The Module System

The module system extends the Calculus of Inductive Constructions providing a convenient way to structure large developments as well as a means of massive abstraction.

Modules and module types

Access path. An access path is denoted by p and can be either a module variable X or, if p is an access path and id an identifier, then p.id is an access path.

Structure element. A structure element is denoted by e and is either a definition of a constant, an assumption, a definition of an inductive, a definition of a module, an alias of a module or a module type abbreviation.

Structure expression. A structure expression is denoted by S and can be:

  • an access path p

  • a plain structure Struct e;;e End

  • a functor Functor(X:S) S, where X is a module variable, S and S are structure expressions

  • an application S p, where S is a structure expression and p an access path

  • a refined structure S with p:=p or S with p:=t:T where S is a structure expression, p and p are access paths, t is a term and T is the type of t.

Module definition. A module definition is written Mod(X:S[:=S]) and consists of a module variable X, a module type S which can be any structure expression and optionally a module implementation S which can be any structure expression except a refined structure.

Module alias. A module alias is written ModA(X==p) and consists of a module variable X and a module path p.

Module type abbreviation. A module type abbreviation is written ModType(Y:=S), where Y is an identifier and S is any structure expression .

Using modules

The module system provides a way of packaging related elements together, as well as a means of massive abstraction.

Command Module ImportExport import_categories?? ident module_binder* of_module_type? := module_expr_inl+<+?
module_binder::=( ImportExport import_categories?? ident+ : module_type_inl )module_type_inl::=! module_type|module_type functor_app_annot?functor_app_annot::=[ inline at level natural ]|[ no inline ]module_type::=qualid|( module_type )|module_type module_expr_atom|module_type with with_declarationwith_declaration::=Definition qualid univ_decl? := term|Module qualid := qualidmodule_expr_atom::=qualid|( module_expr_atom )of_module_type::=: module_type_inl|<: module_type_inl*module_expr_inl::=! module_expr_atom+|module_expr_atom+ functor_app_annot?

Defines a module named ident. See the examples here.

The Import and Export flags specify whether the module should be automatically imported or exported.

Specifying module_binder* starts a functor with parameters given by the module_binders. (A functor is a function from modules to modules.)

of_module_type specifies the module type. <: module_type_inl+ starts a module that satisfies each module_type_inl.

:= module_expr_inl+<+ specifies the body of a module or functor definition. If it's not specified, then the module is defined interactively, meaning that the module is defined as a series of commands terminated with End instead of in a single Module command. Interactively defining the module_expr_inls in a series of Include commands is equivalent to giving them all in a single non-interactive Module command.

The ! prefix indicates that any assumption command (such as Axiom) with an Inline clause in the type of the functor arguments will be ignored.

Command Module Type ident module_binder* <: module_type_inl* := module_type_inl+<+?

Defines a module type named ident. See the example here.

Specifying module_binder* starts a functor type with parameters given by the module_binders.

:= module_type_inl+<+ specifies the body of a module or functor type definition. If it's not specified, then the module type is defined interactively, meaning that the module type is defined as a series of commands terminated with End instead of in a single Module Type command. Interactively defining the module_type_inls in a series of Include commands is equivalent to giving them all in a single non-interactive Module Type command.

Terminating an interactive module or module type definition

Interactive modules are terminated with the End command, which is also used to terminate Sections. End ident closes the interactive module or module type ident. If the module type was given, the command verifies that the content of the module matches the module type. If the module is not a functor, its components (constants, inductive types, submodules etc.) are now available through the dot notation.

Error Signature components for field ident do not match.
Error The field ident is missing in qualid.

Note

  1. Interactive modules and module types can be nested.

  2. Interactive modules and module types can't be defined inside of sections. Sections can be defined inside of interactive modules and module types.

  3. Hints and notations (the Hint and Notation commands) can also appear inside interactive modules and module types. Note that with module definitions like:

    Module ident1 : module_type := ident2.

    or

    Module ident1 : module_type.
    Include ident2.
    End ident1.

    hints and the like valid for ident1 are the ones defined in module_type rather then those defined in ident2 (or the module body).

