docs: estate-wide consistency pass (workflow audit, 36 findings, all verified before fixing)

Nine parallel readers audited every doc against measured ground truth; every
finding was re-verified against the file before any edit, and the sweep fixed
by PROPERTY, not by flag — wording the readers caught in one repo was hunted
in all siblings (the two-button README sentence existed in all four forks,
not the three flagged; likewise the cone-overclaim in TRUSTED-BASE item 1).

This repo: see the diff. Records were not rewritten; clarifications are
dated. Doc-only except where noted in the estate summary; every gated doc
change was followed by a green button run.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
mrwulf 2026-08-07 16:00:54 +02:00
parent 640b81c1e5
commit 64dfe090c7
3 changed files with 21 additions and 11 deletions

View file

@ -22,9 +22,12 @@ Lean 4 against models extracted from the actual Rust sources:
## The book ## The book
**[`main.pdf`](main.pdf)** — twelve chapters + interlude + three **[`main.pdf`](main.pdf)** — thirteen chapters + interlude + three
appendices, 106 pages, full color, built with LaTeX/TikZ from the sources appendices, full color, built with LaTeX/TikZ from the sources in this
in this repo. No prior Lean or formal methods assumed; high-school algebra repo. **Honesty note:** the committed PDF (109 pages) was built 2026-07-06,
before chapter 13 was committed (2026-07-28) — rebuild with the command
below to get the current book; the committed PDF lags the committed
sources until the next rebuild on a LaTeX-equipped machine. No prior Lean or formal methods assumed; high-school algebra
and a little programming suffice. and a little programming suffice.
1. **Why Verify?** — the carry bug testing cannot find 1. **Why Verify?** — the carry bug testing cannot find
@ -40,6 +43,7 @@ and a little programming suffice.
10. **Verifying a Field** — the full campaign, told honestly (including the crash) 10. **Verifying a Field** — the full campaign, told honestly (including the crash)
11. **Honesty and Axioms**`#print axioms`, hollow certificates, trusted bases 11. **Honesty and Axioms**`#print axioms`, hollow certificates, trusted bases
12. **The Pyramid** — group law, scalars, signatures, and where you come in 12. **The Pyramid** — group law, scalars, signatures, and where you come in
13. **The Attestation Protocol** — what it takes to make "it is proven" checkable by a stranger
Appendices: **A** — the pen-and-paper toolkit (recipe cards with drills); Appendices: **A** — the pen-and-paper toolkit (recipe cards with drills);
**B** — guided walkthroughs of every exercise-file hole; **C** — a tour of **B** — guided walkthroughs of every exercise-file hole; **C** — a tour of
@ -118,10 +122,12 @@ In the spirit of Chapter 11:
twice (mod-13 sign-bit walk, then the real compressed base point: twice (mod-13 sign-bit walk, then the real compressed base point:
byte-31 sign bit, and the full-size hand verification 5·y_B 4 = 4·p, byte-31 sign bit, and the full-size hand verification 5·y_B 4 = 4·p,
every digit printed), plus a new paper exercise (12.4). Every printed every digit printed), plus a new paper exercise (12.4). Every printed
constant was machine-verified before typesetting; the PDF (109 pages) constant was machine-verified before typesetting; the PDF (109 pages,
is rebuilt from these sources. 2026-07-06 build — predates ch13) is rebuilt from these sources.
- The PDF in the repo is built from the committed sources by the command - The PDF in the repo is built from the committed sources by the command
above; rebuild it yourself if you don't trust binaries (good instinct). above — but the committed build currently predates chapter 13 (see the
honesty note at the top); rebuild it yourself if you don't trust binaries
(good instinct), and you will get the thirteen-chapter book.
- The three named solution certificates were kernel-audited - The three named solution certificates were kernel-audited
(coherence pass 2, 2026-07-03): `Ch09.add_spec` depends on (coherence pass 2, 2026-07-03): `Ch09.add_spec` depends on
`[propext, Classical.choice, Quot.sound]`; `Ch09.mulVal_spec` and `[propext, Classical.choice, Quot.sound]`; `Ch09.mulVal_spec` and

View file

@ -171,7 +171,9 @@ actually wrote.
\medskip \medskip
\noindent That is the last hole in the last file. If you worked them \noindent That is the last hole in the last file. If you worked them
all: the companion repositories' open scalar-layer lemmas are shaped all: the scalar layer that was open when this appendix was first written is
exactly like 9.B --- bigger constants, same bones --- and the now complete on all four companion forks (thirteen certificates each ---
\code{CONTRIBUTING} notes there will treat you as what you now are: lemmas shaped exactly like 9.B, bigger constants, same bones). The open
someone who has done this before. frontier today is the paused Pasta curve layer, and chapter 12's ``Extend
the pyramid'' item points at it; the \code{CONTRIBUTING} notes there will
treat you as what you now are: someone who has done this before.

View file

@ -225,7 +225,9 @@ A verified fork is verified \emph{at a commit}. Change one line of
arithmetic and the certificate is stale --- that is a feature (the proof arithmetic and the certificate is stale --- that is a feature (the proof
\emph{should} break when the code changes), but it means verification is a \emph{should} break when the code changes), but it means verification is a
\emph{process wired into maintenance}, not a trophy. The companion repos \emph{process wired into maintenance}, not a trophy. The companion repos
ship \code{check.sh} scripts that re-extract and re-verify from scratch; ship \code{check.sh} scripts that recompile and re-audit every shipped
proof from scratch (extraction replay is a separate pinned recipe,
\code{verification/extract.sh});
treat those as the project's pulse, not as CI decoration. treat those as the project's pulse, not as CI decoration.
\end{pitfall} \end{pitfall}