> (s: seq<T>) returns (a:array<T>)
      ensures a[..] == s
      ensures fresh(a)
      s


      I would like to substitute the first two lines in the body by the third one, in order to avoid the qualifier (0) in type T, but it raises an "index out of range" error.










      share|improve this question













      method arrayFromSeq<T(0)> (s: seq<T>) returns (a:array<T>)
      ensures a[..] == s
      ensures fresh(a)
      s


      I would like to substitute the first two lines in the body by the third one, in order to avoid the qualifier (0) in type T, but it raises an "index out of range" error.







      arrays initialization dafny






      share|improve this question













      share|improve this question











      share|improve this question




      share|improve this question










      asked Nov 9 at 11:50









      Paqui Lucio

      163




      163






















          1 Answer
          1






          active

          oldest

          votes


















          0














          You can use this modified version of the third line instead



          a := new T[|s|] (i requires 0 <= i < |s| => s[i]);


          The reason that your version of the third line doesn't work is that Dafny verifies anonymous functions separately from their context. By looking at the function i => s[i] in isolation, Dafny is worried that i might be out of bounds.



          The fix is to introduce a precondition to this anonymous function, which is what I showed above. Now, when looking at the function in isolation, the precondition guarantees that the index will be in bounds.



          Separately, Dafny has to check that this precondition is satisfied by the use of the function. This check passes, because Dafny knows that array initialization new T[|s|] will only call the function on arguments that are between 0 and |s|.






          share|improve this answer




















            Your Answer






            StackExchange.ifUsing("editor", function ()
            StackExchange.using("externalEditor", function ()
            StackExchange.using("snippets", function ()
            StackExchange.snippets.init();
            );
            );
            , "code-snippets");

            StackExchange.ready(function()
            var channelOptions =
            tags: "".split(" "),
            id: "1"
            ;
            initTagRenderer("".split(" "), "".split(" "), channelOptions);

            StackExchange.using("externalEditor", function()
            // Have to fire editor after snippets, if snippets enabled
            if (StackExchange.settings.snippets.snippetsEnabled)
            StackExchange.using("snippets", function()
            createEditor();
            );

            else
            createEditor();

            );

            function createEditor()
            StackExchange.prepareEditor(
            heartbeatType: 'answer',
            autoActivateHeartbeat: false,
            convertImagesToLinks: true,
            noModals: true,
            showLowRepImageUploadWarning: true,
            reputationToPostImages: 10,
            bindNavPrevention: true,
            postfix: "",
            imageUploader:
            brandingHtml: "Powered by u003ca class="icon-imgur-white" href="https://imgur.com/"u003eu003c/au003e",
            contentPolicyHtml: "User contributions licensed under u003ca href="https://creativecommons.org/licenses/by-sa/3.0/"u003ecc by-sa 3.0 with attribution requiredu003c/au003e u003ca href="https://stackoverflow.com/legal/content-policy"u003e(content policy)u003c/au003e",
            allowUrls: true
            ,
            onDemand: true,
            discardSelector: ".discard-answer"
            ,immediatelyShowMarkdownHelp:true
            );



            );













            draft saved

            draft discarded


















            StackExchange.ready(
            function ()
            StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fstackoverflow.com%2fquestions%2f53225213%2farray-initialization-with-a-function%23new-answer', 'question_page');

            );

            Post as a guest















            Required, but never shown

























            1 Answer
            1






            active

            oldest

            votes








            1 Answer
            1






            active

            oldest

            votes









            active

            oldest

            votes






            active

            oldest

            votes









            0














            You can use this modified version of the third line instead



            a := new T[|s|] (i requires 0 <= i < |s| => s[i]);


            The reason that your version of the third line doesn't work is that Dafny verifies anonymous functions separately from their context. By looking at the function i => s[i] in isolation, Dafny is worried that i might be out of bounds.



            The fix is to introduce a precondition to this anonymous function, which is what I showed above. Now, when looking at the function in isolation, the precondition guarantees that the index will be in bounds.



            Separately, Dafny has to check that this precondition is satisfied by the use of the function. This check passes, because Dafny knows that array initialization new T[|s|] will only call the function on arguments that are between 0 and |s|.






            share|improve this answer

























              0














              You can use this modified version of the third line instead



              a := new T[|s|] (i requires 0 <= i < |s| => s[i]);


              The reason that your version of the third line doesn't work is that Dafny verifies anonymous functions separately from their context. By looking at the function i => s[i] in isolation, Dafny is worried that i might be out of bounds.