  4. Within an interactive module type definition, the Parameter command declares a constant instead of definining a new axiom (which it does when not in a module type definition).

  5. Assumptions such as Axiom that include the Inline clause will be automatically expanded when the functor is applied, except when the function application is prefixed by !.

Command Include module_type_inl <+ module_type_inl*

Includes the content of module(s) in the current interactive module. Here module_type_inl can be a module expression or a module type expression. If it is a high-order module or module type expression then the system tries to instantiate module_type_inl with the current interactive module.

Including multiple modules in a single Include is equivalent to including each module in a separate Include command.

Command Include Type module_type_inl+<+

Deprecated since version 8.3: Use Include instead.

Command Declare Module ImportExport import_categories?? ident module_binder* : module_type_inl

Declares a module ident of type module_type_inl.

If module_binders are specified, declares a functor with parameters given by the list of module_binders.

Command Import import_categories? filtered_import+
import_categories::=-? ( qualid+, )filtered_import::=qualid ( qualid ( .. )?+, )?

If qualid denotes a valid basic module (i.e. its module type is a signature), makes its components available by their short names.

Example

Module Mod.
Interactive Module Mod started
Definition T:=nat.
T is defined
Check T.
T : Set
End Mod.
Module Mod is defined
Check Mod.T.
Mod.T : Set
Fail Check T.
The command has indeed failed with message: The reference T was not found in the current environment.
Import Mod.
Check T.
T : Set

Some features defined in modules are activated only when a module is imported. This is for instance the case of notations (see Notations).

Declarations made with the local attribute are never imported by the Import command. Such declarations are only accessible through their fully qualified name.

Example

Module A.
Interactive Module A started
Module B.
Interactive Module B started
Local Definition T := nat.
T is defined
End B.
Module B is defined
End A.
Module A is defined
Import A.
Check B.T.
Toplevel input, characters 6-9: > Check B.T. > ^^^ Error: The reference B.T was not found in the current environment.

Appending a module name with a parenthesized list of names will make only those names available with short names, not other names defined in the module nor will it activate other features.

The names to import may be constants, inductive types and constructors, and notation aliases (for instance, Ltac definitions cannot be selectively imported). If they are from an inner module to the one being imported, they must be prefixed by the inner path.

The name of an inductive type may also be followed by (..) to import it, its constructors and its eliminators if they exist. For this purpose "eliminator" means a constant in the same module whose name is the inductive type's name suffixed by one of _sind, _ind, _rec or _rect.

Example

Module A.
Interactive Module A started
Module B.
Interactive Module B started
Inductive T := C.
T is defined T_rect is defined T_ind is defined T_rec is defined T_sind is defined
Definition U := nat.
U is defined
End B.
Module B is defined
Definition Z := Prop.
Z is defined
End A.
Module A is defined
Import A(B.T(..), Z).
Check B.T.
B.T : Prop
Check B.C.
B.C : B.T
Check Z.
Z : Type
Fail Check B.U.
The command has indeed failed with message: The reference B.U was not found in the current environment.
Check A.B.U.
A.B.U : Set
Warning Cannot import local constant, it will be ignored.

This warning is printed when a name in the list of names to import was declared as a local constant, and the name is not imported.

Putting a list of import_categories after Import will restrict activation of features according to those categories. Currently supported categories are:

Plugins may define their own categories.

Command Export import_categories? filtered_import+

Similar to Import, except that when the module containing this command is imported, the qualid+ are imported as well.

The selective import syntax also works with Export.

Error qualid is not a module.
Warning Trying to mask the absolute name qualid!
Command Print Module qualid

Prints the module type and (optionally) the body of the module qualid.

Command Print Module Type qualid

Prints the module type corresponding to qualid.

Flag Short Module Printing

This flag (off by default) disables the printing of the types of fields, leaving only their names, for the commands Print Module and Print Module Type.

Command Print Namespace dirpath

Prints the names and types of all loaded constants whose fully qualified names start with dirpath. For example, the command Print Namespace Coq. displays the names and types of all loaded constants in the standard library. The command Print Namespace Coq.Init only shows constants defined in one of the files in the Init directory. The command Print Namespace Coq.Init.Nat shows what is in the Nat library file inside the Init directory. Module names may appear in dirpath.

