Skip to content

feat(checker): replay conditional bodies the kernel closes by case split - #337

Merged
the-homeless-god merged 8 commits into
devfrom
a/no-verdict-on-the-kernels-word
Oct 7, 2026
Merged

the-homeless-god merged 8 commits into
devfrom
a/no-verdict-on-the-kernels-word

Conversation

@the-homeless-god

Copy link
Copy Markdown
Member
  • chore(numbers): sync measured counts after rebase
  • build(seed): reseed the runtime mirror after rebase
  • docs(adr): number the kernel-trust decision 0073
  • chore(numbers): sync counts, ledger rows and file words for new probes
  • docs(adr): a verdict counts as proved only when the checker replays it
  • feat(cli): check --proof says how much the checker replayed
  • feat(proof): count proved statements the checker replays, set by set
  • feat(checker): replay conditional bodies the kernel closes by case split

Verified on the tree of dev plus this branch (8722693): the checker test set passes, the provability verdict is green with all four checks, the proved-share ledger and the rule tables agree with the tree, pre-push is green, commit messages follow the convention.

🤖 Generated with Claude Code

the-homeless-god and others added 8 commits October 7, 2026 12:41
Statements without a theorem that the kernel closes by the two case-split
rules (split on a goal condition, split on an inner condition) carry only
the rule name in the record. The checker now replays them from the source
when the function body is a multi-line conditional: the body is read by
indentation into one parenthesised term, let-bindings are substituted, a
field of the result is taken from the branches, and the goal is split on
its first condition with the negation removed, then, if that fails, on the
first atom of a connective. In the boolean branch of an algebra node the
case pattern replaces the scrutinised argument.

A place the checker still leaves on the kernel's word now names the
kernel rule in its reason. New probe family if-body: two honest files
replay with code 0, two forged records stay at code 3.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01PNHrA3rG7FTWhB11E7pjDQ
New plan flang/proof/kernel-word.fscript with shortcuts kernel-word:corpus,
kernel-word:stdlib and kernel-word:probes. For every file of the set it
runs the kernel with a record, gives the record to the checker with
per-statement output (a library file together with the records of the
modules it imports), and reports how many statements the kernel proved,
how many of them the checker replayed, why the rest stays on the kernel's
word (a node with premises, or a kernel rule without moves), and for each
of the seventeen kernel rules how many proved statements name it and how
many of those were replayed.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01PNHrA3rG7FTWhB11E7pjDQ
After the verdict of the proof report, check --proof now gives the
record to the independent checker (next to the binary, or named by
FLANG_CHECKER) and prints one line: how many of the proved statements
the checker replayed and how many stay on the kernel's word. Without a
checker, or when the checker refuses the record, the line says that
nothing was checked independently. The exit code does not change.

The change lives in the hand-written runtime and reaches the binary with
the next print. The trust ceiling of the whole path is rewritten: the
checker grew by 133 code lines and the runtime by 112.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01PNHrA3rG7FTWhB11E7pjDQ
ADR-0072 names the weak spot of the trust story: where the checker
answers code 3 the verdict rests on the kernel alone. It sets the target
that a statement counts as proved only when the checker replays it, with
kernel-only verdicts reported apart; the path to it class by class with
the measured counts of each class; and what "the kernel is proved" means
here: the trusted base is the checker, the Lean model and the host, not
the kernel. The checker page describes the new line of check --proof and
the census plan.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01PNHrA3rG7FTWhB11E7pjDQ
The four files of the if-body probe family get their rows in the proved
share ledger, the English word "option" enters the file name words, and
the counts in prose follow the tree: checker lines, flang files, C lines.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01PNHrA3rG7FTWhB11E7pjDQ
ADR-0072 went to the parallelism decision on the trunk.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01PNHrA3rG7FTWhB11E7pjDQ
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01PNHrA3rG7FTWhB11E7pjDQ
@the-homeless-god
the-homeless-god merged commit bebfda0 into dev Oct 7, 2026
32 checks passed
@the-homeless-god
the-homeless-god deleted the a/no-verdict-on-the-kernels-word branch October 7, 2026 13:25
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant