Download Adi-Sosnovich-lecture4-combination-Adi

Document related concepts

Structure (mathematical logic) wikipedia , lookup

Transcript
Deciding Combined
Theories
Presented by Adi Sosnovich
Based on presentation from:
Decision Procedures An Algorithmic Point of View
Daniel Kroening and Ofer Strichman
Outline

Introduction
 The

Theory Combination Problem
The Nelson-Oppen Combination Procedure
 Combining
convex theories
 Combining nonconvex theories
 Correctness proof

Abstract version of the procedure

Extensions

Summary
Introduction

The decision procedures we studied so far focus on
one specific theory (equality and UF, bit-vectors)

Examples for other common theories:
linear arithmetic, arrays, pointer logic.

Verification conditions frequently mix expressions
from several theories:
f(a[32], b[1]) = f(b[32], a[1]) Æ a[32] = b[32]
bit vectors and uninterpreted functions
(x2 ¸ x1) Æ (x1- x3 ¸ x2) Æ (x3 ¸ 0) Æ f(f(x1) - f(x2))  f(x3)
linear arithmetic and uninterpreted functions
Combining theories

Approach #1: Reduce all theories to a common logic, if
possible (e.g. Propositional Logic).

Approach #2: Combine decision procedures of the
individual theories.
 How?
we will learn the Nelson-Oppen method*
* Greg Nelson and Derek Oppen, simplification by cooperating decision procedures,
1979
Reminders: theories and signatures

First order logic –



First order theories –



Symbols (Boolean connectives and quantifiers over variables), Syntax
(wff-s ).
Axioms, inference rules.
Additional axioms and symbols characterizing the theory.
The signature  of a theory T holds the set of functions and predicates
of the theory.
“First order quantifier-free theories with equality” – the
equality predicate must be part of the signature.
Additional reminders

Let  be a signature.
A  -interpretation A with domain A over a set of
variables V is a map which interprets:
 Each
variable as a domain element
 Each constant as a domain element
 Each function symbol as a function of the same arity in the
domain
 Each predicate symbol of arity n as a subset of An.
Additional reminders

A formula  is satisfied by an interpretation A if it
evaluates to true under A.

If  is satisfied by A , we say that A is a model of  .

A formula  over a set of V variables is satisfiable if
it is satisfied by some interpretation over V.
Additional reminders

Given a  - theory , a T-model is a interpretation
that satisfies all axioms in T.

A formula over a set of V variables is T-satisfiable, if
it is satisfied by some T-model over V.
The Theory-Combination problem

Given theories T1 and T2 with signatures 1 and 2,
the combined theory T1 © T2
 has
signature 1 [ 2 and
 the
union of their axioms.

Let  be a 1 [ 2 formula.

The problem: Does T1 © T2 ²  ?
The problem

The Theory-Combination problem is undecidable (even when
the individual theories are decidable).

Under certain restrictions, it becomes decidable.

We will assume the following restrictions:


T1 and T2 are quantifier-free first-order theories with equality.

Disjoint signatures (other than equality): 1 Å 2 = ;

There is a decision procedure for each of the theories

T1 and T2 are theories that are interpreted over an infinite domain
(e.g. Linear arithmetic over R , but not finite-width bit vectors).
There are extensions to the basic N.O. procedure that
overcome each of these restrictions.
The Nelson-Oppen method

The Nelson-Oppen combination procedure solves the
theory combination problem for theories that comply
with the restrictions.

