The Module System¶
The module system extends the Calculus of Inductive Constructions providing a convenient way to structure large developments as well as a means of massive abstraction.
Modules and module types¶
Access path. An access path is denoted by
Structure element. A structure element is denoted by
Structure expression. A structure expression is denoted by
an access path
a plain structure
a functor
, where is a module variable, and are structure expressionsan application
, where is a structure expression and an access patha refined structure
or where is a structure expression, and are access paths, is a term and is the type of .
Module definition. A module definition is written
Module alias. A module alias is written
Module type abbreviation.
A module type abbreviation is written
Using modules¶
The module system provides a way of packaging related elements together, as well as a means of massive abstraction.
- Command Module ImportExport import_categories?? ident module_binder* of_module_type? := module_expr_inl+<+?¶
- module_binder
::=
( ImportExport import_categories?? ident+ : module_type_inl )module_type_inl
::=
! module_type|
module_type functor_app_annot?functor_app_annot
::=
[ inline at level natural ]|
[ no inline ]module_type
::=
qualid|
( module_type )|
module_type module_expr_atom|
module_type with with_declarationwith_declaration
::=
Definition qualid univ_decl? := term|
Module qualid := qualidmodule_expr_atom
::=
qualid|
( module_expr_atom )of_module_type
::=
: module_type_inl|
<: module_type_inl*module_expr_inl
::=
! module_expr_atom+|
module_expr_atom+ functor_app_annot?Defines a module named
ident
. See the examples here.The
Import
andExport
flags specify whether the module should be automatically imported or exported.Specifying
module_binder*
starts a functor with parameters given by themodule_binder
s. (A functor is a function from modules to modules.)of_module_type
specifies the module type.<: module_type_inl+
starts a module that satisfies eachmodule_type_inl
.:= module_expr_inl+<+
specifies the body of a module or functor definition. If it's not specified, then the module is defined interactively, meaning that the module is defined as a series of commands terminated withEnd
instead of in a singleModule
command. Interactively defining themodule_expr_inl
s in a series ofInclude
commands is equivalent to giving them all in a single non-interactiveModule
command.The ! prefix indicates that any assumption command (such as
Axiom
) with anInline
clause in the type of the functor arguments will be ignored.
- Command Module Type ident module_binder* <: module_type_inl* := module_type_inl+<+?¶
Defines a module type named
ident
. See the example here.Specifying
module_binder*
starts a functor type with parameters given by themodule_binder
s.:= module_type_inl+<+
specifies the body of a module or functor type definition. If it's not specified, then the module type is defined interactively, meaning that the module type is defined as a series of commands terminated withEnd
instead of in a singleModule Type
command. Interactively defining themodule_type_inl
s in a series ofInclude
commands is equivalent to giving them all in a single non-interactiveModule Type
command.
Terminating an interactive module or module type definition
Interactive modules are terminated with the End
command, which
is also used to terminate Sections.
End ident
closes the interactive module or module type ident
.
If the module type was given, the command verifies that the content of the module
matches the module type. If the module is not a
functor, its components (constants, inductive types, submodules etc.)
are now available through the dot notation.
Note
Interactive modules and module types can be nested.
Interactive modules and module types can't be defined inside of sections. Sections can be defined inside of interactive modules and module types.
Hints and notations (the Hint and
Notation
commands) can also appear inside interactive modules and module types. Note that with module definitions like:Module ident1 : module_type := ident2.
or
Module ident1 : module_type.
Include ident2.
End ident1.
hints and the like valid for
ident1
are the ones defined inmodule_type
rather then those defined inident2
(or the module body).Within an interactive module type definition, the
Parameter
command declares a constant instead of definining a new axiom (which it does when not in a module type definition).Assumptions such as
Axiom
that include theInline
clause will be automatically expanded when the functor is applied, except when the function application is prefixed by!
.
- Command Include module_type_inl <+ module_type_inl*¶
Includes the content of module(s) in the current interactive module. Here
module_type_inl
can be a module expression or a module type expression. If it is a high-order module or module type expression then the system tries to instantiatemodule_type_inl
with the current interactive module.Including multiple modules in a single
Include
is equivalent to including each module in a separateInclude
command.
- Command Include Type module_type_inl+<+¶
Deprecated since version 8.3: Use
Include
instead.
- Command Declare Module ImportExport import_categories?? ident module_binder* : module_type_inl¶
Declares a module
ident
of typemodule_type_inl
.If
module_binder
s are specified, declares a functor with parameters given by the list ofmodule_binder
s.
