STATEMENT BINDING (Phase 3d). The coverage gate pins every constant's name,
kind and axiom cone, both directions, and none of selftest_audit.sh's nine
attacks defeat it. It is nevertheless blind to what a declaration SAYS — and
that is demonstrated here rather than argued:
Wrapping one branch of `LTLAcc.pinAccept`'s body in `id (…)` is
definitionally equal. Every downstream proof still compiles. The name, the
kind, the type and the axiom cone are unchanged. The inventory gate reports
"222 constants, environment == allowlist" — GREEN.
That edit is harmless by construction; the point is that nothing stood between
it and a genuinely vacuous redefinition of a specification. Proofs/Inventory.lean
now also emits, for every inventoried constant, its fully-elaborated TYPE, and
for every definition its fully-elaborated BODY — 266 lines over 222 constants.
Proof terms are deliberately absent: by proof irrelevance a theorem's content
is its statement. check.sh Phase 3d binds the SHA-256 and the block is
committed as AUDIT-MANIFEST.txt so a mismatch is DIFFED, not merely reported.
The existing gate is untouched, per the standing rule that the port flows FROM
this repo, not to it: INV lines are byte-identical, inventory_gate.sh is
unchanged, and all nine of its attacks still fail as before.
selftest_statements.sh replays the defeq edit as case 1, asserting BOTH that
the coverage gate passes it and that Phase 3d catches it — so if the coverage
gate ever grows to see this, the test says so instead of quietly re-labelling.
Cases 2-4 cover a hand-edited committed block, a truncated block, and a
constant inventoried without a statement.
FIDELITY PIN (unrelated, found while running the button). Phase 4 had been
failing since 2026-07-23: LIED_PIN_DIV expected 3,867 divergences between the
Lean model and the deployed consistency verifier, and observed 0. Cause is
pacta ddbb5a4, which restored the RFC 9162 2.1.4.2 Step-7 terminal `sn == 0`
condition; that one conjunct removes every divergence in the pinned
73,573-case family. KNOWN-GAPS gap 14 already recorded the closure on the day
it landed — only this constant was stale, so the button had been red for five
days with nobody running it. The pin now reads 0 with the history in a comment.
Nothing about the paper, public log entry 13, or the attested commit
|
||
|---|---|---|
| docs | ||
| verification | ||
| .gitignore | ||
| ATTESTATION-RUNBOOK.md | ||
| KNOWN-GAPS.md | ||
| README.md | ||
| RESPONSE-TO-REVIEWERS.md | ||
| STATEMENT-MAP.md | ||
ltl-accumulator-verified
Lean 4 mechanization of the security analysis (§6) of the system
report "The Lean Transparency Log" (archived at
https://ltl.zkdefi.org/paper/v0.2 — the version this corpus was built
against; the current paper, "Accountable Distribution of Machine-Checked
Correctness Evidence" at https://ltl.zkdefi.org/paper, presents these
results in its §5 and carries this corpus as entry 13): the Merkle
accumulator's own correctness and soundness theorems, kernel-checked, in
the same discipline as the four *-ed25519-verified subject corpora.
Status: ATTESTED — LTL entry 13, live (2026-07-16)
This corpus is now itself a leaf of the log it describes. It was appended
as entry 13 of the Lean Transparency Log (freeze 172a1d0), so the
log carries kernel-checked proofs about the accumulator model
underlying its own inclusion and consistency reasoning (a deployment we
are unaware of a precedent for; scoped to the mechanized model, not the
deployed verifier — see below). Live head after the append:
tree size 13, root
3488a2d0ff9f00415bb561d61b01a420e3ca2e0f7b29351ec9ebb3f57319da0d; this
corpus is leaf index 12, hash
8cb258d657f1fd00baaa9e0091e26c316cb69b591cb249a9543f51cade57c50a. The
old 12-leaf head (bcd15f9d…) is a proven prefix; the 12→13 consistency
transition is accepted by both the deployed verifier and the mechanized
model. Fetch and verify it at
ltl.zkdefi.org/v1/sth. The leaf carries
its own scope block: what is kernel-checked is the mechanized model
(§6), and correspondence to the deployed verifier is scoped by
KNOWN-GAPS 14/15 — the leaf does not claim the deployed verifier is
formally verified.