Example

Module A.
Interactive Module A started
Definition foo := 0.
foo is defined
Module B.
Interactive Module B started
Definition bar := 1.
bar is defined
End B.
Module B is defined
End A.
Module A is defined
Print Namespace Top.
Top: A.foo: nat A.B.bar: nat
Print Namespace Top.A.
Top.A: foo: nat B.bar: nat
Print Namespace Top.A.B.
Top.A.B: bar: nat

Examples

Example: Defining a simple module interactively

Module M.
Interactive Module M started
Definition T := nat.
T is defined
Definition x := 0.
x is defined
Definition y : bool.
1 goal ============================ bool
exact true.
No more goals.
Defined.
End M.
Module M is defined

Inside a module one can define constants, prove theorems and do anything else that can be done in the toplevel. Components of a closed module can be accessed using the dot notation:

Print M.x.
M.x = 0 : nat

Example: Defining a simple module type interactively

Module Type SIG.
Interactive Module Type SIG started
Parameter T : Set.
T is declared
Parameter x : T.
x is declared
End SIG.
Module Type SIG is defined

Example: Creating a new module that omits some items from an existing module

Since SIG, the type of the new module N, doesn't define y or give the body of x, which are not included in N.

Module N : SIG with Definition T := nat := M.
Module N is defined
Print N.T.
N.T = nat : Set
Print N.x.
*** [ N.x : N.T ]
Fail Print N.y.
The command has indeed failed with message: N.y not a defined object.
Module M.
Interactive Module M started
Definition T := nat.
T is defined
Definition x := 0.
x is defined
Definition y : bool.
1 goal ============================ bool
exact true.
No more goals.
Defined.
End M.
Module M is defined
Module Type SIG.
Interactive Module Type SIG started
Parameter T : Set.
T is declared
Parameter x : T.
x is declared
End SIG.
Module Type SIG is defined

The definition of N using the module type expression SIG with Definition T := nat is equivalent to the following one:

Module Type SIG'.
Interactive Module Type SIG' started
Definition T : Set := nat.
T is defined
Parameter x : T.
x is declared
End SIG'.
Module Type SIG' is defined
Module N : SIG' := M.
Module N is defined
Error No field named ident in qualid.

Raised when the final ident in the left-hand side qualid of a with_declaration is applied to a module type qualid that has no field named this ident.

If we just want to be sure that our implementation satisfies a given module type without restricting the interface, we can use a transparent constraint

Module P <: SIG := M.
Module P is defined
Print P.y.
P.y = true : bool

Example: Creating a functor (a module with parameters)

Module Two (X Y: SIG).
Interactive Module Two started
Definition T := (X.T * Y.T)%type.
T is defined
Definition x := (X.x, Y.x).
x is defined
End Two.
Module Two is defined

and apply it to our modules and do some computations:

Module Q := Two M N.
Module Q is defined
Eval compute in (fst Q.x + snd Q.x).
= N.x : nat

Example: A module type with two sub-modules, sharing some fields

Module Type SIG2.
Interactive Module Type SIG2 started
  Declare Module M1 : SIG.
Module M1 is declared
  Module M2 <: SIG.
Interactive Module M2 started
    Definition T := M1.T.
T is defined
    Parameter x : T.
x is declared
  End M2.
Module M2 is defined
End SIG2.
Module Type SIG2 is defined
Module Mod <: SIG2.
Interactive Module Mod started
  Module M1.
Interactive Module M1 started
    Definition T := nat.
T is defined
    Definition x := 1.
x is defined
  End M1.
Module M1 is defined
Module M2 := M.
Module M2 is defined
End Mod.
Module Mod is defined

Notice that M is a correct body for the component M2 since its T component is nat as specified for M1.T.

Typing Modules

In order to introduce the typing system we first slightly extend the syntactic class of terms and environments given in section The terms. The environments, apart from definitions of constants and inductive types now also hold any other structure elements. Terms, apart from variables, constants and complex terms, also include access paths.

We also need additional typing judgments:

  • E[]WF(S), denoting that a structure S is well-formed,

  • E[]p:S, denoting that the module pointed by p has type S in the global environment E.