- Command Import import_categories? filtered_import+¶
- import_categories
::=
-? ( qualid+, )filtered_import
::=
qualid ( qualid ( .. )?+, )?If
qualid
denotes a valid basic module (i.e. its module type is a signature), makes its components available by their short names.Example
- Module Mod.
- Interactive Module Mod started
- Definition T:=nat.
- T is defined
- Check T.
- T : Set
- End Mod.
- Module Mod is defined
- Check Mod.T.
- Mod.T : Set
- Fail Check T.
- The command has indeed failed with message: The reference T was not found in the current environment.
- Import Mod.
- Check T.
- T : Set
Some features defined in modules are activated only when a module is imported. This is for instance the case of notations (see Notations).
Declarations made with the
local
attribute are never imported by theImport
command. Such declarations are only accessible through their fully qualified name.Example
- Module A.
- Interactive Module A started
- Module B.
- Interactive Module B started
- Local Definition T := nat.
- T is defined
- End B.
- Module B is defined
- End A.
- Module A is defined
- Import A.
- Check B.T.
- Toplevel input, characters 6-9: > Check B.T. > ^^^ Error: The reference B.T was not found in the current environment.
Appending a module name with a parenthesized list of names will make only those names available with short names, not other names defined in the module nor will it activate other features.
The names to import may be constants, inductive types and constructors, and notation aliases (for instance, Ltac definitions cannot be selectively imported). If they are from an inner module to the one being imported, they must be prefixed by the inner path.
The name of an inductive type may also be followed by
(..)
to import it, its constructors and its eliminators if they exist. For this purpose "eliminator" means a constant in the same module whose name is the inductive type's name suffixed by one of_sind
,_ind
,_rec
or_rect
.Example
- Module A.
- Interactive Module A started
- Module B.
- Interactive Module B started
- Inductive T := C.
- T is defined T_rect is defined T_ind is defined T_rec is defined T_sind is defined
- Definition U := nat.
- U is defined
- End B.
- Module B is defined
- Definition Z := Prop.
- Z is defined
- End A.
- Module A is defined
- Import A(B.T(..), Z).
- Check B.T.
- B.T : Prop
- Check B.C.
- B.C : B.T
- Check Z.
- Z : Type
- Fail Check B.U.
- The command has indeed failed with message: The reference B.U was not found in the current environment.
- Check A.B.U.
- A.B.U : Set
- Warning Cannot import local constant, it will be ignored.¶
This warning is printed when a name in the list of names to import was declared as a local constant, and the name is not imported.
Putting a list of
import_categories
afterImport
will restrict activation of features according to those categories. Currently supported categories are:coercions
corresponding toCoercion
.hints
corresponding to theHint
commands (e.g.Hint Resolve
orHint Rewrite
) and typeclass instances.canonicals
corresponding toCanonical Structure
.notations
corresponding toNotation
(includingReserved Notation
), scope controls (Delimit Scope
,Bind Scope
,Open Scope
) but not Abbreviations.options
for Flags, Options and Tablesltac.notations
corresponding toTactic Notation
.ltac2.notations
corresponding toLtac2 Notation
(including Ltac2 abbreviations).
Plugins may define their own categories.
- Command Export import_categories? filtered_import+¶
Similar to
Import
, except that when the module containing this command is imported, thequalid+
are imported as well.The selective import syntax also works with Export.
- Flag Short Module Printing¶
This flag (off by default) disables the printing of the types of fields, leaving only their names, for the commands
Print Module
andPrint Module Type
.
- Command Print Namespace dirpath¶
Prints the names and types of all loaded constants whose fully qualified names start with
dirpath
. For example, the commandPrint Namespace Coq.
displays the names and types of all loaded constants in the standard library. The commandPrint Namespace Coq.Init
only shows constants defined in one of the files in theInit
directory. The commandPrint Namespace Coq.Init.Nat
shows what is in theNat
library file inside theInit
directory. Module names may appear indirpath
.Example
- Module A.
- Interactive Module A started
- Definition foo := 0.
- foo is defined
- Module B.
- Interactive Module B started
- Definition bar := 1.
- bar is defined
- End B.
- Module B is defined
- End A.
- Module A is defined
- Print Namespace Top.
- Top: A.foo: nat A.B.bar: nat
- Print Namespace Top.A.
- Top.A: foo: nat B.bar: nat
- Print Namespace Top.A.B.
- Top.A.B: bar: nat
Examples¶
Example: Defining a simple module interactively
- Module M.
- Interactive Module M started
- Definition T := nat.
- T is defined
- Definition x := 0.
- x is defined
- Definition y : bool.
- 1 goal ============================ bool
- exact true.
- No more goals.
- Defined.
- End M.