The input formula must be a conjunction of literals.
The Nelson-Oppen method (1)

Purification: validity-preserving transformation of
the formula after which predicates from different
theories are not mixed.
1.
Replace an `alien’ sub-expression  with a new auxiliary
variable a
2.
Constrain the formula with a = 
Transform
… into
x1· f(x1)
x1· a1 Æ a1 = f(x1)
Uninterpreted Functions
Pure expressions, shared variables
Arithmetic
Purification in more details (formal description)

For term t, let hd(t) be the root symbol.
 For

example: hd(f(x)) = f
Then for i,j ∈{1,2} and i  j, repeat the following
transformations as long as possible:
 If
function f∈ i and hd(t) ∈ j
F  f ( t1 ,..., t ,..., tn )   F  f ( t1 ,..., w,..., tn )   w = t
 If
predicate p∈ i and hd(t) ∈ j
F  p ( t1 ,..., t ,..., tn )   F  p ( t1 ,..., w,..., tn )   w = t
 If
hd(s)∈ i and hd(t) ∈ j
F s = t   F w = t   w = s
Purification – detailed example

F: x¸1 Æ 2¸x Æ f(x)  f(1) Æ f(x)  f(2)

Theories involved: TEUF and TZ

Since f ∈ EUF and 1 ∈ Z , replace f(1) by f(w1) and add
w1=1.

Similarly, replace f(2) by f(w2) and add w2=2.

Now, the literals x¸1 , 2¸x , w1=1 , w2=2 , are TZ –literals,
and the literals f(x)  f(w1) , f(x)  f(w2) are TEUF –literals

Formula after purification:

x¸1 Æ 2¸x Æ f(x)  f(w1) Æ f(x)  f(w2) Æw1=1Æw2=2
Purification – another example

F: f(x)=x+y Æ z+y ¸x Æ y¸x+z Æ y=1 Æ f(x)  f(2)

In the first literal hd(f(x))= f∈ EUF and hd(x+y) =+∈ Z ,
Thus, replace the literal with: w1=x+y Æ w1=f(x)

In the last literal, f∈ EUF but 2∈ Z , therefore replace it by
f(x)  f(w2) Æ w2=2

Formula after purification:

w1=x+y Æ z+y ¸x Æ y¸x+z Æ y=1 Æ w2=2 Æ
w1=f(x) Æ f(x)  f(w2)
The Nelson-Oppen method (2)

After purification we are left with several sets of pure
expressions F1,…,Fn such that:
 Fi
belongs to some ‘pure’ theory which we can decide.
 Shared
variables are allowed, i.e. it is possible that for
some i,j: vars(Fi) Å vars(Fj)  ;.

 is satisfiable $ F1 Æ … Æ Fn is satisfiable
 If
sati reports that any Fi is unsat, then  is unsat
 But
 We
the converse is not true in general
need a way for the decision procedures to communicate
with each other about shared variables
The Nelson-Oppen method* (3)
1.
Purify  into F1Æ … Æ Fn.
2.
If 9i. Fi is unsatisfiable, return `unsatisfiable’ .
3.
If 9i,j. Fi implies an equality not implied by Fj, add
it to Fj and goto step 2.
4.
Return `satisfiable’.
* So far only for ‘convex’ theories – to be explained
Example(1)
f(x1,0) ¸ x3 Æ f(x2,0) · x3 Æ (x1 ¸ x2) Æ (x2 ¸ x1) Æ
( x3 – f(x1,0) ¸ 1)

Purification:
a1 ¸ x3 Æ a2 · x3 Æ (x1 ¸ x2) Æ (x2 ¸ x1) Æ
( x3 – a1¸ 1) Æ a0 = 0 Æ a1 = f(x1, a0) Æ a2 = f(x2, a0)

Neither F1 nor F2 is contradictory, thus we proceed to step (3)
Example (1) – cont’d
Linear Arithmetic
EUF
a1 ¸ x3
a1 = f(x1, a0)
a2 · x3
a2 = f(x2, a0)
x1 ¸ x2
x2 ¸ x1
x3 – a1¸1
a0=0
x1 = x2
x1 = x2
a1 = a2
a1 = a2
a1 = x3
False
Example(2)
(x2 ¸ x1) Æ (x1 – x3 ¸ x2) Æ (x3 ¸ 0) Æ f(f(x1) – f(x2))  f(x3)