  • E[]SS, denoting that a structure S is evaluated to a structure S in weak head normal form.

  • E[]S1<:S2 , denoting that a structure S1 is a subtype of a structure S2.

  • E[]e1<:e2 , denoting that a structure element e1 is more precise than a structure element e2.

The rules for forming structures are the following:

WF-STR
WF(E;E)[]E[]WF(Struct E End)
WF-FUN
E;Mod(X:S)[]WF(S)E[]WF(Functor(X:S) S)

Evaluation of structures to weak head normal form:

WEVAL-APP
E[]SFunctor(X:S1) S2     E[]S1S1E[]p:S3     E[]S3<:S1E[]S pS2{X/p}
WEVAL-WITH-MOD
E[]SStruct e1;;ei;Mod(X:S1);ei+2;;en EndE;e1;;ei[]S1S1      E[]p:S2E;e1;;ei[]S2<:S1E[]S with X:=pStruct e1;;ei;ModA(X==p);ei+2{X/p};;en{X/p} End
WEVAL-WITH-MOD-REC
E[]SStruct e1;;ei;Mod(X1:S1);ei+2;;en EndE;e1;;ei[]S1 with p:=p1S2E[]S with X1.p:=p1Struct e1;;ei;Mod(X:S2);ei+2{X1.p/p1};;en{X1.p/p1} End
WEVAL-WITH-DEF
E[]SStruct e1;;ei;(c:T1);ei+2;;en EndE;e1;;ei[](c:=t:T)<:(c:T1)E[]S with c:=t:TStruct e1;;ei;(c:=t:T);ei+2;;en End
WEVAL-WITH-DEF-REC
E[]SStruct e1;;ei;Mod(X1:S1);ei+2;;en EndE;e1;;ei[]S1 with p:=p1S2E[]S with X1.p:=t:TStruct e1;;ei;Mod(X:S2);ei+2;;en End
WEVAL-PATH-MOD1
E[]pStruct e1;;ei;Mod(X:S[:=S1]);ei+2;;en EndE;e1;;ei[]SSE[]p.XS
WEVAL-PATH-MOD2
WF(E)[]Mod(X:S[:=S1])EE[]SSE[]XS
WEVAL-PATH-ALIAS1
E[]p Struct e1;;ei;ModA(X==p1);ei+2;;en EndE;e1;;ei[]p1SE[]p.XS
WEVAL-PATH-ALIAS2
WF(E)[]ModA(X==p1)EE[]p1SE[]XS
WEVAL-PATH-TYPE1
E[]p Struct e1;;ei;ModType(Y:=S);ei+2;;en EndE;e1;;ei[]SSE[]p.YS
WEVAL-PATH-TYPE2
WF(E)[]ModType(Y:=S)EE[]SSE[]YS

Rules for typing module:

MT-EVAL
E[]pSE[]p:S
MT-STR
E[]p:SE[]p:S/p

The last rule, called strengthening is used to make all module fields manifestly equal to themselves. The notation S/p has the following meaning:

  • if S Struct e1;;en End then S/p= Struct e1/p;;en/p End where e/p is defined as follows (note that opaque definitions are processed as assumptions):

    • (c:=t:T)/p=(c:=t:T)

    • (c:U)/p=(c:=p.c:U)

    • Mod(X:S)/p=ModA(X==p.X)

    • ModA(X==p)/p=ModA(X==p)

    • Ind [r](ΓI := ΓC)/p=Indp[r](ΓI:=ΓC)

    • Indp[r](ΓI:=ΓC)/p=Indp[r](ΓI:=ΓC)

  • if SFunctor(X:S) S then S/p=S

The notation Indp[r](ΓI:=ΓC) denotes an inductive definition that is definitionally equal to the inductive definition in the module denoted by the path p. All rules which have Ind [r](ΓI := ΓC) as premises are also valid for Indp[r](ΓI:=ΓC). We give the formation rule for Indp[r](ΓI:=ΓC) below as well as the equality rules on inductive types and constructors.