- Module M is defined
Inside a module one can define constants, prove theorems and do anything else that can be done in the toplevel. Components of a closed module can be accessed using the dot notation:
- Print M.x.
- M.x = 0 : nat
Example: Defining a simple module type interactively
- Module Type SIG.
- Interactive Module Type SIG started
- Parameter T : Set.
- T is declared
- Parameter x : T.
- x is declared
- End SIG.
- Module Type SIG is defined
Example: Creating a new module that omits some items from an existing module
Since SIG
, the type of the new module N
, doesn't define y
or
give the body of x
, which are not included in N
.
- Module N : SIG with Definition T := nat := M.
- Module N is defined
- Print N.T.
- N.T = nat : Set
- Print N.x.
- *** [ N.x : N.T ]
- Fail Print N.y.
- The command has indeed failed with message: N.y not a defined object.
- Module M.
- Interactive Module M started
- Definition T := nat.
- T is defined
- Definition x := 0.
- x is defined
- Definition y : bool.
- 1 goal ============================ bool
- exact true.
- No more goals.
- Defined.
- End M.
- Module M is defined
- Module Type SIG.
- Interactive Module Type SIG started
- Parameter T : Set.
- T is declared
- Parameter x : T.
- x is declared
- End SIG.
- Module Type SIG is defined
The definition of N
using the module type expression SIG
with
Definition T := nat
is equivalent to the following one:
- Module Type SIG'.
- Interactive Module Type SIG' started
- Definition T : Set := nat.
- T is defined
- Parameter x : T.
- x is declared
- End SIG'.
- Module Type SIG' is defined
- Module N : SIG' := M.
- Module N is defined
- Error No field named ident in qualid.¶
Raised when the final
ident
in the left-hand sidequalid
of awith_declaration
is applied to a module typequalid
that has no field named thisident
.
If we just want to be sure that our implementation satisfies a given module type without restricting the interface, we can use a transparent constraint
- Module P <: SIG := M.
- Module P is defined
- Print P.y.
- P.y = true : bool
Example: Creating a functor (a module with parameters)
- Module Two (X Y: SIG).
- Interactive Module Two started
- Definition T := (X.T * Y.T)%type.
- T is defined
- Definition x := (X.x, Y.x).
- x is defined
- End Two.
- Module Two is defined
and apply it to our modules and do some computations:
- Module Q := Two M N.
- Module Q is defined
- Eval compute in (fst Q.x + snd Q.x).
- = N.x : nat
Example: A module type with two sub-modules, sharing some fields
- Module Type SIG2.
- Interactive Module Type SIG2 started
- Declare Module M1 : SIG.
- Module M1 is declared
- Module M2 <: SIG.
- Interactive Module M2 started
- Definition T := M1.T.
- T is defined
- Parameter x : T.
- x is declared
- End M2.
- Module M2 is defined
- End SIG2.
- Module Type SIG2 is defined
- Module Mod <: SIG2.
- Interactive Module Mod started
- Module M1.
- Interactive Module M1 started
- Definition T := nat.
- T is defined
- Definition x := 1.
- x is defined
- End M1.
- Module M1 is defined
- Module M2 := M.
- Module M2 is defined
- End Mod.
- Module Mod is defined
Notice that M
is a correct body for the component M2
since its T
component is nat
as specified for M1.T
.
Typing Modules¶
In order to introduce the typing system we first slightly extend the syntactic class of terms and environments given in section The terms. The environments, apart from definitions of constants and inductive types now also hold any other structure elements. Terms, apart from variables, constants and complex terms, also include access paths.
We also need additional typing judgments:
, denoting that a structure is well-formed, , denoting that the module pointed by has type in the global environment . , denoting that a structure is evaluated to a structure in weak head normal form. , denoting that a structure is a subtype of a structure . , denoting that a structure element is more precise than a structure element .
