ltl-accumulator-verified/verification/Proofs/AxiomCheck.lean
mrwulf db45c0e33f S7 Fable re-audit: close the cone-audit COVERAGE gap (52/52), verify button by exit code
Re-derived S7 as Fable, practicing the standing rule (check exit code +
ALL GREEN, not tail). Confirmed committed button genuinely exits 0.

FINDING: the cone audit had a COVERAGE gap — 34 of 52 proven objects
were pinned; 18 (incl. core defs kbelow/hleaf/hnode and the pin-store
defs pinAccept/pinExtract/acceptCons, plus intermediate lemmas) were
never cone-audited. Transitively safe (Phase 1 forbids axiom under
Proofs/, Phase 2 forbids sorry, universally) — but 'transitively
covered' is not good enough for an externally-reviewed corpus. Closed:
every proven theorem/def now has its EXACT cone pinned, read from
#print axioms (not guessed). Coverage now 52/52, empty unaudited list.

Cones of note: hleaf/hnode = [LTLAcc.sha256] only; kbelow and the pure
arithmetic/list helpers = no hash axiom; the def-level objects that
touch MTH carry the single sha256 boundary. No surprise axioms anywhere.

Button verified: EXIT 0, ALL GREEN, FIDELITY GREEN, 164,479/164,224
pinned. LTL untouched.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-11 20:56:17 +02:00

63 lines
2.1 KiB
Text

/- Axiom-cone observation for the audit (Phase 3 of check.sh). -/
import Proofs.Basic
import Proofs.Completeness
import Proofs.Extract
import Proofs.Descent
import Proofs.Consistency
import Proofs.Binding3
import Proofs.Refactor
import Proofs.Theorem3
import Proofs.PinStore
#print axioms LTLAcc.domsep
#print axioms LTLAcc.kbelow_pos
#print axioms LTLAcc.kbelow_lt
#print axioms LTLAcc.le_two_kbelow
#print axioms LTLAcc.kbelow_pow2
#print axioms LTLAcc.MTH
#print axioms LTLAcc.Root
#print axioms LTLAcc.ConsRec
#print axioms LTLAcc.Path
#print axioms LTLAcc.incl_complete
#print axioms LTLAcc.hnode_preimage_inj
#print axioms LTLAcc.IsCollision
#print axioms LTLAcc.extractIncl
#print axioms LTLAcc.extractIncl_correct
#print axioms LTLAcc.extractIncl_nonvacuous
#print axioms LTLAcc.extractMTH
#print axioms LTLAcc.extractMTH_correct
#print axioms LTLAcc.extractMTH_nonvacuous
#print axioms LTLAcc.kbelow_prefix_eq
#print axioms LTLAcc.take_take_le
#print axioms LTLAcc.take_drop_prefix
#print axioms LTLAcc.extractConsNode
#print axioms LTLAcc.take_all
#print axioms LTLAcc.consRecBinding
#print axioms LTLAcc.consRec_base_false_eq
#print axioms LTLAcc.consRec_base_true_eq
#print axioms LTLAcc.extractCons
#print axioms LTLAcc.extractCons_correct
#print axioms LTLAcc.extractCons_nonvacuous
#print axioms LTLAcc.pinAccept_monotone
#print axioms LTLAcc.pin_prefix_correct
#print axioms LTLAcc.fork_distinct
#print axioms LTLAcc.pin_prefix_nonvacuous
#print axioms LTLAcc.MTH_single
#print axioms LTLAcc.MTH_split
#print axioms LTLAcc.Root_left
#print axioms LTLAcc.Root_one
#print axioms LTLAcc.Root_one_cons
#print axioms LTLAcc.Root_right
#print axioms LTLAcc.acceptCons
#print axioms LTLAcc.eq_dropLast_append_of_getLast?
#print axioms LTLAcc.exists_singleton_of_length_one
#print axioms LTLAcc.getD_drop
#print axioms LTLAcc.getD_take
#print axioms LTLAcc.hleaf
#print axioms LTLAcc.hnode
#print axioms LTLAcc.kbelow
#print axioms LTLAcc.kbelow_eq_of_pow2_between
#print axioms LTLAcc.pinAccept
#print axioms LTLAcc.pinExtract
#print axioms LTLAcc.pow2_exp_unique
#print axioms LTLAcc.take_append_drop