The module subtyping rules:

MSUB-STR
E;e1;;en[]eσ(i)<:ei for i=1..mσ:{1m}{1n} injectiveE[]Struct e1;;en End<: Struct e1;;em End
MSUB-FUN
E[]S1<:S1E;Mod(X:S1)[]S2<:S2E[]Functor(X:S1)S2<:Functor(X:S1)S2

Structure element subtyping rules:

ASSUM-ASSUM
E[]T1βδιζηT2E[](c:T1)<:(c:T2)
DEF-ASSUM
E[]T1βδιζηT2E[](c:=t:T1)<:(c:T2)
ASSUM-DEF
E[]T1βδιζηT2E[]c=βδιζηt2E[](c:T1)<:(c:=t2:T2)
DEF-DEF
E[]T1βδιζηT2E[]t1=βδιζηt2E[](c:=t1:T1)<:(c:=t2:T2)
IND-IND
E[]ΓI=βδιζηΓIE[ΓI]ΓC=βδιζηΓCE[]Ind [r](ΓI := ΓC)<:Ind [r](ΓI := ΓC)
INDP-IND
E[]ΓI=βδιζηΓIE[ΓI]ΓC=βδιζηΓCE[]Indp[r](ΓI:=ΓC)<:Ind [r](ΓI := ΓC)
INDP-INDP
E[]ΓI=βδιζηΓIE[ΓI]ΓC=βδιζηΓCE[]p=βδιζηpE[]Indp[r](ΓI:=ΓC)<:Indp[r](ΓI:=ΓC)
MOD-MOD
E[]S1<:S2E[]Mod(X:S1)<:Mod(X:S2)
ALIAS-MOD
E[]p:S1E[]S1<:S2E[]ModA(X==p)<:Mod(X:S2)
MOD-ALIAS
E[]p:S2E[]S1<:S2E[]X=βδιζηpE[]Mod(X:S1)<:ModA(X==p)
ALIAS-ALIAS
E[]p1=βδιζηp2E[]ModA(X==p1)<:ModA(X==p2)
MODTYPE-MODTYPE
E[]S1<:S2E[]S2<:S1E[]ModType(Y:=S1)<:ModType(Y:=S2)

New environment formation rules

WF-MOD1
WF(E)[]E[]WF(S)WF(E;Mod(X:S))[]
WF-MOD2
E[]S2<:S1WF(E)[]E[]WF(S1)E[]WF(S2)WF(E;Mod(X:S1:=S2))[]
WF-ALIAS
WF(E)[]E[]p:SWF(E;ModA(X==p))[]
WF-MODTYPE
WF(E)[]E[]WF(S)WF(E;ModType(Y:=S))[]
WF-IND
WF(E;Ind [r](ΓI := ΓC))[]E[]p: Struct e1;;en;Ind [r](ΓI := ΓC); EndE[]Ind [r](ΓI := ΓC)<:Ind [r](ΓI := ΓC)WF(E;Indp[r](ΓI:=ΓC))[]

Component access rules

ACC-TYPE1
E[Γ]p: Struct e1;;ei;(c:T); EndE[Γ]p.c:T
ACC-TYPE2
E[Γ]p: Struct e1;;ei;(c:=t:T); EndE[Γ]p.c:T

Notice that the following rule extends the delta rule defined in section Conversion rules

ACC-DELTA
E[Γ]p: Struct e1;;ei;(c:=t:U); EndE[Γ]p.cδt

In the rules below we assume ΓP is [p1:P1;;pr:Pr], ΓI is [I1:ΓP,A1;;Ik:ΓP,Ak], and ΓC is [c1:ΓP,C1;;cn:ΓP,Cn].

ACC-IND1
E[Γ]p: Struct e1;;ei;Ind [r](ΓI := ΓC); EndE[Γ]p.Ij:ΓP,Aj
ACC-IND2
E[Γ]p: Struct e1;;ei;Ind [r](ΓI := ΓC); EndE[Γ]p.cm:ΓP,Cm
ACC-INDP1
E[]p: Struct e1;;ei;Indp[r](ΓI:=ΓC); EndE[]p.Iiδp.Ii
ACC-INDP2
E[]p: Struct e1;;ei;Indp[r](ΓI:=ΓC); EndE[]p.ciδp.ci

Qualified names

Qualified names (qualids) are hierarchical names that are used to identify items such as definitions, theorems and parameters that may be defined inside modules (see Module). In addition, they are used to identify compiled files. Syntactically, they have this form:

qualid::=ident .ident*

Fully qualified or absolute qualified names uniquely identify files (as in the Require command) and items within files, such as a single Variable definition. It's usually possible to use a suffix of the fully qualified name (a short name) that uniquely identifies an item.