Purification:
(x2 ¸ x1) Æ (x1 – x3 ¸ x2) Æ (x3 ¸ 0 ) Æ f(a1)  f(x3) Æ
a 1 = a2 – a3 Æ
a2 = f(x1)
Æ
a3 = f(x2)
Æ
Example (2) – cont’d
Arithmetic
EUF
x2 ¸ x1
f(a1)  f(x3)
x1 – x3 ¸ x2
a2 = f(x1)
x3 ¸ 0
a3 = f(x2)
a1 = a2 – a3
x3 = 0
x1 = x2
x1 = x2
a2 = a3
a2 = a3
a1 = 0
a1 = x3
a1 = x3
False
Wait, it’s not so simple…

Consider: : 1 · x Æ x · 2 Æ p(x) Æ :p(1) Æ :p(2 )
x2Z
Arithmetic over Z
Uninterpreted
predicates
1 · x
p(x)
x·2
:p(1)
:p(2)

Neither theories imply an equality, and both are
satisfiable.

But  is unsatisfiable!
Some theories have it, some don’t

Definition: A theory T is convex if for all
conjunctions  it holds that
(  ! Çi=1..n xi=yi for some finite n > 1 ) 
( ! xi = yi for some i 2 {1..n})

Convex: Linear Arithmetic over R, EUF

Non-convex: Almost anything else…
Convexity: examples

Linear arithmetic over R is convex
: x1 · 1 Æ x1 ¸ 0 implies an infinite disjunction of equalities,

: x1 · 1 Æ x1 ¸ 1 ! x1 = 1
implies a singleton
: x1 · 1 Æ x1 ¸ 2
implies everything
Linear arithmetic over Z is not convex
: 1 · x1 Æ x1 · 2 Æ u = 1 Æ v = 2
Although
 ! (x1 = u Ç x1 = v)
It is not the case that  ! x1 = u Ç  ! x1 = v
Convexity: examples

The conjunctive fragment of equality logic is convex
: x1 = x2 Æ x2 = x3 Æ x5 = x3 ! x5 = x2 Ç x5 = x1
 ! x5 = x2 and
 ! x5 = x1
Many theories used in practice are in fact nonconvex.
It makes them computaionally harder to combine with other
theories.
So why is convexity important ?

Recall:
: 1 · x Æ x · 2 Æ p(x) Æ :p(1) Æ :p(2)
x2Z
Arithmetic over Z
Uninterpreted
predicates
1 · x
p(x)
x·2
:p(1)
:p(2)

Neither theories imply an equality, and both are
satisfiable.
So why is convexity important ? (cont’d)

But: 1· x Æ x · 2 imply the disjunction x = 1 Ç x = 2

Since the theory is non-convex we cannot propagate
either x=1 or x=2.

We can only propagate the disjunction itself.
So why is convexity important ? (cont’d)

Propagate the disjunction and perform case-splitting.
Arithmetic over Z
Uninterpreted
predicates
1 · x
p(x)
x·2
:p(1) Æ :p(2)
x=1Çx=2
x=1Çx=2
Split!
h¢i Æ x = 1 h¢i Æ x = 2
False
False
So why is convexity important? (cont’d)

Conclusion: when the theory is non-convex, we must
case-split.

This adds a splitting step in Nelson-Oppen.

As a result:
 Convex
theories: Polynomial
 Non-Convex theories: Exponential
The (full) Nelson-Oppen method
1.
Purify  into ’: F1Æ…Æ Fn.
2.
If 9i. Fi is unsatisfiable, return `unsatisfiable’ .
3.
If 9i,j. Fi implies an equality not implied by Fj, add it to Fj
and goto step 2.
4.
5.
If 9i. Fi ! (x1= y1Ç…Ç xk= yk) but 8j Fi 9 xj= yj,
apply recursively to ’Æ x1= y1, … ,’Æ xk= yk.
If any of them is satisfiable, return ‘satisfiable’. Otherwise
return ‘unsatisfiable’.
Return `satisfiable’.
Example(3)
Consider the ( E [ Z)-formula :
(x ¸ 1) Æ ( 3 ¸ x) Æ (f(x)  f(1)) Æ (f(x)  f(3)) Æ (f(1)  f(2))