The rules for forming structures are the following:
- WF-STR
- WF-FUN
Evaluation of structures to weak head normal form:
- WEVAL-APP
- WEVAL-WITH-MOD
- WEVAL-WITH-MOD-REC
- WEVAL-WITH-DEF
- WEVAL-WITH-DEF-REC
- WEVAL-PATH-MOD1
- WEVAL-PATH-MOD2
- WEVAL-PATH-ALIAS1
- WEVAL-PATH-ALIAS2
- WEVAL-PATH-TYPE1
- WEVAL-PATH-TYPE2
Rules for typing module:
- MT-EVAL
- MT-STR
The last rule, called strengthening is used to make all module fields
manifestly equal to themselves. The notation
if
then where is defined as follows (note that opaque definitions are processed as assumptions):if
then
The notation
The module subtyping rules:
- MSUB-STR
- MSUB-FUN
Structure element subtyping rules:
- ASSUM-ASSUM
- DEF-ASSUM
- ASSUM-DEF
- DEF-DEF
- IND-IND
- INDP-IND
- INDP-INDP
- MOD-MOD
- ALIAS-MOD
- MOD-ALIAS
- ALIAS-ALIAS
- MODTYPE-MODTYPE
New environment formation rules
- WF-MOD1
- WF-MOD2
- WF-ALIAS
- WF-MODTYPE
- WF-IND
Component access rules
- ACC-TYPE1
- ACC-TYPE2
Notice that the following rule extends the delta rule defined in section Conversion rules
- ACC-DELTA
In the rules below we assume
- ACC-IND1
- ACC-IND2
- ACC-INDP1
- ACC-INDP2
Qualified names¶
Qualified names (qualid
s) are hierarchical names that are used to
identify items such as definitions, theorems and parameters that may be defined
inside modules (see Module
). In addition, they are used to identify
compiled files. Syntactically, they have this form:
::=
ident .ident*
Fully qualified or absolute qualified names uniquely identify files
(as in the Require
command) and items within files, such as a single
Variable
definition. It's usually possible to use a suffix of the fully
qualified name (a short name) that uniquely identifies an item.
The first part of a fully qualified name identifies a file, which may be followed by a second part that identifies a specific item within that file. Qualified names that identify files don't have a second part.
While qualified names always consist of a series of dot-separated ident
s,
the following few paragraphs omit the dots for the sake of simplicity.
File part. Files are identified by logical paths,
which are prefixes in the form identlogical* identfile+
, such
as Coq.Init.Logic
, in which:
identlogical*
, the logical name, maps to one or more directories (or physical paths) in the user's file system. The logical name is used so that Coq scripts don't depend on where files are installed. For example, the directory associated withCoq
contains Coq's standard library. The logical name is generally a singleident
.identfile+
corresponds to the file system path of the file relative to the directory that contains it. For example,Init.Logic
corresponds to the file system pathInit/Logic.v
on Linux)
When Coq is processing a script that hasn't been saved in a file, such as a new
buffer in CoqIDE or anything in coqtop, definitions in the script are associated
with the logical name Top
and there is no associated file system path.
Item part. Items are further qualified by a suffix in the form
identmodule* identbase
in which:
identmodule*
gives the names of the nested modules, if any, that syntactically contain the definition of the item. (SeeModule
.)identbase
is the base name used in the command defining the item. For example,eq
in theInductive
command defining it inCoq.Init.Logic
is the base name forCoq.Init.Logic.eq
, the standard library definition of Leibniz equality.
If qualid
is the fully qualified name of an item, Coq
always interprets qualid
as a reference to that item. If qualid
is also a
partially qualified name for another item, then you must provide a more-qualified
name to uniquely identify that other item. For example, if there are two
fully qualified items named Foo.Bar
and Coq.X.Foo.Bar
, then Foo.Bar
refers
to the first item and X.Foo.Bar
is the shortest name for referring to the second item.
Definitions with the local
attribute are only accessible with
their fully qualified name (see Top-level definitions).
Example
- Check 0.
- 0 : nat
- Definition nat := bool.
- nat is defined
- Check 0.
- 0 : Datatypes.nat
- Check Datatypes.nat.
- Datatypes.nat : Set
- Locate nat.
- Constant Top.nat Inductive Coq.Init.Datatypes.nat (shorter name to refer to it in current context is Datatypes.nat)
See also
Commands Locate
.
Logical paths and the load path describes how logical paths become associated with specific files.
Controlling the scope of commands with locality attributes¶
Many commands have effects that apply only within a specific scope,
typically the section or the module in which the command was
called. Locality attributes can alter the scope of
the effect. Below, we give the semantics of each locality attribute
while noting a few exceptional commands for which local
and
global
attributes are interpreted differently.
- Attribute local¶
This attribute limits the effect of the command to the current scope (section or module).
The
Local
prefix is an alternative syntax for thelocal
attribute (seelegacy_attr
).Note
Warning
Exception: when
local
is applied toDefinition
,Theorem
or their variants, its semantics are different: it makes the defined objects available only through their fully qualified names rather than their unqualified names after anImport
.
- Attribute export¶
This attribute makes the effect of the command persist when the section is closed and applies the effect when the module containing the command is imported.
Commands supporting this attribute include
Set
,Unset
and the Hint commands, although the latter don't support it within sections.
- Attribute global¶
This attribute makes the effect of the command persist even when the current section or module is closed. Loading the file containing the command (possibly transitively) applies the effect of the command.
The
Global
prefix is an alternative syntax for theglobal
attribute (seelegacy_attr
).