Bunched logic


Bunched logic is a variety of substructural logic proposed by Peter O'Hearn and David Pym. Bunched logic provides primitives for reasoning about resource composition, which aid in the compositional analysis of computer and other systems. It has category-theoretic and truth-functional semantics which can be understood in terms of an abstract concept of resource, and a proof theory in which the contexts Γ in an entailment judgement Γ ⊢ A are tree-like structures rather than lists or sets as in most proof calculi. Bunched logic has an associated type theory, and its first application was in providing a way to control the aliasing and other forms of interference in imperative programs.
The logic has seen further applications in program verification, where it is the basis of the assertion language of separation logic, and in systems modelling, where it provides a way to decompose the resources used by components of a system.

Foundations

The deduction theorem of classical logic relates conjunction and implication:
Bunched logic has two versions of the deduction theorem:
and are forms of conjunction and implication that take resources into account. In addition to these connectives
bunched logic has a formula, sometimes written I or emp, which is the unit of *. In the original version of bunched logic and were the connectives from intuitionistic logic, while a boolean variant takes and as from traditional boolean logic. Thus, bunched logic is compatible with constructive principles, but is in no way dependent on them.

Truth-functional Semantics (resource semantics)

The easiest way to understand these formulae is in terms of its truth-functional semantics. In this semantics a formula is true or false with respect to given resources.
asserts that the resource at hand can be decomposed into resources that satisfy and.
says that if we compose the resource at hand with additional resource that satisfies, then the combined resource satisfies. and have their familiar meanings.
The foundation for this reading of formulae was provided by
a forcing semantics advanced by Pym, where the forcing relation means `A holds of resource r`. The semantics is analogous to Kripke's semantics of intuitionistic or modal logic, but where the elements of the model are regarded as resources which can be composed and decomposed, rather than as possible worlds that are accessible from one another. For example, the forcing semantics for the conjunction is of the form
where is a way of combining resources and is a relation of approximation.
This semantics of bunched logic draws on prior work in Relevant Logic, but differs from it by not requiring and by accepting the semantics of standard intuitionistic or classical versions of and. The property is justified when thinking about relevance but denied by considerations of resource; having two copies of a resource is not the same as having one, and in some models might not even be defined. The standard semantics of is often rejected by relevantists in their bid to escape the `paradoxes of material implication', which are not a problem from the perspective of modelling resources and so not rejected by bunched logic. The semantics is also related to the 'phase semantics' of linear logic, but again is differentiated by accepting the standard semantics of and which in linear logic is rejected in a bid to be constructive. These considerations are discussed in detail in an article on Resource semantics by Pym, O'Hearn and Yang.

Categorical semantics (doubly closed categories)

The double version of the deduction theorem of bunched logic has a corresponding category-theoretic structure. Proofs in intuitionistic logic can be interpreted in
cartesian closed categories, that is, categories with finite products satisfying the adjunction correspondence relating hom sets:
Bunched logic can be interpreted in categories possessing two such structures
A host of categorial models can be given using Day's tensor product construction.
Additionally, implicational fragment of bunched logic has been given a games semantics.

Algebraic semantics

The algebraic semantics of bunched logic is a special case of its categorical semantics, but is simple to state and can be more approachable.
The boolean version of bunched logic has models as follows.

Proof theory and type theory (bunches)

The proof calculus of bunched logic
differs from usual sequent calculi in having a tree-like context of hypotheses instead of a flat list-like structure. In its sequent-based proof theories, the
context in an entailment judgement
is a tree whose leaves are propositions and whose internal nodes are labelled with modes of composition corresponding to the two conjunctions.
The two combining operators, comma and semicolon, are used in the introduction rules for the two implications.
The difference between the two composition rules comes from additional rules that apply to them.
The structural rules and other operations on bunches are often applied deep within a tree-context, and not only at the top level: it is thus in a sense a calculus of deep inference.
Corresponding to bunched logic is a type theory having two kinds of function type. Following the Curry–Howard correspondence, introduction rules for implications correspond to introduction rules for function types.
Here, there are two distinct binders, and, one for each kind of function type.
The proof theory of bunched logic has an historical debt to the use of bunches in Relevance logic. But the bunched structure can in a sense be derived from the categorical and algebraic semantics:
to formulate an introduction rule for we should mimick on the left in sequents, and to introduce we should mimick. This consideration leads to the use of two combining operators.
James Brotherston has done further significant work on a unified proof theory for bunched logic and variants, employing Belnap's notion of display logic.
Galmiche, Méry, and Pym have provided a comprehensive treatment of bunched logic, including completeness and other meta-theory, based on labelled tableaux.

Applications

Interference control

In perhaps the first use of substructural type theory to control resources, John C. Reynolds showed how to use an affine type theory to control aliasing and other forms of interference in Algol-like programming languages. O'Hearn used bunched type theory to extend Reynolds system by allowing interference and non-interference to be more flexibly mixed. This resolved open problems concerning recursion and jumps in Reynolds's system.

Separation logic

Separation logic is an extension of Hoare logic which facilitates reasoning about mutable data structures that use pointers. Following Hoare logic the formulae of separation logic are of the form
, but the preconditions and postconditions are formulae interpreted in a model of bunched logic.
The original version of the logic was based on models as follows:
It is the undefinedness of the composition on overlapping heaps that models the separation idea. This is a model of the boolean variant of bunched logic.
Separation logic was used originally to prove sequential programs, but then was extended to concurrency using a proof rule
that divides the storage accessed by parallel threads.
Later, the greater generality of the resource semantics was utilized: an abstract version of separation logic works for Hoare triples
where the preconditions and postconditions are formulae interpreted over an arbitrary partial commutative monoid instead of a particular heap model.
By suitable choice of commutative monoid, it was surprisingly found that the proofs rules of abstract versions of concurrent separation logic could be used to reason about interfering concurrent processes, for example by encoding rely-guarantee and trace-based reasoning.
Separation logic is the basis of a number of tools for automatic and semi-automatic reasoning about programs, and is used in the Infer program analyzer currently deployed at Facebook.

Resources and processes

Bunched logic has been used in connection with the resource-process calculus SCRP in order to give a logic which characterizes, in the sense of Hennessey-Milner, the compositional structure of concurrent systems.
SCRP is notable for interpreting in terms of both parallel composition of systems and composition of their associated resources.
The semantic clause of SCRP's process logic that corresponds to separation logic's rule for concurrency asserts that a formula is true in resource-process state, just in case there are decompositions of the resource and process
~, where ~ denotes bisimulation, such that is true in the resource-process state , and is true in the resource-process state , ; that is iff and.
The system SCRP is based directly on bunched logic's resource semantics; that is, on ordered monoids of resource elements. While direct and intuitively appealing, this choice leads to a specific technical problem: the Hennessy-Milner completeness theorem holds only for fragments of the modal logic that exclude the multiplicative implication and multiplicative modalities. This problem is solved by basing resource-process calculus on a resource semantics in which resource elements are combined using two combinators, one corresponding to concurrent composition and one corresponding to choice.

Spatial logics

Cardelli, Caires, Gordon and others have investigated a series of logics of process calculi, where a conjunction is interpreted in terms of parallel composition.
Unlike the work of Pym et al. in SCRP, they do not distinguish between parallel composition of systems and composition of resources accessed by the systems.
Their logics are based on instances of the resource semantics which give rise to models of the boolean variant of bunched logic.
Although these logics give rise to instances of boolean bunched logic, they appear to have been arrived at independently, and in any case have significant additional structure in the way of modalities and binders. Related logics have been proposed as well for modelling XML data.