Purification:
(x ¸ 1) Æ ( 3 ¸ x) Æ a1 =1 Æ a2 =2 Æ a3 =3 Æ
(f(x)  f(a1)) Æ (f(x)  f(a3)) Æ (f(a1)  f(a2))
Example(3)
Arithmetic over Z
Uninterpreted functions
1 · x
f(x)  f(a1)
x·3
f(x)  f(a3)
a1 =1
f(a2)  f(a1)
a2 =2
a3 =3
x = a1 Ç x = a2 Ç x = a3
x = a1 Ç x = a2 Ç x = a3
h¢i Æ x = a1
Split!
h¢i Æ x = a2
False
Neither decision procedure discovers any contradiction or new equality
Thus F is satisfiable in the combined theory
Equality Propagation

For a convex theory:
 It
is sufficient to test each equality possible of the form
x=y.
 Any equality implied should be propagated to the other
theories.

For a non-convex theory:

The procedure must find disjunction of equalities implied
by some Fk.
 The disjunctions should be as small as possible since the
N.O method must branch on each disjunct
 A disjunction is minimal if it is implied by Fk and each
smaller disjunction is not implied by Fk .
Equality Propagation

Simple procedure to find minimal disjunction:
 Observation: any
disjunction that contains a minimal
disjunction implied by Fk - is also implied by Fk .
 The


idea: strip off extra disjuncts one-by-one
Start with the disjunction of all equalities at once
Remove disjuncts that their removal preserves the implication.
Correctness is hard to prove…

Theorem: N.O. returns unsatisfiable if and only if its input
formula  is unsatisfiable.

We will prove this theorem for the case of combining two
convex theories.
The generalization is not hard.
Correctness Proof

()  is satisfiable! N.O. returns ‘satisfiable’
(That’s the simple side)

Assume  is satisfiable and let  be a satisfying assignment of .

Let A = {a1,…,an} be the purification (auxiliary) variables.

Claim: there exists an assignment to the A variables such that 
extended with this assignment satisfies F1Æ F2.
(because F1Æ F2 and  are equisatisfiable)

Let ’ be this extended assignment.
Example for the assignment extension
f(x1,0) ¸ x3 Æ f(x2,0) · x3 Æ (x1 ¸ x2) Æ (x2 ¸ x1) Æ
( x3 – f(x1,0) ¸ 0)

Purification:
a1 ¸ x3 Æ a2 · x3 Æ (x1 ¸ x2) Æ (x2 ¸ x1) Æ
( x3 – a1¸ 0) Æ a0 = 0 Æ a1 = f(x1, a0) Æ a2 = f(x2, a0)

Satisfying assignment for  :


:{ x1 ! 1, x2 !1, x3!1 }
Extended satisfying assignment:

’:{a0 ! 0, a1 ! 1,a2 ! 1, x1 ! 1, x2 !1, x3!1 }
Correctness Proof

Lemma 1:
Let  be satisfiable. After Each loop iteration F1Æ F2 is satisfiable in the
combined theory.

Proof by induction on the number of loop iterations.

Base: for iteration #0: F1,0Æ F2,0 is satisfiable (’ is the satisfying
assignment)

Induction Step: assuming correctness up to iteration j, and we shall
prove for j+1:
For any x=y added in step (3) there exists i s.t Fi,j ! x=y in Ti .
Correctness Proof


’ |= Fi,j in Ti by the Induction Hypothesis.

Fi,j ! x=y and ’ |= Fi,j implies that ’ |= x=y .

’ |= Fi,j for all i , therefore ’ |= Fi,j Æ (x=y) , in Ti , for all i.

’ |= Fi,j+1 , in Ti , for all i.
Conclusion: The algorithm will not return unsat in
step (2).
Proof ()

() If N.O. returns ‘satisfiable’,  is satisfiable.
(This will require several definition and lemmas)

Observation: The algorithm always terminates


There are only finitely many equalities over the variables in the formula
Lemma 2:
Let Fi‘ denote the formula Fi upon termination of the
algorithm. Upon termination with the answer ‘satisfiable’ , any
equality between ‘ variables that is implied by any of the Fi‘
is also implied by all Fj‘ for any j.
Proof ()

Assume falsely that  is unsat, and the algorithm returnes ‘sat’.

