【发布时间】:2021-12-26 02:22:52
【问题描述】:
我有以下问题:我必须在 Dafny 中实现一个优先级队列。我有如下界面:
trait PQSpec {
var nrOfElements: int;
var capacity: int;
var contents: array<int>;
var priorities: array<int>;
predicate Valid()
reads this
{
0 <= nrOfElements <= capacity &&
capacity == contents.Length &&
capacity == priorities.Length
}
method isEmpty() returns (b: bool)
requires capacity > 0
{
return nrOfElements > 0;
}
我没有在特征中插入抽象方法,因为它们与我的问题无关
nrOfElements - 将保存优先级队列中的元素数量
容量 - 将保存可以存储的最大元素数
contents 将保存值
priorities 将保留优先级
有效 - 应该确保我的优先级队列在 nrOfElements 和容量方面是有效的(或者至少我希望我这样做)
问题出在下面这段代码:
class PQImpl extends PQSpec{
constructor (aCapacity: int)
requires aCapacity > 0
ensures Valid(){
contents := new int[aCapacity](_ => 1);
priorities := new int[aCapacity](_ => -1);
nrOfElements:= 0;
capacity := aCapacity;
}
method eliminateElementAtIndexFromArray(indexOfElementToBeEliminated: int)
modifies this
requires Valid()
requires indexOfElementToBeEliminated < nrOfElements
requires indexOfElementToBeEliminated < capacity
requires nrOfElements <= capacity
requires nrOfElements > 0
ensures Valid()
{
var copyOfContents := new int[capacity](_ => 0);
var copyOfPriorities := new int[capacity](_ => -1);
var currentIndex := 0;
var indexOfCopy := 0;
while(currentIndex < nrOfElements )
decreases nrOfElements - currentIndex
invariant currentIndex + 1 <= capacity
invariant indexOfCopy + 1 <= capacity
invariant indexOfElementToBeEliminated < nrOfElements
{
assert nrOfElements <= capacity
assert currentIndex <= nrOfElements + 1;
assert indexOfCopy < capacity;
if(indexOfElementToBeEliminated != currentIndex){
copyOfContents[indexOfCopy] := contents[currentIndex];
copyOfPriorities[indexOfCopy] := priorities[currentIndex];
indexOfCopy:=indexOfCopy+1;
}
currentIndex:=currentIndex+1;
}
contents := copyOfContents;
priorities := copyOfPriorities;
nrOfElements := nrOfElements - 1;
}
我尝试做的是从数组中删除在给定索引处找到的元素。这样做的方法是简单地创建一个新数组而不包含该值。但是,每当我在 while 中进行分配时,都会遇到索引越界错误。
任何帮助将不胜感激!
【问题讨论】:
标签: dafny formal-verification induction