All paper-§6/§10 mechanization targets (v0.2 numbering) are
kernel-checked; the audit
surface is defined and green (verification/check.sh, exit 0). See
STATEMENT-MAP.md for the paper↔Lean review surface and
KNOWN-GAPS.md for the honest scope ledger.
Reviewed across six external adversarial rounds (GPT-5.6 + a second
Claude; zero broken theorems in any round; both approved). The audit
surface is an environment-derived inventory (Proofs/Inventory.lean +
pinned allowlist — 222 constants, 61 human-reviewed cones, self-tested by
selftest_audit.sh); the review kit is push-button reproducible
(run_bare.sh, self-contained fidelity target);
acceptIncl/acceptCons_sound route the theorems through the named
acceptance predicates; fidelity = agreement over pinned families
(230,271 + 230,016 baseline; 73,573 lied-size boundary cases with
3,867 expected one-sided divergences — KNOWN-GAPS gaps 14/15, not
extensional equality). Doc counts are asserted by check.sh Phase 3c.
How the append was done — release tuple, preflight, candidate-inspection
gate, and the 12→13 structural rehearsal — is recorded in
ATTESTATION-RUNBOOK.md.
| layer | content | status |
|---|---|---|
| L1 | bytes, hleaf/hnode, domain separation (Lemma 1) | done (domsep: axiom-free) |
| L2 | MTH, Root, ConsRec definitions + termination | done (cones: propext, LTLAcc.sha256, Quot.sound) |
| L3 | inclusion completeness (Theorem 1) + named acceptance acceptIncl |
done (incl_complete: propext, Classical.choice, LTLAcc.sha256, Quot.sound) |
| L4 | frontier binding content (Lemma 2) | done as specializations — inlined in the extractor walk (extractIncl), whole-tree (extractMTH), ConsRec (consRecBinding); the standalone Root receipt-uniqueness instance was deleted with the vacuous root_binding in S3.5 and deliberately NOT restored (optional, unused — KNOWN-GAPS gap 3) |
| L5 | inclusion soundness = EXPLICIT extractor extractIncl (Theorem 2) |
done, non-vacuous |
| L6a | descent extractor extractMTH (Theorem 3 step 3 = Lemma 2, whole-tree instance) |
done, non-vacuous |
| L6b | Theorem 3 (consistency soundness): consRecBinding (steps 1–2) + extractCons/extractCons_correct (+ _paper at the paper's exact quantifiers; acceptCons_sound routes it through the named acceptCons predicate, size bound derived from acceptance via consRec_some_le) |
done, non-vacuous |
| L6c | pin-store state machine safety (Proposition 1): pinAccept_monotone, pin_prefix_correct, fork_distinct |
done, non-vacuous (per-step; multi-step chain = gap 7) |
Discipline (identical to the subject corpora)
verification/Proofs/contains ZEROaxiomdeclarations; the single sanctioned axiom site isverification/gen/— here, one opaque function: SHA-256. The theorems are constructive collision extractors, so collision resistance is never assumed, only interpreted.verification/check.shis THE button: compiles every file throughlean-guard(memory cap, core pinning, timeout, single-flight lock) and axiom-audits every certificate against its documented exact cone.- Reviewers without the operator toolchain:
verification/run_bare.shcompiles, axiom-audits, and inventory-gates the corpus with a plain publiclean(version pinned inverification/lean-toolchain); the operator path is overridable viaAENEAS_ENV. - Expected boundary:
propext, Classical.choice, Quot.soundplusLTLAcc.sha256for hash-touching certificates — documented per certificate incheck.sh, audited both directions.
The finished certificates are destined for the LTL itself as attestation leaves: the log carrying kernel-checked proofs of its own machinery.