Let E1,…,Em be a set of equivalence classes of the variables in
 s.t x,y are in the same class iff F1’! x=y in T1

From Lemma 2, x,y are in the same class Ei iff F2’! x=y in
T2

Let ri for i in {1,…,m} be a representative element of the
class Ei .

We define a constraint ∆ as follows:
∆ = Æi≠j(ri ≠rj)
Proof ()

Lemma 3
Given that both T1 and T2 have an infinite domain and are convex, ∆ is
T1–consistent with F1’ and T2 -consistent with F2’ .

Proof Sketch

Let x and y be two variables that are not implied to be equal.

Owing to convexity, they do not have to be equal to satisfy Fi’ .

As the domain is infinite, there are always values left in the domain that
we can choose in order to make x and y different.

Owing to convexity, they do not have to be equal to satisfy Fi’
the theory was non-convex, it wouldn’t be necessarily
true
 If
 For example:
 : z · x Æ x · y Æ p(x) Æ :p(y) Æ :p(z) Æ y=2 Æ z=1


Adding ∆ to F1’ will cause a conflict
That is because the theory is not convex and a finite disjunction is
implied by F1’
 As
the domain is infinite, there are always values left in the
domain that we can choose in order to make x and y
different.
 If
the domain was finite, it wouldn’t be necessarily true
 For example:
 Consider a theory
 F1’ : g(x1)  g(x3) Æ g(x2)  g(x3)
T1 :



Adding x1  x2 to F1’ will cause a conflict
in the given theory
That is because the domain size is finite
and its size is up to 2.

1: A function g,
Axioms that only
allow solutions with
2 distinct values.
Proof ()

Conclusion from the Lemma:

There are satisfying assignments 1 and 2 for F1’ Æ ∆ and F2’ Æ ∆
in T1 and T2 , respectively.

These assignments are maximally diverse
Two variables assigned equal values by them, must be equal.
Note that 1 |= x=y iff 2 |= x=y , for every pair of variables x,y.


Given this property, it is easy to build a mapping M (an
isomorphism) from domain elements to domain elements such
that 2(x) is mapped to 1(x) for any variable x.

Not necessarily possible unless the assignments are maximally diverse.

Example
(x ¸ y) Æ (y ¸ x) Æ (z ¸ y) Æ (w ¸ z) Æ (f(z)  f(y)) Æ
(f(x)  f(w))
E2
E1
x,y
z
E3
w
Assignments that satisfy F1’ and F2’ that are not maximally diverse:
α1 = {x→1, y→1, z→1 , w→1}
α2 = {x→5, y→5, z→3 , w→4}
We cannot build here the mapping M

Example
(x ¸ y) Æ (y ¸ x) Æ (z ¸ y) Æ (w ¸ z) Æ (f(z)  f(y)) Æ
(f(x)  f(w))
E2
E1
x,y
z
E3
w
Assignments that satisfy F1’ Æ ∆ and F2’ Æ ∆ are maximally diverse:
α1 = {x→1, y→1, z→2 , w→3}
α2 = {x→5, y→5, z→3 , w→4}
We can build here a mapping M: M(1)=5, M(2)=3, M(3)=4,…

Example
(x ¸ y) Æ (y ¸ x) Æ (z ¸ y) Æ (w ¸ z) Æ (f(z)  f(y)) Æ
(f(x)  f(w))
Defining an interpretation that satisfies both F1’ Æ ∆ and F2’ Æ ∆
based on the isomorphism M:
Option 1:
If we choose the mapping : M: M(5)=1, M(3)=2, M(4)=3,…
α2 = {x→5, y→5, z→3 , w→4} z ¸ y iff M(z) ¸ M(y)
Option 2: the mapping M: M(1)=5, M(2)=3, M(3)=4,…
α1 = {x→1, y→1, z→2 , w→3} f(z) = M-1(f(M(z))
Note that we rely on the fact that the signatures are disjoint
Proof ()

Using the mapping M, we can obtain a model α’ for F1’ Æ F2’
in the combined theory.