The first part of a fully qualified name identifies a file, which may be followed by a second part that identifies a specific item within that file. Qualified names that identify files don't have a second part.

While qualified names always consist of a series of dot-separated idents, the following few paragraphs omit the dots for the sake of simplicity.

File part. Files are identified by logical paths, which are prefixes in the form identlogical* identfile+, such as Coq.Init.Logic, in which:

  • identlogical*, the logical name, maps to one or more directories (or physical paths) in the user's file system. The logical name is used so that Coq scripts don't depend on where files are installed. For example, the directory associated with Coq contains Coq's standard library. The logical name is generally a single ident.

  • identfile+ corresponds to the file system path of the file relative to the directory that contains it. For example, Init.Logic corresponds to the file system path Init/Logic.v on Linux)

When Coq is processing a script that hasn't been saved in a file, such as a new buffer in CoqIDE or anything in coqtop, definitions in the script are associated with the logical name Top and there is no associated file system path.

Item part. Items are further qualified by a suffix in the form identmodule* identbase in which:

  • identmodule* gives the names of the nested modules, if any, that syntactically contain the definition of the item. (See Module.)

  • identbase is the base name used in the command defining the item. For example, eq in the Inductive command defining it in Coq.Init.Logic is the base name for Coq.Init.Logic.eq, the standard library definition of Leibniz equality.

If qualid is the fully qualified name of an item, Coq always interprets qualid as a reference to that item. If qualid is also a partially qualified name for another item, then you must provide a more-qualified name to uniquely identify that other item. For example, if there are two fully qualified items named Foo.Bar and Coq.X.Foo.Bar, then Foo.Bar refers to the first item and X.Foo.Bar is the shortest name for referring to the second item.

Definitions with the local attribute are only accessible with their fully qualified name (see Top-level definitions).

Example

Check 0.
0 : nat
Definition nat := bool.
nat is defined
Check 0.
0 : Datatypes.nat
Check Datatypes.nat.
Datatypes.nat : Set
Locate nat.
Constant Top.nat Inductive Coq.Init.Datatypes.nat (shorter name to refer to it in current context is Datatypes.nat)

See also

Commands Locate.

Logical paths and the load path describes how logical paths become associated with specific files.

Controlling the scope of commands with locality attributes

Many commands have effects that apply only within a specific scope, typically the section or the module in which the command was called. Locality attributes can alter the scope of the effect. Below, we give the semantics of each locality attribute while noting a few exceptional commands for which local and global attributes are interpreted differently.

Attribute local

This attribute limits the effect of the command to the current scope (section or module).

The Local prefix is an alternative syntax for the local attribute (see legacy_attr).

Note

  • For some commands, this is the only locality supported within sections (e.g., for Notation, Ltac and Hint commands).

  • For some commands, this is the default locality within sections even though other locality attributes are supported as well (e.g., for the Arguments command).

Warning

Exception: when local is applied to Definition, Theorem or their variants, its semantics are different: it makes the defined objects available only through their fully qualified names rather than their unqualified names after an Import.

Attribute export

This attribute makes the effect of the command persist when the section is closed and applies the effect when the module containing the command is imported.

Commands supporting this attribute include Set, Unset and the Hint commands, although the latter don't support it within sections.

Attribute global

This attribute makes the effect of the command persist even when the current section or module is closed. Loading the file containing the command (possibly transitively) applies the effect of the command.

The Global prefix is an alternative syntax for the global attribute (see legacy_attr).

Warning

Exception: for a few commands (like Notation and Ltac), this attribute behaves like export.

Warning

We strongly discourage using the global locality attribute because the transitive nature of file loading gives the user little control. We recommend using the export locality attribute where it is supported.