The consumer pin store (§5.4) as a transition predicate; the paper's
Prop 1(1) fully mechanized:
- pinAccept: same-size ⇒ root match; smaller ⇒ reject (rollback); larger
⇒ consistency proof verifies. Mirrors sthstore.py.
- pinAccept_monotone: an accepted step never shrinks the pin (definitional).
- pin_prefix_correct: an honest advance where D is NOT the prefix of D'
makes pinExtract output a genuine collision — same-size routes to
extractMTH (whole-tree Lemma 2), grow routes to extractCons (Theorem 3).
Explicit named-extractor form ⇒ non-vacuous (pin_prefix_nonvacuous
pinned).
- fork_distinct: the Merkle share of Prop 1(2) — different roots at equal
size commit to different content. EUF-CMA transferable-evidence is
signature-layer, OUT OF SCOPE and documented in the file header (not
smuggled).
Cones: single hash axiom (pin_prefix_correct adds Classical.choice via
functional induction downstream). 33 certs green. Fable statement-audit:
matches paper Prop 1(1); Prop 1(2) scope-bounded honestly. LTL untouched.
Every §6 statement is now kernel-checked: Lemma 1, Theorems 1-3,
whole-tree Lemma 2, Proposition 1. Remaining: S7 fidelity, S8 freeze.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>