As Fi’ implies Fi , α’ is also a model for F1 Æ F2 in the
combined theory, which contradicts our assumption that  is
unsatisfiable.
Proof - More details

Theorem 1
1 and 2 be signatures with 1 ∩  2 = Ø , and for
i=1,2 let Fi be a set of i –formulas, and Vi the set of
variables appearing in Fi. Let V = V1 ∩ V2 .
 Let
Then F1 Æ F2 is satisfiable iff there exists an
interpretation A satisfying F1 and an interpretation B
satisfying F2 such that :


|A|=|B|
xA=yA iff xB=yB for every pair of variables x,y in V

The proof is based on an isomorphism and obtaining an interpretation
satisfying F1 Æ F2

There is another theorem in logic saying that formula is satisfiable iff there
exist isomorphic interpretations satisfying the sub-formulas
Proof - More details

There exist A and B which are interpretations over
infinite domains since the theories are restricted to
infinite domains

How can we be sure that we can obtain interpretations
of the same cardinality?
Proof - More details

Theorem 2 - Löwenheim–Skolem theorem
 The
theorem states that if a countable first-order theory has
an infinite model, then for every infinite cardinal number κ
it has a model of size κ. The result implies that first-order
theories are unable to control the cardinality of their infinite
models.
 Therefore
we can obtain interpretations of the same
cardinality for infinite domains
Proof ()

Proof sketch summary:

Based on Lemma 3 there are interpretations A , B over infinite domains
satisfying F1 and F2 respectively

The assignments of the interpretations are maximally diverse and
therefore
1 |= x=y iff 2 |= x=y , for every pair of variables x,y.

Based on Theorem 2 there exist interpretations A, B of the same
infinite cardinality : |A|=|B|

Based on Theorem 1 , F1 Æ F2 is satisfiable
Correctness for convex and non-convex theories
 On
the case-splitting:

If on all branches the conjunction is unsatisfiable, then the original
formula is necessarily unsatisfiable.

If there exists a branch on which the conjunction is satisfiable, then
the original formula is satisfiable and no other branches need to be
checked.
Abstract (non-deterministic) version for the
Nelson-Oppen procedure

Let V be the set of variables used in F1 ,…,Fn .

A partition P of V induces equivalence classes

Every assignment to V’s variables induces such a
partition

Denote by R the equivalence relation corresponding
to these classes

The arrangement corresponding to P is:

ar(P) = [ÆviRvj, i<j(vi = vj) ] Æ [ƬviRvj,i<j(vi ≠vj) ]
Abstract (non-deterministic) version for the
Nelson-Oppen procedure

For example, if V={x1,x2,x3}, and
P = {{x1,x2},{x3}}
 ar(P) :=
x1=x2 Æ x1 ≠ x3 Æ x2 ≠ x3
Abstract (non-deterministic) version for the
Nelson-Oppen procedure

The abstract version of the Nelson-Oppen procedure:
1.
Purification – the same as in the deterministic version.
2.
Choose nondeterministically a partition P of V’s
variables.
3.
If one of Fi Æ ar(P) is unsatisfiable, return unsat.
Otherwise, return sat.
Abstract version - example
Consider the ( E [ Z)-formula :
F: (x ¸ 1) Æ ( 2 ¸ x) Æ (f(x)  f(1)) Æ (f(x)  f(2))
After purification we have:
F1: (f(x)  f(y)) Æ (f(x)  f(z))
F2: (x ¸ 1) Æ ( 2 ¸ x) Æ (y = 1) Æ ( z = 2)
1. {x = y , x = z , y = z }
Inconsistent with F1
2. {x = y , x  z , y  z }
Inconsistent with F1
3. {x  y , x = z , y  z }
Inconsistent with F1
4. {x  y , x  z , y = z }
Inconsistent with F2
5. {x  y , x  z , y  z }
Inconsistent with F2
Abstract (non-deterministic) version for the
Nelson-Oppen procedure

The nondeterministic step can be replaced with a
deterministic one, by trying all such partitions
possible.