              The fix is to introduce a precondition to this anonymous function, which is what I showed above. Now, when looking at the function in isolation, the precondition guarantees that the index will be in bounds.



              Separately, Dafny has to check that this precondition is satisfied by the use of the function. This check passes, because Dafny knows that array initialization new T[|s|] will only call the function on arguments that are between 0 and |s|.






              share|improve this answer























                0












                0








                0






                You can use this modified version of the third line instead



                a := new T[|s|] (i requires 0 <= i < |s| => s[i]);


                The reason that your version of the third line doesn't work is that Dafny verifies anonymous functions separately from their context. By looking at the function i => s[i] in isolation, Dafny is worried that i might be out of bounds.



                The fix is to introduce a precondition to this anonymous function, which is what I showed above. Now, when looking at the function in isolation, the precondition guarantees that the index will be in bounds.



                Separately, Dafny has to check that this precondition is satisfied by the use of the function. This check passes, because Dafny knows that array initialization new T[|s|] will only call the function on arguments that are between 0 and |s|.






                share|improve this answer












                You can use this modified version of the third line instead



                a := new T[|s|] (i requires 0 <= i < |s| => s[i]);


                The reason that your version of the third line doesn't work is that Dafny verifies anonymous functions separately from their context. By looking at the function i => s[i] in isolation, Dafny is worried that i might be out of bounds.



                The fix is to introduce a precondition to this anonymous function, which is what I showed above. Now, when looking at the function in isolation, the precondition guarantees that the index will be in bounds.



                Separately, Dafny has to check that this precondition is satisfied by the use of the function. This check passes, because Dafny knows that array initialization new T[|s|] will only call the function on arguments that are between 0 and |s|.







                share|improve this answer












                share|improve this answer



                share|improve this answer










                answered Nov 9 at 19:40









                James Wilcox

                2,5001120




                2,5001120



























                    draft saved

                    draft discarded
















































                    Thanks for contributing an answer to Stack Overflow!


                    • Please be sure to answer the question. Provide details and share your research!

                    But avoid


                    • Asking for help, clarification, or responding to other answers.

                    • Making statements based on opinion; back them up with references or personal experience.

                    To learn more, see our tips on writing great answers.





                    Some of your past answers have not been well-received, and you're in danger of being blocked from answering.


                    Please pay close attention to the following guidance:


                    • Please be sure to answer the question. Provide details and share your research!

                    But avoid


                    • Asking for help, clarification, or responding to other answers.

                    • Making statements based on opinion; back them up with references or personal experience.

                    To learn more, see our tips on writing great answers.




                    draft saved


                    draft discarded














                    StackExchange.ready(
                    function ()
                    StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fstackoverflow.com%2fquestions%2f53225213%2farray-initialization-with-a-function%23new-answer', 'question_page');

                    );

                    Post as a guest















                    Required, but never shown





















































                    Required, but never shown














                    Required, but never shown












                    Required, but never shown







                    Required, but never shown

































                    Required, but never shown














                    Required, but never shown












                    Required, but never shown







                    Required, but never shown







                    Popular posts from this blog

                    𛂒𛀶,𛀽𛀑𛂀𛃧𛂓𛀙𛃆𛃑𛃷𛂟𛁡𛀢𛀟𛁤𛂽𛁕𛁪𛂟𛂯,𛁞𛂧𛀴𛁄𛁠𛁼𛂿𛀤 𛂘,𛁺𛂾𛃭𛃭𛃵𛀺,𛂣𛃍𛂖𛃶 𛀸𛃀𛂖𛁶𛁏𛁚 𛂢𛂞 𛁰𛂆𛀔,𛁸𛀽𛁓𛃋𛂇𛃧𛀧𛃣𛂐𛃇,𛂂𛃻𛃲𛁬𛃞𛀧𛃃𛀅 𛂭𛁠𛁡𛃇𛀷𛃓𛁥,𛁙𛁘𛁞𛃸𛁸𛃣𛁜,𛂛,𛃿,𛁯𛂘𛂌𛃛𛁱𛃌𛂈𛂇 𛁊𛃲,𛀕𛃴𛀜 𛀶𛂆𛀶𛃟𛂉𛀣,𛂐𛁞𛁾 𛁷𛂑𛁳𛂯𛀬𛃅,𛃶𛁼

                    Edmonton

                    Crossroads (UK TV series)