The requirement in the N.O. procedure for sharing
implied equalities can be understood as optimization
over an exhaustive search, rather then a necessity for
correctness.
Abstract (non-deterministic) version for the
Nelson-Oppen procedure

Advantages of the abstract presentation:
 Abstracting implementation details (typically by
nondeterminism) is helpful for clarity, generality,
simplicity of proofs.
 Can
help in designing concrete procedures in a more
modular way
Practical efficiency of the non-deterministic method

Phase 2 is formulated as “guess and check”

The number of equivalence relations increases
significantly with the number of shared variables.

The number of equivalence relations is given by the
sequence of Bell numbers which grows superexponentially
 For
example: 12 shared variables induce over 4 million
equivalence relations
Practical efficiency of the non-deterministic method

In fact, there is no need to guess the entire
equivalence relation at once

Instead it can be constructed incrementally

In practice, implementations are based on the
deterministic method
Example for incremental “optimization” of the
nondeterministic method

(a1 = x+y) Æ (y+z ¸ x) Æ (y ¸ x+z) Æ (y=1) Æ (a2=2) Æ (a1 = f(x)) Æ
(f(x)  f(a2))

Shared variables: x,a1,a2

We attempt to construct an arrangement incrementally






Suppose x=a1 => from F1, a1 = x+y implies y=0 which contradicts
(y=1) in F1. => x  a1
F1 Æ (x  a1) and F2 Æ (x  a1) are satisfiable
Suppose x=a2 => from F2 (f(x)  f(a2)) thus contradiction => x  a2
F1 Æ (x  a1) Æ (x  a2) and F2 Æ (x  a1) Æ (x  a2) are satisfiable
Suppose a1=a2 => no contradiction exists.
We discovered the arrangement {{a1,a2},{x}}, so F is
satisfiable in the combined theory
Stably Infinite Theories

Definition: A -theory T is Stably-infinite if for every
quantifier-free -formula 
 is satisfiable ,
 can be satisfied by an interpretation with an infinite
domain.

The requirement that Ti has an infinite domain can be
generalized to the requirement that Ti is stablyinfinite.
 Correctness
of N.O. procedure is preserved for stably
infinite theories
Stably Infinite Theories

Example 1:
 Consider


the theory Ta,b with the signature {a,b,=}
a,b are constants
The axiom: for all x : (x=a) or (x=b)
 For
every T-interpretation, the domain has at most 2
elements.
 Hence, Ta,b is not stably infinite
Stably Infinite Theories

Example 2:
theory TE is stably infinite
 Proof:
 The



Let F be a formula with arbitrary satisfying TE -interpretation I:
(DI, αI).
Let A be any infinite set disjoint from DI
Then construct a new interpretation J (DJ, αJ) :
 DJ = DI ∪ A
v1 = J v2




T
F

v1 = I v2
if v1 , v2  DI
if v1 , v2 are the same element
otherwise
J is a TE -interpretation satisfying F with infinite domain.
Hence, TE is stably infinite.
The problem with a non-stably infinite theory

Definition: A -theory T is Stably-infinite if for every
quantifier-free -formula 
 is satisfiable ,
 can be satisfied by an interpretation with an infinite
domain.

Specifically, this means that no theory with a finite
domain is stably infinite.
Problem: non-stably infinite theories

Consider a theory T1:


1: A function f,
Axioms that only allow
solutions with 2 distinct values.

And a theory T2:


2: A function g,
Domain: N
Recall that the combined theory T1 © T2 has the union of the axioms.
Hence the solution to any formula  2 T1 © T2 cannot have more than 2 distinct
values.
So this formula is unsatisfiable:
: f(x1)  f(x2) Æ g(x1)  g(x3) Æ g(x2)  g(x3)
Problem: non-stably infinite theories
: f(x1)  f(x2) Æ g(x1)  g(x3) Æ g(x2)  g(x3)
T1
T2
f(x1)  f(x2)
g(x1)  g(x3)
g(x2)  g(x3)
No equalities to propagate: Satisfiable !
Solution to non-stable infinite theories

Nelson-Oppen method cannot be used.

Recently a solution to this problem was suggested by Tinelli &
Zarba [TZ05]
Extension 1: Shiny Theory with non-stably infinite theory
Tinelli & Zarba [TZ05]

Smooth Theory
is smooth if for every quantifier free formula  , for
every T-model A satisfying , and for every cardinal
number k > |A|, there exists a T-model B satisfying  s.t
|B|=k.
T

Minimal cardinality
 mincardT()
– the smallest cardinality of a T-model
satisfying .
 If T is stably-finite, then for every satisfiable formula
mincardT() is a natural number
Extension 1: Shiny Theory with non-stably
infinite theory

Shiny Theory
A



theory T is shiny if:
T is smooth
T is stably finite
mincardT is computable
 Examples
for some shiny theories: equality (over an
arbitrary signature), partial orders, total orders

The combination method
that T1 is shiny and T2 is some theory (not
necessarily stably infinite)
 Assume
Extension 1: Shiny Theory with non-stably
infinite theory - The combination method
1.
Purification
2.
Choose nondeterministically a partition P of V’s variables.
3.
If F1 Æ ar(P) is satisfiable go to the next step. Otherwise
output fail.
4.
Compute n = mincardT1(F1 Æ ar(P) )
5.
Construct a set δn of literals whose purpose is to force models
with cardinality at least n.
•
•
6.
Generate n new variables w1,…,wn not occurring in F1 Æ F2
Let δn ={wi ≠ wj | 1≤ i<j ≤ n }
If F2 Æ ar(P) Æ δn is satisfiable, output succeed. Otherwise
output fail.
Extension 1: Shiny Theory with non-stably
infinite theory

If there exists an equivalence relation for which the
check phase outputs succeed then the formula is
satisfiable in the combined theory, otherwise it is
unsatisfiable

In N.O we assume that T2 is stably infinite, and
therefore the constraint δn is guaranteed to hold.

In this extended variant of N.O there is a propagation
of certain cardinality constraints in addition to
propagating equality constraints.
Back to the example
: f(x1)  f(x2) Æ g(x1)  g(x3) Æ g(x2)  g(x3)
T1
T2
f(x1)  f(x2)
g(x1)  g(x3)
g(x2)  g(x3)
If x1 x2 ∈ Ei in the partition , then we will output fail because F1 is unsat
Back to the example
: f(x1)  f(x2) Æ g(x1)  g(x3) Æ g(x2)  g(x3)
T1
T2
f(x1)  f(x2)
g(x1)  g(x3)
g(x2)  g(x3)
If x1 x2 ∉ Ei in the partition , then F2 is satisfiable.
In addition, we have mincard(F2Æ(x1 ≠x2 ))=3
In the third step: F1Æ(x1 ≠x2 )Æ δ3 is T1-unsatisfiable
We therefore declare that  is unsat.
Extension 2: combining stably-finite theories

Assuming all combined theories are stably-finite (in
particular, it has a small model property), it computes,
if possible, the upper bound on the minimal satisfying
assignment, and propagates this information between
the theories.
Extension 2: combining stably-finite theories

Assume all combined theories are stably finite (i.e. have a small model
property), and one has only finite models. The bound Ni on the
minimal satisfying assignment of formulas in theory Ti is computable.

Transfer Ni between theories.

If there is no solution to theory j with cardinality at least N_i (for all i),
return unsatisfiable.

…
Summary

The N.O. combination method provides a general
means of reasoning simultaneously about several
theories using the individual decision procedures.

In practice, the main application of N.O. procedure is
the combination of equality logic with UF with other
theories, for example linear arithmetic.

It is implemented in this way in most state-of-the-art
solvers.